Shadow AI: how to discover, govern, and secure AI apps
Blocking AI tools doesn't stop employees from using AI — it stops you seeing how they use it. The solution: make the governed path easier than the workaround.
Stop account takeover
Stop ATO with stolen credential and compromised token detection.
Harden unmanaged identities
Harden access paths with visibility, detection, and guardrails.
Investigate browser-related incidents
Investigate and respond faster with unique browser telemetry.
Secure shadow SaaS
See and control shadow SaaS in the browser.
Secure AI
See and control AI apps in the browser.
Secure BYOD
Extend consistent browser-based protection to unmanaged devices.
Secure Chromebooks
Secure browser activity on Chromebooks without endpoint agents.
Investigate and stop data loss
Detect and prevent data loss across AI tools, apps, and sessions.
22 posts
AI is reshaping both sides of the security equation: employees adopt AI tools faster than security teams can track them, while attackers use AI to scale and automate campaigns. Shadow AI adoption may now outpace wider shadow SaaS, and attackers are already turning AI chatbot platforms into malware delivery channels. Push has researched the offensive potential of computer-using agents and now applies AI agents to its own threat hunting. This hub covers AI as risk, target, and defensive tool.
Blocking AI tools doesn't stop employees from using AI — it stops you seeing how they use it. The solution: make the governed path easier than the workaround.
Security outcomes you can achieve when AI agents hunt in the browser, identify new threats, and ship detections that benefit everyone.
Someone created a fake OpenAI organization using our company's name and invited specific Push employees to join it. Here's what we learned.
Most organizations know they have an AI security problem. A new SANS framework shows why so few are making progress - and what it actually takes to get unstuck.
AI regulations across the US, EU, and UK are converging on obligations that most organizations can't meet without browser visibility into AI tool use.
Why the right browser security tool makes a separate AI visibility and control purchase unnecessary — and how to decide what you actually need.
Push uses commercial AI models to deliver agentic threat hunting. Can’t you just build something yourself with those same models? Well, no.
AI is accelerating the collapse of indicator-based threat detection. Here's why you need technique-level detection to stay ahead.
How attackers are using shared content features on AI chatbot platforms to deliver malware via pages hosted on legitimate domains, sent via malvertising.
Browser security is one of the fastest-growing investment areas in enterprise security. Here's our proven framework to create budget for browser security tools.
Push telemetry shows the average organization has 16 AI apps, 17 AI browser extensions, and 17 AI OAuth integrations in use. Here's what it means for security.
What we can learn from 2026's installment of the Verizon Data Breach Investigations Report.
Here are 7 things we learned from our conversation with John Hammond on the "Why the browser is the new battleground" webinar.
Why "good enough" isn’t enough when it comes to browser security, and a best-of-breed approach is needed to tackle emerging threats.
Ranking the security problems you can solve in the browser by security value and browser fit.
Unpacking the latest research report from Omdia and what it means for the secure enterprise browser market.
How we built an end-to-end threat hunting and detection engineering capability at Push that uses AI agents as a force multiplier.
How CISOs can use browser telemetry to support cyber risk quantification in areas where traditional data points fall short.
In April 2026, Vercel was compromised via an OAuth app integrated into their Google Workspace tenant stemming from a compromised third-party AI SaaS provider.
We're back with part 2 of our research into OpenAI Operator to share our findings on how it can be used to automate identity attacks.
Credential stuffing attacks had a huge impact in 2024. But things could be dialled up even further with Computer-Using Agents like OpenAI Operator.
CUAs are a new type of AI agent that drives your browser/OS for you, enabling effortless automation of web tasks — including those performed by attackers.
The latest news, articles, and resources, sent to your inbox.