Shadow AI: how to discover, govern, and secure AI apps
Blocking AI tools doesn't stop employees from using AI — it stops you seeing how they use it. The solution: make the governed path easier than the workaround.
Stop account takeover
Stop ATO with stolen credential and compromised token detection.
Harden unmanaged identities
Harden access paths with visibility, detection, and guardrails.
Investigate browser-related incidents
Investigate and respond faster with unique browser telemetry.
Secure shadow SaaS
See and control shadow SaaS in the browser.
Secure AI
See and control AI apps in the browser.
Secure BYOD
Extend consistent browser-based protection to unmanaged devices.
Secure Chromebooks
Secure browser activity on Chromebooks without endpoint agents.
Investigate and stop data loss
Detect and prevent data loss across AI tools, apps, and sessions.
42 posts
Detection engineering turns threat research into reliable, high-fidelity detections — and as AI accelerates the churn of attacker infrastructure, indicator-based detection is collapsing in favor of technique-level approaches. Here you’ll find teardowns of AiTM kits, ClickFix pages, and malvertising campaigns, alongside Push’s own account of building an agentic threat hunting pipeline that turns hunts into shipped detections.
Blocking AI tools doesn't stop employees from using AI — it stops you seeing how they use it. The solution: make the governed path easier than the workaround.
Security outcomes you can achieve when AI agents hunt in the browser, identify new threats, and ship detections that benefit everyone.
Push uses commercial AI models to deliver agentic threat hunting. Can’t you just build something yourself with those same models? Well, no.
AI is accelerating the collapse of indicator-based threat detection. Here's why you need technique-level detection to stay ahead.
How we built an end-to-end threat hunting and detection engineering capability at Push that uses AI agents as a force multiplier.
How to use in-browser controls to stop browser-based attacks before compromise can occur
How to detect risky and malicious extensions and block them from running in employee browsers.
New insights on the ConsentFix campaign stopped by Push.
Push recently detected and blocked a malvertising attack impersonating TradingView designed to hijack Google Workspace accounts.
Analysing a malvertising attack targeting Google business accounts that was intercepted by Push.
Investigating a phishing campaign targeting Google Ads Manager MCC accounts to propagate malvertising lures.
Analyzing a BITB phishing page linked to the Sneaky2FA Phishing-as-a-Service operation.
Breaking down the most sophisticated ClickFix page we’ve seen in the wild — and what it tells us about the future of malicious copy-and-paste attacks.
Diving into the latest sophisticated LinkedIn phishing campaign intercepted by Push.
Push now detects malware delivery in the browser, supporting a layered defense against endpoint attacks.
How browser data can improve detection fidelity and reduce alert fatigue, enabling SecOps teams to save time and detect more attacks.
How Push saved a company exec from a sophisticated Attacker-in-the-Middle phishing attack delivered via a LinkedIn direct message.
Push recently identified a novel phishing attack using Active Directory Federation Services to get Microsoft to send victims to a phishing site.
Introducing our latest resource for security teams breaking down the techniques that modern phishing attacks are using to evade detection.
We’re launching a new Detections capability, enabling security teams to more effectively investigate and triage alerts, and build more effective workflows.
Push now blocks URL schema obfuscation, countering a common technique used by attackers to bypass URL detections for phishing pages and malicious IPs.
Attackers are routinely defeating conventional email, network, and endpoint-based security controls. Here's how browser controls can level the playing field.
We’re thrilled to announce our partnership with Cribl to make it much easier to snapshot, transform, and query Push telemetry.
Why being in the browser gives defenders a key advantage over network and email phishing prevention, detection, and response tools.
Most phishing attacks involve a phishing page that has never been seen before. When detection relies on known-bad, this makes every attack feel like a zero-day.
We recently investigated a malvertising campaign using Evilginx to target Onfido customers via Google ads.
Consent phishing is where attackers trick users into authorizing access for malicious OAuth apps. Here's how attackers are using this technique in the wild.
Modern MFA-bypass phishing attacks are routinely defeating primarily email-based security controls. Why are controls failing and what can we do about it?
How attackers are breaking detection signatures designed to identify phishing sites impersonating real login pages.
Why relying on post-compromise detection and response is no longer an option for modern browser-based attacks.
How Push detects and blocks phishing attempts in the browser – explained in less than two minutes.
How Push stops attackers from using identity attack tools and techniques to compromise your employee user accounts.
We've added cloned login page detection, providing yet another layer of protection against phishing attacks.
This is the first blog in a short series we’re putting together about the ‘why’ behind the ‘what’ at Push. This entry is focused on threat detection.
Taking a closer look at the steps that AitM phishing kits take to hide from the prying eyes of security teams and threat intelligence vendors.
Enable detections and interventions in the browser using Push’s new security controls.
Push is excited to partner with Panther, bringing our unique browser telemetry to your SIEM.
Push's browser agent identifies session token theft by adding telemetry to the user agent string to create a new high-fidelity signal for your security team.
Push analyzes behavioral attributes of malware to identify phishing tools like Evilginx and NakedPages and immediately block end-users from visiting them.
Attackers are using Adversary in the Middle (AitM) phishing toolkits to bypass MFA. We look at what AitM is, how it works, and what you can do about it.
Behind the scenes of our approach to designing and developing our latest feature, SSO password protection.
Use the Push browser agent’s unique vantage point to protect SSO credentials by blocking employees from entering their password into any other site.
The latest news, articles, and resources, sent to your inbox.