[{"data":1,"prerenderedAt":4056},["ShallowReactive",2],{"application-flags":3,"navbar":7,"always-visible-banner":95,"navbar-about-highlight":155,"navbar-resource-highlight":211,"use-case-page":256,"blog/how-consent-phishing-is-evolving":1276},[4],{"name":5,"enabled":6},"maintenanceMode",false,[8,59,76],{"createdDate":9,"id":10,"name":11,"modelId":12,"published":13,"stageModifiedSincePublish":6,"query":14,"data":15,"variations":50,"lastUpdated":51,"firstPublished":52,"testRatio":33,"createdBy":53,"lastUpdatedBy":53,"folders":54,"meta":55,"rev":58},1742213002749,"efff2a27faf4408e9f908eba4b5542fe","inductive-automation","1c6207a5f24948ab82d4a0b17f251193","published",[],{"testimonial":16,"description":43,"type":19,"link":44,"title":47,"testimonialLink":48,"image":49},{"@type":17,"id":18,"model":19,"value":20},"@builder.io/core:Reference","f028f2b685bb47cd8bf9e82a26dd5a79","testimonial",{"query":21,"folders":22,"createdDate":23,"id":18,"name":24,"modelId":25,"published":13,"data":26,"variations":30,"lastUpdated":31,"firstPublished":32,"testRatio":33,"createdBy":34,"lastUpdatedBy":34,"meta":35,"rev":42},[],[],1735823466309,"We found Push to be more accurate when compared to competitors and the browser agent offered features that others couldn’t match.","42035571a56940ac98bff4544aa79aa5",{"author":27,"jobTitle":28,"quote":24,"image":29},"Jason Waits","\u003Cp>CISO at Inductive Automation\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Ff04c0c0689ce4a89ac0f0708d78c0a07",{},1735910703862,1735823501152,1,"ST0tXQM8slWpFrmioqKHmENB2qe2",{"kind":36,"lastPreviewUrl":37,"breakpoints":38,"hasAutosaves":41},"data","",{"small":39,"medium":40},640,768,true,"3v32gocrrqz","Join the industry's top security minds as they break down the browser attack landscape.",{"url":45,"text":46},"https://pushsecurity.com/webinar/state-of-browser-security","Save Your Spot","State of Browser Attacks Series","/customer-stories/inductive-automation","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fe94fca10aa7b46ac8052b7ea22de54cd",{},1776257019270,1742221533648,"CydmZnOWU1XuAaLhEDCoYNM4Z8W2",[],{"breakpoints":56,"kind":36,"lastPreviewUrl":37,"hasAutosaves":6},{"xsmall":57,"small":39,"medium":40},320,"motto9r9yg",{"createdDate":60,"id":61,"name":62,"modelId":12,"published":13,"query":63,"data":64,"variations":69,"lastUpdated":70,"firstPublished":71,"testRatio":33,"createdBy":53,"lastUpdatedBy":72,"folders":73,"meta":74,"rev":58},1742208588866,"1c7a4e423bf54ac1a328bb4063459ef2","Banner",[],{"type":65,"url":66,"text":67,"link":68},"web-banner","https://pushsecurity.com/resources/browser-attacks-report","Get our latest report analyzing browser attack techniques in 2026",{},{},1774258294825,1742208637545,"jKjF9r5jcvXU8tzZEfFQm31Iyvr2",[],{"kind":36,"lastPreviewUrl":37,"breakpoints":75,"hasAutosaves":41},{"xsmall":57,"small":39,"medium":40},{"createdDate":77,"id":78,"name":79,"modelId":12,"published":13,"stageModifiedSincePublish":6,"query":80,"data":81,"variations":89,"lastUpdated":90,"firstPublished":91,"testRatio":33,"createdBy":53,"lastUpdatedBy":53,"folders":92,"meta":93,"rev":58},1742208469288,"6763051b201f44a0838c6400c580ca67","Resource highlight",[],{"image":82,"type":83,"description":84,"link":85,"title":88},"https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F7b4a5ebf81d64e8c9d7fc35f6c96c4a9","resource","Learn about the latest techniques being used in the wild.",{"url":86,"text":87},"/resources/browser-attacks-report","Download now","Report: 2026 Browser Attack Techniques",{},1776255866789,1742208570400,[],{"kind":36,"lastPreviewUrl":37,"breakpoints":94,"hasAutosaves":6},{"xsmall":57,"small":39,"medium":40},{"createdDate":96,"id":97,"name":98,"modelId":99,"published":13,"query":100,"data":101,"variations":145,"lastUpdated":146,"firstPublished":147,"testRatio":33,"createdBy":34,"lastUpdatedBy":148,"folders":149,"meta":150,"rev":154},1774965361051,"fd266d0172cc47429be7ad10f48c99ad","always visible banner","0678d178ec8b41efb8a23c09dba7874d",[],{"ctaText":102,"text":103,"url":37,"blocks":104,"state":141},"ewrererw","testrfesssssssssss",[105,129],{"@type":106,"@version":107,"id":108,"component":109,"responsiveStyles":119},"@builder.io/sdk:Element",2,"builder-ca12c06a52de41d7b8743da53118cd38",{"name":110,"tag":110,"options":111,"isRSC":118},"TopBannerContent",{"text":112,"ctaText":46,"url":45,"mainText":113,"cta":116},"New Webinar Series: Join John Hammond, Troy Hunt, and Matt Johansen for the State of Browser Attacks",{"content":114,"fontSize":115},"\u003Cp>New Webinar Series: Join John Hammond, Troy Hunt, and Matt Johansen for the State of Browser Attacks\u003C/p>","text-base",{"content":117,"fontSize":115,"url":45},"\u003Cp>\u003Cstrong style=\"font-weight:700;\">Save Your Spot\u003C/strong>\u003C/p>\n",null,{"large":120},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"marginTop":126,"marginBottom":126,"fontSize":127,"fontWeight":128},"flex","column","relative","0","border-box",".56rem","1.125rem","700",{"id":130,"@type":106,"tagName":131,"properties":132,"responsiveStyles":136},"builder-pixel-08zrjigffq5t","img",{"src":133,"aria-hidden":134,"alt":37,"role":135,"width":124,"height":124},"https://cdn.builder.io/api/v1/pixel?apiKey=f3a1111ff5be48cdbb123cd9f5795a05","true","presentation",{"large":137},{"height":124,"width":124,"display":138,"opacity":124,"overflow":139,"pointerEvents":140},"block","hidden","none",{"deviceSize":142,"location":143},"large",{"path":37,"query":144},{},{},1775137295127,1774968080803,"ax7YYfD0OCeqT1Vxxv1G4FUbqVr1",[],{"breakpoints":151,"hasLinks":6,"kind":152,"lastPreviewUrl":153,"hasAutosaves":6},{"xsmall":57,"small":39,"medium":40},"component","https://pushsecurity.com/?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditCode%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CeditProjects%2CmodifyMcpServers%2CmodifyWorkflowIntegrations%2CmodifyProjectSettings%2CconnectCodeRepository%2CcreateProjects%2CindexDesignSystems%2CsendPullRequests%2CmergePullRequests&builder.user.role.name=Developer&builder.user.role.id=developer&builder.cachebust=true&builder.preview=always-visible-banner&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.always-visible-banner=fd266d0172cc47429be7ad10f48c99ad&builder.overrides.fd266d0172cc47429be7ad10f48c99ad=fd266d0172cc47429be7ad10f48c99ad&builder.options.locale=Default","2lvuonnywj",[156,180],{"createdDate":157,"id":158,"name":159,"modelId":160,"published":13,"stageModifiedSincePublish":6,"query":161,"data":162,"variations":173,"lastUpdated":174,"firstPublished":175,"testRatio":33,"createdBy":53,"lastUpdatedBy":53,"folders":176,"meta":177,"rev":179},1776247359804,"9136a8f18b3b4a6ba29b8653a99372b1","testimonial-inductive-automation","20d9eaa352304613b3d1a794b400703d",[],{"link":163,"type":19,"testimonialLink":48,"testimonial":164},{},{"@type":17,"id":18,"model":19,"value":165},{"query":166,"folders":167,"createdDate":23,"id":18,"name":24,"modelId":25,"published":13,"data":168,"variations":169,"lastUpdated":31,"firstPublished":32,"testRatio":33,"createdBy":34,"lastUpdatedBy":34,"meta":170,"rev":172},[],[],{"author":27,"jobTitle":28,"quote":24,"image":29},{},{"kind":36,"lastPreviewUrl":37,"breakpoints":171,"hasAutosaves":41},{"small":39,"medium":40},"7t755zfvte3",{},1776247404986,1776247404973,[],{"breakpoints":178,"kind":36,"lastPreviewUrl":37,"hasAutosaves":6},{"xsmall":57,"small":39,"medium":40},"4moh0qpywtr",{"createdDate":181,"id":182,"name":88,"modelId":160,"published":13,"meta":183,"stageModifiedSincePublish":6,"query":185,"data":186,"variations":207,"lastUpdated":208,"firstPublished":209,"testRatio":33,"createdBy":53,"lastUpdatedBy":53,"folders":210,"rev":179},1776255761419,"05a9322735fc427db12e2740e4302300",{"breakpoints":184,"kind":36,"lastPreviewUrl":37,"hasAutosaves":6},{"xsmall":57,"small":39,"medium":40},[],{"testimonial":187,"link":206,"type":83,"title":88,"description":84,"image":82},{"@type":17,"id":188,"model":19,"value":189},"192acbb1f9ca4cac918c0ec435a8bae3",{"query":190,"folders":191,"createdDate":192,"id":188,"name":193,"modelId":25,"published":13,"data":194,"variations":200,"lastUpdated":201,"firstPublished":202,"testRatio":33,"createdBy":34,"lastUpdatedBy":53,"meta":203,"rev":205},[],[],1728981467463,"Push does for identity what CrowdStrike did for the endpoint",{"video":195,"jobTitle":196,"author":197,"qoute":37,"quote":198,"image":199},"https://cdn.builder.io/o/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F8b30e8ca50064058bbaef0f3c6164575%2Fcompressed?apiKey=f3a1111ff5be48cdbb123cd9f5795a05&token=8b30e8ca50064058bbaef0f3c6164575&alt=media&optimized=true","\u003Cp>Deputy CISO at Microsoft\u003C/p>\u003Cp>Former LinkedIn, Slack, Palantir\u003C/p>","Geoff Belknap","Push does for identity what CrowdStrike did for the endpoint.","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F748f0ad0a5064a00a13f4721fcc8dea1",{},1742902158597,1728981782923,{"kind":36,"lastPreviewUrl":37,"breakpoints":204,"hasAutosaves":41},{"small":39,"medium":40},"6s8ic0w0ao6",{"text":87,"url":86},{},1776255810913,1776255810900,[],[212,235],{"createdDate":213,"id":214,"name":88,"modelId":215,"published":13,"meta":216,"stageModifiedSincePublish":6,"query":218,"data":219,"variations":230,"lastUpdated":231,"firstPublished":232,"testRatio":33,"createdBy":53,"lastUpdatedBy":53,"folders":233,"rev":234},1776256900280,"1f429607996e4e5fae8fe3f9b9610e55","4829faa81e7c4ee8bd2d000e160e8d3c",{"breakpoints":217,"kind":36,"lastPreviewUrl":37,"hasAutosaves":6},{"xsmall":57,"small":39,"medium":40},[],{"testimonial":220,"link":229,"type":83,"title":88,"description":84,"image":82},{"@type":17,"id":188,"model":19,"value":221},{"query":222,"folders":223,"createdDate":192,"id":188,"name":193,"modelId":25,"published":13,"data":224,"variations":225,"lastUpdated":201,"firstPublished":202,"testRatio":33,"createdBy":34,"lastUpdatedBy":53,"meta":226,"rev":228},[],[],{"video":195,"jobTitle":196,"author":197,"qoute":37,"quote":198,"image":199},{},{"kind":36,"lastPreviewUrl":37,"breakpoints":227,"hasAutosaves":41},{"small":39,"medium":40},"r77qqueuo3j",{"text":87,"url":86},{},1776256937553,1776256937540,[],"q0jkez80wkg",{"createdDate":236,"id":237,"name":11,"modelId":215,"published":13,"stageModifiedSincePublish":6,"query":238,"data":239,"variations":250,"lastUpdated":251,"firstPublished":252,"testRatio":33,"createdBy":53,"lastUpdatedBy":53,"folders":253,"meta":254,"rev":234},1776256949234,"ce043785b71b4ece98eac811ecf4ba10",[],{"link":240,"type":19,"testimonial":241,"testimonialLink":48},{},{"@type":17,"id":18,"model":19,"value":242},{"query":243,"folders":244,"createdDate":23,"id":18,"name":24,"modelId":25,"published":13,"data":245,"variations":246,"lastUpdated":31,"firstPublished":32,"testRatio":33,"createdBy":34,"lastUpdatedBy":34,"meta":247,"rev":249},[],[],{"author":27,"jobTitle":28,"quote":24,"image":29},{},{"kind":36,"lastPreviewUrl":37,"breakpoints":248,"hasAutosaves":41},{"small":39,"medium":40},"mnaneamy308",{},1776256974140,1776256974130,[],{"breakpoints":255,"kind":36,"lastPreviewUrl":37,"hasAutosaves":6},{"xsmall":57,"small":39,"medium":40},[257,441,560,679,797,917,1037,1157],{"createdDate":258,"id":259,"name":260,"modelId":261,"published":13,"stageModifiedSincePublish":6,"query":262,"data":268,"variations":429,"lastUpdated":430,"firstPublished":431,"testRatio":33,"screenshot":432,"createdBy":34,"lastUpdatedBy":433,"folders":434,"meta":435,"rev":440},1744829487099,"387451215c314dd5bd654668cdc1a197","Zero-day phishing","cca4143377554c5a9163cc203a8ed2ba",[263],{"@type":264,"property":265,"operator":266,"value":267},"@builder.io/core:Query","urlPath","is","/uc/zero-day-phishing-protection",{"inputs":269,"customFonts":270,"seoTitle":318,"title":318,"tsCode":37,"seoDescription":319,"fontAwesomeIcon":320,"jsCode":37,"blocks":321,"url":267,"state":426},[],[271],{"family":272,"kind":273,"version":274,"lastModified":275,"files":276,"category":295,"menu":296,"subsets":297,"variants":300},"DM Sans","webfonts#webfont","v14","2023-07-13",{"100":277,"200":278,"300":279,"500":280,"600":281,"700":282,"800":283,"900":284,"800italic":285,"900italic":286,"700italic":287,"100italic":288,"italic":289,"regular":290,"200italic":291,"500italic":292,"300italic":293,"600italic":294},"https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwAop1hTmf3ZGMZpg.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwAIpxhTmf3ZGMZpg.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwA_JxhTmf3ZGMZpg.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwAkJxhTmf3ZGMZpg.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwAfJthTmf3ZGMZpg.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwARZthTmf3ZGMZpg.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwAIpthTmf3ZGMZpg.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwAC5thTmf3ZGMZpg.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2rp2ywxg089UriCZaSExd86J3t9jz86Mvy4qCRAL19DksVat8JCm3zRmYJpso5.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2rp2ywxg089UriCZaSExd86J3t9jz86Mvy4qCRAL19DksVat8gCm3zRmYJpso5.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2rp2ywxg089UriCZaSExd86J3t9jz86Mvy4qCRAL19DksVat9uCm3zRmYJpso5.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2rp2ywxg089UriCZaSExd86J3t9jz86Mvy4qCRAL19DksVat-JDG3zRmYJpso5.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2rp2ywxg089UriCZaSExd86J3t9jz86Mvy4qCRAL19DksVat-JDW3zRmYJpso5.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwAopxhTmf3ZGMZpg.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2rp2ywxg089UriCZaSExd86J3t9jz86Mvy4qCRAL19DksVat8JDW3zRmYJpso5.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2rp2ywxg089UriCZaSExd86J3t9jz86Mvy4qCRAL19DksVat-7DW3zRmYJpso5.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2rp2ywxg089UriCZaSExd86J3t9jz86Mvy4qCRAL19DksVat_XDW3zRmYJpso5.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2rp2ywxg089UriCZaSExd86J3t9jz86Mvy4qCRAL19DksVat9XCm3zRmYJpso5.ttf","sans-serif","https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwAopxRT23z.ttf",[298,299],"latin","latin-ext",[301,302,303,304,305,306,128,307,308,309,310,311,312,313,314,315,316,317],"100","200","300","regular","500","600","800","900","100italic","200italic","300italic","italic","500italic","600italic","700italic","800italic","900italic","Zero-day phishing protection","Detect phishing TTPs directly in the browser and stop credential theft.","faFishingRod",[322,421],{"@type":106,"@version":107,"tagName":323,"id":324,"children":325},"div","builder-76c6b8d1499346c7bc1fd56ae4e93638",[326,343,351,358,370,385,396,407,413],{"@type":106,"@version":107,"layerName":327,"id":328,"component":329,"responsiveStyles":340},"UseCaseHero","builder-5228fe062bef4a40a91e43f1112832fa",{"name":327,"options":330,"isRSC":118},{"title":318,"description":331,"points":332,"video":339},"\u003Cp>Push detects phishing as it happens. Autonomous agents hunt for new phishing techniques, identify kit signatures, and deploy detections within minutes of a new attack being analyzed. From cloned login pages to AiTM credential harvesting, Push sees what traditional filters miss and stops threats before they escalate.\u003C/p>",[333,335,337],{"item":334},"Detect phishing that bypasses traditional filters, including AiTM, SSO password theft, and fake login pages",{"item":336},"Stop never-before-seen attacks with AI-native behavioral and on-page analysis inside the browser",{"item":338},"Investigate faster with unified browser, user, and page context","https://cdn.builder.io/o/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F40433ceeb4f94b43a82e039a0f4fd411%2Fcompressed?apiKey=f3a1111ff5be48cdbb123cd9f5795a05&token=40433ceeb4f94b43a82e039a0f4fd411&alt=media&optimized=true",{"large":341},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":342},"transparent",{"@type":106,"@version":107,"id":344,"component":345,"responsiveStyles":348},"builder-96634044407e491299e291ed64669e39",{"name":346,"options":347,"isRSC":118},"TrustedBy",{"AllPartners":41,"backgroundTransparent":6},{"large":349},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":350},"#000",{"@type":106,"@version":107,"id":352,"component":353,"responsiveStyles":356},"builder-2c3768f930534557bb8978e32b6a6a0f",{"name":354,"options":355,"isRSC":118},"Diagonal",{"darkMode":41},{"large":357},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"layerName":359,"id":360,"component":361,"responsiveStyles":368},"TextImageBlockVertical","builder-7c3c1c2840424db2ad2ccbfaf382dd64",{"name":359,"tag":359,"options":362,"isRSC":118},{"darkMode":6,"maxWidth":363,"maxTextWidth":364,"title":365,"description":366,"animatedTitle":37,"image":367,"reverse":6,"descriptionPaddingHorizontal":118},1200,800,"\u003Ch2>Why stop at the inbox?\u003C/h2>","\u003Cp>Phishing attacks have evolved. Whether attackers lure users with QR codes, instant messages, or OAuth consent screens, the outcome is the same: it plays out in the browser. Push gives you real-time detection for in-browser threats, stopping phishing and consent-based attacks before they lead to compromise\u003C/p>\u003Cp>\u003Cbr>\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F7fdcac241f0e4a049166d7076858adeb",{"large":369},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":371,"component":372,"responsiveStyles":380},"builder-41c978b3669749cf947e622b4e79e4d7",{"name":373,"options":374,"isRSC":118},"TextImageBlockHorizontal",{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":376,"title":377,"description":378,"reverse":41,"image":379},600,100,"\u003Cp>Detect phishing at the edge\u003C/p>","\u003Cp>Push uses industry-first telemetry to detect phishing based on behavior, not static indicators. Autonomous agents analyze how phishing pages behave and how users interact with them, uncovering fake logins, credential theft, and phishing kits the moment they load in the browser.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F9df3d180c97b4e61af142af2ccd68721",{"large":381},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"fontFamily":382,"paddingTop":383,"marginTop":384},"DM Sans, sans-serif","20px","0px",{"@type":106,"@version":107,"id":386,"component":387,"responsiveStyles":393},"builder-d2a7bc941feb43cdb898bc116b203cf9",{"name":373,"options":388,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":389,"title":390,"description":391,"reverse":6,"image":392},120,"\u003Ch2>Go beyond blocklists and IOCs\u003C/h2>","\u003Cp>Push goes beyond URLs and easy-to-change indicators. It reads the full phishing playbook like script behavior, session hijacks, DOM changes, user inputs, then connects the dots in real time. This gives your team a complete picture of how the phishing attempt worked, not just an alert.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fabfd58db169b433e96d3f1261797156e",{"large":394},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":395},"36px",{"@type":106,"@version":107,"layerName":373,"id":397,"component":398,"responsiveStyles":404},"builder-42c32198083f4880acb37c5cb76934da",{"name":373,"options":399,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":400,"title":401,"description":402,"reverse":41,"image":403},140,"\u003Ch2>Enhance your phishing response\u003C/h2>","\u003Cp>When phishing enters your environment, speed matters. Push gives you instant access to the telemetry that counts like session data, user behavior, and page activity, so you can investigate fast, trigger in-browser prompts, or forward alerts to your SIEM or SOAR for response. All in real time, right from the browser.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fbb195aec46904056b85e8688629e558e",{"large":405},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":406},"47px",{"@type":106,"@version":107,"id":408,"component":409,"responsiveStyles":411},"builder-9a95b9cbc4854421a92ef7b90f6c7adb",{"name":354,"options":410,"isRSC":118},{"darkMode":6},{"large":412},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":414,"component":415,"responsiveStyles":419},"builder-0afa17a9f25c4661a90f314d5578aa18",{"name":416,"tag":416,"options":417,"isRSC":118},"LatestResources",{"sectionHeading":37,"customClass":418},"bg-black",{"large":420},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"id":422,"@type":106,"tagName":131,"properties":423,"responsiveStyles":424},"builder-pixel-21yj6h3p4wh",{"src":133,"aria-hidden":134,"alt":37,"role":135,"width":124,"height":124},{"large":425},{"height":124,"width":124,"display":138,"opacity":124,"overflow":139,"pointerEvents":140},{"deviceSize":142,"location":427},{"path":37,"query":428},{},{},1776275046831,1745499158657,"https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fff60c30a8442489c8ed7e0af9599d14f","kYgMv6WsbvfmlOUYqR2SFwGzw6e2",[],{"lastPreviewUrl":436,"winningTest":118,"breakpoints":437,"kind":438,"hasLinks":6,"originalContentId":439,"hasAutosaves":6},"https://pushsecurity.com/uc/zero-day-phishing-protection?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CcreateProjects%2CsendPullRequests&builder.user.role.name=Designer&builder.user.role.id=creator&builder.cachebust=true&builder.preview=use-case-page&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.use-case-page=387451215c314dd5bd654668cdc1a197&builder.overrides.387451215c314dd5bd654668cdc1a197=387451215c314dd5bd654668cdc1a197&builder.overrides.use-case-page:/uc/zero-day-phishing-protection=387451215c314dd5bd654668cdc1a197&builder.options.locale=Default",{"xsmall":57,"small":39,"medium":40},"page","2daa5670b8504fc7ba4700633e8bd921","atvz4dp24b7",{"createdDate":442,"id":443,"name":444,"modelId":261,"published":13,"stageModifiedSincePublish":6,"query":445,"data":448,"variations":552,"lastUpdated":553,"firstPublished":554,"testRatio":33,"screenshot":555,"createdBy":34,"lastUpdatedBy":433,"folders":556,"meta":557,"rev":440},1756833377777,"54f8256648f54d439303734b1e69221b","Browser extension security",[446],{"@type":264,"property":265,"operator":266,"value":447},"/uc/browser-extension-security",{"seoDescription":449,"jsCode":37,"fontAwesomeIcon":450,"tsCode":37,"title":444,"seoTitle":444,"customFonts":451,"inputs":456,"blocks":457,"url":447,"state":549},"Shine a light on risky browser extensions.","faPuzzlePiece",[452],{"kind":273,"family":272,"version":274,"files":453,"category":295,"lastModified":275,"subsets":454,"variants":455,"menu":296},{"100":277,"200":278,"300":279,"500":280,"600":281,"700":282,"800":283,"900":284,"100italic":288,"italic":289,"regular":290,"900italic":286,"800italic":285,"700italic":287,"200italic":291,"300italic":293,"500italic":292,"600italic":294},[298,299],[301,302,303,304,305,306,128,307,308,309,310,311,312,313,314,315,316,317],[],[458,544],{"@type":106,"@version":107,"tagName":323,"id":459,"meta":460,"children":461},"builder-71d0648c1d2f4ede8d0d0b5b28b7b94c",{"previousId":324},[462,478,485,492,501,511,521,531,538],{"@type":106,"@version":107,"id":463,"meta":464,"component":465,"responsiveStyles":476},"builder-ff325b4b8fad4edea53f38865947e854",{"previousId":328},{"name":327,"options":466,"isRSC":118},{"title":444,"description":467,"points":468,"video":475},"\u003Cp>Browser extensions introduce new code, new permissions, and new potential for risk. Many include AI features, and most go completely unnoticed. Push gives you full visibility into every extension used across your workforce, across major browsers, so you can uncover shadow IT, assess risky permissions, and block unsafe tools before they lead to compromise.\u003C/p>",[469,471,473],{"item":470},"Discover every browser extension in use",{"item":472},"Spot risky or unsanctioned behavior",{"item":474},"Make informed decisions on extension policy","https://cdn.builder.io/o/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fc538aad95d7f403aa3c3551af72f67c0?alt=media&token=1411fa6d-2eac-4e6c-94bf-ea117da12d67&apiKey=f3a1111ff5be48cdbb123cd9f5795a05",{"large":477},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":342},{"@type":106,"@version":107,"id":479,"meta":480,"component":481,"responsiveStyles":483},"builder-fb89d128c64e47cf9cbb11d90fc24523",{"previousId":344},{"name":346,"options":482,"isRSC":118},{"AllPartners":41,"backgroundTransparent":6},{"large":484},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":350},{"@type":106,"@version":107,"id":486,"meta":487,"component":488,"responsiveStyles":490},"builder-54388d35126c4d0096eeebaf8c4448cd",{"previousId":352},{"name":354,"options":489,"isRSC":118},{"darkMode":41},{"large":491},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"layerName":359,"id":493,"component":494,"responsiveStyles":499},"builder-3c8fa6785dd6466abf52a2470d66d85a",{"name":359,"tag":359,"options":495,"isRSC":118},{"darkMode":6,"maxWidth":363,"maxTextWidth":364,"title":496,"description":497,"image":498,"reverse":6},"\u003Ch2>Take control of browser extensions\u003C/h2>","\u003Cp>Attackers are increasingly using malicious browser extensions to gain access to data processed and stored in the browser. And the problem is, most security teams have no visibility into what extensions are being used. Push changes that. With browser-native telemetry, the Push extension continuously inventories browser extensions across your environment, flags the risky ones, and gives you intelligence to act.&nbsp;\u003C/p>\u003Cp>\u003Cbr>\u003C/p>\u003Cp>\u003Cbr>\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F0a004f16a6874f4c8fdf14344acc9fec",{"large":500},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":502,"meta":503,"component":504,"responsiveStyles":509},"builder-93738f98109a4009affb349afd7bb182",{"previousId":371},{"name":373,"options":505,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":376,"title":506,"description":507,"reverse":41,"image":508},"\u003Ch2>Discover every extension in use\u003C/h2>","\u003Cp>Push gives you structured, searchable data about every extension in your environment, so you’re not just seeing what’s there, but also understanding how it got there, what it can do, and who it affects. It’s the kind of granular insight that’s nearly impossible to get from traditional tools, and it lays the groundwork for better policy decisions and faster investigations.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F0e5727ca99474f14b1b7916bf6bbb782",{"large":510},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"fontFamily":382,"paddingTop":383,"marginTop":384},{"@type":106,"@version":107,"id":512,"meta":513,"component":514,"responsiveStyles":519},"builder-83393acb12ee4fdd840839185b51edb4",{"previousId":386},{"name":373,"options":515,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":389,"title":516,"description":517,"reverse":6,"image":518},"\u003Ch2>Spot risky or malicious extensions\u003C/h2>","\u003Cp>Push highlights extensions with dangerous permissions, broad access, or poor reputations. This includes AI extensions that request access far beyond what their stated purpose requires. You can quickly detect sideloaded, manually installed, or development-mode extensions that bypass normal controls. And because Push shows you who’s using them and where, you can respond precisely and effectively.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fa104d58c8da34fbb8901f738fb21453b",{"large":520},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":395},{"@type":106,"@version":107,"layerName":373,"id":522,"meta":523,"component":524,"responsiveStyles":529},"builder-da98e3de949646d89c53a0d1c2784664",{"previousId":397},{"name":373,"options":525,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":400,"title":526,"description":527,"reverse":41,"image":528},"\u003Ch2>Accelerate security reviews\u003C/h2>","\u003Cp>Most teams have extension policies, they just don’t have the data to enforce them. Push reveals how each extension entered your environment, whether it was installed manually, sideloaded, or deployed in dev mode. You’ll see which users are running what, and where, so you can surface violations, investigate quickly, and respond with confidence.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F229f355be6f243b180f410d237a75bb3",{"large":530},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":406},{"@type":106,"@version":107,"id":532,"meta":533,"component":534,"responsiveStyles":536},"builder-1a689287d1a1418997d57db578a71105",{"previousId":408},{"name":354,"options":535,"isRSC":118},{"darkMode":6},{"large":537},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":539,"component":540,"responsiveStyles":542},"builder-feb4e75029f84c10b6498ef1f8f79128",{"name":416,"tag":416,"options":541,"isRSC":118},{"sectionHeading":37,"customClass":418},{"large":543},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"id":545,"@type":106,"tagName":131,"properties":546,"responsiveStyles":547},"builder-pixel-0edn39avfcei",{"src":133,"aria-hidden":134,"alt":37,"role":135,"width":124,"height":124},{"large":548},{"height":124,"width":124,"display":138,"opacity":124,"overflow":139,"pointerEvents":140},{"deviceSize":142,"location":550},{"path":37,"query":551},{},{},1776275365038,1757000441666,"https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F8d496cf111644ee5afcc046b72d1ca5a",[],{"kind":438,"winningTest":118,"breakpoints":558,"lastPreviewUrl":559,"hasLinks":6,"originalContentId":259,"hasAutosaves":6},{"xsmall":57,"small":39,"medium":40},"https://pushsecurity.com/uc/browser-extension-security?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CcreateProjects%2CsendPullRequests&builder.user.role.name=Designer&builder.user.role.id=creator&builder.cachebust=true&builder.preview=use-case-page&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.use-case-page=54f8256648f54d439303734b1e69221b&builder.overrides.54f8256648f54d439303734b1e69221b=54f8256648f54d439303734b1e69221b&builder.overrides.use-case-page:/uc/browser-extension-security=54f8256648f54d439303734b1e69221b&builder.options.locale=Default",{"createdDate":561,"id":562,"name":563,"modelId":261,"published":13,"query":564,"data":567,"variations":670,"lastUpdated":671,"firstPublished":672,"testRatio":33,"screenshot":673,"createdBy":34,"lastUpdatedBy":674,"folders":675,"meta":676,"rev":440},1744923509705,"94bebb7bb99d48629ad157e80cf4d81d","Account takeover detection",[565],{"@type":264,"property":265,"operator":266,"value":566},"/uc/account-takeover-detection",{"title":563,"customFonts":568,"jsCode":37,"seoTitle":563,"seoDescription":573,"fontAwesomeIcon":574,"tsCode":37,"blocks":575,"url":566,"state":667},[569],{"kind":273,"category":295,"variants":570,"menu":296,"files":571,"family":272,"subsets":572,"version":274,"lastModified":275},[301,302,303,304,305,306,128,307,308,309,310,311,312,313,314,315,316,317],{"100":277,"200":278,"300":279,"500":280,"600":281,"700":282,"800":283,"900":284,"300italic":293,"500italic":292,"800italic":285,"700italic":287,"italic":289,"900italic":286,"600italic":294,"200italic":291,"regular":290,"100italic":288},[298,299],"Stop ATO with stolen credential and compromised token detection.","faUserSecret",[576,662],{"@type":106,"@version":107,"tagName":323,"id":577,"meta":578,"children":579},"builder-e7913a774cae44c5a23d6081c5c30a52",{"previousId":324},[580,596,603,610,619,629,639,649,656],{"@type":106,"@version":107,"id":581,"meta":582,"component":583,"responsiveStyles":594},"builder-f1f1ab1601bc4c0f8c2a8aafd173675d",{"previousId":328},{"name":327,"options":584,"isRSC":118},{"title":563,"description":585,"points":586,"video":593},"\u003Cp>Attackers don’t need to phish, they just need a password that works. Push monitors for signs of credential-based attacks in real time, directly in the browser, catching account takeover attempts before the damage spreads. From ghost logins to credential stuffing, Push cuts off the paths attackers use to quietly slip in the back door.\u003C/p>\u003Cp>\u003Cbr>\u003C/p>",[587,589,591],{"item":588},"Identify credential-based ATO as it unfolds",{"item":590},"Surface hijacked sessions and token misuse",{"item":592},"Strengthen authentication where your IdP can’t","https://cdn.builder.io/o/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fb4dd9db24bc9495b8a686b1b4d492016%2Fcompressed?apiKey=f3a1111ff5be48cdbb123cd9f5795a05&token=b4dd9db24bc9495b8a686b1b4d492016&alt=media&optimized=true",{"large":595},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":342},{"@type":106,"@version":107,"id":597,"meta":598,"component":599,"responsiveStyles":601},"builder-0bc0d1c78ece4994993c3a6427a4d533",{"previousId":344},{"name":346,"options":600,"isRSC":118},{"AllPartners":41,"backgroundTransparent":6},{"large":602},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":350},{"@type":106,"@version":107,"id":604,"meta":605,"component":606,"responsiveStyles":608},"builder-e45de8f3768c4f16938dbf78e4e87524",{"previousId":352},{"name":354,"options":607,"isRSC":118},{"darkMode":41},{"large":609},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":611,"component":612,"responsiveStyles":617},"builder-c98e8bfd341146c1b67c02d5698ff093",{"name":359,"tag":359,"options":613,"isRSC":118},{"darkMode":6,"maxWidth":363,"maxTextWidth":364,"title":614,"description":615,"image":616,"reverse":6},"\u003Ch2>Assume less. See more.\u003C/h2>","\u003Cp>Most account takeovers don’t start with a breach, they start with a login. Whether it’s a reused password, a local account, or an outdated login flow, Push shows you how accounts are actually accessed day to day, not just how policies say they should be. That means no more blind spots around ghost logins, bypassed SSO, or stale access paths that quietly persist.\u003C/p>\u003Cp>\u003Cbr>\u003C/p>\u003Cp>\u003Cbr>\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F18630ad2746d4eb7b7fcc0428b11a8f0",{"large":618},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":620,"meta":621,"component":622,"responsiveStyles":627},"builder-55c1fc38ddc04fd1a0d6a8e2fb819e00",{"previousId":371},{"name":373,"options":623,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":376,"title":624,"description":625,"reverse":41,"image":626},"\u003Ch2>Catch stolen credential use in real time\u003C/h2>","\u003Cp>Push monitors login activity directly in the browser to detect signs of credential-based attacks like leaked password use or suspicious login flows. By analyzing attacker TTPs instead of relying on known indicators, Push spots credential stuffing and account takeover attempts the moment they begin, not after they’ve succeeded.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F52b0123cac2c4dfdb1dc0af6adf9d603",{"large":628},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"fontFamily":382,"paddingTop":384,"marginTop":384},{"@type":106,"@version":107,"id":630,"meta":631,"component":632,"responsiveStyles":637},"builder-dfb31737b30948c6b95323655d571a50",{"previousId":386},{"name":373,"options":633,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":389,"title":634,"description":635,"reverse":6,"image":636},"\u003Ch2>Detect session hijacks and stealth access\u003C/h2>","\u003Cp>Attackers don’t always need a login screen, they often sidestep it entirely using stolen session tokens. Push detects when valid sessions are reused in unexpected ways, identifying hijacked sessions and stealth access attempts that traditional tools miss. Because we monitor directly in the browser, you see what’s happening inside active sessions in real time.\u003C/p>\u003Cp>\u003Cbr>\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F94a6859a99e04d309ffe5841f3dbdf5c",{"large":638},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":395},{"@type":106,"@version":107,"layerName":373,"id":640,"meta":641,"component":642,"responsiveStyles":647},"builder-f7585b90eb974d03a7dc7eae5b58d227",{"previousId":397},{"name":373,"options":643,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":400,"title":644,"description":645,"reverse":41,"image":646},"\u003Ch2>Harden accounts before they’re compromised\u003C/h2>","\u003Cp>Push goes beyond alerts. It identifies apps that still allow local logins, even when SSO is configured, so you can remove weak access paths. Push also flags users without MFA, reused work credentials, or weak passwords, and prompts users in-browser to fix risky behaviors before they’re exploited.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F01c1b638f1b6497093a4f2b8ceddb5bb",{"large":648},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":406},{"@type":106,"@version":107,"id":650,"meta":651,"component":652,"responsiveStyles":654},"builder-ad81d1e3afec49a791214194eae09bdc",{"previousId":408},{"name":354,"options":653,"isRSC":118},{"darkMode":6},{"large":655},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":657,"component":658,"responsiveStyles":660},"builder-8dac1aa4b9d148628d92252bd8eff822",{"name":416,"tag":416,"options":659,"isRSC":118},{"sectionHeading":37,"customClass":418},{"large":661},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"id":663,"@type":106,"tagName":131,"properties":664,"responsiveStyles":665},"builder-pixel-s5u3wmvz7jq",{"src":133,"aria-hidden":134,"alt":37,"role":135,"width":124,"height":124},{"large":666},{"height":124,"width":124,"display":138,"opacity":124,"overflow":139,"pointerEvents":140},{"deviceSize":142,"location":668},{"path":37,"query":669},{},{},1770892814499,1745499162732,"https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F58b660fa94aa4b30b0faeb9b663ae41a","SfUPqW5tkibIPby49keNFMdHFTr1",[],{"lastPreviewUrl":677,"hasLinks":6,"originalContentId":259,"breakpoints":678,"winningTest":118,"kind":438,"hasAutosaves":41},"https://pushsecurity.com/uc/account-takeover-detection?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditCode%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CeditProjects%2CmodifyMcpServers%2CmodifyWorkflowIntegrations%2CmodifyProjectSettings%2CconnectCodeRepository%2CcreateProjects%2CindexDesignSystems%2CsendPullRequests&builder.user.role.name=Developer&builder.user.role.id=developer&builder.cachebust=true&builder.preview=use-case-page&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.use-case-page=94bebb7bb99d48629ad157e80cf4d81d&builder.overrides.94bebb7bb99d48629ad157e80cf4d81d=94bebb7bb99d48629ad157e80cf4d81d&builder.overrides.use-case-page:/uc/account-takeover-detection=94bebb7bb99d48629ad157e80cf4d81d&builder.options.includeRefs=true&builder.options.enrich=true&builder.options.locale=Default",{"xsmall":57,"small":39,"medium":40},{"createdDate":680,"id":681,"name":682,"modelId":261,"published":13,"query":683,"data":686,"variations":789,"lastUpdated":790,"firstPublished":791,"testRatio":33,"screenshot":792,"createdBy":34,"lastUpdatedBy":674,"folders":793,"meta":794,"rev":440},1745009370904,"23eb48fb56d3451cab77cb6ed140ee6d","Attack path hardening",[684],{"@type":264,"property":265,"operator":266,"value":685},"/uc/attack-path-hardening",{"tsCode":37,"seoDescription":687,"jsCode":37,"customFonts":688,"fontAwesomeIcon":693,"seoTitle":682,"title":682,"blocks":694,"url":685,"state":786},"Harden access paths with visibility,  detection, and guardrails.",[689],{"kind":273,"files":690,"version":274,"lastModified":275,"subsets":691,"menu":296,"category":295,"variants":692,"family":272},{"100":277,"200":278,"300":279,"500":280,"600":281,"700":282,"800":283,"900":284,"regular":290,"italic":289,"800italic":285,"500italic":292,"600italic":294,"200italic":291,"900italic":286,"700italic":287,"100italic":288,"300italic":293},[298,299],[301,302,303,304,305,306,128,307,308,309,310,311,312,313,314,315,316,317],"faRadar",[695,781],{"@type":106,"@version":107,"tagName":323,"id":696,"meta":697,"children":698},"builder-1d8553eddcaa44d7bba9e2f4ca13af2a",{"previousId":577},[699,715,722,729,738,748,758,768,775],{"@type":106,"@version":107,"id":700,"meta":701,"component":702,"responsiveStyles":713},"builder-84fe3d7c85a743cf8cef649aa974f1ef",{"previousId":581},{"name":327,"options":703,"isRSC":118},{"title":682,"description":704,"points":705,"video":712},"\u003Cp>Push continuously monitors your environment for exposed login paths, weak credentials, and missing protections like MFA. It detects the gaps attackers exploit and helps you close them before they’re used.\u003C/p>",[706,708,710],{"item":707},"Find weak spots like reused passwords, local logins, and missing MFA",{"item":709},"Monitor how users actually log in across apps, flows, and tools",{"item":711},"Enforce secure access with in-browser guardrails","https://cdn.builder.io/o/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fdbdcf52892034f1bbddded77f753a343%2Fcompressed?apiKey=f3a1111ff5be48cdbb123cd9f5795a05&token=dbdcf52892034f1bbddded77f753a343&alt=media&optimized=true",{"large":714},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":342},{"@type":106,"@version":107,"id":716,"meta":717,"component":718,"responsiveStyles":720},"builder-b3f66f5b08054cc78a06fecfc3ae2337",{"previousId":597},{"name":346,"options":719,"isRSC":118},{"AllPartners":41,"backgroundTransparent":6},{"large":721},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":350},{"@type":106,"@version":107,"id":723,"meta":724,"component":725,"responsiveStyles":727},"builder-4c73418b84be49ed85e6e13d2625c5a0",{"previousId":604},{"name":354,"options":726,"isRSC":118},{"darkMode":41},{"large":728},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":730,"component":731,"responsiveStyles":736},"builder-dec0246085e1485c803f7152b1922a81",{"name":359,"tag":359,"options":732,"isRSC":118},{"darkMode":6,"maxWidth":363,"maxTextWidth":364,"title":733,"description":734,"image":735,"reverse":6},"\u003Ch2>Find the gaps that lead to compromise\u003C/h2>","\u003Cp>Misconfigurations don’t show up in your config files, they show up in how users actually access apps. Push monitors real login behavior in the browser, surfacing risky patterns like local login access, duplicate accounts, or missing protections that leave doors wide open.\u003C/p>\u003Cp>\u003Cbr>\u003C/p>\u003Cp>\u003Cbr>\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F309a59bba8d247a19476bb369397460e",{"large":737},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":739,"meta":740,"component":741,"responsiveStyles":746},"builder-ebf049a645604a249550996a88f8f3b6",{"previousId":620},{"name":373,"options":742,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":376,"title":743,"description":744,"reverse":41,"image":745},"\u003Ch2>See real login behavior\u003C/h2>","\u003Cp>Push watches authentication flows as they happen, giving you a live view of how users log in, which methods they choose, and where protections like MFA are missing. Plus, uncover every app and account in use, even shadow IT you didn’t know existed, without relying on stale config files or IdP assumptions. \u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fb51f6b0357cc451b87a7a5016d984e5e",{"large":747},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"fontFamily":382,"paddingTop":383,"marginTop":384},{"@type":106,"@version":107,"id":749,"meta":750,"component":751,"responsiveStyles":756},"builder-431d175c59004669b0b2776b07d71737",{"previousId":630},{"name":373,"options":752,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":389,"title":753,"description":754,"reverse":6,"image":755},"\u003Ch2>Find and fix posture drift\u003C/h2>","\u003Cp>Security posture isn’t static. Push continuously monitors for issues like missing MFA or legacy login methods. When something falls out of policy, you know immediately with custom notifications so you can act before it turns into risk.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F324e39127dfc41e592b1183dfb39892d",{"large":757},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":395},{"@type":106,"@version":107,"layerName":373,"id":759,"meta":760,"component":761,"responsiveStyles":766},"builder-3dffdcbe0a484e2ca4c03f019b6d40ee",{"previousId":640},{"name":373,"options":762,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":400,"title":763,"description":764,"reverse":41,"image":765},"\u003Ch2>Guide users with in-browser guardrails\u003C/h2>","\u003Cp>Push doesn’t just surface problems, it helps you fix them. When users sign in without MFA, reuse a password, or use insecure credentials, Push prompts them directly in the browser to secure their access. It’s faster, more effective, and actually gets results.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fee8b75d13e45488aba55434a8b49ebb0",{"large":767},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":406},{"@type":106,"@version":107,"id":769,"meta":770,"component":771,"responsiveStyles":773},"builder-976bc222cd7647ff905f1e01cfedc453",{"previousId":650},{"name":354,"options":772,"isRSC":118},{"darkMode":6},{"large":774},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":776,"component":777,"responsiveStyles":779},"builder-8c47ec2fd0f74382bb3e6c870555632c",{"name":416,"tag":416,"options":778,"isRSC":118},{"sectionHeading":37,"customClass":418},{"large":780},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"id":782,"@type":106,"tagName":131,"properties":783,"responsiveStyles":784},"builder-pixel-7akm7dayau8",{"src":133,"aria-hidden":134,"alt":37,"role":135,"width":124,"height":124},{"large":785},{"height":124,"width":124,"display":138,"opacity":124,"overflow":139,"pointerEvents":140},{"deviceSize":142,"location":787},{"path":37,"query":788},{},{},1770892844854,1745499166112,"https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F6ca12bf728a045f1a31d40c0beb3bfe5",[],{"kind":438,"lastPreviewUrl":795,"breakpoints":796,"hasLinks":6,"originalContentId":562,"winningTest":118,"hasAutosaves":6},"https://pushsecurity.com/uc/attack-path-hardening?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditCode%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CeditProjects%2CmodifyMcpServers%2CmodifyWorkflowIntegrations%2CmodifyProjectSettings%2CconnectCodeRepository%2CcreateProjects%2CindexDesignSystems%2CsendPullRequests&builder.user.role.name=Developer&builder.user.role.id=developer&builder.cachebust=true&builder.preview=use-case-page&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.use-case-page=23eb48fb56d3451cab77cb6ed140ee6d&builder.overrides.23eb48fb56d3451cab77cb6ed140ee6d=23eb48fb56d3451cab77cb6ed140ee6d&builder.overrides.use-case-page:/uc/attack-path-hardening=23eb48fb56d3451cab77cb6ed140ee6d&builder.options.includeRefs=true&builder.options.enrich=true&builder.options.locale=Default",{"xsmall":57,"small":39,"medium":40},{"createdDate":798,"id":799,"name":800,"modelId":261,"published":13,"query":801,"data":804,"variations":909,"lastUpdated":910,"firstPublished":911,"testRatio":33,"screenshot":912,"createdBy":34,"lastUpdatedBy":674,"folders":913,"meta":914,"rev":440},1761675020232,"ea4f309d2ffe46c5aa97ebf0fda4e2e3","ClickFix Protection",[802],{"@type":264,"property":265,"operator":266,"value":803},"/uc/clickfix-protection",{"seoDescription":805,"fontAwesomeIcon":806,"customFonts":807,"seoTitle":812,"jsCode":37,"tsCode":37,"title":812,"blocks":813,"url":803,"state":906},"Block attacks that trick users into running malicious code.","faLaptopCode",[808],{"files":809,"subsets":810,"menu":296,"version":274,"kind":273,"family":272,"lastModified":275,"variants":811,"category":295},{"100":277,"200":278,"300":279,"500":280,"600":281,"700":282,"800":283,"900":284,"200italic":291,"800italic":285,"700italic":287,"600italic":294,"100italic":288,"italic":289,"regular":290,"300italic":293,"500italic":292,"900italic":286},[298,299],[301,302,303,304,305,306,128,307,308,309,310,311,312,313,314,315,316,317],"ClickFix protection",[814,901],{"@type":106,"@version":107,"tagName":323,"id":815,"meta":816,"children":817},"builder-d7eefdde0f2a4b2b9de3dcb2978fd6cb",{"previousId":696},[818,834,841,848,858,868,878,888,895],{"@type":106,"@version":107,"id":819,"meta":820,"component":821,"responsiveStyles":832},"builder-56e2c54bcce040a4af8b92ae03706c12",{"previousId":700},{"name":327,"options":822,"isRSC":118},{"title":812,"description":823,"points":824,"image":831},"\u003Cp>ClickFix attacks are one of the fastest-growing threats, tricking users into copying malicious code from a webpage and running it locally. This technique bypasses traditional EDR, email gateways, and network filters, leading directly to ransomware and data theft. Push stops this attack at the source, in the browser, by detecting and blocking the malicious behavior before the user can ever paste the code.\u003C/p>\u003Cp>\u003Cbr>\u003C/p>",[825,827,829],{"item":826},"Detect ClickFix, FileFix, and fake CAPTCHA in the browser",{"item":828},"Block malicious copy-and-paste actions before code is executed",{"item":830},"See full telemetry into which users were targeted and what they saw","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F7b74af62889847ebb3927364485b0546",{"large":833},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":342},{"@type":106,"@version":107,"id":835,"meta":836,"component":837,"responsiveStyles":839},"builder-05f9614d4e3e4dc88b3ee8658f54e10e",{"previousId":716},{"name":346,"options":838,"isRSC":118},{"AllPartners":41,"backgroundTransparent":6},{"large":840},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":350},{"@type":106,"@version":107,"id":842,"meta":843,"component":844,"responsiveStyles":846},"builder-c4fb5179366243c1b6c32d368675cf47",{"previousId":723},{"name":354,"options":845,"isRSC":118},{"darkMode":41},{"large":847},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":849,"meta":850,"component":851,"responsiveStyles":856},"builder-261af50705fd445d8cca4a6ba20d5391",{"previousId":730},{"name":359,"tag":359,"options":852,"isRSC":118},{"darkMode":6,"maxWidth":363,"maxTextWidth":364,"title":853,"description":854,"reverse":6,"image":855},"\u003Ch2>Stop ClickFix-style attacks before they become a breach\u003C/h2>","\u003Cp>Traditional security tools are blind to malicious copy and paste attacks because the attack exploits a gap between the browser and the endpoint. EDR only sees the payload after it runs, and network tools see only part of the picture.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F98b2f7e08dec4eafaf8e24937605b8cf",{"large":857},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":859,"meta":860,"component":861,"responsiveStyles":866},"builder-7d21b8aab8064c40b1e5dd23c4749309",{"previousId":739},{"name":373,"options":862,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":376,"title":863,"description":864,"reverse":41,"image":865},"\u003Ch2>Discover lures at the source\u003C/h2>","\u003Cp>Push inspects page behavior to identify ClickFix attacks as they happen. By inspecting the page, its structure, and how the user interacts with it, Push can detect and block these in-browser threats in real time. This deep, TTP-based inspection spots the trap even on novel pages that are built to bypass traditional web filters and blocklists.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F665bf47e01544c75bf9ddafd3917927b",{"large":867},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"fontFamily":382,"paddingTop":383,"marginTop":384},{"@type":106,"@version":107,"id":869,"meta":870,"component":871,"responsiveStyles":876},"builder-fb91943adf6149259ed9e1e6566c9afe",{"previousId":749},{"name":373,"options":872,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":389,"title":873,"description":874,"reverse":6,"image":875},"\u003Ch2>Block the malicious action\u003C/h2>","\u003Cp>When Push detects a malicious script, it intercepts the user's action and blocks the code from being copied to the clipboard. The user is protected, the attack is stopped, and no malicious code ever reaches the endpoint. Unlike broad DLP tools, this action is surgical, targeting only malicious behavior without disrupting normal work.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F5ee68f81f1ac416685cbfe91298cf827",{"large":877},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":395},{"@type":106,"@version":107,"layerName":373,"id":879,"meta":880,"component":881,"responsiveStyles":886},"builder-bfac95fada864e5a8259b955b5b5f98b",{"previousId":759},{"name":373,"options":882,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":400,"title":883,"description":884,"reverse":41,"image":885},"\u003Ch2>Accelerate ClickFix investigations\u003C/h2>","\u003Cp>When an attack happens, knowing what the user saw or did is critical. Push provides rich browser session data for rapid investigation and containment. Security teams get detailed telemetry on which users were targeted, what lure they were served, and when the block occurred. This enables defenders to reconstruct what happened and respond quickly, even when other tools miss the activity entirely.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F6cdf2a8aeddc4e9a9023cbf974e40239",{"large":887},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":406},{"@type":106,"@version":107,"id":889,"meta":890,"component":891,"responsiveStyles":893},"builder-136892e831684a6987f87d3be67c33d1",{"previousId":769},{"name":354,"options":892,"isRSC":118},{"darkMode":6},{"large":894},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":896,"component":897,"responsiveStyles":899},"builder-dec26b739f2f42beb5a73cfc6c675b60",{"name":416,"tag":416,"options":898,"isRSC":118},{"sectionHeading":37,"customClass":418},{"large":900},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"id":902,"@type":106,"tagName":131,"properties":903,"responsiveStyles":904},"builder-pixel-zzjpxxgrc2l",{"src":133,"aria-hidden":134,"alt":37,"role":135,"width":124,"height":124},{"large":905},{"height":124,"width":124,"display":138,"opacity":124,"overflow":139,"pointerEvents":140},{"deviceSize":142,"location":907},{"path":37,"query":908},{},{},1770892881888,1761847585203,"https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F375467b8bef34ed1a8a1cc5b8b67d75f",[],{"lastPreviewUrl":915,"originalContentId":681,"winningTest":118,"hasLinks":6,"kind":438,"breakpoints":916,"hasAutosaves":6},"https://pushsecurity.com/uc/clickfix-protection?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditCode%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CeditProjects%2CmodifyMcpServers%2CmodifyWorkflowIntegrations%2CmodifyProjectSettings%2CconnectCodeRepository%2CcreateProjects%2CindexDesignSystems%2CsendPullRequests&builder.user.role.name=Developer&builder.user.role.id=developer&builder.cachebust=true&builder.preview=use-case-page&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.use-case-page=ea4f309d2ffe46c5aa97ebf0fda4e2e3&builder.overrides.ea4f309d2ffe46c5aa97ebf0fda4e2e3=ea4f309d2ffe46c5aa97ebf0fda4e2e3&builder.overrides.use-case-page:/uc/clickfix-protection=ea4f309d2ffe46c5aa97ebf0fda4e2e3&builder.options.includeRefs=true&builder.options.enrich=true&builder.options.locale=Default",{"xsmall":57,"small":39,"medium":40},{"createdDate":918,"id":919,"name":920,"modelId":261,"published":13,"query":921,"data":924,"variations":1029,"lastUpdated":1030,"firstPublished":1031,"testRatio":33,"screenshot":1032,"createdBy":34,"lastUpdatedBy":674,"folders":1033,"meta":1034,"rev":440},1745009743870,"a9d5556e77f84a37b5bd52310a7110c1","Incident response",[922],{"@type":264,"property":265,"operator":266,"value":923},"/uc/incident-response",{"seoDescription":925,"customFonts":926,"title":920,"jsCode":37,"fontAwesomeIcon":931,"seoTitle":932,"tsCode":37,"blocks":933,"url":923,"state":1026},"Investigate and respond faster with unique browser telemetry.",[927],{"kind":273,"subsets":928,"menu":296,"variants":929,"category":295,"family":272,"version":274,"lastModified":275,"files":930},[298,299],[301,302,303,304,305,306,128,307,308,309,310,311,312,313,314,315,316,317],{"100":277,"200":278,"300":279,"500":280,"600":281,"700":282,"800":283,"900":284,"900italic":286,"600italic":294,"200italic":291,"300italic":293,"100italic":288,"700italic":287,"800italic":285,"regular":290,"italic":289,"500italic":292},"faSatelliteDish","Browser based incident response",[934,1021],{"@type":106,"@version":107,"tagName":323,"id":935,"meta":936,"children":937},"builder-653c4aed737b4def88dc4cd2d695660a",{"previousId":696},[938,955,962,969,978,988,998,1008,1015],{"@type":106,"@version":107,"id":939,"meta":940,"component":941,"responsiveStyles":953},"builder-18190bd36518467d9154d27d7e945b9b",{"previousId":700},{"name":327,"options":942,"isRSC":118},{"title":943,"description":944,"points":945,"video":952},"Browser-based incident response","\u003Cp>Push gives you real-time visibility into what actually happened during a breach, right in the browser where the attack played out. From credential theft to session hijacking, Push captures high-fidelity telemetry so you can investigate quickly, contain confidently, and shut it down before it spreads.\u003C/p>\u003Cp>\u003Cbr>\u003C/p>",[946,948,950],{"item":947},"Reconstruct what happened with real browser session context",{"item":949},"Investigate faster with real-world session context",{"item":951},"Trigger response actions automatically through your SIEM or SOAR","https://cdn.builder.io/o/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fd00e39d3b6e346c296261d875cf55652%2Fcompressed?apiKey=f3a1111ff5be48cdbb123cd9f5795a05&token=d00e39d3b6e346c296261d875cf55652&alt=media&optimized=true",{"large":954},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":342},{"@type":106,"@version":107,"id":956,"meta":957,"component":958,"responsiveStyles":960},"builder-8a0a8ea63f5d48dd8a6726f2d49cf0ca",{"previousId":716},{"name":346,"options":959,"isRSC":118},{"AllPartners":41,"backgroundTransparent":6},{"large":961},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":350},{"@type":106,"@version":107,"id":963,"meta":964,"component":965,"responsiveStyles":967},"builder-2df65c3f54334df2b26e7cb744886cdc",{"previousId":723},{"name":354,"options":966,"isRSC":118},{"darkMode":41},{"large":968},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":970,"component":971,"responsiveStyles":976},"builder-2c32c869efc2423ab69ef06b150e9f97",{"name":359,"tag":359,"options":972,"isRSC":118},{"darkMode":6,"maxWidth":363,"maxTextWidth":364,"title":973,"description":974,"image":975,"reverse":6},"\u003Ch2>See attacks unfold, not just their aftermath\u003C/h2>","\u003Cp>Attacks happen in the browser, not in logs. Push captures what traditional tools miss: what users clicked, what loaded, what was entered, and how attackers moved. That gives you real-world evidence, not just assumptions, when every second matters.\u003C/p>\u003Cp>\u003Cbr>\u003C/p>\u003Cp>\u003Cbr>\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F36fc719bd1de4a38b916f4d25c81a26d",{"large":977},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":979,"meta":980,"component":981,"responsiveStyles":986},"builder-370e53c6016e432db01e9193a2ce90f6",{"previousId":739},{"name":373,"options":982,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":376,"title":983,"description":984,"reverse":41,"image":985},"\u003Ch2>Investigate faster with high-fidelity data\u003C/h2>","\u003Cp>Reconstructing an incident shouldn’t feel like guesswork. Push records detailed telemetry from inside the browser: page loads, credential inputs, DOM changes, session activity, user behavior. It’s structured, exportable, and ready to plug into your investigation workflows, so you can move fast without digging through proxy logs or relying on user reports.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fa6adda040e684e67a8d68a55c5ce5f6d",{"large":987},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"fontFamily":382,"paddingTop":384,"marginTop":384},{"@type":106,"@version":107,"id":989,"meta":990,"component":991,"responsiveStyles":996},"builder-a7f3767a8d184bd08fb24520bf210e95",{"previousId":749},{"name":373,"options":992,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":389,"title":993,"description":994,"reverse":6,"image":995},"\u003Ch2>Contain and respond in real time\u003C/h2>","\u003Cp>When something looks off, Push doesn’t just alert you, it gives you options. Guide users with in-browser prompts. Terminate sessions. Trigger SOAR workflows. Enrich SIEM alerts. Push gives you the context and control to stop spread before it starts.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fb3dedeed5aba4847a2c2d22e10d0ec12",{"large":997},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":395},{"@type":106,"@version":107,"layerName":373,"id":999,"meta":1000,"component":1001,"responsiveStyles":1006},"builder-b92036ee0ece4b32acdbdcc7c377366b",{"previousId":759},{"name":373,"options":1002,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":400,"title":1003,"description":1004,"reverse":41,"image":1005},"\u003Ch2>Prevent the next one\u003C/h2>","\u003Cp>Push helps you respond fast, but it also helps you fix what went wrong. It surfaces misconfigurations and risky behaviors that made the attack possible in the first place, then guides users in-browser to remediate. One tool. Full loop. No loose ends.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fc1ecc2d5d3814b62b072fac01827ff96",{"large":1007},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":406},{"@type":106,"@version":107,"id":1009,"meta":1010,"component":1011,"responsiveStyles":1013},"builder-5e8ae39655274de89da32ab573a2525a",{"previousId":769},{"name":354,"options":1012,"isRSC":118},{"darkMode":6},{"large":1014},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":1016,"component":1017,"responsiveStyles":1019},"builder-dfd6850cfb4741d2b8a0c16c2780f00a",{"name":416,"tag":416,"options":1018,"isRSC":118},{"sectionHeading":37,"customClass":418},{"large":1020},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"id":1022,"@type":106,"tagName":131,"properties":1023,"responsiveStyles":1024},"builder-pixel-z197gdgcmu",{"src":133,"aria-hidden":134,"alt":37,"role":135,"width":124,"height":124},{"large":1025},{"height":124,"width":124,"display":138,"opacity":124,"overflow":139,"pointerEvents":140},{"deviceSize":142,"location":1027},{"path":37,"query":1028},{},{},1770892908052,1745427419274,"https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fb07017bfd318431690a5bb35bda35b99",[],{"kind":438,"breakpoints":1035,"originalContentId":681,"winningTest":118,"lastPreviewUrl":1036,"hasLinks":6,"hasAutosaves":6},{"xsmall":57,"small":39,"medium":40},"https://pushsecurity.com/uc/incident-response?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditCode%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CeditProjects%2CmodifyMcpServers%2CmodifyWorkflowIntegrations%2CmodifyProjectSettings%2CconnectCodeRepository%2CcreateProjects%2CindexDesignSystems%2CsendPullRequests&builder.user.role.name=Developer&builder.user.role.id=developer&builder.cachebust=true&builder.preview=use-case-page&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.use-case-page=a9d5556e77f84a37b5bd52310a7110c1&builder.overrides.a9d5556e77f84a37b5bd52310a7110c1=a9d5556e77f84a37b5bd52310a7110c1&builder.overrides.use-case-page:/uc/incident-response=a9d5556e77f84a37b5bd52310a7110c1&builder.options.includeRefs=true&builder.options.enrich=true&builder.options.locale=Default",{"createdDate":1038,"id":1039,"name":1040,"modelId":261,"published":13,"query":1041,"data":1044,"variations":1149,"lastUpdated":1150,"firstPublished":1151,"testRatio":33,"screenshot":1152,"createdBy":34,"lastUpdatedBy":674,"folders":1153,"meta":1154,"rev":440},1746122471259,"5f118e24433d46ceb79f5099987156d7","Shadow SaaS",[1042],{"@type":264,"property":265,"operator":266,"value":1043},"/uc/shadow-saas",{"seoTitle":1045,"seoDescription":1046,"customFonts":1047,"fontAwesomeIcon":1052,"title":1053,"jsCode":37,"tsCode":37,"blocks":1054,"url":1043,"state":1146},"Find and secure shadow SaaS","See and control shadow SaaS in the browser.",[1048],{"kind":273,"variants":1049,"files":1050,"family":272,"version":274,"subsets":1051,"lastModified":275,"category":295,"menu":296},[301,302,303,304,305,306,128,307,308,309,310,311,312,313,314,315,316,317],{"100":277,"200":278,"300":279,"500":280,"600":281,"700":282,"800":283,"900":284,"300italic":293,"500italic":292,"regular":290,"900italic":286,"italic":289,"100italic":288,"200italic":291,"600italic":294,"700italic":287,"800italic":285},[298,299],"faShieldCheck","Secure shadow SaaS",[1055,1141],{"@type":106,"@version":107,"tagName":323,"id":1056,"meta":1057,"children":1058},"builder-04da805c4cd34652a2db452fcda52e1d",{"previousId":935},[1059,1075,1082,1089,1098,1108,1118,1128,1135],{"@type":106,"@version":107,"id":1060,"meta":1061,"component":1062,"responsiveStyles":1073},"builder-830d414faeaf41439142f9157e8288c8",{"previousId":939},{"name":327,"options":1063,"isRSC":118},{"title":1045,"description":1064,"points":1065,"video":1072},"\u003Cp>SaaS sprawl is one of today’s fastest-growing security blind spots because most tools monitor around the edges. Push sees it at the source, in the browser, revealing every app users access, flagging risky tools, and helping you shut down exposure before it leads to a breach. No guesswork. No nasty surprises. Just real-time visibility and control.\u003C/p>",[1066,1068,1070],{"item":1067},"Discover every SaaS app users access, managed or not",{"item":1069},"Spot accounts with weak security postures like missing MFA, unmanaged access, and no SSO",{"item":1071},"Control usage with in-browser prompts, blocks, and security guardrails","https://cdn.builder.io/o/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F3e4eece318d04d6586e691d59d0741cf%2Fcompressed?apiKey=f3a1111ff5be48cdbb123cd9f5795a05&token=3e4eece318d04d6586e691d59d0741cf&alt=media&optimized=true",{"large":1074},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":342},{"@type":106,"@version":107,"id":1076,"meta":1077,"component":1078,"responsiveStyles":1080},"builder-cd7833f966cb4c7e8adf0d6c979414a6",{"previousId":956},{"name":346,"options":1079,"isRSC":118},{"AllPartners":41,"backgroundTransparent":6},{"large":1081},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":350},{"@type":106,"@version":107,"id":1083,"meta":1084,"component":1085,"responsiveStyles":1087},"builder-49d720b45430454e8b08c526f267c19f",{"previousId":963},{"name":354,"options":1086,"isRSC":118},{"darkMode":41},{"large":1088},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":1090,"component":1091,"responsiveStyles":1096},"builder-3dde0bf6c8544e5e9ab41b18a9d68034",{"name":359,"tag":359,"options":1092,"isRSC":118},{"darkMode":6,"maxWidth":363,"maxTextWidth":364,"title":1093,"description":1094,"image":1095,"reverse":6},"\u003Ch2>Use your browser to curb Saas Sprawl\u003C/h2>","\u003Cp>Shadow SaaS isn’t hiding in your network, it’s in your browser. From AI tools to unsanctioned file-sharing sites, security risks live in the apps your users sign into every day. Push maps your organization's true SaaS footprint in real time, exposing apps and accounts with unmanaged access, poor authentication, or no security oversight.\u003C/p>\u003Cp>\u003Cbr>\u003C/p>\u003Cp>\u003Cbr>\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fb6811a214c7949b6bbe0b9a3bca62efd",{"large":1097},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":1099,"meta":1100,"component":1101,"responsiveStyles":1106},"builder-e2420451ccdc4f088d0a4904cff45935",{"previousId":979},{"name":373,"options":1102,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":376,"title":1103,"description":1104,"reverse":41,"image":1105},"\u003Ch2>Discover hidden SaaS usage\u003C/h2>","\u003Cp>Push captures live browser telemetry across every tab and session. Whether a user signs into a sanctioned app with a personal account or tries a new AI plugin, you’ll see it in real time, with no integrations or manual tagging.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fe16e301f9af94665b95d98232a863d8a",{"large":1107},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"fontFamily":382,"paddingTop":384,"marginTop":384},{"@type":106,"@version":107,"id":1109,"meta":1110,"component":1111,"responsiveStyles":1116},"builder-b36de7fce7994beea9e58d94662e7166",{"previousId":989},{"name":373,"options":1112,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":389,"title":1113,"description":1114,"reverse":6,"image":1115},"\u003Ch2>Spot risky access and unsafe usage\u003C/h2>","\u003Cp>Discovery is just the beginning. Push flags apps with risky traits, no MFA, no SSO, known vulnerabilities, or broad access scopes. You’ll know which tools introduce real risk, and which users are exposed so you can act with precision.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F6585f3c242da4d70ae3cb7d02f481bef",{"large":1117},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":395},{"@type":106,"@version":107,"layerName":373,"id":1119,"meta":1120,"component":1121,"responsiveStyles":1126},"builder-dc366b5134684fe7a508edf8913103ea",{"previousId":999},{"name":373,"options":1122,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":400,"title":1123,"description":1124,"reverse":41,"image":1125},"\u003Ch2>Close gaps before they grow\u003C/h2>","\u003Cp>Push turns insight into action. When risky SaaS use is detected, guide users to enable MFA, block high-risk apps, or apply in-browser guardrails automatically. All without deploying new infrastructure or managing dozens of integrations.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fe6d60b6d91414819bc6258a318f00557",{"large":1127},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":406},{"@type":106,"@version":107,"id":1129,"meta":1130,"component":1131,"responsiveStyles":1133},"builder-8708f6f0d8da4b3f9e17bf16cda70219",{"previousId":1009},{"name":354,"options":1132,"isRSC":118},{"darkMode":6},{"large":1134},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":1136,"component":1137,"responsiveStyles":1139},"builder-8ff4b38d60534cf28cb523ab0f754875",{"name":416,"tag":416,"options":1138,"isRSC":118},{"sectionHeading":37,"customClass":418},{"large":1140},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"id":1142,"@type":106,"tagName":131,"properties":1143,"responsiveStyles":1144},"builder-pixel-d1ul2kmxbed",{"src":133,"aria-hidden":134,"alt":37,"role":135,"width":124,"height":124},{"large":1145},{"height":124,"width":124,"display":138,"opacity":124,"overflow":139,"pointerEvents":140},{"deviceSize":142,"location":1147},{"path":37,"query":1148},{},{},1770892936802,1746714967208,"https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F01bfb2304521412fbd2e1a1180904d40",[],{"originalContentId":919,"winningTest":118,"lastPreviewUrl":1155,"breakpoints":1156,"kind":438,"hasLinks":6,"hasAutosaves":6},"https://pushsecurity.com/uc/shadow-saas?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditCode%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CeditProjects%2CmodifyMcpServers%2CmodifyWorkflowIntegrations%2CmodifyProjectSettings%2CconnectCodeRepository%2CcreateProjects%2CindexDesignSystems%2CsendPullRequests&builder.user.role.name=Developer&builder.user.role.id=developer&builder.cachebust=true&builder.preview=use-case-page&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.use-case-page=5f118e24433d46ceb79f5099987156d7&builder.overrides.5f118e24433d46ceb79f5099987156d7=5f118e24433d46ceb79f5099987156d7&builder.overrides.use-case-page:/uc/shadow-saas=5f118e24433d46ceb79f5099987156d7&builder.options.includeRefs=true&builder.options.enrich=true&builder.options.locale=Default",{"xsmall":57,"small":39,"medium":40},{"createdDate":1158,"id":1159,"name":1160,"modelId":261,"published":13,"query":1161,"data":1164,"variations":1268,"lastUpdated":1269,"firstPublished":1270,"testRatio":33,"screenshot":1271,"createdBy":34,"lastUpdatedBy":674,"folders":1272,"meta":1273,"rev":440},1764707470172,"b62629ce2f3741158d961cd10fe74b31","Shadow AI",[1162],{"@type":264,"property":265,"operator":266,"value":1163},"/uc/shadow-ai",{"fontAwesomeIcon":1165,"seoTitle":1166,"jsCode":37,"customFonts":1167,"title":1172,"tsCode":37,"seoDescription":1173,"blocks":1174,"url":1163,"state":1265},"faBrainCircuit","Secure AI native and AI enhanced apps. ",[1168],{"variants":1169,"category":295,"files":1170,"subsets":1171,"family":272,"kind":273,"menu":296,"lastModified":275,"version":274},[301,302,303,304,305,306,128,307,308,309,310,311,312,313,314,315,316,317],{"100":277,"200":278,"300":279,"500":280,"600":281,"700":282,"800":283,"900":284,"800italic":285,"regular":290,"700italic":287,"200italic":291,"italic":289,"500italic":292,"600italic":294,"300italic":293,"100italic":288,"900italic":286},[298,299],"Secure shadow AI","See and control shadow AI apps in the browser.",[1175,1260],{"@type":106,"@version":107,"tagName":323,"id":1176,"meta":1177,"children":1178},"builder-a6e5717a2c914d5695058e4ee201a05d",{"previousId":1056},[1179,1195,1202,1209,1219,1228,1237,1247,1254],{"@type":106,"@version":107,"id":1180,"meta":1181,"component":1182,"responsiveStyles":1193},"builder-3e0ed678683f4a0eb7aa00253cf263b2",{"previousId":1060},{"name":327,"options":1183,"isRSC":118},{"title":1172,"description":1184,"points":1185,"image":1192},"\u003Cp>Your employees are adopting AI faster than you can track it. From native features in corporate apps to unapproved shadow tools, it’s all happening in the browser. Push detects every AI interaction in real time, letting you categorize apps and enforce acceptable use policies in the browser.\u003C/p>",[1186,1188,1190],{"item":1187},"Map every AI tool used across your workforce",{"item":1189},"Review and classify apps by sensitivity, purpose, and policy status",{"item":1191},"Enforce AI usage rules directly in the browser","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F33cf153d920f4e389f3650253577cff7",{"large":1194},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":342},{"@type":106,"@version":107,"id":1196,"meta":1197,"component":1198,"responsiveStyles":1200},"builder-76968f8471d14893b8189d75b08fb426",{"previousId":1076},{"name":346,"options":1199,"isRSC":118},{"AllPartners":41,"backgroundTransparent":6},{"large":1201},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":350},{"@type":106,"@version":107,"id":1203,"meta":1204,"component":1205,"responsiveStyles":1207},"builder-b55b9d4bc5a649d8839ce7f6c2043d95",{"previousId":1083},{"name":354,"options":1206,"isRSC":118},{"darkMode":41},{"large":1208},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":1210,"meta":1211,"component":1212,"responsiveStyles":1217},"builder-c3f38ef4d75d4989a29b5903175ed8a1",{"previousId":1090},{"name":359,"tag":359,"options":1213,"isRSC":118},{"darkMode":6,"maxWidth":363,"maxTextWidth":364,"title":1214,"description":1215,"image":1216,"reverse":6},"\u003Ch2>Use your browser to govern AI \u003C/h2>","\u003Cp>The AI footprint inside your company is bigger than you think. From text generators to meeting assistants and design copilots, employees test, adopt, and connect new tools constantly. Push shows you those tools and which users are accessing them, without relying on network scans or API integrations.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F30b43bda6f1644c19478fb1efa20050c",{"large":1218},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":1220,"meta":1221,"component":1222,"responsiveStyles":1226},"builder-90ee9cb9afc44e7f885523715bf51a53",{"previousId":1099},{"name":373,"options":1223,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":376,"title":1224,"description":1225,"reverse":41,"image":1115},"\u003Ch2>Discover every AI tool users touch\u003C/h2>","\u003Cp>Push captures live telemetry from the browser, identifying every AI-native and AI-enhanced application users access. You’ll know which corporate identities are connected, how data flows, and what new AI apps appear across your environment. \u003C/p>",{"large":1227},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"fontFamily":382,"paddingTop":384,"marginTop":384},{"@type":106,"@version":107,"id":1229,"meta":1230,"component":1231,"responsiveStyles":1235},"builder-9e44539fa53c4d8e87406036c921fc46",{"previousId":1109},{"name":373,"options":1232,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":389,"title":1233,"description":1234,"reverse":6,"image":1125},"\u003Ch2>Classify and manage AI risk\u003C/h2>","\u003Cp>For apps you choose to allow, Push lets you apply custom in-browser banners. You can bulk-select categories of AI tools and require users to read and acknowledge your acceptable use policy before they proceed. This creates an auditable trail and moves policy from an easy to forget document to an active, in-workflow control.\u003C/p>",{"large":1236},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":395},{"@type":106,"@version":107,"layerName":373,"id":1238,"meta":1239,"component":1240,"responsiveStyles":1245},"builder-44c1a891926f4bdeaaa37e90721fe6ac",{"previousId":1119},{"name":373,"options":1241,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":400,"title":1242,"description":1243,"reverse":41,"image":1244},"\u003Ch2>Enforce your AI policy in the browser\u003C/h2>","\u003Cp>When an AI tool is deemed non-compliant or too risky, Push blocks it at the source. The block happens directly in the browser, preventing the user from accessing the site or submitting data. This gives you an immediate, powerful lever to stop data exfiltration and enforce a hard line on unacceptable risk.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fa359ac1805af4e15a8a7f84632b9bb55",{"large":1246},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":406},{"@type":106,"@version":107,"id":1248,"meta":1249,"component":1250,"responsiveStyles":1252},"builder-dcc906f9cbe54dc68b3c672668e7a38f",{"previousId":1129},{"name":354,"options":1251,"isRSC":118},{"darkMode":6},{"large":1253},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":1255,"component":1256,"responsiveStyles":1258},"builder-d2d64780c31b4349bc75805b23a07e38",{"name":416,"tag":416,"options":1257,"isRSC":118},{"sectionHeading":37,"customClass":418},{"large":1259},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"id":1261,"@type":106,"tagName":131,"properties":1262,"responsiveStyles":1263},"builder-pixel-wxx9tk70r9p",{"src":133,"aria-hidden":134,"alt":37,"role":135,"width":124,"height":124},{"large":1264},{"height":124,"width":124,"display":138,"opacity":124,"overflow":139,"pointerEvents":140},{"deviceSize":142,"location":1266},{"path":37,"query":1267},{},{},1770892957225,1764950077593,"https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fe558b8b069884037a8e6904f7ecc029c",[],{"winningTest":118,"breakpoints":1274,"originalContentId":1039,"kind":438,"lastPreviewUrl":1275,"hasLinks":6,"hasAutosaves":41},{"xsmall":57,"small":39,"medium":40},"https://pushsecurity.com/uc/shadow-ai?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditCode%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CeditProjects%2CmodifyMcpServers%2CmodifyWorkflowIntegrations%2CmodifyProjectSettings%2CconnectCodeRepository%2CcreateProjects%2CindexDesignSystems%2CsendPullRequests&builder.user.role.name=Developer&builder.user.role.id=developer&builder.cachebust=true&builder.preview=use-case-page&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.use-case-page=b62629ce2f3741158d961cd10fe74b31&builder.overrides.b62629ce2f3741158d961cd10fe74b31=b62629ce2f3741158d961cd10fe74b31&builder.overrides.use-case-page:/uc/shadow-ai=b62629ce2f3741158d961cd10fe74b31&builder.options.includeRefs=true&builder.options.enrich=true&builder.options.locale=Default",{"_path":1277,"_dir":1278,"_draft":6,"_partial":6,"_locale":37,"sys":1279,"ogImage":118,"summary":1282,"title":1296,"subtitle":118,"metaTitle":1297,"synopsis":1298,"hashTags":118,"publishedDate":1299,"slug":1300,"tagsCollection":1301,"relatedBlogPostsCollection":1311,"authorsCollection":3484,"content":3488,"_id":4051,"_type":4052,"_source":4053,"_file":4054,"_stem":4055,"_extension":4052},"/blog/how-consent-phishing-is-evolving","blog",{"id":1280,"publishedAt":1281},"3uLWz59In1waXGcLB9cnPq","2025-03-31T11:57:32.747Z",{"json":1283},{"data":1284,"content":1285,"nodeType":1295},{},[1286],{"data":1287,"content":1288,"nodeType":1294},{},[1289],{"data":1290,"marks":1291,"value":1292,"nodeType":1293},{},[],"Consent phishing is where attackers trick users into authorizing malicious OAuth apps. But we’re now seeing different use cases emerge as attackers get creative to evade detection controls. ","text","paragraph","document","How consent phishing is evolving to defeat detection controls","Analyzing two different forms of consent phishing","Consent phishing is where attackers trick users into authorizing access for malicious OAuth apps. Here's how attackers are using this technique in the wild.","2025-03-31T00:00:00.000Z","how-consent-phishing-is-evolving",{"items":1302},[1303,1307],{"sys":1304,"name":1306},{"id":1305},"6A5RXS31ZQx3PwryGb1IMy","Browser-based attacks",{"sys":1308,"name":1310},{"id":1309},"4ksQNCFeBf8H4QIORqpRLw","Detection & response",{"items":1312},[1313,1665,2689],{"__typename":1314,"sys":1315,"content":1317,"title":1647,"synopsis":1648,"hashTags":118,"publishedDate":1649,"slug":1650,"tagsCollection":1651,"authorsCollection":1657},"BlogPosts",{"id":1316},"4bYO5rVy9n2OO3vtMVQeda",{"json":1318},{"nodeType":1295,"data":1319,"content":1320},{},[1321,1329,1351,1367,1374,1381,1385,1393,1400,1455,1462,1471,1474,1481,1488,1495,1502,1509,1527,1533,1540,1547,1564,1570,1577,1584,1591,1598,1605,1608,1615,1635,1641],{"nodeType":1322,"data":1323,"content":1324},"heading-1",{},[1325],{"nodeType":1293,"value":1326,"marks":1327,"data":1328},"All phishing eventually leads to the browser",[],{},{"nodeType":1294,"data":1330,"content":1331},{},[1332,1336,1347],{"nodeType":1293,"value":1333,"marks":1334,"data":1335},"The best attack detection methods are those that focus on ",[],{},{"nodeType":1337,"data":1338,"content":1340},"hyperlink",{"uri":1339},"https://pushsecurity.com/blog/our-design-philosophy-detecting-what-matters/",[1341],{"nodeType":1293,"value":1342,"marks":1343,"data":1346},"detecting indicators that are difficult for attackers to change or obfuscate",[1344],{"type":1345},"underline",{},{"nodeType":1293,"value":1348,"marks":1349,"data":1350},". ",[],{},{"nodeType":1294,"data":1352,"content":1353},{},[1354,1358,1363],{"nodeType":1293,"value":1355,"marks":1356,"data":1357},"For a credential phishing attack to succeed, the victim ",[],{},{"nodeType":1293,"value":1359,"marks":1360,"data":1362},"has",[1361],{"type":1345},{},{"nodeType":1293,"value":1364,"marks":1365,"data":1366}," to enter their password into a webpage. There’s no two-ways about it, attackers cannot change this. ",[],{},{"nodeType":1294,"data":1368,"content":1369},{},[1370],{"nodeType":1293,"value":1371,"marks":1372,"data":1373},"So it stands to reason that, if you can detect this user behavior, and block them from entering their password, then you can stop phishing. ",[],{},{"nodeType":1294,"data":1375,"content":1376},{},[1377],{"nodeType":1293,"value":1378,"marks":1379,"data":1380},"This is exactly what Push does.",[],{},{"nodeType":1382,"data":1383,"content":1384},"hr",{},[],{"nodeType":1386,"data":1387,"content":1388},"heading-2",{},[1389],{"nodeType":1293,"value":1390,"marks":1391,"data":1392},"Most anti-phishing tools are easily bypassed",[],{},{"nodeType":1294,"data":1394,"content":1395},{},[1396],{"nodeType":1293,"value":1397,"marks":1398,"data":1399},"Other anti-phishing tools rely on detecting elements of the attack that attackers can change and hide, such as domains or the webpage contents. Attackers use tricks to evade these detection, like:",[],{},{"nodeType":1401,"data":1402,"content":1403},"unordered-list",{},[1404,1415,1425,1435,1445],{"nodeType":1405,"data":1406,"content":1407},"list-item",{},[1408],{"nodeType":1294,"data":1409,"content":1410},{},[1411],{"nodeType":1293,"value":1412,"marks":1413,"data":1414},"Using Cloudflare Workers to block automatic analysis of their phishing site",[],{},{"nodeType":1405,"data":1416,"content":1417},{},[1418],{"nodeType":1294,"data":1419,"content":1420},{},[1421],{"nodeType":1293,"value":1422,"marks":1423,"data":1424},"Hacking a Wordpress blog to get a reputable domain that passes domain checks ",[],{},{"nodeType":1405,"data":1426,"content":1427},{},[1428],{"nodeType":1294,"data":1429,"content":1430},{},[1431],{"nodeType":1293,"value":1432,"marks":1433,"data":1434},"Using redirects and rotating the URLs delivered to the victim to bypass link analysis",[],{},{"nodeType":1405,"data":1436,"content":1437},{},[1438],{"nodeType":1294,"data":1439,"content":1440},{},[1441],{"nodeType":1293,"value":1442,"marks":1443,"data":1444},"Randomizing the HTML title for the web page to bypass blocklists ",[],{},{"nodeType":1405,"data":1446,"content":1447},{},[1448],{"nodeType":1294,"data":1449,"content":1450},{},[1451],{"nodeType":1293,"value":1452,"marks":1453,"data":1454},"One-time phishing links that only work the first time they are clicked",[],{},{"nodeType":1294,"data":1456,"content":1457},{},[1458],{"nodeType":1293,"value":1459,"marks":1460,"data":1461},"Push is putting an end to this game of cat and mouse, by keeping it really simple; you can’t phish someone who can’t put their password into a phishing page. ",[],{},{"nodeType":1463,"data":1464,"content":1470},"embedded-entry-block",{"target":1465},{"sys":1466},{"id":1467,"type":1468,"linkType":1469},"6AwOZSpqaChmeksnj4SyWE","Link","Entry",[],{"nodeType":1382,"data":1472,"content":1473},{},[],{"nodeType":1386,"data":1475,"content":1476},{},[1477],{"nodeType":1293,"value":1478,"marks":1479,"data":1480},"Domain-binding passwords",[],{},{"nodeType":1294,"data":1482,"content":1483},{},[1484],{"nodeType":1293,"value":1485,"marks":1486,"data":1487},"If you’re familiar with how passkeys are domain-bound, then think of what Push does as domain-binding passwords. We pin the password to its legitimate domain(s) and then don’t allow it to be entered into any webpage on any other domain. ",[],{},{"nodeType":1294,"data":1489,"content":1490},{},[1491],{"nodeType":1293,"value":1492,"marks":1493,"data":1494},"But just because you’ve stopped your users from being phished doesn’t mean you don’t want to know when attackers are attempting to phish your users and how. ",[],{},{"nodeType":1294,"data":1496,"content":1497},{},[1498],{"nodeType":1293,"value":1499,"marks":1500,"data":1501},"Push still inspects webpages to see if attackers are rendering cloned app login pages in the browser or if known AitM and BitM toolkits are being used. This way you don’t lose visibility of the unsuccessful attacks that are targeting your users. Think of it as a handy second and third layer of defense.",[],{},{"nodeType":1294,"data":1503,"content":1504},{},[1505],{"nodeType":1293,"value":1506,"marks":1507,"data":1508},"Lets run through a quick before and after example:",[],{},{"nodeType":1386,"data":1510,"content":1511},{},[1512,1516,1523],{"nodeType":1293,"value":1513,"marks":1514,"data":1515},"Scenario 1: An attacker attempts to phish an employee that ",[],{},{"nodeType":1293,"value":1517,"marks":1518,"data":1522},"doesn’t",[1519,1520],{"type":1345},{"type":1521},"bold",{},{"nodeType":1293,"value":1524,"marks":1525,"data":1526}," have Push deployed to their browser.",[],{},{"nodeType":1463,"data":1528,"content":1532},{"target":1529},{"sys":1530},{"id":1531,"type":1468,"linkType":1469},"2CbGMUSJsP1mNeHkmpLl6N",[],{"nodeType":1294,"data":1534,"content":1535},{},[1536],{"nodeType":1293,"value":1537,"marks":1538,"data":1539},"Here, an attacker hacks a Wordpress blog to get a reputable domain and then runs a phishing toolkit on the webpage. They email one of your employees a link to it. Your SWG / email scanning solution inspects it in a sandbox but the phish kit detects this and redirects to a benign site so that it passes the inspection. ",[],{},{"nodeType":1294,"data":1541,"content":1542},{},[1543],{"nodeType":1293,"value":1544,"marks":1545,"data":1546},"Your user gets the email with the link and is now free to interact with the phishing page. They enter their credentials plus MFA code into the page and voila! The attacker steals them and is able to compromise the user’s account.  ",[],{},{"nodeType":1386,"data":1548,"content":1549},{},[1550,1554,1560],{"nodeType":1293,"value":1551,"marks":1552,"data":1553},"Scenario 2: An attacker attempts to phish an employee that ",[],{},{"nodeType":1293,"value":1555,"marks":1556,"data":1559},"does",[1557,1558],{"type":1345},{"type":1521},{},{"nodeType":1293,"value":1561,"marks":1562,"data":1563}," have Push deployed to their browser. ",[],{},{"nodeType":1463,"data":1565,"content":1569},{"target":1566},{"sys":1567},{"id":1568,"type":1468,"linkType":1469},"77smnID1woCfFJrJPyTvKY",[],{"nodeType":1294,"data":1571,"content":1572},{},[1573],{"nodeType":1293,"value":1574,"marks":1575,"data":1576},"This time, the attacker uses the same phishing toolkit and domain from the first example. But in reality, they don’t have to send it to your employee using email, instead, they could use LinkedIn messenger, Slack, Teams, or any application that allows employees to communicate with each other. ",[],{},{"nodeType":1294,"data":1578,"content":1579},{},[1580],{"nodeType":1293,"value":1581,"marks":1582,"data":1583},"Like before, the user receives the link, opens it and starts to enter their credentials into the webpage. This time though, the Push browser extension inspects the webpage running in the user's browser. Push observes that the webpage is a login page and the user is entering their password into the page.",[],{},{"nodeType":1294,"data":1585,"content":1586},{},[1587],{"nodeType":1293,"value":1588,"marks":1589,"data":1590},"The first detection Push makes is checking that the password the user is entering matches the domain that password is pinned to. Since it doesn't match, based on this detection alone the user is automatically redirected to a blocking page. An important point to make here is that the password never leaves the user’s browser and the check is made using a shortened salted hash of the password.   ",[],{},{"nodeType":1294,"data":1592,"content":1593},{},[1594],{"nodeType":1293,"value":1595,"marks":1596,"data":1597},"The second detection Push makes is that the rendered web app is using a cloned app login page. The third detection is that a phishing toolkit is running in the web app code. ",[],{},{"nodeType":1294,"data":1599,"content":1600},{},[1601],{"nodeType":1293,"value":1602,"marks":1603,"data":1604},"In this particular scenario these second and third detections serve as useful context for understanding the nature of the phishing attack. But both will still redirect to a blocking page if they are triggered in isolation of the other phishing detections. ",[],{},{"nodeType":1382,"data":1606,"content":1607},{},[],{"nodeType":1322,"data":1609,"content":1610},{},[1611],{"nodeType":1293,"value":1612,"marks":1613,"data":1614},"We don’t just stop phishing attacks",[],{},{"nodeType":1294,"data":1616,"content":1617},{},[1618,1622,1631],{"nodeType":1293,"value":1619,"marks":1620,"data":1621},"We also detect other identity-related attack techniques used to compromise user accounts. That includes credential stuffing, password spraying and session hijacking using stolen session tokens. If you want to learn more about how Push helps you to detect and defeat common identity attack techniques, ",[],{},{"nodeType":1337,"data":1623,"content":1625},{"uri":1624},"https://pushsecurity.com/demo/",[1626],{"nodeType":1293,"value":1627,"marks":1628,"data":1630},"book some time with one of our team",[1629],{"type":1345},{},{"nodeType":1293,"value":1632,"marks":1633,"data":1634},".  ",[],{},{"nodeType":1463,"data":1636,"content":1640},{"target":1637},{"sys":1638},{"id":1639,"type":1468,"linkType":1469},"2JSmYDaiAciOx7Z1MRuJlA",[],{"nodeType":1294,"data":1642,"content":1643},{},[1644],{"nodeType":1293,"value":37,"marks":1645,"data":1646},[],{},"Detecting and blocking phishing attacks in the browser","How Push detects and blocks phishing attempts in the browser – explained in less than two minutes. ","2024-10-23T00:00:00.000Z","detecting-and-blocking-phishing-attacks-in-the-browser",{"items":1652},[1653,1655],{"sys":1654,"name":1306},{"id":1305},{"sys":1656,"name":1310},{"id":1309},{"items":1658},[1659],{"fullName":1660,"firstName":1661,"jobTitle":1662,"profilePicture":1663},"Alex Henshall","Alex","Product Team",{"url":1664},"https://images.ctfassets.net/y1cdw1ablpvd/2rz3Pre3b1MexPIQ4hzPUe/0ef8a092b7e7df00fbce3f7d1ccb96d1/Alex_Henshall.jpeg",{"__typename":1314,"sys":1666,"content":1668,"title":2670,"synopsis":2671,"hashTags":118,"publishedDate":2672,"slug":2673,"tagsCollection":2674,"authorsCollection":2682},{"id":1667},"5aB5x5VXrMv7PDmH0iiK0c",{"json":1669},{"nodeType":1295,"data":1670,"content":1671},{},[1672,1692,1699,1706,1713,1720,1726,1733,1749,1752,1759,1766,1773,1780,1791,1798,1805,1812,1820,1827,1901,1913,1920,1928,1935,1994,2006,2013,2019,2027,2034,2067,2091,2098,2108,2111,2118,2138,2145,2178,2185,2192,2199,2205,2208,2215,2222,2230,2237,2244,2260,2266,2274,2281,2287,2295,2315,2322,2355,2376,2382,2402,2422,2430,2437,2444,2450,2470,2473,2481,2496,2503,2510,2560,2566,2573,2580,2623,2626,2634,2641,2644,2651],{"nodeType":1294,"data":1673,"content":1674},{},[1675,1679,1688],{"nodeType":1293,"value":1676,"marks":1677,"data":1678},"It wasn’t supposed to be like this. Passwords were supposed to be dead (just ask ",[],{},{"nodeType":1337,"data":1680,"content":1682},{"uri":1681},"https://www.cnet.com/news/privacy/gates-predicts-death-of-the-password/",[1683],{"nodeType":1293,"value":1684,"marks":1685,"data":1687},"Bill Gates",[1686],{"type":1345},{},{"nodeType":1293,"value":1689,"marks":1690,"data":1691},").",[],{},{"nodeType":1294,"data":1693,"content":1694},{},[1695],{"nodeType":1293,"value":1696,"marks":1697,"data":1698},"Instead, hardworking security pros are left to sit around in community center basements drinking mediocre coffee and commiserating.",[],{},{"nodeType":1294,"data":1700,"content":1701},{},[1702],{"nodeType":1293,"value":1703,"marks":1704,"data":1705},"“I admit it. My users still use passwords.”",[],{},{"nodeType":1294,"data":1707,"content":1708},{},[1709],{"nodeType":1293,"value":1710,"marks":1711,"data":1712},"“Yeah, mine too. I’ve been telling people we’re rolling out passkeys for three years now. I’m not sure how much longer I can keep this up …”",[],{},{"nodeType":1294,"data":1714,"content":1715},{},[1716],{"nodeType":1293,"value":1717,"marks":1718,"data":1719},"Somber nodding all around. Hugs. A few chocolate-chip cookies on paper napkins.",[],{},{"nodeType":1463,"data":1721,"content":1725},{"target":1722},{"sys":1723},{"id":1724,"type":1468,"linkType":1469},"4Wt29DxSSczFt5THWkuIiS",[],{"nodeType":1294,"data":1727,"content":1728},{},[1729],{"nodeType":1293,"value":1730,"marks":1731,"data":1732},"This is a no-judgment zone here at Push Security. So let’s take a look at why we’re still stuck with passwords, how attackers are increasingly exploiting weak credentials to infiltrate organizations, and how Push can help you get visibility and control of all your workforce identities.",[],{},{"nodeType":1294,"data":1734,"content":1735},{},[1736,1740,1745],{"nodeType":1293,"value":1737,"marks":1738,"data":1739},"We’ll also cover how you can use Push’s latest feature, ",[],{},{"nodeType":1293,"value":1741,"marks":1742,"data":1744},"Strong password enforcement",[1743],{"type":1521},{},{"nodeType":1293,"value":1746,"marks":1747,"data":1748},", to require that employees use strong, unique passwords. Push automatically detects when employees have weak, reused, or stolen passwords and then guides them to update their password using in-browser messaging — even on apps that don’t natively support administrative control of password posture.",[],{},{"nodeType":1382,"data":1750,"content":1751},{},[],{"nodeType":1322,"data":1753,"content":1754},{},[1755],{"nodeType":1293,"value":1756,"marks":1757,"data":1758},"3 reasons why we’re still stuck with passwords",[],{},{"nodeType":1294,"data":1760,"content":1761},{},[1762],{"nodeType":1293,"value":1763,"marks":1764,"data":1765},"At the risk of preaching to the choir, let’s review why we’re still stuck with passwords. ",[],{},{"nodeType":1294,"data":1767,"content":1768},{},[1769],{"nodeType":1293,"value":1770,"marks":1771,"data":1772},"It’s worth stating the Push perspective up front: We’re not here to push the narrative that you must completely get rid of passwords. To begin with, it’s not easy to get rid of them. Like the imaginary scene from the passwordless support group, we’ve lived the reality of this.",[],{},{"nodeType":1294,"data":1774,"content":1775},{},[1776],{"nodeType":1293,"value":1777,"marks":1778,"data":1779},"What we observe across our install base for the Push browser agent reinforces this reality. For the last 1 million or so logins that Push recorded, more than a quarter (26%) were password logins.",[],{},{"nodeType":1781,"data":1782,"content":1783},"blockquote",{},[1784],{"nodeType":1294,"data":1785,"content":1786},{},[1787],{"nodeType":1293,"value":1788,"marks":1789,"data":1790},"For the last 1M+ logins that the Push browser agent observed, more than a quarter were password logins.",[],{},{"nodeType":1294,"data":1792,"content":1793},{},[1794],{"nodeType":1293,"value":1795,"marks":1796,"data":1797},"Of those password logins, 18% had a security issue with the password — reused, easily guessable, already leaked in a public breach list, or actively for sale in criminal forums.",[],{},{"nodeType":1294,"data":1799,"content":1800},{},[1801],{"nodeType":1293,"value":1802,"marks":1803,"data":1804},"Yet when strong, unique passwords are used in conjunction with MFA, they can provide a powerful line of defense. Indeed, in cases where onboarding an app to SSO isn’t possible (for reasons we’ll cover below), a strong, unique password plus MFA is the most pragmatic solution you can achieve.",[],{},{"nodeType":1294,"data":1806,"content":1807},{},[1808],{"nodeType":1293,"value":1809,"marks":1810,"data":1811},"Here’s why bad passwords persist, and why it matters.",[],{},{"nodeType":1386,"data":1813,"content":1814},{},[1815],{"nodeType":1293,"value":1816,"marks":1817,"data":1819},"Systemic reasons",[1818],{"type":1521},{},{"nodeType":1294,"data":1821,"content":1822},{},[1823],{"nodeType":1293,"value":1824,"marks":1825,"data":1826},"If we zoom out, there are several systemic reasons that contribute to the persistence of password security issues:",[],{},{"nodeType":1401,"data":1828,"content":1829},{},[1830,1858,1886],{"nodeType":1405,"data":1831,"content":1832},{},[1833],{"nodeType":1294,"data":1834,"content":1835},{},[1836,1841,1845,1854],{"nodeType":1293,"value":1837,"marks":1838,"data":1840},"Self-adoption of work apps",[1839],{"type":1521},{},{"nodeType":1293,"value":1842,"marks":1843,"data":1844}," makes it extremely difficult to know all the workforce identities that exist across your environment, let alone whether they’re using a secure authentication method, or the strength or uniqueness of their password. Push’s ",[],{},{"nodeType":1337,"data":1846,"content":1848},{"uri":1847},"https://pushsecurity.com/blog/how-many-vulnerable-identities-do-you-have/",[1849],{"nodeType":1293,"value":1850,"marks":1851,"data":1853},"own research",[1852],{"type":1345},{},{"nodeType":1293,"value":1855,"marks":1856,"data":1857}," shows that for an average organization, each employee has 15 identities.",[],{},{"nodeType":1405,"data":1859,"content":1860},{},[1861],{"nodeType":1294,"data":1862,"content":1863},{},[1864,1869,1873,1882],{"nodeType":1293,"value":1865,"marks":1866,"data":1868},"Apps optimize signups for low friction, not security.",[1867],{"type":1521},{},{"nodeType":1293,"value":1870,"marks":1871,"data":1872}," That often results in multiple authentication methods tied to any given account because local password accounts can still persist even after SSO onboarding — a phenomenon that we call ",[],{},{"nodeType":1337,"data":1874,"content":1876},{"uri":1875},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/ghost_logins/description.md",[1877],{"nodeType":1293,"value":1878,"marks":1879,"data":1881},"ghost logins",[1880],{"type":1345},{},{"nodeType":1293,"value":1883,"marks":1884,"data":1885}," because they provide attackers with a way around a company’s enterprise SSO solution. These local accounts represent a significant risk, and most are invisible. Which brings us to …",[],{},{"nodeType":1405,"data":1887,"content":1888},{},[1889],{"nodeType":1294,"data":1890,"content":1891},{},[1892,1897],{"nodeType":1293,"value":1893,"marks":1894,"data":1896},"Many apps provide very little information to admins about the posture of accounts",[1895],{"type":1521},{},{"nodeType":1293,"value":1898,"marks":1899,"data":1900}," on that service, and even fewer offer management options to address security issues on those accounts. Some services provide no information at all about which accounts can even access a given tenant.",[],{},{"nodeType":1294,"data":1902,"content":1903},{},[1904,1909],{"nodeType":1293,"value":1905,"marks":1906,"data":1908},"The impact: ",[1907],{"type":1521},{},{"nodeType":1293,"value":1910,"marks":1911,"data":1912},"These systemic factors contribute to what we see many organizations grappling with: Known visibility gaps in their workforce identities, which are scattered across many more third-party apps than they imagine, and unknown account security risks for both managed and unmanaged apps.",[],{},{"nodeType":1294,"data":1914,"content":1915},{},[1916],{"nodeType":1293,"value":1917,"marks":1918,"data":1919},"These gaps open up a large attack surface for organizations. The 2024 Verizon DBIR found that 79% of web application compromises were the result of breached creds, and researchers at IBM reported last year that they observed a 71% year-over-year increase in cyberattacks using stolen or compromised credentials.",[],{},{"nodeType":1386,"data":1921,"content":1922},{},[1923],{"nodeType":1293,"value":1924,"marks":1925,"data":1927},"Technical reasons",[1926],{"type":1521},{},{"nodeType":1294,"data":1929,"content":1930},{},[1931],{"nodeType":1293,"value":1932,"marks":1933,"data":1934},"There are also several technical reasons why bad passwords persist:",[],{},{"nodeType":1401,"data":1936,"content":1937},{},[1938,1966],{"nodeType":1405,"data":1939,"content":1940},{},[1941],{"nodeType":1294,"data":1942,"content":1943},{},[1944,1947,1957,1962],{"nodeType":1293,"value":37,"marks":1945,"data":1946},[],{},{"nodeType":1337,"data":1948,"content":1950},{"uri":1949},"https://www.ncsc.gov.uk/blog-post/passkeys-not-perfect-getting-better",[1951],{"nodeType":1293,"value":1952,"marks":1953,"data":1956},"Going passwordless is hard",[1954,1955],{"type":1345},{"type":1521},{},{"nodeType":1293,"value":1958,"marks":1959,"data":1961}," ",[1960],{"type":1521},{},{"nodeType":1293,"value":1963,"marks":1964,"data":1965},"because it requires a large investment of time, money, and training for end-users. In environments with a mix of older and newer infrastructure, it can be challenging to get complete coverage, and employees may struggle with the transition to device-based authentication (especially when they lose their device and aren’t familiar with how to regain account access).",[],{},{"nodeType":1405,"data":1967,"content":1968},{},[1969],{"nodeType":1294,"data":1970,"content":1971},{},[1972,1977,1981,1990],{"nodeType":1293,"value":1973,"marks":1974,"data":1976},"Many apps do not even provide a SAML option",[1975],{"type":1521},{},{"nodeType":1293,"value":1978,"marks":1979,"data":1980},", making it difficult to onboard every business app to SSO even once you know about them all. Last we checked, only about 30% of commonly used work apps supported SAML. Even when apps do provide the option, many charge the infamous “",[],{},{"nodeType":1337,"data":1982,"content":1984},{"uri":1983},"https://sso.tax/",[1985],{"nodeType":1293,"value":1986,"marks":1987,"data":1989},"SSO tax",[1988],{"type":1345},{},{"nodeType":1293,"value":1991,"marks":1992,"data":1993},",” putting the feature behind enterprise plans.",[],{},{"nodeType":1294,"data":1995,"content":1996},{},[1997,2002],{"nodeType":1293,"value":1998,"marks":1999,"data":2001},"The impact:",[2000],{"type":1521},{},{"nodeType":1293,"value":2003,"marks":2004,"data":2005}," What ends up happening in many organizations is a patchwork of login methods, including passwords, passkeys, OIDC, and SAML. Looking at data from Push’s install base, we see on average around 15,000 accounts per 1,000 users, with 5,900+ outside of SSO — about 40%. ",[],{},{"nodeType":1294,"data":2007,"content":2008},{},[2009],{"nodeType":1293,"value":2010,"marks":2011,"data":2012},"That means more — not less — for a security and IT team to manage, often without the visibility or control they need to do so effectively.",[],{},{"nodeType":1463,"data":2014,"content":2018},{"target":2015},{"sys":2016},{"id":2017,"type":1468,"linkType":1469},"2QnWVpPYRyJQaQ5TuKSSLp",[],{"nodeType":1386,"data":2020,"content":2021},{},[2022],{"nodeType":1293,"value":2023,"marks":2024,"data":2026},"Human reasons",[2025],{"type":1521},{},{"nodeType":1294,"data":2028,"content":2029},{},[2030],{"nodeType":1293,"value":2031,"marks":2032,"data":2033},"Finally, there are a lot of human reasons why poor passwords persist, all of them familiar and intractable:",[],{},{"nodeType":1401,"data":2035,"content":2036},{},[2037,2052],{"nodeType":1405,"data":2038,"content":2039},{},[2040],{"nodeType":1294,"data":2041,"content":2042},{},[2043,2048],{"nodeType":1293,"value":2044,"marks":2045,"data":2047},"Password change fatigue",[2046],{"type":1521},{},{"nodeType":1293,"value":2049,"marks":2050,"data":2051},", resulting in weak and reused passwords — often driven by incomplete adoption of enterprise password managers or outdated password security policies that require users to rotate passwords frequently. ",[],{},{"nodeType":1405,"data":2053,"content":2054},{},[2055],{"nodeType":1294,"data":2056,"content":2057},{},[2058,2063],{"nodeType":1293,"value":2059,"marks":2060,"data":2062},"Shortcuts that busy humans take",[2061],{"type":1521},{},{"nodeType":1293,"value":2064,"marks":2065,"data":2066}," to get work done on a daily basis, including reusing passwords across personal and corporate accounts, storing passwords insecurely, and using easier-to-remember passwords over secure, complex ones.  ",[],{},{"nodeType":1294,"data":2068,"content":2069},{},[2070,2074,2078,2087],{"nodeType":1293,"value":1998,"marks":2071,"data":2073},[2072],{"type":1521},{},{"nodeType":1293,"value":2075,"marks":2076,"data":2077}," When there’s a large, complex, and largely invisible attack surface made up of these online corporate identities, adversaries profit. Just look at any of the ",[],{},{"nodeType":1337,"data":2079,"content":2081},{"uri":2080},"https://pushsecurity.com/resources/2024-identity-attacks",[2082],{"nodeType":1293,"value":2083,"marks":2084,"data":2086},"major identity attacks",[2085],{"type":1345},{},{"nodeType":1293,"value":2088,"marks":2089,"data":2090}," of the past year, some of which used password-spraying and credential-stuffing techniques to compromise accounts and pivot to high-value systems and data.",[],{},{"nodeType":1294,"data":2092,"content":2093},{},[2094],{"nodeType":1293,"value":2095,"marks":2096,"data":2097},"Password reuse also extends the blast radius for any account takeover incident when MFA is missing — a gap that occurs more often than you may think. Typically, 37% of logins observed by Push upon initial deployment into a new customer environment do not use any form of MFA.",[],{},{"nodeType":1781,"data":2099,"content":2100},{},[2101],{"nodeType":1294,"data":2102,"content":2103},{},[2104],{"nodeType":1293,"value":2105,"marks":2106,"data":2107},"2 in 5 logins observed by Push upon initial deployment into a new customer environment do not use any form of MFA.",[],{},{"nodeType":1382,"data":2109,"content":2110},{},[],{"nodeType":1322,"data":2112,"content":2113},{},[2114],{"nodeType":1293,"value":2115,"marks":2116,"data":2117},"Why identity posture matters more in a SaaS-first world",[],{},{"nodeType":1294,"data":2119,"content":2120},{},[2121,2125,2134],{"nodeType":1293,"value":2122,"marks":2123,"data":2124},"When most work now happens via the browser on web-based applications, the stakes are even higher for preventing account takeover. That’s because the way that attacks occur in a SaaS environment is ",[],{},{"nodeType":1337,"data":2126,"content":2128},{"uri":2127},"https://pushsecurity.com/blog/shifting-detection-left-for-more-effective-itdr/",[2129],{"nodeType":1293,"value":2130,"marks":2131,"data":2133},"very different",[2132],{"type":1345},{},{"nodeType":1293,"value":2135,"marks":2136,"data":2137}," from traditional network attacks, and there are few effective ways to detect and respond post-account compromise.",[],{},{"nodeType":1294,"data":2139,"content":2140},{},[2141],{"nodeType":1293,"value":2142,"marks":2143,"data":2144},"The average SaaS attack path looks like this:",[],{},{"nodeType":1401,"data":2146,"content":2147},{},[2148,2158,2168],{"nodeType":1405,"data":2149,"content":2150},{},[2151],{"nodeType":1294,"data":2152,"content":2153},{},[2154],{"nodeType":1293,"value":2155,"marks":2156,"data":2157},"Attackers gain control of legitimate employee accounts using stolen credentials or via password-spraying or credential-stuffing techniques.",[],{},{"nodeType":1405,"data":2159,"content":2160},{},[2161],{"nodeType":1294,"data":2162,"content":2163},{},[2164],{"nodeType":1293,"value":2165,"marks":2166,"data":2167},"Attackers exfiltrate data.",[],{},{"nodeType":1405,"data":2169,"content":2170},{},[2171],{"nodeType":1294,"data":2172,"content":2173},{},[2174],{"nodeType":1293,"value":2175,"marks":2176,"data":2177},"The end.",[],{},{"nodeType":1294,"data":2179,"content":2180},{},[2181],{"nodeType":1293,"value":2182,"marks":2183,"data":2184},"Compare that to traditional network or enterprise cloud attacks, which usually involve more complex lateral movement, privilege escalation, and defense evasion.",[],{},{"nodeType":1294,"data":2186,"content":2187},{},[2188],{"nodeType":1293,"value":2189,"marks":2190,"data":2191},"With limited log data and few response capabilities provided by most SaaS apps, security teams also have few good options to stop the damage of an account takeover once one has occurred. ",[],{},{"nodeType":1294,"data":2193,"content":2194},{},[2195],{"nodeType":1293,"value":2196,"marks":2197,"data":2198},"That’s why at Push, we advocate for “shifting left,” and preventing account takeover before it happens.",[],{},{"nodeType":1463,"data":2200,"content":2204},{"target":2201},{"sys":2202},{"id":2203,"type":1468,"linkType":1469},"6wIzMu3jBhaas9jtpV48bz",[],{"nodeType":1382,"data":2206,"content":2207},{},[],{"nodeType":1322,"data":2209,"content":2210},{},[2211],{"nodeType":1293,"value":2212,"marks":2213,"data":2214},"How Push helps you ensure strong passwords",[],{},{"nodeType":1294,"data":2216,"content":2217},{},[2218],{"nodeType":1293,"value":2219,"marks":2220,"data":2221},"There are four capabilities that security teams need in order to regain control over password security issues across their corporate accounts. Here’s how Push accomplishes each one.",[],{},{"nodeType":1386,"data":2223,"content":2224},{},[2225],{"nodeType":1293,"value":2226,"marks":2227,"data":2229},"1. A reliable inventory of all the apps that employees are using, including work apps and internal apps.",[2228],{"type":1521},{},{"nodeType":1294,"data":2231,"content":2232},{},[2233],{"nodeType":1293,"value":2234,"marks":2235,"data":2236},"Push achieves this by deploying a browser agent to employee browsers that can directly observe their login activity, which feeds the data back into an admin console (or your SIEM/SOAR or other third-party system). You can enforce the installation of the agent using any MDM solution, on all major browsers.",[],{},{"nodeType":1294,"data":2238,"content":2239},{},[2240],{"nodeType":1293,"value":2241,"marks":2242,"data":2243},"Once the agent is activated, it begins immediately capturing employee logins and produces a real-time inventory of all your work and internal apps. Because Push observes the login directly in the browser, it can identify all the apps and accounts being used by your employees — both managed and unmanaged (shadow IT).",[],{},{"nodeType":1294,"data":2245,"content":2246},{},[2247,2251,2256],{"nodeType":1293,"value":2248,"marks":2249,"data":2250},"You can also configure Push to monitor ",[],{},{"nodeType":1293,"value":2252,"marks":2253,"data":2255},"any",[2254],{"type":312},{},{"nodeType":1293,"value":2257,"marks":2258,"data":2259}," login to a work app, regardless of the associated email domain of the employee. This means you can monitor personal account logins to apps that are commonly used for work.",[],{},{"nodeType":1463,"data":2261,"content":2265},{"target":2262},{"sys":2263},{"id":2264,"type":1468,"linkType":1469},"4ctCB7kBscj12BnfHhk3ro",[],{"nodeType":1386,"data":2267,"content":2268},{},[2269],{"nodeType":1293,"value":2270,"marks":2271,"data":2273},"2. A way to identify the login methods an account is using, whether that’s SAML, OIDC, or password.",[2272],{"type":1521},{},{"nodeType":1294,"data":2275,"content":2276},{},[2277],{"nodeType":1293,"value":2278,"marks":2279,"data":2280},"Again, because Push observes the login event, it can analyze the authentication method or methods in use by a given account. Push tells you which SSO accounts still have passwords associated with them, and which authentication methods are being actively used.",[],{},{"nodeType":1463,"data":2282,"content":2286},{"target":2283},{"sys":2284},{"id":2285,"type":1468,"linkType":1469},"pVD238hZ331gjWalDTM1q",[],{"nodeType":1386,"data":2288,"content":2289},{},[2290],{"nodeType":1293,"value":2291,"marks":2292,"data":2294},"3. A method for analyzing whether an employee is using secure passwords on all their accounts.",[2293],{"type":1521},{},{"nodeType":1294,"data":2296,"content":2297},{},[2298,2302,2311],{"nodeType":1293,"value":2299,"marks":2300,"data":2301},"Using Push, you can also check the posture of all your employee accounts. The browser agent accomplishes this by ",[],{},{"nodeType":1337,"data":2303,"content":2305},{"uri":2304},"https://pushsecurity.com/help/10065#start",[2306],{"nodeType":1293,"value":2307,"marks":2308,"data":2310},"creating a salted hash",[2309],{"type":1345},{},{"nodeType":1293,"value":2312,"marks":2313,"data":2314}," of a user’s observed password and then taking the first 8 characters of that hash to store locally in the browser.",[],{},{"nodeType":1294,"data":2316,"content":2317},{},[2318],{"nodeType":1293,"value":2319,"marks":2320,"data":2321},"This allows Push to analyze whether the password is weak (comparing the hash to a list of 10,000 common basewords and common permutations); or reused across accounts.",[],{},{"nodeType":1294,"data":2323,"content":2324},{},[2325,2329,2338,2342,2351],{"nodeType":1293,"value":2326,"marks":2327,"data":2328},"Push can also identify when employee passwords have ",[],{},{"nodeType":1337,"data":2330,"content":2332},{"uri":2331},"https://pushsecurity.com/help/10066#start",[2333],{"nodeType":1293,"value":2334,"marks":2335,"data":2337},"appeared in a public breach list",[2336],{"type":1345},{},{"nodeType":1293,"value":2339,"marks":2340,"data":2341}," using the Have I Been Pwned service, using a k-anonymized hash. Using similar secure methods, Push can detect when employees are sharing account credentials, whether they’re using a ",[],{},{"nodeType":1337,"data":2343,"content":2345},{"uri":2344},"https://pushsecurity.com/help/10085/#start",[2346],{"nodeType":1293,"value":2347,"marks":2348,"data":2350},"password manager",[2349],{"type":1345},{},{"nodeType":1293,"value":2352,"marks":2353,"data":2354},", and which one.",[],{},{"nodeType":1294,"data":2356,"content":2357},{},[2358,2362,2372],{"nodeType":1293,"value":2359,"marks":2360,"data":2361},"Using Push’s ",[],{},{"nodeType":1337,"data":2363,"content":2365},{"uri":2364},"https://pushsecurity.com/blog/verified-stolen-credential-detection/",[2366],{"nodeType":1293,"value":2367,"marks":2368,"data":2371},"Stolen credentials detection",[2369,2370],{"type":1345},{"type":1521},{},{"nodeType":1293,"value":2373,"marks":2374,"data":2375}," feature, you can also get alerted when an employee is using credentials that match those for sale in criminal forums. Push integrates with commercial threat intelligence sources to perform these matches, and you can also bring your own TI using the Push REST API to perform additional checks for in-use stolen creds. This check still happens locally in the browser, so no hashes are sent to third-party systems.",[],{},{"nodeType":1463,"data":2377,"content":2381},{"target":2378},{"sys":2379},{"id":2380,"type":1468,"linkType":1469},"6wfLCTzvHeMzagyuEWGyJg",[],{"nodeType":1294,"data":2383,"content":2384},{},[2385,2389,2398],{"nodeType":1293,"value":2386,"marks":2387,"data":2388},"If you configure Push to also monitor for employees who are logging in to work apps using ",[],{},{"nodeType":1337,"data":2390,"content":2392},{"uri":2391},"https://pushsecurity.com/help/10105#start",[2393],{"nodeType":1293,"value":2394,"marks":2395,"data":2397},"personal email addresses",[2396],{"type":1345},{},{"nodeType":1293,"value":2399,"marks":2400,"data":2401}," or any non-corporate email, Push can identify when personal accounts and work accounts are reusing passwords for the same work application.",[],{},{"nodeType":1294,"data":2403,"content":2404},{},[2405,2409,2418],{"nodeType":1293,"value":2406,"marks":2407,"data":2408},"Using the Push ",[],{},{"nodeType":1337,"data":2410,"content":2412},{"uri":2411},"https://pushsecurity.com/help/audience/administrators/docs/getting-started/#api-and-webhooks",[2413],{"nodeType":1293,"value":2414,"marks":2415,"data":2417},"REST API and webhooks",[2416],{"type":1345},{},{"nodeType":1293,"value":2419,"marks":2420,"data":2421},", you can get alerted when Push raises a security finding for an account, and when a finding is resolved.",[],{},{"nodeType":1386,"data":2423,"content":2424},{},[2425],{"nodeType":1293,"value":2426,"marks":2427,"data":2429},"4. The ability to solve any issues at scale, including remediating bad passwords and enforcing MFA, even on apps where the security team doesn’t have administrative control.",[2428],{"type":1521},{},{"nodeType":1294,"data":2431,"content":2432},{},[2433],{"nodeType":1293,"value":2434,"marks":2435,"data":2436},"Finally, you can enforce self-remediation workflows using Push’s position in the browser, right where employees are working. ",[],{},{"nodeType":1294,"data":2438,"content":2439},{},[2440],{"nodeType":1293,"value":2441,"marks":2442,"data":2443},"Push recently released a new in-browser control to enforce strong passwords. It works by detecting when an employee has a password security issue, and then prompting them to update their password by displaying a customizable banner message when they log in to the affected account.",[],{},{"nodeType":1463,"data":2445,"content":2449},{"target":2446},{"sys":2447},{"id":2448,"type":1468,"linkType":1469},"4IfBLaE66CJSsb5h44vSNp",[],{"nodeType":1294,"data":2451,"content":2452},{},[2453,2457,2466],{"nodeType":1293,"value":2454,"marks":2455,"data":2456},"This control complements an existing ",[],{},{"nodeType":1337,"data":2458,"content":2460},{"uri":2459},"https://pushsecurity.com/blog/enforce-mfa-on-third-party-apps/",[2461],{"nodeType":1293,"value":2462,"marks":2463,"data":2465},"MFA enforcement",[2464],{"type":1345},{},{"nodeType":1293,"value":2467,"marks":2468,"data":2469}," guardrail, which uses a similar workflow to prompt employees to register for MFA on apps where it’s missing.",[],{},{"nodeType":1382,"data":2471,"content":2472},{},[],{"nodeType":1322,"data":2474,"content":2475},{},[2476],{"nodeType":1293,"value":2477,"marks":2478,"data":2480},"A closer look at password enforcement",[2479],{"type":1521},{},{"nodeType":1294,"data":2482,"content":2483},{},[2484,2488,2492],{"nodeType":1293,"value":2485,"marks":2486,"data":2487},"In the spirit of helping users do the right thing, we designed the",[],{},{"nodeType":1293,"value":1958,"marks":2489,"data":2491},[2490],{"type":1521},{},{"nodeType":1293,"value":2493,"marks":2494,"data":2495},"password enforcement control to meet users where they are, in the most relevant context where they can fix the problem. ",[],{},{"nodeType":1294,"data":2497,"content":2498},{},[2499],{"nodeType":1293,"value":2500,"marks":2501,"data":2502},"Because this control is powered by the Push browser agent, security teams don’t need administrative control over every app where password accounts exist — which often isn’t practical for all the reasons we reviewed earlier. Instead, they can use Push to prompt employees to fix the issue themselves.",[],{},{"nodeType":1294,"data":2504,"content":2505},{},[2506],{"nodeType":1293,"value":2507,"marks":2508,"data":2509},"Here’s a closer look at how it works:",[],{},{"nodeType":1401,"data":2511,"content":2512},{},[2513,2540,2550],{"nodeType":1405,"data":2514,"content":2515},{},[2516],{"nodeType":1294,"data":2517,"content":2518},{},[2519,2523,2527,2531,2536],{"nodeType":1293,"value":2520,"marks":2521,"data":2522},"You can enable ",[],{},{"nodeType":1293,"value":1741,"marks":2524,"data":2526},[2525],{"type":1521},{},{"nodeType":1293,"value":2528,"marks":2529,"data":2530}," from the tile on the ",[],{},{"nodeType":1293,"value":2532,"marks":2533,"data":2535},"Controls",[2534],{"type":1521},{},{"nodeType":1293,"value":2537,"marks":2538,"data":2539}," page of the Push admin console. ",[],{},{"nodeType":1405,"data":2541,"content":2542},{},[2543],{"nodeType":1294,"data":2544,"content":2545},{},[2546],{"nodeType":1293,"value":2547,"marks":2548,"data":2549},"Using the rule editor, select whether you want to apply the control for all employees, or just specific groups or individuals, and which apps it should apply to. You can also select which types of password security issues you want to prompt users about.",[],{},{"nodeType":1405,"data":2551,"content":2552},{},[2553],{"nodeType":1294,"data":2554,"content":2555},{},[2556],{"nodeType":1293,"value":2557,"marks":2558,"data":2559},"Then customize the message that employees will see. Push will then automatically display the banner based on your criteria. Where possible, Push will include a link in the banner that takes employees directly to the page in the app where they can change their password — or you can add a link yourself.",[],{},{"nodeType":1463,"data":2561,"content":2565},{"target":2562},{"sys":2563},{"id":2564,"type":1468,"linkType":1469},"shpVOAMlk7OE1mWrE9h8S",[],{"nodeType":1294,"data":2567,"content":2568},{},[2569],{"nodeType":1293,"value":2570,"marks":2571,"data":2572},"Once the password has been changed and Push verifies that the new password is strong, you’ll see the security finding cleared from the account record in the admin console and the banner will no longer display to the end-user.",[],{},{"nodeType":1294,"data":2574,"content":2575},{},[2576],{"nodeType":1293,"value":2577,"marks":2578,"data":2579},"Push also sends webhook events when:",[],{},{"nodeType":1401,"data":2581,"content":2582},{},[2583,2593,2603,2613],{"nodeType":1405,"data":2584,"content":2585},{},[2586],{"nodeType":1294,"data":2587,"content":2588},{},[2589],{"nodeType":1293,"value":2590,"marks":2591,"data":2592},"A banner is displayed",[],{},{"nodeType":1405,"data":2594,"content":2595},{},[2596],{"nodeType":1294,"data":2597,"content":2598},{},[2599],{"nodeType":1293,"value":2600,"marks":2601,"data":2602},"A user clicks the link in the banner to take action",[],{},{"nodeType":1405,"data":2604,"content":2605},{},[2606],{"nodeType":1294,"data":2607,"content":2608},{},[2609],{"nodeType":1293,"value":2610,"marks":2611,"data":2612},"A password is updated",[],{},{"nodeType":1405,"data":2614,"content":2615},{},[2616],{"nodeType":1294,"data":2617,"content":2618},{},[2619],{"nodeType":1293,"value":2620,"marks":2621,"data":2622},"A password security finding is resolved",[],{},{"nodeType":1382,"data":2624,"content":2625},{},[],{"nodeType":1322,"data":2627,"content":2628},{},[2629],{"nodeType":1293,"value":2630,"marks":2631,"data":2633},"Where to begin",[2632],{"type":1521},{},{"nodeType":1294,"data":2635,"content":2636},{},[2637],{"nodeType":1293,"value":2638,"marks":2639,"data":2640},"Most organizations we work with deploy the Push agent first to get an initial understanding of their attack surface and account posture issues. Then we recommend enabling the one-two punch of MFA and strong password enforcement guardrails. You can use both controls in tandem, and Push will first seek to resolve the password issues on a given account, and then prompt the user to register for MFA.",[],{},{"nodeType":1382,"data":2642,"content":2643},{},[],{"nodeType":1322,"data":2645,"content":2646},{},[2647],{"nodeType":1293,"value":2648,"marks":2649,"data":2650},"Find out more",[],{},{"nodeType":1294,"data":2652,"content":2653},{},[2654,2658,2666],{"nodeType":1293,"value":2655,"marks":2656,"data":2657},"If you want to learn more about how Push helps you to detect and defeat common identity attack techniques like AiTM phishing, credential stuffing, and session hijacking while improving your workforce identity posture, book some time with one of our team for a ",[],{},{"nodeType":1337,"data":2659,"content":2660},{"uri":1624},[2661],{"nodeType":1293,"value":2662,"marks":2663,"data":2665},"live demo",[2664],{"type":1345},{},{"nodeType":1293,"value":2667,"marks":2668,"data":2669},".",[],{},"Introducing Push password enforcement — for when weak passwords are still plaguing you","Detects when employees have weak, reused, or stolen passwords and guide them to update their password using in-browser messaging on any app. ","2025-03-25T00:00:00.000Z","introducing-strong-password-enforcement",{"items":2675},[2676,2680],{"sys":2677,"name":2679},{"id":2678},"3pjES4THCIfSAwhGdNwBcy","Identity security",{"sys":2681,"name":1306},{"id":1305},{"items":2683},[2684],{"fullName":2685,"firstName":2686,"jobTitle":1662,"profilePicture":2687},"Kelly Davenport","Kelly",{"url":2688},"https://images.ctfassets.net/y1cdw1ablpvd/1hi8bEuVfn5sF57LivAq6d/9a3b82426c697d765e2e450e33a18424/kelly_profile_pic.jpeg",{"__typename":1314,"sys":2690,"content":2692,"title":3466,"synopsis":3467,"hashTags":118,"publishedDate":3468,"slug":3469,"tagsCollection":3470,"authorsCollection":3476},{"id":2691},"3RhqaMQEBAQBdfHDQeoELF",{"json":2693},{"nodeType":1295,"data":2694,"content":2695},{},[2696,2703,2736,2743,2762,2769,2772,2780,2787,2793,2800,2806,2812,2819,2837,2843,2850,2853,2861,2881,2904,2911,2919,2926,2933,2939,2947,2967,2986,2992,2999,3005,3013,3046,3052,3059,3062,3070,3077,3097,3104,3110,3118,3125,3132,3139,3146,3218,3225,3233,3252,3258,3265,3272,3278,3285,3291,3299,3306,3312,3318,3325,3328,3336,3368,3375,3394,3401,3412,3419,3422,3430,3449],{"nodeType":1294,"data":2697,"content":2698},{},[2699],{"nodeType":1293,"value":2700,"marks":2701,"data":2702},"Phishing attacks using Attacker-in-the-Middle (AitM) kits are increasingly the default for both credential harvesting campaigns and targeted phishing attacks. It’s easy to see why, too:",[],{},{"nodeType":1401,"data":2704,"content":2705},{},[2706,2716,2726],{"nodeType":1405,"data":2707,"content":2708},{},[2709],{"nodeType":1294,"data":2710,"content":2711},{},[2712],{"nodeType":1293,"value":2713,"marks":2714,"data":2715},"They’re very difficult to spot as a user and often function like the real page should, logging the victim into the genuine site once the phish is complete",[],{},{"nodeType":1405,"data":2717,"content":2718},{},[2719],{"nodeType":1294,"data":2720,"content":2721},{},[2722],{"nodeType":1293,"value":2723,"marks":2724,"data":2725},"They’re incredibly scalable, and attackers have an increasing number of options to choose from when it comes to off-the-shelf tools and commercial Phishing-as-a-Service offerings ",[],{},{"nodeType":1405,"data":2727,"content":2728},{},[2729],{"nodeType":1294,"data":2730,"content":2731},{},[2732],{"nodeType":1293,"value":2733,"marks":2734,"data":2735},"And most importantly, they reliably bypass 99% of the MFA methods encountered in the wild, defeating OTP, SMS and push-based authentication",[],{},{"nodeType":1294,"data":2737,"content":2738},{},[2739],{"nodeType":1293,"value":2740,"marks":2741,"data":2742},"There are basically no downsides to AitM for an attacker. But all the same, they don’t get all that much publicity — probably because traditional phishing prevention solutions are failing to detect them (before the attack succeeds, anyway — and nobody really wants to own up to that). ",[],{},{"nodeType":1294,"data":2744,"content":2745},{},[2746,2750,2759],{"nodeType":1293,"value":2747,"marks":2748,"data":2749},"So, it’s refreshing to see Troy Hunt, creator of the widely used Have I Been Pwned (HIBP) service, ",[],{},{"nodeType":1337,"data":2751,"content":2753},{"uri":2752},"https://www.troyhunt.com/a-sneaky-phish-just-grabbed-my-mailchimp-mailing-list/",[2754],{"nodeType":1293,"value":2755,"marks":2756,"data":2758},"publicly discussing a recent attack he fell victim to",[2757],{"type":1345},{},{"nodeType":1293,"value":1348,"marks":2760,"data":2761},[],{},{"nodeType":1294,"data":2763,"content":2764},{},[2765],{"nodeType":1293,"value":2766,"marks":2767,"data":2768},"Before we consider the significance of Troy failing to spot the phish — the creator of one of the most widely used services for stolen passwords, working with government on phishing prevention guidance — let's start by breaking down the attack itself. ",[],{},{"nodeType":1382,"data":2770,"content":2771},{},[],{"nodeType":1322,"data":2773,"content":2774},{},[2775],{"nodeType":1293,"value":2776,"marks":2777,"data":2779},"What happened",[2778],{"type":1521},{},{"nodeType":1294,"data":2781,"content":2782},{},[2783],{"nodeType":1293,"value":2784,"marks":2785,"data":2786},"Troy received a phishing email appearing to be from MailChimp prompting him to sign into his account, with the lure informing him it had had been restricted due to a spam complaint",[],{},{"nodeType":1463,"data":2788,"content":2792},{"target":2789},{"sys":2790},{"id":2791,"type":1468,"linkType":1469},"5A4CPvTyKhClC8LgHY5916",[],{"nodeType":1294,"data":2794,"content":2795},{},[2796],{"nodeType":1293,"value":2797,"marks":2798,"data":2799},"The email matched Mailchimp’s brand, but the sender address was obviously suspicious. Unfortunately, Troy initially accessed the email via mobile, which hid the sender address — which he then missed when accessing from his PC. ",[],{},{"nodeType":1463,"data":2801,"content":2805},{"target":2802},{"sys":2803},{"id":2804,"type":1468,"linkType":1469},"1JWw4jO3qxxJeHO3qtMuZc",[],{"nodeType":1463,"data":2807,"content":2811},{"target":2808},{"sys":2809},{"id":2810,"type":1468,"linkType":1469},"1ebM2R90arTKlCmxmtvYjz",[],{"nodeType":1294,"data":2813,"content":2814},{},[2815],{"nodeType":1293,"value":2816,"marks":2817,"data":2818},"Troy was directed to the page hxxps://mailchimp-sso.com. Troy entered his credentials and MFA token and logged in. The page hung and he realized he had been phished…",[],{},{"nodeType":1294,"data":2820,"content":2821},{},[2822,2826,2834],{"nodeType":1293,"value":2823,"marks":2824,"data":2825},"The attack then automatically executed, with the attacker exporting 16,000 contact records from MailChimp and creating an API key to provide backdoor access to the app (a form of ",[],{},{"nodeType":1337,"data":2827,"content":2828},{"uri":1875},[2829],{"nodeType":1293,"value":2830,"marks":2831,"data":2833},"ghost login",[2832],{"type":1345},{},{"nodeType":1293,"value":1689,"marks":2835,"data":2836},[],{},{"nodeType":1463,"data":2838,"content":2842},{"target":2839},{"sys":2840},{"id":2841,"type":1468,"linkType":1469},"2MDWfQFU69GaiMCxdvvq8U",[],{"nodeType":1294,"data":2844,"content":2845},{},[2846],{"nodeType":1293,"value":2847,"marks":2848,"data":2849},"Let’s have a look at what makes this attack interesting. ",[],{},{"nodeType":1382,"data":2851,"content":2852},{},[],{"nodeType":1322,"data":2854,"content":2855},{},[2856],{"nodeType":1293,"value":2857,"marks":2858,"data":2860},"Breaking the attack down",[2859],{"type":1521},{},{"nodeType":1294,"data":2862,"content":2863},{},[2864,2868,2877],{"nodeType":1293,"value":2865,"marks":2866,"data":2867},"As far as ",[],{},{"nodeType":1337,"data":2869,"content":2871},{"uri":2870},"https://pushsecurity.com/blog/how-aitm-phishing-kits-evade-detection-p2/",[2872],{"nodeType":1293,"value":2873,"marks":2874,"data":2876},"some of the AitM attacks we’ve observed in the wild",[2875],{"type":1345},{},{"nodeType":1293,"value":2878,"marks":2879,"data":2880}," go, this wasn’t the most advanced example we’ve seen: ",[],{},{"nodeType":1401,"data":2882,"content":2883},{},[2884,2894],{"nodeType":1405,"data":2885,"content":2886},{},[2887],{"nodeType":1294,"data":2888,"content":2889},{},[2890],{"nodeType":1293,"value":2891,"marks":2892,"data":2893},"It didn’t try to obfuscate the notably suspicious sender address or use a legit SaaS service to give the email sender a reputable domain.",[],{},{"nodeType":1405,"data":2895,"content":2896},{},[2897],{"nodeType":1294,"data":2898,"content":2899},{},[2900],{"nodeType":1293,"value":2901,"marks":2902,"data":2903},"It didn’t see the victim access the real login page, and instead terminated the connection at the point the credentials were captured — meaning Troy was immediately suspicious (I guess it doesn’t really matter given the attack executed instantly, automatically).",[],{},{"nodeType":1294,"data":2905,"content":2906},{},[2907],{"nodeType":1293,"value":2908,"marks":2909,"data":2910},"That said, it did use a few interesting tricks and techniques. ",[],{},{"nodeType":1386,"data":2912,"content":2913},{},[2914],{"nodeType":1293,"value":2915,"marks":2916,"data":2918},"Enumerating suitable victims",[2917],{"type":1521},{},{"nodeType":1294,"data":2920,"content":2921},{},[2922],{"nodeType":1293,"value":2923,"marks":2924,"data":2925},"It’s notable that Troy claims the email he used to access MailChimp wasn’t used anywhere else — meaning the attacker probably guessed it. The domain is partially obscured here but it's likely that this is Troy’s own personal domain. It isn’t too much of a stretch to imagine that organizations frequently set up dedicated email addresses for their MailChimp accounts or newsletters generally (e.g. mailchimp@exampledomain.com). ",[],{},{"nodeType":1294,"data":2927,"content":2928},{},[2929],{"nodeType":1293,"value":2930,"marks":2931,"data":2932},"Undeniably, Troy’s MailChimp account is probably more of a target than most given the success of his newsletter, but it’s still likely that the attacker spammed many possible address and domain combinations to see what stuck. There’s a degree of luck, but also some smart guesswork at play here. ",[],{},{"nodeType":1463,"data":2934,"content":2938},{"target":2935},{"sys":2936},{"id":2937,"type":1468,"linkType":1469},"5TgXthj5tsvWX87QHZH1WQ",[],{"nodeType":1386,"data":2940,"content":2941},{},[2942],{"nodeType":1293,"value":2943,"marks":2944,"data":2946},"Using legit services like Cloudflare to defeat detections ",[2945],{"type":1521},{},{"nodeType":1294,"data":2948,"content":2949},{},[2950,2954,2963],{"nodeType":1293,"value":2951,"marks":2952,"data":2953},"The attacker used Cloudflare to host the domain, which is ",[],{},{"nodeType":1337,"data":2955,"content":2957},{"uri":2956},"https://pushsecurity.com/blog/how-aitm-phishing-kits-evade-detection/",[2958],{"nodeType":1293,"value":2959,"marks":2960,"data":2962},"consistent with what we’ve observed attackers doing in the wild",[2961],{"type":1345},{},{"nodeType":1293,"value":2964,"marks":2965,"data":2966},". Even if this means that Cloudflare will probably take the domain down eventually, they aren’t great at identifying the page right away. Given the rate at which attacker infrastructure is burned and rotated, the pros outweigh the cons for the attacker by giving the site legitimate hosting infrastructure, which can defeat some of the common checks performed by anti-phishing tools.",[],{},{"nodeType":1294,"data":2968,"content":2969},{},[2970,2974,2982],{"nodeType":1293,"value":2971,"marks":2972,"data":2973},"Troy also mentions seeing a 'Cloudflare anti-automation widget' when accessing the page, which is most likely Cloudflare Turnstile — a creative alternative to CAPTCHA to prevent security bots from accessing and loading malicious pages to analyse them. We've seen attackers use Turnstile ",[],{},{"nodeType":1337,"data":2975,"content":2976},{"uri":2956},[2977],{"nodeType":1293,"value":2978,"marks":2979,"data":2981},"along with a host of other obfuscation techniques",[2980],{"type":1345},{},{"nodeType":1293,"value":2983,"marks":2984,"data":2985}," to defeat common detections by preventing security tools from analysing the malicious page. ",[],{},{"nodeType":1463,"data":2987,"content":2991},{"target":2988},{"sys":2989},{"id":2990,"type":1468,"linkType":1469},"2X1r1qbE5CVcJ0xVcESGK7",[],{"nodeType":1294,"data":2993,"content":2994},{},[2995],{"nodeType":1293,"value":2996,"marks":2997,"data":2998},"Although this page has now been taken down, the campaign undoubtedly continues — another will have been rotated in to take its place. ",[],{},{"nodeType":1463,"data":3000,"content":3004},{"target":3001},{"sys":3002},{"id":3003,"type":1468,"linkType":1469},"26wnNFTED2f6O1HtqL3Cgu",[],{"nodeType":1386,"data":3006,"content":3007},{},[3008],{"nodeType":1293,"value":3009,"marks":3010,"data":3012},"Configuring ghost logins via API keys to backdoor the account ",[3011],{"type":1521},{},{"nodeType":1294,"data":3014,"content":3015},{},[3016,3020,3029,3033,3042],{"nodeType":1293,"value":3017,"marks":3018,"data":3019},"The attacker also configured an API key — a smart way to backdoor an app and something we’ve previously ",[],{},{"nodeType":1337,"data":3021,"content":3023},{"uri":3022},"https://pushsecurity.com/resources/phishing-detecting-evilginx-evilnovnc-muraena-and-modlishka",[3024],{"nodeType":1293,"value":3025,"marks":3026,"data":3028},"demonstrated in our webinars",[3027],{"type":1345},{},{"nodeType":1293,"value":3030,"marks":3031,"data":3032}," as a ",[],{},{"nodeType":1337,"data":3034,"content":3036},{"uri":3035},"https://github.com/pushsecurity/saas-attacks",[3037],{"nodeType":1293,"value":3038,"marks":3039,"data":3041},"SaaS-native attack technique",[3040],{"type":1345},{},{"nodeType":1293,"value":3043,"marks":3044,"data":3045}," for persistence. It means that even if the credentials are changed, the attacker can maintain access to the account.",[],{},{"nodeType":1463,"data":3047,"content":3051},{"target":3048},{"sys":3049},{"id":3050,"type":1468,"linkType":1469},"35GkKL1rXnWHNZa1EBHLyD",[],{"nodeType":1294,"data":3053,"content":3054},{},[3055],{"nodeType":1293,"value":3056,"marks":3057,"data":3058},"Now, as a security pro, Troy noticed this and deleted it — but many less technical victims wouldn’t know to do this. It’s also not unusual for automated emails from applications to go to spam — meaning some victims potentially wouldn’t spot the notification sent to them. ",[],{},{"nodeType":1382,"data":3060,"content":3061},{},[],{"nodeType":1322,"data":3063,"content":3064},{},[3065],{"nodeType":1293,"value":3066,"marks":3067,"data":3069},"But — why MailChimp? ",[3068],{"type":1521},{},{"nodeType":1294,"data":3071,"content":3072},{},[3073],{"nodeType":1293,"value":3074,"marks":3075,"data":3076},"This was the big question we asked ourselves when looking into this attack. Most phishing attacks targeting businesses tend to focus on core platforms like Microsoft, Google Workspace, etc. — usually Identity Providers (IdPs) that provide both access to email and downstream apps via SSO. It’s the biggest bang for their buck and most tooling is preconfigured to support these platforms. So MailChimp seems an unusual choice at first glance. ",[],{},{"nodeType":1294,"data":3078,"content":3079},{},[3080,3084,3093],{"nodeType":1293,"value":3081,"marks":3082,"data":3083},"But, we’ve seen recently that it's getting easier for attackers to ",[],{},{"nodeType":1337,"data":3085,"content":3087},{"uri":3086},"https://www.bleepingcomputer.com/news/security/darcula-phaas-can-now-auto-generate-phishing-kits-for-any-brand/",[3088],{"nodeType":1293,"value":3089,"marks":3090,"data":3092},"impersonate a broader range of brands",[3091],{"type":1345},{},{"nodeType":1293,"value":3094,"marks":3095,"data":3096},". And there’s something to be said for targeting an app like MailChimp — your guard is naturally probably lower than it would be for a Microsoft-based phish, increasing the chance of success. ",[],{},{"nodeType":1294,"data":3098,"content":3099},{},[3100],{"nodeType":1293,"value":3101,"marks":3102,"data":3103},"But what’s the payout? The data collected doesn’t seem to be overly valuable — 16k records including email address, IP, and rough geolocation data. Not particularly exploitable by itself…",[],{},{"nodeType":1463,"data":3105,"content":3109},{"target":3106},{"sys":3107},{"id":3108,"type":1468,"linkType":1469},"OjZtHXit6WO6Zd9tCUYpJ",[],{"nodeType":1386,"data":3111,"content":3112},{},[3113],{"nodeType":1293,"value":3114,"marks":3115,"data":3117},"Part of a multi stage attack? ",[3116],{"type":1521},{},{"nodeType":1294,"data":3119,"content":3120},{},[3121],{"nodeType":1293,"value":3122,"marks":3123,"data":3124},"This gets a lot more interesting when you consider the different things an attacker might do as part of a broader campaign. ",[],{},{"nodeType":1294,"data":3126,"content":3127},{},[3128],{"nodeType":1293,"value":3129,"marks":3130,"data":3131},"With access to MailChimp, an attacker can send emails on behalf of the compromised account. These emails are highly trusted and expected from the sender, meaning people receiving them are much more likely to engage with the content, click the links, etc. ",[],{},{"nodeType":1294,"data":3133,"content":3134},{},[3135],{"nodeType":1293,"value":3136,"marks":3137,"data":3138},"So what if an attacker compromised an account, inserted a load of malicious links into the newsletter, and used it in itself as a mass-phishing vector, designed to capture user credentials or deliver malware? Pretty devious! If you scale this up across multiple victims (and not all of them realize that they’ve been phished) you’ve suddenly got your hands on an incredibly valuable phishing vector that is much more likely to succeed than your average cold approach. ",[],{},{"nodeType":1294,"data":3140,"content":3141},{},[3142],{"nodeType":1293,"value":3143,"marks":3144,"data":3145},"Then, with the additional victims, you could target accounts that are much more inherently valuable to an attacker. You could:",[],{},{"nodeType":1401,"data":3147,"content":3148},{},[3149,3185,3208],{"nodeType":1405,"data":3150,"content":3151},{},[3152],{"nodeType":1294,"data":3153,"content":3154},{},[3155,3159,3168,3172,3181],{"nodeType":1293,"value":3156,"marks":3157,"data":3158},"Deploy infostealer malware, which has dominated the headlines since the success of the ",[],{},{"nodeType":1337,"data":3160,"content":3162},{"uri":3161},"https://pushsecurity.com/blog/snowflake-retro/",[3163],{"nodeType":1293,"value":3164,"marks":3165,"data":3167},"Snowflake",[3166],{"type":1345},{},{"nodeType":1293,"value":3169,"marks":3170,"data":3171}," attacks last year, and are continually resulting in data breaches via attackers logging into apps using stolen credentials such as the recent attacks on ",[],{},{"nodeType":1337,"data":3173,"content":3175},{"uri":3174},"https://pushsecurity.com/blog/why-attackers-are-targeting-jira-with-stolen-credentials/",[3176],{"nodeType":1293,"value":3177,"marks":3178,"data":3180},"Jira",[3179],{"type":1345},{},{"nodeType":1293,"value":3182,"marks":3183,"data":3184}," platforms.",[],{},{"nodeType":1405,"data":3186,"content":3187},{},[3188],{"nodeType":1294,"data":3189,"content":3190},{},[3191,3195,3204],{"nodeType":1293,"value":3192,"marks":3193,"data":3194},"Target personal apps for banking, email, e-com, and other easily monetizable services — which is increasingly easy to do at-scale using ",[],{},{"nodeType":1337,"data":3196,"content":3198},{"uri":3197},"https://www.bleepingcomputer.com/news/security/new-atlantis-aio-automates-credential-stuffing-on-140-services/",[3199],{"nodeType":1293,"value":3200,"marks":3201,"data":3203},"tooling for hire",[3202],{"type":1345},{},{"nodeType":1293,"value":3205,"marks":3206,"data":3207}," with stolen credentials.",[],{},{"nodeType":1405,"data":3209,"content":3210},{},[3211],{"nodeType":1294,"data":3212,"content":3213},{},[3214],{"nodeType":1293,"value":3215,"marks":3216,"data":3217},"Even attempt to deploy ransomware and other malicious software to progress an attack on user devices and networks (a pretty relevant use case for the many subscribers of Troy’s newsletter accessing it on their corporate device!).",[],{},{"nodeType":1294,"data":3219,"content":3220},{},[3221],{"nodeType":1293,"value":3222,"marks":3223,"data":3224},"Even grabbing the list of newsletter sign-ups could enable the attacker to perform this attack from a different MailChimp account, so anyone subscribed to Troy’s newsletter should be wary of emails impersonating Troy’s newsletter reaching them from a different sender address than usual. ",[],{},{"nodeType":1386,"data":3226,"content":3227},{},[3228],{"nodeType":1293,"value":3229,"marks":3230,"data":3232},"Account security limitations",[3231],{"type":1521},{},{"nodeType":1294,"data":3234,"content":3235},{},[3236,3240,3248],{"nodeType":1293,"value":3237,"marks":3238,"data":3239},"On the theme of MailChimp, it’s also notable that MailChimp doesn’t appear to offer SAML support. ",[],{},{"nodeType":1337,"data":3241,"content":3243},{"uri":3242},"https://www.okta.com/integrations/mailchimp/",[3244],{"nodeType":1293,"value":3245,"marks":3246,"data":3247},"Okta lists the app as only available for SWA",[],{},{"nodeType":1293,"value":3249,"marks":3250,"data":3251}," (where separate credentials are created to access the app, managed through Okta — more like a password manager than genuine SSO via SAML or OIDC).",[],{},{"nodeType":1463,"data":3253,"content":3257},{"target":3254},{"sys":3255},{"id":3256,"type":1468,"linkType":1469},"7b4RZhUIqJMF1OxmyR0qKH",[],{"nodeType":1294,"data":3259,"content":3260},{},[3261],{"nodeType":1293,"value":3262,"marks":3263,"data":3264},"This means you’re forced to use a username and password. Your only SSO option is to sign in with Google — which many non-Google Workspace users may not have access to. ",[],{},{"nodeType":1294,"data":3266,"content":3267},{},[3268],{"nodeType":1293,"value":3269,"marks":3270,"data":3271},"As Troy points out, MailChimp also fails to offer support for phishing-resistant MFA. This is pretty typical (if disappointing) for the long tail of SaaS apps, which typically leave WebAuthn / passkey support to the IdP. Except in this case, support for SSO in general is limited, meaning you can only use passkeys if you’re logging in with Google. ",[],{},{"nodeType":1463,"data":3273,"content":3277},{"target":3274},{"sys":3275},{"id":3276,"type":1468,"linkType":1469},"2lT7fBiOq4JxpMxSLrdUOv",[],{"nodeType":1294,"data":3279,"content":3280},{},[3281],{"nodeType":1293,"value":3282,"marks":3283,"data":3284},"So it’s possible that attackers have noticed that accounts in MailChimp are far more likely to have insecure accounts than other traditional phishing targets — simply because they cannot be configured as securely. ",[],{},{"nodeType":1463,"data":3286,"content":3290},{"target":3287},{"sys":3288},{"id":3289,"type":1468,"linkType":1469},"30APqb65kzTA4ySWJIkxGh",[],{"nodeType":1386,"data":3292,"content":3293},{},[3294],{"nodeType":1293,"value":3295,"marks":3296,"data":3298},"It might not just be MailChimp",[3297],{"type":1521},{},{"nodeType":1294,"data":3300,"content":3301},{},[3302],{"nodeType":1293,"value":3303,"marks":3304,"data":3305},"It looks like the same attackers have previously targeted ActiveCampaign, a marketing email and automation platform, based on GitHub comments from December. A domain previously flagged as malicious relating to ActiveCampaign currently redirects to the malicious MailChimp domain seen in Troy’s attack.",[],{},{"nodeType":1463,"data":3307,"content":3311},{"target":3308},{"sys":3309},{"id":3310,"type":1468,"linkType":1469},"7M8W9vAYdqPN8NMU8Ug7jq",[],{"nodeType":1463,"data":3313,"content":3317},{"target":3314},{"sys":3315},{"id":3316,"type":1468,"linkType":1469},"7CJfZwc9BpzIL7Fma1Y6o1",[],{"nodeType":1294,"data":3319,"content":3320},{},[3321],{"nodeType":1293,"value":3322,"marks":3323,"data":3324},"This could point to a broader campaign targeting similar SaaS platforms for marketing automation and email distribution.",[],{},{"nodeType":1382,"data":3326,"content":3327},{},[],{"nodeType":1322,"data":3329,"content":3330},{},[3331],{"nodeType":1293,"value":3332,"marks":3333,"data":3335},"Closing thoughts",[3334],{"type":1521},{},{"nodeType":1294,"data":3337,"content":3338},{},[3339,3343,3351,3355,3364],{"nodeType":1293,"value":3340,"marks":3341,"data":3342},"MailChimp might seem an unusual target but there are a lot of ways that attackers can abuse SaaS services, as we’ve discussed at length in our public research with the ",[],{},{"nodeType":1337,"data":3344,"content":3345},{"uri":3035},[3346],{"nodeType":1293,"value":3347,"marks":3348,"data":3350},"SaaS attacks matrix",[3349],{"type":1345},{},{"nodeType":1293,"value":3352,"marks":3353,"data":3354}," and ",[],{},{"nodeType":1337,"data":3356,"content":3358},{"uri":3357},"https://pushsecurity.com/resources/",[3359],{"nodeType":1293,"value":3360,"marks":3361,"data":3363},"many webinars and conference talks",[3362],{"type":1345},{},{"nodeType":1293,"value":3365,"marks":3366,"data":3367},". Account takeover through modern phishing attacks like the one we've analysed here is key to unlocking this attack surface. ",[],{},{"nodeType":1294,"data":3369,"content":3370},{},[3371],{"nodeType":1293,"value":3372,"marks":3373,"data":3374},"While the vast majority of phishing attacks that we observe do focus on core platforms like Microsoft, Google Workspace and Okta, it makes sense that attackers are broadening their focus to take advantage of the fact that phishing targeting these accounts is less obviously a target, and these accounts are often much less securely configured. But there are many ways to target the interconnected ecosystem of SaaS apps in creative ways that most organizations (and users) are seriously underprepared for. ",[],{},{"nodeType":1294,"data":3376,"content":3377},{},[3378,3382,3390],{"nodeType":1293,"value":3379,"marks":3380,"data":3381},"Attackers have been targeting consumers and individuals via their sprawl of internet apps for some time — are more business-focused threat groups waking up to the opportunity of targeting SaaS? After all, it’s a ",[],{},{"nodeType":1337,"data":3383,"content":3384},{"uri":2127},[3385],{"nodeType":1293,"value":3386,"marks":3387,"data":3389},"great way to evade established controls elsewhere on the network and endpoints",[3388],{"type":1345},{},{"nodeType":1293,"value":3391,"marks":3392,"data":3393},", and you can achieve your objectives simply by logging in to (often weakly secured) user accounts.  ",[],{},{"nodeType":1294,"data":3395,"content":3396},{},[3397],{"nodeType":1293,"value":3398,"marks":3399,"data":3400},"The moral of the story? Phishing attacks are getting pretty sophisticated (and often much more sophisticated than this). Even security pros get phished sometimes!",[],{},{"nodeType":1781,"data":3402,"content":3403},{},[3404],{"nodeType":1294,"data":3405,"content":3406},{},[3407],{"nodeType":1293,"value":3408,"marks":3409,"data":3411},"This is clear indicator that we need stronger technical controls to prevent phishing. If even someone like Troy can be phished, the only reasonable conclusion is that humans will always be susceptible to phishing, no matter how much awareness training they receive. ",[3410],{"type":1521},{},{"nodeType":1294,"data":3413,"content":3414},{},[3415],{"nodeType":1293,"value":3416,"marks":3417,"data":3418},"A big thanks to Troy for sharing his write-up of the incident!",[],{},{"nodeType":1382,"data":3420,"content":3421},{},[],{"nodeType":1322,"data":3423,"content":3424},{},[3425],{"nodeType":1293,"value":3426,"marks":3427,"data":3429},"How Push can help",[3428],{"type":1521},{},{"nodeType":1294,"data":3431,"content":3432},{},[3433,3437,3446],{"nodeType":1293,"value":3434,"marks":3435,"data":3436},"Push takes a unique browser-based approach to detecting and intercepting phishing attacks that overcomes many of the tricks and techniques attackers use to defeat conventional anti-phishing controls. To learn more, ",[],{},{"nodeType":1337,"data":3438,"content":3440},{"uri":3439},"https://pushsecurity.com/blog/why-its-time-for-phishing-prevention-to-move-beyond-email/",[3441],{"nodeType":1293,"value":3442,"marks":3443,"data":3445},"check out our recent blog post",[3444],{"type":1345},{},{"nodeType":1293,"value":1348,"marks":3447,"data":3448},[],{},{"nodeType":1294,"data":3450,"content":3451},{},[3452,3456,3463],{"nodeType":1293,"value":3453,"marks":3454,"data":3455},"And if you want to see how Push helps you to detect and defeat common identity attack techniques like AiTM phishing, credential stuffing, and session hijacking while improving your workforce identity posture, book some time with one of our team for a ",[],{},{"nodeType":1337,"data":3457,"content":3458},{"uri":1624},[3459],{"nodeType":1293,"value":2662,"marks":3460,"data":3462},[3461],{"type":1345},{},{"nodeType":1293,"value":2667,"marks":3464,"data":3465},[],{},"Dissecting a recent MailChimp phishing attack","HIBP creator and well-known security person Troy Hunt recently blogged about a phish he fell for. Here’s what it tells us about how phishing is evolving. ","2025-03-28T00:00:00.000Z","dissecting-a-recent-mailchimp-phishing-attack",{"items":3471},[3472,3474],{"sys":3473,"name":1306},{"id":1305},{"sys":3475,"name":1310},{"id":1309},{"items":3477},[3478],{"fullName":3479,"firstName":3480,"jobTitle":3481,"profilePicture":3482},"Dan Green","Dan","Threat Research",{"url":3483},"https://images.ctfassets.net/y1cdw1ablpvd/7jik1VhFgA3kgzXBXTm2Vw/fcd8c171da644903d0827eafcfbcaad0/Dan_Headshot_2025.png",{"items":3485},[3486],{"fullName":3479,"firstName":3480,"jobTitle":3481,"profilePicture":3487},{"url":3483},{"json":3489,"links":3929},{"data":3490,"content":3491,"nodeType":1295},{},[3492,3523,3543,3550,3557,3560,3568,3575,3581,3587,3593,3600,3620,3626,3629,3637,3644,3651,3658,3664,3671,3678,3684,3691,3710,3716,3723,3726,3734,3741,3747,3754,3799,3805,3812,3815,3823,3830,3837,3843,3849,3855,3858,3866,3873,3879,3886,3893,3896,3903,3910],{"data":3493,"content":3494,"nodeType":1294},{},[3495,3498,3507,3511,3519],{"data":3496,"marks":3497,"value":37,"nodeType":1293},{},[],{"data":3499,"content":3501,"nodeType":1337},{"uri":3500},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/consent_phishing/description.md",[3502],{"data":3503,"marks":3504,"value":3506,"nodeType":1293},{},[3505],{"type":1345},"Consent phishing",{"data":3508,"marks":3509,"value":3510,"nodeType":1293},{},[]," was one of the first techniques we added to the ",{"data":3512,"content":3514,"nodeType":1337},{"uri":3513},"https://github.com/pushsecurity/saas-attacks?tab=readme-ov-file",[3515],{"data":3516,"marks":3517,"value":3347,"nodeType":1293},{},[3518],{"type":1345},{"data":3520,"marks":3521,"value":3522,"nodeType":1293},{},[],", where attackers trick users into authorizing malicious OAuth apps. ",{"data":3524,"content":3525,"nodeType":1294},{},[3526,3530,3539],{"data":3527,"marks":3528,"value":3529,"nodeType":1293},{},[],"The attacker sends a phishing link to a target that requests permissions to access sensitive data or permissions to perform dangerous actions for an app the victim is using. If the target grants consent for the permissions, the adversary gains that level of access over the target’s account — and certain data and functionality ",{"data":3531,"content":3533,"nodeType":1337},{"uri":3532},"https://pushsecurity.com/blog/the-risky-terrain-of-oauth-scopes-in-third-party/",[3534],{"data":3535,"marks":3536,"value":3538,"nodeType":1293},{},[3537],{"type":1345},"depending on the scopes granted",{"data":3540,"marks":3541,"value":3542,"nodeType":1293},{},[],". This attack bypasses MFA entirely (including phishing-resistant MFA) by sidestepping the login process — think of it as an authorization attack, as opposed to an authentication one. Naturally, this means it also persists through typical authentication changes like a password reset. ",{"data":3544,"content":3545,"nodeType":1294},{},[3546],{"data":3547,"marks":3548,"value":3549,"nodeType":1293},{},[],"Consent phishing has been primarily aimed at getting access to larger cloud platforms like Microsoft Azure or Google Workspace tenants, or more complex apps like GitHub. These apps present an obvious opportunity to attackers in terms of the functionality and and data they contain.  ",{"data":3551,"content":3552,"nodeType":1294},{},[3553],{"data":3554,"marks":3555,"value":3556,"nodeType":1293},{},[],"Two separate cases of consent phishing have hit the headlines this month representing very different use cases — let’s compare them. ",{"data":3558,"content":3559,"nodeType":1382},{},[],{"data":3561,"content":3562,"nodeType":1322},{},[3563],{"data":3564,"marks":3565,"value":3567,"nodeType":1293},{},[3566],{"type":1521},"1. Classic consent phishing",{"data":3569,"content":3570,"nodeType":1294},{},[3571],{"data":3572,"marks":3573,"value":3574,"nodeType":1293},{},[],"Attackers targeted GitHub users across 12,000 repositories by creating fake security alert issues in GitHub repositories. These legit-looking alerts send the victim to a GitHub authorization page for a \"gitsecurityapp\" OAuth app that requests a lot of very risky scopes granting full access to a user's account and repositories.",{"data":3576,"content":3580,"nodeType":1463},{"target":3577},{"sys":3578},{"id":3579,"type":1468,"linkType":1469},"7s7VLePAQzhzXJ6cFkSCAe",[],{"data":3582,"content":3586,"nodeType":1463},{"target":3583},{"sys":3584},{"id":3585,"type":1468,"linkType":1469},"5dppSzNOgffeZTZK2lG6V5",[],{"data":3588,"content":3592,"nodeType":1463},{"target":3589},{"sys":3590},{"id":3591,"type":1468,"linkType":1469},"1dsYU7bM5mPW1AXyRLnqpp",[],{"data":3594,"content":3595,"nodeType":1294},{},[3596],{"data":3597,"marks":3598,"value":3599,"nodeType":1293},{},[],"Once authorized, the attacker has extensive access to the account, from which point they can modify repositories to conduct further attacks against users (e.g. by infecting them with malware), poison the repos and services connected to the repository, and exfiltrate any sensitive data the account has access to. ",{"data":3601,"content":3602,"nodeType":1294},{},[3603,3607,3616],{"data":3604,"marks":3605,"value":3606,"nodeType":1293},{},[],"Alongside consent phishing, this is an example of ",{"data":3608,"content":3610,"nodeType":1337},{"uri":3609},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/in-app_phishing/description.md",[3611],{"data":3612,"marks":3613,"value":3615,"nodeType":1293},{},[3614],{"type":1345},"in-app phishing",{"data":3617,"marks":3618,"value":3619,"nodeType":1293},{},[],", which avoids delivering the message via corporate email. Even if the target gets an email notification, the phish isn’t delivered via email directly, and so email-based scanning solutions won’t detect it — they’ll receive a legitimate notification email directly from GitHub. It’s also less likely to raise suspicion as GitHub issue notifications are expected, increasing the click chance. ",{"data":3621,"content":3625,"nodeType":1463},{"target":3622},{"sys":3623},{"id":3624,"type":1468,"linkType":1469},"6d6MMyPQ7vaY2KrJTHGeO6",[],{"data":3627,"content":3628,"nodeType":1382},{},[],{"data":3630,"content":3631,"nodeType":1322},{},[3632],{"data":3633,"marks":3634,"value":3636,"nodeType":1293},{},[3635],{"type":1521},"2. Not really consent phishing?",{"data":3638,"content":3639,"nodeType":1294},{},[3640],{"data":3641,"marks":3642,"value":3643,"nodeType":1293},{},[],"This example is much more unusual. In this case, the attacker used malicious Microsoft OAuth apps impersonating Adobe and DocuSign. ",{"data":3645,"content":3646,"nodeType":1294},{},[3647],{"data":3648,"marks":3649,"value":3650,"nodeType":1293},{},[],"Rather than trying to grab lots of juicy permissions for Microsoft, the attacker used consent phishing to prevent automated analysis of their phishing page by security tools. To be served the real phishing page, you need to first authorize the fake OAuth app — meaning that security tools and bots won’t be able to reach the page to determine if it’s malicious or not. ",{"data":3652,"content":3653,"nodeType":1294},{},[3654],{"data":3655,"marks":3656,"value":3657,"nodeType":1293},{},[],"The attack started with attackers sending phishing emails to target users with a fake password reset lure. ",{"data":3659,"content":3663,"nodeType":1463},{"target":3660},{"sys":3661},{"id":3662,"type":1468,"linkType":1469},"3cLd6EbraN9fKuGgL0kkgC",[],{"data":3665,"content":3666,"nodeType":1294},{},[3667],{"data":3668,"marks":3669,"value":3670,"nodeType":1293},{},[],"Because the initial phishing link directs to the legitimate login.microsoftonline.com URL, it appears legitimate and bypasses common domain-based security checks. ",{"data":3672,"content":3673,"nodeType":1294},{},[3674],{"data":3675,"marks":3676,"value":3677,"nodeType":1293},{},[],"After clicking the link, the user signs into their real Microsoft account (this might even happen automatically if the user is already signed in on the device/browser they’re using). They are then redirected to a permissions request page for the fake OAuth app. ",{"data":3679,"content":3683,"nodeType":1463},{"target":3680},{"sys":3681},{"id":3682,"type":1468,"linkType":1469},"6O4CSx1VCoPAIjjsnKzu75",[],{"data":3685,"content":3686,"nodeType":1294},{},[3687],{"data":3688,"marks":3689,"value":3690,"nodeType":1293},{},[],"The permissions requested by the app (profile, email, openid) are so limited as to be basically unexploitable. They are also the same permissions you would accept if you were authorizing Microsoft to perform a social login (SSO via OIDC) to a third party app.",{"data":3692,"content":3693,"nodeType":1294},{},[3694,3698,3706],{"data":3695,"marks":3696,"value":3697,"nodeType":1293},{},[],"Clicking the link redirects the victim to the malicious page but masks it using the legit Cloudflare Turnstile service. As well as making the page look more credible (since its fronted by a legit service to block bots) this is a common detection evasion technique we’ve ",{"data":3699,"content":3700,"nodeType":1337},{"uri":2956},[3701],{"data":3702,"marks":3703,"value":3705,"nodeType":1293},{},[3704],{"type":1345},"blogged about previously",{"data":3707,"marks":3708,"value":3709,"nodeType":1293},{},[]," which prevents security solutions from accessing and analysing the malicious page. ",{"data":3711,"content":3715,"nodeType":1463},{"target":3712},{"sys":3713},{"id":3714,"type":1468,"linkType":1469},"7csybR6fJlCWsRy91CbNYL",[],{"data":3717,"content":3718,"nodeType":1294},{},[3719],{"data":3720,"marks":3721,"value":3722,"nodeType":1293},{},[],"After completing the verification, the page (and the malicious phishing kit element) is finally loaded. If the victim authenticates, the session will be stolen by the attacker, along with the captured credentials and MFA code. ",{"data":3724,"content":3725,"nodeType":1382},{},[],{"data":3727,"content":3728,"nodeType":1322},{},[3729],{"data":3730,"marks":3731,"value":3733,"nodeType":1293},{},[3732],{"type":1521},"Using consent phishing to evade detection",{"data":3735,"content":3736,"nodeType":1294},{},[3737],{"data":3738,"marks":3739,"value":3740,"nodeType":1293},{},[],"The attacker is essentially using their fake OAuth app to prevent security analysts and bots from analysing the real phishing page, because the first page loaded is a link to a legitimate Microsoft domain. They’re also layering it with a range of other detection evasion techniques like using Cloudflare Turnstile.  ",{"data":3742,"content":3746,"nodeType":1463},{"target":3743},{"sys":3744},{"id":3745,"type":1468,"linkType":1469},"4Bi9YoMwWVmKoWfkh5tiTA",[],{"data":3748,"content":3749,"nodeType":1294},{},[3750],{"data":3751,"marks":3752,"value":3753,"nodeType":1293},{},[],"We’ve previously blogged about how attackers are using layered detection evasion techniques to circumvent typical phishing page detections, which are often email-based, including:",{"data":3755,"content":3756,"nodeType":1401},{},[3757,3778],{"data":3758,"content":3759,"nodeType":1405},{},[3760],{"data":3761,"content":3762,"nodeType":1294},{},[3763,3766,3774],{"data":3764,"marks":3765,"value":37,"nodeType":1293},{},[],{"data":3767,"content":3768,"nodeType":1337},{"uri":2956},[3769],{"data":3770,"marks":3771,"value":3773,"nodeType":1293},{},[3772],{"type":1345},"Prevent analysis of phishing pages",{"data":3775,"marks":3776,"value":3777,"nodeType":1293},{},[]," by security bots, including using legitimate services like Cloudflare Workers and Turnstile (as above), CAPTCHA, and various sandbox-aware techniques to ensure only the intended victim is served the phishing page, such as only providing the correct parameters to load the page if the correct path is followed (rather than attempting to load the malicious page by going directly to the domain). ",{"data":3779,"content":3780,"nodeType":1405},{},[3781],{"data":3782,"content":3783,"nodeType":1294},{},[3784,3787,3795],{"data":3785,"marks":3786,"value":37,"nodeType":1293},{},[],{"data":3788,"content":3789,"nodeType":1337},{"uri":2870},[3790],{"data":3791,"marks":3792,"value":3794,"nodeType":1293},{},[3793],{"type":1345},"DOM and visual obfuscation",{"data":3796,"marks":3797,"value":3798,"nodeType":1293},{},[]," of phishing pages when the victim does land on the page to prevent it from being identified as malicious through signature-based detection of page elements. ",{"data":3800,"content":3804,"nodeType":1463},{"target":3801},{"sys":3802},{"id":3803,"type":1468,"linkType":1469},"2dN8np5odBecf7r1vBr69K",[],{"data":3806,"content":3807,"nodeType":1294},{},[3808],{"data":3809,"marks":3810,"value":3811,"nodeType":1293},{},[],"This seems a bit overkill and many of the steps here are likely to raise suspicion — like the fact that you’re never asked to provide the original code for the password reset, and are asked to unexpectedly consent to an OAuth app. But clearly, the attacker is more concerned about bypassing technical safeguards than human ones (not a great endorsement for the state of phishing awareness training). ",{"data":3813,"content":3814,"nodeType":1382},{},[],{"data":3816,"content":3817,"nodeType":1322},{},[3818],{"data":3819,"marks":3820,"value":3822,"nodeType":1293},{},[3821],{"type":1521},"How Push detects and blocks phishing attacks",{"data":3824,"content":3825,"nodeType":1294},{},[3826],{"data":3827,"marks":3828,"value":3829,"nodeType":1293},{},[],"Push overcomes the various detection evasion techniques shown here by using in-browser detections based on the phishing page that the user sees. This means that no matter where the user accesses the link from (email, IM platform, social media, or anywhere else on the internet) Push can observe and analyse the page to determine if it's malicious. ",{"data":3831,"content":3832,"nodeType":1294},{},[3833],{"data":3834,"marks":3835,"value":3836,"nodeType":1293},{},[],"Push uses layered detections based on identifying the phishing kit running on the page itself, whether the page is cloned from a legitimate login page, as well as detecting whether the credentials being entered on the page have been used to log into your SSO account previously. ",{"data":3838,"content":3842,"nodeType":1463},{"target":3839},{"sys":3840},{"id":3841,"type":1468,"linkType":1469},"6B1toQAf44rDzQZijYRd9g",[],{"data":3844,"content":3848,"nodeType":1463},{"target":3845},{"sys":3846},{"id":3847,"type":1468,"linkType":1469},"4ixcEsEW4EyqckOTmP5Pbb",[],{"data":3850,"content":3854,"nodeType":1463},{"target":3851},{"sys":3852},{"id":3853,"type":1468,"linkType":1469},"01musWa3FUiO0CVFNWfwcy",[],{"data":3856,"content":3857,"nodeType":1382},{},[],{"data":3859,"content":3860,"nodeType":1322},{},[3861],{"data":3862,"marks":3863,"value":3865,"nodeType":1293},{},[3864],{"type":1521},"Using Push to review OAuth integrations",{"data":3867,"content":3868,"nodeType":1294},{},[3869],{"data":3870,"marks":3871,"value":3872,"nodeType":1293},{},[],"You can also use Push to discover and remove risky OAuth integrations accepted by your users. ",{"data":3874,"content":3878,"nodeType":1463},{"target":3875},{"sys":3876},{"id":3877,"type":1468,"linkType":1469},"5kJvy5SBcWLrK2EhLyR1ZD",[],{"data":3880,"content":3881,"nodeType":1294},{},[3882],{"data":3883,"marks":3884,"value":3885,"nodeType":1293},{},[],"This shows which OAuth apps have been added, which apps they are integrated with, what permissions they’ve been granted, as well as other properties that indicate risk (e.g. whether the app’s publisher has been verified). ",{"data":3887,"content":3888,"nodeType":1294},{},[3889],{"data":3890,"marks":3891,"value":3892,"nodeType":1293},{},[],"If your users are consent phished, you’ll be notified via webhook event that a new integration has been added. These risky integrations can be removed via the Push platform by clicking ‘delete integration’. ",{"data":3894,"content":3895,"nodeType":1382},{},[],{"data":3897,"content":3898,"nodeType":1322},{},[3899],{"data":3900,"marks":3901,"value":1612,"nodeType":1293},{},[3902],{"type":1521},{"data":3904,"content":3905,"nodeType":1294},{},[3906],{"data":3907,"marks":3908,"value":3909,"nodeType":1293},{},[],"It doesn’t stop there — Push provides comprehensive identity attack detection and response capabilities against techniques like credential stuffing, password spraying and session hijacking using stolen session tokens. You can also use Push to find and fix identity vulnerabilities across every app that your employees use like: ghost logins; SSO coverage gaps; MFA gaps; weak, breached and reused passwords; risky OAuth integrations; and more. ",{"data":3911,"content":3912,"nodeType":1294},{},[3913,3917,3925],{"data":3914,"marks":3915,"value":3916,"nodeType":1293},{},[],"If you want to learn more about how Push helps you to detect and defeat common identity attack techniques, ",{"data":3918,"content":3920,"nodeType":1337},{"uri":3919},"https://pushsecurity.com/demo?utm_campaign=9983377-FY25Q1_Bleeping-Computer-Organic-Article&utm_source=bleepingcomputer&utm_medium=sponsored-content&utm_content=organic%20article",[3921],{"data":3922,"marks":3923,"value":1627,"nodeType":1293},{},[3924],{"type":1345},{"data":3926,"marks":3927,"value":3928,"nodeType":1293},{},[]," for a live demo.",{"entries":3930},{"hyperlink":3931,"inline":3932,"block":3933},[],[],[3934,3943,3951,3959,3966,3974,3981,3989,3997,4004,4012,4020,4043],{"sys":3935,"__typename":3936,"title":3937,"caption":3938,"layoutMode":118,"file":3939},{"id":3579},"Image","Consent phishing blog image 1","Initial notification in GitHub repo",{"url":3940,"width":3941,"height":3942},"https://images.ctfassets.net/y1cdw1ablpvd/45AWiiVZDMMx4wkVeh4OmH/e043c8d9975ad87c354c60ed2b95f3d8/image11_1.png",1145,520,{"sys":3944,"__typename":3936,"title":3945,"caption":3946,"layoutMode":118,"file":3947},{"id":3585},"Consent phishing image 2","Phishing message delivered via GitHub",{"url":3948,"width":3949,"height":3950},"https://images.ctfassets.net/y1cdw1ablpvd/5SF3XeGhHBxwDX8WamgdOI/66abad1b2770344e360c276c33528129/image_506.png",1372,1045,{"sys":3952,"__typename":3936,"title":3953,"caption":3954,"layoutMode":118,"file":3955},{"id":3591},"Consent phishing image 3","Consent phishing authorization page connecting the victim's GitHub account to the malicious app",{"url":3956,"width":3957,"height":3958},"https://images.ctfassets.net/y1cdw1ablpvd/2NfxL5bELb1XbET7MubvGN/e47630f6d0a3c85c3f2c567c4e443a0c/image1.png",1600,1065,{"sys":3960,"__typename":3961,"type":3962,"ctaText":3963,"buttonLabel":3964,"buttonColour":3965,"buttonUrl":3439},{"id":3624},"CtaWidget","Custom","Learn why phishing prevention needs to move beyond email to stop modern attacks taking place inside apps, IM platforms, via malvertising, and on social media.","Read the Blog","sunny orange",{"sys":3967,"__typename":3936,"title":3968,"caption":3969,"layoutMode":118,"file":3970},{"id":3662},"Consent phishing image 4","Phishing email prompting the user to reset their password",{"url":3971,"width":3972,"height":3973},"https://images.ctfassets.net/y1cdw1ablpvd/7z6EOVPvvj2gxyafDubSEa/fc4ad4cd51af2da38478313fe991f445/Group_524.png",997,544,{"sys":3975,"__typename":3936,"title":3976,"caption":3977,"layoutMode":118,"file":3978},{"id":3682},"Consent phishing image 5","OAuth apps impersonating Adobe and DocuSign",{"url":3979,"width":3957,"height":3980},"https://images.ctfassets.net/y1cdw1ablpvd/maxSjZ6EyNf0ZL9tgcUBU/3d6da51a409fd1273b576ebc9b132703/image2.png",629,{"sys":3982,"__typename":3936,"title":3983,"caption":3984,"layoutMode":118,"file":3985},{"id":3714},"Consent phishing blog image 6","Cloudflare Turnstile is often used to prevent security bots from analysing the attacker's phishing page.",{"url":3986,"width":3987,"height":3988},"https://images.ctfassets.net/y1cdw1ablpvd/DbEYzQt7m3jY56ALCYWEy/59846e7bd4a3ed204722a9d561e97231/image2.png",938,361,{"sys":3990,"__typename":3936,"title":3991,"caption":3992,"layoutMode":118,"file":3993},{"id":3745},"Consent phishing image 8","Summary of the attack path",{"url":3994,"width":3995,"height":3996},"https://images.ctfassets.net/y1cdw1ablpvd/6aWw8YdAR2WFHvFlTeshsQ/76236f4031c3d921cd1cd00887ce0e90/Slide_16_9_-_110.png",1920,649,{"sys":3998,"__typename":3936,"title":3999,"caption":3999,"layoutMode":118,"file":4000},{"id":3803},"Comparing a legitimate page’s DOM structure with an attacker’s cloned page",{"url":4001,"width":4002,"height":4003},"https://images.ctfassets.net/y1cdw1ablpvd/4HmklQ1H0YIMlNdTkZR8B0/e2e727d9d96867b9d46e35bf097f7a0f/6.png",1875,562,{"sys":4005,"__typename":3936,"title":4006,"caption":4007,"layoutMode":118,"file":4008},{"id":3841},"How Push stops phishing attacks","Push detects and intercepts phishing attackers in the browser when the victim tries to load the page. ",{"url":4009,"width":4010,"height":4011},"https://images.ctfassets.net/y1cdw1ablpvd/2CPV9LSQGHdFgmTxyF1c6s/c1ddb7eb7352ad7a161e447a8fa400e6/image1.png",1535,764,{"sys":4013,"__typename":3936,"title":4014,"caption":4015,"layoutMode":118,"file":4016},{"id":3847},"Phishing toolkit detection","Accessing pages running malicious phishing toolkits is automatically blocked. ",{"url":4017,"width":4018,"height":4019},"https://images.ctfassets.net/y1cdw1ablpvd/3ylgW0MDCCesBjQsoqjD4P/a8bc4df9a430aca6c725f913d2bc6444/image11.png",1440,767,{"sys":4021,"__typename":4022,"content":4023,"name":4042,"title":118},{"id":3853},"InsightTextBlockComponent",{"json":4024},{"nodeType":1295,"data":4025,"content":4026},{},[4027,4034],{"nodeType":1294,"data":4028,"content":4029},{},[4030],{"nodeType":1293,"value":4031,"marks":4032,"data":4033},"By fingerprinting the password for your most important accounts used to log into IdPs like Microsoft, Google, Okta, etc. Push can prevent users from entering this password into any other page. So for example, if the user attempts to enter their real Microsoft password onto a phishing page, Push detects and intercepts it, blocking the phishing attempt. ",[],{},{"nodeType":1294,"data":4035,"content":4036},{},[4037],{"nodeType":1293,"value":4038,"marks":4039,"data":4041},"You can’t phish a victim if they can’t enter their credentials into your phishing site!",[4040],{"type":1521},{},"Consent phishing blog insight box 1",{"sys":4044,"__typename":3936,"title":4045,"caption":4046,"layoutMode":118,"file":4047},{"id":3877},"Consent phishing blog image 7","Using Push to analyze and manage OAuth integrations detected in your environment. ",{"url":4048,"width":4049,"height":4050},"https://images.ctfassets.net/y1cdw1ablpvd/37VWcMZobEQXskI8lbfadH/8d771afb2d57258f16c542517b910d72/image10.png",1999,1111,"content:blog:how-consent-phishing-is-evolving.json","json","content","blog/how-consent-phishing-is-evolving.json","blog/how-consent-phishing-is-evolving",1776359985145]