[{"data":1,"prerenderedAt":4067},["ShallowReactive",2],{"application-flags":3,"navbar":7,"always-visible-banner":95,"navbar-about-highlight":155,"navbar-resource-highlight":211,"use-case-page":255,"blog/mfa-downgrade-attacks":1275},[4],{"name":5,"enabled":6},"maintenanceMode",false,[8,59,76],{"createdDate":9,"id":10,"name":11,"modelId":12,"published":13,"stageModifiedSincePublish":6,"query":14,"data":15,"variations":50,"lastUpdated":51,"firstPublished":52,"testRatio":33,"createdBy":53,"lastUpdatedBy":53,"folders":54,"meta":55,"rev":58},1742213002749,"efff2a27faf4408e9f908eba4b5542fe","inductive-automation","1c6207a5f24948ab82d4a0b17f251193","published",[],{"testimonial":16,"description":43,"type":19,"link":44,"title":47,"testimonialLink":48,"image":49},{"@type":17,"id":18,"model":19,"value":20},"@builder.io/core:Reference","f028f2b685bb47cd8bf9e82a26dd5a79","testimonial",{"query":21,"folders":22,"createdDate":23,"id":18,"name":24,"modelId":25,"published":13,"data":26,"variations":30,"lastUpdated":31,"firstPublished":32,"testRatio":33,"createdBy":34,"lastUpdatedBy":34,"meta":35,"rev":42},[],[],1735823466309,"We found Push to be more accurate when compared to competitors and the browser agent offered features that others couldn’t match.","42035571a56940ac98bff4544aa79aa5",{"author":27,"jobTitle":28,"quote":24,"image":29},"Jason Waits","\u003Cp>CISO at Inductive Automation\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Ff04c0c0689ce4a89ac0f0708d78c0a07",{},1735910703862,1735823501152,1,"ST0tXQM8slWpFrmioqKHmENB2qe2",{"kind":36,"lastPreviewUrl":37,"breakpoints":38,"hasAutosaves":41},"data","",{"small":39,"medium":40},640,768,true,"ler0kdbvts","Join the industry's top security minds as they break down the browser attack landscape.",{"url":45,"text":46},"https://pushsecurity.com/webinar/state-of-browser-security","Save Your Spot","State of Browser Attacks Series","/customer-stories/inductive-automation","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fe94fca10aa7b46ac8052b7ea22de54cd",{},1776257019270,1742221533648,"CydmZnOWU1XuAaLhEDCoYNM4Z8W2",[],{"breakpoints":56,"kind":36,"lastPreviewUrl":37,"hasAutosaves":6},{"xsmall":57,"small":39,"medium":40},320,"bb7erm0g0dk",{"createdDate":60,"id":61,"name":62,"modelId":12,"published":13,"query":63,"data":64,"variations":69,"lastUpdated":70,"firstPublished":71,"testRatio":33,"createdBy":53,"lastUpdatedBy":72,"folders":73,"meta":74,"rev":58},1742208588866,"1c7a4e423bf54ac1a328bb4063459ef2","Banner",[],{"type":65,"url":66,"text":67,"link":68},"web-banner","https://pushsecurity.com/resources/browser-attacks-report","Get our latest report analyzing browser attack techniques in 2026",{},{},1774258294825,1742208637545,"jKjF9r5jcvXU8tzZEfFQm31Iyvr2",[],{"kind":36,"lastPreviewUrl":37,"breakpoints":75,"hasAutosaves":41},{"xsmall":57,"small":39,"medium":40},{"createdDate":77,"id":78,"name":79,"modelId":12,"published":13,"stageModifiedSincePublish":6,"query":80,"data":81,"variations":89,"lastUpdated":90,"firstPublished":91,"testRatio":33,"createdBy":53,"lastUpdatedBy":53,"folders":92,"meta":93,"rev":58},1742208469288,"6763051b201f44a0838c6400c580ca67","Resource highlight",[],{"image":82,"type":83,"description":84,"link":85,"title":88},"https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F7b4a5ebf81d64e8c9d7fc35f6c96c4a9","resource","Learn about the latest techniques being used in the wild.",{"url":86,"text":87},"/resources/browser-attacks-report","Download now","Report: 2026 Browser Attack Techniques",{},1776255866789,1742208570400,[],{"kind":36,"lastPreviewUrl":37,"breakpoints":94,"hasAutosaves":6},{"xsmall":57,"small":39,"medium":40},{"createdDate":96,"id":97,"name":98,"modelId":99,"published":13,"query":100,"data":101,"variations":145,"lastUpdated":146,"firstPublished":147,"testRatio":33,"createdBy":34,"lastUpdatedBy":148,"folders":149,"meta":150,"rev":154},1774965361051,"fd266d0172cc47429be7ad10f48c99ad","always visible banner","0678d178ec8b41efb8a23c09dba7874d",[],{"ctaText":102,"text":103,"url":37,"blocks":104,"state":141},"ewrererw","testrfesssssssssss",[105,129],{"@type":106,"@version":107,"id":108,"component":109,"responsiveStyles":119},"@builder.io/sdk:Element",2,"builder-ca12c06a52de41d7b8743da53118cd38",{"name":110,"tag":110,"options":111,"isRSC":118},"TopBannerContent",{"text":112,"ctaText":46,"url":45,"mainText":113,"cta":116},"New Webinar Series: Join John Hammond, Troy Hunt, and Matt Johansen for the State of Browser Attacks",{"content":114,"fontSize":115},"\u003Cp>New Webinar Series: Join John Hammond, Troy Hunt, and Matt Johansen for the State of Browser Attacks\u003C/p>","text-base",{"content":117,"fontSize":115,"url":45},"\u003Cp>\u003Cstrong style=\"font-weight:700;\">Save Your Spot\u003C/strong>\u003C/p>\n",null,{"large":120},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"marginTop":126,"marginBottom":126,"fontSize":127,"fontWeight":128},"flex","column","relative","0","border-box",".56rem","1.125rem","700",{"id":130,"@type":106,"tagName":131,"properties":132,"responsiveStyles":136},"builder-pixel-bkiyc9w0oy","img",{"src":133,"aria-hidden":134,"alt":37,"role":135,"width":124,"height":124},"https://cdn.builder.io/api/v1/pixel?apiKey=f3a1111ff5be48cdbb123cd9f5795a05","true","presentation",{"large":137},{"height":124,"width":124,"display":138,"opacity":124,"overflow":139,"pointerEvents":140},"block","hidden","none",{"deviceSize":142,"location":143},"large",{"path":37,"query":144},{},{},1775137295127,1774968080803,"ax7YYfD0OCeqT1Vxxv1G4FUbqVr1",[],{"breakpoints":151,"hasLinks":6,"kind":152,"lastPreviewUrl":153,"hasAutosaves":6},{"xsmall":57,"small":39,"medium":40},"component","https://pushsecurity.com/?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditCode%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CeditProjects%2CmodifyMcpServers%2CmodifyWorkflowIntegrations%2CmodifyProjectSettings%2CconnectCodeRepository%2CcreateProjects%2CindexDesignSystems%2CsendPullRequests%2CmergePullRequests&builder.user.role.name=Developer&builder.user.role.id=developer&builder.cachebust=true&builder.preview=always-visible-banner&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.always-visible-banner=fd266d0172cc47429be7ad10f48c99ad&builder.overrides.fd266d0172cc47429be7ad10f48c99ad=fd266d0172cc47429be7ad10f48c99ad&builder.options.locale=Default","pb0681e6gl",[156,180],{"createdDate":157,"id":158,"name":159,"modelId":160,"published":13,"stageModifiedSincePublish":6,"query":161,"data":162,"variations":173,"lastUpdated":174,"firstPublished":175,"testRatio":33,"createdBy":53,"lastUpdatedBy":53,"folders":176,"meta":177,"rev":179},1776247359804,"9136a8f18b3b4a6ba29b8653a99372b1","testimonial-inductive-automation","20d9eaa352304613b3d1a794b400703d",[],{"link":163,"type":19,"testimonialLink":48,"testimonial":164},{},{"@type":17,"id":18,"model":19,"value":165},{"query":166,"folders":167,"createdDate":23,"id":18,"name":24,"modelId":25,"published":13,"data":168,"variations":169,"lastUpdated":31,"firstPublished":32,"testRatio":33,"createdBy":34,"lastUpdatedBy":34,"meta":170,"rev":172},[],[],{"author":27,"jobTitle":28,"quote":24,"image":29},{},{"kind":36,"lastPreviewUrl":37,"breakpoints":171,"hasAutosaves":41},{"small":39,"medium":40},"kycjhxhhr1l",{},1776247404986,1776247404973,[],{"breakpoints":178,"kind":36,"lastPreviewUrl":37,"hasAutosaves":6},{"xsmall":57,"small":39,"medium":40},"eprevsfdagb",{"createdDate":181,"id":182,"name":88,"modelId":160,"published":13,"meta":183,"stageModifiedSincePublish":6,"query":185,"data":186,"variations":207,"lastUpdated":208,"firstPublished":209,"testRatio":33,"createdBy":53,"lastUpdatedBy":53,"folders":210,"rev":179},1776255761419,"05a9322735fc427db12e2740e4302300",{"breakpoints":184,"kind":36,"lastPreviewUrl":37,"hasAutosaves":6},{"xsmall":57,"small":39,"medium":40},[],{"testimonial":187,"link":206,"type":83,"title":88,"description":84,"image":82},{"@type":17,"id":188,"model":19,"value":189},"192acbb1f9ca4cac918c0ec435a8bae3",{"query":190,"folders":191,"createdDate":192,"id":188,"name":193,"modelId":25,"published":13,"data":194,"variations":200,"lastUpdated":201,"firstPublished":202,"testRatio":33,"createdBy":34,"lastUpdatedBy":53,"meta":203,"rev":205},[],[],1728981467463,"Push does for identity what CrowdStrike did for the endpoint",{"video":195,"jobTitle":196,"author":197,"qoute":37,"quote":198,"image":199},"https://cdn.builder.io/o/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F8b30e8ca50064058bbaef0f3c6164575%2Fcompressed?apiKey=f3a1111ff5be48cdbb123cd9f5795a05&token=8b30e8ca50064058bbaef0f3c6164575&alt=media&optimized=true","\u003Cp>Deputy CISO at Microsoft\u003C/p>\u003Cp>Former LinkedIn, Slack, Palantir\u003C/p>","Geoff Belknap","Push does for identity what CrowdStrike did for the endpoint.","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F748f0ad0a5064a00a13f4721fcc8dea1",{},1742902158597,1728981782923,{"kind":36,"lastPreviewUrl":37,"breakpoints":204,"hasAutosaves":41},{"small":39,"medium":40},"rf1nk49uvdm",{"text":87,"url":86},{},1776255810913,1776255810900,[],[212,235],{"createdDate":213,"id":214,"name":88,"modelId":215,"published":13,"meta":216,"stageModifiedSincePublish":6,"query":218,"data":219,"variations":230,"lastUpdated":231,"firstPublished":232,"testRatio":33,"createdBy":53,"lastUpdatedBy":53,"folders":233,"rev":234},1776256900280,"1f429607996e4e5fae8fe3f9b9610e55","4829faa81e7c4ee8bd2d000e160e8d3c",{"breakpoints":217,"kind":36,"lastPreviewUrl":37,"hasAutosaves":6},{"xsmall":57,"small":39,"medium":40},[],{"testimonial":220,"link":229,"type":83,"title":88,"description":84,"image":82},{"@type":17,"id":188,"model":19,"value":221},{"query":222,"folders":223,"createdDate":192,"id":188,"name":193,"modelId":25,"published":13,"data":224,"variations":225,"lastUpdated":201,"firstPublished":202,"testRatio":33,"createdBy":34,"lastUpdatedBy":53,"meta":226,"rev":228},[],[],{"video":195,"jobTitle":196,"author":197,"qoute":37,"quote":198,"image":199},{},{"kind":36,"lastPreviewUrl":37,"breakpoints":227,"hasAutosaves":41},{"small":39,"medium":40},"uy1z1ivff9",{"text":87,"url":86},{},1776256937553,1776256937540,[],"4st6n1usgrx",{"createdDate":236,"id":237,"name":11,"modelId":215,"published":13,"stageModifiedSincePublish":6,"query":238,"data":239,"variations":249,"lastUpdated":250,"firstPublished":251,"testRatio":33,"createdBy":53,"lastUpdatedBy":53,"folders":252,"meta":253,"rev":234},1776256949234,"ce043785b71b4ece98eac811ecf4ba10",[],{"link":240,"type":19,"testimonial":241,"testimonialLink":48},{},{"@type":17,"id":18,"model":19,"value":242},{"query":243,"folders":244,"createdDate":23,"id":18,"name":24,"modelId":25,"published":13,"data":245,"variations":246,"lastUpdated":31,"firstPublished":32,"testRatio":33,"createdBy":34,"lastUpdatedBy":34,"meta":247,"rev":42},[],[],{"author":27,"jobTitle":28,"quote":24,"image":29},{},{"kind":36,"lastPreviewUrl":37,"breakpoints":248,"hasAutosaves":41},{"small":39,"medium":40},{},1776256974140,1776256974130,[],{"breakpoints":254,"kind":36,"lastPreviewUrl":37,"hasAutosaves":6},{"xsmall":57,"small":39,"medium":40},[256,440,559,678,796,916,1036,1156],{"createdDate":257,"id":258,"name":259,"modelId":260,"published":13,"stageModifiedSincePublish":6,"query":261,"data":267,"variations":428,"lastUpdated":429,"firstPublished":430,"testRatio":33,"screenshot":431,"createdBy":34,"lastUpdatedBy":432,"folders":433,"meta":434,"rev":439},1744829487099,"387451215c314dd5bd654668cdc1a197","Zero-day phishing","cca4143377554c5a9163cc203a8ed2ba",[262],{"@type":263,"property":264,"operator":265,"value":266},"@builder.io/core:Query","urlPath","is","/uc/zero-day-phishing-protection",{"inputs":268,"customFonts":269,"seoTitle":317,"title":317,"tsCode":37,"seoDescription":318,"fontAwesomeIcon":319,"jsCode":37,"blocks":320,"url":266,"state":425},[],[270],{"family":271,"kind":272,"version":273,"lastModified":274,"files":275,"category":294,"menu":295,"subsets":296,"variants":299},"DM Sans","webfonts#webfont","v14","2023-07-13",{"100":276,"200":277,"300":278,"500":279,"600":280,"700":281,"800":282,"900":283,"800italic":284,"900italic":285,"700italic":286,"100italic":287,"italic":288,"regular":289,"200italic":290,"500italic":291,"300italic":292,"600italic":293},"https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwAop1hTmf3ZGMZpg.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwAIpxhTmf3ZGMZpg.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwA_JxhTmf3ZGMZpg.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwAkJxhTmf3ZGMZpg.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwAfJthTmf3ZGMZpg.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwARZthTmf3ZGMZpg.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwAIpthTmf3ZGMZpg.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwAC5thTmf3ZGMZpg.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2rp2ywxg089UriCZaSExd86J3t9jz86Mvy4qCRAL19DksVat8JCm3zRmYJpso5.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2rp2ywxg089UriCZaSExd86J3t9jz86Mvy4qCRAL19DksVat8gCm3zRmYJpso5.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2rp2ywxg089UriCZaSExd86J3t9jz86Mvy4qCRAL19DksVat9uCm3zRmYJpso5.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2rp2ywxg089UriCZaSExd86J3t9jz86Mvy4qCRAL19DksVat-JDG3zRmYJpso5.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2rp2ywxg089UriCZaSExd86J3t9jz86Mvy4qCRAL19DksVat-JDW3zRmYJpso5.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwAopxhTmf3ZGMZpg.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2rp2ywxg089UriCZaSExd86J3t9jz86Mvy4qCRAL19DksVat8JDW3zRmYJpso5.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2rp2ywxg089UriCZaSExd86J3t9jz86Mvy4qCRAL19DksVat-7DW3zRmYJpso5.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2rp2ywxg089UriCZaSExd86J3t9jz86Mvy4qCRAL19DksVat_XDW3zRmYJpso5.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2rp2ywxg089UriCZaSExd86J3t9jz86Mvy4qCRAL19DksVat9XCm3zRmYJpso5.ttf","sans-serif","https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwAopxRT23z.ttf",[297,298],"latin","latin-ext",[300,301,302,303,304,305,128,306,307,308,309,310,311,312,313,314,315,316],"100","200","300","regular","500","600","800","900","100italic","200italic","300italic","italic","500italic","600italic","700italic","800italic","900italic","Zero-day phishing protection","Detect phishing TTPs directly in the browser and stop credential theft.","faFishingRod",[321,420],{"@type":106,"@version":107,"tagName":322,"id":323,"children":324},"div","builder-76c6b8d1499346c7bc1fd56ae4e93638",[325,342,350,357,369,384,395,406,412],{"@type":106,"@version":107,"layerName":326,"id":327,"component":328,"responsiveStyles":339},"UseCaseHero","builder-5228fe062bef4a40a91e43f1112832fa",{"name":326,"options":329,"isRSC":118},{"title":317,"description":330,"points":331,"video":338},"\u003Cp>Push detects phishing as it happens. Autonomous agents hunt for new phishing techniques, identify kit signatures, and deploy detections within minutes of a new attack being analyzed. From cloned login pages to AiTM credential harvesting, Push sees what traditional filters miss and stops threats before they escalate.\u003C/p>",[332,334,336],{"item":333},"Detect phishing that bypasses traditional filters, including AiTM, SSO password theft, and fake login pages",{"item":335},"Stop never-before-seen attacks with AI-native behavioral and on-page analysis inside the browser",{"item":337},"Investigate faster with unified browser, user, and page context","https://cdn.builder.io/o/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F40433ceeb4f94b43a82e039a0f4fd411%2Fcompressed?apiKey=f3a1111ff5be48cdbb123cd9f5795a05&token=40433ceeb4f94b43a82e039a0f4fd411&alt=media&optimized=true",{"large":340},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":341},"transparent",{"@type":106,"@version":107,"id":343,"component":344,"responsiveStyles":347},"builder-96634044407e491299e291ed64669e39",{"name":345,"options":346,"isRSC":118},"TrustedBy",{"AllPartners":41,"backgroundTransparent":6},{"large":348},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":349},"#000",{"@type":106,"@version":107,"id":351,"component":352,"responsiveStyles":355},"builder-2c3768f930534557bb8978e32b6a6a0f",{"name":353,"options":354,"isRSC":118},"Diagonal",{"darkMode":41},{"large":356},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"layerName":358,"id":359,"component":360,"responsiveStyles":367},"TextImageBlockVertical","builder-7c3c1c2840424db2ad2ccbfaf382dd64",{"name":358,"tag":358,"options":361,"isRSC":118},{"darkMode":6,"maxWidth":362,"maxTextWidth":363,"title":364,"description":365,"animatedTitle":37,"image":366,"reverse":6,"descriptionPaddingHorizontal":118},1200,800,"\u003Ch2>Why stop at the inbox?\u003C/h2>","\u003Cp>Phishing attacks have evolved. Whether attackers lure users with QR codes, instant messages, or OAuth consent screens, the outcome is the same: it plays out in the browser. Push gives you real-time detection for in-browser threats, stopping phishing and consent-based attacks before they lead to compromise\u003C/p>\u003Cp>\u003Cbr>\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F7fdcac241f0e4a049166d7076858adeb",{"large":368},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":370,"component":371,"responsiveStyles":379},"builder-41c978b3669749cf947e622b4e79e4d7",{"name":372,"options":373,"isRSC":118},"TextImageBlockHorizontal",{"darkMode":6,"maxWidth":362,"imageMaxWidth":374,"textPaddingTop":375,"title":376,"description":377,"reverse":41,"image":378},600,100,"\u003Cp>Detect phishing at the edge\u003C/p>","\u003Cp>Push uses industry-first telemetry to detect phishing based on behavior, not static indicators. Autonomous agents analyze how phishing pages behave and how users interact with them, uncovering fake logins, credential theft, and phishing kits the moment they load in the browser.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F9df3d180c97b4e61af142af2ccd68721",{"large":380},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"fontFamily":381,"paddingTop":382,"marginTop":383},"DM Sans, sans-serif","20px","0px",{"@type":106,"@version":107,"id":385,"component":386,"responsiveStyles":392},"builder-d2a7bc941feb43cdb898bc116b203cf9",{"name":372,"options":387,"isRSC":118},{"darkMode":6,"maxWidth":362,"imageMaxWidth":374,"textPaddingTop":388,"title":389,"description":390,"reverse":6,"image":391},120,"\u003Ch2>Go beyond blocklists and IOCs\u003C/h2>","\u003Cp>Push goes beyond URLs and easy-to-change indicators. It reads the full phishing playbook like script behavior, session hijacks, DOM changes, user inputs, then connects the dots in real time. This gives your team a complete picture of how the phishing attempt worked, not just an alert.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fabfd58db169b433e96d3f1261797156e",{"large":393},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":394},"36px",{"@type":106,"@version":107,"layerName":372,"id":396,"component":397,"responsiveStyles":403},"builder-42c32198083f4880acb37c5cb76934da",{"name":372,"options":398,"isRSC":118},{"darkMode":6,"maxWidth":362,"imageMaxWidth":374,"textPaddingTop":399,"title":400,"description":401,"reverse":41,"image":402},140,"\u003Ch2>Enhance your phishing response\u003C/h2>","\u003Cp>When phishing enters your environment, speed matters. Push gives you instant access to the telemetry that counts like session data, user behavior, and page activity, so you can investigate fast, trigger in-browser prompts, or forward alerts to your SIEM or SOAR for response. All in real time, right from the browser.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fbb195aec46904056b85e8688629e558e",{"large":404},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":405},"47px",{"@type":106,"@version":107,"id":407,"component":408,"responsiveStyles":410},"builder-9a95b9cbc4854421a92ef7b90f6c7adb",{"name":353,"options":409,"isRSC":118},{"darkMode":6},{"large":411},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":413,"component":414,"responsiveStyles":418},"builder-0afa17a9f25c4661a90f314d5578aa18",{"name":415,"tag":415,"options":416,"isRSC":118},"LatestResources",{"sectionHeading":37,"customClass":417},"bg-black",{"large":419},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"id":421,"@type":106,"tagName":131,"properties":422,"responsiveStyles":423},"builder-pixel-3f5qy8b7nr2",{"src":133,"aria-hidden":134,"alt":37,"role":135,"width":124,"height":124},{"large":424},{"height":124,"width":124,"display":138,"opacity":124,"overflow":139,"pointerEvents":140},{"deviceSize":142,"location":426},{"path":37,"query":427},{},{},1776275046831,1745499158657,"https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fff60c30a8442489c8ed7e0af9599d14f","kYgMv6WsbvfmlOUYqR2SFwGzw6e2",[],{"lastPreviewUrl":435,"winningTest":118,"breakpoints":436,"kind":437,"hasLinks":6,"originalContentId":438,"hasAutosaves":6},"https://pushsecurity.com/uc/zero-day-phishing-protection?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CcreateProjects%2CsendPullRequests&builder.user.role.name=Designer&builder.user.role.id=creator&builder.cachebust=true&builder.preview=use-case-page&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.use-case-page=387451215c314dd5bd654668cdc1a197&builder.overrides.387451215c314dd5bd654668cdc1a197=387451215c314dd5bd654668cdc1a197&builder.overrides.use-case-page:/uc/zero-day-phishing-protection=387451215c314dd5bd654668cdc1a197&builder.options.locale=Default",{"xsmall":57,"small":39,"medium":40},"page","2daa5670b8504fc7ba4700633e8bd921","ab51vau1ylb",{"createdDate":441,"id":442,"name":443,"modelId":260,"published":13,"stageModifiedSincePublish":6,"query":444,"data":447,"variations":551,"lastUpdated":552,"firstPublished":553,"testRatio":33,"screenshot":554,"createdBy":34,"lastUpdatedBy":432,"folders":555,"meta":556,"rev":439},1756833377777,"54f8256648f54d439303734b1e69221b","Browser extension security",[445],{"@type":263,"property":264,"operator":265,"value":446},"/uc/browser-extension-security",{"seoDescription":448,"jsCode":37,"fontAwesomeIcon":449,"tsCode":37,"title":443,"seoTitle":443,"customFonts":450,"inputs":455,"blocks":456,"url":446,"state":548},"Shine a light on risky browser extensions.","faPuzzlePiece",[451],{"kind":272,"family":271,"version":273,"files":452,"category":294,"lastModified":274,"subsets":453,"variants":454,"menu":295},{"100":276,"200":277,"300":278,"500":279,"600":280,"700":281,"800":282,"900":283,"100italic":287,"italic":288,"regular":289,"900italic":285,"800italic":284,"700italic":286,"200italic":290,"300italic":292,"500italic":291,"600italic":293},[297,298],[300,301,302,303,304,305,128,306,307,308,309,310,311,312,313,314,315,316],[],[457,543],{"@type":106,"@version":107,"tagName":322,"id":458,"meta":459,"children":460},"builder-71d0648c1d2f4ede8d0d0b5b28b7b94c",{"previousId":323},[461,477,484,491,500,510,520,530,537],{"@type":106,"@version":107,"id":462,"meta":463,"component":464,"responsiveStyles":475},"builder-ff325b4b8fad4edea53f38865947e854",{"previousId":327},{"name":326,"options":465,"isRSC":118},{"title":443,"description":466,"points":467,"video":474},"\u003Cp>Browser extensions introduce new code, new permissions, and new potential for risk. Many include AI features, and most go completely unnoticed. Push gives you full visibility into every extension used across your workforce, across major browsers, so you can uncover shadow IT, assess risky permissions, and block unsafe tools before they lead to compromise.\u003C/p>",[468,470,472],{"item":469},"Discover every browser extension in use",{"item":471},"Spot risky or unsanctioned behavior",{"item":473},"Make informed decisions on extension policy","https://cdn.builder.io/o/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fc538aad95d7f403aa3c3551af72f67c0?alt=media&token=1411fa6d-2eac-4e6c-94bf-ea117da12d67&apiKey=f3a1111ff5be48cdbb123cd9f5795a05",{"large":476},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":341},{"@type":106,"@version":107,"id":478,"meta":479,"component":480,"responsiveStyles":482},"builder-fb89d128c64e47cf9cbb11d90fc24523",{"previousId":343},{"name":345,"options":481,"isRSC":118},{"AllPartners":41,"backgroundTransparent":6},{"large":483},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":349},{"@type":106,"@version":107,"id":485,"meta":486,"component":487,"responsiveStyles":489},"builder-54388d35126c4d0096eeebaf8c4448cd",{"previousId":351},{"name":353,"options":488,"isRSC":118},{"darkMode":41},{"large":490},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"layerName":358,"id":492,"component":493,"responsiveStyles":498},"builder-3c8fa6785dd6466abf52a2470d66d85a",{"name":358,"tag":358,"options":494,"isRSC":118},{"darkMode":6,"maxWidth":362,"maxTextWidth":363,"title":495,"description":496,"image":497,"reverse":6},"\u003Ch2>Take control of browser extensions\u003C/h2>","\u003Cp>Attackers are increasingly using malicious browser extensions to gain access to data processed and stored in the browser. And the problem is, most security teams have no visibility into what extensions are being used. Push changes that. With browser-native telemetry, the Push extension continuously inventories browser extensions across your environment, flags the risky ones, and gives you intelligence to act.&nbsp;\u003C/p>\u003Cp>\u003Cbr>\u003C/p>\u003Cp>\u003Cbr>\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F0a004f16a6874f4c8fdf14344acc9fec",{"large":499},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":501,"meta":502,"component":503,"responsiveStyles":508},"builder-93738f98109a4009affb349afd7bb182",{"previousId":370},{"name":372,"options":504,"isRSC":118},{"darkMode":6,"maxWidth":362,"imageMaxWidth":374,"textPaddingTop":375,"title":505,"description":506,"reverse":41,"image":507},"\u003Ch2>Discover every extension in use\u003C/h2>","\u003Cp>Push gives you structured, searchable data about every extension in your environment, so you’re not just seeing what’s there, but also understanding how it got there, what it can do, and who it affects. It’s the kind of granular insight that’s nearly impossible to get from traditional tools, and it lays the groundwork for better policy decisions and faster investigations.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F0e5727ca99474f14b1b7916bf6bbb782",{"large":509},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"fontFamily":381,"paddingTop":382,"marginTop":383},{"@type":106,"@version":107,"id":511,"meta":512,"component":513,"responsiveStyles":518},"builder-83393acb12ee4fdd840839185b51edb4",{"previousId":385},{"name":372,"options":514,"isRSC":118},{"darkMode":6,"maxWidth":362,"imageMaxWidth":374,"textPaddingTop":388,"title":515,"description":516,"reverse":6,"image":517},"\u003Ch2>Spot risky or malicious extensions\u003C/h2>","\u003Cp>Push highlights extensions with dangerous permissions, broad access, or poor reputations. This includes AI extensions that request access far beyond what their stated purpose requires. You can quickly detect sideloaded, manually installed, or development-mode extensions that bypass normal controls. And because Push shows you who’s using them and where, you can respond precisely and effectively.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fa104d58c8da34fbb8901f738fb21453b",{"large":519},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":394},{"@type":106,"@version":107,"layerName":372,"id":521,"meta":522,"component":523,"responsiveStyles":528},"builder-da98e3de949646d89c53a0d1c2784664",{"previousId":396},{"name":372,"options":524,"isRSC":118},{"darkMode":6,"maxWidth":362,"imageMaxWidth":374,"textPaddingTop":399,"title":525,"description":526,"reverse":41,"image":527},"\u003Ch2>Accelerate security reviews\u003C/h2>","\u003Cp>Most teams have extension policies, they just don’t have the data to enforce them. Push reveals how each extension entered your environment, whether it was installed manually, sideloaded, or deployed in dev mode. You’ll see which users are running what, and where, so you can surface violations, investigate quickly, and respond with confidence.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F229f355be6f243b180f410d237a75bb3",{"large":529},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":405},{"@type":106,"@version":107,"id":531,"meta":532,"component":533,"responsiveStyles":535},"builder-1a689287d1a1418997d57db578a71105",{"previousId":407},{"name":353,"options":534,"isRSC":118},{"darkMode":6},{"large":536},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":538,"component":539,"responsiveStyles":541},"builder-feb4e75029f84c10b6498ef1f8f79128",{"name":415,"tag":415,"options":540,"isRSC":118},{"sectionHeading":37,"customClass":417},{"large":542},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"id":544,"@type":106,"tagName":131,"properties":545,"responsiveStyles":546},"builder-pixel-l4m8coeeg6k",{"src":133,"aria-hidden":134,"alt":37,"role":135,"width":124,"height":124},{"large":547},{"height":124,"width":124,"display":138,"opacity":124,"overflow":139,"pointerEvents":140},{"deviceSize":142,"location":549},{"path":37,"query":550},{},{},1776275365038,1757000441666,"https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F8d496cf111644ee5afcc046b72d1ca5a",[],{"kind":437,"winningTest":118,"breakpoints":557,"lastPreviewUrl":558,"hasLinks":6,"originalContentId":258,"hasAutosaves":6},{"xsmall":57,"small":39,"medium":40},"https://pushsecurity.com/uc/browser-extension-security?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CcreateProjects%2CsendPullRequests&builder.user.role.name=Designer&builder.user.role.id=creator&builder.cachebust=true&builder.preview=use-case-page&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.use-case-page=54f8256648f54d439303734b1e69221b&builder.overrides.54f8256648f54d439303734b1e69221b=54f8256648f54d439303734b1e69221b&builder.overrides.use-case-page:/uc/browser-extension-security=54f8256648f54d439303734b1e69221b&builder.options.locale=Default",{"createdDate":560,"id":561,"name":562,"modelId":260,"published":13,"query":563,"data":566,"variations":669,"lastUpdated":670,"firstPublished":671,"testRatio":33,"screenshot":672,"createdBy":34,"lastUpdatedBy":673,"folders":674,"meta":675,"rev":439},1744923509705,"94bebb7bb99d48629ad157e80cf4d81d","Account takeover detection",[564],{"@type":263,"property":264,"operator":265,"value":565},"/uc/account-takeover-detection",{"title":562,"customFonts":567,"jsCode":37,"seoTitle":562,"seoDescription":572,"fontAwesomeIcon":573,"tsCode":37,"blocks":574,"url":565,"state":666},[568],{"kind":272,"category":294,"variants":569,"menu":295,"files":570,"family":271,"subsets":571,"version":273,"lastModified":274},[300,301,302,303,304,305,128,306,307,308,309,310,311,312,313,314,315,316],{"100":276,"200":277,"300":278,"500":279,"600":280,"700":281,"800":282,"900":283,"300italic":292,"500italic":291,"800italic":284,"700italic":286,"italic":288,"900italic":285,"600italic":293,"200italic":290,"regular":289,"100italic":287},[297,298],"Stop ATO with stolen credential and compromised token detection.","faUserSecret",[575,661],{"@type":106,"@version":107,"tagName":322,"id":576,"meta":577,"children":578},"builder-e7913a774cae44c5a23d6081c5c30a52",{"previousId":323},[579,595,602,609,618,628,638,648,655],{"@type":106,"@version":107,"id":580,"meta":581,"component":582,"responsiveStyles":593},"builder-f1f1ab1601bc4c0f8c2a8aafd173675d",{"previousId":327},{"name":326,"options":583,"isRSC":118},{"title":562,"description":584,"points":585,"video":592},"\u003Cp>Attackers don’t need to phish, they just need a password that works. Push monitors for signs of credential-based attacks in real time, directly in the browser, catching account takeover attempts before the damage spreads. From ghost logins to credential stuffing, Push cuts off the paths attackers use to quietly slip in the back door.\u003C/p>\u003Cp>\u003Cbr>\u003C/p>",[586,588,590],{"item":587},"Identify credential-based ATO as it unfolds",{"item":589},"Surface hijacked sessions and token misuse",{"item":591},"Strengthen authentication where your IdP can’t","https://cdn.builder.io/o/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fb4dd9db24bc9495b8a686b1b4d492016%2Fcompressed?apiKey=f3a1111ff5be48cdbb123cd9f5795a05&token=b4dd9db24bc9495b8a686b1b4d492016&alt=media&optimized=true",{"large":594},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":341},{"@type":106,"@version":107,"id":596,"meta":597,"component":598,"responsiveStyles":600},"builder-0bc0d1c78ece4994993c3a6427a4d533",{"previousId":343},{"name":345,"options":599,"isRSC":118},{"AllPartners":41,"backgroundTransparent":6},{"large":601},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":349},{"@type":106,"@version":107,"id":603,"meta":604,"component":605,"responsiveStyles":607},"builder-e45de8f3768c4f16938dbf78e4e87524",{"previousId":351},{"name":353,"options":606,"isRSC":118},{"darkMode":41},{"large":608},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":610,"component":611,"responsiveStyles":616},"builder-c98e8bfd341146c1b67c02d5698ff093",{"name":358,"tag":358,"options":612,"isRSC":118},{"darkMode":6,"maxWidth":362,"maxTextWidth":363,"title":613,"description":614,"image":615,"reverse":6},"\u003Ch2>Assume less. See more.\u003C/h2>","\u003Cp>Most account takeovers don’t start with a breach, they start with a login. Whether it’s a reused password, a local account, or an outdated login flow, Push shows you how accounts are actually accessed day to day, not just how policies say they should be. That means no more blind spots around ghost logins, bypassed SSO, or stale access paths that quietly persist.\u003C/p>\u003Cp>\u003Cbr>\u003C/p>\u003Cp>\u003Cbr>\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F18630ad2746d4eb7b7fcc0428b11a8f0",{"large":617},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":619,"meta":620,"component":621,"responsiveStyles":626},"builder-55c1fc38ddc04fd1a0d6a8e2fb819e00",{"previousId":370},{"name":372,"options":622,"isRSC":118},{"darkMode":6,"maxWidth":362,"imageMaxWidth":374,"textPaddingTop":375,"title":623,"description":624,"reverse":41,"image":625},"\u003Ch2>Catch stolen credential use in real time\u003C/h2>","\u003Cp>Push monitors login activity directly in the browser to detect signs of credential-based attacks like leaked password use or suspicious login flows. By analyzing attacker TTPs instead of relying on known indicators, Push spots credential stuffing and account takeover attempts the moment they begin, not after they’ve succeeded.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F52b0123cac2c4dfdb1dc0af6adf9d603",{"large":627},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"fontFamily":381,"paddingTop":383,"marginTop":383},{"@type":106,"@version":107,"id":629,"meta":630,"component":631,"responsiveStyles":636},"builder-dfb31737b30948c6b95323655d571a50",{"previousId":385},{"name":372,"options":632,"isRSC":118},{"darkMode":6,"maxWidth":362,"imageMaxWidth":374,"textPaddingTop":388,"title":633,"description":634,"reverse":6,"image":635},"\u003Ch2>Detect session hijacks and stealth access\u003C/h2>","\u003Cp>Attackers don’t always need a login screen, they often sidestep it entirely using stolen session tokens. Push detects when valid sessions are reused in unexpected ways, identifying hijacked sessions and stealth access attempts that traditional tools miss. Because we monitor directly in the browser, you see what’s happening inside active sessions in real time.\u003C/p>\u003Cp>\u003Cbr>\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F94a6859a99e04d309ffe5841f3dbdf5c",{"large":637},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":394},{"@type":106,"@version":107,"layerName":372,"id":639,"meta":640,"component":641,"responsiveStyles":646},"builder-f7585b90eb974d03a7dc7eae5b58d227",{"previousId":396},{"name":372,"options":642,"isRSC":118},{"darkMode":6,"maxWidth":362,"imageMaxWidth":374,"textPaddingTop":399,"title":643,"description":644,"reverse":41,"image":645},"\u003Ch2>Harden accounts before they’re compromised\u003C/h2>","\u003Cp>Push goes beyond alerts. It identifies apps that still allow local logins, even when SSO is configured, so you can remove weak access paths. Push also flags users without MFA, reused work credentials, or weak passwords, and prompts users in-browser to fix risky behaviors before they’re exploited.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F01c1b638f1b6497093a4f2b8ceddb5bb",{"large":647},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":405},{"@type":106,"@version":107,"id":649,"meta":650,"component":651,"responsiveStyles":653},"builder-ad81d1e3afec49a791214194eae09bdc",{"previousId":407},{"name":353,"options":652,"isRSC":118},{"darkMode":6},{"large":654},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":656,"component":657,"responsiveStyles":659},"builder-8dac1aa4b9d148628d92252bd8eff822",{"name":415,"tag":415,"options":658,"isRSC":118},{"sectionHeading":37,"customClass":417},{"large":660},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"id":662,"@type":106,"tagName":131,"properties":663,"responsiveStyles":664},"builder-pixel-vowakgqrn1",{"src":133,"aria-hidden":134,"alt":37,"role":135,"width":124,"height":124},{"large":665},{"height":124,"width":124,"display":138,"opacity":124,"overflow":139,"pointerEvents":140},{"deviceSize":142,"location":667},{"path":37,"query":668},{},{},1770892814499,1745499162732,"https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F58b660fa94aa4b30b0faeb9b663ae41a","SfUPqW5tkibIPby49keNFMdHFTr1",[],{"lastPreviewUrl":676,"hasLinks":6,"originalContentId":258,"breakpoints":677,"winningTest":118,"kind":437,"hasAutosaves":41},"https://pushsecurity.com/uc/account-takeover-detection?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditCode%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CeditProjects%2CmodifyMcpServers%2CmodifyWorkflowIntegrations%2CmodifyProjectSettings%2CconnectCodeRepository%2CcreateProjects%2CindexDesignSystems%2CsendPullRequests&builder.user.role.name=Developer&builder.user.role.id=developer&builder.cachebust=true&builder.preview=use-case-page&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.use-case-page=94bebb7bb99d48629ad157e80cf4d81d&builder.overrides.94bebb7bb99d48629ad157e80cf4d81d=94bebb7bb99d48629ad157e80cf4d81d&builder.overrides.use-case-page:/uc/account-takeover-detection=94bebb7bb99d48629ad157e80cf4d81d&builder.options.includeRefs=true&builder.options.enrich=true&builder.options.locale=Default",{"xsmall":57,"small":39,"medium":40},{"createdDate":679,"id":680,"name":681,"modelId":260,"published":13,"query":682,"data":685,"variations":788,"lastUpdated":789,"firstPublished":790,"testRatio":33,"screenshot":791,"createdBy":34,"lastUpdatedBy":673,"folders":792,"meta":793,"rev":439},1745009370904,"23eb48fb56d3451cab77cb6ed140ee6d","Attack path hardening",[683],{"@type":263,"property":264,"operator":265,"value":684},"/uc/attack-path-hardening",{"tsCode":37,"seoDescription":686,"jsCode":37,"customFonts":687,"fontAwesomeIcon":692,"seoTitle":681,"title":681,"blocks":693,"url":684,"state":785},"Harden access paths with visibility,  detection, and guardrails.",[688],{"kind":272,"files":689,"version":273,"lastModified":274,"subsets":690,"menu":295,"category":294,"variants":691,"family":271},{"100":276,"200":277,"300":278,"500":279,"600":280,"700":281,"800":282,"900":283,"regular":289,"italic":288,"800italic":284,"500italic":291,"600italic":293,"200italic":290,"900italic":285,"700italic":286,"100italic":287,"300italic":292},[297,298],[300,301,302,303,304,305,128,306,307,308,309,310,311,312,313,314,315,316],"faRadar",[694,780],{"@type":106,"@version":107,"tagName":322,"id":695,"meta":696,"children":697},"builder-1d8553eddcaa44d7bba9e2f4ca13af2a",{"previousId":576},[698,714,721,728,737,747,757,767,774],{"@type":106,"@version":107,"id":699,"meta":700,"component":701,"responsiveStyles":712},"builder-84fe3d7c85a743cf8cef649aa974f1ef",{"previousId":580},{"name":326,"options":702,"isRSC":118},{"title":681,"description":703,"points":704,"video":711},"\u003Cp>Push continuously monitors your environment for exposed login paths, weak credentials, and missing protections like MFA. It detects the gaps attackers exploit and helps you close them before they’re used.\u003C/p>",[705,707,709],{"item":706},"Find weak spots like reused passwords, local logins, and missing MFA",{"item":708},"Monitor how users actually log in across apps, flows, and tools",{"item":710},"Enforce secure access with in-browser guardrails","https://cdn.builder.io/o/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fdbdcf52892034f1bbddded77f753a343%2Fcompressed?apiKey=f3a1111ff5be48cdbb123cd9f5795a05&token=dbdcf52892034f1bbddded77f753a343&alt=media&optimized=true",{"large":713},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":341},{"@type":106,"@version":107,"id":715,"meta":716,"component":717,"responsiveStyles":719},"builder-b3f66f5b08054cc78a06fecfc3ae2337",{"previousId":596},{"name":345,"options":718,"isRSC":118},{"AllPartners":41,"backgroundTransparent":6},{"large":720},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":349},{"@type":106,"@version":107,"id":722,"meta":723,"component":724,"responsiveStyles":726},"builder-4c73418b84be49ed85e6e13d2625c5a0",{"previousId":603},{"name":353,"options":725,"isRSC":118},{"darkMode":41},{"large":727},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":729,"component":730,"responsiveStyles":735},"builder-dec0246085e1485c803f7152b1922a81",{"name":358,"tag":358,"options":731,"isRSC":118},{"darkMode":6,"maxWidth":362,"maxTextWidth":363,"title":732,"description":733,"image":734,"reverse":6},"\u003Ch2>Find the gaps that lead to compromise\u003C/h2>","\u003Cp>Misconfigurations don’t show up in your config files, they show up in how users actually access apps. Push monitors real login behavior in the browser, surfacing risky patterns like local login access, duplicate accounts, or missing protections that leave doors wide open.\u003C/p>\u003Cp>\u003Cbr>\u003C/p>\u003Cp>\u003Cbr>\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F309a59bba8d247a19476bb369397460e",{"large":736},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":738,"meta":739,"component":740,"responsiveStyles":745},"builder-ebf049a645604a249550996a88f8f3b6",{"previousId":619},{"name":372,"options":741,"isRSC":118},{"darkMode":6,"maxWidth":362,"imageMaxWidth":374,"textPaddingTop":375,"title":742,"description":743,"reverse":41,"image":744},"\u003Ch2>See real login behavior\u003C/h2>","\u003Cp>Push watches authentication flows as they happen, giving you a live view of how users log in, which methods they choose, and where protections like MFA are missing. Plus, uncover every app and account in use, even shadow IT you didn’t know existed, without relying on stale config files or IdP assumptions. \u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fb51f6b0357cc451b87a7a5016d984e5e",{"large":746},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"fontFamily":381,"paddingTop":382,"marginTop":383},{"@type":106,"@version":107,"id":748,"meta":749,"component":750,"responsiveStyles":755},"builder-431d175c59004669b0b2776b07d71737",{"previousId":629},{"name":372,"options":751,"isRSC":118},{"darkMode":6,"maxWidth":362,"imageMaxWidth":374,"textPaddingTop":388,"title":752,"description":753,"reverse":6,"image":754},"\u003Ch2>Find and fix posture drift\u003C/h2>","\u003Cp>Security posture isn’t static. Push continuously monitors for issues like missing MFA or legacy login methods. When something falls out of policy, you know immediately with custom notifications so you can act before it turns into risk.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F324e39127dfc41e592b1183dfb39892d",{"large":756},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":394},{"@type":106,"@version":107,"layerName":372,"id":758,"meta":759,"component":760,"responsiveStyles":765},"builder-3dffdcbe0a484e2ca4c03f019b6d40ee",{"previousId":639},{"name":372,"options":761,"isRSC":118},{"darkMode":6,"maxWidth":362,"imageMaxWidth":374,"textPaddingTop":399,"title":762,"description":763,"reverse":41,"image":764},"\u003Ch2>Guide users with in-browser guardrails\u003C/h2>","\u003Cp>Push doesn’t just surface problems, it helps you fix them. When users sign in without MFA, reuse a password, or use insecure credentials, Push prompts them directly in the browser to secure their access. It’s faster, more effective, and actually gets results.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fee8b75d13e45488aba55434a8b49ebb0",{"large":766},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":405},{"@type":106,"@version":107,"id":768,"meta":769,"component":770,"responsiveStyles":772},"builder-976bc222cd7647ff905f1e01cfedc453",{"previousId":649},{"name":353,"options":771,"isRSC":118},{"darkMode":6},{"large":773},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":775,"component":776,"responsiveStyles":778},"builder-8c47ec2fd0f74382bb3e6c870555632c",{"name":415,"tag":415,"options":777,"isRSC":118},{"sectionHeading":37,"customClass":417},{"large":779},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"id":781,"@type":106,"tagName":131,"properties":782,"responsiveStyles":783},"builder-pixel-w6n5c4hrdvc",{"src":133,"aria-hidden":134,"alt":37,"role":135,"width":124,"height":124},{"large":784},{"height":124,"width":124,"display":138,"opacity":124,"overflow":139,"pointerEvents":140},{"deviceSize":142,"location":786},{"path":37,"query":787},{},{},1770892844854,1745499166112,"https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F6ca12bf728a045f1a31d40c0beb3bfe5",[],{"kind":437,"lastPreviewUrl":794,"breakpoints":795,"hasLinks":6,"originalContentId":561,"winningTest":118,"hasAutosaves":6},"https://pushsecurity.com/uc/attack-path-hardening?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditCode%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CeditProjects%2CmodifyMcpServers%2CmodifyWorkflowIntegrations%2CmodifyProjectSettings%2CconnectCodeRepository%2CcreateProjects%2CindexDesignSystems%2CsendPullRequests&builder.user.role.name=Developer&builder.user.role.id=developer&builder.cachebust=true&builder.preview=use-case-page&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.use-case-page=23eb48fb56d3451cab77cb6ed140ee6d&builder.overrides.23eb48fb56d3451cab77cb6ed140ee6d=23eb48fb56d3451cab77cb6ed140ee6d&builder.overrides.use-case-page:/uc/attack-path-hardening=23eb48fb56d3451cab77cb6ed140ee6d&builder.options.includeRefs=true&builder.options.enrich=true&builder.options.locale=Default",{"xsmall":57,"small":39,"medium":40},{"createdDate":797,"id":798,"name":799,"modelId":260,"published":13,"query":800,"data":803,"variations":908,"lastUpdated":909,"firstPublished":910,"testRatio":33,"screenshot":911,"createdBy":34,"lastUpdatedBy":673,"folders":912,"meta":913,"rev":439},1761675020232,"ea4f309d2ffe46c5aa97ebf0fda4e2e3","ClickFix Protection",[801],{"@type":263,"property":264,"operator":265,"value":802},"/uc/clickfix-protection",{"seoDescription":804,"fontAwesomeIcon":805,"customFonts":806,"seoTitle":811,"jsCode":37,"tsCode":37,"title":811,"blocks":812,"url":802,"state":905},"Block attacks that trick users into running malicious code.","faLaptopCode",[807],{"files":808,"subsets":809,"menu":295,"version":273,"kind":272,"family":271,"lastModified":274,"variants":810,"category":294},{"100":276,"200":277,"300":278,"500":279,"600":280,"700":281,"800":282,"900":283,"200italic":290,"800italic":284,"700italic":286,"600italic":293,"100italic":287,"italic":288,"regular":289,"300italic":292,"500italic":291,"900italic":285},[297,298],[300,301,302,303,304,305,128,306,307,308,309,310,311,312,313,314,315,316],"ClickFix protection",[813,900],{"@type":106,"@version":107,"tagName":322,"id":814,"meta":815,"children":816},"builder-d7eefdde0f2a4b2b9de3dcb2978fd6cb",{"previousId":695},[817,833,840,847,857,867,877,887,894],{"@type":106,"@version":107,"id":818,"meta":819,"component":820,"responsiveStyles":831},"builder-56e2c54bcce040a4af8b92ae03706c12",{"previousId":699},{"name":326,"options":821,"isRSC":118},{"title":811,"description":822,"points":823,"image":830},"\u003Cp>ClickFix attacks are one of the fastest-growing threats, tricking users into copying malicious code from a webpage and running it locally. This technique bypasses traditional EDR, email gateways, and network filters, leading directly to ransomware and data theft. Push stops this attack at the source, in the browser, by detecting and blocking the malicious behavior before the user can ever paste the code.\u003C/p>\u003Cp>\u003Cbr>\u003C/p>",[824,826,828],{"item":825},"Detect ClickFix, FileFix, and fake CAPTCHA in the browser",{"item":827},"Block malicious copy-and-paste actions before code is executed",{"item":829},"See full telemetry into which users were targeted and what they saw","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F7b74af62889847ebb3927364485b0546",{"large":832},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":341},{"@type":106,"@version":107,"id":834,"meta":835,"component":836,"responsiveStyles":838},"builder-05f9614d4e3e4dc88b3ee8658f54e10e",{"previousId":715},{"name":345,"options":837,"isRSC":118},{"AllPartners":41,"backgroundTransparent":6},{"large":839},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":349},{"@type":106,"@version":107,"id":841,"meta":842,"component":843,"responsiveStyles":845},"builder-c4fb5179366243c1b6c32d368675cf47",{"previousId":722},{"name":353,"options":844,"isRSC":118},{"darkMode":41},{"large":846},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":848,"meta":849,"component":850,"responsiveStyles":855},"builder-261af50705fd445d8cca4a6ba20d5391",{"previousId":729},{"name":358,"tag":358,"options":851,"isRSC":118},{"darkMode":6,"maxWidth":362,"maxTextWidth":363,"title":852,"description":853,"reverse":6,"image":854},"\u003Ch2>Stop ClickFix-style attacks before they become a breach\u003C/h2>","\u003Cp>Traditional security tools are blind to malicious copy and paste attacks because the attack exploits a gap between the browser and the endpoint. EDR only sees the payload after it runs, and network tools see only part of the picture.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F98b2f7e08dec4eafaf8e24937605b8cf",{"large":856},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":858,"meta":859,"component":860,"responsiveStyles":865},"builder-7d21b8aab8064c40b1e5dd23c4749309",{"previousId":738},{"name":372,"options":861,"isRSC":118},{"darkMode":6,"maxWidth":362,"imageMaxWidth":374,"textPaddingTop":375,"title":862,"description":863,"reverse":41,"image":864},"\u003Ch2>Discover lures at the source\u003C/h2>","\u003Cp>Push inspects page behavior to identify ClickFix attacks as they happen. By inspecting the page, its structure, and how the user interacts with it, Push can detect and block these in-browser threats in real time. This deep, TTP-based inspection spots the trap even on novel pages that are built to bypass traditional web filters and blocklists.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F665bf47e01544c75bf9ddafd3917927b",{"large":866},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"fontFamily":381,"paddingTop":382,"marginTop":383},{"@type":106,"@version":107,"id":868,"meta":869,"component":870,"responsiveStyles":875},"builder-fb91943adf6149259ed9e1e6566c9afe",{"previousId":748},{"name":372,"options":871,"isRSC":118},{"darkMode":6,"maxWidth":362,"imageMaxWidth":374,"textPaddingTop":388,"title":872,"description":873,"reverse":6,"image":874},"\u003Ch2>Block the malicious action\u003C/h2>","\u003Cp>When Push detects a malicious script, it intercepts the user's action and blocks the code from being copied to the clipboard. The user is protected, the attack is stopped, and no malicious code ever reaches the endpoint. Unlike broad DLP tools, this action is surgical, targeting only malicious behavior without disrupting normal work.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F5ee68f81f1ac416685cbfe91298cf827",{"large":876},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":394},{"@type":106,"@version":107,"layerName":372,"id":878,"meta":879,"component":880,"responsiveStyles":885},"builder-bfac95fada864e5a8259b955b5b5f98b",{"previousId":758},{"name":372,"options":881,"isRSC":118},{"darkMode":6,"maxWidth":362,"imageMaxWidth":374,"textPaddingTop":399,"title":882,"description":883,"reverse":41,"image":884},"\u003Ch2>Accelerate ClickFix investigations\u003C/h2>","\u003Cp>When an attack happens, knowing what the user saw or did is critical. Push provides rich browser session data for rapid investigation and containment. Security teams get detailed telemetry on which users were targeted, what lure they were served, and when the block occurred. This enables defenders to reconstruct what happened and respond quickly, even when other tools miss the activity entirely.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F6cdf2a8aeddc4e9a9023cbf974e40239",{"large":886},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":405},{"@type":106,"@version":107,"id":888,"meta":889,"component":890,"responsiveStyles":892},"builder-136892e831684a6987f87d3be67c33d1",{"previousId":768},{"name":353,"options":891,"isRSC":118},{"darkMode":6},{"large":893},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":895,"component":896,"responsiveStyles":898},"builder-dec26b739f2f42beb5a73cfc6c675b60",{"name":415,"tag":415,"options":897,"isRSC":118},{"sectionHeading":37,"customClass":417},{"large":899},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"id":901,"@type":106,"tagName":131,"properties":902,"responsiveStyles":903},"builder-pixel-qoj56hxyz3e",{"src":133,"aria-hidden":134,"alt":37,"role":135,"width":124,"height":124},{"large":904},{"height":124,"width":124,"display":138,"opacity":124,"overflow":139,"pointerEvents":140},{"deviceSize":142,"location":906},{"path":37,"query":907},{},{},1770892881888,1761847585203,"https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F375467b8bef34ed1a8a1cc5b8b67d75f",[],{"lastPreviewUrl":914,"originalContentId":680,"winningTest":118,"hasLinks":6,"kind":437,"breakpoints":915,"hasAutosaves":6},"https://pushsecurity.com/uc/clickfix-protection?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditCode%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CeditProjects%2CmodifyMcpServers%2CmodifyWorkflowIntegrations%2CmodifyProjectSettings%2CconnectCodeRepository%2CcreateProjects%2CindexDesignSystems%2CsendPullRequests&builder.user.role.name=Developer&builder.user.role.id=developer&builder.cachebust=true&builder.preview=use-case-page&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.use-case-page=ea4f309d2ffe46c5aa97ebf0fda4e2e3&builder.overrides.ea4f309d2ffe46c5aa97ebf0fda4e2e3=ea4f309d2ffe46c5aa97ebf0fda4e2e3&builder.overrides.use-case-page:/uc/clickfix-protection=ea4f309d2ffe46c5aa97ebf0fda4e2e3&builder.options.includeRefs=true&builder.options.enrich=true&builder.options.locale=Default",{"xsmall":57,"small":39,"medium":40},{"createdDate":917,"id":918,"name":919,"modelId":260,"published":13,"query":920,"data":923,"variations":1028,"lastUpdated":1029,"firstPublished":1030,"testRatio":33,"screenshot":1031,"createdBy":34,"lastUpdatedBy":673,"folders":1032,"meta":1033,"rev":439},1745009743870,"a9d5556e77f84a37b5bd52310a7110c1","Incident response",[921],{"@type":263,"property":264,"operator":265,"value":922},"/uc/incident-response",{"seoDescription":924,"customFonts":925,"title":919,"jsCode":37,"fontAwesomeIcon":930,"seoTitle":931,"tsCode":37,"blocks":932,"url":922,"state":1025},"Investigate and respond faster with unique browser telemetry.",[926],{"kind":272,"subsets":927,"menu":295,"variants":928,"category":294,"family":271,"version":273,"lastModified":274,"files":929},[297,298],[300,301,302,303,304,305,128,306,307,308,309,310,311,312,313,314,315,316],{"100":276,"200":277,"300":278,"500":279,"600":280,"700":281,"800":282,"900":283,"900italic":285,"600italic":293,"200italic":290,"300italic":292,"100italic":287,"700italic":286,"800italic":284,"regular":289,"italic":288,"500italic":291},"faSatelliteDish","Browser based incident response",[933,1020],{"@type":106,"@version":107,"tagName":322,"id":934,"meta":935,"children":936},"builder-653c4aed737b4def88dc4cd2d695660a",{"previousId":695},[937,954,961,968,977,987,997,1007,1014],{"@type":106,"@version":107,"id":938,"meta":939,"component":940,"responsiveStyles":952},"builder-18190bd36518467d9154d27d7e945b9b",{"previousId":699},{"name":326,"options":941,"isRSC":118},{"title":942,"description":943,"points":944,"video":951},"Browser-based incident response","\u003Cp>Push gives you real-time visibility into what actually happened during a breach, right in the browser where the attack played out. From credential theft to session hijacking, Push captures high-fidelity telemetry so you can investigate quickly, contain confidently, and shut it down before it spreads.\u003C/p>\u003Cp>\u003Cbr>\u003C/p>",[945,947,949],{"item":946},"Reconstruct what happened with real browser session context",{"item":948},"Investigate faster with real-world session context",{"item":950},"Trigger response actions automatically through your SIEM or SOAR","https://cdn.builder.io/o/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fd00e39d3b6e346c296261d875cf55652%2Fcompressed?apiKey=f3a1111ff5be48cdbb123cd9f5795a05&token=d00e39d3b6e346c296261d875cf55652&alt=media&optimized=true",{"large":953},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":341},{"@type":106,"@version":107,"id":955,"meta":956,"component":957,"responsiveStyles":959},"builder-8a0a8ea63f5d48dd8a6726f2d49cf0ca",{"previousId":715},{"name":345,"options":958,"isRSC":118},{"AllPartners":41,"backgroundTransparent":6},{"large":960},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":349},{"@type":106,"@version":107,"id":962,"meta":963,"component":964,"responsiveStyles":966},"builder-2df65c3f54334df2b26e7cb744886cdc",{"previousId":722},{"name":353,"options":965,"isRSC":118},{"darkMode":41},{"large":967},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":969,"component":970,"responsiveStyles":975},"builder-2c32c869efc2423ab69ef06b150e9f97",{"name":358,"tag":358,"options":971,"isRSC":118},{"darkMode":6,"maxWidth":362,"maxTextWidth":363,"title":972,"description":973,"image":974,"reverse":6},"\u003Ch2>See attacks unfold, not just their aftermath\u003C/h2>","\u003Cp>Attacks happen in the browser, not in logs. Push captures what traditional tools miss: what users clicked, what loaded, what was entered, and how attackers moved. That gives you real-world evidence, not just assumptions, when every second matters.\u003C/p>\u003Cp>\u003Cbr>\u003C/p>\u003Cp>\u003Cbr>\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F36fc719bd1de4a38b916f4d25c81a26d",{"large":976},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":978,"meta":979,"component":980,"responsiveStyles":985},"builder-370e53c6016e432db01e9193a2ce90f6",{"previousId":738},{"name":372,"options":981,"isRSC":118},{"darkMode":6,"maxWidth":362,"imageMaxWidth":374,"textPaddingTop":375,"title":982,"description":983,"reverse":41,"image":984},"\u003Ch2>Investigate faster with high-fidelity data\u003C/h2>","\u003Cp>Reconstructing an incident shouldn’t feel like guesswork. Push records detailed telemetry from inside the browser: page loads, credential inputs, DOM changes, session activity, user behavior. It’s structured, exportable, and ready to plug into your investigation workflows, so you can move fast without digging through proxy logs or relying on user reports.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fa6adda040e684e67a8d68a55c5ce5f6d",{"large":986},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"fontFamily":381,"paddingTop":383,"marginTop":383},{"@type":106,"@version":107,"id":988,"meta":989,"component":990,"responsiveStyles":995},"builder-a7f3767a8d184bd08fb24520bf210e95",{"previousId":748},{"name":372,"options":991,"isRSC":118},{"darkMode":6,"maxWidth":362,"imageMaxWidth":374,"textPaddingTop":388,"title":992,"description":993,"reverse":6,"image":994},"\u003Ch2>Contain and respond in real time\u003C/h2>","\u003Cp>When something looks off, Push doesn’t just alert you, it gives you options. Guide users with in-browser prompts. Terminate sessions. Trigger SOAR workflows. Enrich SIEM alerts. Push gives you the context and control to stop spread before it starts.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fb3dedeed5aba4847a2c2d22e10d0ec12",{"large":996},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":394},{"@type":106,"@version":107,"layerName":372,"id":998,"meta":999,"component":1000,"responsiveStyles":1005},"builder-b92036ee0ece4b32acdbdcc7c377366b",{"previousId":758},{"name":372,"options":1001,"isRSC":118},{"darkMode":6,"maxWidth":362,"imageMaxWidth":374,"textPaddingTop":399,"title":1002,"description":1003,"reverse":41,"image":1004},"\u003Ch2>Prevent the next one\u003C/h2>","\u003Cp>Push helps you respond fast, but it also helps you fix what went wrong. It surfaces misconfigurations and risky behaviors that made the attack possible in the first place, then guides users in-browser to remediate. One tool. Full loop. No loose ends.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fc1ecc2d5d3814b62b072fac01827ff96",{"large":1006},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":405},{"@type":106,"@version":107,"id":1008,"meta":1009,"component":1010,"responsiveStyles":1012},"builder-5e8ae39655274de89da32ab573a2525a",{"previousId":768},{"name":353,"options":1011,"isRSC":118},{"darkMode":6},{"large":1013},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":1015,"component":1016,"responsiveStyles":1018},"builder-dfd6850cfb4741d2b8a0c16c2780f00a",{"name":415,"tag":415,"options":1017,"isRSC":118},{"sectionHeading":37,"customClass":417},{"large":1019},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"id":1021,"@type":106,"tagName":131,"properties":1022,"responsiveStyles":1023},"builder-pixel-jlzqxmnuhxk",{"src":133,"aria-hidden":134,"alt":37,"role":135,"width":124,"height":124},{"large":1024},{"height":124,"width":124,"display":138,"opacity":124,"overflow":139,"pointerEvents":140},{"deviceSize":142,"location":1026},{"path":37,"query":1027},{},{},1770892908052,1745427419274,"https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fb07017bfd318431690a5bb35bda35b99",[],{"kind":437,"breakpoints":1034,"originalContentId":680,"winningTest":118,"lastPreviewUrl":1035,"hasLinks":6,"hasAutosaves":6},{"xsmall":57,"small":39,"medium":40},"https://pushsecurity.com/uc/incident-response?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditCode%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CeditProjects%2CmodifyMcpServers%2CmodifyWorkflowIntegrations%2CmodifyProjectSettings%2CconnectCodeRepository%2CcreateProjects%2CindexDesignSystems%2CsendPullRequests&builder.user.role.name=Developer&builder.user.role.id=developer&builder.cachebust=true&builder.preview=use-case-page&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.use-case-page=a9d5556e77f84a37b5bd52310a7110c1&builder.overrides.a9d5556e77f84a37b5bd52310a7110c1=a9d5556e77f84a37b5bd52310a7110c1&builder.overrides.use-case-page:/uc/incident-response=a9d5556e77f84a37b5bd52310a7110c1&builder.options.includeRefs=true&builder.options.enrich=true&builder.options.locale=Default",{"createdDate":1037,"id":1038,"name":1039,"modelId":260,"published":13,"query":1040,"data":1043,"variations":1148,"lastUpdated":1149,"firstPublished":1150,"testRatio":33,"screenshot":1151,"createdBy":34,"lastUpdatedBy":673,"folders":1152,"meta":1153,"rev":439},1746122471259,"5f118e24433d46ceb79f5099987156d7","Shadow SaaS",[1041],{"@type":263,"property":264,"operator":265,"value":1042},"/uc/shadow-saas",{"seoTitle":1044,"seoDescription":1045,"customFonts":1046,"fontAwesomeIcon":1051,"title":1052,"jsCode":37,"tsCode":37,"blocks":1053,"url":1042,"state":1145},"Find and secure shadow SaaS","See and control shadow SaaS in the browser.",[1047],{"kind":272,"variants":1048,"files":1049,"family":271,"version":273,"subsets":1050,"lastModified":274,"category":294,"menu":295},[300,301,302,303,304,305,128,306,307,308,309,310,311,312,313,314,315,316],{"100":276,"200":277,"300":278,"500":279,"600":280,"700":281,"800":282,"900":283,"300italic":292,"500italic":291,"regular":289,"900italic":285,"italic":288,"100italic":287,"200italic":290,"600italic":293,"700italic":286,"800italic":284},[297,298],"faShieldCheck","Secure shadow SaaS",[1054,1140],{"@type":106,"@version":107,"tagName":322,"id":1055,"meta":1056,"children":1057},"builder-04da805c4cd34652a2db452fcda52e1d",{"previousId":934},[1058,1074,1081,1088,1097,1107,1117,1127,1134],{"@type":106,"@version":107,"id":1059,"meta":1060,"component":1061,"responsiveStyles":1072},"builder-830d414faeaf41439142f9157e8288c8",{"previousId":938},{"name":326,"options":1062,"isRSC":118},{"title":1044,"description":1063,"points":1064,"video":1071},"\u003Cp>SaaS sprawl is one of today’s fastest-growing security blind spots because most tools monitor around the edges. Push sees it at the source, in the browser, revealing every app users access, flagging risky tools, and helping you shut down exposure before it leads to a breach. No guesswork. No nasty surprises. Just real-time visibility and control.\u003C/p>",[1065,1067,1069],{"item":1066},"Discover every SaaS app users access, managed or not",{"item":1068},"Spot accounts with weak security postures like missing MFA, unmanaged access, and no SSO",{"item":1070},"Control usage with in-browser prompts, blocks, and security guardrails","https://cdn.builder.io/o/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F3e4eece318d04d6586e691d59d0741cf%2Fcompressed?apiKey=f3a1111ff5be48cdbb123cd9f5795a05&token=3e4eece318d04d6586e691d59d0741cf&alt=media&optimized=true",{"large":1073},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":341},{"@type":106,"@version":107,"id":1075,"meta":1076,"component":1077,"responsiveStyles":1079},"builder-cd7833f966cb4c7e8adf0d6c979414a6",{"previousId":955},{"name":345,"options":1078,"isRSC":118},{"AllPartners":41,"backgroundTransparent":6},{"large":1080},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":349},{"@type":106,"@version":107,"id":1082,"meta":1083,"component":1084,"responsiveStyles":1086},"builder-49d720b45430454e8b08c526f267c19f",{"previousId":962},{"name":353,"options":1085,"isRSC":118},{"darkMode":41},{"large":1087},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":1089,"component":1090,"responsiveStyles":1095},"builder-3dde0bf6c8544e5e9ab41b18a9d68034",{"name":358,"tag":358,"options":1091,"isRSC":118},{"darkMode":6,"maxWidth":362,"maxTextWidth":363,"title":1092,"description":1093,"image":1094,"reverse":6},"\u003Ch2>Use your browser to curb Saas Sprawl\u003C/h2>","\u003Cp>Shadow SaaS isn’t hiding in your network, it’s in your browser. From AI tools to unsanctioned file-sharing sites, security risks live in the apps your users sign into every day. Push maps your organization's true SaaS footprint in real time, exposing apps and accounts with unmanaged access, poor authentication, or no security oversight.\u003C/p>\u003Cp>\u003Cbr>\u003C/p>\u003Cp>\u003Cbr>\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fb6811a214c7949b6bbe0b9a3bca62efd",{"large":1096},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":1098,"meta":1099,"component":1100,"responsiveStyles":1105},"builder-e2420451ccdc4f088d0a4904cff45935",{"previousId":978},{"name":372,"options":1101,"isRSC":118},{"darkMode":6,"maxWidth":362,"imageMaxWidth":374,"textPaddingTop":375,"title":1102,"description":1103,"reverse":41,"image":1104},"\u003Ch2>Discover hidden SaaS usage\u003C/h2>","\u003Cp>Push captures live browser telemetry across every tab and session. Whether a user signs into a sanctioned app with a personal account or tries a new AI plugin, you’ll see it in real time, with no integrations or manual tagging.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fe16e301f9af94665b95d98232a863d8a",{"large":1106},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"fontFamily":381,"paddingTop":383,"marginTop":383},{"@type":106,"@version":107,"id":1108,"meta":1109,"component":1110,"responsiveStyles":1115},"builder-b36de7fce7994beea9e58d94662e7166",{"previousId":988},{"name":372,"options":1111,"isRSC":118},{"darkMode":6,"maxWidth":362,"imageMaxWidth":374,"textPaddingTop":388,"title":1112,"description":1113,"reverse":6,"image":1114},"\u003Ch2>Spot risky access and unsafe usage\u003C/h2>","\u003Cp>Discovery is just the beginning. Push flags apps with risky traits, no MFA, no SSO, known vulnerabilities, or broad access scopes. You’ll know which tools introduce real risk, and which users are exposed so you can act with precision.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F6585f3c242da4d70ae3cb7d02f481bef",{"large":1116},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":394},{"@type":106,"@version":107,"layerName":372,"id":1118,"meta":1119,"component":1120,"responsiveStyles":1125},"builder-dc366b5134684fe7a508edf8913103ea",{"previousId":998},{"name":372,"options":1121,"isRSC":118},{"darkMode":6,"maxWidth":362,"imageMaxWidth":374,"textPaddingTop":399,"title":1122,"description":1123,"reverse":41,"image":1124},"\u003Ch2>Close gaps before they grow\u003C/h2>","\u003Cp>Push turns insight into action. When risky SaaS use is detected, guide users to enable MFA, block high-risk apps, or apply in-browser guardrails automatically. All without deploying new infrastructure or managing dozens of integrations.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fe6d60b6d91414819bc6258a318f00557",{"large":1126},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":405},{"@type":106,"@version":107,"id":1128,"meta":1129,"component":1130,"responsiveStyles":1132},"builder-8708f6f0d8da4b3f9e17bf16cda70219",{"previousId":1008},{"name":353,"options":1131,"isRSC":118},{"darkMode":6},{"large":1133},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":1135,"component":1136,"responsiveStyles":1138},"builder-8ff4b38d60534cf28cb523ab0f754875",{"name":415,"tag":415,"options":1137,"isRSC":118},{"sectionHeading":37,"customClass":417},{"large":1139},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"id":1141,"@type":106,"tagName":131,"properties":1142,"responsiveStyles":1143},"builder-pixel-g9x03slx23",{"src":133,"aria-hidden":134,"alt":37,"role":135,"width":124,"height":124},{"large":1144},{"height":124,"width":124,"display":138,"opacity":124,"overflow":139,"pointerEvents":140},{"deviceSize":142,"location":1146},{"path":37,"query":1147},{},{},1770892936802,1746714967208,"https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F01bfb2304521412fbd2e1a1180904d40",[],{"originalContentId":918,"winningTest":118,"lastPreviewUrl":1154,"breakpoints":1155,"kind":437,"hasLinks":6,"hasAutosaves":6},"https://pushsecurity.com/uc/shadow-saas?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditCode%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CeditProjects%2CmodifyMcpServers%2CmodifyWorkflowIntegrations%2CmodifyProjectSettings%2CconnectCodeRepository%2CcreateProjects%2CindexDesignSystems%2CsendPullRequests&builder.user.role.name=Developer&builder.user.role.id=developer&builder.cachebust=true&builder.preview=use-case-page&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.use-case-page=5f118e24433d46ceb79f5099987156d7&builder.overrides.5f118e24433d46ceb79f5099987156d7=5f118e24433d46ceb79f5099987156d7&builder.overrides.use-case-page:/uc/shadow-saas=5f118e24433d46ceb79f5099987156d7&builder.options.includeRefs=true&builder.options.enrich=true&builder.options.locale=Default",{"xsmall":57,"small":39,"medium":40},{"createdDate":1157,"id":1158,"name":1159,"modelId":260,"published":13,"query":1160,"data":1163,"variations":1267,"lastUpdated":1268,"firstPublished":1269,"testRatio":33,"screenshot":1270,"createdBy":34,"lastUpdatedBy":673,"folders":1271,"meta":1272,"rev":439},1764707470172,"b62629ce2f3741158d961cd10fe74b31","Shadow AI",[1161],{"@type":263,"property":264,"operator":265,"value":1162},"/uc/shadow-ai",{"fontAwesomeIcon":1164,"seoTitle":1165,"jsCode":37,"customFonts":1166,"title":1171,"tsCode":37,"seoDescription":1172,"blocks":1173,"url":1162,"state":1264},"faBrainCircuit","Secure AI native and AI enhanced apps. ",[1167],{"variants":1168,"category":294,"files":1169,"subsets":1170,"family":271,"kind":272,"menu":295,"lastModified":274,"version":273},[300,301,302,303,304,305,128,306,307,308,309,310,311,312,313,314,315,316],{"100":276,"200":277,"300":278,"500":279,"600":280,"700":281,"800":282,"900":283,"800italic":284,"regular":289,"700italic":286,"200italic":290,"italic":288,"500italic":291,"600italic":293,"300italic":292,"100italic":287,"900italic":285},[297,298],"Secure shadow AI","See and control shadow AI apps in the browser.",[1174,1259],{"@type":106,"@version":107,"tagName":322,"id":1175,"meta":1176,"children":1177},"builder-a6e5717a2c914d5695058e4ee201a05d",{"previousId":1055},[1178,1194,1201,1208,1218,1227,1236,1246,1253],{"@type":106,"@version":107,"id":1179,"meta":1180,"component":1181,"responsiveStyles":1192},"builder-3e0ed678683f4a0eb7aa00253cf263b2",{"previousId":1059},{"name":326,"options":1182,"isRSC":118},{"title":1171,"description":1183,"points":1184,"image":1191},"\u003Cp>Your employees are adopting AI faster than you can track it. From native features in corporate apps to unapproved shadow tools, it’s all happening in the browser. Push detects every AI interaction in real time, letting you categorize apps and enforce acceptable use policies in the browser.\u003C/p>",[1185,1187,1189],{"item":1186},"Map every AI tool used across your workforce",{"item":1188},"Review and classify apps by sensitivity, purpose, and policy status",{"item":1190},"Enforce AI usage rules directly in the browser","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F33cf153d920f4e389f3650253577cff7",{"large":1193},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":341},{"@type":106,"@version":107,"id":1195,"meta":1196,"component":1197,"responsiveStyles":1199},"builder-76968f8471d14893b8189d75b08fb426",{"previousId":1075},{"name":345,"options":1198,"isRSC":118},{"AllPartners":41,"backgroundTransparent":6},{"large":1200},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":349},{"@type":106,"@version":107,"id":1202,"meta":1203,"component":1204,"responsiveStyles":1206},"builder-b55b9d4bc5a649d8839ce7f6c2043d95",{"previousId":1082},{"name":353,"options":1205,"isRSC":118},{"darkMode":41},{"large":1207},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":1209,"meta":1210,"component":1211,"responsiveStyles":1216},"builder-c3f38ef4d75d4989a29b5903175ed8a1",{"previousId":1089},{"name":358,"tag":358,"options":1212,"isRSC":118},{"darkMode":6,"maxWidth":362,"maxTextWidth":363,"title":1213,"description":1214,"image":1215,"reverse":6},"\u003Ch2>Use your browser to govern AI \u003C/h2>","\u003Cp>The AI footprint inside your company is bigger than you think. From text generators to meeting assistants and design copilots, employees test, adopt, and connect new tools constantly. Push shows you those tools and which users are accessing them, without relying on network scans or API integrations.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F30b43bda6f1644c19478fb1efa20050c",{"large":1217},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":1219,"meta":1220,"component":1221,"responsiveStyles":1225},"builder-90ee9cb9afc44e7f885523715bf51a53",{"previousId":1098},{"name":372,"options":1222,"isRSC":118},{"darkMode":6,"maxWidth":362,"imageMaxWidth":374,"textPaddingTop":375,"title":1223,"description":1224,"reverse":41,"image":1114},"\u003Ch2>Discover every AI tool users touch\u003C/h2>","\u003Cp>Push captures live telemetry from the browser, identifying every AI-native and AI-enhanced application users access. You’ll know which corporate identities are connected, how data flows, and what new AI apps appear across your environment. \u003C/p>",{"large":1226},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"fontFamily":381,"paddingTop":383,"marginTop":383},{"@type":106,"@version":107,"id":1228,"meta":1229,"component":1230,"responsiveStyles":1234},"builder-9e44539fa53c4d8e87406036c921fc46",{"previousId":1108},{"name":372,"options":1231,"isRSC":118},{"darkMode":6,"maxWidth":362,"imageMaxWidth":374,"textPaddingTop":388,"title":1232,"description":1233,"reverse":6,"image":1124},"\u003Ch2>Classify and manage AI risk\u003C/h2>","\u003Cp>For apps you choose to allow, Push lets you apply custom in-browser banners. You can bulk-select categories of AI tools and require users to read and acknowledge your acceptable use policy before they proceed. This creates an auditable trail and moves policy from an easy to forget document to an active, in-workflow control.\u003C/p>",{"large":1235},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":394},{"@type":106,"@version":107,"layerName":372,"id":1237,"meta":1238,"component":1239,"responsiveStyles":1244},"builder-44c1a891926f4bdeaaa37e90721fe6ac",{"previousId":1118},{"name":372,"options":1240,"isRSC":118},{"darkMode":6,"maxWidth":362,"imageMaxWidth":374,"textPaddingTop":399,"title":1241,"description":1242,"reverse":41,"image":1243},"\u003Ch2>Enforce your AI policy in the browser\u003C/h2>","\u003Cp>When an AI tool is deemed non-compliant or too risky, Push blocks it at the source. The block happens directly in the browser, preventing the user from accessing the site or submitting data. This gives you an immediate, powerful lever to stop data exfiltration and enforce a hard line on unacceptable risk.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fa359ac1805af4e15a8a7f84632b9bb55",{"large":1245},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":405},{"@type":106,"@version":107,"id":1247,"meta":1248,"component":1249,"responsiveStyles":1251},"builder-dcc906f9cbe54dc68b3c672668e7a38f",{"previousId":1128},{"name":353,"options":1250,"isRSC":118},{"darkMode":6},{"large":1252},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":1254,"component":1255,"responsiveStyles":1257},"builder-d2d64780c31b4349bc75805b23a07e38",{"name":415,"tag":415,"options":1256,"isRSC":118},{"sectionHeading":37,"customClass":417},{"large":1258},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"id":1260,"@type":106,"tagName":131,"properties":1261,"responsiveStyles":1262},"builder-pixel-vyp0tpf7bf",{"src":133,"aria-hidden":134,"alt":37,"role":135,"width":124,"height":124},{"large":1263},{"height":124,"width":124,"display":138,"opacity":124,"overflow":139,"pointerEvents":140},{"deviceSize":142,"location":1265},{"path":37,"query":1266},{},{},1770892957225,1764950077593,"https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fe558b8b069884037a8e6904f7ecc029c",[],{"winningTest":118,"breakpoints":1273,"originalContentId":1038,"kind":437,"lastPreviewUrl":1274,"hasLinks":6,"hasAutosaves":41},{"xsmall":57,"small":39,"medium":40},"https://pushsecurity.com/uc/shadow-ai?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditCode%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CeditProjects%2CmodifyMcpServers%2CmodifyWorkflowIntegrations%2CmodifyProjectSettings%2CconnectCodeRepository%2CcreateProjects%2CindexDesignSystems%2CsendPullRequests&builder.user.role.name=Developer&builder.user.role.id=developer&builder.cachebust=true&builder.preview=use-case-page&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.use-case-page=b62629ce2f3741158d961cd10fe74b31&builder.overrides.b62629ce2f3741158d961cd10fe74b31=b62629ce2f3741158d961cd10fe74b31&builder.overrides.use-case-page:/uc/shadow-ai=b62629ce2f3741158d961cd10fe74b31&builder.options.includeRefs=true&builder.options.enrich=true&builder.options.locale=Default",{"_path":1276,"_dir":1277,"_draft":6,"_partial":6,"_locale":37,"sys":1278,"ogImage":118,"summary":1281,"title":1295,"subtitle":118,"metaTitle":1296,"synopsis":1297,"hashTags":118,"publishedDate":1298,"slug":1299,"tagsCollection":1300,"relatedBlogPostsCollection":1310,"authorsCollection":3343,"content":3351,"_id":4063,"_type":4064,"_source":2823,"_file":4065,"_stem":4066,"_extension":4064},"/blog/mfa-downgrade-attacks","blog",{"id":1279,"publishedAt":1280},"7dqGkFzSMA00bIJ94rW4na","2025-07-24T12:34:44.666Z",{"json":1282},{"data":1283,"content":1284,"nodeType":1294},{},[1285],{"data":1286,"content":1287,"nodeType":1293},{},[1288],{"data":1289,"marks":1290,"value":1291,"nodeType":1292},{},[],"MFA downgrade (also known as auth downgrade) is an increasingly common technique used by attackers to bypass phishing-resistant authentication methods registered to an account — simply by selecting an alternative (phishable) method. ","text","paragraph","document","MFA downgrade: How attackers are getting around phishing-resistant authentication","How attackers are getting around phishing-resistant auth","MFA downgrade attacks are an increasingly common technique used by attackers to bypass phishing-resistant authentication methods registered to an account.","2025-07-21T00:00:00.000Z","mfa-downgrade-attacks",{"items":1301},[1302,1306],{"sys":1303,"name":1305},{"id":1304},"4ksQNCFeBf8H4QIORqpRLw","Detection & response",{"sys":1307,"name":1309},{"id":1308},"6A5RXS31ZQx3PwryGb1IMy","Browser-based attacks",{"items":1311},[1312,2036,2675],{"__typename":1313,"sys":1314,"content":1316,"title":2018,"synopsis":2019,"hashTags":118,"publishedDate":2020,"slug":2021,"tagsCollection":2022,"authorsCollection":2028},"BlogPosts",{"id":1315},"3c9KMXYa1A9rOg61Kmg7j4",{"json":1317},{"nodeType":1294,"data":1318,"content":1319},{},[1320,1368,1375,1382,1415,1422,1426,1436,1456,1465,1472,1479,1486,1489,1497,1504,1524,1531,1537,1540,1548,1555,1626,1633,1636,1644,1651,1658,1776,1783,1786,1794,1827,1834,1837,1845,1852,1872,1879,1882,1890,1897,1903,1910,1916,1923,1966,1973,1980,1983,1991,1998],{"nodeType":1293,"data":1321,"content":1322},{},[1323,1327,1338,1342,1351,1355,1364],{"nodeType":1292,"value":1324,"marks":1325,"data":1326},"App-Specific Passwords (ASPs) are a way for users to access applications that do not support MFA or are otherwise incompatible with a platform’s standard login workflows. They are intended to enable a user to login to “legacy” (typically desktop) applications that do not support modern authentication (e.g. OAuth 2.0). For example, you might use this feature to allow a third-party mail client access to an email account by logging in with your ",[],{},{"nodeType":1328,"data":1329,"content":1331},"hyperlink",{"uri":1330},"https://support.microsoft.com/en-gb/account-billing/how-to-get-and-use-app-passwords-5896ed9b-4263-e681-128a-a6f2979a7944",[1332],{"nodeType":1292,"value":1333,"marks":1334,"data":1337},"Microsoft",[1335],{"type":1336},"underline",{},{"nodeType":1292,"value":1339,"marks":1340,"data":1341},", ",[],{},{"nodeType":1328,"data":1343,"content":1345},{"uri":1344},"https://support.google.com/accounts/answer/185833?hl=en",[1346],{"nodeType":1292,"value":1347,"marks":1348,"data":1350},"Google",[1349],{"type":1336},{},{"nodeType":1292,"value":1352,"marks":1353,"data":1354},", or ",[],{},{"nodeType":1328,"data":1356,"content":1358},{"uri":1357},"https://support.apple.com/en-us/102654",[1359],{"nodeType":1292,"value":1360,"marks":1361,"data":1363},"Apple",[1362],{"type":1336},{},{"nodeType":1292,"value":1365,"marks":1366,"data":1367}," account. ",[],{},{"nodeType":1293,"data":1369,"content":1370},{},[1371],{"nodeType":1292,"value":1372,"marks":1373,"data":1374},"The logic behind this is that it is comparatively more secure than giving your critical IdP password to less secure apps — likely due to the volume of accounts compromised as a result of third-party breaches. It also means that if someone phishes your primary account password that normally has a second factor, that specific password can’t be used without the second factor. ",[],{},{"nodeType":1293,"data":1376,"content":1377},{},[1378],{"nodeType":1292,"value":1379,"marks":1380,"data":1381},"However, if an ASP is acquired by an attacker, it can be used to login to the target app — circumventing phishing-resistant authentication methods such as passkeys, and bypassing MFA checks. It effectively provides a method of sidestepping your preferred login method. So for example, if you're an organization that uses a passwordless login to access your Google Workspace account and has disabled secondary login methods (the gold standard in terms of secure authentication), an ASP gives attackers a way around this. ",[],{},{"nodeType":1293,"data":1383,"content":1384},{},[1385,1389,1398,1402,1411],{"nodeType":1292,"value":1386,"marks":1387,"data":1388},"With recent evidence of exploitation in the wild in the form of ",[],{},{"nodeType":1328,"data":1390,"content":1392},{"uri":1391},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/app_specific_password_phishing/description.md",[1393],{"nodeType":1292,"value":1394,"marks":1395,"data":1397},"app-specific password phishing",[1396],{"type":1336},{},{"nodeType":1292,"value":1399,"marks":1400,"data":1401},", our latest addition to the ",[],{},{"nodeType":1328,"data":1403,"content":1405},{"uri":1404},"https://github.com/pushsecurity/saas-attacks",[1406],{"nodeType":1292,"value":1407,"marks":1408,"data":1410},"SaaS attacks matrix",[1409],{"type":1336},{},{"nodeType":1292,"value":1412,"marks":1413,"data":1414},", it’s important that security teams are aware of this technique, what the risks are, and how to defend against it.  ",[],{},{"nodeType":1293,"data":1416,"content":1417},{},[1418],{"nodeType":1292,"value":1419,"marks":1420,"data":1421},"Let’s take a quick look at how this actually works before we dive into the malicious use cases. ",[],{},{"nodeType":1423,"data":1424,"content":1425},"hr",{},[],{"nodeType":1427,"data":1428,"content":1429},"heading-1",{},[1430],{"nodeType":1292,"value":1431,"marks":1432,"data":1435},"ASPs 101",[1433],{"type":1434},"bold",{},{"nodeType":1293,"data":1437,"content":1438},{},[1439,1443,1452],{"nodeType":1292,"value":1440,"marks":1441,"data":1442},"ASPs are pretty straightforward. You log into your chosen account (e.g. Microsoft, Google, or Apple) and navigate to the ASP creation page — in Google’s case ",[],{},{"nodeType":1328,"data":1444,"content":1446},{"uri":1445},"http://myaccount.google.com/apppasswords",[1447],{"nodeType":1292,"value":1448,"marks":1449,"data":1451},"myaccount.google.com/apppasswords",[1450],{"type":1336},{},{"nodeType":1292,"value":1453,"marks":1454,"data":1455},". Then, it’s as simple as typing in a name and hitting the “create” button. ",[],{},{"nodeType":1457,"data":1458,"content":1464},"embedded-entry-block",{"target":1459},{"sys":1460},{"id":1461,"type":1462,"linkType":1463},"76qanYHiwrSyrkwlYnCuCZ","Link","Entry",[],{"nodeType":1293,"data":1466,"content":1467},{},[1468],{"nodeType":1292,"value":1469,"marks":1470,"data":1471},"This isn’t actually app-specific in the sense that it’s tied to a specific app at the point of creation, but the idea is that you’d create a unique password for each app you want to log into. ",[],{},{"nodeType":1293,"data":1473,"content":1474},{},[1475],{"nodeType":1292,"value":1476,"marks":1477,"data":1478},"From this point, you can use the password along with your email address to log into apps normally. It’s important to note that this isn’t available for every app, but is specifically intended for things like third-party email clients. By logging in with an ASP, you are also granting specific permissions to the app. So in the case of Google, you can view, send and delete emails, access contacts, and access the calendar, but you can’t add mail rules, or access other G-Suite apps like Google Drive.   ",[],{},{"nodeType":1293,"data":1480,"content":1481},{},[1482],{"nodeType":1292,"value":1483,"marks":1484,"data":1485},"It’s important to note that you can’t use this as a substitute for SSO — e.g. you can’t authenticate to a third-party app like Slack using your Google account with an ASP, so the risk is somewhat limited to basic email functionality. That said, email access gives an attacker plenty to work with, and it’s enough to move laterally to other accounts through password and MFA resets — so there’s plenty of scope to expand the blast radius with a little extra legwork.  ",[],{},{"nodeType":1423,"data":1487,"content":1488},{},[],{"nodeType":1427,"data":1490,"content":1491},{},[1492],{"nodeType":1292,"value":1493,"marks":1494,"data":1496},"How ASP phishing works",[1495],{"type":1434},{},{"nodeType":1293,"data":1498,"content":1499},{},[1500],{"nodeType":1292,"value":1501,"marks":1502,"data":1503},"While logging in with an ASP doesn’t grant an attacker full access to the account, there’s still a lot that an attacker can do with access to email, contact, and calendar information. It’s certainly enough to be used in social engineering attacks impersonating the compromised user, as well as generally monitoring email activity. ",[],{},{"nodeType":1293,"data":1505,"content":1506},{},[1507,1511,1520],{"nodeType":1292,"value":1508,"marks":1509,"data":1510},"An ",[],{},{"nodeType":1328,"data":1512,"content":1514},{"uri":1513},"https://cloud.google.com/blog/topics/threat-intelligence/creative-phishing-academics-critics-of-russia",[1515],{"nodeType":1292,"value":1516,"marks":1517,"data":1519},"example of this was recently disclosed",[1518],{"type":1336},{},{"nodeType":1292,"value":1521,"marks":1522,"data":1523}," where an expert on Russian information operations was targeted with a sophisticated and personalized social engineering attack, where the attacker was able to establish persistent access to the victim’s mailbox using ASPs by logging into a mail client. ",[],{},{"nodeType":1293,"data":1525,"content":1526},{},[1527],{"nodeType":1292,"value":1528,"marks":1529,"data":1530},"This involved a sophisticated lure impersonating the US Department of State instructing the victim on how to create and share an ASP with the attacker, granting access to their Google mailbox. ",[],{},{"nodeType":1457,"data":1532,"content":1536},{"target":1533},{"sys":1534},{"id":1535,"type":1462,"linkType":1463},"Lt93bzQNcEzg2OoCSrgED",[],{"nodeType":1423,"data":1538,"content":1539},{},[],{"nodeType":1427,"data":1541,"content":1542},{},[1543],{"nodeType":1292,"value":1544,"marks":1545,"data":1547},"Benefits and limitations of ASP phishing",[1546],{"type":1434},{},{"nodeType":1293,"data":1549,"content":1550},{},[1551],{"nodeType":1292,"value":1552,"marks":1553,"data":1554},"This approach has a few advantages over conventional credential phishing:",[],{},{"nodeType":1556,"data":1557,"content":1558},"unordered-list",{},[1559,1570,1580,1590],{"nodeType":1560,"data":1561,"content":1562},"list-item",{},[1563],{"nodeType":1293,"data":1564,"content":1565},{},[1566],{"nodeType":1292,"value":1567,"marks":1568,"data":1569},"It completely sidesteps otherwise phishing-resistant login methods such as passkeys, and by design does not require MFA. ",[],{},{"nodeType":1560,"data":1571,"content":1572},{},[1573],{"nodeType":1293,"data":1574,"content":1575},{},[1576],{"nodeType":1292,"value":1577,"marks":1578,"data":1579},"This kind of attack also naturally doesn’t trigger many typical phishing or malware-based detections. As it’s pure social engineering, there is no malicious link, page, or file to analyse. ",[],{},{"nodeType":1560,"data":1581,"content":1582},{},[1583],{"nodeType":1293,"data":1584,"content":1585},{},[1586],{"nodeType":1292,"value":1587,"marks":1588,"data":1589},"For less technically aware victims, this might present a more effective alternative to traditional credential phishing — awareness training won’t extend to this kind of use case. ",[],{},{"nodeType":1560,"data":1591,"content":1592},{},[1593],{"nodeType":1293,"data":1594,"content":1595},{},[1596,1600,1609,1613,1622],{"nodeType":1292,"value":1597,"marks":1598,"data":1599},"While generic security alert emails are generated when an app password is created, visibility of actual login events is limited. For example, ",[],{},{"nodeType":1328,"data":1601,"content":1603},{"uri":1602},"https://issuetracker.google.com/issues/298128558",[1604],{"nodeType":1292,"value":1605,"marks":1606,"data":1608},"Google provides no logs for ASP creation and usage",[1607],{"type":1336},{},{"nodeType":1292,"value":1610,"marks":1611,"data":1612},", while ",[],{},{"nodeType":1328,"data":1614,"content":1616},{"uri":1615},"https://learn.microsoft.com/en-us/entra/identity/authentication/howto-mfa-app-passwords",[1617],{"nodeType":1292,"value":1618,"marks":1619,"data":1621},"Microsoft provides no on-premises logging or auditing capability",[1620],{"type":1336},{},{"nodeType":1292,"value":1623,"marks":1624,"data":1625},".  ",[],{},{"nodeType":1293,"data":1627,"content":1628},{},[1629],{"nodeType":1292,"value":1630,"marks":1631,"data":1632},"However, there are also limitations that will probably see this technique remain a niche choice for attackers. Namely, the complexity of the attack doesn’t necessarily map to the payoff, where it doesn’t result in full account compromise and the permissions/scopes of an ASP login are limited. This means that it lends itself to multi-step attacks, most likely as part of more targeted and stealthy attacks against specific individuals (as seen in the example above). For this reason, attackers are likely to prioritize other methods when they are available. ",[],{},{"nodeType":1423,"data":1634,"content":1635},{},[],{"nodeType":1427,"data":1637,"content":1638},{},[1639],{"nodeType":1292,"value":1640,"marks":1641,"data":1643},"Comparing ASPs with other auth bypasses",[1642],{"type":1434},{},{"nodeType":1293,"data":1645,"content":1646},{},[1647],{"nodeType":1292,"value":1648,"marks":1649,"data":1650},"ASP phishing is part of a growing trend of phishing techniques focused on bypassing conventional authentication. With more organizations investing in phishing-resistant authentication methods like passkeys/WebAuthn and using SSO as standard, attackers are increasingly looking to circumvent the standard login process entirely. ",[],{},{"nodeType":1293,"data":1652,"content":1653},{},[1654],{"nodeType":1292,"value":1655,"marks":1656,"data":1657},"Similar phishing approaches designed to circumvent an account’s authentication controls include:",[],{},{"nodeType":1556,"data":1659,"content":1660},{},[1661,1684,1719,1741],{"nodeType":1560,"data":1662,"content":1663},{},[1664],{"nodeType":1293,"data":1665,"content":1666},{},[1667,1671,1680],{"nodeType":1292,"value":1668,"marks":1669,"data":1670},"Phishing for ",[],{},{"nodeType":1328,"data":1672,"content":1674},{"uri":1673},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/api_keys/description.md",[1675],{"nodeType":1292,"value":1676,"marks":1677,"data":1679},"API keys",[1678],{"type":1336},{},{"nodeType":1292,"value":1681,"marks":1682,"data":1683},", which has the advantage of granting full access to the account, and persisting even if the account password is changed (in contrast, Google resets all ASPs if the account password is changed). ",[],{},{"nodeType":1560,"data":1685,"content":1686},{},[1687],{"nodeType":1293,"data":1688,"content":1689},{},[1690,1693,1702,1706,1715],{"nodeType":1292,"value":37,"marks":1691,"data":1692},[],{},{"nodeType":1328,"data":1694,"content":1696},{"uri":1695},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/consent_phishing/description.md",[1697],{"nodeType":1292,"value":1698,"marks":1699,"data":1701},"Consent phishing",[1700],{"type":1336},{},{"nodeType":1292,"value":1703,"marks":1704,"data":1705},", which sees the victim accept OAuth scopes for an attacker-controlled app integration granting access to the account without needing to directly compromise it. (",[],{},{"nodeType":1328,"data":1707,"content":1709},{"uri":1708},"https://pushsecurity.com/blog/how-consent-phishing-is-evolving/",[1710],{"nodeType":1292,"value":1711,"marks":1712,"data":1714},"You can read more about recent examples here",[1713],{"type":1336},{},{"nodeType":1292,"value":1716,"marks":1717,"data":1718},".) ",[],{},{"nodeType":1560,"data":1720,"content":1721},{},[1722],{"nodeType":1293,"data":1723,"content":1724},{},[1725,1728,1737],{"nodeType":1292,"value":37,"marks":1726,"data":1727},[],{},{"nodeType":1328,"data":1729,"content":1731},{"uri":1730},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/device_code_phishing/description.md",[1732],{"nodeType":1292,"value":1733,"marks":1734,"data":1736},"Device code phishing",[1735],{"type":1336},{},{"nodeType":1292,"value":1738,"marks":1739,"data":1740},", functionally very similar to consent phishing but involving the victim entering a code for authorization. ",[],{},{"nodeType":1560,"data":1742,"content":1743},{},[1744],{"nodeType":1293,"data":1745,"content":1746},{},[1747,1750,1759,1763,1772],{"nodeType":1292,"value":37,"marks":1748,"data":1749},[],{},{"nodeType":1328,"data":1751,"content":1753},{"uri":1752},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/cross-idp_impersonation/description.md",[1754],{"nodeType":1292,"value":1755,"marks":1756,"data":1758},"Cross-IdP impersonation",[1757],{"type":1336},{},{"nodeType":1292,"value":1760,"marks":1761,"data":1762},", which sees the attacker register a new IdP connected to the victim’s email account that can be used to access connected apps via SSO without directly compromising the primary IdP. (",[],{},{"nodeType":1328,"data":1764,"content":1766},{"uri":1765},"https://pushsecurity.com/blog/a-new-class-of-phishing-verification-phishing-and-cross-idp-impersonation/",[1767],{"nodeType":1292,"value":1768,"marks":1769,"data":1771},"You can read more about this here",[1770],{"type":1336},{},{"nodeType":1292,"value":1773,"marks":1774,"data":1775},".)",[],{},{"nodeType":1293,"data":1777,"content":1778},{},[1779],{"nodeType":1292,"value":1780,"marks":1781,"data":1782},"Clearly, ASP phishing is part of a much bigger trend in which attackers are moving away from conventional phishing tactics in order to sidestep the authentication process. ",[],{},{"nodeType":1423,"data":1784,"content":1785},{},[],{"nodeType":1427,"data":1787,"content":1788},{},[1789],{"nodeType":1292,"value":1790,"marks":1791,"data":1793},"Conclusion",[1792],{"type":1434},{},{"nodeType":1293,"data":1795,"content":1796},{},[1797,1801,1810,1814,1823],{"nodeType":1292,"value":1798,"marks":1799,"data":1800},"There is a common misconception that adopting SSO-based logins, with a locked-down IdP account is an identity security silver bullet. The reality is that identity, authentication, and authorization is a complex and little-understood space. Even with SSO, there are ",[],{},{"nodeType":1328,"data":1802,"content":1804},{"uri":1803},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/ghost_logins/description.md",[1805],{"nodeType":1292,"value":1806,"marks":1807,"data":1809},"ghost logins",[1808],{"type":1336},{},{"nodeType":1292,"value":1811,"marks":1812,"data":1813},", backup login and MFA methods susceptible to ",[],{},{"nodeType":1328,"data":1815,"content":1817},{"uri":1816},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/mfa_downgrade/description.md",[1818],{"nodeType":1292,"value":1819,"marks":1820,"data":1822},"downgrade attacks",[1821],{"type":1336},{},{"nodeType":1292,"value":1824,"marks":1825,"data":1826},", and as we’ve seen with ASP phishing and similar techniques, many, many more ways to compromise an identity. ",[],{},{"nodeType":1293,"data":1828,"content":1829},{},[1830],{"nodeType":1292,"value":1831,"marks":1832,"data":1833},"Security teams need to approach the complexity of identity security with their eyes open to reality. Without a full picture of how your various workforce identities can be accessed by your users, exploitable gaps will inevitably be left for attackers to take advantage of. ",[],{},{"nodeType":1423,"data":1835,"content":1836},{},[],{"nodeType":1427,"data":1838,"content":1839},{},[1840],{"nodeType":1292,"value":1841,"marks":1842,"data":1844},"Recommendations",[1843],{"type":1434},{},{"nodeType":1293,"data":1846,"content":1847},{},[1848],{"nodeType":1292,"value":1849,"marks":1850,"data":1851},"Given the logging challenges relating to ASP creation and use, the best option is to prevent ASPs from being created in the first place. ",[],{},{"nodeType":1293,"data":1853,"content":1854},{},[1855,1859,1868],{"nodeType":1292,"value":1856,"marks":1857,"data":1858},"By default, users can't create app passwords in Microsoft. The app passwords feature must be enabled before users can use them. To check if this option is turned on, ",[],{},{"nodeType":1328,"data":1860,"content":1862},{"uri":1861},"https://learn.microsoft.com/en-gb/entra/identity/authentication/howto-mfa-app-passwords",[1863],{"nodeType":1292,"value":1864,"marks":1865,"data":1867},"you can see and toggle the setting in Entra",[1866],{"type":1336},{},{"nodeType":1292,"value":1869,"marks":1870,"data":1871}," by browsing to Conditional Access > Named locations > Configure MFA trusted IPs > Multifactor authentication page > Allow users to create app passwords to sign in to non-browser apps option.",[],{},{"nodeType":1293,"data":1873,"content":1874},{},[1875],{"nodeType":1292,"value":1876,"marks":1877,"data":1878},"Apple and Google ASPs can’t be disabled in the same way… but don’t worry. That’s where Push comes in. ",[],{},{"nodeType":1423,"data":1880,"content":1881},{},[],{"nodeType":1427,"data":1883,"content":1884},{},[1885],{"nodeType":1292,"value":1886,"marks":1887,"data":1889},"How Push can help",[1888],{"type":1434},{},{"nodeType":1293,"data":1891,"content":1892},{},[1893],{"nodeType":1292,"value":1894,"marks":1895,"data":1896},"We’re working on adding visibility for ASPs being created, but users of our browser-based security platform can use existing features to prevent ASP phishing. Realistically, there’s no good reason for the average user to be configuring ASPs. So, you can use our URL blocking feature to prevent employees from accessing the pages for ASP creation on relevant apps. ",[],{},{"nodeType":1457,"data":1898,"content":1902},{"target":1899},{"sys":1900},{"id":1901,"type":1462,"linkType":1463},"5i0Ou5a27XOt7gxJo9cu0P",[],{"nodeType":1293,"data":1904,"content":1905},{},[1906],{"nodeType":1292,"value":1907,"marks":1908,"data":1909},"When a user tries to access the page, they’ll see this message instead and a security alert will be generated. ",[],{},{"nodeType":1457,"data":1911,"content":1915},{"target":1912},{"sys":1913},{"id":1914,"type":1462,"linkType":1463},"7nsimiWtv5XOuKkE9wL3A3",[],{"nodeType":1293,"data":1917,"content":1918},{},[1919],{"nodeType":1292,"value":1920,"marks":1921,"data":1922},"It is recommended that you block the following URLs for Google and Apple:",[],{},{"nodeType":1556,"data":1924,"content":1925},{},[1926,1945],{"nodeType":1560,"data":1927,"content":1928},{},[1929],{"nodeType":1293,"data":1930,"content":1931},{},[1932,1935,1942],{"nodeType":1292,"value":37,"marks":1933,"data":1934},[],{},{"nodeType":1328,"data":1936,"content":1937},{"uri":1445},[1938],{"nodeType":1292,"value":1448,"marks":1939,"data":1941},[1940],{"type":1336},{},{"nodeType":1292,"value":37,"marks":1943,"data":1944},[],{},{"nodeType":1560,"data":1946,"content":1947},{},[1948],{"nodeType":1293,"data":1949,"content":1950},{},[1951,1954,1963],{"nodeType":1292,"value":37,"marks":1952,"data":1953},[],{},{"nodeType":1328,"data":1955,"content":1957},{"uri":1956},"http://appleid.apple.com/account/manage/security/secondary-password",[1958],{"nodeType":1292,"value":1959,"marks":1960,"data":1962},"appleid.apple.com/account/manage/security/secondary-password",[1961],{"type":1336},{},{"nodeType":1292,"value":37,"marks":1964,"data":1965},[],{},{"nodeType":1293,"data":1967,"content":1968},{},[1969],{"nodeType":1292,"value":1970,"marks":1971,"data":1972},"Unfortunately, there is no specific link to the Microsoft creation page — but as established above, this should not be enabled by default in Microsoft. ",[],{},{"nodeType":1293,"data":1974,"content":1975},{},[1976],{"nodeType":1292,"value":1977,"marks":1978,"data":1979},"If you encounter any more apps which allow ASPs, you can similarly add the specific ASP creation page to the list of blocked URLs.",[],{},{"nodeType":1423,"data":1981,"content":1982},{},[],{"nodeType":1427,"data":1984,"content":1985},{},[1986],{"nodeType":1292,"value":1987,"marks":1988,"data":1990},"Want to learn more about Push?",[1989],{"type":1434},{},{"nodeType":1293,"data":1992,"content":1993},{},[1994],{"nodeType":1292,"value":1995,"marks":1996,"data":1997},"And that’s not all — Push provides comprehensive identity attack detection and response capabilities against techniques like AiTM phishing, credential stuffing, password spraying and session hijacking using stolen session tokens. You can also use Push to find and fix identity vulnerabilities across every app that your employees use, like: ghost logins; SSO coverage gaps; MFA gaps; weak, breached and reused passwords; risky OAuth integrations; and more. ",[],{},{"nodeType":1293,"data":1999,"content":2000},{},[2001,2005,2014],{"nodeType":1292,"value":2002,"marks":2003,"data":2004},"If you want to learn more about how Push helps you to detect and defeat common identity attack techniques, ",[],{},{"nodeType":1328,"data":2006,"content":2008},{"uri":2007},"https://pushsecurity.com/",[2009],{"nodeType":1292,"value":2010,"marks":2011,"data":2013},"book some time with one of our team for a live demo",[2012],{"type":1336},{},{"nodeType":1292,"value":2015,"marks":2016,"data":2017},".",[],{},"App-Specific Password phishing: another novel way to get around passkeys and MFA","How App-Specific Password phishing is being used in the wild to bypass phishing-resistant authentication controls like passkeys. ","2025-06-26T00:00:00.000Z","app-specific-password-phishing",{"items":2023},[2024,2026],{"sys":2025,"name":1309},{"id":1308},{"sys":2027,"name":1305},{"id":1304},{"items":2029},[2030],{"fullName":2031,"firstName":2032,"jobTitle":2033,"profilePicture":2034},"Dan Green","Dan","Threat Research",{"url":2035},"https://images.ctfassets.net/y1cdw1ablpvd/7jik1VhFgA3kgzXBXTm2Vw/fcd8c171da644903d0827eafcfbcaad0/Dan_Headshot_2025.png",{"__typename":1313,"sys":2037,"content":2039,"title":2658,"synopsis":2659,"hashTags":118,"publishedDate":2020,"slug":2660,"tagsCollection":2661,"authorsCollection":2667},{"id":2038},"XQHcBu5kiSBd6MMwICYI4",{"json":2040},{"nodeType":1294,"data":2041,"content":2042},{},[2043,2050,2057,2065,2094,2101,2107,2110,2118,2125,2132,2175,2182,2189,2192,2200,2207,2214,2221,2241,2248,2254,2262,2269,2276,2283,2289,2292,2300,2309,2316,2324,2331,2396,2403,2411,2418,2451,2459,2466,2474,2481,2489,2496,2549,2556,2559,2567,2574,2591,2624,2646,2652],{"nodeType":1293,"data":2044,"content":2045},{},[2046],{"nodeType":1292,"value":2047,"marks":2048,"data":2049},"Phishing has undergone a radical transformation. The laughably bad emails and fake PayPal logins of the past have given way to sophisticated campaigns engineered to slip through even the most hardened security stacks. ",[],{},{"nodeType":1293,"data":2051,"content":2052},{},[2053],{"nodeType":1292,"value":2054,"marks":2055,"data":2056},"Today’s phishing attacks are faster, more adaptable, and harder to catch with traditional tools. Email filters and threat intel still play an important role, but they’re often reacting to threats that are already in motion, and by the time a phishing link is flagged and blocklisted, someone has probably already clicked — and the attacker has moved onto their next set of links.",[],{},{"nodeType":1293,"data":2058,"content":2059},{},[2060],{"nodeType":1292,"value":2061,"marks":2062,"data":2064},"The problem isn’t that phishing has evolved. It’s that our defenses haven’t.",[2063],{"type":1434},{},{"nodeType":1293,"data":2066,"content":2067},{},[2068,2072,2081,2085,2090],{"nodeType":1292,"value":2069,"marks":2070,"data":2071},"That’s where ",[],{},{"nodeType":1328,"data":2073,"content":2075},{"uri":2074},"https://pushsecurity.com/uc/zero-day-phishing-protection",[2076],{"nodeType":1292,"value":2077,"marks":2078,"data":2080},"Push Security",[2079],{"type":1336},{},{"nodeType":1292,"value":2082,"marks":2083,"data":2084}," comes in. By embedding real-time detection directly into the browser, the very place where phishing attacks unfold, Push offers a fundamentally new way to stop phishing: ",[],{},{"nodeType":1292,"value":2086,"marks":2087,"data":2089},"as it happens",[2088],{"type":311},{},{"nodeType":1292,"value":2091,"marks":2092,"data":2093},", regardless of whether or not the exact attack has ever been seen before. ",[],{},{"nodeType":1293,"data":2095,"content":2096},{},[2097],{"nodeType":1292,"value":2098,"marks":2099,"data":2100},"Check out the video to see how it works. ",[],{},{"nodeType":1457,"data":2102,"content":2106},{"target":2103},{"sys":2104},{"id":2105,"type":1462,"linkType":1463},"4LaKobadjp19jjocLXcW4E",[],{"nodeType":1423,"data":2108,"content":2109},{},[],{"nodeType":1427,"data":2111,"content":2112},{},[2113],{"nodeType":1292,"value":2114,"marks":2115,"data":2117},"The modern phishing playground",[2116],{"type":1434},{},{"nodeType":1293,"data":2119,"content":2120},{},[2121],{"nodeType":1292,"value":2122,"marks":2123,"data":2124},"Phishing attacks today look nothing like the blunt instruments of a few years ago. These are fast, customized, and often completely ephemeral. A phishing domain might go live at 9 a.m., compromise scores of credentials, and be gone before lunch, long before it ever hits a threat intel feed.",[],{},{"nodeType":1293,"data":2126,"content":2127},{},[2128],{"nodeType":1292,"value":2129,"marks":2130,"data":2131},"Modern attackers use:",[],{},{"nodeType":1556,"data":2133,"content":2134},{},[2135,2145,2155,2165],{"nodeType":1560,"data":2136,"content":2137},{},[2138],{"nodeType":1293,"data":2139,"content":2140},{},[2141],{"nodeType":1292,"value":2142,"marks":2143,"data":2144},"Dynamic content and user-adaptive emails that can be easily changed based on the target’s identity and environment.",[],{},{"nodeType":1560,"data":2146,"content":2147},{},[2148],{"nodeType":1293,"data":2149,"content":2150},{},[2151],{"nodeType":1292,"value":2152,"marks":2153,"data":2154},"Obfuscated URLs hidden behind trusted services (like Google Sites), making reputation analysis less than reliable.",[],{},{"nodeType":1560,"data":2156,"content":2157},{},[2158],{"nodeType":1293,"data":2159,"content":2160},{},[2161],{"nodeType":1292,"value":2162,"marks":2163,"data":2164},"Real-time proxying tools to clone login flows and harvest credentials.",[],{},{"nodeType":1560,"data":2166,"content":2167},{},[2168],{"nodeType":1293,"data":2169,"content":2170},{},[2171],{"nodeType":1292,"value":2172,"marks":2173,"data":2174},"Rapid-fire infrastructure rotation, making the attack’s infrastructure almost impossible to track in time.",[],{},{"nodeType":1293,"data":2176,"content":2177},{},[2178],{"nodeType":1292,"value":2179,"marks":2180,"data":2181},"These attacks often bypass traditional defenses entirely, not because the tools are broken, but because they were designed for a different era, one where phishing pages lived for days or weeks, not minutes.",[],{},{"nodeType":1293,"data":2183,"content":2184},{},[2185],{"nodeType":1292,"value":2186,"marks":2187,"data":2188},"It’s not enough to know what was bad yesterday. You need to know what’s happening now.",[],{},{"nodeType":1423,"data":2190,"content":2191},{},[],{"nodeType":1427,"data":2193,"content":2194},{},[2195],{"nodeType":1292,"value":2196,"marks":2197,"data":2199},"Why blocklists and perimeter defenses are falling behind",[2198],{"type":1434},{},{"nodeType":1293,"data":2201,"content":2202},{},[2203],{"nodeType":1292,"value":2204,"marks":2205,"data":2206},"The security ecosystem has long depended on reputation-based systems: block the known bad, allow the rest. That worked when attackers reused infrastructure and relied on mass campaigns. Today’s adversaries have adapted.",[],{},{"nodeType":1293,"data":2208,"content":2209},{},[2210],{"nodeType":1292,"value":2211,"marks":2212,"data":2213},"Consider a scenario similar to the one from our video:",[],{},{"nodeType":1293,"data":2215,"content":2216},{},[2217],{"nodeType":1292,"value":2218,"marks":2219,"data":2220},"A staff member receives an email appearing to be from Microsoft Teams. It includes dynamic content that mirrors their actual environment, including their username, company logo, and real collaboration data. The embedded link takes them to a cloned Microsoft login page hosted on a benign-looking subdomain. The site is brand new. It’s not on any blocklist. Your email filter passes it. The employee logs in. Credentials and session tokens? Gone.",[],{},{"nodeType":1293,"data":2222,"content":2223},{},[2224,2228,2237],{"nodeType":1292,"value":2225,"marks":2226,"data":2227},"And that’s just step one. The attacker now pivots to connected apps like ",[],{},{"nodeType":1328,"data":2229,"content":2231},{"uri":2230},"https://pushsecurity.com/blog/why-attackers-are-targeting-jira-with-stolen-credentials/",[2232],{"nodeType":1292,"value":2233,"marks":2234,"data":2236},"Jira",[2235],{"type":1336},{},{"nodeType":1292,"value":2238,"marks":2239,"data":2240},", Confluence, or AWS, moving laterally through your cloud environment using the compromised credentials.",[],{},{"nodeType":1293,"data":2242,"content":2243},{},[2244],{"nodeType":1292,"value":2245,"marks":2246,"data":2247},"Traditional tools often miss these threats not due to a lack of sophistication, but because they’re looking from the outside in. The browser is where the attack actually unfolds. Without visibility there, key indicators of compromise go undetected.",[],{},{"nodeType":1457,"data":2249,"content":2253},{"target":2250},{"sys":2251},{"id":2252,"type":1462,"linkType":1463},"1UGu43QxCiYofkeGtOMp5J",[],{"nodeType":1427,"data":2255,"content":2256},{},[2257],{"nodeType":1292,"value":2258,"marks":2259,"data":2261},"Rethinking where phishing defense happens",[2260],{"type":1434},{},{"nodeType":1293,"data":2263,"content":2264},{},[2265],{"nodeType":1292,"value":2266,"marks":2267,"data":2268},"Push changes where phishing protection happens, from upstream detection to point-of-interaction control. Instead of chasing malicious links through email gateways or external threat feeds, Push embeds lightweight, always-on protection directly, as users go about their work in the browser.",[],{},{"nodeType":1293,"data":2270,"content":2271},{},[2272],{"nodeType":1292,"value":2273,"marks":2274,"data":2275},"Push monitors what’s happening in each session: how pages are built, how they behave, and how users interact with them. That means it can recognize when a login prompt doesn’t match your identity provider or when a script behaves like part of a phishing toolkit.",[],{},{"nodeType":1293,"data":2277,"content":2278},{},[2279],{"nodeType":1292,"value":2280,"marks":2281,"data":2282},"When Push identifies something suspicious, it takes action right away. Logins are interrupted before any data is exposed. Users get clear guidance in-browser. And security teams receive detailed telemetry that shows exactly what happened, who was targeted, and how the threat was stopped.",[],{},{"nodeType":1457,"data":2284,"content":2288},{"target":2285},{"sys":2286},{"id":2287,"type":1462,"linkType":1463},"7Hu3kypFWwJAGOuQp0kYmU",[],{"nodeType":1423,"data":2290,"content":2291},{},[],{"nodeType":1427,"data":2293,"content":2294},{},[2295],{"nodeType":1292,"value":2296,"marks":2297,"data":2299},"The benefits of browser-native phishing defense",[2298],{"type":1434},{},{"nodeType":2301,"data":2302,"content":2303},"heading-2",{},[2304],{"nodeType":1292,"value":2305,"marks":2306,"data":2308},"True zero-day protection",[2307],{"type":1434},{},{"nodeType":1293,"data":2310,"content":2311},{},[2312],{"nodeType":1292,"value":2313,"marks":2314,"data":2315},"Push doesn’t rely on known indicators of compromise. It evaluates the actual behavior and context of every session in real-time. Whether the phishing site was created 5 months ago or 5 minutes ago is irrelevant — Push detects it and shuts it down.",[],{},{"nodeType":2301,"data":2317,"content":2318},{},[2319],{"nodeType":1292,"value":2320,"marks":2321,"data":2323},"Contextual threat detection",[2322],{"type":1434},{},{"nodeType":1293,"data":2325,"content":2326},{},[2327],{"nodeType":1292,"value":2328,"marks":2329,"data":2330},"Because Push operates in the browser, it sees everything:",[],{},{"nodeType":1556,"data":2332,"content":2333},{},[2334,2344,2354,2376,2386],{"nodeType":1560,"data":2335,"content":2336},{},[2337],{"nodeType":1293,"data":2338,"content":2339},{},[2340],{"nodeType":1292,"value":2341,"marks":2342,"data":2343},"The page layout",[],{},{"nodeType":1560,"data":2345,"content":2346},{},[2347],{"nodeType":1293,"data":2348,"content":2349},{},[2350],{"nodeType":1292,"value":2351,"marks":2352,"data":2353},"Where the user came from",[],{},{"nodeType":1560,"data":2355,"content":2356},{},[2357],{"nodeType":1293,"data":2358,"content":2359},{},[2360,2364,2373],{"nodeType":1292,"value":2361,"marks":2362,"data":2363},"The password they enter ",[],{},{"nodeType":1328,"data":2365,"content":2367},{"uri":2366},"https://pushsecurity.com/help/10043/#how-push-securely-analyzes-passwords",[2368],{"nodeType":1292,"value":2369,"marks":2370,"data":2372},"(as a salted, abbreviated hash)",[2371],{"type":1336},{},{"nodeType":1292,"value":37,"marks":2374,"data":2375},[],{},{"nodeType":1560,"data":2377,"content":2378},{},[2379],{"nodeType":1293,"data":2380,"content":2381},{},[2382],{"nodeType":1292,"value":2383,"marks":2384,"data":2385},"What scripts are running",[],{},{"nodeType":1560,"data":2387,"content":2388},{},[2389],{"nodeType":1293,"data":2390,"content":2391},{},[2392],{"nodeType":1292,"value":2393,"marks":2394,"data":2395},"And where credentials are being sent",[],{},{"nodeType":1293,"data":2397,"content":2398},{},[2399],{"nodeType":1292,"value":2400,"marks":2401,"data":2402},"This context enables Push to stop even well-camouflaged phishing attempts, including AitM attacks that bypass MFA.",[],{},{"nodeType":2301,"data":2404,"content":2405},{},[2406],{"nodeType":1292,"value":2407,"marks":2408,"data":2410},"Real-time interception of malicious activity",[2409],{"type":1434},{},{"nodeType":1293,"data":2412,"content":2413},{},[2414],{"nodeType":1292,"value":2415,"marks":2416,"data":2417},"As soon as a phishing attempt is confirmed, the response is immediate:",[],{},{"nodeType":1556,"data":2419,"content":2420},{},[2421,2431,2441],{"nodeType":1560,"data":2422,"content":2423},{},[2424],{"nodeType":1293,"data":2425,"content":2426},{},[2427],{"nodeType":1292,"value":2428,"marks":2429,"data":2430},"Credential entry is halted.",[],{},{"nodeType":1560,"data":2432,"content":2433},{},[2434],{"nodeType":1293,"data":2435,"content":2436},{},[2437],{"nodeType":1292,"value":2438,"marks":2439,"data":2440},"Sessions are revoked.",[],{},{"nodeType":1560,"data":2442,"content":2443},{},[2444],{"nodeType":1293,"data":2445,"content":2446},{},[2447],{"nodeType":1292,"value":2448,"marks":2449,"data":2450},"The user is protected without delay.",[],{},{"nodeType":2301,"data":2452,"content":2453},{},[2454],{"nodeType":1292,"value":2455,"marks":2456,"data":2458},"Reduced incident response overhead",[2457],{"type":1434},{},{"nodeType":1293,"data":2460,"content":2461},{},[2462],{"nodeType":1292,"value":2463,"marks":2464,"data":2465},"Most phishing attacks end in hours of IR and expensive cleanup. With Push, attacks don’t escalate beyond the initial click. That means fewer compromised accounts, fewer escalations, and less fatigue on your security team.",[],{},{"nodeType":2301,"data":2467,"content":2468},{},[2469],{"nodeType":1292,"value":2470,"marks":2471,"data":2473},"Empowered, educated users",[2472],{"type":1434},{},{"nodeType":1293,"data":2475,"content":2476},{},[2477],{"nodeType":1292,"value":2478,"marks":2479,"data":2480},"Push doesn’t just block phishing; it helps users learn from it. When someone interacts with a suspicious page, they get clear, actionable feedback right in the browser. Over time, these in-the-moment cues help build stronger phishing awareness across your workforce. Employee-facing messages are fully customizable to match the tone and style of your organization.",[],{},{"nodeType":2301,"data":2482,"content":2483},{},[2484],{"nodeType":1292,"value":2485,"marks":2486,"data":2488},"A new paradigm for identity security",[2487],{"type":1434},{},{"nodeType":1293,"data":2490,"content":2491},{},[2492],{"nodeType":1292,"value":2493,"marks":2494,"data":2495},"While phishing detection is core, Push also helps you defend your entire browser-based identity attack surface. That means protecting against other common forms of account compromise, like:",[],{},{"nodeType":1556,"data":2497,"content":2498},{},[2499,2509,2519,2529,2539],{"nodeType":1560,"data":2500,"content":2501},{},[2502],{"nodeType":1293,"data":2503,"content":2504},{},[2505],{"nodeType":1292,"value":2506,"marks":2507,"data":2508},"Employees using breached or reused passwords",[],{},{"nodeType":1560,"data":2510,"content":2511},{},[2512],{"nodeType":1293,"data":2513,"content":2514},{},[2515],{"nodeType":1292,"value":2516,"marks":2517,"data":2518},"Missing or misconfigured MFA",[],{},{"nodeType":1560,"data":2520,"content":2521},{},[2522],{"nodeType":1293,"data":2523,"content":2524},{},[2525],{"nodeType":1292,"value":2526,"marks":2527,"data":2528},"Ghost logins that bypass your identity provider",[],{},{"nodeType":1560,"data":2530,"content":2531},{},[2532],{"nodeType":1293,"data":2533,"content":2534},{},[2535],{"nodeType":1292,"value":2536,"marks":2537,"data":2538},"Token-based session hijacking",[],{},{"nodeType":1560,"data":2540,"content":2541},{},[2542],{"nodeType":1293,"data":2543,"content":2544},{},[2545],{"nodeType":1292,"value":2546,"marks":2547,"data":2548},"Shadow SaaS usage",[],{},{"nodeType":1293,"data":2550,"content":2551},{},[2552],{"nodeType":1292,"value":2553,"marks":2554,"data":2555},"Because Push runs directly in the browser, it gives you visibility across every app your employees access, whether it’s officially managed or not. And it doesn’t just alert, it actively helps you fix the issues, guiding users to take action when risks are found.",[],{},{"nodeType":1423,"data":2557,"content":2558},{},[],{"nodeType":1427,"data":2560,"content":2561},{},[2562],{"nodeType":1292,"value":2563,"marks":2564,"data":2566},"Modern phishing requires a modern defense",[2565],{"type":1434},{},{"nodeType":1293,"data":2568,"content":2569},{},[2570],{"nodeType":1292,"value":2571,"marks":2572,"data":2573},"Phishing is no longer an email problem. It’s not even just a domain reputation problem. It’s an identity attack problem, and the only place you can see those attacks in action is inside the browser.",[],{},{"nodeType":1293,"data":2575,"content":2576},{},[2577,2581,2588],{"nodeType":1292,"value":2578,"marks":2579,"data":2580},"Push Security gives you a new advantage: proactive, in-browser protection against modern phishing campaigns — ",[],{},{"nodeType":1328,"data":2582,"content":2583},{"uri":2074},[2584],{"nodeType":1292,"value":2585,"marks":2586,"data":2587},"even those with never-before-seen phishing sites",[],{},{"nodeType":1292,"value":2015,"marks":2589,"data":2590},[],{},{"nodeType":1556,"data":2592,"content":2593},{},[2594,2604,2614],{"nodeType":1560,"data":2595,"content":2596},{},[2597],{"nodeType":1293,"data":2598,"content":2599},{},[2600],{"nodeType":1292,"value":2601,"marks":2602,"data":2603},"See the phish happen.",[],{},{"nodeType":1560,"data":2605,"content":2606},{},[2607],{"nodeType":1293,"data":2608,"content":2609},{},[2610],{"nodeType":1292,"value":2611,"marks":2612,"data":2613},"Stop it in real time.",[],{},{"nodeType":1560,"data":2615,"content":2616},{},[2617],{"nodeType":1293,"data":2618,"content":2619},{},[2620],{"nodeType":1292,"value":2621,"marks":2622,"data":2623},"Keep your workforce identities safe.",[],{},{"nodeType":1293,"data":2625,"content":2626},{},[2627,2632,2641],{"nodeType":1292,"value":2628,"marks":2629,"data":2631},"Want to see Push in action? ",[2630],{"type":1434},{},{"nodeType":1328,"data":2633,"content":2635},{"uri":2634},"https://pushsecurity.com/demo/",[2636],{"nodeType":1292,"value":2637,"marks":2638,"data":2640},"Book a demo",[2639],{"type":1434},{},{"nodeType":1292,"value":2642,"marks":2643,"data":2645}," and watch a real-time phishing attack get stopped mid-flow.",[2644],{"type":1434},{},{"nodeType":1457,"data":2647,"content":2651},{"target":2648},{"sys":2649},{"id":2650,"type":1462,"linkType":1463},"7eSsPjEj178j3ViloaChbQ",[],{"nodeType":1293,"data":2653,"content":2654},{},[2655],{"nodeType":1292,"value":37,"marks":2656,"data":2657},[],{},"How browser-level controls change the fight against phishing","Attackers are routinely defeating conventional email, network, and endpoint-based security controls. Here's how browser controls can level the playing field.","how-browser-level-controls-change-the-fight-against-phishing",{"items":2662},[2663,2665],{"sys":2664,"name":1309},{"id":1308},{"sys":2666,"name":1305},{"id":1304},{"items":2668},[2669],{"fullName":2670,"firstName":2671,"jobTitle":2672,"profilePicture":2673},"Peyton Padfield","Peyton","Product Team",{"url":2674},"https://images.ctfassets.net/y1cdw1ablpvd/1GU01HXElmc07nwi89qP3b/3188050420106c62e9df2ed4e4893b7f/1677005177901__1_.jpeg",{"__typename":1313,"sys":2676,"content":2678,"title":3329,"synopsis":3330,"hashTags":118,"publishedDate":3331,"slug":3332,"tagsCollection":3333,"authorsCollection":3339},{"id":2677},"3dtvtDQdcQ6fAW7CB8VOFP",{"json":2679},{"nodeType":1294,"data":2680,"content":2681},{},[2682,2689,2696,2703,2706,2714,2721,2741,2774,2780,2800,2806,2831,2834,2842,2849,2865,2881,2887,2894,2901,2907,2923,2926,2934,2941,2948,2955,2962,2965,2973,2980,2987,3007,3014,3022,3065,3072,3078,3085,3091,3098,3101,3109,3124,3131,3173,3185,3188,3196,3203,3210,3243,3250,3270,3276,3282,3285,3293,3300,3317,3323],{"nodeType":1293,"data":2683,"content":2684},{},[2685],{"nodeType":1292,"value":2686,"marks":2687,"data":2688},"Phishing attacks remain a huge challenge for organizations in 2025. In fact, with attackers increasingly leveraging identity-based techniques over software exploits, phishing arguably poses a bigger threat than ever before. ",[],{},{"nodeType":1293,"data":2690,"content":2691},{},[2692],{"nodeType":1292,"value":2693,"marks":2694,"data":2695},"Attackers are turning to identity attacks like phishing because they can achieve all of the same objectives as they would in a traditional endpoint or network attack, simply by logging into a victim’s account. And with organizations now using hundreds of internet apps across their workforce, the scope of accounts that can be phished or targeted with stolen credentials has grown exponentially. ",[],{},{"nodeType":1293,"data":2697,"content":2698},{},[2699],{"nodeType":1292,"value":2700,"marks":2701,"data":2702},"With MFA-bypassing phishing kits the new normal, capable of phishing accounts protected by SMS, OTP, and push-based methods, detection controls are being put under constant pressure as prevention controls fall short. ",[],{},{"nodeType":1423,"data":2704,"content":2705},{},[],{"nodeType":1427,"data":2707,"content":2708},{},[2709],{"nodeType":1292,"value":2710,"marks":2711,"data":2713},"Attackers are bypassing detection controls",[2712],{"type":1434},{},{"nodeType":1293,"data":2715,"content":2716},{},[2717],{"nodeType":1292,"value":2718,"marks":2719,"data":2720},"The majority of phishing detection and control enforcement is focused at the email and network layer — typically at the Secure Email Gateway (SEG), Secure Web Gateway (SWG)/proxy, or both. ",[],{},{"nodeType":1293,"data":2722,"content":2723},{},[2724,2728,2737],{"nodeType":1292,"value":2725,"marks":2726,"data":2727},"But attackers know this, ",[],{},{"nodeType":1328,"data":2729,"content":2731},{"uri":2730},"https://pushsecurity.com/blog/how-aitm-phishing-kits-evade-detection-p2/",[2732],{"nodeType":1292,"value":2733,"marks":2734,"data":2736},"and are taking steps to avoid these controls",[2735],{"type":1336},{},{"nodeType":1292,"value":2738,"marks":2739,"data":2740},", by:",[],{},{"nodeType":1556,"data":2742,"content":2743},{},[2744,2754,2764],{"nodeType":1560,"data":2745,"content":2746},{},[2747],{"nodeType":1293,"data":2748,"content":2749},{},[2750],{"nodeType":1292,"value":2751,"marks":2752,"data":2753},"Routinely evading IoC driven blocklists by dynamically rotating and updating commonly signatured elements like IPs, domains, and URLs.",[],{},{"nodeType":1560,"data":2755,"content":2756},{},[2757],{"nodeType":1293,"data":2758,"content":2759},{},[2760],{"nodeType":1292,"value":2761,"marks":2762,"data":2763},"Preventing analysis of their phishing pages by implementing bot protection like CAPTCHA or Cloudflare Turnstile alongside other detection evasion methods. ",[],{},{"nodeType":1560,"data":2765,"content":2766},{},[2767],{"nodeType":1293,"data":2768,"content":2769},{},[2770],{"nodeType":1292,"value":2771,"marks":2772,"data":2773},"Changing visual and DOM elements on the page so that even when the page is loaded, detection signatures may fail to trigger.  ",[],{},{"nodeType":1457,"data":2775,"content":2779},{"target":2776},{"sys":2777},{"id":2778,"type":1462,"linkType":1463},"5w44LsamEfcwSACx3MA997",[],{"nodeType":1293,"data":2781,"content":2782},{},[2783,2787,2796],{"nodeType":1292,"value":2784,"marks":2785,"data":2786},"And in fact, by launching multi- and cross-channel attacks, attackers are evading email-based controls entirely. Just see ",[],{},{"nodeType":1328,"data":2788,"content":2790},{"uri":2789},"https://pushsecurity.com/blog/investigating-a-recent-malvertising-campaign-targeting-onfido-customers/?utm_campaign=12081956-FY25Q2_Hacker-News-Article&utm_source=thehackernews&utm_medium=sponsored&utm_content=external-article",[2791],{"nodeType":1292,"value":2792,"marks":2793,"data":2795},"this recent example",[2794],{"type":1336},{},{"nodeType":1292,"value":2797,"marks":2798,"data":2799},", where attackers impersonating Onfido delivered their phishing attack via malicious Google ads (aka malvertising) — bypassing email altogether. ",[],{},{"nodeType":1457,"data":2801,"content":2805},{"target":2802},{"sys":2803},{"id":2804,"type":1462,"linkType":1463},"3sGmVHl1Rwjyw3TMZSYuy4",[],{"nodeType":1293,"data":2807,"content":2808},{},[2809,2813,2818,2822,2827],{"nodeType":1292,"value":2810,"marks":2811,"data":2812},"It’s worth pointing out the limitations of email-based solutions here too. Email has some additional checks around the sender’s reputation and things like DMARC/DKIM, but these don’t actually identify malicious ",[],{},{"nodeType":1292,"value":2814,"marks":2815,"data":2817},"pages",[2816],{"type":1434},{},{"nodeType":1292,"value":2819,"marks":2820,"data":2821},". Similarly, some modern email solutions are doing much deeper analysis of the ",[],{},{"nodeType":1292,"value":2823,"marks":2824,"data":2826},"content",[2825],{"type":1434},{},{"nodeType":1292,"value":2828,"marks":2829,"data":2830}," of an email. But… that doesn’t really help with identifying the phishing sites themselves (just indicates that one might be linked in the email). This is much more appropriate for BEC-style attacks where the goal is to social engineer the victim, as opposed to linking them to a malicious page. And this still doesn’t help with attacks launched over different mediums as we’ve highlighted above.",[],{},{"nodeType":1423,"data":2832,"content":2833},{},[],{"nodeType":1427,"data":2835,"content":2836},{},[2837],{"nodeType":1292,"value":2838,"marks":2839,"data":2841},"How browser-based detection and response can level the playing field",[2840],{"type":1434},{},{"nodeType":1293,"data":2843,"content":2844},{},[2845],{"nodeType":1292,"value":2846,"marks":2847,"data":2848},"Most phishing attacks involve the delivery of a malicious link to a user. The user clicks the link and loads a malicious page. In the vast majority of cases, the malicious page is a login portal for a specific website, where the goal for the attacker is to steal the victim’s account.",[],{},{"nodeType":1293,"data":2850,"content":2851},{},[2852,2856,2861],{"nodeType":1292,"value":2853,"marks":2854,"data":2855},"These attacks are happening pretty much exclusively in the victim’s browser. So rather than building more email or network based controls looking from the outside-in at phishing pages accessed in the browser, there’s a huge opportunity presented by building phishing detection and response capabilities ",[],{},{"nodeType":1292,"value":2857,"marks":2858,"data":2860},"inside",[2859],{"type":311},{},{"nodeType":1292,"value":2862,"marks":2863,"data":2864}," the browser. ",[],{},{"nodeType":1293,"data":2866,"content":2867},{},[2868,2872,2877],{"nodeType":1292,"value":2869,"marks":2870,"data":2871},"When we look at the history of detection and response, this makes a lot of sense. When endpoint attacks skyrocketed in the late 2000s / early 2010s, they took advantage of the fact that defenders were trying to detect malware with primarily network-based detections, signature-based analysis of files, and running files in sandboxes (which was reliably defeated with sandbox-aware malware and using things as simple as putting an execution delay in the code). But this gave way to EDR, which presented a better way of observing and intercepting malicious software in ",[],{},{"nodeType":1292,"value":2873,"marks":2874,"data":2876},"real-time",[2875],{"type":1434},{},{"nodeType":1292,"value":2878,"marks":2879,"data":2880},". ",[],{},{"nodeType":1457,"data":2882,"content":2886},{"target":2883},{"sys":2884},{"id":2885,"type":1462,"linkType":1463},"1KFwJvbIMiWHb1erWlljZf",[],{"nodeType":1293,"data":2888,"content":2889},{},[2890],{"nodeType":1292,"value":2891,"marks":2892,"data":2893},"The key here was getting inside the data stream to be able to observe activity in real-time on the endpoint. ",[],{},{"nodeType":1293,"data":2895,"content":2896},{},[2897],{"nodeType":1292,"value":2898,"marks":2899,"data":2900},"We’re in a similar position today. Modern phishing attacks are happening on web pages accessed via the browser, and the tools we’re relying on — email, network, even endpoint — don’t have the required visibility. They’re looking from the outside-in. ",[],{},{"nodeType":1457,"data":2902,"content":2906},{"target":2903},{"sys":2904},{"id":2905,"type":1462,"linkType":1463},"59t6AcjpRjs3VQQXQO3PWu",[],{"nodeType":1293,"data":2908,"content":2909},{},[2910,2914,2919],{"nodeType":1292,"value":2911,"marks":2912,"data":2913},"But what if we could do detection and response from ",[],{},{"nodeType":1292,"value":2915,"marks":2916,"data":2918},"inside the browser?",[2917],{"type":1434},{},{"nodeType":1292,"value":2920,"marks":2921,"data":2922}," Here’s three reasons why the browser is best for stopping phishing attacks:",[],{},{"nodeType":1423,"data":2924,"content":2925},{},[],{"nodeType":1427,"data":2927,"content":2928},{},[2929],{"nodeType":1292,"value":2930,"marks":2931,"data":2933},"#1: Analyze pages, not links",[2932],{"type":1434},{},{"nodeType":1293,"data":2935,"content":2936},{},[2937],{"nodeType":1292,"value":2938,"marks":2939,"data":2940},"Common phishing detections rely on the analysis of links or static HTML as opposed to malicious pages. Modern phishing pages are no longer static HTML — like most other modern web pages, these are dynamic web apps rendered in the browser, with JavaScript dynamically rewriting the page and launching the malicious content. This means that most basic, static checks fail to identify the malicious content running on the page. ",[],{},{"nodeType":1293,"data":2942,"content":2943},{},[2944],{"nodeType":1292,"value":2945,"marks":2946,"data":2947},"Without deeper analysis, you’re reliant on analysing things like domains, URLs and IP addresses against known-bad blocklists. But these are all highly disposable. Attackers are buying them in bulk, constantly taking over legitimate domains, and generally planning for the fact that they’ll get through a lot of them. Modern phishing architecture is also able to dynamically rotate and update the links served to visitors from a continually refreshed pool (so every person that clicks the link gets served a different URL) and even going as far as using things like one-time magic links (which also means that any security team members trying to investigate the page later won’t be able to do so). ",[],{},{"nodeType":1293,"data":2949,"content":2950},{},[2951],{"nodeType":1292,"value":2952,"marks":2953,"data":2954},"Ultimately, this means that blocklists just aren’t that effective — because it’s trivial for attackers to change the indicators being used to create detections. If you think about the Pyramid of Pain, these indicators sit right at the bottom — the kind of thing we’ve been moving away from for years in the endpoint security world.  ",[],{},{"nodeType":1293,"data":2956,"content":2957},{},[2958],{"nodeType":1292,"value":2959,"marks":2960,"data":2961},"But in the browser, you can observe the rendered web page in all its glory. With much deeper visibility of the page (and its malicious elements) you can…",[],{},{"nodeType":1423,"data":2963,"content":2964},{},[],{"nodeType":1427,"data":2966,"content":2967},{},[2968],{"nodeType":1292,"value":2969,"marks":2970,"data":2972},"#2: Detect TTPs, not IoCs",[2971],{"type":1434},{},{"nodeType":1293,"data":2974,"content":2975},{},[2976],{"nodeType":1292,"value":2977,"marks":2978,"data":2979},"Even where TTP-based detections are in play, they’re typically reliant on either piecing together network requests, or loading the page in a sandbox. ",[],{},{"nodeType":1293,"data":2981,"content":2982},{},[2983],{"nodeType":1292,"value":2984,"marks":2985,"data":2986},"However, attackers are getting pretty good at evading sandbox analysis — simply by implementing bot protection by requiring user interaction with a CAPTCHA or Cloudflare Turnstile. Even if you can get past Turnstile, then you’ll need to supply the correct URL parameters and headers, and execute JavaScript, to be served the malicious page. This means that a defender who knows the domain name can’t discover the malicious behavior just by making a simple HTTP(S) request to the domain.",[],{},{"nodeType":1293,"data":2988,"content":2989},{},[2990,2994,3003],{"nodeType":1292,"value":2991,"marks":2992,"data":2993},"And if all this wasn’t enough, ",[],{},{"nodeType":1328,"data":2995,"content":2997},{"uri":2996},"https://pushsecurity.com/blog/how-aitm-phishing-kits-evade-detection-p2/?utm_campaign=12081956-FY25Q2_Hacker-News-Article&utm_source=thehackernews&utm_medium=sponsored&utm_content=external-article",[2998],{"nodeType":1292,"value":2999,"marks":3000,"data":3002},"they’re also obfuscating both visual and DOM elements to prevent signature-based detections from picking them up",[3001],{"type":1336},{},{"nodeType":1292,"value":3004,"marks":3005,"data":3006}," — so even if you can land on the page, there’s a high chance that your detections won’t trigger.",[],{},{"nodeType":1293,"data":3008,"content":3009},{},[3010],{"nodeType":1292,"value":3011,"marks":3012,"data":3013},"When using a proxy, you’ll have some visibility of the network traffic generated by a user accessing and interacting with a page. However, you’ll struggle to correlate key actions like whether the user entered their password with the specific tab when dealing with the sheer volume of disorganized network traffic data. ",[],{},{"nodeType":1293,"data":3015,"content":3016},{},[3017],{"nodeType":1292,"value":3018,"marks":3019,"data":3021},"But you get much better visibility of all this in the browser, with access to:",[3020],{"type":1434},{},{"nodeType":1556,"data":3023,"content":3024},{},[3025,3035,3045,3055],{"nodeType":1560,"data":3026,"content":3027},{},[3028],{"nodeType":1293,"data":3029,"content":3030},{},[3031],{"nodeType":1292,"value":3032,"marks":3033,"data":3034},"Full decrypted HTTP traffic — not just DNS and TCP/IP metadata",[],{},{"nodeType":1560,"data":3036,"content":3037},{},[3038],{"nodeType":1293,"data":3039,"content":3040},{},[3041],{"nodeType":1292,"value":3042,"marks":3043,"data":3044},"Full user interaction tracing — every click, keystroke, or DOM change can be traced",[],{},{"nodeType":1560,"data":3046,"content":3047},{},[3048],{"nodeType":1293,"data":3049,"content":3050},{},[3051],{"nodeType":1292,"value":3052,"marks":3053,"data":3054},"Full inspection at every layer of execution, not just initial HTML served",[],{},{"nodeType":1560,"data":3056,"content":3057},{},[3058],{"nodeType":1293,"data":3059,"content":3060},{},[3061],{"nodeType":1292,"value":3062,"marks":3063,"data":3064},"Full access to browser APIs, to correlate with browser history, local storage, attached cookies, etc.",[],{},{"nodeType":1293,"data":3066,"content":3067},{},[3068],{"nodeType":1292,"value":3069,"marks":3070,"data":3071},"This gives you everything you need to build high-fidelity detections focused on page behavior and user interaction – that are much harder for attackers to get around when compared to IoC-based detections. ",[],{},{"nodeType":1457,"data":3073,"content":3077},{"target":3074},{"sys":3075},{"id":3076,"type":1462,"linkType":1463},"1YggWcADAWgt3sUkXMsVIw",[],{"nodeType":1293,"data":3079,"content":3080},{},[3081],{"nodeType":1292,"value":3082,"marks":3083,"data":3084},"In the browser, you get much better visibility of the user and page behavior to enable phishing page detection.",[],{},{"nodeType":1457,"data":3086,"content":3090},{"target":3087},{"sys":3088},{"id":3089,"type":1462,"linkType":1463},"1BKgjnYkLJIRW0LJZYpfga",[],{"nodeType":1293,"data":3092,"content":3093},{},[3094],{"nodeType":1292,"value":3095,"marks":3096,"data":3097},"And with this new visibility, because you’re in the browser and seeing the page at the same time as the user is interacting with it, you can…",[],{},{"nodeType":1423,"data":3099,"content":3100},{},[],{"nodeType":1427,"data":3102,"content":3103},{},[3104],{"nodeType":1292,"value":3105,"marks":3106,"data":3108},"#3: Intercept in real time, not post mortem",[3107],{"type":1434},{},{"nodeType":1293,"data":3110,"content":3111},{},[3112,3116,3121],{"nodeType":1292,"value":3113,"marks":3114,"data":3115},"For non-browser solutions, ",[],{},{"nodeType":1292,"value":3117,"marks":3118,"data":3120},"real-time phishing detection is basically nonexistent",[3119],{"type":1434},{},{"nodeType":1292,"value":2878,"marks":3122,"data":3123},[],{},{"nodeType":1293,"data":3125,"content":3126},{},[3127],{"nodeType":1292,"value":3128,"marks":3129,"data":3130},"At best, your proxy-based solution might be able to detect malicious behavior via the network traffic generated by your user interacting with the page. But because of the complexity of reconstructing network requests post-TLS-encryption, this typically happens on a time delay and is not entirely reliable. ",[],{},{"nodeType":1293,"data":3132,"content":3133},{},[3134,3138,3143,3147,3152,3156,3160,3164,3169],{"nodeType":1292,"value":3135,"marks":3136,"data":3137},"If a page is flagged, it usually requires further investigation by a security team to rule out any false positives and kick off an investigation. This can take ",[],{},{"nodeType":1292,"value":3139,"marks":3140,"data":3142},"hours",[3141],{"type":1434},{},{"nodeType":1292,"value":3144,"marks":3145,"data":3146}," at best, probably ",[],{},{"nodeType":1292,"value":3148,"marks":3149,"data":3151},"days",[3150],{"type":1434},{},{"nodeType":1292,"value":3153,"marks":3154,"data":3155},". Then, once a page is identified as malicious and IoCs are created, it can take ",[],{},{"nodeType":1292,"value":3148,"marks":3157,"data":3159},[3158],{"type":1434},{},{"nodeType":1292,"value":3161,"marks":3162,"data":3163}," or even ",[],{},{"nodeType":1292,"value":3165,"marks":3166,"data":3168},"weeks",[3167],{"type":1434},{},{"nodeType":1292,"value":3170,"marks":3171,"data":3172}," before the information is distributed, TI feeds are updated, and ingested into blocklists. ",[],{},{"nodeType":1293,"data":3174,"content":3175},{},[3176,3180],{"nodeType":1292,"value":3177,"marks":3178,"data":3179},"But in the browser, you’re observing the page in real-time, as the user sees it, from inside the browser. This is a game changer when it comes to not just detecting, but intercepting and shutting down attacks before a user is phished and the damage is done. ",[],{},{"nodeType":1292,"value":3181,"marks":3182,"data":3184},"This changes the focus from post mortem containment and cleanup, to pre-compromise interception in real time. ",[3183],{"type":1434},{},{"nodeType":1423,"data":3186,"content":3187},{},[],{"nodeType":1427,"data":3189,"content":3190},{},[3191],{"nodeType":1292,"value":3192,"marks":3193,"data":3195},"The future of phishing detection and response is browser based",[3194],{"type":1434},{},{"nodeType":1293,"data":3197,"content":3198},{},[3199],{"nodeType":1292,"value":3200,"marks":3201,"data":3202},"Push provides a browser-based identity security solution that intercepts phishing attacks as they happen — in employee browsers. Being in the browser delivers a lot of advantages when it comes to detecting and intercepting phishing attacks. You see the live webpage that the user sees, as they see it, meaning you have much better visibility of malicious elements running on the page. It also means that you can implement real-time controls that kick in when a malicious element is detected. ",[],{},{"nodeType":1293,"data":3204,"content":3205},{},[3206],{"nodeType":1292,"value":3207,"marks":3208,"data":3209},"When a phishing attack hits a user with Push, regardless of the delivery channel, our browser extension inspects the webpage running in the user's browser. Push observes that the webpage is a login page and the user is entering their password into the page, detecting that:",[],{},{"nodeType":1556,"data":3211,"content":3212},{},[3213,3223,3233],{"nodeType":1560,"data":3214,"content":3215},{},[3216],{"nodeType":1293,"data":3217,"content":3218},{},[3219],{"nodeType":1292,"value":3220,"marks":3221,"data":3222},"The password the user is entering into the phishing site has been used to log into another site previously. This means that the password is being reused (bad) or the user is being phished (even worse).  ",[],{},{"nodeType":1560,"data":3224,"content":3225},{},[3226],{"nodeType":1293,"data":3227,"content":3228},{},[3229],{"nodeType":1292,"value":3230,"marks":3231,"data":3232},"The web page is cloned from a legitimate login page that has been fingerprinted by Push. ",[],{},{"nodeType":1560,"data":3234,"content":3235},{},[3236],{"nodeType":1293,"data":3237,"content":3238},{},[3239],{"nodeType":1292,"value":3240,"marks":3241,"data":3242},"A phishing toolkit is running on the web page. ",[],{},{"nodeType":1293,"data":3244,"content":3245},{},[3246],{"nodeType":1292,"value":3247,"marks":3248,"data":3249},"As a result, the user is blocked from interacting with the phishing site and prevented from continuing. ",[],{},{"nodeType":1293,"data":3251,"content":3252},{},[3253,3258,3267],{"nodeType":1292,"value":3254,"marks":3255,"data":3257},"These are good examples of detections that are difficult (or impossible) for an attacker to evade — you can’t phish a victim if they can’t enter their credentials into your phishing site! ",[3256],{"type":1434},{},{"nodeType":1328,"data":3259,"content":3261},{"uri":3260},"https://pushsecurity.com/blog/detecting-and-blocking-phishing-attacks-in-the-browser/?utm_campaign=12081956-FY25Q2_Hacker-News-Article&utm_source=thehackernews&utm_medium=sponsored&utm_content=external-article",[3262],{"nodeType":1292,"value":3263,"marks":3264,"data":3266},"Find out more about how Push detects and blocks phishing attacks here.",[3265],{"type":1336},{},{"nodeType":1292,"value":37,"marks":3268,"data":3269},[],{},{"nodeType":1457,"data":3271,"content":3275},{"target":3272},{"sys":3273},{"id":3274,"type":1462,"linkType":1463},"4ixcEsEW4EyqckOTmP5Pbb",[],{"nodeType":1457,"data":3277,"content":3281},{"target":3278},{"sys":3279},{"id":3280,"type":1462,"linkType":1463},"4PJKxWTroEPohYm4mklfl6",[],{"nodeType":1423,"data":3283,"content":3284},{},[],{"nodeType":1427,"data":3286,"content":3287},{},[3288],{"nodeType":1292,"value":3289,"marks":3290,"data":3292},"Learn more",[3291],{"type":1434},{},{"nodeType":1293,"data":3294,"content":3295},{},[3296],{"nodeType":1292,"value":3297,"marks":3298,"data":3299},"It doesn’t stop there — Push provides comprehensive identity attack detection and response capabilities against techniques like credential stuffing, password spraying and session hijacking using stolen session tokens. You can also use Push to find and fix identity vulnerabilities across every app that your employees use like: ghost logins; SSO coverage gaps; MFA gaps; weak, breached and reused passwords; risky OAuth integrations; and more. ",[],{},{"nodeType":1293,"data":3301,"content":3302},{},[3303,3306,3314],{"nodeType":1292,"value":2002,"marks":3304,"data":3305},[],{},{"nodeType":1328,"data":3307,"content":3309},{"uri":3308},"https://pushsecurity.com/demo?utm_campaign=12081956-FY25Q2_Hacker-News-Article&utm_source=thehackernews&utm_medium=sponsored&utm_content=external-article",[3310],{"nodeType":1292,"value":2010,"marks":3311,"data":3313},[3312],{"type":1336},{},{"nodeType":1292,"value":2015,"marks":3315,"data":3316},[],{},{"nodeType":1457,"data":3318,"content":3322},{"target":3319},{"sys":3320},{"id":3321,"type":1462,"linkType":1463},"2DviJNOMbKgbcqwkNl0LDP",[],{"nodeType":1293,"data":3324,"content":3325},{},[3326],{"nodeType":1292,"value":37,"marks":3327,"data":3328},[],{},"Three reasons why browser is best for stopping phishing attacks","Why being in the browser gives defenders a key advantage over network and email phishing prevention, detection, and response tools. ","2025-04-28T00:00:00.000Z","three-reasons-why-browser-is-best-for-stopping-phishing-attacks",{"items":3334},[3335,3337],{"sys":3336,"name":1305},{"id":1304},{"sys":3338,"name":1309},{"id":1308},{"items":3340},[3341],{"fullName":2031,"firstName":2032,"jobTitle":2033,"profilePicture":3342},{"url":2035},{"items":3344},[3345],{"fullName":3346,"firstName":3347,"jobTitle":3348,"profilePicture":3349},"Luke Jennings","Luke","Vice President, R&D",{"url":3350},"https://images.ctfassets.net/y1cdw1ablpvd/4Hosb4zKi1dA0PUyDLMe1h/27e09d894861f2196ba794037986fb08/T016S22KZ96-U02NVQM7ZD4-57761d542d83-512.jpeg",{"json":3352,"links":3998},{"nodeType":1294,"data":3353,"content":3354},{},[3355,3362,3369,3375,3400,3419,3422,3430,3437,3444,3452,3472,3475,3483,3490,3496,3503,3509,3512,3520,3527,3534,3557,3564,3597,3604,3612,3631,3638,3644,3671,3704,3712,3719,3726,3759,3762,3770,3790,3797,3820,3827,3833,3836,3844,3851,3965,3968,3975,3982],{"nodeType":1293,"data":3356,"content":3357},{},[3358],{"nodeType":1292,"value":3359,"marks":3360,"data":3361},"As awareness grows around many MFA methods being “phishable” (i.e. not phishing resistant), passwordless authentication methods are being increasingly advocated. ",[],{},{"nodeType":1293,"data":3363,"content":3364},{},[3365],{"nodeType":1292,"value":3366,"marks":3367,"data":3368},"This is a good thing. The most commonly used MFA factors (like SMS codes, push notifications, and app-based OTP) are routinely bypassed, with modern reverse-proxy phishing kits the most common method. ",[],{},{"nodeType":1457,"data":3370,"content":3374},{"target":3371},{"sys":3372},{"id":3373,"type":1462,"linkType":1463},"ImwzE2R9qaHaqlWn0GqIa",[],{"nodeType":1293,"data":3376,"content":3377},{},[3378,3382,3387,3391,3396],{"nodeType":1292,"value":3379,"marks":3380,"data":3381},"Often referred to as a “passkey”, passwordless authentication typically consists of a hardware security device that is built-into your laptop (e.g. the fingerprint sensor on a laptop) or something you plug into your device (e.g. a Yubikey). Because passkey-based logins are domain-bound, trying to use a passkey for ",[],{},{"nodeType":1292,"value":3383,"marks":3384,"data":3386},"microsoft.com",[3385],{"type":1336},{},{"nodeType":1292,"value":3388,"marks":3389,"data":3390}," on ",[],{},{"nodeType":1292,"value":3392,"marks":3393,"data":3395},"phishing.com",[3394],{"type":1336},{},{"nodeType":1292,"value":3397,"marks":3398,"data":3399}," simply won’t generate the correct value to pass the authentication check, even when proxied using an AitM kit. ",[],{},{"nodeType":1293,"data":3401,"content":3402},{},[3403,3407,3416],{"nodeType":1292,"value":3404,"marks":3405,"data":3406},"However, attackers have realized that even as these new phishing-resistant methods are starting to become used, most users still have alternative MFA methods active. The attacker can then do what’s called a ",[],{},{"nodeType":1328,"data":3408,"content":3409},{"uri":1816},[3410],{"nodeType":1292,"value":3411,"marks":3412,"data":3415},"downgrade attack",[3413,3414],{"type":1336},{"type":1434},{},{"nodeType":1292,"value":2015,"marks":3417,"data":3418},[],{},{"nodeType":1423,"data":3420,"content":3421},{},[],{"nodeType":1427,"data":3423,"content":3424},{},[3425],{"nodeType":1292,"value":3426,"marks":3427,"data":3429},"Downgrade attacks 101",[3428],{"type":1434},{},{"nodeType":1293,"data":3431,"content":3432},{},[3433],{"nodeType":1292,"value":3434,"marks":3435,"data":3436},"When conducting an Attacker-in-the-Middle phishing attack, the attacker doesn’t need to relay 100% of the messages accurately. Instead, they can alter some of them. The app might ask the user “You need to MFA — do you want to use your passkey, or your backup authenticator code?”, but the phishing website might modify this page to say “You need to MFA — use your backup authenticator code” not giving you the option to use your secure passkey. This is called a downgrade attack.",[],{},{"nodeType":1293,"data":3438,"content":3439},{},[3440],{"nodeType":1292,"value":3441,"marks":3442,"data":3443},"This can also be applied to accounts that use SSO as the default login method. In this scenario, the phish kit can select a backup username and password option to allow the phishing attack to proceed.  ",[],{},{"nodeType":1293,"data":3445,"content":3446},{},[3447],{"nodeType":1292,"value":3448,"marks":3449,"data":3451},"So, you have a situation where even if a phishing-resistant login method exists, the presence of a less secure backup method means the account is still vulnerable to phishing attacks. ",[3450],{"type":1434},{},{"nodeType":1293,"data":3453,"content":3454},{},[3455,3459,3468],{"nodeType":1292,"value":3456,"marks":3457,"data":3458},"These attacks are effective across a number of sites and login methods that support passkey-based logins, for example, Windows Hello, Okta FastPass, and Google Workspace. As an example, here’s a link to a ",[],{},{"nodeType":1328,"data":3460,"content":3462},{"uri":3461},"https://github.com/yudasm/WHfB-o365-Phishlet",[3463],{"nodeType":1292,"value":3464,"marks":3465,"data":3467},"custom phishlet for Evilginx",[3466],{"type":1336},{},{"nodeType":1292,"value":3469,"marks":3470,"data":3471}," targeting Windows Hello for Business. A small caveat is that changes made by Microsoft have since broken this plugin, but we were able to write our own custom phishlet to achieve the same outcome. ",[],{},{"nodeType":1423,"data":3473,"content":3474},{},[],{"nodeType":1427,"data":3476,"content":3477},{},[3478],{"nodeType":1292,"value":3479,"marks":3480,"data":3482},"MFA downgrade in action",[3481],{"type":1434},{},{"nodeType":1293,"data":3484,"content":3485},{},[3486],{"nodeType":1292,"value":3487,"marks":3488,"data":3489},"Check out the video below to see an example of using Evilginx with a custom phishlet to downgrade authentication for a Microsoft account using Windows Hello. ",[],{},{"nodeType":1457,"data":3491,"content":3495},{"target":3492},{"sys":3493},{"id":3494,"type":1462,"linkType":1463},"54I3YQ2gK26a8FIocQ3WYT",[],{"nodeType":1293,"data":3497,"content":3498},{},[3499],{"nodeType":1292,"value":3500,"marks":3501,"data":3502},"We’ve encountered similar functionality in criminal phishing platforms we’ve investigated such as Tycoon — in this case, targeting Google accounts. This snippet is notable in that it includes JavaScript to abuse UI features to bypass passkeys.",[],{},{"nodeType":1457,"data":3504,"content":3508},{"target":3505},{"sys":3506},{"id":3507,"type":1462,"linkType":1463},"5Vya1VApSisr0000HuTLY2",[],{"nodeType":1423,"data":3510,"content":3511},{},[],{"nodeType":1427,"data":3513,"content":3514},{},[3515],{"nodeType":1292,"value":3516,"marks":3517,"data":3519},"Mitigations (and challenges)",[3518],{"type":1434},{},{"nodeType":1293,"data":3521,"content":3522},{},[3523],{"nodeType":1292,"value":3524,"marks":3525,"data":3526},"MFA downgrade is made possible by the existence of backup authentication methods. So the obvious solution is to remove backup/unused login and MFA methods from your accounts, ensuring you’re accessing apps using SSO from a hardened Identity Provider (IdP) account (e.g. Okta, Entra, Google Workspace). ",[],{},{"nodeType":1293,"data":3528,"content":3529},{},[3530],{"nodeType":1292,"value":3531,"marks":3532,"data":3533},"In the ideal world, you’d be:",[],{},{"nodeType":1556,"data":3535,"content":3536},{},[3537,3547],{"nodeType":1560,"data":3538,"content":3539},{},[3540],{"nodeType":1293,"data":3541,"content":3542},{},[3543],{"nodeType":1292,"value":3544,"marks":3545,"data":3546},"Using only one IdP account, which you access via passkey, with no backup methods.",[],{},{"nodeType":1560,"data":3548,"content":3549},{},[3550],{"nodeType":1293,"data":3551,"content":3552},{},[3553],{"nodeType":1292,"value":3554,"marks":3555,"data":3556},"Accessing all business apps using SSO from your locked-down IdP account. ",[],{},{"nodeType":1293,"data":3558,"content":3559},{},[3560],{"nodeType":1292,"value":3561,"marks":3562,"data":3563},"The reality is way different, though. Because going totally passwordless is hard. It requires a large investment of time, money, and training for end-users. You’ll find many cautionary tales of companies starting on their passkey adoption journey and ultimately failing to make it a reality. This is largely because:",[],{},{"nodeType":1556,"data":3565,"content":3566},{},[3567,3577,3587],{"nodeType":1560,"data":3568,"content":3569},{},[3570],{"nodeType":1293,"data":3571,"content":3572},{},[3573],{"nodeType":1292,"value":3574,"marks":3575,"data":3576},"In environments with a mix of older and newer infrastructure, it can be challenging to get complete coverage. ",[],{},{"nodeType":1560,"data":3578,"content":3579},{},[3580],{"nodeType":1293,"data":3581,"content":3582},{},[3583],{"nodeType":1292,"value":3584,"marks":3585,"data":3586},"Not every device comes with an in-built biometric identification method, so you need to use a second device — which employees may struggle with (especially when they lose it and aren’t familiar with how to regain account access).",[],{},{"nodeType":1560,"data":3588,"content":3589},{},[3590],{"nodeType":1293,"data":3591,"content":3592},{},[3593],{"nodeType":1292,"value":3594,"marks":3595,"data":3596},"Most apps don’t allow you to log in directly with a passkey, meaning you need to SSO from your IdP account. But many apps don’t support every preferred SSO provider, and fail to provide SAML support, so there can be gaps.  ",[],{},{"nodeType":1293,"data":3598,"content":3599},{},[3600],{"nodeType":1292,"value":3601,"marks":3602,"data":3603},"And ultimately, because of the self-service, product-led growth fuelled nature of most online services today, it’s easy for users to slip back into using passwords — and hard for security teams to find and remove them (particularly if an app isn’t centrally managed). And the level of support that different apps provide users and administrators to secure how they access their services varies significantly. ",[],{},{"nodeType":2301,"data":3605,"content":3606},{},[3607],{"nodeType":1292,"value":3608,"marks":3609,"data":3611},"Most apps make removing phishable authentication hard",[3610],{"type":1434},{},{"nodeType":1293,"data":3613,"content":3614},{},[3615,3619,3627],{"nodeType":1292,"value":3616,"marks":3617,"data":3618},"While some providers are taking steps to go passwordless by default, which makes it easier to remove passwords (e.g. ",[],{},{"nodeType":1328,"data":3620,"content":3622},{"uri":3621},"https://techcommunity.microsoft.com/blog/microsoft-entra-blog/introducing-password-removal-for-microsoft-accounts/2747280",[3623],{"nodeType":1292,"value":1333,"marks":3624,"data":3626},[3625],{"type":1336},{},{"nodeType":1292,"value":3628,"marks":3629,"data":3630}," recently made a big deal of its desire to get rid of passwords), the quality of identity security management functionality varies significantly from app to app. ",[],{},{"nodeType":1293,"data":3632,"content":3633},{},[3634],{"nodeType":1292,"value":3635,"marks":3636,"data":3637},"Many apps default to the most recently used or strongest login method, but very few automatically lock you in to using the strongest method available. Most of the time, these kinds of controls also need to be configured in the app — which can be challenging if your security team doesn’t manage it (or simply isn’t aware of it). ",[],{},{"nodeType":1457,"data":3639,"content":3643},{"target":3640},{"sys":3641},{"id":3642,"type":1462,"linkType":1463},"4X9MR0CbSMltOmw767XNOm",[],{"nodeType":1293,"data":3645,"content":3646},{},[3647,3651,3656,3660,3667],{"nodeType":1292,"value":3648,"marks":3649,"data":3650},"Finally, configuring MFA is often an additive process — you start by adding a phone number, then you add an authenticator app or a passkey. Just like we find that most accounts with SSO ",[],{},{"nodeType":1292,"value":3652,"marks":3653,"data":3655},"also",[3654],{"type":1434},{},{"nodeType":1292,"value":3657,"marks":3658,"data":3659}," have a password login configured (also known as ",[],{},{"nodeType":1328,"data":3661,"content":3662},{"uri":1803},[3663],{"nodeType":1292,"value":1806,"marks":3664,"data":3666},[3665],{"type":1336},{},{"nodeType":1292,"value":3668,"marks":3669,"data":3670},"), most accounts with MFA typically have multiple methods attached to their account. ",[],{},{"nodeType":1293,"data":3672,"content":3673},{},[3674,3678,3687,3691,3700],{"nodeType":1292,"value":3675,"marks":3676,"data":3677},"The result is that even if you can successfully lock down a handful of apps, many more will continue to be susceptible to phishing attacks using commonly available downgrade functionality. And as attackers diversify the apps they target (such as these recent examples targeting ",[],{},{"nodeType":1328,"data":3679,"content":3681},{"uri":3680},"https://pushsecurity.com/blog/investigating-a-recent-malvertising-campaign-targeting-onfido-customers/",[3682],{"nodeType":1292,"value":3683,"marks":3684,"data":3686},"Onfido",[3685],{"type":1336},{},{"nodeType":1292,"value":3688,"marks":3689,"data":3690}," and ",[],{},{"nodeType":1328,"data":3692,"content":3694},{"uri":3693},"https://pushsecurity.com/blog/dissecting-a-recent-mailchimp-phishing-attack/",[3695],{"nodeType":1292,"value":3696,"marks":3697,"data":3699},"MailChimp",[3698],{"type":1336},{},{"nodeType":1292,"value":3701,"marks":3702,"data":3703},"), this becomes increasingly likely. ",[],{},{"nodeType":2301,"data":3705,"content":3706},{},[3707],{"nodeType":1292,"value":3708,"marks":3709,"data":3711},"Conditional access is a useful mitigation if configured properly, but only on apps which support it",[3710],{"type":1434},{},{"nodeType":1293,"data":3713,"content":3714},{},[3715],{"nodeType":1292,"value":3716,"marks":3717,"data":3718},"Conditional access policies are a useful last line of defense against account takeover attacks by denying logins that don't meet certain criteria, even if they user is able to authenticate. In larger IdP platforms that typically support more granular conditional access policies, this is a useful addition when configured correctly. However, many apps simply don't support conditional access, so will be vulnerable to attackers targeting them directly (as opposed to first logging into e.g. Microsoft or Google, and then accessing downstream apps via SSO). ",[],{},{"nodeType":1293,"data":3720,"content":3721},{},[3722],{"nodeType":1292,"value":3723,"marks":3724,"data":3725},"That said, locking down your core IdP platforms with robust conditional access should be a top priority for security teams. Useful policies that should be configured include:",[],{},{"nodeType":1556,"data":3727,"content":3728},{},[3729,3739,3749],{"nodeType":1560,"data":3730,"content":3731},{},[3732],{"nodeType":1293,"data":3733,"content":3734},{},[3735],{"nodeType":1292,"value":3736,"marks":3737,"data":3738},"Limiting logins to domain-joined devices.",[],{},{"nodeType":1560,"data":3740,"content":3741},{},[3742],{"nodeType":1293,"data":3743,"content":3744},{},[3745],{"nodeType":1292,"value":3746,"marks":3747,"data":3748},"Set phishing-resistant MFA as required. ",[],{},{"nodeType":1560,"data":3750,"content":3751},{},[3752],{"nodeType":1293,"data":3753,"content":3754},{},[3755],{"nodeType":1292,"value":3756,"marks":3757,"data":3758},"(Where possible) limit logins to trusted IP ranges. ",[],{},{"nodeType":1423,"data":3760,"content":3761},{},[],{"nodeType":1427,"data":3763,"content":3764},{},[3765],{"nodeType":1292,"value":3766,"marks":3767,"data":3769},"Tackling MFA downgrade with Push Security",[3768],{"type":1434},{},{"nodeType":1293,"data":3771,"content":3772},{},[3773,3777,3786],{"nodeType":1292,"value":3774,"marks":3775,"data":3776},"Phishing-resistant authentication methods like passkeys are key to the future of enterprise identity security, but organizations need to recognize that adopting passkeys isn’t a silver bullet. Ensuring that passkeys are the only authentication method supported by your business apps is no mean feat, considering ",[],{},{"nodeType":1328,"data":3778,"content":3780},{"uri":3779},"https://pushsecurity.com/blog/how-many-vulnerable-identities-do-you-have/",[3781],{"nodeType":1292,"value":3782,"marks":3783,"data":3785},"most organizations are using hundreds of them",[3784],{"type":1336},{},{"nodeType":1292,"value":3787,"marks":3788,"data":3789}," — all with their own specific ways of handling and administering identities. ",[],{},{"nodeType":1293,"data":3791,"content":3792},{},[3793],{"nodeType":1292,"value":3794,"marks":3795,"data":3796},"That’s why we support a layered defense, providing last-mile protection by:",[],{},{"nodeType":1556,"data":3798,"content":3799},{},[3800,3810],{"nodeType":1560,"data":3801,"content":3802},{},[3803],{"nodeType":1293,"data":3804,"content":3805},{},[3806],{"nodeType":1292,"value":3807,"marks":3808,"data":3809},"Intercepting and blocking phishing attacks in the browser to prevent AiTM attacks using downgrade techniques.",[],{},{"nodeType":1560,"data":3811,"content":3812},{},[3813],{"nodeType":1293,"data":3814,"content":3815},{},[3816],{"nodeType":1292,"value":3817,"marks":3818,"data":3819},"Identifying backup MFA and login methods across the business apps your employees use, so they can be removed (individually or through app-level configuration changes).",[],{},{"nodeType":1293,"data":3821,"content":3822},{},[3823],{"nodeType":1292,"value":3824,"marks":3825,"data":3826},"Here’s how it works.",[],{},{"nodeType":1457,"data":3828,"content":3832},{"target":3829},{"sys":3830},{"id":3831,"type":1462,"linkType":1463},"2uvItnfaOQZHa4a9BIIhRn",[],{"nodeType":1423,"data":3834,"content":3835},{},[],{"nodeType":1427,"data":3837,"content":3838},{},[3839],{"nodeType":1292,"value":3840,"marks":3841,"data":3843},"Further reading",[3842],{"type":1434},{},{"nodeType":1293,"data":3845,"content":3846},{},[3847],{"nodeType":1292,"value":3848,"marks":3849,"data":3850},"MFA downgrade is just one method of getting into an otherwise locked-down account. Attackers are also finding ways to bypass the standard authentication process entirely, through: ",[],{},{"nodeType":1556,"data":3852,"content":3853},{},[3854,3888,3917,3936],{"nodeType":1560,"data":3855,"content":3856},{},[3857],{"nodeType":1293,"data":3858,"content":3859},{},[3860,3863,3871,3875,3884],{"nodeType":1292,"value":37,"marks":3861,"data":3862},[],{},{"nodeType":1328,"data":3864,"content":3865},{"uri":1391},[3866],{"nodeType":1292,"value":3867,"marks":3868,"data":3870},"App-specific password phishing",[3869],{"type":1336},{},{"nodeType":1292,"value":3872,"marks":3873,"data":3874},", where attackers can abuse functionality designed to enable users to log into apps that don’t support modern authentication. (",[],{},{"nodeType":1328,"data":3876,"content":3878},{"uri":3877},"https://pushsecurity.com/blog/app-specific-password-phishing/",[3879],{"nodeType":1292,"value":3880,"marks":3881,"data":3883},"Read the article for more information here",[3882],{"type":1336},{},{"nodeType":1292,"value":3885,"marks":3886,"data":3887},").",[],{},{"nodeType":1560,"data":3889,"content":3890},{},[3891],{"nodeType":1293,"data":3892,"content":3893},{},[3894,3897,3904,3907,3914],{"nodeType":1292,"value":37,"marks":3895,"data":3896},[],{},{"nodeType":1328,"data":3898,"content":3899},{"uri":1695},[3900],{"nodeType":1292,"value":1698,"marks":3901,"data":3903},[3902],{"type":1336},{},{"nodeType":1292,"value":1703,"marks":3905,"data":3906},[],{},{"nodeType":1328,"data":3908,"content":3909},{"uri":1708},[3910],{"nodeType":1292,"value":1711,"marks":3911,"data":3913},[3912],{"type":1336},{},{"nodeType":1292,"value":1716,"marks":3915,"data":3916},[],{},{"nodeType":1560,"data":3918,"content":3919},{},[3920],{"nodeType":1293,"data":3921,"content":3922},{},[3923,3926,3933],{"nodeType":1292,"value":37,"marks":3924,"data":3925},[],{},{"nodeType":1328,"data":3927,"content":3928},{"uri":1730},[3929],{"nodeType":1292,"value":1733,"marks":3930,"data":3932},[3931],{"type":1336},{},{"nodeType":1292,"value":1738,"marks":3934,"data":3935},[],{},{"nodeType":1560,"data":3937,"content":3938},{},[3939],{"nodeType":1293,"data":3940,"content":3941},{},[3942,3945,3952,3955,3962],{"nodeType":1292,"value":37,"marks":3943,"data":3944},[],{},{"nodeType":1328,"data":3946,"content":3947},{"uri":1752},[3948],{"nodeType":1292,"value":1755,"marks":3949,"data":3951},[3950],{"type":1336},{},{"nodeType":1292,"value":1760,"marks":3953,"data":3954},[],{},{"nodeType":1328,"data":3956,"content":3957},{"uri":1765},[3958],{"nodeType":1292,"value":1768,"marks":3959,"data":3961},[3960],{"type":1336},{},{"nodeType":1292,"value":1773,"marks":3963,"data":3964},[],{},{"nodeType":1423,"data":3966,"content":3967},{},[],{"nodeType":1427,"data":3969,"content":3970},{},[3971],{"nodeType":1292,"value":3289,"marks":3972,"data":3974},[3973],{"type":1434},{},{"nodeType":1293,"data":3976,"content":3977},{},[3978],{"nodeType":1292,"value":3979,"marks":3980,"data":3981},"Push Security’s browser-based security platform provides comprehensive identity attack detection and response capabilities against techniques like AiTM phishing, credential stuffing, password spraying and session hijacking using stolen session tokens. You can also use Push to find and fix identity vulnerabilities across every app that your employees use, like: ghost logins; SSO coverage gaps; MFA gaps; weak, breached and reused passwords; risky OAuth integrations; and more.",[],{},{"nodeType":1293,"data":3983,"content":3984},{},[3985,3988,3995],{"nodeType":1292,"value":2002,"marks":3986,"data":3987},[],{},{"nodeType":1328,"data":3989,"content":3990},{"uri":2634},[3991],{"nodeType":1292,"value":2010,"marks":3992,"data":3994},[3993],{"type":1336},{},{"nodeType":1292,"value":2015,"marks":3996,"data":3997},[],{},{"entries":3999},{"hyperlink":4000,"inline":4001,"block":4002},[],[],[4003,4018,4024,4033,4059],{"sys":4004,"__typename":4005,"content":4006,"name":4017,"title":118},{"id":3373},"InsightTextBlockComponent",{"json":4007},{"nodeType":1294,"data":4008,"content":4009},{},[4010],{"nodeType":1293,"data":4011,"content":4012},{},[4013],{"nodeType":1292,"value":4014,"marks":4015,"data":4016},"MFA-bypassing Attacker-in-the-Middle phishing kits are the standard choice for attackers today. These work by intercepting the authenticated session created when a victim enters their password and completes an MFA check. To do this, the phishing website simply passes messages between the user and the real website — hence “Attacker-in-the-Middle”.",[],{},"MFA downgrade insight box 1",{"sys":4019,"__typename":4020,"title":4021,"arcadeDemoUrl":4022,"playText":4023},{"id":3494},"ArcadeDemo","MFA Downgrade Demo","https://demo.arcade.software/1MzRfFaRCD2pYPhIXkvi?embed","2 mins",{"sys":4025,"__typename":4026,"title":4027,"caption":4028,"layoutMode":118,"file":4029},{"id":3507},"Image","Tycoon Passkeys Code Snippet","Tycoon code snippet from a phishing campaign targeting Google accounts.",{"url":4030,"width":4031,"height":4032},"https://images.ctfassets.net/y1cdw1ablpvd/21d3KTcWt9GBJ4712OoPYg/4062faca94e8e326db8fc84fd7a21f74/carbon_1.png",1784,2066,{"sys":4034,"__typename":4005,"content":4035,"name":4058,"title":118},{"id":3642},{"json":4036},{"data":4037,"content":4038,"nodeType":1294},{},[4039],{"data":4040,"content":4041,"nodeType":1293},{},[4042,4046,4055],{"data":4043,"marks":4044,"value":4045,"nodeType":1292},{},[],"We wrote about the big variance in app identity security controls ",{"data":4047,"content":4049,"nodeType":1328},{"uri":4048},"https://pushsecurity.com/blog/minimum-viable-identity-security/",[4050],{"data":4051,"marks":4052,"value":4054,"nodeType":1292},{},[4053],{"type":1336},"in a recent blog post",{"data":4056,"marks":4057,"value":2015,"nodeType":1292},{},[],"MFA downgrade insight box 2",{"sys":4060,"__typename":4020,"title":4061,"arcadeDemoUrl":4062,"playText":4023},{"id":3831},"How Push stops phishing attacks in the browser","https://demo.arcade.software/SyrZLMa3pLKrNudoaQnD?embed","content:blog:mfa-downgrade-attacks.json","json","blog/mfa-downgrade-attacks.json","blog/mfa-downgrade-attacks",1776357817109]