[{"data":1,"prerenderedAt":3865},["ShallowReactive",2],{"application-flags":3,"navbar":7,"always-visible-banner":36,"navbar-about-highlight":99,"navbar-resource-highlight":173,"trust-badges":217,"solution-nav":238,"fa-icon-sharp-regular-faFishingRod":378,"fa-icon-solid-faUserSecret":382,"fa-icon-sharp-regular-faLaptopCode":384,"fa-icon-solid-faTabletScreenButton":386,"fa-icon-solid-faThumbsUp":388,"fa-icon-solid-faPlugCircleXmark":390,"fa-icon-sharp-regular-faPuzzlePiece":392,"fa-icon-solid-faFileCircleXmark":394,"fa-icon-solid-faGhost":397,"fa-icon-solid-faQrcode":400,"fa-icon-solid-faCookieBite":402,"fa-icon-sharp-regular-faUserSecret":404,"fa-icon-sharp-regular-faRadar":406,"fa-icon-sharp-regular-faSatelliteDish":408,"fa-icon-sharp-regular-faShieldCheck":410,"fa-icon-sharp-regular-faBrainCircuit":412,"fa-icon-solid-faMobileScreenButton":414,"fa-icon-brands-faChrome":416,"fa-icon-solid-faDisplay":418,"fa-icon-solid-faFilter":420,"fa-icon-solid-faCloudArrowUp":422,"blog\u002Fproofpoint-x-push-partnership-announcement":424,"blog-topics":3461},[4],{"name":5,"enabled":6},"maintenanceMode",false,[8],{"createdDate":9,"id":10,"name":11,"modelId":12,"published":13,"meta":14,"query":22,"data":23,"variations":28,"lastUpdated":29,"firstPublished":30,"testRatio":31,"createdBy":32,"lastUpdatedBy":33,"folders":34,"rev":35},1742208588866,"1c7a4e423bf54ac1a328bb4063459ef2","Banner","1c6207a5f24948ab82d4a0b17f251193","published",{"breakpoints":15,"hasAutosaves":19,"kind":20,"lastPreviewUrl":21},{"medium":16,"small":17,"xsmall":18},768,640,320,true,"data","",[],{"link":24,"text":25,"type":26,"url":27},{},"Get our latest report analyzing browser attack techniques in 2026","web-banner","https:\u002F\u002Fpushsecurity.com\u002Fresources\u002Fbrowser-attacks-report",{},1774258294825,1742208637545,1,"CydmZnOWU1XuAaLhEDCoYNM4Z8W2","jKjF9r5jcvXU8tzZEfFQm31Iyvr2",[],"cu8s1bgrun",{"createdBy":37,"createdDate":38,"data":39,"folders":86,"id":87,"lastUpdated":88,"lastUpdatedBy":37,"meta":89,"modelId":93,"name":94,"published":13,"query":95,"testRatio":31,"variations":96,"firstPublished":97,"stageModifiedSincePublish":6,"lastUpdateSource":60,"rev":98},"ST0tXQM8slWpFrmioqKHmENB2qe2",1774965361051,{"ctaText":40,"text":41,"url":21,"blocks":42,"state":82},"ewrererw","testrfesssssssssss",[43,71],{"@type":44,"@version":45,"id":46,"component":47,"responsiveStyles":61},"@builder.io\u002Fsdk:Element",2,"builder-ca12c06a52de41d7b8743da53118cd38",{"name":48,"tag":48,"options":49,"isRSC":60},"TopBannerContent",{"text":50,"ctaText":51,"url":52,"mainText":53,"cta":56,"styleVariant":59,"showMonsters":19},"New Webinar Series: Join John Hammond, Troy Hunt, and Matt Johansen for the State of Browser Attacks","Save Your Spot","https:\u002F\u002Fpushsecurity.com\u002Fwebinar\u002Fstate-of-browser-security",{"content":54,"fontSize":55},"\u003Cp class=\"\">Shadow AI monsters are lurking in the dark! Bust them all in our retro-inspired arcade game.\u003C\u002Fp>","text-base",{"content":57,"fontSize":55,"url":58},"\u003Cp class=\"\">Press start &gt;&gt;\u003C\u002Fp>","https:\u002F\u002Fpushsecurity.com\u002Flp\u002Fshadow-ai-busters","arcade",null,{"large":62},{"display":63,"flexDirection":64,"position":65,"flexShrink":66,"boxSizing":67,"marginTop":68,"marginBottom":68,"fontSize":69,"fontWeight":70},"flex","column","relative","0","border-box",".56rem","1.125rem","700",{"id":72,"@type":44,"tagName":73,"properties":74,"responsiveStyles":77},"builder-pixel-nmrnkreld9","img",{"src":75,"aria-hidden":76,"alt":21,"width":66,"height":66},"https:\u002F\u002Fcdn.builder.io\u002Fapi\u002Fv1\u002Fpixel?apiKey=f3a1111ff5be48cdbb123cd9f5795a05","true",{"large":78},{"height":66,"width":66,"display":79,"opacity":66,"overflow":80,"pointerEvents":81},"block","hidden","none",{"deviceSize":83,"location":84},"large",{"path":21,"query":85},{},[],"fd266d0172cc47429be7ad10f48c99ad",1789552629325,{"breakpoints":90,"hasAutosaves":19,"hasErrors":6,"hasLinks":6,"kind":91,"lastPreviewUrl":92},{"medium":16,"small":17,"xsmall":18},"component","https:\u002F\u002Fsite.dev.pushsecurity.com\u002F?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditCode%2CeditDesigns%2Cadmin%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CeditProjects%2CmodifyMcpServers%2CmodifyWorkflowIntegrations%2CmodifyProjectSettings%2CconnectCodeRepository%2CcreateProjects%2CindexDesignSystems%2CsendPullRequests%2CmergePullRequests%2CfusionHostingPublish%2CfusionHostingRevokeAiToken&builder.user.role.name=Admin&builder.user.role.id=admin&builder.cachebust=true&builder.preview=always-visible-banner&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.always-visible-banner=fd266d0172cc47429be7ad10f48c99ad&builder.overrides.fd266d0172cc47429be7ad10f48c99ad=fd266d0172cc47429be7ad10f48c99ad&builder.options.locale=Default","0678d178ec8b41efb8a23c09dba7874d","always visible banner",[],{},1774968080803,"lmu43pypdb",[100,136],{"createdBy":32,"createdDate":101,"data":102,"folders":125,"id":126,"lastUpdated":127,"lastUpdatedBy":32,"meta":128,"modelId":130,"name":131,"published":13,"query":132,"stageModifiedSincePublish":6,"testRatio":31,"variations":133,"firstPublished":134,"rev":135},1776247359804,{"link":103,"testimonial":104,"testimonialLink":124,"type":107},{},{"@type":105,"id":106,"model":107,"value":108},"@builder.io\u002Fcore:Reference","f028f2b685bb47cd8bf9e82a26dd5a79","testimonial",{"query":109,"folders":110,"createdDate":111,"id":106,"name":112,"modelId":113,"published":13,"data":114,"variations":118,"lastUpdated":119,"firstPublished":120,"testRatio":31,"createdBy":37,"lastUpdatedBy":37,"meta":121,"rev":123},[],[],1735823466309,"We found Push to be more accurate when compared to competitors and the browser agent offered features that others couldn’t match.","42035571a56940ac98bff4544aa79aa5",{"author":115,"jobTitle":116,"quote":112,"image":117},"Jason Waits","\u003Cp>CISO at Inductive Automation\u003C\u002Fp>","https:\u002F\u002Fcdn.builder.io\u002Fapi\u002Fv1\u002Fimage\u002Fassets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Ff04c0c0689ce4a89ac0f0708d78c0a07",{},1735910703862,1735823501152,{"kind":20,"lastPreviewUrl":21,"breakpoints":122,"hasAutosaves":19},{"small":17,"medium":16},"4ryyzlvud4a","\u002Fcustomer-stories\u002Finductive-automation",[],"9136a8f18b3b4a6ba29b8653a99372b1",1776247404986,{"breakpoints":129,"hasAutosaves":6,"kind":20,"lastPreviewUrl":21},{"medium":16,"small":17,"xsmall":18},"20d9eaa352304613b3d1a794b400703d","testimonial-inductive-automation",[],{},1776247404973,"83wwox7t9hk",{"createdBy":32,"createdDate":137,"data":138,"folders":165,"id":166,"lastUpdated":167,"lastUpdatedBy":32,"meta":168,"modelId":130,"name":163,"published":13,"query":170,"stageModifiedSincePublish":6,"testRatio":31,"variations":171,"firstPublished":172,"rev":135},1776255761419,{"description":139,"image":140,"link":141,"testimonial":144,"title":163,"type":164},"Learn about the latest techniques being used in the wild.","https:\u002F\u002Fcdn.builder.io\u002Fapi\u002Fv1\u002Fimage\u002Fassets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F7b4a5ebf81d64e8c9d7fc35f6c96c4a9",{"text":142,"url":143},"Download now","\u002Fresources\u002Fbrowser-attacks-report",{"@type":105,"id":145,"model":107,"value":146},"192acbb1f9ca4cac918c0ec435a8bae3",{"query":147,"folders":148,"createdDate":149,"id":145,"name":150,"modelId":113,"published":13,"data":151,"variations":157,"lastUpdated":158,"firstPublished":159,"testRatio":31,"createdBy":37,"lastUpdatedBy":32,"meta":160,"rev":162},[],[],1728981467463,"Push does for identity what CrowdStrike did for the endpoint",{"video":152,"jobTitle":153,"author":154,"qoute":21,"quote":155,"image":156},"https:\u002F\u002Fcdn.builder.io\u002Fo\u002Fassets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F8b30e8ca50064058bbaef0f3c6164575%2Fcompressed?apiKey=f3a1111ff5be48cdbb123cd9f5795a05&token=8b30e8ca50064058bbaef0f3c6164575&alt=media&optimized=true","\u003Cp>Deputy CISO at Microsoft\u003C\u002Fp>\u003Cp>Former LinkedIn, Slack, Palantir\u003C\u002Fp>","Geoff Belknap","Push does for identity what CrowdStrike did for the endpoint.","https:\u002F\u002Fcdn.builder.io\u002Fapi\u002Fv1\u002Fimage\u002Fassets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F748f0ad0a5064a00a13f4721fcc8dea1",{},1742902158597,1728981782923,{"kind":20,"lastPreviewUrl":21,"breakpoints":161,"hasAutosaves":19},{"small":17,"medium":16},"l3cndi0gnw","Report: 2026 Browser Attack Techniques","resource",[],"05a9322735fc427db12e2740e4302300",1776255810913,{"breakpoints":169,"hasAutosaves":6,"kind":20,"lastPreviewUrl":21},{"medium":16,"small":17,"xsmall":18},[],{},1776255810900,[174,196],{"createdBy":32,"createdDate":175,"data":176,"folders":186,"id":187,"lastUpdated":188,"lastUpdatedBy":32,"meta":189,"modelId":191,"name":163,"published":13,"query":192,"stageModifiedSincePublish":6,"testRatio":31,"variations":193,"firstPublished":194,"rev":195},1776256900280,{"description":139,"image":140,"link":177,"testimonial":178,"title":163,"type":164},{"text":142,"url":143},{"@type":105,"id":145,"model":107,"value":179},{"query":180,"folders":181,"createdDate":149,"id":145,"name":150,"modelId":113,"published":13,"data":182,"variations":183,"lastUpdated":158,"firstPublished":159,"testRatio":31,"createdBy":37,"lastUpdatedBy":32,"meta":184,"rev":162},[],[],{"video":152,"jobTitle":153,"author":154,"qoute":21,"quote":155,"image":156},{},{"kind":20,"lastPreviewUrl":21,"breakpoints":185,"hasAutosaves":19},{"small":17,"medium":16},[],"1f429607996e4e5fae8fe3f9b9610e55",1776256937553,{"breakpoints":190,"hasAutosaves":6,"kind":20,"lastPreviewUrl":21},{"medium":16,"small":17,"xsmall":18},"4829faa81e7c4ee8bd2d000e160e8d3c",[],{},1776256937540,"xyasj27wu8",{"createdBy":32,"createdDate":197,"data":198,"folders":208,"id":209,"lastUpdated":210,"lastUpdatedBy":32,"meta":211,"modelId":191,"name":213,"published":13,"query":214,"stageModifiedSincePublish":6,"testRatio":31,"variations":215,"firstPublished":216,"rev":195},1776256949234,{"link":199,"testimonial":200,"testimonialLink":124,"type":107},{},{"@type":105,"id":106,"model":107,"value":201},{"query":202,"folders":203,"createdDate":111,"id":106,"name":112,"modelId":113,"published":13,"data":204,"variations":205,"lastUpdated":119,"firstPublished":120,"testRatio":31,"createdBy":37,"lastUpdatedBy":37,"meta":206,"rev":123},[],[],{"author":115,"jobTitle":116,"quote":112,"image":117},{},{"kind":20,"lastPreviewUrl":21,"breakpoints":207,"hasAutosaves":19},{"small":17,"medium":16},[],"ce043785b71b4ece98eac811ecf4ba10",1776256974140,{"breakpoints":212,"hasAutosaves":6,"kind":20,"lastPreviewUrl":21},{"medium":16,"small":17,"xsmall":18},"inductive-automation",[],{},1776256974130,[218,222,226,230,234],{"title":219,"logo":220,"createdDate":221},"SOC2","https:\u002F\u002Fcdn.builder.io\u002Fapi\u002Fv1\u002Fimage\u002Fassets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fb6727a5e00004d6e9e69fc3068b8b64c",1784291539953,{"title":223,"logo":224,"createdDate":225},"GDPR","https:\u002F\u002Fcdn.builder.io\u002Fapi\u002Fv1\u002Fimage\u002Fassets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Ffe49f53211674deaa5a6640d929cdf42?format=webp",1784291672535,{"title":227,"logo":228,"createdDate":229},"Cyber essentials","https:\u002F\u002Fcdn.builder.io\u002Fapi\u002Fv1\u002Fimage\u002Fassets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F53558c1045a342a7a28def960cd54ae7?format=webp",1784291702710,{"title":231,"logo":232,"createdDate":233},"ISO IEC 27001","https:\u002F\u002Fcdn.builder.io\u002Fapi\u002Fv1\u002Fimage\u002Fassets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F578a404a61cf45db951a41fe3554d12d",1784291766222,{"title":235,"logo":236,"createdDate":237},"ISO IEC 27701","https:\u002F\u002Fcdn.builder.io\u002Fapi\u002Fv1\u002Fimage\u002Fassets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fbe219844b13242fbba531959579a753c",1784291858848,[239,308,353],{"id":240,"label":241,"text":21,"navIcon":242,"items":243},"stop-browser-based-attacks","Stop browser-based attacks","solid:faShieldHalved",[244,249,254,259,264,269,274,279,284,288,293,298,303],{"title":245,"text":246,"url":247,"navIcon":248},"Phishing","Detect phishing behaviorally in the browser, regardless of the payload or delivery channel.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fzero-day-phishing","sharp-regular:faFishingRod",{"title":250,"text":251,"url":252,"navIcon":253},"Adversary-in-the-Middle","Detect and block MFA-bypassing AiTM phishing pages in real-time.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fadversary-in-the-middle-attacks","solid:faUserSecret",{"title":255,"text":256,"url":257,"navIcon":258},"ClickFix (and variants)","Intercept malicious copy and paste attacks at the point of interaction.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fclickfix-fix-variants","sharp-regular:faLaptopCode",{"title":260,"text":261,"url":262,"navIcon":263},"Device code phishing","Detect and block device code phishing kits designed to get around passkeys.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fdevice-code-phishing","solid:faTabletScreenButton",{"title":265,"text":266,"url":267,"navIcon":268},"Consent phishing","Detect and block malicious OAuth consent grants before access is authorized.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fconsent-phishing","solid:faThumbsUp",{"title":270,"text":271,"url":272,"navIcon":273},"Malicious OAuth integrations","Detect and block the root cause of SaaS supply chain attacks.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fmalicious-oauth-integrations","solid:faPlugCircleXmark",{"title":275,"text":276,"url":277,"navIcon":278},"Malicious browser extensions","Inventory, monitor, and block risky browser extensions.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fmalicious-browser-extensions","sharp-regular:faPuzzlePiece",{"title":280,"text":281,"url":282,"navIcon":283},"Malicious file downloads","Control which files users can download by type, source, and user group.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fmalicious-file-downloads","solid:faFileCircleXmark",{"title":285,"text":286,"url":287,"navIcon":283},"Infostealers","Detect infostealer delivery and respond to a compromise.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Finfostealer-malware",{"title":289,"text":290,"url":291,"navIcon":292},"Ghost logins","Surface hidden login paths that bypass SSO and expose accounts.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fghost-logins","solid:faGhost",{"title":294,"text":295,"url":296,"navIcon":297},"Mobile phishing (QR & SMS)","Detect phishing regardless of whether it arrives via email, SMS, or QR code.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fmobile-phishing-qr-code-sms","solid:faQrcode",{"title":299,"text":300,"url":301,"navIcon":302},"Credential stuffing","Identify reused and compromised credentials across SaaS logins.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fcredential-stuffing","custom:credentialStuffing",{"title":304,"text":305,"url":306,"navIcon":307},"Session hijacking","Detect and respond to stolen session token replay with browser session markers.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fsession-hijacking","solid:faCookieBite",{"id":309,"label":310,"text":21,"navIcon":311,"items":312},"achieve-security-outcomes","Achieve security outcomes","solid:faCheckToSlot",[313,318,323,328,333,338,343,348],{"title":314,"text":315,"url":316,"navIcon":317},"Stop account takeover","Stop ATO with stolen credential and compromised token detection.","\u002Fsolution\u002Fachieve-security-outcomes\u002Fstop-account-takeover","sharp-regular:faUserSecret",{"title":319,"text":320,"url":321,"navIcon":322},"Harden unmanaged identities","Harden access paths with visibility, detection, and guardrails.","\u002Fsolution\u002Fachieve-security-outcomes\u002Fharden-unmanaged-identities","sharp-regular:faRadar",{"title":324,"text":325,"url":326,"navIcon":327},"Investigate browser-related incidents","Investigate and respond faster with unique browser telemetry.","\u002Fsolution\u002Fachieve-security-outcomes\u002Finvestigate-browser-related-incidents","sharp-regular:faSatelliteDish",{"title":329,"text":330,"url":331,"navIcon":332},"Secure shadow IT","See and control shadow SaaS in the browser.","\u002Fsolution\u002Fachieve-security-outcomes\u002Fsecure-shadow-saas","sharp-regular:faShieldCheck",{"title":334,"text":335,"url":336,"navIcon":337},"Secure AI","See and control AI apps in the browser.","\u002Fsolution\u002Fachieve-security-outcomes\u002Fsecure-ai","sharp-regular:faBrainCircuit",{"title":339,"text":340,"url":341,"navIcon":342},"Secure BYOD","Extend security to unmanaged devices without MDM.","\u002Fsolution\u002Fachieve-security-outcomes\u002Fsecure-bring-your-own-device","solid:faMobileScreenButton",{"title":344,"text":345,"url":346,"navIcon":347},"Secure Chromebooks","Secure Chromebooks in the enterprise without endpoint agents. Push deploys as a browser extension — phishing detection, credential monitoring, and SaaS visibility via browser extension that works with Chrome OS.","\u002Fsolution\u002Fachieve-security-outcomes\u002Fsecure-chromebooks","brands:faChrome",{"title":349,"text":350,"url":351,"navIcon":352},"Data loss prevention","Enforce DLP at the point of interaction in the browser","\u002Fsolution\u002Fachieve-security-outcomes\u002Finvestigate-and-stop-data-loss","custom:investigateAndStopDataLoss",{"id":354,"label":355,"text":21,"navIcon":356,"items":357},"tool-replacements","Tool replacements","solid:faScrewdriverWrench",[358,363,368,373],{"title":359,"text":360,"url":361,"navIcon":362},"Remote browser isolation","Detect attacks that look like normal browsing.","\u002Fsolution\u002Ftool-replacements\u002Fremote-browser-isolation","solid:faDisplay",{"title":364,"text":365,"url":366,"navIcon":367},"Secure web gateways","Detect attacks inside the browser after SWGs allowed the connection.","\u002Fsolution\u002Ftool-replacements\u002Fsecure-web-gateways","solid:faFilter",{"title":369,"text":370,"url":371,"navIcon":372},"Cloud access security broker","Catch browser-based identity threats in real time, not after the fact.","\u002Fsolution\u002Ftool-replacements\u002Fcloud-access-security-broker","solid:faCloudArrowUp",{"title":374,"text":375,"url":376,"navIcon":377},"Security awareness training","Block real phishing instead of training users on simulations.","\u002Fsolution\u002Ftool-replacements\u002Fsecurity-awareness-training","custom:securityAwareness",{"w":379,"h":380,"d":381},448,512,"M284.6 0l91.4 0 0 160-48 0 0-112-36.6 0-203.4 58.1 0 181.9 40 0 0 224-128 0 0-224 40 0 0-218.1 17.4-5 224-64 3.2-.9zM80 336l-32 0 0 128 32 0 0-128zm176 8c0-76.8 64-136 96-152 32 16 96 75.2 96 152 0 32-16 80-64 112l32 40 0 16-128 0 0-16 32-40c-48-32-64-80-64-112zm128-32a24 24 0 1 0 -48 0 24 24 0 1 0 48 0z",{"w":379,"h":380,"d":383},"M171-16c-36.4 0-57.8 58.3-68.3 112L72 96c-13.3 0-24 10.7-24 24s10.7 24 24 24l24 0 0 32c0 17 3.3 33.2 9.3 48l-9.3 0 0 0-20.5 0c-15.2 0-27.5 12.3-27.5 27.5 0 3 .5 5.9 1.4 8.7l28.9 86.6C40.2 379.6 16 428.1 16 482.3 16 498.7 29.3 512 45.7 512l356.6 0c16.4 0 29.7-13.3 29.7-29.7 0-54.2-24.2-102.7-62.3-135.4l28.9-86.6c.9-2.8 1.4-5.7 1.4-8.7 0-15.2-12.3-27.5-27.5-27.5l-20.5 0 0 0-9.3 0c6-14.8 9.3-31 9.3-48l0-32 24 0c13.3 0 24-10.7 24-24s-10.7-24-24-24l-30.7 0c-10.4-53.7-31.9-112-68.3-112-9.6 0-19 3.9-27.5 8.2-8.2 4.1-18.4 7.8-25.5 7.8s-17.3-3.7-25.5-7.8C190-12.1 180.6-16 171-16zm93.7 484.4l-24.8-70.9 27.9-32.5c2.7-3.2 4.2-7.2 4.2-11.4 0-9.7-7.8-17.5-17.5-17.5l-61 0c-9.7 0-17.5 7.8-17.5 17.5 0 4.2 1.5 8.2 4.2 11.4l27.9 32.5-24.8 70.9-57-180.4 35.7 0c18.4 10.2 39.5 16 62 16s43.6-5.8 62-16l35.7 0-57 180.4zM224 256c-34.7 0-64.2-22.1-75.3-53 5.7 3.2 12.3 5 19.3 5l12.4 0c16.5 0 31.1-10.6 36.3-26.2 2.3-7 12.2-7 14.5 0 5.2 15.6 19.9 26.2 36.3 26.2l12.4 0c7 0 13.6-1.8 19.3-5-11.1 30.9-40.6 53-75.3 53z",{"w":17,"h":380,"d":385},"M112 80l416 0 0 224 48 0 0-272-512 0 0 272 48 0 0-224zM48 404.1l0-4.1 544 0 0 4.1-27.9 27.9-488.2 0-27.9-27.9zM592 352l-592 0 0 72 56 56 528 0 56-56 0-72-48 0zM281 169l17-17-33.9-33.9c-6.1 6.1-27.8 27.8-65 65l-17 17c6.1 6.1 27.8 27.8 65 65l17 17 33.9-33.9c-9-9-25-25-48-48l31-31zM393 135l-17-17-33.9 33.9c9 9 25 25 48 48-23 23-39 39-48 48L376 281.9c6.1-6.1 27.8-27.8 65-65l17-17c-6.1-6.1-27.8-27.8-65-65z",{"w":379,"h":380,"d":387},"M0 64C0 28.7 28.7 0 64 0L384 0c35.3 0 64 28.7 64 64l0 384c0 35.3-28.7 64-64 64L64 512c-35.3 0-64-28.7-64-64L0 64zM256 432a32 32 0 1 0 -64 0 32 32 0 1 0 64 0zM384 64l-320 0 0 288 320 0 0-288z",{"w":380,"h":380,"d":389},"M80 160c17.7 0 32 14.3 32 32l0 256c0 17.7-14.3 32-32 32l-48 0c-17.7 0-32-14.3-32-32L0 192c0-17.7 14.3-32 32-32l48 0zM270.6 16C297.9 16 320 38.1 320 65.4l0 4.2c0 6.8-1.3 13.6-3.8 19.9L288 160 448 160c26.5 0 48 21.5 48 48 0 19.7-11.9 36.6-28.9 44 17 7.4 28.9 24.3 28.9 44 0 23.4-16.8 42.9-39 47.1 4.4 7.3 7 15.8 7 24.9 0 22.2-15 40.8-35.4 46.3 2.2 5.5 3.4 11.5 3.4 17.7 0 26.5-21.5 48-48 48l-87.9 0c-36.3 0-71.6-12.4-99.9-35.1L184 435.2c-15.2-12.1-24-30.5-24-50l0-186.6c0-14.9 3.5-29.6 10.1-42.9L226.3 43.3C234.7 26.6 251.8 16 270.6 16z",{"w":17,"h":380,"d":391},"M192-32c17.7 0 32 14.3 32 32l0 96 128 0 0-96c0-17.7 14.3-32 32-32s32 14.3 32 32l0 96 64 0c17.7 0 32 14.3 32 32s-14.3 32-32 32l0 48.7c-98.6 8.1-176 90.7-176 191.3 0 27.3 5.7 53.3 16 76.9l0 3.1c0 17.7-14.3 32-32 32s-32-14.3-32-32l0-66.7C165.2 398.1 96 319.1 96 224l0-64c-17.7 0-32-14.3-32-32S78.3 96 96 96l64 0 0-96c0-17.7 14.3-32 32-32zM496 256a144 144 0 1 1 0 288 144 144 0 1 1 0-288zm59.3 107.3c6.2-6.2 6.2-16.4 0-22.6s-16.4-6.2-22.6 0l-36.7 36.7-36.7-36.7c-6.2-6.2-16.4-6.2-22.6 0s-6.2 16.4 0 22.6l36.7 36.7-36.7 36.7c-6.2 6.2-6.2 16.4 0 22.6s16.4 6.2 22.6 0l36.7-36.7 36.7 36.7c6.2 6.2 16.4 6.2 22.6 0s6.2-16.4 0-22.6l-36.7-36.7 36.7-36.7z",{"w":380,"h":380,"d":393},"M201.1 57.3c-7 5.3-9.1 10.7-9.1 14.7 0 4.5 2.8 11.2 12.4 16.9l11.6 7 0 48.1-168 0 0 60.5c7.4-2.9 15.5-4.5 24-4.5 43.1 0 72 39.4 72 80s-28.9 80-72 80c-8.5 0-16.6-1.6-24-4.5l0 108.5 108.5 0c-2.9-7.4-4.5-15.5-4.5-24 0-43.1 39.4-72 80-72s80 28.9 80 72c0 8.5-1.6 16.6-4.5 24l60.5 0 0-168 48.1 0 7 11.6c5.8 9.6 12.4 12.4 16.9 12.4 4 0 9.5-2.1 14.7-9.1s9.3-17.9 9.3-30.9-4-23.8-9.3-30.9-10.7-9.1-14.7-9.1c-4.5 0-11.2 2.8-16.9 12.4l-7 11.6-48.1 0 0-120-120 0 0-48.1 11.6-7c9.6-5.8 12.4-12.4 12.4-16.9 0-4-2.1-9.5-9.1-14.7S245 48 232 48 208.2 52 201.1 57.3zM172.3 18.9C188.5 6.8 209.6 0 232 0S275.5 6.8 291.7 18.9 320 49.5 320 72c0 8.6-1.8 16.7-4.9 24l100.9 0 0 100.9c7.3-3.1 15.4-4.9 24-4.9 22.5 0 41 12.2 53.1 28.3s18.9 37.3 18.9 59.7-6.8 43.5-18.9 59.7-30.6 28.3-53.1 28.3c-8.6 0-16.7-1.8-24-4.9l0 148.9-168 0 0-49.3 8.2-7.2c5.4-4.7 7.8-10.3 7.8-15.5 0-9.9-10.7-24-32-24s-32 14.1-32 24c0 5.3 2.4 10.8 7.8 15.5l8.2 7.2 0 49.3-216 0 0-216 49.3 0 7.2 8.2c4.7 5.4 10.3 7.8 15.5 7.8 9.9 0 24-10.7 24-32s-14.1-32-24-32c-5.3 0-10.8 2.4-15.5 7.8L49.3 264 0 264 0 96 148.9 96c-3.1-7.3-4.9-15.4-4.9-24 0-22.5 12.2-41 28.3-53.1z",{"w":395,"h":380,"d":396},576,"M96 0C60.7 0 32 28.7 32 64l0 384c0 35.3 28.7 64 64 64l180 0c-22.7-31.5-36-70.2-36-112 0-100.6 77.4-183.2 176-191.3l0-38.1c0-17-6.7-33.3-18.7-45.3L290.7 18.7C278.7 6.7 262.5 0 245.5 0L96 0zM357.5 176L264 176c-13.3 0-24-10.7-24-24L240 58.5 357.5 176zM432 544a144 144 0 1 0 0-288 144 144 0 1 0 0 288zm59.3-180.7l-36.7 36.7 36.7 36.7c6.2 6.2 6.2 16.4 0 22.6s-16.4 6.2-22.6 0l-36.7-36.7-36.7 36.7c-6.2 6.2-16.4 6.2-22.6 0s-6.2-16.4 0-22.6l36.7-36.7-36.7-36.7c-6.2-6.2-6.2-16.4 0-22.6s16.4-6.2 22.6 0l36.7 36.7 36.7-36.7c6.2-6.2 16.4-6.2 22.6 0s6.2 16.4 0 22.6z",{"w":398,"h":380,"d":399},384,"M40.1 467.1l-11.2 9C25.7 478.6 21.8 480 17.8 480 8 480 0 472 0 462.2L0 192C0 86 86 0 192 0S384 86 384 192l0 270.2c0 9.8-8 17.8-17.8 17.8-4 0-7.9-1.4-11.1-3.9l-11.2-9c-13.4-10.7-32.8-9-44.1 3.9L269.3 506c-3.3 3.8-8.2 6-13.3 6s-9.9-2.2-13.3-6l-26.6-30.5c-12.7-14.6-35.4-14.6-48.2 0L141.3 506c-3.3 3.8-8.2 6-13.3 6s-9.9-2.2-13.3-6L84.2 471c-11.3-12.9-30.7-14.6-44.1-3.9zM160 192a32 32 0 1 0 -64 0 32 32 0 1 0 64 0zm96 32a32 32 0 1 0 0-64 32 32 0 1 0 0 64z",{"w":379,"h":380,"d":401},"M64 160l64 0 0-64-64 0 0 64zM0 80C0 53.5 21.5 32 48 32l96 0c26.5 0 48 21.5 48 48l0 96c0 26.5-21.5 48-48 48l-96 0c-26.5 0-48-21.5-48-48L0 80zM64 416l64 0 0-64-64 0 0 64zM0 336c0-26.5 21.5-48 48-48l96 0c26.5 0 48 21.5 48 48l0 96c0 26.5-21.5 48-48 48l-96 0c-26.5 0-48-21.5-48-48l0-96zM320 96l0 64 64 0 0-64-64 0zM304 32l96 0c26.5 0 48 21.5 48 48l0 96c0 26.5-21.5 48-48 48l-96 0c-26.5 0-48-21.5-48-48l0-96c0-26.5 21.5-48 48-48zM288 352a32 32 0 1 1 0-64 32 32 0 1 1 0 64zm0 64c17.7 0 32 14.3 32 32s-14.3 32-32 32-32-14.3-32-32 14.3-32 32-32zm96 32c0-17.7 14.3-32 32-32s32 14.3 32 32-14.3 32-32 32-32-14.3-32-32zm32-96a32 32 0 1 1 0-64 32 32 0 1 1 0 64zm-32 32a32 32 0 1 1 -64 0 32 32 0 1 1 64 0z",{"w":380,"h":380,"d":403},"M257.5 27.6c-.8-5.4-4.9-9.8-10.3-10.6-22.1-3.1-44.6 .9-64.4 11.4l-74 39.5C89.1 78.4 73.2 94.9 63.4 115L26.7 190.6c-9.8 20.1-13 42.9-9.1 64.9l14.5 82.8c3.9 22.1 14.6 42.3 30.7 57.9l60.3 58.4c16.1 15.6 36.6 25.6 58.7 28.7l83 11.7c22.1 3.1 44.6-.9 64.4-11.4l74-39.5c19.7-10.5 35.6-27 45.4-47.2l36.7-75.5c9.8-20.1 13-42.9 9.1-64.9-.9-5.3-5.3-9.3-10.6-10.1-51.5-8.2-92.8-47.1-104.5-97.4-1.8-7.6-8-13.4-15.7-14.6-54.6-8.7-97.7-52-106.2-106.8zM208 144a32 32 0 1 1 0 64 32 32 0 1 1 0-64zM144 336a32 32 0 1 1 64 0 32 32 0 1 1 -64 0zm224-64a32 32 0 1 1 0 64 32 32 0 1 1 0-64z",{"w":379,"h":380,"d":405},"M144-16l-48 112-48 0 0 48 48 0 0 32c0 17 3.3 33.2 9.3 48l-73.3 0 0 32 5.3 16 26.7 80-64 160 51.7 0 56.9-142.2 6.5-16.3c-1-3.1-10.1-30.3-27.2-81.5l51.4 0c22.6 19.9 52.2 32 84.7 32s62.1-12.1 84.7-32l51.4 0c-17.1 51.2-26.1 78.4-27.2 81.5l6.5 16.3 56.9 142.2 51.7 0-64-160 26.7-80 5.3-16 0-32-73.3 0c6-14.8 9.3-31 9.3-48l0-32 48 0 0-48-48 0-48-112-32 0-48 32-48-32-32 0zm80 272c-32.8 0-61-19.7-73.3-48l57.3 0 16-40 16 40 57.3 0c-12.3 28.3-40.5 48-73.3 48zm17.5 139.6l30.5-35.6 0-24-96 0 0 24 30.5 35.6-46.5 116.4 128 0-46.5-116.4z",{"w":380,"h":380,"d":407},"M497.4 49l17-17-33.9-33.9C473.6 4.9 453.3 25.2 419.7 58.8 375.4 22.1 318.5 0 256.4 0 115.1 0 .4 114.6 .4 256s114.6 256 256 256 256-114.6 256-256l-48 0c0 114.9-93.1 208-208 208s-208-93.1-208-208 93.1-208 208-208c48.8 0 93.7 16.8 129.1 44.9l-45.7 45.7c-23.5-16.8-52.3-26.6-83.4-26.6-79.5 0-144 64.5-144 144s64.5 144 144 144 144-64.5 144-144l-48 0c0 53-43 96-96 96s-96-43-96-96 43-96 96-96c17.8 0 34.5 4.8 48.8 13.3-52 52-79.5 79.5-82.7 82.7l33.9 33.9 17-17 224-224z",{"w":380,"h":380,"d":409},"M208 0l24 0C386.6 0 512 125.4 512 280l0 24-48 0 0-24C464 151.9 360.1 48 232 48l-24 0 0-48zm24 96c101.6 0 184 82.4 184 184l0 24-48 0 0-24c0-75.1-60.9-136-136-136l-24 0 0-48 24 0zM48 256c0 114.9 93.1 208 208 208 22.9 0 45-3.7 65.6-10.5l-263-263C51.7 211 48 233.1 48 256zM0 256c0-36.5 7.6-71.3 21.4-102.7 6.7-15.3 14.9-29.9 24.4-43.5 7.7 7.7 61.5 61.5 161.2 161.2 30.5-30.5 49.5-49.5 57-57L297.9 248c-7.5 7.5-26.5 26.5-57 57 99.7 99.7 153.5 153.5 161.2 161.2-13.6 9.5-28.2 17.7-43.5 24.4-31.4 13.8-66.2 21.4-102.7 21.4-141.4 0-256-114.6-256-256z",{"w":380,"h":380,"d":411},"M267.6 4.5l207.5 80.5 19.2 7.4 1.2 20.5c2.9 50-4.9 126.3-37.3 200.9-32.7 75.2-91.1 150-189.4 192.5l-12.7 5.5-12.7-5.5C144.9 463.9 86.6 389.2 53.9 313.9 21.5 239.3 13.7 162.9 16.6 113L17.8 92.5 37 85 244.5 4.5 256 0 267.6 4.5zM64.1 126C63.1 169.5 71 232.9 97.9 294.8 126.1 359.7 175 422.4 256 459.6 337.1 422.4 385.9 359.7 414.2 294.8 441 232.9 449 169.5 448 126L256 51.5 64.1 126zm302.3 44.7L352.3 190.1 249.8 330.9 233 354c-8.8-9.1-30.9-32-66.2-68.6l-16.7-17.3 34.5-33.3c9.5 9.8 23.9 24.7 43.2 44.7l85.6-117.7 14.1-19.4 38.8 28.2z",{"w":380,"h":380,"d":413},"M192 48l40 0 0 108-12.4 0c-7.6-16.5-24.3-28-43.6-28-26.5 0-48 21.5-48 48s21.5 48 48 48c19.4 0 36.1-11.5 43.6-28l12.4 0 0 56-92 0 0 56.4c-16.5 7.6-28 24.3-28 43.6 0 26.5 21.5 48 48 48s48-21.5 48-48c0-19.4-11.5-36.1-28-43.6l0-16.4 52 0 0 172-40 0c-16.8 0-31.2-10.3-37.1-25.1l-6.4-16-17.2 1c-1.1 .1-2.2 .1-3.2 .1-30.9 0-56-25.1-56-56 0-9.5 2.4-18.5 6.5-26.3l8.7-16.2-13.4-12.6c-11-10.2-17.8-24.8-17.8-40.9 0-21.6 12.2-40.4 30.3-49.8l22.6-11.7-13.1-21.9c-5-8.4-7.9-18.1-7.9-28.6 0-30.9 25.1-56 56-56l24 0 0-32c0-13.3 10.7-24 24-24zm88 148l12.4 0c7.6 16.5 24.3 28 43.6 28 26.5 0 48-21.5 48-48s-21.5-48-48-48c-19.4 0-36.1 11.5-43.6 28l-12.4 0 0-108 40 0c13.3 0 24 10.7 24 24l0 32 24 0c30.9 0 56 25.1 56 56 0 10.5-2.9 20.3-7.9 28.6l-13.1 21.9 22.6 11.7c18 9.3 30.3 28.1 30.3 49.8 0 16.1-6.8 30.7-17.8 40.9l-13.4 12.6 8.7 16.2c4.2 7.8 6.5 16.7 6.5 26.3 0 30.9-25.1 56-56 56-1.1 0-2.2 0-3.2-.1l-17.2-1-6.4 16C351.2 453.7 336.8 464 320 464l-40 0 0-76 92 0 0-56.4c16.5-7.6 28-24.3 28-43.6 0-26.5-21.5-48-48-48s-48 21.5-48 48c0 19.4 11.5 36.1 28 43.6l0 16.4-52 0 0-152zM192 512l128 0c31.1 0 58.4-16.2 74.1-40.5 52.7-5.1 93.9-49.5 93.9-103.5 0-11.5-1.9-22.5-5.3-32.9 13.4-17.5 21.3-39.4 21.3-63.1 0-32-14.5-60.6-37.1-79.7 3.3-10.2 5.1-21.1 5.1-32.3 0-49.6-34.8-91.1-81.3-101.5-6.3-33.3-35.6-58.5-70.7-58.5L192 0c-35.1 0-64.4 25.2-70.7 58.5-46.5 10.4-81.3 51.9-81.3 101.5 0 11.3 1.8 22.2 5.1 32.3-22.7 19.1-37.1 47.7-37.1 79.7 0 23.7 8 45.6 21.3 63.1-3.5 10.4-5.3 21.4-5.3 32.9 0 54 41.2 98.5 93.9 103.5 15.6 24.3 42.9 40.5 74.1 40.5zM336 192a16 16 0 1 1 0-32 16 16 0 1 1 0 32zm32 96a16 16 0 1 1 -32 0 16 16 0 1 1 32 0zM176 352a16 16 0 1 1 -32 0 16 16 0 1 1 32 0zm16-176a16 16 0 1 1 -32 0 16 16 0 1 1 32 0z",{"w":398,"h":380,"d":415},"M16 64C16 28.7 44.7 0 80 0L304 0c35.3 0 64 28.7 64 64l0 384c0 35.3-28.7 64-64 64L80 512c-35.3 0-64-28.7-64-64L16 64zm64 0l0 304 224 0 0-304-224 0zM192 472c17.7 0 32-14.3 32-32s-14.3-32-32-32-32 14.3-32 32 14.3 32 32 32z",{"w":380,"h":380,"d":417},"M0 256c0-46.6 12.5-90.4 34.3-128.9L144.1 318.3c21.9 39.2 63.8 65.7 111.9 65.7 14.3 0 27.1-2.3 40.8-6.6L220.5 509.6C95.9 492.3 0 385.3 0 256zm365.1 65.6c12.3-19.2 18.9-42.5 18.9-65.6 0-38.2-16.8-72.5-43.3-96l152.7 0c12 29.6 18.6 62.1 18.6 96 0 141.4-114.6 255.1-256 256L365.1 321.6zM477.8 128L256 128c-62.9 0-113.7 44.1-125.5 102.7L54.2 98.5C101 38.5 174 0 256 0 350.8 0 433.5 51.5 477.8 128zM344 256a88 88 0 1 1 -176 0 88 88 0 1 1 176 0z",{"w":380,"h":380,"d":419},"M448 96l0 256-384 0 0-256 384 0zM64 32C28.7 32 0 60.7 0 96L0 352c0 35.3 28.7 64 64 64l144 0-16 48-72 0c-13.3 0-24 10.7-24 24s10.7 24 24 24l272 0c13.3 0 24-10.7 24-24s-10.7-24-24-24l-72 0-16-48 144 0c35.3 0 64-28.7 64-64l0-256c0-35.3-28.7-64-64-64L64 32z",{"w":380,"h":380,"d":421},"M32 64C19.1 64 7.4 71.8 2.4 83.8S.2 109.5 9.4 118.6L192 301.3 192 416c0 8.5 3.4 16.6 9.4 22.6l64 64c9.2 9.2 22.9 11.9 34.9 6.9S320 492.9 320 480l0-178.7 182.6-182.6c9.2-9.2 11.9-22.9 6.9-34.9S492.9 64 480 64L32 64z",{"w":395,"h":380,"d":423},"M144 480c-79.5 0-144-64.5-144-144 0-63.4 41-117.2 97.9-136.5-1.3-7.7-1.9-15.5-1.9-23.5 0-79.5 64.5-144 144-144 55.4 0 103.5 31.3 127.6 77.1 14.2-8.3 30.8-13.1 48.4-13.1 53 0 96 43 96 96 0 15.7-3.8 30.6-10.5 43.7 44 20.3 74.5 64.7 74.5 116.3 0 70.7-57.3 128-128 128l-304 0zM305 191c-9.4-9.4-24.6-9.4-33.9 0l-72 72c-9.4 9.4-9.4 24.6 0 33.9s24.6 9.4 33.9 0l31-31 0 102.1c0 13.3 10.7 24 24 24s24-10.7 24-24l0-102.1 31 31c9.4 9.4 24.6 9.4 33.9 0s9.4-24.6 0-33.9l-72-72z",{"id":425,"title":426,"authorsCollection":427,"content":435,"extension":688,"faqItemsCollection":689,"faqTitle":60,"featured":19,"hashTags":60,"meta":691,"metaTitle":692,"ogImage":60,"postType":693,"publishedDate":694,"relatedBlogPostsCollection":695,"slug":3398,"stem":3399,"subtitle":60,"summary":3400,"synopsis":3411,"sys":3412,"tagsCollection":3415,"topicsCollection":3421,"__hash__":3460},"blog\u002Fblog\u002Fproofpoint-x-push-partnership-announcement.json","Proofpoint x Push: Why browser security is now a non-negotiable for security teams",{"items":428},[429],{"fullName":430,"firstName":431,"jobTitle":432,"socialLinks":60,"profilePicture":433},"Adam Bateman","Adam","Co-founder \u002F CEO",{"url":434},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F3Bt9feB72kxdWlS0hvpldi\u002F904bdb8b20d98e53c574f8be2f60996b\u002FPush_Founders_at_Cahoots_October_28_2022_by_Doug_Coombe-20.jpg",{"json":436,"links":683},{"nodeType":437,"data":438,"content":439},"document",{},[440,459,466,470,479,486,493,500,507,514,523,530,551,559,566,573,580,583,591,598,605,612,619,627,634,641,648,651,658,665],{"nodeType":441,"data":442,"content":443},"paragraph",{},[444,449,455],{"nodeType":445,"value":446,"marks":447,"data":448},"text","We're announcing a partnership with Proofpoint to power ",[],{},{"nodeType":445,"value":450,"marks":451,"data":454},"Proofpoint Advanced Browser Protection ",[452],{"type":453},"bold",{},{"nodeType":445,"value":456,"marks":457,"data":458},"— a new addition to Proofpoint's collaboration security platform that extends protection from the inbox into the browser session. Push provides the real-time behavioral detection, in-session blocking, and browser telemetry that feeds directly into Proofpoint's Threat Protection Workbench, Security Graph, and Investigation Agent.",[],{},{"nodeType":441,"data":460,"content":461},{},[462],{"nodeType":445,"value":463,"marks":464,"data":465},"Proofpoint is one of the biggest names in cybersecurity. They've spent two decades building the most comprehensive picture of how attacks reach people via email. This partnership exists because Proofpoint recognizes that today’s attacks don’t stop at the inbox: they happen inside the browser session. ",[],{},{"nodeType":467,"data":468,"content":469},"hr",{},[],{"nodeType":471,"data":472,"content":473},"heading-1",{},[474],{"nodeType":445,"value":475,"marks":476,"data":478},"Phishing doesn't stop at the inbox anymore",[477],{"type":453},{},{"nodeType":441,"data":480,"content":481},{},[482],{"nodeType":445,"value":483,"marks":484,"data":485},"Email is one of the most heavily defended delivery channels in the enterprise. Enterprise organizations have multiple layers of email security, scanning messages for malicious links, sandboxing attachments, and rewriting URLs. ",[],{},{"nodeType":441,"data":487,"content":488},{},[489],{"nodeType":445,"value":490,"marks":491,"data":492},"But better controls doesn't mean attackers stopped phishing: they adapted.",[],{},{"nodeType":441,"data":494,"content":495},{},[496],{"nodeType":445,"value":497,"marks":498,"data":499},"Push data shows a growing number of malicious payloads now arrive outside of email entirely — via messaging apps, social media, search results, and malvertising.",[],{},{"nodeType":441,"data":501,"content":502},{},[503],{"nodeType":445,"value":504,"marks":505,"data":506},"As email defenses improve, attackers increasingly conceal malicious content during delivery, such as multi-stage redirect chains and conditional loading based on email,  IP and browser checks that prevent the true destination from being revealed until a user interacts with the link. These techniques allow links to appear legitimate during email inspection while exposing malicious content only at the point of interaction, making the browser a critical control point for detecting and stopping modern attacks.",[],{},{"nodeType":441,"data":508,"content":509},{},[510],{"nodeType":445,"value":511,"marks":512,"data":513},"All of this makes it increasingly difficult for traditional time-of-click URL and page analysis to find and block bad before a user has the chance to get phished. ",[],{},{"nodeType":515,"data":516,"content":517},"heading-2",{},[518],{"nodeType":445,"value":519,"marks":520,"data":522},"No matter the delivery vector, the attack plays out in the browser ",[521],{"type":453},{},{"nodeType":441,"data":524,"content":525},{},[526],{"nodeType":445,"value":527,"marks":528,"data":529},"Either way, the attack ends up rendering in the browser session, where the user enters credentials and completes MFA checks, authorizes an OAuth consent grant, copies a malicious command, downloads a file, or installs a malicious extension. That's the moment that determines whether the attack succeeds or fails.",[],{},{"nodeType":441,"data":531,"content":532},{},[533,536,547],{"nodeType":445,"value":21,"marks":534,"data":535},[],{},{"nodeType":537,"data":538,"content":540},"hyperlink",{"uri":539},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002F7-things-omdias-latest-report-tells-us-about-the-secure-enterprise-browser-market",[541],{"nodeType":445,"value":542,"marks":543,"data":546},"Omdia's Browser Management and Security ",[544],{"type":545},"underline",{},{"nodeType":445,"value":548,"marks":549,"data":550},"report puts a number on the consequence: 49% of organizations suffered a confirmed successful browser-based attack in the preceding 12 months, and 88% now rank browser security among their top 5 priorities.",[],{},{"nodeType":471,"data":552,"content":553},{},[554],{"nodeType":445,"value":555,"marks":556,"data":558},"Known-bad blocklists can’t keep up: Real-time behavioral analysis in the browser is the answer",[557],{"type":453},{},{"nodeType":441,"data":560,"content":561},{},[562],{"nodeType":445,"value":563,"marks":564,"data":565},"89% of phishing domains are active for less than two days. Phishing kits rotate infrastructure continuously. Attackers host phishing content on trusted cloud platforms — Azure Blob Storage, Cloudflare Workers, Google-owned domains, and many more — that carry clean reputations by default. A URL that returns \"safe\" at time of delivery tells you very little about what the page will do when the user clicks through an hour later.",[],{},{"nodeType":441,"data":567,"content":568},{},[569],{"nodeType":445,"value":570,"marks":571,"data":572},"Push detects attacks by analyzing what the page actually does. Because we operate inside the browser session, we see the page load in real time and how the user interacts with it, including all of the client-side scripting and DOM loading that happens with modern web pages (and is invisible at the network layer). This means we can spot attacks by technique and behavior rather than just looking at things like domains, URLs, or static HTML.",[],{},{"nodeType":441,"data":574,"content":575},{},[576],{"nodeType":445,"value":577,"marks":578,"data":579},"AiTM kits, cloned login pages, Browser-in-the-Browser pop-ups, the ClickFix family of malicious copy-and-paste attacks, device code phishing, malicious OAuth consent grants — our behavioral detection catches them all, regardless of the infrastructure, hosting, or phish kits used. ",[],{},{"nodeType":467,"data":581,"content":582},{},[],{"nodeType":471,"data":584,"content":585},{},[586],{"nodeType":445,"value":587,"marks":588,"data":590},"What Push brings to Advanced Browser Protection",[589],{"type":453},{},{"nodeType":441,"data":592,"content":593},{},[594],{"nodeType":445,"value":595,"marks":596,"data":597},"Push detects and blocks attacks regardless of whether a phishing link arrived via email, social media DM,  a Teams message, a Google search ad, or a compromised website. The delivery channel is irrelevant to Push's detection model — which is the point. ",[],{},{"nodeType":441,"data":599,"content":600},{},[601],{"nodeType":445,"value":602,"marks":603,"data":604},"With Push, no matter where a link is clicked and a page is loaded from, malicious content is detected and blocked in real time, before the user is compromised. Even if a page has never been flagged before, Push analyzes, detects the malicious elements of the page, and blocks access before the user has time to interact with it. Every session and interaction is protected by Push, without any need for sandboxing or latency-inducing remote isolation technology. ",[],{},{"nodeType":441,"data":606,"content":607},{},[608],{"nodeType":445,"value":609,"marks":610,"data":611},"Push's browser telemetry — every page load, credential entry, session event, and OAuth consent — feeds directly into Proofpoint's Threat Protection Workbench and Investigation Agent, giving security teams a unified view from the message that carried the lure through to the credential entered and the session compromised. ",[],{},{"nodeType":441,"data":613,"content":614},{},[615],{"nodeType":445,"value":616,"marks":617,"data":618},"An analyst working in Proofpoint's platform can now follow a single attack end-to-end without stitching together data from disconnected tools and limited data sources, significantly reducing investigation and response times. ",[],{},{"nodeType":471,"data":620,"content":621},{},[622],{"nodeType":445,"value":623,"marks":624,"data":626},"What this means for Proofpoint customers",[625],{"type":453},{},{"nodeType":441,"data":628,"content":629},{},[630],{"nodeType":445,"value":631,"marks":632,"data":633},"Proofpoint customers get a first-class browser security integration that covers the attacks email security was never architecturally positioned to catch — and delivers that detection data back into the Proofpoint platform. When Push detects and stops an attack for one Proofpoint customer, the data feeds back into the Proofpoint platform to block it everywhere.",[],{},{"nodeType":441,"data":635,"content":636},{},[637],{"nodeType":445,"value":638,"marks":639,"data":640},"For the broader market, the signal here is hard to miss. When a company of Proofpoint's scale — one that has the highest level of visibility into email-based threats — concludes that browser security is a critical piece for threat protection, that's extreme validation for the secure enterprise browser market. Browser security isn't a niche add-on anymore. It's a non-negotiable.",[],{},{"nodeType":441,"data":642,"content":643},{},[644],{"nodeType":445,"value":645,"marks":646,"data":647},"Proofpoint Advanced Browser Protection will be generally available from early 2027. ",[],{},{"nodeType":467,"data":649,"content":650},{},[],{"nodeType":441,"data":652,"content":653},{},[654],{"nodeType":445,"value":655,"marks":656,"data":657},"Push Security is the most powerful AI-native security tool in the browser. Think EDR, but for the browser — high-fidelity telemetry and real-time control across every session, on every device, with no browser migration required.",[],{},{"nodeType":441,"data":659,"content":660},{},[661],{"nodeType":445,"value":662,"marks":663,"data":664},"Security teams use Push to detect and stop advanced browser-based attacks like AiTM phishing, ClickFix, and session hijacking; gain visibility and control over AI tool usage across their workforce; harden identities by surfacing credential reuse, SSO gaps, and shadow IT; and support data loss and insider investigations with browser-layer telemetry that other tools can't see.",[],{},{"nodeType":441,"data":666,"content":667},{},[668,671,680],{"nodeType":445,"value":21,"marks":669,"data":670},[],{},{"nodeType":537,"data":672,"content":674},{"uri":673},"https:\u002F\u002Fpushsecurity.com\u002Fdemo",[675],{"nodeType":445,"value":676,"marks":677,"data":679},"Book a live demo to learn more.",[678],{"type":545},{},{"nodeType":445,"value":21,"marks":681,"data":682},[],{},{"entries":684},{"hyperlink":685,"block":686,"inline":687},[],[],[],"json",{"items":690},[],{},"Announcing the Proofpoint and Push Security partnership","company-news","2026-09-29T00:00:00.000Z",{"items":696},[697,1592,2088],{"__typename":698,"sys":699,"content":701,"title":1570,"synopsis":1571,"hashTags":60,"publishedDate":1572,"slug":1573,"tagsCollection":1574,"authorsCollection":1584},"BlogPosts",{"id":700},"62Zyr35VUmijkpupWk3hoD",{"json":702},{"nodeType":437,"data":703,"content":704},{},[705,722,729,732,740,747,754,786,795,802,809,816,819,827,834,837,845,852,858,865,871,891,898,905,912,918,921,929,936,942,973,980,996,1015,1022,1028,1031,1039,1058,1065,1088,1120,1156,1163,1169,1172,1180,1187,1193,1212,1219,1247,1278,1284,1287,1295,1302,1308,1327,1334,1384,1422,1429,1435,1438,1446,1453,1460,1486,1505,1511,1514,1522,1540,1546,1552],{"nodeType":441,"data":706,"content":707},{},[708,712,718],{"nodeType":445,"value":709,"marks":710,"data":711},"The view that \"the browser is the new endpoint\" and \"the new battleground for cyber attacks\" is becoming increasingly advocated by security leaders. But what does this ",[],{},{"nodeType":445,"value":713,"marks":714,"data":717},"actually",[715],{"type":716},"italic",{},{"nodeType":445,"value":719,"marks":720,"data":721}," mean for security teams? ",[],{},{"nodeType":441,"data":723,"content":724},{},[725],{"nodeType":445,"value":726,"marks":727,"data":728},"In this article, we’re cutting out the jargon to explore what a browser-based attack is, and what’s required for effective detection and response. ",[],{},{"nodeType":467,"data":730,"content":731},{},[],{"nodeType":471,"data":733,"content":734},{},[735],{"nodeType":445,"value":736,"marks":737,"data":739},"What is the goal of a browser-based attack?   ",[738],{"type":453},{},{"nodeType":441,"data":741,"content":742},{},[743],{"nodeType":445,"value":744,"marks":745,"data":746},"First, it’s important to establish what the point of a browser-based attack is.",[],{},{"nodeType":441,"data":748,"content":749},{},[750],{"nodeType":445,"value":751,"marks":752,"data":753},"In most scenarios, attackers don’t think of themselves as attacking your web browser. Their end-goal is to compromise your business apps and data. That means going after the third-party apps and services that are now the backbone of business IT — and therefore the top target for attackers. ",[],{},{"nodeType":441,"data":755,"content":756},{},[757,761,770,774,782],{"nodeType":445,"value":758,"marks":759,"data":760},"The most common attack path today sees attackers log into third-party services, dump the data, and monetize it through extortion. You need only look at last year’s ",[],{},{"nodeType":537,"data":762,"content":764},{"uri":763},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fsnowflake-retro",[765],{"nodeType":445,"value":766,"marks":767,"data":769},"Snowflake",[768],{"type":545},{},{"nodeType":445,"value":771,"marks":772,"data":773}," customer breaches that impacted 165+ organizations, or the still-ongoing ",[],{},{"nodeType":537,"data":775,"content":777},{"uri":776},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fanalyzing-the-instructure-breach",[778],{"nodeType":445,"value":779,"marks":780,"data":781},"Salesforce attacks",[],{},{"nodeType":445,"value":783,"marks":784,"data":785}," to see the scale of the problem. Identity weaknesses played a material role in almost 90% of Unit 42's investigations, and Google\u002FMandiant reported that identity issues were the initial access vector in 83% of cloud-related incidents.",[],{},{"nodeType":787,"data":788,"content":794},"embedded-entry-block",{"target":789},{"sys":790},{"id":791,"type":792,"linkType":793},"5agrVXzEdwALmew2F5SPDp","Link","Entry",[],{"nodeType":441,"data":796,"content":797},{},[798],{"nodeType":445,"value":799,"marks":800,"data":801},"The most logical way to do this is by targeting users of those apps. And because of the changes to working practices, your users are more accessible than ever to external attackers.",[],{},{"nodeType":441,"data":803,"content":804},{},[805],{"nodeType":445,"value":806,"marks":807,"data":808},"Once upon a time, email was the primary communication channel with the wider world, and work happened locally — on your device, and inside your locked-down network environment. This made email and the endpoint the highest priority from a security perspective. But now, with modern work happening across a network of decentralized internet apps, and more varied communication channels outside of email, it’s harder to stop users from interacting with malicious content (at least, without significantly impeding their ability to do their jobs).",[],{},{"nodeType":441,"data":810,"content":811},{},[812],{"nodeType":445,"value":813,"marks":814,"data":815},"Given that the browser is the place where business apps are accessed and used, it makes sense that attacks are increasingly playing out there too. ",[],{},{"nodeType":467,"data":817,"content":818},{},[],{"nodeType":471,"data":820,"content":821},{},[822],{"nodeType":445,"value":823,"marks":824,"data":826},"The 6 key browser-based attacks that security teams need to know about",[825],{"type":453},{},{"nodeType":441,"data":828,"content":829},{},[830],{"nodeType":445,"value":831,"marks":832,"data":833},"Here's our breakdown of the top 6 browser-based attacks that should be on every security team's radar right now. Check out the videos for 101 explainers!",[],{},{"nodeType":467,"data":835,"content":836},{},[],{"nodeType":515,"data":838,"content":839},{},[840],{"nodeType":445,"value":841,"marks":842,"data":844},"1. Phishing for credentials and sessions",[843],{"type":453},{},{"nodeType":441,"data":846,"content":847},{},[848],{"nodeType":445,"value":849,"marks":850,"data":851},"The most direct way for an attacker to compromise a business application is to phish a user of that app. You might not necessarily think of phishing as a browser-based attack, but that’s exactly what it is today. ",[],{},{"nodeType":787,"data":853,"content":857},{"target":854},{"sys":855},{"id":856,"type":792,"linkType":793},"6wn81JTcqktmJSSFfTzNSc",[],{"nodeType":441,"data":859,"content":860},{},[861],{"nodeType":445,"value":862,"marks":863,"data":864},"Phishing tooling and infrastructure has evolved a lot in the past decade, while the changes to business IT means there are both many more vectors for phishing attack delivery, and apps and identities to target. Attackers can deliver links over instant messenger apps, social media, SMS, malicious ads, and using in-app messenger functionality, as well as sending emails directly from SaaS services to bypass email-based checks. Likewise, there are now hundreds of apps per enterprise to target, with varying levels of account security configuration. ",[],{},{"nodeType":787,"data":866,"content":870},{"target":867},{"sys":868},{"id":869,"type":792,"linkType":793},"3SrKOgpedLMQRpKIZqUQur",[],{"nodeType":441,"data":872,"content":873},{},[874,878,887],{"nodeType":445,"value":875,"marks":876,"data":877},"Whereas phishing was once entirely focused on credential theft, modern phishing attacks see the attacker intercept the victim’s session on the target app, using reverse-proxy Attacker-in-the-Middle kits that are the standard choice for attackers today. This means most forms of MFA can be bypassed, with the exception of passkeys (though attackers are finding ways to work around passkeys using ",[],{},{"nodeType":537,"data":879,"content":881},{"uri":880},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fmfa-downgrade-attacks\u002F",[882],{"nodeType":445,"value":883,"marks":884,"data":886},"downgrade attacks",[885],{"type":545},{},{"nodeType":445,"value":888,"marks":889,"data":890},"). ",[],{},{"nodeType":441,"data":892,"content":893},{},[894],{"nodeType":445,"value":895,"marks":896,"data":897},"There are other key differences to be aware of too. Today, phishing operates on an industrial scale, using an array of obfuscation and detection evasion techniques. The latest generation of fully customized AitM phishing kits are dynamically obfuscating the code that loads the web page, implementing custom bot protection (e.g. CAPTCHA or Cloudflare Turnstile), using runtime anti-analysis features, and using legitimate SaaS and cloud services to host and deliver phishing links to cover their tracks.",[],{},{"nodeType":441,"data":899,"content":900},{},[901],{"nodeType":445,"value":902,"marks":903,"data":904},"This means that traditional anti-phishing tools at the email and network layer are struggling to keep up, with many attacks evading email-based detections (or bypassing email altogether). At the same time, proxy-based solutions now see a garbled mess of JavaScript code without the necessary context of what is actually happening in the browser to be able to piece it together effectively. Even if they don’t realize it, this means many organizations are now relying solely on blocking known-bad sites and hosts — a wildly ineffective solution with the rate that attackers refresh and rotate their phishing infrastructure. ",[],{},{"nodeType":441,"data":906,"content":907},{},[908],{"nodeType":445,"value":909,"marks":910,"data":911},"These changes make phishing more effective than ever, and increasingly difficult to detect and block without being able to observe and analyze web pages that a user interacts with in real time — something only possible with browser-level visibility. ",[],{},{"nodeType":787,"data":913,"content":917},{"target":914},{"sys":915},{"id":916,"type":792,"linkType":793},"NHu0Q6ac9mLOPPMoswB8B",[],{"nodeType":467,"data":919,"content":920},{},[],{"nodeType":515,"data":922,"content":923},{},[924],{"nodeType":445,"value":925,"marks":926,"data":928},"2. Malicious copy and paste (aka. ClickFix, FileFix, etc.)",[927],{"type":453},{},{"nodeType":441,"data":930,"content":931},{},[932],{"nodeType":445,"value":933,"marks":934,"data":935},"Since late 2024, attackers have been tricking users into performing malicious actions under the pretext of \"fixing\" an issue for a webpage to load. The most common scenarios relate to \"verifying that you are human,\" styled as a version of the bot protection challenges we're all used to encountering on the internet today. ",[],{},{"nodeType":787,"data":937,"content":941},{"target":938},{"sys":939},{"id":940,"type":792,"linkType":793},"4Tp6KL7yz8CdxdKu5ieWMt",[],{"nodeType":441,"data":943,"content":944},{},[945,949,957,961,969],{"nodeType":445,"value":946,"marks":947,"data":948},"Microsoft's Digital Defense Report identified ClickFix as the ",[],{},{"nodeType":537,"data":950,"content":952},{"uri":951},"https:\u002F\u002Fcdn-dynmedia-1.microsoft.com\u002Fis\u002Fcontent\u002Fmicrosoftcorp\u002Fmicrosoft\u002Fmsc\u002Fdocuments\u002Fpresentations\u002FCSR\u002FMicrosoft-Digital-Defense-Report-2025.pdf",[953],{"nodeType":445,"value":954,"marks":955,"data":956},"most common initial access vector, accounting for 47% of observed attacks",[],{},{"nodeType":445,"value":958,"marks":959,"data":960},". CrowdStrike recorded a ",[],{},{"nodeType":537,"data":962,"content":964},{"uri":963},"https:\u002F\u002Fwww.crowdstrike.com\u002Fexplore\u002F2026-global-threat-report",[965],{"nodeType":445,"value":966,"marks":967,"data":968},"563% increase in fake CAPTCHA ClickFix lures",[],{},{"nodeType":445,"value":970,"marks":971,"data":972},". Push's own detection data tells a similar story: ClickFix made up an average of 52% of detections through Q2 2026, surpassing all other browser-based attack categories for the first time.",[],{},{"nodeType":441,"data":974,"content":975},{},[976],{"nodeType":445,"value":977,"marks":978,"data":979},"Traditional ClickFix-style attacks are a hybrid of browser and endpoint targeting. While delivered via the browser, the user copies and runs malicious scripts on their endpoint, targeting a wide range of legitimate, pre-installed system tools that allow commands to be run (Living Off the Land Binaries, or LOLBins). This results in the user installing malicious software on their machine — typically Remote Access Tools (RATs) and infostealer malware.",[],{},{"nodeType":441,"data":981,"content":982},{},[983,987,992],{"nodeType":445,"value":984,"marks":985,"data":986},"Notably, ClickFix remains a trap that users fall into rather than something they're targeted with directly. ",[],{},{"nodeType":445,"value":988,"marks":989,"data":991},"4 in 5 ClickFix payloads intercepted by Push are accessed from search engines",[990],{"type":453},{},{"nodeType":445,"value":993,"marks":994,"data":995}," — the result of compromised sites, malvertising, and SEO poisoning. This naturally means they completely bypass email-based security controls. ",[],{},{"nodeType":441,"data":997,"content":998},{},[999,1003,1011],{"nodeType":445,"value":1000,"marks":1001,"data":1002},"ClickFix continues to spawn new tools and sub-techniques. ClickFix-as-a-Service platforms are achieving 60% victim conversion rates. Payloads are highly variable, with Push capturing 84 distinct command forms targeting 16+ different system binaries. EtherHiding — storing kit configuration on public blockchains — means there's no host to take down and no domain to block. Attackers are also using shared conversations on AI chatbot platforms like ",[],{},{"nodeType":537,"data":1004,"content":1006},{"uri":1005},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fllmshare-malvertising-campaign\u002F",[1007],{"nodeType":445,"value":1008,"marks":1009,"data":1010},"ChatGPT and Claude to deliver malware",[],{},{"nodeType":445,"value":1012,"marks":1013,"data":1014}," via pages hosted on trusted, legitimate domains.",[],{},{"nodeType":441,"data":1016,"content":1017},{},[1018],{"nodeType":445,"value":1019,"marks":1020,"data":1021},"These varied delivery mechanisms and payloads make ClickFix tricky for traditional security tools to detect in real time. However, every ClickFix attack and variant happens in the browser with a malicious copy and paste event, which is where browser-based tools like Push have a great opportunity to intercept them.",[],{},{"nodeType":787,"data":1023,"content":1027},{"target":1024},{"sys":1025},{"id":1026,"type":792,"linkType":793},"29Y7nRr39TiUyvAwinYctG",[],{"nodeType":467,"data":1029,"content":1030},{},[],{"nodeType":515,"data":1032,"content":1033},{},[1034],{"nodeType":445,"value":1035,"marks":1036,"data":1038},"3. Authorization phishing",[1037],{"type":453},{},{"nodeType":441,"data":1040,"content":1041},{},[1042,1046,1054],{"nodeType":445,"value":1043,"marks":1044,"data":1045},"While AiTM phishing targets the login — the moment a user proves their identity — a growing class of attacks targets what happens after the login. Instead of stealing a session from the authentication flow, ",[],{},{"nodeType":537,"data":1047,"content":1049},{"uri":1048},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fauthorization-phishing",[1050],{"nodeType":445,"value":1051,"marks":1052,"data":1053},"authorization phishing",[],{},{"nodeType":445,"value":1055,"marks":1056,"data":1057}," abuses OAuth authorization mechanisms — consent grants, device code flows, and token exchanges — to obtain access tokens. The attacker never touches the authentication flow at all, which means every form of MFA, including phishing-resistant passkeys, is irrelevant.",[],{},{"nodeType":441,"data":1059,"content":1060},{},[1061],{"nodeType":445,"value":1062,"marks":1063,"data":1064},"Three techniques currently fall under the authorization phishing umbrella:",[],{},{"nodeType":441,"data":1066,"content":1067},{},[1068,1072,1076,1084],{"nodeType":445,"value":265,"marks":1069,"data":1071},[1070],{"type":453},{},{"nodeType":445,"value":1073,"marks":1074,"data":1075}," sees the victim authorize a third-party app via an OAuth consent grant. This can be an app the attacker has created, or a legitimate SaaS app tenant — you can simply sign up for an account and ",[],{},{"nodeType":537,"data":1077,"content":1079},{"uri":1078},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fopenai-poisoned-tenant-attack",[1080],{"nodeType":445,"value":1081,"marks":1082,"data":1083},"invite targets to your app tenant",[],{},{"nodeType":445,"value":1085,"marks":1086,"data":1087},". Identity providers have substantially hardened their defaults against consent phishing (Microsoft now blocks unverified third-party app consent by default, for example), which is why attackers have increasingly shifted to the next two techniques.",[],{},{"nodeType":441,"data":1089,"content":1090},{},[1091,1095,1099,1107,1111,1116],{"nodeType":445,"value":260,"marks":1092,"data":1094},[1093],{"type":453},{},{"nodeType":445,"value":1096,"marks":1097,"data":1098}," targets a different OAuth flow entirely: the RFC 8628 device authorization grant, originally designed for input-constrained devices like smart TVs. The attacker generates a code, delivers it to the victim via a phishing page, and the victim enters the code on the real identity provider's device login page. Push has tracked a ",[],{},{"nodeType":537,"data":1100,"content":1102},{"uri":1101},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fdevice-code-phishing",[1103],{"nodeType":445,"value":1104,"marks":1105,"data":1106},"37.5x increase in device code phishing attacks",[],{},{"nodeType":445,"value":1108,"marks":1109,"data":1110}," in 2026, with ",[],{},{"nodeType":445,"value":1112,"marks":1113,"data":1115},"30+ distinct kits",[1114],{"type":453},{},{"nodeType":445,"value":1117,"marks":1118,"data":1119}," now offering the technique. Because device code phishing targets apps already consented in the user's tenant (usually first-party Microsoft apps), it sidesteps the consent restrictions that shut down traditional consent phishing.",[],{},{"nodeType":441,"data":1121,"content":1122},{},[1123,1128,1132,1140,1144,1152],{"nodeType":445,"value":1124,"marks":1125,"data":1127},"ConsentFix",[1126],{"type":453},{},{"nodeType":445,"value":1129,"marks":1130,"data":1131}," occupies a middle ground — a ClickFix-OAuth hybrid that targets the standard authorization code grant flow rather than the device code flow. ",[],{},{"nodeType":537,"data":1133,"content":1135},{"uri":1134},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fconsentfix\u002F",[1136],{"nodeType":445,"value":1137,"marks":1138,"data":1139},"First observed in Russian APT29 campaigns",[],{},{"nodeType":445,"value":1141,"marks":1142,"data":1143},", it has since been ",[],{},{"nodeType":537,"data":1145,"content":1147},{"uri":1146},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fconsentfix-v3-analyzing-a-new-toolkit\u002F",[1148],{"nodeType":445,"value":1149,"marks":1150,"data":1151},"commoditized into criminal tooling",[],{},{"nodeType":445,"value":1153,"marks":1154,"data":1155},".",[],{},{"nodeType":441,"data":1157,"content":1158},{},[1159],{"nodeType":445,"value":1160,"marks":1161,"data":1162},"Preventing malicious OAuth grants requires tight in-app management of user permissions and tenant security settings across every app in the estate. Conditional access policies help, but their effectiveness varies significantly by technique — \"require compliant device\" blocks device code phishing but not ConsentFix, while \"block device code flow\" breaks legitimate use cases like Azure CLI and conference room hardware. Browser-based security tools are well positioned to observe OAuth grants across all apps accessed in the browser — even the ones the security team doesn't manage or know about.",[],{},{"nodeType":787,"data":1164,"content":1168},{"target":1165},{"sys":1166},{"id":1167,"type":792,"linkType":793},"1Fxgll8d4vVwtkGdwIAgkm",[],{"nodeType":467,"data":1170,"content":1171},{},[],{"nodeType":515,"data":1173,"content":1174},{},[1175],{"nodeType":445,"value":1176,"marks":1177,"data":1179},"4. Malicious browser extensions",[1178],{"type":453},{},{"nodeType":441,"data":1181,"content":1182},{},[1183],{"nodeType":445,"value":1184,"marks":1185,"data":1186},"Attackers use malicious extensions to steal data, log keystrokes, and intercept credentials and tokens as they transit the browser. ",[],{},{"nodeType":787,"data":1188,"content":1192},{"target":1189},{"sys":1190},{"id":1191,"type":792,"linkType":793},"5fuigCAUuHxP49KjWgP8SO",[],{"nodeType":441,"data":1194,"content":1195},{},[1196,1200,1208],{"nodeType":445,"value":1197,"marks":1198,"data":1199},"Most malicious extensions didn't start that way — attackers begin with a legitimate extension and bide their time, waiting until install counts reach maximum impact before deploying a malicious update. It's ",[],{},{"nodeType":537,"data":1201,"content":1203},{"uri":1202},"https:\u002F\u002Fsecureannex.com\u002Fblog\u002Fbuying-browser-extensions\u002F",[1204],{"nodeType":445,"value":1205,"marks":1206,"data":1207},"very easy for attackers to buy and add malicious updates",[],{},{"nodeType":445,"value":1209,"marks":1210,"data":1211}," to existing extensions, easily passing extension web store security checks.",[],{},{"nodeType":441,"data":1213,"content":1214},{},[1215],{"nodeType":445,"value":1216,"marks":1217,"data":1218},"There are four common entry paths: phish the developer of a popular extension; offer to buy a widely-installed extension outright; vibe-code your own extension and market it to users; or upload a malicious version and let user browsers auto-update on next launch.",[],{},{"nodeType":441,"data":1220,"content":1221},{},[1222,1226,1231,1235,1243],{"nodeType":445,"value":1223,"marks":1224,"data":1225},"Permissions alone don't indicate risk, since nearly every extension has exploitable ones — ",[],{},{"nodeType":445,"value":1227,"marks":1228,"data":1230},"46.76% of extensions across Push customers have the permission combinations needed for account takeover with no user interaction",[1229],{"type":453},{},{"nodeType":445,"value":1232,"marks":1233,"data":1234},". The most dangerous let attackers intercept sensitive data, credentials, and session tokens in transit. Malicious extensions routinely evade static and sandbox analysis via dynamically compiled, smuggled code, letting them reach official stores and even earn \"Featured\" or \"Verified\" status. AI browser extensions add a further dimension: the ",[],{},{"nodeType":537,"data":1236,"content":1238},{"uri":1237},"https:\u002F\u002Fwww.verizon.com\u002Fbusiness\u002Fresources\u002Freports\u002Fdbir\u002F",[1239],{"nodeType":445,"value":1240,"marks":1241,"data":1242},"Verizon DBIR 2026",[],{},{"nodeType":445,"value":1244,"marks":1245,"data":1246}," found that more than 15% of corporate users had unauthorized AI browser extensions installed — extensions that collect and retain browsing context from internal sites, creating a data exfiltration pathway that operates independently of traditional DLP controls.",[],{},{"nodeType":441,"data":1248,"content":1249},{},[1250,1254,1262,1266,1274],{"nodeType":445,"value":1251,"marks":1252,"data":1253},"Generally, your employees should not be randomly installing browser extensions unless pre-approved by your security team. But the reality is that many organizations have very little visibility of the extensions their employees are using, and the potential risk they're exposed to as a result. Static risk scoring is a ",[],{},{"nodeType":537,"data":1255,"content":1257},{"uri":1256},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fwhy-browser-extension-risk-scoring-wont-predict-your-next-breach\u002F",[1258],{"nodeType":445,"value":1259,"marks":1260,"data":1261},"poor predictor of supply chain compromise",[],{},{"nodeType":445,"value":1263,"marks":1264,"data":1265}," — every major breach of the past 18 months involved extensions that scored as low-risk beforehand. A default-deny approach with ",[],{},{"nodeType":537,"data":1267,"content":1269},{"uri":1268},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fbrowser-extension-management-guide\u002F",[1270],{"nodeType":445,"value":1271,"marks":1272,"data":1273},"allowlisting plus monitoring for change events",[],{},{"nodeType":445,"value":1275,"marks":1276,"data":1277}," is more effective than risk-score-based removal.",[],{},{"nodeType":787,"data":1279,"content":1283},{"target":1280},{"sys":1281},{"id":1282,"type":792,"linkType":793},"6WRUfE4LepAQ35hRz2UlH1",[],{"nodeType":467,"data":1285,"content":1286},{},[],{"nodeType":515,"data":1288,"content":1289},{},[1290],{"nodeType":445,"value":1291,"marks":1292,"data":1294},"5. Credential stuffing and ghost logins",[1293],{"type":453},{},{"nodeType":441,"data":1296,"content":1297},{},[1298],{"nodeType":445,"value":1299,"marks":1300,"data":1301},"Password-based compromise remains one of the leading causes of breaches. This might surprise you if you think that SSO solved credential attacks. ",[],{},{"nodeType":787,"data":1303,"content":1307},{"target":1304},{"sys":1305},{"id":1306,"type":792,"linkType":793},"5RJyr7JbVhUnccMIMsGtnE",[],{"nodeType":441,"data":1309,"content":1310},{},[1311,1315,1323],{"nodeType":445,"value":1312,"marks":1313,"data":1314},"But SSO isn't universal — SAML often costs extra, requires admin setup, and self-adopted apps rarely get configured, while most apps allow simultaneous login methods and don't restrict login methods. The result is ",[],{},{"nodeType":537,"data":1316,"content":1318},{"uri":1317},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fhow-many-vulnerable-identities-do-you-have\u002F",[1319],{"nodeType":445,"value":1320,"marks":1321,"data":1322},"ghost logins",[],{},{"nodeType":445,"value":1324,"marks":1325,"data":1326},": backup credentials outside SSO, invisible to IdP logs, created at adoption and still active unless disabled — gaps that stay hidden since most orgs focus MFA at the IdP layer, not on local app config, until an attacker finds them.",[],{},{"nodeType":441,"data":1328,"content":1329},{},[1330],{"nodeType":445,"value":1331,"marks":1332,"data":1333},"The data supports this. Of the last million logins observed by Push:",[],{},{"nodeType":1335,"data":1336,"content":1337},"unordered-list",{},[1338,1354,1369],{"nodeType":1339,"data":1340,"content":1341},"list-item",{},[1342],{"nodeType":441,"data":1343,"content":1344},{},[1345,1350],{"nodeType":445,"value":1346,"marks":1347,"data":1349},"1 in 4",[1348],{"type":453},{},{"nodeType":445,"value":1351,"marks":1352,"data":1353}," were password logins, not SSO",[],{},{"nodeType":1339,"data":1355,"content":1356},{},[1357],{"nodeType":441,"data":1358,"content":1359},{},[1360,1365],{"nodeType":445,"value":1361,"marks":1362,"data":1364},"2 in 5",[1363],{"type":453},{},{"nodeType":445,"value":1366,"marks":1367,"data":1368}," were not protected by MFA",[],{},{"nodeType":1339,"data":1370,"content":1371},{},[1372],{"nodeType":441,"data":1373,"content":1374},{},[1375,1380],{"nodeType":445,"value":1376,"marks":1377,"data":1379},"1 in 5",[1378],{"type":453},{},{"nodeType":445,"value":1381,"marks":1382,"data":1383}," used a weak, breached, or reused password",[],{},{"nodeType":441,"data":1385,"content":1386},{},[1387,1391,1399,1403,1408,1412,1418],{"nodeType":445,"value":1388,"marks":1389,"data":1390},"And the external sources also paint this picture. ",[],{},{"nodeType":537,"data":1392,"content":1394},{"uri":1393},"https:\u002F\u002Fcf-assets.www.cloudflare.com\u002Fslt3lc6tev37\u002FsWDBUMNVtEJB9ZFLt1dUU\u002F8d69e92de2edfb3bf59e7d21d57e7e1a\u002FCloudflare-2026-threat-report.pdf",[1395],{"nodeType":445,"value":1396,"marks":1397,"data":1398},"Cloudflare's 2026 Threat Report",[],{},{"nodeType":445,"value":1400,"marks":1401,"data":1402}," found that ",[],{},{"nodeType":445,"value":1404,"marks":1405,"data":1407},"63% of all human logins involve credentials already compromised elsewhere",[1406],{"type":453},{},{"nodeType":445,"value":1409,"marks":1410,"data":1411},". And the ",[],{},{"nodeType":537,"data":1413,"content":1414},{"uri":1237},[1415],{"nodeType":445,"value":1240,"marks":1416,"data":1417},[],{},{"nodeType":445,"value":1419,"marks":1420,"data":1421}," found that 50% of ransomware victims had a credential or infostealer event within 95 days prior to the attack, with infostealers surfacing an average of 2,362 breached corporate credentials per month from organizational email domains.",[],{},{"nodeType":441,"data":1423,"content":1424},{},[1425],{"nodeType":445,"value":1426,"marks":1427,"data":1428},"Logins can be observed in the browser — in fact, it's as close to a universal source of truth as you're going to get about how your employees are actually logging in, which apps they're using, and whether MFA is present, enabling security teams to find and fix vulnerable logins before they can be exploited.",[],{},{"nodeType":787,"data":1430,"content":1434},{"target":1431},{"sys":1432},{"id":1433,"type":792,"linkType":793},"1tX9gSZ51VEmXjRliTXuPV",[],{"nodeType":467,"data":1436,"content":1437},{},[],{"nodeType":515,"data":1439,"content":1440},{},[1441],{"nodeType":445,"value":1442,"marks":1443,"data":1445},"6. Session hijacking",[1444],{"type":453},{},{"nodeType":441,"data":1447,"content":1448},{},[1449],{"nodeType":445,"value":1450,"marks":1451,"data":1452},"Session hijacking (aka token replay) allows attackers to bypass the authentication process by taking an already-approved session token that they've stolen from the victim's device or browser, and reusing it in their own browser. This enables them to get around even phishing-resistant authentication controls like passkeys.",[],{},{"nodeType":441,"data":1454,"content":1455},{},[1456],{"nodeType":445,"value":1457,"marks":1458,"data":1459},"This is different to AiTM attacks, which see a new session created via the attacker's reverse-proxy connection to the target app. Sessions can be stolen using a variety of methods, some of which we've already discussed. Malicious browser extensions can extract them from webpages visited by the user, for example. But the most prominent source of stolen tokens is infostealer malware — also the leading source of stolen credentials powering credential stuffing attacks.",[],{},{"nodeType":441,"data":1461,"content":1462},{},[1463,1467,1474,1477,1482],{"nodeType":445,"value":1464,"marks":1465,"data":1466},"As mentioned previously, ClickFix is now the go-to method for delivering malware like infostealers. ClickFix is more detection-resistant than a normal file download, which is more likely to be intercepted and analyzed by controls like a web sandbox before hitting the endpoint and more likely to trigger endpoint alarms during execution. The problem extends beyond managed corporate machines, too: the ",[],{},{"nodeType":537,"data":1468,"content":1469},{"uri":1237},[1470],{"nodeType":445,"value":1471,"marks":1472,"data":1473},"Verizon DBIR 2025",[],{},{"nodeType":445,"value":1400,"marks":1475,"data":1476},[],{},{"nodeType":445,"value":1478,"marks":1479,"data":1481},"46% of infostealer infections that lead to corporate breaches originate on non-managed devices",[1480],{"type":453},{},{"nodeType":445,"value":1483,"marks":1484,"data":1485}," — personal machines, developer workstations, and contractor laptops where EDR is absent.",[],{},{"nodeType":441,"data":1487,"content":1488},{},[1489,1493,1501],{"nodeType":445,"value":1490,"marks":1491,"data":1492},"There's also a less obvious path for session theft. ",[],{},{"nodeType":537,"data":1494,"content":1496},{"uri":1495},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fbrowser-sync-attacks-where-personal-account-hacks-lead-to-corporate-breaches\u002F",[1497],{"nodeType":445,"value":1498,"marks":1499,"data":1500},"Browser sync features",[],{},{"nodeType":445,"value":1502,"marks":1503,"data":1504}," create a bridge between personal and corporate credential stores, meaning personal account or device compromises can directly lead to corporate breaches — as demonstrated in the Okta incident below, where corporate credentials had been synced to an engineer's personal Google account via Chrome profile sync.",[],{},{"nodeType":787,"data":1506,"content":1510},{"target":1507},{"sys":1508},{"id":1509,"type":792,"linkType":793},"51WVinSAV5wN7mVny7v9QC",[],{"nodeType":467,"data":1512,"content":1513},{},[],{"nodeType":471,"data":1515,"content":1516},{},[1517],{"nodeType":445,"value":1518,"marks":1519,"data":1521},"Conclusion",[1520],{"type":453},{},{"nodeType":441,"data":1523,"content":1524},{},[1525,1529,1536],{"nodeType":445,"value":1526,"marks":1527,"data":1528},"Attacks are increasingly happening in the browser. That makes it the perfect place to detect and respond to these attacks. But right now, the browser is a blind-spot for most security teams — ",[],{},{"nodeType":537,"data":1530,"content":1531},{"uri":539},[1532],{"nodeType":445,"value":1533,"marks":1534,"data":1535},"according to Omdia",[],{},{"nodeType":445,"value":1537,"marks":1538,"data":1539},", 49% of organizations suffered a successful browser-based attack in the last 12 months, and browser security is now a top-five priority for 88% of organizations. ",[],{},{"nodeType":441,"data":1541,"content":1542},{},[1543],{"nodeType":445,"value":655,"marks":1544,"data":1545},[],{},{"nodeType":441,"data":1547,"content":1548},{},[1549],{"nodeType":445,"value":662,"marks":1550,"data":1551},[],{},{"nodeType":441,"data":1553,"content":1554},{},[1555,1559,1567],{"nodeType":445,"value":1556,"marks":1557,"data":1558},"If you want to learn more about how Push helps you to detect and stop attacks in the browser, ",[],{},{"nodeType":537,"data":1560,"content":1561},{"uri":673},[1562],{"nodeType":445,"value":1563,"marks":1564,"data":1566},"book some time with one of our team for a live demo",[1565],{"type":545},{},{"nodeType":445,"value":1153,"marks":1568,"data":1569},[],{},"6 browser-based attacks every security team should be prepared for","What security teams need to know about the browser-based attack techniques that are the leading cause of breaches.","2026-09-15T00:00:00.000Z","6-browser-based-attacks-every-security-team-should-be-prepared-for",{"items":1575},[1576,1580],{"sys":1577,"name":1579},{"id":1578},"6A5RXS31ZQx3PwryGb1IMy","Browser-based attacks",{"sys":1581,"name":1583},{"id":1582},"4ksQNCFeBf8H4QIORqpRLw","Detection & response",{"items":1585},[1586],{"fullName":1587,"firstName":1588,"jobTitle":1589,"profilePicture":1590},"Dan Green","Dan","Threat Research",{"url":1591},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F7jik1VhFgA3kgzXBXTm2Vw\u002Ffcd8c171da644903d0827eafcfbcaad0\u002FDan_Headshot_2025.png",{"__typename":698,"sys":1593,"content":1595,"title":2068,"synopsis":2069,"hashTags":60,"publishedDate":2070,"slug":2071,"tagsCollection":2072,"authorsCollection":2080},{"id":1594},"ThcZepauVfA5fKossdkbm",{"json":1596},{"data":1597,"content":1598,"nodeType":437},{},[1599,1606,1613,1643,1650,1658,1664,1667,1675,1718,1738,1744,1747,1755,1762,1781,1784,1792,1799,1806,1809,1817,1824,1831,1834,1842,1849,1867,1870,1878,1885,1892,1895,1903,1910,1917,1920,1928,1947,1950,1958,1965,1972,1978,1981,1989,1996,2003,2006,2014,2020,2038,2044,2050],{"data":1600,"content":1601,"nodeType":441},{},[1602],{"data":1603,"marks":1604,"value":1605,"nodeType":445},{},[],"Ask a security team where most of their tools are and it's the endpoint, network, or cloud. But ask where their users spend most of their time and it's the browser.",{"data":1607,"content":1608,"nodeType":441},{},[1609],{"data":1610,"marks":1611,"value":1612,"nodeType":445},{},[],"So we got a category: browser security. And when it comes to the best browser security tools, there's a problem. Browser security means three different things depending on who's talking: enterprise browser extensions, enterprise browsers, and remote browser isolation (RBI).",{"data":1614,"content":1615,"nodeType":441},{},[1616,1620,1627,1631,1639],{"data":1617,"marks":1618,"value":1619,"nodeType":445},{},[],"The market reflects that confusion, but the momentum is real. According to ",{"data":1621,"content":1622,"nodeType":537},{"uri":539},[1623],{"data":1624,"marks":1625,"value":1626,"nodeType":445},{},[],"Omdia's 2026 research",{"data":1628,"marks":1629,"value":1630,"nodeType":445},{},[],", browser security is already a top-five priority for 88% of organizations and the top priority for 26%, with 86% having meaningfully increased their browser security spending in response to emerging threats. ",{"data":1632,"content":1634,"nodeType":537},{"uri":1633},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fthe-case-for-best-of-breed-browser-security",[1635],{"data":1636,"marks":1637,"value":1638,"nodeType":445},{},[],"Three browser security startups were acquired",{"data":1640,"marks":1641,"value":1642,"nodeType":445},{},[]," by major platform vendors in 2026 alone — CrowdStrike bought Seraphic, Zscaler absorbed SquareX, and Akamai announced intent to acquire LayerX.",{"data":1644,"content":1645,"nodeType":441},{},[1646],{"data":1647,"marks":1648,"value":1649,"nodeType":445},{},[],"Here's what the browser security market looks like in 2026.",{"data":1651,"content":1652,"nodeType":441},{},[1653],{"data":1654,"marks":1655,"value":1657,"nodeType":445},{},[1656],{"type":453},"The top enterprise browser solutions in 2026 include Push Security, Island, and LayerX.",{"data":1659,"content":1663,"nodeType":787},{"target":1660},{"sys":1661},{"id":1662,"type":792,"linkType":793},"5d35fpWpgIytQhhiABQray",[],{"data":1665,"content":1666,"nodeType":467},{},[],{"data":1668,"content":1669,"nodeType":471},{},[1670],{"data":1671,"marks":1672,"value":1674,"nodeType":445},{},[1673],{"type":453},"1. Push Security – Enterprise browser extension",{"data":1676,"content":1677,"nodeType":441},{},[1678,1682,1690,1694,1702,1706,1714],{"data":1679,"marks":1680,"value":1681,"nodeType":445},{},[],"Push is a browser extension, not a browser, that turns whatever browser your people already use into a detection and response platform for the security team. With no migration, no user disruption, no new browser to manage. It covers ",{"data":1683,"content":1685,"nodeType":537},{"uri":1684},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fthe-top-10-security-problems-you-can-solve-in-the-browser-ranked-by-value",[1686],{"data":1687,"marks":1688,"value":1689,"nodeType":445},{},[],"four use cases from a single deployment",{"data":1691,"marks":1692,"value":1693,"nodeType":445},{},[],": detecting and stopping sophisticated browser-based attacks, AI visibility and control, identity and shadow IT security, and DLP and insider investigations. Detections are built on ",{"data":1695,"content":1697,"nodeType":537},{"uri":1696},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fhow-to-avoid-the-browser-security-buyers-trap",[1698],{"data":1699,"marks":1700,"value":1701,"nodeType":445},{},[],"in-house threat research",{"data":1703,"marks":1704,"value":1705,"nodeType":445},{},[]," and operationalized by autonomous agents, so what Push catches is based on attacker techniques and behaviors rather than a blocklist. It ",{"data":1707,"content":1709,"nodeType":537},{"uri":1708},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fmaking-the-business-case-for-a-browser-security-solution",[1710],{"data":1711,"marks":1712,"value":1713,"nodeType":445},{},[],"deploys in minutes",{"data":1715,"marks":1716,"value":1717,"nodeType":445},{},[]," across managed and unmanaged devices.",{"data":1719,"content":1720,"nodeType":441},{},[1721,1725,1734],{"data":1722,"marks":1723,"value":1724,"nodeType":445},{},[],"Push detects AiTM and device code phishing kits (",{"data":1726,"content":1728,"nodeType":537},{"uri":1727},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fagentic-threat-hunting-benefits-for-customers",[1729],{"data":1730,"marks":1731,"value":1733,"nodeType":445},{},[1732],{"type":545},"75+ across Tycoon 2FA, Sneaky 2FA, Evilginx, and many others",{"data":1735,"marks":1736,"value":1737,"nodeType":445},{},[],") behaviorally by analyzing page structure and script execution — so detection survives infrastructure rotation. It catches ClickFix-style clipboard injection before the payload executes, detects stolen session tokens via marker injection when they appear in uninstrumented browsers, and monitors OAuth consent flows across 20+ authorization servers. Push is deployed across 3 million browsers worldwide and has been rolled out to 100,000 users in under one hour during normal office hours.",{"data":1739,"content":1743,"nodeType":787},{"target":1740},{"sys":1741},{"id":1742,"type":792,"linkType":793},"ZmRwtfBPVptxTOE6wt1Yq",[],{"data":1745,"content":1746,"nodeType":467},{},[],{"data":1748,"content":1749,"nodeType":471},{},[1750],{"data":1751,"marks":1752,"value":1754,"nodeType":445},{},[1753],{"type":453},"2. Island – Enterprise browser",{"data":1756,"content":1757,"nodeType":441},{},[1758],{"data":1759,"marks":1760,"value":1761,"nodeType":445},{},[],"Island was one of the first to market in the enterprise browser category and still defines it. It replaces current browsers with a managed Chromium fork that gives IT granular control over copy-paste, screenshots, downloads, session recording, and application access — all enforced at the browser level without routing traffic through a proxy. For highly regulated environments where that degree of governance is a requirement, it's a capable platform with real enterprise traction.",{"data":1763,"content":1764,"nodeType":441},{},[1765,1769,1778],{"data":1766,"marks":1767,"value":1768,"nodeType":445},{},[],"It's a full browser replacement, with primary use cases around VDI replacement, contractor access, BYOD governance, and zero-trust network access. Most organizations plan for a ",{"data":1770,"content":1772,"nodeType":537},{"uri":1771},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fenterprise-browser-vs-browser-extension-which-should-your-security-team-choose",[1773],{"data":1774,"marks":1775,"value":1777,"nodeType":445},{},[1776],{"type":545},"phased rollout",{"data":1779,"marks":1780,"value":1153,"nodeType":445},{},[],{"data":1782,"content":1783,"nodeType":467},{},[],{"data":1785,"content":1786,"nodeType":471},{},[1787],{"data":1788,"marks":1789,"value":1791,"nodeType":445},{},[1790],{"type":453},"3. Prisma Browser – Enterprise browser",{"data":1793,"content":1794,"nodeType":441},{},[1795],{"data":1796,"marks":1797,"value":1798,"nodeType":445},{},[],"Formerly Talon, now Palo Alto Networks' enterprise browser and the last-mile enforcement layer of its SASE platform. Prisma Browser is a managed Chromium browser with DLP that inspects the rendered page and zero-trust access controls, designed primarily for contractor, BYOD, and remote worker populations accessing corporate apps from unmanaged devices.",{"data":1800,"content":1801,"nodeType":441},{},[1802],{"data":1803,"marks":1804,"value":1805,"nodeType":445},{},[],"Like Island, it's a browser replacement. It integrates natively with the broader Prisma Access and Cortex stack, feeding browser telemetry into Palo Alto Networks' existing correlation and response workflows.",{"data":1807,"content":1808,"nodeType":467},{},[],{"data":1810,"content":1811,"nodeType":471},{},[1812],{"data":1813,"marks":1814,"value":1816,"nodeType":445},{},[1815],{"type":453},"4. Seraphic Security (CrowdStrike) – Enterprise browser extension",{"data":1818,"content":1819,"nodeType":441},{},[1820],{"data":1821,"marks":1822,"value":1823,"nodeType":445},{},[],"Seraphic works across any browser through an endpoint agent that adds enterprise security without replacing what's deployed. CrowdStrike acquired Seraphic in early 2026 to extend Falcon past the endpoint and into the browser layer, with the stated goal of correlating endpoint and browser telemetry in a single platform.",{"data":1825,"content":1826,"nodeType":441},{},[1827],{"data":1828,"marks":1829,"value":1830,"nodeType":445},{},[],"For existing CrowdStrike customers, the extension into the browser is a natural addition to the Falcon ecosystem. Cross-browser coverage remains a differentiator for mixed environments.",{"data":1832,"content":1833,"nodeType":467},{},[],{"data":1835,"content":1836,"nodeType":471},{},[1837],{"data":1838,"marks":1839,"value":1841,"nodeType":445},{},[1840],{"type":453},"5. LayerX Security (Akamai) – Enterprise browser extension",{"data":1843,"content":1844,"nodeType":441},{},[1845],{"data":1846,"marks":1847,"value":1848,"nodeType":445},{},[],"LayerX is extension-based, focused on real-time DLP and AI governance which captures what happens inside AI tools, flagging sensitive data submissions, and enforcing policy, all without requiring a new browser. Low deployment friction and a growing AI visibility capability are the draw.",{"data":1850,"content":1851,"nodeType":441},{},[1852,1856,1863],{"data":1853,"marks":1854,"value":1855,"nodeType":445},{},[],"Akamai announced the intent to acquire LayerX in mid-2026 to complement its Zero Trust portfolio. For buyers evaluating LayerX as a long-term platform bet, the ",{"data":1857,"content":1858,"nodeType":537},{"uri":1633},[1859],{"data":1860,"marks":1861,"value":1862,"nodeType":445},{},[],"question is what the roadmap looks like 18 months post-close",{"data":1864,"marks":1865,"value":1866,"nodeType":445},{},[],", given Akamai's track record of absorbing acquisitions (Guardicore, Neosec, Inverse) into its broader platform.",{"data":1868,"content":1869,"nodeType":467},{},[],{"data":1871,"content":1872,"nodeType":471},{},[1873],{"data":1874,"marks":1875,"value":1877,"nodeType":445},{},[1876],{"type":453},"6. SquareX (Zscaler) – Enterprise browser extension",{"data":1879,"content":1880,"nodeType":441},{},[1881],{"data":1882,"marks":1883,"value":1884,"nodeType":445},{},[],"SquareX takes a detection-minded posture, inspecting files and links while browsing, neutralizing malicious content before it reaches the endpoint, and offering disposable browser environments for high-risk activity. It was clearly built by people who think in attacker terms.",{"data":1886,"content":1887,"nodeType":441},{},[1888],{"data":1889,"marks":1890,"value":1891,"nodeType":445},{},[],"Zscaler acquired SquareX in early 2026, integrating it into the Zero Trust Exchange alongside its existing SSE capabilities.",{"data":1893,"content":1894,"nodeType":467},{},[],{"data":1896,"content":1897,"nodeType":471},{},[1898],{"data":1899,"marks":1900,"value":1902,"nodeType":445},{},[1901],{"type":453},"7. Keep Aware – Enterprise browser extension",{"data":1904,"content":1905,"nodeType":441},{},[1906],{"data":1907,"marks":1908,"value":1909,"nodeType":445},{},[],"Keep Aware is an agentless extension built with security operations in mind. It's quick to deploy through MDM or group policy, and focused on surfacing browser threats, extension risk, and AI usage into existing SOC workflows. Detection and response is the throughline, with SIEM integration as a core part of the offering.",{"data":1911,"content":1912,"nodeType":441},{},[1913],{"data":1914,"marks":1915,"value":1916,"nodeType":445},{},[],"Founded in 2022, Keep Aware has been iterating quickly with a focused product roadmap around browser detection and response.",{"data":1918,"content":1919,"nodeType":467},{},[],{"data":1921,"content":1922,"nodeType":471},{},[1923],{"data":1924,"marks":1925,"value":1927,"nodeType":445},{},[1926],{"type":453},"8. Menlo Security – Remote browser isolation",{"data":1929,"content":1930,"nodeType":441},{},[1931,1935,1943],{"data":1932,"marks":1933,"value":1934,"nodeType":445},{},[],"Menlo pioneered ",{"data":1936,"content":1938,"nodeType":537},{"uri":1937},"https:\u002F\u002Fpushsecurity.com\u002Fsolution\u002Ftool-replacements\u002Fremote-browser-isolation",[1939],{"data":1940,"marks":1941,"value":1942,"nodeType":445},{},[],"remote browser isolation",{"data":1944,"marks":1945,"value":1946,"nodeType":445},{},[],": web content renders in a disposable cloud container and the user receives a clean visual stream, so nothing malicious ever touches the endpoint. For zero-tolerance environments and third-party or contractor access where you don't fully trust the device, the approach has a solid track record. Cloud rendering introduces latency and the occasional site-compatibility issue, though Menlo has invested in reducing both over the years.",{"data":1948,"content":1949,"nodeType":467},{},[],{"data":1951,"content":1952,"nodeType":471},{},[1953],{"data":1954,"marks":1955,"value":1957,"nodeType":445},{},[1956],{"type":453},"9. Chrome Enterprise \u002F Edge for Business – Enterprise browser",{"data":1959,"content":1960,"nodeType":441},{},[1961],{"data":1962,"marks":1963,"value":1964,"nodeType":445},{},[],"The security controls are already built into the browsers most of your people use. Chrome Enterprise offers centralized management, Safe Browsing, and identity tool integration across the fleet; Edge for Business adds work-and-personal separation, phishing protection, and tight integration with Microsoft 365 and Defender.",{"data":1966,"content":1967,"nodeType":441},{},[1968],{"data":1969,"marks":1970,"value":1971,"nodeType":445},{},[],"These are baseline controls, and for many organizations they're effectively free with what's already deployed. Most organizations treat them as the foundation that the rest of the tools on this list build on.",{"data":1973,"content":1977,"nodeType":787},{"target":1974},{"sys":1975},{"id":1976,"type":792,"linkType":793},"7Gbd8bBWa19gP5DMfeeB7J",[],{"data":1979,"content":1980,"nodeType":467},{},[],{"data":1982,"content":1983,"nodeType":471},{},[1984],{"data":1985,"marks":1986,"value":1988,"nodeType":445},{},[1987],{"type":453},"10. SURF Security – Enterprise browser",{"data":1990,"content":1991,"nodeType":441},{},[1992],{"data":1993,"marks":1994,"value":1995,"nodeType":445},{},[],"SURF is a Chromium-based enterprise browser built zero-trust-first, with identity-based access controls, DLP, and session security inside a fully managed environment. Centralized, policy-driven control by default is the pitch, aimed at security-first organizations that want a locked-down browser from day one.",{"data":1997,"content":1998,"nodeType":441},{},[1999],{"data":2000,"marks":2001,"value":2002,"nodeType":445},{},[],"Like Island and Prisma, it's a browser replacement, so it follows the same deployment model — plan for a migration alongside the capabilities.",{"data":2004,"content":2005,"nodeType":467},{},[],{"data":2007,"content":2008,"nodeType":471},{},[2009],{"data":2010,"marks":2011,"value":2013,"nodeType":445},{},[2012],{"type":453},"Learn more about Push Security",{"data":2015,"content":2016,"nodeType":441},{},[2017],{"data":2018,"marks":2019,"value":655,"nodeType":445},{},[],{"data":2021,"content":2022,"nodeType":441},{},[2023,2027,2034],{"data":2024,"marks":2025,"value":2026,"nodeType":445},{},[],"Push is the best choice for organizations looking to ",{"data":2028,"content":2029,"nodeType":537},{"uri":1684},[2030],{"data":2031,"marks":2032,"value":2033,"nodeType":445},{},[],"solve the most impactful security problems in the browse",{"data":2035,"marks":2036,"value":2037,"nodeType":445},{},[],"r, with use cases including detecting and stopping advanced attacks, data loss and insider investigations, identity and shadow IT security, and AI visibility and control. ",{"data":2039,"content":2043,"nodeType":787},{"target":2040},{"sys":2041},{"id":2042,"type":792,"linkType":793},"4nGzT9cNG0Yid93uUCCuTt",[],{"data":2045,"content":2046,"nodeType":441},{},[2047],{"data":2048,"marks":2049,"value":662,"nodeType":445},{},[],{"data":2051,"content":2052,"nodeType":441},{},[2053,2057,2064],{"data":2054,"marks":2055,"value":2056,"nodeType":445},{},[],"Book a ",{"data":2058,"content":2059,"nodeType":537},{"uri":673},[2060],{"data":2061,"marks":2062,"value":2063,"nodeType":445},{},[],"live demo",{"data":2065,"marks":2066,"value":2067,"nodeType":445},{},[]," to learn more.","The top 10 browser security solutions: Push Security, Island, LayerX and more","Browser security means a lot of different things depending on who's talking. Here's your guide to the browser security market from a vendor perspective in 2026.","2026-07-27T00:00:00.000Z","the-top-10-browser-security-solutions-in-2026",{"items":2073},[2074,2078],{"sys":2075,"name":2077},{"id":2076},"3pjES4THCIfSAwhGdNwBcy","Browser security",{"sys":2079,"name":1583},{"id":1582},{"items":2081},[2082],{"fullName":2083,"firstName":2084,"jobTitle":2085,"profilePicture":2086},"Alex Henshall","Alex","Product Team",{"url":2087},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F2rz3Pre3b1MexPIQ4hzPUe\u002F0ef8a092b7e7df00fbce3f7d1ccb96d1\u002FAlex_Henshall.jpeg",{"__typename":698,"sys":2089,"content":2091,"title":3384,"synopsis":3385,"hashTags":60,"publishedDate":3386,"slug":3387,"tagsCollection":3388,"authorsCollection":3394},{"id":2090},"vLb3RhwYt7Xc6mkX3pWyI",{"json":2092},{"data":2093,"content":2094,"nodeType":437},{},[2095,2102,2105,2113,2143,2151,2157,2188,2303,2344,2352,2407,2438,2444,2447,2455,2462,2470,2487,2542,2548,2555,2574,2580,2587,2593,2600,2606,2613,2619,2627,2670,2701,2720,2751,2759,2790,2821,2852,2860,2867,2886,2940,2971,2979,2997,3040,3043,3051,3058,3065,3083,3089,3096,3208,3250,3258,3277,3284,3287,3295,3302,3345,3352,3355,3361,3367],{"data":2096,"content":2097,"nodeType":441},{},[2098],{"data":2099,"marks":2100,"value":2101,"nodeType":445},{},[],"Feeling overwhelmed with the amount of cyber news stories? Tired of dodging AI vendors boasting about their agents escaping the lab? This threat landscape update cuts through the noise and covers the key developments that security teams need to be on top of.",{"data":2103,"content":2104,"nodeType":467},{},[],{"data":2106,"content":2107,"nodeType":471},{},[2108],{"data":2109,"marks":2110,"value":2112,"nodeType":445},{},[2111],{"type":453},"The SLH playbook becomes the industry standard",{"data":2114,"content":2115,"nodeType":441},{},[2116,2120,2128,2132,2139],{"data":2117,"marks":2118,"value":2119,"nodeType":445},{},[],"Criminals associated with \"The Com,\" broadly known as the ",{"data":2121,"content":2123,"nodeType":537},{"uri":2122},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fscattered-lapsus-hunters",[2124],{"data":2125,"marks":2126,"value":2127,"nodeType":445},{},[],"Scattered Lapsus$ Hunters",{"data":2129,"marks":2130,"value":2131,"nodeType":445},{},[]," collective, have spent the past three years establishing a playbook ",{"data":2133,"content":2134,"nodeType":537},{"uri":776},[2135],{"data":2136,"marks":2137,"value":2138,"nodeType":445},{},[],"focused on identity compromise and cloud data theft",{"data":2140,"marks":2141,"value":2142,"nodeType":445},{},[]," for extortion. They've dominated the news when it comes to public breaches: a sign of their effectiveness, or perhaps more their desire for notoriety (something that has come back to bite individuals later with a series of arrests, but hasn't hampered the overall trajectory of the breaches).",{"data":2144,"content":2145,"nodeType":441},{},[2146],{"data":2147,"marks":2148,"value":2150,"nodeType":445},{},[2149],{"type":453},"Regardless, the data doesn't lie. Of the browser and identity-related breaches we've tracked, groups linked to \"The Com\" such as Scattered Spider, ShinyHunters, and Lapsus$ are responsible for roughly 70% (not just in 2026, but since the start of 2024). ",{"data":2152,"content":2156,"nodeType":787},{"target":2153},{"sys":2154},{"id":2155,"type":792,"linkType":793},"3hODobO3VJr3LvbXkzso8I",[],{"data":2158,"content":2159,"nodeType":441},{},[2160,2164,2172,2176,2184],{"data":2161,"marks":2162,"value":2163,"nodeType":445},{},[],"The trump card of prolific criminal groups like Scattered Spider, Lapsus$, and ShinyHunters has always been their social engineering skill. Last year, they had huge success in ",{"data":2165,"content":2167,"nodeType":537},{"uri":2166},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fscattered-spider-defending-against-help-desk-scams",[2168],{"data":2169,"marks":2170,"value":2171,"nodeType":445},{},[],"tricking help desks into performing account resets",{"data":2173,"marks":2174,"value":2175,"nodeType":445},{},[],". This year, they've switched to using voice-based lures in tandem with ",{"data":2177,"content":2179,"nodeType":537},{"uri":2178},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Funpacking-the-latest-slh-campaign",[2180],{"data":2181,"marks":2182,"value":2183,"nodeType":445},{},[],"browser-based phishing payloads",{"data":2185,"marks":2186,"value":2187,"nodeType":445},{},[]," — usually impersonating IT staff under the guise of \"setting up passkeys.\"",{"data":2189,"content":2190,"nodeType":441},{},[2191,2195,2203,2207,2215,2219,2227,2231,2239,2243,2251,2255,2263,2267,2275,2279,2287,2291,2299],{"data":2192,"marks":2193,"value":2194,"nodeType":445},{},[],"The vishing-to-SSO-takeover campaign has been prolific, running continuously since January: ",{"data":2196,"content":2198,"nodeType":537},{"uri":2197},"https:\u002F\u002Fwww.securityweek.com\u002Fpanera-bread-data-breach-linked-to-shinyhunters-sso-campaign\u002F",[2199],{"data":2200,"marks":2201,"value":2202,"nodeType":445},{},[],"Panera Bread",{"data":2204,"marks":2205,"value":2206,"nodeType":445},{},[]," (~14M records), ",{"data":2208,"content":2210,"nodeType":537},{"uri":2209},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fmatch-group-breach-exposes-data-from-hinge-tinder-okcupid-and-match\u002F",[2211],{"data":2212,"marks":2213,"value":2214,"nodeType":445},{},[],"Match Group",{"data":2216,"marks":2217,"value":2218,"nodeType":445},{},[]," (Hinge, Tinder, OkCupid; 10M+ records), ",{"data":2220,"content":2222,"nodeType":537},{"uri":2221},"https:\u002F\u002Fcloud.google.com\u002Fblog\u002Ftopics\u002Fthreat-intelligence\u002Fexpansion-shinyhunters-saas-data-theft",[2223],{"data":2224,"marks":2225,"value":2226,"nodeType":445},{},[],"Betterment",{"data":2228,"marks":2229,"value":2230,"nodeType":445},{},[]," (~20M records), ",{"data":2232,"content":2234,"nodeType":537},{"uri":2233},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fshinyhunters-extortion-gang-claims-odido-breach-affecting-millions\u002F",[2235],{"data":2236,"marks":2237,"value":2238,"nodeType":445},{},[],"Odido",{"data":2240,"marks":2241,"value":2242,"nodeType":445},{},[]," (6.2M Dutch telecom customers with BSNs and IBANs exposed), ",{"data":2244,"content":2246,"nodeType":537},{"uri":2245},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fadt-confirms-data-breach-after-shinyhunters-leak-threat\u002F",[2247],{"data":2248,"marks":2249,"value":2250,"nodeType":445},{},[],"ADT",{"data":2252,"marks":2253,"value":2254,"nodeType":445},{},[]," (5.5M records), ",{"data":2256,"content":2258,"nodeType":537},{"uri":2257},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fcharter-communications-data-breach-affects-49-million-accounts\u002F",[2259],{"data":2260,"marks":2261,"value":2262,"nodeType":445},{},[],"Charter Communications",{"data":2264,"marks":2265,"value":2266,"nodeType":445},{},[]," (4.9M accounts), ",{"data":2268,"content":2270,"nodeType":537},{"uri":2269},"https:\u002F\u002Fwww.theregister.com\u002F2026\u002F04\u002F24\u002Fshinyhunters_claim_cruise_giant_carnivals\u002F",[2271],{"data":2272,"marks":2273,"value":2274,"nodeType":445},{},[],"Carnival Corporation",{"data":2276,"marks":2277,"value":2278,"nodeType":445},{},[]," (6M records), and",{"data":2280,"content":2282,"nodeType":537},{"uri":2281},"https:\u002F\u002Fwww.theregister.com\u002F2026\u002F04\u002F28\u002Fpitney_bowes_is_the_latest\u002F",[2283],{"data":2284,"marks":2285,"value":2286,"nodeType":445},{},[]," Pitney Bowes",{"data":2288,"marks":2289,"value":2290,"nodeType":445},{},[]," (8.2M emails per HIBP). ",{"data":2292,"content":2294,"nodeType":537},{"uri":2293},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fad-tech-firm-optimizely-confirms-data-breach-after-vishing-attack\u002F",[2295],{"data":2296,"marks":2297,"value":2298,"nodeType":445},{},[],"Optimizely",{"data":2300,"marks":2301,"value":2302,"nodeType":445},{},[]," is notable as the first confirmed case where attackers deployed both AiTM credential harvesting and device code phishing against the same target.",{"data":2304,"content":2305,"nodeType":441},{},[2306,2310,2317,2321,2329,2333,2341],{"data":2307,"marks":2308,"value":2309,"nodeType":445},{},[],"Since mid-2025, SaaS apps like Salesforce have been a persistent target for data theft and extortion — as seen in the first large-scale criminal ",{"data":2311,"content":2312,"nodeType":537},{"uri":1101},[2313],{"data":2314,"marks":2315,"value":2316,"nodeType":445},{},[],"device code phishing",{"data":2318,"marks":2319,"value":2320,"nodeType":445},{},[]," campaign that preceded this year's adoption spike. ShinyHunters also led the way with OAuth supply chain abuse — compromising SaaS vendors like ",{"data":2322,"content":2324,"nodeType":537},{"uri":2323},"https:\u002F\u002Fcloud.google.com\u002Fblog\u002Ftopics\u002Fthreat-intelligence\u002Fdata-theft-salesforce-instances-via-salesloft-drift",[2325],{"data":2326,"marks":2327,"value":2328,"nodeType":445},{},[],"Salesloft, Drift, and GainSight",{"data":2330,"marks":2331,"value":2332,"nodeType":445},{},[]," and leveraging stored OAuth tokens to penetrate downstream customer environments, a pattern that has since ",{"data":2334,"content":2336,"nodeType":537},{"uri":2335},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Funpacking-the-vercel-breach",[2337],{"data":2338,"marks":2339,"value":2340,"nodeType":445},{},[],"repeated at scale",{"data":2342,"marks":2343,"value":1153,"nodeType":445},{},[],{"data":2345,"content":2346,"nodeType":515},{},[2347],{"data":2348,"marks":2349,"value":2351,"nodeType":445},{},[2350],{"type":453},"Copycats and nation-state adoption",{"data":2353,"content":2354,"nodeType":441},{},[2355,2359,2367,2371,2379,2383,2391,2395,2403],{"data":2356,"marks":2357,"value":2358,"nodeType":445},{},[],"Wider groups are now running the SLH playbook independently. ",{"data":2360,"content":2362,"nodeType":537},{"uri":2361},"https:\u002F\u002Fhackread.com\u002Fpink-extortion-microsoft-365-cloud-data-vishing-scams\u002F",[2363],{"data":2364,"marks":2365,"value":2366,"nodeType":445},{},[],"Pink",{"data":2368,"marks":2369,"value":2370,"nodeType":445},{},[]," (the latest rebrand in the",{"data":2372,"content":2374,"nodeType":537},{"uri":2373},"https:\u002F\u002Fcloud.google.com\u002Fblog\u002Ftopics\u002Fthreat-intelligence\u002Func6671-targets-financial-services-and-enterprise-cloud-environments",[2375],{"data":2376,"marks":2377,"value":2378,"nodeType":445},{},[]," BlackFile",{"data":2380,"marks":2381,"value":2382,"nodeType":445},{},[],"-Redact succession) runs vishing combined with passkey-themed credential phishing for M365 extortion. ",{"data":2384,"content":2386,"nodeType":537},{"uri":2385},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fnew-helix-vishing-group-emerges-in-sharepoint-data-theft-attacks\u002F",[2387],{"data":2388,"marks":2389,"value":2390,"nodeType":445},{},[],"Helix",{"data":2392,"marks":2393,"value":2394,"nodeType":445},{},[]," also emerged shortly after BlackFile shut down, pairing vishing with device code phishing and MFA registration for persistence. ",{"data":2396,"content":2398,"nodeType":537},{"uri":2397},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fkongtuke-hackers-now-use-microsoft-teams-for-corporate-breaches\u002F",[2399],{"data":2400,"marks":2401,"value":2402,"nodeType":445},{},[],"KongTuke",{"data":2404,"marks":2405,"value":2406,"nodeType":445},{},[],", an independent initial access broker, adopted a similar help-desk impersonation model via Teams external messaging.",{"data":2408,"content":2409,"nodeType":441},{},[2410,2414,2422,2426,2434],{"data":2411,"marks":2412,"value":2413,"nodeType":445},{},[],"It's not just criminal groups either. Recently, we saw a campaign linked to Russian actors that used ",{"data":2415,"content":2417,"nodeType":537},{"uri":2416},"https:\u002F\u002Fwww.microsoft.com\u002Fen-us\u002Fsecurity\u002Fblog\u002F2026\u002F07\u002F31\u002Fcaptivecrunch-midnight-blizzard-targets-travelers-worldwide-for-malware-delivery-and-credential-theft\u002F",[2418],{"data":2419,"marks":2420,"value":2421,"nodeType":445},{},[],"compromised hotel and conference Wi-Fi gateways",{"data":2423,"marks":2424,"value":2425,"nodeType":445},{},[]," to direct victims to AiTM, ClickFix, and device code phishing pages. And ",{"data":2427,"content":2429,"nodeType":537},{"uri":2428},"https:\u002F\u002Fcloud.google.com\u002Fblog\u002Ftopics\u002Fthreat-intelligence\u002Fchinese-language-phishing-services\u002F",[2430],{"data":2431,"marks":2432,"value":2433,"nodeType":445},{},[],"Google Threat Intelligence mapped",{"data":2435,"marks":2436,"value":2437,"nodeType":445},{},[]," a dozen Chinese-language PhaaS platforms with real-time MFA interception.",{"data":2439,"content":2443,"nodeType":787},{"target":2440},{"sys":2441},{"id":2442,"type":792,"linkType":793},"6q2NwH6Q4DJE7RNeYheIvJ",[],{"data":2445,"content":2446,"nodeType":467},{},[],{"data":2448,"content":2449,"nodeType":471},{},[2450],{"data":2451,"marks":2452,"value":2454,"nodeType":445},{},[2453],{"type":453},"Phishing infrastructure has reached an industrial scale",{"data":2456,"content":2457,"nodeType":441},{},[2458],{"data":2459,"marks":2460,"value":2461,"nodeType":445},{},[],"The SLH playbook works because it sits on top of an industrialized infrastructure layer that continues to grow. Phishing-as-a-Service platforms, device code phishing kits, ClickFix Malware-as-a-Service providers, vishing operations, and OAuth supply chain attacks have all matured into commodity services — and they're shipping faster than ever.",{"data":2463,"content":2464,"nodeType":515},{},[2465],{"data":2466,"marks":2467,"value":2469,"nodeType":445},{},[2468],{"type":453},"Device code phishing goes mainstream",{"data":2471,"content":2472,"nodeType":441},{},[2473,2477,2483],{"data":2474,"marks":2475,"value":2476,"nodeType":445},{},[],"We're tracking a huge spike in ",{"data":2478,"content":2479,"nodeType":537},{"uri":1101},[2480],{"data":2481,"marks":2482,"value":2316,"nodeType":445},{},[],{"data":2484,"marks":2485,"value":2486,"nodeType":445},{},[]," since the start of 2026, with 25+ distinct kits now offering the technique. At the beginning of the year, we were tracking one or two.",{"data":2488,"content":2489,"nodeType":441},{},[2490,2494,2502,2506,2514,2518,2526,2530,2538],{"data":2491,"marks":2492,"value":2493,"nodeType":445},{},[],"What began with ",{"data":2495,"content":2497,"nodeType":537},{"uri":2496},"https:\u002F\u002Fwww.microsoft.com\u002Fen-us\u002Fsecurity\u002Fblog\u002F2025\u002F02\u002F13\u002Fstorm-2372-conducts-device-code-phishing-campaign\u002F",[2498],{"data":2499,"marks":2500,"value":2501,"nodeType":445},{},[],"Storm-2372's nation-state campaigns",{"data":2503,"marks":2504,"value":2505,"nodeType":445},{},[]," in August 2024 has proliferated through criminal kits like ",{"data":2507,"content":2509,"nodeType":537},{"uri":2508},"https:\u002F\u002Fthehackernews.com\u002F2026\u002F05\u002Fthe-new-phishing-click-how-oauth-consent.html",[2510],{"data":2511,"marks":2512,"value":2513,"nodeType":445},{},[],"EvilTokens",{"data":2515,"marks":2516,"value":2517,"nodeType":445},{},[]," (340+ organizations in its first five weeks), ",{"data":2519,"content":2521,"nodeType":537},{"uri":2520},"https:\u002F\u002Fwww.huntress.com\u002Fblog\u002Fkali365-device-code-phishing-kit",[2522],{"data":2523,"marks":2524,"value":2525,"nodeType":445},{},[],"Kali365",{"data":2527,"marks":2528,"value":2529,"nodeType":445},{},[]," (which earned an FBI public advisory), ",{"data":2531,"content":2533,"nodeType":537},{"uri":2532},"https:\u002F\u002Fblog.talosintelligence.com\u002Fartoken-inside-an-eviltokens-affiliate-panel-targeting-microsoft-365\u002F",[2534],{"data":2535,"marks":2536,"value":2537,"nodeType":445},{},[],"ARToken",{"data":2539,"marks":2540,"value":2541,"nodeType":445},{},[],", DEBULL, Forg365, and many more.",{"data":2543,"content":2547,"nodeType":787},{"target":2544},{"sys":2545},{"id":2546,"type":792,"linkType":793},"7G6ytXRQPWatOyYarqgMK2",[],{"data":2549,"content":2550,"nodeType":441},{},[2551],{"data":2552,"marks":2553,"value":2554,"nodeType":445},{},[],"The existing PhaaS marketplace, previously dominated by AiTM phishing kits as the standard, has also pivoted to take advantage of the demand for the technique.",{"data":2556,"content":2557,"nodeType":441},{},[2558,2562,2570],{"data":2559,"marks":2560,"value":2561,"nodeType":445},{},[],"Established AiTM vendors like Tycoon 2FA have ",{"data":2563,"content":2565,"nodeType":537},{"uri":2564},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fdevice-code-phishing\u002F",[2566],{"data":2567,"marks":2568,"value":2569,"nodeType":445},{},[],"added device code phishing",{"data":2571,"marks":2572,"value":2573,"nodeType":445},{},[]," alongside their existing credential-harvesting capabilities, meaning the same platforms now offer both techniques interchangeably based on what works against a given target. Several kits like Venom, EvilTokens, Kali365 all reportedly offer both capabilities, while many of the detections we see match the signatures for existing kits in our database (for example, with Venom triggering our existing Sneaky2FA detections) — suggesting an overlap in kit developers or their codebases.",{"data":2575,"content":2579,"nodeType":787},{"target":2576},{"sys":2577},{"id":2578,"type":792,"linkType":793},"3urXbEwK0OSjXQ7lOMDEoc",[],{"data":2581,"content":2582,"nodeType":441},{},[2583],{"data":2584,"marks":2585,"value":2586,"nodeType":445},{},[],"When you look at the full picture, it's notable to see a mixture of AiTM and device code kits in our top detected kits, with most of the top 5 now offering both.",{"data":2588,"content":2592,"nodeType":787},{"target":2589},{"sys":2590},{"id":2591,"type":792,"linkType":793},"4ipTS2U4HE1VLSLmA6DJgB",[],{"data":2594,"content":2595,"nodeType":441},{},[2596],{"data":2597,"marks":2598,"value":2599,"nodeType":445},{},[],"PhaaS vendors are pivoting because device code phishing defeats all MFA (including passkeys) by targeting the authorization layer rather than the login. It's also an unfamiliar phishing scenario that most people aren't really prepared for.",{"data":2601,"content":2605,"nodeType":787},{"target":2602},{"sys":2603},{"id":2604,"type":792,"linkType":793},"3UDzUCCizPJhXp3SsoZuSK",[],{"data":2607,"content":2608,"nodeType":441},{},[2609],{"data":2610,"marks":2611,"value":2612,"nodeType":445},{},[],"And because they're being used interchangeably, there's no downside for the attacker. In one recent example, we saw the attack automatically fall back to AiTM after the device code method timed out, giving the operator two shots at the same victim without manual intervention.",{"data":2614,"content":2618,"nodeType":787},{"target":2615},{"sys":2616},{"id":2617,"type":792,"linkType":793},"3SPsKzwBNxl4d9QRukBtwt",[],{"data":2620,"content":2621,"nodeType":515},{},[2622],{"data":2623,"marks":2624,"value":2626,"nodeType":445},{},[2625],{"type":453},"PhaaS platform evolution and evasion",{"data":2628,"content":2629,"nodeType":441},{},[2630,2634,2642,2646,2654,2658,2666],{"data":2631,"marks":2632,"value":2633,"nodeType":445},{},[],"The broader PhaaS ecosystem continues to expand and evolve. New platform launches this quarter include ",{"data":2635,"content":2637,"nodeType":537},{"uri":2636},"https:\u002F\u002Fwww.cloudsek.com\u002Fblog\u002Fbluekit-phishing-as-a-service-phaas",[2638],{"data":2639,"marks":2640,"value":2641,"nodeType":445},{},[],"Bluekit",{"data":2643,"marks":2644,"value":2645,"nodeType":445},{},[],", ",{"data":2647,"content":2649,"nodeType":537},{"uri":2648},"https:\u002F\u002Fabnormal.ai\u002Fblog\u002Fblacksite-aitm-phishing-kit-cloaked-gg",[2650],{"data":2651,"marks":2652,"value":2653,"nodeType":445},{},[],"Blacksite and Cloaked.gg",{"data":2655,"marks":2656,"value":2657,"nodeType":445},{},[]," — offering dedicated anti-scanner cloaking as a service for phishing infrastructure — and ",{"data":2659,"content":2661,"nodeType":537},{"uri":2660},"https:\u002F\u002Fthreatactix.com\u002F2026\u002F07\u002F02\u002Fa-rare-look-inside-the-command-and-control-panel-behind-modern-phishing-operations\u002F",[2662],{"data":2663,"marks":2664,"value":2665,"nodeType":445},{},[],"WackoGinx",{"data":2667,"marks":2668,"value":2669,"nodeType":445},{},[],", a multi-platform C2 panel that enables operators to manage simultaneous phishing campaigns.",{"data":2671,"content":2672,"nodeType":441},{},[2673,2677,2685,2689,2697],{"data":2674,"marks":2675,"value":2676,"nodeType":445},{},[],"Sneaky 2FA changes have also been documented, with what ",{"data":2678,"content":2680,"nodeType":537},{"uri":2679},"https:\u002F\u002Fzerobec.com\u002Fblog\u002Fsneaky-2fa-returns-trusted-sender-tenant-branded-microsoft-365-replay",[2681],{"data":2682,"marks":2683,"value":2684,"nodeType":445},{},[],"ZeroBEC calls \"route polymorphism\"",{"data":2686,"marks":2687,"value":2688,"nodeType":445},{},[]," (a complicated way of saying the kit randomizes URL paths and filenames on every visit) while separately adopting ",{"data":2690,"content":2692,"nodeType":537},{"uri":2691},"https:\u002F\u002Fblog.barracuda.com\u002F2026\u002F06\u002F29\u002Femail-threat-radar-june-2026",[2693],{"data":2694,"marks":2695,"value":2696,"nodeType":445},{},[],"split-click buttons and blob URLs",{"data":2698,"marks":2699,"value":2700,"nodeType":445},{},[]," designed to evade link analysis (where buttons have two links: automated scanners interact with one and see a legitimate Microsoft page, but humans naturally click the larger, more visually prominent bottom one and get routed via a blob URL to the phishing page). ",{"data":2702,"content":2703,"nodeType":441},{},[2704,2708,2716],{"data":2705,"marks":2706,"value":2707,"nodeType":445},{},[],"The speed of technique adoption across these platforms is itself accelerating. ",{"data":2709,"content":2711,"nodeType":537},{"uri":2710},"https:\u002F\u002Fsublime.security\u002Fblog\u002Fflowerstorm-unleashes-the-krakvm-phaas-operators-turn-to-vm-based-obfuscation\u002F",[2712],{"data":2713,"marks":2714,"value":2715,"nodeType":445},{},[],"FlowerStorm adopted",{"data":2717,"marks":2718,"value":2719,"nodeType":445},{},[]," KrakVM (an open-source JavaScript VM that compiles malicious JS into encrypted bytecode, defeating email security static analysis) within a month of KrakVM's public release on GitHub. The gap between a new evasion technique appearing publicly and its incorporation into commodity phishing kits has compressed to weeks.",{"data":2721,"content":2722,"nodeType":441},{},[2723,2727,2735,2739,2747],{"data":2724,"marks":2725,"value":2726,"nodeType":445},{},[],"At the same time, target surfaces are expanding: ",{"data":2728,"content":2730,"nodeType":537},{"uri":2729},"https:\u002F\u002Fsecuritylabs.datadoghq.com\u002Farticles\u002Fbehind-the-console-aws-aitm-phishing-kit-and-beyond\u002F",[2731],{"data":2732,"marks":2733,"value":2734,"nodeType":445},{},[],"Datadog documented",{"data":2736,"marks":2737,"value":2738,"nodeType":445},{},[]," an AWS console AiTM kit that dynamically adapts to the victim's configured second factor (an example of ",{"data":2740,"content":2742,"nodeType":537},{"uri":2741},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fmfa-downgrade-attacks",[2743],{"data":2744,"marks":2745,"value":2746,"nodeType":445},{},[],"MFA downgrade",{"data":2748,"marks":2749,"value":2750,"nodeType":445},{},[]," in the wild), extending AiTM phishing from IdPs and SaaS applications to cloud infrastructure consoles.",{"data":2752,"content":2753,"nodeType":515},{},[2754],{"data":2755,"marks":2756,"value":2758,"nodeType":445},{},[2757],{"type":453},"ClickFix as a service",{"data":2760,"content":2761,"nodeType":441},{},[2762,2766,2774,2778,2786],{"data":2763,"marks":2764,"value":2765,"nodeType":445},{},[],"ClickFix has also continued to industrialize. ",{"data":2767,"content":2769,"nodeType":537},{"uri":2768},"https:\u002F\u002Fblog.sekoia.io\u002Funveiling-errtraffic-inside-a-growing-clickfix-malware-distribution-framework\u002F",[2770],{"data":2771,"marks":2772,"value":2773,"nodeType":445},{},[],"Sekoia documented",{"data":2775,"marks":2776,"value":2777,"nodeType":445},{},[]," the ErrTraffic MaaS platform achieving a 60% victim conversion rate, while researchers ",{"data":2779,"content":2781,"nodeType":537},{"uri":2780},"https:\u002F\u002Fkqlquery.com\u002Fposts\u002Fclickfix-gift-that-keeps-on-giving\u002F",[2782],{"data":2783,"marks":2784,"value":2785,"nodeType":445},{},[],"mapped approximately 3,000 live ClickFix payloads",{"data":2787,"marks":2788,"value":2789,"nodeType":445},{},[]," being served through API-driven backends that dynamically generate uniquely obfuscated payloads per victim — essentially the ClickFix PhaaS equivalent.",{"data":2791,"content":2792,"nodeType":441},{},[2793,2797,2805,2809,2817],{"data":2794,"marks":2795,"value":2796,"nodeType":445},{},[],"The technique has also expanded cross-platform, with Unit 42 documenting ",{"data":2798,"content":2800,"nodeType":537},{"uri":2799},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fnew-macos-clickfix-attack-silently-mounts-dmgs-to-push-infostealer\u002F",[2801],{"data":2802,"marks":2803,"value":2804,"nodeType":445},{},[],"macOS ClickFix variants",{"data":2806,"marks":2807,"value":2808,"nodeType":445},{},[]," that mount DMGs and bypass Gatekeeper to deliver AMOS infostealer. At the mass deployment end, over ",{"data":2810,"content":2812,"nodeType":537},{"uri":2811},"https:\u002F\u002Fblog.xlab.qianxin.com\u002Fghost-cms-mass-compromised-via-cve-2026-26980-now-fueling-clickfix-attacks\u002F",[2813],{"data":2814,"marks":2815,"value":2816,"nodeType":445},{},[],"700 Ghost CMS sites were compromised",{"data":2818,"marks":2819,"value":2820,"nodeType":445},{},[]," to serve ClickFix payloads in May, and the Gizmodo homepage was injected in June.",{"data":2822,"content":2823,"nodeType":441},{},[2824,2828,2836,2840,2848],{"data":2825,"marks":2826,"value":2827,"nodeType":445},{},[],"Nation-state actors are building around ClickFix too. Two DPRK subgroups independently stood up ClickFix infrastructure in July: ",{"data":2829,"content":2831,"nodeType":537},{"uri":2830},"https:\u002F\u002Fthehackernews.com\u002F2026\u002F07\u002Fbluenoroff-zoom-phishing-kit-profiles.html",[2832],{"data":2833,"marks":2834,"value":2835,"nodeType":445},{},[],"BlueNoroff",{"data":2837,"marks":2838,"value":2839,"nodeType":445},{},[]," targeting crypto professionals via Zoom impersonation with wallet profiling before payload delivery, and ",{"data":2841,"content":2843,"nodeType":537},{"uri":2842},"https:\u002F\u002Fsocradar.io\u002Fblog\u002Fdprk-clickfake-pylangghost-golangghost-rats\u002F",[2844],{"data":2845,"marks":2846,"value":2847,"nodeType":445},{},[],"Famous Chollima",{"data":2849,"marks":2850,"value":2851,"nodeType":445},{},[]," embedding ClickFix in multi-stage fake job interviews.",{"data":2853,"content":2854,"nodeType":515},{},[2855],{"data":2856,"marks":2857,"value":2859,"nodeType":445},{},[2858],{"type":453},"Vishing as a payload delivery mechanism",{"data":2861,"content":2862,"nodeType":441},{},[2863],{"data":2864,"marks":2865,"value":2866,"nodeType":445},{},[],"Vishing functions as a reliable delivery mechanism for all of these payloads, leveraged by ShinyHunters, Pink, and Helix (among many others) to deliver AiTM and device code phishing. A human operator on a phone call drives the victim through a browser-based technical payload, and the vishing delivery gets around email security controls.",{"data":2868,"content":2869,"nodeType":441},{},[2870,2874,2882],{"data":2871,"marks":2872,"value":2873,"nodeType":445},{},[],"When Push researchers ",{"data":2875,"content":2877,"nodeType":537},{"uri":2876},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Finside-criminal-phishing-panel\u002F",[2878],{"data":2879,"marks":2880,"value":2881,"nodeType":445},{},[],"infiltrated the phishing panels",{"data":2883,"marks":2884,"value":2885,"nodeType":445},{},[]," linked to ShinyHunters' campaigns, we found the mechanics for a live attacker relaying credentials and pushing new prompts in real time during the call, across 400+ linked domains and four infrastructure clusters.",{"data":2887,"content":2888,"nodeType":441},{},[2889,2893,2901,2905,2913,2917,2925,2929,2937],{"data":2890,"marks":2891,"value":2892,"nodeType":445},{},[],"The financial scale is now quantifiable: ",{"data":2894,"content":2896,"nodeType":537},{"uri":2895},"https:\u002F\u002Fwww.darkreading.com\u002Fcyberattacks-data-breaches\u002Fsilent-ransom-us-law-firms-extortion-attacks",[2897],{"data":2898,"marks":2899,"value":2900,"nodeType":445},{},[],"Luna Moth",{"data":2902,"marks":2903,"value":2904,"nodeType":445},{},[]," (Silent Ransom Group), a ",{"data":2906,"content":2908,"nodeType":537},{"uri":2907},"https:\u002F\u002Fwww.crowdstrike.com\u002Fen-us\u002Fadversaries\u002Fchatty-spider\u002F",[2909],{"data":2910,"marks":2911,"value":2912,"nodeType":445},{},[],"Russia-linked Conti spinoff",{"data":2914,"marks":2915,"value":2916,"nodeType":445},{},[]," operating independently of the Com, has extracted ",{"data":2918,"content":2920,"nodeType":537},{"uri":2919},"https:\u002F\u002Fwww.theinsurer.com\u002Fti\u002Fnews\u002Fexclusive-weil-gotshal-paid-double-digit-millions-in-suppression-payment-to-luna-2026-05-27\u002F",[2921],{"data":2922,"marks":2923,"value":2924,"nodeType":445},{},[],"up to $48 million",{"data":2926,"marks":2927,"value":2928,"nodeType":445},{},[]," from Am Law 100 firms in 2026 alone, with 48 law firms on their leak site and the ",{"data":2930,"content":2932,"nodeType":537},{"uri":2931},"https:\u002F\u002Fwww.ic3.gov\u002FCSA\u002F2026\u002F260526.pdf",[2933],{"data":2934,"marks":2935,"value":2936,"nodeType":445},{},[],"FBI issuing a dedicated flash alert",{"data":2938,"marks":2939,"value":1153,"nodeType":445},{},[],{"data":2941,"content":2942,"nodeType":441},{},[2943,2947,2955,2959,2967],{"data":2944,"marks":2945,"value":2946,"nodeType":445},{},[],"The infrastructure behind these campaigns is industrializing independently. ",{"data":2948,"content":2950,"nodeType":537},{"uri":2949},"https:\u002F\u002Fwww.okta.com\u002Fblog\u002Fthreat-intelligence\u002Fbehind-the-scenes-of-a-vishing-operation\u002F",[2951],{"data":2952,"marks":2953,"value":2954,"nodeType":445},{},[],"Okta obtained access to Work Panel",{"data":2956,"marks":2957,"value":2958,"nodeType":445},{},[],", a multi-tenant vishing MaaS platform where phishing site standup is a one-button operation and callers are deliberately insulated from the credentials they help steal. Zscaler separately ",{"data":2960,"content":2962,"nodeType":537},{"uri":2961},"https:\u002F\u002Fwww.zscaler.com\u002Fblogs\u002Fsecurity-research\u002Fhelpdesk-hijackers-teams-vishing-quick-assist-and-gogrpc-backdoor",[2963],{"data":2964,"marks":2965,"value":2966,"nodeType":445},{},[],"documented a dedicated Teams-vishing initial access broker",{"data":2968,"marks":2969,"value":2970,"nodeType":445},{},[]," operating since January 2026, building bespoke post-access tooling and selling access to ransomware operators.",{"data":2972,"content":2973,"nodeType":515},{},[2974],{"data":2975,"marks":2976,"value":2978,"nodeType":445},{},[2977],{"type":453},"OAuth supply chain attacks",{"data":2980,"content":2981,"nodeType":441},{},[2982,2986,2993],{"data":2983,"marks":2984,"value":2985,"nodeType":445},{},[],"The OAuth supply chain dimension has also continued to produce confirmed victims. The ",{"data":2987,"content":2988,"nodeType":537},{"uri":2323},[2989],{"data":2990,"marks":2991,"value":2992,"nodeType":445},{},[],"Salesloft\u002FDrift supply chain attack",{"data":2994,"marks":2995,"value":2996,"nodeType":445},{},[]," in 2025 set the template: compromise one SaaS vendor, steal OAuth tokens, access 700+ downstream customer Salesforce environments.",{"data":2998,"content":2999,"nodeType":441},{},[3000,3004,3012,3016,3024,3028,3036],{"data":3001,"marks":3002,"value":3003,"nodeType":445},{},[],"In 2026, the ",{"data":3005,"content":3007,"nodeType":537},{"uri":3006},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fvimeo-data-breach-exposes-personal-information-of-119-000-people\u002F",[3008],{"data":3009,"marks":3010,"value":3011,"nodeType":445},{},[],"Anodot compromise",{"data":3013,"marks":3014,"value":3015,"nodeType":445},{},[]," cascaded through to Vimeo, Rockstar Games, and Zara. The ",{"data":3017,"content":3019,"nodeType":537},{"uri":3018},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Funpacking-the-vercel-breach\u002F",[3020],{"data":3021,"marks":3022,"value":3023,"nodeType":445},{},[],"Context.ai → Vercel",{"data":3025,"marks":3026,"value":3027,"nodeType":445},{},[]," breach followed the same structural pattern. And the ",{"data":3029,"content":3031,"nodeType":537},{"uri":3030},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fklue-oauth-breach-victim-list-grows-as-icarus-hackers-claim-attack\u002F",[3032],{"data":3033,"marks":3034,"value":3035,"nodeType":445},{},[],"Klue\u002FIcarus breach",{"data":3037,"marks":3038,"value":3039,"nodeType":445},{},[]," in June — where attackers pivoted from a legacy credential through stored OAuth tokens to exfiltrate Salesforce data from Huntress, Recorded Future, and Jamf among others — showed that OAuth tokens have become a tried and tested lateral movement vector in SaaS environments.",{"data":3041,"content":3042,"nodeType":467},{},[],{"data":3044,"content":3045,"nodeType":471},{},[3046],{"data":3047,"marks":3048,"value":3050,"nodeType":445},{},[3049],{"type":453},"AI is a force multiplier for attackers",{"data":3052,"content":3053,"nodeType":441},{},[3054],{"data":3055,"marks":3056,"value":3057,"nodeType":445},{},[],"Much of the security industry's AI threat discussion has focused on autonomous offensive AI and novel attack classes like prompt injection. But the place where AI is having the most measurable impact right now is less dramatic and more consequential: it's accelerating how the techniques we've already been tracking get built and operated.",{"data":3059,"content":3060,"nodeType":441},{},[3061],{"data":3062,"marks":3063,"value":3064,"nodeType":445},{},[],"The evidence is visible at every layer of the attack chain. Pretty much every phishing kit we come across in 2026 shows clear signs of vibe coding. For the classic AiTM lure, we used to find heavy obfuscation — attackers used to put a lot of effort into hiding their attacks. But now, they're essentially built to be disposable, and are full of verbose comments and nicely named unobfuscated functions. Why bother hiding when you can just spin up a new one? This is particularly notable when it comes to device code phishing, which owes its massive scale-up this year to vibecoded kits. ",{"data":3066,"content":3067,"nodeType":441},{},[3068,3072,3080],{"data":3069,"marks":3070,"value":3071,"nodeType":445},{},[],"You can see more examples of these kits under the hood in our blog post ",{"data":3073,"content":3075,"nodeType":537},{"uri":3074},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Finside-criminal-phishing-panel",[3076],{"data":3077,"marks":3078,"value":3079,"nodeType":445},{},[],"infiltrating a criminal phishing panel. ",{"data":3081,"marks":3082,"value":21,"nodeType":445},{},[],{"data":3084,"content":3088,"nodeType":787},{"target":3085},{"sys":3086},{"id":3087,"type":792,"linkType":793},"01mOiserRBXraawXwQyJNm",[],{"data":3090,"content":3091,"nodeType":441},{},[3092],{"data":3093,"marks":3094,"value":3095,"nodeType":445},{},[],"Beyond vibe-coded kits, attackers are embedding AI as an integrated operational capability. ",{"data":3097,"content":3098,"nodeType":1335},{},[3099,3121,3142,3164,3186],{"data":3100,"content":3101,"nodeType":1339},{},[3102],{"data":3103,"content":3104,"nodeType":441},{},[3105,3109,3117],{"data":3106,"marks":3107,"value":3108,"nodeType":445},{},[],"The first major device code phishing kit identified in the wild, EvilTokens, ",{"data":3110,"content":3112,"nodeType":537},{"uri":3111},"https:\u002F\u002Fwww.huntress.com\u002Fblog\u002Frailway-paas-m365-token-replay-campaign",[3113],{"data":3114,"marks":3115,"value":3116,"nodeType":445},{},[],"heavily used Railway",{"data":3118,"marks":3119,"value":3120,"nodeType":445},{},[],", a PaaS built for vibe coding with prompt-based deployment and teardown of infrastructure. EvilTokens itself packaged AI workflows for email filter bypass, lure tailoring, and identifying high-value mailboxes. ",{"data":3122,"content":3123,"nodeType":1339},{},[3124],{"data":3125,"content":3126,"nodeType":441},{},[3127,3131,3138],{"data":3128,"marks":3129,"value":3130,"nodeType":445},{},[],"Kali365's E2 edition includes an AI-powered BEC module that ",{"data":3132,"content":3133,"nodeType":537},{"uri":2520},[3134],{"data":3135,"marks":3136,"value":3137,"nodeType":445},{},[],"uses Claude Sonnet",{"data":3139,"marks":3140,"value":3141,"nodeType":445},{},[]," to score intercepted conversations for fraud opportunity and draft contextual wire-transfer redirect replies — not an autonomous attack, but an AI-augmented workflow that makes an existing phishing kit more effective.",{"data":3143,"content":3144,"nodeType":1339},{},[3145],{"data":3146,"content":3147,"nodeType":441},{},[3148,3151,3160],{"data":3149,"marks":3150,"value":21,"nodeType":445},{},[],{"data":3152,"content":3154,"nodeType":537},{"uri":3153},"https:\u002F\u002Fthehackernews.com\u002F2026\u002F07\u002Fexposed-server-reveals-ai-assisted.html",[3155],{"data":3156,"marks":3157,"value":3159,"nodeType":445},{},[3158],{"type":545},"Rapid7's analysis of an exposed server",{"data":3161,"marks":3162,"value":3163,"nodeType":445},{},[]," containing a complete phishing toolkit turned up over 1,000 delivery artifacts alongside hardcoded paths to AI coding tools and LLM-style documentation.",{"data":3165,"content":3166,"nodeType":1339},{},[3167],{"data":3168,"content":3169,"nodeType":441},{},[3170,3174,3182],{"data":3171,"marks":3172,"value":3173,"nodeType":445},{},[],"Three independent operators were ",{"data":3175,"content":3177,"nodeType":537},{"uri":3176},"https:\u002F\u002Fthehackernews.com\u002F2026\u002F07\u002Fmisconfigured-server-reveals-three.html",[3178],{"data":3179,"marks":3180,"value":3181,"nodeType":445},{},[],"found running kits from public GitHub forks",{"data":3183,"marks":3184,"value":3185,"nodeType":445},{},[]," with minimal, AI-assisted customization: one had been operating for over a year with 218 victims across 12 countries, running infrastructure that would previously have required significantly more technical ability to maintain. ",{"data":3187,"content":3188,"nodeType":1339},{},[3189],{"data":3190,"content":3191,"nodeType":441},{},[3192,3196,3204],{"data":3193,"marks":3194,"value":3195,"nodeType":445},{},[],"The tooling itself is starting to embed AI as a product feature — ",{"data":3197,"content":3199,"nodeType":537},{"uri":3198},"https:\u002F\u002Fwww.varonis.com\u002Fblog\u002Fdolphin-x-stealer",[3200],{"data":3201,"marks":3202,"value":3203,"nodeType":445},{},[],"Dolphin X",{"data":3205,"marks":3206,"value":3207,"nodeType":445},{},[],", a new MaaS infostealer targeting 300+ applications across browsers, password managers, cloud CLI tools, and crypto wallets, ships an AI Profiler that scores infected machines by application usage and installed software, then delivers daily ranked summaries so operators can prioritize high-value victims from thousands of infections.",{"data":3209,"content":3210,"nodeType":441},{},[3211,3215,3223,3227,3234,3238,3246],{"data":3212,"marks":3213,"value":3214,"nodeType":445},{},[],"AI adoption itself has also become an attack surface. Users searching for AI desktop applications are already looking to download and install software, and attackers are capitalizing on that behavior: a ",{"data":3216,"content":3218,"nodeType":537},{"uri":3217},"https:\u002F\u002Fwww.huntress.com\u002Fblog\u002Ffakeagent-claude-desktop-malvertising-ends-in-dotnet-rat",[3219],{"data":3220,"marks":3221,"value":3222,"nodeType":445},{},[],"malicious Claude.ai Artifact impersonating a download portal",{"data":3224,"marks":3225,"value":3226,"nodeType":445},{},[]," drew 7,100 visits via Bing search ads and compromised 29 organizations in 48 hours, following the ",{"data":3228,"content":3229,"nodeType":537},{"uri":1005},[3230],{"data":3231,"marks":3232,"value":3233,"nodeType":445},{},[],"LLMShare attack pattern",{"data":3235,"marks":3236,"value":3237,"nodeType":445},{},[]," we documented in May. A second campaign, ",{"data":3239,"content":3241,"nodeType":537},{"uri":3240},"https:\u002F\u002Fwww.huntress.com\u002Fblog\u002Fmacsync-stealer-rat-reverse-engineering",[3242],{"data":3243,"marks":3244,"value":3245,"nodeType":445},{},[],"MacSync",{"data":3247,"marks":3248,"value":3249,"nodeType":445},{},[],", used a claude.ai conversation styled as an installation guide to deliver a macOS infostealer via a ClickFix-adjacent terminal paste, also distributed through Google Ads. In both cases, the AI platform's trusted domain carried the malicious content past URL reputation filters.",{"data":3251,"content":3252,"nodeType":515},{},[3253],{"data":3254,"marks":3255,"value":3257,"nodeType":445},{},[3256],{"type":453},"But the core techniques aren't changing",{"data":3259,"content":3260,"nodeType":441},{},[3261,3265,3273],{"data":3262,"marks":3263,"value":3264,"nodeType":445},{},[],"AI compresses the bottom layers of the ",{"data":3266,"content":3268,"nodeType":537},{"uri":3267},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fthe-pyramid-of-pain-in-the-ai-era\u002F",[3269],{"data":3270,"marks":3271,"value":3272,"nodeType":445},{},[],"Pyramid of Pain",{"data":3274,"marks":3275,"value":3276,"nodeType":445},{},[]," (unique hashes, domains, IP addresses, host artifacts) by enabling faster domain rotation, cheaper kit development, and rotating payloads, but the technique-level behaviors remain unchanged.",{"data":3278,"content":3279,"nodeType":441},{},[3280],{"data":3281,"marks":3282,"value":3283,"nodeType":445},{},[],"A phishing page still has to harvest credentials. Device code phishing still has to abuse the authorization grant. ClickFix still has to inject a clipboard payload. Those behavioral signatures are structurally resistant to AI-driven variation because changing them means changing how the attack works.",{"data":3285,"content":3286,"nodeType":467},{},[],{"data":3288,"content":3289,"nodeType":471},{},[3290],{"data":3291,"marks":3292,"value":3294,"nodeType":445},{},[3293],{"type":453},"What this means for defenders",{"data":3296,"content":3297,"nodeType":441},{},[3298],{"data":3299,"marks":3300,"value":3301,"nodeType":445},{},[],"Every trend documented here converges on the same control point: the browser. The AI acceleration that makes all of it faster and cheaper doesn't change where the attacks execute, or how Push intercepts them.",{"data":3303,"content":3304,"nodeType":1335},{},[3305,3315,3325,3335],{"data":3306,"content":3307,"nodeType":1339},{},[3308],{"data":3309,"content":3310,"nodeType":441},{},[3311],{"data":3312,"marks":3313,"value":3314,"nodeType":445},{},[],"For AiTM phishing, Push's behavioral detection analyzes and blocks the phishing page in real time, regardless of which domains or hosting infrastructure the kit uses on any given day.",{"data":3316,"content":3317,"nodeType":1339},{},[3318],{"data":3319,"content":3320,"nodeType":441},{},[3321],{"data":3322,"marks":3323,"value":3324,"nodeType":445},{},[],"For device code phishing, Push detects both the phishing pages associated with device code kits and provides an additional layer on the legitimate device code authentication pages themselves, so users cannot enter attacker-supplied codes.",{"data":3326,"content":3327,"nodeType":1339},{},[3328],{"data":3329,"content":3330,"nodeType":441},{},[3331],{"data":3332,"marks":3333,"value":3334,"nodeType":445},{},[],"For ClickFix, Push detects the clipboard injection at the moment the malicious payload is written.",{"data":3336,"content":3337,"nodeType":1339},{},[3338],{"data":3339,"content":3340,"nodeType":441},{},[3341],{"data":3342,"marks":3343,"value":3344,"nodeType":445},{},[],"For OAuth supply chain attacks, Push monitors and controls consent flows at the browser layer, so security teams can govern which applications obtain tokens in the first place.",{"data":3346,"content":3347,"nodeType":441},{},[3348],{"data":3349,"marks":3350,"value":3351,"nodeType":445},{},[],"As AI enables more kits, more operators, and faster infrastructure rotation, indicator-based defenses that target domains, IPs, and hashes become less effective by the day. Behavioral detection that targets technique-class signatures (what the attack does) is the approach that scales.",{"data":3353,"content":3354,"nodeType":467},{},[],{"data":3356,"content":3357,"nodeType":441},{},[3358],{"data":3359,"marks":3360,"value":655,"nodeType":445},{},[],{"data":3362,"content":3363,"nodeType":441},{},[3364],{"data":3365,"marks":3366,"value":662,"nodeType":445},{},[],{"data":3368,"content":3369,"nodeType":441},{},[3370,3373,3381],{"data":3371,"marks":3372,"value":21,"nodeType":445},{},[],{"data":3374,"content":3376,"nodeType":537},{"uri":3375},"https:\u002F\u002Fpushsecurity.com\u002Fdemo\u002F",[3377],{"data":3378,"marks":3379,"value":676,"nodeType":445},{},[3380],{"type":545},{"data":3382,"marks":3383,"value":21,"nodeType":445},{},[],"Browser threat landscape: mid-year update 2026","PhaaS industrialization, Scattered Spider copycats, and AI-augmented tooling — what the threat landscape looks like in 2026 so far.","2026-08-10T00:00:00.000Z","browser-threat-landscape-mid-year-update-2026",{"items":3389},[3390,3392],{"sys":3391,"name":1579},{"id":1578},{"sys":3393,"name":1583},{"id":1582},{"items":3395},[3396],{"fullName":1587,"firstName":1588,"jobTitle":1589,"profilePicture":3397},{"url":1591},"proofpoint-x-push-partnership-announcement","blog\u002Fproofpoint-x-push-partnership-announcement",{"json":3401},{"data":3402,"content":3403,"nodeType":437},{},[3404],{"data":3405,"content":3406,"nodeType":441},{},[3407],{"data":3408,"marks":3409,"value":3410,"nodeType":445},{},[],"Push Security is partnering with Proofpoint, bringing Push’s in-browser threat protection to Proofpoint customers to tackle browser-native threats as phishing moves beyond the inbox.","Push Security is partnering with Proofpoint, bringing Push’s in-browser threat protection to Proofpoint customers.",{"id":3413,"publishedAt":3414},"2W68nOLYgy1TpDqV5yWdRT","2026-09-29T07:17:47.925Z",{"items":3416},[3417],{"sys":3418,"name":3420},{"id":3419},"4EtskIWlj3SOH3UHbFR8uG","Company news",{"items":3422},[3423,3427,3431,3436,3441,3446,3451,3456],{"sys":3424,"name":245,"slug":3426,"tier":31},{"id":3425},"topic-phishing","phishing",{"sys":3428,"name":2077,"slug":3430,"tier":31},{"id":3429},"topic-browser-security","browser-security",{"sys":3432,"name":3434,"slug":3435,"tier":45},{"id":3433},"topic-bec","BEC","bec",{"sys":3437,"name":3439,"slug":3440,"tier":45},{"id":3438},"topic-non-email-phishing","Non-email phishing","non-email-phishing",{"sys":3442,"name":3444,"slug":3445,"tier":45},{"id":3443},"topic-enterprise-browser","Enterprise browser","enterprise-browser",{"sys":3447,"name":3449,"slug":3450,"tier":45},{"id":3448},"topic-social-engineering","Social engineering","social-engineering",{"sys":3452,"name":3454,"slug":3455,"tier":31},{"id":3453},"topic-browser-attacks","Browser attacks","browser-attacks",{"sys":3457,"name":1583,"slug":3459,"tier":31},{"id":3458},"topic-detection-and-response","detection-and-response","JHpj6BtfH61p_Q8YYHAiMGE95UGIMSW6QZBSioI_ruY",{"id":3462,"extension":688,"items":3463,"meta":3862,"stem":3863,"__hash__":3864},"blogTopics\u002Fblogtopics.json",[3464,3473,3482,3491,3500,3506,3512,3521,3527,3536,3545,3554,3562,3568,3577,3584,3593,3602,3607,3615,3624,3633,3642,3651,3660,3668,3677,3686,3692,3701,3710,3719,3727,3733,3742,3751,3760,3769,3778,3786,3795,3804,3812,3818,3826,3835,3844,3853],{"sys":3465,"faqItemsCollection":3467,"name":3469,"slug":3470,"tier":31,"intro":3471,"faqTitle":60,"postCount":3472,"hasPage":19},{"id":3466},"topic-ai",{"items":3468},[],"AI","ai","AI is reshaping both sides of the security equation: employees adopt AI tools faster than security teams can track them, while attackers use AI to scale and automate campaigns. Shadow AI adoption may now outpace wider shadow SaaS, and attackers are already turning AI chatbot platforms into malware delivery channels. Push has researched the offensive potential of computer-using agents and now applies AI agents to its own threat hunting. This hub covers AI as risk, target, and defensive tool.",22,{"sys":3474,"faqItemsCollection":3476,"name":3478,"slug":3479,"tier":45,"intro":3480,"faqTitle":60,"postCount":3481,"hasPage":19},{"id":3475},"topic-ai-attacks",{"items":3477},[],"AI attacks","ai-attacks","AI attacks run in both directions: attackers using AI to scale phishing, malware delivery, and identity attacks, and AI platforms themselves becoming the attack surface. Push has researched how computer-using agents can automate identity attacks, and has seen the poisoned tenant technique it coined used against its own employees in the wild.",24,{"sys":3483,"faqItemsCollection":3485,"name":3487,"slug":3488,"tier":45,"intro":3489,"faqTitle":60,"postCount":3490,"hasPage":19},{"id":3484},"topic-ai-governance",{"items":3486},[],"AI governance","ai-governance","AI governance is how organizations set and enforce rules for workplace AI use — which tools are allowed, what data can enter them, and how to evidence it to regulators. With US, EU, and UK AI regulations converging on obligations most organizations can’t yet meet, Push’s research makes the case that enforcement starts in the browser, where AI tools are actually used.",9,{"sys":3492,"faqItemsCollection":3494,"name":3496,"slug":3497,"tier":45,"intro":3498,"faqTitle":60,"postCount":3499,"hasPage":19},{"id":3493},"topic-aitm",{"items":3495},[],"AiTM phishing","aitm","Adversary-in-the-middle (AiTM) phishing proxies a real login page through an attacker-controlled site, capturing credentials, MFA codes, and session tokens in real time to bypass multi-factor authentication. Push’s research into kits like Evilginx and Sneaky2FA documents how they evade URL- and signature-based detection — and why analyzing toolkit behavior in the browser catches attacks that blocklists miss.",78,{"sys":3501,"faqItemsCollection":3502,"name":3434,"slug":3435,"tier":45,"intro":3504,"faqTitle":60,"postCount":3505,"hasPage":19},{"id":3433},{"items":3503},[],"Business email compromise (BEC) turns a hijacked mailbox into a fraud tool: attackers use mail rules, auto-forwarding, and payment redirection to steal money while staying invisible to the account owner. Alongside a first-hand case study of a BEC attack that nearly cost an engineering firm millions, Push breaks down these mailbox persistence tricks and how to detect them.",5,{"sys":3507,"faqItemsCollection":3508,"name":3454,"slug":3455,"tier":31,"intro":3510,"faqTitle":60,"postCount":3511,"hasPage":19},{"id":3453},{"items":3509},[],"Browser attacks target users through the web pages, sessions, and extensions they rely on every day — bypassing endpoint and network defenses that never see inside the browser. Techniques like AiTM phishing kits, ClickFix-style copy-paste attacks, OAuth consent abuse, malvertising, and browser sync abuse have become a leading path to account takeover. Push researchers analyze these attacks in the wild, from infiltrating criminal phishing panels to dissecting toolkits like ConsentFix and Sneaky2FA. Use this hub to track how the techniques evolve and how to defend against them.",124,{"sys":3513,"faqItemsCollection":3515,"name":3517,"slug":3518,"tier":45,"intro":3519,"faqTitle":60,"postCount":3520,"hasPage":19},{"id":3514},"topic-browser-extensions",{"items":3516},[],"Browser extensions","browser-extensions","Browser extensions cut both ways for security teams: malicious or compromised extensions are a growing attack vector, while an extension is also the lightest-weight way to deploy security controls into the browsers employees already use. These posts cover both sides — extension-borne risks like browser sync attacks and the limits of risk scoring, and how Push uses its extension to detect threats and block risky extensions.",31,{"sys":3522,"faqItemsCollection":3523,"name":2077,"slug":3430,"tier":31,"intro":3525,"faqTitle":60,"postCount":3526,"hasPage":19},{"id":3429},{"items":3524},[],"Work now happens in the browser, making browser security — visibility and control at the point where users meet the web — a core layer of enterprise defense. Endpoint, network, and email tools miss attacks that unfold inside the browser session, from AiTM phishing to risky extensions and shadow SaaS. Push has published extensively on choosing between enterprise browsers and browser extensions, using browser telemetry, and making the business case for browser security. Start here for both strategy and hands-on guidance.",130,{"sys":3528,"faqItemsCollection":3530,"name":3532,"slug":3533,"tier":45,"intro":3534,"faqTitle":60,"postCount":3535,"hasPage":19},{"id":3529},"topic-casb",{"items":3531},[],"CASB","casb","Cloud access security brokers (CASBs) govern cloud app usage through API integrations and network proxies — an approach that works for sanctioned apps but struggles with the long tail of shadow SaaS employees adopt on their own. Because every SaaS signup happens in a browser, Push captures that adoption in real time at the point of login, and these posts cover what proxy-based discovery misses.",12,{"sys":3537,"faqItemsCollection":3539,"name":3541,"slug":3542,"tier":45,"intro":3543,"faqTitle":60,"postCount":3544,"hasPage":19},{"id":3538},"topic-clickfix",{"items":3540},[],"ClickFix","clickfix","ClickFix attacks trick users into copying and running malicious commands themselves — typically through fake CAPTCHA, error, or fix-it prompts — so malware executes without a download for security tools to scan. Push researchers track the technique’s evolution in the wild and identified the ConsentFix and InstallFix variants, which extend it to OAuth consent grants and fake install guides.",41,{"sys":3546,"faqItemsCollection":3548,"name":3550,"slug":3551,"tier":45,"intro":3552,"faqTitle":60,"postCount":3553,"hasPage":19},{"id":3547},"topic-credential-phishing",{"items":3549},[],"Credential phishing","credential-phishing","Credential phishing steals usernames and passwords through fake login pages impersonating the services employees use, handing attackers direct access to corporate accounts. Attackers don’t hack in — they log in. Push’s browser extension analyzes login pages as users actually see them, blocking cloned pages and stopping employees from entering company passwords on lookalike sites.",90,{"sys":3555,"faqItemsCollection":3557,"name":299,"slug":3559,"tier":45,"intro":3560,"faqTitle":60,"postCount":3561,"hasPage":19},{"id":3556},"topic-credential-stuffing",{"items":3558},[],"credential-stuffing","Credential stuffing is an attack where criminals replay username-password pairs stolen from one breach against other services, exploiting password reuse to take over accounts. Major breaches have shown how far a single set of stolen credentials can travel. Push detects verified stolen credentials by comparing employee passwords against breach datasets and dark-web threat intelligence, eliminating false positives.",64,{"sys":3563,"faqItemsCollection":3564,"name":1583,"slug":3459,"tier":31,"intro":3566,"faqTitle":60,"postCount":3567,"hasPage":19},{"id":3458},{"items":3565},[],"Detection and response is being reshaped as attacks move into the browser, where EDR, SIEM, and network tools have limited visibility. Modern phishing kits evade signature-based detection, and most malicious pages have never been seen before — so technique-level, in-browser detection matters more than known-bad indicators. Push’s work here spans high-fidelity browser telemetry, session token theft detection, and agentic threat hunting, plus practical IR guidance for compromised SaaS accounts and malicious OAuth apps. These posts cover both the philosophy and the workflows.",103,{"sys":3569,"faqItemsCollection":3571,"name":3573,"slug":3574,"tier":45,"intro":3575,"faqTitle":60,"postCount":3576,"hasPage":19},{"id":3570},"topic-detection-engineering",{"items":3572},[],"Detection engineering","detection-engineering","Detection engineering turns threat research into reliable, high-fidelity detections — and as AI accelerates the churn of attacker infrastructure, indicator-based detection is collapsing in favor of technique-level approaches. Here you’ll find teardowns of AiTM kits, ClickFix pages, and malvertising campaigns, alongside Push’s own account of building an agentic threat hunting pipeline that turns hunts into shipped detections.",43,{"sys":3578,"faqItemsCollection":3580,"name":260,"slug":3582,"tier":45,"intro":3583,"faqTitle":60,"postCount":3481,"hasPage":19},{"id":3579},"topic-device-code-phishing",{"items":3581},[],"device-code-phishing","Device code phishing abuses the OAuth device authorization flow: attackers generate a legitimate sign-in code, trick the victim into entering it on the vendor’s real login page, and walk away with access tokens — no fake site or password capture required. Push research tracked a sharp spike in adoption during 2026 as attackers use the technique to sidestep standard access controls.",{"sys":3585,"faqItemsCollection":3587,"name":3589,"slug":3590,"tier":45,"intro":3591,"faqTitle":60,"postCount":3592,"hasPage":19},{"id":3586},"topic-dlp",{"items":3588},[],"DLP","dlp","Data loss prevention (DLP) is the practice of stopping sensitive data from leaving your control — a problem that has shifted from email and endpoints to the browser, where employees move data into SaaS and AI tools. Push applies controls at that point of use, from keeping corporate credentials out of personal password managers to governing what flows into unsanctioned apps.",15,{"sys":3594,"faqItemsCollection":3596,"name":3598,"slug":3599,"tier":45,"intro":3600,"faqTitle":60,"postCount":3601,"hasPage":19},{"id":3595},"topic-edr",{"items":3597},[],"EDR","edr","Endpoint detection and response (EDR) watches processes, files, and memory on the device — a vantage point that never sees the phishing pages, stolen sessions, and identity attacks playing out inside the browser. That’s not an EDR failure; attackers have simply moved where it can’t follow. These posts map that gap and show how Push pairs browser-level detection and response with endpoint security to close it.",26,{"sys":3603,"faqItemsCollection":3604,"name":3444,"slug":3445,"tier":45,"intro":3606,"faqTitle":60,"postCount":3490,"hasPage":19},{"id":3443},{"items":3605},[],"An enterprise browser is a standalone, security-hardened browser that organizations deploy in place of Chrome, Edge, or other defaults. The real buying question is whether replacing the browser beats securing the browsers employees already use — a trade-off these posts examine directly, alongside analysis of Omdia’s secure enterprise browser market report and Push’s framework for weighing full browsers against extension-based deployment.",{"sys":3608,"faqItemsCollection":3610,"name":289,"slug":3612,"tier":45,"intro":3613,"faqTitle":60,"postCount":3614,"hasPage":19},{"id":3609},"topic-ghost-logins",{"items":3611},[],"ghost-logins","Ghost logins are overlooked authentication routes into an account — like a password login lingering behind SSO, or a forgotten secondary auth method — that attackers exploit for account takeover and persistence. Push coined the term after research showing how these forgotten login paths let attackers sidestep the MFA and SSO controls guarding an account’s primary sign-in method.",48,{"sys":3616,"faqItemsCollection":3618,"name":3620,"slug":3621,"tier":45,"intro":3622,"faqTitle":60,"postCount":3623,"hasPage":19},{"id":3617},"topic-identity-attacks",{"items":3619},[],"Identity attacks","identity-attacks","Identity attacks target user accounts rather than infrastructure — phishing credentials, stealing sessions, abusing OAuth grants — because logging in is easier than hacking in. Identity-based techniques are now the leading cause of breaches. Push’s offensive research maps these techniques continuously, coining attacks like SAMLjacking and the poisoned tenant before they appeared in the wild.",58,{"sys":3625,"faqItemsCollection":3627,"name":3629,"slug":3630,"tier":31,"intro":3631,"faqTitle":60,"postCount":3632,"hasPage":19},{"id":3626},"topic-identity-security",{"items":3628},[],"Identity security","identity-security","Identity security is the practice of protecting workforce accounts, credentials, and sessions — the primary route attackers now use to breach organizations. Instead of hacking in, attackers log in: through phished credentials, stolen session tokens, MFA bypass, and forgotten ghost logins. Push’s research team documents these techniques continuously, from cross-IdP impersonation and SAMLjacking to analyses of major identity-driven breaches. This hub collects that research alongside practical guidance on MFA, SSO, and stopping account takeover.",154,{"sys":3634,"faqItemsCollection":3636,"name":3638,"slug":3639,"tier":45,"intro":3640,"faqTitle":60,"postCount":3641,"hasPage":19},{"id":3635},"topic-infostealer",{"items":3637},[],"Infostealer","infostealer","Infostealers are malware built to harvest saved passwords, cookies, and session tokens from infected devices, supplying the stolen credentials behind some of the most consequential breaches of recent years. Push traces the ecosystem trading this data and checks employee passwords against threat intel feeds, flagging verified stolen credentials before attackers can log in with them.",54,{"sys":3643,"faqItemsCollection":3645,"name":3647,"slug":3648,"tier":45,"intro":3649,"faqTitle":60,"postCount":3650,"hasPage":19},{"id":3644},"topic-legitimate-service-abuse",{"items":3646},[],"Legitimate service abuse","legitimate-service-abuse","Legitimate service abuse means staging attacks on trusted platforms — Google Ads, AI chatbot share pages, office.com links, Slack, SaaS tenants — so malicious content inherits the reputation of the service hosting it. Push research has documented the pattern repeatedly, from malvertising run through hijacked Google Ad Manager accounts to phishing links generated by Active Directory Federation Services.",29,{"sys":3652,"faqItemsCollection":3654,"name":3656,"slug":3657,"tier":45,"intro":3658,"faqTitle":60,"postCount":3659,"hasPage":19},{"id":3653},"topic-malvertising",{"items":3655},[],"Malvertising","malvertising","Malvertising uses paid search and display ads to put phishing pages and malware in front of users, often by impersonating trusted brands at the top of Google results. Push tracks these campaigns continuously — intercepting live attacks spoofing well-known brands — and has documented how criminals hijack Google Ads accounts to fund and run them.",32,{"sys":3661,"faqItemsCollection":3663,"name":3665,"slug":3666,"tier":45,"intro":3667,"faqTitle":60,"postCount":3592,"hasPage":19},{"id":3662},"topic-malware-delivery",{"items":3664},[],"Malware delivery","malware-delivery","Malware delivery has moved into the browser: rather than email attachments, attackers now rely on malvertising, fake install guides, and ClickFix-style copy-paste lures to get code running on endpoints. Push research on techniques like InstallFix maps the playbook, and in-browser detection of malicious copy and paste blocks these attacks before commands reach the endpoint.",{"sys":3669,"faqItemsCollection":3671,"name":3673,"slug":3674,"tier":45,"intro":3675,"faqTitle":60,"postCount":3676,"hasPage":19},{"id":3670},"topic-mfa",{"items":3672},[],"MFA","mfa","Multi-factor authentication (MFA) requires a second proof of identity beyond a password, and it remains one of the most effective controls against account takeover. Regulators from Cyber Essentials to NYDFS now mandate it across cloud services. Push enforces MFA in the browser on third-party apps — even those with no native enforcement option — and shows security teams where coverage gaps remain.",83,{"sys":3678,"faqItemsCollection":3680,"name":3682,"slug":3683,"tier":45,"intro":3684,"faqTitle":60,"postCount":3685,"hasPage":19},{"id":3679},"topic-mfa-bypass",{"items":3681},[],"MFA bypass","mfa-bypass","MFA bypass covers the techniques attackers use to defeat multi-factor authentication — AiTM phishing kits, consent phishing, device code phishing, and MFA downgrade attacks among them. None of these break the second factor; they route around it. Push researchers regularly get hands-on with phishing kits like Evilginx and Sneaky2FA, analyzing how these attacks work in the wild and how they evolve.",60,{"sys":3687,"faqItemsCollection":3688,"name":3439,"slug":3440,"tier":45,"intro":3690,"faqTitle":60,"postCount":3691,"hasPage":19},{"id":3438},{"items":3689},[],"Non-email phishing delivers malicious links through channels your secure email gateway never sees — social media messages, IM apps like Slack and Teams, search ads, and SMS. Push has intercepted live campaigns arriving via LinkedIn DMs, malvertising, and messaging platforms, which is why it detects phishing pages in the browser at the point of click, regardless of delivery channel.",53,{"sys":3693,"faqItemsCollection":3695,"name":3697,"slug":3698,"tier":45,"intro":3699,"faqTitle":60,"postCount":3700,"hasPage":19},{"id":3694},"topic-oauth-abuse",{"items":3696},[],"OAuth abuse","oauth-abuse","OAuth abuse is attackers exploiting app-to-app authorization — consent phishing, malicious OAuth apps, stolen tokens, and device code flows — to gain persistent access to cloud tenants without touching a password or MFA prompt. Push tracks these techniques continuously and discovered ConsentFix, a browser-native attack in the wild that pairs OAuth consent phishing with a ClickFix-style prompt.",70,{"sys":3702,"faqItemsCollection":3704,"name":3706,"slug":3707,"tier":45,"intro":3708,"faqTitle":60,"postCount":3709,"hasPage":19},{"id":3703},"topic-passkeys",{"items":3705},[],"Passkeys","passkeys","Passkeys are phishing-resistant credentials that replace passwords with cryptographic key pairs bound to a user’s device. They defeat conventional credential phishing, but attackers adapt: Push research has documented MFA downgrade, app-specific password phishing, and device code phishing being used in the wild to route around passkey-protected accounts. Deploying passkeys is step one; closing those fallback paths is step two.",23,{"sys":3711,"faqItemsCollection":3713,"name":3715,"slug":3716,"tier":45,"intro":3717,"faqTitle":60,"postCount":3718,"hasPage":19},{"id":3712},"topic-password-security",{"items":3714},[],"Password security","password-security","Password security is the practice of keeping workforce credentials strong, unique, and out of attackers’ hands — still a frontline defense while most SaaS logins depend on passwords. Expiration policies don’t fix weak or reused passwords; visibility does. Push observes real logins in the browser to flag weak, reused, and breached passwords and guide employees to reset them on any app.",80,{"sys":3720,"faqItemsCollection":3722,"name":3724,"slug":3725,"tier":45,"intro":3726,"faqTitle":60,"postCount":3544,"hasPage":19},{"id":3721},"topic-phaas",{"items":3723},[],"PhaaS","phaas","Phishing-as-a-service (PhaaS) platforms sell ready-made phishing kits, hosted infrastructure, and management panels on subscription, letting low-skill criminals run MFA-bypassing campaigns at scale. Kits like Evilginx, Tycoon2FA, Sneaky2FA, FlowerStorm, and EvilTokens each add their own evasion and session-theft capabilities, and new entrants appear regularly. Push researchers continuously get hands-on with these tools — investigating attacks in the wild, reverse-engineering kit behavior, and turning that research into detections.",{"sys":3728,"faqItemsCollection":3729,"name":245,"slug":3426,"tier":31,"intro":3731,"faqTitle":60,"postCount":3732,"hasPage":19},{"id":3425},{"items":3730},[],"Phishing remains the most common way attackers compromise business accounts — and it has moved far beyond suspicious emails. Modern campaigns use AiTM toolkits that bypass MFA, consent phishing against OAuth, device code phishing, and lures delivered through malvertising, LinkedIn, and Slack. Push detects and blocks these attacks in the browser, and its researchers publish teardowns of live campaigns and kits like Evilginx and Sneaky2FA. Read on for how phishing actually works today and what stops it.",94,{"sys":3734,"faqItemsCollection":3736,"name":3738,"slug":3739,"tier":45,"intro":3740,"faqTitle":60,"postCount":3741,"hasPage":19},{"id":3735},"topic-public-breach",{"items":3737},[],"Public breach","public-breach","Public breaches are the disclosed incidents that show how attacks actually unfold once the headlines fade. Push’s breach analyses keep finding identity at the entry point: stolen credentials, OAuth abuse, and missing MFA recur across the incidents analyzed here.",30,{"sys":3743,"faqItemsCollection":3745,"name":3747,"slug":3748,"tier":45,"intro":3749,"faqTitle":60,"postCount":3750,"hasPage":19},{"id":3744},"topic-ransomware",{"items":3746},[],"Ransomware","ransomware","Ransomware attacks increasingly begin with an identity, not an exploit: stolen credentials, MFA bypass, and help desk scams give operators their initial foothold. The analysis here follows that front end of the kill chain — how identity compromise leads to ransomware deployment, and the breaches driving regulators toward tighter MFA requirements.",14,{"sys":3752,"faqItemsCollection":3754,"name":3756,"slug":3757,"tier":31,"intro":3758,"faqTitle":60,"postCount":3759,"hasPage":19},{"id":3753},"topic-saas-security",{"items":3755},[],"SaaS security","saas-security","SaaS security means protecting the sprawl of cloud apps, accounts, and integrations your employees adopt — often without IT ever knowing. Shadow SaaS, risky OAuth grants, ghost logins, and unmanaged third-party access create attack paths traditional controls can’t see, as recent high-profile breaches have demonstrated. Building on the original SaaS attack matrix, Push continues to map SaaS-native attack techniques alongside practical guides for discovering and securing unsanctioned apps, and this hub gathers all of it.",97,{"sys":3761,"faqItemsCollection":3763,"name":3765,"slug":3766,"tier":45,"intro":3767,"faqTitle":60,"postCount":3768,"hasPage":6},{"id":3762},"topic-security-training",{"items":3764},[],"Security training","security-training","Security training aims to teach employees to recognize and avoid attacks — yet modern phishing routinely fools even seasoned security professionals. Push argues that training budgets work harder as real-time, in-browser intervention: guardrails and warnings at the moment of risk, rather than lessons employees must recall under pressure.",4,{"sys":3770,"faqItemsCollection":3772,"name":3774,"slug":3775,"tier":45,"intro":3776,"faqTitle":60,"postCount":3777,"hasPage":19},{"id":3771},"topic-seo-poisoning",{"items":3773},[],"SEO poisoning","seo-poisoning","SEO poisoning manipulates search engine results so malicious pages rank prominently for the software, tools, or services users are actively searching for, turning a routine search into an infection vector. It often pairs with malvertising and ClickFix-style payloads — Push has documented attackers abusing shared pages on legitimate AI chatbot domains to deliver malware from trusted infrastructure.",8,{"sys":3779,"faqItemsCollection":3781,"name":304,"slug":3783,"tier":45,"intro":3784,"faqTitle":60,"postCount":3785,"hasPage":19},{"id":3780},"topic-session-hijacking",{"items":3782},[],"session-hijacking","Session hijacking is the theft of an authenticated session — usually via stolen session cookies or tokens — letting attackers walk past passwords and MFA into a live account. AiTM phishing kits and infostealers have made it a mainstream attack technique across both criminal and targeted intrusions. Push’s browser agent detects session token theft by adding telemetry to the user agent string, creating a high-fidelity signal for security teams.",76,{"sys":3787,"faqItemsCollection":3789,"name":3791,"slug":3792,"tier":45,"intro":3793,"faqTitle":60,"postCount":3794,"hasPage":19},{"id":3788},"topic-shadow-ai",{"items":3790},[],"Shadow AI","shadow-ai","Shadow AI is employees’ unsanctioned use of AI tools at work, putting corporate data into chatbots and assistants that security teams never approved and can’t see. Push’s own browser telemetry shows AI adoption acting as a force multiplier for shadow IT — potentially now outscaling shadow SaaS — and this hub tracks that research, real-world breach examples, and practical controls.",20,{"sys":3796,"faqItemsCollection":3798,"name":3800,"slug":3801,"tier":45,"intro":3802,"faqTitle":60,"postCount":3803,"hasPage":19},{"id":3797},"topic-shadow-saas",{"items":3799},[],"Shadow SaaS","shadow-saas","Shadow SaaS is the cloud applications employees adopt for work without IT approval, each one creating unmanaged accounts, identities, and data outside your security controls. Push covers the problem end to end — from browser-based SaaS discovery to in-browser app banners and MFA enforcement — alongside breach analyses that show where unmanaged accounts lead.",75,{"sys":3805,"faqItemsCollection":3807,"name":3809,"slug":3810,"tier":45,"intro":3811,"faqTitle":60,"postCount":3794,"hasPage":19},{"id":3806},"topic-siem",{"items":3808},[],"SIEM","siem","A SIEM is only as good as the telemetry feeding it, and most log sources never see what happens inside the browser — where phishing, session token theft, and account takeover actually play out. Push streams browser-level detections and identity telemetry into SIEMs, and these posts show how that data improves detection fidelity and cuts alert fatigue.",{"sys":3813,"faqItemsCollection":3814,"name":3449,"slug":3450,"tier":45,"intro":3816,"faqTitle":60,"postCount":3817,"hasPage":19},{"id":3448},{"items":3815},[],"Social engineering is the manipulation of people — through phishing pages, help desk impersonation, vishing calls, and poisoned tenant invites — into handing over access that no exploit could take. Coverage here tracks how threat actors run these plays — drawing on Push’s ongoing investigation of live phishing infrastructure and criminal tooling.",62,{"sys":3819,"faqItemsCollection":3821,"name":3823,"slug":3824,"tier":31,"intro":3825,"faqTitle":60,"postCount":3768,"hasPage":6},{"id":3820},"topic-supply-chain-security",{"items":3822},[],"Supply chain security","supply-chain-security","Supply chain security extends beyond your own perimeter to the vendors, platforms, and browser extensions your organization depends on. A compromised third party can hand attackers legitimate access — as recent campaigns against SaaS providers have shown. Push’s research examines the browser-extension supply chain in particular: why extension risk scores fail to predict compromise, and how developers can harden extensions against takeover. These posts frame supply chain risk through a browser and identity lens.",{"sys":3827,"faqItemsCollection":3829,"name":3831,"slug":3832,"tier":45,"intro":3833,"faqTitle":60,"postCount":3834,"hasPage":19},{"id":3828},"topic-swg",{"items":3830},[],"SWG","swg","A secure web gateway (SWG) filters and inspects web traffic in transit, sitting in the network path between users and the internet. That position shows you the packet but not the session: Push’s research on AitM phishing kits documents how attackers break the signatures proxies rely on, and these posts explain why phishing detection is moving from the network path into the browser itself.",18,{"sys":3836,"faqItemsCollection":3838,"name":3840,"slug":3841,"tier":45,"intro":3842,"faqTitle":60,"postCount":3843,"hasPage":19},{"id":3837},"topic-third-party-risk",{"items":3839},[],"Third-party risk","third-party-risk","Third-party risk is the exposure your organization inherits from vendors, SaaS providers, and integrations that hold your data or access your tenants — a chain now extended one employee sign-up at a time. This hub collects Push’s breach analyses and guides for assessing OAuth integrations, managing browser extensions, and responding when a supplier is compromised.",44,{"sys":3845,"faqItemsCollection":3847,"name":3849,"slug":3850,"tier":31,"intro":3851,"faqTitle":60,"postCount":3852,"hasPage":19},{"id":3846},"topic-threat-landscape",{"items":3848},[],"Threat landscape","threat-landscape","The enterprise threat landscape is now defined by identity attacks: criminals log in with phished, stolen, or stuffed credentials rather than breaking infrastructure. Threat actors keep proving how effective help desk scams, MFA bypass, and session theft are against well-defended organizations. Drawing on breach analyses, annual phishing trend reviews, and in-the-wild campaign tracking, Push documents how attacker TTPs are shifting. This hub is where to follow those changes.",50,{"sys":3854,"faqItemsCollection":3856,"name":3858,"slug":3859,"tier":45,"intro":3860,"faqTitle":60,"postCount":3861,"hasPage":19},{"id":3855},"topic-vishing",{"items":3857},[],"Vishing","vishing","Vishing — voice phishing — uses phone calls to impersonate IT support, help desks, or employees, talking targets into password resets, MFA approvals, or opening attacker-controlled pages. Threat actors now routinely pair calls with AiTM phishing to hijack SSO accounts, a chain Push has analyzed across campaigns targeting hundreds of organizations.",16,{},"blogtopics","qtNMnplEXowqr6wsMGgTGOB2ggNwhNDP5HHoUK1bdKc",1790667118031]