Push Security is partnering with Proofpoint, bringing Push’s in-browser threat protection to Proofpoint customers to tackle browser-native threats as phishing moves beyond the inbox.
Push Security is partnering with Proofpoint, bringing Push’s in-browser threat protection to Proofpoint customers to tackle browser-native threats as phishing moves beyond the inbox.
We're announcing a partnership with Proofpoint to power Proofpoint Advanced Browser Protection — a new addition to Proofpoint's collaboration security platform that extends protection from the inbox into the browser session. Push provides the real-time behavioral detection, in-session blocking, and browser telemetry that feeds directly into Proofpoint's Threat Protection Workbench, Security Graph, and Investigation Agent.
Proofpoint is one of the biggest names in cybersecurity. They've spent two decades building the most comprehensive picture of how attacks reach people via email. This partnership exists because Proofpoint recognizes that today’s attacks don’t stop at the inbox: they happen inside the browser session.
Phishing doesn't stop at the inbox anymore
Email is one of the most heavily defended delivery channels in the enterprise. Enterprise organizations have multiple layers of email security, scanning messages for malicious links, sandboxing attachments, and rewriting URLs.
But better controls doesn't mean attackers stopped phishing: they adapted.
Push data shows a growing number of malicious payloads now arrive outside of email entirely — via messaging apps, social media, search results, and malvertising.
As email defenses improve, attackers increasingly conceal malicious content during delivery, such as multi-stage redirect chains and conditional loading based on email, IP and browser checks that prevent the true destination from being revealed until a user interacts with the link. These techniques allow links to appear legitimate during email inspection while exposing malicious content only at the point of interaction, making the browser a critical control point for detecting and stopping modern attacks.
All of this makes it increasingly difficult for traditional time-of-click URL and page analysis to find and block bad before a user has the chance to get phished.
No matter the delivery vector, the attack plays out in the browser
Either way, the attack ends up rendering in the browser session, where the user enters credentials and completes MFA checks, authorizes an OAuth consent grant, copies a malicious command, downloads a file, or installs a malicious extension. That's the moment that determines whether the attack succeeds or fails.
Omdia's Browser Management and Security report puts a number on the consequence: 49% of organizations suffered a confirmed successful browser-based attack in the preceding 12 months, and 88% now rank browser security among their top 5 priorities.
Known-bad blocklists can’t keep up: Real-time behavioral analysis in the browser is the answer
89% of phishing domains are active for less than two days. Phishing kits rotate infrastructure continuously. Attackers host phishing content on trusted cloud platforms — Azure Blob Storage, Cloudflare Workers, Google-owned domains, and many more — that carry clean reputations by default. A URL that returns "safe" at time of delivery tells you very little about what the page will do when the user clicks through an hour later.
Push detects attacks by analyzing what the page actually does. Because we operate inside the browser session, we see the page load in real time and how the user interacts with it, including all of the client-side scripting and DOM loading that happens with modern web pages (and is invisible at the network layer). This means we can spot attacks by technique and behavior rather than just looking at things like domains, URLs, or static HTML.
AiTM kits, cloned login pages, Browser-in-the-Browser pop-ups, the ClickFix family of malicious copy-and-paste attacks, device code phishing, malicious OAuth consent grants — our behavioral detection catches them all, regardless of the infrastructure, hosting, or phish kits used.
What Push brings to Advanced Browser Protection
Push detects and blocks attacks regardless of whether a phishing link arrived via email, social media DM, a Teams message, a Google search ad, or a compromised website. The delivery channel is irrelevant to Push's detection model — which is the point.
With Push, no matter where a link is clicked and a page is loaded from, malicious content is detected and blocked in real time, before the user is compromised. Even if a page has never been flagged before, Push analyzes, detects the malicious elements of the page, and blocks access before the user has time to interact with it. Every session and interaction is protected by Push, without any need for sandboxing or latency-inducing remote isolation technology.
Push's browser telemetry — every page load, credential entry, session event, and OAuth consent — feeds directly into Proofpoint's Threat Protection Workbench and Investigation Agent, giving security teams a unified view from the message that carried the lure through to the credential entered and the session compromised.
An analyst working in Proofpoint's platform can now follow a single attack end-to-end without stitching together data from disconnected tools and limited data sources, significantly reducing investigation and response times.
What this means for Proofpoint customers
Proofpoint customers get a first-class browser security integration that covers the attacks email security was never architecturally positioned to catch — and delivers that detection data back into the Proofpoint platform. When Push detects and stops an attack for one Proofpoint customer, the data feeds back into the Proofpoint platform to block it everywhere.
For the broader market, the signal here is hard to miss. When a company of Proofpoint's scale — one that has the highest level of visibility into email-based threats — concludes that browser security is a critical piece for threat protection, that's extreme validation for the secure enterprise browser market. Browser security isn't a niche add-on anymore. It's a non-negotiable.
Proofpoint Advanced Browser Protection will be generally available from early 2027.
Push Security is the most powerful AI-native security tool in the browser. Think EDR, but for the browser — high-fidelity telemetry and real-time control across every session, on every device, with no browser migration required.
Security teams use Push to detect and stop advanced browser-based attacks like AiTM phishing, ClickFix, and session hijacking; gain visibility and control over AI tool usage across their workforce; harden identities by surfacing credential reuse, SSO gaps, and shadow IT; and support data loss and insider investigations with browser-layer telemetry that other tools can't see.
