Shadow AI: how to discover, govern, and secure AI apps
Blocking AI tools doesn't stop employees from using AI — it stops you seeing how they use it. The solution: make the governed path easier than the workaround.
Stop account takeover
Stop ATO with stolen credential and compromised token detection.
Harden unmanaged identities
Harden access paths with visibility, detection, and guardrails.
Investigate browser-related incidents
Investigate and respond faster with unique browser telemetry.
Secure shadow SaaS
See and control shadow SaaS in the browser.
Secure AI
See and control AI apps in the browser.
Secure BYOD
Extend consistent browser-based protection to unmanaged devices.
Secure Chromebooks
Secure browser activity on Chromebooks without endpoint agents.
Investigate and stop data loss
Detect and prevent data loss across AI tools, apps, and sessions.
22 posts
AI attacks run in both directions: attackers using AI to scale phishing, malware delivery, and identity attacks, and AI platforms themselves becoming the attack surface. Push has researched how computer-using agents can automate identity attacks, and has seen the poisoned tenant technique it coined used against its own employees in the wild.
Blocking AI tools doesn't stop employees from using AI — it stops you seeing how they use it. The solution: make the governed path easier than the workaround.
Someone created a fake OpenAI organization using our company's name and invited specific Push employees to join it. Here's what we learned.
Organizations spend billions annually on awareness training. Here's why browser-based technical controls can make the difference where training falls short.
This article explains the gap between what EDR sees and what happens inside the browser, and what it takes to close it.
Why the right browser security tool makes a separate AI visibility and control purchase unnecessary — and how to decide what you actually need.
Push uses commercial AI models to deliver agentic threat hunting. Can’t you just build something yourself with those same models? Well, no.
AI is accelerating the collapse of indicator-based threat detection. Here's why you need technique-level detection to stay ahead.
How attackers are using shared content features on AI chatbot platforms to deliver malware via pages hosted on legitimate domains, sent via malvertising.
What we learned from sitting down with Matt Johansen to discuss the difference between security theater and security that actually works.
What we can learn from 2026's installment of the Verizon Data Breach Investigations Report.
Here are 7 things we learned from our conversation with John Hammond on the "Why the browser is the new battleground" webinar.
Why "good enough" isn’t enough when it comes to browser security, and a best-of-breed approach is needed to tackle emerging threats.
Unpacking the latest research report from Omdia and what it means for the secure enterprise browser market.
Securing the browser vs. securing the organization via the browser — what's the difference?
How we built an end-to-end threat hunting and detection engineering capability at Push that uses AI agents as a force multiplier.
We got an inside look at a phishing panel used in criminal campaigns linked to operators like ShinyHunters and BlackFile. Here’s what we found.
Investigating a new criminal toolkit for ConsentFix being promoted on criminal forums.
Attackers are impersonating popular developer tools like Claude Code to distribute fake install instructions via malicious search engine ads.
Investigating a phishing campaign targeting Google Ads Manager MCC accounts to propagate malvertising lures.
We're back with part 2 of our research into OpenAI Operator to share our findings on how it can be used to automate identity attacks.
Credential stuffing attacks had a huge impact in 2024. But things could be dialled up even further with Computer-Using Agents like OpenAI Operator.
CUAs are a new type of AI agent that drives your browser/OS for you, enabling effortless automation of web tasks — including those performed by attackers.
The latest news, articles, and resources, sent to your inbox.