Shadow AI: how to discover, govern, and secure AI apps
Blocking AI tools doesn't stop employees from using AI — it stops you seeing how they use it. The solution: make the governed path easier than the workaround.
Stop account takeover
Stop ATO with stolen credential and compromised token detection.
Harden unmanaged identities
Harden access paths with visibility, detection, and guardrails.
Investigate browser-related incidents
Investigate and respond faster with unique browser telemetry.
Secure shadow SaaS
See and control shadow SaaS in the browser.
Secure AI
See and control AI apps in the browser.
Secure BYOD
Extend consistent browser-based protection to unmanaged devices.
Secure Chromebooks
Secure browser activity on Chromebooks without endpoint agents.
Investigate and stop data loss
Detect and prevent data loss across AI tools, apps, and sessions.
30 posts
Browser extensions cut both ways for security teams: malicious or compromised extensions are a growing attack vector, while an extension is also the lightest-weight way to deploy security controls into the browsers employees already use. These posts cover both sides — extension-borne risks like browser sync attacks and the limits of risk scoring, and how Push uses its extension to detect threats and block risky extensions.
Blocking AI tools doesn't stop employees from using AI — it stops you seeing how they use it. The solution: make the governed path easier than the workaround.
Most organizations know they have an AI security problem. A new SANS framework shows why so few are making progress - and what it actually takes to get unstuck.
AI regulations across the US, EU, and UK are converging on obligations that most organizations can't meet without browser visibility into AI tool use.
Why the right browser security tool makes a separate AI visibility and control purchase unnecessary — and how to decide what you actually need.
Push telemetry shows the average organization has 16 AI apps, 17 AI browser extensions, and 17 AI OAuth integrations in use. Here's what it means for security.
What we learned from sitting down with Matt Johansen to discuss the difference between security theater and security that actually works.
If you're building a shortlist of browser security vendors, do you need a full-stack enterprise browser, or browser security extension?
What we can learn from 2026's installment of the Verizon Data Breach Investigations Report.
Why "good enough" isn’t enough when it comes to browser security, and a best-of-breed approach is needed to tackle emerging threats.
Ranking the security problems you can solve in the browser by security value and browser fit.
Unpacking the latest research report from Omdia and what it means for the secure enterprise browser market.
Securing the browser vs. securing the organization via the browser — what's the difference?
How CISOs can use browser telemetry to support cyber risk quantification in areas where traditional data points fall short.
We're re-releasing the SaaS attack matrix as the Browser & Identity Attacks Matrix. Here's why we've decided to make the change and what it means.
Why typical browser extension risk scores are poor predictors of which extensions will actually lead to a compromise.
In April 2026, Vercel was compromised via an OAuth app integrated into their Google Workspace tenant stemming from a compromised third-party AI SaaS provider.
Browser sync attacks result in business credentials being compromised via personal account and device breaches. Here's what you need to know.
How to use in-browser controls to stop browser-based attacks before compromise can occur
Here’s what’s new on the Push platform for March 2026.
How to detect risky and malicious extensions and block them from running in employee browsers.
Why extending detection and response into the browser is crucial in the face of modern attacks that consciously evade the network and endpoint.
Here’s how real-world attacks and our own R&D informed what we built for Push customers over the last year.
Analyzing the key trends that defined phishing attacks in 2025, and what these changes mean for security teams heading into 2026.
How Scattered Lapsus$ Hunters breaches demonstrate the evolution of attacker TTPs, shaping the future of cyber attacks.
Here’s what’s new on the Push platform for November 2025.
What security teams need to know about the browser-based attack techniques that are the leading cause of breaches.
How attacks have moved away from endpoints and internal networks to the browser — a blind spot for traditional security tools.
CUAs are a new type of AI agent that drives your browser/OS for you, enabling effortless automation of web tasks — including those performed by attackers.
How extension developers can improve their security controls to prevent extension compromise.
Browser extensions are the most effective SaaS discovery tool because they can capture employee SaaS use and adoption in real time, as employees sign up.
The latest news, articles, and resources, sent to your inbox.