Browser threat landscape: mid-year update 2026
PhaaS industrialization, Scattered Spider copycats, and AI-augmented tooling — what the threat landscape looks like in 2026 so far.
7 posts
SEO poisoning manipulates search engine results so malicious pages rank prominently for the software, tools, or services users are actively searching for, turning a routine search into an infection vector. It often pairs with malvertising and ClickFix-style payloads — Push has documented attackers abusing shared pages on legitimate AI chatbot domains to deliver malware from trusted infrastructure.
PhaaS industrialization, Scattered Spider copycats, and AI-augmented tooling — what the threat landscape looks like in 2026 so far.
How attackers are using shared content features on AI chatbot platforms to deliver malware via pages hosted on legitimate domains, sent via malvertising.
How we built an end-to-end threat hunting and detection engineering capability at Push that uses AI agents as a force multiplier.
Analyzing the key trends that defined phishing attacks in 2025, and what these changes mean for security teams heading into 2026.
Breaking down the most sophisticated ClickFix page we’ve seen in the wild — and what it tells us about the future of malicious copy-and-paste attacks.
Why phishing attacks are moving away from exclusively email-based delivery, and what this means for security teams.
Push recently identified a novel phishing attack using Active Directory Federation Services to get Microsoft to send victims to a phishing site.
The latest news, articles, and resources, sent to your inbox.