[{"data":1,"prerenderedAt":2317},["ShallowReactive",2],{"application-flags":3,"navbar":7,"always-visible-banner":35,"trust-badges":98,"solution-nav":119,"mega-nav":264,"fa-icon-solid-faDisplay":419,"fa-icon-solid-faFilter":422,"fa-icon-solid-faCloudArrowUp":424,"fa-icon-solid-faEnvelope":427,"fa-icon-sharp-regular-faUserSecret":429,"fa-icon-sharp-regular-faBrainCircuit":432,"fa-icon-sharp-regular-faShieldCheck":434,"fa-icon-sharp-regular-faRadar":436,"fa-icon-solid-faMobileScreenButton":438,"fa-icon-sharp-regular-faSatelliteDish":441,"fa-icon-brands-faChrome":443,"fa-icon-sharp-regular-faPenNib":445,"fa-icon-sharp-regular-faBooks":447,"fa-icon-sharp-regular-faBriefcase":449,"fa-icon-sharp-regular-faBookOpenCover":451,"fa-icon-sharp-regular-faBrowser":453,"fa-icon-sharp-regular-faBook":455,"fa-icon-sharp-regular-faGrid":457,"fa-icon-sharp-regular-faBuilding":459,"fa-icon-sharp-regular-faHandshakeSimple":461,"fa-icon-sharp-regular-faArrowTrendUp":463,"fa-icon-sharp-regular-faCalendarStar":465,"fa-icon-sharp-regular-faNewspaper":467,"fa-icon-sharp-regular-faUsers":469,"fa-icon-sharp-regular-faMessagesQuestion":471,"blog\u002Fthe-top-10-shadow-ai-discovery-and-governance-tools":473,"blog-topics":1927},[4],{"name":5,"enabled":6},"maintenanceMode",false,[8],{"createdDate":9,"id":10,"name":11,"modelId":12,"published":13,"meta":14,"query":20,"data":21,"variations":26,"lastUpdated":27,"firstPublished":28,"testRatio":29,"createdBy":30,"lastUpdatedBy":31,"folders":32,"lastUpdateSource":33,"stageModifiedSincePublish":6,"rev":34},1742208588866,"1c7a4e423bf54ac1a328bb4063459ef2","Banner","1c6207a5f24948ab82d4a0b17f251193","published",{"breakpoints":15,"hasAutosaves":6,"hasErrors":6,"kind":19},{"medium":16,"small":17,"xsmall":18},768,640,320,"data",[],{"link":22,"text":23,"type":24,"url":25},{},"Get the latest stats and analysis on browser-based attacks","web-banner","https:\u002F\u002Fpushsecurity.com\u002Fresources\u002Fbrowser-attacks",{},1790775413052,1742208637545,1,"CydmZnOWU1XuAaLhEDCoYNM4Z8W2","jKjF9r5jcvXU8tzZEfFQm31Iyvr2",[],null,"on6p1q4p98",{"createdBy":36,"createdDate":37,"data":38,"folders":86,"id":87,"lastUpdated":88,"lastUpdatedBy":36,"meta":89,"modelId":92,"name":93,"published":13,"query":94,"testRatio":29,"variations":95,"firstPublished":96,"stageModifiedSincePublish":6,"lastUpdateSource":33,"rev":97},"ST0tXQM8slWpFrmioqKHmENB2qe2",1774965361051,{"ctaText":39,"text":40,"url":41,"blocks":42,"state":82},"ewrererw","testrfesssssssssss","",[43,71],{"@type":44,"@version":45,"id":46,"component":47,"responsiveStyles":61},"@builder.io\u002Fsdk:Element",2,"builder-ca12c06a52de41d7b8743da53118cd38",{"name":48,"tag":48,"options":49,"isRSC":33},"TopBannerContent",{"text":50,"ctaText":51,"url":52,"mainText":53,"cta":56,"styleVariant":59,"showMonsters":60},"New Webinar Series: Join John Hammond, Troy Hunt, and Matt Johansen for the State of Browser Attacks","Save Your Spot","https:\u002F\u002Fpushsecurity.com\u002Fwebinar\u002Fstate-of-browser-security",{"content":54,"fontSize":55},"\u003Cp class=\"\">Shadow AI monsters are lurking in the dark! Bust them all in our retro-inspired arcade game.\u003C\u002Fp>","text-base",{"content":57,"fontSize":55,"url":58},"\u003Cp class=\"\">Press start &gt;&gt;\u003C\u002Fp>","https:\u002F\u002Fpushsecurity.com\u002Flp\u002Fshadow-ai-busters","arcade",true,{"large":62},{"display":63,"flexDirection":64,"position":65,"flexShrink":66,"boxSizing":67,"marginTop":68,"marginBottom":68,"fontSize":69,"fontWeight":70},"flex","column","relative","0","border-box",".56rem","1.125rem","700",{"id":72,"@type":44,"tagName":73,"properties":74,"responsiveStyles":77},"builder-pixel-hwfp3plvehv","img",{"src":75,"aria-hidden":76,"alt":41,"width":66,"height":66},"https:\u002F\u002Fcdn.builder.io\u002Fapi\u002Fv1\u002Fpixel?apiKey=f3a1111ff5be48cdbb123cd9f5795a05","true",{"large":78},{"height":66,"width":66,"display":79,"opacity":66,"overflow":80,"pointerEvents":81},"block","hidden","none",{"deviceSize":83,"location":84},"large",{"path":41,"query":85},{},[],"fd266d0172cc47429be7ad10f48c99ad",1789552629325,{"breakpoints":90,"hasAutosaves":60,"hasErrors":6,"hasLinks":6,"kind":91},{"medium":16,"small":17,"xsmall":18},"component","0678d178ec8b41efb8a23c09dba7874d","always visible banner",[],{},1774968080803,"j4297y5gebo",[99,103,107,111,115],{"title":100,"logo":101,"createdDate":102},"SOC2","https:\u002F\u002Fcdn.builder.io\u002Fapi\u002Fv1\u002Fimage\u002Fassets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fb6727a5e00004d6e9e69fc3068b8b64c",1784291539953,{"title":104,"logo":105,"createdDate":106},"GDPR","https:\u002F\u002Fcdn.builder.io\u002Fapi\u002Fv1\u002Fimage\u002Fassets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Ffe49f53211674deaa5a6640d929cdf42?format=webp",1784291672535,{"title":108,"logo":109,"createdDate":110},"Cyber essentials","https:\u002F\u002Fcdn.builder.io\u002Fapi\u002Fv1\u002Fimage\u002Fassets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F53558c1045a342a7a28def960cd54ae7?format=webp",1784291702710,{"title":112,"logo":113,"createdDate":114},"ISO IEC 27001","https:\u002F\u002Fcdn.builder.io\u002Fapi\u002Fv1\u002Fimage\u002Fassets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F578a404a61cf45db951a41fe3554d12d",1784291766222,{"title":116,"logo":117,"createdDate":118},"ISO IEC 27701","https:\u002F\u002Fcdn.builder.io\u002Fapi\u002Fv1\u002Fimage\u002Fassets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fbe219844b13242fbba531959579a753c",1784291858848,[120,189,234],{"id":121,"label":122,"text":41,"navIcon":123,"items":124},"stop-browser-based-attacks","Stop browser-based attacks","solid:faShieldHalved",[125,130,135,140,145,150,155,160,165,169,174,179,184],{"title":126,"text":127,"url":128,"navIcon":129},"Phishing","Detect phishing behaviorally in the browser, regardless of the payload or delivery channel.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fzero-day-phishing","sharp-regular:faFishingRod",{"title":131,"text":132,"url":133,"navIcon":134},"Adversary-in-the-Middle","Detect and block MFA-bypassing AiTM phishing pages in real-time.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fadversary-in-the-middle-attacks","solid:faUserSecret",{"title":136,"text":137,"url":138,"navIcon":139},"ClickFix (and variants)","Intercept malicious copy and paste attacks at the point of interaction.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fclickfix-fix-variants","sharp-regular:faLaptopCode",{"title":141,"text":142,"url":143,"navIcon":144},"Device code phishing","Detect and block device code phishing kits designed to get around passkeys.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fdevice-code-phishing","solid:faTabletScreenButton",{"title":146,"text":147,"url":148,"navIcon":149},"Consent phishing","Detect and block malicious OAuth consent grants before access is authorized.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fconsent-phishing","solid:faThumbsUp",{"title":151,"text":152,"url":153,"navIcon":154},"Malicious OAuth integrations","Detect and block the root cause of SaaS supply chain attacks.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fmalicious-oauth-integrations","solid:faPlugCircleXmark",{"title":156,"text":157,"url":158,"navIcon":159},"Malicious browser extensions","Inventory, monitor, and block risky browser extensions.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fmalicious-browser-extensions","sharp-regular:faPuzzlePiece",{"title":161,"text":162,"url":163,"navIcon":164},"Malicious file downloads","Control which files users can download by type, source, and user group.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fmalicious-file-downloads","solid:faFileCircleXmark",{"title":166,"text":167,"url":168,"navIcon":164},"Infostealers","Detect infostealer delivery and respond to a compromise.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Finfostealer-malware",{"title":170,"text":171,"url":172,"navIcon":173},"Ghost logins","Surface hidden login paths that bypass SSO and expose accounts.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fghost-logins","solid:faGhost",{"title":175,"text":176,"url":177,"navIcon":178},"Mobile phishing (QR & SMS)","Detect phishing regardless of whether it arrives via email, SMS, or QR code.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fmobile-phishing-qr-code-sms","solid:faQrcode",{"title":180,"text":181,"url":182,"navIcon":183},"Credential stuffing","Identify reused and compromised credentials across SaaS logins.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fcredential-stuffing","custom:credentialStuffing",{"title":185,"text":186,"url":187,"navIcon":188},"Session hijacking","Detect and respond to stolen session token replay with browser session markers.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fsession-hijacking","solid:faCookieBite",{"id":190,"label":191,"text":41,"navIcon":192,"items":193},"achieve-security-outcomes","Achieve security outcomes","solid:faCheckToSlot",[194,199,204,209,214,219,224,229],{"title":195,"text":196,"url":197,"navIcon":198},"Stop account takeover","Stop ATO with stolen credential and compromised token detection","\u002Fsolution\u002Fachieve-security-outcomes\u002Fstop-account-takeover","sharp-regular:faUserSecret",{"title":200,"text":201,"url":202,"navIcon":203},"Harden unmanaged identities","Harden access paths with visibility, detection, and guardrails","\u002Fsolution\u002Fachieve-security-outcomes\u002Fharden-unmanaged-identities","sharp-regular:faRadar",{"title":205,"text":206,"url":207,"navIcon":208},"Investigate browser-related incidents","Investigate and respond faster with unique browser telemetry","\u002Fsolution\u002Fachieve-security-outcomes\u002Finvestigate-browser-related-incidents","sharp-regular:faSatelliteDish",{"title":210,"text":211,"url":212,"navIcon":213},"Secure shadow IT","See and control shadow SaaS in the browser","\u002Fsolution\u002Fachieve-security-outcomes\u002Fsecure-shadow-saas","sharp-regular:faShieldCheck",{"title":215,"text":216,"url":217,"navIcon":218},"Secure AI","See and control AI apps in the browser","\u002Fsolution\u002Fachieve-security-outcomes\u002Fsecure-ai","sharp-regular:faBrainCircuit",{"title":220,"text":221,"url":222,"navIcon":223},"Secure BYOD","Extend security to unmanaged devices without MDM","\u002Fsolution\u002Fachieve-security-outcomes\u002Fsecure-bring-your-own-device","solid:faMobileScreenButton",{"title":225,"text":226,"url":227,"navIcon":228},"Secure Chromebooks","Protect Chromebooks against in-browser attacks","\u002Fsolution\u002Fachieve-security-outcomes\u002Fsecure-chromebooks","brands:faChrome",{"title":230,"text":231,"url":232,"navIcon":233},"Data loss prevention","Enforce DLP at the point of interaction in the browser","\u002Fsolution\u002Fachieve-security-outcomes\u002Finvestigate-and-stop-data-loss","custom:investigateAndStopDataLoss",{"id":235,"label":236,"text":41,"navIcon":237,"items":238},"tool-replacements","Tool replacements","solid:faScrewdriverWrench",[239,244,249,254,259],{"title":240,"text":241,"url":242,"navIcon":243},"Email Security","Stop phishing outside of the inbox.","\u002Fsolution\u002Ftool-replacements\u002Femail-security","faEnvelope",{"title":245,"text":246,"url":247,"navIcon":248},"Remote browser isolation","Detect attacks that happen inside the browser session.","\u002Fsolution\u002Ftool-replacements\u002Fremote-browser-isolation","solid:faDisplay",{"title":250,"text":251,"url":252,"navIcon":253},"Secure web gateways","Detect attacks inside the browser after SWGs allowed the connection.","\u002Fsolution\u002Ftool-replacements\u002Fsecure-web-gateways","solid:faFilter",{"title":255,"text":256,"url":257,"navIcon":258},"CASB alternative","Catch browser-based identity threats in real time, not after the fact.","\u002Fsolution\u002Ftool-replacements\u002Fcloud-access-security-broker","solid:faCloudArrowUp",{"title":260,"text":261,"url":262,"navIcon":263},"Security awareness training","Block real phishing instead of training users on simulations.","\u002Fsolution\u002Ftool-replacements\u002Fsecurity-awareness-training","custom:securityAwareness",[265,293,354],{"id":266,"columns":267},"Solution",[268,283],{"kind":269,"heading":270,"span":29,"links":271},"links","Compare Push",[272,275,277,279,281],{"title":273,"url":247,"text":246,"navIcon":248,"variant":274},"vs Remote Browser Isolation","compact",{"title":276,"url":252,"text":251,"navIcon":253,"variant":274},"vs Secure Web Gateways",{"title":278,"url":257,"text":256,"navIcon":258,"variant":274},"vs Cloud Access Security Broker",{"title":280,"url":262,"text":261,"navIcon":263,"variant":274},"vs Security Awareness Training",{"title":282,"url":242,"text":241,"navIcon":243,"variant":274},"+ Email Security",{"kind":269,"heading":266,"span":45,"links":284},[285,286,287,288,289,290,291,292],{"title":195,"url":197,"text":196,"navIcon":198},{"title":215,"url":217,"text":216,"navIcon":218},{"title":230,"url":232,"text":231,"navIcon":233},{"title":210,"url":212,"text":211,"navIcon":213},{"title":200,"url":202,"text":201,"navIcon":203},{"title":220,"url":222,"text":221,"navIcon":223},{"title":205,"url":207,"text":206,"navIcon":208},{"title":225,"url":227,"text":226,"navIcon":228},{"id":294,"columns":295},"resources",[296,321,339],{"kind":269,"heading":297,"span":29,"links":298},"Resources",[299,306,311,316],{"title":300,"url":301,"text":302,"navIcon":303,"variant":304,"badge":305},"Research blog","\u002Fblog","Latest threat research and insights","sharp-regular:faPenNib","featured","Latest",{"title":307,"url":308,"text":309,"navIcon":310},"Resource library","\u002Fresources","Check out our webinars and downloads","sharp-regular:faBooks",{"title":312,"url":313,"text":314,"navIcon":315},"Customer stories","\u002Fcustomer-stories","What customers love about Push","sharp-regular:faBriefcase",{"title":317,"url":318,"text":319,"navIcon":320},"Help center","\u002Fhelp\u002Faudience\u002Fadministrators","Guides for employees and admins","sharp-regular:faBookOpenCover",{"kind":269,"heading":322,"span":29,"links":323},"Learn",[324,329,334],{"title":325,"url":326,"text":327,"navIcon":328},"Browser attacks in 2026","\u002Fresources\u002Fbrowser-attacks","The latest stats & analysis","sharp-regular:faBrowser",{"title":330,"url":331,"text":332,"navIcon":333},"Browser attacks glossary","\u002Fresources\u002Fbrowser-attacks-glossary","Understand the threat landscape","sharp-regular:faBook",{"title":335,"url":336,"text":337,"navIcon":338},"Browser attacks matrix","\u002Fresources\u002Fbrowser-identity-attacks-matrix","MITRE-inspired resource for red & blue teams","sharp-regular:faGrid",{"kind":294,"heading":340,"cards":341},"Latest resources",[342,348],{"title":343,"description":344,"cta":345,"background":347},"Browser-based attacks: the 2026 threat landscape","Half of attacks now reach victims outside of email. ClickFix is now the dominant browser attack technique. Get the latest stats and analysis from the Push Security team.",{"text":346,"url":326},"Read the report","orange",{"title":349,"description":350,"cta":351,"background":353},"The browser & identity attacks matrix","Check out the MITRE-inspired matrix of browser & identity attack techniques for red and blue teams. Get involved on GitHub.",{"text":352,"url":336},"Explore the matrix","black",{"id":355,"columns":356},"About",[357,375,398],{"kind":269,"heading":358,"span":29,"links":359},"Get to know us",[360,365,370],{"title":361,"url":362,"text":363,"navIcon":364},"About us","\u002Fabout","Meet the team and learn what drives us","sharp-regular:faBuilding",{"title":366,"url":367,"text":368,"navIcon":369},"Partners","\u002Fpartner","Become a partner and access resources","sharp-regular:faHandshakeSimple",{"title":371,"url":372,"text":373,"navIcon":374},"Investors","\u002Fabout#investors","Learn more about our investors and advisors","sharp-regular:faArrowTrendUp",{"kind":269,"heading":376,"span":29,"links":377},"Keep up with us",[378,383,388,393],{"title":379,"url":380,"text":381,"navIcon":382},"Events","\u002Fevents","See upcoming webinars and in-person events","sharp-regular:faCalendarStar",{"title":384,"url":385,"text":386,"navIcon":387},"News","\u002Fnews","Stay up to date on company news","sharp-regular:faNewspaper",{"title":389,"url":390,"text":391,"navIcon":392},"Careers","\u002Fcareers","Explore open roles","sharp-regular:faUsers",{"title":394,"url":395,"text":396,"navIcon":397},"Contact us","\u002Fcontact","Have a question? We're here to help","sharp-regular:faMessagesQuestion",{"kind":399,"heading":400,"testimonials":401},"testimonials","What customers say",[402,409,414],{"quote":403,"author":404,"jobTitle":405,"image":406,"url":313,"ctaText":407,"background":408},"Security is only as good as its weakest link. From day one, Push found the gaps that would allow attackers to circumvent our controls. We use Push every day — they're one of my favourite teams to work with.","Jason Waits","\u003Cp>CISO, Inductive Automation\u003C\u002Fp>","https:\u002F\u002Fcdn.builder.io\u002Fapi\u002Fv1\u002Fimage\u002Fassets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Ff04c0c0689ce4a89ac0f0708d78c0a07","Read the customer story","white",{"quote":410,"author":411,"jobTitle":412,"image":413,"url":313,"ctaText":407,"background":408},"I'm not going to be able to shove a browser on everybody. I need to be able to support them where they are. Push gave us the visibility and control we needed while allowing people to choose their paths.","Myke Lyons","\u003Cp>CISO, Cribl\u003C\u002Fp>","https:\u002F\u002Fcdn.builder.io\u002Fapi\u002Fv1\u002Fimage\u002Fassets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F61920ec05c7a45b4b2259b8dded43c9b",{"quote":415,"author":416,"jobTitle":417,"image":418,"url":313,"ctaText":407,"background":408},"No matter the channel for phishing — email, LinkedIn, text — the employee clicks a link that opens a browser session. We see the main control point moving from the endpoint to the browser.","Ash Devata","\u003Cp>CEO, GreyNoise\u003C\u002Fp>","https:\u002F\u002Fcdn.builder.io\u002Fapi\u002Fv1\u002Fimage\u002Fassets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F392c75ae282342008130cf1147c20e82",{"w":420,"h":420,"d":421},512,"M448 96l0 256-384 0 0-256 384 0zM64 32C28.7 32 0 60.7 0 96L0 352c0 35.3 28.7 64 64 64l144 0-16 48-72 0c-13.3 0-24 10.7-24 24s10.7 24 24 24l272 0c13.3 0 24-10.7 24-24s-10.7-24-24-24l-72 0-16-48 144 0c35.3 0 64-28.7 64-64l0-256c0-35.3-28.7-64-64-64L64 32z",{"w":420,"h":420,"d":423},"M32 64C19.1 64 7.4 71.8 2.4 83.8S.2 109.5 9.4 118.6L192 301.3 192 416c0 8.5 3.4 16.6 9.4 22.6l64 64c9.2 9.2 22.9 11.9 34.9 6.9S320 492.9 320 480l0-178.7 182.6-182.6c9.2-9.2 11.9-22.9 6.9-34.9S492.9 64 480 64L32 64z",{"w":425,"h":420,"d":426},576,"M144 480c-79.5 0-144-64.5-144-144 0-63.4 41-117.2 97.9-136.5-1.3-7.7-1.9-15.5-1.9-23.5 0-79.5 64.5-144 144-144 55.4 0 103.5 31.3 127.6 77.1 14.2-8.3 30.8-13.1 48.4-13.1 53 0 96 43 96 96 0 15.7-3.8 30.6-10.5 43.7 44 20.3 74.5 64.7 74.5 116.3 0 70.7-57.3 128-128 128l-304 0zM305 191c-9.4-9.4-24.6-9.4-33.9 0l-72 72c-9.4 9.4-9.4 24.6 0 33.9s24.6 9.4 33.9 0l31-31 0 102.1c0 13.3 10.7 24 24 24s24-10.7 24-24l0-102.1 31 31c9.4 9.4 24.6 9.4 33.9 0s9.4-24.6 0-33.9l-72-72z",{"w":420,"h":420,"d":428},"M48 64c-26.5 0-48 21.5-48 48 0 15.1 7.1 29.3 19.2 38.4l208 156c17.1 12.8 40.5 12.8 57.6 0l208-156c12.1-9.1 19.2-23.3 19.2-38.4 0-26.5-21.5-48-48-48L48 64zM0 196L0 384c0 35.3 28.7 64 64 64l384 0c35.3 0 64-28.7 64-64l0-188-198.4 148.8c-34.1 25.6-81.1 25.6-115.2 0L0 196z",{"w":430,"h":420,"d":431},448,"M144-16l-48 112-48 0 0 48 48 0 0 32c0 17 3.3 33.2 9.3 48l-73.3 0 0 32 5.3 16 26.7 80-64 160 51.7 0 56.9-142.2 6.5-16.3c-1-3.1-10.1-30.3-27.2-81.5l51.4 0c22.6 19.9 52.2 32 84.7 32s62.1-12.1 84.7-32l51.4 0c-17.1 51.2-26.1 78.4-27.2 81.5l6.5 16.3 56.9 142.2 51.7 0-64-160 26.7-80 5.3-16 0-32-73.3 0c6-14.8 9.3-31 9.3-48l0-32 48 0 0-48-48 0-48-112-32 0-48 32-48-32-32 0zm80 272c-32.8 0-61-19.7-73.3-48l57.3 0 16-40 16 40 57.3 0c-12.3 28.3-40.5 48-73.3 48zm17.5 139.6l30.5-35.6 0-24-96 0 0 24 30.5 35.6-46.5 116.4 128 0-46.5-116.4z",{"w":420,"h":420,"d":433},"M192 48l40 0 0 108-12.4 0c-7.6-16.5-24.3-28-43.6-28-26.5 0-48 21.5-48 48s21.5 48 48 48c19.4 0 36.1-11.5 43.6-28l12.4 0 0 56-92 0 0 56.4c-16.5 7.6-28 24.3-28 43.6 0 26.5 21.5 48 48 48s48-21.5 48-48c0-19.4-11.5-36.1-28-43.6l0-16.4 52 0 0 172-40 0c-16.8 0-31.2-10.3-37.1-25.1l-6.4-16-17.2 1c-1.1 .1-2.2 .1-3.2 .1-30.9 0-56-25.1-56-56 0-9.5 2.4-18.5 6.5-26.3l8.7-16.2-13.4-12.6c-11-10.2-17.8-24.8-17.8-40.9 0-21.6 12.2-40.4 30.3-49.8l22.6-11.7-13.1-21.9c-5-8.4-7.9-18.1-7.9-28.6 0-30.9 25.1-56 56-56l24 0 0-32c0-13.3 10.7-24 24-24zm88 148l12.4 0c7.6 16.5 24.3 28 43.6 28 26.5 0 48-21.5 48-48s-21.5-48-48-48c-19.4 0-36.1 11.5-43.6 28l-12.4 0 0-108 40 0c13.3 0 24 10.7 24 24l0 32 24 0c30.9 0 56 25.1 56 56 0 10.5-2.9 20.3-7.9 28.6l-13.1 21.9 22.6 11.7c18 9.3 30.3 28.1 30.3 49.8 0 16.1-6.8 30.7-17.8 40.9l-13.4 12.6 8.7 16.2c4.2 7.8 6.5 16.7 6.5 26.3 0 30.9-25.1 56-56 56-1.1 0-2.2 0-3.2-.1l-17.2-1-6.4 16C351.2 453.7 336.8 464 320 464l-40 0 0-76 92 0 0-56.4c16.5-7.6 28-24.3 28-43.6 0-26.5-21.5-48-48-48s-48 21.5-48 48c0 19.4 11.5 36.1 28 43.6l0 16.4-52 0 0-152zM192 512l128 0c31.1 0 58.4-16.2 74.1-40.5 52.7-5.1 93.9-49.5 93.9-103.5 0-11.5-1.9-22.5-5.3-32.9 13.4-17.5 21.3-39.4 21.3-63.1 0-32-14.5-60.6-37.1-79.7 3.3-10.2 5.1-21.1 5.1-32.3 0-49.6-34.8-91.1-81.3-101.5-6.3-33.3-35.6-58.5-70.7-58.5L192 0c-35.1 0-64.4 25.2-70.7 58.5-46.5 10.4-81.3 51.9-81.3 101.5 0 11.3 1.8 22.2 5.1 32.3-22.7 19.1-37.1 47.7-37.1 79.7 0 23.7 8 45.6 21.3 63.1-3.5 10.4-5.3 21.4-5.3 32.9 0 54 41.2 98.5 93.9 103.5 15.6 24.3 42.9 40.5 74.1 40.5zM336 192a16 16 0 1 1 0-32 16 16 0 1 1 0 32zm32 96a16 16 0 1 1 -32 0 16 16 0 1 1 32 0zM176 352a16 16 0 1 1 -32 0 16 16 0 1 1 32 0zm16-176a16 16 0 1 1 -32 0 16 16 0 1 1 32 0z",{"w":420,"h":420,"d":435},"M267.6 4.5l207.5 80.5 19.2 7.4 1.2 20.5c2.9 50-4.9 126.3-37.3 200.9-32.7 75.2-91.1 150-189.4 192.5l-12.7 5.5-12.7-5.5C144.9 463.9 86.6 389.2 53.9 313.9 21.5 239.3 13.7 162.9 16.6 113L17.8 92.5 37 85 244.5 4.5 256 0 267.6 4.5zM64.1 126C63.1 169.5 71 232.9 97.9 294.8 126.1 359.7 175 422.4 256 459.6 337.1 422.4 385.9 359.7 414.2 294.8 441 232.9 449 169.5 448 126L256 51.5 64.1 126zm302.3 44.7L352.3 190.1 249.8 330.9 233 354c-8.8-9.1-30.9-32-66.2-68.6l-16.7-17.3 34.5-33.3c9.5 9.8 23.9 24.7 43.2 44.7l85.6-117.7 14.1-19.4 38.8 28.2z",{"w":420,"h":420,"d":437},"M497.4 49l17-17-33.9-33.9C473.6 4.9 453.3 25.2 419.7 58.8 375.4 22.1 318.5 0 256.4 0 115.1 0 .4 114.6 .4 256s114.6 256 256 256 256-114.6 256-256l-48 0c0 114.9-93.1 208-208 208s-208-93.1-208-208 93.1-208 208-208c48.8 0 93.7 16.8 129.1 44.9l-45.7 45.7c-23.5-16.8-52.3-26.6-83.4-26.6-79.5 0-144 64.5-144 144s64.5 144 144 144 144-64.5 144-144l-48 0c0 53-43 96-96 96s-96-43-96-96 43-96 96-96c17.8 0 34.5 4.8 48.8 13.3-52 52-79.5 79.5-82.7 82.7l33.9 33.9 17-17 224-224z",{"w":439,"h":420,"d":440},384,"M16 64C16 28.7 44.7 0 80 0L304 0c35.3 0 64 28.7 64 64l0 384c0 35.3-28.7 64-64 64L80 512c-35.3 0-64-28.7-64-64L16 64zm64 0l0 304 224 0 0-304-224 0zM192 472c17.7 0 32-14.3 32-32s-14.3-32-32-32-32 14.3-32 32 14.3 32 32 32z",{"w":420,"h":420,"d":442},"M208 0l24 0C386.6 0 512 125.4 512 280l0 24-48 0 0-24C464 151.9 360.1 48 232 48l-24 0 0-48zm24 96c101.6 0 184 82.4 184 184l0 24-48 0 0-24c0-75.1-60.9-136-136-136l-24 0 0-48 24 0zM48 256c0 114.9 93.1 208 208 208 22.9 0 45-3.7 65.6-10.5l-263-263C51.7 211 48 233.1 48 256zM0 256c0-36.5 7.6-71.3 21.4-102.7 6.7-15.3 14.9-29.9 24.4-43.5 7.7 7.7 61.5 61.5 161.2 161.2 30.5-30.5 49.5-49.5 57-57L297.9 248c-7.5 7.5-26.5 26.5-57 57 99.7 99.7 153.5 153.5 161.2 161.2-13.6 9.5-28.2 17.7-43.5 24.4-31.4 13.8-66.2 21.4-102.7 21.4-141.4 0-256-114.6-256-256z",{"w":420,"h":420,"d":444},"M0 256c0-46.6 12.5-90.4 34.3-128.9L144.1 318.3c21.9 39.2 63.8 65.7 111.9 65.7 14.3 0 27.1-2.3 40.8-6.6L220.5 509.6C95.9 492.3 0 385.3 0 256zm365.1 65.6c12.3-19.2 18.9-42.5 18.9-65.6 0-38.2-16.8-72.5-43.3-96l152.7 0c12 29.6 18.6 62.1 18.6 96 0 141.4-114.6 255.1-256 256L365.1 321.6zM477.8 128L256 128c-62.9 0-113.7 44.1-125.5 102.7L54.2 98.5C101 38.5 174 0 256 0 350.8 0 433.5 51.5 477.8 128zM344 256a88 88 0 1 1 -176 0 88 88 0 1 1 176 0z",{"w":425,"h":420,"d":446},"M406.1 198.1l0 0-3.6 10.7-56.3 168.8-221.5 69.9 98.5-98.5c5.2 1.9 10.8 3 16.7 3 26.5 0 48-21.5 48-48s-21.5-48-48-48-48 21.5-48 48c0 5.9 1.1 11.5 3 16.7l-98.5 98.5 69.9-221.5 168.8-56.3 10.8-3.6 0 0 60.1 60.1zM80 512l304-96 64-192c59.4-59.4 96.7-96.7 112-112-18.3-18.3-49.6-49.6-94.1-94.1L432-16C416.7-.7 379.4 36.6 320 96l-192 64-96 304 48 48z",{"w":425,"h":420,"d":448},"M404.8 45.3l12.4 46.4-77.3 20.7-12.4-46.4 77.3-20.7zm5.5 329.8l-58-216.4 77.3-20.7 58 216.4-77.3 20.7zm12.4 46.4l77.3-20.7 12.4 46.4-77.3 20.7-12.4-46.4zM315.1 19.6l-46.4 12.4 8.6 32-69.2 0 0-64-176 0 0 512 304 0 0-228.4c41.8 156.2 63.5 237.1 65.1 243 64.4-17.3 167.4-44.9 170-45.6l-12.4-46.4-107.7-401.8-12.4-46.4C413-6.6 371.7 4.4 315.1 19.6zM208.1 464l0-352 80 0 0 352-80 0zm-48-400l0 32-80 0 0-48 80 0 0 16zm0 80l0 224-80 0 0-224 80 0zm0 272l0 48-80 0 0-48 80 0z",{"w":420,"h":420,"d":450},"M168 0l-24 0 0 96-144 0 0 384 512 0 0-384-144 0 0-96-200 0zM464 256l-416 0 0-112 416 0 0 112zM320 304l144 0 0 128-416 0 0-128 144 0 0 48 128 0 0-48zm0-208l-128 0 0-48 128 0 0 48z",{"w":425,"h":420,"d":452},"M312 114.4l0 282.1 9.2-3.3C367.8 376.5 417 368 466.5 368l61.5 0 0-288-61.5 0c-38.5 0-76.7 6.6-113 19.6L312 114.4zM264 396.5l0-282.1-41.5-14.8C186.2 86.6 148 80 109.5 80l-61.5 0 0 288 61.5 0c49.5 0 98.7 8.5 145.3 25.2l9.2 3.3zM528 32l48 0 0 384-109.5 0c-44 0-87.7 7.6-129.2 22.4L288 456 238.6 438.4C197.2 423.6 153.5 416 109.5 416L0 416 0 32 109.5 32c44 0 87.7 7.6 129.2 22.4L288 72 337.4 54.4C378.8 39.6 422.5 32 466.5 32L528 32zM0 464l91.7 0c36.9 0 73.6 5 109.2 14.9l86.2 24 42.2-15.1c44-15.7 90.5-23.8 137.2-23.8l109.5 0 0 48-109.5 0c-41.3 0-82.2 7.1-121.1 21l-49.4 17.6-7.2 2.6-7.3-2-93.6-26c-31.4-8.7-63.8-13.1-96.4-13.1L0 512 0 464z",{"w":420,"h":420,"d":454},"M48 256l0 144 416 0 0-144-416 0zM0 64l512 0 0 384-512 0 0-384zm64 64l0 64 64 0 0-64-64 0zm120 8l-24 0 0 48 288 0 0-48-264 0z",{"w":430,"h":420,"d":456},"M24 0L0 0 0 432 .4 432c-.2 2.6-.4 5.3-.4 8l0 72 448 0 0-48-32 0 0-64 32 0 0-400-424 0zM368 400l0 64-320 0 0-24c0-22.1 17.9-40 40-40l280 0zM88 352c-14.4 0-28 3.5-40 9.6l0-313.6 352 0 0 304-312 0zm40-224l0 48 224 0 0-48-224 0zm224 96l-224 0 0 48 224 0 0-48z",{"w":420,"h":420,"d":458},"M112 64l0 48-48 0 0-48 48 0zM64 24l-40 0 0 128 128 0 0-128-88 0zm48 208l0 48-48 0 0-48 48 0zM64 192l-40 0 0 128 128 0 0-128-88 0zm0 208l48 0 0 48-48 0 0-48zM24 360l0 128 128 0 0-128-128 0zM280 64l0 48-48 0 0-48 48 0zM232 24l-40 0 0 128 128 0 0-128-88 0zm0 208l48 0 0 48-48 0 0-48zm-40-40l0 128 128 0 0-128-128 0zm88 208l0 48-48 0 0-48 48 0zm-48-40l-40 0 0 128 128 0 0-128-88 0zM400 64l48 0 0 48-48 0 0-48zM360 24l0 128 128 0 0-128-128 0zm88 208l0 48-48 0 0-48 48 0zm-48-40l-40 0 0 128 128 0 0-128-88 0zm0 208l48 0 0 48-48 0 0-48zm-40-40l0 128 128 0 0-128-128 0z",{"w":439,"h":420,"d":460},"M48 48l0 416 96 0 0-112 96 0 0 112 96 0 0-416-288 0zM0 0L384 0 384 512 0 512 0 0zM96 96l64 0 0 64-64 0 0-64zm192 0l0 64-64 0 0-64 64 0zM96 224l64 0 0 64-64 0 0-64zm192 0l0 64-64 0 0-64 64 0z",{"w":17,"h":420,"d":462},"M598.6 75.4L618 61.3 589.7 22.5C586 25.2 554.7 48 495.8 90.8l-34.1-22.7-6-4-145.2 0 0 0-144 0c-2.9 2.9-11.1 11.1-24.5 24.5-56.3-40.9-86.6-62.9-90.8-66.1L22.9 61.3c1.5 1.1 37.3 27.1 107.4 78.1l16.6 12.1c7.9-7.9 21.1-21.1 39.5-39.5l76.1 0-103 103-17 17c12.1 12.1 21.8 21.8 29.1 29.1 46.9 46.9 122.8 46.9 169.7 0L368.4 233.9 494.5 360c-16.7 16.7-29.4 29.4-38.1 38.1l-47-47-33.9 33.9 47 47-16 16-44.1 0-65-65-33.9 33.9 31 31-60.1 0-169-169-17-17-33.9 33.9 17 17 176 176 7 7 128 0 1 1 1-1 81.9 0 7-7c225.8-225.8 167.2-167.2 193-193l-33.9-33.9-64 64-143-143-17-17c-6.8 6.8-27.2 27.2-61.1 61.1-26.5 26.5-68.5 28-96.7 4.6l119.8-119.8 62.1 0 0 0 48.7 0c32.6 21.8 51.3 34.2 55.9 37.2l13.5-9.8 88-64z",{"w":425,"h":420,"d":464},"M352 96l224 0 0 224-48 0 0-142.1-191 191-17 17-17-17-111-111-139.8 139.8-17 17-33.9-33.9 17-17 156.8-156.8 17-17 17 17 111 111 174.1-174.1-142.1 0 0-48z",{"w":430,"h":420,"d":466},"M144 0l0 64 160 0 0-64 48 0 0 64 96 0 0 416-448 0 0-416 96 0 0-64 48 0zm0 112l-96 0 0 320 352 0 0-320-256 0zM261.6 228.2l84.1 12.2-60.9 59.3 14.4 83.8-75.2-39.6-75.2 39.6 14.4-83.8-60.9-59.3 84.1-12.2 37.6-76.2 37.6 76.2z",{"w":420,"h":420,"d":468},"M96 32l416 0 0 448-512 0 0-392 48 0 0 344 8 0c22.1 0 40-17.9 40-40L96 32zm38.4 400l329.6 0 0-352-320 0 0 312c0 14.4-3.5 28-9.6 40zM192 128l96 0 0 96-96 0 0-96zm152 48l72 0 0 48-96 0 0-48 24 0zM216 256l200 0 0 48-224 0 0-48 24 0zm0 80l200 0 0 48-224 0 0-48 24 0z",{"w":17,"h":420,"d":470},"M384 128a64 64 0 1 0 -128 0 64 64 0 1 0 128 0zm-176 0a112 112 0 1 1 224 0 112 112 0 1 1 -224 0zm252.8 76c5.9 2.6 12.4 4 19.2 4 26.5 0 48-21.5 48-48s-21.5-48-48-48l-.8 0c-1.6-16.6-5.8-32.4-12.1-47.1 4.2-.6 8.6-.9 12.9-.9 53 0 96 43 96 96s-43 96-96 96c-17.7 0-34.3-4.8-48.6-13.2 11.7-11.3 21.6-24.4 29.4-38.8zM208.6 242.8c-14.2 8.4-30.8 13.2-48.6 13.2-53 0-96-43-96-96s43-96 96-96c4.4 0 8.7 .3 12.9 .9-6.3 14.7-10.5 30.6-12.1 47.1l-.8 0c-26.5 0-48 21.5-48 48s21.5 48 48 48c6.8 0 13.3-1.4 19.2-4 7.8 14.4 17.7 27.5 29.4 38.8zM432 288l69.8 192-51.1 0-52.4-144-156.8 0-52.4 144-51.1 0 69.8-192 224 0zM151.2 304l-17.3 48-36.3 0-46.5 128-51.1 0 64-176 87.2 0zm354.8 48l-17.3-48 87.2 0 64 176-51.1 0-46.5-128-36.3 0z",{"w":425,"h":420,"d":472},"M144 354l-48 30 0-80-96 0 0-336 384 0 0 336-160 0-80 50zm0-56.6c43.5-27.2 65.6-41 66.2-41.4l125.8 0 0-240-288 0 0 240 96 0 0 41.4zM192 416l0-35.4 45.8-28.6 2.2 0 0 64 125.8 0c.6 .4 22.7 14.2 66.2 41.4l0-41.4 96 0 0-240-96 0 0-48 144 0 0 336-96 0 0 80-128-80-160 0 0-48zm0-340c-14.4 0-26.1 11.7-26.1 26.1l-40 0C125.9 65.6 155.5 36 192 36s66.1 29.6 66.1 66.1c0 29.7-17.7 46.9-33.3 55.6-4.5 2.5-8.9 4.8-12.9 6.2l-40 0 0-33.4c1.8-.2 3.6-.4 5.4-.6 9.7-1.1 19-2.1 27.9-7.1 7.5-4.2 12.9-10.1 12.9-20.8 0-14.4-11.7-26.1-26.1-26.1zM172 188l40 0 0 40-40 0 0-40z",{"id":474,"title":475,"authorsCollection":476,"content":486,"extension":1537,"faqItemsCollection":1538,"faqTitle":1797,"featured":6,"hashTags":33,"meta":1798,"metaTitle":1799,"ogImage":33,"postType":1800,"publishedDate":1801,"relatedBlogPostsCollection":1802,"slug":1842,"stem":1843,"subtitle":33,"summary":1844,"synopsis":1855,"sys":1856,"tagsCollection":1859,"topicsCollection":1865,"__hash__":1926},"blog\u002Fblog\u002Fthe-top-10-shadow-ai-discovery-and-governance-tools.json","The top 10 shadow AI discovery and governance tools: Push Security, Harmonic, Island and more",{"items":477},[478],{"fullName":479,"firstName":480,"jobTitle":481,"socialLinks":482,"profilePicture":484},"Alex Henshall","Alex","Product Team",[483],"https:\u002F\u002Fwww.linkedin.com\u002Fin\u002Falexhenshall\u002F",{"url":485},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F2rz3Pre3b1MexPIQ4hzPUe\u002F0ef8a092b7e7df00fbce3f7d1ccb96d1\u002FAlex_Henshall.jpeg",{"json":487,"links":1517},{"data":488,"content":489,"nodeType":1516},{},[490,499,506,513,522,529,538,542,551,558,565,572,592,612,620,627,634,642,649,656,664,671,678,686,693,712,720,727,746,754,761,768,776,783,790,798,805,812,820,827,834,837,845,852,859,862,870,877,1459,1462,1471,1478,1497],{"data":491,"content":492,"nodeType":498},{},[493],{"data":494,"marks":495,"value":496,"nodeType":497},{},[],"Shadow AI discovery and governance tools show security teams how employees actually use AI and give them the controls to keep that use within policy.","text","paragraph",{"data":500,"content":501,"nodeType":498},{},[502],{"data":503,"marks":504,"value":505,"nodeType":497},{},[],"These tools approach the problem from different directions: network proxies that inspect AI traffic, endpoint agents on managed devices which see what apps are being used, identity platforms that map who has access to which apps, data security tools that classify what's being shared, and enterprise browsers and browser extensions that work inside the session itself.",{"data":507,"content":508,"nodeType":498},{},[509],{"data":510,"marks":511,"value":512,"nodeType":497},{},[],"Increasingly, they're converging on the browser, because that's where most AI use happens. This means many vendors are now bolting on new browser capabilities, typically through an extension, to get the visibility they need. But a predominantly network or endpoint tool with a browser extension added will see and do different things from a browser-native tool, where the same in-session telemetry supports discovery, enforcement, investigation, and threat detection at once.",{"data":514,"content":520,"nodeType":521},{"target":515},{"sys":516},{"id":517,"type":518,"linkType":519},"5GB5JmifdYz8GurORBqszF","Link","Entry",[],"embedded-entry-block",{"data":523,"content":524,"nodeType":498},{},[525],{"data":526,"marks":527,"value":528,"nodeType":497},{},[],"Here's what the shadow AI tools market looks like in 2026.",{"data":530,"content":531,"nodeType":498},{},[532],{"data":533,"marks":534,"value":537,"nodeType":497},{},[535],{"type":536},"bold","The top shadow AI discovery and governance tools in 2026 include Push Security, Harmonic, Island, and Akamai Workforce Protector (formerly LayerX).",{"data":539,"content":540,"nodeType":541},{},[],"hr",{"data":543,"content":544,"nodeType":550},{},[545],{"data":546,"marks":547,"value":549,"nodeType":497},{},[548],{"type":536},"1. Push Security – Enterprise browser extension","heading-2",{"data":552,"content":553,"nodeType":498},{},[554],{"data":555,"marks":556,"value":557,"nodeType":497},{},[],"Push is a browser extension, not a browser, so coverage doesn’t depend on standardizing on one browser. Push discovers the apps that employees use from browser logins and events. It covers every dimension of shadow AI from one deployment, including AI apps, personal accounts on approved tools, AI browser extensions, OAuth integrations, and agentic browsers like Comet, Atlas, and Dia, and it controls how AI is used in the browser in real time. ",{"data":559,"content":560,"nodeType":498},{},[561],{"data":562,"marks":563,"value":564,"nodeType":497},{},[],"Push enforces governance policy at the point of use. Each AI app can be set to inform, acknowledge, or block, scoped by user group, with in-browser banners that send people to the approved tool instead of just blocking them, or guide the user’s behavior when using an app. Push detects how people log in (to identify password vulnerabilities, SSO gaps, MFA gaps, and so on) as well as how they interact with an app. This means you can detect and block risky actions such as API keys, credentials, and other sensitive data patterns pasted into AI apps. File upload rules block uploads by file type, app, and user group. AI conversation logs stream prompts (and optionally responses) to your SIEM, giving you one audit trail across every AI app in the browser.",{"data":566,"content":567,"nodeType":498},{},[568],{"data":569,"marks":570,"value":571,"nodeType":497},{},[],"Because Push runs in the browsers you already use, it gets you closest to the user and enforces policy at the point of interaction, across every app. In contrast, native controls stop at one vendor's corporate tenant, proxies act only on traffic they route and decrypt, and enterprise browsers act only inside their own contained browser. API-based tools only see the apps and tenants they've been connected to, which by definition leaves out most shadow AI, and identity tools mostly act after the fact. ",{"data":573,"content":574,"nodeType":498},{},[575,579,588],{"data":576,"marks":577,"value":578,"nodeType":497},{},[],"AI adoption isn't just a governance problem. Attackers use AI to build convincing phishing pages at scale, and ",{"data":580,"content":582,"nodeType":587},{"uri":581},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fanalyzing-the-latest-ai-themed-malware-delivery-attacks",[583],{"data":584,"marks":585,"value":586,"nodeType":497},{},[],"AI-themed lures","hyperlink",{"data":589,"marks":590,"value":591,"nodeType":497},{},[],", from fake AI tool installers to malicious instructions hosted on AI chatbot pages, target exactly the employees keen to try new tools. The same Push deployment detects and blocks those attacks too.",{"data":593,"content":594,"nodeType":498},{},[595,598,608],{"data":596,"marks":597,"value":41,"nodeType":497},{},[],{"data":599,"content":601,"nodeType":587},{"uri":600},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fshadow-ai-how-to-discover-govern-and-secure-ai-apps",[602],{"data":603,"marks":604,"value":607,"nodeType":497},{},[605],{"type":606},"underline","Learn more",{"data":609,"marks":610,"value":611,"nodeType":497},{},[]," about how to discover, govern, and secure AI apps with Push. ",{"data":613,"content":614,"nodeType":550},{},[615],{"data":616,"marks":617,"value":619,"nodeType":497},{},[618],{"type":536},"2. Harmonic Security – Browser extension and endpoint agent",{"data":621,"content":622,"nodeType":498},{},[623],{"data":624,"marks":625,"value":626,"nodeType":497},{},[],"Harmonic is built specifically for AI data protection. Its browser extension inventories AI use across standalone tools and the AI features embedded in approved apps like Canva and Grammarly, and it tells corporate accounts from personal ones, down to the subscription plan. Small language models classify sensitive data in prompts fast enough to coach, warn, ask for a business justification, or block inline, and to steer people from a free tool to the sanctioned one. An endpoint agent extends the same controls to desktop AI apps, coding tools, and local models, and an MCP gateway covers agent tool calls.",{"data":628,"content":629,"nodeType":498},{},[630],{"data":631,"marks":632,"value":633,"nodeType":497},{},[],"Harmonic's focus is the AI interaction itself. Its MCP gateway governs the connections AI coding tools make to external tools and data sources, but it doesn't extend to the wider SaaS estate beyond AI, and its published capabilities don't cover AI browser extensions or the OAuth grants that give third-party AI apps access to Google Workspace and Microsoft 365.",{"data":635,"content":636,"nodeType":550},{},[637],{"data":638,"marks":639,"value":641,"nodeType":497},{},[640],{"type":536},"3. Island – Enterprise browser",{"data":643,"content":644,"nodeType":498},{},[645],{"data":646,"marks":647,"value":648,"nodeType":497},{},[],"Island's AI Protect, launched in March 2026, brings AI governance into its managed browser. It separates corporate and personal tenants, enforces data boundaries before data reaches an AI provider, redacts sensitive content from prompts, and records prompts, responses, and agent activity. Island now describes itself as an agentic control plane, and it raised a large Series F in September 2026 to expand further into AI and agent controls.",{"data":650,"content":651,"nodeType":498},{},[652],{"data":653,"marks":654,"value":655,"nodeType":497},{},[],"AI Protect now reaches beyond Island's own browser through an Island extension for other browsers, plus endpoint and network components. The deepest controls, such as session recording and full workspace governance, still depend on moving users onto the Island browser.",{"data":657,"content":658,"nodeType":550},{},[659],{"data":660,"marks":661,"value":663,"nodeType":497},{},[662],{"type":536},"4. SentinelOne (Prompt Security) – Browser extension and endpoint platform",{"data":665,"content":666,"nodeType":498},{},[667],{"data":668,"marks":669,"value":670,"nodeType":497},{},[],"SentinelOne acquired Prompt Security in 2025 and has folded it into the Singularity platform as a set of AI products covering AI usage control, agentic AI security, and security for the AI applications teams build themselves. On the workforce side, it gives visibility into AI use across a broad range of AI apps and sites, blocks sensitive data from reaching them, and defends against prompt injection. ",{"data":672,"content":673,"nodeType":498},{},[674],{"data":675,"marks":676,"value":677,"nodeType":497},{},[],"Prompt Security's browser extension covers AI use in the browser, and SentinelOne extends the same policies to desktop AI apps and code assistants like GitHub Copilot, Cursor, and Claude Code, redacting sensitive data before a prompt leaves the device. It runs in the same console as SentinelOne's endpoint, identity, and cloud protection, which makes it a natural fit for organizations already standardized on SentinelOne.",{"data":679,"content":680,"nodeType":550},{},[681],{"data":682,"marks":683,"value":685,"nodeType":497},{},[684],{"type":536},"5. Microsoft Edge for Business & Purview – Built-in browser and DLP controls",{"data":687,"content":688,"nodeType":498},{},[689],{"data":690,"marks":691,"value":692,"nodeType":497},{},[],"Microsoft is the one platform vendor whose built-in controls reach beyond its own AI app, and if your organization runs on Microsoft they go a long way. At RSAC 2026 Microsoft added inline Purview DLP for AI prompts in Edge for Business, so sensitive prompts and file uploads to consumer AI tools can be audited or blocked, with an option to send the user to Microsoft 365 Copilot instead. DSPM for AI adds discovery and reporting on third-party AI use.",{"data":694,"content":695,"nodeType":498},{},[696,700,708],{"data":697,"marks":698,"value":699,"nodeType":497},{},[],"The catch is the setup. Most Purview controls for third-party AI apps need pay-as-you-go billing, the Purview browser extension, and devices onboarded to Purview, and retention and eDiscovery for those apps are limited to Edge. As in our ",{"data":701,"content":703,"nodeType":587},{"uri":702},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fthe-top-10-browser-security-solutions-in-2026",[704],{"data":705,"marks":706,"value":707,"nodeType":497},{},[],"browser security list",{"data":709,"marks":710,"value":711,"nodeType":497},{},[],", these are a foundation that the other tools here build on.",{"data":713,"content":714,"nodeType":550},{},[715],{"data":716,"marks":717,"value":719,"nodeType":497},{},[718],{"type":536},"6. Akamai Workforce Protector (formerly LayerX) – Enterprise browser extension",{"data":721,"content":722,"nodeType":498},{},[723],{"data":724,"marks":725,"value":726,"nodeType":497},{},[],"LayerX built its product as a browser extension focused on AI usage control and browser DLP. It captures prompts and file uploads inside AI tools, classifies sensitive submissions, flags personal accounts, and enforces policy without a new browser, including on contractor and BYOD devices. It also scores installed browser extensions for risk, many of which are now AI-powered, and has extended coverage toward desktop AI apps and developer tools.",{"data":728,"content":729,"nodeType":498},{},[730,734,742],{"data":731,"marks":732,"value":733,"nodeType":497},{},[],"Akamai completed its acquisition in July 2026 and now sells the product as Workforce Protector within its Zero Trust portfolio, alongside segmentation, ZTNA, and DNS security. For existing Akamai customers that makes it easy to add. For everyone else, the open question is the same one raised with any acquired product: ",{"data":735,"content":737,"nodeType":587},{"uri":736},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fthe-case-for-best-of-breed-browser-security\u002F",[738],{"data":739,"marks":740,"value":741,"nodeType":497},{},[],"what the roadmap looks like 18 months after close",{"data":743,"marks":744,"value":745,"nodeType":497},{},[],".",{"data":747,"content":748,"nodeType":550},{},[749],{"data":750,"marks":751,"value":753,"nodeType":497},{},[752],{"type":536},"7. Zscaler and Palo Alto Networks – SSE \u002F network proxy",{"data":755,"content":756,"nodeType":498},{},[757],{"data":758,"marks":759,"value":760,"nodeType":497},{},[],"The two biggest security service edge vendors both extend their proxies to AI traffic. Zscaler's AI Security Suite pairs an inventory of AI apps, agents, and models with inline inspection and prompt classification for the AI services you allow. Palo Alto's AI Access Security classifies GenAI apps by risk, with inline DLP and user coaching. For organizations already routing traffic through either platform, adding AI policy is a natural next step.",{"data":762,"content":763,"nodeType":498},{},[764],{"data":765,"marks":766,"value":767,"nodeType":497},{},[],"A proxy enforces policy on the traffic it can see and decrypt, which leaves less context about the account, extension, or action involved than a view from inside the session. Both vendors have bought their way into the browser to close that gap: Zscaler with SquareX, and Palo Alto with Talon, now Prisma Browser.",{"data":769,"content":770,"nodeType":550},{},[771],{"data":772,"marks":773,"value":775,"nodeType":497},{},[774],{"type":536},"8. Grip Security – Identity and SaaS platform",{"data":777,"content":778,"nodeType":498},{},[779],{"data":780,"marks":781,"value":782,"nodeType":497},{},[],"Grip discovers SaaS and AI apps from identity signals such as email, SSO, and identity provider data, so it can build an inventory without deploying anything to endpoints. Its AI Security Platform, expanded in August 2026, maps users, AI agents, apps, and permissions into an identity graph, and adds AI posture management, non-human identity governance, and automated remediation such as revoking access.",{"data":784,"content":785,"nodeType":498},{},[786],{"data":787,"marks":788,"value":789,"nodeType":497},{},[],"Grip has since added an optional browser extension and prompt monitoring to an identity posture platform. That's a good fit when the question you most need answered is who has access to which AI tools and what permissions those tools hold. Email and identity signals are better at showing that an account exists than whether an app is in use today or which account someone actually signed in with, and the approach is a weaker fit when you need to enforce policy at the moment someone pastes data or signs in with a personal account.",{"data":791,"content":792,"nodeType":550},{},[793],{"data":794,"marks":795,"value":797,"nodeType":497},{},[796],{"type":536},"9. Nightfall AI – AI-native DLP",{"data":799,"content":800,"nodeType":498},{},[801],{"data":802,"marks":803,"value":804,"nodeType":497},{},[],"Nightfall applies one AI-native detection engine across SaaS, endpoints, browsers, email, AI apps, and MCP workflows. Its browser plugin inspects prompts and file uploads before submission, recognizes when a file being uploaded originated in a corporate SaaS app, and can redact just the sensitive part of a prompt rather than blocking all of it. When it intervenes, it coaches the user, for example by pointing them to the corporate ChatGPT tenant instead of a personal one.",{"data":806,"content":807,"nodeType":498},{},[808],{"data":809,"marks":810,"value":811,"nodeType":497},{},[],"Nightfall is strongest for teams whose main problem is classifying sensitive data accurately across many channels, with AI as one of them. Like most DLP-first tools, it's typically paired with something else for discovery and access governance.",{"data":813,"content":814,"nodeType":550},{},[815],{"data":816,"marks":817,"value":819,"nodeType":497},{},[818],{"type":536},"10. Cyberhaven – Endpoint and browser data security",{"data":821,"content":822,"nodeType":498},{},[823],{"data":824,"marks":825,"value":826,"nodeType":497},{},[],"Cyberhaven tracks where data came from and where it goes, including into AI tools, which makes it a strong fit for insider risk and IP protection programs. In 2026 it added discovery and runtime controls for AI agents and MCP servers on endpoints, and in July launched Cyberhaven Flow, a platform that ties lineage, identity, and behavior together across endpoints, browsers, and cloud, with integrations into the ChatGPT Enterprise and Claude compliance APIs.",{"data":828,"content":829,"nodeType":498},{},[830],{"data":831,"marks":832,"value":833,"nodeType":497},{},[],"Cyberhaven's browser extension originally required its endpoint sensor. A standalone version released in May 2026 extends coverage to ChromeOS, contractor, and other unmanaged devices, inspecting uploads, form inputs, and AI prompts and distinguishing corporate from personal accounts.",{"data":835,"content":836,"nodeType":541},{},[],{"data":838,"content":839,"nodeType":550},{},[840],{"data":841,"marks":842,"value":844,"nodeType":497},{},[843],{"type":536},"Native controls vs. shadow AI tools",{"data":846,"content":847,"nodeType":498},{},[848],{"data":849,"marks":850,"value":851,"nodeType":497},{},[],"Most organizations now pay for at least one business AI plan, and the security controls on those plans are improving. ChatGPT Enterprise exposes a Compliance Platform for audit logs and DLP integrations. Claude Enterprise added inference hooks that send each prompt to your own security server for an allow-or-deny verdict. Copilot inherits Microsoft's identity and Purview controls. If you're paying for these plans, you want people using them, because that's where the return on the license comes from and where those controls apply.",{"data":853,"content":854,"nodeType":498},{},[855],{"data":856,"marks":857,"value":858,"nodeType":497},{},[],"We haven't included them in this list because each one governs a single vendor's corporate tenant, and the richest controls usually sit on the top tier. None of them can see the personal ChatGPT account on a corporate laptop, the AI note-taker someone connected to Google Workspace, the AI extension installed last week, or the dozen AI apps nobody approved. Native controls are the baseline; the tools above cover everything outside it, including steering people back onto the plans you pay for. The one platform vendor on the list is Microsoft, because Edge for Business and Purview govern other vendors' AI apps, not just Copilot.",{"data":860,"content":861,"nodeType":541},{},[],{"data":863,"content":864,"nodeType":550},{},[865],{"data":866,"marks":867,"value":869,"nodeType":497},{},[868],{"type":536},"How the approaches compare",{"data":871,"content":872,"nodeType":498},{},[873],{"data":874,"marks":875,"value":876,"nodeType":497},{},[],"Each approach enforces AI policy at a different point. The table shows typical coverage by approach; individual vendors vary.",{"data":878,"content":879,"nodeType":1458},{},[880,962,1032,1103,1175,1245,1317,1386],{"data":881,"content":882,"nodeType":961},{},[883,895,906,917,928,939,950],{"data":884,"content":885,"nodeType":894},{},[886],{"data":887,"content":888,"nodeType":498},{},[889],{"data":890,"marks":891,"value":893,"nodeType":497},{},[892],{"type":536},"Approach","table-cell",{"data":896,"content":897,"nodeType":894},{},[898],{"data":899,"content":900,"nodeType":498},{},[901],{"data":902,"marks":903,"value":905,"nodeType":497},{},[904],{"type":536},"Where it enforces",{"data":907,"content":908,"nodeType":894},{},[909],{"data":910,"content":911,"nodeType":498},{},[912],{"data":913,"marks":914,"value":916,"nodeType":497},{},[915],{"type":536},"Personal accounts on approved AI tools",{"data":918,"content":919,"nodeType":894},{},[920],{"data":921,"content":922,"nodeType":498},{},[923],{"data":924,"marks":925,"value":927,"nodeType":497},{},[926],{"type":536},"AI browser extensions",{"data":929,"content":930,"nodeType":894},{},[931],{"data":932,"content":933,"nodeType":498},{},[934],{"data":935,"marks":936,"value":938,"nodeType":497},{},[937],{"type":536},"MCP grants to third-party AI apps via OAuth",{"data":940,"content":941,"nodeType":894},{},[942],{"data":943,"content":944,"nodeType":498},{},[945],{"data":946,"marks":947,"value":949,"nodeType":497},{},[948],{"type":536},"Paste and upload enforcement",{"data":951,"content":952,"nodeType":894},{},[953],{"data":954,"content":955,"nodeType":498},{},[956],{"data":957,"marks":958,"value":960,"nodeType":497},{},[959],{"type":536},"Deployment","table-row",{"data":963,"content":964,"nodeType":961},{},[965,975,985,995,1004,1013,1022],{"data":966,"content":967,"nodeType":894},{},[968],{"data":969,"content":970,"nodeType":498},{},[971],{"data":972,"marks":973,"value":974,"nodeType":497},{},[],"Enterprise browser extension",{"data":976,"content":977,"nodeType":894},{},[978],{"data":979,"content":980,"nodeType":498},{},[981],{"data":982,"marks":983,"value":984,"nodeType":497},{},[],"In existing browsers, at login, paste, upload, or consent",{"data":986,"content":987,"nodeType":894},{},[988],{"data":989,"content":990,"nodeType":498},{},[991],{"data":992,"marks":993,"value":994,"nodeType":497},{},[],"Yes",{"data":996,"content":997,"nodeType":894},{},[998],{"data":999,"content":1000,"nodeType":498},{},[1001],{"data":1002,"marks":1003,"value":994,"nodeType":497},{},[],{"data":1005,"content":1006,"nodeType":894},{},[1007],{"data":1008,"content":1009,"nodeType":498},{},[1010],{"data":1011,"marks":1012,"value":994,"nodeType":497},{},[],{"data":1014,"content":1015,"nodeType":894},{},[1016],{"data":1017,"content":1018,"nodeType":498},{},[1019],{"data":1020,"marks":1021,"value":994,"nodeType":497},{},[],{"data":1023,"content":1024,"nodeType":894},{},[1025],{"data":1026,"content":1027,"nodeType":498},{},[1028],{"data":1029,"marks":1030,"value":1031,"nodeType":497},{},[],"Extension in existing browsers, including BYOD",{"data":1033,"content":1034,"nodeType":961},{},[1035,1045,1055,1065,1074,1084,1093],{"data":1036,"content":1037,"nodeType":894},{},[1038],{"data":1039,"content":1040,"nodeType":498},{},[1041],{"data":1042,"marks":1043,"value":1044,"nodeType":497},{},[],"Enterprise browser",{"data":1046,"content":1047,"nodeType":894},{},[1048],{"data":1049,"content":1050,"nodeType":498},{},[1051],{"data":1052,"marks":1053,"value":1054,"nodeType":497},{},[],"Inside the managed browser only",{"data":1056,"content":1057,"nodeType":894},{},[1058],{"data":1059,"content":1060,"nodeType":498},{},[1061],{"data":1062,"marks":1063,"value":1064,"nodeType":497},{},[],"Yes, inside the managed browser",{"data":1066,"content":1067,"nodeType":894},{},[1068],{"data":1069,"content":1070,"nodeType":498},{},[1071],{"data":1072,"marks":1073,"value":1064,"nodeType":497},{},[],{"data":1075,"content":1076,"nodeType":894},{},[1077],{"data":1078,"content":1079,"nodeType":498},{},[1080],{"data":1081,"marks":1082,"value":1083,"nodeType":497},{},[],"Partial",{"data":1085,"content":1086,"nodeType":894},{},[1087],{"data":1088,"content":1089,"nodeType":498},{},[1090],{"data":1091,"marks":1092,"value":994,"nodeType":497},{},[],{"data":1094,"content":1095,"nodeType":894},{},[1096],{"data":1097,"content":1098,"nodeType":498},{},[1099],{"data":1100,"marks":1101,"value":1102,"nodeType":497},{},[],"Browser migration",{"data":1104,"content":1105,"nodeType":961},{},[1106,1116,1126,1136,1146,1155,1165],{"data":1107,"content":1108,"nodeType":894},{},[1109],{"data":1110,"content":1111,"nodeType":498},{},[1112],{"data":1113,"marks":1114,"value":1115,"nodeType":497},{},[],"SSE \u002F network proxy",{"data":1117,"content":1118,"nodeType":894},{},[1119],{"data":1120,"content":1121,"nodeType":498},{},[1122],{"data":1123,"marks":1124,"value":1125,"nodeType":497},{},[],"On traffic it routes and decrypts",{"data":1127,"content":1128,"nodeType":894},{},[1129],{"data":1130,"content":1131,"nodeType":498},{},[1132],{"data":1133,"marks":1134,"value":1135,"nodeType":497},{},[],"Partial (tenant restrictions)",{"data":1137,"content":1138,"nodeType":894},{},[1139],{"data":1140,"content":1141,"nodeType":498},{},[1142],{"data":1143,"marks":1144,"value":1145,"nodeType":497},{},[],"No",{"data":1147,"content":1148,"nodeType":894},{},[1149],{"data":1150,"content":1151,"nodeType":498},{},[1152],{"data":1153,"marks":1154,"value":1145,"nodeType":497},{},[],{"data":1156,"content":1157,"nodeType":894},{},[1158],{"data":1159,"content":1160,"nodeType":498},{},[1161],{"data":1162,"marks":1163,"value":1164,"nodeType":497},{},[],"Partial, with TLS inspection",{"data":1166,"content":1167,"nodeType":894},{},[1168],{"data":1169,"content":1170,"nodeType":498},{},[1171],{"data":1172,"marks":1173,"value":1174,"nodeType":497},{},[],"Traffic routing and TLS inspection",{"data":1176,"content":1177,"nodeType":961},{},[1178,1188,1198,1207,1216,1226,1235],{"data":1179,"content":1180,"nodeType":894},{},[1181],{"data":1182,"content":1183,"nodeType":498},{},[1184],{"data":1185,"marks":1186,"value":1187,"nodeType":497},{},[],"Endpoint agent",{"data":1189,"content":1190,"nodeType":894},{},[1191],{"data":1192,"content":1193,"nodeType":498},{},[1194],{"data":1195,"marks":1196,"value":1197,"nodeType":497},{},[],"On managed devices with the agent installed",{"data":1199,"content":1200,"nodeType":894},{},[1201],{"data":1202,"content":1203,"nodeType":498},{},[1204],{"data":1205,"marks":1206,"value":1083,"nodeType":497},{},[],{"data":1208,"content":1209,"nodeType":894},{},[1210],{"data":1211,"content":1212,"nodeType":498},{},[1213],{"data":1214,"marks":1215,"value":1083,"nodeType":497},{},[],{"data":1217,"content":1218,"nodeType":894},{},[1219],{"data":1220,"content":1221,"nodeType":498},{},[1222],{"data":1223,"marks":1224,"value":1225,"nodeType":497},{},[],"No — consent to third-party apps happens in the browser",{"data":1227,"content":1228,"nodeType":894},{},[1229],{"data":1230,"content":1231,"nodeType":498},{},[1232],{"data":1233,"marks":1234,"value":994,"nodeType":497},{},[],{"data":1236,"content":1237,"nodeType":894},{},[1238],{"data":1239,"content":1240,"nodeType":498},{},[1241],{"data":1242,"marks":1243,"value":1244,"nodeType":497},{},[],"Agent on managed devices",{"data":1246,"content":1247,"nodeType":961},{},[1248,1258,1268,1277,1287,1297,1307],{"data":1249,"content":1250,"nodeType":894},{},[1251],{"data":1252,"content":1253,"nodeType":498},{},[1254],{"data":1255,"marks":1256,"value":1257,"nodeType":497},{},[],"Identity \u002F SaaS platform",{"data":1259,"content":1260,"nodeType":894},{},[1261],{"data":1262,"content":1263,"nodeType":498},{},[1264],{"data":1265,"marks":1266,"value":1267,"nodeType":497},{},[],"Mostly after the fact (revoke access, notify the user)",{"data":1269,"content":1270,"nodeType":894},{},[1271],{"data":1272,"content":1273,"nodeType":498},{},[1274],{"data":1275,"marks":1276,"value":1083,"nodeType":497},{},[],{"data":1278,"content":1279,"nodeType":894},{},[1280],{"data":1281,"content":1282,"nodeType":498},{},[1283],{"data":1284,"marks":1285,"value":1286,"nodeType":497},{},[],"Varies",{"data":1288,"content":1289,"nodeType":894},{},[1290],{"data":1291,"content":1292,"nodeType":498},{},[1293],{"data":1294,"marks":1295,"value":1296,"nodeType":497},{},[],"Partial — only grants against platforms it's connected to",{"data":1298,"content":1299,"nodeType":894},{},[1300],{"data":1301,"content":1302,"nodeType":498},{},[1303],{"data":1304,"marks":1305,"value":1306,"nodeType":497},{},[],"Limited",{"data":1308,"content":1309,"nodeType":894},{},[1310],{"data":1311,"content":1312,"nodeType":498},{},[1313],{"data":1314,"marks":1315,"value":1316,"nodeType":497},{},[],"API connections",{"data":1318,"content":1319,"nodeType":961},{},[1320,1330,1340,1349,1358,1367,1376],{"data":1321,"content":1322,"nodeType":894},{},[1323],{"data":1324,"content":1325,"nodeType":498},{},[1326],{"data":1327,"marks":1328,"value":1329,"nodeType":497},{},[],"AI-native DLP",{"data":1331,"content":1332,"nodeType":894},{},[1333],{"data":1334,"content":1335,"nodeType":498},{},[1336],{"data":1337,"marks":1338,"value":1339,"nodeType":497},{},[],"On the data channels it monitors",{"data":1341,"content":1342,"nodeType":894},{},[1343],{"data":1344,"content":1345,"nodeType":498},{},[1346],{"data":1347,"marks":1348,"value":1286,"nodeType":497},{},[],{"data":1350,"content":1351,"nodeType":894},{},[1352],{"data":1353,"content":1354,"nodeType":498},{},[1355],{"data":1356,"marks":1357,"value":1145,"nodeType":497},{},[],{"data":1359,"content":1360,"nodeType":894},{},[1361],{"data":1362,"content":1363,"nodeType":498},{},[1364],{"data":1365,"marks":1366,"value":1145,"nodeType":497},{},[],{"data":1368,"content":1369,"nodeType":894},{},[1370],{"data":1371,"content":1372,"nodeType":498},{},[1373],{"data":1374,"marks":1375,"value":994,"nodeType":497},{},[],{"data":1377,"content":1378,"nodeType":894},{},[1379],{"data":1380,"content":1381,"nodeType":498},{},[1382],{"data":1383,"marks":1384,"value":1385,"nodeType":497},{},[],"Varies by channel",{"data":1387,"content":1388,"nodeType":961},{},[1389,1399,1409,1419,1428,1438,1448],{"data":1390,"content":1391,"nodeType":894},{},[1392],{"data":1393,"content":1394,"nodeType":498},{},[1395],{"data":1396,"marks":1397,"value":1398,"nodeType":497},{},[],"Native in-app controls",{"data":1400,"content":1401,"nodeType":894},{},[1402],{"data":1403,"content":1404,"nodeType":498},{},[1405],{"data":1406,"marks":1407,"value":1408,"nodeType":497},{},[],"Inside one vendor's corporate tenant",{"data":1410,"content":1411,"nodeType":894},{},[1412],{"data":1413,"content":1414,"nodeType":498},{},[1415],{"data":1416,"marks":1417,"value":1418,"nodeType":497},{},[],"No (your corporate tenant only)",{"data":1420,"content":1421,"nodeType":894},{},[1422],{"data":1423,"content":1424,"nodeType":498},{},[1425],{"data":1426,"marks":1427,"value":1145,"nodeType":497},{},[],{"data":1429,"content":1430,"nodeType":894},{},[1431],{"data":1432,"content":1433,"nodeType":498},{},[1434],{"data":1435,"marks":1436,"value":1437,"nodeType":497},{},[],"Partial (own connectors)",{"data":1439,"content":1440,"nodeType":894},{},[1441],{"data":1442,"content":1443,"nodeType":498},{},[1444],{"data":1445,"marks":1446,"value":1447,"nodeType":497},{},[],"Top tiers, per vendor",{"data":1449,"content":1450,"nodeType":894},{},[1451],{"data":1452,"content":1453,"nodeType":498},{},[1454],{"data":1455,"marks":1456,"value":1457,"nodeType":497},{},[],"Included in plan tier","table",{"data":1460,"content":1461,"nodeType":541},{},[],{"data":1463,"content":1464,"nodeType":1470},{},[1465],{"data":1466,"marks":1467,"value":1469,"nodeType":497},{},[1468],{"type":536},"Learn more about Push Security","heading-1",{"data":1472,"content":1473,"nodeType":498},{},[1474],{"data":1475,"marks":1476,"value":1477,"nodeType":497},{},[],"Push Security is the most powerful AI-native security tool in the browser. Think EDR, but for the browser — high-fidelity telemetry and real-time control across every session, on every device, with no browser migration required.",{"data":1479,"content":1480,"nodeType":498},{},[1481,1485,1493],{"data":1482,"marks":1483,"value":1484,"nodeType":497},{},[],"Push isn't a just an AI governance platform. It's what makes your AI governance policy enforceable: it finds AI use your policy doesn't reach, steers people to the tools you've approved, and blocks what shouldn't leave. The same deployment also covers the ",{"data":1486,"content":1488,"nodeType":587},{"uri":1487},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fthe-top-10-security-problems-you-can-solve-in-the-browser-ranked-by-value",[1489],{"data":1490,"marks":1491,"value":1492,"nodeType":497},{},[],"other security problems you can solve in the browser",{"data":1494,"marks":1495,"value":1496,"nodeType":497},{},[],", including detecting and stopping advanced attacks, identity and shadow IT security, and DLP and insider investigations.",{"data":1498,"content":1499,"nodeType":498},{},[1500,1504,1512],{"data":1501,"marks":1502,"value":1503,"nodeType":497},{},[],"Book a ",{"data":1505,"content":1507,"nodeType":587},{"uri":1506},"https:\u002F\u002Fpushsecurity.com\u002Fdemo",[1508],{"data":1509,"marks":1510,"value":1511,"nodeType":497},{},[],"live demo",{"data":1513,"marks":1514,"value":1515,"nodeType":497},{},[]," to learn more.","document",{"entries":1518},{"hyperlink":1519,"inline":1520,"block":1521},[],[],[1522],{"sys":1523,"__typename":1524,"content":1525,"name":1536,"title":33},{"id":517},"InsightTextBlockComponent",{"json":1526},{"nodeType":1516,"data":1527,"content":1528},{},[1529],{"nodeType":498,"data":1530,"content":1531},{},[1532],{"nodeType":497,"value":1533,"marks":1534,"data":1535},"A note on scope: this list covers securing how people use AI, not securing the AI agents organizations deploy. Agent security governs what autonomous agents do once they're running, such as the tools they call and the permissions they hold. For most organizations it's a later-stage problem with a different owner, and it's increasingly handled inside the platforms where agents are built. Where the two meet, such as when an employee grants an AI agent OAuth access to their mailbox, the tools below cover the grant.",[],{},"Top 10 AI tools IB1","json",{"items":1539},[1540,1565,1585,1605,1632,1645,1681,1694,1707,1720,1733,1746,1766],{"answer":1541,"question":1564},{"json":1542},{"nodeType":1516,"data":1543,"content":1544},{},[1545],{"nodeType":498,"data":1546,"content":1547},{},[1548,1552,1560],{"nodeType":497,"value":1549,"marks":1550,"data":1551},"Shadow AI is any use of AI at work that your organization's AI policy doesn't reach. It has ",[],{},{"nodeType":587,"data":1553,"content":1555},{"uri":1554},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fwhat-push-data-reveals-about-the-state-of-shadow-ai\u002F",[1556],{"nodeType":497,"value":1557,"marks":1558,"data":1559},"four dimensions",[],{},{"nodeType":497,"value":1561,"marks":1562,"data":1563},": unapproved AI apps, personal accounts on approved apps, AI browser extensions, and OAuth integrations that connect AI tools to corporate systems. The risk isn't that people use AI. It's that sensitive data goes into tools and accounts where none of your controls apply, so the policy you wrote for AI never takes effect for that activity.",[],{},"What is shadow AI, and why is it a security risk?",{"answer":1566,"question":1584},{"json":1567},{"nodeType":1516,"data":1568,"content":1569},{},[1570,1577],{"nodeType":498,"data":1571,"content":1572},{},[1573],{"nodeType":497,"value":1574,"marks":1575,"data":1576},"It depends on where the tool gets its signal. Network logs show traffic to AI domains but not which account was used. Identity provider data shows apps connected through SSO or OAuth but misses everything people sign up to directly. Email-based discovery infers apps from welcome messages, receipts, and vendor mail. An email shows a vendor contacted someone or an account was once created, but not that the app is in use today, which account was used, or how the person signs in. Inventories built that way tend to fill up with marketing mail, abandoned trials, and dormant accounts, while missing apps that never send one. Discovery from the login event itself is the most direct signal: it shows actual use, the account, the sign-in method, and whether MFA is on, alongside the extensions installed and the OAuth grants approved. ",[],{},{"nodeType":498,"data":1578,"content":1579},{},[1580],{"nodeType":497,"value":1581,"marks":1582,"data":1583},"Treat visibility as the first step of governance rather than governance itself: an inventory shows you where your policy is being ignored, and enforcement is what changes the outcome.",[],{},"How do I get visibility into which AI tools my employees are using?",{"answer":1586,"question":1604},{"json":1587},{"nodeType":1516,"data":1588,"content":1589},{},[1590,1597],{"nodeType":498,"data":1591,"content":1592},{},[1593],{"nodeType":497,"value":1594,"marks":1595,"data":1596},"A personal account on an approved tool sits entirely outside your policy, with no corporate audit log, no DLP, and no retention control. Okta found that 80% of employees using unapproved AI do so because their own account is easier. Blanket bans tend to push that usage further out of sight. The more effective approach is to catch the personal-account login and redirect the person to the corporate tenant at that moment, escalating from a banner to an acknowledgment to a block. ",[],{},{"nodeType":498,"data":1598,"content":1599},{},[1600],{"nodeType":497,"value":1601,"marks":1602,"data":1603},"Network tenant restrictions can enforce part of this for some apps, but they don't explain to the user what to do instead. The only reliable way to do this across all apps is to be able to intervene in the browser session in real time. ",[],{},"How do I stop employees using personal AI accounts?",{"answer":1606,"question":1631},{"json":1607},{"nodeType":1516,"data":1608,"content":1609},{},[1610,1617,1624],{"nodeType":498,"data":1611,"content":1612},{},[1613],{"nodeType":497,"value":1614,"marks":1615,"data":1616},"Use the native controls first: SSO, audit logs, retention, and prompt-level controls where your plan includes them. Several of the most useful ones, including the ChatGPT Compliance Platform and Claude inference hooks, are only available on enterprise tiers. ",[],{},{"nodeType":498,"data":1618,"content":1619},{},[1620],{"nodeType":497,"value":1621,"marks":1622,"data":1623},"But even at the top tier, each vendor governs its own corporate tenant. What's left is the AI apps you don't pay for, personal accounts on the ones you do, AI extensions, OAuth grants to AI tools, and a single view across vendors. A shadow AI tool protects the investment you've made in those plans by steering people onto them, and it applies the same policy everywhere else.",[],{},{"nodeType":498,"data":1625,"content":1626},{},[1627],{"nodeType":497,"value":1628,"marks":1629,"data":1630},"This is particularly cost-effective if you're paying for multiple enterprise plans. Funnelling users to the apps you want them to use, and stripping out expensive subscriptions, means that a shadow AI tool isn't just a fraction of the cost, it can probably save you money. ",[],{},"We're on ChatGPT Claude, or Copilot enterprise plans. What else do we need for AI security?",{"answer":1633,"question":1644},{"json":1634},{"nodeType":1516,"data":1635,"content":1636},{},[1637],{"nodeType":498,"data":1638,"content":1639},{},[1640],{"nodeType":497,"value":1641,"marks":1642,"data":1643},"This is the core of AI data security for most organizations. Almost every AI policy says not to paste customer data, credentials, or source code into AI tools, and that rule only holds if something checks at the moment of the paste or upload. Native prompt controls exist at a few vendors, mostly on enterprise tiers, and each covers only its own product. Browser-layer controls apply the same rules across every AI app, including personal accounts. ",[],{},"How do I stop employees pasting sensitive data into AI tools like ChatGPT?",{"answer":1646,"question":1680},{"json":1647},{"nodeType":1516,"data":1648,"content":1649},{},[1650],{"nodeType":498,"data":1651,"content":1652},{},[1653,1657,1665,1669,1676],{"nodeType":497,"value":1654,"marks":1655,"data":1656},"Governance defines the policy, and enforcement makes it hold. Map each rule in your policy to a control at the point of use: approved tools get allowed, tolerated tools get a banner and an acknowledgment, prohibited tools and sensitive data get blocked. Graduated enforcement matters because blocking everything drives usage underground, the pattern SANS calls the ",[],{},{"nodeType":587,"data":1658,"content":1660},{"uri":1659},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fcrossing-the-ai-security-chasm-sans-security-maturity-model",[1661],{"nodeType":497,"value":1662,"marks":1663,"data":1664},"\"Framework of No\"",[],{},{"nodeType":497,"value":1666,"marks":1667,"data":1668},". Pointing people to an approved alternative is what makes a policy realistic enough to follow: ",[],{},{"nodeType":587,"data":1670,"content":1671},{"uri":600},[1672],{"nodeType":497,"value":1673,"marks":1674,"data":1675},"making the path you want them to follow the easiest",[],{},{"nodeType":497,"value":1677,"marks":1678,"data":1679},". ",[],{},"How do I enforce an AI acceptable use policy?",{"answer":1682,"question":1693},{"json":1683},{"nodeType":1516,"data":1684,"content":1685},{},[1686],{"nodeType":498,"data":1687,"content":1688},{},[1689],{"nodeType":497,"value":1690,"marks":1691,"data":1692},"It depends which side of AI governance you mean. AI governance platforms (Gartner published its first Magic Quadrant for the category in June 2026, with vendors like IBM, ServiceNow, Credo AI, and OneTrust) manage AI policy, model risk assessments, and compliance records. Tools for governing AI use, like Push Security, Harmonic, Island, and Akamai Workforce Protector, discover how employees actually use AI and enforce that policy where they use it. Most organizations need both, and a governance program is only as strong as the enforcement underneath it.",[],{},"What are the best AI governance tools for enterprise?",{"answer":1695,"question":1706},{"json":1696},{"nodeType":1516,"data":1697,"content":1698},{},[1699],{"nodeType":498,"data":1700,"content":1701},{},[1702],{"nodeType":497,"value":1703,"marks":1704,"data":1705},"AI security covers several different problems, and the best tool depends on which one you're solving. Securing how employees use AI, a large part of what's usually meant by generative AI security, is about controlling which AI tools and accounts people use and what data goes into them, and that's where tools like Push Security, Harmonic, Island, and SentinelOne's Prompt Security fit. Securing AI agents covers what autonomous agents do once they're deployed, with vendors like Zenity, Aembit, and Astrix Security. Securing the AI applications and models you build yourself covers testing, runtime protection, and model scanning, from vendors like Lakera, HiddenLayer, and Mindgard. A fourth category, AI-powered security tools, uses AI to improve existing security functions rather than securing AI at all. For most enterprises, employee use is where the exposure is today and where governance needs enforcement first.",[],{},"What are the best AI security tools for enterprises?",{"answer":1708,"question":1719},{"json":1709},{"nodeType":1516,"data":1710,"content":1711},{},[1712],{"nodeType":498,"data":1713,"content":1714},{},[1715],{"nodeType":497,"value":1716,"marks":1717,"data":1718},"Securing AI use governs what people do with AI tools: which tools and accounts they use, what data they share, and what access they grant. Securing AI agents governs what autonomous agents do after deployment. Agent governance is increasingly built into the platforms where agents run, such as Microsoft Agent 365 and ServiceNow AI Control Tower. For most organizations, governing AI use comes first, and the moment an employee approves an agent's access through an OAuth grant is itself a point where policy can be enforced.",[],{},"What's the difference between securing AI use and securing AI agents?",{"answer":1721,"question":1732},{"json":1722},{"nodeType":1516,"data":1723,"content":1724},{},[1725],{"nodeType":498,"data":1726,"content":1727},{},[1728],{"nodeType":497,"value":1729,"marks":1730,"data":1731},"Native audit logs cover one vendor's corporate tenant, usually at its enterprise tier. Microsoft Purview can audit third-party AI apps for organizations running its stack, with some capabilities limited to Edge. Browser-layer tools like Push can stream AI conversation logs (prompts, and optionally responses) from every AI app used in enrolled browsers into your SIEM. An audit trail is how you prove your AI policy held, which auditors and regulators increasingly ask for.",[],{},"Which security tools provide audit trails for AI activity?",{"answer":1734,"question":1745},{"json":1735},{"nodeType":1516,"data":1736,"content":1737},{},[1738],{"nodeType":498,"data":1739,"content":1740},{},[1741],{"nodeType":497,"value":1742,"marks":1743,"data":1744},"They can cover part of it. SSE platforms from vendors like Zscaler and Palo Alto Networks can allow or block AI apps, apply tenant restrictions, and inspect decrypted traffic for sensitive data. What they see is the traffic, not the session, so they have less context about which account is in use, which extension is acting, or what the user is doing. Browser-layer controls add that context, and the two work well together.",[],{},"Can my SWG or CASB control AI usage?",{"answer":1747,"question":1765},{"json":1748},{"nodeType":1516,"data":1749,"content":1750},{},[1751,1758],{"nodeType":498,"data":1752,"content":1753},{},[1754],{"nodeType":497,"value":1755,"marks":1756,"data":1757},"Start with how the tool enforces policy, not how it builds an inventory. Does it see personal accounts on approved tools? Does it offer graduated enforcement and redirect users to approved tools, or only allow and block? Was its browser extension built in from the start or added to a product built for something else? Does it detect attacks that come in through AI tools, such as malicious extensions and consent phishing? Can it deploy to BYOD and contractor devices, and does it feed your SIEM? ",[],{},{"nodeType":498,"data":1759,"content":1760},{},[1761],{"nodeType":497,"value":1762,"marks":1763,"data":1764},"\n",[],{},"What should I look for in a shadow AI tool?",{"answer":1767,"question":1796},{"json":1768},{"nodeType":1516,"data":1769,"content":1770},{},[1771,1789],{"nodeType":498,"data":1772,"content":1773},{},[1774,1778,1785],{"nodeType":497,"value":1775,"marks":1776,"data":1777},"It depends on where the connection is made. MCP (Model Context Protocol) connections let AI tools read from and act on other systems, and they show up in three places. Connectors added inside web AI apps like ChatGPT and Claude, and remote MCP servers that use OAuth, are requested and approved in the browser, so browser-layer tools can see them and stop unapproved ones at the point of connection. Push can ",[],{},{"nodeType":587,"data":1779,"content":1780},{"uri":600},[1781],{"nodeType":497,"value":1782,"marks":1783,"data":1784},"block unapproved MCP connection requests in real time",[],{},{"nodeType":497,"value":1786,"marks":1787,"data":1788},". ",[],{},{"nodeType":498,"data":1790,"content":1791},{},[1792],{"nodeType":497,"value":1793,"marks":1794,"data":1795},"Local MCP servers that developers configure for tools like Claude Code and Cursor live in config files on the device, so they're visible to endpoint tools rather than the browser. MCP servers your own teams deploy for internal agents fall under agent security. Most organizations need the browser view for employees and an endpoint view for developer machines.",[],{},"How do I detect and manage MCP connections?","FAQs: AI discovery and governance",{},"Guide to the top 10 shadow AI discovery and governance tools","guide","2026-10-09T00:00:00.000Z",{"items":1803},[1804,1818,1829],{"__typename":1805,"sys":1806,"title":1808,"synopsis":1809,"publishedDate":1810,"slug":1811,"authorsCollection":1812},"BlogPosts",{"id":1807},"7MB9tEe6mrdNXbkYVhgyWn","Shadow AI: how to discover, govern, and secure AI apps","Blocking AI tools doesn't stop employees from using AI — it stops you seeing how they use it. The solution: make the governed path easier than the workaround.","2026-08-13T00:00:00.000Z","shadow-ai-how-to-discover-govern-and-secure-ai-apps",{"items":1813},[1814],{"firstName":1815,"profilePicture":1816},"Kelly",{"url":1817},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F1hi8bEuVfn5sF57LivAq6d\u002F9a3b82426c697d765e2e450e33a18424\u002Fkelly_profile_pic.jpeg",{"__typename":1805,"sys":1819,"title":1821,"synopsis":1822,"publishedDate":1823,"slug":1824,"authorsCollection":1825},{"id":1820},"ThcZepauVfA5fKossdkbm","The top 10 browser security solutions: Push Security, Island, LayerX and more","Browser security means a lot of different things depending on who's talking. Here's your guide to the browser security market from a vendor perspective in 2026.","2026-07-27T00:00:00.000Z","the-top-10-browser-security-solutions-in-2026",{"items":1826},[1827],{"firstName":480,"profilePicture":1828},{"url":485},{"__typename":1805,"sys":1830,"title":1832,"synopsis":1833,"publishedDate":1834,"slug":1835,"authorsCollection":1836},{"id":1831},"4NY2NbkAPucFOJY45yrrrE","Shadow AI: what Push data reveals about the scale of the problem","Push telemetry shows the average organization has 16 AI apps, 17 AI browser extensions, and 17 AI OAuth integrations in use. Here's what it means for security.","2026-05-28T00:00:00.000Z","what-push-data-reveals-about-the-state-of-shadow-ai",{"items":1837},[1838],{"firstName":1839,"profilePicture":1840},"Dan",{"url":1841},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F7jik1VhFgA3kgzXBXTm2Vw\u002Ffcd8c171da644903d0827eafcfbcaad0\u002FDan_Headshot_2025.png","the-top-10-shadow-ai-discovery-and-governance-tools","blog\u002Fthe-top-10-shadow-ai-discovery-and-governance-tools",{"json":1845},{"data":1846,"content":1847,"nodeType":1516},{},[1848],{"data":1849,"content":1850,"nodeType":498},{},[1851],{"data":1852,"marks":1853,"value":1854,"nodeType":497},{},[],"Your guide to the tools that discover and govern how employees use AI in 2026: the approaches they take, what each can enforce, and how they fit alongside the native controls in the AI apps you already pay for.","Your guide to the tools that discover and govern how employees use AI in 2026.",{"id":1857,"publishedAt":1858},"2IV0lMBhJ75R696mo40kqZ","2026-10-09T12:54:40.642Z",{"items":1860},[1861],{"sys":1862,"name":1864},{"id":1863},"3pjES4THCIfSAwhGdNwBcy","Browser security",{"items":1866},[1867,1872,1877,1882,1887,1892,1897,1902,1907,1912,1916,1921],{"sys":1868,"name":1870,"slug":1871,"tier":29},{"id":1869},"topic-ai","AI","ai",{"sys":1873,"name":1875,"slug":1876,"tier":45},{"id":1874},"topic-ai-governance","AI governance","ai-governance",{"sys":1878,"name":1880,"slug":1881,"tier":45},{"id":1879},"topic-shadow-ai","Shadow AI","shadow-ai",{"sys":1883,"name":1885,"slug":1886,"tier":45},{"id":1884},"topic-dlp","DLP","dlp",{"sys":1888,"name":1890,"slug":1891,"tier":45},{"id":1889},"topic-shadow-saas","Shadow SaaS","shadow-saas",{"sys":1893,"name":1895,"slug":1896,"tier":45},{"id":1894},"topic-casb","CASB","casb",{"sys":1898,"name":1900,"slug":1901,"tier":45},{"id":1899},"topic-siem","SIEM","siem",{"sys":1903,"name":1905,"slug":1906,"tier":45},{"id":1904},"topic-swg","SWG","swg",{"sys":1908,"name":1910,"slug":1911,"tier":45},{"id":1909},"topic-edr","EDR","edr",{"sys":1913,"name":1044,"slug":1915,"tier":45},{"id":1914},"topic-enterprise-browser","enterprise-browser",{"sys":1917,"name":1919,"slug":1920,"tier":45},{"id":1918},"topic-browser-extensions","Browser extensions","browser-extensions",{"sys":1922,"name":1924,"slug":1925,"tier":45},{"id":1923},"topic-third-party-risk","Third-party risk","third-party-risk","Ywcb_N7fAB3gLonW_aG6VBvA7N80fKGwEQ_4OiUuy1o",{"id":1928,"extension":1537,"items":1929,"meta":2314,"stem":2315,"__hash__":2316},"blogTopics\u002Fblogtopics.json",[1930,1936,1945,1951,1960,1969,1978,1984,1992,1998,2007,2016,2024,2033,2041,2048,2054,2060,2066,2074,2083,2092,2101,2110,2119,2127,2136,2145,2154,2163,2172,2181,2190,2198,2207,2216,2225,2234,2243,2251,2257,2262,2268,2276,2284,2290,2296,2305],{"sys":1931,"faqItemsCollection":1932,"name":1870,"slug":1871,"tier":29,"intro":1934,"faqTitle":33,"postCount":1935,"hasPage":60},{"id":1869},{"items":1933},[],"AI is reshaping both sides of the security equation: employees adopt AI tools faster than security teams can track them, while attackers use AI to scale and automate campaigns. Shadow AI adoption may now outpace wider shadow SaaS, and attackers are already turning AI chatbot platforms into malware delivery channels. Push has researched the offensive potential of computer-using agents and now applies AI agents to its own threat hunting. This hub covers AI as risk, target, and defensive tool.",24,{"sys":1937,"faqItemsCollection":1939,"name":1941,"slug":1942,"tier":45,"intro":1943,"faqTitle":33,"postCount":1944,"hasPage":60},{"id":1938},"topic-ai-attacks",{"items":1940},[],"AI attacks","ai-attacks","AI attacks run in both directions: attackers using AI to scale phishing, malware delivery, and identity attacks, and AI platforms themselves becoming the attack surface. Push has researched how computer-using agents can automate identity attacks, and has seen the poisoned tenant technique it coined used against its own employees in the wild.",26,{"sys":1946,"faqItemsCollection":1947,"name":1875,"slug":1876,"tier":45,"intro":1949,"faqTitle":33,"postCount":1950,"hasPage":60},{"id":1874},{"items":1948},[],"AI governance is how organizations set and enforce rules for workplace AI use — which tools are allowed, what data can enter them, and how to evidence it to regulators. With US, EU, and UK AI regulations converging on obligations most organizations can’t yet meet, Push’s research makes the case that enforcement starts in the browser, where AI tools are actually used.",11,{"sys":1952,"faqItemsCollection":1954,"name":1956,"slug":1957,"tier":45,"intro":1958,"faqTitle":33,"postCount":1959,"hasPage":60},{"id":1953},"topic-aitm",{"items":1955},[],"AiTM phishing","aitm","Adversary-in-the-middle (AiTM) phishing proxies a real login page through an attacker-controlled site, capturing credentials, MFA codes, and session tokens in real time to bypass multi-factor authentication. Push’s research into kits like Evilginx and Sneaky2FA documents how they evade URL- and signature-based detection — and why analyzing toolkit behavior in the browser catches attacks that blocklists miss.",78,{"sys":1961,"faqItemsCollection":1963,"name":1965,"slug":1966,"tier":45,"intro":1967,"faqTitle":33,"postCount":1968,"hasPage":60},{"id":1962},"topic-bec",{"items":1964},[],"BEC","bec","Business email compromise (BEC) turns a hijacked mailbox into a fraud tool: attackers use mail rules, auto-forwarding, and payment redirection to steal money while staying invisible to the account owner. Alongside a first-hand case study of a BEC attack that nearly cost an engineering firm millions, Push breaks down these mailbox persistence tricks and how to detect them.",5,{"sys":1970,"faqItemsCollection":1972,"name":1974,"slug":1975,"tier":29,"intro":1976,"faqTitle":33,"postCount":1977,"hasPage":60},{"id":1971},"topic-browser-attacks",{"items":1973},[],"Browser attacks","browser-attacks","Browser attacks target users through the web pages, sessions, and extensions they rely on every day — bypassing endpoint and network defenses that never see inside the browser. Techniques like AiTM phishing kits, ClickFix-style copy-paste attacks, OAuth consent abuse, malvertising, and browser sync abuse have become a leading path to account takeover. Push researchers analyze these attacks in the wild, from infiltrating criminal phishing panels to dissecting toolkits like ConsentFix and Sneaky2FA. Use this hub to track how the techniques evolve and how to defend against them.",126,{"sys":1979,"faqItemsCollection":1980,"name":1919,"slug":1920,"tier":45,"intro":1982,"faqTitle":33,"postCount":1983,"hasPage":60},{"id":1918},{"items":1981},[],"Browser extensions cut both ways for security teams: malicious or compromised extensions are a growing attack vector, while an extension is also the lightest-weight way to deploy security controls into the browsers employees already use. These posts cover both sides — extension-borne risks like browser sync attacks and the limits of risk scoring, and how Push uses its extension to detect threats and block risky extensions.",32,{"sys":1985,"faqItemsCollection":1987,"name":1864,"slug":1989,"tier":29,"intro":1990,"faqTitle":33,"postCount":1991,"hasPage":60},{"id":1986},"topic-browser-security",{"items":1988},[],"browser-security","Work now happens in the browser, making browser security — visibility and control at the point where users meet the web — a core layer of enterprise defense. Endpoint, network, and email tools miss attacks that unfold inside the browser session, from AiTM phishing to risky extensions and shadow SaaS. Push has published extensively on choosing between enterprise browsers and browser extensions, using browser telemetry, and making the business case for browser security. Start here for both strategy and hands-on guidance.",130,{"sys":1993,"faqItemsCollection":1994,"name":1895,"slug":1896,"tier":45,"intro":1996,"faqTitle":33,"postCount":1997,"hasPage":60},{"id":1894},{"items":1995},[],"Cloud access security brokers (CASBs) govern cloud app usage through API integrations and network proxies — an approach that works for sanctioned apps but struggles with the long tail of shadow SaaS employees adopt on their own. Because every SaaS signup happens in a browser, Push captures that adoption in real time at the point of login, and these posts cover what proxy-based discovery misses.",13,{"sys":1999,"faqItemsCollection":2001,"name":2003,"slug":2004,"tier":45,"intro":2005,"faqTitle":33,"postCount":2006,"hasPage":60},{"id":2000},"topic-clickfix",{"items":2002},[],"ClickFix","clickfix","ClickFix attacks trick users into copying and running malicious commands themselves — typically through fake CAPTCHA, error, or fix-it prompts — so malware executes without a download for security tools to scan. Push researchers track the technique’s evolution in the wild and identified the ConsentFix and InstallFix variants, which extend it to OAuth consent grants and fake install guides.",43,{"sys":2008,"faqItemsCollection":2010,"name":2012,"slug":2013,"tier":45,"intro":2014,"faqTitle":33,"postCount":2015,"hasPage":60},{"id":2009},"topic-credential-phishing",{"items":2011},[],"Credential phishing","credential-phishing","Credential phishing steals usernames and passwords through fake login pages impersonating the services employees use, handing attackers direct access to corporate accounts. Attackers don’t hack in — they log in. Push’s browser extension analyzes login pages as users actually see them, blocking cloned pages and stopping employees from entering company passwords on lookalike sites.",90,{"sys":2017,"faqItemsCollection":2019,"name":180,"slug":2021,"tier":45,"intro":2022,"faqTitle":33,"postCount":2023,"hasPage":60},{"id":2018},"topic-credential-stuffing",{"items":2020},[],"credential-stuffing","Credential stuffing is an attack where criminals replay username-password pairs stolen from one breach against other services, exploiting password reuse to take over accounts. Major breaches have shown how far a single set of stolen credentials can travel. Push detects verified stolen credentials by comparing employee passwords against breach datasets and dark-web threat intelligence, eliminating false positives.",64,{"sys":2025,"faqItemsCollection":2027,"name":2029,"slug":2030,"tier":29,"intro":2031,"faqTitle":33,"postCount":2032,"hasPage":60},{"id":2026},"topic-detection-and-response",{"items":2028},[],"Detection & response","detection-and-response","Detection and response is being reshaped as attacks move into the browser, where EDR, SIEM, and network tools have limited visibility. Modern phishing kits evade signature-based detection, and most malicious pages have never been seen before — so technique-level, in-browser detection matters more than known-bad indicators. Push’s work here spans high-fidelity browser telemetry, session token theft detection, and agentic threat hunting, plus practical IR guidance for compromised SaaS accounts and malicious OAuth apps. These posts cover both the philosophy and the workflows.",103,{"sys":2034,"faqItemsCollection":2036,"name":2038,"slug":2039,"tier":45,"intro":2040,"faqTitle":33,"postCount":2006,"hasPage":60},{"id":2035},"topic-detection-engineering",{"items":2037},[],"Detection engineering","detection-engineering","Detection engineering turns threat research into reliable, high-fidelity detections — and as AI accelerates the churn of attacker infrastructure, indicator-based detection is collapsing in favor of technique-level approaches. Here you’ll find teardowns of AiTM kits, ClickFix pages, and malvertising campaigns, alongside Push’s own account of building an agentic threat hunting pipeline that turns hunts into shipped detections.",{"sys":2042,"faqItemsCollection":2044,"name":141,"slug":2046,"tier":45,"intro":2047,"faqTitle":33,"postCount":1935,"hasPage":60},{"id":2043},"topic-device-code-phishing",{"items":2045},[],"device-code-phishing","Device code phishing abuses the OAuth device authorization flow: attackers generate a legitimate sign-in code, trick the victim into entering it on the vendor’s real login page, and walk away with access tokens — no fake site or password capture required. Push research tracked a sharp spike in adoption during 2026 as attackers use the technique to sidestep standard access controls.",{"sys":2049,"faqItemsCollection":2050,"name":1885,"slug":1886,"tier":45,"intro":2052,"faqTitle":33,"postCount":2053,"hasPage":60},{"id":1884},{"items":2051},[],"Data loss prevention (DLP) is the practice of stopping sensitive data from leaving your control — a problem that has shifted from email and endpoints to the browser, where employees move data into SaaS and AI tools. Push applies controls at that point of use, from keeping corporate credentials out of personal password managers to governing what flows into unsanctioned apps.",17,{"sys":2055,"faqItemsCollection":2056,"name":1910,"slug":1911,"tier":45,"intro":2058,"faqTitle":33,"postCount":2059,"hasPage":60},{"id":1909},{"items":2057},[],"Endpoint detection and response (EDR) watches processes, files, and memory on the device — a vantage point that never sees the phishing pages, stolen sessions, and identity attacks playing out inside the browser. That’s not an EDR failure; attackers have simply moved where it can’t follow. These posts map that gap and show how Push pairs browser-level detection and response with endpoint security to close it.",28,{"sys":2061,"faqItemsCollection":2062,"name":1044,"slug":1915,"tier":45,"intro":2064,"faqTitle":33,"postCount":2065,"hasPage":60},{"id":1914},{"items":2063},[],"An enterprise browser is a standalone, security-hardened browser that organizations deploy in place of Chrome, Edge, or other defaults. The real buying question is whether replacing the browser beats securing the browsers employees already use — a trade-off these posts examine directly, alongside analysis of Omdia’s secure enterprise browser market report and Push’s framework for weighing full browsers against extension-based deployment.",10,{"sys":2067,"faqItemsCollection":2069,"name":170,"slug":2071,"tier":45,"intro":2072,"faqTitle":33,"postCount":2073,"hasPage":60},{"id":2068},"topic-ghost-logins",{"items":2070},[],"ghost-logins","Ghost logins are overlooked authentication routes into an account — like a password login lingering behind SSO, or a forgotten secondary auth method — that attackers exploit for account takeover and persistence. Push coined the term after research showing how these forgotten login paths let attackers sidestep the MFA and SSO controls guarding an account’s primary sign-in method.",48,{"sys":2075,"faqItemsCollection":2077,"name":2079,"slug":2080,"tier":45,"intro":2081,"faqTitle":33,"postCount":2082,"hasPage":60},{"id":2076},"topic-identity-attacks",{"items":2078},[],"Identity attacks","identity-attacks","Identity attacks target user accounts rather than infrastructure — phishing credentials, stealing sessions, abusing OAuth grants — because logging in is easier than hacking in. Identity-based techniques are now the leading cause of breaches. Push’s offensive research maps these techniques continuously, coining attacks like SAMLjacking and the poisoned tenant before they appeared in the wild.",59,{"sys":2084,"faqItemsCollection":2086,"name":2088,"slug":2089,"tier":29,"intro":2090,"faqTitle":33,"postCount":2091,"hasPage":60},{"id":2085},"topic-identity-security",{"items":2087},[],"Identity security","identity-security","Identity security is the practice of protecting workforce accounts, credentials, and sessions — the primary route attackers now use to breach organizations. Instead of hacking in, attackers log in: through phished credentials, stolen session tokens, MFA bypass, and forgotten ghost logins. Push’s research team documents these techniques continuously, from cross-IdP impersonation and SAMLjacking to analyses of major identity-driven breaches. This hub collects that research alongside practical guidance on MFA, SSO, and stopping account takeover.",154,{"sys":2093,"faqItemsCollection":2095,"name":2097,"slug":2098,"tier":45,"intro":2099,"faqTitle":33,"postCount":2100,"hasPage":60},{"id":2094},"topic-infostealer",{"items":2096},[],"Infostealer","infostealer","Infostealers are malware built to harvest saved passwords, cookies, and session tokens from infected devices, supplying the stolen credentials behind some of the most consequential breaches of recent years. Push traces the ecosystem trading this data and checks employee passwords against threat intel feeds, flagging verified stolen credentials before attackers can log in with them.",56,{"sys":2102,"faqItemsCollection":2104,"name":2106,"slug":2107,"tier":45,"intro":2108,"faqTitle":33,"postCount":2109,"hasPage":60},{"id":2103},"topic-legitimate-service-abuse",{"items":2105},[],"Legitimate service abuse","legitimate-service-abuse","Legitimate service abuse means staging attacks on trusted platforms — Google Ads, AI chatbot share pages, office.com links, Slack, SaaS tenants — so malicious content inherits the reputation of the service hosting it. Push research has documented the pattern repeatedly, from malvertising run through hijacked Google Ad Manager accounts to phishing links generated by Active Directory Federation Services.",29,{"sys":2111,"faqItemsCollection":2113,"name":2115,"slug":2116,"tier":45,"intro":2117,"faqTitle":33,"postCount":2118,"hasPage":60},{"id":2112},"topic-malvertising",{"items":2114},[],"Malvertising","malvertising","Malvertising uses paid search and display ads to put phishing pages and malware in front of users, often by impersonating trusted brands at the top of Google results. Push tracks these campaigns continuously — intercepting live attacks spoofing well-known brands — and has documented how criminals hijack Google Ads accounts to fund and run them.",34,{"sys":2120,"faqItemsCollection":2122,"name":2124,"slug":2125,"tier":45,"intro":2126,"faqTitle":33,"postCount":2053,"hasPage":60},{"id":2121},"topic-malware-delivery",{"items":2123},[],"Malware delivery","malware-delivery","Malware delivery has moved into the browser: rather than email attachments, attackers now rely on malvertising, fake install guides, and ClickFix-style copy-paste lures to get code running on endpoints. Push research on techniques like InstallFix maps the playbook, and in-browser detection of malicious copy and paste blocks these attacks before commands reach the endpoint.",{"sys":2128,"faqItemsCollection":2130,"name":2132,"slug":2133,"tier":45,"intro":2134,"faqTitle":33,"postCount":2135,"hasPage":60},{"id":2129},"topic-mfa",{"items":2131},[],"MFA","mfa","Multi-factor authentication (MFA) requires a second proof of identity beyond a password, and it remains one of the most effective controls against account takeover. Regulators from Cyber Essentials to NYDFS now mandate it across cloud services. Push enforces MFA in the browser on third-party apps — even those with no native enforcement option — and shows security teams where coverage gaps remain.",83,{"sys":2137,"faqItemsCollection":2139,"name":2141,"slug":2142,"tier":45,"intro":2143,"faqTitle":33,"postCount":2144,"hasPage":60},{"id":2138},"topic-mfa-bypass",{"items":2140},[],"MFA bypass","mfa-bypass","MFA bypass covers the techniques attackers use to defeat multi-factor authentication — AiTM phishing kits, consent phishing, device code phishing, and MFA downgrade attacks among them. None of these break the second factor; they route around it. Push researchers regularly get hands-on with phishing kits like Evilginx and Sneaky2FA, analyzing how these attacks work in the wild and how they evolve.",60,{"sys":2146,"faqItemsCollection":2148,"name":2150,"slug":2151,"tier":45,"intro":2152,"faqTitle":33,"postCount":2153,"hasPage":60},{"id":2147},"topic-non-email-phishing",{"items":2149},[],"Non-email phishing","non-email-phishing","Non-email phishing delivers malicious links through channels your secure email gateway never sees — social media messages, IM apps like Slack and Teams, search ads, and SMS. Push has intercepted live campaigns arriving via LinkedIn DMs, malvertising, and messaging platforms, which is why it detects phishing pages in the browser at the point of click, regardless of delivery channel.",53,{"sys":2155,"faqItemsCollection":2157,"name":2159,"slug":2160,"tier":45,"intro":2161,"faqTitle":33,"postCount":2162,"hasPage":60},{"id":2156},"topic-oauth-abuse",{"items":2158},[],"OAuth abuse","oauth-abuse","OAuth abuse is attackers exploiting app-to-app authorization — consent phishing, malicious OAuth apps, stolen tokens, and device code flows — to gain persistent access to cloud tenants without touching a password or MFA prompt. Push tracks these techniques continuously and discovered ConsentFix, a browser-native attack in the wild that pairs OAuth consent phishing with a ClickFix-style prompt.",70,{"sys":2164,"faqItemsCollection":2166,"name":2168,"slug":2169,"tier":45,"intro":2170,"faqTitle":33,"postCount":2171,"hasPage":60},{"id":2165},"topic-passkeys",{"items":2167},[],"Passkeys","passkeys","Passkeys are phishing-resistant credentials that replace passwords with cryptographic key pairs bound to a user’s device. They defeat conventional credential phishing, but attackers adapt: Push research has documented MFA downgrade, app-specific password phishing, and device code phishing being used in the wild to route around passkey-protected accounts. Deploying passkeys is step one; closing those fallback paths is step two.",23,{"sys":2173,"faqItemsCollection":2175,"name":2177,"slug":2178,"tier":45,"intro":2179,"faqTitle":33,"postCount":2180,"hasPage":60},{"id":2174},"topic-password-security",{"items":2176},[],"Password security","password-security","Password security is the practice of keeping workforce credentials strong, unique, and out of attackers’ hands — still a frontline defense while most SaaS logins depend on passwords. Expiration policies don’t fix weak or reused passwords; visibility does. Push observes real logins in the browser to flag weak, reused, and breached passwords and guide employees to reset them on any app.",80,{"sys":2182,"faqItemsCollection":2184,"name":2186,"slug":2187,"tier":45,"intro":2188,"faqTitle":33,"postCount":2189,"hasPage":60},{"id":2183},"topic-phaas",{"items":2185},[],"PhaaS","phaas","Phishing-as-a-service (PhaaS) platforms sell ready-made phishing kits, hosted infrastructure, and management panels on subscription, letting low-skill criminals run MFA-bypassing campaigns at scale. Kits like Evilginx, Tycoon2FA, Sneaky2FA, FlowerStorm, and EvilTokens each add their own evasion and session-theft capabilities, and new entrants appear regularly. Push researchers continuously get hands-on with these tools — investigating attacks in the wild, reverse-engineering kit behavior, and turning that research into detections.",41,{"sys":2191,"faqItemsCollection":2193,"name":126,"slug":2195,"tier":29,"intro":2196,"faqTitle":33,"postCount":2197,"hasPage":60},{"id":2192},"topic-phishing",{"items":2194},[],"phishing","Phishing remains the most common way attackers compromise business accounts — and it has moved far beyond suspicious emails. Modern campaigns use AiTM toolkits that bypass MFA, consent phishing against OAuth, device code phishing, and lures delivered through malvertising, LinkedIn, and Slack. Push detects and blocks these attacks in the browser, and its researchers publish teardowns of live campaigns and kits like Evilginx and Sneaky2FA. Read on for how phishing actually works today and what stops it.",94,{"sys":2199,"faqItemsCollection":2201,"name":2203,"slug":2204,"tier":45,"intro":2205,"faqTitle":33,"postCount":2206,"hasPage":60},{"id":2200},"topic-public-breach",{"items":2202},[],"Public breach","public-breach","Public breaches are the disclosed incidents that show how attacks actually unfold once the headlines fade. Push’s breach analyses keep finding identity at the entry point: stolen credentials, OAuth abuse, and missing MFA recur across the incidents analyzed here.",30,{"sys":2208,"faqItemsCollection":2210,"name":2212,"slug":2213,"tier":45,"intro":2214,"faqTitle":33,"postCount":2215,"hasPage":60},{"id":2209},"topic-ransomware",{"items":2211},[],"Ransomware","ransomware","Ransomware attacks increasingly begin with an identity, not an exploit: stolen credentials, MFA bypass, and help desk scams give operators their initial foothold. The analysis here follows that front end of the kill chain — how identity compromise leads to ransomware deployment, and the breaches driving regulators toward tighter MFA requirements.",14,{"sys":2217,"faqItemsCollection":2219,"name":2221,"slug":2222,"tier":29,"intro":2223,"faqTitle":33,"postCount":2224,"hasPage":60},{"id":2218},"topic-saas-security",{"items":2220},[],"SaaS security","saas-security","SaaS security means protecting the sprawl of cloud apps, accounts, and integrations your employees adopt — often without IT ever knowing. Shadow SaaS, risky OAuth grants, ghost logins, and unmanaged third-party access create attack paths traditional controls can’t see, as recent high-profile breaches have demonstrated. Building on the original SaaS attack matrix, Push continues to map SaaS-native attack techniques alongside practical guides for discovering and securing unsanctioned apps, and this hub gathers all of it.",97,{"sys":2226,"faqItemsCollection":2228,"name":2230,"slug":2231,"tier":45,"intro":2232,"faqTitle":33,"postCount":2233,"hasPage":6},{"id":2227},"topic-security-training",{"items":2229},[],"Security training","security-training","Security training aims to teach employees to recognize and avoid attacks — yet modern phishing routinely fools even seasoned security professionals. Push argues that training budgets work harder as real-time, in-browser intervention: guardrails and warnings at the moment of risk, rather than lessons employees must recall under pressure.",4,{"sys":2235,"faqItemsCollection":2237,"name":2239,"slug":2240,"tier":45,"intro":2241,"faqTitle":33,"postCount":2242,"hasPage":60},{"id":2236},"topic-seo-poisoning",{"items":2238},[],"SEO poisoning","seo-poisoning","SEO poisoning manipulates search engine results so malicious pages rank prominently for the software, tools, or services users are actively searching for, turning a routine search into an infection vector. It often pairs with malvertising and ClickFix-style payloads — Push has documented attackers abusing shared pages on legitimate AI chatbot domains to deliver malware from trusted infrastructure.",8,{"sys":2244,"faqItemsCollection":2246,"name":185,"slug":2248,"tier":45,"intro":2249,"faqTitle":33,"postCount":2250,"hasPage":60},{"id":2245},"topic-session-hijacking",{"items":2247},[],"session-hijacking","Session hijacking is the theft of an authenticated session — usually via stolen session cookies or tokens — letting attackers walk past passwords and MFA into a live account. AiTM phishing kits and infostealers have made it a mainstream attack technique across both criminal and targeted intrusions. Push’s browser agent detects session token theft by adding telemetry to the user agent string, creating a high-fidelity signal for security teams.",77,{"sys":2252,"faqItemsCollection":2253,"name":1880,"slug":1881,"tier":45,"intro":2255,"faqTitle":33,"postCount":2256,"hasPage":60},{"id":1879},{"items":2254},[],"Shadow AI is employees’ unsanctioned use of AI tools at work, putting corporate data into chatbots and assistants that security teams never approved and can’t see. Push’s own browser telemetry shows AI adoption acting as a force multiplier for shadow IT — potentially now outscaling shadow SaaS — and this hub tracks that research, real-world breach examples, and practical controls.",22,{"sys":2258,"faqItemsCollection":2259,"name":1890,"slug":1891,"tier":45,"intro":2261,"faqTitle":33,"postCount":2250,"hasPage":60},{"id":1889},{"items":2260},[],"Shadow SaaS is the cloud applications employees adopt for work without IT approval, each one creating unmanaged accounts, identities, and data outside your security controls. Push covers the problem end to end — from browser-based SaaS discovery to in-browser app banners and MFA enforcement — alongside breach analyses that show where unmanaged accounts lead.",{"sys":2263,"faqItemsCollection":2264,"name":1900,"slug":1901,"tier":45,"intro":2266,"faqTitle":33,"postCount":2267,"hasPage":60},{"id":1899},{"items":2265},[],"A SIEM is only as good as the telemetry feeding it, and most log sources never see what happens inside the browser — where phishing, session token theft, and account takeover actually play out. Push streams browser-level detections and identity telemetry into SIEMs, and these posts show how that data improves detection fidelity and cuts alert fatigue.",21,{"sys":2269,"faqItemsCollection":2271,"name":2273,"slug":2274,"tier":45,"intro":2275,"faqTitle":33,"postCount":2023,"hasPage":60},{"id":2270},"topic-social-engineering",{"items":2272},[],"Social engineering","social-engineering","Social engineering is the manipulation of people — through phishing pages, help desk impersonation, vishing calls, and poisoned tenant invites — into handing over access that no exploit could take. Coverage here tracks how threat actors run these plays — drawing on Push’s ongoing investigation of live phishing infrastructure and criminal tooling.",{"sys":2277,"faqItemsCollection":2279,"name":2281,"slug":2282,"tier":29,"intro":2283,"faqTitle":33,"postCount":2233,"hasPage":6},{"id":2278},"topic-supply-chain-security",{"items":2280},[],"Supply chain security","supply-chain-security","Supply chain security extends beyond your own perimeter to the vendors, platforms, and browser extensions your organization depends on. A compromised third party can hand attackers legitimate access — as recent campaigns against SaaS providers have shown. Push’s research examines the browser-extension supply chain in particular: why extension risk scores fail to predict compromise, and how developers can harden extensions against takeover. These posts frame supply chain risk through a browser and identity lens.",{"sys":2285,"faqItemsCollection":2286,"name":1905,"slug":1906,"tier":45,"intro":2288,"faqTitle":33,"postCount":2289,"hasPage":60},{"id":1904},{"items":2287},[],"A secure web gateway (SWG) filters and inspects web traffic in transit, sitting in the network path between users and the internet. That position shows you the packet but not the session: Push’s research on AitM phishing kits documents how attackers break the signatures proxies rely on, and these posts explain why phishing detection is moving from the network path into the browser itself.",19,{"sys":2291,"faqItemsCollection":2292,"name":1924,"slug":1925,"tier":45,"intro":2294,"faqTitle":33,"postCount":2295,"hasPage":60},{"id":1923},{"items":2293},[],"Third-party risk is the exposure your organization inherits from vendors, SaaS providers, and integrations that hold your data or access your tenants — a chain now extended one employee sign-up at a time. This hub collects Push’s breach analyses and guides for assessing OAuth integrations, managing browser extensions, and responding when a supplier is compromised.",45,{"sys":2297,"faqItemsCollection":2299,"name":2301,"slug":2302,"tier":29,"intro":2303,"faqTitle":33,"postCount":2304,"hasPage":60},{"id":2298},"topic-threat-landscape",{"items":2300},[],"Threat landscape","threat-landscape","The enterprise threat landscape is now defined by identity attacks: criminals log in with phished, stolen, or stuffed credentials rather than breaking infrastructure. Threat actors keep proving how effective help desk scams, MFA bypass, and session theft are against well-defended organizations. Drawing on breach analyses, annual phishing trend reviews, and in-the-wild campaign tracking, Push documents how attacker TTPs are shifting. This hub is where to follow those changes.",52,{"sys":2306,"faqItemsCollection":2308,"name":2310,"slug":2311,"tier":45,"intro":2312,"faqTitle":33,"postCount":2313,"hasPage":60},{"id":2307},"topic-vishing",{"items":2309},[],"Vishing","vishing","Vishing — voice phishing — uses phone calls to impersonate IT support, help desks, or employees, talking targets into password resets, MFA approvals, or opening attacker-controlled pages. Threat actors now routinely pair calls with AiTM phishing to hijack SSO accounts, a chain Push has analyzed across campaigns targeting hundreds of organizations.",16,{},"blogtopics","VRRMwuyoErKjQX0UcVvfC8Wz9Q98OpB99BfmJteMepQ",1791552950373]