
If you're interested in defending against Cyberhaven-style attacks against browser extension vendors, I wrote a guide around hardening browser extension deployments you might find interesting: pushsecurity.com/blog/guide-to-…
English
Jacques Louw
31 posts

@jacques_sec
Co-founder @pushsecurity



Back by popular demand, I wrote a second part blog post on the many defense mechanisms phishing kits are using to avoid detection. This second part dives deep on one specific strategy - preventing detection of commonly cloned login pages e.g. Microsoft pushsecurity.com/blog/how-aitm-…






I feel like shadow workflows are the closest equivalent of offensive PowerShell for the SaaS world. Check out the second post in my series on chaining SaaS attacks and come see me speak about this and a lot more at #44con on Thursday 14th September! pushsecurity.com/blog/nearly-in…


















