Shadow AI: how to discover, govern, and secure AI apps
Blocking AI tools doesn't stop employees from using AI — it stops you seeing how they use it. The solution: make the governed path easier than the workaround.
Stop account takeover
Stop ATO with stolen credential and compromised token detection.
Harden unmanaged identities
Harden access paths with visibility, detection, and guardrails.
Investigate browser-related incidents
Investigate and respond faster with unique browser telemetry.
Secure shadow SaaS
See and control shadow SaaS in the browser.
Secure AI
See and control AI apps in the browser.
Secure BYOD
Extend consistent browser-based protection to unmanaged devices.
Secure Chromebooks
Secure browser activity on Chromebooks without endpoint agents.
Investigate and stop data loss
Detect and prevent data loss across AI tools, apps, and sessions.
17 posts
A secure web gateway (SWG) filters and inspects web traffic in transit, sitting in the network path between users and the internet. That position shows you the packet but not the session: Push’s research on AitM phishing kits documents how attackers break the signatures proxies rely on, and these posts explain why phishing detection is moving from the network path into the browser itself.
Blocking AI tools doesn't stop employees from using AI — it stops you seeing how they use it. The solution: make the governed path easier than the workaround.
Browser security is one of the fastest-growing investment areas in enterprise security. Here's our proven framework to create budget for browser security tools.
If you're building a shortlist of browser security vendors, do you need a full-stack enterprise browser, or browser security extension?
Unpacking the latest research report from Omdia and what it means for the secure enterprise browser market.
Securing the browser vs. securing the organization via the browser — what's the difference?
Why network and web traffic only gives you part of the picture when it comes to modern browser-based attacks.
Why being in the browser gives defenders a key advantage over network and email phishing prevention, detection, and response tools.
Most phishing attacks involve a phishing page that has never been seen before. When detection relies on known-bad, this makes every attack feel like a zero-day.
Modern MFA-bypass phishing attacks are routinely defeating primarily email-based security controls. Why are controls failing and what can we do about it?
How attackers are breaking detection signatures designed to identify phishing sites impersonating real login pages.
Why relying on post-compromise detection and response is no longer an option for modern browser-based attacks.
How Push detects and blocks phishing attempts in the browser – explained in less than two minutes.
This is the first blog in a short series we’re putting together about the ‘why’ behind the ‘what’ at Push. This entry is focused on threat detection.
Breaking down common misconceptions about identity threats and controls like MFA, SSO, passkeys, password managers, and more.
How to use Push to investigate and respond to a third-party data breach, which results in credentials being stolen and sold on criminal marketplaces.
Right now the majority of detections for identity attacks rely on web proxy telemetry. Here’s why the browser can be a better alternative.
In this guide, we’ll break down some major SaaS use cases and match them up with solutions that can address them, covering pros and cons for each.
The latest news, articles, and resources, sent to your inbox.