LLMShare: how attackers are turning AI chatbot pages into malware delivery platforms
How attackers are using shared content features on AI chatbot platforms to deliver malware via pages hosted on legitimate domains, sent via malvertising.
Stop account takeover
Stop ATO with stolen credential and compromised token detection.
Harden unmanaged identities
Harden access paths with visibility, detection, and guardrails.
Investigate browser-related incidents
Investigate and respond faster with unique browser telemetry.
Secure shadow SaaS
See and control shadow SaaS in the browser.
Secure AI
See and control AI apps in the browser.
Secure BYOD
Extend consistent browser-based protection to unmanaged devices.
Secure Chromebooks
Secure browser activity on Chromebooks without endpoint agents.
Investigate and stop data loss
Detect and prevent data loss across AI tools, apps, and sessions.
13 posts
Malware delivery has moved into the browser: rather than email attachments, attackers now rely on malvertising, fake install guides, and ClickFix-style copy-paste lures to get code running on endpoints. Push research on techniques like InstallFix maps the playbook, and in-browser detection of malicious copy and paste blocks these attacks before commands reach the endpoint.
How attackers are using shared content features on AI chatbot platforms to deliver malware via pages hosted on legitimate domains, sent via malvertising.
Here are 7 things we learned from our conversation with John Hammond on the "Why the browser is the new battleground" webinar.
How we built an end-to-end threat hunting and detection engineering capability at Push that uses AI agents as a force multiplier.
We're re-releasing the SaaS attack matrix as the Browser & Identity Attacks Matrix. Here's why we've decided to make the change and what it means.
How to use in-browser controls to stop browser-based attacks before compromise can occur
Here’s what’s new on the Push platform for March 2026.
Attackers are impersonating popular developer tools like Claude Code to distribute fake install instructions via malicious search engine ads.
Breaking down the most sophisticated ClickFix page we’ve seen in the wild — and what it tells us about the future of malicious copy-and-paste attacks.
Push now detects malware delivery in the browser, supporting a layered defense against endpoint attacks.
What security teams need to know about the browser-based attack techniques that are the leading cause of breaches.
Push now blocks URL schema obfuscation, countering a common technique used by attackers to bypass URL detections for phishing pages and malicious IPs.
What the rise in popularity of infostealers tells us about the cybercrime ecosystem and the shift toward identity attacks.
In this article, we will cover a number of spoofing and phishing strategies that can be employed by external attackers to target an organization using Teams.
The latest news, articles, and resources, sent to your inbox.