Shadow AI: how to discover, govern, and secure AI apps
Blocking AI tools doesn't stop employees from using AI — it stops you seeing how they use it. The solution: make the governed path easier than the workaround.
Stop account takeover
Stop ATO with stolen credential and compromised token detection.
Harden unmanaged identities
Harden access paths with visibility, detection, and guardrails.
Investigate browser-related incidents
Investigate and respond faster with unique browser telemetry.
Secure shadow SaaS
See and control shadow SaaS in the browser.
Secure AI
See and control AI apps in the browser.
Secure BYOD
Extend consistent browser-based protection to unmanaged devices.
Secure Chromebooks
Secure browser activity on Chromebooks without endpoint agents.
Investigate and stop data loss
Detect and prevent data loss across AI tools, apps, and sessions.
70 posts
OAuth abuse is attackers exploiting app-to-app authorization — consent phishing, malicious OAuth apps, stolen tokens, and device code flows — to gain persistent access to cloud tenants without touching a password or MFA prompt. Push tracks these techniques continuously and discovered ConsentFix, a browser-native attack in the wild that pairs OAuth consent phishing with a ClickFix-style prompt.
Blocking AI tools doesn't stop employees from using AI — it stops you seeing how they use it. The solution: make the governed path easier than the workaround.
Someone created a fake OpenAI organization using our company's name and invited specific Push employees to join it. Here's what we learned.
Most organizations know they have an AI security problem. A new SANS framework shows why so few are making progress - and what it actually takes to get unstuck.
AI regulations across the US, EU, and UK are converging on obligations that most organizations can't meet without browser visibility into AI tool use.
This article explains the gap between what EDR sees and what happens inside the browser, and what it takes to close it.
Why the right browser security tool makes a separate AI visibility and control purchase unnecessary — and how to decide what you actually need.
AI is accelerating the collapse of indicator-based threat detection. Here's why you need technique-level detection to stay ahead.
Push telemetry shows the average organization has 16 AI apps, 17 AI browser extensions, and 17 AI OAuth integrations in use. Here's what it means for security.
What we learned from sitting down with Matt Johansen to discuss the difference between security theater and security that actually works.
If you're building a shortlist of browser security vendors, do you need a full-stack enterprise browser, or browser security extension?
What we can learn from 2026's installment of the Verizon Data Breach Investigations Report.
Here are 7 things we learned from our conversation with John Hammond on the "Why the browser is the new battleground" webinar.
Why "good enough" isn’t enough when it comes to browser security, and a best-of-breed approach is needed to tackle emerging threats.
Ranking the security problems you can solve in the browser by security value and browser fit.
Securing the browser vs. securing the organization via the browser — what's the difference?
How we built an end-to-end threat hunting and detection engineering capability at Push that uses AI agents as a force multiplier.
How CISOs can use browser telemetry to support cyber risk quantification in areas where traditional data points fall short.
ShinyHunters' breach of Instructure is the latest in a long series of attacks. Here's our view of the big picture.
We're re-releasing the SaaS attack matrix as the Browser & Identity Attacks Matrix. Here's why we've decided to make the change and what it means.
Why typical browser extension risk scores are poor predictors of which extensions will actually lead to a compromise.
Investigating a new criminal toolkit for ConsentFix being promoted on criminal forums.
In April 2026, Vercel was compromised via an OAuth app integrated into their Google Workspace tenant stemming from a compromised third-party AI SaaS provider.
Device code phishing is seeing a huge spike in adoption in 2026, enabling attackers to steal access tokens while bypassing standard access controls.
Analysing the Stryker breach in line with recent changes to the Iran-nexus cyber playbook.
New insights on the ConsentFix campaign stopped by Push.
Analyzing the key trends that defined phishing attacks in 2025, and what these changes mean for security teams heading into 2026.
Analyzing "ConsentFix", a new browser-native attack technique we've detected in the wild, combining OAuth consent phishing with a ClickFix-style user prompt.
How Scattered Lapsus$ Hunters breaches demonstrate the evolution of attacker TTPs, shaping the future of cyber attacks.
What security teams need to know about the browser-based attack techniques that are the leading cause of breaches.
How attacks have moved away from endpoints and internal networks to the browser — a blind spot for traditional security tools.
Introducing our latest resource for security teams breaking down the techniques that modern phishing attacks are using to evade detection.
We’re launching a new Detections capability, enabling security teams to more effectively investigate and triage alerts, and build more effective workflows.
MFA downgrade attacks are an increasingly common technique used by attackers to bypass phishing-resistant authentication methods registered to an account.
How App-Specific Password phishing is being used in the wild to bypass phishing-resistant authentication controls like passkeys.
How the notorious Scattered Spider cyber criminal group are switching up their TTPs in 2025 to bypass MFA and breach cloud services via account takeover.
I’m thrilled to share that Push Security has raised our Series B funding. This is a huge moment for us and our customers in the fight against identity attacks.
Consent phishing is where attackers trick users into authorizing access for malicious OAuth apps. Here's how attackers are using this technique in the wild.
Detects when employees have weak, reused, or stolen passwords and guide them to update their password using in-browser messaging on any app.
We're back with part 2 of our research into OpenAI Operator to share our findings on how it can be used to automate identity attacks.
How app developers can go beyond Minimum Viable Secure Product (MVSP) to implement better identity protections and prevent identity-based attacks.
How extension developers can improve their security controls to prevent extension compromise.
Reviewing public breaches that stemmed from identity attacks in 2024.
How phishing for email verification can be combined with cross-IdP impersonation to gain direct access to downstream SaaS and bypass hardened IdP accounts.
Cross-IdP impersonation is a method of hijacking SSO to access downstream apps — without needing to compromise accounts on your company’s main IdP.
It’s been almost exactly a year since we released our open source repository of SaaS-native attack techniques. Let's reflect on what’s changed.
Attackers are using Adversary in the Middle (AitM) phishing toolkits to bypass MFA. We look at what AitM is, how it works, and what you can do about it.
To help organizations keep track of how browser-based identity attacks are evolving, we've put together this index of recent breaches.
Can admins access the secrets from your corporate password manager? If so, how does this affect incident response in a compromised admin account scenario?
In this blog post we will cover what identities are, how we secure perimeters in general, and and how this maps to the identity space.
We'll cover the implications of using Okta's SWA authentication method. Learn what security teams need to know in an account breach and IR scenario.
In this article, we define third-party risk management and explore additional approaches that can help manage third-party risk.
In this post, we're going to demonstrate how to phish via Slack to gain persistence and move laterally.
Employees are self-adopting SaaS apps and creating new cloud identities without IT approval. Learn how to manage which third parties have access to your data.
In this article, we’re going to demonstrate how combining two of our favorite new SaaS attack techniques makes a simple, but very stealthy persistence approach.
While OAuth scopes provide seamless online user authentication, they also carry significant risk. Watch out for these common, dangerous scopes.
Offensive security drives defensive security. We're sharing a collection of SaaS attack techniques to help defenders understand the threats they face.
Adapt your thinking to secure your data. Security needs to move from being the Department of No to the Department of Yes, Unless...
Look at enabling SaaS from a broader understanding of the business and not just the impact to security
SaaS sprawl is not just a raw increase of apps in-use, but also due to employees self-adopting new apps. Orgs need sensible guardrails for employees.
An employee has added a new integration to your Azure tenant or Google Workspace. How do you assess risk? We’ll cover a few techniques in this article.
This article covers common ways an app could lead to compromise in Microsoft Azure, and what to look out for when determining risk to your organization.
Attackers have loads of persistence options in an endpoint compromise scenario, but what changes in a SaaS-first world? We talk new attack methods in this post.
Learn about the benefits and risks of SaaS integrations and get tips for how to manage the risks.
Is logging in with Google or Microsoft secure? Yes, with caveats.
We'll walk through how to quickly detect and mitigate business email compromise (BEC) and then prevent future attacks.
Learn some lightweight ways to manage the risks SaaS introduces without relying on restrictive policies that block employees from using their preferred tools.
Here’s what’s new on the Push platform for July 2022.
How do you find a malicious Microsoft 365 OAuth app? Learn what to look for, and what to ignore, when checking your users haven't been consent phished.
Introduction to OAuth tokens in Google Workspace, how they are used, reasons you might want to review them, and a discussion of how you might go about it.
Consent phishing is an emerging technique attackers are using to compromise user accounts, even if they have Multi-factor Authentication (MFA or 2FA) enabled.
The latest news, articles, and resources, sent to your inbox.