Press start >>

Push Logo

The browser is
the new battleground

Modern breaches happen in the browser.

At the risk of using a few too many buzzwords: we've lived through a paradigm shift. Where we used to talk about novel software exploits and advanced endpoint malware, in 2026 we're talking about cloud apps and identities as the "patient zero" of modern breaches.

But there's more to it. This shift has been accompanied by an evolution in attack paths themselves — one that many security teams haven't adjusted to.

The best way to understand this shift is that the browser is the new endpoint. Once you frame modern attacks as being browser-based, it's easy to see why existing security tools are failing to intercept them — because they have partial visibility at best.

  1. Malicious JavaScript runs
  2. Browser payload triggered
  3. Apps & accounts hijacked

Traffic looks legitimate

  • Sites not known bad
  • No malware in sandbox
  • Requests seem legitimate

No endpoint alerts

  • No malware detected on device
  • User activity looks normal

Activity looks legitimate

  • Successful authentication
  • Expected behavior
  • Legitimate API use

Phishing isn't just about credentials now.

Modern phishing isn’t just credential theft.

Phishing techniques look very different to what they did even a few years ago. Once upon a time, phishing just meant stealing credentials or sending malware via email.

Now, phishing attacks routinely bypass MFA by targeting tokens, not credentials, and take several different forms — like entering a device code, authorizing a consent grant, installing a browser extension, or even directly running malicious code on your machine.

Users aren’t (and can’t be) trained to spot modern phishing, while typical technical controls weren’t designed for it — creating blind spots on multiple fronts.

Malvertising: a sponsored search result for a fake ChatGPT desktop app download.Consent phishing: an unverified app requesting permission to read and send your mail and read your files.Malicious extension: an AI assistant browser extension added to Chrome.Attacker-in-the-middle phishing: a proxied Microsoft sign-in page capturing an email address and password.Instant message lure: an external "IT Helpdesk" Slack message asking you to re-verify MFA at a lookalike link.ClickFix: a fake "verify you are human" check telling you to press Win+R, Ctrl+V and Enter.Device code phishing: a sign-in code with instructions to enter it at microsoft.com/devicelogin.Malicious download: a file named ChatGPT_Setup_v1.9.pdf.exe downloading in the browser.Social media lure: a LinkedIn InMail from a recruiter linking to a take-home task zip file.

Hiding in plain sight.

Attackers abuse a wide range of legitimate, trusted services to host malicious content, benign decoy pages, and redirect chains — allowing them to blend in with normal web traffic and fly under the radar.

Services like Microsoft Dynamics, SharePoint, Adobe, Google Firebase, Google Sites, Jotform, Linode, Azure, Cloudflare, Atlassian, and many more are commonly abused.

They’re even using legitimate bot protection tools to bypass other legitimate security tools for web content scanning and analysis, meaning pages go undetected until it’s too late.

Web hosting & cloud infra
22.2%
Cloud storage
5.1%
Forms & surveys
17.2%
Marketing & ads
5.1%
Design
12.1%
Document mgmt
5.1%
Automation & dev
10.1%
Scheduling & booking
2%
Project management
10.1%
CRM
2%
Collaboration
7.1%
IT service mgmt
2%

Standard detections can't keep up.

Not only are attackers utilizing trusted sites and bot protection, they’re combining them with detection evasion techniques like rapid domain rotation, complex redirect chains, and screening checks to filter out unwanted visitors.

Meanwhile, modern phishing pages are designed to be disposable. So even if they do get detected, attackers are proactively tearing down and spinning up new pages to stay ahead of blocklists.

If you’re primarily looking at static IoCs, pretty much every attack is a “zero-day” and will catch you off-guard.

You can find bad anywhere.

Attackers are reaching their targets in lots of different places, not just email.

Users can stumble upon malicious content pretty much everywhere they work in the browser. Search engines, IM platforms, and social media apps are increasingly popular delivery vectors as an alternative to email. Malicious ads are being delivered across Google Search and Facebook, LinkedIn DM’s and job posts are being used to distribute phishing links.

These channels have virtually no screening of content or messages and are invisible to security tools, while also being places users aren’t trained to suspect foul play.

Modern phishing isn’t obvious or predictable. It can hit your users anywhere they work, comes in many different forms, and exploits normal user behaviors.

Attack channels — email, Slack and Teams, social DMs, SMS, search ads, in-app messages, docs and invites, service desk and vishing — reaching an employee's browser. Only email passes through a secure email gateway; every other channel arrives uninspected.

Which delivery channels a security tool inspects before they reach the employee's browser
Delivery channelStatusInspected by
EmailInspectedA secure email gateway (SEG)
Social DMsUninspectedNo security tool
Slack / TeamsUninspectedNo security tool
SMSUninspectedNo security tool
Docs & InvitesUninspectedNo security tool
Search AdsUninspectedNo security tool
In-app messagesUninspectedNo security tool
Service DeskUninspectedNo security tool
VishingUninspectedNo security tool

Attackers are innovating faster than ever.

Like your employees, attackers are harnessing the power of AI.

This means better quality phishing messages and AI-powered social engineering scams, but most importantly every attacker has become a way better developer overnight. This means new and improved phishing kits-for-hire, as well as the ability for attackers to simply vibe-code their own tools.

AI adoption also opens up a whole new attack surface of AI apps to target that concentrate application access and integrations, with new “normal” user behaviors to take advantage of around AI use too (as we covered in our LLMShare and InstallFix campaign teardowns).

Overall, this means new techniques can reach mass adoption faster. For example, the explosion of device code phishing attacks this year is enabled by AI-assisted development, as existing phishing tool vendors quickly add it to their existing stack to maintain feature parity with the criminal market.

An attacker vibe-coding their own tools sends a stream of attack traffic into an employee's browser, which connects on to an AI hub and the AI services behind it.

Attacks in the browser, not on it.

Exploiting the browser itself is way more expensive than buying a set of infostealer logs with stolen credentials and sessions, renting a phishing service, or just vibe-coding your own tool.

AI is making software exploits more accessible, but for well-resourced browser vendors it also makes them much easier to find and fix. This is already happening.

Identities can’t be patched in the same way as a software exploit. There’s a way in to pretty much every account (yes, even if you’re using passkeys). And most identity configurations fall way short of the ideal.

That’s why identity attacks remain one of the most useful tools in the attacker’s toolkit, and why the criminal ecosystem continues to double down on them.

Attacks on the browser are beyond most criminals — but attacks in the browser are within reach for all.

Chrome RCE bug bounty

The result?

More delivery channels, more techniques, more payloads, with controls lagging behind.

  1. Malicious links delivered over many channels
  2. Redirect chains through legitimate, trusted sites
  3. Evolving payloads, rotating domains and infrastructure.

How browser-based attacks bypass traditional controls.

Most of your existing controls weren't designed with browser-based attacks in mind. Any red teamer will tell you: just because a tool counters an attack on paper, doesn't mean there isn't a way around it in practice.

  • Deliver over non-email channel
  • Send emails from trusted apps
  • Don’t use known-bad domains — constant rotation

Public breaches tell the story.

Browser-based techniques have been behind some of the biggest public cybercriminal campaigns and breaches of recent years. Attacks that make it into the public domain are in the minority, but give an indicator of the patterns of criminal behavior happening behind the scenes.

Public breaches by month
Public breaches by month
Month Stolen credentialsPhishing*Help desk vishingAitM phishingClickFixConsent & device code phishingOAuth supply chainOther Total
January 2024300000003
February 2024100000001
March 2024000000000
April 2024100000001
May 2024200000013
June 2024800100009
July 2024100000012
August 2024000000000
September 2024001100002
October 2024000100001
November 2024200000002
December 2024100001002
January 2025100000001
February 2025100001002
March 2025400100005
April 2025303110008
May 2025202011028
June 2025006000006
July 2025000004004
August 202500000815023
September 2025002001205
October 2025000000000
November 2025101100104
December 2025000000000
January 2026000700108
February 2026070000029
March 2026220200129
April 202601101105220
May 2026110100036
June 202601010012216
Total 342215183163715160
  • Password spray → OAuth app abuse → email exfiltration (APT29). Top breaches: Microsoft, HPE.

  • Infostealer-harvested credentials → credential stuffing against MFA-less Snowflake tenants. Top breaches: AT&T, Ticketmaster. 1B+ records stolen, 165 victims total (not all publicly disclosed).

  • Infostealer-sourced Jira credentials → data exfiltration. Top breaches: Telefónica, Jaguar Land Rover

  • Vishing outsourced help desks → IdP compromise → ransomware/data theft. Top breaches: M&S, Co-op, Hawaiian Airlines, WestJet, Aflac, Erie Insurance, Philadelphia Insurance.

  • Vishing → Salesforce DataLoader App device code authorization → CRM data exfiltration. Top breaches: Qantas, LVMH, Chanel, Allianz Life, Air France-KLM, Farmers Insurance.

  • Compromised SaaS vendors → stolen OAuth tokens → downstream Salesforce access.
Top breaches: Cloudflare, Palo Alto Networks, Zscaler, CyberArk, Proofpoint. More than 1000 victims claimed.

  • Breaches linked to vishing + browser-based payload (combination of AITM phishing & device code phishing). Top breaches: Panera Bread, Match Group, SoundCloud, Crunchbase, Optimizely.

  • Stolen vendor auth tokens → downstream Snowflake/BigQuery/Salesforce access.
Top breaches: Anodot/Glassbox, Zara/Inditex, Rockstar Games, Vimeo, Booking.com, Klue, Recorded Future, Hugging Face, Vercel.

Watch Push in action

Push intercepts browser attacks in real time, before they hit the user

See how Push stops browser attacks

  • Adversary-in-the-middle phishing uses a reverse proxy to sit between the victim and a legitimate login page, relaying credentials and MFA challenges in real time to steal the resulting session token.

    Blocked by Push

    How Push stops it

    • Push detects AITM phishing pages behaviorally — analyzing page structure, script behavior, and credential-harvesting mechanics rather than relying on domain blocklists or known kit signatures
    • SSO password protection blocks credential entry on pages that don't belong to that credential's identity provider
  • Device code phishing abuses the OAuth 2.0 device authorization flow — the attacker generates a legitimate device code and tricks the victim into entering it, granting the attacker a valid access token without ever touching the victim's credentials.

    Blocked by Push

    How Push stops it

    • Push detects and blocks device code phishing kits, stopping the attack before the user completes the authorization flow
    • Push delivers app-agnostic warnings during the device code authentication flow, alerting users before they authorize a device they don't control
  • Browser-in-the-browser (BITB) attacks render a fake browser popup inside the page — complete with a spoofed address bar showing a legitimate login URL — so victims believe they're signing in through a real SSO window.

    Blocked by Push

    How Push stops it

    • Push analyzes the actual page, not the pixels drawn on it — the credential-harvesting form is detected behaviorally no matter what fake window chrome surrounds it
    • SSO password protection blocks entry of corporate credentials on pages that don't belong to the real identity provider, whatever URL the fake address bar displays
  • Consent phishing tricks users into granting OAuth permissions to a malicious application, giving the attacker persistent API-level access to the victim's data without needing their password.

    Blocked by Push

    How Push stops it

    • Push monitors and can block OAuth consent flows across 20+ authorization servers, recording client ID, scopes, and outcome in real time
    • Security teams can manage and remove malicious OAuth apps from the Push console
  • Social media phishing delivers malicious links through trusted platforms like LinkedIn — recruiter outreach, direct messages, and connection requests lead victims to phishing pages, malware downloads, or other payloads, entirely outside email security's view.

    Blocked by Push

    How Push stops it

    • Push detects the malicious destination behaviorally at the moment it loads — regardless of delivery channel, so links from LinkedIn DMs are caught just like email phishing
    • Protection covers whatever the payload is: credential phishing, ClickFix-style clipboard hijacks, malicious OAuth grants, or file downloads
  • Malvertising uses paid search ads or display ads to place malicious links above legitimate results, directing victims to phishing pages or malware downloads through a trusted delivery channel.

    Blocked by Push

    How Push stops it

    • Push detects the phishing destination page behaviorally, regardless of how the user arrived — whether via a search ad, display ad, email, or any other channel
  • Malicious browser extensions either start as outright malware or become compromised through supply chain attacks like ownership transfers and permission escalations, gaining broad access to browsing data and credentials.

    Blocked by Push

    How Push stops it

    • Push inventories all browser extensions across the organization with full permissions analysis, giving security teams visibility into what's installed
    • Malicious extension detection and blocking identifies and removes known-malicious extensions across any browser in the environment
  • Malicious file downloads deliver malware payloads through the browser, often via phishing pages, compromised websites, or drive-by downloads that exploit user trust or curiosity.

    Blocked by Push

    How Push stops it

    • Push streams all file download events to SIEM with full metadata, giving security teams visibility into what's being downloaded and where from
    • Configurable blocking rules prevent risky downloads based on file type, extension, file name patterns, browser profile, and user group
  • ClickFix attacks use fake CAPTCHA pages, error messages, or install prompts to silently load malicious commands into the victim's clipboard and instruct them to paste and execute the payload — typically PowerShell or mshta commands.

    Blocked by Push

    How Push stops it

    • Push detects when a page silently writes malicious commands to the clipboard, identifying the technique regardless of the social engineering wrapper (fake CAPTCHAs, fake errors, fake install prompts)
    • Detection covers the entire x-Fix family — ClickFix, FileFix, CrashFix, ConsentFix, and InstallFix — through a single technique-class detection
  • ConsentFix wraps OAuth consent abuse in a ClickFix-style lure — a fake verification page walks the victim through approving a malicious consent grant.

    Blocked by Push

    How Push stops it

    • Push detects the fake verification pattern and page behavior behind ConsentFix lures, regardless of the social engineering wrapper
    • Risky consent grants can be blocked at the point of authorization, and security teams can revoke malicious grants from the Push console
  • Session hijacking occurs when an attacker steals a valid session token — typically via infostealer malware, AITM phishing, or cross-site scripting — and replays it from their own browser to take over an authenticated session.

    Blocked by Push

    How Push stops it

    • Push injects a unique marker into every session originating from a Push-protected browser — if that session token later appears in an uninstrumented browser, it's confirmed stolen
    • Browser sync detection catches corporate credentials syncing to personal browser profiles, closing a common token and credential leakage path
  • Credential stuffing uses stolen username-password pairs from breached databases and infostealer logs to attempt logins at scale, exploiting password reuse across services.

    Blocked by Push

    How Push stops it

    • Push detects when employees log in with weak, reused, or breached passwords that have appeared in infostealer logs, enabling remediation before they become attack vectors
    • MFA enforcement via in-browser guardrails ensures employees enroll in MFA, closing the gaps that credential stuffing relies on

See Push in action

Browser security that detects and blocks the attacks in this report — in real time, without ripping out your existing stack.