7 things we learned from ‘Why the browser is the new battleground’ with John Hammond
Here are 7 things we learned from our conversation with John Hammond on the "Why the browser is the new battleground" webinar.
Stop account takeover
Stop ATO with stolen credential and compromised token detection.
Harden unmanaged identities
Harden access paths with visibility, detection, and guardrails.
Investigate browser-related incidents
Investigate and respond faster with unique browser telemetry.
Secure shadow SaaS
See and control shadow SaaS in the browser.
Secure AI
See and control AI apps in the browser.
Secure BYOD
Extend consistent browser-based protection to unmanaged devices.
Secure Chromebooks
Secure browser activity on Chromebooks without endpoint agents.
Investigate and stop data loss
Detect and prevent data loss across AI tools, apps, and sessions.
21 posts
Passkeys are phishing-resistant credentials that replace passwords with cryptographic key pairs bound to a user’s device. They defeat conventional credential phishing, but attackers adapt: Push research has documented MFA downgrade, app-specific password phishing, and device code phishing being used in the wild to route around passkey-protected accounts. Deploying passkeys is step one; closing those fallback paths is step two.
Here are 7 things we learned from our conversation with John Hammond on the "Why the browser is the new battleground" webinar.
Investigating a new criminal toolkit for ConsentFix being promoted on criminal forums.
Device code phishing is seeing a huge spike in adoption in 2026, enabling attackers to steal access tokens while bypassing standard access controls.
Analyzing the latest Scattered Lapsus$ Hunters (SLH) phishing campaign targeting hundreds of organizations.
New insights on the ConsentFix campaign stopped by Push.
Analyzing the key trends that defined phishing attacks in 2025, and what these changes mean for security teams heading into 2026.
Analyzing "ConsentFix", a new browser-native attack technique we've detected in the wild, combining OAuth consent phishing with a ClickFix-style user prompt.
How attacks have moved away from endpoints and internal networks to the browser — a blind spot for traditional security tools.
Introducing our latest resource for security teams breaking down the techniques that modern phishing attacks are using to evade detection.
MFA downgrade attacks are an increasingly common technique used by attackers to bypass phishing-resistant authentication methods registered to an account.
How App-Specific Password phishing is being used in the wild to bypass phishing-resistant authentication controls like passkeys.
HIBP creator and well-known security person Troy Hunt recently blogged about a phish he fell for. Here’s what it tells us about how phishing is evolving.
How app developers can go beyond Minimum Viable Secure Product (MVSP) to implement better identity protections and prevent identity-based attacks.
How extension developers can improve their security controls to prevent extension compromise.
How phishing for email verification can be combined with cross-IdP impersonation to gain direct access to downstream SaaS and bypass hardened IdP accounts.
Cross-IdP impersonation is a method of hijacking SSO to access downstream apps — without needing to compromise accounts on your company’s main IdP.
How Push detects and blocks phishing attempts in the browser – explained in less than two minutes.
Using Push data to calculate how many vulnerable identities the average organization has, and how they lead to different methods of account takeover.
It’s been almost exactly a year since we released our open source repository of SaaS-native attack techniques. Let's reflect on what’s changed.
Breaking down common misconceptions about identity threats and controls like MFA, SSO, passkeys, password managers, and more.
SMS, Authenticator apps, Security Keys, and more! We compare them from a user experience, security, cost, and security aspect.
The latest news, articles, and resources, sent to your inbox.