Push

303 posts

Push banner
Push

Push

@PushSecurity

A browser-based agent that detects and prevents identity breaches.

Entrou em Kasım 2019
71 Seguindo679 Seguidores
Tweet fixado
Push
Push@PushSecurity·
💡 Introducing a SaaS attack matrix of networkless SaaS attack techniques - These attacks bypass EDR and network detection 💬 #Pentesters #Redteams We’d love to some comments or contributions for things you've tried on GitHub! Links in 🧵 #security #infosec #SaaSsecurity
Push tweet media
English
2
5
17
2.9K
Push
Push@PushSecurity·
With Push, you get an OS and browser agnostic way to manage and remove browser extensions. With our latest feature, you can now also automatically block known-bad extensions from running in your environment. Read our guide to securing browser extensions hubs.li/Q045MP4-0
English
0
0
1
86
Push
Push@PushSecurity·
The next evolution of ClickFix is here: InstallFix. Attackers distribute cloned Claude Code websites via malicious search ads. The pages contain fake instructions that trick victims into installing infostealer malware instead. Read the breakdown hubs.li/Q045TM6F0
English
0
0
0
100
Push
Push@PushSecurity·
Most breaches now start in the cloud — no malware needed. Attackers exploit legit functionality, dump data, and demand ransom. The common thread? It all happens in the browser. See how these attacks work in the wild 👉hubs.li/Q045KBZv0
Push tweet media
English
0
0
0
81
Push
Push@PushSecurity·
ClickFix, FileFix & related browser attacks are up 517% in 6 months. Push now detects ClickFix, FileFix, and other browser-based attacks that copy malicious code and run it on the victim’s machine. Learn more: pushsecurity.com/blog/introduci…
English
1
0
5
362
Push
Push@PushSecurity·
Attacks have moved away from endpoints and internal networks to the browser — a blind spot for traditional security tools. Read more below 👇 pushsecurity.com/blog/how-the-b…
English
0
1
3
284
Push
Push@PushSecurity·
🚀 We’re thrilled to announce our $30M Series B led by @Redpoint, supercharging our mission to stop identity attacks 🚀 Check out the press release here: pushsecurity.com/news/push-secu…
English
2
4
15
1.5K
Push
Push@PushSecurity·
Have you signed up to see @jukelennings use OpenAI Operator to automate identity attacks? Watch the clip below to see how it responds when tasked with logging into apps using stolen credentials. Want to see more? Register for the webinar here 👇 pushsecurity.com/webinar/automa…
English
0
2
3
942
Push
Push@PushSecurity·
We're ready for @BlackHatEvents Europe this week! Stop by booth 436 to chat with @ajaybateman, @jukelennings and the team about the rise in identity attacks – and how Push's browser-based ITDR solution gives defenders the advantage they need. We’ve got brand new swag too!
Push tweet media
English
0
0
3
402
Push retweetou
Luke Jennings
Luke Jennings@jukelennings·
1/ A new class of phishing - how verification phishing and cross-idp impersonation can bypass your SSO. Here is a video demo, but this is one where you really need to read the full article too - pushsecurity.com/blog/a-new-cla… I'll summarize the key points in this thread.
English
5
19
54
7K
Push
Push@PushSecurity·
Are you at GrrCON? Join us tonight for an epic evening of delicious food, refreshing drinks, and fantastic networking. Spots are going quickly! Register now: lu.ma/grrconhappyhou…
English
0
1
1
374
Push
Push@PushSecurity·
Ready to meet the REAL cookie monster? Join us on September 12th where @jukelennings will be compromising MFA-protected services by stealing session cookies and hijacking live sessions. Don’t miss out – register here: pushsecurity.com/webinar/infost…
Push tweet media
English
0
1
3
358
Push
Push@PushSecurity·
Don't miss out on our upcoming webinar where @jukelennings will be demoing infostealers, showing how to steal cookies and hijack sessions for MFA-protected services like M365 and downstream SaaS apps. Details below 👇 Pick a time and register here: pushsecurity.com/webinar/infost…
Push tweet media
English
0
0
2
307
Push retweetou
Luke Jennings
Luke Jennings@jukelennings·
Some of my research on SaaS attacks, including ghost logins and other persistence vectors, made it on to @DarknetDiaries Achievement unlocked.
English
1
3
7
637
Push retweetou
Luke Jennings
Luke Jennings@jukelennings·
I wrote a blog post on the many defense mechanisms phishing kits are using to avoid discovery and analysis now. I used a recent instance of NakedPages and cover 9 different techniques, including Cloudflare Workers and Turnstile abuse. IOCs included. pushsecurity.com/blog/how-aitm-…
English
0
33
76
6K
Push
Push@PushSecurity·
Join us for happy hour with @sublime_sec on August 8! Grab a drink, have a bite, catch up with old friends (and make some new ones) at KUMI in Mandalay Bay! RSVP: lu.ma/bh24-sublime-p…
Push tweet media
English
0
0
0
166
Push retweetou
Luke Jennings
Luke Jennings@jukelennings·
If you missed my Snowflake webinar yesterday and you’re impacted by the recent breach, you can check out this link to the demo segment from the webinar, where I show how to disable ghost logins in Snowflake. Remember, this is not just a Snowflake problem pushsecurity.com/resources/vide…
English
0
2
6
617
Push retweetou
The Hacker News
The Hacker News@TheHackersNews·
Is the Snowflake breach, touted as the biggest in history, identity security’s WannaCry moment? Join Luke Jennings, VP R&D at @PushSecurity, to explore what Snowflake shows us about the complexity of the identity attack surface, and discuss the practical steps that organizations can take to investigate and respond effectively. Register for the webinar here: go.thn.li/snowflake-webi…
The Hacker News tweet media
English
3
22
40
13.5K
Push
Push@PushSecurity·
The Snowflake breach will be for cloud identity attacks what WannaCry was for Ransomware. Join @jukelennings to explore the practical takeaways from the incident. Select the best time for you using the dropdown menu. pushsecurity.com/webinar/snowfl…
Push tweet media
English
0
3
2
393
Push retweetou
Luke Jennings
Luke Jennings@jukelennings·
7/ Well, when we investigated, we discovered that if you enable SAML SSO for a Snowflake account for a local account with no MFA, the local password still works unless you explicitly create an authentication policy to prevent it.
English
1
4
14
2.9K
Push retweetou
Luke Jennings
Luke Jennings@jukelennings·
1/ The ongoing Snowflake situation has made me realize just how dangerous ghost logins – a SaaS-based persistence technique that I coined last year – can be as an initial access vector. So what is a ghost login, exactly?
English
2
38
131
33.1K