[{"data":1,"prerenderedAt":4015},["ShallowReactive",2],{"application-flags":3,"navbar":7,"always-visible-banner":95,"navbar-about-highlight":155,"navbar-resource-highlight":211,"use-case-page":256,"blog/cross-idp-impersonation":1276},[4],{"name":5,"enabled":6},"maintenanceMode",false,[8,59,76],{"createdDate":9,"id":10,"name":11,"modelId":12,"published":13,"stageModifiedSincePublish":6,"query":14,"data":15,"variations":50,"lastUpdated":51,"firstPublished":52,"testRatio":33,"createdBy":53,"lastUpdatedBy":53,"folders":54,"meta":55,"rev":58},1742213002749,"efff2a27faf4408e9f908eba4b5542fe","inductive-automation","1c6207a5f24948ab82d4a0b17f251193","published",[],{"testimonial":16,"description":43,"type":19,"link":44,"title":47,"testimonialLink":48,"image":49},{"@type":17,"id":18,"model":19,"value":20},"@builder.io/core:Reference","f028f2b685bb47cd8bf9e82a26dd5a79","testimonial",{"query":21,"folders":22,"createdDate":23,"id":18,"name":24,"modelId":25,"published":13,"data":26,"variations":30,"lastUpdated":31,"firstPublished":32,"testRatio":33,"createdBy":34,"lastUpdatedBy":34,"meta":35,"rev":42},[],[],1735823466309,"We found Push to be more accurate when compared to competitors and the browser agent offered features that others couldn’t match.","42035571a56940ac98bff4544aa79aa5",{"author":27,"jobTitle":28,"quote":24,"image":29},"Jason Waits","\u003Cp>CISO at Inductive Automation\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Ff04c0c0689ce4a89ac0f0708d78c0a07",{},1735910703862,1735823501152,1,"ST0tXQM8slWpFrmioqKHmENB2qe2",{"kind":36,"lastPreviewUrl":37,"breakpoints":38,"hasAutosaves":41},"data","",{"small":39,"medium":40},640,768,true,"3v32gocrrqz","Join the industry's top security minds as they break down the browser attack landscape.",{"url":45,"text":46},"https://pushsecurity.com/webinar/state-of-browser-security","Save Your Spot","State of Browser Attacks Series","/customer-stories/inductive-automation","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fe94fca10aa7b46ac8052b7ea22de54cd",{},1776257019270,1742221533648,"CydmZnOWU1XuAaLhEDCoYNM4Z8W2",[],{"breakpoints":56,"kind":36,"lastPreviewUrl":37,"hasAutosaves":6},{"xsmall":57,"small":39,"medium":40},320,"motto9r9yg",{"createdDate":60,"id":61,"name":62,"modelId":12,"published":13,"query":63,"data":64,"variations":69,"lastUpdated":70,"firstPublished":71,"testRatio":33,"createdBy":53,"lastUpdatedBy":72,"folders":73,"meta":74,"rev":58},1742208588866,"1c7a4e423bf54ac1a328bb4063459ef2","Banner",[],{"type":65,"url":66,"text":67,"link":68},"web-banner","https://pushsecurity.com/resources/browser-attacks-report","Get our latest report analyzing browser attack techniques in 2026",{},{},1774258294825,1742208637545,"jKjF9r5jcvXU8tzZEfFQm31Iyvr2",[],{"kind":36,"lastPreviewUrl":37,"breakpoints":75,"hasAutosaves":41},{"xsmall":57,"small":39,"medium":40},{"createdDate":77,"id":78,"name":79,"modelId":12,"published":13,"stageModifiedSincePublish":6,"query":80,"data":81,"variations":89,"lastUpdated":90,"firstPublished":91,"testRatio":33,"createdBy":53,"lastUpdatedBy":53,"folders":92,"meta":93,"rev":58},1742208469288,"6763051b201f44a0838c6400c580ca67","Resource highlight",[],{"image":82,"type":83,"description":84,"link":85,"title":88},"https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F7b4a5ebf81d64e8c9d7fc35f6c96c4a9","resource","Learn about the latest techniques being used in the wild.",{"url":86,"text":87},"/resources/browser-attacks-report","Download now","Report: 2026 Browser Attack Techniques",{},1776255866789,1742208570400,[],{"kind":36,"lastPreviewUrl":37,"breakpoints":94,"hasAutosaves":6},{"xsmall":57,"small":39,"medium":40},{"createdDate":96,"id":97,"name":98,"modelId":99,"published":13,"query":100,"data":101,"variations":145,"lastUpdated":146,"firstPublished":147,"testRatio":33,"createdBy":34,"lastUpdatedBy":148,"folders":149,"meta":150,"rev":154},1774965361051,"fd266d0172cc47429be7ad10f48c99ad","always visible banner","0678d178ec8b41efb8a23c09dba7874d",[],{"ctaText":102,"text":103,"url":37,"blocks":104,"state":141},"ewrererw","testrfesssssssssss",[105,129],{"@type":106,"@version":107,"id":108,"component":109,"responsiveStyles":119},"@builder.io/sdk:Element",2,"builder-ca12c06a52de41d7b8743da53118cd38",{"name":110,"tag":110,"options":111,"isRSC":118},"TopBannerContent",{"text":112,"ctaText":46,"url":45,"mainText":113,"cta":116},"New Webinar Series: Join John Hammond, Troy Hunt, and Matt Johansen for the State of Browser Attacks",{"content":114,"fontSize":115},"\u003Cp>New Webinar Series: Join John Hammond, Troy Hunt, and Matt Johansen for the State of Browser Attacks\u003C/p>","text-base",{"content":117,"fontSize":115,"url":45},"\u003Cp>\u003Cstrong style=\"font-weight:700;\">Save Your Spot\u003C/strong>\u003C/p>\n",null,{"large":120},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"marginTop":126,"marginBottom":126,"fontSize":127,"fontWeight":128},"flex","column","relative","0","border-box",".56rem","1.125rem","700",{"id":130,"@type":106,"tagName":131,"properties":132,"responsiveStyles":136},"builder-pixel-08zrjigffq5t","img",{"src":133,"aria-hidden":134,"alt":37,"role":135,"width":124,"height":124},"https://cdn.builder.io/api/v1/pixel?apiKey=f3a1111ff5be48cdbb123cd9f5795a05","true","presentation",{"large":137},{"height":124,"width":124,"display":138,"opacity":124,"overflow":139,"pointerEvents":140},"block","hidden","none",{"deviceSize":142,"location":143},"large",{"path":37,"query":144},{},{},1775137295127,1774968080803,"ax7YYfD0OCeqT1Vxxv1G4FUbqVr1",[],{"breakpoints":151,"hasLinks":6,"kind":152,"lastPreviewUrl":153,"hasAutosaves":6},{"xsmall":57,"small":39,"medium":40},"component","https://pushsecurity.com/?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditCode%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CeditProjects%2CmodifyMcpServers%2CmodifyWorkflowIntegrations%2CmodifyProjectSettings%2CconnectCodeRepository%2CcreateProjects%2CindexDesignSystems%2CsendPullRequests%2CmergePullRequests&builder.user.role.name=Developer&builder.user.role.id=developer&builder.cachebust=true&builder.preview=always-visible-banner&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.always-visible-banner=fd266d0172cc47429be7ad10f48c99ad&builder.overrides.fd266d0172cc47429be7ad10f48c99ad=fd266d0172cc47429be7ad10f48c99ad&builder.options.locale=Default","2lvuonnywj",[156,180],{"createdDate":157,"id":158,"name":159,"modelId":160,"published":13,"stageModifiedSincePublish":6,"query":161,"data":162,"variations":173,"lastUpdated":174,"firstPublished":175,"testRatio":33,"createdBy":53,"lastUpdatedBy":53,"folders":176,"meta":177,"rev":179},1776247359804,"9136a8f18b3b4a6ba29b8653a99372b1","testimonial-inductive-automation","20d9eaa352304613b3d1a794b400703d",[],{"link":163,"type":19,"testimonialLink":48,"testimonial":164},{},{"@type":17,"id":18,"model":19,"value":165},{"query":166,"folders":167,"createdDate":23,"id":18,"name":24,"modelId":25,"published":13,"data":168,"variations":169,"lastUpdated":31,"firstPublished":32,"testRatio":33,"createdBy":34,"lastUpdatedBy":34,"meta":170,"rev":172},[],[],{"author":27,"jobTitle":28,"quote":24,"image":29},{},{"kind":36,"lastPreviewUrl":37,"breakpoints":171,"hasAutosaves":41},{"small":39,"medium":40},"7t755zfvte3",{},1776247404986,1776247404973,[],{"breakpoints":178,"kind":36,"lastPreviewUrl":37,"hasAutosaves":6},{"xsmall":57,"small":39,"medium":40},"4moh0qpywtr",{"createdDate":181,"id":182,"name":88,"modelId":160,"published":13,"meta":183,"stageModifiedSincePublish":6,"query":185,"data":186,"variations":207,"lastUpdated":208,"firstPublished":209,"testRatio":33,"createdBy":53,"lastUpdatedBy":53,"folders":210,"rev":179},1776255761419,"05a9322735fc427db12e2740e4302300",{"breakpoints":184,"kind":36,"lastPreviewUrl":37,"hasAutosaves":6},{"xsmall":57,"small":39,"medium":40},[],{"testimonial":187,"link":206,"type":83,"title":88,"description":84,"image":82},{"@type":17,"id":188,"model":19,"value":189},"192acbb1f9ca4cac918c0ec435a8bae3",{"query":190,"folders":191,"createdDate":192,"id":188,"name":193,"modelId":25,"published":13,"data":194,"variations":200,"lastUpdated":201,"firstPublished":202,"testRatio":33,"createdBy":34,"lastUpdatedBy":53,"meta":203,"rev":205},[],[],1728981467463,"Push does for identity what CrowdStrike did for the endpoint",{"video":195,"jobTitle":196,"author":197,"qoute":37,"quote":198,"image":199},"https://cdn.builder.io/o/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F8b30e8ca50064058bbaef0f3c6164575%2Fcompressed?apiKey=f3a1111ff5be48cdbb123cd9f5795a05&token=8b30e8ca50064058bbaef0f3c6164575&alt=media&optimized=true","\u003Cp>Deputy CISO at Microsoft\u003C/p>\u003Cp>Former LinkedIn, Slack, Palantir\u003C/p>","Geoff Belknap","Push does for identity what CrowdStrike did for the endpoint.","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F748f0ad0a5064a00a13f4721fcc8dea1",{},1742902158597,1728981782923,{"kind":36,"lastPreviewUrl":37,"breakpoints":204,"hasAutosaves":41},{"small":39,"medium":40},"6s8ic0w0ao6",{"text":87,"url":86},{},1776255810913,1776255810900,[],[212,235],{"createdDate":213,"id":214,"name":88,"modelId":215,"published":13,"meta":216,"stageModifiedSincePublish":6,"query":218,"data":219,"variations":230,"lastUpdated":231,"firstPublished":232,"testRatio":33,"createdBy":53,"lastUpdatedBy":53,"folders":233,"rev":234},1776256900280,"1f429607996e4e5fae8fe3f9b9610e55","4829faa81e7c4ee8bd2d000e160e8d3c",{"breakpoints":217,"kind":36,"lastPreviewUrl":37,"hasAutosaves":6},{"xsmall":57,"small":39,"medium":40},[],{"testimonial":220,"link":229,"type":83,"title":88,"description":84,"image":82},{"@type":17,"id":188,"model":19,"value":221},{"query":222,"folders":223,"createdDate":192,"id":188,"name":193,"modelId":25,"published":13,"data":224,"variations":225,"lastUpdated":201,"firstPublished":202,"testRatio":33,"createdBy":34,"lastUpdatedBy":53,"meta":226,"rev":228},[],[],{"video":195,"jobTitle":196,"author":197,"qoute":37,"quote":198,"image":199},{},{"kind":36,"lastPreviewUrl":37,"breakpoints":227,"hasAutosaves":41},{"small":39,"medium":40},"r77qqueuo3j",{"text":87,"url":86},{},1776256937553,1776256937540,[],"q0jkez80wkg",{"createdDate":236,"id":237,"name":11,"modelId":215,"published":13,"stageModifiedSincePublish":6,"query":238,"data":239,"variations":250,"lastUpdated":251,"firstPublished":252,"testRatio":33,"createdBy":53,"lastUpdatedBy":53,"folders":253,"meta":254,"rev":234},1776256949234,"ce043785b71b4ece98eac811ecf4ba10",[],{"link":240,"type":19,"testimonial":241,"testimonialLink":48},{},{"@type":17,"id":18,"model":19,"value":242},{"query":243,"folders":244,"createdDate":23,"id":18,"name":24,"modelId":25,"published":13,"data":245,"variations":246,"lastUpdated":31,"firstPublished":32,"testRatio":33,"createdBy":34,"lastUpdatedBy":34,"meta":247,"rev":249},[],[],{"author":27,"jobTitle":28,"quote":24,"image":29},{},{"kind":36,"lastPreviewUrl":37,"breakpoints":248,"hasAutosaves":41},{"small":39,"medium":40},"mnaneamy308",{},1776256974140,1776256974130,[],{"breakpoints":255,"kind":36,"lastPreviewUrl":37,"hasAutosaves":6},{"xsmall":57,"small":39,"medium":40},[257,441,560,679,797,917,1037,1157],{"createdDate":258,"id":259,"name":260,"modelId":261,"published":13,"stageModifiedSincePublish":6,"query":262,"data":268,"variations":429,"lastUpdated":430,"firstPublished":431,"testRatio":33,"screenshot":432,"createdBy":34,"lastUpdatedBy":433,"folders":434,"meta":435,"rev":440},1744829487099,"387451215c314dd5bd654668cdc1a197","Zero-day phishing","cca4143377554c5a9163cc203a8ed2ba",[263],{"@type":264,"property":265,"operator":266,"value":267},"@builder.io/core:Query","urlPath","is","/uc/zero-day-phishing-protection",{"inputs":269,"customFonts":270,"seoTitle":318,"title":318,"tsCode":37,"seoDescription":319,"fontAwesomeIcon":320,"jsCode":37,"blocks":321,"url":267,"state":426},[],[271],{"family":272,"kind":273,"version":274,"lastModified":275,"files":276,"category":295,"menu":296,"subsets":297,"variants":300},"DM Sans","webfonts#webfont","v14","2023-07-13",{"100":277,"200":278,"300":279,"500":280,"600":281,"700":282,"800":283,"900":284,"800italic":285,"900italic":286,"700italic":287,"100italic":288,"italic":289,"regular":290,"200italic":291,"500italic":292,"300italic":293,"600italic":294},"https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwAop1hTmf3ZGMZpg.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwAIpxhTmf3ZGMZpg.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwA_JxhTmf3ZGMZpg.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwAkJxhTmf3ZGMZpg.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwAfJthTmf3ZGMZpg.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwARZthTmf3ZGMZpg.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwAIpthTmf3ZGMZpg.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwAC5thTmf3ZGMZpg.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2rp2ywxg089UriCZaSExd86J3t9jz86Mvy4qCRAL19DksVat8JCm3zRmYJpso5.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2rp2ywxg089UriCZaSExd86J3t9jz86Mvy4qCRAL19DksVat8gCm3zRmYJpso5.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2rp2ywxg089UriCZaSExd86J3t9jz86Mvy4qCRAL19DksVat9uCm3zRmYJpso5.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2rp2ywxg089UriCZaSExd86J3t9jz86Mvy4qCRAL19DksVat-JDG3zRmYJpso5.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2rp2ywxg089UriCZaSExd86J3t9jz86Mvy4qCRAL19DksVat-JDW3zRmYJpso5.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwAopxhTmf3ZGMZpg.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2rp2ywxg089UriCZaSExd86J3t9jz86Mvy4qCRAL19DksVat8JDW3zRmYJpso5.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2rp2ywxg089UriCZaSExd86J3t9jz86Mvy4qCRAL19DksVat-7DW3zRmYJpso5.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2rp2ywxg089UriCZaSExd86J3t9jz86Mvy4qCRAL19DksVat_XDW3zRmYJpso5.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2rp2ywxg089UriCZaSExd86J3t9jz86Mvy4qCRAL19DksVat9XCm3zRmYJpso5.ttf","sans-serif","https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwAopxRT23z.ttf",[298,299],"latin","latin-ext",[301,302,303,304,305,306,128,307,308,309,310,311,312,313,314,315,316,317],"100","200","300","regular","500","600","800","900","100italic","200italic","300italic","italic","500italic","600italic","700italic","800italic","900italic","Zero-day phishing protection","Detect phishing TTPs directly in the browser and stop credential theft.","faFishingRod",[322,421],{"@type":106,"@version":107,"tagName":323,"id":324,"children":325},"div","builder-76c6b8d1499346c7bc1fd56ae4e93638",[326,343,351,358,370,385,396,407,413],{"@type":106,"@version":107,"layerName":327,"id":328,"component":329,"responsiveStyles":340},"UseCaseHero","builder-5228fe062bef4a40a91e43f1112832fa",{"name":327,"options":330,"isRSC":118},{"title":318,"description":331,"points":332,"video":339},"\u003Cp>Push detects phishing as it happens. Autonomous agents hunt for new phishing techniques, identify kit signatures, and deploy detections within minutes of a new attack being analyzed. From cloned login pages to AiTM credential harvesting, Push sees what traditional filters miss and stops threats before they escalate.\u003C/p>",[333,335,337],{"item":334},"Detect phishing that bypasses traditional filters, including AiTM, SSO password theft, and fake login pages",{"item":336},"Stop never-before-seen attacks with AI-native behavioral and on-page analysis inside the browser",{"item":338},"Investigate faster with unified browser, user, and page context","https://cdn.builder.io/o/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F40433ceeb4f94b43a82e039a0f4fd411%2Fcompressed?apiKey=f3a1111ff5be48cdbb123cd9f5795a05&token=40433ceeb4f94b43a82e039a0f4fd411&alt=media&optimized=true",{"large":341},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":342},"transparent",{"@type":106,"@version":107,"id":344,"component":345,"responsiveStyles":348},"builder-96634044407e491299e291ed64669e39",{"name":346,"options":347,"isRSC":118},"TrustedBy",{"AllPartners":41,"backgroundTransparent":6},{"large":349},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":350},"#000",{"@type":106,"@version":107,"id":352,"component":353,"responsiveStyles":356},"builder-2c3768f930534557bb8978e32b6a6a0f",{"name":354,"options":355,"isRSC":118},"Diagonal",{"darkMode":41},{"large":357},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"layerName":359,"id":360,"component":361,"responsiveStyles":368},"TextImageBlockVertical","builder-7c3c1c2840424db2ad2ccbfaf382dd64",{"name":359,"tag":359,"options":362,"isRSC":118},{"darkMode":6,"maxWidth":363,"maxTextWidth":364,"title":365,"description":366,"animatedTitle":37,"image":367,"reverse":6,"descriptionPaddingHorizontal":118},1200,800,"\u003Ch2>Why stop at the inbox?\u003C/h2>","\u003Cp>Phishing attacks have evolved. Whether attackers lure users with QR codes, instant messages, or OAuth consent screens, the outcome is the same: it plays out in the browser. Push gives you real-time detection for in-browser threats, stopping phishing and consent-based attacks before they lead to compromise\u003C/p>\u003Cp>\u003Cbr>\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F7fdcac241f0e4a049166d7076858adeb",{"large":369},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":371,"component":372,"responsiveStyles":380},"builder-41c978b3669749cf947e622b4e79e4d7",{"name":373,"options":374,"isRSC":118},"TextImageBlockHorizontal",{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":376,"title":377,"description":378,"reverse":41,"image":379},600,100,"\u003Cp>Detect phishing at the edge\u003C/p>","\u003Cp>Push uses industry-first telemetry to detect phishing based on behavior, not static indicators. Autonomous agents analyze how phishing pages behave and how users interact with them, uncovering fake logins, credential theft, and phishing kits the moment they load in the browser.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F9df3d180c97b4e61af142af2ccd68721",{"large":381},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"fontFamily":382,"paddingTop":383,"marginTop":384},"DM Sans, sans-serif","20px","0px",{"@type":106,"@version":107,"id":386,"component":387,"responsiveStyles":393},"builder-d2a7bc941feb43cdb898bc116b203cf9",{"name":373,"options":388,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":389,"title":390,"description":391,"reverse":6,"image":392},120,"\u003Ch2>Go beyond blocklists and IOCs\u003C/h2>","\u003Cp>Push goes beyond URLs and easy-to-change indicators. It reads the full phishing playbook like script behavior, session hijacks, DOM changes, user inputs, then connects the dots in real time. This gives your team a complete picture of how the phishing attempt worked, not just an alert.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fabfd58db169b433e96d3f1261797156e",{"large":394},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":395},"36px",{"@type":106,"@version":107,"layerName":373,"id":397,"component":398,"responsiveStyles":404},"builder-42c32198083f4880acb37c5cb76934da",{"name":373,"options":399,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":400,"title":401,"description":402,"reverse":41,"image":403},140,"\u003Ch2>Enhance your phishing response\u003C/h2>","\u003Cp>When phishing enters your environment, speed matters. Push gives you instant access to the telemetry that counts like session data, user behavior, and page activity, so you can investigate fast, trigger in-browser prompts, or forward alerts to your SIEM or SOAR for response. All in real time, right from the browser.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fbb195aec46904056b85e8688629e558e",{"large":405},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":406},"47px",{"@type":106,"@version":107,"id":408,"component":409,"responsiveStyles":411},"builder-9a95b9cbc4854421a92ef7b90f6c7adb",{"name":354,"options":410,"isRSC":118},{"darkMode":6},{"large":412},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":414,"component":415,"responsiveStyles":419},"builder-0afa17a9f25c4661a90f314d5578aa18",{"name":416,"tag":416,"options":417,"isRSC":118},"LatestResources",{"sectionHeading":37,"customClass":418},"bg-black",{"large":420},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"id":422,"@type":106,"tagName":131,"properties":423,"responsiveStyles":424},"builder-pixel-21yj6h3p4wh",{"src":133,"aria-hidden":134,"alt":37,"role":135,"width":124,"height":124},{"large":425},{"height":124,"width":124,"display":138,"opacity":124,"overflow":139,"pointerEvents":140},{"deviceSize":142,"location":427},{"path":37,"query":428},{},{},1776275046831,1745499158657,"https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fff60c30a8442489c8ed7e0af9599d14f","kYgMv6WsbvfmlOUYqR2SFwGzw6e2",[],{"lastPreviewUrl":436,"winningTest":118,"breakpoints":437,"kind":438,"hasLinks":6,"originalContentId":439,"hasAutosaves":6},"https://pushsecurity.com/uc/zero-day-phishing-protection?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CcreateProjects%2CsendPullRequests&builder.user.role.name=Designer&builder.user.role.id=creator&builder.cachebust=true&builder.preview=use-case-page&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.use-case-page=387451215c314dd5bd654668cdc1a197&builder.overrides.387451215c314dd5bd654668cdc1a197=387451215c314dd5bd654668cdc1a197&builder.overrides.use-case-page:/uc/zero-day-phishing-protection=387451215c314dd5bd654668cdc1a197&builder.options.locale=Default",{"xsmall":57,"small":39,"medium":40},"page","2daa5670b8504fc7ba4700633e8bd921","atvz4dp24b7",{"createdDate":442,"id":443,"name":444,"modelId":261,"published":13,"stageModifiedSincePublish":6,"query":445,"data":448,"variations":552,"lastUpdated":553,"firstPublished":554,"testRatio":33,"screenshot":555,"createdBy":34,"lastUpdatedBy":433,"folders":556,"meta":557,"rev":440},1756833377777,"54f8256648f54d439303734b1e69221b","Browser extension security",[446],{"@type":264,"property":265,"operator":266,"value":447},"/uc/browser-extension-security",{"seoDescription":449,"jsCode":37,"fontAwesomeIcon":450,"tsCode":37,"title":444,"seoTitle":444,"customFonts":451,"inputs":456,"blocks":457,"url":447,"state":549},"Shine a light on risky browser extensions.","faPuzzlePiece",[452],{"kind":273,"family":272,"version":274,"files":453,"category":295,"lastModified":275,"subsets":454,"variants":455,"menu":296},{"100":277,"200":278,"300":279,"500":280,"600":281,"700":282,"800":283,"900":284,"100italic":288,"italic":289,"regular":290,"900italic":286,"800italic":285,"700italic":287,"200italic":291,"300italic":293,"500italic":292,"600italic":294},[298,299],[301,302,303,304,305,306,128,307,308,309,310,311,312,313,314,315,316,317],[],[458,544],{"@type":106,"@version":107,"tagName":323,"id":459,"meta":460,"children":461},"builder-71d0648c1d2f4ede8d0d0b5b28b7b94c",{"previousId":324},[462,478,485,492,501,511,521,531,538],{"@type":106,"@version":107,"id":463,"meta":464,"component":465,"responsiveStyles":476},"builder-ff325b4b8fad4edea53f38865947e854",{"previousId":328},{"name":327,"options":466,"isRSC":118},{"title":444,"description":467,"points":468,"video":475},"\u003Cp>Browser extensions introduce new code, new permissions, and new potential for risk. Many include AI features, and most go completely unnoticed. Push gives you full visibility into every extension used across your workforce, across major browsers, so you can uncover shadow IT, assess risky permissions, and block unsafe tools before they lead to compromise.\u003C/p>",[469,471,473],{"item":470},"Discover every browser extension in use",{"item":472},"Spot risky or unsanctioned behavior",{"item":474},"Make informed decisions on extension policy","https://cdn.builder.io/o/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fc538aad95d7f403aa3c3551af72f67c0?alt=media&token=1411fa6d-2eac-4e6c-94bf-ea117da12d67&apiKey=f3a1111ff5be48cdbb123cd9f5795a05",{"large":477},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":342},{"@type":106,"@version":107,"id":479,"meta":480,"component":481,"responsiveStyles":483},"builder-fb89d128c64e47cf9cbb11d90fc24523",{"previousId":344},{"name":346,"options":482,"isRSC":118},{"AllPartners":41,"backgroundTransparent":6},{"large":484},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":350},{"@type":106,"@version":107,"id":486,"meta":487,"component":488,"responsiveStyles":490},"builder-54388d35126c4d0096eeebaf8c4448cd",{"previousId":352},{"name":354,"options":489,"isRSC":118},{"darkMode":41},{"large":491},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"layerName":359,"id":493,"component":494,"responsiveStyles":499},"builder-3c8fa6785dd6466abf52a2470d66d85a",{"name":359,"tag":359,"options":495,"isRSC":118},{"darkMode":6,"maxWidth":363,"maxTextWidth":364,"title":496,"description":497,"image":498,"reverse":6},"\u003Ch2>Take control of browser extensions\u003C/h2>","\u003Cp>Attackers are increasingly using malicious browser extensions to gain access to data processed and stored in the browser. And the problem is, most security teams have no visibility into what extensions are being used. Push changes that. With browser-native telemetry, the Push extension continuously inventories browser extensions across your environment, flags the risky ones, and gives you intelligence to act.&nbsp;\u003C/p>\u003Cp>\u003Cbr>\u003C/p>\u003Cp>\u003Cbr>\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F0a004f16a6874f4c8fdf14344acc9fec",{"large":500},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":502,"meta":503,"component":504,"responsiveStyles":509},"builder-93738f98109a4009affb349afd7bb182",{"previousId":371},{"name":373,"options":505,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":376,"title":506,"description":507,"reverse":41,"image":508},"\u003Ch2>Discover every extension in use\u003C/h2>","\u003Cp>Push gives you structured, searchable data about every extension in your environment, so you’re not just seeing what’s there, but also understanding how it got there, what it can do, and who it affects. It’s the kind of granular insight that’s nearly impossible to get from traditional tools, and it lays the groundwork for better policy decisions and faster investigations.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F0e5727ca99474f14b1b7916bf6bbb782",{"large":510},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"fontFamily":382,"paddingTop":383,"marginTop":384},{"@type":106,"@version":107,"id":512,"meta":513,"component":514,"responsiveStyles":519},"builder-83393acb12ee4fdd840839185b51edb4",{"previousId":386},{"name":373,"options":515,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":389,"title":516,"description":517,"reverse":6,"image":518},"\u003Ch2>Spot risky or malicious extensions\u003C/h2>","\u003Cp>Push highlights extensions with dangerous permissions, broad access, or poor reputations. This includes AI extensions that request access far beyond what their stated purpose requires. You can quickly detect sideloaded, manually installed, or development-mode extensions that bypass normal controls. And because Push shows you who’s using them and where, you can respond precisely and effectively.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fa104d58c8da34fbb8901f738fb21453b",{"large":520},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":395},{"@type":106,"@version":107,"layerName":373,"id":522,"meta":523,"component":524,"responsiveStyles":529},"builder-da98e3de949646d89c53a0d1c2784664",{"previousId":397},{"name":373,"options":525,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":400,"title":526,"description":527,"reverse":41,"image":528},"\u003Ch2>Accelerate security reviews\u003C/h2>","\u003Cp>Most teams have extension policies, they just don’t have the data to enforce them. Push reveals how each extension entered your environment, whether it was installed manually, sideloaded, or deployed in dev mode. You’ll see which users are running what, and where, so you can surface violations, investigate quickly, and respond with confidence.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F229f355be6f243b180f410d237a75bb3",{"large":530},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":406},{"@type":106,"@version":107,"id":532,"meta":533,"component":534,"responsiveStyles":536},"builder-1a689287d1a1418997d57db578a71105",{"previousId":408},{"name":354,"options":535,"isRSC":118},{"darkMode":6},{"large":537},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":539,"component":540,"responsiveStyles":542},"builder-feb4e75029f84c10b6498ef1f8f79128",{"name":416,"tag":416,"options":541,"isRSC":118},{"sectionHeading":37,"customClass":418},{"large":543},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"id":545,"@type":106,"tagName":131,"properties":546,"responsiveStyles":547},"builder-pixel-0edn39avfcei",{"src":133,"aria-hidden":134,"alt":37,"role":135,"width":124,"height":124},{"large":548},{"height":124,"width":124,"display":138,"opacity":124,"overflow":139,"pointerEvents":140},{"deviceSize":142,"location":550},{"path":37,"query":551},{},{},1776275365038,1757000441666,"https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F8d496cf111644ee5afcc046b72d1ca5a",[],{"kind":438,"winningTest":118,"breakpoints":558,"lastPreviewUrl":559,"hasLinks":6,"originalContentId":259,"hasAutosaves":6},{"xsmall":57,"small":39,"medium":40},"https://pushsecurity.com/uc/browser-extension-security?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CcreateProjects%2CsendPullRequests&builder.user.role.name=Designer&builder.user.role.id=creator&builder.cachebust=true&builder.preview=use-case-page&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.use-case-page=54f8256648f54d439303734b1e69221b&builder.overrides.54f8256648f54d439303734b1e69221b=54f8256648f54d439303734b1e69221b&builder.overrides.use-case-page:/uc/browser-extension-security=54f8256648f54d439303734b1e69221b&builder.options.locale=Default",{"createdDate":561,"id":562,"name":563,"modelId":261,"published":13,"query":564,"data":567,"variations":670,"lastUpdated":671,"firstPublished":672,"testRatio":33,"screenshot":673,"createdBy":34,"lastUpdatedBy":674,"folders":675,"meta":676,"rev":440},1744923509705,"94bebb7bb99d48629ad157e80cf4d81d","Account takeover detection",[565],{"@type":264,"property":265,"operator":266,"value":566},"/uc/account-takeover-detection",{"title":563,"customFonts":568,"jsCode":37,"seoTitle":563,"seoDescription":573,"fontAwesomeIcon":574,"tsCode":37,"blocks":575,"url":566,"state":667},[569],{"kind":273,"category":295,"variants":570,"menu":296,"files":571,"family":272,"subsets":572,"version":274,"lastModified":275},[301,302,303,304,305,306,128,307,308,309,310,311,312,313,314,315,316,317],{"100":277,"200":278,"300":279,"500":280,"600":281,"700":282,"800":283,"900":284,"300italic":293,"500italic":292,"800italic":285,"700italic":287,"italic":289,"900italic":286,"600italic":294,"200italic":291,"regular":290,"100italic":288},[298,299],"Stop ATO with stolen credential and compromised token detection.","faUserSecret",[576,662],{"@type":106,"@version":107,"tagName":323,"id":577,"meta":578,"children":579},"builder-e7913a774cae44c5a23d6081c5c30a52",{"previousId":324},[580,596,603,610,619,629,639,649,656],{"@type":106,"@version":107,"id":581,"meta":582,"component":583,"responsiveStyles":594},"builder-f1f1ab1601bc4c0f8c2a8aafd173675d",{"previousId":328},{"name":327,"options":584,"isRSC":118},{"title":563,"description":585,"points":586,"video":593},"\u003Cp>Attackers don’t need to phish, they just need a password that works. Push monitors for signs of credential-based attacks in real time, directly in the browser, catching account takeover attempts before the damage spreads. From ghost logins to credential stuffing, Push cuts off the paths attackers use to quietly slip in the back door.\u003C/p>\u003Cp>\u003Cbr>\u003C/p>",[587,589,591],{"item":588},"Identify credential-based ATO as it unfolds",{"item":590},"Surface hijacked sessions and token misuse",{"item":592},"Strengthen authentication where your IdP can’t","https://cdn.builder.io/o/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fb4dd9db24bc9495b8a686b1b4d492016%2Fcompressed?apiKey=f3a1111ff5be48cdbb123cd9f5795a05&token=b4dd9db24bc9495b8a686b1b4d492016&alt=media&optimized=true",{"large":595},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":342},{"@type":106,"@version":107,"id":597,"meta":598,"component":599,"responsiveStyles":601},"builder-0bc0d1c78ece4994993c3a6427a4d533",{"previousId":344},{"name":346,"options":600,"isRSC":118},{"AllPartners":41,"backgroundTransparent":6},{"large":602},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":350},{"@type":106,"@version":107,"id":604,"meta":605,"component":606,"responsiveStyles":608},"builder-e45de8f3768c4f16938dbf78e4e87524",{"previousId":352},{"name":354,"options":607,"isRSC":118},{"darkMode":41},{"large":609},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":611,"component":612,"responsiveStyles":617},"builder-c98e8bfd341146c1b67c02d5698ff093",{"name":359,"tag":359,"options":613,"isRSC":118},{"darkMode":6,"maxWidth":363,"maxTextWidth":364,"title":614,"description":615,"image":616,"reverse":6},"\u003Ch2>Assume less. See more.\u003C/h2>","\u003Cp>Most account takeovers don’t start with a breach, they start with a login. Whether it’s a reused password, a local account, or an outdated login flow, Push shows you how accounts are actually accessed day to day, not just how policies say they should be. That means no more blind spots around ghost logins, bypassed SSO, or stale access paths that quietly persist.\u003C/p>\u003Cp>\u003Cbr>\u003C/p>\u003Cp>\u003Cbr>\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F18630ad2746d4eb7b7fcc0428b11a8f0",{"large":618},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":620,"meta":621,"component":622,"responsiveStyles":627},"builder-55c1fc38ddc04fd1a0d6a8e2fb819e00",{"previousId":371},{"name":373,"options":623,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":376,"title":624,"description":625,"reverse":41,"image":626},"\u003Ch2>Catch stolen credential use in real time\u003C/h2>","\u003Cp>Push monitors login activity directly in the browser to detect signs of credential-based attacks like leaked password use or suspicious login flows. By analyzing attacker TTPs instead of relying on known indicators, Push spots credential stuffing and account takeover attempts the moment they begin, not after they’ve succeeded.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F52b0123cac2c4dfdb1dc0af6adf9d603",{"large":628},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"fontFamily":382,"paddingTop":384,"marginTop":384},{"@type":106,"@version":107,"id":630,"meta":631,"component":632,"responsiveStyles":637},"builder-dfb31737b30948c6b95323655d571a50",{"previousId":386},{"name":373,"options":633,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":389,"title":634,"description":635,"reverse":6,"image":636},"\u003Ch2>Detect session hijacks and stealth access\u003C/h2>","\u003Cp>Attackers don’t always need a login screen, they often sidestep it entirely using stolen session tokens. Push detects when valid sessions are reused in unexpected ways, identifying hijacked sessions and stealth access attempts that traditional tools miss. Because we monitor directly in the browser, you see what’s happening inside active sessions in real time.\u003C/p>\u003Cp>\u003Cbr>\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F94a6859a99e04d309ffe5841f3dbdf5c",{"large":638},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":395},{"@type":106,"@version":107,"layerName":373,"id":640,"meta":641,"component":642,"responsiveStyles":647},"builder-f7585b90eb974d03a7dc7eae5b58d227",{"previousId":397},{"name":373,"options":643,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":400,"title":644,"description":645,"reverse":41,"image":646},"\u003Ch2>Harden accounts before they’re compromised\u003C/h2>","\u003Cp>Push goes beyond alerts. It identifies apps that still allow local logins, even when SSO is configured, so you can remove weak access paths. Push also flags users without MFA, reused work credentials, or weak passwords, and prompts users in-browser to fix risky behaviors before they’re exploited.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F01c1b638f1b6497093a4f2b8ceddb5bb",{"large":648},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":406},{"@type":106,"@version":107,"id":650,"meta":651,"component":652,"responsiveStyles":654},"builder-ad81d1e3afec49a791214194eae09bdc",{"previousId":408},{"name":354,"options":653,"isRSC":118},{"darkMode":6},{"large":655},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":657,"component":658,"responsiveStyles":660},"builder-8dac1aa4b9d148628d92252bd8eff822",{"name":416,"tag":416,"options":659,"isRSC":118},{"sectionHeading":37,"customClass":418},{"large":661},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"id":663,"@type":106,"tagName":131,"properties":664,"responsiveStyles":665},"builder-pixel-s5u3wmvz7jq",{"src":133,"aria-hidden":134,"alt":37,"role":135,"width":124,"height":124},{"large":666},{"height":124,"width":124,"display":138,"opacity":124,"overflow":139,"pointerEvents":140},{"deviceSize":142,"location":668},{"path":37,"query":669},{},{},1770892814499,1745499162732,"https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F58b660fa94aa4b30b0faeb9b663ae41a","SfUPqW5tkibIPby49keNFMdHFTr1",[],{"lastPreviewUrl":677,"hasLinks":6,"originalContentId":259,"breakpoints":678,"winningTest":118,"kind":438,"hasAutosaves":41},"https://pushsecurity.com/uc/account-takeover-detection?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditCode%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CeditProjects%2CmodifyMcpServers%2CmodifyWorkflowIntegrations%2CmodifyProjectSettings%2CconnectCodeRepository%2CcreateProjects%2CindexDesignSystems%2CsendPullRequests&builder.user.role.name=Developer&builder.user.role.id=developer&builder.cachebust=true&builder.preview=use-case-page&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.use-case-page=94bebb7bb99d48629ad157e80cf4d81d&builder.overrides.94bebb7bb99d48629ad157e80cf4d81d=94bebb7bb99d48629ad157e80cf4d81d&builder.overrides.use-case-page:/uc/account-takeover-detection=94bebb7bb99d48629ad157e80cf4d81d&builder.options.includeRefs=true&builder.options.enrich=true&builder.options.locale=Default",{"xsmall":57,"small":39,"medium":40},{"createdDate":680,"id":681,"name":682,"modelId":261,"published":13,"query":683,"data":686,"variations":789,"lastUpdated":790,"firstPublished":791,"testRatio":33,"screenshot":792,"createdBy":34,"lastUpdatedBy":674,"folders":793,"meta":794,"rev":440},1745009370904,"23eb48fb56d3451cab77cb6ed140ee6d","Attack path hardening",[684],{"@type":264,"property":265,"operator":266,"value":685},"/uc/attack-path-hardening",{"tsCode":37,"seoDescription":687,"jsCode":37,"customFonts":688,"fontAwesomeIcon":693,"seoTitle":682,"title":682,"blocks":694,"url":685,"state":786},"Harden access paths with visibility,  detection, and guardrails.",[689],{"kind":273,"files":690,"version":274,"lastModified":275,"subsets":691,"menu":296,"category":295,"variants":692,"family":272},{"100":277,"200":278,"300":279,"500":280,"600":281,"700":282,"800":283,"900":284,"regular":290,"italic":289,"800italic":285,"500italic":292,"600italic":294,"200italic":291,"900italic":286,"700italic":287,"100italic":288,"300italic":293},[298,299],[301,302,303,304,305,306,128,307,308,309,310,311,312,313,314,315,316,317],"faRadar",[695,781],{"@type":106,"@version":107,"tagName":323,"id":696,"meta":697,"children":698},"builder-1d8553eddcaa44d7bba9e2f4ca13af2a",{"previousId":577},[699,715,722,729,738,748,758,768,775],{"@type":106,"@version":107,"id":700,"meta":701,"component":702,"responsiveStyles":713},"builder-84fe3d7c85a743cf8cef649aa974f1ef",{"previousId":581},{"name":327,"options":703,"isRSC":118},{"title":682,"description":704,"points":705,"video":712},"\u003Cp>Push continuously monitors your environment for exposed login paths, weak credentials, and missing protections like MFA. It detects the gaps attackers exploit and helps you close them before they’re used.\u003C/p>",[706,708,710],{"item":707},"Find weak spots like reused passwords, local logins, and missing MFA",{"item":709},"Monitor how users actually log in across apps, flows, and tools",{"item":711},"Enforce secure access with in-browser guardrails","https://cdn.builder.io/o/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fdbdcf52892034f1bbddded77f753a343%2Fcompressed?apiKey=f3a1111ff5be48cdbb123cd9f5795a05&token=dbdcf52892034f1bbddded77f753a343&alt=media&optimized=true",{"large":714},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":342},{"@type":106,"@version":107,"id":716,"meta":717,"component":718,"responsiveStyles":720},"builder-b3f66f5b08054cc78a06fecfc3ae2337",{"previousId":597},{"name":346,"options":719,"isRSC":118},{"AllPartners":41,"backgroundTransparent":6},{"large":721},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":350},{"@type":106,"@version":107,"id":723,"meta":724,"component":725,"responsiveStyles":727},"builder-4c73418b84be49ed85e6e13d2625c5a0",{"previousId":604},{"name":354,"options":726,"isRSC":118},{"darkMode":41},{"large":728},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":730,"component":731,"responsiveStyles":736},"builder-dec0246085e1485c803f7152b1922a81",{"name":359,"tag":359,"options":732,"isRSC":118},{"darkMode":6,"maxWidth":363,"maxTextWidth":364,"title":733,"description":734,"image":735,"reverse":6},"\u003Ch2>Find the gaps that lead to compromise\u003C/h2>","\u003Cp>Misconfigurations don’t show up in your config files, they show up in how users actually access apps. Push monitors real login behavior in the browser, surfacing risky patterns like local login access, duplicate accounts, or missing protections that leave doors wide open.\u003C/p>\u003Cp>\u003Cbr>\u003C/p>\u003Cp>\u003Cbr>\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F309a59bba8d247a19476bb369397460e",{"large":737},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":739,"meta":740,"component":741,"responsiveStyles":746},"builder-ebf049a645604a249550996a88f8f3b6",{"previousId":620},{"name":373,"options":742,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":376,"title":743,"description":744,"reverse":41,"image":745},"\u003Ch2>See real login behavior\u003C/h2>","\u003Cp>Push watches authentication flows as they happen, giving you a live view of how users log in, which methods they choose, and where protections like MFA are missing. Plus, uncover every app and account in use, even shadow IT you didn’t know existed, without relying on stale config files or IdP assumptions. \u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fb51f6b0357cc451b87a7a5016d984e5e",{"large":747},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"fontFamily":382,"paddingTop":383,"marginTop":384},{"@type":106,"@version":107,"id":749,"meta":750,"component":751,"responsiveStyles":756},"builder-431d175c59004669b0b2776b07d71737",{"previousId":630},{"name":373,"options":752,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":389,"title":753,"description":754,"reverse":6,"image":755},"\u003Ch2>Find and fix posture drift\u003C/h2>","\u003Cp>Security posture isn’t static. Push continuously monitors for issues like missing MFA or legacy login methods. When something falls out of policy, you know immediately with custom notifications so you can act before it turns into risk.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F324e39127dfc41e592b1183dfb39892d",{"large":757},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":395},{"@type":106,"@version":107,"layerName":373,"id":759,"meta":760,"component":761,"responsiveStyles":766},"builder-3dffdcbe0a484e2ca4c03f019b6d40ee",{"previousId":640},{"name":373,"options":762,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":400,"title":763,"description":764,"reverse":41,"image":765},"\u003Ch2>Guide users with in-browser guardrails\u003C/h2>","\u003Cp>Push doesn’t just surface problems, it helps you fix them. When users sign in without MFA, reuse a password, or use insecure credentials, Push prompts them directly in the browser to secure their access. It’s faster, more effective, and actually gets results.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fee8b75d13e45488aba55434a8b49ebb0",{"large":767},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":406},{"@type":106,"@version":107,"id":769,"meta":770,"component":771,"responsiveStyles":773},"builder-976bc222cd7647ff905f1e01cfedc453",{"previousId":650},{"name":354,"options":772,"isRSC":118},{"darkMode":6},{"large":774},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":776,"component":777,"responsiveStyles":779},"builder-8c47ec2fd0f74382bb3e6c870555632c",{"name":416,"tag":416,"options":778,"isRSC":118},{"sectionHeading":37,"customClass":418},{"large":780},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"id":782,"@type":106,"tagName":131,"properties":783,"responsiveStyles":784},"builder-pixel-7akm7dayau8",{"src":133,"aria-hidden":134,"alt":37,"role":135,"width":124,"height":124},{"large":785},{"height":124,"width":124,"display":138,"opacity":124,"overflow":139,"pointerEvents":140},{"deviceSize":142,"location":787},{"path":37,"query":788},{},{},1770892844854,1745499166112,"https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F6ca12bf728a045f1a31d40c0beb3bfe5",[],{"kind":438,"lastPreviewUrl":795,"breakpoints":796,"hasLinks":6,"originalContentId":562,"winningTest":118,"hasAutosaves":6},"https://pushsecurity.com/uc/attack-path-hardening?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditCode%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CeditProjects%2CmodifyMcpServers%2CmodifyWorkflowIntegrations%2CmodifyProjectSettings%2CconnectCodeRepository%2CcreateProjects%2CindexDesignSystems%2CsendPullRequests&builder.user.role.name=Developer&builder.user.role.id=developer&builder.cachebust=true&builder.preview=use-case-page&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.use-case-page=23eb48fb56d3451cab77cb6ed140ee6d&builder.overrides.23eb48fb56d3451cab77cb6ed140ee6d=23eb48fb56d3451cab77cb6ed140ee6d&builder.overrides.use-case-page:/uc/attack-path-hardening=23eb48fb56d3451cab77cb6ed140ee6d&builder.options.includeRefs=true&builder.options.enrich=true&builder.options.locale=Default",{"xsmall":57,"small":39,"medium":40},{"createdDate":798,"id":799,"name":800,"modelId":261,"published":13,"query":801,"data":804,"variations":909,"lastUpdated":910,"firstPublished":911,"testRatio":33,"screenshot":912,"createdBy":34,"lastUpdatedBy":674,"folders":913,"meta":914,"rev":440},1761675020232,"ea4f309d2ffe46c5aa97ebf0fda4e2e3","ClickFix Protection",[802],{"@type":264,"property":265,"operator":266,"value":803},"/uc/clickfix-protection",{"seoDescription":805,"fontAwesomeIcon":806,"customFonts":807,"seoTitle":812,"jsCode":37,"tsCode":37,"title":812,"blocks":813,"url":803,"state":906},"Block attacks that trick users into running malicious code.","faLaptopCode",[808],{"files":809,"subsets":810,"menu":296,"version":274,"kind":273,"family":272,"lastModified":275,"variants":811,"category":295},{"100":277,"200":278,"300":279,"500":280,"600":281,"700":282,"800":283,"900":284,"200italic":291,"800italic":285,"700italic":287,"600italic":294,"100italic":288,"italic":289,"regular":290,"300italic":293,"500italic":292,"900italic":286},[298,299],[301,302,303,304,305,306,128,307,308,309,310,311,312,313,314,315,316,317],"ClickFix protection",[814,901],{"@type":106,"@version":107,"tagName":323,"id":815,"meta":816,"children":817},"builder-d7eefdde0f2a4b2b9de3dcb2978fd6cb",{"previousId":696},[818,834,841,848,858,868,878,888,895],{"@type":106,"@version":107,"id":819,"meta":820,"component":821,"responsiveStyles":832},"builder-56e2c54bcce040a4af8b92ae03706c12",{"previousId":700},{"name":327,"options":822,"isRSC":118},{"title":812,"description":823,"points":824,"image":831},"\u003Cp>ClickFix attacks are one of the fastest-growing threats, tricking users into copying malicious code from a webpage and running it locally. This technique bypasses traditional EDR, email gateways, and network filters, leading directly to ransomware and data theft. Push stops this attack at the source, in the browser, by detecting and blocking the malicious behavior before the user can ever paste the code.\u003C/p>\u003Cp>\u003Cbr>\u003C/p>",[825,827,829],{"item":826},"Detect ClickFix, FileFix, and fake CAPTCHA in the browser",{"item":828},"Block malicious copy-and-paste actions before code is executed",{"item":830},"See full telemetry into which users were targeted and what they saw","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F7b74af62889847ebb3927364485b0546",{"large":833},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":342},{"@type":106,"@version":107,"id":835,"meta":836,"component":837,"responsiveStyles":839},"builder-05f9614d4e3e4dc88b3ee8658f54e10e",{"previousId":716},{"name":346,"options":838,"isRSC":118},{"AllPartners":41,"backgroundTransparent":6},{"large":840},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":350},{"@type":106,"@version":107,"id":842,"meta":843,"component":844,"responsiveStyles":846},"builder-c4fb5179366243c1b6c32d368675cf47",{"previousId":723},{"name":354,"options":845,"isRSC":118},{"darkMode":41},{"large":847},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":849,"meta":850,"component":851,"responsiveStyles":856},"builder-261af50705fd445d8cca4a6ba20d5391",{"previousId":730},{"name":359,"tag":359,"options":852,"isRSC":118},{"darkMode":6,"maxWidth":363,"maxTextWidth":364,"title":853,"description":854,"reverse":6,"image":855},"\u003Ch2>Stop ClickFix-style attacks before they become a breach\u003C/h2>","\u003Cp>Traditional security tools are blind to malicious copy and paste attacks because the attack exploits a gap between the browser and the endpoint. EDR only sees the payload after it runs, and network tools see only part of the picture.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F98b2f7e08dec4eafaf8e24937605b8cf",{"large":857},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":859,"meta":860,"component":861,"responsiveStyles":866},"builder-7d21b8aab8064c40b1e5dd23c4749309",{"previousId":739},{"name":373,"options":862,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":376,"title":863,"description":864,"reverse":41,"image":865},"\u003Ch2>Discover lures at the source\u003C/h2>","\u003Cp>Push inspects page behavior to identify ClickFix attacks as they happen. By inspecting the page, its structure, and how the user interacts with it, Push can detect and block these in-browser threats in real time. This deep, TTP-based inspection spots the trap even on novel pages that are built to bypass traditional web filters and blocklists.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F665bf47e01544c75bf9ddafd3917927b",{"large":867},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"fontFamily":382,"paddingTop":383,"marginTop":384},{"@type":106,"@version":107,"id":869,"meta":870,"component":871,"responsiveStyles":876},"builder-fb91943adf6149259ed9e1e6566c9afe",{"previousId":749},{"name":373,"options":872,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":389,"title":873,"description":874,"reverse":6,"image":875},"\u003Ch2>Block the malicious action\u003C/h2>","\u003Cp>When Push detects a malicious script, it intercepts the user's action and blocks the code from being copied to the clipboard. The user is protected, the attack is stopped, and no malicious code ever reaches the endpoint. Unlike broad DLP tools, this action is surgical, targeting only malicious behavior without disrupting normal work.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F5ee68f81f1ac416685cbfe91298cf827",{"large":877},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":395},{"@type":106,"@version":107,"layerName":373,"id":879,"meta":880,"component":881,"responsiveStyles":886},"builder-bfac95fada864e5a8259b955b5b5f98b",{"previousId":759},{"name":373,"options":882,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":400,"title":883,"description":884,"reverse":41,"image":885},"\u003Ch2>Accelerate ClickFix investigations\u003C/h2>","\u003Cp>When an attack happens, knowing what the user saw or did is critical. Push provides rich browser session data for rapid investigation and containment. Security teams get detailed telemetry on which users were targeted, what lure they were served, and when the block occurred. This enables defenders to reconstruct what happened and respond quickly, even when other tools miss the activity entirely.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F6cdf2a8aeddc4e9a9023cbf974e40239",{"large":887},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":406},{"@type":106,"@version":107,"id":889,"meta":890,"component":891,"responsiveStyles":893},"builder-136892e831684a6987f87d3be67c33d1",{"previousId":769},{"name":354,"options":892,"isRSC":118},{"darkMode":6},{"large":894},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":896,"component":897,"responsiveStyles":899},"builder-dec26b739f2f42beb5a73cfc6c675b60",{"name":416,"tag":416,"options":898,"isRSC":118},{"sectionHeading":37,"customClass":418},{"large":900},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"id":902,"@type":106,"tagName":131,"properties":903,"responsiveStyles":904},"builder-pixel-zzjpxxgrc2l",{"src":133,"aria-hidden":134,"alt":37,"role":135,"width":124,"height":124},{"large":905},{"height":124,"width":124,"display":138,"opacity":124,"overflow":139,"pointerEvents":140},{"deviceSize":142,"location":907},{"path":37,"query":908},{},{},1770892881888,1761847585203,"https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F375467b8bef34ed1a8a1cc5b8b67d75f",[],{"lastPreviewUrl":915,"originalContentId":681,"winningTest":118,"hasLinks":6,"kind":438,"breakpoints":916,"hasAutosaves":6},"https://pushsecurity.com/uc/clickfix-protection?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditCode%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CeditProjects%2CmodifyMcpServers%2CmodifyWorkflowIntegrations%2CmodifyProjectSettings%2CconnectCodeRepository%2CcreateProjects%2CindexDesignSystems%2CsendPullRequests&builder.user.role.name=Developer&builder.user.role.id=developer&builder.cachebust=true&builder.preview=use-case-page&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.use-case-page=ea4f309d2ffe46c5aa97ebf0fda4e2e3&builder.overrides.ea4f309d2ffe46c5aa97ebf0fda4e2e3=ea4f309d2ffe46c5aa97ebf0fda4e2e3&builder.overrides.use-case-page:/uc/clickfix-protection=ea4f309d2ffe46c5aa97ebf0fda4e2e3&builder.options.includeRefs=true&builder.options.enrich=true&builder.options.locale=Default",{"xsmall":57,"small":39,"medium":40},{"createdDate":918,"id":919,"name":920,"modelId":261,"published":13,"query":921,"data":924,"variations":1029,"lastUpdated":1030,"firstPublished":1031,"testRatio":33,"screenshot":1032,"createdBy":34,"lastUpdatedBy":674,"folders":1033,"meta":1034,"rev":440},1745009743870,"a9d5556e77f84a37b5bd52310a7110c1","Incident response",[922],{"@type":264,"property":265,"operator":266,"value":923},"/uc/incident-response",{"seoDescription":925,"customFonts":926,"title":920,"jsCode":37,"fontAwesomeIcon":931,"seoTitle":932,"tsCode":37,"blocks":933,"url":923,"state":1026},"Investigate and respond faster with unique browser telemetry.",[927],{"kind":273,"subsets":928,"menu":296,"variants":929,"category":295,"family":272,"version":274,"lastModified":275,"files":930},[298,299],[301,302,303,304,305,306,128,307,308,309,310,311,312,313,314,315,316,317],{"100":277,"200":278,"300":279,"500":280,"600":281,"700":282,"800":283,"900":284,"900italic":286,"600italic":294,"200italic":291,"300italic":293,"100italic":288,"700italic":287,"800italic":285,"regular":290,"italic":289,"500italic":292},"faSatelliteDish","Browser based incident response",[934,1021],{"@type":106,"@version":107,"tagName":323,"id":935,"meta":936,"children":937},"builder-653c4aed737b4def88dc4cd2d695660a",{"previousId":696},[938,955,962,969,978,988,998,1008,1015],{"@type":106,"@version":107,"id":939,"meta":940,"component":941,"responsiveStyles":953},"builder-18190bd36518467d9154d27d7e945b9b",{"previousId":700},{"name":327,"options":942,"isRSC":118},{"title":943,"description":944,"points":945,"video":952},"Browser-based incident response","\u003Cp>Push gives you real-time visibility into what actually happened during a breach, right in the browser where the attack played out. From credential theft to session hijacking, Push captures high-fidelity telemetry so you can investigate quickly, contain confidently, and shut it down before it spreads.\u003C/p>\u003Cp>\u003Cbr>\u003C/p>",[946,948,950],{"item":947},"Reconstruct what happened with real browser session context",{"item":949},"Investigate faster with real-world session context",{"item":951},"Trigger response actions automatically through your SIEM or SOAR","https://cdn.builder.io/o/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fd00e39d3b6e346c296261d875cf55652%2Fcompressed?apiKey=f3a1111ff5be48cdbb123cd9f5795a05&token=d00e39d3b6e346c296261d875cf55652&alt=media&optimized=true",{"large":954},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":342},{"@type":106,"@version":107,"id":956,"meta":957,"component":958,"responsiveStyles":960},"builder-8a0a8ea63f5d48dd8a6726f2d49cf0ca",{"previousId":716},{"name":346,"options":959,"isRSC":118},{"AllPartners":41,"backgroundTransparent":6},{"large":961},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":350},{"@type":106,"@version":107,"id":963,"meta":964,"component":965,"responsiveStyles":967},"builder-2df65c3f54334df2b26e7cb744886cdc",{"previousId":723},{"name":354,"options":966,"isRSC":118},{"darkMode":41},{"large":968},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":970,"component":971,"responsiveStyles":976},"builder-2c32c869efc2423ab69ef06b150e9f97",{"name":359,"tag":359,"options":972,"isRSC":118},{"darkMode":6,"maxWidth":363,"maxTextWidth":364,"title":973,"description":974,"image":975,"reverse":6},"\u003Ch2>See attacks unfold, not just their aftermath\u003C/h2>","\u003Cp>Attacks happen in the browser, not in logs. Push captures what traditional tools miss: what users clicked, what loaded, what was entered, and how attackers moved. That gives you real-world evidence, not just assumptions, when every second matters.\u003C/p>\u003Cp>\u003Cbr>\u003C/p>\u003Cp>\u003Cbr>\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F36fc719bd1de4a38b916f4d25c81a26d",{"large":977},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":979,"meta":980,"component":981,"responsiveStyles":986},"builder-370e53c6016e432db01e9193a2ce90f6",{"previousId":739},{"name":373,"options":982,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":376,"title":983,"description":984,"reverse":41,"image":985},"\u003Ch2>Investigate faster with high-fidelity data\u003C/h2>","\u003Cp>Reconstructing an incident shouldn’t feel like guesswork. Push records detailed telemetry from inside the browser: page loads, credential inputs, DOM changes, session activity, user behavior. It’s structured, exportable, and ready to plug into your investigation workflows, so you can move fast without digging through proxy logs or relying on user reports.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fa6adda040e684e67a8d68a55c5ce5f6d",{"large":987},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"fontFamily":382,"paddingTop":384,"marginTop":384},{"@type":106,"@version":107,"id":989,"meta":990,"component":991,"responsiveStyles":996},"builder-a7f3767a8d184bd08fb24520bf210e95",{"previousId":749},{"name":373,"options":992,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":389,"title":993,"description":994,"reverse":6,"image":995},"\u003Ch2>Contain and respond in real time\u003C/h2>","\u003Cp>When something looks off, Push doesn’t just alert you, it gives you options. Guide users with in-browser prompts. Terminate sessions. Trigger SOAR workflows. Enrich SIEM alerts. Push gives you the context and control to stop spread before it starts.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fb3dedeed5aba4847a2c2d22e10d0ec12",{"large":997},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":395},{"@type":106,"@version":107,"layerName":373,"id":999,"meta":1000,"component":1001,"responsiveStyles":1006},"builder-b92036ee0ece4b32acdbdcc7c377366b",{"previousId":759},{"name":373,"options":1002,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":400,"title":1003,"description":1004,"reverse":41,"image":1005},"\u003Ch2>Prevent the next one\u003C/h2>","\u003Cp>Push helps you respond fast, but it also helps you fix what went wrong. It surfaces misconfigurations and risky behaviors that made the attack possible in the first place, then guides users in-browser to remediate. One tool. Full loop. No loose ends.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fc1ecc2d5d3814b62b072fac01827ff96",{"large":1007},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":406},{"@type":106,"@version":107,"id":1009,"meta":1010,"component":1011,"responsiveStyles":1013},"builder-5e8ae39655274de89da32ab573a2525a",{"previousId":769},{"name":354,"options":1012,"isRSC":118},{"darkMode":6},{"large":1014},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":1016,"component":1017,"responsiveStyles":1019},"builder-dfd6850cfb4741d2b8a0c16c2780f00a",{"name":416,"tag":416,"options":1018,"isRSC":118},{"sectionHeading":37,"customClass":418},{"large":1020},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"id":1022,"@type":106,"tagName":131,"properties":1023,"responsiveStyles":1024},"builder-pixel-z197gdgcmu",{"src":133,"aria-hidden":134,"alt":37,"role":135,"width":124,"height":124},{"large":1025},{"height":124,"width":124,"display":138,"opacity":124,"overflow":139,"pointerEvents":140},{"deviceSize":142,"location":1027},{"path":37,"query":1028},{},{},1770892908052,1745427419274,"https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fb07017bfd318431690a5bb35bda35b99",[],{"kind":438,"breakpoints":1035,"originalContentId":681,"winningTest":118,"lastPreviewUrl":1036,"hasLinks":6,"hasAutosaves":6},{"xsmall":57,"small":39,"medium":40},"https://pushsecurity.com/uc/incident-response?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditCode%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CeditProjects%2CmodifyMcpServers%2CmodifyWorkflowIntegrations%2CmodifyProjectSettings%2CconnectCodeRepository%2CcreateProjects%2CindexDesignSystems%2CsendPullRequests&builder.user.role.name=Developer&builder.user.role.id=developer&builder.cachebust=true&builder.preview=use-case-page&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.use-case-page=a9d5556e77f84a37b5bd52310a7110c1&builder.overrides.a9d5556e77f84a37b5bd52310a7110c1=a9d5556e77f84a37b5bd52310a7110c1&builder.overrides.use-case-page:/uc/incident-response=a9d5556e77f84a37b5bd52310a7110c1&builder.options.includeRefs=true&builder.options.enrich=true&builder.options.locale=Default",{"createdDate":1038,"id":1039,"name":1040,"modelId":261,"published":13,"query":1041,"data":1044,"variations":1149,"lastUpdated":1150,"firstPublished":1151,"testRatio":33,"screenshot":1152,"createdBy":34,"lastUpdatedBy":674,"folders":1153,"meta":1154,"rev":440},1746122471259,"5f118e24433d46ceb79f5099987156d7","Shadow SaaS",[1042],{"@type":264,"property":265,"operator":266,"value":1043},"/uc/shadow-saas",{"seoTitle":1045,"seoDescription":1046,"customFonts":1047,"fontAwesomeIcon":1052,"title":1053,"jsCode":37,"tsCode":37,"blocks":1054,"url":1043,"state":1146},"Find and secure shadow SaaS","See and control shadow SaaS in the browser.",[1048],{"kind":273,"variants":1049,"files":1050,"family":272,"version":274,"subsets":1051,"lastModified":275,"category":295,"menu":296},[301,302,303,304,305,306,128,307,308,309,310,311,312,313,314,315,316,317],{"100":277,"200":278,"300":279,"500":280,"600":281,"700":282,"800":283,"900":284,"300italic":293,"500italic":292,"regular":290,"900italic":286,"italic":289,"100italic":288,"200italic":291,"600italic":294,"700italic":287,"800italic":285},[298,299],"faShieldCheck","Secure shadow SaaS",[1055,1141],{"@type":106,"@version":107,"tagName":323,"id":1056,"meta":1057,"children":1058},"builder-04da805c4cd34652a2db452fcda52e1d",{"previousId":935},[1059,1075,1082,1089,1098,1108,1118,1128,1135],{"@type":106,"@version":107,"id":1060,"meta":1061,"component":1062,"responsiveStyles":1073},"builder-830d414faeaf41439142f9157e8288c8",{"previousId":939},{"name":327,"options":1063,"isRSC":118},{"title":1045,"description":1064,"points":1065,"video":1072},"\u003Cp>SaaS sprawl is one of today’s fastest-growing security blind spots because most tools monitor around the edges. Push sees it at the source, in the browser, revealing every app users access, flagging risky tools, and helping you shut down exposure before it leads to a breach. No guesswork. No nasty surprises. Just real-time visibility and control.\u003C/p>",[1066,1068,1070],{"item":1067},"Discover every SaaS app users access, managed or not",{"item":1069},"Spot accounts with weak security postures like missing MFA, unmanaged access, and no SSO",{"item":1071},"Control usage with in-browser prompts, blocks, and security guardrails","https://cdn.builder.io/o/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F3e4eece318d04d6586e691d59d0741cf%2Fcompressed?apiKey=f3a1111ff5be48cdbb123cd9f5795a05&token=3e4eece318d04d6586e691d59d0741cf&alt=media&optimized=true",{"large":1074},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":342},{"@type":106,"@version":107,"id":1076,"meta":1077,"component":1078,"responsiveStyles":1080},"builder-cd7833f966cb4c7e8adf0d6c979414a6",{"previousId":956},{"name":346,"options":1079,"isRSC":118},{"AllPartners":41,"backgroundTransparent":6},{"large":1081},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":350},{"@type":106,"@version":107,"id":1083,"meta":1084,"component":1085,"responsiveStyles":1087},"builder-49d720b45430454e8b08c526f267c19f",{"previousId":963},{"name":354,"options":1086,"isRSC":118},{"darkMode":41},{"large":1088},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":1090,"component":1091,"responsiveStyles":1096},"builder-3dde0bf6c8544e5e9ab41b18a9d68034",{"name":359,"tag":359,"options":1092,"isRSC":118},{"darkMode":6,"maxWidth":363,"maxTextWidth":364,"title":1093,"description":1094,"image":1095,"reverse":6},"\u003Ch2>Use your browser to curb Saas Sprawl\u003C/h2>","\u003Cp>Shadow SaaS isn’t hiding in your network, it’s in your browser. From AI tools to unsanctioned file-sharing sites, security risks live in the apps your users sign into every day. Push maps your organization's true SaaS footprint in real time, exposing apps and accounts with unmanaged access, poor authentication, or no security oversight.\u003C/p>\u003Cp>\u003Cbr>\u003C/p>\u003Cp>\u003Cbr>\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fb6811a214c7949b6bbe0b9a3bca62efd",{"large":1097},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":1099,"meta":1100,"component":1101,"responsiveStyles":1106},"builder-e2420451ccdc4f088d0a4904cff45935",{"previousId":979},{"name":373,"options":1102,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":376,"title":1103,"description":1104,"reverse":41,"image":1105},"\u003Ch2>Discover hidden SaaS usage\u003C/h2>","\u003Cp>Push captures live browser telemetry across every tab and session. Whether a user signs into a sanctioned app with a personal account or tries a new AI plugin, you’ll see it in real time, with no integrations or manual tagging.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fe16e301f9af94665b95d98232a863d8a",{"large":1107},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"fontFamily":382,"paddingTop":384,"marginTop":384},{"@type":106,"@version":107,"id":1109,"meta":1110,"component":1111,"responsiveStyles":1116},"builder-b36de7fce7994beea9e58d94662e7166",{"previousId":989},{"name":373,"options":1112,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":389,"title":1113,"description":1114,"reverse":6,"image":1115},"\u003Ch2>Spot risky access and unsafe usage\u003C/h2>","\u003Cp>Discovery is just the beginning. Push flags apps with risky traits, no MFA, no SSO, known vulnerabilities, or broad access scopes. You’ll know which tools introduce real risk, and which users are exposed so you can act with precision.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F6585f3c242da4d70ae3cb7d02f481bef",{"large":1117},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":395},{"@type":106,"@version":107,"layerName":373,"id":1119,"meta":1120,"component":1121,"responsiveStyles":1126},"builder-dc366b5134684fe7a508edf8913103ea",{"previousId":999},{"name":373,"options":1122,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":400,"title":1123,"description":1124,"reverse":41,"image":1125},"\u003Ch2>Close gaps before they grow\u003C/h2>","\u003Cp>Push turns insight into action. When risky SaaS use is detected, guide users to enable MFA, block high-risk apps, or apply in-browser guardrails automatically. All without deploying new infrastructure or managing dozens of integrations.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fe6d60b6d91414819bc6258a318f00557",{"large":1127},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":406},{"@type":106,"@version":107,"id":1129,"meta":1130,"component":1131,"responsiveStyles":1133},"builder-8708f6f0d8da4b3f9e17bf16cda70219",{"previousId":1009},{"name":354,"options":1132,"isRSC":118},{"darkMode":6},{"large":1134},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":1136,"component":1137,"responsiveStyles":1139},"builder-8ff4b38d60534cf28cb523ab0f754875",{"name":416,"tag":416,"options":1138,"isRSC":118},{"sectionHeading":37,"customClass":418},{"large":1140},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"id":1142,"@type":106,"tagName":131,"properties":1143,"responsiveStyles":1144},"builder-pixel-d1ul2kmxbed",{"src":133,"aria-hidden":134,"alt":37,"role":135,"width":124,"height":124},{"large":1145},{"height":124,"width":124,"display":138,"opacity":124,"overflow":139,"pointerEvents":140},{"deviceSize":142,"location":1147},{"path":37,"query":1148},{},{},1770892936802,1746714967208,"https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F01bfb2304521412fbd2e1a1180904d40",[],{"originalContentId":919,"winningTest":118,"lastPreviewUrl":1155,"breakpoints":1156,"kind":438,"hasLinks":6,"hasAutosaves":6},"https://pushsecurity.com/uc/shadow-saas?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditCode%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CeditProjects%2CmodifyMcpServers%2CmodifyWorkflowIntegrations%2CmodifyProjectSettings%2CconnectCodeRepository%2CcreateProjects%2CindexDesignSystems%2CsendPullRequests&builder.user.role.name=Developer&builder.user.role.id=developer&builder.cachebust=true&builder.preview=use-case-page&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.use-case-page=5f118e24433d46ceb79f5099987156d7&builder.overrides.5f118e24433d46ceb79f5099987156d7=5f118e24433d46ceb79f5099987156d7&builder.overrides.use-case-page:/uc/shadow-saas=5f118e24433d46ceb79f5099987156d7&builder.options.includeRefs=true&builder.options.enrich=true&builder.options.locale=Default",{"xsmall":57,"small":39,"medium":40},{"createdDate":1158,"id":1159,"name":1160,"modelId":261,"published":13,"query":1161,"data":1164,"variations":1268,"lastUpdated":1269,"firstPublished":1270,"testRatio":33,"screenshot":1271,"createdBy":34,"lastUpdatedBy":674,"folders":1272,"meta":1273,"rev":440},1764707470172,"b62629ce2f3741158d961cd10fe74b31","Shadow AI",[1162],{"@type":264,"property":265,"operator":266,"value":1163},"/uc/shadow-ai",{"fontAwesomeIcon":1165,"seoTitle":1166,"jsCode":37,"customFonts":1167,"title":1172,"tsCode":37,"seoDescription":1173,"blocks":1174,"url":1163,"state":1265},"faBrainCircuit","Secure AI native and AI enhanced apps. ",[1168],{"variants":1169,"category":295,"files":1170,"subsets":1171,"family":272,"kind":273,"menu":296,"lastModified":275,"version":274},[301,302,303,304,305,306,128,307,308,309,310,311,312,313,314,315,316,317],{"100":277,"200":278,"300":279,"500":280,"600":281,"700":282,"800":283,"900":284,"800italic":285,"regular":290,"700italic":287,"200italic":291,"italic":289,"500italic":292,"600italic":294,"300italic":293,"100italic":288,"900italic":286},[298,299],"Secure shadow AI","See and control shadow AI apps in the browser.",[1175,1260],{"@type":106,"@version":107,"tagName":323,"id":1176,"meta":1177,"children":1178},"builder-a6e5717a2c914d5695058e4ee201a05d",{"previousId":1056},[1179,1195,1202,1209,1219,1228,1237,1247,1254],{"@type":106,"@version":107,"id":1180,"meta":1181,"component":1182,"responsiveStyles":1193},"builder-3e0ed678683f4a0eb7aa00253cf263b2",{"previousId":1060},{"name":327,"options":1183,"isRSC":118},{"title":1172,"description":1184,"points":1185,"image":1192},"\u003Cp>Your employees are adopting AI faster than you can track it. From native features in corporate apps to unapproved shadow tools, it’s all happening in the browser. Push detects every AI interaction in real time, letting you categorize apps and enforce acceptable use policies in the browser.\u003C/p>",[1186,1188,1190],{"item":1187},"Map every AI tool used across your workforce",{"item":1189},"Review and classify apps by sensitivity, purpose, and policy status",{"item":1191},"Enforce AI usage rules directly in the browser","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F33cf153d920f4e389f3650253577cff7",{"large":1194},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":342},{"@type":106,"@version":107,"id":1196,"meta":1197,"component":1198,"responsiveStyles":1200},"builder-76968f8471d14893b8189d75b08fb426",{"previousId":1076},{"name":346,"options":1199,"isRSC":118},{"AllPartners":41,"backgroundTransparent":6},{"large":1201},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":350},{"@type":106,"@version":107,"id":1203,"meta":1204,"component":1205,"responsiveStyles":1207},"builder-b55b9d4bc5a649d8839ce7f6c2043d95",{"previousId":1083},{"name":354,"options":1206,"isRSC":118},{"darkMode":41},{"large":1208},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":1210,"meta":1211,"component":1212,"responsiveStyles":1217},"builder-c3f38ef4d75d4989a29b5903175ed8a1",{"previousId":1090},{"name":359,"tag":359,"options":1213,"isRSC":118},{"darkMode":6,"maxWidth":363,"maxTextWidth":364,"title":1214,"description":1215,"image":1216,"reverse":6},"\u003Ch2>Use your browser to govern AI \u003C/h2>","\u003Cp>The AI footprint inside your company is bigger than you think. From text generators to meeting assistants and design copilots, employees test, adopt, and connect new tools constantly. Push shows you those tools and which users are accessing them, without relying on network scans or API integrations.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F30b43bda6f1644c19478fb1efa20050c",{"large":1218},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":1220,"meta":1221,"component":1222,"responsiveStyles":1226},"builder-90ee9cb9afc44e7f885523715bf51a53",{"previousId":1099},{"name":373,"options":1223,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":376,"title":1224,"description":1225,"reverse":41,"image":1115},"\u003Ch2>Discover every AI tool users touch\u003C/h2>","\u003Cp>Push captures live telemetry from the browser, identifying every AI-native and AI-enhanced application users access. You’ll know which corporate identities are connected, how data flows, and what new AI apps appear across your environment. \u003C/p>",{"large":1227},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"fontFamily":382,"paddingTop":384,"marginTop":384},{"@type":106,"@version":107,"id":1229,"meta":1230,"component":1231,"responsiveStyles":1235},"builder-9e44539fa53c4d8e87406036c921fc46",{"previousId":1109},{"name":373,"options":1232,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":389,"title":1233,"description":1234,"reverse":6,"image":1125},"\u003Ch2>Classify and manage AI risk\u003C/h2>","\u003Cp>For apps you choose to allow, Push lets you apply custom in-browser banners. You can bulk-select categories of AI tools and require users to read and acknowledge your acceptable use policy before they proceed. This creates an auditable trail and moves policy from an easy to forget document to an active, in-workflow control.\u003C/p>",{"large":1236},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":395},{"@type":106,"@version":107,"layerName":373,"id":1238,"meta":1239,"component":1240,"responsiveStyles":1245},"builder-44c1a891926f4bdeaaa37e90721fe6ac",{"previousId":1119},{"name":373,"options":1241,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":400,"title":1242,"description":1243,"reverse":41,"image":1244},"\u003Ch2>Enforce your AI policy in the browser\u003C/h2>","\u003Cp>When an AI tool is deemed non-compliant or too risky, Push blocks it at the source. The block happens directly in the browser, preventing the user from accessing the site or submitting data. This gives you an immediate, powerful lever to stop data exfiltration and enforce a hard line on unacceptable risk.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fa359ac1805af4e15a8a7f84632b9bb55",{"large":1246},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":406},{"@type":106,"@version":107,"id":1248,"meta":1249,"component":1250,"responsiveStyles":1252},"builder-dcc906f9cbe54dc68b3c672668e7a38f",{"previousId":1129},{"name":354,"options":1251,"isRSC":118},{"darkMode":6},{"large":1253},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":1255,"component":1256,"responsiveStyles":1258},"builder-d2d64780c31b4349bc75805b23a07e38",{"name":416,"tag":416,"options":1257,"isRSC":118},{"sectionHeading":37,"customClass":418},{"large":1259},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"id":1261,"@type":106,"tagName":131,"properties":1262,"responsiveStyles":1263},"builder-pixel-wxx9tk70r9p",{"src":133,"aria-hidden":134,"alt":37,"role":135,"width":124,"height":124},{"large":1264},{"height":124,"width":124,"display":138,"opacity":124,"overflow":139,"pointerEvents":140},{"deviceSize":142,"location":1266},{"path":37,"query":1267},{},{},1770892957225,1764950077593,"https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fe558b8b069884037a8e6904f7ecc029c",[],{"winningTest":118,"breakpoints":1274,"originalContentId":1039,"kind":438,"lastPreviewUrl":1275,"hasLinks":6,"hasAutosaves":41},{"xsmall":57,"small":39,"medium":40},"https://pushsecurity.com/uc/shadow-ai?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditCode%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CeditProjects%2CmodifyMcpServers%2CmodifyWorkflowIntegrations%2CmodifyProjectSettings%2CconnectCodeRepository%2CcreateProjects%2CindexDesignSystems%2CsendPullRequests&builder.user.role.name=Developer&builder.user.role.id=developer&builder.cachebust=true&builder.preview=use-case-page&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.use-case-page=b62629ce2f3741158d961cd10fe74b31&builder.overrides.b62629ce2f3741158d961cd10fe74b31=b62629ce2f3741158d961cd10fe74b31&builder.overrides.use-case-page:/uc/shadow-ai=b62629ce2f3741158d961cd10fe74b31&builder.options.includeRefs=true&builder.options.enrich=true&builder.options.locale=Default",{"_path":1277,"_dir":1278,"_draft":6,"_partial":6,"_locale":37,"sys":1279,"summary":1282,"title":1296,"subtitle":118,"metaTitle":1297,"synopsis":1298,"hashTags":118,"publishedDate":1299,"slug":1300,"ogImage":1301,"tagsCollection":1303,"relatedBlogPostsCollection":1313,"authorsCollection":3054,"content":3058,"_id":4010,"_type":4011,"_source":4012,"_file":4013,"_stem":4014,"_extension":4011},"/blog/cross-idp-impersonation","blog",{"id":1280,"publishedAt":1281},"2PpB1KSjZkmpzYDhDLRBYx","2024-11-25T09:54:10.238Z",{"json":1283},{"data":1284,"content":1285,"nodeType":1295},{},[1286],{"data":1287,"content":1288,"nodeType":1294},{},[1289],{"data":1290,"marks":1291,"value":1292,"nodeType":1293},{},[],"Cross-IdP impersonation is a growing trend as a method of hijacking SSO to access downstream apps — without needing to compromise accounts on your company’s main IdP. ","text","paragraph","document","Cross-IdP impersonation: Hijacking SSO to access downstream apps","Cross-IdP impersonation: hijacking SSO using fraudulent IdPs","Cross-IdP impersonation is a method of hijacking SSO to access downstream apps — without needing to compromise accounts on your company’s main IdP. ","2024-11-19T00:00:00.000Z","cross-idp-impersonation",{"url":1302},"https://images.ctfassets.net/y1cdw1ablpvd/3fPWMDLgVomv5ePNfVRJl1/fb870e9bfef9d402791086c3ce01f8fb/ServiceNow_Attack_Path__2_.png",{"items":1304},[1305,1309],{"sys":1306,"name":1308},{"id":1307},"6A5RXS31ZQx3PwryGb1IMy","Browser-based attacks",{"sys":1310,"name":1312},{"id":1311},"4ksQNCFeBf8H4QIORqpRLw","Detection & response",{"items":1314},[1315,1862,2716],{"__typename":1316,"sys":1317,"content":1319,"title":1842,"synopsis":1843,"hashTags":118,"publishedDate":1844,"slug":1845,"tagsCollection":1846,"authorsCollection":1854},"BlogPosts",{"id":1318},"3N6eBccHWWc3cZWTZsaJVV",{"json":1320},{"nodeType":1295,"data":1321,"content":1322},{},[1323,1358,1378,1385,1392,1396,1406,1413,1438,1445,1454,1461,1468,1503,1506,1514,1521,1541,1544,1552,1559,1566,1572,1592,1595,1603,1622,1629,1636,1656,1659,1667,1674,1681,1688,1691,1699,1706,1726,1733,1740,1747,1754,1761,1764,1772,1779,1822],{"nodeType":1294,"data":1324,"content":1325},{},[1326,1330,1341,1345,1354],{"nodeType":1293,"value":1327,"marks":1328,"data":1329},"We’ve been shouting about the risk posed by account takeover attacks on third party apps since we first released the ",[],{},{"nodeType":1331,"data":1332,"content":1334},"hyperlink",{"uri":1333},"https://github.com/pushsecurity/saas-attacks",[1335],{"nodeType":1293,"value":1336,"marks":1337,"data":1340},"SaaS attack matrix",[1338],{"type":1339},"underline",{},{"nodeType":1293,"value":1342,"marks":1343,"data":1344}," in early 2023. 18 months later (and with some encouragement from the success of the ",[],{},{"nodeType":1331,"data":1346,"content":1348},{"uri":1347},"https://pushsecurity.com/blog/identity-attacks-in-the-wild/#id-snowflake-june-2024",[1349],{"nodeType":1293,"value":1350,"marks":1351,"data":1353},"attacks on Snowflake customers",[1352],{"type":1339},{},{"nodeType":1293,"value":1355,"marks":1356,"data":1357},") it feels like the security community has woken up to the risk — and attackers likewise have sensed the opportunity. ",[],{},{"nodeType":1294,"data":1359,"content":1360},{},[1361,1365,1374],{"nodeType":1293,"value":1362,"marks":1363,"data":1364},"Last week, it emerged that ",[],{},{"nodeType":1331,"data":1366,"content":1368},{"uri":1367},"https://medium.com/@moblig/how-i-accessed-microsofts-servicenow-exposing-all-microsoft-employee-emails-chat-support-5f8d535eb63b",[1369],{"nodeType":1293,"value":1370,"marks":1371,"data":1373},"bug bounty hunters were able to use stolen credentials from a TI platform to Microsoft’s ServiceNow tenant",[1372],{"type":1339},{},{"nodeType":1293,"value":1375,"marks":1376,"data":1377},", accessing 1,000s of support ticket descriptions and attachments, and 250k+ employee emails. ",[],{},{"nodeType":1294,"data":1379,"content":1380},{},[1381],{"nodeType":1293,"value":1382,"marks":1383,"data":1384},"But this isn’t specifically a Microsoft problem. The researcher could have picked from a long list of potential targets. If even Microsoft with their vast security resources can be caught off guard by this, what chance do other organizations have? If anything, it illustrates the scale of the challenge facing organizations when it comes to securing their identity surface. ",[],{},{"nodeType":1294,"data":1386,"content":1387},{},[1388],{"nodeType":1293,"value":1389,"marks":1390,"data":1391},"Let’s take a closer look at what we can learn from this attack — and what it tells us about the direction that identity attacks are (rapidly) heading in. ",[],{},{"nodeType":1393,"data":1394,"content":1395},"hr",{},[],{"nodeType":1397,"data":1398,"content":1399},"heading-1",{},[1400],{"nodeType":1293,"value":1401,"marks":1402,"data":1405},"Taking over ServiceNow accounts through credential stuffing (via infostealers)",[1403],{"type":1404},"bold",{},{"nodeType":1294,"data":1407,"content":1408},{},[1409],{"nodeType":1293,"value":1410,"marks":1411,"data":1412},"A bug bounty hunter was able to compromise Microsoft’s ServiceNow account using stolen credentials from historical infostealer infections, found using a commercial TI feed. ",[],{},{"nodeType":1294,"data":1414,"content":1415},{},[1416,1420,1425,1429,1434],{"nodeType":1293,"value":1417,"marks":1418,"data":1419},"The researcher was able to enumerate a login page for Microsoft at ",[],{},{"nodeType":1293,"value":1421,"marks":1422,"data":1424},"microsoft.servicenow.com/login.do",[1423],{"type":1339},{},{"nodeType":1293,"value":1426,"marks":1427,"data":1428},", with the /login.do meaning that ",[],{},{"nodeType":1293,"value":1430,"marks":1431,"data":1433},"SSO was enabled but not enforced",[1432],{"type":1404},{},{"nodeType":1293,"value":1435,"marks":1436,"data":1437},". At this point, the attacker was able to authenticate using the stolen credentials only (as the target account lacked MFA).",[],{},{"nodeType":1294,"data":1439,"content":1440},{},[1441],{"nodeType":1293,"value":1442,"marks":1443,"data":1444},"After logging in they were presented with a blank UI. However, because they now had an authenticated session, they were able to switch to the REST API, and subsequently access two key endpoints through which they were able to collect and exfiltrate sensitive data including 1,000s of support ticket attachments, over 250,000+ employee emails, and an xlsx file with historical ticket submissions to the MSRC team. ",[],{},{"nodeType":1446,"data":1447,"content":1453},"embedded-entry-block",{"target":1448},{"sys":1449},{"id":1450,"type":1451,"linkType":1452},"1Q2cL7mJhQUx1it0tU3MhJ","Link","Entry",[],{"nodeType":1294,"data":1455,"content":1456},{},[1457],{"nodeType":1293,"value":1458,"marks":1459,"data":1460},"Naturally, at this point the researcher ended their attack and sought out a bounty for their efforts. ",[],{},{"nodeType":1294,"data":1462,"content":1463},{},[1464],{"nodeType":1293,"value":1465,"marks":1466,"data":1467},"But a real attacker wouldn’t have stopped there. Immediately, you’d be thinking:",[],{},{"nodeType":1469,"data":1470,"content":1471},"unordered-list",{},[1472,1483,1493],{"nodeType":1473,"data":1474,"content":1475},"list-item",{},[1476],{"nodeType":1294,"data":1477,"content":1478},{},[1479],{"nodeType":1293,"value":1480,"marks":1481,"data":1482},"How many other organizations are likely impacted by this issue? Are there other credentials that correspond with these exposed login pages available online? ",[],{},{"nodeType":1473,"data":1484,"content":1485},{},[1486],{"nodeType":1294,"data":1487,"content":1488},{},[1489],{"nodeType":1293,"value":1490,"marks":1491,"data":1492},"Are there any ways that I could turn this access into a privileged account takeover? Would I be able to access even more information that way? ",[],{},{"nodeType":1473,"data":1494,"content":1495},{},[1496],{"nodeType":1294,"data":1497,"content":1498},{},[1499],{"nodeType":1293,"value":1500,"marks":1501,"data":1502},"How could this data be used to conduct further attacks? Would other criminal groups pay me for this information if I don’t want to do this myself? ",[],{},{"nodeType":1393,"data":1504,"content":1505},{},[],{"nodeType":1397,"data":1507,"content":1508},{},[1509],{"nodeType":1293,"value":1510,"marks":1511,"data":1513},"This isn’t just a Microsoft problem",[1512],{"type":1404},{},{"nodeType":1294,"data":1515,"content":1516},{},[1517],{"nodeType":1293,"value":1518,"marks":1519,"data":1520},"It seems unlikely that only Microsoft is affected here. Other ServiceNow tenants could have been taken over using the same approach. Other company credentials could be (will be) available online.",[],{},{"nodeType":1294,"data":1522,"content":1523},{},[1524,1528,1537],{"nodeType":1293,"value":1525,"marks":1526,"data":1527},"Using straightforward ",[],{},{"nodeType":1331,"data":1529,"content":1531},{"uri":1530},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/subdomain_tenant_discovery/description.md",[1532],{"nodeType":1293,"value":1533,"marks":1534,"data":1536},"tenant enumeration techniques",[1535],{"type":1339},{},{"nodeType":1293,"value":1538,"marks":1539,"data":1540}," and the list of ServiceNow named customers, it’s very easy to identify different customer tenants. And spending a few minutes using the same credential feed as the researcher, I found multiple organizations with many more breached credentials available linked to the same login.do page. ",[],{},{"nodeType":1393,"data":1542,"content":1543},{},[],{"nodeType":1397,"data":1545,"content":1546},{},[1547],{"nodeType":1293,"value":1548,"marks":1549,"data":1551},"Similarities with Snowflake",[1550],{"type":1404},{},{"nodeType":1294,"data":1553,"content":1554},{},[1555],{"nodeType":1293,"value":1556,"marks":1557,"data":1558},"There are no prizes for connecting this attack path with the infamous attacks on Snowflake customers earlier this year, which resulted in 165+ victims, and hundreds of millions of breached customer records. ",[],{},{"nodeType":1294,"data":1560,"content":1561},{},[1562],{"nodeType":1293,"value":1563,"marks":1564,"data":1565},"The Snowflake attack path was startlingly similar, and gives us a feel for what this attack could have turned into if conducted by a real attacker. ",[],{},{"nodeType":1446,"data":1567,"content":1571},{"target":1568},{"sys":1569},{"id":1570,"type":1451,"linkType":1452},"2J92gFLs1wAAGC4nQTaiWu",[],{"nodeType":1294,"data":1573,"content":1574},{},[1575,1579,1588],{"nodeType":1293,"value":1576,"marks":1577,"data":1578},"Both attacks began with stolen credentials breached in historical infostealer infections. In Snowflake’s case, 80% of the credentials used were connected to infostealer infections dating back to 2020, ",[],{},{"nodeType":1331,"data":1580,"content":1582},{"uri":1581},"https://cloud.google.com/blog/topics/threat-intelligence/unc5537-snowflake-data-theft-extortion",[1583],{"nodeType":1293,"value":1584,"marks":1585,"data":1587},"according to Mandiant",[1586],{"type":1339},{},{"nodeType":1293,"value":1589,"marks":1590,"data":1591},". ",[],{},{"nodeType":1393,"data":1593,"content":1594},{},[],{"nodeType":1397,"data":1596,"content":1597},{},[1598],{"nodeType":1293,"value":1599,"marks":1600,"data":1602},"Ghost logins strike again",[1601],{"type":1404},{},{"nodeType":1294,"data":1604,"content":1605},{},[1606,1609,1618],{"nodeType":1293,"value":37,"marks":1607,"data":1608},[],{},{"nodeType":1331,"data":1610,"content":1612},{"uri":1611},"https://pushsecurity.com/blog/ghost-logins-when-forgotten-identities-come-back-to-haunt-you/",[1613],{"nodeType":1293,"value":1614,"marks":1615,"data":1617},"Ghost logins",[1616],{"type":1339},{},{"nodeType":1293,"value":1619,"marks":1620,"data":1621}," are one of the leading factors in successful credential stuffing attacks. Simply put, ghost logins are often-forgotten local logins that are tricky for security teams to manage and secure.  ",[],{},{"nodeType":1294,"data":1623,"content":1624},{},[1625],{"nodeType":1293,"value":1626,"marks":1627,"data":1628},"Ghost logins are a problem for security teams because they often lack best practice security configurations, with things like weak, previously breached, and reused passwords — and no MFA. ",[],{},{"nodeType":1294,"data":1630,"content":1631},{},[1632],{"nodeType":1293,"value":1633,"marks":1634,"data":1635},"Many organizations think that by migrating an app to use SSO, where they’ve enforced MFA at the IdP level, it’s job done. However, this usually doesn’t eliminate previously created local accounts, meaning they need to be manually unset. But because organizations often lack app-level visibility of account configuration and login methods (it’s simply not provided by most app vendors) these accounts can fly under the radar for extended periods — often until situations like this when they are compromised. ",[],{},{"nodeType":1294,"data":1637,"content":1638},{},[1639,1643,1652],{"nodeType":1293,"value":1640,"marks":1641,"data":1642},"Ghost logins were a particular problem in the Snowflake attacks because MFA could not be globally enforced at the time of the incident. This meant that local accounts would need to be manually unset using the SQL interface — which unhelpfully ",[],{},{"nodeType":1331,"data":1644,"content":1646},{"uri":1645},"https://pushsecurity.com/resources/video/demonstrating-ghost-logins-in-snowflake-and-how-to-remediate-them/",[1647],{"nodeType":1293,"value":1648,"marks":1649,"data":1651},"provided inaccurate information about the account status and took extended periods of time to update",[1650],{"type":1339},{},{"nodeType":1293,"value":1653,"marks":1654,"data":1655}," after a change had been made, creating uncertainty and confusion for responders. But this is just one example of many illustrating how difficult in-app identity management can be. ",[],{},{"nodeType":1393,"data":1657,"content":1658},{},[],{"nodeType":1397,"data":1660,"content":1661},{},[1662],{"nodeType":1293,"value":1663,"marks":1664,"data":1666},"So what?",[1665],{"type":1404},{},{"nodeType":1294,"data":1668,"content":1669},{},[1670],{"nodeType":1293,"value":1671,"marks":1672,"data":1673},"If we hadn’t realized it yet, attacks targeting third-party business apps are everywhere. It’s not just the flavor of the month — it’s here to stay. ",[],{},{"nodeType":1294,"data":1675,"content":1676},{},[1677],{"nodeType":1293,"value":1678,"marks":1679,"data":1680},"This is because it’s so easy for attackers to monetize these compromises. Log into app > dump data > profit. ",[],{},{"nodeType":1294,"data":1682,"content":1683},{},[1684],{"nodeType":1293,"value":1685,"marks":1686,"data":1687},"And the easiest way to achieve this isn’t through complex software exploits, it’s through identity attacks. In the ServiceNow case, using public information (that was available to the security team too) to log into an app. It’s too easy.",[],{},{"nodeType":1393,"data":1689,"content":1690},{},[],{"nodeType":1397,"data":1692,"content":1693},{},[1694],{"nodeType":1293,"value":1695,"marks":1696,"data":1698},"Identity attacks are misunderstood",[1697],{"type":1404},{},{"nodeType":1294,"data":1700,"content":1701},{},[1702],{"nodeType":1293,"value":1703,"marks":1704,"data":1705},"The researcher notes that, despite the severity of the bug, it wasn’t paid out under the MSRC bug bounty scheme. And while this is perhaps not a classic software exploit, you can’t argue about the risk it poses. This is just as impactful as any classic vulnerability, if not more so — because the technical barrier to entry is so much lower. ",[],{},{"nodeType":1294,"data":1707,"content":1708},{},[1709,1713,1722],{"nodeType":1293,"value":1710,"marks":1711,"data":1712},"Pat Gray of the Risky Biz podcast ",[],{},{"nodeType":1331,"data":1714,"content":1716},{"uri":1715},"https://risky.biz/RB766/",[1717],{"nodeType":1293,"value":1718,"marks":1719,"data":1721},"said of another recent disclosure",[1720],{"type":1339},{},{"nodeType":1293,"value":1723,"marks":1724,"data":1725},", where a 15 year-old researcher was able to turn a Zendesk ‘feature’ into hijacking Apple SSO to log into downstream SaaS, that there’s a lack of imagination in understanding how these third-party apps can be abused by an attacker. I’d tend to agree here.",[],{},{"nodeType":1294,"data":1727,"content":1728},{},[1729],{"nodeType":1293,"value":1730,"marks":1731,"data":1732},"Part of the challenge here is perhaps a lack of awareness of just how severe these issues are. Certainly in the Zendesk case, the initial disclosure (email spoofing) was thrown out, but when it was demonstrated that it could be used to take over downstream apps like Slack, affected companies were happy to pay up, and Zendesk (via HackerOne) got back in touch. ",[],{},{"nodeType":1294,"data":1734,"content":1735},{},[1736],{"nodeType":1293,"value":1737,"marks":1738,"data":1739},"If I were the researcher, I would have considered reporting this issue to ServiceNow too, not just Microsoft — as it undoubtedly affects many organizations. Yes, the fact that Microsoft credentials were accessible online is a Microsoft problem, but given the potential spread of organizations also susceptible to this attack, does the vendor not have a responsibility to help mitigate these attacks? I would hope that ServiceNow have contacted their customers to be cautious of experiencing an increase in credential stuffing attacks in the near future at the very least. ",[],{},{"nodeType":1294,"data":1741,"content":1742},{},[1743],{"nodeType":1293,"value":1744,"marks":1745,"data":1746},"There’s clearly a need for better security-by-default from SaaS vendors — things like mandatory MFA enforcement would be a good start. Because there are simply too many apps, and too many accounts to manage — and no effective centralized way of managing them across your SaaS inventory. ",[],{},{"nodeType":1294,"data":1748,"content":1749},{},[1750],{"nodeType":1293,"value":1751,"marks":1752,"data":1753},"It makes you wonder how many other apps are impacted by ‘on by default’ configurations that can be abused in ways we just don’t know about yet. Partly because nobody is really looking — bug bounties aren’t being paid out, and I know of only a handful of forward-thinking security consultancies conducting any real offensive security testing with their clients in this space. ",[],{},{"nodeType":1294,"data":1755,"content":1756},{},[1757],{"nodeType":1293,"value":1758,"marks":1759,"data":1760},"We are also reminded, again and again, that credential stuffing attacks are as effective as ever. Despite the investment in SSO, MFA, and all of the identity management and hygiene tools that organizations have nowadays, attackers and researchers keep finding gaps.  ",[],{},{"nodeType":1393,"data":1762,"content":1763},{},[],{"nodeType":1397,"data":1765,"content":1766},{},[1767],{"nodeType":1293,"value":1768,"marks":1769,"data":1771},"What can you do about it? ",[1770],{"type":1404},{},{"nodeType":1294,"data":1773,"content":1774},{},[1775],{"nodeType":1293,"value":1776,"marks":1777,"data":1778},"The most important step is to acknowledge the severity of the threat — and the ways that expected controls are failing.",[],{},{"nodeType":1469,"data":1780,"content":1781},{},[1782,1792,1802,1812],{"nodeType":1473,"data":1783,"content":1784},{},[1785],{"nodeType":1294,"data":1786,"content":1787},{},[1788],{"nodeType":1293,"value":1789,"marks":1790,"data":1791},"There will almost always be gaps in any organization’s identity security perimeter, simply because it’s almost impossible to have the required visibility — even if you’re Microsoft with your vast security resources.",[],{},{"nodeType":1473,"data":1793,"content":1794},{},[1795],{"nodeType":1294,"data":1796,"content":1797},{},[1798],{"nodeType":1293,"value":1799,"marks":1800,"data":1801},"There will always be ways to abuse app features and configurations, and we’ve barely begun to scratch the surface of what’s now possible in the world of connected SaaS.",[],{},{"nodeType":1473,"data":1803,"content":1804},{},[1805],{"nodeType":1294,"data":1806,"content":1807},{},[1808],{"nodeType":1293,"value":1809,"marks":1810,"data":1811},"These attacks are very difficult to intercept once an attacker is active inside an app, because there’s very little meaningful visibility. ",[],{},{"nodeType":1473,"data":1813,"content":1814},{},[1815],{"nodeType":1294,"data":1816,"content":1817},{},[1818],{"nodeType":1293,"value":1819,"marks":1820,"data":1821},"Once they’re inside, the attack can be over incredibly quickly, and can be repeated across app tenants for maximum impact (again, just look at Snowflake). ",[],{},{"nodeType":1294,"data":1823,"content":1824},{},[1825,1829,1838],{"nodeType":1293,"value":1826,"marks":1827,"data":1828},"At Push, we’re focused primarily on detecting and intercepting account takeover for these reasons — it’s your earliest opportunity, and for many attacks it’s also your last. If you want to learn more, ",[],{},{"nodeType":1331,"data":1830,"content":1832},{"uri":1831},"https://pushsecurity.com/blog/shifting-detection-left-for-more-effective-itdr/",[1833],{"nodeType":1293,"value":1834,"marks":1835,"data":1837},"check out our recent design philosophy blog",[1836],{"type":1339},{},{"nodeType":1293,"value":1839,"marks":1840,"data":1841}," discussing why we’re shifting detection left to focus on account takeover.  ",[],{},"What we can learn from the recent ServiceNow/Microsoft disclosure","Account takeover on third-party apps is the flavor of the month for security researchers — what can we learn from it? ","2024-11-01T00:00:00.000Z","learning-from-the-servicenow-disclosure",{"items":1847},[1848,1850],{"sys":1849,"name":1308},{"id":1307},{"sys":1851,"name":1853},{"id":1852},"3pjES4THCIfSAwhGdNwBcy","Identity security",{"items":1855},[1856],{"fullName":1857,"firstName":1858,"jobTitle":1859,"profilePicture":1860},"Dan Green","Dan","Threat Research",{"url":1861},"https://images.ctfassets.net/y1cdw1ablpvd/7jik1VhFgA3kgzXBXTm2Vw/fcd8c171da644903d0827eafcfbcaad0/Dan_Headshot_2025.png",{"__typename":1316,"sys":1863,"content":1865,"title":2702,"synopsis":2703,"hashTags":118,"publishedDate":2704,"slug":2705,"tagsCollection":2706,"authorsCollection":2712},{"id":1864},"174u87EYeKMKHzYYxBLlHO",{"json":1866},{"nodeType":1295,"data":1867,"content":1868},{},[1869,1876,1883,1890,1921,1928,1935,1954,1962,1969,1987,1994,2001,2008,2014,2021,2064,2071,2078,2085,2108,2115,2122,2129,2177,2184,2191,2198,2205,2217,2224,2232,2239,2272,2279,2286,2293,2300,2370,2378,2385,2392,2426,2433,2441,2448,2455,2467,2483,2516,2536,2543,2561,2568,2575,2592,2599,2606,2613,2646,2653,2672,2690,2696],{"nodeType":1294,"data":1870,"content":1871},{},[1872],{"nodeType":1293,"value":1873,"marks":1874,"data":1875},"Identity attacks like phishing, credential stuffing, and session hijacking are now the leading cause of cyber security breaches, as attackers shift their attention to the sprawl of third-party applications and services that has become the backbone of business IT. ",[],{},{"nodeType":1294,"data":1877,"content":1878},{},[1879],{"nodeType":1293,"value":1880,"marks":1881,"data":1882},"The attacker’s goal in these attacks is account takeover: logging into a user account to access your company app tenant. From there, the attacker can usually achieve all of their objectives from inside the compromised app, usually involving dumping sensitive data with which to hold the company to ransom, or selling the data on underground criminal marketplaces. ",[],{},{"nodeType":1294,"data":1884,"content":1885},{},[1886],{"nodeType":1293,"value":1887,"marks":1888,"data":1889},"These attack techniques have been commonplace for over a decade — but the shift in attack context away from attacking endpoints (user devices and servers) to cloud services is seeing something of an identity attack renaissance. ",[],{},{"nodeType":1294,"data":1891,"content":1892},{},[1893,1896,1904,1908,1917],{"nodeType":1293,"value":37,"marks":1894,"data":1895},[],{},{"nodeType":1331,"data":1897,"content":1899},{"uri":1898},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/ghost_logins/description.md",[1900],{"nodeType":1293,"value":1614,"marks":1901,"data":1903},[1902],{"type":1339},{},{"nodeType":1293,"value":1905,"marks":1906,"data":1907}," are one of the leading factors in successful ",[],{},{"nodeType":1331,"data":1909,"content":1911},{"uri":1910},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/credential_stuffing/description.md",[1912],{"nodeType":1293,"value":1913,"marks":1914,"data":1916},"credential stuffing",[1915],{"type":1339},{},{"nodeType":1293,"value":1918,"marks":1919,"data":1920}," attacks driving account takeover.",[],{},{"nodeType":1397,"data":1922,"content":1923},{},[1924],{"nodeType":1293,"value":1925,"marks":1926,"data":1927},"Ghost logins 101",[],{},{"nodeType":1294,"data":1929,"content":1930},{},[1931],{"nodeType":1293,"value":1932,"marks":1933,"data":1934},"Simply put, ghost logins are often-forgotten alternative login methods that are tricky for security teams to manage and secure — because they don’t know about them. Because of this, they’re likely to possess weak configurations that make them susceptible to account takeover attacks. ",[],{},{"nodeType":1294,"data":1936,"content":1937},{},[1938,1942,1950],{"nodeType":1293,"value":1939,"marks":1940,"data":1941},"We found that ",[],{},{"nodeType":1331,"data":1943,"content":1945},{"uri":1944},"https://pushsecurity.com/blog/how-many-vulnerable-identities-do-you-have/",[1946],{"nodeType":1293,"value":1947,"marks":1948,"data":1949},"ghost logins are present in ~10% of the accounts per organization",[],{},{"nodeType":1293,"value":1951,"marks":1952,"data":1953},". ",[],{},{"nodeType":1955,"data":1956,"content":1957},"heading-2",{},[1958],{"nodeType":1293,"value":1959,"marks":1960,"data":1961},"Why do ghost logins exist?",[],{},{"nodeType":1294,"data":1963,"content":1964},{},[1965],{"nodeType":1293,"value":1966,"marks":1967,"data":1968},"Identity management used to be something that was centrally contained and managed using an enterprise identity service like Active Directory. Most users probably only had one or two identities that you really cared about: the one they used to log into their company laptop and domain, and maybe also to log into a VPN. ",[],{},{"nodeType":1294,"data":1970,"content":1971},{},[1972,1976,1983],{"nodeType":1293,"value":1973,"marks":1974,"data":1975},"Now, there are ",[],{},{"nodeType":1331,"data":1977,"content":1978},{"uri":1944},[1979],{"nodeType":1293,"value":1980,"marks":1981,"data":1982},"200+ business apps in use per company, creating 1000s of sprawled identities",[],{},{"nodeType":1293,"value":1984,"marks":1985,"data":1986}," across an ecosystem of business apps and services accessed over the internet.",[],{},{"nodeType":1294,"data":1988,"content":1989},{},[1990],{"nodeType":1293,"value":1991,"marks":1992,"data":1993},"Most businesses have tried to solve this problem with single sign on (SSO). The logic being that if you can use a single set of credentials (and therefore, a single identity) to access all of your business apps, and then secure those credentials with MFA, then this problem goes away. However…",[],{},{"nodeType":1955,"data":1995,"content":1996},{},[1997],{"nodeType":1293,"value":1998,"marks":1999,"data":2000},"SSO expectations versus reality",[],{},{"nodeType":1294,"data":2002,"content":2003},{},[2004],{"nodeType":1293,"value":2005,"marks":2006,"data":2007},"Unfortunately, the reality of SSO implementation is flawed. Most apps accept multiple login methods that can be configured — and used — simultaneously (yes, most apps don’t have proper session controls).  ",[],{},{"nodeType":1446,"data":2009,"content":2013},{"target":2010},{"sys":2011},{"id":2012,"type":1451,"linkType":1452},"3sOz3HkiyJpY9nFtGCWEOV",[],{"nodeType":1294,"data":2015,"content":2016},{},[2017],{"nodeType":1293,"value":2018,"marks":2019,"data":2020},"This is made worse by the fact that:",[],{},{"nodeType":1469,"data":2022,"content":2023},{},[2024,2034,2044,2054],{"nodeType":1473,"data":2025,"content":2026},{},[2027],{"nodeType":1294,"data":2028,"content":2029},{},[2030],{"nodeType":1293,"value":2031,"marks":2032,"data":2033},"Most apps can't be locked down to restrict which login methods are accepted.",[],{},{"nodeType":1473,"data":2035,"content":2036},{},[2037],{"nodeType":1294,"data":2038,"content":2039},{},[2040],{"nodeType":1293,"value":2041,"marks":2042,"data":2043},"Users often self-adopt apps, and default to a username and password (and typically miss out MFA). ",[],{},{"nodeType":1473,"data":2045,"content":2046},{},[2047],{"nodeType":1294,"data":2048,"content":2049},{},[2050],{"nodeType":1293,"value":2051,"marks":2052,"data":2053},"SSO isn’t always possible if you aren’t using a supported IdP — and only one in three apps support SAML, the preferred enterprise-grade protocol.",[],{},{"nodeType":1473,"data":2055,"content":2056},{},[2057],{"nodeType":1294,"data":2058,"content":2059},{},[2060],{"nodeType":1293,"value":2061,"marks":2062,"data":2063},"Even where SSO is possible, configuring an app for SSO doesn't automatically delete any legacy local logins.",[],{},{"nodeType":1294,"data":2065,"content":2066},{},[2067],{"nodeType":1293,"value":2068,"marks":2069,"data":2070},"Inevitably, this means that there are many situations in which users will create local accounts — typically with a username and password, and without MFA. This is how ghost logins are born.",[],{},{"nodeType":1955,"data":2072,"content":2073},{},[2074],{"nodeType":1293,"value":2075,"marks":2076,"data":2077},"How are ghost logins created? ",[],{},{"nodeType":1294,"data":2079,"content":2080},{},[2081],{"nodeType":1293,"value":2082,"marks":2083,"data":2084},"Ghost logins can be created in the following ways:",[],{},{"nodeType":1469,"data":2086,"content":2087},{},[2088,2098],{"nodeType":1473,"data":2089,"content":2090},{},[2091],{"nodeType":1294,"data":2092,"content":2093},{},[2094],{"nodeType":1293,"value":2095,"marks":2096,"data":2097},"A user self-adopts an app, setting up an account with a local username and password. The app is later adopted companywide and brought under SSO. This creates an additional SSO login method, likely as the default, but the local login will continue to exist unless explicitly disabled or deleted. ",[],{},{"nodeType":1473,"data":2099,"content":2100},{},[2101],{"nodeType":1294,"data":2102,"content":2103},{},[2104],{"nodeType":1293,"value":2105,"marks":2106,"data":2107},"Secondary/backup login methods can often be added later in the app settings after logging in. This includes things like setting up a secondary email to send a login link to, or setting up API access to remove the need to authenticate altogether. ",[],{},{"nodeType":1294,"data":2109,"content":2110},{},[2111],{"nodeType":1293,"value":2112,"marks":2113,"data":2114},"So, ghost logins are very easily introduced through the normal course of app adoption and use by employees. ",[],{},{"nodeType":1955,"data":2116,"content":2117},{},[2118],{"nodeType":1293,"value":2119,"marks":2120,"data":2121},"Why do ghost logins pose a risk? ",[],{},{"nodeType":1294,"data":2123,"content":2124},{},[2125],{"nodeType":1293,"value":2126,"marks":2127,"data":2128},"Ghost logins pose a risk for a number of reasons, as they: ",[],{},{"nodeType":1469,"data":2130,"content":2131},{},[2132,2147,2162],{"nodeType":1473,"data":2133,"content":2134},{},[2135],{"nodeType":1294,"data":2136,"content":2137},{},[2138,2143],{"nodeType":1293,"value":2139,"marks":2140,"data":2142},"Typically have less secure configurations ",[2141],{"type":1404},{},{"nodeType":1293,"value":2144,"marks":2145,"data":2146},"than your preferred login method – and may be missing key controls like MFA.  ",[],{},{"nodeType":1473,"data":2148,"content":2149},{},[2150],{"nodeType":1294,"data":2151,"content":2152},{},[2153,2158],{"nodeType":1293,"value":2154,"marks":2155,"data":2157},"Are effectively shadow logins",[2156],{"type":1404},{},{"nodeType":1293,"value":2159,"marks":2160,"data":2161}," – IT/security don’t know about them, and if using an IdP as your primary identity security interface, they won’t necessarily be visible without taking a deeper look at individual apps. ",[],{},{"nodeType":1473,"data":2163,"content":2164},{},[2165],{"nodeType":1294,"data":2166,"content":2167},{},[2168,2173],{"nodeType":1293,"value":2169,"marks":2170,"data":2172},"Can be used simultaneously with SSO",[2171],{"type":1404},{},{"nodeType":1293,"value":2174,"marks":2175,"data":2176}," – so you can have an unrestricted number of concurrent sessions with SSO and non SSO logins active at the same time, without the user being kicked out of the previous session.",[],{},{"nodeType":1294,"data":2178,"content":2179},{},[2180],{"nodeType":1293,"value":2181,"marks":2182,"data":2183},"Ghost logins provide opportunities for attackers to bypass security controls for initial access and persistence in an application (which we’ll come onto in more detail later). They also provide an opportunity for malicious insiders, e.g. a disgruntled employee, to access systems even after SSO access is revoked. If the security team relies on IdP logs to audit app logins, these accounts can go undetected.",[],{},{"nodeType":1294,"data":2185,"content":2186},{},[2187],{"nodeType":1293,"value":2188,"marks":2189,"data":2190},"To be able to identify them, you’d need to log into the app admin dashboard. But depending on how the app was adopted, you (as a security admin) may not even be an app-level admin — it’s not unusual for individual teams to administer their own apps. And even if you do have access, it’s not always easy (or possible) to gather this level of information about user account configuration. ",[],{},{"nodeType":1294,"data":2192,"content":2193},{},[2194],{"nodeType":1293,"value":2195,"marks":2196,"data":2197},"It’s very easy to see how these vulnerable login methods can be overlooked by security teams – let’s look at how they can be identified and exploited by attackers. ",[],{},{"nodeType":1397,"data":2199,"content":2200},{},[2201],{"nodeType":1293,"value":2202,"marks":2203,"data":2204},"How can ghost logins be exploited by attackers?",[],{},{"nodeType":1294,"data":2206,"content":2207},{},[2208,2213],{"nodeType":1293,"value":2209,"marks":2210,"data":2212},"Let’s take an example scenario:",[2211],{"type":1404},{},{"nodeType":1293,"value":2214,"marks":2215,"data":2216}," You’re using an IdP solution like Okta or Microsoft/Entra with SAML SSO as the default login method for your core business apps. Via your IdP you require MFA when authenticating to your IdP apps page, and also potentially when signing into an individual connected app. ",[],{},{"nodeType":1294,"data":2218,"content":2219},{},[2220],{"nodeType":1293,"value":2221,"marks":2222,"data":2223},"However, you only recently introduced your IdP solution, and your users previously accessed this app with a local username and password. Although you asked your users to configure MFA in the app itself, not all of them did. And when you deployed your IdP solution, you didn’t manually unset all the local password-based logins for the apps you connected to it. ",[],{},{"nodeType":1294,"data":2225,"content":2226},{},[2227],{"nodeType":1293,"value":2228,"marks":2229,"data":2231},"Unknown to you, there are now hundreds of local accounts for core business apps which lack MFA. ",[2230],{"type":1404},{},{"nodeType":1294,"data":2233,"content":2234},{},[2235],{"nodeType":1293,"value":2236,"marks":2237,"data":2238},"There are two main scenarios in which ghost logins can be utilized by an attacker:",[],{},{"nodeType":1469,"data":2240,"content":2241},{},[2242,2257],{"nodeType":1473,"data":2243,"content":2244},{},[2245],{"nodeType":1294,"data":2246,"content":2247},{},[2248,2253],{"nodeType":1293,"value":2249,"marks":2250,"data":2252},"To bypass robustly configured login methods",[2251],{"type":1404},{},{"nodeType":1293,"value":2254,"marks":2255,"data":2256}," such as SSO to compromise an app identity during the initial access phase of an attack. ",[],{},{"nodeType":1473,"data":2258,"content":2259},{},[2260],{"nodeType":1294,"data":2261,"content":2262},{},[2263,2268],{"nodeType":1293,"value":2264,"marks":2265,"data":2267},"To create additional login methods for an already compromised account to ensure persistent access",[2266],{"type":1404},{},{"nodeType":1293,"value":2269,"marks":2270,"data":2271}," – even if the original compromised login method is revoked or disabled. This could be either the result of compromising an identity belonging to a specific app, or having previously compromised an IdP account (e.g. Okta).",[],{},{"nodeType":1294,"data":2273,"content":2274},{},[2275],{"nodeType":1293,"value":2276,"marks":2277,"data":2278},"Let's look at these use cases in more detail. ",[],{},{"nodeType":1955,"data":2280,"content":2281},{},[2282],{"nodeType":1293,"value":2283,"marks":2284,"data":2285},"Ghost logins for initial access",[],{},{"nodeType":1294,"data":2287,"content":2288},{},[2289],{"nodeType":1293,"value":2290,"marks":2291,"data":2292},"Arguably the most dangerous use case for ghost logins is to conduct credential attacks against accounts using a username and password. Logins with a weak or guessable password, or a reused password that has appeared in a public data breach dump, are primed for account takeover. ",[],{},{"nodeType":1294,"data":2294,"content":2295},{},[2296],{"nodeType":1293,"value":2297,"marks":2298,"data":2299},"The cyber crime ecosystem is leaning toward the theft, sale, and use of stolen credentials (not just emails and passwords, but session tokens too). ",[],{},{"nodeType":1469,"data":2301,"content":2302},{},[2303,2326,2348],{"nodeType":1473,"data":2304,"content":2305},{},[2306],{"nodeType":1294,"data":2307,"content":2308},{},[2309,2313,2322],{"nodeType":1293,"value":2310,"marks":2311,"data":2312},"There are 600 million identity attacks per day, with 99% involving passwords (",[],{},{"nodeType":1331,"data":2314,"content":2316},{"uri":2315},"https://cdn-dynmedia-1.microsoft.com/is/content/microsoftcorp/microsoft/final/en-us/microsoft-brand/documents/Microsoft%20Digital%20Defense%20Report%202024%20%281%29.pdf",[2317],{"nodeType":1293,"value":2318,"marks":2319,"data":2321},"Microsoft",[2320],{"type":1339},{},{"nodeType":1293,"value":2323,"marks":2324,"data":2325},").",[],{},{"nodeType":1473,"data":2327,"content":2328},{},[2329],{"nodeType":1294,"data":2330,"content":2331},{},[2332,2336,2345],{"nodeType":1293,"value":2333,"marks":2334,"data":2335},"Over 1000 credentials are posted online per day, per marketplace with an average sale price of $10, and 65% posted less than one day after being collected (",[],{},{"nodeType":1331,"data":2337,"content":2339},{"uri":2338},"https://www.verizon.com/business/en-gb/resources/reports/dbir/",[2340],{"nodeType":1293,"value":2341,"marks":2342,"data":2344},"Verizon",[2343],{"type":1339},{},{"nodeType":1293,"value":2323,"marks":2346,"data":2347},[],{},{"nodeType":1473,"data":2349,"content":2350},{},[2351],{"nodeType":1294,"data":2352,"content":2353},{},[2354,2358,2367],{"nodeType":1293,"value":2355,"marks":2356,"data":2357},"One million new stealer logs are distributed every month, with an estimated 3-5% containing credentials and session cookies to corporate IT environments (",[],{},{"nodeType":1331,"data":2359,"content":2361},{"uri":2360},"https://www.bleepingcomputer.com/news/security/single-sign-on-and-the-cybercrime-ecosystem/",[2362],{"nodeType":1293,"value":2363,"marks":2364,"data":2366},"Flare",[2365],{"type":1339},{},{"nodeType":1293,"value":2323,"marks":2368,"data":2369},[],{},{"nodeType":1294,"data":2371,"content":2372},{},[2373],{"nodeType":1293,"value":2374,"marks":2375,"data":2377},"So, it’s easier than ever for attackers to gather breached credentials and weaponize them at scale. ",[2376],{"type":1404},{},{"nodeType":1294,"data":2379,"content":2380},{},[2381],{"nodeType":1293,"value":2382,"marks":2383,"data":2384},"Realistically, any username and password combination for addresses belonging to a specific organization/domain can be attempted on any app. Breached credential data will often provide a strong indicator of other apps also in use for that organization. And for apps with a custom tenant URL (that cannot be easily guessed) data dumps often helpfully include the URLs for those login pages, too.  ",[],{},{"nodeType":1294,"data":2386,"content":2387},{},[2388],{"nodeType":1293,"value":2389,"marks":2390,"data":2391},"The risk posed by the massive amounts of leaked credentials available is heightened because: ",[],{},{"nodeType":1469,"data":2393,"content":2394},{},[2395,2416],{"nodeType":1473,"data":2396,"content":2397},{},[2398],{"nodeType":1294,"data":2399,"content":2400},{},[2401,2405,2412],{"nodeType":1293,"value":2402,"marks":2403,"data":2404},"Many employees reuse passwords, with ",[],{},{"nodeType":1331,"data":2406,"content":2407},{"uri":1944},[2408],{"nodeType":1293,"value":2409,"marks":2410,"data":2411},"~9% of all accounts using a breached, weak, or reused password",[],{},{"nodeType":1293,"value":2413,"marks":2414,"data":2415},". This isn’t just for low-risk apps either, and includes the reuse of highly sensitive IdP creds. ",[],{},{"nodeType":1473,"data":2417,"content":2418},{},[2419],{"nodeType":1294,"data":2420,"content":2421},{},[2422],{"nodeType":1293,"value":2423,"marks":2424,"data":2425},"Organizations don’t typically rotate or enforce changes to SaaS app passwords in the same way they might for company account/device login connected to Active Directory.  ",[],{},{"nodeType":1294,"data":2427,"content":2428},{},[2429],{"nodeType":1293,"value":2430,"marks":2431,"data":2432},"Ghost logins aren’t limited to just username and password either. For example, a breached social account such as Facebook or Google can result in a broader compromise if those accounts have been connected to any corporate apps.   ",[],{},{"nodeType":1294,"data":2434,"content":2435},{},[2436],{"nodeType":1293,"value":2437,"marks":2438,"data":2440},"So, exploiting ghost logins can be a highly effective method for attackers to gain initial access to a user account from which to launch further attacks.  ",[2439],{"type":1404},{},{"nodeType":1955,"data":2442,"content":2443},{},[2444],{"nodeType":1293,"value":2445,"marks":2446,"data":2447},"Ghost logins for persistence and defense evasion",[],{},{"nodeType":1294,"data":2449,"content":2450},{},[2451],{"nodeType":1293,"value":2452,"marks":2453,"data":2454},"Now, we’ll take a look at how attackers can leverage ghost logins as part of the later stages of an attack, having already established an initial foothold via account compromise. ",[],{},{"nodeType":1294,"data":2456,"content":2457},{},[2458,2462],{"nodeType":1293,"value":2459,"marks":2460,"data":2461},"If an organization has a reasonable level of security monitoring in-place (depending on log availability from the particular app vendor), or a victim receives a notification about an unusual login (e.g. from a new device or unusual IP) then access to an account can be short-lived. ",[],{},{"nodeType":1293,"value":2463,"marks":2464,"data":2466},"However, ghost logins can provide attackers with the tools to maintain persistent access to a compromised account, even if the initial compromised login method is disabled or revoked. ",[2465],{"type":1404},{},{"nodeType":1294,"data":2468,"content":2469},{},[2470,2474,2479],{"nodeType":1293,"value":2471,"marks":2472,"data":2473},"For example, if a social login is used to access an account, an adversary may be able to configure a separate username/password login, or even (though much less commonly) connect a second social account that the adversary controls. This allows the adversary to maintain persistent access to the user account ",[],{},{"nodeType":1293,"value":2475,"marks":2476,"data":2478},"even in the event of password changes or MFA changes",[2477],{"type":1404},{},{"nodeType":1293,"value":2480,"marks":2481,"data":2482},". The attack will go unnoticed if the victim organization relies on SSO logs for auditing access to SaaS applications because the attack bypasses SSO, as the login remains local to the SaaS app or, in the case of an OIDC SSO login, the adversary’s own social account.",[],{},{"nodeType":1294,"data":2484,"content":2485},{},[2486,2490,2499,2503,2512],{"nodeType":1293,"value":2487,"marks":2488,"data":2489},"Another quirk is that it’s common for ordinary users to become app-level admins when an app is self-adopted by an individual or team. If an attacker is able to gain control of such an account, it can then be used to target other users without needing to deliver phishing links by hijacking SAML-based authentication. In this scenario, users attempting to sign in using SAML SSO are directed it to an attacker-controlled tenant in a watering hole attack (also known as ",[],{},{"nodeType":1331,"data":2491,"content":2493},{"uri":2492},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/samljacking/description.md",[2494],{"nodeType":1293,"value":2495,"marks":2496,"data":2498},"SAMLjacking",[2497],{"type":1339},{},{"nodeType":1293,"value":2500,"marks":2501,"data":2502},", which you can ",[],{},{"nodeType":1331,"data":2504,"content":2506},{"uri":2505},"https://pushsecurity.com/blog/samljacking-a-poisoned-tenant/",[2507],{"nodeType":1293,"value":2508,"marks":2509,"data":2511},"read more about in another blog post",[2510],{"type":1339},{},{"nodeType":1293,"value":2513,"marks":2514,"data":2515},"). ",[],{},{"nodeType":1294,"data":2517,"content":2518},{},[2519,2523,2532],{"nodeType":1293,"value":2520,"marks":2521,"data":2522},"If you're curious as to how an attacker might be able to compromise an IdP account such as Okta, ",[],{},{"nodeType":1331,"data":2524,"content":2526},{"uri":2525},"https://pushsecurity.com/blog/phishing-2-0-how-phishing-toolkits-are-evolving-with-aitm/",[2527],{"nodeType":1293,"value":2528,"marks":2529,"data":2531},"you should check out our blog post on AitM and BitM phishing techniques",[2530],{"type":1339},{},{"nodeType":1293,"value":2533,"marks":2534,"data":2535},".  ",[],{},{"nodeType":1397,"data":2537,"content":2538},{},[2539],{"nodeType":1293,"value":2540,"marks":2541,"data":2542},"Case study: Snowflake",[],{},{"nodeType":1294,"data":2544,"content":2545},{},[2546,2550,2557],{"nodeType":1293,"value":2547,"marks":2548,"data":2549},"The ",[],{},{"nodeType":1331,"data":2551,"content":2552},{"uri":1347},[2553],{"nodeType":1293,"value":2554,"marks":2555,"data":2556},"recent attacks on 165 Snowflake customers",[],{},{"nodeType":1293,"value":2558,"marks":2559,"data":2560},", resulting in hundreds of millions of breached customer records, were the product of a credential stuffing campaign using stolen credentials from infostealer infections dating back to 2020. ",[],{},{"nodeType":1294,"data":2562,"content":2563},{},[2564],{"nodeType":1293,"value":2565,"marks":2566,"data":2567},"The industry response to Snowflake was typical: check whether Snowflake has been set up for SSO, and if so, job done — we’re protected by MFA.",[],{},{"nodeType":1294,"data":2569,"content":2570},{},[2571],{"nodeType":1293,"value":2572,"marks":2573,"data":2574},"The reality was that MFA was not — and could not — be centrally enforced for username and password accounts. Even if MFA was applied at the IdP level for SSO logins, it was not enforced for local username and password logins. It needed to be opted-into by the user. ",[],{},{"nodeType":1294,"data":2576,"content":2577},{},[2578,2582,2589],{"nodeType":1293,"value":2579,"marks":2580,"data":2581},"This meant the most logical thing to do was to disable local accounts. But because Snowflake is essentially a cloud-hosted SQL database, there was no easy-to-use GUI to access local account config data. Once you’d managed to get an admin account with the right permissions, you needed to run various commands to find and unset the accounts. ",[],{},{"nodeType":1331,"data":2583,"content":2584},{"uri":1645},[2585],{"nodeType":1293,"value":2586,"marks":2587,"data":2588},"But if you didn’t have the exact type of admin account, misleading results would be returned — and even after you had fixed the vulnerability it took hours to update the database. ",[],{},{"nodeType":1293,"value":37,"marks":2590,"data":2591},[],{},{"nodeType":1294,"data":2593,"content":2594},{},[2595],{"nodeType":1293,"value":2596,"marks":2597,"data":2598},"This meant that organizations were exposed to these attacks for a prolonged period, and were left uncertain as to whether they had addressed the vulnerabilities or not. ",[],{},{"nodeType":1397,"data":2600,"content":2601},{},[2602],{"nodeType":1293,"value":2603,"marks":2604,"data":2605},"Using Push to find and fix ghost logins across your app inventory",[],{},{"nodeType":1294,"data":2607,"content":2608},{},[2609],{"nodeType":1293,"value":2610,"marks":2611,"data":2612},"Finding and fixing ghost logins is a challenge for most organizations. Since you can’t rely on the view provided by your IdP, you need to:",[],{},{"nodeType":1469,"data":2614,"content":2615},{},[2616,2626,2636],{"nodeType":1473,"data":2617,"content":2618},{},[2619],{"nodeType":1294,"data":2620,"content":2621},{},[2622],{"nodeType":1293,"value":2623,"marks":2624,"data":2625},"Discover the apps in use across your organization",[],{},{"nodeType":1473,"data":2627,"content":2628},{},[2629],{"nodeType":1294,"data":2630,"content":2631},{},[2632],{"nodeType":1293,"value":2633,"marks":2634,"data":2635},"Get admin rights, audit each app, and unset any local credentials (enforcing MFA at the app-level too if you can, for good measure)",[],{},{"nodeType":1473,"data":2637,"content":2638},{},[2639],{"nodeType":1294,"data":2640,"content":2641},{},[2642],{"nodeType":1293,"value":2643,"marks":2644,"data":2645},"Configure the app to prevent local accounts being created (again, if possible)",[],{},{"nodeType":1294,"data":2647,"content":2648},{},[2649],{"nodeType":1293,"value":2650,"marks":2651,"data":2652},"Not only is this a sisyphean task with continually moving goalposts, but depending on which apps you use, and how they’ve been designed, it may not be possible to remediate every instance of ghost logins. For that reason, it’s important to also invest in your identity threat detection and response capabilities — for when, not if, an account takeover attempt occurs. ",[],{},{"nodeType":1294,"data":2654,"content":2655},{},[2656,2660,2669],{"nodeType":1293,"value":2657,"marks":2658,"data":2659},"Push helps organizations to defend against ghost logins and other identity threats with a defense-in-depth approach: Using a browser-based agent to generate visibility of all logins (not just via IdP logs) while also detecting, intercepting, and shutting down account takeover attempts via phishing, credential stuffing, and session hijacking. ",[],{},{"nodeType":1331,"data":2661,"content":2663},{"uri":2662},"https://pushsecurity.com/",[2664],{"nodeType":1293,"value":2665,"marks":2666,"data":2668},"Learn more here.",[2667],{"type":1339},{},{"nodeType":1293,"value":37,"marks":2670,"data":2671},[],{},{"nodeType":1294,"data":2673,"content":2674},{},[2675,2679,2687],{"nodeType":1293,"value":2676,"marks":2677,"data":2678},"And if you'd like to learn more about ghost logins and other identity attack techniques, ",[],{},{"nodeType":1331,"data":2680,"content":2682},{"uri":2681},"https://github.com/pushsecurity/saas-attacks?tab=readme-ov-file",[2683],{"nodeType":1293,"value":2684,"marks":2685,"data":2686},"check out the SaaS attack matrix on GitHub",[],{},{"nodeType":1293,"value":1951,"marks":2688,"data":2689},[],{},{"nodeType":1446,"data":2691,"content":2695},{"target":2692},{"sys":2693},{"id":2694,"type":1451,"linkType":1452},"1VMpMgZvx9hgps2OoxCTmF",[],{"nodeType":1294,"data":2697,"content":2698},{},[2699],{"nodeType":1293,"value":37,"marks":2700,"data":2701},[],{},"Ghost logins: When forgotten identities come back to haunt you","How ghost logins can be used by cyber attackers for account takeover and persistence.","2024-07-10T00:00:00.000Z","ghost-logins-when-forgotten-identities-come-back-to-haunt-you",{"items":2707},[2708,2710],{"sys":2709,"name":1308},{"id":1307},{"sys":2711,"name":1312},{"id":1311},{"items":2713},[2714],{"fullName":1857,"firstName":1858,"jobTitle":1859,"profilePicture":2715},{"url":1861},{"__typename":1316,"sys":2717,"content":2719,"title":3036,"synopsis":3037,"hashTags":118,"publishedDate":3038,"slug":3039,"tagsCollection":3040,"authorsCollection":3046},{"id":2718},"4bYO5rVy9n2OO3vtMVQeda",{"json":2720},{"nodeType":1295,"data":2721,"content":2722},{},[2723,2730,2749,2765,2772,2779,2782,2789,2796,2849,2856,2862,2865,2872,2879,2886,2893,2900,2917,2923,2930,2937,2954,2960,2967,2974,2981,2988,2995,2998,3005,3024,3030],{"nodeType":1397,"data":2724,"content":2725},{},[2726],{"nodeType":1293,"value":2727,"marks":2728,"data":2729},"All phishing eventually leads to the browser",[],{},{"nodeType":1294,"data":2731,"content":2732},{},[2733,2737,2746],{"nodeType":1293,"value":2734,"marks":2735,"data":2736},"The best attack detection methods are those that focus on ",[],{},{"nodeType":1331,"data":2738,"content":2740},{"uri":2739},"https://pushsecurity.com/blog/our-design-philosophy-detecting-what-matters/",[2741],{"nodeType":1293,"value":2742,"marks":2743,"data":2745},"detecting indicators that are difficult for attackers to change or obfuscate",[2744],{"type":1339},{},{"nodeType":1293,"value":1589,"marks":2747,"data":2748},[],{},{"nodeType":1294,"data":2750,"content":2751},{},[2752,2756,2761],{"nodeType":1293,"value":2753,"marks":2754,"data":2755},"For a credential phishing attack to succeed, the victim ",[],{},{"nodeType":1293,"value":2757,"marks":2758,"data":2760},"has",[2759],{"type":1339},{},{"nodeType":1293,"value":2762,"marks":2763,"data":2764}," to enter their password into a webpage. There’s no two-ways about it, attackers cannot change this. ",[],{},{"nodeType":1294,"data":2766,"content":2767},{},[2768],{"nodeType":1293,"value":2769,"marks":2770,"data":2771},"So it stands to reason that, if you can detect this user behavior, and block them from entering their password, then you can stop phishing. ",[],{},{"nodeType":1294,"data":2773,"content":2774},{},[2775],{"nodeType":1293,"value":2776,"marks":2777,"data":2778},"This is exactly what Push does.",[],{},{"nodeType":1393,"data":2780,"content":2781},{},[],{"nodeType":1955,"data":2783,"content":2784},{},[2785],{"nodeType":1293,"value":2786,"marks":2787,"data":2788},"Most anti-phishing tools are easily bypassed",[],{},{"nodeType":1294,"data":2790,"content":2791},{},[2792],{"nodeType":1293,"value":2793,"marks":2794,"data":2795},"Other anti-phishing tools rely on detecting elements of the attack that attackers can change and hide, such as domains or the webpage contents. Attackers use tricks to evade these detection, like:",[],{},{"nodeType":1469,"data":2797,"content":2798},{},[2799,2809,2819,2829,2839],{"nodeType":1473,"data":2800,"content":2801},{},[2802],{"nodeType":1294,"data":2803,"content":2804},{},[2805],{"nodeType":1293,"value":2806,"marks":2807,"data":2808},"Using Cloudflare Workers to block automatic analysis of their phishing site",[],{},{"nodeType":1473,"data":2810,"content":2811},{},[2812],{"nodeType":1294,"data":2813,"content":2814},{},[2815],{"nodeType":1293,"value":2816,"marks":2817,"data":2818},"Hacking a Wordpress blog to get a reputable domain that passes domain checks ",[],{},{"nodeType":1473,"data":2820,"content":2821},{},[2822],{"nodeType":1294,"data":2823,"content":2824},{},[2825],{"nodeType":1293,"value":2826,"marks":2827,"data":2828},"Using redirects and rotating the URLs delivered to the victim to bypass link analysis",[],{},{"nodeType":1473,"data":2830,"content":2831},{},[2832],{"nodeType":1294,"data":2833,"content":2834},{},[2835],{"nodeType":1293,"value":2836,"marks":2837,"data":2838},"Randomizing the HTML title for the web page to bypass blocklists ",[],{},{"nodeType":1473,"data":2840,"content":2841},{},[2842],{"nodeType":1294,"data":2843,"content":2844},{},[2845],{"nodeType":1293,"value":2846,"marks":2847,"data":2848},"One-time phishing links that only work the first time they are clicked",[],{},{"nodeType":1294,"data":2850,"content":2851},{},[2852],{"nodeType":1293,"value":2853,"marks":2854,"data":2855},"Push is putting an end to this game of cat and mouse, by keeping it really simple; you can’t phish someone who can’t put their password into a phishing page. ",[],{},{"nodeType":1446,"data":2857,"content":2861},{"target":2858},{"sys":2859},{"id":2860,"type":1451,"linkType":1452},"6AwOZSpqaChmeksnj4SyWE",[],{"nodeType":1393,"data":2863,"content":2864},{},[],{"nodeType":1955,"data":2866,"content":2867},{},[2868],{"nodeType":1293,"value":2869,"marks":2870,"data":2871},"Domain-binding passwords",[],{},{"nodeType":1294,"data":2873,"content":2874},{},[2875],{"nodeType":1293,"value":2876,"marks":2877,"data":2878},"If you’re familiar with how passkeys are domain-bound, then think of what Push does as domain-binding passwords. We pin the password to its legitimate domain(s) and then don’t allow it to be entered into any webpage on any other domain. ",[],{},{"nodeType":1294,"data":2880,"content":2881},{},[2882],{"nodeType":1293,"value":2883,"marks":2884,"data":2885},"But just because you’ve stopped your users from being phished doesn’t mean you don’t want to know when attackers are attempting to phish your users and how. ",[],{},{"nodeType":1294,"data":2887,"content":2888},{},[2889],{"nodeType":1293,"value":2890,"marks":2891,"data":2892},"Push still inspects webpages to see if attackers are rendering cloned app login pages in the browser or if known AitM and BitM toolkits are being used. This way you don’t lose visibility of the unsuccessful attacks that are targeting your users. Think of it as a handy second and third layer of defense.",[],{},{"nodeType":1294,"data":2894,"content":2895},{},[2896],{"nodeType":1293,"value":2897,"marks":2898,"data":2899},"Lets run through a quick before and after example:",[],{},{"nodeType":1955,"data":2901,"content":2902},{},[2903,2907,2913],{"nodeType":1293,"value":2904,"marks":2905,"data":2906},"Scenario 1: An attacker attempts to phish an employee that ",[],{},{"nodeType":1293,"value":2908,"marks":2909,"data":2912},"doesn’t",[2910,2911],{"type":1339},{"type":1404},{},{"nodeType":1293,"value":2914,"marks":2915,"data":2916}," have Push deployed to their browser.",[],{},{"nodeType":1446,"data":2918,"content":2922},{"target":2919},{"sys":2920},{"id":2921,"type":1451,"linkType":1452},"2CbGMUSJsP1mNeHkmpLl6N",[],{"nodeType":1294,"data":2924,"content":2925},{},[2926],{"nodeType":1293,"value":2927,"marks":2928,"data":2929},"Here, an attacker hacks a Wordpress blog to get a reputable domain and then runs a phishing toolkit on the webpage. They email one of your employees a link to it. Your SWG / email scanning solution inspects it in a sandbox but the phish kit detects this and redirects to a benign site so that it passes the inspection. ",[],{},{"nodeType":1294,"data":2931,"content":2932},{},[2933],{"nodeType":1293,"value":2934,"marks":2935,"data":2936},"Your user gets the email with the link and is now free to interact with the phishing page. They enter their credentials plus MFA code into the page and voila! The attacker steals them and is able to compromise the user’s account.  ",[],{},{"nodeType":1955,"data":2938,"content":2939},{},[2940,2944,2950],{"nodeType":1293,"value":2941,"marks":2942,"data":2943},"Scenario 2: An attacker attempts to phish an employee that ",[],{},{"nodeType":1293,"value":2945,"marks":2946,"data":2949},"does",[2947,2948],{"type":1339},{"type":1404},{},{"nodeType":1293,"value":2951,"marks":2952,"data":2953}," have Push deployed to their browser. ",[],{},{"nodeType":1446,"data":2955,"content":2959},{"target":2956},{"sys":2957},{"id":2958,"type":1451,"linkType":1452},"77smnID1woCfFJrJPyTvKY",[],{"nodeType":1294,"data":2961,"content":2962},{},[2963],{"nodeType":1293,"value":2964,"marks":2965,"data":2966},"This time, the attacker uses the same phishing toolkit and domain from the first example. But in reality, they don’t have to send it to your employee using email, instead, they could use LinkedIn messenger, Slack, Teams, or any application that allows employees to communicate with each other. ",[],{},{"nodeType":1294,"data":2968,"content":2969},{},[2970],{"nodeType":1293,"value":2971,"marks":2972,"data":2973},"Like before, the user receives the link, opens it and starts to enter their credentials into the webpage. This time though, the Push browser extension inspects the webpage running in the user's browser. Push observes that the webpage is a login page and the user is entering their password into the page.",[],{},{"nodeType":1294,"data":2975,"content":2976},{},[2977],{"nodeType":1293,"value":2978,"marks":2979,"data":2980},"The first detection Push makes is checking that the password the user is entering matches the domain that password is pinned to. Since it doesn't match, based on this detection alone the user is automatically redirected to a blocking page. An important point to make here is that the password never leaves the user’s browser and the check is made using a shortened salted hash of the password.   ",[],{},{"nodeType":1294,"data":2982,"content":2983},{},[2984],{"nodeType":1293,"value":2985,"marks":2986,"data":2987},"The second detection Push makes is that the rendered web app is using a cloned app login page. The third detection is that a phishing toolkit is running in the web app code. ",[],{},{"nodeType":1294,"data":2989,"content":2990},{},[2991],{"nodeType":1293,"value":2992,"marks":2993,"data":2994},"In this particular scenario these second and third detections serve as useful context for understanding the nature of the phishing attack. But both will still redirect to a blocking page if they are triggered in isolation of the other phishing detections. ",[],{},{"nodeType":1393,"data":2996,"content":2997},{},[],{"nodeType":1397,"data":2999,"content":3000},{},[3001],{"nodeType":1293,"value":3002,"marks":3003,"data":3004},"We don’t just stop phishing attacks",[],{},{"nodeType":1294,"data":3006,"content":3007},{},[3008,3012,3021],{"nodeType":1293,"value":3009,"marks":3010,"data":3011},"We also detect other identity-related attack techniques used to compromise user accounts. That includes credential stuffing, password spraying and session hijacking using stolen session tokens. If you want to learn more about how Push helps you to detect and defeat common identity attack techniques, ",[],{},{"nodeType":1331,"data":3013,"content":3015},{"uri":3014},"https://pushsecurity.com/demo/",[3016],{"nodeType":1293,"value":3017,"marks":3018,"data":3020},"book some time with one of our team",[3019],{"type":1339},{},{"nodeType":1293,"value":2533,"marks":3022,"data":3023},[],{},{"nodeType":1446,"data":3025,"content":3029},{"target":3026},{"sys":3027},{"id":3028,"type":1451,"linkType":1452},"2JSmYDaiAciOx7Z1MRuJlA",[],{"nodeType":1294,"data":3031,"content":3032},{},[3033],{"nodeType":1293,"value":37,"marks":3034,"data":3035},[],{},"Detecting and blocking phishing attacks in the browser","How Push detects and blocks phishing attempts in the browser – explained in less than two minutes. ","2024-10-23T00:00:00.000Z","detecting-and-blocking-phishing-attacks-in-the-browser",{"items":3041},[3042,3044],{"sys":3043,"name":1308},{"id":1307},{"sys":3045,"name":1312},{"id":1311},{"items":3047},[3048],{"fullName":3049,"firstName":3050,"jobTitle":3051,"profilePicture":3052},"Alex Henshall","Alex","Product Team",{"url":3053},"https://images.ctfassets.net/y1cdw1ablpvd/2rz3Pre3b1MexPIQ4hzPUe/0ef8a092b7e7df00fbce3f7d1ccb96d1/Alex_Henshall.jpeg",{"items":3055},[3056],{"fullName":1857,"firstName":1858,"jobTitle":1859,"profilePicture":3057},{"url":1861},{"json":3059,"links":3957},{"nodeType":1295,"data":3060,"content":3061},{},[3062,3069,3076,3107,3114,3117,3124,3132,3152,3159,3166,3172,3179,3186,3209,3216,3223,3264,3271,3274,3281,3318,3324,3331,3338,3341,3349,3356,3389,3395,3402,3405,3413,3433,3440,3447,3467,3470,3478,3498,3505,3521,3537,3540,3548,3568,3575,3582,3675,3682,3688,3695,3702,3735,3742,3745,3753,3760,3767,3800,3807,3814,3817,3825,3844,3851,3858,3901,3907,3914,3933,3939,3945,3951],{"nodeType":1294,"data":3063,"content":3064},{},[3065],{"nodeType":1293,"value":3066,"marks":3067,"data":3068},"Two stories have hit the headlines in recent months involving attackers and researchers, demonstrating ways of taking over a SaaS account by accessing it using an SSO login from an IdP that you’ve never used before.",[],{},{"nodeType":1294,"data":3070,"content":3071},{},[3072],{"nodeType":1293,"value":3073,"marks":3074,"data":3075},"Yes, you read that right. An attacker created an IdP account on an IdP that you don’t use. And because the account matched your actual company domain, they used it to log into your actual downstream accounts on the apps that you use. ",[],{},{"nodeType":1294,"data":3077,"content":3078},{},[3079,3083,3091,3095,3103],{"nodeType":1293,"value":3080,"marks":3081,"data":3082},"We're calling this technique ",[],{},{"nodeType":1331,"data":3084,"content":3086},{"uri":3085},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/cross-idp_impersonation/description.md",[3087],{"nodeType":1293,"value":3088,"marks":3089,"data":3090},"cross-IdP impersonation",[],{},{"nodeType":1293,"value":3092,"marks":3093,"data":3094},". If you’re familiar with our other research, this is basically ",[],{},{"nodeType":1331,"data":3096,"content":3097},{"uri":1611},[3098],{"nodeType":1293,"value":3099,"marks":3100,"data":3102},"ghost logins",[3101],{"type":1339},{},{"nodeType":1293,"value":3104,"marks":3105,"data":3106}," on steroids — you’re effectively making your own! ",[],{},{"nodeType":1294,"data":3108,"content":3109},{},[3110],{"nodeType":1293,"value":3111,"marks":3112,"data":3113},"Let’s take a look at some examples.",[],{},{"nodeType":1393,"data":3115,"content":3116},{},[],{"nodeType":1397,"data":3118,"content":3119},{},[3120],{"nodeType":1293,"value":3121,"marks":3122,"data":3123},"Cross-IdP impersonation in the wild",[],{},{"nodeType":1955,"data":3125,"content":3126},{},[3127],{"nodeType":1293,"value":3128,"marks":3129,"data":3131},"Spoofing Zendesk support emails and infiltrating connected apps (via Apple SSO)",[3130],{"type":1404},{},{"nodeType":1294,"data":3133,"content":3134},{},[3135,3139,3148],{"nodeType":1293,"value":3136,"marks":3137,"data":3138},"A 15-year-old researcher was able to ",[],{},{"nodeType":1331,"data":3140,"content":3142},{"uri":3141},"https://gist.github.com/hackermondev/68ec8ed145fcee49d2f5e2b9d2cf2e52",[3143],{"nodeType":1293,"value":3144,"marks":3145,"data":3147},"access Zendesk support ticket history via spoofing a company’s support email, and later use it to access connected apps",[3146],{"type":1339},{},{"nodeType":1293,"value":3149,"marks":3150,"data":3151}," (Slack, in this case) via SSO, successfully targeting hundreds of companies.  ",[],{},{"nodeType":1294,"data":3153,"content":3154},{},[3155],{"nodeType":1293,"value":3156,"marks":3157,"data":3158},"The attack is based around the fact that Zendesk support tickets are easy to enumerate. The typical method of setting up Zendesk is to have your existing support email address (e.g. support@company.com) forward emails to Zendesk. ",[],{},{"nodeType":1294,"data":3160,"content":3161},{},[3162],{"nodeType":1293,"value":3163,"marks":3164,"data":3165},"The researcher was able to abuse this feature to create an account for an existing company domain on an IdP not currently being used by the company, and then use that account to authenticate to a third-party app used by the company. ",[],{},{"nodeType":1446,"data":3167,"content":3171},{"target":3168},{"sys":3169},{"id":3170,"type":1451,"linkType":1452},"3A6fHQ0XB2qAjQdJGvAb9N",[],{"nodeType":1294,"data":3173,"content":3174},{},[3175],{"nodeType":1293,"value":3176,"marks":3177,"data":3178},"The researcher found that, although Zendesk had started blocking emails from ‘noreply@’ addresses (probably to prevent this kind of attack), Apple sent its verification emails from an ‘appleid@’ address, making the attack possible when using Apple IdP.",[],{},{"nodeType":1294,"data":3180,"content":3181},{},[3182],{"nodeType":1293,"value":3183,"marks":3184,"data":3185},"There’s a couple of things to note here:",[],{},{"nodeType":1469,"data":3187,"content":3188},{},[3189,3199],{"nodeType":1473,"data":3190,"content":3191},{},[3192],{"nodeType":1294,"data":3193,"content":3194},{},[3195],{"nodeType":1293,"value":3196,"marks":3197,"data":3198},"Apple could be swapped out for any IdP that doesn’t send verification emails from a ‘noreply@’ address.",[],{},{"nodeType":1473,"data":3200,"content":3201},{},[3202],{"nodeType":1294,"data":3203,"content":3204},{},[3205],{"nodeType":1293,"value":3206,"marks":3207,"data":3208},"Slack could be swapped out for just about any downstream SaaS app. ",[],{},{"nodeType":1294,"data":3210,"content":3211},{},[3212],{"nodeType":1293,"value":3213,"marks":3214,"data":3215},"Taking a step back — what if an attacker had discovered this exploit? The researcher states that, after Zendesk refused to acknowledge the issue through its bug bounty program operated by HackerOne, he individually contacted ‘hundreds’ of affected organizations. ",[],{},{"nodeType":1294,"data":3217,"content":3218},{},[3219],{"nodeType":1293,"value":3220,"marks":3221,"data":3222},"So that’s hundreds of vulnerable organizations, and potentially tens to hundreds of business apps per victim organization that could be accessed via Apple SSO. Any app that allows ‘sign in with Apple’ could be targeted where:",[],{},{"nodeType":1469,"data":3224,"content":3225},{},[3226,3245],{"nodeType":1473,"data":3227,"content":3228},{},[3229],{"nodeType":1294,"data":3230,"content":3231},{},[3232,3236,3241],{"nodeType":1293,"value":3233,"marks":3234,"data":3235},"An app with an ",[],{},{"nodeType":1293,"value":3237,"marks":3238,"data":3240},"existing",[3239],{"type":1339},{},{"nodeType":1293,"value":3242,"marks":3243,"data":3244}," account belonging to the specific email & domain combination could be taken over.",[],{},{"nodeType":1473,"data":3246,"content":3247},{},[3248],{"nodeType":1294,"data":3249,"content":3250},{},[3251,3255,3260],{"nodeType":1293,"value":3252,"marks":3253,"data":3254},"A ",[],{},{"nodeType":1293,"value":3256,"marks":3257,"data":3259},"new",[3258],{"type":1339},{},{"nodeType":1293,"value":3261,"marks":3262,"data":3263}," account could also be created on apps allowing anyone with a company email to join the company tenant. ",[],{},{"nodeType":1294,"data":3265,"content":3266},{},[3267],{"nodeType":1293,"value":3268,"marks":3269,"data":3270},"It’s unclear whether Zendesk will have implemented a global fix for the issue either, as the vulnerability stems from a configuration option that could be remediated by disabling email collaboration, but is on by default. ",[],{},{"nodeType":1393,"data":3272,"content":3273},{},[],{"nodeType":1955,"data":3275,"content":3276},{},[3277],{"nodeType":1293,"value":3278,"marks":3279,"data":3280},"Google domain verification bug similarities",[],{},{"nodeType":1294,"data":3282,"content":3283},{},[3284,3288,3297,3301,3306,3310,3315],{"nodeType":1293,"value":3285,"marks":3286,"data":3287},"The Zendesk attack shares some similarities with ",[],{},{"nodeType":1331,"data":3289,"content":3291},{"uri":3290},"https://krebsonsecurity.com/2024/07/crooks-bypassed-googles-email-verification-to-create-workspace-accounts-access-3rd-party-services/",[3292],{"nodeType":1293,"value":3293,"marks":3294,"data":3296},"a recent (now resolved) Google email verification vulnerability",[3295],{"type":1339},{},{"nodeType":1293,"value":3298,"marks":3299,"data":3300}," which allowed a newly created Google account/domain to be used to authenticate to downstream apps via SSO — ",[],{},{"nodeType":1293,"value":3302,"marks":3303,"data":3305},"this time",[3304],{"type":1404},{},{"nodeType":1293,"value":3307,"marks":3308,"data":3309}," ",[],{},{"nodeType":1293,"value":3311,"marks":3312,"data":3314},"without verifying ownership of the domain",[3313],{"type":1404},{},{"nodeType":1293,"value":1589,"marks":3316,"data":3317},[],{},{"nodeType":1446,"data":3319,"content":3323},{"target":3320},{"sys":3321},{"id":3322,"type":1451,"linkType":1452},"6EeN0uKbhz9daUOo4E6wzR",[],{"nodeType":1294,"data":3325,"content":3326},{},[3327],{"nodeType":1293,"value":3328,"marks":3329,"data":3330},"Whereas the Zendesk attack took advantage of Apple email configs, this attack was much more direct in that Google enabled SSO to downstream apps prior to domain verification. ",[],{},{"nodeType":1294,"data":3332,"content":3333},{},[3334],{"nodeType":1293,"value":3335,"marks":3336,"data":3337},"The Google attack is definitely a bug rather than abusing a feature, and has since been patched. But, we’re starting to see a concerning pattern emerge. ",[],{},{"nodeType":1393,"data":3339,"content":3340},{},[],{"nodeType":1397,"data":3342,"content":3343},{},[3344],{"nodeType":1293,"value":3345,"marks":3346,"data":3348},"How big of a problem is this?",[3347],{"type":1404},{},{"nodeType":1294,"data":3350,"content":3351},{},[3352],{"nodeType":1293,"value":3353,"marks":3354,"data":3355},"First, let’s recap the general attack path:",[],{},{"nodeType":1469,"data":3357,"content":3358},{},[3359,3369,3379],{"nodeType":1473,"data":3360,"content":3361},{},[3362],{"nodeType":1294,"data":3363,"content":3364},{},[3365],{"nodeType":1293,"value":3366,"marks":3367,"data":3368},"The attacker signs up for an account on an app that functions as an IdP, linking it to the victim’s existing company email address via the ‘use existing email’ option.",[],{},{"nodeType":1473,"data":3370,"content":3371},{},[3372],{"nodeType":1294,"data":3373,"content":3374},{},[3375],{"nodeType":1293,"value":3376,"marks":3377,"data":3378},"The attacker either bypasses domain verification or verifies the domain via email (typically by clicking a link or entering a one-time password) either through an attack like the ones above, or by social engineering the victim user.",[],{},{"nodeType":1473,"data":3380,"content":3381},{},[3382],{"nodeType":1294,"data":3383,"content":3384},{},[3385],{"nodeType":1293,"value":3386,"marks":3387,"data":3388},"The attacker logs into an account on a downstream app using the ‘sign in with …’ SSO login option. ",[],{},{"nodeType":1446,"data":3390,"content":3394},{"target":3391},{"sys":3392},{"id":3393,"type":1451,"linkType":1452},"5lz0Nqq3j3Q1XasHYszRXy",[],{"nodeType":1294,"data":3396,"content":3397},{},[3398],{"nodeType":1293,"value":3399,"marks":3400,"data":3401},"Let’s look more closely at why this is a cause for concern.",[],{},{"nodeType":1393,"data":3403,"content":3404},{},[],{"nodeType":1955,"data":3406,"content":3407},{},[3408],{"nodeType":1293,"value":3409,"marks":3410,"data":3412},"It gets around your most hardened IdP accounts",[3411],{"type":1404},{},{"nodeType":1294,"data":3414,"content":3415},{},[3416,3420,3429],{"nodeType":1293,"value":3417,"marks":3418,"data":3419},"The notion of IdP impersonation isn’t necessarily new. Take for example ",[],{},{"nodeType":1331,"data":3421,"content":3423},{"uri":3422},"https://sec.okta.com/articles/2023/08/cross-tenant-impersonation-prevention-and-detection",[3424],{"nodeType":1293,"value":3425,"marks":3426,"data":3428},"cross-tenant impersonation",[3427],{"type":1339},{},{"nodeType":1293,"value":3430,"marks":3431,"data":3432},", which focuses on mapping an attacker-controlled Okta tenant to a compromised Okta tenant to give full access to connected user accounts and enable unrestricted lateral movement.",[],{},{"nodeType":1294,"data":3434,"content":3435},{},[3436],{"nodeType":1293,"value":3437,"marks":3438,"data":3439},"Cross-IdP impersonation, however, doesn’t require that you’ve already compromised an IdP admin account. You pick a user account (or multiple) that you want to take over, you enroll them with a new IdP matching the tenant and address structure, and then authenticate to whichever apps you’re interested in taking over. ",[],{},{"nodeType":1294,"data":3441,"content":3442},{},[3443],{"nodeType":1293,"value":3444,"marks":3445,"data":3446},"So, compromising your target’s main IdP isn’t necessary when the data and functionality that you’re most interested in lives in downstream apps. This means that even if your primary IdP is super locked down with phishing-resistant authentication (e.g. passkeys) this technique enables attackers to get around it. ",[],{},{"nodeType":1294,"data":3448,"content":3449},{},[3450,3454,3463],{"nodeType":1293,"value":3451,"marks":3452,"data":3453},"And a smart attacker who does their OSINT will identify potential app admins whose accounts to mirror, eliminating any noise that would be generated by privilege escalation & lateral movement attempts such as ",[],{},{"nodeType":1331,"data":3455,"content":3457},{"uri":3456},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/in-app_phishing/description.md",[3458],{"nodeType":1293,"value":3459,"marks":3460,"data":3462},"in-app phishing.",[3461],{"type":1339},{},{"nodeType":1293,"value":3464,"marks":3465,"data":3466}," ",[],{},{"nodeType":1393,"data":3468,"content":3469},{},[],{"nodeType":1955,"data":3471,"content":3472},{},[3473],{"nodeType":1293,"value":3474,"marks":3475,"data":3477},"App-based prevention measures are inconsistent",[3476],{"type":1404},{},{"nodeType":1294,"data":3479,"content":3480},{},[3481,3485,3494],{"nodeType":1293,"value":3482,"marks":3483,"data":3484},"It’s worth noting that this attack doesn’t work the same on all apps. At the point of using a new login method to access an app, ",[],{},{"nodeType":1331,"data":3486,"content":3488},{"uri":3487},"https://auth0.com/docs/manage-users/user-accounts/user-account-linking",[3489],{"nodeType":1293,"value":3490,"marks":3491,"data":3493},"it is considered best practice to require re-verification",[3492],{"type":1339},{},{"nodeType":1293,"value":3495,"marks":3496,"data":3497}," — for example by logging in with the original login method, or approving the request via an email code or link. ",[],{},{"nodeType":1294,"data":3499,"content":3500},{},[3501],{"nodeType":1293,"value":3502,"marks":3503,"data":3504},"Requiring re-authentication with the original login method is probably game over for the attacker, but if the attacker has already found a way of verifying a new IdP via email, the latter option is probably less of an obstacle. ",[],{},{"nodeType":1294,"data":3506,"content":3507},{},[3508,3512,3517],{"nodeType":1293,"value":3509,"marks":3510,"data":3511},"But not all apps follow these best practices around adding new login methods. We tested a range of the most popular apps that our customers use by creating an account, adding a password and an SSO method, and subsequently adding another SSO method using a different IdP, and ",[],{},{"nodeType":1293,"value":3513,"marks":3514,"data":3516},"found that 60% (3 in 5) of the apps we tested do not require re-verification by default",[3515],{"type":1404},{},{"nodeType":1293,"value":3518,"marks":3519,"data":3520}," when adding a new SSO login method.",[],{},{"nodeType":3522,"data":3523,"content":3524},"blockquote",{},[3525],{"nodeType":1294,"data":3526,"content":3527},{},[3528,3533],{"nodeType":1293,"value":3529,"marks":3530,"data":3532},"60% (3 in 5) of the apps we tested do not require re-verification by default",[3531],{"type":1404},{},{"nodeType":1293,"value":3534,"marks":3535,"data":3536}," when adding a new SSO login method",[],{},{"nodeType":1393,"data":3538,"content":3539},{},[],{"nodeType":1955,"data":3541,"content":3542},{},[3543],{"nodeType":1293,"value":3544,"marks":3545,"data":3547},"There are more IdPs than you realize",[3546],{"type":1404},{},{"nodeType":1294,"data":3549,"content":3550},{},[3551,3555,3564],{"nodeType":1293,"value":3552,"marks":3553,"data":3554},"IdP accounts have always been a valuable target. Earlier this year we saw ",[],{},{"nodeType":1331,"data":3556,"content":3558},{"uri":3557},"https://www.bleepingcomputer.com/news/security/okta-warns-of-unprecedented-credential-stuffing-attacks-on-customers/",[3559],{"nodeType":1293,"value":3560,"marks":3561,"data":3563},"a dramatic spike in the attacks on Okta accounts",[3562],{"type":1339},{},{"nodeType":1293,"value":3565,"marks":3566,"data":3567},", for example. But these accounts are often well protected with strong credentials (or passkeys) and MFA. ",[],{},{"nodeType":1294,"data":3569,"content":3570},{},[3571],{"nodeType":1293,"value":3572,"marks":3573,"data":3574},"In contrast, cross-IdP impersonation gives attackers a way of getting the benefit of an IdP compromise without needing to take over a locked down IdP account. ",[],{},{"nodeType":1294,"data":3576,"content":3577},{},[3578],{"nodeType":1293,"value":3579,"marks":3580,"data":3581},"Apps accept a wide variety of SSO login options. An app might support any combination of, for example:",[],{},{"nodeType":1469,"data":3583,"content":3584},{},[3585,3595,3605,3615,3625,3635,3645,3655,3665],{"nodeType":1473,"data":3586,"content":3587},{},[3588],{"nodeType":1294,"data":3589,"content":3590},{},[3591],{"nodeType":1293,"value":3592,"marks":3593,"data":3594},"Log in with Google",[],{},{"nodeType":1473,"data":3596,"content":3597},{},[3598],{"nodeType":1294,"data":3599,"content":3600},{},[3601],{"nodeType":1293,"value":3602,"marks":3603,"data":3604},"Log in with Facebook",[],{},{"nodeType":1473,"data":3606,"content":3607},{},[3608],{"nodeType":1294,"data":3609,"content":3610},{},[3611],{"nodeType":1293,"value":3612,"marks":3613,"data":3614},"Log in with Apple",[],{},{"nodeType":1473,"data":3616,"content":3617},{},[3618],{"nodeType":1294,"data":3619,"content":3620},{},[3621],{"nodeType":1293,"value":3622,"marks":3623,"data":3624},"Log in with X",[],{},{"nodeType":1473,"data":3626,"content":3627},{},[3628],{"nodeType":1294,"data":3629,"content":3630},{},[3631],{"nodeType":1293,"value":3632,"marks":3633,"data":3634},"Log in with Microsoft",[],{},{"nodeType":1473,"data":3636,"content":3637},{},[3638],{"nodeType":1294,"data":3639,"content":3640},{},[3641],{"nodeType":1293,"value":3642,"marks":3643,"data":3644},"Log in with GitHub",[],{},{"nodeType":1473,"data":3646,"content":3647},{},[3648],{"nodeType":1294,"data":3649,"content":3650},{},[3651],{"nodeType":1293,"value":3652,"marks":3653,"data":3654},"Log in with Okta ",[],{},{"nodeType":1473,"data":3656,"content":3657},{},[3658],{"nodeType":1294,"data":3659,"content":3660},{},[3661],{"nodeType":1293,"value":3662,"marks":3663,"data":3664},"Log in with SAML",[],{},{"nodeType":1473,"data":3666,"content":3667},{},[3668],{"nodeType":1294,"data":3669,"content":3670},{},[3671],{"nodeType":1293,"value":3672,"marks":3673,"data":3674},"Log in with SSO",[],{},{"nodeType":1294,"data":3676,"content":3677},{},[3678],{"nodeType":1293,"value":3679,"marks":3680,"data":3681},"And there are many, many IdPs — probably more than you realize — all of which could potentially be hijacked by an attacker to impersonate your organization.  ",[],{},{"nodeType":1446,"data":3683,"content":3687},{"target":3684},{"sys":3685},{"id":3686,"type":1451,"linkType":1452},"3EOOr4dVQoiPjl2ucUs1mA",[],{"nodeType":1294,"data":3689,"content":3690},{},[3691],{"nodeType":1293,"value":3692,"marks":3693,"data":3694},"But it’s not just about attackers creating new IdP accounts: What other IdPs might your users have inadvertently created? And are these accounts as securely configured as your primary company IdP (most commonly Okta, Microsoft Entra, or Google Workspace)?",[],{},{"nodeType":1294,"data":3696,"content":3697},{},[3698],{"nodeType":1293,"value":3699,"marks":3700,"data":3701},"In fact, there are a few different scenarios to be aware of here:",[],{},{"nodeType":1469,"data":3703,"content":3704},{},[3705,3715,3725],{"nodeType":1473,"data":3706,"content":3707},{},[3708],{"nodeType":1294,"data":3709,"content":3710},{},[3711],{"nodeType":1293,"value":3712,"marks":3713,"data":3714},"An attacker creates a new account on a previously unused IdP mapping to your company domain and email, and exploits a flaw to bypass domain verification.",[],{},{"nodeType":1473,"data":3716,"content":3717},{},[3718],{"nodeType":1294,"data":3719,"content":3720},{},[3721],{"nodeType":1293,"value":3722,"marks":3723,"data":3724},"An attacker creates a new account on a previously unused IdP mapping to your company domain and email, and social engineers the target user to convince them to complete the domain verification request. ",[],{},{"nodeType":1473,"data":3726,"content":3727},{},[3728],{"nodeType":1294,"data":3729,"content":3730},{},[3731],{"nodeType":1293,"value":3732,"marks":3733,"data":3734},"A legitimate user signs up for an account that functions as an IdP with their company email, using a weak password and no MFA. This account is later compromised by an attacker. ",[],{},{"nodeType":1294,"data":3736,"content":3737},{},[3738],{"nodeType":1293,"value":3739,"marks":3740,"data":3741},"In all of these cases, an attacker would be able to authenticate to downstream apps and take over user accounts. ",[],{},{"nodeType":1393,"data":3743,"content":3744},{},[],{"nodeType":1955,"data":3746,"content":3747},{},[3748],{"nodeType":1293,"value":3749,"marks":3750,"data":3752},"We’re only scratching the surface of what’s possible",[3751],{"type":1404},{},{"nodeType":1294,"data":3754,"content":3755},{},[3756],{"nodeType":1293,"value":3757,"marks":3758,"data":3759},"The Zendesk attack demonstrates a creative way of abusing an app’s functionality, combined with the way in which the Apple IdP is configured. ",[],{},{"nodeType":1294,"data":3761,"content":3762},{},[3763],{"nodeType":1293,"value":3764,"marks":3765,"data":3766},"It would be naive to suggest that similar issues don’t exist for other IdPs. Or that apps other than Zendesk don’t have features that can be exploited.",[],{},{"nodeType":1294,"data":3768,"content":3769},{},[3770,3774,3783,3787,3796],{"nodeType":1293,"value":3771,"marks":3772,"data":3773},"For example, we’ve previously documented ",[],{},{"nodeType":1331,"data":3775,"content":3777},{"uri":3776},"https://pushsecurity.com/blog/nearly-invisible-attack-chain/#id-an-example-attack-zapier",[3778],{"nodeType":1293,"value":3779,"marks":3780,"data":3782},"using Zapier to create malicious automated workflows",[3781],{"type":1339},{},{"nodeType":1293,"value":3784,"marks":3785,"data":3786}," to compromise integrated apps, or ",[],{},{"nodeType":1331,"data":3788,"content":3790},{"uri":3789},"https://pushsecurity.com/blog/oktajacking/",[3791],{"nodeType":1293,"value":3792,"marks":3793,"data":3795},"changing the SAML configuration of an app",[3794],{"type":1339},{},{"nodeType":1293,"value":3797,"marks":3798,"data":3799}," to direct logins to a malicious Okta tenant. ",[],{},{"nodeType":1294,"data":3801,"content":3802},{},[3803],{"nodeType":1293,"value":3804,"marks":3805,"data":3806},"Until now, there hasn’t been much research in this space. It’s not surprising when we consider that this kind of bug bounty isn’t paying out, and I know of only a handful of forward-thinking security consultancies conducting any real offensive security testing with their clients in this space. ",[],{},{"nodeType":1294,"data":3808,"content":3809},{},[3810],{"nodeType":1293,"value":3811,"marks":3812,"data":3813},"All organizations should be taking SaaS and identity attacks seriously — a good starting point would be to normalize SaaS and IdP configuration testing as part of routine security assessments, as well as demonstrating in-app post exploitation activity to raise awareness of how direct and dangerous these attacks can be. ",[],{},{"nodeType":1393,"data":3815,"content":3816},{},[],{"nodeType":1397,"data":3818,"content":3819},{},[3820],{"nodeType":1293,"value":3821,"marks":3822,"data":3824},"Expect more cross-IdP impersonation in future",[3823],{"type":1404},{},{"nodeType":1294,"data":3826,"content":3827},{},[3828,3832,3840],{"nodeType":1293,"value":3829,"marks":3830,"data":3831},"With the ",[],{},{"nodeType":1331,"data":3833,"content":3834},{"uri":1347},[3835],{"nodeType":1293,"value":3836,"marks":3837,"data":3839},"success of the attacks on Snowflake customers",[3838],{"type":1339},{},{"nodeType":1293,"value":3841,"marks":3842,"data":3843}," it feels like attackers and researchers are starting to take note, and the research scrutiny is amping up. It would be wise to expect more of these attacks in future. ",[],{},{"nodeType":1294,"data":3845,"content":3846},{},[3847],{"nodeType":1293,"value":3848,"marks":3849,"data":3850},"Cross-IdP impersonation could be largely prevented if all apps required re-verification upon adding a new login method by default (specifically, requiring that you log in with the original method, not approving via email link/code). This is yet another example of the inconsistencies in SaaS authentication introducing vulnerabilities. ",[],{},{"nodeType":1294,"data":3852,"content":3853},{},[3854],{"nodeType":1293,"value":3855,"marks":3856,"data":3857},"As this is unlikely to happen anytime soon, to mitigate the threat of cross-IdP impersonation we recommend that you:",[],{},{"nodeType":1469,"data":3859,"content":3860},{},[3861,3871,3881,3891],{"nodeType":1473,"data":3862,"content":3863},{},[3864],{"nodeType":1294,"data":3865,"content":3866},{},[3867],{"nodeType":1293,"value":3868,"marks":3869,"data":3870},"Set email alerts for employees receiving IdP activation emails to their corporate mailbox and forward to your SIEM. This will provide visibility both of unauthorized IdPs being connected to your domain by employees (which can lead to your corporate apps and accounts being compromised via less secure accounts, such as their Apple, LinkedIn, X, etc.), and of attackers attempting to register a new IdP as part of an attack. ",[],{},{"nodeType":1473,"data":3872,"content":3873},{},[3874],{"nodeType":1294,"data":3875,"content":3876},{},[3877],{"nodeType":1293,"value":3878,"marks":3879,"data":3880},"Warn users of the risks associated with creating new IdP accounts and connecting them to their primary corporate email (as well as the possibility of phishing scams designed to trick the user into completing the verification process or passing on a verification code). ",[],{},{"nodeType":1473,"data":3882,"content":3883},{},[3884],{"nodeType":1294,"data":3885,"content":3886},{},[3887],{"nodeType":1293,"value":3888,"marks":3889,"data":3890},"Where configurable, require downstream applications to enforce re-verification when adding new SSO methods. Requiring login with the original method, rather than email approval, is a more secure approach.",[],{},{"nodeType":1473,"data":3892,"content":3893},{},[3894],{"nodeType":1294,"data":3895,"content":3896},{},[3897],{"nodeType":1293,"value":3898,"marks":3899,"data":3900},"Where possible, prevent the conversion of personal accounts to corporate accounts within the main IdP providers. For example, Apple Business Manager recently released the ability to lock your domain and prevent new accounts being created, as well as locking the authentication to your preferred IdP (preventing local accounts from being created) — convenient timing!",[],{},{"nodeType":1446,"data":3902,"content":3906},{"target":3903},{"sys":3904},{"id":3905,"type":1451,"linkType":1452},"56sqxSy9QuTxzOGvUmcYBK",[],{"nodeType":1294,"data":3908,"content":3909},{},[3910],{"nodeType":1293,"value":3911,"marks":3912,"data":3913},"However, your ability to prevent attackers from creating new accounts on IdPs and connecting them to your domain is going to vary from IdP to IdP, so complete remediation may not be possible. And unless handled carefully, joining multiple IdPs to your primary IdP has the potential to increase your attack surface, not reduce it!",[],{},{"nodeType":1294,"data":3915,"content":3916},{},[3917,3921,3929],{"nodeType":1293,"value":3918,"marks":3919,"data":3920},"If you want a bit more technical detail on how this technique can be combined with verification phishing to reliably create new IdP accounts, ",[],{},{"nodeType":1331,"data":3922,"content":3924},{"uri":3923},"https://pushsecurity.com/blog/a-new-class-of-phishing-verification-phishing-and-cross-idp-impersonation/",[3925],{"nodeType":1293,"value":3926,"marks":3927,"data":3928},"check out this blog post.",[],{},{"nodeType":1293,"value":3930,"marks":3931,"data":3932}," Here's a quick demo of the attack chain to whet your appetite... ",[],{},{"nodeType":1446,"data":3934,"content":3938},{"target":3935},{"sys":3936},{"id":3937,"type":1451,"linkType":1452},"1rfmqEdOlYeWCkpQE0c0IE",[],{"nodeType":1294,"data":3940,"content":3941},{},[3942],{"nodeType":1293,"value":37,"marks":3943,"data":3944},[],{},{"nodeType":1446,"data":3946,"content":3950},{"target":3947},{"sys":3948},{"id":3949,"type":1451,"linkType":1452},"3MGuq0h7IfW7F2ueNbc5v4",[],{"nodeType":1294,"data":3952,"content":3953},{},[3954],{"nodeType":1293,"value":37,"marks":3955,"data":3956},[],{},{"entries":3958},{"hyperlink":3959,"inline":3960,"block":3961},[],[],[3962,3970,3975,3979,3987,3994,4003],{"sys":3963,"__typename":3964,"title":3965,"caption":3965,"layoutMode":118,"file":3966},{"id":3170},"Image","Zendesk to Slack attack path (via Apple SSO)",{"url":3967,"width":3968,"height":3969},"https://images.ctfassets.net/y1cdw1ablpvd/4i4h3IKgVEPtLH5Egs8qND/4b0c1c8dea8b4c0a8721cfceb51b925d/image5.png",1535,690,{"sys":3971,"__typename":3964,"title":3972,"caption":3972,"layoutMode":118,"file":3973},{"id":3322},"Google domain verification bypass",{"url":3974,"width":3968,"height":3969},"https://images.ctfassets.net/y1cdw1ablpvd/7EbqwEZZ6Z0J4bSmwAavvI/becb2d959771dfe75f86807779a1a933/image4.png",{"sys":3976,"__typename":3964,"title":3977,"caption":3977,"layoutMode":118,"file":3978},{"id":3393},"Generic cross-IdP impersonation attack path",{"url":1302,"width":3968,"height":3969},{"sys":3980,"__typename":3964,"title":3981,"caption":3982,"layoutMode":118,"file":3983},{"id":3686},"Managed vs. unmanaged IdPs","Managed IdPs can be administered centrally by the organization (which owns and operates the IdP and the identities on it), whereas unmanaged ‘social’ IdPs are controlled by the vendor, and identities are owned and administered by the user.",{"url":3984,"width":3985,"height":3986},"https://images.ctfassets.net/y1cdw1ablpvd/6qDjvYcLbUxlC4w24VvDLO/4da66c4e755c9b1c00b285a5ab3f9c57/image1.png",1500,1000,{"sys":3988,"__typename":3964,"title":3989,"caption":3989,"layoutMode":118,"file":3990},{"id":3905},"Apple business manager update providing more options to manage verified domains",{"url":3991,"width":3992,"height":3993},"https://images.ctfassets.net/y1cdw1ablpvd/3NH2d6WMqAmPfrPMQas4e0/35676fdc69d7e91c3c1dd163fe3ff51d/image2.png",1394,942,{"sys":3995,"__typename":3996,"title":3997,"youTubeUrl":3998,"imagePlaceholder":3999},{"id":3937},"ExternalVideo","Verification Phishing & Cross-IdP Impersonation Demo","https://www.youtube.com/watch?v=53JMEmZV6ck",{"url":4000,"width":4001,"height":4002},"https://images.ctfassets.net/y1cdw1ablpvd/KXQAXbpFMRJprAkzoKhtx/ac370fb92687122022e753120bb7cb47/Slide_Front_Cover__20_.png",1920,1080,{"sys":4004,"__typename":4005,"type":4006,"ctaText":4007,"buttonLabel":4008,"buttonColour":4009,"buttonUrl":3923},{"id":3949},"CtaWidget","Custom","Learn how cross-IdP impersonation can be combined with verification phishing to bypass locked-down IdP accounts by phishing a single OTP","Read Blog","sunny orange","content:blog:cross-idp-impersonation.json","json","content","blog/cross-idp-impersonation.json","blog/cross-idp-impersonation",1776359986967]