[{"data":1,"prerenderedAt":3818},["ShallowReactive",2],{"application-flags":3,"navbar":7,"always-visible-banner":95,"navbar-about-highlight":155,"navbar-resource-highlight":211,"use-case-page":256,"blog/key-takeaways-from-the-scattered-spider-attacks-on-insurance-firms":1276},[4],{"name":5,"enabled":6},"maintenanceMode",false,[8,59,76],{"createdDate":9,"id":10,"name":11,"modelId":12,"published":13,"stageModifiedSincePublish":6,"query":14,"data":15,"variations":50,"lastUpdated":51,"firstPublished":52,"testRatio":33,"createdBy":53,"lastUpdatedBy":53,"folders":54,"meta":55,"rev":58},1742213002749,"efff2a27faf4408e9f908eba4b5542fe","inductive-automation","1c6207a5f24948ab82d4a0b17f251193","published",[],{"testimonial":16,"description":43,"type":19,"link":44,"title":47,"testimonialLink":48,"image":49},{"@type":17,"id":18,"model":19,"value":20},"@builder.io/core:Reference","f028f2b685bb47cd8bf9e82a26dd5a79","testimonial",{"query":21,"folders":22,"createdDate":23,"id":18,"name":24,"modelId":25,"published":13,"data":26,"variations":30,"lastUpdated":31,"firstPublished":32,"testRatio":33,"createdBy":34,"lastUpdatedBy":34,"meta":35,"rev":42},[],[],1735823466309,"We found Push to be more accurate when compared to competitors and the browser agent offered features that others couldn’t match.","42035571a56940ac98bff4544aa79aa5",{"author":27,"jobTitle":28,"quote":24,"image":29},"Jason Waits","\u003Cp>CISO at Inductive Automation\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Ff04c0c0689ce4a89ac0f0708d78c0a07",{},1735910703862,1735823501152,1,"ST0tXQM8slWpFrmioqKHmENB2qe2",{"kind":36,"lastPreviewUrl":37,"breakpoints":38,"hasAutosaves":41},"data","",{"small":39,"medium":40},640,768,true,"3v32gocrrqz","Join the industry's top security minds as they break down the browser attack landscape.",{"url":45,"text":46},"https://pushsecurity.com/webinar/state-of-browser-security","Save Your Spot","State of Browser Attacks Series","/customer-stories/inductive-automation","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fe94fca10aa7b46ac8052b7ea22de54cd",{},1776257019270,1742221533648,"CydmZnOWU1XuAaLhEDCoYNM4Z8W2",[],{"breakpoints":56,"kind":36,"lastPreviewUrl":37,"hasAutosaves":6},{"xsmall":57,"small":39,"medium":40},320,"motto9r9yg",{"createdDate":60,"id":61,"name":62,"modelId":12,"published":13,"query":63,"data":64,"variations":69,"lastUpdated":70,"firstPublished":71,"testRatio":33,"createdBy":53,"lastUpdatedBy":72,"folders":73,"meta":74,"rev":58},1742208588866,"1c7a4e423bf54ac1a328bb4063459ef2","Banner",[],{"type":65,"url":66,"text":67,"link":68},"web-banner","https://pushsecurity.com/resources/browser-attacks-report","Get our latest report analyzing browser attack techniques in 2026",{},{},1774258294825,1742208637545,"jKjF9r5jcvXU8tzZEfFQm31Iyvr2",[],{"kind":36,"lastPreviewUrl":37,"breakpoints":75,"hasAutosaves":41},{"xsmall":57,"small":39,"medium":40},{"createdDate":77,"id":78,"name":79,"modelId":12,"published":13,"stageModifiedSincePublish":6,"query":80,"data":81,"variations":89,"lastUpdated":90,"firstPublished":91,"testRatio":33,"createdBy":53,"lastUpdatedBy":53,"folders":92,"meta":93,"rev":58},1742208469288,"6763051b201f44a0838c6400c580ca67","Resource highlight",[],{"image":82,"type":83,"description":84,"link":85,"title":88},"https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F7b4a5ebf81d64e8c9d7fc35f6c96c4a9","resource","Learn about the latest techniques being used in the wild.",{"url":86,"text":87},"/resources/browser-attacks-report","Download now","Report: 2026 Browser Attack Techniques",{},1776255866789,1742208570400,[],{"kind":36,"lastPreviewUrl":37,"breakpoints":94,"hasAutosaves":6},{"xsmall":57,"small":39,"medium":40},{"createdDate":96,"id":97,"name":98,"modelId":99,"published":13,"query":100,"data":101,"variations":145,"lastUpdated":146,"firstPublished":147,"testRatio":33,"createdBy":34,"lastUpdatedBy":148,"folders":149,"meta":150,"rev":154},1774965361051,"fd266d0172cc47429be7ad10f48c99ad","always visible banner","0678d178ec8b41efb8a23c09dba7874d",[],{"ctaText":102,"text":103,"url":37,"blocks":104,"state":141},"ewrererw","testrfesssssssssss",[105,129],{"@type":106,"@version":107,"id":108,"component":109,"responsiveStyles":119},"@builder.io/sdk:Element",2,"builder-ca12c06a52de41d7b8743da53118cd38",{"name":110,"tag":110,"options":111,"isRSC":118},"TopBannerContent",{"text":112,"ctaText":46,"url":45,"mainText":113,"cta":116},"New Webinar Series: Join John Hammond, Troy Hunt, and Matt Johansen for the State of Browser Attacks",{"content":114,"fontSize":115},"\u003Cp>New Webinar Series: Join John Hammond, Troy Hunt, and Matt Johansen for the State of Browser Attacks\u003C/p>","text-base",{"content":117,"fontSize":115,"url":45},"\u003Cp>\u003Cstrong style=\"font-weight:700;\">Save Your Spot\u003C/strong>\u003C/p>\n",null,{"large":120},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"marginTop":126,"marginBottom":126,"fontSize":127,"fontWeight":128},"flex","column","relative","0","border-box",".56rem","1.125rem","700",{"id":130,"@type":106,"tagName":131,"properties":132,"responsiveStyles":136},"builder-pixel-08zrjigffq5t","img",{"src":133,"aria-hidden":134,"alt":37,"role":135,"width":124,"height":124},"https://cdn.builder.io/api/v1/pixel?apiKey=f3a1111ff5be48cdbb123cd9f5795a05","true","presentation",{"large":137},{"height":124,"width":124,"display":138,"opacity":124,"overflow":139,"pointerEvents":140},"block","hidden","none",{"deviceSize":142,"location":143},"large",{"path":37,"query":144},{},{},1775137295127,1774968080803,"ax7YYfD0OCeqT1Vxxv1G4FUbqVr1",[],{"breakpoints":151,"hasLinks":6,"kind":152,"lastPreviewUrl":153,"hasAutosaves":6},{"xsmall":57,"small":39,"medium":40},"component","https://pushsecurity.com/?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditCode%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CeditProjects%2CmodifyMcpServers%2CmodifyWorkflowIntegrations%2CmodifyProjectSettings%2CconnectCodeRepository%2CcreateProjects%2CindexDesignSystems%2CsendPullRequests%2CmergePullRequests&builder.user.role.name=Developer&builder.user.role.id=developer&builder.cachebust=true&builder.preview=always-visible-banner&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.always-visible-banner=fd266d0172cc47429be7ad10f48c99ad&builder.overrides.fd266d0172cc47429be7ad10f48c99ad=fd266d0172cc47429be7ad10f48c99ad&builder.options.locale=Default","2lvuonnywj",[156,180],{"createdDate":157,"id":158,"name":159,"modelId":160,"published":13,"stageModifiedSincePublish":6,"query":161,"data":162,"variations":173,"lastUpdated":174,"firstPublished":175,"testRatio":33,"createdBy":53,"lastUpdatedBy":53,"folders":176,"meta":177,"rev":179},1776247359804,"9136a8f18b3b4a6ba29b8653a99372b1","testimonial-inductive-automation","20d9eaa352304613b3d1a794b400703d",[],{"link":163,"type":19,"testimonialLink":48,"testimonial":164},{},{"@type":17,"id":18,"model":19,"value":165},{"query":166,"folders":167,"createdDate":23,"id":18,"name":24,"modelId":25,"published":13,"data":168,"variations":169,"lastUpdated":31,"firstPublished":32,"testRatio":33,"createdBy":34,"lastUpdatedBy":34,"meta":170,"rev":172},[],[],{"author":27,"jobTitle":28,"quote":24,"image":29},{},{"kind":36,"lastPreviewUrl":37,"breakpoints":171,"hasAutosaves":41},{"small":39,"medium":40},"7t755zfvte3",{},1776247404986,1776247404973,[],{"breakpoints":178,"kind":36,"lastPreviewUrl":37,"hasAutosaves":6},{"xsmall":57,"small":39,"medium":40},"4moh0qpywtr",{"createdDate":181,"id":182,"name":88,"modelId":160,"published":13,"meta":183,"stageModifiedSincePublish":6,"query":185,"data":186,"variations":207,"lastUpdated":208,"firstPublished":209,"testRatio":33,"createdBy":53,"lastUpdatedBy":53,"folders":210,"rev":179},1776255761419,"05a9322735fc427db12e2740e4302300",{"breakpoints":184,"kind":36,"lastPreviewUrl":37,"hasAutosaves":6},{"xsmall":57,"small":39,"medium":40},[],{"testimonial":187,"link":206,"type":83,"title":88,"description":84,"image":82},{"@type":17,"id":188,"model":19,"value":189},"192acbb1f9ca4cac918c0ec435a8bae3",{"query":190,"folders":191,"createdDate":192,"id":188,"name":193,"modelId":25,"published":13,"data":194,"variations":200,"lastUpdated":201,"firstPublished":202,"testRatio":33,"createdBy":34,"lastUpdatedBy":53,"meta":203,"rev":205},[],[],1728981467463,"Push does for identity what CrowdStrike did for the endpoint",{"video":195,"jobTitle":196,"author":197,"qoute":37,"quote":198,"image":199},"https://cdn.builder.io/o/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F8b30e8ca50064058bbaef0f3c6164575%2Fcompressed?apiKey=f3a1111ff5be48cdbb123cd9f5795a05&token=8b30e8ca50064058bbaef0f3c6164575&alt=media&optimized=true","\u003Cp>Deputy CISO at Microsoft\u003C/p>\u003Cp>Former LinkedIn, Slack, Palantir\u003C/p>","Geoff Belknap","Push does for identity what CrowdStrike did for the endpoint.","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F748f0ad0a5064a00a13f4721fcc8dea1",{},1742902158597,1728981782923,{"kind":36,"lastPreviewUrl":37,"breakpoints":204,"hasAutosaves":41},{"small":39,"medium":40},"6s8ic0w0ao6",{"text":87,"url":86},{},1776255810913,1776255810900,[],[212,235],{"createdDate":213,"id":214,"name":88,"modelId":215,"published":13,"meta":216,"stageModifiedSincePublish":6,"query":218,"data":219,"variations":230,"lastUpdated":231,"firstPublished":232,"testRatio":33,"createdBy":53,"lastUpdatedBy":53,"folders":233,"rev":234},1776256900280,"1f429607996e4e5fae8fe3f9b9610e55","4829faa81e7c4ee8bd2d000e160e8d3c",{"breakpoints":217,"kind":36,"lastPreviewUrl":37,"hasAutosaves":6},{"xsmall":57,"small":39,"medium":40},[],{"testimonial":220,"link":229,"type":83,"title":88,"description":84,"image":82},{"@type":17,"id":188,"model":19,"value":221},{"query":222,"folders":223,"createdDate":192,"id":188,"name":193,"modelId":25,"published":13,"data":224,"variations":225,"lastUpdated":201,"firstPublished":202,"testRatio":33,"createdBy":34,"lastUpdatedBy":53,"meta":226,"rev":228},[],[],{"video":195,"jobTitle":196,"author":197,"qoute":37,"quote":198,"image":199},{},{"kind":36,"lastPreviewUrl":37,"breakpoints":227,"hasAutosaves":41},{"small":39,"medium":40},"r77qqueuo3j",{"text":87,"url":86},{},1776256937553,1776256937540,[],"q0jkez80wkg",{"createdDate":236,"id":237,"name":11,"modelId":215,"published":13,"stageModifiedSincePublish":6,"query":238,"data":239,"variations":250,"lastUpdated":251,"firstPublished":252,"testRatio":33,"createdBy":53,"lastUpdatedBy":53,"folders":253,"meta":254,"rev":234},1776256949234,"ce043785b71b4ece98eac811ecf4ba10",[],{"link":240,"type":19,"testimonial":241,"testimonialLink":48},{},{"@type":17,"id":18,"model":19,"value":242},{"query":243,"folders":244,"createdDate":23,"id":18,"name":24,"modelId":25,"published":13,"data":245,"variations":246,"lastUpdated":31,"firstPublished":32,"testRatio":33,"createdBy":34,"lastUpdatedBy":34,"meta":247,"rev":249},[],[],{"author":27,"jobTitle":28,"quote":24,"image":29},{},{"kind":36,"lastPreviewUrl":37,"breakpoints":248,"hasAutosaves":41},{"small":39,"medium":40},"mnaneamy308",{},1776256974140,1776256974130,[],{"breakpoints":255,"kind":36,"lastPreviewUrl":37,"hasAutosaves":6},{"xsmall":57,"small":39,"medium":40},[257,441,560,679,797,917,1037,1157],{"createdDate":258,"id":259,"name":260,"modelId":261,"published":13,"stageModifiedSincePublish":6,"query":262,"data":268,"variations":429,"lastUpdated":430,"firstPublished":431,"testRatio":33,"screenshot":432,"createdBy":34,"lastUpdatedBy":433,"folders":434,"meta":435,"rev":440},1744829487099,"387451215c314dd5bd654668cdc1a197","Zero-day phishing","cca4143377554c5a9163cc203a8ed2ba",[263],{"@type":264,"property":265,"operator":266,"value":267},"@builder.io/core:Query","urlPath","is","/uc/zero-day-phishing-protection",{"inputs":269,"customFonts":270,"seoTitle":318,"title":318,"tsCode":37,"seoDescription":319,"fontAwesomeIcon":320,"jsCode":37,"blocks":321,"url":267,"state":426},[],[271],{"family":272,"kind":273,"version":274,"lastModified":275,"files":276,"category":295,"menu":296,"subsets":297,"variants":300},"DM Sans","webfonts#webfont","v14","2023-07-13",{"100":277,"200":278,"300":279,"500":280,"600":281,"700":282,"800":283,"900":284,"800italic":285,"900italic":286,"700italic":287,"100italic":288,"italic":289,"regular":290,"200italic":291,"500italic":292,"300italic":293,"600italic":294},"https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwAop1hTmf3ZGMZpg.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwAIpxhTmf3ZGMZpg.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwA_JxhTmf3ZGMZpg.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwAkJxhTmf3ZGMZpg.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwAfJthTmf3ZGMZpg.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwARZthTmf3ZGMZpg.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwAIpthTmf3ZGMZpg.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwAC5thTmf3ZGMZpg.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2rp2ywxg089UriCZaSExd86J3t9jz86Mvy4qCRAL19DksVat8JCm3zRmYJpso5.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2rp2ywxg089UriCZaSExd86J3t9jz86Mvy4qCRAL19DksVat8gCm3zRmYJpso5.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2rp2ywxg089UriCZaSExd86J3t9jz86Mvy4qCRAL19DksVat9uCm3zRmYJpso5.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2rp2ywxg089UriCZaSExd86J3t9jz86Mvy4qCRAL19DksVat-JDG3zRmYJpso5.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2rp2ywxg089UriCZaSExd86J3t9jz86Mvy4qCRAL19DksVat-JDW3zRmYJpso5.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwAopxhTmf3ZGMZpg.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2rp2ywxg089UriCZaSExd86J3t9jz86Mvy4qCRAL19DksVat8JDW3zRmYJpso5.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2rp2ywxg089UriCZaSExd86J3t9jz86Mvy4qCRAL19DksVat-7DW3zRmYJpso5.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2rp2ywxg089UriCZaSExd86J3t9jz86Mvy4qCRAL19DksVat_XDW3zRmYJpso5.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2rp2ywxg089UriCZaSExd86J3t9jz86Mvy4qCRAL19DksVat9XCm3zRmYJpso5.ttf","sans-serif","https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwAopxRT23z.ttf",[298,299],"latin","latin-ext",[301,302,303,304,305,306,128,307,308,309,310,311,312,313,314,315,316,317],"100","200","300","regular","500","600","800","900","100italic","200italic","300italic","italic","500italic","600italic","700italic","800italic","900italic","Zero-day phishing protection","Detect phishing TTPs directly in the browser and stop credential theft.","faFishingRod",[322,421],{"@type":106,"@version":107,"tagName":323,"id":324,"children":325},"div","builder-76c6b8d1499346c7bc1fd56ae4e93638",[326,343,351,358,370,385,396,407,413],{"@type":106,"@version":107,"layerName":327,"id":328,"component":329,"responsiveStyles":340},"UseCaseHero","builder-5228fe062bef4a40a91e43f1112832fa",{"name":327,"options":330,"isRSC":118},{"title":318,"description":331,"points":332,"video":339},"\u003Cp>Push detects phishing as it happens. Autonomous agents hunt for new phishing techniques, identify kit signatures, and deploy detections within minutes of a new attack being analyzed. From cloned login pages to AiTM credential harvesting, Push sees what traditional filters miss and stops threats before they escalate.\u003C/p>",[333,335,337],{"item":334},"Detect phishing that bypasses traditional filters, including AiTM, SSO password theft, and fake login pages",{"item":336},"Stop never-before-seen attacks with AI-native behavioral and on-page analysis inside the browser",{"item":338},"Investigate faster with unified browser, user, and page context","https://cdn.builder.io/o/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F40433ceeb4f94b43a82e039a0f4fd411%2Fcompressed?apiKey=f3a1111ff5be48cdbb123cd9f5795a05&token=40433ceeb4f94b43a82e039a0f4fd411&alt=media&optimized=true",{"large":341},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":342},"transparent",{"@type":106,"@version":107,"id":344,"component":345,"responsiveStyles":348},"builder-96634044407e491299e291ed64669e39",{"name":346,"options":347,"isRSC":118},"TrustedBy",{"AllPartners":41,"backgroundTransparent":6},{"large":349},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":350},"#000",{"@type":106,"@version":107,"id":352,"component":353,"responsiveStyles":356},"builder-2c3768f930534557bb8978e32b6a6a0f",{"name":354,"options":355,"isRSC":118},"Diagonal",{"darkMode":41},{"large":357},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"layerName":359,"id":360,"component":361,"responsiveStyles":368},"TextImageBlockVertical","builder-7c3c1c2840424db2ad2ccbfaf382dd64",{"name":359,"tag":359,"options":362,"isRSC":118},{"darkMode":6,"maxWidth":363,"maxTextWidth":364,"title":365,"description":366,"animatedTitle":37,"image":367,"reverse":6,"descriptionPaddingHorizontal":118},1200,800,"\u003Ch2>Why stop at the inbox?\u003C/h2>","\u003Cp>Phishing attacks have evolved. Whether attackers lure users with QR codes, instant messages, or OAuth consent screens, the outcome is the same: it plays out in the browser. Push gives you real-time detection for in-browser threats, stopping phishing and consent-based attacks before they lead to compromise\u003C/p>\u003Cp>\u003Cbr>\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F7fdcac241f0e4a049166d7076858adeb",{"large":369},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":371,"component":372,"responsiveStyles":380},"builder-41c978b3669749cf947e622b4e79e4d7",{"name":373,"options":374,"isRSC":118},"TextImageBlockHorizontal",{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":376,"title":377,"description":378,"reverse":41,"image":379},600,100,"\u003Cp>Detect phishing at the edge\u003C/p>","\u003Cp>Push uses industry-first telemetry to detect phishing based on behavior, not static indicators. Autonomous agents analyze how phishing pages behave and how users interact with them, uncovering fake logins, credential theft, and phishing kits the moment they load in the browser.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F9df3d180c97b4e61af142af2ccd68721",{"large":381},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"fontFamily":382,"paddingTop":383,"marginTop":384},"DM Sans, sans-serif","20px","0px",{"@type":106,"@version":107,"id":386,"component":387,"responsiveStyles":393},"builder-d2a7bc941feb43cdb898bc116b203cf9",{"name":373,"options":388,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":389,"title":390,"description":391,"reverse":6,"image":392},120,"\u003Ch2>Go beyond blocklists and IOCs\u003C/h2>","\u003Cp>Push goes beyond URLs and easy-to-change indicators. It reads the full phishing playbook like script behavior, session hijacks, DOM changes, user inputs, then connects the dots in real time. This gives your team a complete picture of how the phishing attempt worked, not just an alert.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fabfd58db169b433e96d3f1261797156e",{"large":394},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":395},"36px",{"@type":106,"@version":107,"layerName":373,"id":397,"component":398,"responsiveStyles":404},"builder-42c32198083f4880acb37c5cb76934da",{"name":373,"options":399,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":400,"title":401,"description":402,"reverse":41,"image":403},140,"\u003Ch2>Enhance your phishing response\u003C/h2>","\u003Cp>When phishing enters your environment, speed matters. Push gives you instant access to the telemetry that counts like session data, user behavior, and page activity, so you can investigate fast, trigger in-browser prompts, or forward alerts to your SIEM or SOAR for response. All in real time, right from the browser.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fbb195aec46904056b85e8688629e558e",{"large":405},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":406},"47px",{"@type":106,"@version":107,"id":408,"component":409,"responsiveStyles":411},"builder-9a95b9cbc4854421a92ef7b90f6c7adb",{"name":354,"options":410,"isRSC":118},{"darkMode":6},{"large":412},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":414,"component":415,"responsiveStyles":419},"builder-0afa17a9f25c4661a90f314d5578aa18",{"name":416,"tag":416,"options":417,"isRSC":118},"LatestResources",{"sectionHeading":37,"customClass":418},"bg-black",{"large":420},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"id":422,"@type":106,"tagName":131,"properties":423,"responsiveStyles":424},"builder-pixel-21yj6h3p4wh",{"src":133,"aria-hidden":134,"alt":37,"role":135,"width":124,"height":124},{"large":425},{"height":124,"width":124,"display":138,"opacity":124,"overflow":139,"pointerEvents":140},{"deviceSize":142,"location":427},{"path":37,"query":428},{},{},1776275046831,1745499158657,"https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fff60c30a8442489c8ed7e0af9599d14f","kYgMv6WsbvfmlOUYqR2SFwGzw6e2",[],{"lastPreviewUrl":436,"winningTest":118,"breakpoints":437,"kind":438,"hasLinks":6,"originalContentId":439,"hasAutosaves":6},"https://pushsecurity.com/uc/zero-day-phishing-protection?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CcreateProjects%2CsendPullRequests&builder.user.role.name=Designer&builder.user.role.id=creator&builder.cachebust=true&builder.preview=use-case-page&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.use-case-page=387451215c314dd5bd654668cdc1a197&builder.overrides.387451215c314dd5bd654668cdc1a197=387451215c314dd5bd654668cdc1a197&builder.overrides.use-case-page:/uc/zero-day-phishing-protection=387451215c314dd5bd654668cdc1a197&builder.options.locale=Default",{"xsmall":57,"small":39,"medium":40},"page","2daa5670b8504fc7ba4700633e8bd921","atvz4dp24b7",{"createdDate":442,"id":443,"name":444,"modelId":261,"published":13,"stageModifiedSincePublish":6,"query":445,"data":448,"variations":552,"lastUpdated":553,"firstPublished":554,"testRatio":33,"screenshot":555,"createdBy":34,"lastUpdatedBy":433,"folders":556,"meta":557,"rev":440},1756833377777,"54f8256648f54d439303734b1e69221b","Browser extension security",[446],{"@type":264,"property":265,"operator":266,"value":447},"/uc/browser-extension-security",{"seoDescription":449,"jsCode":37,"fontAwesomeIcon":450,"tsCode":37,"title":444,"seoTitle":444,"customFonts":451,"inputs":456,"blocks":457,"url":447,"state":549},"Shine a light on risky browser extensions.","faPuzzlePiece",[452],{"kind":273,"family":272,"version":274,"files":453,"category":295,"lastModified":275,"subsets":454,"variants":455,"menu":296},{"100":277,"200":278,"300":279,"500":280,"600":281,"700":282,"800":283,"900":284,"100italic":288,"italic":289,"regular":290,"900italic":286,"800italic":285,"700italic":287,"200italic":291,"300italic":293,"500italic":292,"600italic":294},[298,299],[301,302,303,304,305,306,128,307,308,309,310,311,312,313,314,315,316,317],[],[458,544],{"@type":106,"@version":107,"tagName":323,"id":459,"meta":460,"children":461},"builder-71d0648c1d2f4ede8d0d0b5b28b7b94c",{"previousId":324},[462,478,485,492,501,511,521,531,538],{"@type":106,"@version":107,"id":463,"meta":464,"component":465,"responsiveStyles":476},"builder-ff325b4b8fad4edea53f38865947e854",{"previousId":328},{"name":327,"options":466,"isRSC":118},{"title":444,"description":467,"points":468,"video":475},"\u003Cp>Browser extensions introduce new code, new permissions, and new potential for risk. Many include AI features, and most go completely unnoticed. Push gives you full visibility into every extension used across your workforce, across major browsers, so you can uncover shadow IT, assess risky permissions, and block unsafe tools before they lead to compromise.\u003C/p>",[469,471,473],{"item":470},"Discover every browser extension in use",{"item":472},"Spot risky or unsanctioned behavior",{"item":474},"Make informed decisions on extension policy","https://cdn.builder.io/o/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fc538aad95d7f403aa3c3551af72f67c0?alt=media&token=1411fa6d-2eac-4e6c-94bf-ea117da12d67&apiKey=f3a1111ff5be48cdbb123cd9f5795a05",{"large":477},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":342},{"@type":106,"@version":107,"id":479,"meta":480,"component":481,"responsiveStyles":483},"builder-fb89d128c64e47cf9cbb11d90fc24523",{"previousId":344},{"name":346,"options":482,"isRSC":118},{"AllPartners":41,"backgroundTransparent":6},{"large":484},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":350},{"@type":106,"@version":107,"id":486,"meta":487,"component":488,"responsiveStyles":490},"builder-54388d35126c4d0096eeebaf8c4448cd",{"previousId":352},{"name":354,"options":489,"isRSC":118},{"darkMode":41},{"large":491},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"layerName":359,"id":493,"component":494,"responsiveStyles":499},"builder-3c8fa6785dd6466abf52a2470d66d85a",{"name":359,"tag":359,"options":495,"isRSC":118},{"darkMode":6,"maxWidth":363,"maxTextWidth":364,"title":496,"description":497,"image":498,"reverse":6},"\u003Ch2>Take control of browser extensions\u003C/h2>","\u003Cp>Attackers are increasingly using malicious browser extensions to gain access to data processed and stored in the browser. And the problem is, most security teams have no visibility into what extensions are being used. Push changes that. With browser-native telemetry, the Push extension continuously inventories browser extensions across your environment, flags the risky ones, and gives you intelligence to act.&nbsp;\u003C/p>\u003Cp>\u003Cbr>\u003C/p>\u003Cp>\u003Cbr>\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F0a004f16a6874f4c8fdf14344acc9fec",{"large":500},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":502,"meta":503,"component":504,"responsiveStyles":509},"builder-93738f98109a4009affb349afd7bb182",{"previousId":371},{"name":373,"options":505,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":376,"title":506,"description":507,"reverse":41,"image":508},"\u003Ch2>Discover every extension in use\u003C/h2>","\u003Cp>Push gives you structured, searchable data about every extension in your environment, so you’re not just seeing what’s there, but also understanding how it got there, what it can do, and who it affects. It’s the kind of granular insight that’s nearly impossible to get from traditional tools, and it lays the groundwork for better policy decisions and faster investigations.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F0e5727ca99474f14b1b7916bf6bbb782",{"large":510},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"fontFamily":382,"paddingTop":383,"marginTop":384},{"@type":106,"@version":107,"id":512,"meta":513,"component":514,"responsiveStyles":519},"builder-83393acb12ee4fdd840839185b51edb4",{"previousId":386},{"name":373,"options":515,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":389,"title":516,"description":517,"reverse":6,"image":518},"\u003Ch2>Spot risky or malicious extensions\u003C/h2>","\u003Cp>Push highlights extensions with dangerous permissions, broad access, or poor reputations. This includes AI extensions that request access far beyond what their stated purpose requires. You can quickly detect sideloaded, manually installed, or development-mode extensions that bypass normal controls. And because Push shows you who’s using them and where, you can respond precisely and effectively.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fa104d58c8da34fbb8901f738fb21453b",{"large":520},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":395},{"@type":106,"@version":107,"layerName":373,"id":522,"meta":523,"component":524,"responsiveStyles":529},"builder-da98e3de949646d89c53a0d1c2784664",{"previousId":397},{"name":373,"options":525,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":400,"title":526,"description":527,"reverse":41,"image":528},"\u003Ch2>Accelerate security reviews\u003C/h2>","\u003Cp>Most teams have extension policies, they just don’t have the data to enforce them. Push reveals how each extension entered your environment, whether it was installed manually, sideloaded, or deployed in dev mode. You’ll see which users are running what, and where, so you can surface violations, investigate quickly, and respond with confidence.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F229f355be6f243b180f410d237a75bb3",{"large":530},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":406},{"@type":106,"@version":107,"id":532,"meta":533,"component":534,"responsiveStyles":536},"builder-1a689287d1a1418997d57db578a71105",{"previousId":408},{"name":354,"options":535,"isRSC":118},{"darkMode":6},{"large":537},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":539,"component":540,"responsiveStyles":542},"builder-feb4e75029f84c10b6498ef1f8f79128",{"name":416,"tag":416,"options":541,"isRSC":118},{"sectionHeading":37,"customClass":418},{"large":543},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"id":545,"@type":106,"tagName":131,"properties":546,"responsiveStyles":547},"builder-pixel-0edn39avfcei",{"src":133,"aria-hidden":134,"alt":37,"role":135,"width":124,"height":124},{"large":548},{"height":124,"width":124,"display":138,"opacity":124,"overflow":139,"pointerEvents":140},{"deviceSize":142,"location":550},{"path":37,"query":551},{},{},1776275365038,1757000441666,"https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F8d496cf111644ee5afcc046b72d1ca5a",[],{"kind":438,"winningTest":118,"breakpoints":558,"lastPreviewUrl":559,"hasLinks":6,"originalContentId":259,"hasAutosaves":6},{"xsmall":57,"small":39,"medium":40},"https://pushsecurity.com/uc/browser-extension-security?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CcreateProjects%2CsendPullRequests&builder.user.role.name=Designer&builder.user.role.id=creator&builder.cachebust=true&builder.preview=use-case-page&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.use-case-page=54f8256648f54d439303734b1e69221b&builder.overrides.54f8256648f54d439303734b1e69221b=54f8256648f54d439303734b1e69221b&builder.overrides.use-case-page:/uc/browser-extension-security=54f8256648f54d439303734b1e69221b&builder.options.locale=Default",{"createdDate":561,"id":562,"name":563,"modelId":261,"published":13,"query":564,"data":567,"variations":670,"lastUpdated":671,"firstPublished":672,"testRatio":33,"screenshot":673,"createdBy":34,"lastUpdatedBy":674,"folders":675,"meta":676,"rev":440},1744923509705,"94bebb7bb99d48629ad157e80cf4d81d","Account takeover detection",[565],{"@type":264,"property":265,"operator":266,"value":566},"/uc/account-takeover-detection",{"title":563,"customFonts":568,"jsCode":37,"seoTitle":563,"seoDescription":573,"fontAwesomeIcon":574,"tsCode":37,"blocks":575,"url":566,"state":667},[569],{"kind":273,"category":295,"variants":570,"menu":296,"files":571,"family":272,"subsets":572,"version":274,"lastModified":275},[301,302,303,304,305,306,128,307,308,309,310,311,312,313,314,315,316,317],{"100":277,"200":278,"300":279,"500":280,"600":281,"700":282,"800":283,"900":284,"300italic":293,"500italic":292,"800italic":285,"700italic":287,"italic":289,"900italic":286,"600italic":294,"200italic":291,"regular":290,"100italic":288},[298,299],"Stop ATO with stolen credential and compromised token detection.","faUserSecret",[576,662],{"@type":106,"@version":107,"tagName":323,"id":577,"meta":578,"children":579},"builder-e7913a774cae44c5a23d6081c5c30a52",{"previousId":324},[580,596,603,610,619,629,639,649,656],{"@type":106,"@version":107,"id":581,"meta":582,"component":583,"responsiveStyles":594},"builder-f1f1ab1601bc4c0f8c2a8aafd173675d",{"previousId":328},{"name":327,"options":584,"isRSC":118},{"title":563,"description":585,"points":586,"video":593},"\u003Cp>Attackers don’t need to phish, they just need a password that works. Push monitors for signs of credential-based attacks in real time, directly in the browser, catching account takeover attempts before the damage spreads. From ghost logins to credential stuffing, Push cuts off the paths attackers use to quietly slip in the back door.\u003C/p>\u003Cp>\u003Cbr>\u003C/p>",[587,589,591],{"item":588},"Identify credential-based ATO as it unfolds",{"item":590},"Surface hijacked sessions and token misuse",{"item":592},"Strengthen authentication where your IdP can’t","https://cdn.builder.io/o/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fb4dd9db24bc9495b8a686b1b4d492016%2Fcompressed?apiKey=f3a1111ff5be48cdbb123cd9f5795a05&token=b4dd9db24bc9495b8a686b1b4d492016&alt=media&optimized=true",{"large":595},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":342},{"@type":106,"@version":107,"id":597,"meta":598,"component":599,"responsiveStyles":601},"builder-0bc0d1c78ece4994993c3a6427a4d533",{"previousId":344},{"name":346,"options":600,"isRSC":118},{"AllPartners":41,"backgroundTransparent":6},{"large":602},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":350},{"@type":106,"@version":107,"id":604,"meta":605,"component":606,"responsiveStyles":608},"builder-e45de8f3768c4f16938dbf78e4e87524",{"previousId":352},{"name":354,"options":607,"isRSC":118},{"darkMode":41},{"large":609},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":611,"component":612,"responsiveStyles":617},"builder-c98e8bfd341146c1b67c02d5698ff093",{"name":359,"tag":359,"options":613,"isRSC":118},{"darkMode":6,"maxWidth":363,"maxTextWidth":364,"title":614,"description":615,"image":616,"reverse":6},"\u003Ch2>Assume less. See more.\u003C/h2>","\u003Cp>Most account takeovers don’t start with a breach, they start with a login. Whether it’s a reused password, a local account, or an outdated login flow, Push shows you how accounts are actually accessed day to day, not just how policies say they should be. That means no more blind spots around ghost logins, bypassed SSO, or stale access paths that quietly persist.\u003C/p>\u003Cp>\u003Cbr>\u003C/p>\u003Cp>\u003Cbr>\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F18630ad2746d4eb7b7fcc0428b11a8f0",{"large":618},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":620,"meta":621,"component":622,"responsiveStyles":627},"builder-55c1fc38ddc04fd1a0d6a8e2fb819e00",{"previousId":371},{"name":373,"options":623,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":376,"title":624,"description":625,"reverse":41,"image":626},"\u003Ch2>Catch stolen credential use in real time\u003C/h2>","\u003Cp>Push monitors login activity directly in the browser to detect signs of credential-based attacks like leaked password use or suspicious login flows. By analyzing attacker TTPs instead of relying on known indicators, Push spots credential stuffing and account takeover attempts the moment they begin, not after they’ve succeeded.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F52b0123cac2c4dfdb1dc0af6adf9d603",{"large":628},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"fontFamily":382,"paddingTop":384,"marginTop":384},{"@type":106,"@version":107,"id":630,"meta":631,"component":632,"responsiveStyles":637},"builder-dfb31737b30948c6b95323655d571a50",{"previousId":386},{"name":373,"options":633,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":389,"title":634,"description":635,"reverse":6,"image":636},"\u003Ch2>Detect session hijacks and stealth access\u003C/h2>","\u003Cp>Attackers don’t always need a login screen, they often sidestep it entirely using stolen session tokens. Push detects when valid sessions are reused in unexpected ways, identifying hijacked sessions and stealth access attempts that traditional tools miss. Because we monitor directly in the browser, you see what’s happening inside active sessions in real time.\u003C/p>\u003Cp>\u003Cbr>\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F94a6859a99e04d309ffe5841f3dbdf5c",{"large":638},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":395},{"@type":106,"@version":107,"layerName":373,"id":640,"meta":641,"component":642,"responsiveStyles":647},"builder-f7585b90eb974d03a7dc7eae5b58d227",{"previousId":397},{"name":373,"options":643,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":400,"title":644,"description":645,"reverse":41,"image":646},"\u003Ch2>Harden accounts before they’re compromised\u003C/h2>","\u003Cp>Push goes beyond alerts. It identifies apps that still allow local logins, even when SSO is configured, so you can remove weak access paths. Push also flags users without MFA, reused work credentials, or weak passwords, and prompts users in-browser to fix risky behaviors before they’re exploited.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F01c1b638f1b6497093a4f2b8ceddb5bb",{"large":648},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":406},{"@type":106,"@version":107,"id":650,"meta":651,"component":652,"responsiveStyles":654},"builder-ad81d1e3afec49a791214194eae09bdc",{"previousId":408},{"name":354,"options":653,"isRSC":118},{"darkMode":6},{"large":655},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":657,"component":658,"responsiveStyles":660},"builder-8dac1aa4b9d148628d92252bd8eff822",{"name":416,"tag":416,"options":659,"isRSC":118},{"sectionHeading":37,"customClass":418},{"large":661},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"id":663,"@type":106,"tagName":131,"properties":664,"responsiveStyles":665},"builder-pixel-s5u3wmvz7jq",{"src":133,"aria-hidden":134,"alt":37,"role":135,"width":124,"height":124},{"large":666},{"height":124,"width":124,"display":138,"opacity":124,"overflow":139,"pointerEvents":140},{"deviceSize":142,"location":668},{"path":37,"query":669},{},{},1770892814499,1745499162732,"https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F58b660fa94aa4b30b0faeb9b663ae41a","SfUPqW5tkibIPby49keNFMdHFTr1",[],{"lastPreviewUrl":677,"hasLinks":6,"originalContentId":259,"breakpoints":678,"winningTest":118,"kind":438,"hasAutosaves":41},"https://pushsecurity.com/uc/account-takeover-detection?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditCode%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CeditProjects%2CmodifyMcpServers%2CmodifyWorkflowIntegrations%2CmodifyProjectSettings%2CconnectCodeRepository%2CcreateProjects%2CindexDesignSystems%2CsendPullRequests&builder.user.role.name=Developer&builder.user.role.id=developer&builder.cachebust=true&builder.preview=use-case-page&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.use-case-page=94bebb7bb99d48629ad157e80cf4d81d&builder.overrides.94bebb7bb99d48629ad157e80cf4d81d=94bebb7bb99d48629ad157e80cf4d81d&builder.overrides.use-case-page:/uc/account-takeover-detection=94bebb7bb99d48629ad157e80cf4d81d&builder.options.includeRefs=true&builder.options.enrich=true&builder.options.locale=Default",{"xsmall":57,"small":39,"medium":40},{"createdDate":680,"id":681,"name":682,"modelId":261,"published":13,"query":683,"data":686,"variations":789,"lastUpdated":790,"firstPublished":791,"testRatio":33,"screenshot":792,"createdBy":34,"lastUpdatedBy":674,"folders":793,"meta":794,"rev":440},1745009370904,"23eb48fb56d3451cab77cb6ed140ee6d","Attack path hardening",[684],{"@type":264,"property":265,"operator":266,"value":685},"/uc/attack-path-hardening",{"tsCode":37,"seoDescription":687,"jsCode":37,"customFonts":688,"fontAwesomeIcon":693,"seoTitle":682,"title":682,"blocks":694,"url":685,"state":786},"Harden access paths with visibility,  detection, and guardrails.",[689],{"kind":273,"files":690,"version":274,"lastModified":275,"subsets":691,"menu":296,"category":295,"variants":692,"family":272},{"100":277,"200":278,"300":279,"500":280,"600":281,"700":282,"800":283,"900":284,"regular":290,"italic":289,"800italic":285,"500italic":292,"600italic":294,"200italic":291,"900italic":286,"700italic":287,"100italic":288,"300italic":293},[298,299],[301,302,303,304,305,306,128,307,308,309,310,311,312,313,314,315,316,317],"faRadar",[695,781],{"@type":106,"@version":107,"tagName":323,"id":696,"meta":697,"children":698},"builder-1d8553eddcaa44d7bba9e2f4ca13af2a",{"previousId":577},[699,715,722,729,738,748,758,768,775],{"@type":106,"@version":107,"id":700,"meta":701,"component":702,"responsiveStyles":713},"builder-84fe3d7c85a743cf8cef649aa974f1ef",{"previousId":581},{"name":327,"options":703,"isRSC":118},{"title":682,"description":704,"points":705,"video":712},"\u003Cp>Push continuously monitors your environment for exposed login paths, weak credentials, and missing protections like MFA. It detects the gaps attackers exploit and helps you close them before they’re used.\u003C/p>",[706,708,710],{"item":707},"Find weak spots like reused passwords, local logins, and missing MFA",{"item":709},"Monitor how users actually log in across apps, flows, and tools",{"item":711},"Enforce secure access with in-browser guardrails","https://cdn.builder.io/o/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fdbdcf52892034f1bbddded77f753a343%2Fcompressed?apiKey=f3a1111ff5be48cdbb123cd9f5795a05&token=dbdcf52892034f1bbddded77f753a343&alt=media&optimized=true",{"large":714},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":342},{"@type":106,"@version":107,"id":716,"meta":717,"component":718,"responsiveStyles":720},"builder-b3f66f5b08054cc78a06fecfc3ae2337",{"previousId":597},{"name":346,"options":719,"isRSC":118},{"AllPartners":41,"backgroundTransparent":6},{"large":721},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":350},{"@type":106,"@version":107,"id":723,"meta":724,"component":725,"responsiveStyles":727},"builder-4c73418b84be49ed85e6e13d2625c5a0",{"previousId":604},{"name":354,"options":726,"isRSC":118},{"darkMode":41},{"large":728},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":730,"component":731,"responsiveStyles":736},"builder-dec0246085e1485c803f7152b1922a81",{"name":359,"tag":359,"options":732,"isRSC":118},{"darkMode":6,"maxWidth":363,"maxTextWidth":364,"title":733,"description":734,"image":735,"reverse":6},"\u003Ch2>Find the gaps that lead to compromise\u003C/h2>","\u003Cp>Misconfigurations don’t show up in your config files, they show up in how users actually access apps. Push monitors real login behavior in the browser, surfacing risky patterns like local login access, duplicate accounts, or missing protections that leave doors wide open.\u003C/p>\u003Cp>\u003Cbr>\u003C/p>\u003Cp>\u003Cbr>\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F309a59bba8d247a19476bb369397460e",{"large":737},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":739,"meta":740,"component":741,"responsiveStyles":746},"builder-ebf049a645604a249550996a88f8f3b6",{"previousId":620},{"name":373,"options":742,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":376,"title":743,"description":744,"reverse":41,"image":745},"\u003Ch2>See real login behavior\u003C/h2>","\u003Cp>Push watches authentication flows as they happen, giving you a live view of how users log in, which methods they choose, and where protections like MFA are missing. Plus, uncover every app and account in use, even shadow IT you didn’t know existed, without relying on stale config files or IdP assumptions. \u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fb51f6b0357cc451b87a7a5016d984e5e",{"large":747},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"fontFamily":382,"paddingTop":383,"marginTop":384},{"@type":106,"@version":107,"id":749,"meta":750,"component":751,"responsiveStyles":756},"builder-431d175c59004669b0b2776b07d71737",{"previousId":630},{"name":373,"options":752,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":389,"title":753,"description":754,"reverse":6,"image":755},"\u003Ch2>Find and fix posture drift\u003C/h2>","\u003Cp>Security posture isn’t static. Push continuously monitors for issues like missing MFA or legacy login methods. When something falls out of policy, you know immediately with custom notifications so you can act before it turns into risk.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F324e39127dfc41e592b1183dfb39892d",{"large":757},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":395},{"@type":106,"@version":107,"layerName":373,"id":759,"meta":760,"component":761,"responsiveStyles":766},"builder-3dffdcbe0a484e2ca4c03f019b6d40ee",{"previousId":640},{"name":373,"options":762,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":400,"title":763,"description":764,"reverse":41,"image":765},"\u003Ch2>Guide users with in-browser guardrails\u003C/h2>","\u003Cp>Push doesn’t just surface problems, it helps you fix them. When users sign in without MFA, reuse a password, or use insecure credentials, Push prompts them directly in the browser to secure their access. It’s faster, more effective, and actually gets results.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fee8b75d13e45488aba55434a8b49ebb0",{"large":767},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":406},{"@type":106,"@version":107,"id":769,"meta":770,"component":771,"responsiveStyles":773},"builder-976bc222cd7647ff905f1e01cfedc453",{"previousId":650},{"name":354,"options":772,"isRSC":118},{"darkMode":6},{"large":774},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":776,"component":777,"responsiveStyles":779},"builder-8c47ec2fd0f74382bb3e6c870555632c",{"name":416,"tag":416,"options":778,"isRSC":118},{"sectionHeading":37,"customClass":418},{"large":780},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"id":782,"@type":106,"tagName":131,"properties":783,"responsiveStyles":784},"builder-pixel-7akm7dayau8",{"src":133,"aria-hidden":134,"alt":37,"role":135,"width":124,"height":124},{"large":785},{"height":124,"width":124,"display":138,"opacity":124,"overflow":139,"pointerEvents":140},{"deviceSize":142,"location":787},{"path":37,"query":788},{},{},1770892844854,1745499166112,"https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F6ca12bf728a045f1a31d40c0beb3bfe5",[],{"kind":438,"lastPreviewUrl":795,"breakpoints":796,"hasLinks":6,"originalContentId":562,"winningTest":118,"hasAutosaves":6},"https://pushsecurity.com/uc/attack-path-hardening?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditCode%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CeditProjects%2CmodifyMcpServers%2CmodifyWorkflowIntegrations%2CmodifyProjectSettings%2CconnectCodeRepository%2CcreateProjects%2CindexDesignSystems%2CsendPullRequests&builder.user.role.name=Developer&builder.user.role.id=developer&builder.cachebust=true&builder.preview=use-case-page&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.use-case-page=23eb48fb56d3451cab77cb6ed140ee6d&builder.overrides.23eb48fb56d3451cab77cb6ed140ee6d=23eb48fb56d3451cab77cb6ed140ee6d&builder.overrides.use-case-page:/uc/attack-path-hardening=23eb48fb56d3451cab77cb6ed140ee6d&builder.options.includeRefs=true&builder.options.enrich=true&builder.options.locale=Default",{"xsmall":57,"small":39,"medium":40},{"createdDate":798,"id":799,"name":800,"modelId":261,"published":13,"query":801,"data":804,"variations":909,"lastUpdated":910,"firstPublished":911,"testRatio":33,"screenshot":912,"createdBy":34,"lastUpdatedBy":674,"folders":913,"meta":914,"rev":440},1761675020232,"ea4f309d2ffe46c5aa97ebf0fda4e2e3","ClickFix Protection",[802],{"@type":264,"property":265,"operator":266,"value":803},"/uc/clickfix-protection",{"seoDescription":805,"fontAwesomeIcon":806,"customFonts":807,"seoTitle":812,"jsCode":37,"tsCode":37,"title":812,"blocks":813,"url":803,"state":906},"Block attacks that trick users into running malicious code.","faLaptopCode",[808],{"files":809,"subsets":810,"menu":296,"version":274,"kind":273,"family":272,"lastModified":275,"variants":811,"category":295},{"100":277,"200":278,"300":279,"500":280,"600":281,"700":282,"800":283,"900":284,"200italic":291,"800italic":285,"700italic":287,"600italic":294,"100italic":288,"italic":289,"regular":290,"300italic":293,"500italic":292,"900italic":286},[298,299],[301,302,303,304,305,306,128,307,308,309,310,311,312,313,314,315,316,317],"ClickFix protection",[814,901],{"@type":106,"@version":107,"tagName":323,"id":815,"meta":816,"children":817},"builder-d7eefdde0f2a4b2b9de3dcb2978fd6cb",{"previousId":696},[818,834,841,848,858,868,878,888,895],{"@type":106,"@version":107,"id":819,"meta":820,"component":821,"responsiveStyles":832},"builder-56e2c54bcce040a4af8b92ae03706c12",{"previousId":700},{"name":327,"options":822,"isRSC":118},{"title":812,"description":823,"points":824,"image":831},"\u003Cp>ClickFix attacks are one of the fastest-growing threats, tricking users into copying malicious code from a webpage and running it locally. This technique bypasses traditional EDR, email gateways, and network filters, leading directly to ransomware and data theft. Push stops this attack at the source, in the browser, by detecting and blocking the malicious behavior before the user can ever paste the code.\u003C/p>\u003Cp>\u003Cbr>\u003C/p>",[825,827,829],{"item":826},"Detect ClickFix, FileFix, and fake CAPTCHA in the browser",{"item":828},"Block malicious copy-and-paste actions before code is executed",{"item":830},"See full telemetry into which users were targeted and what they saw","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F7b74af62889847ebb3927364485b0546",{"large":833},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":342},{"@type":106,"@version":107,"id":835,"meta":836,"component":837,"responsiveStyles":839},"builder-05f9614d4e3e4dc88b3ee8658f54e10e",{"previousId":716},{"name":346,"options":838,"isRSC":118},{"AllPartners":41,"backgroundTransparent":6},{"large":840},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":350},{"@type":106,"@version":107,"id":842,"meta":843,"component":844,"responsiveStyles":846},"builder-c4fb5179366243c1b6c32d368675cf47",{"previousId":723},{"name":354,"options":845,"isRSC":118},{"darkMode":41},{"large":847},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":849,"meta":850,"component":851,"responsiveStyles":856},"builder-261af50705fd445d8cca4a6ba20d5391",{"previousId":730},{"name":359,"tag":359,"options":852,"isRSC":118},{"darkMode":6,"maxWidth":363,"maxTextWidth":364,"title":853,"description":854,"reverse":6,"image":855},"\u003Ch2>Stop ClickFix-style attacks before they become a breach\u003C/h2>","\u003Cp>Traditional security tools are blind to malicious copy and paste attacks because the attack exploits a gap between the browser and the endpoint. EDR only sees the payload after it runs, and network tools see only part of the picture.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F98b2f7e08dec4eafaf8e24937605b8cf",{"large":857},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":859,"meta":860,"component":861,"responsiveStyles":866},"builder-7d21b8aab8064c40b1e5dd23c4749309",{"previousId":739},{"name":373,"options":862,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":376,"title":863,"description":864,"reverse":41,"image":865},"\u003Ch2>Discover lures at the source\u003C/h2>","\u003Cp>Push inspects page behavior to identify ClickFix attacks as they happen. By inspecting the page, its structure, and how the user interacts with it, Push can detect and block these in-browser threats in real time. This deep, TTP-based inspection spots the trap even on novel pages that are built to bypass traditional web filters and blocklists.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F665bf47e01544c75bf9ddafd3917927b",{"large":867},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"fontFamily":382,"paddingTop":383,"marginTop":384},{"@type":106,"@version":107,"id":869,"meta":870,"component":871,"responsiveStyles":876},"builder-fb91943adf6149259ed9e1e6566c9afe",{"previousId":749},{"name":373,"options":872,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":389,"title":873,"description":874,"reverse":6,"image":875},"\u003Ch2>Block the malicious action\u003C/h2>","\u003Cp>When Push detects a malicious script, it intercepts the user's action and blocks the code from being copied to the clipboard. The user is protected, the attack is stopped, and no malicious code ever reaches the endpoint. Unlike broad DLP tools, this action is surgical, targeting only malicious behavior without disrupting normal work.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F5ee68f81f1ac416685cbfe91298cf827",{"large":877},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":395},{"@type":106,"@version":107,"layerName":373,"id":879,"meta":880,"component":881,"responsiveStyles":886},"builder-bfac95fada864e5a8259b955b5b5f98b",{"previousId":759},{"name":373,"options":882,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":400,"title":883,"description":884,"reverse":41,"image":885},"\u003Ch2>Accelerate ClickFix investigations\u003C/h2>","\u003Cp>When an attack happens, knowing what the user saw or did is critical. Push provides rich browser session data for rapid investigation and containment. Security teams get detailed telemetry on which users were targeted, what lure they were served, and when the block occurred. This enables defenders to reconstruct what happened and respond quickly, even when other tools miss the activity entirely.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F6cdf2a8aeddc4e9a9023cbf974e40239",{"large":887},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":406},{"@type":106,"@version":107,"id":889,"meta":890,"component":891,"responsiveStyles":893},"builder-136892e831684a6987f87d3be67c33d1",{"previousId":769},{"name":354,"options":892,"isRSC":118},{"darkMode":6},{"large":894},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":896,"component":897,"responsiveStyles":899},"builder-dec26b739f2f42beb5a73cfc6c675b60",{"name":416,"tag":416,"options":898,"isRSC":118},{"sectionHeading":37,"customClass":418},{"large":900},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"id":902,"@type":106,"tagName":131,"properties":903,"responsiveStyles":904},"builder-pixel-zzjpxxgrc2l",{"src":133,"aria-hidden":134,"alt":37,"role":135,"width":124,"height":124},{"large":905},{"height":124,"width":124,"display":138,"opacity":124,"overflow":139,"pointerEvents":140},{"deviceSize":142,"location":907},{"path":37,"query":908},{},{},1770892881888,1761847585203,"https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F375467b8bef34ed1a8a1cc5b8b67d75f",[],{"lastPreviewUrl":915,"originalContentId":681,"winningTest":118,"hasLinks":6,"kind":438,"breakpoints":916,"hasAutosaves":6},"https://pushsecurity.com/uc/clickfix-protection?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditCode%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CeditProjects%2CmodifyMcpServers%2CmodifyWorkflowIntegrations%2CmodifyProjectSettings%2CconnectCodeRepository%2CcreateProjects%2CindexDesignSystems%2CsendPullRequests&builder.user.role.name=Developer&builder.user.role.id=developer&builder.cachebust=true&builder.preview=use-case-page&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.use-case-page=ea4f309d2ffe46c5aa97ebf0fda4e2e3&builder.overrides.ea4f309d2ffe46c5aa97ebf0fda4e2e3=ea4f309d2ffe46c5aa97ebf0fda4e2e3&builder.overrides.use-case-page:/uc/clickfix-protection=ea4f309d2ffe46c5aa97ebf0fda4e2e3&builder.options.includeRefs=true&builder.options.enrich=true&builder.options.locale=Default",{"xsmall":57,"small":39,"medium":40},{"createdDate":918,"id":919,"name":920,"modelId":261,"published":13,"query":921,"data":924,"variations":1029,"lastUpdated":1030,"firstPublished":1031,"testRatio":33,"screenshot":1032,"createdBy":34,"lastUpdatedBy":674,"folders":1033,"meta":1034,"rev":440},1745009743870,"a9d5556e77f84a37b5bd52310a7110c1","Incident response",[922],{"@type":264,"property":265,"operator":266,"value":923},"/uc/incident-response",{"seoDescription":925,"customFonts":926,"title":920,"jsCode":37,"fontAwesomeIcon":931,"seoTitle":932,"tsCode":37,"blocks":933,"url":923,"state":1026},"Investigate and respond faster with unique browser telemetry.",[927],{"kind":273,"subsets":928,"menu":296,"variants":929,"category":295,"family":272,"version":274,"lastModified":275,"files":930},[298,299],[301,302,303,304,305,306,128,307,308,309,310,311,312,313,314,315,316,317],{"100":277,"200":278,"300":279,"500":280,"600":281,"700":282,"800":283,"900":284,"900italic":286,"600italic":294,"200italic":291,"300italic":293,"100italic":288,"700italic":287,"800italic":285,"regular":290,"italic":289,"500italic":292},"faSatelliteDish","Browser based incident response",[934,1021],{"@type":106,"@version":107,"tagName":323,"id":935,"meta":936,"children":937},"builder-653c4aed737b4def88dc4cd2d695660a",{"previousId":696},[938,955,962,969,978,988,998,1008,1015],{"@type":106,"@version":107,"id":939,"meta":940,"component":941,"responsiveStyles":953},"builder-18190bd36518467d9154d27d7e945b9b",{"previousId":700},{"name":327,"options":942,"isRSC":118},{"title":943,"description":944,"points":945,"video":952},"Browser-based incident response","\u003Cp>Push gives you real-time visibility into what actually happened during a breach, right in the browser where the attack played out. From credential theft to session hijacking, Push captures high-fidelity telemetry so you can investigate quickly, contain confidently, and shut it down before it spreads.\u003C/p>\u003Cp>\u003Cbr>\u003C/p>",[946,948,950],{"item":947},"Reconstruct what happened with real browser session context",{"item":949},"Investigate faster with real-world session context",{"item":951},"Trigger response actions automatically through your SIEM or SOAR","https://cdn.builder.io/o/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fd00e39d3b6e346c296261d875cf55652%2Fcompressed?apiKey=f3a1111ff5be48cdbb123cd9f5795a05&token=d00e39d3b6e346c296261d875cf55652&alt=media&optimized=true",{"large":954},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":342},{"@type":106,"@version":107,"id":956,"meta":957,"component":958,"responsiveStyles":960},"builder-8a0a8ea63f5d48dd8a6726f2d49cf0ca",{"previousId":716},{"name":346,"options":959,"isRSC":118},{"AllPartners":41,"backgroundTransparent":6},{"large":961},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":350},{"@type":106,"@version":107,"id":963,"meta":964,"component":965,"responsiveStyles":967},"builder-2df65c3f54334df2b26e7cb744886cdc",{"previousId":723},{"name":354,"options":966,"isRSC":118},{"darkMode":41},{"large":968},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":970,"component":971,"responsiveStyles":976},"builder-2c32c869efc2423ab69ef06b150e9f97",{"name":359,"tag":359,"options":972,"isRSC":118},{"darkMode":6,"maxWidth":363,"maxTextWidth":364,"title":973,"description":974,"image":975,"reverse":6},"\u003Ch2>See attacks unfold, not just their aftermath\u003C/h2>","\u003Cp>Attacks happen in the browser, not in logs. Push captures what traditional tools miss: what users clicked, what loaded, what was entered, and how attackers moved. That gives you real-world evidence, not just assumptions, when every second matters.\u003C/p>\u003Cp>\u003Cbr>\u003C/p>\u003Cp>\u003Cbr>\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F36fc719bd1de4a38b916f4d25c81a26d",{"large":977},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":979,"meta":980,"component":981,"responsiveStyles":986},"builder-370e53c6016e432db01e9193a2ce90f6",{"previousId":739},{"name":373,"options":982,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":376,"title":983,"description":984,"reverse":41,"image":985},"\u003Ch2>Investigate faster with high-fidelity data\u003C/h2>","\u003Cp>Reconstructing an incident shouldn’t feel like guesswork. Push records detailed telemetry from inside the browser: page loads, credential inputs, DOM changes, session activity, user behavior. It’s structured, exportable, and ready to plug into your investigation workflows, so you can move fast without digging through proxy logs or relying on user reports.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fa6adda040e684e67a8d68a55c5ce5f6d",{"large":987},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"fontFamily":382,"paddingTop":384,"marginTop":384},{"@type":106,"@version":107,"id":989,"meta":990,"component":991,"responsiveStyles":996},"builder-a7f3767a8d184bd08fb24520bf210e95",{"previousId":749},{"name":373,"options":992,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":389,"title":993,"description":994,"reverse":6,"image":995},"\u003Ch2>Contain and respond in real time\u003C/h2>","\u003Cp>When something looks off, Push doesn’t just alert you, it gives you options. Guide users with in-browser prompts. Terminate sessions. Trigger SOAR workflows. Enrich SIEM alerts. Push gives you the context and control to stop spread before it starts.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fb3dedeed5aba4847a2c2d22e10d0ec12",{"large":997},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":395},{"@type":106,"@version":107,"layerName":373,"id":999,"meta":1000,"component":1001,"responsiveStyles":1006},"builder-b92036ee0ece4b32acdbdcc7c377366b",{"previousId":759},{"name":373,"options":1002,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":400,"title":1003,"description":1004,"reverse":41,"image":1005},"\u003Ch2>Prevent the next one\u003C/h2>","\u003Cp>Push helps you respond fast, but it also helps you fix what went wrong. It surfaces misconfigurations and risky behaviors that made the attack possible in the first place, then guides users in-browser to remediate. One tool. Full loop. No loose ends.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fc1ecc2d5d3814b62b072fac01827ff96",{"large":1007},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":406},{"@type":106,"@version":107,"id":1009,"meta":1010,"component":1011,"responsiveStyles":1013},"builder-5e8ae39655274de89da32ab573a2525a",{"previousId":769},{"name":354,"options":1012,"isRSC":118},{"darkMode":6},{"large":1014},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":1016,"component":1017,"responsiveStyles":1019},"builder-dfd6850cfb4741d2b8a0c16c2780f00a",{"name":416,"tag":416,"options":1018,"isRSC":118},{"sectionHeading":37,"customClass":418},{"large":1020},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"id":1022,"@type":106,"tagName":131,"properties":1023,"responsiveStyles":1024},"builder-pixel-z197gdgcmu",{"src":133,"aria-hidden":134,"alt":37,"role":135,"width":124,"height":124},{"large":1025},{"height":124,"width":124,"display":138,"opacity":124,"overflow":139,"pointerEvents":140},{"deviceSize":142,"location":1027},{"path":37,"query":1028},{},{},1770892908052,1745427419274,"https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fb07017bfd318431690a5bb35bda35b99",[],{"kind":438,"breakpoints":1035,"originalContentId":681,"winningTest":118,"lastPreviewUrl":1036,"hasLinks":6,"hasAutosaves":6},{"xsmall":57,"small":39,"medium":40},"https://pushsecurity.com/uc/incident-response?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditCode%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CeditProjects%2CmodifyMcpServers%2CmodifyWorkflowIntegrations%2CmodifyProjectSettings%2CconnectCodeRepository%2CcreateProjects%2CindexDesignSystems%2CsendPullRequests&builder.user.role.name=Developer&builder.user.role.id=developer&builder.cachebust=true&builder.preview=use-case-page&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.use-case-page=a9d5556e77f84a37b5bd52310a7110c1&builder.overrides.a9d5556e77f84a37b5bd52310a7110c1=a9d5556e77f84a37b5bd52310a7110c1&builder.overrides.use-case-page:/uc/incident-response=a9d5556e77f84a37b5bd52310a7110c1&builder.options.includeRefs=true&builder.options.enrich=true&builder.options.locale=Default",{"createdDate":1038,"id":1039,"name":1040,"modelId":261,"published":13,"query":1041,"data":1044,"variations":1149,"lastUpdated":1150,"firstPublished":1151,"testRatio":33,"screenshot":1152,"createdBy":34,"lastUpdatedBy":674,"folders":1153,"meta":1154,"rev":440},1746122471259,"5f118e24433d46ceb79f5099987156d7","Shadow SaaS",[1042],{"@type":264,"property":265,"operator":266,"value":1043},"/uc/shadow-saas",{"seoTitle":1045,"seoDescription":1046,"customFonts":1047,"fontAwesomeIcon":1052,"title":1053,"jsCode":37,"tsCode":37,"blocks":1054,"url":1043,"state":1146},"Find and secure shadow SaaS","See and control shadow SaaS in the browser.",[1048],{"kind":273,"variants":1049,"files":1050,"family":272,"version":274,"subsets":1051,"lastModified":275,"category":295,"menu":296},[301,302,303,304,305,306,128,307,308,309,310,311,312,313,314,315,316,317],{"100":277,"200":278,"300":279,"500":280,"600":281,"700":282,"800":283,"900":284,"300italic":293,"500italic":292,"regular":290,"900italic":286,"italic":289,"100italic":288,"200italic":291,"600italic":294,"700italic":287,"800italic":285},[298,299],"faShieldCheck","Secure shadow SaaS",[1055,1141],{"@type":106,"@version":107,"tagName":323,"id":1056,"meta":1057,"children":1058},"builder-04da805c4cd34652a2db452fcda52e1d",{"previousId":935},[1059,1075,1082,1089,1098,1108,1118,1128,1135],{"@type":106,"@version":107,"id":1060,"meta":1061,"component":1062,"responsiveStyles":1073},"builder-830d414faeaf41439142f9157e8288c8",{"previousId":939},{"name":327,"options":1063,"isRSC":118},{"title":1045,"description":1064,"points":1065,"video":1072},"\u003Cp>SaaS sprawl is one of today’s fastest-growing security blind spots because most tools monitor around the edges. Push sees it at the source, in the browser, revealing every app users access, flagging risky tools, and helping you shut down exposure before it leads to a breach. No guesswork. No nasty surprises. Just real-time visibility and control.\u003C/p>",[1066,1068,1070],{"item":1067},"Discover every SaaS app users access, managed or not",{"item":1069},"Spot accounts with weak security postures like missing MFA, unmanaged access, and no SSO",{"item":1071},"Control usage with in-browser prompts, blocks, and security guardrails","https://cdn.builder.io/o/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F3e4eece318d04d6586e691d59d0741cf%2Fcompressed?apiKey=f3a1111ff5be48cdbb123cd9f5795a05&token=3e4eece318d04d6586e691d59d0741cf&alt=media&optimized=true",{"large":1074},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":342},{"@type":106,"@version":107,"id":1076,"meta":1077,"component":1078,"responsiveStyles":1080},"builder-cd7833f966cb4c7e8adf0d6c979414a6",{"previousId":956},{"name":346,"options":1079,"isRSC":118},{"AllPartners":41,"backgroundTransparent":6},{"large":1081},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":350},{"@type":106,"@version":107,"id":1083,"meta":1084,"component":1085,"responsiveStyles":1087},"builder-49d720b45430454e8b08c526f267c19f",{"previousId":963},{"name":354,"options":1086,"isRSC":118},{"darkMode":41},{"large":1088},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":1090,"component":1091,"responsiveStyles":1096},"builder-3dde0bf6c8544e5e9ab41b18a9d68034",{"name":359,"tag":359,"options":1092,"isRSC":118},{"darkMode":6,"maxWidth":363,"maxTextWidth":364,"title":1093,"description":1094,"image":1095,"reverse":6},"\u003Ch2>Use your browser to curb Saas Sprawl\u003C/h2>","\u003Cp>Shadow SaaS isn’t hiding in your network, it’s in your browser. From AI tools to unsanctioned file-sharing sites, security risks live in the apps your users sign into every day. Push maps your organization's true SaaS footprint in real time, exposing apps and accounts with unmanaged access, poor authentication, or no security oversight.\u003C/p>\u003Cp>\u003Cbr>\u003C/p>\u003Cp>\u003Cbr>\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fb6811a214c7949b6bbe0b9a3bca62efd",{"large":1097},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":1099,"meta":1100,"component":1101,"responsiveStyles":1106},"builder-e2420451ccdc4f088d0a4904cff45935",{"previousId":979},{"name":373,"options":1102,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":376,"title":1103,"description":1104,"reverse":41,"image":1105},"\u003Ch2>Discover hidden SaaS usage\u003C/h2>","\u003Cp>Push captures live browser telemetry across every tab and session. Whether a user signs into a sanctioned app with a personal account or tries a new AI plugin, you’ll see it in real time, with no integrations or manual tagging.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fe16e301f9af94665b95d98232a863d8a",{"large":1107},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"fontFamily":382,"paddingTop":384,"marginTop":384},{"@type":106,"@version":107,"id":1109,"meta":1110,"component":1111,"responsiveStyles":1116},"builder-b36de7fce7994beea9e58d94662e7166",{"previousId":989},{"name":373,"options":1112,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":389,"title":1113,"description":1114,"reverse":6,"image":1115},"\u003Ch2>Spot risky access and unsafe usage\u003C/h2>","\u003Cp>Discovery is just the beginning. Push flags apps with risky traits, no MFA, no SSO, known vulnerabilities, or broad access scopes. You’ll know which tools introduce real risk, and which users are exposed so you can act with precision.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F6585f3c242da4d70ae3cb7d02f481bef",{"large":1117},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":395},{"@type":106,"@version":107,"layerName":373,"id":1119,"meta":1120,"component":1121,"responsiveStyles":1126},"builder-dc366b5134684fe7a508edf8913103ea",{"previousId":999},{"name":373,"options":1122,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":400,"title":1123,"description":1124,"reverse":41,"image":1125},"\u003Ch2>Close gaps before they grow\u003C/h2>","\u003Cp>Push turns insight into action. When risky SaaS use is detected, guide users to enable MFA, block high-risk apps, or apply in-browser guardrails automatically. All without deploying new infrastructure or managing dozens of integrations.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fe6d60b6d91414819bc6258a318f00557",{"large":1127},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":406},{"@type":106,"@version":107,"id":1129,"meta":1130,"component":1131,"responsiveStyles":1133},"builder-8708f6f0d8da4b3f9e17bf16cda70219",{"previousId":1009},{"name":354,"options":1132,"isRSC":118},{"darkMode":6},{"large":1134},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":1136,"component":1137,"responsiveStyles":1139},"builder-8ff4b38d60534cf28cb523ab0f754875",{"name":416,"tag":416,"options":1138,"isRSC":118},{"sectionHeading":37,"customClass":418},{"large":1140},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"id":1142,"@type":106,"tagName":131,"properties":1143,"responsiveStyles":1144},"builder-pixel-d1ul2kmxbed",{"src":133,"aria-hidden":134,"alt":37,"role":135,"width":124,"height":124},{"large":1145},{"height":124,"width":124,"display":138,"opacity":124,"overflow":139,"pointerEvents":140},{"deviceSize":142,"location":1147},{"path":37,"query":1148},{},{},1770892936802,1746714967208,"https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F01bfb2304521412fbd2e1a1180904d40",[],{"originalContentId":919,"winningTest":118,"lastPreviewUrl":1155,"breakpoints":1156,"kind":438,"hasLinks":6,"hasAutosaves":6},"https://pushsecurity.com/uc/shadow-saas?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditCode%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CeditProjects%2CmodifyMcpServers%2CmodifyWorkflowIntegrations%2CmodifyProjectSettings%2CconnectCodeRepository%2CcreateProjects%2CindexDesignSystems%2CsendPullRequests&builder.user.role.name=Developer&builder.user.role.id=developer&builder.cachebust=true&builder.preview=use-case-page&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.use-case-page=5f118e24433d46ceb79f5099987156d7&builder.overrides.5f118e24433d46ceb79f5099987156d7=5f118e24433d46ceb79f5099987156d7&builder.overrides.use-case-page:/uc/shadow-saas=5f118e24433d46ceb79f5099987156d7&builder.options.includeRefs=true&builder.options.enrich=true&builder.options.locale=Default",{"xsmall":57,"small":39,"medium":40},{"createdDate":1158,"id":1159,"name":1160,"modelId":261,"published":13,"query":1161,"data":1164,"variations":1268,"lastUpdated":1269,"firstPublished":1270,"testRatio":33,"screenshot":1271,"createdBy":34,"lastUpdatedBy":674,"folders":1272,"meta":1273,"rev":440},1764707470172,"b62629ce2f3741158d961cd10fe74b31","Shadow AI",[1162],{"@type":264,"property":265,"operator":266,"value":1163},"/uc/shadow-ai",{"fontAwesomeIcon":1165,"seoTitle":1166,"jsCode":37,"customFonts":1167,"title":1172,"tsCode":37,"seoDescription":1173,"blocks":1174,"url":1163,"state":1265},"faBrainCircuit","Secure AI native and AI enhanced apps. ",[1168],{"variants":1169,"category":295,"files":1170,"subsets":1171,"family":272,"kind":273,"menu":296,"lastModified":275,"version":274},[301,302,303,304,305,306,128,307,308,309,310,311,312,313,314,315,316,317],{"100":277,"200":278,"300":279,"500":280,"600":281,"700":282,"800":283,"900":284,"800italic":285,"regular":290,"700italic":287,"200italic":291,"italic":289,"500italic":292,"600italic":294,"300italic":293,"100italic":288,"900italic":286},[298,299],"Secure shadow AI","See and control shadow AI apps in the browser.",[1175,1260],{"@type":106,"@version":107,"tagName":323,"id":1176,"meta":1177,"children":1178},"builder-a6e5717a2c914d5695058e4ee201a05d",{"previousId":1056},[1179,1195,1202,1209,1219,1228,1237,1247,1254],{"@type":106,"@version":107,"id":1180,"meta":1181,"component":1182,"responsiveStyles":1193},"builder-3e0ed678683f4a0eb7aa00253cf263b2",{"previousId":1060},{"name":327,"options":1183,"isRSC":118},{"title":1172,"description":1184,"points":1185,"image":1192},"\u003Cp>Your employees are adopting AI faster than you can track it. From native features in corporate apps to unapproved shadow tools, it’s all happening in the browser. Push detects every AI interaction in real time, letting you categorize apps and enforce acceptable use policies in the browser.\u003C/p>",[1186,1188,1190],{"item":1187},"Map every AI tool used across your workforce",{"item":1189},"Review and classify apps by sensitivity, purpose, and policy status",{"item":1191},"Enforce AI usage rules directly in the browser","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F33cf153d920f4e389f3650253577cff7",{"large":1194},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":342},{"@type":106,"@version":107,"id":1196,"meta":1197,"component":1198,"responsiveStyles":1200},"builder-76968f8471d14893b8189d75b08fb426",{"previousId":1076},{"name":346,"options":1199,"isRSC":118},{"AllPartners":41,"backgroundTransparent":6},{"large":1201},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":350},{"@type":106,"@version":107,"id":1203,"meta":1204,"component":1205,"responsiveStyles":1207},"builder-b55b9d4bc5a649d8839ce7f6c2043d95",{"previousId":1083},{"name":354,"options":1206,"isRSC":118},{"darkMode":41},{"large":1208},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":1210,"meta":1211,"component":1212,"responsiveStyles":1217},"builder-c3f38ef4d75d4989a29b5903175ed8a1",{"previousId":1090},{"name":359,"tag":359,"options":1213,"isRSC":118},{"darkMode":6,"maxWidth":363,"maxTextWidth":364,"title":1214,"description":1215,"image":1216,"reverse":6},"\u003Ch2>Use your browser to govern AI \u003C/h2>","\u003Cp>The AI footprint inside your company is bigger than you think. From text generators to meeting assistants and design copilots, employees test, adopt, and connect new tools constantly. Push shows you those tools and which users are accessing them, without relying on network scans or API integrations.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F30b43bda6f1644c19478fb1efa20050c",{"large":1218},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":1220,"meta":1221,"component":1222,"responsiveStyles":1226},"builder-90ee9cb9afc44e7f885523715bf51a53",{"previousId":1099},{"name":373,"options":1223,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":376,"title":1224,"description":1225,"reverse":41,"image":1115},"\u003Ch2>Discover every AI tool users touch\u003C/h2>","\u003Cp>Push captures live telemetry from the browser, identifying every AI-native and AI-enhanced application users access. You’ll know which corporate identities are connected, how data flows, and what new AI apps appear across your environment. \u003C/p>",{"large":1227},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"fontFamily":382,"paddingTop":384,"marginTop":384},{"@type":106,"@version":107,"id":1229,"meta":1230,"component":1231,"responsiveStyles":1235},"builder-9e44539fa53c4d8e87406036c921fc46",{"previousId":1109},{"name":373,"options":1232,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":389,"title":1233,"description":1234,"reverse":6,"image":1125},"\u003Ch2>Classify and manage AI risk\u003C/h2>","\u003Cp>For apps you choose to allow, Push lets you apply custom in-browser banners. You can bulk-select categories of AI tools and require users to read and acknowledge your acceptable use policy before they proceed. This creates an auditable trail and moves policy from an easy to forget document to an active, in-workflow control.\u003C/p>",{"large":1236},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":395},{"@type":106,"@version":107,"layerName":373,"id":1238,"meta":1239,"component":1240,"responsiveStyles":1245},"builder-44c1a891926f4bdeaaa37e90721fe6ac",{"previousId":1119},{"name":373,"options":1241,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":400,"title":1242,"description":1243,"reverse":41,"image":1244},"\u003Ch2>Enforce your AI policy in the browser\u003C/h2>","\u003Cp>When an AI tool is deemed non-compliant or too risky, Push blocks it at the source. The block happens directly in the browser, preventing the user from accessing the site or submitting data. This gives you an immediate, powerful lever to stop data exfiltration and enforce a hard line on unacceptable risk.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fa359ac1805af4e15a8a7f84632b9bb55",{"large":1246},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":406},{"@type":106,"@version":107,"id":1248,"meta":1249,"component":1250,"responsiveStyles":1252},"builder-dcc906f9cbe54dc68b3c672668e7a38f",{"previousId":1129},{"name":354,"options":1251,"isRSC":118},{"darkMode":6},{"large":1253},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":1255,"component":1256,"responsiveStyles":1258},"builder-d2d64780c31b4349bc75805b23a07e38",{"name":416,"tag":416,"options":1257,"isRSC":118},{"sectionHeading":37,"customClass":418},{"large":1259},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"id":1261,"@type":106,"tagName":131,"properties":1262,"responsiveStyles":1263},"builder-pixel-wxx9tk70r9p",{"src":133,"aria-hidden":134,"alt":37,"role":135,"width":124,"height":124},{"large":1264},{"height":124,"width":124,"display":138,"opacity":124,"overflow":139,"pointerEvents":140},{"deviceSize":142,"location":1266},{"path":37,"query":1267},{},{},1770892957225,1764950077593,"https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fe558b8b069884037a8e6904f7ecc029c",[],{"winningTest":118,"breakpoints":1274,"originalContentId":1039,"kind":438,"lastPreviewUrl":1275,"hasLinks":6,"hasAutosaves":41},{"xsmall":57,"small":39,"medium":40},"https://pushsecurity.com/uc/shadow-ai?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditCode%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CeditProjects%2CmodifyMcpServers%2CmodifyWorkflowIntegrations%2CmodifyProjectSettings%2CconnectCodeRepository%2CcreateProjects%2CindexDesignSystems%2CsendPullRequests&builder.user.role.name=Developer&builder.user.role.id=developer&builder.cachebust=true&builder.preview=use-case-page&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.use-case-page=b62629ce2f3741158d961cd10fe74b31&builder.overrides.b62629ce2f3741158d961cd10fe74b31=b62629ce2f3741158d961cd10fe74b31&builder.overrides.use-case-page:/uc/shadow-ai=b62629ce2f3741158d961cd10fe74b31&builder.options.includeRefs=true&builder.options.enrich=true&builder.options.locale=Default",{"_path":1277,"_dir":1278,"_draft":6,"_partial":6,"_locale":37,"sys":1279,"summary":1282,"title":1296,"subtitle":118,"metaTitle":1297,"synopsis":1298,"hashTags":118,"publishedDate":1299,"slug":1300,"ogImage":1301,"tagsCollection":1303,"relatedBlogPostsCollection":1313,"authorsCollection":2986,"content":2990,"_id":3813,"_type":3814,"_source":3815,"_file":3816,"_stem":3817,"_extension":3814},"/blog/key-takeaways-from-the-scattered-spider-attacks-on-insurance-firms","blog",{"id":1280,"publishedAt":1281},"3JS30QKx42bLnGYZh5K9ZP","2025-11-13T19:48:04.209Z",{"json":1283},{"data":1284,"content":1285,"nodeType":1295},{},[1286],{"data":1287,"content":1288,"nodeType":1294},{},[1289],{"data":1290,"marks":1291,"value":1292,"nodeType":1293},{},[],"Scattered Spider continues to dominate the headlines, with the latest news linking the hackers to attacks on U.S. insurance giant Aflac, Philadelphia Insurance Companies, Erie Insurance, Hawaiian Airlines, WestJet, and Qantas. Here's what you need to know to defend your organization. ","text","paragraph","document","3 key takeaways from the Scattered Spider attacks on aviation & insurance firms","Scattered Spider target aviation & insurance firms","Scattered Spider continues to dominate the headlines, with attacks on aviation and insurance companies worldwide.","2025-06-30T00:00:00.000Z","key-takeaways-from-the-scattered-spider-attacks-on-insurance-firms",{"url":1302},"https://images.ctfassets.net/y1cdw1ablpvd/mMbgUER8qJH3p4YF8CsAE/cfc45da4f29fb417a627be97335ab23e/Help_desk_verification_codes.png",{"items":1304},[1305,1309],{"sys":1306,"name":1308},{"id":1307},"6A5RXS31ZQx3PwryGb1IMy","Browser-based attacks",{"sys":1310,"name":1312},{"id":1311},"4ksQNCFeBf8H4QIORqpRLw","Detection & response",{"items":1314},[1315,1981,2349],{"__typename":1316,"sys":1317,"content":1319,"title":1963,"synopsis":1964,"hashTags":118,"publishedDate":1965,"slug":1966,"tagsCollection":1967,"authorsCollection":1973},"BlogPosts",{"id":1318},"3ExexM6DB2QBOQrtbMrXnN",{"json":1320},{"nodeType":1295,"data":1321,"content":1322},{},[1323,1332,1367,1461,1539,1546,1550,1558,1565,1572,1588,1595,1602,1605,1612,1619,1626,1661,1668,1691,1698,1701,1708,1715,1734,1823,1830,1836,1839,1846,1853,1860,1866,1888,1894,1901,1904,1911,1931,1951,1957],{"nodeType":1324,"data":1325,"content":1331},"embedded-entry-block",{"target":1326},{"sys":1327},{"id":1328,"type":1329,"linkType":1330},"6BjaSruVecmhn1NoHreRni","Link","Entry",[],{"nodeType":1294,"data":1333,"content":1334},{},[1335,1339,1350,1354,1363],{"nodeType":1293,"value":1336,"marks":1337,"data":1338},"Scattered Spider have been busy. Major breaches of UK retailers ",[],{},{"nodeType":1340,"data":1341,"content":1343},"hyperlink",{"uri":1342},"https://www.bleepingcomputer.com/news/security/mands-says-customer-data-stolen-in-cyberattack-forces-password-resets/",[1344],{"nodeType":1293,"value":1345,"marks":1346,"data":1349},"Marks and Spencer",[1347],{"type":1348},"underline",{},{"nodeType":1293,"value":1351,"marks":1352,"data":1353}," and ",[],{},{"nodeType":1340,"data":1355,"content":1357},{"uri":1356},"https://www.bleepingcomputer.com/news/security/co-op-confirms-data-theft-after-dragonforce-ransomware-claims-attack/",[1358],{"nodeType":1293,"value":1359,"marks":1360,"data":1362},"Co-op",[1361],{"type":1348},{},{"nodeType":1293,"value":1364,"marks":1365,"data":1366}," resulted in the loss of sensitive data and prolonged disruption to in-store and digital services, with M&S feeling the pain of £300m in lost profits and a share value hit approaching £1b, and a multimillion-pound class action lawsuit and possible ICO fines looming.",[],{},{"nodeType":1294,"data":1368,"content":1369},{},[1370,1374,1383,1387,1396,1399,1408,1411,1420,1423,1432,1435,1444,1448,1457],{"nodeType":1293,"value":1371,"marks":1372,"data":1373},"A series of attacks against retailers worldwide soon followed, at an unprecedented rate. ",[],{},{"nodeType":1340,"data":1375,"content":1377},{"uri":1376},"https://www.bleepingcomputer.com/news/security/fashion-giant-dior-discloses-cyberattack-warns-of-data-breach/",[1378],{"nodeType":1293,"value":1379,"marks":1380,"data":1382},"Dior",[1381],{"type":1348},{},{"nodeType":1293,"value":1384,"marks":1385,"data":1386},", ",[],{},{"nodeType":1340,"data":1388,"content":1390},{"uri":1389},"https://www.bleepingcomputer.com/news/security/the-north-face-warns-customers-of-april-credential-stuffing-attack/",[1391],{"nodeType":1293,"value":1392,"marks":1393,"data":1395},"The North Face",[1394],{"type":1348},{},{"nodeType":1293,"value":1384,"marks":1397,"data":1398},[],{},{"nodeType":1340,"data":1400,"content":1402},{"uri":1401},"https://www.bleepingcomputer.com/news/security/cartier-discloses-data-breach-amid-fashion-brand-cyberattacks/",[1403],{"nodeType":1293,"value":1404,"marks":1405,"data":1407},"Cartier",[1406],{"type":1348},{},{"nodeType":1293,"value":1384,"marks":1409,"data":1410},[],{},{"nodeType":1340,"data":1412,"content":1414},{"uri":1413},"https://www.bleepingcomputer.com/news/security/victorias-secret-delays-earnings-release-after-security-incident/",[1415],{"nodeType":1293,"value":1416,"marks":1417,"data":1419},"Victoria’s Secret",[1418],{"type":1348},{},{"nodeType":1293,"value":1384,"marks":1421,"data":1422},[],{},{"nodeType":1340,"data":1424,"content":1426},{"uri":1425},"https://www.bleepingcomputer.com/news/security/adidas-warns-of-data-breach-after-customer-service-provider-hack/",[1427],{"nodeType":1293,"value":1428,"marks":1429,"data":1431},"Adidas",[1430],{"type":1348},{},{"nodeType":1293,"value":1384,"marks":1433,"data":1434},[],{},{"nodeType":1340,"data":1436,"content":1438},{"uri":1437},"https://www.scworld.com/brief/separate-ransomware-attacks-purportedly-hit-coca-cola-bottling-partner",[1439],{"nodeType":1293,"value":1440,"marks":1441,"data":1443},"Coca-Cola",[1442],{"type":1348},{},{"nodeType":1293,"value":1445,"marks":1446,"data":1447},", and ",[],{},{"nodeType":1340,"data":1449,"content":1451},{"uri":1450},"https://www.bleepingcomputer.com/news/security/grocery-wholesale-giant-united-natural-foods-hit-by-cyberattack/",[1452],{"nodeType":1293,"value":1453,"marks":1454,"data":1456},"United Natural Foods",[1455],{"type":1348},{},{"nodeType":1293,"value":1458,"marks":1459,"data":1460}," were among the retailers to suffer a breach between May-June 2025. ",[],{},{"nodeType":1294,"data":1462,"content":1463},{},[1464,1468,1477,1480,1489,1493,1502,1506,1514,1517,1525,1528,1535],{"nodeType":1293,"value":1465,"marks":1466,"data":1467},"The latest news links the hackers to attacks on ",[],{},{"nodeType":1340,"data":1469,"content":1471},{"uri":1470},"https://www.bleepingcomputer.com/news/security/aflac-discloses-breach-amidst-scattered-spider-insurance-attacks/",[1472],{"nodeType":1293,"value":1473,"marks":1474,"data":1476},"Aflac",[1475],{"type":1348},{},{"nodeType":1293,"value":1384,"marks":1478,"data":1479},[],{},{"nodeType":1340,"data":1481,"content":1483},{"uri":1482},"https://www.bleepingcomputer.com/news/security/google-warns-scattered-spider-hackers-now-target-us-insurance-companies/",[1484],{"nodeType":1293,"value":1485,"marks":1486,"data":1488},"Philadelphia Insurance Companies",[1487],{"type":1348},{},{"nodeType":1293,"value":1490,"marks":1491,"data":1492},",  ",[],{},{"nodeType":1340,"data":1494,"content":1496},{"uri":1495},"https://www.bleepingcomputer.com/news/security/erie-insurance-confirms-cyberattack-behind-business-disruptions/amp/",[1497],{"nodeType":1293,"value":1498,"marks":1499,"data":1501},"Erie Insurance",[1500],{"type":1348},{},{"nodeType":1293,"value":1503,"marks":1504,"data":1505},", and most recently ",[],{},{"nodeType":1340,"data":1507,"content":1509},{"uri":1508},"https://www.bleepingcomputer.com/news/security/qantas-is-being-extorted-in-recent-data-theft-cyberattack/",[1510],{"nodeType":1293,"value":1511,"marks":1512,"data":1513},"Qantas",[],{},{"nodeType":1293,"value":1384,"marks":1515,"data":1516},[],{},{"nodeType":1340,"data":1518,"content":1520},{"uri":1519},"https://www.bleepingcomputer.com/news/security/scattered-spider-hackers-shift-focus-to-aviation-transportation-firms/",[1521],{"nodeType":1293,"value":1522,"marks":1523,"data":1524},"Hawaiian Airlines",[],{},{"nodeType":1293,"value":1351,"marks":1526,"data":1527},[],{},{"nodeType":1340,"data":1529,"content":1530},{"uri":1519},[1531],{"nodeType":1293,"value":1532,"marks":1533,"data":1534},"WestJet",[],{},{"nodeType":1293,"value":1536,"marks":1537,"data":1538},". ",[],{},{"nodeType":1294,"data":1540,"content":1541},{},[1542],{"nodeType":1293,"value":1543,"marks":1544,"data":1545},"The top story from recent campaigns is the use of help desk scams. This typically involves the attacker calling up a company’s help desk with some level of information — at minimum, PII that allows them to impersonate their victim, and sometimes a password, leaning heavily on their native English-speaking abilities to trick the help desk operator into giving them access to a user account. ",[],{},{"nodeType":1547,"data":1548,"content":1549},"hr",{},[],{"nodeType":1551,"data":1552,"content":1553},"heading-1",{},[1554],{"nodeType":1293,"value":1555,"marks":1556,"data":1557},"Help desk scams 101",[],{},{"nodeType":1294,"data":1559,"content":1560},{},[1561],{"nodeType":1293,"value":1562,"marks":1563,"data":1564},"The goal of a help desk scam is to get the help desk operator to reset the credentials and/or MFA used to access an account so the attacker can take control of it. They’ll use a variety of backstories and tactics to get that done, but most of the time it’s as simple as saying “I’ve got a new phone, can you remove my existing MFA and allow me to enroll a new one?”",[],{},{"nodeType":1294,"data":1566,"content":1567},{},[1568],{"nodeType":1293,"value":1569,"marks":1570,"data":1571},"From there, the attacker is then sent an MFA reset link via email or SMS. Usually, this would be sent to, for example, a number on file — but at this point, the attacker has already established trust and bypassed the help desk process to a degree. So asking “can you send it to this email address” or “I’ve actually got a new number too, can you send it to…” gets this sent directly to the attacker. ",[],{},{"nodeType":1294,"data":1573,"content":1574},{},[1575,1579,1584],{"nodeType":1293,"value":1576,"marks":1577,"data":1578},"At this point, it’s simply a case of using the self service password reset functionality for Okta or Entra (which you can get around because you now have the MFA factor to verify yourself) and ",[],{},{"nodeType":1293,"value":1580,"marks":1581,"data":1583},"voila",[1582],{"type":312},{},{"nodeType":1293,"value":1585,"marks":1586,"data":1587},", the attacker has taken control of the account. ",[],{},{"nodeType":1294,"data":1589,"content":1590},{},[1591],{"nodeType":1293,"value":1592,"marks":1593,"data":1594},"And the best part? Most help desks have the same process for every account — it doesn’t matter who you’re impersonating or which account you’re trying to reset. So, attackers are specifically targeting accounts likely to have top tier admin privileges — meaning once they get in, progressing the attack is trivial and much of the typical privilege escalation and lateral movement is removed from the attack path. ",[],{},{"nodeType":1294,"data":1596,"content":1597},{},[1598],{"nodeType":1293,"value":1599,"marks":1600,"data":1601},"So, help desk scams have proved to be a reliable way of bypassing MFA and achieving account takeover — the foothold from which to launch the rest of an attack, such as stealing data, deploying ransomware, etc. ",[],{},{"nodeType":1547,"data":1603,"content":1604},{},[],{"nodeType":1551,"data":1606,"content":1607},{},[1608],{"nodeType":1293,"value":1609,"marks":1610,"data":1611},"Avoiding help desk gotchas",[],{},{"nodeType":1294,"data":1613,"content":1614},{},[1615],{"nodeType":1293,"value":1616,"marks":1617,"data":1618},"There’s lots of advice for securing help desks being circulated, but much of the advice still results in a process that is either phishable or difficult to implement. ",[],{},{"nodeType":1294,"data":1620,"content":1621},{},[1622],{"nodeType":1293,"value":1623,"marks":1624,"data":1625},"Ultimately, organizations need to be prepared to introduce friction to their help desk process and either delay or deny requests in situations where there’s significant risk. So, for example, having a process for MFA reset that recognizes the risk associated with resetting a high-privileged account:",[],{},{"nodeType":1627,"data":1628,"content":1629},"unordered-list",{},[1630,1641,1651],{"nodeType":1631,"data":1632,"content":1633},"list-item",{},[1634],{"nodeType":1294,"data":1635,"content":1636},{},[1637],{"nodeType":1293,"value":1638,"marks":1639,"data":1640},"Require multi-party approval / escalation for admin-level account resets",[],{},{"nodeType":1631,"data":1642,"content":1643},{},[1644],{"nodeType":1294,"data":1645,"content":1646},{},[1647],{"nodeType":1293,"value":1648,"marks":1649,"data":1650},"Require in-person verification if the process can’t be followed remotely",[],{},{"nodeType":1631,"data":1652,"content":1653},{},[1654],{"nodeType":1294,"data":1655,"content":1656},{},[1657],{"nodeType":1293,"value":1658,"marks":1659,"data":1660},"Freeze self-service resets when suspicious behavior is encountered (this would require some kind of internal process and awareness training to raise the alarm if an attack is suspected)",[],{},{"nodeType":1294,"data":1662,"content":1663},{},[1664],{"nodeType":1293,"value":1665,"marks":1666,"data":1667},"And watch out for these gotchas: ",[],{},{"nodeType":1627,"data":1669,"content":1670},{},[1671,1681],{"nodeType":1631,"data":1672,"content":1673},{},[1674],{"nodeType":1294,"data":1675,"content":1676},{},[1677],{"nodeType":1293,"value":1678,"marks":1679,"data":1680},"If you receive a call, good practice is to terminate the call and dial the number on file for the employee. But, in a world of SIM swapping, this isn’t a foolproof solution — you could just be re-dialing the attacker. ",[],{},{"nodeType":1631,"data":1682,"content":1683},{},[1684],{"nodeType":1294,"data":1685,"content":1686},{},[1687],{"nodeType":1293,"value":1688,"marks":1689,"data":1690},"If your solution is to get the employee on camera, increasingly sophisticated deepfakes can thwart this approach.  ",[],{},{"nodeType":1294,"data":1692,"content":1693},{},[1694],{"nodeType":1293,"value":1695,"marks":1696,"data":1697},"But, help desks are a target for a reason. They’re “helpful” by nature. This is usually reflected in how they’re operated and performance measured — delays won’t help you to hit those SLAs! Ultimately, a process only works if employees are willing to adhere to it — and can’t be socially engineered to break it. Help desks that are removed from day-to-day operations (especially when outsourced or offshored) are also inherently susceptible to attacks where employees are impersonated. ",[],{},{"nodeType":1547,"data":1699,"content":1700},{},[],{"nodeType":1551,"data":1702,"content":1703},{},[1704],{"nodeType":1293,"value":1705,"marks":1706,"data":1707},"Comparing help desk scams with other approaches",[],{},{"nodeType":1294,"data":1709,"content":1710},{},[1711],{"nodeType":1293,"value":1712,"marks":1713,"data":1714},"Taking a step back, it’s worth thinking about how help desk scams fit into the wider toolkit of tactics, techniques and procedures (TTPs) used by threat actors like Scattered Spider. ",[],{},{"nodeType":1294,"data":1716,"content":1717},{},[1718,1721,1730],{"nodeType":1293,"value":37,"marks":1719,"data":1720},[],{},{"nodeType":1340,"data":1722,"content":1724},{"uri":1723},"https://pushsecurity.com/blog/scattered-spider-ttp-evolution-in-2025/",[1725],{"nodeType":1293,"value":1726,"marks":1727,"data":1729},"Scattered Spider has heavily relied on identity-based TTPs since they first emerged in 2022",[1728],{"type":1348},{},{"nodeType":1293,"value":1731,"marks":1732,"data":1733},", following a repeatable path of bypassing MFA, achieving account takeover on privileged accounts, stealing data from cloud services, and deploying ransomware (principally to VMware environments). ",[],{},{"nodeType":1627,"data":1735,"content":1736},{},[1737,1747,1757,1780,1790,1800],{"nodeType":1631,"data":1738,"content":1739},{},[1740],{"nodeType":1294,"data":1741,"content":1742},{},[1743],{"nodeType":1293,"value":1744,"marks":1745,"data":1746},"Credential phishing via email and SMS (smishing) to harvest passwords en masse",[],{},{"nodeType":1631,"data":1748,"content":1749},{},[1750],{"nodeType":1294,"data":1751,"content":1752},{},[1753],{"nodeType":1293,"value":1754,"marks":1755,"data":1756},"Using SIM swapping (where you get the carrier to transfer a number to your attacker-controlled SIM card) to bypass SMS-based MFA",[],{},{"nodeType":1631,"data":1758,"content":1759},{},[1760],{"nodeType":1294,"data":1761,"content":1762},{},[1763,1767,1776],{"nodeType":1293,"value":1764,"marks":1765,"data":1766},"Using ",[],{},{"nodeType":1340,"data":1768,"content":1770},{"uri":1769},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/mfa_fatigue/description.md",[1771],{"nodeType":1293,"value":1772,"marks":1773,"data":1775},"MFA fatigue",[1774],{"type":1348},{},{"nodeType":1293,"value":1777,"marks":1778,"data":1779}," (aka. push bombing) to bypass app-based push authentication",[],{},{"nodeType":1631,"data":1781,"content":1782},{},[1783],{"nodeType":1294,"data":1784,"content":1785},{},[1786],{"nodeType":1293,"value":1787,"marks":1788,"data":1789},"Using vishing (i.e. directly calling a victim to social engineer their MFA code, as opposed to a help desk attack)",[],{},{"nodeType":1631,"data":1791,"content":1792},{},[1793],{"nodeType":1294,"data":1794,"content":1795},{},[1796],{"nodeType":1293,"value":1797,"marks":1798,"data":1799},"Social engineering domain registrars to take control of the target organization’s DNS, hijacking their MX records and inbound mail, and using this to take over the company’s business app environments ",[],{},{"nodeType":1631,"data":1801,"content":1802},{},[1803],{"nodeType":1294,"data":1804,"content":1805},{},[1806,1810,1819],{"nodeType":1293,"value":1807,"marks":1808,"data":1809},"And latterly, using ",[],{},{"nodeType":1340,"data":1811,"content":1813},{"uri":1812},"https://pushsecurity.com/blog/phishing-2-0-how-phishing-toolkits-are-evolving-with-aitm/",[1814],{"nodeType":1293,"value":1815,"marks":1816,"data":1818},"MFA-bypass AiTM phishing kits like Evilginx",[1817],{"type":1348},{},{"nodeType":1293,"value":1820,"marks":1821,"data":1822}," to steal live user sessions, bypassing all common forms of MFA (with the exception of WebAuthn/FIDO2) ",[],{},{"nodeType":1294,"data":1824,"content":1825},{},[1826],{"nodeType":1293,"value":1827,"marks":1828,"data":1829},"So, help desk scams are an important part of their toolkit, but it’s not the whole picture. Methods like AiTM in particular have spiked in popularity this year as a reliable and scalable way of bypassing MFA and achieving account takeover, with attackers using these toolkits as the de facto standard, getting creative in their detection evasion methods and in some cases, evading standard delivery vectors like email altogether to ensure the success of their phishing campaigns. ",[],{},{"nodeType":1324,"data":1831,"content":1835},{"target":1832},{"sys":1833},{"id":1834,"type":1329,"linkType":1330},"2F2dpOkyXWnrKgFC3dSl67",[],{"nodeType":1547,"data":1837,"content":1838},{},[],{"nodeType":1551,"data":1840,"content":1841},{},[1842],{"nodeType":1293,"value":1843,"marks":1844,"data":1845},"Stop identity attacks with Push Security",[],{},{"nodeType":1294,"data":1847,"content":1848},{},[1849],{"nodeType":1293,"value":1850,"marks":1851,"data":1852},"Modern attacks no longer take place on the endpoint or network — they target identities created and used via the web browser. This means that attacks increasingly take place in the browser (or rather, on resources your employees access through the browser). ",[],{},{"nodeType":1294,"data":1854,"content":1855},{},[1856],{"nodeType":1293,"value":1857,"marks":1858,"data":1859},"Push Security’s browser-based security platform provides comprehensive identity attack detection and response capabilities against techniques like AiTM phishing, credential stuffing, password spraying and session hijacking using stolen session tokens. You can also use Push to find and fix identity vulnerabilities across every app that your employees use, like: ghost logins; SSO coverage gaps; MFA gaps; weak, breached and reused passwords; risky OAuth integrations; and more. ",[],{},{"nodeType":1324,"data":1861,"content":1865},{"target":1862},{"sys":1863},{"id":1864,"type":1329,"linkType":1330},"4atESpAAPAC0zP8CO4m8oa",[],{"nodeType":1294,"data":1867,"content":1868},{},[1869,1873,1884],{"nodeType":1293,"value":1870,"marks":1871,"data":1872},"To help combat help desk scams, we recently released ",[],{},{"nodeType":1340,"data":1874,"content":1876},{"uri":1875},"https://pushsecurity.com/blog/employee-identity-verification-codes-release/",[1877],{"nodeType":1293,"value":1878,"marks":1879,"data":1883},"Employee Identity Verification Codes",[1880,1881],{"type":1348},{"type":1882},"bold",{},{"nodeType":1293,"value":1885,"marks":1886,"data":1887}," — a simple, browser-based identity check that gives your help desk a reliable way to confirm they’re talking to someone from your organization.",[],{},{"nodeType":1324,"data":1889,"content":1893},{"target":1890},{"sys":1891},{"id":1892,"type":1329,"linkType":1330},"1TEpCjh8UGwmejgYSGC1by",[],{"nodeType":1294,"data":1895,"content":1896},{},[1897],{"nodeType":1293,"value":1898,"marks":1899,"data":1900},"It enables legitimate help desk callers to quickly verify that they’re in possession of their primary device (i.e. laptop) by relaying a rotating 6-digit verification code in their browser via the Push extension. This is a great way to securely confirm caller identity and sniff out fraudulent callers, and can be used as part of a phishing-resistant help desk process. ",[],{},{"nodeType":1547,"data":1902,"content":1903},{},[],{"nodeType":1551,"data":1905,"content":1906},{},[1907],{"nodeType":1293,"value":1908,"marks":1909,"data":1910},"Get started today!",[],{},{"nodeType":1294,"data":1912,"content":1913},{},[1914,1918,1927],{"nodeType":1293,"value":1915,"marks":1916,"data":1917},"You can use Employee Verification Codes as a free tool by installing the Push browser extension. Simply ",[],{},{"nodeType":1340,"data":1919,"content":1921},{"uri":1920},"https://pushsecurity.com/free-tool/employee-verification-codes",[1922],{"nodeType":1293,"value":1923,"marks":1924,"data":1926},"sign up for a trial account and you can deploy the extension organization-wide to make use of this feature",[1925],{"type":1348},{},{"nodeType":1293,"value":1928,"marks":1929,"data":1930},". While you’re at it, you can trial Push’s full features for up to 10 users for free. ",[],{},{"nodeType":1294,"data":1932,"content":1933},{},[1934,1938,1947],{"nodeType":1293,"value":1935,"marks":1936,"data":1937},"Or if you want to learn more about how Push helps you to detect and defeat common identity attack techniques, ",[],{},{"nodeType":1340,"data":1939,"content":1941},{"uri":1940},"https://pushsecurity.com/demo/",[1942],{"nodeType":1293,"value":1943,"marks":1944,"data":1946},"book some time with one of our team for a live demo",[1945],{"type":1348},{},{"nodeType":1293,"value":1948,"marks":1949,"data":1950},".",[],{},{"nodeType":1324,"data":1952,"content":1956},{"target":1953},{"sys":1954},{"id":1955,"type":1329,"linkType":1330},"6Td0hDBYdeT8tlnnfwipmD",[],{"nodeType":1294,"data":1958,"content":1959},{},[1960],{"nodeType":1293,"value":37,"marks":1961,"data":1962},[],{},"Scattered Spider: Understanding help desk scams and how to defend your organization","Scattered Spider has dominated the headlines in recent months with a consistent focus on help desk scams. Here's what you need to know to protect your business.","2025-06-27T00:00:00.000Z","scattered-spider-defending-against-help-desk-scams",{"items":1968},[1969,1971],{"sys":1970,"name":1308},{"id":1307},{"sys":1972,"name":1312},{"id":1311},{"items":1974},[1975],{"fullName":1976,"firstName":1977,"jobTitle":1978,"profilePicture":1979},"Dan Green","Dan","Threat Research",{"url":1980},"https://images.ctfassets.net/y1cdw1ablpvd/7jik1VhFgA3kgzXBXTm2Vw/fcd8c171da644903d0827eafcfbcaad0/Dan_Headshot_2025.png",{"__typename":1316,"sys":1982,"content":1984,"title":2331,"synopsis":2332,"hashTags":118,"publishedDate":2333,"slug":2334,"tagsCollection":2335,"authorsCollection":2341},{"id":1983},"4rLP8wr6HnvBG2OzqYYKpF",{"json":1985},{"nodeType":1295,"data":1986,"content":1987},{},[1988,1995,2002,2009,2015,2022,2055,2062,2069,2076,2082,2089,2096,2114,2119,2127,2147,2167,2174,2181,2188,2195,2202,2209,2216,2236,2243,2250,2256,2262,2269,2294,2300,2319,2325],{"nodeType":1294,"data":1989,"content":1990},{},[1991],{"nodeType":1293,"value":1992,"marks":1993,"data":1994},"Scattered Spider has shown the world the devastating effects attackers can achieve by socially engineering IT help desks into performing MFA resets so they can take over accounts on sensitive corporate apps. ",[],{},{"nodeType":1294,"data":1996,"content":1997},{},[1998],{"nodeType":1293,"value":1999,"marks":2000,"data":2001},"That’s why we’re introducing Employee Identity Verification Codes — a simple, browser-based identity check that gives your help desk a reliable way to confirm they’re talking to someone from your organization.",[],{},{"nodeType":1294,"data":2003,"content":2004},{},[2005],{"nodeType":1293,"value":2006,"marks":2007,"data":2008},"Push now provides your employees with a rotating 6-digit verification code in their browser via the Push Security extension. When an employee contacts your IT help desk to request an MFA reset or access recovery, the help desk can ask for this code to verify their identity — ensuring it’s really them, and not an attacker.",[],{},{"nodeType":1324,"data":2010,"content":2014},{"target":2011},{"sys":2012},{"id":2013,"type":1329,"linkType":1330},"3PkiGgzwSt9Nb5rsGRiQVZ",[],{"nodeType":1294,"data":2016,"content":2017},{},[2018],{"nodeType":1293,"value":2019,"marks":2020,"data":2021},"The employee identity verification codes are:",[],{},{"nodeType":1627,"data":2023,"content":2024},{},[2025,2035,2045],{"nodeType":1631,"data":2026,"content":2027},{},[2028],{"nodeType":1294,"data":2029,"content":2030},{},[2031],{"nodeType":1293,"value":2032,"marks":2033,"data":2034},"Session-aware - generated in users’ browsers and only visible to them when they click on the Push Security extension icon in their browser toolbar.",[],{},{"nodeType":1631,"data":2036,"content":2037},{},[2038],{"nodeType":1294,"data":2039,"content":2040},{},[2041],{"nodeType":1293,"value":2042,"marks":2043,"data":2044},"Rotating: they change every 24 hours",[],{},{"nodeType":1631,"data":2046,"content":2047},{},[2048],{"nodeType":1294,"data":2049,"content":2050},{},[2051],{"nodeType":1293,"value":2052,"marks":2053,"data":2054},"Lightweight: no additional apps or devices required",[],{},{"nodeType":1294,"data":2056,"content":2057},{},[2058],{"nodeType":1293,"value":2059,"marks":2060,"data":2061},"It’s a fast, simple verification method — directly in the employee’s browser — that addresses a real-world threat.",[],{},{"nodeType":1551,"data":2063,"content":2064},{},[2065],{"nodeType":1293,"value":2066,"marks":2067,"data":2068},"We think it’s swell, but don’t just take our word for it …",[],{},{"nodeType":1294,"data":2070,"content":2071},{},[2072],{"nodeType":1293,"value":2073,"marks":2074,"data":2075},"Eric Rubin — a Senior Manager in GitLab’s Corporate Security team — has already rolled out Employee Identity Verification Codes across his workforce. Here’s what he had to say about it:",[],{},{"nodeType":1324,"data":2077,"content":2081},{"target":2078},{"sys":2079},{"id":2080,"type":1329,"linkType":1330},"5ZLaA869NXpMjVwkswEyOB",[],{"nodeType":1294,"data":2083,"content":2084},{},[2085],{"nodeType":1293,"value":2086,"marks":2087,"data":2088},"Thank you, Eric!",[],{},{"nodeType":1551,"data":2090,"content":2091},{},[2092],{"nodeType":1293,"value":2093,"marks":2094,"data":2095},"Why are help desk identity verification methods so hot right now?",[],{},{"nodeType":1294,"data":2097,"content":2098},{},[2099,2103,2110],{"nodeType":1293,"value":2100,"marks":2101,"data":2102},"A number of the high-profile incidents attributed to the ",[],{},{"nodeType":1340,"data":2104,"content":2105},{"uri":1723},[2106],{"nodeType":1293,"value":2107,"marks":2108,"data":2109},"Scattered Spider cybercriminal group",[],{},{"nodeType":1293,"value":2111,"marks":2112,"data":2113}," saw them socially engineer IT help desks into resetting MFA on employee accounts that they had already acquired valid credentials for. These compromised accounts were typically on IdP systems like Okta providing SSO access to large numbers of downstream applications.",[],{},{"nodeType":1324,"data":2115,"content":2118},{"target":2116},{"sys":2117},{"id":1834,"type":1329,"linkType":1330},[],{"nodeType":2120,"data":2121,"content":2122},"heading-2",{},[2123],{"nodeType":1293,"value":2124,"marks":2125,"data":2126},"Case study: The MGM Resorts breach",[],{},{"nodeType":1294,"data":2128,"content":2129},{},[2130,2134,2143],{"nodeType":1293,"value":2131,"marks":2132,"data":2133},"One of Scattered Spider’s most notorious and well-documented attacks was against ",[],{},{"nodeType":1340,"data":2135,"content":2137},{"uri":2136},"https://pushsecurity.com/blog/identity-attacks-in-the-wild/#id-mgm-resorts-september-2023",[2138],{"nodeType":1293,"value":2139,"marks":2140,"data":2142},"MGM Resorts",[2141],{"type":1348},{},{"nodeType":1293,"value":2144,"marks":2145,"data":2146},". Scattered Spider socially engineered MGM Resorts’ help desk personnel to bypass MFA and log in to accounts for which they had acquired valid login credentials via credential phishing and historical infostealer compromises. ",[],{},{"nodeType":1294,"data":2148,"content":2149},{},[2150,2154,2163],{"nodeType":1293,"value":2151,"marks":2152,"data":2153},"They specifically targeted accounts with Super Administrator privileges within MGM Resorts’ Okta tenant, which they then used to register a second, attacker-controlled IdP via ",[],{},{"nodeType":1340,"data":2155,"content":2157},{"uri":2156},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/inbound_federation/description.md",[2158],{"nodeType":1293,"value":2159,"marks":2160,"data":2162},"inbound federation",[2161],{"type":1348},{},{"nodeType":1293,"value":2164,"marks":2165,"data":2166},". This then enabled them to impersonate any user within the Okta tenant. ",[],{},{"nodeType":1294,"data":2168,"content":2169},{},[2170],{"nodeType":1293,"value":2171,"marks":2172,"data":2173},"The attackers were then able to abuse SSO access to downstream apps and platforms from various accounts, culminating in deployment of ransomware to around 100 ESXi servers and data exfiltration. ",[],{},{"nodeType":1294,"data":2175,"content":2176},{},[2177],{"nodeType":1293,"value":2178,"marks":2179,"data":2180},"The breach resulted in a 36-hour outage, a $100M hit to its Q3 results, one-time cyber consulting fees in the region of $10M, and a class-action lawsuit later settled for $45M. ",[],{},{"nodeType":2120,"data":2182,"content":2183},{},[2184],{"nodeType":1293,"value":2185,"marks":2186,"data":2187},"Reassessing help desk verification processes",[],{},{"nodeType":1294,"data":2189,"content":2190},{},[2191],{"nodeType":1293,"value":2192,"marks":2193,"data":2194},"Scattered Spider’s high-profile attacks — including its most recent against UK retailers Marks & Spencer’s and the Co-op — has prompted many security teams to reassess the verification processes used by their IT help desks when an employee requests an MFA reset or access to sensitive applications. ",[],{},{"nodeType":1294,"data":2196,"content":2197},{},[2198],{"nodeType":1293,"value":2199,"marks":2200,"data":2201},"Initial guidance from across the industry included the use of call-back verification for any MFA or credential changes requested by an employee. However, Scattered Spider are also known to use SIM-swapping to trick mobile carriers into transferring a victim’s phone number to a SIM card controlled by the attacker - thereby allowing them to intercept verification calls. ",[],{},{"nodeType":1551,"data":2203,"content":2204},{},[2205],{"nodeType":1293,"value":2206,"marks":2207,"data":2208},"Simple verification using your employees’ browsers",[],{},{"nodeType":1294,"data":2210,"content":2211},{},[2212],{"nodeType":1293,"value":2213,"marks":2214,"data":2215},"Push already provides several controls that directly align to the other TTPs used by Scattered Spider. They include detecting stolen credentials, cloned login pages, AitM toolkits and compromised IdP sessions. ",[],{},{"nodeType":1294,"data":2217,"content":2218},{},[2219,2223,2232],{"nodeType":1293,"value":2220,"marks":2221,"data":2222},"(BTW, if this piques your interest, you can ",[],{},{"nodeType":1340,"data":2224,"content":2226},{"uri":2225},"https://pushsecurity.com/resources?type=webinar#content",[2227],{"nodeType":1293,"value":2228,"marks":2229,"data":2231},"stream our latest webinar",[2230],{"type":1348},{},{"nodeType":1293,"value":2233,"marks":2234,"data":2235}," where we deep-dive into Scattered Spider, how their TTPs are evolving in 2025, and what Push is doing to protect organizations against them.) ",[],{},{"nodeType":1294,"data":2237,"content":2238},{},[2239],{"nodeType":1293,"value":2240,"marks":2241,"data":2242},"But to provide our customers with an additional layer of defense against the Scattered Spider attack chain, we wanted to see how we could make it harder for attackers to socially engineer IT help desks into gaining access to IdP systems and sensitive apps.",[],{},{"nodeType":1294,"data":2244,"content":2245},{},[2246],{"nodeType":1293,"value":2247,"marks":2248,"data":2249},"As so often is the case, the answer was staring us right in the face - we can use our browser extension. By placing a verification code in the details tray of every employees’ Push extension, they can use that to verify their identity with their help desk team.",[],{},{"nodeType":1324,"data":2251,"content":2255},{"target":2252},{"sys":2253},{"id":2254,"type":1329,"linkType":1330},"4hRJVGqKGyOHJ8NSsQYWGP",[],{"nodeType":1551,"data":2257,"content":2258},{},[2259],{"nodeType":1293,"value":1908,"marks":2260,"data":2261},[],{},{"nodeType":1294,"data":2263,"content":2264},{},[2265],{"nodeType":1293,"value":2266,"marks":2267,"data":2268},"Employee verification codes is a Labs feature, which means it’s available on an early-access basis. We're particularly interested in hearing your feedback on how to develop this feature further.",[],{},{"nodeType":1294,"data":2270,"content":2271},{},[2272,2276,2281,2285,2290],{"nodeType":1293,"value":2273,"marks":2274,"data":2275},"You can enable Labs features by going to the ",[],{},{"nodeType":1293,"value":2277,"marks":2278,"data":2280},"Settings",[2279],{"type":1882},{},{"nodeType":1293,"value":2282,"marks":2283,"data":2284}," page of the Push admin console and choosing the ",[],{},{"nodeType":1293,"value":2286,"marks":2287,"data":2289},"Labs",[2288],{"type":1882},{},{"nodeType":1293,"value":2291,"marks":2292,"data":2293}," tab.",[],{},{"nodeType":1324,"data":2295,"content":2299},{"target":2296},{"sys":2297},{"id":2298,"type":1329,"linkType":1330},"6TyqP2eOmalIF6RRoe476Y",[],{"nodeType":1294,"data":2301,"content":2302},{},[2303,2307,2315],{"nodeType":1293,"value":2304,"marks":2305,"data":2306},"If you’d like to find out more about this feature, and the other ways Push is stopping identity attacks in the browser, ",[],{},{"nodeType":1340,"data":2308,"content":2309},{"uri":1940},[2310],{"nodeType":1293,"value":2311,"marks":2312,"data":2314},"book a demo",[2313],{"type":1348},{},{"nodeType":1293,"value":2316,"marks":2317,"data":2318}," with one of our team. ",[],{},{"nodeType":1324,"data":2320,"content":2324},{"target":2321},{"sys":2322},{"id":2323,"type":1329,"linkType":1330},"7xBE9MrnMy3hfwIkhLhNhQ",[],{"nodeType":1294,"data":2326,"content":2327},{},[2328],{"nodeType":1293,"value":37,"marks":2329,"data":2330},[],{},"A simple, browser-based way to protect your help desk against social engineering","Push's new Employee Identity Verification Codes feature is a simple way for your help desk to confirm they’re talking to someone from your organization.\n","2025-06-19T00:00:00.000Z","employee-identity-verification-codes-release",{"items":2336},[2337],{"sys":2338,"name":2340},{"id":2339},"3pjES4THCIfSAwhGdNwBcy","Identity security",{"items":2342},[2343],{"fullName":2344,"firstName":2345,"jobTitle":2346,"profilePicture":2347},"Alex Henshall","Alex","Product Team",{"url":2348},"https://images.ctfassets.net/y1cdw1ablpvd/2rz3Pre3b1MexPIQ4hzPUe/0ef8a092b7e7df00fbce3f7d1ccb96d1/Alex_Henshall.jpeg",{"__typename":1316,"sys":2350,"content":2352,"title":2969,"synopsis":2970,"hashTags":118,"publishedDate":2971,"slug":2972,"tagsCollection":2973,"authorsCollection":2979},{"id":2351},"XQHcBu5kiSBd6MMwICYI4",{"json":2353},{"nodeType":1295,"data":2354,"content":2355},{},[2356,2363,2370,2378,2407,2414,2420,2423,2431,2438,2445,2488,2495,2502,2505,2513,2520,2527,2534,2554,2561,2567,2575,2582,2589,2596,2602,2605,2613,2621,2628,2636,2643,2708,2715,2723,2730,2763,2771,2778,2786,2793,2801,2808,2861,2868,2871,2879,2886,2903,2936,2957,2963],{"nodeType":1294,"data":2357,"content":2358},{},[2359],{"nodeType":1293,"value":2360,"marks":2361,"data":2362},"Phishing has undergone a radical transformation. The laughably bad emails and fake PayPal logins of the past have given way to sophisticated campaigns engineered to slip through even the most hardened security stacks. ",[],{},{"nodeType":1294,"data":2364,"content":2365},{},[2366],{"nodeType":1293,"value":2367,"marks":2368,"data":2369},"Today’s phishing attacks are faster, more adaptable, and harder to catch with traditional tools. Email filters and threat intel still play an important role, but they’re often reacting to threats that are already in motion, and by the time a phishing link is flagged and blocklisted, someone has probably already clicked — and the attacker has moved onto their next set of links.",[],{},{"nodeType":1294,"data":2371,"content":2372},{},[2373],{"nodeType":1293,"value":2374,"marks":2375,"data":2377},"The problem isn’t that phishing has evolved. It’s that our defenses haven’t.",[2376],{"type":1882},{},{"nodeType":1294,"data":2379,"content":2380},{},[2381,2385,2394,2398,2403],{"nodeType":1293,"value":2382,"marks":2383,"data":2384},"That’s where ",[],{},{"nodeType":1340,"data":2386,"content":2388},{"uri":2387},"https://pushsecurity.com/uc/zero-day-phishing-protection",[2389],{"nodeType":1293,"value":2390,"marks":2391,"data":2393},"Push Security",[2392],{"type":1348},{},{"nodeType":1293,"value":2395,"marks":2396,"data":2397}," comes in. By embedding real-time detection directly into the browser, the very place where phishing attacks unfold, Push offers a fundamentally new way to stop phishing: ",[],{},{"nodeType":1293,"value":2399,"marks":2400,"data":2402},"as it happens",[2401],{"type":312},{},{"nodeType":1293,"value":2404,"marks":2405,"data":2406},", regardless of whether or not the exact attack has ever been seen before. ",[],{},{"nodeType":1294,"data":2408,"content":2409},{},[2410],{"nodeType":1293,"value":2411,"marks":2412,"data":2413},"Check out the video to see how it works. ",[],{},{"nodeType":1324,"data":2415,"content":2419},{"target":2416},{"sys":2417},{"id":2418,"type":1329,"linkType":1330},"4LaKobadjp19jjocLXcW4E",[],{"nodeType":1547,"data":2421,"content":2422},{},[],{"nodeType":1551,"data":2424,"content":2425},{},[2426],{"nodeType":1293,"value":2427,"marks":2428,"data":2430},"The modern phishing playground",[2429],{"type":1882},{},{"nodeType":1294,"data":2432,"content":2433},{},[2434],{"nodeType":1293,"value":2435,"marks":2436,"data":2437},"Phishing attacks today look nothing like the blunt instruments of a few years ago. These are fast, customized, and often completely ephemeral. A phishing domain might go live at 9 a.m., compromise scores of credentials, and be gone before lunch, long before it ever hits a threat intel feed.",[],{},{"nodeType":1294,"data":2439,"content":2440},{},[2441],{"nodeType":1293,"value":2442,"marks":2443,"data":2444},"Modern attackers use:",[],{},{"nodeType":1627,"data":2446,"content":2447},{},[2448,2458,2468,2478],{"nodeType":1631,"data":2449,"content":2450},{},[2451],{"nodeType":1294,"data":2452,"content":2453},{},[2454],{"nodeType":1293,"value":2455,"marks":2456,"data":2457},"Dynamic content and user-adaptive emails that can be easily changed based on the target’s identity and environment.",[],{},{"nodeType":1631,"data":2459,"content":2460},{},[2461],{"nodeType":1294,"data":2462,"content":2463},{},[2464],{"nodeType":1293,"value":2465,"marks":2466,"data":2467},"Obfuscated URLs hidden behind trusted services (like Google Sites), making reputation analysis less than reliable.",[],{},{"nodeType":1631,"data":2469,"content":2470},{},[2471],{"nodeType":1294,"data":2472,"content":2473},{},[2474],{"nodeType":1293,"value":2475,"marks":2476,"data":2477},"Real-time proxying tools to clone login flows and harvest credentials.",[],{},{"nodeType":1631,"data":2479,"content":2480},{},[2481],{"nodeType":1294,"data":2482,"content":2483},{},[2484],{"nodeType":1293,"value":2485,"marks":2486,"data":2487},"Rapid-fire infrastructure rotation, making the attack’s infrastructure almost impossible to track in time.",[],{},{"nodeType":1294,"data":2489,"content":2490},{},[2491],{"nodeType":1293,"value":2492,"marks":2493,"data":2494},"These attacks often bypass traditional defenses entirely, not because the tools are broken, but because they were designed for a different era, one where phishing pages lived for days or weeks, not minutes.",[],{},{"nodeType":1294,"data":2496,"content":2497},{},[2498],{"nodeType":1293,"value":2499,"marks":2500,"data":2501},"It’s not enough to know what was bad yesterday. You need to know what’s happening now.",[],{},{"nodeType":1547,"data":2503,"content":2504},{},[],{"nodeType":1551,"data":2506,"content":2507},{},[2508],{"nodeType":1293,"value":2509,"marks":2510,"data":2512},"Why blocklists and perimeter defenses are falling behind",[2511],{"type":1882},{},{"nodeType":1294,"data":2514,"content":2515},{},[2516],{"nodeType":1293,"value":2517,"marks":2518,"data":2519},"The security ecosystem has long depended on reputation-based systems: block the known bad, allow the rest. That worked when attackers reused infrastructure and relied on mass campaigns. Today’s adversaries have adapted.",[],{},{"nodeType":1294,"data":2521,"content":2522},{},[2523],{"nodeType":1293,"value":2524,"marks":2525,"data":2526},"Consider a scenario similar to the one from our video:",[],{},{"nodeType":1294,"data":2528,"content":2529},{},[2530],{"nodeType":1293,"value":2531,"marks":2532,"data":2533},"A staff member receives an email appearing to be from Microsoft Teams. It includes dynamic content that mirrors their actual environment, including their username, company logo, and real collaboration data. The embedded link takes them to a cloned Microsoft login page hosted on a benign-looking subdomain. The site is brand new. It’s not on any blocklist. Your email filter passes it. The employee logs in. Credentials and session tokens? Gone.",[],{},{"nodeType":1294,"data":2535,"content":2536},{},[2537,2541,2550],{"nodeType":1293,"value":2538,"marks":2539,"data":2540},"And that’s just step one. The attacker now pivots to connected apps like ",[],{},{"nodeType":1340,"data":2542,"content":2544},{"uri":2543},"https://pushsecurity.com/blog/why-attackers-are-targeting-jira-with-stolen-credentials/",[2545],{"nodeType":1293,"value":2546,"marks":2547,"data":2549},"Jira",[2548],{"type":1348},{},{"nodeType":1293,"value":2551,"marks":2552,"data":2553},", Confluence, or AWS, moving laterally through your cloud environment using the compromised credentials.",[],{},{"nodeType":1294,"data":2555,"content":2556},{},[2557],{"nodeType":1293,"value":2558,"marks":2559,"data":2560},"Traditional tools often miss these threats not due to a lack of sophistication, but because they’re looking from the outside in. The browser is where the attack actually unfolds. Without visibility there, key indicators of compromise go undetected.",[],{},{"nodeType":1324,"data":2562,"content":2566},{"target":2563},{"sys":2564},{"id":2565,"type":1329,"linkType":1330},"1UGu43QxCiYofkeGtOMp5J",[],{"nodeType":1551,"data":2568,"content":2569},{},[2570],{"nodeType":1293,"value":2571,"marks":2572,"data":2574},"Rethinking where phishing defense happens",[2573],{"type":1882},{},{"nodeType":1294,"data":2576,"content":2577},{},[2578],{"nodeType":1293,"value":2579,"marks":2580,"data":2581},"Push changes where phishing protection happens, from upstream detection to point-of-interaction control. Instead of chasing malicious links through email gateways or external threat feeds, Push embeds lightweight, always-on protection directly, as users go about their work in the browser.",[],{},{"nodeType":1294,"data":2583,"content":2584},{},[2585],{"nodeType":1293,"value":2586,"marks":2587,"data":2588},"Push monitors what’s happening in each session: how pages are built, how they behave, and how users interact with them. That means it can recognize when a login prompt doesn’t match your identity provider or when a script behaves like part of a phishing toolkit.",[],{},{"nodeType":1294,"data":2590,"content":2591},{},[2592],{"nodeType":1293,"value":2593,"marks":2594,"data":2595},"When Push identifies something suspicious, it takes action right away. Logins are interrupted before any data is exposed. Users get clear guidance in-browser. And security teams receive detailed telemetry that shows exactly what happened, who was targeted, and how the threat was stopped.",[],{},{"nodeType":1324,"data":2597,"content":2601},{"target":2598},{"sys":2599},{"id":2600,"type":1329,"linkType":1330},"7Hu3kypFWwJAGOuQp0kYmU",[],{"nodeType":1547,"data":2603,"content":2604},{},[],{"nodeType":1551,"data":2606,"content":2607},{},[2608],{"nodeType":1293,"value":2609,"marks":2610,"data":2612},"The benefits of browser-native phishing defense",[2611],{"type":1882},{},{"nodeType":2120,"data":2614,"content":2615},{},[2616],{"nodeType":1293,"value":2617,"marks":2618,"data":2620},"True zero-day protection",[2619],{"type":1882},{},{"nodeType":1294,"data":2622,"content":2623},{},[2624],{"nodeType":1293,"value":2625,"marks":2626,"data":2627},"Push doesn’t rely on known indicators of compromise. It evaluates the actual behavior and context of every session in real-time. Whether the phishing site was created 5 months ago or 5 minutes ago is irrelevant — Push detects it and shuts it down.",[],{},{"nodeType":2120,"data":2629,"content":2630},{},[2631],{"nodeType":1293,"value":2632,"marks":2633,"data":2635},"Contextual threat detection",[2634],{"type":1882},{},{"nodeType":1294,"data":2637,"content":2638},{},[2639],{"nodeType":1293,"value":2640,"marks":2641,"data":2642},"Because Push operates in the browser, it sees everything:",[],{},{"nodeType":1627,"data":2644,"content":2645},{},[2646,2656,2666,2688,2698],{"nodeType":1631,"data":2647,"content":2648},{},[2649],{"nodeType":1294,"data":2650,"content":2651},{},[2652],{"nodeType":1293,"value":2653,"marks":2654,"data":2655},"The page layout",[],{},{"nodeType":1631,"data":2657,"content":2658},{},[2659],{"nodeType":1294,"data":2660,"content":2661},{},[2662],{"nodeType":1293,"value":2663,"marks":2664,"data":2665},"Where the user came from",[],{},{"nodeType":1631,"data":2667,"content":2668},{},[2669],{"nodeType":1294,"data":2670,"content":2671},{},[2672,2676,2685],{"nodeType":1293,"value":2673,"marks":2674,"data":2675},"The password they enter ",[],{},{"nodeType":1340,"data":2677,"content":2679},{"uri":2678},"https://pushsecurity.com/help/10043/#how-push-securely-analyzes-passwords",[2680],{"nodeType":1293,"value":2681,"marks":2682,"data":2684},"(as a salted, abbreviated hash)",[2683],{"type":1348},{},{"nodeType":1293,"value":37,"marks":2686,"data":2687},[],{},{"nodeType":1631,"data":2689,"content":2690},{},[2691],{"nodeType":1294,"data":2692,"content":2693},{},[2694],{"nodeType":1293,"value":2695,"marks":2696,"data":2697},"What scripts are running",[],{},{"nodeType":1631,"data":2699,"content":2700},{},[2701],{"nodeType":1294,"data":2702,"content":2703},{},[2704],{"nodeType":1293,"value":2705,"marks":2706,"data":2707},"And where credentials are being sent",[],{},{"nodeType":1294,"data":2709,"content":2710},{},[2711],{"nodeType":1293,"value":2712,"marks":2713,"data":2714},"This context enables Push to stop even well-camouflaged phishing attempts, including AitM attacks that bypass MFA.",[],{},{"nodeType":2120,"data":2716,"content":2717},{},[2718],{"nodeType":1293,"value":2719,"marks":2720,"data":2722},"Real-time interception of malicious activity",[2721],{"type":1882},{},{"nodeType":1294,"data":2724,"content":2725},{},[2726],{"nodeType":1293,"value":2727,"marks":2728,"data":2729},"As soon as a phishing attempt is confirmed, the response is immediate:",[],{},{"nodeType":1627,"data":2731,"content":2732},{},[2733,2743,2753],{"nodeType":1631,"data":2734,"content":2735},{},[2736],{"nodeType":1294,"data":2737,"content":2738},{},[2739],{"nodeType":1293,"value":2740,"marks":2741,"data":2742},"Credential entry is halted.",[],{},{"nodeType":1631,"data":2744,"content":2745},{},[2746],{"nodeType":1294,"data":2747,"content":2748},{},[2749],{"nodeType":1293,"value":2750,"marks":2751,"data":2752},"Sessions are revoked.",[],{},{"nodeType":1631,"data":2754,"content":2755},{},[2756],{"nodeType":1294,"data":2757,"content":2758},{},[2759],{"nodeType":1293,"value":2760,"marks":2761,"data":2762},"The user is protected without delay.",[],{},{"nodeType":2120,"data":2764,"content":2765},{},[2766],{"nodeType":1293,"value":2767,"marks":2768,"data":2770},"Reduced incident response overhead",[2769],{"type":1882},{},{"nodeType":1294,"data":2772,"content":2773},{},[2774],{"nodeType":1293,"value":2775,"marks":2776,"data":2777},"Most phishing attacks end in hours of IR and expensive cleanup. With Push, attacks don’t escalate beyond the initial click. That means fewer compromised accounts, fewer escalations, and less fatigue on your security team.",[],{},{"nodeType":2120,"data":2779,"content":2780},{},[2781],{"nodeType":1293,"value":2782,"marks":2783,"data":2785},"Empowered, educated users",[2784],{"type":1882},{},{"nodeType":1294,"data":2787,"content":2788},{},[2789],{"nodeType":1293,"value":2790,"marks":2791,"data":2792},"Push doesn’t just block phishing; it helps users learn from it. When someone interacts with a suspicious page, they get clear, actionable feedback right in the browser. Over time, these in-the-moment cues help build stronger phishing awareness across your workforce. Employee-facing messages are fully customizable to match the tone and style of your organization.",[],{},{"nodeType":2120,"data":2794,"content":2795},{},[2796],{"nodeType":1293,"value":2797,"marks":2798,"data":2800},"A new paradigm for identity security",[2799],{"type":1882},{},{"nodeType":1294,"data":2802,"content":2803},{},[2804],{"nodeType":1293,"value":2805,"marks":2806,"data":2807},"While phishing detection is core, Push also helps you defend your entire browser-based identity attack surface. That means protecting against other common forms of account compromise, like:",[],{},{"nodeType":1627,"data":2809,"content":2810},{},[2811,2821,2831,2841,2851],{"nodeType":1631,"data":2812,"content":2813},{},[2814],{"nodeType":1294,"data":2815,"content":2816},{},[2817],{"nodeType":1293,"value":2818,"marks":2819,"data":2820},"Employees using breached or reused passwords",[],{},{"nodeType":1631,"data":2822,"content":2823},{},[2824],{"nodeType":1294,"data":2825,"content":2826},{},[2827],{"nodeType":1293,"value":2828,"marks":2829,"data":2830},"Missing or misconfigured MFA",[],{},{"nodeType":1631,"data":2832,"content":2833},{},[2834],{"nodeType":1294,"data":2835,"content":2836},{},[2837],{"nodeType":1293,"value":2838,"marks":2839,"data":2840},"Ghost logins that bypass your identity provider",[],{},{"nodeType":1631,"data":2842,"content":2843},{},[2844],{"nodeType":1294,"data":2845,"content":2846},{},[2847],{"nodeType":1293,"value":2848,"marks":2849,"data":2850},"Token-based session hijacking",[],{},{"nodeType":1631,"data":2852,"content":2853},{},[2854],{"nodeType":1294,"data":2855,"content":2856},{},[2857],{"nodeType":1293,"value":2858,"marks":2859,"data":2860},"Shadow SaaS usage",[],{},{"nodeType":1294,"data":2862,"content":2863},{},[2864],{"nodeType":1293,"value":2865,"marks":2866,"data":2867},"Because Push runs directly in the browser, it gives you visibility across every app your employees access, whether it’s officially managed or not. And it doesn’t just alert, it actively helps you fix the issues, guiding users to take action when risks are found.",[],{},{"nodeType":1547,"data":2869,"content":2870},{},[],{"nodeType":1551,"data":2872,"content":2873},{},[2874],{"nodeType":1293,"value":2875,"marks":2876,"data":2878},"Modern phishing requires a modern defense",[2877],{"type":1882},{},{"nodeType":1294,"data":2880,"content":2881},{},[2882],{"nodeType":1293,"value":2883,"marks":2884,"data":2885},"Phishing is no longer an email problem. It’s not even just a domain reputation problem. It’s an identity attack problem, and the only place you can see those attacks in action is inside the browser.",[],{},{"nodeType":1294,"data":2887,"content":2888},{},[2889,2893,2900],{"nodeType":1293,"value":2890,"marks":2891,"data":2892},"Push Security gives you a new advantage: proactive, in-browser protection against modern phishing campaigns — ",[],{},{"nodeType":1340,"data":2894,"content":2895},{"uri":2387},[2896],{"nodeType":1293,"value":2897,"marks":2898,"data":2899},"even those with never-before-seen phishing sites",[],{},{"nodeType":1293,"value":1948,"marks":2901,"data":2902},[],{},{"nodeType":1627,"data":2904,"content":2905},{},[2906,2916,2926],{"nodeType":1631,"data":2907,"content":2908},{},[2909],{"nodeType":1294,"data":2910,"content":2911},{},[2912],{"nodeType":1293,"value":2913,"marks":2914,"data":2915},"See the phish happen.",[],{},{"nodeType":1631,"data":2917,"content":2918},{},[2919],{"nodeType":1294,"data":2920,"content":2921},{},[2922],{"nodeType":1293,"value":2923,"marks":2924,"data":2925},"Stop it in real time.",[],{},{"nodeType":1631,"data":2927,"content":2928},{},[2929],{"nodeType":1294,"data":2930,"content":2931},{},[2932],{"nodeType":1293,"value":2933,"marks":2934,"data":2935},"Keep your workforce identities safe.",[],{},{"nodeType":1294,"data":2937,"content":2938},{},[2939,2944,2952],{"nodeType":1293,"value":2940,"marks":2941,"data":2943},"Want to see Push in action? ",[2942],{"type":1882},{},{"nodeType":1340,"data":2945,"content":2946},{"uri":1940},[2947],{"nodeType":1293,"value":2948,"marks":2949,"data":2951},"Book a demo",[2950],{"type":1882},{},{"nodeType":1293,"value":2953,"marks":2954,"data":2956}," and watch a real-time phishing attack get stopped mid-flow.",[2955],{"type":1882},{},{"nodeType":1324,"data":2958,"content":2962},{"target":2959},{"sys":2960},{"id":2961,"type":1329,"linkType":1330},"7eSsPjEj178j3ViloaChbQ",[],{"nodeType":1294,"data":2964,"content":2965},{},[2966],{"nodeType":1293,"value":37,"marks":2967,"data":2968},[],{},"How browser-level controls change the fight against phishing","Attackers are routinely defeating conventional email, network, and endpoint-based security controls. Here's how browser controls can level the playing field.","2025-06-26T00:00:00.000Z","how-browser-level-controls-change-the-fight-against-phishing",{"items":2974},[2975,2977],{"sys":2976,"name":1308},{"id":1307},{"sys":2978,"name":1312},{"id":1311},{"items":2980},[2981],{"fullName":2982,"firstName":2983,"jobTitle":2346,"profilePicture":2984},"Peyton Padfield","Peyton",{"url":2985},"https://images.ctfassets.net/y1cdw1ablpvd/1GU01HXElmc07nwi89qP3b/3188050420106c62e9df2ed4e4893b7f/1677005177901__1_.jpeg",{"items":2987},[2988],{"fullName":1976,"firstName":1977,"jobTitle":1978,"profilePicture":2989},{"url":1980},{"json":2991,"links":3705},{"nodeType":1295,"data":2992,"content":2993},{},[2994,2999,3063,3070,3077,3080,3087,3094,3142,3149,3152,3159,3187,3277,3293,3298,3301,3308,3315,3321,3327,3334,3412,3419,3462,3470,3473,3480,3487,3494,3501,3508,3514,3517,3524,3545,3552,3575,3582,3585,3591,3597,3603,3608,3625,3630,3636,3643,3649,3652,3658,3677,3694,3699],{"nodeType":1324,"data":2995,"content":2998},{"target":2996},{"sys":2997},{"id":1328,"type":1329,"linkType":1330},[],{"nodeType":1294,"data":3000,"content":3001},{},[3002,3006,3013,3016,3023,3026,3033,3036,3042,3045,3051,3054,3060],{"nodeType":1293,"value":3003,"marks":3004,"data":3005},"Scattered Spider continues to dominate the headlines, with the latest news linking the hackers to attacks on U.S. insurance giant ",[],{},{"nodeType":1340,"data":3007,"content":3008},{"uri":1470},[3009],{"nodeType":1293,"value":1473,"marks":3010,"data":3012},[3011],{"type":1348},{},{"nodeType":1293,"value":1384,"marks":3014,"data":3015},[],{},{"nodeType":1340,"data":3017,"content":3018},{"uri":1482},[3019],{"nodeType":1293,"value":1485,"marks":3020,"data":3022},[3021],{"type":1348},{},{"nodeType":1293,"value":1384,"marks":3024,"data":3025},[],{},{"nodeType":1340,"data":3027,"content":3028},{"uri":1495},[3029],{"nodeType":1293,"value":1498,"marks":3030,"data":3032},[3031],{"type":1348},{},{"nodeType":1293,"value":1503,"marks":3034,"data":3035},[],{},{"nodeType":1340,"data":3037,"content":3038},{"uri":1508},[3039],{"nodeType":1293,"value":1511,"marks":3040,"data":3041},[],{},{"nodeType":1293,"value":1384,"marks":3043,"data":3044},[],{},{"nodeType":1340,"data":3046,"content":3047},{"uri":1519},[3048],{"nodeType":1293,"value":1522,"marks":3049,"data":3050},[],{},{"nodeType":1293,"value":1351,"marks":3052,"data":3053},[],{},{"nodeType":1340,"data":3055,"content":3056},{"uri":1519},[3057],{"nodeType":1293,"value":1532,"marks":3058,"data":3059},[],{},{"nodeType":1293,"value":1536,"marks":3061,"data":3062},[],{},{"nodeType":1294,"data":3064,"content":3065},{},[3066],{"nodeType":1293,"value":3067,"marks":3068,"data":3069},"This comes at the same time that Google Threat Intelligence Group shared that it “is now aware of multiple intrusions in the U.S. which bear the hallmarks of Scattered Spider activity”, specifically impacting the insurance industry. ",[],{},{"nodeType":1294,"data":3071,"content":3072},{},[3073],{"nodeType":1293,"value":3074,"marks":3075,"data":3076},"But what exactly does this mean? To answer this, let’s quickly recap how we got here and what a Scattered Spider attack looks like.  ",[],{},{"nodeType":1547,"data":3078,"content":3079},{},[],{"nodeType":1551,"data":3081,"content":3082},{},[3083],{"nodeType":1293,"value":3084,"marks":3085,"data":3086},"How did we get here? ",[],{},{"nodeType":1294,"data":3088,"content":3089},{},[3090],{"nodeType":1293,"value":3091,"marks":3092,"data":3093},"The criminal collective tracked by analysts as Scattered Spider has been active since 2022 and have been linked to a range of high-profile breaches, for example the attacks on Caesars and MGM Resorts in 2023, and Transport for London in 2024. ",[],{},{"nodeType":1627,"data":3095,"content":3096},{},[3097,3112,3127],{"nodeType":1631,"data":3098,"content":3099},{},[3100],{"nodeType":1294,"data":3101,"content":3102},{},[3103,3108],{"nodeType":1293,"value":3104,"marks":3105,"data":3107},"Caesars: ",[3106],{"type":1882},{},{"nodeType":1293,"value":3109,"marks":3110,"data":3111},"hackers impersonated an IT user and convinced an outsourced help desk to reset credentials, after which the attacker stole the customer loyalty program database and secured a $15m ransom payment. ",[],{},{"nodeType":1631,"data":3113,"content":3114},{},[3115],{"nodeType":1294,"data":3116,"content":3117},{},[3118,3123],{"nodeType":1293,"value":3119,"marks":3120,"data":3122},"MGM Resorts: ",[3121],{"type":1882},{},{"nodeType":1293,"value":3124,"marks":3125,"data":3126},"hackers used LinkedIn information to impersonate an employee and reset the employee’s credentials, resulting in a 6TB data theft. After MGM refused to pay, the attack eventually resulted in a 36-hour outage, a $100m hit, and a class-action lawsuit settled for $45m. ",[],{},{"nodeType":1631,"data":3128,"content":3129},{},[3130],{"nodeType":1294,"data":3131,"content":3132},{},[3133,3138],{"nodeType":1293,"value":3134,"marks":3135,"data":3137},"Transport for London:",[3136],{"type":1882},{},{"nodeType":1293,"value":3139,"marks":3140,"data":3141}," resulted in 5,000 users’ bank details exposed, 30,000 staff required to attend in-person appointments to verify their identities and reset passwords, and significant disruption to online services lasting for months.",[],{},{"nodeType":1294,"data":3143,"content":3144},{},[3145],{"nodeType":1293,"value":3146,"marks":3147,"data":3148},"The calling card in these attacks was the abuse of help desk processes to reset passwords and/or MFA factors used to access an account. The attacker simply calls up the help desk with enough information to impersonate an employee, asks them to send an MFA enrollment link for their new mobile device, and can then utilize self-service password reset functionality to take control of the account. Scarily simple. ",[],{},{"nodeType":1547,"data":3150,"content":3151},{},[],{"nodeType":1551,"data":3153,"content":3154},{},[3155],{"nodeType":1293,"value":3156,"marks":3157,"data":3158},"Scattered Spider’s resurgence in 2025",[],{},{"nodeType":1294,"data":3160,"content":3161},{},[3162,3166,3173,3176,3183],{"nodeType":1293,"value":3163,"marks":3164,"data":3165},"This technique was reprised in a series of high-profile attacks in 2025, with major breaches of UK retailers ",[],{},{"nodeType":1340,"data":3167,"content":3168},{"uri":1342},[3169],{"nodeType":1293,"value":1345,"marks":3170,"data":3172},[3171],{"type":1348},{},{"nodeType":1293,"value":1351,"marks":3174,"data":3175},[],{},{"nodeType":1340,"data":3177,"content":3178},{"uri":1356},[3179],{"nodeType":1293,"value":1359,"marks":3180,"data":3182},[3181],{"type":1348},{},{"nodeType":1293,"value":3184,"marks":3185,"data":3186}," dominating the headlines. Both resulted in the loss of sensitive data and prolonged disruption to in-store and digital services, with M&S feeling the pain of £300m in lost profits and a share value hit approaching £1b, and a multimillion-pound class action lawsuit and possible ICO fines looming.",[],{},{"nodeType":1294,"data":3188,"content":3189},{},[3190,3193,3200,3203,3210,3213,3220,3223,3230,3233,3240,3243,3250,3253,3260,3264,3273],{"nodeType":1293,"value":1371,"marks":3191,"data":3192},[],{},{"nodeType":1340,"data":3194,"content":3195},{"uri":1376},[3196],{"nodeType":1293,"value":1379,"marks":3197,"data":3199},[3198],{"type":1348},{},{"nodeType":1293,"value":1384,"marks":3201,"data":3202},[],{},{"nodeType":1340,"data":3204,"content":3205},{"uri":1389},[3206],{"nodeType":1293,"value":1392,"marks":3207,"data":3209},[3208],{"type":1348},{},{"nodeType":1293,"value":1384,"marks":3211,"data":3212},[],{},{"nodeType":1340,"data":3214,"content":3215},{"uri":1401},[3216],{"nodeType":1293,"value":1404,"marks":3217,"data":3219},[3218],{"type":1348},{},{"nodeType":1293,"value":1384,"marks":3221,"data":3222},[],{},{"nodeType":1340,"data":3224,"content":3225},{"uri":1413},[3226],{"nodeType":1293,"value":1416,"marks":3227,"data":3229},[3228],{"type":1348},{},{"nodeType":1293,"value":1384,"marks":3231,"data":3232},[],{},{"nodeType":1340,"data":3234,"content":3235},{"uri":1425},[3236],{"nodeType":1293,"value":1428,"marks":3237,"data":3239},[3238],{"type":1348},{},{"nodeType":1293,"value":1384,"marks":3241,"data":3242},[],{},{"nodeType":1340,"data":3244,"content":3245},{"uri":1437},[3246],{"nodeType":1293,"value":1440,"marks":3247,"data":3249},[3248],{"type":1348},{},{"nodeType":1293,"value":1445,"marks":3251,"data":3252},[],{},{"nodeType":1340,"data":3254,"content":3255},{"uri":1450},[3256],{"nodeType":1293,"value":1453,"marks":3257,"data":3259},[3258],{"type":1348},{},{"nodeType":1293,"value":3261,"marks":3262,"data":3263}," were among the retailers to suffer a breach between May-June 2025. Unlike the ",[],{},{"nodeType":1340,"data":3265,"content":3267},{"uri":3266},"https://pushsecurity.com/blog/snowflake-retro/",[3268],{"nodeType":1293,"value":3269,"marks":3270,"data":3272},"mass Snowflake breaches in 2024",[3271],{"type":1348},{},{"nodeType":1293,"value":3274,"marks":3275,"data":3276}," (which targeted a single platform used by many organizations), these attacks are notable in that they are seemingly unrelated — they simply represent a concerted effort by attackers to target the retail sector. ",[],{},{"nodeType":1294,"data":3278,"content":3279},{},[3280,3284,3289],{"nodeType":1293,"value":3281,"marks":3282,"data":3283},"Less details have been provided about these attacks compared to the M&S and Co-op breaches, but a number of them specifically point to the use of ",[],{},{"nodeType":1293,"value":3285,"marks":3286,"data":3288},"identity-based techniques",[3287],{"type":1882},{},{"nodeType":1293,"value":3290,"marks":3291,"data":3292}," as opposed to more traditional software exploits — another hallmark of Scattered Spider. This leads us to our first key takeaway…",[],{},{"nodeType":1324,"data":3294,"content":3297},{"target":3295},{"sys":3296},{"id":1834,"type":1329,"linkType":1330},[],{"nodeType":1547,"data":3299,"content":3300},{},[],{"nodeType":1551,"data":3302,"content":3303},{},[3304],{"nodeType":1293,"value":3305,"marks":3306,"data":3307},"Takeaway #1: Identity-based TTPs are the new normal",[],{},{"nodeType":1294,"data":3309,"content":3310},{},[3311],{"nodeType":1293,"value":3312,"marks":3313,"data":3314},"Scattered Spider’s attacks are the latest in a growing number of identity-based breaches. When we look back at Scattered Spider’s TTP evolution, we can see that they have consistently exploited identity-based weaknesses in order to gain access to victim environments. ",[],{},{"nodeType":1324,"data":3316,"content":3320},{"target":3317},{"sys":3318},{"id":3319,"type":1329,"linkType":1330},"2vs8WgO4gfGLxscjGMBSY6",[],{"nodeType":1294,"data":3322,"content":3323},{},[3324],{"nodeType":1293,"value":1712,"marks":3325,"data":3326},[],{},{"nodeType":1294,"data":3328,"content":3329},{},[3330],{"nodeType":1293,"value":3331,"marks":3332,"data":3333},"Scattered Spider has heavily relied on identity-based TTPs since they first emerged in 2022, following a repeatable path of bypassing MFA, achieving account takeover on privileged accounts, stealing data from cloud services, and deploying ransomware (principally in VMware environments). TTPs used by Scattered Spider include:",[],{},{"nodeType":1627,"data":3335,"content":3336},{},[3337,3346,3355,3374,3383,3392],{"nodeType":1631,"data":3338,"content":3339},{},[3340],{"nodeType":1294,"data":3341,"content":3342},{},[3343],{"nodeType":1293,"value":1744,"marks":3344,"data":3345},[],{},{"nodeType":1631,"data":3347,"content":3348},{},[3349],{"nodeType":1294,"data":3350,"content":3351},{},[3352],{"nodeType":1293,"value":1754,"marks":3353,"data":3354},[],{},{"nodeType":1631,"data":3356,"content":3357},{},[3358],{"nodeType":1294,"data":3359,"content":3360},{},[3361,3364,3371],{"nodeType":1293,"value":1764,"marks":3362,"data":3363},[],{},{"nodeType":1340,"data":3365,"content":3366},{"uri":1769},[3367],{"nodeType":1293,"value":1772,"marks":3368,"data":3370},[3369],{"type":1348},{},{"nodeType":1293,"value":1777,"marks":3372,"data":3373},[],{},{"nodeType":1631,"data":3375,"content":3376},{},[3377],{"nodeType":1294,"data":3378,"content":3379},{},[3380],{"nodeType":1293,"value":1787,"marks":3381,"data":3382},[],{},{"nodeType":1631,"data":3384,"content":3385},{},[3386],{"nodeType":1294,"data":3387,"content":3388},{},[3389],{"nodeType":1293,"value":1797,"marks":3390,"data":3391},[],{},{"nodeType":1631,"data":3393,"content":3394},{},[3395],{"nodeType":1294,"data":3396,"content":3397},{},[3398,3401,3408],{"nodeType":1293,"value":1807,"marks":3399,"data":3400},[],{},{"nodeType":1340,"data":3402,"content":3403},{"uri":1812},[3404],{"nodeType":1293,"value":1815,"marks":3405,"data":3407},[3406],{"type":1348},{},{"nodeType":1293,"value":3409,"marks":3410,"data":3411}," to steal live user sessions",[],{},{"nodeType":1294,"data":3413,"content":3414},{},[3415],{"nodeType":1293,"value":3416,"marks":3417,"data":3418},"So, help desk scams are an important part of their toolkit, but it’s not the whole picture. Methods like AiTM phishing in particular have spiked in popularity this year as a reliable and scalable way of bypassing MFA and achieving account takeover.",[],{},{"nodeType":1294,"data":3420,"content":3421},{},[3422,3426,3435,3438,3446,3450,3459],{"nodeType":1293,"value":3423,"marks":3424,"data":3425},"It’s important not to think about these techniques as just a Scattered Spider trait either. After all, Scattered Spider is not a self-identified group — it’s a name given by analysts to patterns of activity. Given the series of arrests in 2024, it’s unlikely that the current incarnation of Scattered Spider is the same individuals behind the attacks in 2022-2024. And these identity-based attack patterns are shared across various self-named criminal groups like, ",[],{},{"nodeType":1340,"data":3427,"content":3429},{"uri":3428},"https://www.cisa.gov/sites/default/files/2023-08/CSRB_Lapsus%24_508c.pdf",[3430],{"nodeType":1293,"value":3431,"marks":3432,"data":3434},"Lapsus$, Yanluowang, Karakurt",[3433],{"type":1348},{},{"nodeType":1293,"value":1445,"marks":3436,"data":3437},[],{},{"nodeType":1340,"data":3439,"content":3440},{"uri":3266},[3441],{"nodeType":1293,"value":3442,"marks":3443,"data":3445},"ShinyHunters",[3444],{"type":1348},{},{"nodeType":1293,"value":3447,"marks":3448,"data":3449},". Even Russian state-sponsored actors are ",[],{},{"nodeType":1340,"data":3451,"content":3453},{"uri":3452},"https://www.microsoft.com/en-us/security/blog/2025/05/27/new-russia-affiliated-actor-void-blizzard-targets-critical-sectors-for-espionage/",[3454],{"nodeType":1293,"value":3455,"marks":3456,"data":3458},"increasingly using the kinds of techniques popularised by criminal groups",[3457],{"type":1348},{},{"nodeType":1293,"value":1948,"marks":3460,"data":3461},[],{},{"nodeType":1294,"data":3463,"content":3464},{},[3465],{"nodeType":1293,"value":3466,"marks":3467,"data":3469},"Simply, identity-based techniques are the new normal for attackers in 2025. ",[3468],{"type":1882},{},{"nodeType":1547,"data":3471,"content":3472},{},[],{"nodeType":1551,"data":3474,"content":3475},{},[3476],{"nodeType":1293,"value":3477,"marks":3478,"data":3479},"Takeaway #2: Help desk scams aren't new, but they're here to stay",[],{},{"nodeType":1294,"data":3481,"content":3482},{},[3483],{"nodeType":1293,"value":3484,"marks":3485,"data":3486},"As we established earlier, help desk scams are nothing new (we saw them in the Caesars, MGM Resorts, and Transport for London breaches to name a few). But they’re likely to become increasingly prevalent as Scattered Spider continues to demonstrate just how effective help desk scams are. ",[],{},{"nodeType":1294,"data":3488,"content":3489},{},[3490],{"nodeType":1293,"value":3491,"marks":3492,"data":3493},"One of the reasons they’re so effective is that most help desks have the same process for every account — it doesn’t matter who you’re impersonating or which account you’re trying to reset. So, attackers are specifically targeting accounts likely to have top tier admin privileges — meaning once they get in, progressing the attack is trivial and much of the typical privilege escalation and lateral movement is removed from the attack path. ",[],{},{"nodeType":1294,"data":3495,"content":3496},{},[3497],{"nodeType":1293,"value":3498,"marks":3499,"data":3500},"Help desks are a target for a reason. They’re “helpful” by nature. This is usually reflected in how they’re operated and performance measured — delays won’t help you to hit those SLAs! Ultimately, a process only works if employees are willing to adhere to it — and can’t be socially engineered to break it. Help desks that are removed from day-to-day operations (especially when outsourced or offshored) are also inherently susceptible to attacks where employees are impersonated. ",[],{},{"nodeType":1294,"data":3502,"content":3503},{},[3504],{"nodeType":1293,"value":3505,"marks":3506,"data":3507},"But, the attacks that organizations are experiencing at the moment should give security stakeholders plenty of ammunition as to why help desk reforms are vital to securing the business (and what can happen if you don’t make changes). ",[],{},{"nodeType":1324,"data":3509,"content":3513},{"target":3510},{"sys":3511},{"id":3512,"type":1329,"linkType":1330},"5Z3J9QuPKesWShV4OGMrYt",[],{"nodeType":1547,"data":3515,"content":3516},{},[],{"nodeType":1551,"data":3518,"content":3519},{},[3520],{"nodeType":1293,"value":3521,"marks":3522,"data":3523},"Takeaway #3: Scattered Spider are consciously evading established security controls",[],{},{"nodeType":1294,"data":3525,"content":3526},{},[3527,3531,3536,3540],{"nodeType":1293,"value":3528,"marks":3529,"data":3530},"So, there’s more to Scattered Spider’s toolkit than just help desk scams. In fact, their approach can be broadly classified as",[],{},{"nodeType":1293,"value":3532,"marks":3533,"data":3535}," consciously evading established controls",[3534],{"type":1882},{},{"nodeType":1293,"value":3537,"marks":3538,"data":3539}," ",[],{},{"nodeType":1293,"value":3541,"marks":3542,"data":3544},"at the endpoint and network layer by targeting identities. ",[3543],{"type":1882},{},{"nodeType":1294,"data":3546,"content":3547},{},[3548],{"nodeType":1293,"value":3549,"marks":3550,"data":3551},"From the point of account takeover, they also follow repeatable patterns:",[],{},{"nodeType":1627,"data":3553,"content":3554},{},[3555,3565],{"nodeType":1631,"data":3556,"content":3557},{},[3558],{"nodeType":1294,"data":3559,"content":3560},{},[3561],{"nodeType":1293,"value":3562,"marks":3563,"data":3564},"Harvesting and exfiltrating data from cloud and SaaS services, where monitoring is typically less consistent than traditional on-premise environments, and exfiltration often blends in with normal activity. Many organizations simply don’t have the logs or visibility to detect malicious activity in the cloud anyway, and Scattered Spider have also been seen tampering with cloud logs (e.g. filtering risky AWS CloudTrail logs, but not disabling it entirely so as not to raise suspicion).",[],{},{"nodeType":1631,"data":3566,"content":3567},{},[3568],{"nodeType":1294,"data":3569,"content":3570},{},[3571],{"nodeType":1293,"value":3572,"marks":3573,"data":3574},"Targeting VMware environments for ransomware deployment. They do this by adding their compromised user account to the VMware admins group in VCentre (if needed — they are going after accounts with top tier privileges by default). From here, they can access the VMware environment via the ESXi hypervisor layer, where security software is nonexistent — thereby bypassing EDR and other typical endpoint and host based controls you rely on to prevent ransomware execution. ",[],{},{"nodeType":1294,"data":3576,"content":3577},{},[3578],{"nodeType":1293,"value":3579,"marks":3580,"data":3581},"The key theme? Getting around your established security controls. ",[],{},{"nodeType":1547,"data":3583,"content":3584},{},[],{"nodeType":1551,"data":3586,"content":3587},{},[3588],{"nodeType":1293,"value":1843,"marks":3589,"data":3590},[],{},{"nodeType":1294,"data":3592,"content":3593},{},[3594],{"nodeType":1293,"value":1850,"marks":3595,"data":3596},[],{},{"nodeType":1294,"data":3598,"content":3599},{},[3600],{"nodeType":1293,"value":1857,"marks":3601,"data":3602},[],{},{"nodeType":1324,"data":3604,"content":3607},{"target":3605},{"sys":3606},{"id":1864,"type":1329,"linkType":1330},[],{"nodeType":1294,"data":3609,"content":3610},{},[3611,3615,3622],{"nodeType":1293,"value":3612,"marks":3613,"data":3614},"To help combat help desk scams, Push recently released ",[],{},{"nodeType":1340,"data":3616,"content":3617},{"uri":1875},[3618],{"nodeType":1293,"value":1878,"marks":3619,"data":3621},[3620],{"type":1882},{},{"nodeType":1293,"value":1885,"marks":3623,"data":3624},[],{},{"nodeType":1324,"data":3626,"content":3629},{"target":3627},{"sys":3628},{"id":1892,"type":1329,"linkType":1330},[],{"nodeType":1294,"data":3631,"content":3632},{},[3633],{"nodeType":1293,"value":1898,"marks":3634,"data":3635},[],{},{"nodeType":1294,"data":3637,"content":3638},{},[3639],{"nodeType":1293,"value":3640,"marks":3641,"data":3642},"Eric Rubin — a Senior Manager in GitLab’s Corporate Security team — has already rolled out Employee Identity Verification Codes across his workforce. Here’s what he had to say:",[],{},{"nodeType":1324,"data":3644,"content":3648},{"target":3645},{"sys":3646},{"id":3647,"type":1329,"linkType":1330},"jHH13doHHHaqUUxHoBeKW",[],{"nodeType":1547,"data":3650,"content":3651},{},[],{"nodeType":1551,"data":3653,"content":3654},{},[3655],{"nodeType":1293,"value":1908,"marks":3656,"data":3657},[],{},{"nodeType":1294,"data":3659,"content":3660},{},[3661,3664,3673],{"nodeType":1293,"value":1915,"marks":3662,"data":3663},[],{},{"nodeType":1340,"data":3665,"content":3667},{"uri":3666},"https://pushsecurity.com/free-tool/employee-verification-codes?utm_campaign=15408561-FY25Q2-Employee-verification-codes&utm_source=Sponsored-content&utm_content=bleepingcomputer",[3668],{"nodeType":1293,"value":3669,"marks":3670,"data":3672},"sign up for a trial account and you can deploy the extension organization-wide to make use of this feature.",[3671],{"type":1348},{},{"nodeType":1293,"value":3674,"marks":3675,"data":3676}," While you’re at it, you can trial Push’s full features for up to 10 users for free. ",[],{},{"nodeType":1294,"data":3678,"content":3679},{},[3680,3683,3691],{"nodeType":1293,"value":1935,"marks":3681,"data":3682},[],{},{"nodeType":1340,"data":3684,"content":3686},{"uri":3685},"https://pushsecurity.com/demo/?utm_campaign=12883224-FY25Q2_Scattered-Spider&utm_source=bleepingcomputer&utm_content=sponsored-article",[3687],{"nodeType":1293,"value":1943,"marks":3688,"data":3690},[3689],{"type":1348},{},{"nodeType":1293,"value":1948,"marks":3692,"data":3693},[],{},{"nodeType":1324,"data":3695,"content":3698},{"target":3696},{"sys":3697},{"id":1955,"type":1329,"linkType":1330},[],{"nodeType":1294,"data":3700,"content":3701},{},[3702],{"nodeType":1293,"value":37,"marks":3703,"data":3704},[],{},{"entries":3706},{"hyperlink":3707,"inline":3708,"block":3709},[],[],[3710,3748,3756,3764,3789,3794,3802,3809],{"sys":3711,"__typename":3712,"content":3713,"name":3747,"title":118},{"id":1328},"InsightTextBlockComponent",{"json":3714},{"nodeType":1295,"data":3715,"content":3716},{},[3717],{"nodeType":1294,"data":3718,"content":3719},{},[3720,3724,3732,3736,3743],{"nodeType":1293,"value":3721,"marks":3722,"data":3723},"It's been a busy year for cyber criminals! This article has now been superseded with the rise to infamy of ",[],{},{"nodeType":1340,"data":3725,"content":3727},{"uri":3726},"https://pushsecurity.com/blog/scattered-lapsus-hunters",[3728],{"nodeType":1293,"value":3729,"marks":3730,"data":3731},"\"Scattered Lapsus$ Hunters\"",[],{},{"nodeType":1293,"value":3733,"marks":3734,"data":3735},". The guidance and TTPs in this blog post still apply, but ",[],{},{"nodeType":1340,"data":3737,"content":3738},{"uri":3726},[3739],{"nodeType":1293,"value":3740,"marks":3741,"data":3742},"check out our new post",[],{},{"nodeType":1293,"value":3744,"marks":3745,"data":3746}," for the full picture of Scattered Spider-linked breaches dating back to 2021. ",[],{},"SS insight box 1",{"sys":3749,"__typename":3750,"type":3751,"ctaText":3752,"buttonLabel":3753,"buttonColour":3754,"buttonUrl":3755},{"id":1834},"CtaWidget","Custom","Learn about Scattered Spider's latest TTPs in our on-demand webinar","Watch on-demand","sunny orange","https://pushsecurity.com/webinar/scatteredspider",{"sys":3757,"__typename":3758,"title":3759,"caption":3759,"layoutMode":118,"file":3760},{"id":3319},"Image","Scattered Spider initial access vectors in public breaches where the attack vector was disclosed.",{"url":3761,"width":3762,"height":3763},"https://images.ctfassets.net/y1cdw1ablpvd/7hJowGlrqAWDpGIag1xWX5/0ce85d41e117129c3db25ea4a09a5604/image3.png",1999,1136,{"sys":3765,"__typename":3712,"content":3766,"name":3788,"title":118},{"id":3512},{"json":3767},{"nodeType":1295,"data":3768,"content":3769},{},[3770],{"nodeType":1294,"data":3771,"content":3772},{},[3773,3776,3784],{"nodeType":1293,"value":37,"marks":3774,"data":3775},[],{},{"nodeType":1340,"data":3777,"content":3779},{"uri":3778},"https://pushsecurity.com/blog/scattered-spider-defending-against-help-desk-scams/",[3780],{"nodeType":1293,"value":3781,"marks":3782,"data":3783},"Check out our recent blog post",[],{},{"nodeType":1293,"value":3785,"marks":3786,"data":3787}," to learn more about help desk scams and how to protect your organization. ",[],{},"Scattered Spider Insurance Blog Insight Box 1",{"sys":3790,"__typename":3758,"title":3791,"caption":3791,"layoutMode":118,"file":3792},{"id":1864},"Push Security contributes to a layered defense against known Scattered Spider TTPs.",{"url":3793,"width":3762,"height":3763},"https://images.ctfassets.net/y1cdw1ablpvd/1l3phtTjFoQDleiOKYfrXn/ead73aef01e72f08885656d79521a27a/image3.png",{"sys":3795,"__typename":3758,"title":3796,"caption":3797,"layoutMode":118,"file":3798},{"id":1892},"Employee Verification Codes","Push provides a lightweight verification feature in every user’s browser — no additional apps or devices required.",{"url":3799,"width":3800,"height":3801},"https://images.ctfassets.net/y1cdw1ablpvd/41X6fkPJgqf14vO3O14TF3/e0cecdbdfaee1353f15ff77ecb6a55a8/Employee_verification_codes.png",2088,1240,{"sys":3803,"__typename":3758,"title":3804,"caption":118,"layoutMode":118,"file":3805},{"id":3647},"GitLab Quote",{"url":3806,"width":3807,"height":3808},"https://images.ctfassets.net/y1cdw1ablpvd/72pQc6jrPIdG2IMgv45Rf8/4ca5d7c9586d16fdfc0596813156c9b8/GitLab_Quote.png",2000,861,{"sys":3810,"__typename":3750,"type":3751,"ctaText":3811,"buttonLabel":3812,"buttonColour":3754,"buttonUrl":1920},{"id":1955},"Deploy Employee Verification Codes for free today and protect your help desk from Scattered Spider","Try it free","content:blog:key-takeaways-from-the-scattered-spider-attacks-on-insurance-firms.json","json","content","blog/key-takeaways-from-the-scattered-spider-attacks-on-insurance-firms.json","blog/key-takeaways-from-the-scattered-spider-attacks-on-insurance-firms",1776359984187]