[{"data":1,"prerenderedAt":4827},["ShallowReactive",2],{"application-flags":3,"navbar":7,"always-visible-banner":95,"navbar-about-highlight":155,"navbar-resource-highlight":211,"use-case-page":256,"blog/scattered-spider-ttp-evolution-in-2025":1276},[4],{"name":5,"enabled":6},"maintenanceMode",false,[8,59,76],{"createdDate":9,"id":10,"name":11,"modelId":12,"published":13,"stageModifiedSincePublish":6,"query":14,"data":15,"variations":50,"lastUpdated":51,"firstPublished":52,"testRatio":33,"createdBy":53,"lastUpdatedBy":53,"folders":54,"meta":55,"rev":58},1742213002749,"efff2a27faf4408e9f908eba4b5542fe","inductive-automation","1c6207a5f24948ab82d4a0b17f251193","published",[],{"testimonial":16,"description":43,"type":19,"link":44,"title":47,"testimonialLink":48,"image":49},{"@type":17,"id":18,"model":19,"value":20},"@builder.io/core:Reference","f028f2b685bb47cd8bf9e82a26dd5a79","testimonial",{"query":21,"folders":22,"createdDate":23,"id":18,"name":24,"modelId":25,"published":13,"data":26,"variations":30,"lastUpdated":31,"firstPublished":32,"testRatio":33,"createdBy":34,"lastUpdatedBy":34,"meta":35,"rev":42},[],[],1735823466309,"We found Push to be more accurate when compared to competitors and the browser agent offered features that others couldn’t match.","42035571a56940ac98bff4544aa79aa5",{"author":27,"jobTitle":28,"quote":24,"image":29},"Jason Waits","\u003Cp>CISO at Inductive Automation\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Ff04c0c0689ce4a89ac0f0708d78c0a07",{},1735910703862,1735823501152,1,"ST0tXQM8slWpFrmioqKHmENB2qe2",{"kind":36,"lastPreviewUrl":37,"breakpoints":38,"hasAutosaves":41},"data","",{"small":39,"medium":40},640,768,true,"3v32gocrrqz","Join the industry's top security minds as they break down the browser attack landscape.",{"url":45,"text":46},"https://pushsecurity.com/webinar/state-of-browser-security","Save Your Spot","State of Browser Attacks Series","/customer-stories/inductive-automation","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fe94fca10aa7b46ac8052b7ea22de54cd",{},1776257019270,1742221533648,"CydmZnOWU1XuAaLhEDCoYNM4Z8W2",[],{"breakpoints":56,"kind":36,"lastPreviewUrl":37,"hasAutosaves":6},{"xsmall":57,"small":39,"medium":40},320,"motto9r9yg",{"createdDate":60,"id":61,"name":62,"modelId":12,"published":13,"query":63,"data":64,"variations":69,"lastUpdated":70,"firstPublished":71,"testRatio":33,"createdBy":53,"lastUpdatedBy":72,"folders":73,"meta":74,"rev":58},1742208588866,"1c7a4e423bf54ac1a328bb4063459ef2","Banner",[],{"type":65,"url":66,"text":67,"link":68},"web-banner","https://pushsecurity.com/resources/browser-attacks-report","Get our latest report analyzing browser attack techniques in 2026",{},{},1774258294825,1742208637545,"jKjF9r5jcvXU8tzZEfFQm31Iyvr2",[],{"kind":36,"lastPreviewUrl":37,"breakpoints":75,"hasAutosaves":41},{"xsmall":57,"small":39,"medium":40},{"createdDate":77,"id":78,"name":79,"modelId":12,"published":13,"stageModifiedSincePublish":6,"query":80,"data":81,"variations":89,"lastUpdated":90,"firstPublished":91,"testRatio":33,"createdBy":53,"lastUpdatedBy":53,"folders":92,"meta":93,"rev":58},1742208469288,"6763051b201f44a0838c6400c580ca67","Resource highlight",[],{"image":82,"type":83,"description":84,"link":85,"title":88},"https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F7b4a5ebf81d64e8c9d7fc35f6c96c4a9","resource","Learn about the latest techniques being used in the wild.",{"url":86,"text":87},"/resources/browser-attacks-report","Download now","Report: 2026 Browser Attack Techniques",{},1776255866789,1742208570400,[],{"kind":36,"lastPreviewUrl":37,"breakpoints":94,"hasAutosaves":6},{"xsmall":57,"small":39,"medium":40},{"createdDate":96,"id":97,"name":98,"modelId":99,"published":13,"query":100,"data":101,"variations":145,"lastUpdated":146,"firstPublished":147,"testRatio":33,"createdBy":34,"lastUpdatedBy":148,"folders":149,"meta":150,"rev":154},1774965361051,"fd266d0172cc47429be7ad10f48c99ad","always visible banner","0678d178ec8b41efb8a23c09dba7874d",[],{"ctaText":102,"text":103,"url":37,"blocks":104,"state":141},"ewrererw","testrfesssssssssss",[105,129],{"@type":106,"@version":107,"id":108,"component":109,"responsiveStyles":119},"@builder.io/sdk:Element",2,"builder-ca12c06a52de41d7b8743da53118cd38",{"name":110,"tag":110,"options":111,"isRSC":118},"TopBannerContent",{"text":112,"ctaText":46,"url":45,"mainText":113,"cta":116},"New Webinar Series: Join John Hammond, Troy Hunt, and Matt Johansen for the State of Browser Attacks",{"content":114,"fontSize":115},"\u003Cp>New Webinar Series: Join John Hammond, Troy Hunt, and Matt Johansen for the State of Browser Attacks\u003C/p>","text-base",{"content":117,"fontSize":115,"url":45},"\u003Cp>\u003Cstrong style=\"font-weight:700;\">Save Your Spot\u003C/strong>\u003C/p>\n",null,{"large":120},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"marginTop":126,"marginBottom":126,"fontSize":127,"fontWeight":128},"flex","column","relative","0","border-box",".56rem","1.125rem","700",{"id":130,"@type":106,"tagName":131,"properties":132,"responsiveStyles":136},"builder-pixel-08zrjigffq5t","img",{"src":133,"aria-hidden":134,"alt":37,"role":135,"width":124,"height":124},"https://cdn.builder.io/api/v1/pixel?apiKey=f3a1111ff5be48cdbb123cd9f5795a05","true","presentation",{"large":137},{"height":124,"width":124,"display":138,"opacity":124,"overflow":139,"pointerEvents":140},"block","hidden","none",{"deviceSize":142,"location":143},"large",{"path":37,"query":144},{},{},1775137295127,1774968080803,"ax7YYfD0OCeqT1Vxxv1G4FUbqVr1",[],{"breakpoints":151,"hasLinks":6,"kind":152,"lastPreviewUrl":153,"hasAutosaves":6},{"xsmall":57,"small":39,"medium":40},"component","https://pushsecurity.com/?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditCode%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CeditProjects%2CmodifyMcpServers%2CmodifyWorkflowIntegrations%2CmodifyProjectSettings%2CconnectCodeRepository%2CcreateProjects%2CindexDesignSystems%2CsendPullRequests%2CmergePullRequests&builder.user.role.name=Developer&builder.user.role.id=developer&builder.cachebust=true&builder.preview=always-visible-banner&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.always-visible-banner=fd266d0172cc47429be7ad10f48c99ad&builder.overrides.fd266d0172cc47429be7ad10f48c99ad=fd266d0172cc47429be7ad10f48c99ad&builder.options.locale=Default","2lvuonnywj",[156,180],{"createdDate":157,"id":158,"name":159,"modelId":160,"published":13,"stageModifiedSincePublish":6,"query":161,"data":162,"variations":173,"lastUpdated":174,"firstPublished":175,"testRatio":33,"createdBy":53,"lastUpdatedBy":53,"folders":176,"meta":177,"rev":179},1776247359804,"9136a8f18b3b4a6ba29b8653a99372b1","testimonial-inductive-automation","20d9eaa352304613b3d1a794b400703d",[],{"link":163,"type":19,"testimonialLink":48,"testimonial":164},{},{"@type":17,"id":18,"model":19,"value":165},{"query":166,"folders":167,"createdDate":23,"id":18,"name":24,"modelId":25,"published":13,"data":168,"variations":169,"lastUpdated":31,"firstPublished":32,"testRatio":33,"createdBy":34,"lastUpdatedBy":34,"meta":170,"rev":172},[],[],{"author":27,"jobTitle":28,"quote":24,"image":29},{},{"kind":36,"lastPreviewUrl":37,"breakpoints":171,"hasAutosaves":41},{"small":39,"medium":40},"7t755zfvte3",{},1776247404986,1776247404973,[],{"breakpoints":178,"kind":36,"lastPreviewUrl":37,"hasAutosaves":6},{"xsmall":57,"small":39,"medium":40},"4moh0qpywtr",{"createdDate":181,"id":182,"name":88,"modelId":160,"published":13,"meta":183,"stageModifiedSincePublish":6,"query":185,"data":186,"variations":207,"lastUpdated":208,"firstPublished":209,"testRatio":33,"createdBy":53,"lastUpdatedBy":53,"folders":210,"rev":179},1776255761419,"05a9322735fc427db12e2740e4302300",{"breakpoints":184,"kind":36,"lastPreviewUrl":37,"hasAutosaves":6},{"xsmall":57,"small":39,"medium":40},[],{"testimonial":187,"link":206,"type":83,"title":88,"description":84,"image":82},{"@type":17,"id":188,"model":19,"value":189},"192acbb1f9ca4cac918c0ec435a8bae3",{"query":190,"folders":191,"createdDate":192,"id":188,"name":193,"modelId":25,"published":13,"data":194,"variations":200,"lastUpdated":201,"firstPublished":202,"testRatio":33,"createdBy":34,"lastUpdatedBy":53,"meta":203,"rev":205},[],[],1728981467463,"Push does for identity what CrowdStrike did for the endpoint",{"video":195,"jobTitle":196,"author":197,"qoute":37,"quote":198,"image":199},"https://cdn.builder.io/o/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F8b30e8ca50064058bbaef0f3c6164575%2Fcompressed?apiKey=f3a1111ff5be48cdbb123cd9f5795a05&token=8b30e8ca50064058bbaef0f3c6164575&alt=media&optimized=true","\u003Cp>Deputy CISO at Microsoft\u003C/p>\u003Cp>Former LinkedIn, Slack, Palantir\u003C/p>","Geoff Belknap","Push does for identity what CrowdStrike did for the endpoint.","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F748f0ad0a5064a00a13f4721fcc8dea1",{},1742902158597,1728981782923,{"kind":36,"lastPreviewUrl":37,"breakpoints":204,"hasAutosaves":41},{"small":39,"medium":40},"6s8ic0w0ao6",{"text":87,"url":86},{},1776255810913,1776255810900,[],[212,235],{"createdDate":213,"id":214,"name":88,"modelId":215,"published":13,"meta":216,"stageModifiedSincePublish":6,"query":218,"data":219,"variations":230,"lastUpdated":231,"firstPublished":232,"testRatio":33,"createdBy":53,"lastUpdatedBy":53,"folders":233,"rev":234},1776256900280,"1f429607996e4e5fae8fe3f9b9610e55","4829faa81e7c4ee8bd2d000e160e8d3c",{"breakpoints":217,"kind":36,"lastPreviewUrl":37,"hasAutosaves":6},{"xsmall":57,"small":39,"medium":40},[],{"testimonial":220,"link":229,"type":83,"title":88,"description":84,"image":82},{"@type":17,"id":188,"model":19,"value":221},{"query":222,"folders":223,"createdDate":192,"id":188,"name":193,"modelId":25,"published":13,"data":224,"variations":225,"lastUpdated":201,"firstPublished":202,"testRatio":33,"createdBy":34,"lastUpdatedBy":53,"meta":226,"rev":228},[],[],{"video":195,"jobTitle":196,"author":197,"qoute":37,"quote":198,"image":199},{},{"kind":36,"lastPreviewUrl":37,"breakpoints":227,"hasAutosaves":41},{"small":39,"medium":40},"r77qqueuo3j",{"text":87,"url":86},{},1776256937553,1776256937540,[],"q0jkez80wkg",{"createdDate":236,"id":237,"name":11,"modelId":215,"published":13,"stageModifiedSincePublish":6,"query":238,"data":239,"variations":250,"lastUpdated":251,"firstPublished":252,"testRatio":33,"createdBy":53,"lastUpdatedBy":53,"folders":253,"meta":254,"rev":234},1776256949234,"ce043785b71b4ece98eac811ecf4ba10",[],{"link":240,"type":19,"testimonial":241,"testimonialLink":48},{},{"@type":17,"id":18,"model":19,"value":242},{"query":243,"folders":244,"createdDate":23,"id":18,"name":24,"modelId":25,"published":13,"data":245,"variations":246,"lastUpdated":31,"firstPublished":32,"testRatio":33,"createdBy":34,"lastUpdatedBy":34,"meta":247,"rev":249},[],[],{"author":27,"jobTitle":28,"quote":24,"image":29},{},{"kind":36,"lastPreviewUrl":37,"breakpoints":248,"hasAutosaves":41},{"small":39,"medium":40},"mnaneamy308",{},1776256974140,1776256974130,[],{"breakpoints":255,"kind":36,"lastPreviewUrl":37,"hasAutosaves":6},{"xsmall":57,"small":39,"medium":40},[257,441,560,679,797,917,1037,1157],{"createdDate":258,"id":259,"name":260,"modelId":261,"published":13,"stageModifiedSincePublish":6,"query":262,"data":268,"variations":429,"lastUpdated":430,"firstPublished":431,"testRatio":33,"screenshot":432,"createdBy":34,"lastUpdatedBy":433,"folders":434,"meta":435,"rev":440},1744829487099,"387451215c314dd5bd654668cdc1a197","Zero-day phishing","cca4143377554c5a9163cc203a8ed2ba",[263],{"@type":264,"property":265,"operator":266,"value":267},"@builder.io/core:Query","urlPath","is","/uc/zero-day-phishing-protection",{"inputs":269,"customFonts":270,"seoTitle":318,"title":318,"tsCode":37,"seoDescription":319,"fontAwesomeIcon":320,"jsCode":37,"blocks":321,"url":267,"state":426},[],[271],{"family":272,"kind":273,"version":274,"lastModified":275,"files":276,"category":295,"menu":296,"subsets":297,"variants":300},"DM Sans","webfonts#webfont","v14","2023-07-13",{"100":277,"200":278,"300":279,"500":280,"600":281,"700":282,"800":283,"900":284,"800italic":285,"900italic":286,"700italic":287,"100italic":288,"italic":289,"regular":290,"200italic":291,"500italic":292,"300italic":293,"600italic":294},"https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwAop1hTmf3ZGMZpg.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwAIpxhTmf3ZGMZpg.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwA_JxhTmf3ZGMZpg.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwAkJxhTmf3ZGMZpg.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwAfJthTmf3ZGMZpg.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwARZthTmf3ZGMZpg.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwAIpthTmf3ZGMZpg.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwAC5thTmf3ZGMZpg.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2rp2ywxg089UriCZaSExd86J3t9jz86Mvy4qCRAL19DksVat8JCm3zRmYJpso5.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2rp2ywxg089UriCZaSExd86J3t9jz86Mvy4qCRAL19DksVat8gCm3zRmYJpso5.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2rp2ywxg089UriCZaSExd86J3t9jz86Mvy4qCRAL19DksVat9uCm3zRmYJpso5.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2rp2ywxg089UriCZaSExd86J3t9jz86Mvy4qCRAL19DksVat-JDG3zRmYJpso5.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2rp2ywxg089UriCZaSExd86J3t9jz86Mvy4qCRAL19DksVat-JDW3zRmYJpso5.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwAopxhTmf3ZGMZpg.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2rp2ywxg089UriCZaSExd86J3t9jz86Mvy4qCRAL19DksVat8JDW3zRmYJpso5.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2rp2ywxg089UriCZaSExd86J3t9jz86Mvy4qCRAL19DksVat-7DW3zRmYJpso5.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2rp2ywxg089UriCZaSExd86J3t9jz86Mvy4qCRAL19DksVat_XDW3zRmYJpso5.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2rp2ywxg089UriCZaSExd86J3t9jz86Mvy4qCRAL19DksVat9XCm3zRmYJpso5.ttf","sans-serif","https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwAopxRT23z.ttf",[298,299],"latin","latin-ext",[301,302,303,304,305,306,128,307,308,309,310,311,312,313,314,315,316,317],"100","200","300","regular","500","600","800","900","100italic","200italic","300italic","italic","500italic","600italic","700italic","800italic","900italic","Zero-day phishing protection","Detect phishing TTPs directly in the browser and stop credential theft.","faFishingRod",[322,421],{"@type":106,"@version":107,"tagName":323,"id":324,"children":325},"div","builder-76c6b8d1499346c7bc1fd56ae4e93638",[326,343,351,358,370,385,396,407,413],{"@type":106,"@version":107,"layerName":327,"id":328,"component":329,"responsiveStyles":340},"UseCaseHero","builder-5228fe062bef4a40a91e43f1112832fa",{"name":327,"options":330,"isRSC":118},{"title":318,"description":331,"points":332,"video":339},"\u003Cp>Push detects phishing as it happens. Autonomous agents hunt for new phishing techniques, identify kit signatures, and deploy detections within minutes of a new attack being analyzed. From cloned login pages to AiTM credential harvesting, Push sees what traditional filters miss and stops threats before they escalate.\u003C/p>",[333,335,337],{"item":334},"Detect phishing that bypasses traditional filters, including AiTM, SSO password theft, and fake login pages",{"item":336},"Stop never-before-seen attacks with AI-native behavioral and on-page analysis inside the browser",{"item":338},"Investigate faster with unified browser, user, and page context","https://cdn.builder.io/o/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F40433ceeb4f94b43a82e039a0f4fd411%2Fcompressed?apiKey=f3a1111ff5be48cdbb123cd9f5795a05&token=40433ceeb4f94b43a82e039a0f4fd411&alt=media&optimized=true",{"large":341},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":342},"transparent",{"@type":106,"@version":107,"id":344,"component":345,"responsiveStyles":348},"builder-96634044407e491299e291ed64669e39",{"name":346,"options":347,"isRSC":118},"TrustedBy",{"AllPartners":41,"backgroundTransparent":6},{"large":349},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":350},"#000",{"@type":106,"@version":107,"id":352,"component":353,"responsiveStyles":356},"builder-2c3768f930534557bb8978e32b6a6a0f",{"name":354,"options":355,"isRSC":118},"Diagonal",{"darkMode":41},{"large":357},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"layerName":359,"id":360,"component":361,"responsiveStyles":368},"TextImageBlockVertical","builder-7c3c1c2840424db2ad2ccbfaf382dd64",{"name":359,"tag":359,"options":362,"isRSC":118},{"darkMode":6,"maxWidth":363,"maxTextWidth":364,"title":365,"description":366,"animatedTitle":37,"image":367,"reverse":6,"descriptionPaddingHorizontal":118},1200,800,"\u003Ch2>Why stop at the inbox?\u003C/h2>","\u003Cp>Phishing attacks have evolved. Whether attackers lure users with QR codes, instant messages, or OAuth consent screens, the outcome is the same: it plays out in the browser. Push gives you real-time detection for in-browser threats, stopping phishing and consent-based attacks before they lead to compromise\u003C/p>\u003Cp>\u003Cbr>\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F7fdcac241f0e4a049166d7076858adeb",{"large":369},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":371,"component":372,"responsiveStyles":380},"builder-41c978b3669749cf947e622b4e79e4d7",{"name":373,"options":374,"isRSC":118},"TextImageBlockHorizontal",{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":376,"title":377,"description":378,"reverse":41,"image":379},600,100,"\u003Cp>Detect phishing at the edge\u003C/p>","\u003Cp>Push uses industry-first telemetry to detect phishing based on behavior, not static indicators. Autonomous agents analyze how phishing pages behave and how users interact with them, uncovering fake logins, credential theft, and phishing kits the moment they load in the browser.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F9df3d180c97b4e61af142af2ccd68721",{"large":381},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"fontFamily":382,"paddingTop":383,"marginTop":384},"DM Sans, sans-serif","20px","0px",{"@type":106,"@version":107,"id":386,"component":387,"responsiveStyles":393},"builder-d2a7bc941feb43cdb898bc116b203cf9",{"name":373,"options":388,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":389,"title":390,"description":391,"reverse":6,"image":392},120,"\u003Ch2>Go beyond blocklists and IOCs\u003C/h2>","\u003Cp>Push goes beyond URLs and easy-to-change indicators. It reads the full phishing playbook like script behavior, session hijacks, DOM changes, user inputs, then connects the dots in real time. This gives your team a complete picture of how the phishing attempt worked, not just an alert.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fabfd58db169b433e96d3f1261797156e",{"large":394},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":395},"36px",{"@type":106,"@version":107,"layerName":373,"id":397,"component":398,"responsiveStyles":404},"builder-42c32198083f4880acb37c5cb76934da",{"name":373,"options":399,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":400,"title":401,"description":402,"reverse":41,"image":403},140,"\u003Ch2>Enhance your phishing response\u003C/h2>","\u003Cp>When phishing enters your environment, speed matters. Push gives you instant access to the telemetry that counts like session data, user behavior, and page activity, so you can investigate fast, trigger in-browser prompts, or forward alerts to your SIEM or SOAR for response. All in real time, right from the browser.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fbb195aec46904056b85e8688629e558e",{"large":405},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":406},"47px",{"@type":106,"@version":107,"id":408,"component":409,"responsiveStyles":411},"builder-9a95b9cbc4854421a92ef7b90f6c7adb",{"name":354,"options":410,"isRSC":118},{"darkMode":6},{"large":412},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":414,"component":415,"responsiveStyles":419},"builder-0afa17a9f25c4661a90f314d5578aa18",{"name":416,"tag":416,"options":417,"isRSC":118},"LatestResources",{"sectionHeading":37,"customClass":418},"bg-black",{"large":420},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"id":422,"@type":106,"tagName":131,"properties":423,"responsiveStyles":424},"builder-pixel-21yj6h3p4wh",{"src":133,"aria-hidden":134,"alt":37,"role":135,"width":124,"height":124},{"large":425},{"height":124,"width":124,"display":138,"opacity":124,"overflow":139,"pointerEvents":140},{"deviceSize":142,"location":427},{"path":37,"query":428},{},{},1776275046831,1745499158657,"https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fff60c30a8442489c8ed7e0af9599d14f","kYgMv6WsbvfmlOUYqR2SFwGzw6e2",[],{"lastPreviewUrl":436,"winningTest":118,"breakpoints":437,"kind":438,"hasLinks":6,"originalContentId":439,"hasAutosaves":6},"https://pushsecurity.com/uc/zero-day-phishing-protection?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CcreateProjects%2CsendPullRequests&builder.user.role.name=Designer&builder.user.role.id=creator&builder.cachebust=true&builder.preview=use-case-page&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.use-case-page=387451215c314dd5bd654668cdc1a197&builder.overrides.387451215c314dd5bd654668cdc1a197=387451215c314dd5bd654668cdc1a197&builder.overrides.use-case-page:/uc/zero-day-phishing-protection=387451215c314dd5bd654668cdc1a197&builder.options.locale=Default",{"xsmall":57,"small":39,"medium":40},"page","2daa5670b8504fc7ba4700633e8bd921","atvz4dp24b7",{"createdDate":442,"id":443,"name":444,"modelId":261,"published":13,"stageModifiedSincePublish":6,"query":445,"data":448,"variations":552,"lastUpdated":553,"firstPublished":554,"testRatio":33,"screenshot":555,"createdBy":34,"lastUpdatedBy":433,"folders":556,"meta":557,"rev":440},1756833377777,"54f8256648f54d439303734b1e69221b","Browser extension security",[446],{"@type":264,"property":265,"operator":266,"value":447},"/uc/browser-extension-security",{"seoDescription":449,"jsCode":37,"fontAwesomeIcon":450,"tsCode":37,"title":444,"seoTitle":444,"customFonts":451,"inputs":456,"blocks":457,"url":447,"state":549},"Shine a light on risky browser extensions.","faPuzzlePiece",[452],{"kind":273,"family":272,"version":274,"files":453,"category":295,"lastModified":275,"subsets":454,"variants":455,"menu":296},{"100":277,"200":278,"300":279,"500":280,"600":281,"700":282,"800":283,"900":284,"100italic":288,"italic":289,"regular":290,"900italic":286,"800italic":285,"700italic":287,"200italic":291,"300italic":293,"500italic":292,"600italic":294},[298,299],[301,302,303,304,305,306,128,307,308,309,310,311,312,313,314,315,316,317],[],[458,544],{"@type":106,"@version":107,"tagName":323,"id":459,"meta":460,"children":461},"builder-71d0648c1d2f4ede8d0d0b5b28b7b94c",{"previousId":324},[462,478,485,492,501,511,521,531,538],{"@type":106,"@version":107,"id":463,"meta":464,"component":465,"responsiveStyles":476},"builder-ff325b4b8fad4edea53f38865947e854",{"previousId":328},{"name":327,"options":466,"isRSC":118},{"title":444,"description":467,"points":468,"video":475},"\u003Cp>Browser extensions introduce new code, new permissions, and new potential for risk. Many include AI features, and most go completely unnoticed. Push gives you full visibility into every extension used across your workforce, across major browsers, so you can uncover shadow IT, assess risky permissions, and block unsafe tools before they lead to compromise.\u003C/p>",[469,471,473],{"item":470},"Discover every browser extension in use",{"item":472},"Spot risky or unsanctioned behavior",{"item":474},"Make informed decisions on extension policy","https://cdn.builder.io/o/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fc538aad95d7f403aa3c3551af72f67c0?alt=media&token=1411fa6d-2eac-4e6c-94bf-ea117da12d67&apiKey=f3a1111ff5be48cdbb123cd9f5795a05",{"large":477},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":342},{"@type":106,"@version":107,"id":479,"meta":480,"component":481,"responsiveStyles":483},"builder-fb89d128c64e47cf9cbb11d90fc24523",{"previousId":344},{"name":346,"options":482,"isRSC":118},{"AllPartners":41,"backgroundTransparent":6},{"large":484},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":350},{"@type":106,"@version":107,"id":486,"meta":487,"component":488,"responsiveStyles":490},"builder-54388d35126c4d0096eeebaf8c4448cd",{"previousId":352},{"name":354,"options":489,"isRSC":118},{"darkMode":41},{"large":491},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"layerName":359,"id":493,"component":494,"responsiveStyles":499},"builder-3c8fa6785dd6466abf52a2470d66d85a",{"name":359,"tag":359,"options":495,"isRSC":118},{"darkMode":6,"maxWidth":363,"maxTextWidth":364,"title":496,"description":497,"image":498,"reverse":6},"\u003Ch2>Take control of browser extensions\u003C/h2>","\u003Cp>Attackers are increasingly using malicious browser extensions to gain access to data processed and stored in the browser. And the problem is, most security teams have no visibility into what extensions are being used. Push changes that. With browser-native telemetry, the Push extension continuously inventories browser extensions across your environment, flags the risky ones, and gives you intelligence to act.&nbsp;\u003C/p>\u003Cp>\u003Cbr>\u003C/p>\u003Cp>\u003Cbr>\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F0a004f16a6874f4c8fdf14344acc9fec",{"large":500},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":502,"meta":503,"component":504,"responsiveStyles":509},"builder-93738f98109a4009affb349afd7bb182",{"previousId":371},{"name":373,"options":505,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":376,"title":506,"description":507,"reverse":41,"image":508},"\u003Ch2>Discover every extension in use\u003C/h2>","\u003Cp>Push gives you structured, searchable data about every extension in your environment, so you’re not just seeing what’s there, but also understanding how it got there, what it can do, and who it affects. It’s the kind of granular insight that’s nearly impossible to get from traditional tools, and it lays the groundwork for better policy decisions and faster investigations.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F0e5727ca99474f14b1b7916bf6bbb782",{"large":510},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"fontFamily":382,"paddingTop":383,"marginTop":384},{"@type":106,"@version":107,"id":512,"meta":513,"component":514,"responsiveStyles":519},"builder-83393acb12ee4fdd840839185b51edb4",{"previousId":386},{"name":373,"options":515,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":389,"title":516,"description":517,"reverse":6,"image":518},"\u003Ch2>Spot risky or malicious extensions\u003C/h2>","\u003Cp>Push highlights extensions with dangerous permissions, broad access, or poor reputations. This includes AI extensions that request access far beyond what their stated purpose requires. You can quickly detect sideloaded, manually installed, or development-mode extensions that bypass normal controls. And because Push shows you who’s using them and where, you can respond precisely and effectively.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fa104d58c8da34fbb8901f738fb21453b",{"large":520},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":395},{"@type":106,"@version":107,"layerName":373,"id":522,"meta":523,"component":524,"responsiveStyles":529},"builder-da98e3de949646d89c53a0d1c2784664",{"previousId":397},{"name":373,"options":525,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":400,"title":526,"description":527,"reverse":41,"image":528},"\u003Ch2>Accelerate security reviews\u003C/h2>","\u003Cp>Most teams have extension policies, they just don’t have the data to enforce them. Push reveals how each extension entered your environment, whether it was installed manually, sideloaded, or deployed in dev mode. You’ll see which users are running what, and where, so you can surface violations, investigate quickly, and respond with confidence.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F229f355be6f243b180f410d237a75bb3",{"large":530},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":406},{"@type":106,"@version":107,"id":532,"meta":533,"component":534,"responsiveStyles":536},"builder-1a689287d1a1418997d57db578a71105",{"previousId":408},{"name":354,"options":535,"isRSC":118},{"darkMode":6},{"large":537},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":539,"component":540,"responsiveStyles":542},"builder-feb4e75029f84c10b6498ef1f8f79128",{"name":416,"tag":416,"options":541,"isRSC":118},{"sectionHeading":37,"customClass":418},{"large":543},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"id":545,"@type":106,"tagName":131,"properties":546,"responsiveStyles":547},"builder-pixel-0edn39avfcei",{"src":133,"aria-hidden":134,"alt":37,"role":135,"width":124,"height":124},{"large":548},{"height":124,"width":124,"display":138,"opacity":124,"overflow":139,"pointerEvents":140},{"deviceSize":142,"location":550},{"path":37,"query":551},{},{},1776275365038,1757000441666,"https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F8d496cf111644ee5afcc046b72d1ca5a",[],{"kind":438,"winningTest":118,"breakpoints":558,"lastPreviewUrl":559,"hasLinks":6,"originalContentId":259,"hasAutosaves":6},{"xsmall":57,"small":39,"medium":40},"https://pushsecurity.com/uc/browser-extension-security?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CcreateProjects%2CsendPullRequests&builder.user.role.name=Designer&builder.user.role.id=creator&builder.cachebust=true&builder.preview=use-case-page&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.use-case-page=54f8256648f54d439303734b1e69221b&builder.overrides.54f8256648f54d439303734b1e69221b=54f8256648f54d439303734b1e69221b&builder.overrides.use-case-page:/uc/browser-extension-security=54f8256648f54d439303734b1e69221b&builder.options.locale=Default",{"createdDate":561,"id":562,"name":563,"modelId":261,"published":13,"query":564,"data":567,"variations":670,"lastUpdated":671,"firstPublished":672,"testRatio":33,"screenshot":673,"createdBy":34,"lastUpdatedBy":674,"folders":675,"meta":676,"rev":440},1744923509705,"94bebb7bb99d48629ad157e80cf4d81d","Account takeover detection",[565],{"@type":264,"property":265,"operator":266,"value":566},"/uc/account-takeover-detection",{"title":563,"customFonts":568,"jsCode":37,"seoTitle":563,"seoDescription":573,"fontAwesomeIcon":574,"tsCode":37,"blocks":575,"url":566,"state":667},[569],{"kind":273,"category":295,"variants":570,"menu":296,"files":571,"family":272,"subsets":572,"version":274,"lastModified":275},[301,302,303,304,305,306,128,307,308,309,310,311,312,313,314,315,316,317],{"100":277,"200":278,"300":279,"500":280,"600":281,"700":282,"800":283,"900":284,"300italic":293,"500italic":292,"800italic":285,"700italic":287,"italic":289,"900italic":286,"600italic":294,"200italic":291,"regular":290,"100italic":288},[298,299],"Stop ATO with stolen credential and compromised token detection.","faUserSecret",[576,662],{"@type":106,"@version":107,"tagName":323,"id":577,"meta":578,"children":579},"builder-e7913a774cae44c5a23d6081c5c30a52",{"previousId":324},[580,596,603,610,619,629,639,649,656],{"@type":106,"@version":107,"id":581,"meta":582,"component":583,"responsiveStyles":594},"builder-f1f1ab1601bc4c0f8c2a8aafd173675d",{"previousId":328},{"name":327,"options":584,"isRSC":118},{"title":563,"description":585,"points":586,"video":593},"\u003Cp>Attackers don’t need to phish, they just need a password that works. Push monitors for signs of credential-based attacks in real time, directly in the browser, catching account takeover attempts before the damage spreads. From ghost logins to credential stuffing, Push cuts off the paths attackers use to quietly slip in the back door.\u003C/p>\u003Cp>\u003Cbr>\u003C/p>",[587,589,591],{"item":588},"Identify credential-based ATO as it unfolds",{"item":590},"Surface hijacked sessions and token misuse",{"item":592},"Strengthen authentication where your IdP can’t","https://cdn.builder.io/o/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fb4dd9db24bc9495b8a686b1b4d492016%2Fcompressed?apiKey=f3a1111ff5be48cdbb123cd9f5795a05&token=b4dd9db24bc9495b8a686b1b4d492016&alt=media&optimized=true",{"large":595},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":342},{"@type":106,"@version":107,"id":597,"meta":598,"component":599,"responsiveStyles":601},"builder-0bc0d1c78ece4994993c3a6427a4d533",{"previousId":344},{"name":346,"options":600,"isRSC":118},{"AllPartners":41,"backgroundTransparent":6},{"large":602},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":350},{"@type":106,"@version":107,"id":604,"meta":605,"component":606,"responsiveStyles":608},"builder-e45de8f3768c4f16938dbf78e4e87524",{"previousId":352},{"name":354,"options":607,"isRSC":118},{"darkMode":41},{"large":609},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":611,"component":612,"responsiveStyles":617},"builder-c98e8bfd341146c1b67c02d5698ff093",{"name":359,"tag":359,"options":613,"isRSC":118},{"darkMode":6,"maxWidth":363,"maxTextWidth":364,"title":614,"description":615,"image":616,"reverse":6},"\u003Ch2>Assume less. See more.\u003C/h2>","\u003Cp>Most account takeovers don’t start with a breach, they start with a login. Whether it’s a reused password, a local account, or an outdated login flow, Push shows you how accounts are actually accessed day to day, not just how policies say they should be. That means no more blind spots around ghost logins, bypassed SSO, or stale access paths that quietly persist.\u003C/p>\u003Cp>\u003Cbr>\u003C/p>\u003Cp>\u003Cbr>\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F18630ad2746d4eb7b7fcc0428b11a8f0",{"large":618},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":620,"meta":621,"component":622,"responsiveStyles":627},"builder-55c1fc38ddc04fd1a0d6a8e2fb819e00",{"previousId":371},{"name":373,"options":623,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":376,"title":624,"description":625,"reverse":41,"image":626},"\u003Ch2>Catch stolen credential use in real time\u003C/h2>","\u003Cp>Push monitors login activity directly in the browser to detect signs of credential-based attacks like leaked password use or suspicious login flows. By analyzing attacker TTPs instead of relying on known indicators, Push spots credential stuffing and account takeover attempts the moment they begin, not after they’ve succeeded.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F52b0123cac2c4dfdb1dc0af6adf9d603",{"large":628},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"fontFamily":382,"paddingTop":384,"marginTop":384},{"@type":106,"@version":107,"id":630,"meta":631,"component":632,"responsiveStyles":637},"builder-dfb31737b30948c6b95323655d571a50",{"previousId":386},{"name":373,"options":633,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":389,"title":634,"description":635,"reverse":6,"image":636},"\u003Ch2>Detect session hijacks and stealth access\u003C/h2>","\u003Cp>Attackers don’t always need a login screen, they often sidestep it entirely using stolen session tokens. Push detects when valid sessions are reused in unexpected ways, identifying hijacked sessions and stealth access attempts that traditional tools miss. Because we monitor directly in the browser, you see what’s happening inside active sessions in real time.\u003C/p>\u003Cp>\u003Cbr>\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F94a6859a99e04d309ffe5841f3dbdf5c",{"large":638},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":395},{"@type":106,"@version":107,"layerName":373,"id":640,"meta":641,"component":642,"responsiveStyles":647},"builder-f7585b90eb974d03a7dc7eae5b58d227",{"previousId":397},{"name":373,"options":643,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":400,"title":644,"description":645,"reverse":41,"image":646},"\u003Ch2>Harden accounts before they’re compromised\u003C/h2>","\u003Cp>Push goes beyond alerts. It identifies apps that still allow local logins, even when SSO is configured, so you can remove weak access paths. Push also flags users without MFA, reused work credentials, or weak passwords, and prompts users in-browser to fix risky behaviors before they’re exploited.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F01c1b638f1b6497093a4f2b8ceddb5bb",{"large":648},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":406},{"@type":106,"@version":107,"id":650,"meta":651,"component":652,"responsiveStyles":654},"builder-ad81d1e3afec49a791214194eae09bdc",{"previousId":408},{"name":354,"options":653,"isRSC":118},{"darkMode":6},{"large":655},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":657,"component":658,"responsiveStyles":660},"builder-8dac1aa4b9d148628d92252bd8eff822",{"name":416,"tag":416,"options":659,"isRSC":118},{"sectionHeading":37,"customClass":418},{"large":661},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"id":663,"@type":106,"tagName":131,"properties":664,"responsiveStyles":665},"builder-pixel-s5u3wmvz7jq",{"src":133,"aria-hidden":134,"alt":37,"role":135,"width":124,"height":124},{"large":666},{"height":124,"width":124,"display":138,"opacity":124,"overflow":139,"pointerEvents":140},{"deviceSize":142,"location":668},{"path":37,"query":669},{},{},1770892814499,1745499162732,"https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F58b660fa94aa4b30b0faeb9b663ae41a","SfUPqW5tkibIPby49keNFMdHFTr1",[],{"lastPreviewUrl":677,"hasLinks":6,"originalContentId":259,"breakpoints":678,"winningTest":118,"kind":438,"hasAutosaves":41},"https://pushsecurity.com/uc/account-takeover-detection?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditCode%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CeditProjects%2CmodifyMcpServers%2CmodifyWorkflowIntegrations%2CmodifyProjectSettings%2CconnectCodeRepository%2CcreateProjects%2CindexDesignSystems%2CsendPullRequests&builder.user.role.name=Developer&builder.user.role.id=developer&builder.cachebust=true&builder.preview=use-case-page&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.use-case-page=94bebb7bb99d48629ad157e80cf4d81d&builder.overrides.94bebb7bb99d48629ad157e80cf4d81d=94bebb7bb99d48629ad157e80cf4d81d&builder.overrides.use-case-page:/uc/account-takeover-detection=94bebb7bb99d48629ad157e80cf4d81d&builder.options.includeRefs=true&builder.options.enrich=true&builder.options.locale=Default",{"xsmall":57,"small":39,"medium":40},{"createdDate":680,"id":681,"name":682,"modelId":261,"published":13,"query":683,"data":686,"variations":789,"lastUpdated":790,"firstPublished":791,"testRatio":33,"screenshot":792,"createdBy":34,"lastUpdatedBy":674,"folders":793,"meta":794,"rev":440},1745009370904,"23eb48fb56d3451cab77cb6ed140ee6d","Attack path hardening",[684],{"@type":264,"property":265,"operator":266,"value":685},"/uc/attack-path-hardening",{"tsCode":37,"seoDescription":687,"jsCode":37,"customFonts":688,"fontAwesomeIcon":693,"seoTitle":682,"title":682,"blocks":694,"url":685,"state":786},"Harden access paths with visibility,  detection, and guardrails.",[689],{"kind":273,"files":690,"version":274,"lastModified":275,"subsets":691,"menu":296,"category":295,"variants":692,"family":272},{"100":277,"200":278,"300":279,"500":280,"600":281,"700":282,"800":283,"900":284,"regular":290,"italic":289,"800italic":285,"500italic":292,"600italic":294,"200italic":291,"900italic":286,"700italic":287,"100italic":288,"300italic":293},[298,299],[301,302,303,304,305,306,128,307,308,309,310,311,312,313,314,315,316,317],"faRadar",[695,781],{"@type":106,"@version":107,"tagName":323,"id":696,"meta":697,"children":698},"builder-1d8553eddcaa44d7bba9e2f4ca13af2a",{"previousId":577},[699,715,722,729,738,748,758,768,775],{"@type":106,"@version":107,"id":700,"meta":701,"component":702,"responsiveStyles":713},"builder-84fe3d7c85a743cf8cef649aa974f1ef",{"previousId":581},{"name":327,"options":703,"isRSC":118},{"title":682,"description":704,"points":705,"video":712},"\u003Cp>Push continuously monitors your environment for exposed login paths, weak credentials, and missing protections like MFA. It detects the gaps attackers exploit and helps you close them before they’re used.\u003C/p>",[706,708,710],{"item":707},"Find weak spots like reused passwords, local logins, and missing MFA",{"item":709},"Monitor how users actually log in across apps, flows, and tools",{"item":711},"Enforce secure access with in-browser guardrails","https://cdn.builder.io/o/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fdbdcf52892034f1bbddded77f753a343%2Fcompressed?apiKey=f3a1111ff5be48cdbb123cd9f5795a05&token=dbdcf52892034f1bbddded77f753a343&alt=media&optimized=true",{"large":714},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":342},{"@type":106,"@version":107,"id":716,"meta":717,"component":718,"responsiveStyles":720},"builder-b3f66f5b08054cc78a06fecfc3ae2337",{"previousId":597},{"name":346,"options":719,"isRSC":118},{"AllPartners":41,"backgroundTransparent":6},{"large":721},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":350},{"@type":106,"@version":107,"id":723,"meta":724,"component":725,"responsiveStyles":727},"builder-4c73418b84be49ed85e6e13d2625c5a0",{"previousId":604},{"name":354,"options":726,"isRSC":118},{"darkMode":41},{"large":728},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":730,"component":731,"responsiveStyles":736},"builder-dec0246085e1485c803f7152b1922a81",{"name":359,"tag":359,"options":732,"isRSC":118},{"darkMode":6,"maxWidth":363,"maxTextWidth":364,"title":733,"description":734,"image":735,"reverse":6},"\u003Ch2>Find the gaps that lead to compromise\u003C/h2>","\u003Cp>Misconfigurations don’t show up in your config files, they show up in how users actually access apps. Push monitors real login behavior in the browser, surfacing risky patterns like local login access, duplicate accounts, or missing protections that leave doors wide open.\u003C/p>\u003Cp>\u003Cbr>\u003C/p>\u003Cp>\u003Cbr>\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F309a59bba8d247a19476bb369397460e",{"large":737},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":739,"meta":740,"component":741,"responsiveStyles":746},"builder-ebf049a645604a249550996a88f8f3b6",{"previousId":620},{"name":373,"options":742,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":376,"title":743,"description":744,"reverse":41,"image":745},"\u003Ch2>See real login behavior\u003C/h2>","\u003Cp>Push watches authentication flows as they happen, giving you a live view of how users log in, which methods they choose, and where protections like MFA are missing. Plus, uncover every app and account in use, even shadow IT you didn’t know existed, without relying on stale config files or IdP assumptions. \u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fb51f6b0357cc451b87a7a5016d984e5e",{"large":747},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"fontFamily":382,"paddingTop":383,"marginTop":384},{"@type":106,"@version":107,"id":749,"meta":750,"component":751,"responsiveStyles":756},"builder-431d175c59004669b0b2776b07d71737",{"previousId":630},{"name":373,"options":752,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":389,"title":753,"description":754,"reverse":6,"image":755},"\u003Ch2>Find and fix posture drift\u003C/h2>","\u003Cp>Security posture isn’t static. Push continuously monitors for issues like missing MFA or legacy login methods. When something falls out of policy, you know immediately with custom notifications so you can act before it turns into risk.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F324e39127dfc41e592b1183dfb39892d",{"large":757},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":395},{"@type":106,"@version":107,"layerName":373,"id":759,"meta":760,"component":761,"responsiveStyles":766},"builder-3dffdcbe0a484e2ca4c03f019b6d40ee",{"previousId":640},{"name":373,"options":762,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":400,"title":763,"description":764,"reverse":41,"image":765},"\u003Ch2>Guide users with in-browser guardrails\u003C/h2>","\u003Cp>Push doesn’t just surface problems, it helps you fix them. When users sign in without MFA, reuse a password, or use insecure credentials, Push prompts them directly in the browser to secure their access. It’s faster, more effective, and actually gets results.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fee8b75d13e45488aba55434a8b49ebb0",{"large":767},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":406},{"@type":106,"@version":107,"id":769,"meta":770,"component":771,"responsiveStyles":773},"builder-976bc222cd7647ff905f1e01cfedc453",{"previousId":650},{"name":354,"options":772,"isRSC":118},{"darkMode":6},{"large":774},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":776,"component":777,"responsiveStyles":779},"builder-8c47ec2fd0f74382bb3e6c870555632c",{"name":416,"tag":416,"options":778,"isRSC":118},{"sectionHeading":37,"customClass":418},{"large":780},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"id":782,"@type":106,"tagName":131,"properties":783,"responsiveStyles":784},"builder-pixel-7akm7dayau8",{"src":133,"aria-hidden":134,"alt":37,"role":135,"width":124,"height":124},{"large":785},{"height":124,"width":124,"display":138,"opacity":124,"overflow":139,"pointerEvents":140},{"deviceSize":142,"location":787},{"path":37,"query":788},{},{},1770892844854,1745499166112,"https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F6ca12bf728a045f1a31d40c0beb3bfe5",[],{"kind":438,"lastPreviewUrl":795,"breakpoints":796,"hasLinks":6,"originalContentId":562,"winningTest":118,"hasAutosaves":6},"https://pushsecurity.com/uc/attack-path-hardening?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditCode%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CeditProjects%2CmodifyMcpServers%2CmodifyWorkflowIntegrations%2CmodifyProjectSettings%2CconnectCodeRepository%2CcreateProjects%2CindexDesignSystems%2CsendPullRequests&builder.user.role.name=Developer&builder.user.role.id=developer&builder.cachebust=true&builder.preview=use-case-page&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.use-case-page=23eb48fb56d3451cab77cb6ed140ee6d&builder.overrides.23eb48fb56d3451cab77cb6ed140ee6d=23eb48fb56d3451cab77cb6ed140ee6d&builder.overrides.use-case-page:/uc/attack-path-hardening=23eb48fb56d3451cab77cb6ed140ee6d&builder.options.includeRefs=true&builder.options.enrich=true&builder.options.locale=Default",{"xsmall":57,"small":39,"medium":40},{"createdDate":798,"id":799,"name":800,"modelId":261,"published":13,"query":801,"data":804,"variations":909,"lastUpdated":910,"firstPublished":911,"testRatio":33,"screenshot":912,"createdBy":34,"lastUpdatedBy":674,"folders":913,"meta":914,"rev":440},1761675020232,"ea4f309d2ffe46c5aa97ebf0fda4e2e3","ClickFix Protection",[802],{"@type":264,"property":265,"operator":266,"value":803},"/uc/clickfix-protection",{"seoDescription":805,"fontAwesomeIcon":806,"customFonts":807,"seoTitle":812,"jsCode":37,"tsCode":37,"title":812,"blocks":813,"url":803,"state":906},"Block attacks that trick users into running malicious code.","faLaptopCode",[808],{"files":809,"subsets":810,"menu":296,"version":274,"kind":273,"family":272,"lastModified":275,"variants":811,"category":295},{"100":277,"200":278,"300":279,"500":280,"600":281,"700":282,"800":283,"900":284,"200italic":291,"800italic":285,"700italic":287,"600italic":294,"100italic":288,"italic":289,"regular":290,"300italic":293,"500italic":292,"900italic":286},[298,299],[301,302,303,304,305,306,128,307,308,309,310,311,312,313,314,315,316,317],"ClickFix protection",[814,901],{"@type":106,"@version":107,"tagName":323,"id":815,"meta":816,"children":817},"builder-d7eefdde0f2a4b2b9de3dcb2978fd6cb",{"previousId":696},[818,834,841,848,858,868,878,888,895],{"@type":106,"@version":107,"id":819,"meta":820,"component":821,"responsiveStyles":832},"builder-56e2c54bcce040a4af8b92ae03706c12",{"previousId":700},{"name":327,"options":822,"isRSC":118},{"title":812,"description":823,"points":824,"image":831},"\u003Cp>ClickFix attacks are one of the fastest-growing threats, tricking users into copying malicious code from a webpage and running it locally. This technique bypasses traditional EDR, email gateways, and network filters, leading directly to ransomware and data theft. Push stops this attack at the source, in the browser, by detecting and blocking the malicious behavior before the user can ever paste the code.\u003C/p>\u003Cp>\u003Cbr>\u003C/p>",[825,827,829],{"item":826},"Detect ClickFix, FileFix, and fake CAPTCHA in the browser",{"item":828},"Block malicious copy-and-paste actions before code is executed",{"item":830},"See full telemetry into which users were targeted and what they saw","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F7b74af62889847ebb3927364485b0546",{"large":833},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":342},{"@type":106,"@version":107,"id":835,"meta":836,"component":837,"responsiveStyles":839},"builder-05f9614d4e3e4dc88b3ee8658f54e10e",{"previousId":716},{"name":346,"options":838,"isRSC":118},{"AllPartners":41,"backgroundTransparent":6},{"large":840},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":350},{"@type":106,"@version":107,"id":842,"meta":843,"component":844,"responsiveStyles":846},"builder-c4fb5179366243c1b6c32d368675cf47",{"previousId":723},{"name":354,"options":845,"isRSC":118},{"darkMode":41},{"large":847},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":849,"meta":850,"component":851,"responsiveStyles":856},"builder-261af50705fd445d8cca4a6ba20d5391",{"previousId":730},{"name":359,"tag":359,"options":852,"isRSC":118},{"darkMode":6,"maxWidth":363,"maxTextWidth":364,"title":853,"description":854,"reverse":6,"image":855},"\u003Ch2>Stop ClickFix-style attacks before they become a breach\u003C/h2>","\u003Cp>Traditional security tools are blind to malicious copy and paste attacks because the attack exploits a gap between the browser and the endpoint. EDR only sees the payload after it runs, and network tools see only part of the picture.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F98b2f7e08dec4eafaf8e24937605b8cf",{"large":857},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":859,"meta":860,"component":861,"responsiveStyles":866},"builder-7d21b8aab8064c40b1e5dd23c4749309",{"previousId":739},{"name":373,"options":862,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":376,"title":863,"description":864,"reverse":41,"image":865},"\u003Ch2>Discover lures at the source\u003C/h2>","\u003Cp>Push inspects page behavior to identify ClickFix attacks as they happen. By inspecting the page, its structure, and how the user interacts with it, Push can detect and block these in-browser threats in real time. This deep, TTP-based inspection spots the trap even on novel pages that are built to bypass traditional web filters and blocklists.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F665bf47e01544c75bf9ddafd3917927b",{"large":867},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"fontFamily":382,"paddingTop":383,"marginTop":384},{"@type":106,"@version":107,"id":869,"meta":870,"component":871,"responsiveStyles":876},"builder-fb91943adf6149259ed9e1e6566c9afe",{"previousId":749},{"name":373,"options":872,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":389,"title":873,"description":874,"reverse":6,"image":875},"\u003Ch2>Block the malicious action\u003C/h2>","\u003Cp>When Push detects a malicious script, it intercepts the user's action and blocks the code from being copied to the clipboard. The user is protected, the attack is stopped, and no malicious code ever reaches the endpoint. Unlike broad DLP tools, this action is surgical, targeting only malicious behavior without disrupting normal work.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F5ee68f81f1ac416685cbfe91298cf827",{"large":877},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":395},{"@type":106,"@version":107,"layerName":373,"id":879,"meta":880,"component":881,"responsiveStyles":886},"builder-bfac95fada864e5a8259b955b5b5f98b",{"previousId":759},{"name":373,"options":882,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":400,"title":883,"description":884,"reverse":41,"image":885},"\u003Ch2>Accelerate ClickFix investigations\u003C/h2>","\u003Cp>When an attack happens, knowing what the user saw or did is critical. Push provides rich browser session data for rapid investigation and containment. Security teams get detailed telemetry on which users were targeted, what lure they were served, and when the block occurred. This enables defenders to reconstruct what happened and respond quickly, even when other tools miss the activity entirely.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F6cdf2a8aeddc4e9a9023cbf974e40239",{"large":887},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":406},{"@type":106,"@version":107,"id":889,"meta":890,"component":891,"responsiveStyles":893},"builder-136892e831684a6987f87d3be67c33d1",{"previousId":769},{"name":354,"options":892,"isRSC":118},{"darkMode":6},{"large":894},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":896,"component":897,"responsiveStyles":899},"builder-dec26b739f2f42beb5a73cfc6c675b60",{"name":416,"tag":416,"options":898,"isRSC":118},{"sectionHeading":37,"customClass":418},{"large":900},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"id":902,"@type":106,"tagName":131,"properties":903,"responsiveStyles":904},"builder-pixel-zzjpxxgrc2l",{"src":133,"aria-hidden":134,"alt":37,"role":135,"width":124,"height":124},{"large":905},{"height":124,"width":124,"display":138,"opacity":124,"overflow":139,"pointerEvents":140},{"deviceSize":142,"location":907},{"path":37,"query":908},{},{},1770892881888,1761847585203,"https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F375467b8bef34ed1a8a1cc5b8b67d75f",[],{"lastPreviewUrl":915,"originalContentId":681,"winningTest":118,"hasLinks":6,"kind":438,"breakpoints":916,"hasAutosaves":6},"https://pushsecurity.com/uc/clickfix-protection?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditCode%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CeditProjects%2CmodifyMcpServers%2CmodifyWorkflowIntegrations%2CmodifyProjectSettings%2CconnectCodeRepository%2CcreateProjects%2CindexDesignSystems%2CsendPullRequests&builder.user.role.name=Developer&builder.user.role.id=developer&builder.cachebust=true&builder.preview=use-case-page&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.use-case-page=ea4f309d2ffe46c5aa97ebf0fda4e2e3&builder.overrides.ea4f309d2ffe46c5aa97ebf0fda4e2e3=ea4f309d2ffe46c5aa97ebf0fda4e2e3&builder.overrides.use-case-page:/uc/clickfix-protection=ea4f309d2ffe46c5aa97ebf0fda4e2e3&builder.options.includeRefs=true&builder.options.enrich=true&builder.options.locale=Default",{"xsmall":57,"small":39,"medium":40},{"createdDate":918,"id":919,"name":920,"modelId":261,"published":13,"query":921,"data":924,"variations":1029,"lastUpdated":1030,"firstPublished":1031,"testRatio":33,"screenshot":1032,"createdBy":34,"lastUpdatedBy":674,"folders":1033,"meta":1034,"rev":440},1745009743870,"a9d5556e77f84a37b5bd52310a7110c1","Incident response",[922],{"@type":264,"property":265,"operator":266,"value":923},"/uc/incident-response",{"seoDescription":925,"customFonts":926,"title":920,"jsCode":37,"fontAwesomeIcon":931,"seoTitle":932,"tsCode":37,"blocks":933,"url":923,"state":1026},"Investigate and respond faster with unique browser telemetry.",[927],{"kind":273,"subsets":928,"menu":296,"variants":929,"category":295,"family":272,"version":274,"lastModified":275,"files":930},[298,299],[301,302,303,304,305,306,128,307,308,309,310,311,312,313,314,315,316,317],{"100":277,"200":278,"300":279,"500":280,"600":281,"700":282,"800":283,"900":284,"900italic":286,"600italic":294,"200italic":291,"300italic":293,"100italic":288,"700italic":287,"800italic":285,"regular":290,"italic":289,"500italic":292},"faSatelliteDish","Browser based incident response",[934,1021],{"@type":106,"@version":107,"tagName":323,"id":935,"meta":936,"children":937},"builder-653c4aed737b4def88dc4cd2d695660a",{"previousId":696},[938,955,962,969,978,988,998,1008,1015],{"@type":106,"@version":107,"id":939,"meta":940,"component":941,"responsiveStyles":953},"builder-18190bd36518467d9154d27d7e945b9b",{"previousId":700},{"name":327,"options":942,"isRSC":118},{"title":943,"description":944,"points":945,"video":952},"Browser-based incident response","\u003Cp>Push gives you real-time visibility into what actually happened during a breach, right in the browser where the attack played out. From credential theft to session hijacking, Push captures high-fidelity telemetry so you can investigate quickly, contain confidently, and shut it down before it spreads.\u003C/p>\u003Cp>\u003Cbr>\u003C/p>",[946,948,950],{"item":947},"Reconstruct what happened with real browser session context",{"item":949},"Investigate faster with real-world session context",{"item":951},"Trigger response actions automatically through your SIEM or SOAR","https://cdn.builder.io/o/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fd00e39d3b6e346c296261d875cf55652%2Fcompressed?apiKey=f3a1111ff5be48cdbb123cd9f5795a05&token=d00e39d3b6e346c296261d875cf55652&alt=media&optimized=true",{"large":954},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":342},{"@type":106,"@version":107,"id":956,"meta":957,"component":958,"responsiveStyles":960},"builder-8a0a8ea63f5d48dd8a6726f2d49cf0ca",{"previousId":716},{"name":346,"options":959,"isRSC":118},{"AllPartners":41,"backgroundTransparent":6},{"large":961},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":350},{"@type":106,"@version":107,"id":963,"meta":964,"component":965,"responsiveStyles":967},"builder-2df65c3f54334df2b26e7cb744886cdc",{"previousId":723},{"name":354,"options":966,"isRSC":118},{"darkMode":41},{"large":968},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":970,"component":971,"responsiveStyles":976},"builder-2c32c869efc2423ab69ef06b150e9f97",{"name":359,"tag":359,"options":972,"isRSC":118},{"darkMode":6,"maxWidth":363,"maxTextWidth":364,"title":973,"description":974,"image":975,"reverse":6},"\u003Ch2>See attacks unfold, not just their aftermath\u003C/h2>","\u003Cp>Attacks happen in the browser, not in logs. Push captures what traditional tools miss: what users clicked, what loaded, what was entered, and how attackers moved. That gives you real-world evidence, not just assumptions, when every second matters.\u003C/p>\u003Cp>\u003Cbr>\u003C/p>\u003Cp>\u003Cbr>\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F36fc719bd1de4a38b916f4d25c81a26d",{"large":977},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":979,"meta":980,"component":981,"responsiveStyles":986},"builder-370e53c6016e432db01e9193a2ce90f6",{"previousId":739},{"name":373,"options":982,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":376,"title":983,"description":984,"reverse":41,"image":985},"\u003Ch2>Investigate faster with high-fidelity data\u003C/h2>","\u003Cp>Reconstructing an incident shouldn’t feel like guesswork. Push records detailed telemetry from inside the browser: page loads, credential inputs, DOM changes, session activity, user behavior. It’s structured, exportable, and ready to plug into your investigation workflows, so you can move fast without digging through proxy logs or relying on user reports.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fa6adda040e684e67a8d68a55c5ce5f6d",{"large":987},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"fontFamily":382,"paddingTop":384,"marginTop":384},{"@type":106,"@version":107,"id":989,"meta":990,"component":991,"responsiveStyles":996},"builder-a7f3767a8d184bd08fb24520bf210e95",{"previousId":749},{"name":373,"options":992,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":389,"title":993,"description":994,"reverse":6,"image":995},"\u003Ch2>Contain and respond in real time\u003C/h2>","\u003Cp>When something looks off, Push doesn’t just alert you, it gives you options. Guide users with in-browser prompts. Terminate sessions. Trigger SOAR workflows. Enrich SIEM alerts. Push gives you the context and control to stop spread before it starts.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fb3dedeed5aba4847a2c2d22e10d0ec12",{"large":997},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":395},{"@type":106,"@version":107,"layerName":373,"id":999,"meta":1000,"component":1001,"responsiveStyles":1006},"builder-b92036ee0ece4b32acdbdcc7c377366b",{"previousId":759},{"name":373,"options":1002,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":400,"title":1003,"description":1004,"reverse":41,"image":1005},"\u003Ch2>Prevent the next one\u003C/h2>","\u003Cp>Push helps you respond fast, but it also helps you fix what went wrong. It surfaces misconfigurations and risky behaviors that made the attack possible in the first place, then guides users in-browser to remediate. One tool. Full loop. No loose ends.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fc1ecc2d5d3814b62b072fac01827ff96",{"large":1007},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":406},{"@type":106,"@version":107,"id":1009,"meta":1010,"component":1011,"responsiveStyles":1013},"builder-5e8ae39655274de89da32ab573a2525a",{"previousId":769},{"name":354,"options":1012,"isRSC":118},{"darkMode":6},{"large":1014},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":1016,"component":1017,"responsiveStyles":1019},"builder-dfd6850cfb4741d2b8a0c16c2780f00a",{"name":416,"tag":416,"options":1018,"isRSC":118},{"sectionHeading":37,"customClass":418},{"large":1020},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"id":1022,"@type":106,"tagName":131,"properties":1023,"responsiveStyles":1024},"builder-pixel-z197gdgcmu",{"src":133,"aria-hidden":134,"alt":37,"role":135,"width":124,"height":124},{"large":1025},{"height":124,"width":124,"display":138,"opacity":124,"overflow":139,"pointerEvents":140},{"deviceSize":142,"location":1027},{"path":37,"query":1028},{},{},1770892908052,1745427419274,"https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fb07017bfd318431690a5bb35bda35b99",[],{"kind":438,"breakpoints":1035,"originalContentId":681,"winningTest":118,"lastPreviewUrl":1036,"hasLinks":6,"hasAutosaves":6},{"xsmall":57,"small":39,"medium":40},"https://pushsecurity.com/uc/incident-response?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditCode%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CeditProjects%2CmodifyMcpServers%2CmodifyWorkflowIntegrations%2CmodifyProjectSettings%2CconnectCodeRepository%2CcreateProjects%2CindexDesignSystems%2CsendPullRequests&builder.user.role.name=Developer&builder.user.role.id=developer&builder.cachebust=true&builder.preview=use-case-page&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.use-case-page=a9d5556e77f84a37b5bd52310a7110c1&builder.overrides.a9d5556e77f84a37b5bd52310a7110c1=a9d5556e77f84a37b5bd52310a7110c1&builder.overrides.use-case-page:/uc/incident-response=a9d5556e77f84a37b5bd52310a7110c1&builder.options.includeRefs=true&builder.options.enrich=true&builder.options.locale=Default",{"createdDate":1038,"id":1039,"name":1040,"modelId":261,"published":13,"query":1041,"data":1044,"variations":1149,"lastUpdated":1150,"firstPublished":1151,"testRatio":33,"screenshot":1152,"createdBy":34,"lastUpdatedBy":674,"folders":1153,"meta":1154,"rev":440},1746122471259,"5f118e24433d46ceb79f5099987156d7","Shadow SaaS",[1042],{"@type":264,"property":265,"operator":266,"value":1043},"/uc/shadow-saas",{"seoTitle":1045,"seoDescription":1046,"customFonts":1047,"fontAwesomeIcon":1052,"title":1053,"jsCode":37,"tsCode":37,"blocks":1054,"url":1043,"state":1146},"Find and secure shadow SaaS","See and control shadow SaaS in the browser.",[1048],{"kind":273,"variants":1049,"files":1050,"family":272,"version":274,"subsets":1051,"lastModified":275,"category":295,"menu":296},[301,302,303,304,305,306,128,307,308,309,310,311,312,313,314,315,316,317],{"100":277,"200":278,"300":279,"500":280,"600":281,"700":282,"800":283,"900":284,"300italic":293,"500italic":292,"regular":290,"900italic":286,"italic":289,"100italic":288,"200italic":291,"600italic":294,"700italic":287,"800italic":285},[298,299],"faShieldCheck","Secure shadow SaaS",[1055,1141],{"@type":106,"@version":107,"tagName":323,"id":1056,"meta":1057,"children":1058},"builder-04da805c4cd34652a2db452fcda52e1d",{"previousId":935},[1059,1075,1082,1089,1098,1108,1118,1128,1135],{"@type":106,"@version":107,"id":1060,"meta":1061,"component":1062,"responsiveStyles":1073},"builder-830d414faeaf41439142f9157e8288c8",{"previousId":939},{"name":327,"options":1063,"isRSC":118},{"title":1045,"description":1064,"points":1065,"video":1072},"\u003Cp>SaaS sprawl is one of today’s fastest-growing security blind spots because most tools monitor around the edges. Push sees it at the source, in the browser, revealing every app users access, flagging risky tools, and helping you shut down exposure before it leads to a breach. No guesswork. No nasty surprises. Just real-time visibility and control.\u003C/p>",[1066,1068,1070],{"item":1067},"Discover every SaaS app users access, managed or not",{"item":1069},"Spot accounts with weak security postures like missing MFA, unmanaged access, and no SSO",{"item":1071},"Control usage with in-browser prompts, blocks, and security guardrails","https://cdn.builder.io/o/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F3e4eece318d04d6586e691d59d0741cf%2Fcompressed?apiKey=f3a1111ff5be48cdbb123cd9f5795a05&token=3e4eece318d04d6586e691d59d0741cf&alt=media&optimized=true",{"large":1074},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":342},{"@type":106,"@version":107,"id":1076,"meta":1077,"component":1078,"responsiveStyles":1080},"builder-cd7833f966cb4c7e8adf0d6c979414a6",{"previousId":956},{"name":346,"options":1079,"isRSC":118},{"AllPartners":41,"backgroundTransparent":6},{"large":1081},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":350},{"@type":106,"@version":107,"id":1083,"meta":1084,"component":1085,"responsiveStyles":1087},"builder-49d720b45430454e8b08c526f267c19f",{"previousId":963},{"name":354,"options":1086,"isRSC":118},{"darkMode":41},{"large":1088},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":1090,"component":1091,"responsiveStyles":1096},"builder-3dde0bf6c8544e5e9ab41b18a9d68034",{"name":359,"tag":359,"options":1092,"isRSC":118},{"darkMode":6,"maxWidth":363,"maxTextWidth":364,"title":1093,"description":1094,"image":1095,"reverse":6},"\u003Ch2>Use your browser to curb Saas Sprawl\u003C/h2>","\u003Cp>Shadow SaaS isn’t hiding in your network, it’s in your browser. From AI tools to unsanctioned file-sharing sites, security risks live in the apps your users sign into every day. Push maps your organization's true SaaS footprint in real time, exposing apps and accounts with unmanaged access, poor authentication, or no security oversight.\u003C/p>\u003Cp>\u003Cbr>\u003C/p>\u003Cp>\u003Cbr>\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fb6811a214c7949b6bbe0b9a3bca62efd",{"large":1097},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":1099,"meta":1100,"component":1101,"responsiveStyles":1106},"builder-e2420451ccdc4f088d0a4904cff45935",{"previousId":979},{"name":373,"options":1102,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":376,"title":1103,"description":1104,"reverse":41,"image":1105},"\u003Ch2>Discover hidden SaaS usage\u003C/h2>","\u003Cp>Push captures live browser telemetry across every tab and session. Whether a user signs into a sanctioned app with a personal account or tries a new AI plugin, you’ll see it in real time, with no integrations or manual tagging.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fe16e301f9af94665b95d98232a863d8a",{"large":1107},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"fontFamily":382,"paddingTop":384,"marginTop":384},{"@type":106,"@version":107,"id":1109,"meta":1110,"component":1111,"responsiveStyles":1116},"builder-b36de7fce7994beea9e58d94662e7166",{"previousId":989},{"name":373,"options":1112,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":389,"title":1113,"description":1114,"reverse":6,"image":1115},"\u003Ch2>Spot risky access and unsafe usage\u003C/h2>","\u003Cp>Discovery is just the beginning. Push flags apps with risky traits, no MFA, no SSO, known vulnerabilities, or broad access scopes. You’ll know which tools introduce real risk, and which users are exposed so you can act with precision.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F6585f3c242da4d70ae3cb7d02f481bef",{"large":1117},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":395},{"@type":106,"@version":107,"layerName":373,"id":1119,"meta":1120,"component":1121,"responsiveStyles":1126},"builder-dc366b5134684fe7a508edf8913103ea",{"previousId":999},{"name":373,"options":1122,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":400,"title":1123,"description":1124,"reverse":41,"image":1125},"\u003Ch2>Close gaps before they grow\u003C/h2>","\u003Cp>Push turns insight into action. When risky SaaS use is detected, guide users to enable MFA, block high-risk apps, or apply in-browser guardrails automatically. All without deploying new infrastructure or managing dozens of integrations.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fe6d60b6d91414819bc6258a318f00557",{"large":1127},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":406},{"@type":106,"@version":107,"id":1129,"meta":1130,"component":1131,"responsiveStyles":1133},"builder-8708f6f0d8da4b3f9e17bf16cda70219",{"previousId":1009},{"name":354,"options":1132,"isRSC":118},{"darkMode":6},{"large":1134},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":1136,"component":1137,"responsiveStyles":1139},"builder-8ff4b38d60534cf28cb523ab0f754875",{"name":416,"tag":416,"options":1138,"isRSC":118},{"sectionHeading":37,"customClass":418},{"large":1140},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"id":1142,"@type":106,"tagName":131,"properties":1143,"responsiveStyles":1144},"builder-pixel-d1ul2kmxbed",{"src":133,"aria-hidden":134,"alt":37,"role":135,"width":124,"height":124},{"large":1145},{"height":124,"width":124,"display":138,"opacity":124,"overflow":139,"pointerEvents":140},{"deviceSize":142,"location":1147},{"path":37,"query":1148},{},{},1770892936802,1746714967208,"https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F01bfb2304521412fbd2e1a1180904d40",[],{"originalContentId":919,"winningTest":118,"lastPreviewUrl":1155,"breakpoints":1156,"kind":438,"hasLinks":6,"hasAutosaves":6},"https://pushsecurity.com/uc/shadow-saas?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditCode%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CeditProjects%2CmodifyMcpServers%2CmodifyWorkflowIntegrations%2CmodifyProjectSettings%2CconnectCodeRepository%2CcreateProjects%2CindexDesignSystems%2CsendPullRequests&builder.user.role.name=Developer&builder.user.role.id=developer&builder.cachebust=true&builder.preview=use-case-page&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.use-case-page=5f118e24433d46ceb79f5099987156d7&builder.overrides.5f118e24433d46ceb79f5099987156d7=5f118e24433d46ceb79f5099987156d7&builder.overrides.use-case-page:/uc/shadow-saas=5f118e24433d46ceb79f5099987156d7&builder.options.includeRefs=true&builder.options.enrich=true&builder.options.locale=Default",{"xsmall":57,"small":39,"medium":40},{"createdDate":1158,"id":1159,"name":1160,"modelId":261,"published":13,"query":1161,"data":1164,"variations":1268,"lastUpdated":1269,"firstPublished":1270,"testRatio":33,"screenshot":1271,"createdBy":34,"lastUpdatedBy":674,"folders":1272,"meta":1273,"rev":440},1764707470172,"b62629ce2f3741158d961cd10fe74b31","Shadow AI",[1162],{"@type":264,"property":265,"operator":266,"value":1163},"/uc/shadow-ai",{"fontAwesomeIcon":1165,"seoTitle":1166,"jsCode":37,"customFonts":1167,"title":1172,"tsCode":37,"seoDescription":1173,"blocks":1174,"url":1163,"state":1265},"faBrainCircuit","Secure AI native and AI enhanced apps. ",[1168],{"variants":1169,"category":295,"files":1170,"subsets":1171,"family":272,"kind":273,"menu":296,"lastModified":275,"version":274},[301,302,303,304,305,306,128,307,308,309,310,311,312,313,314,315,316,317],{"100":277,"200":278,"300":279,"500":280,"600":281,"700":282,"800":283,"900":284,"800italic":285,"regular":290,"700italic":287,"200italic":291,"italic":289,"500italic":292,"600italic":294,"300italic":293,"100italic":288,"900italic":286},[298,299],"Secure shadow AI","See and control shadow AI apps in the browser.",[1175,1260],{"@type":106,"@version":107,"tagName":323,"id":1176,"meta":1177,"children":1178},"builder-a6e5717a2c914d5695058e4ee201a05d",{"previousId":1056},[1179,1195,1202,1209,1219,1228,1237,1247,1254],{"@type":106,"@version":107,"id":1180,"meta":1181,"component":1182,"responsiveStyles":1193},"builder-3e0ed678683f4a0eb7aa00253cf263b2",{"previousId":1060},{"name":327,"options":1183,"isRSC":118},{"title":1172,"description":1184,"points":1185,"image":1192},"\u003Cp>Your employees are adopting AI faster than you can track it. From native features in corporate apps to unapproved shadow tools, it’s all happening in the browser. Push detects every AI interaction in real time, letting you categorize apps and enforce acceptable use policies in the browser.\u003C/p>",[1186,1188,1190],{"item":1187},"Map every AI tool used across your workforce",{"item":1189},"Review and classify apps by sensitivity, purpose, and policy status",{"item":1191},"Enforce AI usage rules directly in the browser","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F33cf153d920f4e389f3650253577cff7",{"large":1194},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":342},{"@type":106,"@version":107,"id":1196,"meta":1197,"component":1198,"responsiveStyles":1200},"builder-76968f8471d14893b8189d75b08fb426",{"previousId":1076},{"name":346,"options":1199,"isRSC":118},{"AllPartners":41,"backgroundTransparent":6},{"large":1201},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":350},{"@type":106,"@version":107,"id":1203,"meta":1204,"component":1205,"responsiveStyles":1207},"builder-b55b9d4bc5a649d8839ce7f6c2043d95",{"previousId":1083},{"name":354,"options":1206,"isRSC":118},{"darkMode":41},{"large":1208},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":1210,"meta":1211,"component":1212,"responsiveStyles":1217},"builder-c3f38ef4d75d4989a29b5903175ed8a1",{"previousId":1090},{"name":359,"tag":359,"options":1213,"isRSC":118},{"darkMode":6,"maxWidth":363,"maxTextWidth":364,"title":1214,"description":1215,"image":1216,"reverse":6},"\u003Ch2>Use your browser to govern AI \u003C/h2>","\u003Cp>The AI footprint inside your company is bigger than you think. From text generators to meeting assistants and design copilots, employees test, adopt, and connect new tools constantly. Push shows you those tools and which users are accessing them, without relying on network scans or API integrations.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F30b43bda6f1644c19478fb1efa20050c",{"large":1218},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":1220,"meta":1221,"component":1222,"responsiveStyles":1226},"builder-90ee9cb9afc44e7f885523715bf51a53",{"previousId":1099},{"name":373,"options":1223,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":376,"title":1224,"description":1225,"reverse":41,"image":1115},"\u003Ch2>Discover every AI tool users touch\u003C/h2>","\u003Cp>Push captures live telemetry from the browser, identifying every AI-native and AI-enhanced application users access. You’ll know which corporate identities are connected, how data flows, and what new AI apps appear across your environment. \u003C/p>",{"large":1227},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"fontFamily":382,"paddingTop":384,"marginTop":384},{"@type":106,"@version":107,"id":1229,"meta":1230,"component":1231,"responsiveStyles":1235},"builder-9e44539fa53c4d8e87406036c921fc46",{"previousId":1109},{"name":373,"options":1232,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":389,"title":1233,"description":1234,"reverse":6,"image":1125},"\u003Ch2>Classify and manage AI risk\u003C/h2>","\u003Cp>For apps you choose to allow, Push lets you apply custom in-browser banners. You can bulk-select categories of AI tools and require users to read and acknowledge your acceptable use policy before they proceed. This creates an auditable trail and moves policy from an easy to forget document to an active, in-workflow control.\u003C/p>",{"large":1236},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":395},{"@type":106,"@version":107,"layerName":373,"id":1238,"meta":1239,"component":1240,"responsiveStyles":1245},"builder-44c1a891926f4bdeaaa37e90721fe6ac",{"previousId":1119},{"name":373,"options":1241,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":400,"title":1242,"description":1243,"reverse":41,"image":1244},"\u003Ch2>Enforce your AI policy in the browser\u003C/h2>","\u003Cp>When an AI tool is deemed non-compliant or too risky, Push blocks it at the source. The block happens directly in the browser, preventing the user from accessing the site or submitting data. This gives you an immediate, powerful lever to stop data exfiltration and enforce a hard line on unacceptable risk.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fa359ac1805af4e15a8a7f84632b9bb55",{"large":1246},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":406},{"@type":106,"@version":107,"id":1248,"meta":1249,"component":1250,"responsiveStyles":1252},"builder-dcc906f9cbe54dc68b3c672668e7a38f",{"previousId":1129},{"name":354,"options":1251,"isRSC":118},{"darkMode":6},{"large":1253},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":1255,"component":1256,"responsiveStyles":1258},"builder-d2d64780c31b4349bc75805b23a07e38",{"name":416,"tag":416,"options":1257,"isRSC":118},{"sectionHeading":37,"customClass":418},{"large":1259},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"id":1261,"@type":106,"tagName":131,"properties":1262,"responsiveStyles":1263},"builder-pixel-wxx9tk70r9p",{"src":133,"aria-hidden":134,"alt":37,"role":135,"width":124,"height":124},{"large":1264},{"height":124,"width":124,"display":138,"opacity":124,"overflow":139,"pointerEvents":140},{"deviceSize":142,"location":1266},{"path":37,"query":1267},{},{},1770892957225,1764950077593,"https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fe558b8b069884037a8e6904f7ecc029c",[],{"winningTest":118,"breakpoints":1274,"originalContentId":1039,"kind":438,"lastPreviewUrl":1275,"hasLinks":6,"hasAutosaves":41},{"xsmall":57,"small":39,"medium":40},"https://pushsecurity.com/uc/shadow-ai?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditCode%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CeditProjects%2CmodifyMcpServers%2CmodifyWorkflowIntegrations%2CmodifyProjectSettings%2CconnectCodeRepository%2CcreateProjects%2CindexDesignSystems%2CsendPullRequests&builder.user.role.name=Developer&builder.user.role.id=developer&builder.cachebust=true&builder.preview=use-case-page&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.use-case-page=b62629ce2f3741158d961cd10fe74b31&builder.overrides.b62629ce2f3741158d961cd10fe74b31=b62629ce2f3741158d961cd10fe74b31&builder.overrides.use-case-page:/uc/shadow-ai=b62629ce2f3741158d961cd10fe74b31&builder.options.includeRefs=true&builder.options.enrich=true&builder.options.locale=Default",{"_path":1277,"_dir":1278,"_draft":6,"_partial":6,"_locale":37,"sys":1279,"summary":1282,"title":1296,"subtitle":118,"metaTitle":1297,"synopsis":1298,"hashTags":118,"publishedDate":1299,"slug":1300,"ogImage":1301,"tagsCollection":1303,"relatedBlogPostsCollection":1313,"authorsCollection":3152,"content":3156,"_id":4822,"_type":4823,"_source":4824,"_file":4825,"_stem":4826,"_extension":4823},"/blog/scattered-spider-ttp-evolution-in-2025","blog",{"id":1280,"publishedAt":1281},"wgpdyHDn9NcpIJNr7jnFp","2025-11-13T19:47:38.984Z",{"json":1283},{"data":1284,"content":1285,"nodeType":1295},{},[1286],{"data":1287,"content":1288,"nodeType":1294},{},[1289],{"data":1290,"marks":1291,"value":1292,"nodeType":1293},{},[],"How the notorious Scattered Spider cyber criminal group are evolving their TTPs in 2025 to bypass security controls like MFA and take over accounts on internet applications and services. ","text","paragraph","document","Scattered Spider: TTP evolution in 2025","How Scattered Spider TTPs are evolving in 2025","How the notorious Scattered Spider cyber criminal group are switching up their TTPs in 2025 to bypass MFA and breach cloud services via account takeover.","2025-05-06T00:00:00.000Z","scattered-spider-ttp-evolution-in-2025",{"url":1302},"https://images.ctfassets.net/y1cdw1ablpvd/mMbgUER8qJH3p4YF8CsAE/cfc45da4f29fb417a627be97335ab23e/Help_desk_verification_codes.png",{"items":1304},[1305,1309],{"sys":1306,"name":1308},{"id":1307},"6A5RXS31ZQx3PwryGb1IMy","Browser-based attacks",{"sys":1310,"name":1312},{"id":1311},"4ksQNCFeBf8H4QIORqpRLw","Detection & response",{"items":1314},[1315,1697,2515],{"__typename":1316,"sys":1317,"content":1319,"title":1679,"synopsis":1680,"hashTags":118,"publishedDate":1681,"slug":1682,"tagsCollection":1683,"authorsCollection":1689},"BlogPosts",{"id":1318},"4rLP8wr6HnvBG2OzqYYKpF",{"json":1320},{"nodeType":1295,"data":1321,"content":1322},{},[1323,1330,1337,1344,1353,1360,1395,1402,1410,1417,1423,1430,1437,1457,1463,1471,1492,1512,1519,1526,1533,1540,1547,1554,1561,1581,1588,1595,1601,1608,1615,1641,1647,1667,1673],{"nodeType":1294,"data":1324,"content":1325},{},[1326],{"nodeType":1293,"value":1327,"marks":1328,"data":1329},"Scattered Spider has shown the world the devastating effects attackers can achieve by socially engineering IT help desks into performing MFA resets so they can take over accounts on sensitive corporate apps. ",[],{},{"nodeType":1294,"data":1331,"content":1332},{},[1333],{"nodeType":1293,"value":1334,"marks":1335,"data":1336},"That’s why we’re introducing Employee Identity Verification Codes — a simple, browser-based identity check that gives your help desk a reliable way to confirm they’re talking to someone from your organization.",[],{},{"nodeType":1294,"data":1338,"content":1339},{},[1340],{"nodeType":1293,"value":1341,"marks":1342,"data":1343},"Push now provides your employees with a rotating 6-digit verification code in their browser via the Push Security extension. When an employee contacts your IT help desk to request an MFA reset or access recovery, the help desk can ask for this code to verify their identity — ensuring it’s really them, and not an attacker.",[],{},{"nodeType":1345,"data":1346,"content":1352},"embedded-entry-block",{"target":1347},{"sys":1348},{"id":1349,"type":1350,"linkType":1351},"3PkiGgzwSt9Nb5rsGRiQVZ","Link","Entry",[],{"nodeType":1294,"data":1354,"content":1355},{},[1356],{"nodeType":1293,"value":1357,"marks":1358,"data":1359},"The employee identity verification codes are:",[],{},{"nodeType":1361,"data":1362,"content":1363},"unordered-list",{},[1364,1375,1385],{"nodeType":1365,"data":1366,"content":1367},"list-item",{},[1368],{"nodeType":1294,"data":1369,"content":1370},{},[1371],{"nodeType":1293,"value":1372,"marks":1373,"data":1374},"Session-aware - generated in users’ browsers and only visible to them when they click on the Push Security extension icon in their browser toolbar.",[],{},{"nodeType":1365,"data":1376,"content":1377},{},[1378],{"nodeType":1294,"data":1379,"content":1380},{},[1381],{"nodeType":1293,"value":1382,"marks":1383,"data":1384},"Rotating: they change every 24 hours",[],{},{"nodeType":1365,"data":1386,"content":1387},{},[1388],{"nodeType":1294,"data":1389,"content":1390},{},[1391],{"nodeType":1293,"value":1392,"marks":1393,"data":1394},"Lightweight: no additional apps or devices required",[],{},{"nodeType":1294,"data":1396,"content":1397},{},[1398],{"nodeType":1293,"value":1399,"marks":1400,"data":1401},"It’s a fast, simple verification method — directly in the employee’s browser — that addresses a real-world threat.",[],{},{"nodeType":1403,"data":1404,"content":1405},"heading-1",{},[1406],{"nodeType":1293,"value":1407,"marks":1408,"data":1409},"We think it’s swell, but don’t just take our word for it …",[],{},{"nodeType":1294,"data":1411,"content":1412},{},[1413],{"nodeType":1293,"value":1414,"marks":1415,"data":1416},"Eric Rubin — a Senior Manager in GitLab’s Corporate Security team — has already rolled out Employee Identity Verification Codes across his workforce. Here’s what he had to say about it:",[],{},{"nodeType":1345,"data":1418,"content":1422},{"target":1419},{"sys":1420},{"id":1421,"type":1350,"linkType":1351},"5ZLaA869NXpMjVwkswEyOB",[],{"nodeType":1294,"data":1424,"content":1425},{},[1426],{"nodeType":1293,"value":1427,"marks":1428,"data":1429},"Thank you, Eric!",[],{},{"nodeType":1403,"data":1431,"content":1432},{},[1433],{"nodeType":1293,"value":1434,"marks":1435,"data":1436},"Why are help desk identity verification methods so hot right now?",[],{},{"nodeType":1294,"data":1438,"content":1439},{},[1440,1444,1453],{"nodeType":1293,"value":1441,"marks":1442,"data":1443},"A number of the high-profile incidents attributed to the ",[],{},{"nodeType":1445,"data":1446,"content":1448},"hyperlink",{"uri":1447},"https://pushsecurity.com/blog/scattered-spider-ttp-evolution-in-2025/",[1449],{"nodeType":1293,"value":1450,"marks":1451,"data":1452},"Scattered Spider cybercriminal group",[],{},{"nodeType":1293,"value":1454,"marks":1455,"data":1456}," saw them socially engineer IT help desks into resetting MFA on employee accounts that they had already acquired valid credentials for. These compromised accounts were typically on IdP systems like Okta providing SSO access to large numbers of downstream applications.",[],{},{"nodeType":1345,"data":1458,"content":1462},{"target":1459},{"sys":1460},{"id":1461,"type":1350,"linkType":1351},"2F2dpOkyXWnrKgFC3dSl67",[],{"nodeType":1464,"data":1465,"content":1466},"heading-2",{},[1467],{"nodeType":1293,"value":1468,"marks":1469,"data":1470},"Case study: The MGM Resorts breach",[],{},{"nodeType":1294,"data":1472,"content":1473},{},[1474,1478,1488],{"nodeType":1293,"value":1475,"marks":1476,"data":1477},"One of Scattered Spider’s most notorious and well-documented attacks was against ",[],{},{"nodeType":1445,"data":1479,"content":1481},{"uri":1480},"https://pushsecurity.com/blog/identity-attacks-in-the-wild/#id-mgm-resorts-september-2023",[1482],{"nodeType":1293,"value":1483,"marks":1484,"data":1487},"MGM Resorts",[1485],{"type":1486},"underline",{},{"nodeType":1293,"value":1489,"marks":1490,"data":1491},". Scattered Spider socially engineered MGM Resorts’ help desk personnel to bypass MFA and log in to accounts for which they had acquired valid login credentials via credential phishing and historical infostealer compromises. ",[],{},{"nodeType":1294,"data":1493,"content":1494},{},[1495,1499,1508],{"nodeType":1293,"value":1496,"marks":1497,"data":1498},"They specifically targeted accounts with Super Administrator privileges within MGM Resorts’ Okta tenant, which they then used to register a second, attacker-controlled IdP via ",[],{},{"nodeType":1445,"data":1500,"content":1502},{"uri":1501},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/inbound_federation/description.md",[1503],{"nodeType":1293,"value":1504,"marks":1505,"data":1507},"inbound federation",[1506],{"type":1486},{},{"nodeType":1293,"value":1509,"marks":1510,"data":1511},". This then enabled them to impersonate any user within the Okta tenant. ",[],{},{"nodeType":1294,"data":1513,"content":1514},{},[1515],{"nodeType":1293,"value":1516,"marks":1517,"data":1518},"The attackers were then able to abuse SSO access to downstream apps and platforms from various accounts, culminating in deployment of ransomware to around 100 ESXi servers and data exfiltration. ",[],{},{"nodeType":1294,"data":1520,"content":1521},{},[1522],{"nodeType":1293,"value":1523,"marks":1524,"data":1525},"The breach resulted in a 36-hour outage, a $100M hit to its Q3 results, one-time cyber consulting fees in the region of $10M, and a class-action lawsuit later settled for $45M. ",[],{},{"nodeType":1464,"data":1527,"content":1528},{},[1529],{"nodeType":1293,"value":1530,"marks":1531,"data":1532},"Reassessing help desk verification processes",[],{},{"nodeType":1294,"data":1534,"content":1535},{},[1536],{"nodeType":1293,"value":1537,"marks":1538,"data":1539},"Scattered Spider’s high-profile attacks — including its most recent against UK retailers Marks & Spencer’s and the Co-op — has prompted many security teams to reassess the verification processes used by their IT help desks when an employee requests an MFA reset or access to sensitive applications. ",[],{},{"nodeType":1294,"data":1541,"content":1542},{},[1543],{"nodeType":1293,"value":1544,"marks":1545,"data":1546},"Initial guidance from across the industry included the use of call-back verification for any MFA or credential changes requested by an employee. However, Scattered Spider are also known to use SIM-swapping to trick mobile carriers into transferring a victim’s phone number to a SIM card controlled by the attacker - thereby allowing them to intercept verification calls. ",[],{},{"nodeType":1403,"data":1548,"content":1549},{},[1550],{"nodeType":1293,"value":1551,"marks":1552,"data":1553},"Simple verification using your employees’ browsers",[],{},{"nodeType":1294,"data":1555,"content":1556},{},[1557],{"nodeType":1293,"value":1558,"marks":1559,"data":1560},"Push already provides several controls that directly align to the other TTPs used by Scattered Spider. They include detecting stolen credentials, cloned login pages, AitM toolkits and compromised IdP sessions. ",[],{},{"nodeType":1294,"data":1562,"content":1563},{},[1564,1568,1577],{"nodeType":1293,"value":1565,"marks":1566,"data":1567},"(BTW, if this piques your interest, you can ",[],{},{"nodeType":1445,"data":1569,"content":1571},{"uri":1570},"https://pushsecurity.com/resources?type=webinar#content",[1572],{"nodeType":1293,"value":1573,"marks":1574,"data":1576},"stream our latest webinar",[1575],{"type":1486},{},{"nodeType":1293,"value":1578,"marks":1579,"data":1580}," where we deep-dive into Scattered Spider, how their TTPs are evolving in 2025, and what Push is doing to protect organizations against them.) ",[],{},{"nodeType":1294,"data":1582,"content":1583},{},[1584],{"nodeType":1293,"value":1585,"marks":1586,"data":1587},"But to provide our customers with an additional layer of defense against the Scattered Spider attack chain, we wanted to see how we could make it harder for attackers to socially engineer IT help desks into gaining access to IdP systems and sensitive apps.",[],{},{"nodeType":1294,"data":1589,"content":1590},{},[1591],{"nodeType":1293,"value":1592,"marks":1593,"data":1594},"As so often is the case, the answer was staring us right in the face - we can use our browser extension. By placing a verification code in the details tray of every employees’ Push extension, they can use that to verify their identity with their help desk team.",[],{},{"nodeType":1345,"data":1596,"content":1600},{"target":1597},{"sys":1598},{"id":1599,"type":1350,"linkType":1351},"4hRJVGqKGyOHJ8NSsQYWGP",[],{"nodeType":1403,"data":1602,"content":1603},{},[1604],{"nodeType":1293,"value":1605,"marks":1606,"data":1607},"Get started today!",[],{},{"nodeType":1294,"data":1609,"content":1610},{},[1611],{"nodeType":1293,"value":1612,"marks":1613,"data":1614},"Employee verification codes is a Labs feature, which means it’s available on an early-access basis. We're particularly interested in hearing your feedback on how to develop this feature further.",[],{},{"nodeType":1294,"data":1616,"content":1617},{},[1618,1622,1628,1632,1637],{"nodeType":1293,"value":1619,"marks":1620,"data":1621},"You can enable Labs features by going to the ",[],{},{"nodeType":1293,"value":1623,"marks":1624,"data":1627},"Settings",[1625],{"type":1626},"bold",{},{"nodeType":1293,"value":1629,"marks":1630,"data":1631}," page of the Push admin console and choosing the ",[],{},{"nodeType":1293,"value":1633,"marks":1634,"data":1636},"Labs",[1635],{"type":1626},{},{"nodeType":1293,"value":1638,"marks":1639,"data":1640}," tab.",[],{},{"nodeType":1345,"data":1642,"content":1646},{"target":1643},{"sys":1644},{"id":1645,"type":1350,"linkType":1351},"6TyqP2eOmalIF6RRoe476Y",[],{"nodeType":1294,"data":1648,"content":1649},{},[1650,1654,1663],{"nodeType":1293,"value":1651,"marks":1652,"data":1653},"If you’d like to find out more about this feature, and the other ways Push is stopping identity attacks in the browser, ",[],{},{"nodeType":1445,"data":1655,"content":1657},{"uri":1656},"https://pushsecurity.com/demo/",[1658],{"nodeType":1293,"value":1659,"marks":1660,"data":1662},"book a demo",[1661],{"type":1486},{},{"nodeType":1293,"value":1664,"marks":1665,"data":1666}," with one of our team. ",[],{},{"nodeType":1345,"data":1668,"content":1672},{"target":1669},{"sys":1670},{"id":1671,"type":1350,"linkType":1351},"7xBE9MrnMy3hfwIkhLhNhQ",[],{"nodeType":1294,"data":1674,"content":1675},{},[1676],{"nodeType":1293,"value":37,"marks":1677,"data":1678},[],{},"A simple, browser-based way to protect your help desk against social engineering","Push's new Employee Identity Verification Codes feature is a simple way for your help desk to confirm they’re talking to someone from your organization.\n","2025-06-19T00:00:00.000Z","employee-identity-verification-codes-release",{"items":1684},[1685],{"sys":1686,"name":1688},{"id":1687},"3pjES4THCIfSAwhGdNwBcy","Identity security",{"items":1690},[1691],{"fullName":1692,"firstName":1693,"jobTitle":1694,"profilePicture":1695},"Alex Henshall","Alex","Product Team",{"url":1696},"https://images.ctfassets.net/y1cdw1ablpvd/2rz3Pre3b1MexPIQ4hzPUe/0ef8a092b7e7df00fbce3f7d1ccb96d1/Alex_Henshall.jpeg",{"__typename":1316,"sys":1698,"content":1700,"title":2499,"synopsis":2500,"hashTags":118,"publishedDate":2501,"slug":2502,"tagsCollection":2503,"authorsCollection":2507},{"id":1699},"PAPJPr3CIB6J20udYyy1r",{"json":1701},{"data":1702,"content":1703,"nodeType":1295},{},[1704,1710,1730,1737,1744,1750,1754,1762,1769,1789,1801,1808,1815,1822,1915,1918,1926,2009,2015,2018,2026,2034,2041,2048,2056,2075,2082,2090,2097,2104,2112,2119,2126,2146,2152,2155,2163,2171,2178,2284,2291,2299,2306,2313,2319,2327,2334,2341,2348,2356,2363,2370,2377,2384,2390,2393,2401,2408,2441,2448,2467,2487,2493],{"data":1705,"content":1709,"nodeType":1345},{"target":1706},{"sys":1707},{"id":1708,"type":1350,"linkType":1351},"1eBClNW4NOR66F0tl9h6lD",[],{"data":1711,"content":1712,"nodeType":1294},{},[1713,1717,1726],{"data":1714,"marks":1715,"value":1716,"nodeType":1293},{},[],"The attacks on Snowflake customers in 2024 collectively constituted the biggest cyber security event of the year in terms of the number of organizations and individuals affected (at least, if you exclude CrowdStrike causing a worldwide outage in July) — certainly, it was the largest perpetrated by a criminal group against commercial enterprises. It has been touted by some news outlets as ‘",{"data":1718,"content":1720,"nodeType":1445},{"uri":1719},"https://www.wired.com/story/snowflake-breach-advanced-auto-parts-lendingtree/",[1721],{"data":1722,"marks":1723,"value":1725,"nodeType":1293},{},[1724],{"type":1486},"one of the biggest breaches ever",{"data":1727,"marks":1728,"value":1729,"nodeType":1293},{},[],"’.  ",{"data":1731,"content":1732,"nodeType":1294},{},[1733],{"data":1734,"marks":1735,"value":1736,"nodeType":1293},{},[],"Snowflake was a watershed moment that signalled the significant opportunity presented by identity attacks on cloud services. It demonstrated how comparatively unsophisticated methods (logging in to user accounts with stolen credentials and dumping the data) can have the same or greater impact as a traditional network or endpoint based cyber attack involving vulnerability exploitation, malware deployment, ransomware, etc. ",{"data":1738,"content":1739,"nodeType":1294},{},[1740],{"data":1741,"marks":1742,"value":1743,"nodeType":1293},{},[],"Here’s everything you need to know about the Snowflake attacks — and what you can do to protect yourself against the next Snowflake in the future.",{"data":1745,"content":1749,"nodeType":1345},{"target":1746},{"sys":1747},{"id":1748,"type":1350,"linkType":1351},"4QoPUiP5q6Mwj1eWUZT15Q",[],{"data":1751,"content":1752,"nodeType":1753},{},[],"hr",{"data":1755,"content":1756,"nodeType":1403},{},[1757],{"data":1758,"marks":1759,"value":1761,"nodeType":1293},{},[1760],{"type":1626},"Snowflake: The facts",{"data":1763,"content":1764,"nodeType":1294},{},[1765],{"data":1766,"marks":1767,"value":1768,"nodeType":1293},{},[],"Cyber criminals associated with the threat group known as ShinyHunters claimed responsibility for breaching multiple organizations using Snowflake, a cloud-based data warehousing and analytics platform. ",{"data":1770,"content":1771,"nodeType":1294},{},[1772,1776,1785],{"data":1773,"marks":1774,"value":1775,"nodeType":1293},{},[],"ShinyHunters associates targeted ~165 organizations that were subjected to account takeover attacks using stolen credentials harvested from historical infostealer infections dating back as far as 2020, ",{"data":1777,"content":1779,"nodeType":1445},{"uri":1778},"https://cloud.google.com/blog/topics/threat-intelligence/unc5537-snowflake-data-theft-extortion",[1780],{"data":1781,"marks":1782,"value":1784,"nodeType":1293},{},[1783],{"type":1486},"according to Mandiant’s investigation",{"data":1786,"marks":1787,"value":1788,"nodeType":1293},{},[],". ",{"data":1790,"content":1791,"nodeType":1800},{},[1792],{"data":1793,"content":1794,"nodeType":1294},{},[1795],{"data":1796,"marks":1797,"value":1799,"nodeType":1293},{},[1798],{"type":1626},">80% of the compromised accounts belonging to Snowflake customers had prior credential exposure. ","blockquote",{"data":1802,"content":1803,"nodeType":1294},{},[1804],{"data":1805,"marks":1806,"value":1807,"nodeType":1293},{},[],"The impacted accounts lacked MFA, meaning successful authentication only required a valid username and password. As the Snowflake credentials found in infostealer malware credential dumps had not been rotated or updated, they remained valid and could be used to authenticate to user accounts on Snowflake tenants belonging to various customers.",{"data":1809,"content":1810,"nodeType":1294},{},[1811],{"data":1812,"marks":1813,"value":1814,"nodeType":1293},{},[],"As a data warehousing platform integrated with a range of connected cloud services, access to a customer’s Snowflake tenant provided attackers with large quantities of sensitive commercial and personal data that could be stolen and monetized by attackers in a variety of ways — such as by ransoming the victim organization, extorting individual end-customers, and selling the data on to other criminal organizations. ",{"data":1816,"content":1817,"nodeType":1294},{},[1818],{"data":1819,"marks":1820,"value":1821,"nodeType":1293},{},[],"In total, 9 public victims were named following the breach, collectively impacting hundreds of millions of people. ",{"data":1823,"content":1824,"nodeType":1361},{},[1825,1835,1845,1855,1865,1875,1885,1895,1905],{"data":1826,"content":1827,"nodeType":1365},{},[1828],{"data":1829,"content":1830,"nodeType":1294},{},[1831],{"data":1832,"marks":1833,"value":1834,"nodeType":1293},{},[],"Lending Tree: Sensitive data for over 190 million people available online including customer details, partial credit card numbers, insurance quotes and other information, being sold for $2m.",{"data":1836,"content":1837,"nodeType":1365},{},[1838],{"data":1839,"content":1840,"nodeType":1294},{},[1841],{"data":1842,"marks":1843,"value":1844,"nodeType":1293},{},[],"Truist Bank: Information belonging to 65,000 employees being sold online for $1m",{"data":1846,"content":1847,"nodeType":1365},{},[1848],{"data":1849,"content":1850,"nodeType":1294},{},[1851],{"data":1852,"marks":1853,"value":1854,"nodeType":1293},{},[],"Advance Auto Parts: 3TB of data for sale for $1.5 million. Affected 2.3 million people, as well as current and former employees and job applicants.",{"data":1856,"content":1857,"nodeType":1365},{},[1858],{"data":1859,"content":1860,"nodeType":1294},{},[1861],{"data":1862,"marks":1863,"value":1864,"nodeType":1293},{},[],"Pure Storage: Workspace with 11k customer records including company, email, LDAP username and software version numbers.",{"data":1866,"content":1867,"nodeType":1365},{},[1868],{"data":1869,"content":1870,"nodeType":1294},{},[1871],{"data":1872,"marks":1873,"value":1874,"nodeType":1293},{},[],"Los Angeles Unified: Student data, disability information, discipline details, and parent information, being sold online for $150k.",{"data":1876,"content":1877,"nodeType":1365},{},[1878],{"data":1879,"content":1880,"nodeType":1294},{},[1881],{"data":1882,"marks":1883,"value":1884,"nodeType":1293},{},[],"Neiman Marcus: 31m email addresses exposed alongside various personal information.",{"data":1886,"content":1887,"nodeType":1365},{},[1888],{"data":1889,"content":1890,"nodeType":1294},{},[1891],{"data":1892,"marks":1893,"value":1894,"nodeType":1293},{},[],"Santander: 30 million customer details for sale relating to customers of Santander Chile, Spain, and Uruguay.",{"data":1896,"content":1897,"nodeType":1365},{},[1898],{"data":1899,"content":1900,"nodeType":1294},{},[1901],{"data":1902,"marks":1903,"value":1904,"nodeType":1293},{},[],"Ticketmaster: 560 million customer details for sale, disruption to events and ticketing worldwide, increasing in scam ticket production.",{"data":1906,"content":1907,"nodeType":1365},{},[1908],{"data":1909,"content":1910,"nodeType":1294},{},[1911],{"data":1912,"marks":1913,"value":1914,"nodeType":1293},{},[],"AT&T: Call logs stolen for approximately 109 million customers (nearly all of its mobile customers). AT&T paid an undisclosed ransom fee. ",{"data":1916,"content":1917,"nodeType":1753},{},[],{"data":1919,"content":1920,"nodeType":1403},{},[1921],{"data":1922,"marks":1923,"value":1925,"nodeType":1293},{},[1924],{"type":1626},"The Snowflake attacks step-by-step",{"data":1927,"content":1928,"nodeType":1361},{},[1929,1939,1949,1959,1969,1979,1989,1999],{"data":1930,"content":1931,"nodeType":1365},{},[1932],{"data":1933,"content":1934,"nodeType":1294},{},[1935],{"data":1936,"marks":1937,"value":1938,"nodeType":1293},{},[],"Snowflake users were infected with infostealer malware that harvested credentials from user devices over an extended period via several infostealer malware variants, including; VIDAR, RISEPRO, REDLINE, RACOON STEALER, LUMMA and METASTEALER.",{"data":1940,"content":1941,"nodeType":1365},{},[1942],{"data":1943,"content":1944,"nodeType":1294},{},[1945],{"data":1946,"marks":1947,"value":1948,"nodeType":1293},{},[],"Credentials appeared on criminal marketplaces e.g. dark web forums and Telegram channels.",{"data":1950,"content":1951,"nodeType":1365},{},[1952],{"data":1953,"content":1954,"nodeType":1294},{},[1955],{"data":1956,"marks":1957,"value":1958,"nodeType":1293},{},[],"ShinyHunters saw the potential in targeting Snowflake users, based on the availability of credentials, number of customer organizations, and the value of the data that can be accessed in Snowflake. ",{"data":1960,"content":1961,"nodeType":1365},{},[1962],{"data":1963,"content":1964,"nodeType":1294},{},[1965],{"data":1966,"marks":1967,"value":1968,"nodeType":1293},{},[],"ShinyHunters embarked on a large-scale campaign targeting Snowflake customer accounts using previously breached credentials. ",{"data":1970,"content":1971,"nodeType":1365},{},[1972],{"data":1973,"content":1974,"nodeType":1294},{},[1975],{"data":1976,"marks":1977,"value":1978,"nodeType":1293},{},[],"ShinyHunters accessed user accounts that lacked MFA, belonging to approximately 165 Snowflake customers. ",{"data":1980,"content":1981,"nodeType":1365},{},[1982],{"data":1983,"content":1984,"nodeType":1294},{},[1985],{"data":1986,"marks":1987,"value":1988,"nodeType":1293},{},[],"ShinyHunters used SQL-based reconnaissance, staging, and data exfiltration techniques, expedited by custom hacker tooling developed specifically for Snowflake, to conduct attacks at scale.",{"data":1990,"content":1991,"nodeType":1365},{},[1992],{"data":1993,"content":1994,"nodeType":1294},{},[1995],{"data":1996,"marks":1997,"value":1998,"nodeType":1293},{},[],"ShinyHunters acquired massive quantities of Snowflake data based on the information that each customer stored in Snowflake or connected apps. ",{"data":2000,"content":2001,"nodeType":1365},{},[2002],{"data":2003,"content":2004,"nodeType":1294},{},[2005],{"data":2006,"marks":2007,"value":2008,"nodeType":1293},{},[],"ShinyHunters began attempts to extort Snowflake and end-customers using the data acquired.",{"data":2010,"content":2014,"nodeType":1345},{"target":2011},{"sys":2012},{"id":2013,"type":1350,"linkType":1351},"2J92gFLs1wAAGC4nQTaiWu",[],{"data":2016,"content":2017,"nodeType":1753},{},[],{"data":2019,"content":2020,"nodeType":1403},{},[2021],{"data":2022,"marks":2023,"value":2025,"nodeType":1293},{},[2024],{"type":1626},"Why did the Snowflake breaches happen?",{"data":2027,"content":2028,"nodeType":1464},{},[2029],{"data":2030,"marks":2031,"value":2033,"nodeType":1293},{},[2032],{"type":1626},"Stolen credentials remained valid for years",{"data":2035,"content":2036,"nodeType":1294},{},[2037],{"data":2038,"marks":2039,"value":2040,"nodeType":1293},{},[],"The credentials used to access Snowflake accounts from historical infostealer infections had not been changed or rotated despite dating back as far as 2020, and remained valid. ",{"data":2042,"content":2043,"nodeType":1294},{},[2044],{"data":2045,"marks":2046,"value":2047,"nodeType":1293},{},[],"This highlights the potential risk of breached credentials already in the public domain, particularly in the case of cloud services like Snowflake that may not be subject to the same levels of credential hygiene as other traditional enterprise domain accounts. ",{"data":2049,"content":2050,"nodeType":1464},{},[2051],{"data":2052,"marks":2053,"value":2055,"nodeType":1293},{},[2054],{"type":1626},"Local logins lacked MFA ",{"data":2057,"content":2058,"nodeType":1294},{},[2059,2063,2072],{"data":2060,"marks":2061,"value":2062,"nodeType":1293},{},[],"Even where organizations were primarily encouraging employees to use SSO to access their Snowflake tenant, previously created local logins with a username and password continue to exist even after introducing SSO-based logins. Further, MFA was not globally enforceable at the application level, meaning that MFA was only set when logging into an IdP account for SSO, but not for local logins. We call this problem ",{"data":2064,"content":2066,"nodeType":1445},{"uri":2065},"https://pushsecurity.com/blog/ghost-logins-when-forgotten-identities-come-back-to-haunt-you/",[2067],{"data":2068,"marks":2069,"value":2071,"nodeType":1293},{},[2070],{"type":1486},"ghost logins",{"data":2073,"marks":2074,"value":1788,"nodeType":1293},{},[],{"data":2076,"content":2077,"nodeType":1294},{},[2078],{"data":2079,"marks":2080,"value":2081,"nodeType":1293},{},[],"This meant that attackers were able to take over Snowflake accounts with only a single authentication factor (username & password). ",{"data":2083,"content":2084,"nodeType":1464},{},[2085],{"data":2086,"marks":2087,"value":2089,"nodeType":1293},{},[2088],{"type":1626},"Snowflake was a high-value target used by many organizations",{"data":2091,"content":2092,"nodeType":1294},{},[2093],{"data":2094,"marks":2095,"value":2096,"nodeType":1293},{},[],"As a data warehousing platform used by a vast number of organizations, Snowflake represented a high-value target based on the data typically stored within it, and the repeatable way in which Snowflake users could be targeted. ",{"data":2098,"content":2099,"nodeType":1294},{},[2100],{"data":2101,"marks":2102,"value":2103,"nodeType":1293},{},[],"The attacker followed a near identical process when targeting Snowflake victims, meaning it could be scripted and executed at scale, with attacks taking a matter of minutes. ",{"data":2105,"content":2106,"nodeType":1464},{},[2107],{"data":2108,"marks":2109,"value":2111,"nodeType":1293},{},[2110],{"type":1626},"Infostealer infections are driving credential availability",{"data":2113,"content":2114,"nodeType":1294},{},[2115],{"data":2116,"marks":2117,"value":2118,"nodeType":1293},{},[],"Infostealers are often seen as a low-priority issue, but are the primary source of stolen credentials used in campaigns like this one. ",{"data":2120,"content":2121,"nodeType":1294},{},[2122],{"data":2123,"marks":2124,"value":2125,"nodeType":1293},{},[],"EDR is a strong protection but is often bypassed by infostealers as attackers continually modify them to bypass security controls. Further, unmanaged devices such as those used by third-party contractors or BYOD employees often lack the robust controls applied to company-managed devices and are naturally more susceptible to infostealer attacks. And since browser profiles can be synced across devices, even personal device compromises can result in the capture of corporate credentials.  ",{"data":2127,"content":2128,"nodeType":1294},{},[2129,2133,2142],{"data":2130,"marks":2131,"value":2132,"nodeType":1293},{},[],"There is some suggestion that targeting key third-party suppliers – ",{"data":2134,"content":2136,"nodeType":1445},{"uri":2135},"https://www.wired.com/story/epam-snowflake-ticketmaster-breach-shinyhunters/",[2137],{"data":2138,"marks":2139,"value":2141,"nodeType":1293},{},[2140],{"type":1486},"such as EPAM Systems, a software engineering firm and Snowflake ‘Elite Tier Partner’",{"data":2143,"marks":2144,"value":2145,"nodeType":1293},{},[]," – provided some of the access to Snowflake customers needed. It’s unclear what came first, but it’s possible (likely, even) that EPAM was identified as a target specifically because of its lucrative customer base and Snowflake credentials — adding another indicator that Snowflake was potentially a premeditated attack inspired by the availability of Snowflake credentials online.",{"data":2147,"content":2151,"nodeType":1345},{"target":2148},{"sys":2149},{"id":2150,"type":1350,"linkType":1351},"4D0gjt5oJLNKJH8GzjP8Je",[],{"data":2153,"content":2154,"nodeType":1753},{},[],{"data":2156,"content":2157,"nodeType":1403},{},[2158],{"data":2159,"marks":2160,"value":2162,"nodeType":1293},{},[2161],{"type":1626},"Key takeaways from the Snowflake attacks",{"data":2164,"content":2165,"nodeType":1464},{},[2166],{"data":2167,"marks":2168,"value":2170,"nodeType":1293},{},[2169],{"type":1626},"Securing your IdP accounts is not enough",{"data":2172,"content":2173,"nodeType":1294},{},[2174],{"data":2175,"marks":2176,"value":2177,"nodeType":1293},{},[],"SSO can help reduce your identity attack surface, but it's not feasible to get every workforce identity behind it.",{"data":2179,"content":2180,"nodeType":1361},{},[2181,2204,2227,2262],{"data":2182,"content":2183,"nodeType":1365},{},[2184],{"data":2185,"content":2186,"nodeType":1294},{},[2187,2191,2200],{"data":2188,"marks":2189,"value":2190,"nodeType":1293},{},[],"Only 1 in 3 apps support SAML SSO, and those that offer it often charge more for it; the “",{"data":2192,"content":2194,"nodeType":1445},{"uri":2193},"https://ssotax.org/",[2195],{"data":2196,"marks":2197,"value":2199,"nodeType":1293},{},[2198],{"type":1486},"SSO tax",{"data":2201,"marks":2202,"value":2203,"nodeType":1293},{},[],"”.",{"data":2205,"content":2206,"nodeType":1365},{},[2207],{"data":2208,"content":2209,"nodeType":1294},{},[2210,2214,2223],{"data":2211,"marks":2212,"value":2213,"nodeType":1293},{},[],"Many apps are self-adopted by employees, leaving security teams unaware and unable to enforce SSO.  The typical organization has ",{"data":2215,"content":2217,"nodeType":1445},{"uri":2216},"https://pushsecurity.com/blog/how-many-vulnerable-identities-do-you-have/",[2218],{"data":2219,"marks":2220,"value":2222,"nodeType":1293},{},[2221],{"type":1486},"hundreds of apps and thousands of unmanaged identities outside of SSO",{"data":2224,"marks":2225,"value":2226,"nodeType":1293},{},[],".",{"data":2228,"content":2229,"nodeType":1365},{},[2230],{"data":2231,"content":2232,"nodeType":1294},{},[2233,2237,2245,2249,2258],{"data":2234,"marks":2235,"value":2236,"nodeType":1293},{},[],"Most apps do not prevent users from creating additional \"",{"data":2238,"content":2239,"nodeType":1445},{"uri":2065},[2240],{"data":2241,"marks":2242,"value":2244,"nodeType":1293},{},[2243],{"type":1486},"ghost login",{"data":2246,"marks":2247,"value":2248,"nodeType":1293},{},[],"\" methods outside of SSO (especially by default), accounting for around ",{"data":2250,"content":2252,"nodeType":1445},{"uri":2251},"https://pushsecurity.com/blog/how-many-vulnerable-identities-do-you-have/#id-identity-configurations-and-how-they-can-be-exploited_id-many-accounts-lack-the-most-basic-protections",[2253],{"data":2254,"marks":2255,"value":2257,"nodeType":1293},{},[2256],{"type":1486},"10% of all identities",{"data":2259,"marks":2260,"value":2261,"nodeType":1293},{},[]," observed by Push. ",{"data":2263,"content":2264,"nodeType":1365},{},[2265],{"data":2266,"content":2267,"nodeType":1294},{},[2268,2272,2280],{"data":2269,"marks":2270,"value":2271,"nodeType":1293},{},[],"In total, we identified that ",{"data":2273,"content":2274,"nodeType":1445},{"uri":2216},[2275],{"data":2276,"marks":2277,"value":2279,"nodeType":1293},{},[2278],{"type":1486},"37% (2 in 5) accounts have a password login set with no MFA",{"data":2281,"marks":2282,"value":2283,"nodeType":1293},{},[],", while 9% have no MFA AND a weak, breached, or reused password.",{"data":2285,"content":2286,"nodeType":1294},{},[2287],{"data":2288,"marks":2289,"value":2290,"nodeType":1293},{},[],"So, relying on locked-down IdP accounts and maximising the use of SSO is an important pillar of an effective identity security strategy, but there will always be gaps. Unless you recognize this, you may be blindsided by attackers finding them before you do. ",{"data":2292,"content":2293,"nodeType":1464},{},[2294],{"data":2295,"marks":2296,"value":2298,"nodeType":1293},{},[2297],{"type":1626},"The threat of infostealers and stolen credentials needs to be taken seriously",{"data":2300,"content":2301,"nodeType":1294},{},[2302],{"data":2303,"marks":2304,"value":2305,"nodeType":1293},{},[],"Breached credentials appearing online is not always seen as a top priority for security teams, particularly when there’s so much noise from all of the outdated or simply erroneous findings (anyone that’s ever subscribed to a credential TI feed knows the pain of this). ",{"data":2307,"content":2308,"nodeType":1294},{},[2309],{"data":2310,"marks":2311,"value":2312,"nodeType":1293},{},[],"But Snowflake serves as a stark reminder that despite all the false positives, stolen credentials are sometimes valid — and when weaponized at-scale they can be a powerful tool for attackers. ",{"data":2314,"content":2318,"nodeType":1345},{"target":2315},{"sys":2316},{"id":2317,"type":1350,"linkType":1351},"4EODpwKsqNivpvP2yMtZCd",[],{"data":2320,"content":2321,"nodeType":1464},{},[2322],{"data":2323,"marks":2324,"value":2326,"nodeType":1293},{},[2325],{"type":1626},"Don’t rely on third-parties to protect your identities for you",{"data":2328,"content":2329,"nodeType":1294},{},[2330],{"data":2331,"marks":2332,"value":2333,"nodeType":1293},{},[],"Snowflake came under fire following the attacks for not enabling MFA by default, or giving security teams sufficient tools to deal with the incident. ",{"data":2335,"content":2336,"nodeType":1294},{},[2337],{"data":2338,"marks":2339,"value":2340,"nodeType":1293},{},[],"This is perhaps justifiable, but is hardly the exception. Very few apps enforce MFA by default or provide a global MFA enforcement mechanism. Most don’t even provide audit logs (and when they do, the scope of logging is pretty limited). And we regularly encounter apps that don’t give you any information about account configuration as an admin — like which accounts have MFA, or the login methods that they’re using (e.g. SSO via SAML, SSO via OIDC, password, which IdPs are being used…) which is essential information to be able to secure your identity attack surface. ",{"data":2342,"content":2343,"nodeType":1294},{},[2344],{"data":2345,"marks":2346,"value":2347,"nodeType":1293},{},[],"Yes, it would be great if app vendors put security first and made controls available by default, for all customers (not just the premium ones). But in the absence of an industrywide shift toward security-first product development, it’s important that organizations don’t just point the finger at service providers — and take matters into their own hands when it comes to securing their user identities. ",{"data":2349,"content":2350,"nodeType":1464},{},[2351],{"data":2352,"marks":2353,"value":2355,"nodeType":1293},{},[2354],{"type":1626},"This isn’t a specific Snowflake problem — it could have been any application",{"data":2357,"content":2358,"nodeType":1294},{},[2359],{"data":2360,"marks":2361,"value":2362,"nodeType":1293},{},[],"While Snowflake was admittedly a high-value target because of the data it collected, apps with sensitive data (or with integrations connecting them to data collected in adjacent apps) are not in short supply. ",{"data":2364,"content":2365,"nodeType":1294},{},[2366],{"data":2367,"marks":2368,"value":2369,"nodeType":1293},{},[],"If we accept that many other apps are similarly desirable targets, then we should also consider that it’s unlikely that Snowflake is the only app that has valid credentials sitting around on the internet, waiting to be weaponized by criminals. Equally, it’s not the only app that doesn’t require mandatory MFA for user accounts, as we discussed above. The next Snowflake is likely to lurk in the same breached datasets, possibly even using the same credentials.",{"data":2371,"content":2372,"nodeType":1294},{},[2373],{"data":2374,"marks":2375,"value":2376,"nodeType":1293},{},[],"There’s been a clear increase in the number of infostealer and stolen credential related breaches and news stories since Snowflake as attackers wise up to the potential opportunity and start seeing the dollar signs. It would be naive to think that this was a one off event — the next Snowflake is probably not too far away. ",{"data":2378,"content":2379,"nodeType":1294},{},[2380],{"data":2381,"marks":2382,"value":2383,"nodeType":1293},{},[],"For a deep-dive analysis of the impact of Snowflake, check out our on-demand webinar from earlier this year.",{"data":2385,"content":2389,"nodeType":1345},{"target":2386},{"sys":2387},{"id":2388,"type":1350,"linkType":1351},"7LkU5DqE9HJ1PQu9BTg6Mw",[],{"data":2391,"content":2392,"nodeType":1753},{},[],{"data":2394,"content":2395,"nodeType":1403},{},[2396],{"data":2397,"marks":2398,"value":2400,"nodeType":1293},{},[2399],{"type":1626},"How to protect yourself from the next Snowflake using Push",{"data":2402,"content":2403,"nodeType":1294},{},[2404],{"data":2405,"marks":2406,"value":2407,"nodeType":1293},{},[],"Organizations looking to reduce their exposure to account takeover using stolen credentials should look to:",{"data":2409,"content":2410,"nodeType":1361},{},[2411,2421,2431],{"data":2412,"content":2413,"nodeType":1365},{},[2414],{"data":2415,"content":2416,"nodeType":1294},{},[2417],{"data":2418,"marks":2419,"value":2420,"nodeType":1293},{},[],"Identify the apps being used across the business and locate vulnerable workforce identities using weak, breached, or reused credentials, and missing MFA. Where SSO is the preferred login method, local username & password logins should ideally be removed. ",{"data":2422,"content":2423,"nodeType":1365},{},[2424],{"data":2425,"content":2426,"nodeType":1294},{},[2427],{"data":2428,"marks":2429,"value":2430,"nodeType":1293},{},[],"Where credentials appear in third-party data breaches, verify where they are still valid and ensure that the credentials are changed. ",{"data":2432,"content":2433,"nodeType":1365},{},[2434],{"data":2435,"content":2436,"nodeType":1294},{},[2437],{"data":2438,"marks":2439,"value":2440,"nodeType":1293},{},[],"Detect unauthorized access to workforce identities where sessions are initiated or resumed from unusual or unexpected locations. It should be noted that while this is a fairly common feature for larger enterprise cloud platforms with configurable access control policies, this is not typically possible for most SaaS applications.  ",{"data":2442,"content":2443,"nodeType":1294},{},[2444],{"data":2445,"marks":2446,"value":2447,"nodeType":1293},{},[],"All of these use cases can be achieved using Push. The Push browser extension detects all logins performed in employee browsers, capturing granular information about the login method and MFA types used, and enriching this data by integrating with your preferred IdP.",{"data":2449,"content":2450,"nodeType":1294},{},[2451,2455,2463],{"data":2452,"marks":2453,"value":2454,"nodeType":1293},{},[],"Push’s ",{"data":2456,"content":2458,"nodeType":1445},{"uri":2457},"https://pushsecurity.com/blog/verified-stolen-credential-detection",[2459],{"data":2460,"marks":2461,"value":2462,"nodeType":1293},{},[],"verified stolen credential detection feature",{"data":2464,"marks":2465,"value":2466,"nodeType":1293},{},[]," compares a k-anonymized hash of user passwords observed with stolen credential TI feeds to cut through the noise and identify where stolen credentials appearing online represent a genuine vulnerability.   ",{"data":2468,"content":2469,"nodeType":1294},{},[2470,2474,2483],{"data":2471,"marks":2472,"value":2473,"nodeType":1293},{},[],"On top of this, all logins made in browsers protected by the Push extension, across every app, are verified by ",{"data":2475,"content":2477,"nodeType":1445},{"uri":2476},"https://pushsecurity.com/blog/introducing-session-token-theft-detection-why-browser-is-best/",[2478],{"data":2479,"marks":2480,"value":2482,"nodeType":1293},{},[2481],{"type":1486},"adding a unique marker to the user agent string of the session",{"data":2484,"marks":2485,"value":2486,"nodeType":1293},{},[],", which will then appear in your IdP logs. This means that any session occurring outside of the Push-protected estate can be flagged to your security team via SIEM alert — including where an attacker uses stolen credentials to log into an app from a browser without the Push extension running. ",{"data":2488,"content":2492,"nodeType":1345},{"target":2489},{"sys":2490},{"id":2491,"type":1350,"linkType":1351},"3tqVk7Vr7pYLOEVukIJM2g",[],{"data":2494,"content":2495,"nodeType":1294},{},[2496],{"data":2497,"marks":2498,"value":37,"nodeType":1293},{},[],"Snowflake: Looking back on 2024’s landmark security event","165 Snowflake customers were targeted by criminals using stolen credentials from infostealer infections, impacting hundreds of millions of people. ","2024-11-29T00:00:00.000Z","snowflake-retro",{"items":2504},[2505],{"sys":2506,"name":1308},{"id":1307},{"items":2508},[2509],{"fullName":2510,"firstName":2511,"jobTitle":2512,"profilePicture":2513},"Dan Green","Dan","Threat Research",{"url":2514},"https://images.ctfassets.net/y1cdw1ablpvd/7jik1VhFgA3kgzXBXTm2Vw/fcd8c171da644903d0827eafcfbcaad0/Dan_Headshot_2025.png",{"__typename":1316,"sys":2516,"content":2518,"title":3135,"synopsis":3136,"hashTags":118,"publishedDate":3137,"slug":3138,"tagsCollection":3139,"authorsCollection":3145},{"id":2517},"XQHcBu5kiSBd6MMwICYI4",{"json":2519},{"nodeType":1295,"data":2520,"content":2521},{},[2522,2529,2536,2544,2573,2580,2586,2589,2597,2604,2611,2654,2661,2668,2671,2679,2686,2693,2700,2720,2727,2733,2741,2748,2755,2762,2768,2771,2779,2787,2794,2802,2809,2874,2881,2889,2896,2929,2937,2944,2952,2959,2967,2974,3027,3034,3037,3045,3052,3069,3102,3123,3129],{"nodeType":1294,"data":2523,"content":2524},{},[2525],{"nodeType":1293,"value":2526,"marks":2527,"data":2528},"Phishing has undergone a radical transformation. The laughably bad emails and fake PayPal logins of the past have given way to sophisticated campaigns engineered to slip through even the most hardened security stacks. ",[],{},{"nodeType":1294,"data":2530,"content":2531},{},[2532],{"nodeType":1293,"value":2533,"marks":2534,"data":2535},"Today’s phishing attacks are faster, more adaptable, and harder to catch with traditional tools. Email filters and threat intel still play an important role, but they’re often reacting to threats that are already in motion, and by the time a phishing link is flagged and blocklisted, someone has probably already clicked — and the attacker has moved onto their next set of links.",[],{},{"nodeType":1294,"data":2537,"content":2538},{},[2539],{"nodeType":1293,"value":2540,"marks":2541,"data":2543},"The problem isn’t that phishing has evolved. It’s that our defenses haven’t.",[2542],{"type":1626},{},{"nodeType":1294,"data":2545,"content":2546},{},[2547,2551,2560,2564,2569],{"nodeType":1293,"value":2548,"marks":2549,"data":2550},"That’s where ",[],{},{"nodeType":1445,"data":2552,"content":2554},{"uri":2553},"https://pushsecurity.com/uc/zero-day-phishing-protection",[2555],{"nodeType":1293,"value":2556,"marks":2557,"data":2559},"Push Security",[2558],{"type":1486},{},{"nodeType":1293,"value":2561,"marks":2562,"data":2563}," comes in. By embedding real-time detection directly into the browser, the very place where phishing attacks unfold, Push offers a fundamentally new way to stop phishing: ",[],{},{"nodeType":1293,"value":2565,"marks":2566,"data":2568},"as it happens",[2567],{"type":312},{},{"nodeType":1293,"value":2570,"marks":2571,"data":2572},", regardless of whether or not the exact attack has ever been seen before. ",[],{},{"nodeType":1294,"data":2574,"content":2575},{},[2576],{"nodeType":1293,"value":2577,"marks":2578,"data":2579},"Check out the video to see how it works. ",[],{},{"nodeType":1345,"data":2581,"content":2585},{"target":2582},{"sys":2583},{"id":2584,"type":1350,"linkType":1351},"4LaKobadjp19jjocLXcW4E",[],{"nodeType":1753,"data":2587,"content":2588},{},[],{"nodeType":1403,"data":2590,"content":2591},{},[2592],{"nodeType":1293,"value":2593,"marks":2594,"data":2596},"The modern phishing playground",[2595],{"type":1626},{},{"nodeType":1294,"data":2598,"content":2599},{},[2600],{"nodeType":1293,"value":2601,"marks":2602,"data":2603},"Phishing attacks today look nothing like the blunt instruments of a few years ago. These are fast, customized, and often completely ephemeral. A phishing domain might go live at 9 a.m., compromise scores of credentials, and be gone before lunch, long before it ever hits a threat intel feed.",[],{},{"nodeType":1294,"data":2605,"content":2606},{},[2607],{"nodeType":1293,"value":2608,"marks":2609,"data":2610},"Modern attackers use:",[],{},{"nodeType":1361,"data":2612,"content":2613},{},[2614,2624,2634,2644],{"nodeType":1365,"data":2615,"content":2616},{},[2617],{"nodeType":1294,"data":2618,"content":2619},{},[2620],{"nodeType":1293,"value":2621,"marks":2622,"data":2623},"Dynamic content and user-adaptive emails that can be easily changed based on the target’s identity and environment.",[],{},{"nodeType":1365,"data":2625,"content":2626},{},[2627],{"nodeType":1294,"data":2628,"content":2629},{},[2630],{"nodeType":1293,"value":2631,"marks":2632,"data":2633},"Obfuscated URLs hidden behind trusted services (like Google Sites), making reputation analysis less than reliable.",[],{},{"nodeType":1365,"data":2635,"content":2636},{},[2637],{"nodeType":1294,"data":2638,"content":2639},{},[2640],{"nodeType":1293,"value":2641,"marks":2642,"data":2643},"Real-time proxying tools to clone login flows and harvest credentials.",[],{},{"nodeType":1365,"data":2645,"content":2646},{},[2647],{"nodeType":1294,"data":2648,"content":2649},{},[2650],{"nodeType":1293,"value":2651,"marks":2652,"data":2653},"Rapid-fire infrastructure rotation, making the attack’s infrastructure almost impossible to track in time.",[],{},{"nodeType":1294,"data":2655,"content":2656},{},[2657],{"nodeType":1293,"value":2658,"marks":2659,"data":2660},"These attacks often bypass traditional defenses entirely, not because the tools are broken, but because they were designed for a different era, one where phishing pages lived for days or weeks, not minutes.",[],{},{"nodeType":1294,"data":2662,"content":2663},{},[2664],{"nodeType":1293,"value":2665,"marks":2666,"data":2667},"It’s not enough to know what was bad yesterday. You need to know what’s happening now.",[],{},{"nodeType":1753,"data":2669,"content":2670},{},[],{"nodeType":1403,"data":2672,"content":2673},{},[2674],{"nodeType":1293,"value":2675,"marks":2676,"data":2678},"Why blocklists and perimeter defenses are falling behind",[2677],{"type":1626},{},{"nodeType":1294,"data":2680,"content":2681},{},[2682],{"nodeType":1293,"value":2683,"marks":2684,"data":2685},"The security ecosystem has long depended on reputation-based systems: block the known bad, allow the rest. That worked when attackers reused infrastructure and relied on mass campaigns. Today’s adversaries have adapted.",[],{},{"nodeType":1294,"data":2687,"content":2688},{},[2689],{"nodeType":1293,"value":2690,"marks":2691,"data":2692},"Consider a scenario similar to the one from our video:",[],{},{"nodeType":1294,"data":2694,"content":2695},{},[2696],{"nodeType":1293,"value":2697,"marks":2698,"data":2699},"A staff member receives an email appearing to be from Microsoft Teams. It includes dynamic content that mirrors their actual environment, including their username, company logo, and real collaboration data. The embedded link takes them to a cloned Microsoft login page hosted on a benign-looking subdomain. The site is brand new. It’s not on any blocklist. Your email filter passes it. The employee logs in. Credentials and session tokens? Gone.",[],{},{"nodeType":1294,"data":2701,"content":2702},{},[2703,2707,2716],{"nodeType":1293,"value":2704,"marks":2705,"data":2706},"And that’s just step one. The attacker now pivots to connected apps like ",[],{},{"nodeType":1445,"data":2708,"content":2710},{"uri":2709},"https://pushsecurity.com/blog/why-attackers-are-targeting-jira-with-stolen-credentials/",[2711],{"nodeType":1293,"value":2712,"marks":2713,"data":2715},"Jira",[2714],{"type":1486},{},{"nodeType":1293,"value":2717,"marks":2718,"data":2719},", Confluence, or AWS, moving laterally through your cloud environment using the compromised credentials.",[],{},{"nodeType":1294,"data":2721,"content":2722},{},[2723],{"nodeType":1293,"value":2724,"marks":2725,"data":2726},"Traditional tools often miss these threats not due to a lack of sophistication, but because they’re looking from the outside in. The browser is where the attack actually unfolds. Without visibility there, key indicators of compromise go undetected.",[],{},{"nodeType":1345,"data":2728,"content":2732},{"target":2729},{"sys":2730},{"id":2731,"type":1350,"linkType":1351},"1UGu43QxCiYofkeGtOMp5J",[],{"nodeType":1403,"data":2734,"content":2735},{},[2736],{"nodeType":1293,"value":2737,"marks":2738,"data":2740},"Rethinking where phishing defense happens",[2739],{"type":1626},{},{"nodeType":1294,"data":2742,"content":2743},{},[2744],{"nodeType":1293,"value":2745,"marks":2746,"data":2747},"Push changes where phishing protection happens, from upstream detection to point-of-interaction control. Instead of chasing malicious links through email gateways or external threat feeds, Push embeds lightweight, always-on protection directly, as users go about their work in the browser.",[],{},{"nodeType":1294,"data":2749,"content":2750},{},[2751],{"nodeType":1293,"value":2752,"marks":2753,"data":2754},"Push monitors what’s happening in each session: how pages are built, how they behave, and how users interact with them. That means it can recognize when a login prompt doesn’t match your identity provider or when a script behaves like part of a phishing toolkit.",[],{},{"nodeType":1294,"data":2756,"content":2757},{},[2758],{"nodeType":1293,"value":2759,"marks":2760,"data":2761},"When Push identifies something suspicious, it takes action right away. Logins are interrupted before any data is exposed. Users get clear guidance in-browser. And security teams receive detailed telemetry that shows exactly what happened, who was targeted, and how the threat was stopped.",[],{},{"nodeType":1345,"data":2763,"content":2767},{"target":2764},{"sys":2765},{"id":2766,"type":1350,"linkType":1351},"7Hu3kypFWwJAGOuQp0kYmU",[],{"nodeType":1753,"data":2769,"content":2770},{},[],{"nodeType":1403,"data":2772,"content":2773},{},[2774],{"nodeType":1293,"value":2775,"marks":2776,"data":2778},"The benefits of browser-native phishing defense",[2777],{"type":1626},{},{"nodeType":1464,"data":2780,"content":2781},{},[2782],{"nodeType":1293,"value":2783,"marks":2784,"data":2786},"True zero-day protection",[2785],{"type":1626},{},{"nodeType":1294,"data":2788,"content":2789},{},[2790],{"nodeType":1293,"value":2791,"marks":2792,"data":2793},"Push doesn’t rely on known indicators of compromise. It evaluates the actual behavior and context of every session in real-time. Whether the phishing site was created 5 months ago or 5 minutes ago is irrelevant — Push detects it and shuts it down.",[],{},{"nodeType":1464,"data":2795,"content":2796},{},[2797],{"nodeType":1293,"value":2798,"marks":2799,"data":2801},"Contextual threat detection",[2800],{"type":1626},{},{"nodeType":1294,"data":2803,"content":2804},{},[2805],{"nodeType":1293,"value":2806,"marks":2807,"data":2808},"Because Push operates in the browser, it sees everything:",[],{},{"nodeType":1361,"data":2810,"content":2811},{},[2812,2822,2832,2854,2864],{"nodeType":1365,"data":2813,"content":2814},{},[2815],{"nodeType":1294,"data":2816,"content":2817},{},[2818],{"nodeType":1293,"value":2819,"marks":2820,"data":2821},"The page layout",[],{},{"nodeType":1365,"data":2823,"content":2824},{},[2825],{"nodeType":1294,"data":2826,"content":2827},{},[2828],{"nodeType":1293,"value":2829,"marks":2830,"data":2831},"Where the user came from",[],{},{"nodeType":1365,"data":2833,"content":2834},{},[2835],{"nodeType":1294,"data":2836,"content":2837},{},[2838,2842,2851],{"nodeType":1293,"value":2839,"marks":2840,"data":2841},"The password they enter ",[],{},{"nodeType":1445,"data":2843,"content":2845},{"uri":2844},"https://pushsecurity.com/help/10043/#how-push-securely-analyzes-passwords",[2846],{"nodeType":1293,"value":2847,"marks":2848,"data":2850},"(as a salted, abbreviated hash)",[2849],{"type":1486},{},{"nodeType":1293,"value":37,"marks":2852,"data":2853},[],{},{"nodeType":1365,"data":2855,"content":2856},{},[2857],{"nodeType":1294,"data":2858,"content":2859},{},[2860],{"nodeType":1293,"value":2861,"marks":2862,"data":2863},"What scripts are running",[],{},{"nodeType":1365,"data":2865,"content":2866},{},[2867],{"nodeType":1294,"data":2868,"content":2869},{},[2870],{"nodeType":1293,"value":2871,"marks":2872,"data":2873},"And where credentials are being sent",[],{},{"nodeType":1294,"data":2875,"content":2876},{},[2877],{"nodeType":1293,"value":2878,"marks":2879,"data":2880},"This context enables Push to stop even well-camouflaged phishing attempts, including AitM attacks that bypass MFA.",[],{},{"nodeType":1464,"data":2882,"content":2883},{},[2884],{"nodeType":1293,"value":2885,"marks":2886,"data":2888},"Real-time interception of malicious activity",[2887],{"type":1626},{},{"nodeType":1294,"data":2890,"content":2891},{},[2892],{"nodeType":1293,"value":2893,"marks":2894,"data":2895},"As soon as a phishing attempt is confirmed, the response is immediate:",[],{},{"nodeType":1361,"data":2897,"content":2898},{},[2899,2909,2919],{"nodeType":1365,"data":2900,"content":2901},{},[2902],{"nodeType":1294,"data":2903,"content":2904},{},[2905],{"nodeType":1293,"value":2906,"marks":2907,"data":2908},"Credential entry is halted.",[],{},{"nodeType":1365,"data":2910,"content":2911},{},[2912],{"nodeType":1294,"data":2913,"content":2914},{},[2915],{"nodeType":1293,"value":2916,"marks":2917,"data":2918},"Sessions are revoked.",[],{},{"nodeType":1365,"data":2920,"content":2921},{},[2922],{"nodeType":1294,"data":2923,"content":2924},{},[2925],{"nodeType":1293,"value":2926,"marks":2927,"data":2928},"The user is protected without delay.",[],{},{"nodeType":1464,"data":2930,"content":2931},{},[2932],{"nodeType":1293,"value":2933,"marks":2934,"data":2936},"Reduced incident response overhead",[2935],{"type":1626},{},{"nodeType":1294,"data":2938,"content":2939},{},[2940],{"nodeType":1293,"value":2941,"marks":2942,"data":2943},"Most phishing attacks end in hours of IR and expensive cleanup. With Push, attacks don’t escalate beyond the initial click. That means fewer compromised accounts, fewer escalations, and less fatigue on your security team.",[],{},{"nodeType":1464,"data":2945,"content":2946},{},[2947],{"nodeType":1293,"value":2948,"marks":2949,"data":2951},"Empowered, educated users",[2950],{"type":1626},{},{"nodeType":1294,"data":2953,"content":2954},{},[2955],{"nodeType":1293,"value":2956,"marks":2957,"data":2958},"Push doesn’t just block phishing; it helps users learn from it. When someone interacts with a suspicious page, they get clear, actionable feedback right in the browser. Over time, these in-the-moment cues help build stronger phishing awareness across your workforce. Employee-facing messages are fully customizable to match the tone and style of your organization.",[],{},{"nodeType":1464,"data":2960,"content":2961},{},[2962],{"nodeType":1293,"value":2963,"marks":2964,"data":2966},"A new paradigm for identity security",[2965],{"type":1626},{},{"nodeType":1294,"data":2968,"content":2969},{},[2970],{"nodeType":1293,"value":2971,"marks":2972,"data":2973},"While phishing detection is core, Push also helps you defend your entire browser-based identity attack surface. That means protecting against other common forms of account compromise, like:",[],{},{"nodeType":1361,"data":2975,"content":2976},{},[2977,2987,2997,3007,3017],{"nodeType":1365,"data":2978,"content":2979},{},[2980],{"nodeType":1294,"data":2981,"content":2982},{},[2983],{"nodeType":1293,"value":2984,"marks":2985,"data":2986},"Employees using breached or reused passwords",[],{},{"nodeType":1365,"data":2988,"content":2989},{},[2990],{"nodeType":1294,"data":2991,"content":2992},{},[2993],{"nodeType":1293,"value":2994,"marks":2995,"data":2996},"Missing or misconfigured MFA",[],{},{"nodeType":1365,"data":2998,"content":2999},{},[3000],{"nodeType":1294,"data":3001,"content":3002},{},[3003],{"nodeType":1293,"value":3004,"marks":3005,"data":3006},"Ghost logins that bypass your identity provider",[],{},{"nodeType":1365,"data":3008,"content":3009},{},[3010],{"nodeType":1294,"data":3011,"content":3012},{},[3013],{"nodeType":1293,"value":3014,"marks":3015,"data":3016},"Token-based session hijacking",[],{},{"nodeType":1365,"data":3018,"content":3019},{},[3020],{"nodeType":1294,"data":3021,"content":3022},{},[3023],{"nodeType":1293,"value":3024,"marks":3025,"data":3026},"Shadow SaaS usage",[],{},{"nodeType":1294,"data":3028,"content":3029},{},[3030],{"nodeType":1293,"value":3031,"marks":3032,"data":3033},"Because Push runs directly in the browser, it gives you visibility across every app your employees access, whether it’s officially managed or not. And it doesn’t just alert, it actively helps you fix the issues, guiding users to take action when risks are found.",[],{},{"nodeType":1753,"data":3035,"content":3036},{},[],{"nodeType":1403,"data":3038,"content":3039},{},[3040],{"nodeType":1293,"value":3041,"marks":3042,"data":3044},"Modern phishing requires a modern defense",[3043],{"type":1626},{},{"nodeType":1294,"data":3046,"content":3047},{},[3048],{"nodeType":1293,"value":3049,"marks":3050,"data":3051},"Phishing is no longer an email problem. It’s not even just a domain reputation problem. It’s an identity attack problem, and the only place you can see those attacks in action is inside the browser.",[],{},{"nodeType":1294,"data":3053,"content":3054},{},[3055,3059,3066],{"nodeType":1293,"value":3056,"marks":3057,"data":3058},"Push Security gives you a new advantage: proactive, in-browser protection against modern phishing campaigns — ",[],{},{"nodeType":1445,"data":3060,"content":3061},{"uri":2553},[3062],{"nodeType":1293,"value":3063,"marks":3064,"data":3065},"even those with never-before-seen phishing sites",[],{},{"nodeType":1293,"value":2226,"marks":3067,"data":3068},[],{},{"nodeType":1361,"data":3070,"content":3071},{},[3072,3082,3092],{"nodeType":1365,"data":3073,"content":3074},{},[3075],{"nodeType":1294,"data":3076,"content":3077},{},[3078],{"nodeType":1293,"value":3079,"marks":3080,"data":3081},"See the phish happen.",[],{},{"nodeType":1365,"data":3083,"content":3084},{},[3085],{"nodeType":1294,"data":3086,"content":3087},{},[3088],{"nodeType":1293,"value":3089,"marks":3090,"data":3091},"Stop it in real time.",[],{},{"nodeType":1365,"data":3093,"content":3094},{},[3095],{"nodeType":1294,"data":3096,"content":3097},{},[3098],{"nodeType":1293,"value":3099,"marks":3100,"data":3101},"Keep your workforce identities safe.",[],{},{"nodeType":1294,"data":3103,"content":3104},{},[3105,3110,3118],{"nodeType":1293,"value":3106,"marks":3107,"data":3109},"Want to see Push in action? ",[3108],{"type":1626},{},{"nodeType":1445,"data":3111,"content":3112},{"uri":1656},[3113],{"nodeType":1293,"value":3114,"marks":3115,"data":3117},"Book a demo",[3116],{"type":1626},{},{"nodeType":1293,"value":3119,"marks":3120,"data":3122}," and watch a real-time phishing attack get stopped mid-flow.",[3121],{"type":1626},{},{"nodeType":1345,"data":3124,"content":3128},{"target":3125},{"sys":3126},{"id":3127,"type":1350,"linkType":1351},"7eSsPjEj178j3ViloaChbQ",[],{"nodeType":1294,"data":3130,"content":3131},{},[3132],{"nodeType":1293,"value":37,"marks":3133,"data":3134},[],{},"How browser-level controls change the fight against phishing","Attackers are routinely defeating conventional email, network, and endpoint-based security controls. Here's how browser controls can level the playing field.","2025-06-26T00:00:00.000Z","how-browser-level-controls-change-the-fight-against-phishing",{"items":3140},[3141,3143],{"sys":3142,"name":1308},{"id":1307},{"sys":3144,"name":1312},{"id":1311},{"items":3146},[3147],{"fullName":3148,"firstName":3149,"jobTitle":1694,"profilePicture":3150},"Peyton Padfield","Peyton",{"url":3151},"https://images.ctfassets.net/y1cdw1ablpvd/1GU01HXElmc07nwi89qP3b/3188050420106c62e9df2ed4e4893b7f/1677005177901__1_.jpeg",{"items":3153},[3154],{"fullName":2510,"firstName":2511,"jobTitle":2512,"profilePicture":3155},{"url":2514},{"json":3157,"links":4529},{"nodeType":1295,"data":3158,"content":3159},{},[3160,3166,3174,3181,3214,3220,3228,3257,3299,3305,3313,3331,3337,3340,3348,3355,3361,3406,3563,3566,3574,3581,3589,3622,3628,3636,3656,3663,3669,3676,3682,3702,3710,3728,3736,3743,3750,3753,3761,3768,3774,3781,3789,3807,3814,3820,3828,3835,3842,3875,3881,3888,3896,3903,3909,3942,3950,3970,3977,3983,3991,4011,4018,4081,4087,4090,4098,4105,4112,4143,4146,4154,4162,4168,4175,4183,4189,4196,4203,4209,4216,4224,4231,4238,4245,4264,4283,4290,4297,4303,4310,4318,4325,4332,4338,4345,4353,4360,4367,4374,4380,4387,4395,4402,4420,4426,4433,4454,4460,4467,4487,4493,4496,4504,4511],{"nodeType":1345,"data":3161,"content":3165},{"target":3162},{"sys":3163},{"id":3164,"type":1350,"linkType":1351},"6BjaSruVecmhn1NoHreRni",[],{"nodeType":1403,"data":3167,"content":3168},{},[3169],{"nodeType":1293,"value":3170,"marks":3171,"data":3173},"Background: Who are Scattered Spider?",[3172],{"type":1626},{},{"nodeType":1294,"data":3175,"content":3176},{},[3177],{"nodeType":1293,"value":3178,"marks":3179,"data":3180},"Scattered Spider (also tracked as 0ktapus, Octo Tempest, Scatter Swine, Muddled Libra, and UNC3944) is a native English speaking, financially motivated criminal collective known for high-profile cyber breaches in recent years, including MoneyGram, Transport for London, Caesars, MGM Resorts, Clorox, DoorDash, Twilio, Reddit, Coinbase, MailChimp, Okta, HubSpot, Cloudflare, Activision, Pure Storage, and the ongoing Marks & Spencer, Co-op, and Harrods incidents.",[],{},{"nodeType":1294,"data":3182,"content":3183},{},[3184,3188,3197,3201,3210],{"nodeType":1293,"value":3185,"marks":3186,"data":3187},"Scattered Spider shares similar characteristics and TTPs with a number of named threat groups such as ",[],{},{"nodeType":1445,"data":3189,"content":3191},{"uri":3190},"https://www.cisa.gov/sites/default/files/2023-08/CSRB_Lapsus%24_508c.pdf",[3192],{"nodeType":1293,"value":3193,"marks":3194,"data":3196},"Lapsus$, Yanluowang, Karakurt",[3195],{"type":1486},{},{"nodeType":1293,"value":3198,"marks":3199,"data":3200},", and ",[],{},{"nodeType":1445,"data":3202,"content":3204},{"uri":3203},"https://pushsecurity.com/blog/snowflake-retro/",[3205],{"nodeType":1293,"value":3206,"marks":3207,"data":3209},"ShinyHunters",[3208],{"type":1486},{},{"nodeType":1293,"value":3211,"marks":3212,"data":3213}," (behind the Snowflake attacks in 2024).",[],{},{"nodeType":1345,"data":3215,"content":3219},{"target":3216},{"sys":3217},{"id":3218,"type":1350,"linkType":1351},"4sgT2Jw3iODUTdG2oPOrFC",[],{"nodeType":1464,"data":3221,"content":3222},{},[3223],{"nodeType":1293,"value":3224,"marks":3225,"data":3227},"Case study: MGM Resorts",[3226],{"type":1626},{},{"nodeType":1294,"data":3229,"content":3230},{},[3231,3235,3242,3246,3253],{"nodeType":1293,"value":3232,"marks":3233,"data":3234},"One of Scattered Spider’s most notorious and well-documented attacks was that affecting ",[],{},{"nodeType":1445,"data":3236,"content":3237},{"uri":1480},[3238],{"nodeType":1293,"value":1483,"marks":3239,"data":3241},[3240],{"type":1486},{},{"nodeType":1293,"value":3243,"marks":3244,"data":3245},". Scattered Spider socially engineered MGM Resorts helpdesk personnel bypass MFA and log into accounts for which they had acquired valid login credentials for via credential phishing and historical infostealer compromises. They specifically targeted accounts with Super Administrator privileges within MGM Resorts’ Okta tenant, which they then used to register a second, attacker-controlled IdP via ",[],{},{"nodeType":1445,"data":3247,"content":3248},{"uri":1501},[3249],{"nodeType":1293,"value":1504,"marks":3250,"data":3252},[3251],{"type":1486},{},{"nodeType":1293,"value":3254,"marks":3255,"data":3256},", which enabled them to impersonate any user within the Okta tenant. This then enabled them to abuse SSO access to downstream apps and platforms from various accounts, culminating in deployment of ransomware to around 100 ESXi servers and data exfiltration. ",[],{},{"nodeType":1294,"data":3258,"content":3259},{},[3260,3264,3269,3273,3278,3282,3287,3291,3296],{"nodeType":1293,"value":3261,"marks":3262,"data":3263},"The breach resulted in a ",[],{},{"nodeType":1293,"value":3265,"marks":3266,"data":3268},"36-hour outage",[3267],{"type":1626},{},{"nodeType":1293,"value":3270,"marks":3271,"data":3272},", a ",[],{},{"nodeType":1293,"value":3274,"marks":3275,"data":3277},"$100M ",[3276],{"type":1626},{},{"nodeType":1293,"value":3279,"marks":3280,"data":3281},"hit to its Q3 results, one-time cyber consulting fees in the region of ",[],{},{"nodeType":1293,"value":3283,"marks":3284,"data":3286},"$10M",[3285],{"type":1626},{},{"nodeType":1293,"value":3288,"marks":3289,"data":3290},", and a class-action lawsuit later settled for ",[],{},{"nodeType":1293,"value":3292,"marks":3293,"data":3295},"$45M",[3294],{"type":1626},{},{"nodeType":1293,"value":1788,"marks":3297,"data":3298},[],{},{"nodeType":1345,"data":3300,"content":3304},{"target":3301},{"sys":3302},{"id":3303,"type":1350,"linkType":1351},"2vYvBXqFeKt7Ix0Ynh8cZu",[],{"nodeType":1464,"data":3306,"content":3307},{},[3308],{"nodeType":1293,"value":3309,"marks":3310,"data":3312},"Case Study: Snowflake",[3311],{"type":1626},{},{"nodeType":1294,"data":3314,"content":3315},{},[3316,3320,3327],{"nodeType":1293,"value":3317,"marks":3318,"data":3319},"Members of Scattered Spider have been affiliated with ShinyHunters, the group behind the ",[],{},{"nodeType":1445,"data":3321,"content":3322},{"uri":3203},[3323],{"nodeType":1293,"value":3324,"marks":3325,"data":3326},"Snowflake breaches in mid-2024",[],{},{"nodeType":1293,"value":3328,"marks":3329,"data":3330},". ShinyHunters associates targeted ~165 organizations that were subjected to account takeover attacks using stolen credentials harvested from historical infostealer infections dating back as far as 2020, according to Mandiant’s investigation. In total, 9 public victims were named following the breach, collectively impacting hundreds of millions of people. Snowflake was a watershed moment that signalled the significant opportunity presented by identity attacks on cloud services. It demonstrated how comparatively unsophisticated methods (logging in to user accounts with stolen credentials and dumping the data) can have the same or greater impact as a traditional network or endpoint based cyber attack involving vulnerability exploitation, malware deployment, ransomware, etc.",[],{},{"nodeType":1345,"data":3332,"content":3336},{"target":3333},{"sys":3334},{"id":3335,"type":1350,"linkType":1351},"49nJMPQjQ37Mfr2yWA56P3",[],{"nodeType":1753,"data":3338,"content":3339},{},[],{"nodeType":1403,"data":3341,"content":3342},{},[3343],{"nodeType":1293,"value":3344,"marks":3345,"data":3347},"Arrests haven’t slowed Scattered Spider",[3346],{"type":1626},{},{"nodeType":1294,"data":3349,"content":3350},{},[3351],{"nodeType":1293,"value":3352,"marks":3353,"data":3354},"In late 2024 following the Transport for London attacks (which resulted in prolonged disruption to key online services underpinning London’s public transport network, theft of 5,000 users bank details, and all 30,000 staff members having to reset their online credentials in person) a series of arrests were made in the UK and USA. ",[],{},{"nodeType":1345,"data":3356,"content":3360},{"target":3357},{"sys":3358},{"id":3359,"type":1350,"linkType":1351},"2X2nyhO2hOqm9f0Le4lDC5",[],{"nodeType":1294,"data":3362,"content":3363},{},[3364,3368,3377,3381,3390,3393,3402],{"nodeType":1293,"value":3365,"marks":3366,"data":3367},"However, this doesn’t seem to have impacted Scattered Spider’s ability to operate, with the ongoing campaign against UK retail companies including ",[],{},{"nodeType":1445,"data":3369,"content":3371},{"uri":3370},"https://www.bleepingcomputer.com/news/security/marks-and-spencer-breach-linked-to-scattered-spider-ransomware-attack/",[3372],{"nodeType":1293,"value":3373,"marks":3374,"data":3376},"Marks and Spencer",[3375],{"type":1486},{},{"nodeType":1293,"value":3378,"marks":3379,"data":3380},", ",[],{},{"nodeType":1445,"data":3382,"content":3384},{"uri":3383},"https://www.bleepingcomputer.com/news/security/co-op-confirms-data-theft-after-dragonforce-ransomware-claims-attack/",[3385],{"nodeType":1293,"value":3386,"marks":3387,"data":3389},"Co-op",[3388],{"type":1486},{},{"nodeType":1293,"value":3198,"marks":3391,"data":3392},[],{},{"nodeType":1445,"data":3394,"content":3396},{"uri":3395},"https://www.bleepingcomputer.com/news/security/harrods-the-next-uk-retailer-targeted-in-a-cyberattack/",[3397],{"nodeType":1293,"value":3398,"marks":3399,"data":3401},"Harrods",[3400],{"type":1486},{},{"nodeType":1293,"value":3403,"marks":3404,"data":3405}," being strongly linked to Scattered Spider. Beginning on Easter weekend, the Marks and Spencer attack has had the biggest impact so far, resulting in severe disruption to the retailer with agency staff told not to come into work, online shopping services being taken offline, stores running low on products, £300M in lost profits, and almost £1B wiped off the company’s stock market valuation at one stage. ",[],{},{"nodeType":1294,"data":3407,"content":3408},{},[3409,3413,3422,3425,3434,3437,3446,3449,3458,3461,3470,3473,3482,3485,3494,3498,3506,3509,3517,3520,3528,3531,3539,3542,3549,3552,3560],{"nodeType":1293,"value":3410,"marks":3411,"data":3412},"A series of attacks against retailers worldwide soon followed, at an unprecedented rate. ",[],{},{"nodeType":1445,"data":3414,"content":3416},{"uri":3415},"https://www.bleepingcomputer.com/news/security/fashion-giant-dior-discloses-cyberattack-warns-of-data-breach/",[3417],{"nodeType":1293,"value":3418,"marks":3419,"data":3421},"Dior",[3420],{"type":1486},{},{"nodeType":1293,"value":3378,"marks":3423,"data":3424},[],{},{"nodeType":1445,"data":3426,"content":3428},{"uri":3427},"https://www.bleepingcomputer.com/news/security/the-north-face-warns-customers-of-april-credential-stuffing-attack/",[3429],{"nodeType":1293,"value":3430,"marks":3431,"data":3433},"The North Face",[3432],{"type":1486},{},{"nodeType":1293,"value":3378,"marks":3435,"data":3436},[],{},{"nodeType":1445,"data":3438,"content":3440},{"uri":3439},"https://www.bleepingcomputer.com/news/security/cartier-discloses-data-breach-amid-fashion-brand-cyberattacks/",[3441],{"nodeType":1293,"value":3442,"marks":3443,"data":3445},"Cartier",[3444],{"type":1486},{},{"nodeType":1293,"value":3378,"marks":3447,"data":3448},[],{},{"nodeType":1445,"data":3450,"content":3452},{"uri":3451},"https://www.bleepingcomputer.com/news/security/victorias-secret-delays-earnings-release-after-security-incident/",[3453],{"nodeType":1293,"value":3454,"marks":3455,"data":3457},"Victoria’s Secret",[3456],{"type":1486},{},{"nodeType":1293,"value":3378,"marks":3459,"data":3460},[],{},{"nodeType":1445,"data":3462,"content":3464},{"uri":3463},"https://www.bleepingcomputer.com/news/security/adidas-warns-of-data-breach-after-customer-service-provider-hack/",[3465],{"nodeType":1293,"value":3466,"marks":3467,"data":3469},"Adidas",[3468],{"type":1486},{},{"nodeType":1293,"value":3378,"marks":3471,"data":3472},[],{},{"nodeType":1445,"data":3474,"content":3476},{"uri":3475},"https://www.scworld.com/brief/separate-ransomware-attacks-purportedly-hit-coca-cola-bottling-partner",[3477],{"nodeType":1293,"value":3478,"marks":3479,"data":3481},"Coca-Cola",[3480],{"type":1486},{},{"nodeType":1293,"value":3198,"marks":3483,"data":3484},[],{},{"nodeType":1445,"data":3486,"content":3488},{"uri":3487},"https://www.bleepingcomputer.com/news/security/grocery-wholesale-giant-united-natural-foods-hit-by-cyberattack/",[3489],{"nodeType":1293,"value":3490,"marks":3491,"data":3493},"United Natural Foods",[3492],{"type":1486},{},{"nodeType":1293,"value":3495,"marks":3496,"data":3497}," were among the retailers to suffer a breach between May-June 2025. More recently, Scattered Spider has targeted U.S. insurance giant ",[],{},{"nodeType":1445,"data":3499,"content":3501},{"uri":3500},"https://www.bleepingcomputer.com/news/security/aflac-discloses-breach-amidst-scattered-spider-insurance-attacks/",[3502],{"nodeType":1293,"value":3503,"marks":3504,"data":3505},"Aflac",[],{},{"nodeType":1293,"value":3378,"marks":3507,"data":3508},[],{},{"nodeType":1445,"data":3510,"content":3512},{"uri":3511},"https://www.bleepingcomputer.com/news/security/google-warns-scattered-spider-hackers-now-target-us-insurance-companies/",[3513],{"nodeType":1293,"value":3514,"marks":3515,"data":3516},"Philadelphia Insurance Companies",[],{},{"nodeType":1293,"value":3378,"marks":3518,"data":3519},[],{},{"nodeType":1445,"data":3521,"content":3523},{"uri":3522},"https://www.bleepingcomputer.com/news/security/erie-insurance-confirms-cyberattack-behind-business-disruptions/amp/",[3524],{"nodeType":1293,"value":3525,"marks":3526,"data":3527},"Erie Insurance",[],{},{"nodeType":1293,"value":3378,"marks":3529,"data":3530},[],{},{"nodeType":1445,"data":3532,"content":3534},{"uri":3533},"https://www.bleepingcomputer.com/news/security/scattered-spider-hackers-shift-focus-to-aviation-transportation-firms/",[3535],{"nodeType":1293,"value":3536,"marks":3537,"data":3538},"Hawaiian Airlines",[],{},{"nodeType":1293,"value":3378,"marks":3540,"data":3541},[],{},{"nodeType":1445,"data":3543,"content":3544},{"uri":3533},[3545],{"nodeType":1293,"value":3546,"marks":3547,"data":3548},"WestJet",[],{},{"nodeType":1293,"value":3198,"marks":3550,"data":3551},[],{},{"nodeType":1445,"data":3553,"content":3555},{"uri":3554},"https://www.bleepingcomputer.com/news/security/qantas-is-being-extorted-in-recent-data-theft-cyberattack/",[3556],{"nodeType":1293,"value":3557,"marks":3558,"data":3559},"Qantas",[],{},{"nodeType":1293,"value":2226,"marks":3561,"data":3562},[],{},{"nodeType":1753,"data":3564,"content":3565},{},[],{"nodeType":1403,"data":3567,"content":3568},{},[3569],{"nodeType":1293,"value":3570,"marks":3571,"data":3573},"Scattered Spider TTP analysis",[3572],{"type":1626},{},{"nodeType":1294,"data":3575,"content":3576},{},[3577],{"nodeType":1293,"value":3578,"marks":3579,"data":3580},"Along with a clear MO (financial gain via data exfiltration and extortion) Scattered Spider has demonstrated a pattern of go-to TTPs over recent years. ",[],{},{"nodeType":1464,"data":3582,"content":3583},{},[3584],{"nodeType":1293,"value":3585,"marks":3586,"data":3588},"Social engineering, help desk scams, and SIM swapping",[3587],{"type":1626},{},{"nodeType":1294,"data":3590,"content":3591},{},[3592,3596,3605,3609,3618],{"nodeType":1293,"value":3593,"marks":3594,"data":3595},"The public breaches associated with Scattered Spider have predominantly featured social engineering heavy initial access, mainly through help desk scams where the attacker contacts support personnel specifically to bypass MFA for accounts where they have acquired valid credentials via credential phishing or infostealers, but cannot access the account due the additional layer of protection. They have similarly used ",[],{},{"nodeType":1445,"data":3597,"content":3599},{"uri":3598},"https://cloud.google.com/blog/topics/threat-intelligence/unc3944-sms-phishing-sim-swapping-ransomware/",[3600],{"nodeType":1293,"value":3601,"marks":3602,"data":3604},"SIM swapping, smishing",[3603],{"type":1486},{},{"nodeType":1293,"value":3606,"marks":3607,"data":3608}," and ",[],{},{"nodeType":1445,"data":3610,"content":3612},{"uri":3611},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/mfa_fatigue/description.md",[3613],{"nodeType":1293,"value":3614,"marks":3615,"data":3617},"MFA fatigue/push bombing",[3616],{"type":1486},{},{"nodeType":1293,"value":3619,"marks":3620,"data":3621}," to achieve account takeover.",[],{},{"nodeType":1345,"data":3623,"content":3627},{"target":3624},{"sys":3625},{"id":3626,"type":1350,"linkType":1351},"2Z7qnaK4LXRhnQDvPT2ZXe",[],{"nodeType":1464,"data":3629,"content":3630},{},[3631],{"nodeType":1293,"value":3632,"marks":3633,"data":3635},"Impersonating and targeting SaaS services",[3634],{"type":1626},{},{"nodeType":1294,"data":3637,"content":3638},{},[3639,3643,3652],{"nodeType":1293,"value":3640,"marks":3641,"data":3642},"Scattered Spider have also been known to ",[],{},{"nodeType":1445,"data":3644,"content":3646},{"uri":3645},"https://cloud.google.com/blog/topics/threat-intelligence/unc3944-targets-saas-applications",[3647],{"nodeType":1293,"value":3648,"marks":3649,"data":3651},"target SaaS applications and cloud services",[3650],{"type":1486},{},{"nodeType":1293,"value":3653,"marks":3654,"data":3655}," — both as part of their phishing strategies by impersonating app providers, as well as in their lateral movement and exploitation when an identity has been compromised. This has included applications such as vCenter, CyberArk, SalesForce, Azure, CrowdStrike, AWS, and GCP. ",[],{},{"nodeType":1294,"data":3657,"content":3658},{},[3659],{"nodeType":1293,"value":3660,"marks":3661,"data":3662},"When conducting phishing campaigns, they’ve created custom domains for their phishing sites based on the organizations they are targeting: ",[],{},{"nodeType":1345,"data":3664,"content":3668},{"target":3665},{"sys":3666},{"id":3667,"type":1350,"linkType":1351},"3ufdtfyJpZ4FUWbKR2yNNm",[],{"nodeType":1294,"data":3670,"content":3671},{},[3672],{"nodeType":1293,"value":3673,"marks":3674,"data":3675},"And they have impersonated many software brands — either as targets themselves, or as convincing third-parties to lure their targets to interact with. ",[],{},{"nodeType":1345,"data":3677,"content":3681},{"target":3678},{"sys":3679},{"id":3680,"type":1350,"linkType":1351},"XgrG1qKwXrpd399BwkHiR",[],{"nodeType":1294,"data":3683,"content":3684},{},[3685,3689,3698],{"nodeType":1293,"value":3686,"marks":3687,"data":3688},"(Shout out to the excellent analysis by the folks at ",[],{},{"nodeType":1445,"data":3690,"content":3692},{"uri":3691},"https://www.silentpush.com/blog/scattered-spider-2025/#h-new-scattered-spider-ttps-for-2025",[3693],{"nodeType":1293,"value":3694,"marks":3695,"data":3697},"Silent Push",[3696],{"type":1486},{},{"nodeType":1293,"value":3699,"marks":3700,"data":3701},"). ",[],{},{"nodeType":1464,"data":3703,"content":3704},{},[3705],{"nodeType":1293,"value":3706,"marks":3707,"data":3709},"Targeting identity providers to abuse OAuth and SSO",[3708],{"type":1626},{},{"nodeType":1294,"data":3711,"content":3712},{},[3713,3717,3724],{"nodeType":1293,"value":3714,"marks":3715,"data":3716},"A key part of this approach is abusing OAuth by targeting identity providers (IdPs) such as Okta and Microsoft Entra. By compromising IdP accounts with administrator privileges, Scattered Spider has leveraged techniques such as ",[],{},{"nodeType":1445,"data":3718,"content":3719},{"uri":1501},[3720],{"nodeType":1293,"value":1504,"marks":3721,"data":3723},[3722],{"type":1486},{},{"nodeType":1293,"value":3725,"marks":3726,"data":3727}," to gain unrestricted access to the identities within the target IdP tenant (the equivalent of a full Active Directory compromise on-premise).",[],{},{"nodeType":1464,"data":3729,"content":3730},{},[3731],{"nodeType":1293,"value":3732,"marks":3733,"data":3735},"Encryption of cloud servers and data theft for extortion",[3734],{"type":1626},{},{"nodeType":1294,"data":3737,"content":3738},{},[3739],{"nodeType":1293,"value":3740,"marks":3741,"data":3742},"When executing the final stages of an attack, Scattered Spider first exfiltrates data through a variety of methods, even using SaaS services such as DropBox and FiveTran to extract copies of high-value service databases, such as SalesForce and ZenDesk, using API connectors. ",[],{},{"nodeType":1294,"data":3744,"content":3745},{},[3746],{"nodeType":1293,"value":3747,"marks":3748,"data":3749},"In a typical \"double-extortion\" style, they then deploy ransomware by targeting cloud server environments such as VMWare ESXi (specifically to avoid security tools by targeting the hypervisor layer). Scattered Spider have been known to act as affiliates for various ransomware operations, including RansomHub, Qilin, and DragonForce.",[],{},{"nodeType":1753,"data":3751,"content":3752},{},[],{"nodeType":1403,"data":3754,"content":3755},{},[3756],{"nodeType":1293,"value":3757,"marks":3758,"data":3760},"Scattered Spider TTP evolution in 2025",[3759],{"type":1626},{},{"nodeType":1294,"data":3762,"content":3763},{},[3764],{"nodeType":1293,"value":3765,"marks":3766,"data":3767},"In 2025, security researchers have observed a significant increase in Scattered Spider phishing activity, particularly in the form of MFA-bypassing Attacker-in-the-Middle (AiTM) phishing pages. ",[],{},{"nodeType":1345,"data":3769,"content":3773},{"target":3770},{"sys":3771},{"id":3772,"type":1350,"linkType":1351},"2jH5TrpHueIE8qpU3lunJi",[],{"nodeType":1294,"data":3775,"content":3776},{},[3777],{"nodeType":1293,"value":3778,"marks":3779,"data":3780},"Along with this shift, a number of TTPs have been observed relating to detection evasion measures implemented on these phishing pages.",[],{},{"nodeType":1464,"data":3782,"content":3783},{},[3784],{"nodeType":1293,"value":3785,"marks":3786,"data":3788},"Rapid phishing domain rotation",[3787],{"type":1626},{},{"nodeType":1294,"data":3790,"content":3791},{},[3792,3795,3803],{"nodeType":1293,"value":37,"marks":3793,"data":3794},[],{},{"nodeType":1445,"data":3796,"content":3797},{"uri":3691},[3798],{"nodeType":1293,"value":3799,"marks":3800,"data":3802},"According to researchers",[3801],{"type":1486},{},{"nodeType":1293,"value":3804,"marks":3805,"data":3806}," Scattered Spider have been observed using phishing pages hosted on short-lived domains that included specific keywords such as “okta,” “sso,” “help,” “hr,” “corp,” “my,” “internal,” “sso,” or “vpn,”, which were quickly operationalized within minutes of registering a domain. After a couple of hours, the domain would often be taken down by the registrar. However, as we’ve discussed in various blog posts, this is to be expected. Domains are highly disposable by nature and attackers plan to get through them in large numbers. They don’t need their phishing pages to live indefinitely — just as long as it takes for someone to be successfully phished.",[],{},{"nodeType":1294,"data":3808,"content":3809},{},[3810],{"nodeType":1293,"value":3811,"marks":3812,"data":3813},"You would expect these kinds of untrusted links to be flagged by enterprise security tools, but through clever use of obfuscation methods such as using legitimate apps to host the phishing link, using an initially benign link to a document or other source with the malicious link, or avoiding email as the delivery vector altogether, network and email-based controls are being routinely bypassed.  ",[],{},{"nodeType":1345,"data":3815,"content":3819},{"target":3816},{"sys":3817},{"id":3818,"type":1350,"linkType":1351},"2DviJNOMbKgbcqwkNl0LDP",[],{"nodeType":1464,"data":3821,"content":3822},{},[3823],{"nodeType":1293,"value":3824,"marks":3825,"data":3827},"Using custom subdomains that allow public registrations",[3826],{"type":1626},{},{"nodeType":1294,"data":3829,"content":3830},{},[3831],{"nodeType":1293,"value":3832,"marks":3833,"data":3834},"Scattered Spider have been observed registering their malicious domains on publicly rentable subdomains such as it[.]com. This limits the information that can be gathered about the domain (for example, preventing WHOIS information from being accessed) ",[],{},{"nodeType":1294,"data":3836,"content":3837},{},[3838],{"nodeType":1293,"value":3839,"marks":3840,"data":3841},"This is incredibly deceptive to the user and will fool many people glancing at the link. It doesn’t look as obviously suspicious as the typical .xyz or .biz, and has the feel of a legitimate domain. As these convincing rentable subdomains start to appear online more frequently, it becomes easier for attackers to pick up convincing domain names with fewer obvious deviations from the real one, without needing to resort to special characters or other tactics that might be spotted. ",[],{},{"nodeType":1294,"data":3843,"content":3844},{},[3845,3849,3858,3862,3871],{"nodeType":1293,"value":3846,"marks":3847,"data":3848},"This is strikingly similar ",[],{},{"nodeType":1445,"data":3850,"content":3852},{"uri":3851},"https://pushsecurity.com/blog/investigating-a-recent-malvertising-campaign-targeting-onfido-customers/",[3853],{"nodeType":1293,"value":3854,"marks":3855,"data":3857},"to an attack we investigated recently",[3856],{"type":1486},{},{"nodeType":1293,"value":3859,"marks":3860,"data":3861},", where an attacker was using the us[.]com domain to impersonate Onfido, the digital identity platform. These malicious links were actually distributed via malicious advertising on Google, which is an increasingly popular tactic ",[],{},{"nodeType":1445,"data":3863,"content":3865},{"uri":3864},"https://pushsecurity.com/blog/why-most-phishing-attacks-feel-like-a-zero-day/",[3866],{"nodeType":1293,"value":3867,"marks":3868,"data":3870},"to evade email and network detection controls",[3869],{"type":1486},{},{"nodeType":1293,"value":3872,"marks":3873,"data":3874}," for phishing links and pages. ",[],{},{"nodeType":1345,"data":3876,"content":3880},{"target":3877},{"sys":3878},{"id":3879,"type":1350,"linkType":1351},"34ZpjuFhaSMC6MtjThQsnK",[],{"nodeType":1294,"data":3882,"content":3883},{},[3884],{"nodeType":1293,"value":3885,"marks":3886,"data":3887},"This comparison is also interesting when you consider…",[],{},{"nodeType":1464,"data":3889,"content":3890},{},[3891],{"nodeType":1293,"value":3892,"marks":3893,"data":3895},"Using commercial AiTM toolkits like Evilginx to bypass MFA and evade detection",[3894],{"type":1626},{},{"nodeType":1294,"data":3897,"content":3898},{},[3899],{"nodeType":1293,"value":3900,"marks":3901,"data":3902},"Scattered Spider have been observed frequently using Evilginx as their phishing kit of choice. Evilginx is a great choice for attackers looking to target non-standard web apps because it is capable of emulating a range of domains — it’s designed to be flexible and work for any page without generating a load of custom JavaScript that might stand out to security tools/analysts. See an example of Evilginx being used to phish a user below.",[],{},{"nodeType":1345,"data":3904,"content":3908},{"target":3905},{"sys":3906},{"id":3907,"type":1350,"linkType":1351},"7IuP0mcRZJkL8YGNoZo5Dj",[],{"nodeType":1294,"data":3910,"content":3911},{},[3912,3916,3925,3929,3938],{"nodeType":1293,"value":3913,"marks":3914,"data":3915},"By default, Evilginx redirects any site visitor not following the correct url path or supplying the correct parameters to the YouTube video for Rick Astley’s “Never Gonna Give You Up” (aka “Rickrolling”). This behavior has been observed on Scattered Spider phishing sites. Interestingly, we also observed this in the Onfido malvertising example above, ",[],{},{"nodeType":1445,"data":3917,"content":3919},{"uri":3918},"https://www.linkedin.com/feed/update/urn:li:activity:7323102794813505536?commentUrn=urn%3Ali%3Acomment%3A%28activity%3A7323102794813505536%2C7323308731813814272%29&dashCommentUrn=urn%3Ali%3Afsd_comment%3A%287323308731813814272%2Curn%3Ali%3Aactivity%3A7323102794813505536%29",[3920],{"nodeType":1293,"value":3921,"marks":3922,"data":3924},"while members of the infosec community",[3923],{"type":1486},{},{"nodeType":1293,"value":3926,"marks":3927,"data":3928}," are increasingly seeing phishing attacks with this behavior. (This example also features use of ",[],{},{"nodeType":1445,"data":3930,"content":3932},{"uri":3931},"https://pushsecurity.com/blog/how-consent-phishing-is-evolving/",[3933],{"nodeType":1293,"value":3934,"marks":3935,"data":3937},"consent phishing",[3936],{"type":1486},{},{"nodeType":1293,"value":3939,"marks":3940,"data":3941}," to prevent analysis of the malicious link by hiding it behind a legit Microsoft app consent page, another detection evasion tactic). ",[],{},{"nodeType":1464,"data":3943,"content":3944},{},[3945],{"nodeType":1293,"value":3946,"marks":3947,"data":3949},"Pre-populating victim information using targeted phishing links",[3948],{"type":1626},{},{"nodeType":1294,"data":3951,"content":3952},{},[3953,3957,3966],{"nodeType":1293,"value":3954,"marks":3955,"data":3956},"A general trend that we’re seeing in the wild, also utilized by Scattered Spider, is phishing attacks becoming increasingly targeted. This includes using redirects to legitimate apps unless specific parameters are supplied, ",[],{},{"nodeType":1445,"data":3958,"content":3960},{"uri":3959},"https://www.bleepingcomputer.com/news/security/phishing-kits-now-vet-victims-in-real-time-before-stealing-credentials/",[3961],{"nodeType":1293,"value":3962,"marks":3963,"data":3965},"only loading malicious content for specific usernames",[3964],{"type":1486},{},{"nodeType":1293,"value":3967,"marks":3968,"data":3969}," (and redirecting to benign sites otherwise) implementing the use of one-time phishing links (essentially magic links that work once for the victim, preventing security teams or tools from accessing the page to analyse it later), and pre-populating the victim information on the page to make it feel more genuine (you would expect a website you have visited and logged into before to pre-populate some of your details, like your username/email). ",[],{},{"nodeType":1294,"data":3971,"content":3972},{},[3973],{"nodeType":1293,"value":3974,"marks":3975,"data":3976},"See an example of this (along with a few of the detection evasion techniques we've mentioned) below. ",[],{},{"nodeType":1345,"data":3978,"content":3982},{"target":3979},{"sys":3980},{"id":3981,"type":1350,"linkType":1351},"1zn1G6CutY0HBkXHUIo159",[],{"nodeType":1464,"data":3984,"content":3985},{},[3986],{"nodeType":1293,"value":3987,"marks":3988,"data":3990},"Varying login pages to evade cloned page detections",[3989],{"type":1626},{},{"nodeType":1294,"data":3992,"content":3993},{},[3994,3998,4007],{"nodeType":1293,"value":3995,"marks":3996,"data":3997},"Attackers are routinely using a ",[],{},{"nodeType":1445,"data":3999,"content":4001},{"uri":4000},"https://pushsecurity.com/blog/how-aitm-phishing-kits-evade-detection-p2/",[4002],{"nodeType":1293,"value":4003,"marks":4004,"data":4006},"combination of visual and DOM-based obfuscation techniques",[4005],{"type":1486},{},{"nodeType":1293,"value":4008,"marks":4009,"data":4010}," to create convincing phishing pages that are different enough from the real page being impersonated so that detections based on cloned pages do not fire. ",[],{},{"nodeType":1294,"data":4012,"content":4013},{},[4014],{"nodeType":1293,"value":4015,"marks":4016,"data":4017},"While Okta accounts remain a key target for Scattered Spider, they are using a range of customized landing pages to target Okta accounts for various organizations at URLs like:",[],{},{"nodeType":1361,"data":4019,"content":4020},{},[4021,4031,4041,4051,4061,4071],{"nodeType":1365,"data":4022,"content":4023},{},[4024],{"nodeType":1294,"data":4025,"content":4026},{},[4027],{"nodeType":1293,"value":4028,"marks":4029,"data":4030},"corp-hubspot[.]com – HubSpot",[],{},{"nodeType":1365,"data":4032,"content":4033},{},[4034],{"nodeType":1294,"data":4035,"content":4036},{},[4037],{"nodeType":1293,"value":4038,"marks":4039,"data":4040},"morningstar-okta[.]com – Morningstar",[],{},{"nodeType":1365,"data":4042,"content":4043},{},[4044],{"nodeType":1294,"data":4045,"content":4046},{},[4047],{"nodeType":1293,"value":4048,"marks":4049,"data":4050},"pure-okta[.]com – Pure Storage",[],{},{"nodeType":1365,"data":4052,"content":4053},{},[4054],{"nodeType":1294,"data":4055,"content":4056},{},[4057],{"nodeType":1293,"value":4058,"marks":4059,"data":4060},"signin-nydig[.]com – New York Digital Investment Group",[],{},{"nodeType":1365,"data":4062,"content":4063},{},[4064],{"nodeType":1294,"data":4065,"content":4066},{},[4067],{"nodeType":1293,"value":4068,"marks":4069,"data":4070},"sso-instacart[.]com – Instacart",[],{},{"nodeType":1365,"data":4072,"content":4073},{},[4074],{"nodeType":1294,"data":4075,"content":4076},{},[4077],{"nodeType":1293,"value":4078,"marks":4079,"data":4080},"sts-vodafone[.]com – Vodafone",[],{},{"nodeType":1345,"data":4082,"content":4086},{"target":4083},{"sys":4084},{"id":4085,"type":1350,"linkType":1351},"38EyQfvJWcqHukYq8rm8ap",[],{"nodeType":1753,"data":4088,"content":4089},{},[],{"nodeType":1403,"data":4091,"content":4092},{},[4093],{"nodeType":1293,"value":4094,"marks":4095,"data":4097},"Defend your organization from Scattered Spider",[4096],{"type":1626},{},{"nodeType":1294,"data":4099,"content":4100},{},[4101],{"nodeType":1293,"value":4102,"marks":4103,"data":4104},"Scattered Spider have proven to be a highly creative and adaptable threat group, using a range of identity-centric TTPs and evolving (or rather, adding to) their repertoire over time. ",[],{},{"nodeType":1294,"data":4106,"content":4107},{},[4108],{"nodeType":1293,"value":4109,"marks":4110,"data":4111},"Although Scattered Spider have a number of telltale actions and behaviors, like targeting and leveraging SaaS services, utilizing AiTM phishing kits like Evilginx to target IdP accounts like Okta, and deploying ransomware to cloud servers, they are able to flex their approach to take down their targets. ",[],{},{"nodeType":1294,"data":4113,"content":4114},{},[4115,4119,4128,4132,4140],{"nodeType":1293,"value":4116,"marks":4117,"data":4118},"Scattered Spider’s behavior demonstrates that they are extremely ",[],{},{"nodeType":1445,"data":4120,"content":4122},{"uri":4121},"https://www.crowdstrike.com/en-us/resources/crowdcasts/cloud-threat-summit/",[4123],{"nodeType":1293,"value":4124,"marks":4125,"data":4127},"cloud-conscious",[4126],{"type":1486},{},{"nodeType":1293,"value":4129,"marks":4130,"data":4131}," (as many modern threat actors are) and are leveraging modern TTPs designed to evade traditional security controls and exploit blind-spots in enterprise security visibility. For example, by constantly rotating their phishing domains and pages, Scattered Spider (and many threat actors like them) are routinely evading common phishing detection controls, taking advantage of the limitations of ",[],{},{"nodeType":1445,"data":4133,"content":4134},{"uri":3864},[4135],{"nodeType":1293,"value":4136,"marks":4137,"data":4139},"blocklist-driven approaches to phishing detection",[4138],{"type":1486},{},{"nodeType":1293,"value":1788,"marks":4141,"data":4142},[],{},{"nodeType":1753,"data":4144,"content":4145},{},[],{"nodeType":1403,"data":4147,"content":4148},{},[4149],{"nodeType":1293,"value":4150,"marks":4151,"data":4153},"Aligning Push Security’s capabilities against Scattered Spider’s TTPs",[4152],{"type":1626},{},{"nodeType":1294,"data":4155,"content":4156},{},[4157],{"nodeType":1293,"value":4158,"marks":4159,"data":4161},"Push provides a multi-layered set of detections and controls for defending against the TTPs known to be used by Scattered Spider. ",[4160],{"type":1626},{},{"nodeType":1345,"data":4163,"content":4167},{"target":4164},{"sys":4165},{"id":4166,"type":1350,"linkType":1351},"6aB3mLLXZIhrlyuCx2hOzY",[],{"nodeType":1464,"data":4169,"content":4170},{},[4171],{"nodeType":1293,"value":4172,"marks":4173,"data":4174},"Detect and block AiTM phishing toolkits",[],{},{"nodeType":1294,"data":4176,"content":4177},{},[4178],{"nodeType":1293,"value":4179,"marks":4180,"data":4182},"The Push browser agent will detect when employees visit websites running MFA-bypassing phishing toolkits such as Evilginx. ",[4181],{"type":1626},{},{"nodeType":1345,"data":4184,"content":4188},{"target":4185},{"sys":4186},{"id":4187,"type":1350,"linkType":1351},"I19TQYItDFlaOgisrST6P",[],{"nodeType":1294,"data":4190,"content":4191},{},[4192],{"nodeType":1293,"value":4193,"marks":4194,"data":4195},"The Push browser agent analyzes the behavioral attributes of phishing tools, e.g. “something the toolkit does” vs. just a static signature like a URL path or domain.",[],{},{"nodeType":1294,"data":4197,"content":4198},{},[4199],{"nodeType":1293,"value":4200,"marks":4201,"data":4202},"Based on your configuration, Push can then warn or block employees from accessing those phishing sites using a customisable blocking page or banner.",[],{},{"nodeType":1345,"data":4204,"content":4208},{"target":4205},{"sys":4206},{"id":4207,"type":1350,"linkType":1351},"4ixcEsEW4EyqckOTmP5Pbb",[],{"nodeType":1464,"data":4210,"content":4211},{},[4212],{"nodeType":1293,"value":4213,"marks":4214,"data":4215},"Detect cloned login pages",[],{},{"nodeType":1294,"data":4217,"content":4218},{},[4219],{"nodeType":1293,"value":4220,"marks":4221,"data":4223},"The Push browser agent will detect when employees visit websites using cloned login screens to steal credentials - i.e. a cloned Okta login page.",[4222],{"type":1626},{},{"nodeType":1294,"data":4225,"content":4226},{},[4227],{"nodeType":1293,"value":4228,"marks":4229,"data":4230},"Push does this by fingerprinting the page structure and resources of your legitimate login pages and monitoring for pages that are very similar.",[],{},{"nodeType":1294,"data":4232,"content":4233},{},[4234],{"nodeType":1293,"value":4235,"marks":4236,"data":4237},"Push will then emit a webhook event when it detects that an employee has visited a page that appears to be a clone of a legitimate login page.",[],{},{"nodeType":1464,"data":4239,"content":4240},{},[4241],{"nodeType":1293,"value":4242,"marks":4243,"data":4244},"Pin your sensitive passwords to specific sites",[],{},{"nodeType":1294,"data":4246,"content":4247},{},[4248,4253,4259],{"nodeType":1293,"value":4249,"marks":4250,"data":4252},"The Push browser agent will detect when employees attempt to enter their IdP password (such as Okta) into webpages that ",[4251],{"type":1626},{},{"nodeType":1293,"value":4254,"marks":4255,"data":4258},"do not",[4256,4257],{"type":1486},{"type":1626},{},{"nodeType":1293,"value":4260,"marks":4261,"data":4263}," belong to that IdP.",[4262],{"type":1626},{},{"nodeType":1294,"data":4265,"content":4266},{},[4267,4271,4280],{"nodeType":1293,"value":4268,"marks":4269,"data":4270},"When observing logins, the Push browser agent generates a salted partial hash of the user’s password, known as a fingerprint. This fingerprint is then stored locally in the browser to allow Push to perform password comparisons. You can read more about how the extension securely observes passwords in this ",[],{},{"nodeType":1445,"data":4272,"content":4274},{"uri":4273},"https://pushsecurity.com/help/10065/#start",[4275],{"nodeType":1293,"value":4276,"marks":4277,"data":4279},"help article",[4278],{"type":1486},{},{"nodeType":1293,"value":2226,"marks":4281,"data":4282},[],{},{"nodeType":1294,"data":4284,"content":4285},{},[4286],{"nodeType":1293,"value":4287,"marks":4288,"data":4289},"To detect phishing attempts against Okta (and other identity providers), the Push browser agent compares the observed Okta password fingerprint to the known Okta fingerprint that already exists in local storage.",[],{},{"nodeType":1294,"data":4291,"content":4292},{},[4293],{"nodeType":1293,"value":4294,"marks":4295,"data":4296},"If an employee has entered their valid Okta password on a webpage that does not belong to Okta — i.e. a phishing page — Push will enforce the SSO password protection settings set by an administrator (block or warn). This serves as a second layer of defense when used in conjunction with AiTM and cloned login page detections. ",[],{},{"nodeType":1345,"data":4298,"content":4302},{"target":4299},{"sys":4300},{"id":4301,"type":1350,"linkType":1351},"20FIoIyuQYxep3V4SFWdoK",[],{"nodeType":1464,"data":4304,"content":4305},{},[4306],{"nodeType":1293,"value":4307,"marks":4308,"data":4309},"Detect compromised sessions",[],{},{"nodeType":1294,"data":4311,"content":4312},{},[4313],{"nodeType":1293,"value":4314,"marks":4315,"data":4317},"By correlating Push telemetry with Okta logs, Push can detect compromised Okta sessions originating from outside employees’ supported browsers. ",[4316],{"type":1626},{},{"nodeType":1294,"data":4319,"content":4320},{},[4321],{"nodeType":1293,"value":4322,"marks":4323,"data":4324},"Using the Push browser agent, you can inject a unique marker into the User Agent string of Okta sessions that occur in browsers enrolled in Push.",[],{},{"nodeType":1294,"data":4326,"content":4327},{},[4328],{"nodeType":1293,"value":4329,"marks":4330,"data":4331},"By then comparing against Okta logs, you can identify sessions that both have the Push marker and those that lack the marker, the latter indicating the session is being used from a machine without the Push extension and therefore the session token may have been stolen.",[],{},{"nodeType":1345,"data":4333,"content":4337},{"target":4334},{"sys":4335},{"id":4336,"type":1350,"linkType":1351},"1XNNkaoW64t3PPvC54KGXF",[],{"nodeType":1464,"data":4339,"content":4340},{},[4341],{"nodeType":1293,"value":4342,"marks":4343,"data":4344},"Detect when employee credentials are stolen",[],{},{"nodeType":1294,"data":4346,"content":4347},{},[4348],{"nodeType":1293,"value":4349,"marks":4350,"data":4352},"Push will detect when valid credentials appear for sale on criminal forums. ",[4351],{"type":1626},{},{"nodeType":1294,"data":4354,"content":4355},{},[4356],{"nodeType":1293,"value":4357,"marks":4358,"data":4359},"The Push platform detects valid, stolen credentials on criminal forums by ingesting threat intelligence data and then verifying which credentials flagged by TI sources are still being used by employees.",[],{},{"nodeType":1294,"data":4361,"content":4362},{},[4363],{"nodeType":1293,"value":4364,"marks":4365,"data":4366},"When suspected stolen credentials for the corporate domain are present, Push hashes and salts the passwords and then sends those fingerprints to the relevant browser agents for comparison. If the stolen credential fingerprint matches a known credential fingerprint observed to be in use by the Push browser agent, the platform returns a validated true positive alert.",[],{},{"nodeType":1294,"data":4368,"content":4369},{},[4370],{"nodeType":1293,"value":4371,"marks":4372,"data":4373},"You can choose to receive alerts for this detection via webhook, ChatOps notification, or in the Push admin console.",[],{},{"nodeType":1345,"data":4375,"content":4379},{"target":4376},{"sys":4377},{"id":4378,"type":1350,"linkType":1351},"6wfLCTzvHeMzagyuEWGyJg",[],{"nodeType":1464,"data":4381,"content":4382},{},[4383],{"nodeType":1293,"value":4384,"marks":4385,"data":4386},"Map login methods and remove ghost logins",[],{},{"nodeType":1294,"data":4388,"content":4389},{},[4390],{"nodeType":1293,"value":4391,"marks":4392,"data":4394},"Push maps all the identities used by employees to access workforce apps, including local, non-Okta identities. This data can be used to migrate more apps and accounts to Okta SSO and reduce the overall identity attack surface. ",[4393],{"type":1626},{},{"nodeType":1294,"data":4396,"content":4397},{},[4398],{"nodeType":1293,"value":4399,"marks":4400,"data":4401},"The Push browser agent observes employees using their corporate identities to access work applications. Push customers gain accurate visibility across all Okta and non-Okta identities, the employees that are using them, the apps they are accessing and the authentication methods being used. ",[],{},{"nodeType":1294,"data":4403,"content":4404},{},[4405,4409,4416],{"nodeType":1293,"value":4406,"marks":4407,"data":4408},"Armed with this data, security teams can get more workforce apps and accounts behind SSO to reduce the overall identity attack surface, while removing any ",[],{},{"nodeType":1445,"data":4410,"content":4411},{"uri":2065},[4412],{"nodeType":1293,"value":2071,"marks":4413,"data":4415},[4414],{"type":1486},{},{"nodeType":1293,"value":4417,"marks":4418,"data":4419}," that enable attackers to circumvent MFA by logging in directly to the app/page. ",[],{},{"nodeType":1345,"data":4421,"content":4425},{"target":4422},{"sys":4423},{"id":4424,"type":1350,"linkType":1351},"dbDM075qSd4P3wnXuXX2Z",[],{"nodeType":1464,"data":4427,"content":4428},{},[4429],{"nodeType":1293,"value":4430,"marks":4431,"data":4432},"Verify help desk caller identities with in-browser verification codes",[],{},{"nodeType":1294,"data":4434,"content":4435},{},[4436,4440,4450],{"nodeType":1293,"value":4437,"marks":4438,"data":4439},"To help combat help desk scams, we recently released ",[],{},{"nodeType":1445,"data":4441,"content":4443},{"uri":4442},"https://pushsecurity.com/blog/employee-identity-verification-codes-release/",[4444],{"nodeType":1293,"value":4445,"marks":4446,"data":4449},"Employee Identity Verification Codes",[4447,4448],{"type":1486},{"type":1626},{},{"nodeType":1293,"value":4451,"marks":4452,"data":4453}," — a simple, browser-based identity check that gives your help desk a reliable way to confirm they’re talking to someone from your organization.",[],{},{"nodeType":1345,"data":4455,"content":4459},{"target":4456},{"sys":4457},{"id":4458,"type":1350,"linkType":1351},"1TEpCjh8UGwmejgYSGC1by",[],{"nodeType":1294,"data":4461,"content":4462},{},[4463],{"nodeType":1293,"value":4464,"marks":4465,"data":4466},"It enables legitimate help desk callers to quickly verify that they’re in possession of their primary device (i.e. laptop) by relaying a rotating 6-digit verification code in their browser via the Push extension. This is a great way to securely confirm caller identity and sniff out fraudulent callers, and can be used as part of a phishing-resistant help desk process. ",[],{},{"nodeType":1294,"data":4468,"content":4469},{},[4470,4474,4483],{"nodeType":1293,"value":4471,"marks":4472,"data":4473},"You can use Employee Verification Codes as a free tool by installing the Push browser extension. Simply ",[],{},{"nodeType":1445,"data":4475,"content":4477},{"uri":4476},"https://pushsecurity.com/free-tool/employee-verification-codes",[4478],{"nodeType":1293,"value":4479,"marks":4480,"data":4482},"sign up for a trial account and you can deploy the extension organization-wide to make use of this feature",[4481],{"type":1486},{},{"nodeType":1293,"value":4484,"marks":4485,"data":4486},". While you’re at it, you can trial Push’s full features for up to 10 users for free. ",[],{},{"nodeType":1345,"data":4488,"content":4492},{"target":4489},{"sys":4490},{"id":4491,"type":1350,"linkType":1351},"6Td0hDBYdeT8tlnnfwipmD",[],{"nodeType":1753,"data":4494,"content":4495},{},[],{"nodeType":1403,"data":4497,"content":4498},{},[4499],{"nodeType":1293,"value":4500,"marks":4501,"data":4503},"Learn more",[4502],{"type":1626},{},{"nodeType":1294,"data":4505,"content":4506},{},[4507],{"nodeType":1293,"value":4508,"marks":4509,"data":4510},"It doesn’t stop there — Push provides comprehensive identity attack detection and response capabilities against techniques like credential stuffing, password spraying and session hijacking using stolen session tokens. You can also use Push to find and fix identity vulnerabilities across every app that your employees use like: ghost logins; SSO coverage gaps; MFA gaps; weak, breached and reused passwords; risky OAuth integrations; and more. ",[],{},{"nodeType":1294,"data":4512,"content":4513},{},[4514,4518,4526],{"nodeType":1293,"value":4515,"marks":4516,"data":4517},"If you want to learn more about how Push helps you to detect and defeat common identity attack techniques, ",[],{},{"nodeType":1445,"data":4519,"content":4521},{"uri":4520},"https://pushsecurity.com/demo?utm_campaign=12081956-FY25Q2_Hacker-News-Article&utm_source=thehackernews&utm_medium=sponsored&utm_content=external-article",[4522],{"nodeType":1293,"value":4523,"marks":4524,"data":4525},"book some time with one of our team for a live demo",[],{},{"nodeType":1293,"value":2226,"marks":4527,"data":4528},[],{},{"entries":4530},{"hyperlink":4531,"inline":4532,"block":4533},[],[],[4534,4572,4598,4626,4634,4648,4685,4699,4713,4722,4727,4735,4741,4745,4752,4759,4773,4781,4789,4795,4803,4810,4818],{"sys":4535,"__typename":4536,"content":4537,"name":4571,"title":118},{"id":3164},"InsightTextBlockComponent",{"json":4538},{"nodeType":1295,"data":4539,"content":4540},{},[4541],{"nodeType":1294,"data":4542,"content":4543},{},[4544,4548,4556,4560,4567],{"nodeType":1293,"value":4545,"marks":4546,"data":4547},"It's been a busy year for cyber criminals! This article has now been superseded with the rise to infamy of ",[],{},{"nodeType":1445,"data":4549,"content":4551},{"uri":4550},"https://pushsecurity.com/blog/scattered-lapsus-hunters",[4552],{"nodeType":1293,"value":4553,"marks":4554,"data":4555},"\"Scattered Lapsus$ Hunters\"",[],{},{"nodeType":1293,"value":4557,"marks":4558,"data":4559},". The guidance and TTPs in this blog post still apply, but ",[],{},{"nodeType":1445,"data":4561,"content":4562},{"uri":4550},[4563],{"nodeType":1293,"value":4564,"marks":4565,"data":4566},"check out our new post",[],{},{"nodeType":1293,"value":4568,"marks":4569,"data":4570}," for the full picture of Scattered Spider-linked breaches dating back to 2021. ",[],{},"SS insight box 1",{"sys":4573,"__typename":4536,"content":4574,"name":4597,"title":118},{"id":3218},{"json":4575},{"nodeType":1295,"data":4576,"content":4577},{},[4578],{"nodeType":1294,"data":4579,"content":4580},{},[4581,4585,4593],{"nodeType":1293,"value":4582,"marks":4583,"data":4584},"With criminal hacker collectives being fluid in nature, Scattered Spider has also been associated with ",[],{},{"nodeType":1445,"data":4586,"content":4587},{"uri":3203},[4588],{"nodeType":1293,"value":4589,"marks":4590,"data":4592},"the Snowflake attacks",[4591],{"type":1486},{},{"nodeType":1293,"value":4594,"marks":4595,"data":4596}," attributed to the ShinyHunters group, which resulted in hundreds of millions of breached records from 9 public victims including AT&T, Ticketmaster, and Santander (with the full impact suggested to be around 165 organizations), monetized through ransom payments, extortion of individual victims, and resale of the data on criminal forums.",[],{},"Scattered Spider insight box 0",{"sys":4599,"__typename":4536,"content":4600,"name":4625,"title":118},{"id":3303},{"json":4601},{"nodeType":1295,"data":4602,"content":4603},{},[4604],{"nodeType":1294,"data":4605,"content":4606},{},[4607,4612,4616,4621],{"nodeType":1293,"value":4608,"marks":4609,"data":4611},"Caesars",[4610],{"type":1626},{},{"nodeType":1293,"value":4613,"marks":4614,"data":4615}," was also hit at the same time as MGM Resorts. Less is known about the Caesars attack, except that a ransom of ",[],{},{"nodeType":1293,"value":4617,"marks":4618,"data":4620},"$15M",[4619],{"type":1626},{},{"nodeType":1293,"value":4622,"marks":4623,"data":4624}," was paid to Scattered Spider in an attempt to prevent stolen data being leaked online.",[],{},"Scattered Spider insight box 1",{"sys":4627,"__typename":4628,"type":4629,"ctaText":4630,"buttonLabel":4631,"buttonColour":4632,"buttonUrl":4633},{"id":3335},"CtaWidget","Custom","Want to learn more from our security researchers? Watch our webinar on Scattered Spider's 2025 TTPs here. ","Stream On-Demand","sunny orange","https://pushsecurity.com/webinar/scatteredspider",{"sys":4635,"__typename":4536,"content":4636,"name":4647,"title":118},{"id":3359},{"json":4637},{"nodeType":1295,"data":4638,"content":4639},{},[4640],{"nodeType":1294,"data":4641,"content":4642},{},[4643],{"nodeType":1293,"value":4644,"marks":4645,"data":4646},"It's worth thinking about Scattered Spider less as a neatly identified group of individuals, but more as a pattern of activity and behaviors. For this reason, it's unlikely that arrests will have a definitive impact — the TTPs exhibited will continue to be used and refined by newcomers.  ",[],{},"Scattered Spider TTPs Insight Box 5",{"sys":4649,"__typename":4536,"content":4650,"name":4684,"title":118},{"id":3626},{"json":4651},{"nodeType":1295,"data":4652,"content":4653},{},[4654],{"nodeType":1294,"data":4655,"content":4656},{},[4657,4661,4669,4673,4680],{"nodeType":1293,"value":4658,"marks":4659,"data":4660},"Learn more about how Scattered Spider conducts help desk attacks ",[],{},{"nodeType":1445,"data":4662,"content":4664},{"uri":4663},"https://pushsecurity.com/blog/scattered-spider-defending-against-help-desk-scams/",[4665],{"nodeType":1293,"value":4666,"marks":4667,"data":4668},"in our recent blog pos",[],{},{"nodeType":1293,"value":4670,"marks":4671,"data":4672},"t or by checking out ",[],{},{"nodeType":1445,"data":4674,"content":4675},{"uri":4633},[4676],{"nodeType":1293,"value":4677,"marks":4678,"data":4679},"our on-demand webinar — available to stream now",[],{},{"nodeType":1293,"value":4681,"marks":4682,"data":4683},". ",[],{},"Scattered Spider TTPs insight box 6",{"sys":4686,"__typename":4536,"content":4687,"name":4698,"title":118},{"id":3667},{"json":4688},{"nodeType":1295,"data":4689,"content":4690},{},[4691],{"nodeType":1294,"data":4692,"content":4693},{},[4694],{"nodeType":1293,"value":4695,"marks":4696,"data":4697},"Accenture, Aflac, Allstate, Ally Bank, Amica, Apple, AT&T, Athene, Audemars Piguet, Ballet Crypto, BCB Group, Bell, Bitcoin Suisse, Blockdaemon, Blockstream, Charter Communications, Chik-fil-A, Cincinnati Financial, Comcast Corporation, Core Scientific, Costco, Credit Karma, DoorDash, Fireblocks, Forbes, Gemini, Grayscale, H&R Block, Hanover Insurance, Harrow Health, Iliad, Instacart, Jackson Hewitt, Kemper, Louis Vuitton, Luno, Marsh, Mercury, Morningstar, Mutual of Omaha, Nansen, NGRAVE, New York Digital Investment Group, New York Life Insurance, News Corporation, Nike, Orange, P.F. Chang’s, Paxos, PNC Bank, Revolut, RiteAid, 7-Eleven, Singtel, Stargate Industries, Synchrony Bank, Synovus, T-Mobile, Telstra, TIAA, Transamerica, Twitter/X, UScellular, Verizon, Vodafone, WINDTRE, and Xapo Bank.",[],{},"Scattered Spider insight box 3",{"sys":4700,"__typename":4536,"content":4701,"name":4712,"title":118},{"id":3680},{"json":4702},{"nodeType":1295,"data":4703,"content":4704},{},[4705],{"nodeType":1294,"data":4706,"content":4707},{},[4708],{"nodeType":1293,"value":4709,"marks":4710,"data":4711},"ActiveCampaign, Ada CX, Alchemy, Asurion, Bandwith, Bird CRM, Campaign Monitor, Concentrix, Constant Contact, Corporate Tools, CTS, eClerx, Expedia Group, FalconX, FICO, Five9, Foundever, Freshworks, Genesis Trading, Givebutter, GoDaddy, HubSpot, Incode, Intercom, iQor, Iterable, Jumio, Klaviyo, LinkedIn, Mixpanel, Nuance Communications, Onfido, OnSolve, Podium, Pure Storage, Ripple, Roblox, Salesforce, Shipbob, Sinch, Socure, SPOC, Squarespace, TaskUs, TriVista, Twilio, Ulta Beauty, Upland Software, Wix, Workday, Ziff Davis, and 247[.]ai.",[],{},"Scattered Spider insight box 4",{"sys":4714,"__typename":4715,"title":4716,"caption":4717,"layoutMode":118,"file":4718},{"id":3772},"Image","Scattered Spider image 1","Summary of Scattered Spider TTP evolution in the context of an end-to-end attack chain.",{"url":4719,"width":4720,"height":4721},"https://images.ctfassets.net/y1cdw1ablpvd/16ngVb8CXbn6jnv7CNeCs5/1d708ddda20413c228d1239f6739acae/Screenshot_2025-06-27_at_15.30.27.png",3376,1876,{"sys":4723,"__typename":4628,"type":4629,"ctaText":4724,"buttonLabel":4725,"buttonColour":4632,"buttonUrl":4726},{"id":3818},"Frustrated that phishing attacks are still so successful in 2025? Check out on-demand latest webinar where we analyze exactly why and where controls are failing.","Watch On-demand","https://pushsecurity.com/resources/phishing-2025",{"sys":4728,"__typename":4715,"title":4729,"caption":4730,"layoutMode":118,"file":4731},{"id":3879},"Scattered spider image 2","Comparing the it.com domain observed by security researchers with the us.com observed in our recent Onfido malvertising investigation.",{"url":4732,"width":4733,"height":4734},"https://images.ctfassets.net/y1cdw1ablpvd/36YNp6VD5QfqcFcB4actyT/e31cc1dad9f55d49e1d793711199a666/image1.png",1999,791,{"sys":4736,"__typename":4737,"title":4738,"arcadeDemoUrl":4739,"playText":4740},{"id":3907},"ArcadeDemo","Evilginx demo","https://demo.arcade.software/2OpOz9hyjfIu5o8KtAmI?embed","1 mins",{"sys":4742,"__typename":4737,"title":4743,"arcadeDemoUrl":4744,"playText":4740},{"id":3981},"Phishing Toolkit Detection Evasion Arcade","https://demo.arcade.software/tDUPQV1Nlaralf6VQHT2?embed",{"sys":4746,"__typename":4715,"title":4747,"caption":4748,"layoutMode":118,"file":4749},{"id":4085},"Scattered spider image 3","Scattered Spider Okta phishing pages impersonating various brands",{"url":4750,"width":4751,"height":4733},"https://images.ctfassets.net/y1cdw1ablpvd/7HWejTJs8g5dtoZLK2oqg7/72e3461a28811d0b80d6322f2f93a431/image3.png",1645,{"sys":4753,"__typename":4715,"title":4754,"caption":4755,"layoutMode":118,"file":4756},{"id":4166},"Push vs Scattered Spider","Push controls mapped against Scattered Spider TTPs.",{"url":4757,"width":4733,"height":4758},"https://images.ctfassets.net/y1cdw1ablpvd/1l3phtTjFoQDleiOKYfrXn/ead73aef01e72f08885656d79521a27a/image3.png",1136,{"sys":4760,"__typename":4536,"content":4761,"name":4772,"title":118},{"id":4187},{"json":4762},{"nodeType":1295,"data":4763,"content":4764},{},[4765],{"nodeType":1294,"data":4766,"content":4767},{},[4768],{"nodeType":1293,"value":4769,"marks":4770,"data":4771},"To detect modern, sophisticated phishing kits like those used by Scattered Spider, organizations need to be able to detect and block phishing pages in real-time. Push’s browser-based approach intercepts phishing attacks as they happen — in employee browsers. Being in the browser delivers a lot of advantages when it comes to detecting and intercepting phishing attacks. You see the live webpage that the user sees, as they see it, meaning you have much better visibility of malicious elements running on the page. It also means that you can implement real-time controls that kick in when a malicious element is detected.",[],{},"Scattered Spider insight box 2",{"sys":4774,"__typename":4715,"title":4775,"caption":4776,"layoutMode":118,"file":4777},{"id":4207},"Phishing toolkit detection","Accessing pages running malicious phishing toolkits is automatically blocked. ",{"url":4778,"width":4779,"height":4780},"https://images.ctfassets.net/y1cdw1ablpvd/3ylgW0MDCCesBjQsoqjD4P/a8bc4df9a430aca6c725f913d2bc6444/image11.png",1440,767,{"sys":4782,"__typename":4715,"title":4783,"caption":4784,"layoutMode":118,"file":4785},{"id":4301},"Scattered spider image 4","Push detects and blocks when a password is used on a site it doesn't belong to.",{"url":4786,"width":4787,"height":4788},"https://images.ctfassets.net/y1cdw1ablpvd/3DsbAAM2GCMbyfBdENebFJ/89978c80fe97b46d2e80089b19d8cb73/image8.png",1920,1080,{"sys":4790,"__typename":4715,"title":4791,"caption":4791,"layoutMode":118,"file":4792},{"id":4336},"Detecting stolen sessions running on attacker machines. ",{"url":4793,"width":4779,"height":4794},"https://images.ctfassets.net/y1cdw1ablpvd/3Pp4bDB2FkGlHbOEt35j0j/49a92cf3c2f805850eff23bacd43818c/image8.png",398,{"sys":4796,"__typename":4715,"title":4797,"caption":4798,"layoutMode":118,"file":4799},{"id":4378},"Detecting stolen credentials in lastpass","Push shows where stolen credentials have been used to log into an account and the source of the leak",{"url":4800,"width":4801,"height":4802},"https://images.ctfassets.net/y1cdw1ablpvd/HYlWtjgQJdjOYgjmRVMf3/2444a1804ff5c75e88884d75c8735aa8/image8.png",697,668,{"sys":4804,"__typename":4715,"title":4805,"caption":4806,"layoutMode":118,"file":4807},{"id":4424},"Scattered spider image 5","Push identifies where multiple login methods are configured for a single account, as well as when the method was last observed, to surface ghost logins.",{"url":4808,"width":4733,"height":4809},"https://images.ctfassets.net/y1cdw1ablpvd/4LigZHBdaNgpK4vXjr80Ct/5c904257035d6507eff924bff131ced9/image5.png",887,{"sys":4811,"__typename":4715,"title":4812,"caption":4813,"layoutMode":118,"file":4814},{"id":4458},"Employee Verification Codes","Push provides a lightweight verification feature in every user’s browser — no additional apps or devices required.",{"url":4815,"width":4816,"height":4817},"https://images.ctfassets.net/y1cdw1ablpvd/41X6fkPJgqf14vO3O14TF3/e0cecdbdfaee1353f15ff77ecb6a55a8/Employee_verification_codes.png",2088,1240,{"sys":4819,"__typename":4628,"type":4629,"ctaText":4820,"buttonLabel":4821,"buttonColour":4632,"buttonUrl":4476},{"id":4491},"Deploy Employee Verification Codes for free today and protect your help desk from Scattered Spider","Try it free","content:blog:scattered-spider-ttp-evolution-in-2025.json","json","content","blog/scattered-spider-ttp-evolution-in-2025.json","blog/scattered-spider-ttp-evolution-in-2025",1776359984776]