[{"data":1,"prerenderedAt":5151},["ShallowReactive",2],{"application-flags":3,"navbar":7,"always-visible-banner":36,"navbar-about-highlight":108,"navbar-resource-highlight":182,"trust-badges":226,"solution-nav":247,"fa-icon-sharp-regular-faFishingRod":387,"fa-icon-solid-faUserSecret":391,"fa-icon-sharp-regular-faLaptopCode":393,"fa-icon-solid-faTabletScreenButton":395,"fa-icon-solid-faThumbsUp":397,"fa-icon-solid-faPlugCircleXmark":399,"fa-icon-sharp-regular-faPuzzlePiece":401,"fa-icon-solid-faFileCircleXmark":403,"fa-icon-solid-faGhost":406,"fa-icon-solid-faQrcode":409,"fa-icon-solid-faCookieBite":411,"fa-icon-sharp-regular-faUserSecret":413,"fa-icon-sharp-regular-faRadar":415,"fa-icon-sharp-regular-faSatelliteDish":417,"fa-icon-sharp-regular-faShieldCheck":419,"fa-icon-sharp-regular-faBrainCircuit":421,"fa-icon-solid-faMobileScreenButton":423,"fa-icon-brands-faChrome":425,"fa-icon-solid-faDisplay":427,"fa-icon-solid-faFilter":429,"fa-icon-solid-faCloudArrowUp":431,"blog\u002Fthe-top-10-browser-security-solutions-in-2026":433,"blog-topics":4740},[4],{"name":5,"enabled":6},"maintenanceMode",false,[8],{"createdDate":9,"id":10,"name":11,"modelId":12,"published":13,"meta":14,"query":22,"data":23,"variations":28,"lastUpdated":29,"firstPublished":30,"testRatio":31,"createdBy":32,"lastUpdatedBy":33,"folders":34,"rev":35},1742208588866,"1c7a4e423bf54ac1a328bb4063459ef2","Banner","1c6207a5f24948ab82d4a0b17f251193","published",{"breakpoints":15,"hasAutosaves":19,"kind":20,"lastPreviewUrl":21},{"medium":16,"small":17,"xsmall":18},768,640,320,true,"data","",[],{"link":24,"text":25,"type":26,"url":27},{},"Get our latest report analyzing browser attack techniques in 2026","web-banner","https:\u002F\u002Fpushsecurity.com\u002Fresources\u002Fbrowser-attacks-report",{},1774258294825,1742208637545,1,"CydmZnOWU1XuAaLhEDCoYNM4Z8W2","jKjF9r5jcvXU8tzZEfFQm31Iyvr2",[],"brvjc1sslx8",{"createdBy":37,"createdDate":38,"data":39,"folders":94,"id":95,"lastUpdated":96,"lastUpdatedBy":97,"meta":98,"modelId":102,"name":103,"published":13,"query":104,"testRatio":31,"variations":105,"firstPublished":106,"stageModifiedSincePublish":6,"rev":107},"ST0tXQM8slWpFrmioqKHmENB2qe2",1774965361051,{"ctaText":40,"text":41,"url":21,"blocks":42,"state":90},"ewrererw","testrfesssssssssss",[43,70,78],{"@type":44,"@version":45,"id":46,"component":47,"responsiveStyles":60},"@builder.io\u002Fsdk:Element",2,"builder-ca12c06a52de41d7b8743da53118cd38",{"name":48,"tag":48,"options":49,"isRSC":59},"TopBannerContent",{"text":50,"ctaText":51,"url":52,"mainText":53,"cta":56},"New Webinar Series: Join John Hammond, Troy Hunt, and Matt Johansen for the State of Browser Attacks","Save Your Spot","https:\u002F\u002Fpushsecurity.com\u002Fwebinar\u002Fstate-of-browser-security",{"content":54,"fontSize":55},"\u003Cp class=\"\">Employees using shadow AI tools? Push blocks them in the browser and enforces your AI policy.\u003C\u002Fp>","text-base",{"content":57,"fontSize":55,"url":58},"\u003Cp class=\"\">Get a free trial →\u003C\u002Fp>","https:\u002F\u002Fpushsecurity.com\u002Flp\u002Fshadow-ai-trial",null,{"large":61},{"display":62,"flexDirection":63,"position":64,"flexShrink":65,"boxSizing":66,"marginTop":67,"marginBottom":67,"fontSize":68,"fontWeight":69},"flex","column","relative","0","border-box",".56rem","1.125rem","700",{"@type":44,"@version":45,"id":71,"component":72,"responsiveStyles":76},"builder-a2e1f4b9f30b464bb814d7f5de5b0aa7",{"name":73,"options":74,"isRSC":59},"Custom Code",{"code":75,"scriptsClientOnly":6},"\u003Cstyle>\n  .top-banner.bg-web-orange{background:rgb(114, 79, 255);}\n\u003C\u002Fstyle>\n",{"large":77},{"display":62,"flexDirection":63,"position":64,"flexShrink":65,"boxSizing":66},{"id":79,"@type":44,"tagName":80,"properties":81,"responsiveStyles":85},"builder-pixel-65og51xnky7","img",{"src":82,"aria-hidden":83,"alt":21,"role":84,"width":65,"height":65},"https:\u002F\u002Fcdn.builder.io\u002Fapi\u002Fv1\u002Fpixel?apiKey=f3a1111ff5be48cdbb123cd9f5795a05","true","presentation",{"large":86},{"height":65,"width":65,"display":87,"opacity":65,"overflow":88,"pointerEvents":89},"block","hidden","none",{"deviceSize":91,"location":92},"large",{"path":21,"query":93},{},[],"fd266d0172cc47429be7ad10f48c99ad",1787595768418,"tFqFyIzyczYOCRogcShKk6KBmEB2",{"breakpoints":99,"hasAutosaves":19,"hasErrors":6,"hasLinks":6,"kind":100,"lastPreviewUrl":101},{"medium":16,"small":17,"xsmall":18},"component","https:\u002F\u002Fpushsecurity.com\u002F?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CcreateProjects%2CsendPullRequests%2CfusionHostingPublish&builder.user.role.name=Designer&builder.user.role.id=creator&builder.cachebust=true&builder.preview=always-visible-banner&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.always-visible-banner=fd266d0172cc47429be7ad10f48c99ad&builder.overrides.fd266d0172cc47429be7ad10f48c99ad=fd266d0172cc47429be7ad10f48c99ad&builder.options.locale=Default","0678d178ec8b41efb8a23c09dba7874d","always visible banner",[],{},1774968080803,"y4fj9dbjb7k",[109,145],{"createdBy":32,"createdDate":110,"data":111,"folders":134,"id":135,"lastUpdated":136,"lastUpdatedBy":32,"meta":137,"modelId":139,"name":140,"published":13,"query":141,"stageModifiedSincePublish":6,"testRatio":31,"variations":142,"firstPublished":143,"rev":144},1776247359804,{"link":112,"testimonial":113,"testimonialLink":133,"type":116},{},{"@type":114,"id":115,"model":116,"value":117},"@builder.io\u002Fcore:Reference","f028f2b685bb47cd8bf9e82a26dd5a79","testimonial",{"query":118,"folders":119,"createdDate":120,"id":115,"name":121,"modelId":122,"published":13,"data":123,"variations":127,"lastUpdated":128,"firstPublished":129,"testRatio":31,"createdBy":37,"lastUpdatedBy":37,"meta":130,"rev":132},[],[],1735823466309,"We found Push to be more accurate when compared to competitors and the browser agent offered features that others couldn’t match.","42035571a56940ac98bff4544aa79aa5",{"author":124,"jobTitle":125,"quote":121,"image":126},"Jason Waits","\u003Cp>CISO at Inductive Automation\u003C\u002Fp>","https:\u002F\u002Fcdn.builder.io\u002Fapi\u002Fv1\u002Fimage\u002Fassets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Ff04c0c0689ce4a89ac0f0708d78c0a07",{},1735910703862,1735823501152,{"kind":20,"lastPreviewUrl":21,"breakpoints":131,"hasAutosaves":19},{"small":17,"medium":16},"8lr4aug0kgg","\u002Fcustomer-stories\u002Finductive-automation",[],"9136a8f18b3b4a6ba29b8653a99372b1",1776247404986,{"breakpoints":138,"hasAutosaves":6,"kind":20,"lastPreviewUrl":21},{"medium":16,"small":17,"xsmall":18},"20d9eaa352304613b3d1a794b400703d","testimonial-inductive-automation",[],{},1776247404973,"tmziibs9ga9",{"createdBy":32,"createdDate":146,"data":147,"folders":174,"id":175,"lastUpdated":176,"lastUpdatedBy":32,"meta":177,"modelId":139,"name":172,"published":13,"query":179,"stageModifiedSincePublish":6,"testRatio":31,"variations":180,"firstPublished":181,"rev":144},1776255761419,{"description":148,"image":149,"link":150,"testimonial":153,"title":172,"type":173},"Learn about the latest techniques being used in the wild.","https:\u002F\u002Fcdn.builder.io\u002Fapi\u002Fv1\u002Fimage\u002Fassets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F7b4a5ebf81d64e8c9d7fc35f6c96c4a9",{"text":151,"url":152},"Download now","\u002Fresources\u002Fbrowser-attacks-report",{"@type":114,"id":154,"model":116,"value":155},"192acbb1f9ca4cac918c0ec435a8bae3",{"query":156,"folders":157,"createdDate":158,"id":154,"name":159,"modelId":122,"published":13,"data":160,"variations":166,"lastUpdated":167,"firstPublished":168,"testRatio":31,"createdBy":37,"lastUpdatedBy":32,"meta":169,"rev":171},[],[],1728981467463,"Push does for identity what CrowdStrike did for the endpoint",{"video":161,"jobTitle":162,"author":163,"qoute":21,"quote":164,"image":165},"https:\u002F\u002Fcdn.builder.io\u002Fo\u002Fassets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F8b30e8ca50064058bbaef0f3c6164575%2Fcompressed?apiKey=f3a1111ff5be48cdbb123cd9f5795a05&token=8b30e8ca50064058bbaef0f3c6164575&alt=media&optimized=true","\u003Cp>Deputy CISO at Microsoft\u003C\u002Fp>\u003Cp>Former LinkedIn, Slack, Palantir\u003C\u002Fp>","Geoff Belknap","Push does for identity what CrowdStrike did for the endpoint.","https:\u002F\u002Fcdn.builder.io\u002Fapi\u002Fv1\u002Fimage\u002Fassets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F748f0ad0a5064a00a13f4721fcc8dea1",{},1742902158597,1728981782923,{"kind":20,"lastPreviewUrl":21,"breakpoints":170,"hasAutosaves":19},{"small":17,"medium":16},"w423t83vzcq","Report: 2026 Browser Attack Techniques","resource",[],"05a9322735fc427db12e2740e4302300",1776255810913,{"breakpoints":178,"hasAutosaves":6,"kind":20,"lastPreviewUrl":21},{"medium":16,"small":17,"xsmall":18},[],{},1776255810900,[183,205],{"createdBy":32,"createdDate":184,"data":185,"folders":195,"id":196,"lastUpdated":197,"lastUpdatedBy":32,"meta":198,"modelId":200,"name":172,"published":13,"query":201,"stageModifiedSincePublish":6,"testRatio":31,"variations":202,"firstPublished":203,"rev":204},1776256900280,{"description":148,"image":149,"link":186,"testimonial":187,"title":172,"type":173},{"text":151,"url":152},{"@type":114,"id":154,"model":116,"value":188},{"query":189,"folders":190,"createdDate":158,"id":154,"name":159,"modelId":122,"published":13,"data":191,"variations":192,"lastUpdated":167,"firstPublished":168,"testRatio":31,"createdBy":37,"lastUpdatedBy":32,"meta":193,"rev":171},[],[],{"video":161,"jobTitle":162,"author":163,"qoute":21,"quote":164,"image":165},{},{"kind":20,"lastPreviewUrl":21,"breakpoints":194,"hasAutosaves":19},{"small":17,"medium":16},[],"1f429607996e4e5fae8fe3f9b9610e55",1776256937553,{"breakpoints":199,"hasAutosaves":6,"kind":20,"lastPreviewUrl":21},{"medium":16,"small":17,"xsmall":18},"4829faa81e7c4ee8bd2d000e160e8d3c",[],{},1776256937540,"h00i46zz8yj",{"createdBy":32,"createdDate":206,"data":207,"folders":217,"id":218,"lastUpdated":219,"lastUpdatedBy":32,"meta":220,"modelId":200,"name":222,"published":13,"query":223,"stageModifiedSincePublish":6,"testRatio":31,"variations":224,"firstPublished":225,"rev":204},1776256949234,{"link":208,"testimonial":209,"testimonialLink":133,"type":116},{},{"@type":114,"id":115,"model":116,"value":210},{"query":211,"folders":212,"createdDate":120,"id":115,"name":121,"modelId":122,"published":13,"data":213,"variations":214,"lastUpdated":128,"firstPublished":129,"testRatio":31,"createdBy":37,"lastUpdatedBy":37,"meta":215,"rev":132},[],[],{"author":124,"jobTitle":125,"quote":121,"image":126},{},{"kind":20,"lastPreviewUrl":21,"breakpoints":216,"hasAutosaves":19},{"small":17,"medium":16},[],"ce043785b71b4ece98eac811ecf4ba10",1776256974140,{"breakpoints":221,"hasAutosaves":6,"kind":20,"lastPreviewUrl":21},{"medium":16,"small":17,"xsmall":18},"inductive-automation",[],{},1776256974130,[227,231,235,239,243],{"title":228,"logo":229,"createdDate":230},"SOC2","https:\u002F\u002Fcdn.builder.io\u002Fapi\u002Fv1\u002Fimage\u002Fassets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fb6727a5e00004d6e9e69fc3068b8b64c",1784291539953,{"title":232,"logo":233,"createdDate":234},"GDPR","https:\u002F\u002Fcdn.builder.io\u002Fapi\u002Fv1\u002Fimage\u002Fassets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Ffe49f53211674deaa5a6640d929cdf42?format=webp",1784291672535,{"title":236,"logo":237,"createdDate":238},"Cyber essentials","https:\u002F\u002Fcdn.builder.io\u002Fapi\u002Fv1\u002Fimage\u002Fassets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F53558c1045a342a7a28def960cd54ae7?format=webp",1784291702710,{"title":240,"logo":241,"createdDate":242},"ISO IEC 27001","https:\u002F\u002Fcdn.builder.io\u002Fapi\u002Fv1\u002Fimage\u002Fassets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F578a404a61cf45db951a41fe3554d12d",1784291766222,{"title":244,"logo":245,"createdDate":246},"ISO IEC 27701","https:\u002F\u002Fcdn.builder.io\u002Fapi\u002Fv1\u002Fimage\u002Fassets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fbe219844b13242fbba531959579a753c",1784291858848,[248,317,362],{"id":249,"label":250,"text":21,"navIcon":251,"items":252},"stop-browser-based-attacks","Stop browser-based attacks","solid:faShieldHalved",[253,258,263,268,273,278,283,288,293,297,302,307,312],{"title":254,"text":255,"url":256,"navIcon":257},"Phishing","Detect phishing behaviorally in the browser, regardless of the payload or delivery channel.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fzero-day-phishing","sharp-regular:faFishingRod",{"title":259,"text":260,"url":261,"navIcon":262},"Adversary-in-the-Middle","Detect and block MFA-bypassing AiTM phishing pages in real-time.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fadversary-in-the-middle-attacks","solid:faUserSecret",{"title":264,"text":265,"url":266,"navIcon":267},"ClickFix (and variants)","Intercept malicious copy and paste attacks at the point of interaction.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fclickfix-fix-variants","sharp-regular:faLaptopCode",{"title":269,"text":270,"url":271,"navIcon":272},"Device code phishing","Detect and block device code phishing kits designed to get around passkeys.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fdevice-code-phishing","solid:faTabletScreenButton",{"title":274,"text":275,"url":276,"navIcon":277},"Consent phishing","Detect and block malicious OAuth consent grants before access is authorized.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fconsent-phishing","solid:faThumbsUp",{"title":279,"text":280,"url":281,"navIcon":282},"Malicious OAuth integrations","Detect and block the root cause of SaaS supply chain attacks.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fmalicious-oauth-integrations","solid:faPlugCircleXmark",{"title":284,"text":285,"url":286,"navIcon":287},"Malicious browser extensions","Inventory, monitor, and block risky browser extensions.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fmalicious-browser-extensions","sharp-regular:faPuzzlePiece",{"title":289,"text":290,"url":291,"navIcon":292},"Malicious file downloads","Control which files users can download by type, source, and user group.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fmalicious-file-downloads","solid:faFileCircleXmark",{"title":294,"text":295,"url":296,"navIcon":292},"Infostealers","Detect infostealer delivery and respond to a compromise.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Finfostealer-malware",{"title":298,"text":299,"url":300,"navIcon":301},"Ghost logins","Surface hidden login paths that bypass SSO and expose accounts.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fghost-logins","solid:faGhost",{"title":303,"text":304,"url":305,"navIcon":306},"Mobile phishing (QR & SMS)","Detect phishing regardless of whether it arrives via email, SMS, or QR code.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fmobile-phishing-qr-code-sms","solid:faQrcode",{"title":308,"text":309,"url":310,"navIcon":311},"Credential stuffing","Identify reused and compromised credentials across SaaS logins.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fcredential-stuffing","custom:credentialStuffing",{"title":313,"text":314,"url":315,"navIcon":316},"Session hijacking","Detect and respond to stolen session token replay with browser session markers.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fsession-hijacking","solid:faCookieBite",{"id":318,"label":319,"text":21,"navIcon":320,"items":321},"achieve-security-outcomes","Achieve security outcomes","solid:faCheckToSlot",[322,327,332,337,342,347,352,357],{"title":323,"text":324,"url":325,"navIcon":326},"Stop account takeover","Stop ATO with stolen credential and compromised token detection.","\u002Fsolution\u002Fachieve-security-outcomes\u002Fstop-account-takeover","sharp-regular:faUserSecret",{"title":328,"text":329,"url":330,"navIcon":331},"Harden unmanaged identities","Harden access paths with visibility, detection, and guardrails.","\u002Fsolution\u002Fachieve-security-outcomes\u002Fharden-unmanaged-identities","sharp-regular:faRadar",{"title":333,"text":334,"url":335,"navIcon":336},"Investigate browser-related incidents","Investigate and respond faster with unique browser telemetry.","\u002Fsolution\u002Fachieve-security-outcomes\u002Finvestigate-browser-related-incidents","sharp-regular:faSatelliteDish",{"title":338,"text":339,"url":340,"navIcon":341},"Secure shadow SaaS","See and control shadow SaaS in the browser.","\u002Fsolution\u002Fachieve-security-outcomes\u002Fsecure-shadow-saas","sharp-regular:faShieldCheck",{"title":343,"text":344,"url":345,"navIcon":346},"Secure AI","See and control AI apps in the browser.","\u002Fsolution\u002Fachieve-security-outcomes\u002Fsecure-ai","sharp-regular:faBrainCircuit",{"title":348,"text":349,"url":350,"navIcon":351},"Secure BYOD","Extend consistent browser-based protection to unmanaged devices.","\u002Fsolution\u002Fachieve-security-outcomes\u002Fsecure-bring-your-own-device","solid:faMobileScreenButton",{"title":353,"text":354,"url":355,"navIcon":356},"Secure Chromebooks","Secure browser activity on Chromebooks without endpoint agents.","\u002Fsolution\u002Fachieve-security-outcomes\u002Fsecure-chromebooks","brands:faChrome",{"title":358,"text":359,"url":360,"navIcon":361},"Investigate and stop data loss","Detect and prevent data loss across AI tools, apps, and sessions.","\u002Fsolution\u002Fachieve-security-outcomes\u002Finvestigate-and-stop-data-loss","custom:investigateAndStopDataLoss",{"id":363,"label":364,"text":21,"navIcon":365,"items":366},"tool-replacements","Tool replacements","solid:faScrewdriverWrench",[367,372,377,382],{"title":368,"text":369,"url":370,"navIcon":371},"Remote browser isolation","Detect attacks that look like normal browsing.","\u002Fsolution\u002Ftool-replacements\u002Fremote-browser-isolation","solid:faDisplay",{"title":373,"text":374,"url":375,"navIcon":376},"Secure web gateways","Detect attacks inside the browser after SWGs allowed the connection.","\u002Fsolution\u002Ftool-replacements\u002Fsecure-web-gateways","solid:faFilter",{"title":378,"text":379,"url":380,"navIcon":381},"Cloud access security broker","Catch browser-based identity threats in real time, not after the fact.","\u002Fsolution\u002Ftool-replacements\u002Fcloud-access-security-broker","solid:faCloudArrowUp",{"title":383,"text":384,"url":385,"navIcon":386},"Security awareness training","Block real phishing instead of training users on simulations.","\u002Fsolution\u002Ftool-replacements\u002Fsecurity-awareness-training","custom:securityAwareness",{"w":388,"h":389,"d":390},448,512,"M284.6 0l91.4 0 0 160-48 0 0-112-36.6 0-203.4 58.1 0 181.9 40 0 0 224-128 0 0-224 40 0 0-218.1 17.4-5 224-64 3.2-.9zM80 336l-32 0 0 128 32 0 0-128zm176 8c0-76.8 64-136 96-152 32 16 96 75.2 96 152 0 32-16 80-64 112l32 40 0 16-128 0 0-16 32-40c-48-32-64-80-64-112zm128-32a24 24 0 1 0 -48 0 24 24 0 1 0 48 0z",{"w":388,"h":389,"d":392},"M171-16c-36.4 0-57.8 58.3-68.3 112L72 96c-13.3 0-24 10.7-24 24s10.7 24 24 24l24 0 0 32c0 17 3.3 33.2 9.3 48l-9.3 0 0 0-20.5 0c-15.2 0-27.5 12.3-27.5 27.5 0 3 .5 5.9 1.4 8.7l28.9 86.6C40.2 379.6 16 428.1 16 482.3 16 498.7 29.3 512 45.7 512l356.6 0c16.4 0 29.7-13.3 29.7-29.7 0-54.2-24.2-102.7-62.3-135.4l28.9-86.6c.9-2.8 1.4-5.7 1.4-8.7 0-15.2-12.3-27.5-27.5-27.5l-20.5 0 0 0-9.3 0c6-14.8 9.3-31 9.3-48l0-32 24 0c13.3 0 24-10.7 24-24s-10.7-24-24-24l-30.7 0c-10.4-53.7-31.9-112-68.3-112-9.6 0-19 3.9-27.5 8.2-8.2 4.1-18.4 7.8-25.5 7.8s-17.3-3.7-25.5-7.8C190-12.1 180.6-16 171-16zm93.7 484.4l-24.8-70.9 27.9-32.5c2.7-3.2 4.2-7.2 4.2-11.4 0-9.7-7.8-17.5-17.5-17.5l-61 0c-9.7 0-17.5 7.8-17.5 17.5 0 4.2 1.5 8.2 4.2 11.4l27.9 32.5-24.8 70.9-57-180.4 35.7 0c18.4 10.2 39.5 16 62 16s43.6-5.8 62-16l35.7 0-57 180.4zM224 256c-34.7 0-64.2-22.1-75.3-53 5.7 3.2 12.3 5 19.3 5l12.4 0c16.5 0 31.1-10.6 36.3-26.2 2.3-7 12.2-7 14.5 0 5.2 15.6 19.9 26.2 36.3 26.2l12.4 0c7 0 13.6-1.8 19.3-5-11.1 30.9-40.6 53-75.3 53z",{"w":17,"h":389,"d":394},"M112 80l416 0 0 224 48 0 0-272-512 0 0 272 48 0 0-224zM48 404.1l0-4.1 544 0 0 4.1-27.9 27.9-488.2 0-27.9-27.9zM592 352l-592 0 0 72 56 56 528 0 56-56 0-72-48 0zM281 169l17-17-33.9-33.9c-6.1 6.1-27.8 27.8-65 65l-17 17c6.1 6.1 27.8 27.8 65 65l17 17 33.9-33.9c-9-9-25-25-48-48l31-31zM393 135l-17-17-33.9 33.9c9 9 25 25 48 48-23 23-39 39-48 48L376 281.9c6.1-6.1 27.8-27.8 65-65l17-17c-6.1-6.1-27.8-27.8-65-65z",{"w":388,"h":389,"d":396},"M0 64C0 28.7 28.7 0 64 0L384 0c35.3 0 64 28.7 64 64l0 384c0 35.3-28.7 64-64 64L64 512c-35.3 0-64-28.7-64-64L0 64zM256 432a32 32 0 1 0 -64 0 32 32 0 1 0 64 0zM384 64l-320 0 0 288 320 0 0-288z",{"w":389,"h":389,"d":398},"M80 160c17.7 0 32 14.3 32 32l0 256c0 17.7-14.3 32-32 32l-48 0c-17.7 0-32-14.3-32-32L0 192c0-17.7 14.3-32 32-32l48 0zM270.6 16C297.9 16 320 38.1 320 65.4l0 4.2c0 6.8-1.3 13.6-3.8 19.9L288 160 448 160c26.5 0 48 21.5 48 48 0 19.7-11.9 36.6-28.9 44 17 7.4 28.9 24.3 28.9 44 0 23.4-16.8 42.9-39 47.1 4.4 7.3 7 15.8 7 24.9 0 22.2-15 40.8-35.4 46.3 2.2 5.5 3.4 11.5 3.4 17.7 0 26.5-21.5 48-48 48l-87.9 0c-36.3 0-71.6-12.4-99.9-35.1L184 435.2c-15.2-12.1-24-30.5-24-50l0-186.6c0-14.9 3.5-29.6 10.1-42.9L226.3 43.3C234.7 26.6 251.8 16 270.6 16z",{"w":17,"h":389,"d":400},"M192-32c17.7 0 32 14.3 32 32l0 96 128 0 0-96c0-17.7 14.3-32 32-32s32 14.3 32 32l0 96 64 0c17.7 0 32 14.3 32 32s-14.3 32-32 32l0 48.7c-98.6 8.1-176 90.7-176 191.3 0 27.3 5.7 53.3 16 76.9l0 3.1c0 17.7-14.3 32-32 32s-32-14.3-32-32l0-66.7C165.2 398.1 96 319.1 96 224l0-64c-17.7 0-32-14.3-32-32S78.3 96 96 96l64 0 0-96c0-17.7 14.3-32 32-32zM496 256a144 144 0 1 1 0 288 144 144 0 1 1 0-288zm59.3 107.3c6.2-6.2 6.2-16.4 0-22.6s-16.4-6.2-22.6 0l-36.7 36.7-36.7-36.7c-6.2-6.2-16.4-6.2-22.6 0s-6.2 16.4 0 22.6l36.7 36.7-36.7 36.7c-6.2 6.2-6.2 16.4 0 22.6s16.4 6.2 22.6 0l36.7-36.7 36.7 36.7c6.2 6.2 16.4 6.2 22.6 0s6.2-16.4 0-22.6l-36.7-36.7 36.7-36.7z",{"w":389,"h":389,"d":402},"M201.1 57.3c-7 5.3-9.1 10.7-9.1 14.7 0 4.5 2.8 11.2 12.4 16.9l11.6 7 0 48.1-168 0 0 60.5c7.4-2.9 15.5-4.5 24-4.5 43.1 0 72 39.4 72 80s-28.9 80-72 80c-8.5 0-16.6-1.6-24-4.5l0 108.5 108.5 0c-2.9-7.4-4.5-15.5-4.5-24 0-43.1 39.4-72 80-72s80 28.9 80 72c0 8.5-1.6 16.6-4.5 24l60.5 0 0-168 48.1 0 7 11.6c5.8 9.6 12.4 12.4 16.9 12.4 4 0 9.5-2.1 14.7-9.1s9.3-17.9 9.3-30.9-4-23.8-9.3-30.9-10.7-9.1-14.7-9.1c-4.5 0-11.2 2.8-16.9 12.4l-7 11.6-48.1 0 0-120-120 0 0-48.1 11.6-7c9.6-5.8 12.4-12.4 12.4-16.9 0-4-2.1-9.5-9.1-14.7S245 48 232 48 208.2 52 201.1 57.3zM172.3 18.9C188.5 6.8 209.6 0 232 0S275.5 6.8 291.7 18.9 320 49.5 320 72c0 8.6-1.8 16.7-4.9 24l100.9 0 0 100.9c7.3-3.1 15.4-4.9 24-4.9 22.5 0 41 12.2 53.1 28.3s18.9 37.3 18.9 59.7-6.8 43.5-18.9 59.7-30.6 28.3-53.1 28.3c-8.6 0-16.7-1.8-24-4.9l0 148.9-168 0 0-49.3 8.2-7.2c5.4-4.7 7.8-10.3 7.8-15.5 0-9.9-10.7-24-32-24s-32 14.1-32 24c0 5.3 2.4 10.8 7.8 15.5l8.2 7.2 0 49.3-216 0 0-216 49.3 0 7.2 8.2c4.7 5.4 10.3 7.8 15.5 7.8 9.9 0 24-10.7 24-32s-14.1-32-24-32c-5.3 0-10.8 2.4-15.5 7.8L49.3 264 0 264 0 96 148.9 96c-3.1-7.3-4.9-15.4-4.9-24 0-22.5 12.2-41 28.3-53.1z",{"w":404,"h":389,"d":405},576,"M96 0C60.7 0 32 28.7 32 64l0 384c0 35.3 28.7 64 64 64l180 0c-22.7-31.5-36-70.2-36-112 0-100.6 77.4-183.2 176-191.3l0-38.1c0-17-6.7-33.3-18.7-45.3L290.7 18.7C278.7 6.7 262.5 0 245.5 0L96 0zM357.5 176L264 176c-13.3 0-24-10.7-24-24L240 58.5 357.5 176zM432 544a144 144 0 1 0 0-288 144 144 0 1 0 0 288zm59.3-180.7l-36.7 36.7 36.7 36.7c6.2 6.2 6.2 16.4 0 22.6s-16.4 6.2-22.6 0l-36.7-36.7-36.7 36.7c-6.2 6.2-16.4 6.2-22.6 0s-6.2-16.4 0-22.6l36.7-36.7-36.7-36.7c-6.2-6.2-6.2-16.4 0-22.6s16.4-6.2 22.6 0l36.7 36.7 36.7-36.7c6.2-6.2 16.4-6.2 22.6 0s6.2 16.4 0 22.6z",{"w":407,"h":389,"d":408},384,"M40.1 467.1l-11.2 9C25.7 478.6 21.8 480 17.8 480 8 480 0 472 0 462.2L0 192C0 86 86 0 192 0S384 86 384 192l0 270.2c0 9.8-8 17.8-17.8 17.8-4 0-7.9-1.4-11.1-3.9l-11.2-9c-13.4-10.7-32.8-9-44.1 3.9L269.3 506c-3.3 3.8-8.2 6-13.3 6s-9.9-2.2-13.3-6l-26.6-30.5c-12.7-14.6-35.4-14.6-48.2 0L141.3 506c-3.3 3.8-8.2 6-13.3 6s-9.9-2.2-13.3-6L84.2 471c-11.3-12.9-30.7-14.6-44.1-3.9zM160 192a32 32 0 1 0 -64 0 32 32 0 1 0 64 0zm96 32a32 32 0 1 0 0-64 32 32 0 1 0 0 64z",{"w":388,"h":389,"d":410},"M64 160l64 0 0-64-64 0 0 64zM0 80C0 53.5 21.5 32 48 32l96 0c26.5 0 48 21.5 48 48l0 96c0 26.5-21.5 48-48 48l-96 0c-26.5 0-48-21.5-48-48L0 80zM64 416l64 0 0-64-64 0 0 64zM0 336c0-26.5 21.5-48 48-48l96 0c26.5 0 48 21.5 48 48l0 96c0 26.5-21.5 48-48 48l-96 0c-26.5 0-48-21.5-48-48l0-96zM320 96l0 64 64 0 0-64-64 0zM304 32l96 0c26.5 0 48 21.5 48 48l0 96c0 26.5-21.5 48-48 48l-96 0c-26.5 0-48-21.5-48-48l0-96c0-26.5 21.5-48 48-48zM288 352a32 32 0 1 1 0-64 32 32 0 1 1 0 64zm0 64c17.7 0 32 14.3 32 32s-14.3 32-32 32-32-14.3-32-32 14.3-32 32-32zm96 32c0-17.7 14.3-32 32-32s32 14.3 32 32-14.3 32-32 32-32-14.3-32-32zm32-96a32 32 0 1 1 0-64 32 32 0 1 1 0 64zm-32 32a32 32 0 1 1 -64 0 32 32 0 1 1 64 0z",{"w":389,"h":389,"d":412},"M257.5 27.6c-.8-5.4-4.9-9.8-10.3-10.6-22.1-3.1-44.6 .9-64.4 11.4l-74 39.5C89.1 78.4 73.2 94.9 63.4 115L26.7 190.6c-9.8 20.1-13 42.9-9.1 64.9l14.5 82.8c3.9 22.1 14.6 42.3 30.7 57.9l60.3 58.4c16.1 15.6 36.6 25.6 58.7 28.7l83 11.7c22.1 3.1 44.6-.9 64.4-11.4l74-39.5c19.7-10.5 35.6-27 45.4-47.2l36.7-75.5c9.8-20.1 13-42.9 9.1-64.9-.9-5.3-5.3-9.3-10.6-10.1-51.5-8.2-92.8-47.1-104.5-97.4-1.8-7.6-8-13.4-15.7-14.6-54.6-8.7-97.7-52-106.2-106.8zM208 144a32 32 0 1 1 0 64 32 32 0 1 1 0-64zM144 336a32 32 0 1 1 64 0 32 32 0 1 1 -64 0zm224-64a32 32 0 1 1 0 64 32 32 0 1 1 0-64z",{"w":388,"h":389,"d":414},"M144-16l-48 112-48 0 0 48 48 0 0 32c0 17 3.3 33.2 9.3 48l-73.3 0 0 32 5.3 16 26.7 80-64 160 51.7 0 56.9-142.2 6.5-16.3c-1-3.1-10.1-30.3-27.2-81.5l51.4 0c22.6 19.9 52.2 32 84.7 32s62.1-12.1 84.7-32l51.4 0c-17.1 51.2-26.1 78.4-27.2 81.5l6.5 16.3 56.9 142.2 51.7 0-64-160 26.7-80 5.3-16 0-32-73.3 0c6-14.8 9.3-31 9.3-48l0-32 48 0 0-48-48 0-48-112-32 0-48 32-48-32-32 0zm80 272c-32.8 0-61-19.7-73.3-48l57.3 0 16-40 16 40 57.3 0c-12.3 28.3-40.5 48-73.3 48zm17.5 139.6l30.5-35.6 0-24-96 0 0 24 30.5 35.6-46.5 116.4 128 0-46.5-116.4z",{"w":389,"h":389,"d":416},"M497.4 49l17-17-33.9-33.9C473.6 4.9 453.3 25.2 419.7 58.8 375.4 22.1 318.5 0 256.4 0 115.1 0 .4 114.6 .4 256s114.6 256 256 256 256-114.6 256-256l-48 0c0 114.9-93.1 208-208 208s-208-93.1-208-208 93.1-208 208-208c48.8 0 93.7 16.8 129.1 44.9l-45.7 45.7c-23.5-16.8-52.3-26.6-83.4-26.6-79.5 0-144 64.5-144 144s64.5 144 144 144 144-64.5 144-144l-48 0c0 53-43 96-96 96s-96-43-96-96 43-96 96-96c17.8 0 34.5 4.8 48.8 13.3-52 52-79.5 79.5-82.7 82.7l33.9 33.9 17-17 224-224z",{"w":389,"h":389,"d":418},"M208 0l24 0C386.6 0 512 125.4 512 280l0 24-48 0 0-24C464 151.9 360.1 48 232 48l-24 0 0-48zm24 96c101.6 0 184 82.4 184 184l0 24-48 0 0-24c0-75.1-60.9-136-136-136l-24 0 0-48 24 0zM48 256c0 114.9 93.1 208 208 208 22.9 0 45-3.7 65.6-10.5l-263-263C51.7 211 48 233.1 48 256zM0 256c0-36.5 7.6-71.3 21.4-102.7 6.7-15.3 14.9-29.9 24.4-43.5 7.7 7.7 61.5 61.5 161.2 161.2 30.5-30.5 49.5-49.5 57-57L297.9 248c-7.5 7.5-26.5 26.5-57 57 99.7 99.7 153.5 153.5 161.2 161.2-13.6 9.5-28.2 17.7-43.5 24.4-31.4 13.8-66.2 21.4-102.7 21.4-141.4 0-256-114.6-256-256z",{"w":389,"h":389,"d":420},"M267.6 4.5l207.5 80.5 19.2 7.4 1.2 20.5c2.9 50-4.9 126.3-37.3 200.9-32.7 75.2-91.1 150-189.4 192.5l-12.7 5.5-12.7-5.5C144.9 463.9 86.6 389.2 53.9 313.9 21.5 239.3 13.7 162.9 16.6 113L17.8 92.5 37 85 244.5 4.5 256 0 267.6 4.5zM64.1 126C63.1 169.5 71 232.9 97.9 294.8 126.1 359.7 175 422.4 256 459.6 337.1 422.4 385.9 359.7 414.2 294.8 441 232.9 449 169.5 448 126L256 51.5 64.1 126zm302.3 44.7L352.3 190.1 249.8 330.9 233 354c-8.8-9.1-30.9-32-66.2-68.6l-16.7-17.3 34.5-33.3c9.5 9.8 23.9 24.7 43.2 44.7l85.6-117.7 14.1-19.4 38.8 28.2z",{"w":389,"h":389,"d":422},"M192 48l40 0 0 108-12.4 0c-7.6-16.5-24.3-28-43.6-28-26.5 0-48 21.5-48 48s21.5 48 48 48c19.4 0 36.1-11.5 43.6-28l12.4 0 0 56-92 0 0 56.4c-16.5 7.6-28 24.3-28 43.6 0 26.5 21.5 48 48 48s48-21.5 48-48c0-19.4-11.5-36.1-28-43.6l0-16.4 52 0 0 172-40 0c-16.8 0-31.2-10.3-37.1-25.1l-6.4-16-17.2 1c-1.1 .1-2.2 .1-3.2 .1-30.9 0-56-25.1-56-56 0-9.5 2.4-18.5 6.5-26.3l8.7-16.2-13.4-12.6c-11-10.2-17.8-24.8-17.8-40.9 0-21.6 12.2-40.4 30.3-49.8l22.6-11.7-13.1-21.9c-5-8.4-7.9-18.1-7.9-28.6 0-30.9 25.1-56 56-56l24 0 0-32c0-13.3 10.7-24 24-24zm88 148l12.4 0c7.6 16.5 24.3 28 43.6 28 26.5 0 48-21.5 48-48s-21.5-48-48-48c-19.4 0-36.1 11.5-43.6 28l-12.4 0 0-108 40 0c13.3 0 24 10.7 24 24l0 32 24 0c30.9 0 56 25.1 56 56 0 10.5-2.9 20.3-7.9 28.6l-13.1 21.9 22.6 11.7c18 9.3 30.3 28.1 30.3 49.8 0 16.1-6.8 30.7-17.8 40.9l-13.4 12.6 8.7 16.2c4.2 7.8 6.5 16.7 6.5 26.3 0 30.9-25.1 56-56 56-1.1 0-2.2 0-3.2-.1l-17.2-1-6.4 16C351.2 453.7 336.8 464 320 464l-40 0 0-76 92 0 0-56.4c16.5-7.6 28-24.3 28-43.6 0-26.5-21.5-48-48-48s-48 21.5-48 48c0 19.4 11.5 36.1 28 43.6l0 16.4-52 0 0-152zM192 512l128 0c31.1 0 58.4-16.2 74.1-40.5 52.7-5.1 93.9-49.5 93.9-103.5 0-11.5-1.9-22.5-5.3-32.9 13.4-17.5 21.3-39.4 21.3-63.1 0-32-14.5-60.6-37.1-79.7 3.3-10.2 5.1-21.1 5.1-32.3 0-49.6-34.8-91.1-81.3-101.5-6.3-33.3-35.6-58.5-70.7-58.5L192 0c-35.1 0-64.4 25.2-70.7 58.5-46.5 10.4-81.3 51.9-81.3 101.5 0 11.3 1.8 22.2 5.1 32.3-22.7 19.1-37.1 47.7-37.1 79.7 0 23.7 8 45.6 21.3 63.1-3.5 10.4-5.3 21.4-5.3 32.9 0 54 41.2 98.5 93.9 103.5 15.6 24.3 42.9 40.5 74.1 40.5zM336 192a16 16 0 1 1 0-32 16 16 0 1 1 0 32zm32 96a16 16 0 1 1 -32 0 16 16 0 1 1 32 0zM176 352a16 16 0 1 1 -32 0 16 16 0 1 1 32 0zm16-176a16 16 0 1 1 -32 0 16 16 0 1 1 32 0z",{"w":407,"h":389,"d":424},"M16 64C16 28.7 44.7 0 80 0L304 0c35.3 0 64 28.7 64 64l0 384c0 35.3-28.7 64-64 64L80 512c-35.3 0-64-28.7-64-64L16 64zm64 0l0 304 224 0 0-304-224 0zM192 472c17.7 0 32-14.3 32-32s-14.3-32-32-32-32 14.3-32 32 14.3 32 32 32z",{"w":389,"h":389,"d":426},"M0 256c0-46.6 12.5-90.4 34.3-128.9L144.1 318.3c21.9 39.2 63.8 65.7 111.9 65.7 14.3 0 27.1-2.3 40.8-6.6L220.5 509.6C95.9 492.3 0 385.3 0 256zm365.1 65.6c12.3-19.2 18.9-42.5 18.9-65.6 0-38.2-16.8-72.5-43.3-96l152.7 0c12 29.6 18.6 62.1 18.6 96 0 141.4-114.6 255.1-256 256L365.1 321.6zM477.8 128L256 128c-62.9 0-113.7 44.1-125.5 102.7L54.2 98.5C101 38.5 174 0 256 0 350.8 0 433.5 51.5 477.8 128zM344 256a88 88 0 1 1 -176 0 88 88 0 1 1 176 0z",{"w":389,"h":389,"d":428},"M448 96l0 256-384 0 0-256 384 0zM64 32C28.7 32 0 60.7 0 96L0 352c0 35.3 28.7 64 64 64l144 0-16 48-72 0c-13.3 0-24 10.7-24 24s10.7 24 24 24l272 0c13.3 0 24-10.7 24-24s-10.7-24-24-24l-72 0-16-48 144 0c35.3 0 64-28.7 64-64l0-256c0-35.3-28.7-64-64-64L64 32z",{"w":389,"h":389,"d":430},"M32 64C19.1 64 7.4 71.8 2.4 83.8S.2 109.5 9.4 118.6L192 301.3 192 416c0 8.5 3.4 16.6 9.4 22.6l64 64c9.2 9.2 22.9 11.9 34.9 6.9S320 492.9 320 480l0-178.7 182.6-182.6c9.2-9.2 11.9-22.9 6.9-34.9S492.9 64 480 64L32 64z",{"w":404,"h":389,"d":432},"M144 480c-79.5 0-144-64.5-144-144 0-63.4 41-117.2 97.9-136.5-1.3-7.7-1.9-15.5-1.9-23.5 0-79.5 64.5-144 144-144 55.4 0 103.5 31.3 127.6 77.1 14.2-8.3 30.8-13.1 48.4-13.1 53 0 96 43 96 96 0 15.7-3.8 30.6-10.5 43.7 44 20.3 74.5 64.7 74.5 116.3 0 70.7-57.3 128-128 128l-304 0zM305 191c-9.4-9.4-24.6-9.4-33.9 0l-72 72c-9.4 9.4-9.4 24.6 0 33.9s24.6 9.4 33.9 0l31-31 0 102.1c0 13.3 10.7 24 24 24s24-10.7 24-24l0-102.1 31 31c9.4 9.4 24.6 9.4 33.9 0s9.4-24.6 0-33.9l-72-72z",{"id":434,"title":435,"authorsCollection":436,"content":446,"extension":1045,"faqItemsCollection":1046,"faqTitle":1694,"featured":6,"hashTags":59,"meta":1695,"metaTitle":1696,"ogImage":59,"postType":1697,"publishedDate":1698,"relatedBlogPostsCollection":1699,"slug":4695,"stem":4696,"subtitle":59,"summary":4697,"synopsis":4708,"sys":4709,"tagsCollection":4712,"topicsCollection":4718,"__hash__":4739},"blog\u002Fblog\u002Fthe-top-10-browser-security-solutions-in-2026.json","The top 10 browser security solutions: Push Security, Island, LayerX and more",{"items":437},[438],{"fullName":439,"firstName":440,"jobTitle":441,"socialLinks":442,"profilePicture":444},"Alex Henshall","Alex","Product Team",[443],"https:\u002F\u002Fwww.linkedin.com\u002Fin\u002Falexhenshall\u002F",{"url":445},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F2rz3Pre3b1MexPIQ4hzPUe\u002F0ef8a092b7e7df00fbce3f7d1ccb96d1\u002FAlex_Henshall.jpeg",{"json":447,"links":935},{"data":448,"content":449,"nodeType":934},{},[450,459,466,498,505,514,523,527,536,579,600,606,609,617,624,644,647,655,662,669,672,680,687,694,697,705,712,730,733,741,748,755,758,766,773,780,783,791,810,813,821,828,835,841,844,852,859,866,869,877,884,902,908,915],{"data":451,"content":452,"nodeType":458},{},[453],{"data":454,"marks":455,"value":456,"nodeType":457},{},[],"Ask a security team where most of their tools are and it's the endpoint, network, or cloud. But ask where their users spend most of their time and it's the browser.","text","paragraph",{"data":460,"content":461,"nodeType":458},{},[462],{"data":463,"marks":464,"value":465,"nodeType":457},{},[],"So we got a category: browser security. And when it comes to the best browser security tools, there's a problem. Browser security means three different things depending on who's talking: enterprise browser extensions, enterprise browsers, and remote browser isolation (RBI).",{"data":467,"content":468,"nodeType":458},{},[469,473,482,486,494],{"data":470,"marks":471,"value":472,"nodeType":457},{},[],"The market reflects that confusion, but the momentum is real. According to ",{"data":474,"content":476,"nodeType":481},{"uri":475},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002F7-things-omdias-latest-report-tells-us-about-the-secure-enterprise-browser-market",[477],{"data":478,"marks":479,"value":480,"nodeType":457},{},[],"Omdia's 2026 research","hyperlink",{"data":483,"marks":484,"value":485,"nodeType":457},{},[],", browser security is already a top-five priority for 88% of organizations and the top priority for 26%, with 86% having meaningfully increased their browser security spending in response to emerging threats. ",{"data":487,"content":489,"nodeType":481},{"uri":488},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fthe-case-for-best-of-breed-browser-security",[490],{"data":491,"marks":492,"value":493,"nodeType":457},{},[],"Three browser security startups were acquired",{"data":495,"marks":496,"value":497,"nodeType":457},{},[]," by major platform vendors in 2026 alone — CrowdStrike bought Seraphic, Zscaler absorbed SquareX, and Akamai announced intent to acquire LayerX.",{"data":499,"content":500,"nodeType":458},{},[501],{"data":502,"marks":503,"value":504,"nodeType":457},{},[],"Here's what the browser security market looks like in 2026.",{"data":506,"content":507,"nodeType":458},{},[508],{"data":509,"marks":510,"value":513,"nodeType":457},{},[511],{"type":512},"bold","The top enterprise browser solutions in 2026 include Push Security, Island, and LayerX.",{"data":515,"content":521,"nodeType":522},{"target":516},{"sys":517},{"id":518,"type":519,"linkType":520},"5d35fpWpgIytQhhiABQray","Link","Entry",[],"embedded-entry-block",{"data":524,"content":525,"nodeType":526},{},[],"hr",{"data":528,"content":529,"nodeType":535},{},[530],{"data":531,"marks":532,"value":534,"nodeType":457},{},[533],{"type":512},"1. Push Security – Enterprise browser extension","heading-1",{"data":537,"content":538,"nodeType":458},{},[539,543,551,555,563,567,575],{"data":540,"marks":541,"value":542,"nodeType":457},{},[],"Push is a browser extension, not a browser, that turns whatever browser your people already use into a detection and response platform for the security team. With no migration, no user disruption, no new browser to manage. It covers ",{"data":544,"content":546,"nodeType":481},{"uri":545},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fthe-top-10-security-problems-you-can-solve-in-the-browser-ranked-by-value",[547],{"data":548,"marks":549,"value":550,"nodeType":457},{},[],"four use cases from a single deployment",{"data":552,"marks":553,"value":554,"nodeType":457},{},[],": detecting and stopping sophisticated browser-based attacks, AI visibility and control, identity and shadow IT security, and DLP and insider investigations. Detections are built on ",{"data":556,"content":558,"nodeType":481},{"uri":557},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fhow-to-avoid-the-browser-security-buyers-trap",[559],{"data":560,"marks":561,"value":562,"nodeType":457},{},[],"in-house threat research",{"data":564,"marks":565,"value":566,"nodeType":457},{},[]," and operationalized by autonomous agents, so what Push catches is based on attacker techniques and behaviors rather than a blocklist. It ",{"data":568,"content":570,"nodeType":481},{"uri":569},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fmaking-the-business-case-for-a-browser-security-solution",[571],{"data":572,"marks":573,"value":574,"nodeType":457},{},[],"deploys in minutes",{"data":576,"marks":577,"value":578,"nodeType":457},{},[]," across managed and unmanaged devices.",{"data":580,"content":581,"nodeType":458},{},[582,586,596],{"data":583,"marks":584,"value":585,"nodeType":457},{},[],"Push detects AiTM and device code phishing kits (",{"data":587,"content":589,"nodeType":481},{"uri":588},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fagentic-threat-hunting-benefits-for-customers",[590],{"data":591,"marks":592,"value":595,"nodeType":457},{},[593],{"type":594},"underline","75+ across Tycoon 2FA, Sneaky 2FA, Evilginx, and many others",{"data":597,"marks":598,"value":599,"nodeType":457},{},[],") behaviorally by analyzing page structure and script execution — so detection survives infrastructure rotation. It catches ClickFix-style clipboard injection before the payload executes, detects stolen session tokens via marker injection when they appear in uninstrumented browsers, and monitors OAuth consent flows across 20+ authorization servers. Push is deployed across 3 million browsers worldwide and has been rolled out to 100,000 users in under one hour during normal office hours.",{"data":601,"content":605,"nodeType":522},{"target":602},{"sys":603},{"id":604,"type":519,"linkType":520},"ZmRwtfBPVptxTOE6wt1Yq",[],{"data":607,"content":608,"nodeType":526},{},[],{"data":610,"content":611,"nodeType":535},{},[612],{"data":613,"marks":614,"value":616,"nodeType":457},{},[615],{"type":512},"2. Island – Enterprise browser",{"data":618,"content":619,"nodeType":458},{},[620],{"data":621,"marks":622,"value":623,"nodeType":457},{},[],"Island was one of the first to market in the enterprise browser category and still defines it. It replaces current browsers with a managed Chromium fork that gives IT granular control over copy-paste, screenshots, downloads, session recording, and application access — all enforced at the browser level without routing traffic through a proxy. For highly regulated environments where that degree of governance is a requirement, it's a capable platform with real enterprise traction.",{"data":625,"content":626,"nodeType":458},{},[627,631,640],{"data":628,"marks":629,"value":630,"nodeType":457},{},[],"It's a full browser replacement, with primary use cases around VDI replacement, contractor access, BYOD governance, and zero-trust network access. Most organizations plan for a ",{"data":632,"content":634,"nodeType":481},{"uri":633},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fenterprise-browser-vs-browser-extension-which-should-your-security-team-choose",[635],{"data":636,"marks":637,"value":639,"nodeType":457},{},[638],{"type":594},"phased rollout",{"data":641,"marks":642,"value":643,"nodeType":457},{},[],".",{"data":645,"content":646,"nodeType":526},{},[],{"data":648,"content":649,"nodeType":535},{},[650],{"data":651,"marks":652,"value":654,"nodeType":457},{},[653],{"type":512},"3. Prisma Browser – Enterprise browser",{"data":656,"content":657,"nodeType":458},{},[658],{"data":659,"marks":660,"value":661,"nodeType":457},{},[],"Formerly Talon, now Palo Alto Networks' enterprise browser and the last-mile enforcement layer of its SASE platform. Prisma Browser is a managed Chromium browser with DLP that inspects the rendered page and zero-trust access controls, designed primarily for contractor, BYOD, and remote worker populations accessing corporate apps from unmanaged devices.",{"data":663,"content":664,"nodeType":458},{},[665],{"data":666,"marks":667,"value":668,"nodeType":457},{},[],"Like Island, it's a browser replacement. It integrates natively with the broader Prisma Access and Cortex stack, feeding browser telemetry into Palo Alto Networks' existing correlation and response workflows.",{"data":670,"content":671,"nodeType":526},{},[],{"data":673,"content":674,"nodeType":535},{},[675],{"data":676,"marks":677,"value":679,"nodeType":457},{},[678],{"type":512},"4. Seraphic Security (CrowdStrike) – Enterprise browser extension",{"data":681,"content":682,"nodeType":458},{},[683],{"data":684,"marks":685,"value":686,"nodeType":457},{},[],"Seraphic works across any browser through an endpoint agent that adds enterprise security without replacing what's deployed. CrowdStrike acquired Seraphic in early 2026 to extend Falcon past the endpoint and into the browser layer, with the stated goal of correlating endpoint and browser telemetry in a single platform.",{"data":688,"content":689,"nodeType":458},{},[690],{"data":691,"marks":692,"value":693,"nodeType":457},{},[],"For existing CrowdStrike customers, the extension into the browser is a natural addition to the Falcon ecosystem. Cross-browser coverage remains a differentiator for mixed environments.",{"data":695,"content":696,"nodeType":526},{},[],{"data":698,"content":699,"nodeType":535},{},[700],{"data":701,"marks":702,"value":704,"nodeType":457},{},[703],{"type":512},"5. LayerX Security (Akamai) – Enterprise browser extension",{"data":706,"content":707,"nodeType":458},{},[708],{"data":709,"marks":710,"value":711,"nodeType":457},{},[],"LayerX is extension-based, focused on real-time DLP and AI governance which captures what happens inside AI tools, flagging sensitive data submissions, and enforcing policy, all without requiring a new browser. Low deployment friction and a growing AI visibility capability are the draw.",{"data":713,"content":714,"nodeType":458},{},[715,719,726],{"data":716,"marks":717,"value":718,"nodeType":457},{},[],"Akamai announced the intent to acquire LayerX in mid-2026 to complement its Zero Trust portfolio. For buyers evaluating LayerX as a long-term platform bet, the ",{"data":720,"content":721,"nodeType":481},{"uri":488},[722],{"data":723,"marks":724,"value":725,"nodeType":457},{},[],"question is what the roadmap looks like 18 months post-close",{"data":727,"marks":728,"value":729,"nodeType":457},{},[],", given Akamai's track record of absorbing acquisitions (Guardicore, Neosec, Inverse) into its broader platform.",{"data":731,"content":732,"nodeType":526},{},[],{"data":734,"content":735,"nodeType":535},{},[736],{"data":737,"marks":738,"value":740,"nodeType":457},{},[739],{"type":512},"6. SquareX (Zscaler) – Enterprise browser extension",{"data":742,"content":743,"nodeType":458},{},[744],{"data":745,"marks":746,"value":747,"nodeType":457},{},[],"SquareX takes a detection-minded posture, inspecting files and links while browsing, neutralizing malicious content before it reaches the endpoint, and offering disposable browser environments for high-risk activity. It was clearly built by people who think in attacker terms.",{"data":749,"content":750,"nodeType":458},{},[751],{"data":752,"marks":753,"value":754,"nodeType":457},{},[],"Zscaler acquired SquareX in early 2026, integrating it into the Zero Trust Exchange alongside its existing SSE capabilities.",{"data":756,"content":757,"nodeType":526},{},[],{"data":759,"content":760,"nodeType":535},{},[761],{"data":762,"marks":763,"value":765,"nodeType":457},{},[764],{"type":512},"7. Keep Aware – Enterprise browser extension",{"data":767,"content":768,"nodeType":458},{},[769],{"data":770,"marks":771,"value":772,"nodeType":457},{},[],"Keep Aware is an agentless extension built with security operations in mind. It's quick to deploy through MDM or group policy, and focused on surfacing browser threats, extension risk, and AI usage into existing SOC workflows. Detection and response is the throughline, with SIEM integration as a core part of the offering.",{"data":774,"content":775,"nodeType":458},{},[776],{"data":777,"marks":778,"value":779,"nodeType":457},{},[],"Founded in 2022, Keep Aware has been iterating quickly with a focused product roadmap around browser detection and response.",{"data":781,"content":782,"nodeType":526},{},[],{"data":784,"content":785,"nodeType":535},{},[786],{"data":787,"marks":788,"value":790,"nodeType":457},{},[789],{"type":512},"8. Menlo Security – Remote browser isolation",{"data":792,"content":793,"nodeType":458},{},[794,798,806],{"data":795,"marks":796,"value":797,"nodeType":457},{},[],"Menlo pioneered ",{"data":799,"content":801,"nodeType":481},{"uri":800},"https:\u002F\u002Fpushsecurity.com\u002Fsolution\u002Ftool-replacements\u002Fremote-browser-isolation",[802],{"data":803,"marks":804,"value":805,"nodeType":457},{},[],"remote browser isolation",{"data":807,"marks":808,"value":809,"nodeType":457},{},[],": web content renders in a disposable cloud container and the user receives a clean visual stream, so nothing malicious ever touches the endpoint. For zero-tolerance environments and third-party or contractor access where you don't fully trust the device, the approach has a solid track record. Cloud rendering introduces latency and the occasional site-compatibility issue, though Menlo has invested in reducing both over the years.",{"data":811,"content":812,"nodeType":526},{},[],{"data":814,"content":815,"nodeType":535},{},[816],{"data":817,"marks":818,"value":820,"nodeType":457},{},[819],{"type":512},"9. Chrome Enterprise \u002F Edge for Business – Enterprise browser",{"data":822,"content":823,"nodeType":458},{},[824],{"data":825,"marks":826,"value":827,"nodeType":457},{},[],"The security controls are already built into the browsers most of your people use. Chrome Enterprise offers centralized management, Safe Browsing, and identity tool integration across the fleet; Edge for Business adds work-and-personal separation, phishing protection, and tight integration with Microsoft 365 and Defender.",{"data":829,"content":830,"nodeType":458},{},[831],{"data":832,"marks":833,"value":834,"nodeType":457},{},[],"These are baseline controls, and for many organizations they're effectively free with what's already deployed. Most organizations treat them as the foundation that the rest of the tools on this list build on.",{"data":836,"content":840,"nodeType":522},{"target":837},{"sys":838},{"id":839,"type":519,"linkType":520},"7Gbd8bBWa19gP5DMfeeB7J",[],{"data":842,"content":843,"nodeType":526},{},[],{"data":845,"content":846,"nodeType":535},{},[847],{"data":848,"marks":849,"value":851,"nodeType":457},{},[850],{"type":512},"10. SURF Security – Enterprise browser",{"data":853,"content":854,"nodeType":458},{},[855],{"data":856,"marks":857,"value":858,"nodeType":457},{},[],"SURF is a Chromium-based enterprise browser built zero-trust-first, with identity-based access controls, DLP, and session security inside a fully managed environment. Centralized, policy-driven control by default is the pitch, aimed at security-first organizations that want a locked-down browser from day one.",{"data":860,"content":861,"nodeType":458},{},[862],{"data":863,"marks":864,"value":865,"nodeType":457},{},[],"Like Island and Prisma, it's a browser replacement, so it follows the same deployment model — plan for a migration alongside the capabilities.",{"data":867,"content":868,"nodeType":526},{},[],{"data":870,"content":871,"nodeType":535},{},[872],{"data":873,"marks":874,"value":876,"nodeType":457},{},[875],{"type":512},"Learn more about Push Security",{"data":878,"content":879,"nodeType":458},{},[880],{"data":881,"marks":882,"value":883,"nodeType":457},{},[],"Push Security is the most powerful AI-native security tool in the browser. Think EDR, but for the browser — high-fidelity telemetry and real-time control across every session, on every device, with no browser migration required.",{"data":885,"content":886,"nodeType":458},{},[887,891,898],{"data":888,"marks":889,"value":890,"nodeType":457},{},[],"Push is the best choice for organizations looking to ",{"data":892,"content":893,"nodeType":481},{"uri":545},[894],{"data":895,"marks":896,"value":897,"nodeType":457},{},[],"solve the most impactful security problems in the browse",{"data":899,"marks":900,"value":901,"nodeType":457},{},[],"r, with use cases including detecting and stopping advanced attacks, data loss and insider investigations, identity and shadow IT security, and AI visibility and control. ",{"data":903,"content":907,"nodeType":522},{"target":904},{"sys":905},{"id":906,"type":519,"linkType":520},"4nGzT9cNG0Yid93uUCCuTt",[],{"data":909,"content":910,"nodeType":458},{},[911],{"data":912,"marks":913,"value":914,"nodeType":457},{},[],"Security teams use Push to detect and stop advanced browser-based attacks like AiTM phishing, ClickFix, and session hijacking; gain visibility and control over AI tool usage across their workforce; harden identities by surfacing credential reuse, SSO gaps, and shadow IT; and support data loss and insider investigations with browser-layer telemetry that other tools can't see.",{"data":916,"content":917,"nodeType":458},{},[918,922,930],{"data":919,"marks":920,"value":921,"nodeType":457},{},[],"Book a ",{"data":923,"content":925,"nodeType":481},{"uri":924},"https:\u002F\u002Fpushsecurity.com\u002Fdemo",[926],{"data":927,"marks":928,"value":929,"nodeType":457},{},[],"live demo",{"data":931,"marks":932,"value":933,"nodeType":457},{},[]," to learn more.","document",{"entries":936},{"hyperlink":937,"inline":938,"block":939},[],[],[940,973,998,1036],{"sys":941,"__typename":942,"content":943,"name":972,"title":59},{"id":518},"InsightTextBlockComponent",{"json":944},{"data":945,"content":946,"nodeType":934},{},[947,965],{"data":948,"content":949,"nodeType":458},{},[950,954,961],{"data":951,"marks":952,"value":953,"nodeType":457},{},[],"Enterprise browsers are also commonly referred to as Secure Enterprise Browsers (SEBs). These are functionally the same thing, but buyers looking specifically for Secure Enterprise Browsers tend to be focused more on security use-cases (protecting users, and by extension business, from external threats). But all enterprise browsers tend to cover security use cases to a ",{"data":955,"content":956,"nodeType":481},{"uri":545},[957],{"data":958,"marks":959,"value":960,"nodeType":457},{},[],"lesser or greater degree",{"data":962,"marks":963,"value":964,"nodeType":457},{},[],". ",{"data":966,"content":967,"nodeType":458},{},[968],{"data":969,"marks":970,"value":971,"nodeType":457},{},[],"So, this list applies to Secure Enterprise Browsers too. ","Top 10 browser solutions IB3",{"sys":974,"__typename":942,"content":975,"name":997,"title":59},{"id":604},{"json":976},{"data":977,"content":978,"nodeType":934},{},[979],{"data":980,"content":981,"nodeType":458},{},[982,986,994],{"data":983,"marks":984,"value":985,"nodeType":457},{},[],"In a 30-day proof-of-value deployment at a ~4,500-employee financial services organization with a mature existing security stack, Push detected and blocked 6 ClickFix attacks and 10 AiTM phishing attempts — none of which were visible to any other tool in place. ",{"data":987,"content":989,"nodeType":481},{"uri":988},"https:\u002F\u002Fpushsecurity.com\u002Fcustomer-stories",[990],{"data":991,"marks":992,"value":993,"nodeType":457},{},[],"You can read more customer stories here",{"data":995,"marks":996,"value":964,"nodeType":457},{},[],"Top 10 browser solutions IB1",{"sys":999,"__typename":942,"content":1000,"name":1035,"title":59},{"id":839},{"json":1001},{"nodeType":934,"data":1002,"content":1003},{},[1004],{"nodeType":458,"data":1005,"content":1006},{},[1007,1011,1019,1023,1031],{"nodeType":457,"value":1008,"marks":1009,"data":1010},"According to ",[],{},{"nodeType":481,"data":1012,"content":1013},{"uri":475},[1014],{"nodeType":457,"value":1015,"marks":1016,"data":1018},"Omdia",[1017],{"type":594},{},{"nodeType":457,"value":1020,"marks":1021,"data":1022},", 86% of organizations have meaningfully increased browser security investment in response to emerging threats — 85% expect to spend more over the next 12–24 months. The built-in controls in Chrome and Edge are a foundation, but they're ",[],{},{"nodeType":481,"data":1024,"content":1025},{"uri":569},[1026],{"nodeType":457,"value":1027,"marks":1028,"data":1030},"insufficient against the current threat landscape",[1029],{"type":594},{},{"nodeType":457,"value":1032,"marks":1033,"data":1034}," on their own.",[],{},"Top 10 browser solutions IB2",{"sys":1037,"__typename":1038,"title":1039,"caption":1040,"layoutMode":59,"file":1041},{"id":906},"Image","Comparing ease of deployment x security value for browser security solutions","Comparing ease of deployment x security value for browser security solutions.",{"url":1042,"width":1043,"height":1044},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F4z1RAFROesqaBF4H3qR8yu\u002F1e21a68602402773bfa843fd0208d4ca\u002FScreenshot_2026-07-27_at_10.36.43.png",1408,952,"json",{"items":1047},[1048,1072,1109,1132,1163,1191,1332,1367,1427,1533,1557,1611,1663],{"answer":1049,"question":1071},{"json":1050},{"nodeType":934,"data":1051,"content":1052},{},[1053],{"nodeType":458,"data":1054,"content":1055},{},[1056,1060,1067],{"nodeType":457,"value":1057,"marks":1058,"data":1059},"Browser security refers to the tools and practices that protect users, data, and organizations from threats that originate inside the web browser. The browser is where modern work happens: employees access SaaS applications, interact with AI tools, and handle sensitive data — which makes it ",[],{},{"nodeType":481,"data":1061,"content":1062},{"uri":545},[1063],{"nodeType":457,"value":1064,"marks":1065,"data":1066},"the most targeted attack surface in the enterprise",[],{},{"nodeType":457,"value":1068,"marks":1069,"data":1070},". When people discuss browser security solutions, they usually mean secure enterprise browser (SEB) extensions or full-stack enterprise browsers. Remote browser isolation (RBI) is a third category that is not really comparable to the other two, but comes up through virtue of sounding similar. ",[],{},"What is browser security?",{"answer":1073,"question":1108},{"json":1074},{"nodeType":934,"data":1075,"content":1076},{},[1077,1084,1091],{"nodeType":458,"data":1078,"content":1079},{},[1080],{"nodeType":457,"value":1081,"marks":1082,"data":1083},"An enterprise browser extension deploys into whatever browser your users already have and adds security capabilities without changing the user experience or requiring a migration. An enterprise browser replaces the existing browser entirely with a managed application that embeds security controls at the browser level.",[],{},{"nodeType":458,"data":1085,"content":1086},{},[1087],{"nodeType":457,"value":1088,"marks":1089,"data":1090},"Extensions offer faster deployment with no migration required and are typically built for the security team's need to detect and respond to threats — Gartner explicitly notes that extensions have become the preferred deployment option in the category. Full-stack enterprise browsers offer deeper workspace controls (copy\u002Fpaste restrictions, watermarking, VDI replacement) and are typically built for the IT team's need to govern access. ",[],{},{"nodeType":458,"data":1092,"content":1093},{},[1094,1098,1105],{"nodeType":457,"value":1095,"marks":1096,"data":1097},"The two are not mutually exclusive — many organizations use an enterprise browser for contractors or regulated populations and an extension like Push across the rest of the workforce. We cover this in detail in ",[],{},{"nodeType":481,"data":1099,"content":1100},{"uri":633},[1101],{"nodeType":457,"value":1102,"marks":1103,"data":1104},"Enterprise browser vs. browser extension: Which should your security team choose?",[],{},{"nodeType":457,"value":21,"marks":1106,"data":1107},[],{},"What is the difference between an enterprise browser extension and an enterprise browser?",{"answer":1110,"question":1131},{"json":1111},{"nodeType":934,"data":1112,"content":1113},{},[1114],{"nodeType":458,"data":1115,"content":1116},{},[1117,1121,1127],{"nodeType":457,"value":1118,"marks":1119,"data":1120},"No. enterprise browser extensions like Push Security, Seraphic (CrowdStrike), LayerX (Akamai), SquareX (Zscaler), and Keep Aware deploy into existing browsers without requiring users to switch. Enterprise browsers like Island, Prisma Browser, and SURF do require browser replacement. According to ",[],{},{"nodeType":481,"data":1122,"content":1123},{"uri":475},[1124],{"nodeType":457,"value":480,"marks":1125,"data":1126},[],{},{"nodeType":457,"value":1128,"marks":1129,"data":1130},", 48% of organizations cite the ability to use their existing browsers as an important attribute in a secure browsing solution, and 80% expect to use browser security alongside existing tools rather than as a replacement.",[],{},"Do I need to replace my browser to use an enterprise browser?",{"answer":1133,"question":1162},{"json":1134},{"nodeType":934,"data":1135,"content":1136},{},[1137,1144],{"nodeType":458,"data":1138,"content":1139},{},[1140],{"nodeType":457,"value":1141,"marks":1142,"data":1143},"CrowdStrike, Zscaler, and Akamai all acquired browser security startups in 2026. This is significant validation of the the browser security market that the browser is a gap that network and endpoint security vendors have acknowledged and are attempting to close. ",[],{},{"nodeType":458,"data":1145,"content":1146},{},[1147,1151,1159],{"nodeType":457,"value":1148,"marks":1149,"data":1150},"But whether acquired products retain their innovation velocity as they're absorbed into larger platforms is a ",[],{},{"nodeType":481,"data":1152,"content":1153},{"uri":488},[1154],{"nodeType":457,"value":1155,"marks":1156,"data":1158},"legitimate concern for buyers evaluating long-term roadmaps",[1157],{"type":594},{},{"nodeType":457,"value":643,"marks":1160,"data":1161},[],{},"What do browser security vendor acquisitions mean for buyers?",{"answer":1164,"question":1190},{"json":1165},{"nodeType":934,"data":1166,"content":1167},{},[1168],{"nodeType":458,"data":1169,"content":1170},{},[1171,1175,1186],{"nodeType":457,"value":1172,"marks":1173,"data":1174},"Yes, but it depends on the approach and vendor. According to",[],{},{"nodeType":481,"data":1176,"content":1177},{"uri":475},[1178,1182],{"nodeType":457,"value":1179,"marks":1180,"data":1181}," ",[],{},{"nodeType":457,"value":1015,"marks":1183,"data":1185},[1184],{"type":594},{},{"nodeType":457,"value":1187,"marks":1188,"data":1189},", 32% of users access corporate applications from an unmanaged device at least occasionally. Enterprise browsers can be installed on unmanaged devices, but require the user to download and switch to a new browser application. Enterprise browser extensions like Push can be deployed to contractor and BYOD machines without MDM — via email or landing page self-enrollment — providing threat detection and policy enforcement without browser replacement or device management overhead.",[],{},"Can browser security be deployed to unmanaged or BYOD devices?",{"answer":1192,"question":1331},{"json":1193},{"nodeType":934,"data":1194,"content":1195},{},[1196,1267,1285],{"nodeType":458,"data":1197,"content":1198},{},[1199,1203,1212,1216,1225,1228,1237,1241,1250,1254,1263],{"nodeType":457,"value":1200,"marks":1201,"data":1202},"The most common attacks include ",[],{},{"nodeType":481,"data":1204,"content":1206},{"uri":1205},"https:\u002F\u002Fpushsecurity.com\u002Fsolution\u002Fstop-browser-based-attacks\u002Fadversary-in-the-middle-attacks",[1207],{"nodeType":457,"value":1208,"marks":1209,"data":1211},"AiTM phishing",[1210],{"type":594},{},{"nodeType":457,"value":1213,"marks":1214,"data":1215},", ",[],{},{"nodeType":481,"data":1217,"content":1219},{"uri":1218},"https:\u002F\u002Fpushsecurity.com\u002Fsolution\u002Fstop-browser-based-attacks\u002Fclickfix-fix-variants",[1220],{"nodeType":457,"value":1221,"marks":1222,"data":1224},"ClickFix-style social engineering",[1223],{"type":594},{},{"nodeType":457,"value":1213,"marks":1226,"data":1227},[],{},{"nodeType":481,"data":1229,"content":1231},{"uri":1230},"https:\u002F\u002Fpushsecurity.com\u002Fsolution\u002Fstop-browser-based-attacks\u002Fmalicious-browser-extensions",[1232],{"nodeType":457,"value":1233,"marks":1234,"data":1236},"malicious browser extensions",[1235],{"type":594},{},{"nodeType":457,"value":1238,"marks":1239,"data":1240},", and ",[],{},{"nodeType":481,"data":1242,"content":1244},{"uri":1243},"https:\u002F\u002Fpushsecurity.com\u002Fsolution\u002Fstop-browser-based-attacks\u002Fmalicious-oauth-integrations",[1245],{"nodeType":457,"value":1246,"marks":1247,"data":1249},"malicious OAuth consent grants",[1248],{"type":594},{},{"nodeType":457,"value":1251,"marks":1252,"data":1253},". In 2026, ",[],{},{"nodeType":481,"data":1255,"content":1257},{"uri":1256},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fdevice-code-phishing",[1258],{"nodeType":457,"value":1259,"marks":1260,"data":1262},"device code phishing",[1261],{"type":594},{},{"nodeType":457,"value":1264,"marks":1265,"data":1266}," has become a core part of the attacker’s arsenal too, with 25+ unique attacker kits now offering the technique. ",[],{},{"nodeType":458,"data":1268,"content":1269},{},[1270,1274,1281],{"nodeType":457,"value":1271,"marks":1272,"data":1273},"Among browser-based attack victims surveyed by ",[],{},{"nodeType":481,"data":1275,"content":1276},{"uri":475},[1277],{"nodeType":457,"value":1015,"marks":1278,"data":1280},[1279],{"type":594},{},{"nodeType":457,"value":1282,"marks":1283,"data":1284},", phishing was the most common attack type (40%), followed by data loss or leakage (38%), malicious browser extensions (34%), and credential theft (28%). ",[],{},{"nodeType":458,"data":1286,"content":1287},{},[1288,1292,1327],{"nodeType":457,"value":1289,"marks":1290,"data":1291},"It's worth noting the distinction between",[],{},{"nodeType":481,"data":1293,"content":1295},{"uri":1294},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fwhy-modern-browser-attacks-evade-edr",[1296,1299,1304,1311,1316,1322],{"nodeType":457,"value":1179,"marks":1297,"data":1298},[],{},{"nodeType":457,"value":1300,"marks":1301,"data":1303},"attacks ",[1302],{"type":594},{},{"nodeType":457,"value":1305,"marks":1306,"data":1310},"on",[1307,1308],{"type":594},{"type":1309},"italic",{},{"nodeType":457,"value":1312,"marks":1313,"data":1315}," the browser and attacks ",[1314],{"type":594},{},{"nodeType":457,"value":1317,"marks":1318,"data":1321},"inside",[1319,1320],{"type":594},{"type":1309},{},{"nodeType":457,"value":1323,"marks":1324,"data":1326}," the browser",[1325],{"type":594},{},{"nodeType":457,"value":1328,"marks":1329,"data":1330},". A number of the solutions in this list were designed to stop browser exploitation and prevent sandbox escapes. But the vast majority of the attacks in the wild are identity based — they happen in the browser, not on it. ",[],{},"What are the most common browser-based attacks in 2026?",{"answer":1333,"question":1366},{"json":1334},{"nodeType":934,"data":1335,"content":1336},{},[1337,1344],{"nodeType":458,"data":1338,"content":1339},{},[1340],{"nodeType":457,"value":1341,"marks":1342,"data":1343},"EDR monitors the operating system layer — processes, file system activity, registry changes, memory behavior. Browser security operates inside the browser session — observing the rendered page, credential entry, session tokens, and user interaction. ",[],{},{"nodeType":458,"data":1345,"content":1346},{},[1347,1351,1362],{"nodeType":457,"value":1348,"marks":1349,"data":1350},"The two are complementary:",[],{},{"nodeType":481,"data":1352,"content":1353},{"uri":1294},[1354,1357],{"nodeType":457,"value":1179,"marks":1355,"data":1356},[],{},{"nodeType":457,"value":1358,"marks":1359,"data":1361},"EDR catches malware execution and endpoint-level attacks, while browser security catches credential phishing, session hijacking, OAuth consent abuse, and browser-native social engineering",[1360],{"type":594},{},{"nodeType":457,"value":1363,"marks":1364,"data":1365}," like ClickFix that never touch the endpoint in ways EDR can observe. CrowdStrike's acquisition of Seraphic in 2026 reflects the industry recognition that endpoint and browser are separate detection layers that both need to be instrumented.",[],{},"Do I need browser security if I already have EDR?",{"answer":1368,"question":1426},{"json":1369},{"nodeType":934,"data":1370,"content":1371},{},[1372,1379,1408],{"nodeType":458,"data":1373,"content":1374},{},[1375],{"nodeType":457,"value":1376,"marks":1377,"data":1378},"Yes, but the effectiveness depends on the tool and its detection approach. AiTM phishing kits relay credentials and MFA tokens in real time, so most forms of MFA are bypassed. Browser security tools with behavioral detection — analyzing page structure, script behavior, and credential-harvesting mechanics — can detect phishing kits regardless of which domain they're hosted on or how quickly the infrastructure rotates. ",[],{},{"nodeType":458,"data":1380,"content":1381},{},[1382,1386,1394,1398,1404],{"nodeType":457,"value":1383,"marks":1384,"data":1385},"Tools that rely primarily on URL blocklists or reputation scores are less effective because ",[],{},{"nodeType":481,"data":1387,"content":1389},{"uri":1388},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fverizon-dbir-2026-review",[1390],{"nodeType":457,"value":1391,"marks":1392,"data":1393},"89% of phishing domains are active for fewer than two days",[],{},{"nodeType":457,"value":1395,"marks":1396,"data":1397},". It's also worth noting that not all MFA-bypass phishing works the same way. ",[],{},{"nodeType":481,"data":1399,"content":1400},{"uri":1256},[1401],{"nodeType":457,"value":269,"marks":1402,"data":1403},[],{},{"nodeType":457,"value":1405,"marks":1406,"data":1407}," sidesteps authentication entirely — the user authorizes a device on a legitimate identity provider page, and the attacker receives a valid token without ever touching the credential exchange. ",[],{},{"nodeType":458,"data":1409,"content":1410},{},[1411,1414,1422],{"nodeType":457,"value":21,"marks":1412,"data":1413},[],{},{"nodeType":481,"data":1415,"content":1416},{"uri":588},[1417],{"nodeType":457,"value":1418,"marks":1419,"data":1421},"With attacks evolving so quickly, telemetry isn't enough on its own",[1420],{"type":594},{},{"nodeType":457,"value":1423,"marks":1424,"data":1425}," — the vendor needs dedicated threat research expertise to turn that visibility into detections that keep pace with attacker innovation. Push detects and blocks phishing including AiTM reverse-proxy kits, human-operated relay panels, and device code phishing flows, backed by an in-house research team that discovers and publishes new attack techniques as they emerge.",[],{},"Can browser security stop phishing that bypasses MFA?",{"answer":1428,"question":1532},{"json":1429},{"nodeType":934,"data":1430,"content":1431},{},[1432,1439,1504],{"nodeType":458,"data":1433,"content":1434},{},[1435],{"nodeType":457,"value":1436,"marks":1437,"data":1438},"The criteria that matter most are: ",[],{},{"nodeType":1440,"data":1441,"content":1442},"unordered-list",{},[1443,1454,1464,1474,1484,1494],{"nodeType":1444,"data":1445,"content":1446},"list-item",{},[1447],{"nodeType":458,"data":1448,"content":1449},{},[1450],{"nodeType":457,"value":1451,"marks":1452,"data":1453},"Detection model — is the vendor detecting behavioral attacker techniques or relying on URL blocklists that attackers rotate in minutes?",[],{},{"nodeType":1444,"data":1455,"content":1456},{},[1457],{"nodeType":458,"data":1458,"content":1459},{},[1460],{"nodeType":457,"value":1461,"marks":1462,"data":1463},"Deployment model — does it deploy into existing browsers or require a migration? ",[],{},{"nodeType":1444,"data":1465,"content":1466},{},[1467],{"nodeType":458,"data":1468,"content":1469},{},[1470],{"nodeType":457,"value":1471,"marks":1472,"data":1473},"Coverage for unmanaged and BYOD devices — does it need MDM, an endpoint agent, or just a browser? ",[],{},{"nodeType":1444,"data":1475,"content":1476},{},[1477],{"nodeType":458,"data":1478,"content":1479},{},[1480],{"nodeType":457,"value":1481,"marks":1482,"data":1483},"Integration — does it feed telemetry into your SIEM, XDR, and identity tools or create a silo? ",[],{},{"nodeType":1444,"data":1485,"content":1486},{},[1487],{"nodeType":458,"data":1488,"content":1489},{},[1490],{"nodeType":457,"value":1491,"marks":1492,"data":1493},"AI visibility and governance — can it discover shadow AI apps and govern OAuth consent flows? ",[],{},{"nodeType":1444,"data":1495,"content":1496},{},[1497],{"nodeType":458,"data":1498,"content":1499},{},[1500],{"nodeType":457,"value":1501,"marks":1502,"data":1503},"Research depth — is the vendor discovering novel attack techniques or covering what others already documented? ",[],{},{"nodeType":458,"data":1505,"content":1506},{},[1507,1511,1518,1522,1529],{"nodeType":457,"value":1508,"marks":1509,"data":1510},"We've written a detailed guide on ",[],{},{"nodeType":481,"data":1512,"content":1513},{"uri":557},[1514],{"nodeType":457,"value":1515,"marks":1516,"data":1517},"how to avoid the browser security buyer's trap",[],{},{"nodeType":457,"value":1519,"marks":1520,"data":1521}," and ",[],{},{"nodeType":481,"data":1523,"content":1524},{"uri":569},[1525],{"nodeType":457,"value":1526,"marks":1527,"data":1528},"how to make the business case for browser security",[],{},{"nodeType":457,"value":643,"marks":1530,"data":1531},[],{},"What should I look for when evaluating browser security solutions?",{"answer":1534,"question":1556},{"json":1535},{"nodeType":934,"data":1536,"content":1537},{},[1538],{"nodeType":458,"data":1539,"content":1540},{},[1541,1545,1553],{"nodeType":457,"value":1542,"marks":1543,"data":1544},"RBI was designed to prevent malicious content from reaching the endpoint by rendering web pages in a remote container. The architecture is effective for that specific threat model, but the dominant browser-based attacks in 2026 — AiTM phishing, session hijacking, ClickFix, OAuth consent abuse — don't deliver payloads to the endpoint. They manipulate what the user sees, steal session tokens, and hijack authenticated state inside the browser session. There's nothing for RBI to isolate. RBI still has value in specific zero-tolerance environments and for managing untrusted third-party access, but for organizations looking to address the threats driving most browser-based breaches today, an ",[],{},{"nodeType":481,"data":1546,"content":1547},{"uri":800},[1548],{"nodeType":457,"value":1549,"marks":1550,"data":1552},"enterprise browser extension is more appropriate",[1551],{"type":594},{},{"nodeType":457,"value":643,"marks":1554,"data":1555},[],{},"Can remote browser isolation (RBI) stop the same attacks as an enterprise browser?",{"answer":1558,"question":1610},{"json":1559},{"nodeType":934,"data":1560,"content":1561},{},[1562,1603],{"nodeType":458,"data":1563,"content":1564},{},[1565,1568,1576,1580,1586,1590,1599],{"nodeType":457,"value":21,"marks":1566,"data":1567},[],{},{"nodeType":481,"data":1569,"content":1571},{"uri":1570},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fwhy-you-cant-control-ai-without-being-in-the-browser",[1572],{"nodeType":457,"value":1573,"marks":1574,"data":1575},"AI usage is primarily browser-based",[],{},{"nodeType":457,"value":1577,"marks":1578,"data":1579}," — every LLM interaction, every prompt containing sensitive data, every AI agent authorization happens inside a browser session. Browser security tools can discover which AI tools are in use (including shadow AI), monitor what data users share with them, observe OAuth consent flows for AI agent permissions, and block access to unsanctioned AI applications. According to ",[],{},{"nodeType":481,"data":1581,"content":1582},{"uri":475},[1583],{"nodeType":457,"value":1015,"marks":1584,"data":1585},[],{},{"nodeType":457,"value":1587,"marks":1588,"data":1589},", generative AI application security was the #1 capability organizations want from a secure browsing solution at 59%, ahead of data loss prevention and general web security. ",[],{},{"nodeType":481,"data":1591,"content":1593},{"uri":1592},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fwhat-push-data-reveals-about-the-state-of-shadow-ai",[1594],{"nodeType":457,"value":1595,"marks":1596,"data":1598},"Push data shows the average organization has 16 unique AI apps, 17 AI browser extensions, and 17 AI OAuth integrations",[1597],{"type":594},{},{"nodeType":457,"value":1600,"marks":1601,"data":1602}," in active use — most unapproved (or simply not known about).",[],{},{"nodeType":458,"data":1604,"content":1605},{},[1606],{"nodeType":457,"value":1607,"marks":1608,"data":1609},"\n",[],{},"How does browser security help with AI governance?",{"answer":1612,"question":1662},{"json":1613},{"nodeType":934,"data":1614,"content":1615},{},[1616,1656],{"nodeType":458,"data":1617,"content":1618},{},[1619,1622,1631,1634,1642,1646,1653],{"nodeType":457,"value":21,"marks":1620,"data":1621},[],{},{"nodeType":481,"data":1623,"content":1625},{"uri":1624},"https:\u002F\u002Fpushsecurity.com\u002Fsolution\u002Ftool-replacements\u002Fsecure-web-gateways",[1626],{"nodeType":457,"value":1627,"marks":1628,"data":1630},"SWGs",[1629],{"type":594},{},{"nodeType":457,"value":1519,"marks":1632,"data":1633},[],{},{"nodeType":481,"data":1635,"content":1637},{"uri":1636},"https:\u002F\u002Fpushsecurity.com\u002Fsolution\u002Ftool-replacements\u002Fcloud-access-security-broker",[1638],{"nodeType":457,"value":1639,"marks":1640,"data":1641},"CASBs",[],{},{"nodeType":457,"value":1643,"marks":1644,"data":1645}," operate at the network\u002Fproxy layer, inspecting traffic metadata and URLs. Browser security operates inside the browser session, observing the rendered page, script behavior, credential entry, and user interaction. The key difference: network tools can tell you where data went, but browser security sees what the user actually saw and did. SWGs block known-bad URLs via blocklists — but phishing infrastructure rotates faster than blocklists update. Browser-native detection analyzes page behavior regardless of whether the URL is known-bad. The two are complementary, though browser-layer capabilities are ",[],{},{"nodeType":481,"data":1647,"content":1648},{"uri":569},[1649],{"nodeType":457,"value":1650,"marks":1651,"data":1652},"increasingly making network-centric tools redundant for specific use cases",[],{},{"nodeType":457,"value":643,"marks":1654,"data":1655},[],{},{"nodeType":458,"data":1657,"content":1658},{},[1659],{"nodeType":457,"value":1607,"marks":1660,"data":1661},[],{},"Do I still need a secure web gateway (SWG) or CASB if I have browser security?",{"answer":1664,"question":1693},{"json":1665},{"nodeType":934,"data":1666,"content":1667},{},[1668,1675],{"nodeType":458,"data":1669,"content":1670},{},[1671],{"nodeType":457,"value":1672,"marks":1673,"data":1674},"If you're counting on user awareness as a meaningful defense layer, yes. Security awareness training is not a technical control — it depends on every user making the right call, every time, across every delivery channel. Browser-based attacks now arrive through email, search engines, SMS, QR codes, social media, and voice calls, each with different lure formats and social engineering mechanics. The volume and variation makes it impossible for users to keep up. ",[],{},{"nodeType":458,"data":1676,"content":1677},{},[1678,1682,1690],{"nodeType":457,"value":1679,"marks":1680,"data":1681},"Browser security detects and blocks attacks automatically at the point of risk regardless of the delivery channel, because the detection happens inside the browser session where the attack plays out — ",[],{},{"nodeType":481,"data":1683,"content":1685},{"uri":1684},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fwhy-your-training-budget-belongs-in-real-time-browser-security",[1686],{"nodeType":457,"value":1687,"marks":1688,"data":1689},"it should be the primary defense layer, not training",[],{},{"nodeType":457,"value":643,"marks":1691,"data":1692},[],{},"Does browser security replace security awareness training?","Frequently asked questions",{},"The top 10 browser security solutions and tools in 2026","thought-leadership","2026-07-27T00:00:00.000Z",{"items":1700},[1701,2650,3910],{"__typename":1702,"sys":1703,"content":1705,"title":2629,"synopsis":2630,"hashTags":59,"publishedDate":2631,"slug":2632,"tagsCollection":2633,"authorsCollection":2643},"BlogPosts",{"id":1704},"6dJUsirH3rrhy1Stnzkfqk",{"json":1706},{"data":1707,"content":1708,"nodeType":934},{},[1709,1722,1738,1789,1796,1809,1829,1836,1842,1845,1852,1859,1888,1895,1902,1970,1977,1983,1990,1997,2000,2007,2014,2047,2067,2079,2085,2092,2098,2110,2117,2137,2143,2155,2167,2174,2180,2192,2208,2220,2232,2238,2245,2248,2255,2262,2278,2286,2293,2301,2308,2352,2355,2362,2369,2375,2383,2390,2406,2421,2428,2444,2451,2499,2506,2522,2529,2578,2585,2593,2596,2603,2610],{"data":1710,"content":1711,"nodeType":458},{},[1712,1716],{"data":1713,"marks":1714,"value":1715,"nodeType":457},{},[],"Hey all you security engineers, let’s play ",{"data":1717,"marks":1718,"value":1721,"nodeType":457},{},[1719,1720],{"type":1309},{"type":512},"Would You Rather … ?",{"data":1723,"content":1724,"nodeType":458},{},[1725,1729,1734],{"data":1726,"marks":1727,"value":1728,"nodeType":457},{},[],"Would you rather spend time trying to write detections for ",{"data":1730,"marks":1731,"value":1733,"nodeType":457},{},[1732],{"type":512},"modern browser-based attacks",{"data":1735,"marks":1736,"value":1737,"nodeType":457},{},[]," by …",{"data":1739,"content":1740,"nodeType":1440},{},[1741,1756,1774],{"data":1742,"content":1743,"nodeType":1444},{},[1744],{"data":1745,"content":1746,"nodeType":458},{},[1747,1751],{"data":1748,"marks":1749,"value":1750,"nodeType":457},{},[],"Combing through MITRE looking for techniques that you can write detections on, only to find you have",{"data":1752,"marks":1753,"value":1755,"nodeType":457},{},[1754],{"type":512}," little useful telemetry from your typical sources.",{"data":1757,"content":1758,"nodeType":1444},{},[1759],{"data":1760,"content":1761,"nodeType":458},{},[1762,1766,1771],{"data":1763,"marks":1764,"value":1765,"nodeType":457},{},[],"Curating a list of malicious domain IOCs extracted from endless TI pieces, only to ",{"data":1767,"marks":1768,"value":1770,"nodeType":457},{},[1769],{"type":512},"never see a single one of them match",{"data":1772,"marks":1773,"value":643,"nodeType":457},{},[],{"data":1775,"content":1776,"nodeType":1444},{},[1777],{"data":1778,"content":1779,"nodeType":458},{},[1780,1785],{"data":1781,"marks":1782,"value":1784,"nodeType":457},{},[1783],{"type":512},"Just giving up and blocking a bunch of domains or IPs",{"data":1786,"marks":1787,"value":1788,"nodeType":457},{},[]," from every TI feed you come across, while quietly weeping.",{"data":1790,"content":1791,"nodeType":458},{},[1792],{"data":1793,"marks":1794,"value":1795,"nodeType":457},{},[],"Or … ",{"data":1797,"content":1798,"nodeType":1440},{},[1799],{"data":1800,"content":1801,"nodeType":1444},{},[1802],{"data":1803,"content":1804,"nodeType":458},{},[1805],{"data":1806,"marks":1807,"value":1808,"nodeType":457},{},[],"Inherit constantly evolving detections validated across 3 million-plus browsers, tuned to remove false positives, informed by human threat researchers, and tailored to the known and not-yet-known threats that target account compromise and malware delivery via the browser.",{"data":1810,"content":1811,"nodeType":458},{},[1812,1816,1825],{"data":1813,"marks":1814,"value":1815,"nodeType":457},{},[],"At Push, we’ve built an ",{"data":1817,"content":1819,"nodeType":481},{"uri":1818},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fcan-ai-replace-a-threat-researcher-what-we-learned-building-an-agentic-threat-hunting-pipeline",[1820],{"data":1821,"marks":1822,"value":1824,"nodeType":457},{},[1823],{"type":594},"agentic threat hunting and detection engineering pipeline",{"data":1826,"marks":1827,"value":1828,"nodeType":457},{},[]," to take that first set of onerous tasks off your plate. The result is a process that looks a lot like the ideal described in detection engineering maturity models, achieved without any extra headcount or subject matter expertise on your team, and scaled to meet the speed and complexity of our current era of AI-enabled adversaries.",{"data":1830,"content":1831,"nodeType":458},{},[1832],{"data":1833,"marks":1834,"value":1835,"nodeType":457},{},[],"Let’s take a look at how the pipeline delivers a collective good by identifying emerging threats or new technique variants in a single customer environment and then delivering detections to everyone.",{"data":1837,"content":1841,"nodeType":522},{"target":1838},{"sys":1839},{"id":1840,"type":519,"linkType":520},"sN6q7oEwYyJTkXxyLb81m",[],{"data":1843,"content":1844,"nodeType":526},{},[],{"data":1846,"content":1847,"nodeType":535},{},[1848],{"data":1849,"marks":1850,"value":1851,"nodeType":457},{},[],"Why detection engineering from TI is hard — and why AI-enabled attacks are making it even harder",{"data":1853,"content":1854,"nodeType":458},{},[1855],{"data":1856,"marks":1857,"value":1858,"nodeType":457},{},[],"Detection engineers feel the pain that Beethoven must have felt when he got the critique: “There are just too many notes!”",{"data":1860,"content":1861,"nodeType":458},{},[1862,1866,1871,1875,1884],{"data":1863,"marks":1864,"value":1865,"nodeType":457},{},[],"Except where notes = threat intelligence, light on the ",{"data":1867,"marks":1868,"value":1870,"nodeType":457},{},[1869],{"type":1309},"intelligence",{"data":1872,"marks":1873,"value":1874,"nodeType":457},{},[],". (For a great unpacking of what’s hard about transforming TI into detections, check out this ",{"data":1876,"content":1878,"nodeType":481},{"uri":1877},"https:\u002F\u002Fmedium.com\u002Fanton-on-security\u002Fdetection-engineering-is-painful-and-it-shouldnt-be-part-1-3641d8740458",[1879],{"data":1880,"marks":1881,"value":1883,"nodeType":457},{},[1882],{"type":594},"blog series",{"data":1885,"marks":1886,"value":1887,"nodeType":457},{},[]," from Anton Chuvakin and his Google security colleagues from 2023. The challenge has only gotten harder since then!)",{"data":1889,"content":1890,"nodeType":458},{},[1891],{"data":1892,"marks":1893,"value":1894,"nodeType":457},{},[],"In short, there is too much potential TI, too little actionable detail, and a dearth of useful business-relevant context.",{"data":1896,"content":1897,"nodeType":458},{},[1898],{"data":1899,"marks":1900,"value":1901,"nodeType":457},{},[],"This often manifests as:",{"data":1903,"content":1904,"nodeType":1440},{},[1905,1933,1952],{"data":1906,"content":1907,"nodeType":1444},{},[1908],{"data":1909,"content":1910,"nodeType":458},{},[1911,1916,1920,1929],{"data":1912,"marks":1913,"value":1915,"nodeType":457},{},[1914],{"type":512},"Feeling constantly behind the threat landscape. ",{"data":1917,"marks":1918,"value":1919,"nodeType":457},{},[],"SANS Institute’s ",{"data":1921,"content":1923,"nodeType":481},{"uri":1922},"https:\u002F\u002Fwww.sans.org\u002Fwhite-papers\u002Fstate-detection-engineering-2026",[1924],{"data":1925,"marks":1926,"value":1928,"nodeType":457},{},[1927],{"type":594},"State of Detection Engineering 2026",{"data":1930,"marks":1931,"value":1932,"nodeType":457},{},[]," report found that only 18% of practitioners feel like they’re staying ahead; 56% report barely keeping pace.",{"data":1934,"content":1935,"nodeType":1444},{},[1936],{"data":1937,"content":1938,"nodeType":458},{},[1939,1943,1948],{"data":1940,"marks":1941,"value":1942,"nodeType":457},{},[],"Access to a huge amount of potential TI, but ",{"data":1944,"marks":1945,"value":1947,"nodeType":457},{},[1946],{"type":512},"lacking the time, context, and tools needed to parse the data",{"data":1949,"marks":1950,"value":1951,"nodeType":457},{},[]," for threats that matter to the business.",{"data":1953,"content":1954,"nodeType":1444},{},[1955],{"data":1956,"content":1957,"nodeType":458},{},[1958,1962,1967],{"data":1959,"marks":1960,"value":1961,"nodeType":457},{},[],"More information on IOCs than TTPs, leading to ",{"data":1963,"marks":1964,"value":1966,"nodeType":457},{},[1965],{"type":512},"ever-growing blocklists and attacks that still slip through",{"data":1968,"marks":1969,"value":643,"nodeType":457},{},[],{"data":1971,"content":1972,"nodeType":458},{},[1973],{"data":1974,"marks":1975,"value":1976,"nodeType":457},{},[],"As AI-enabled adversaries continue to make it increasingly trivial to rotate infrastructure or abuse trusted services and workflows to deliver modern attacks, the hill gets steeper. ",{"data":1978,"content":1982,"nodeType":522},{"target":1979},{"sys":1980},{"id":1981,"type":519,"linkType":520},"4xlCsISP3OT9MAj3wxw67D",[],{"data":1984,"content":1985,"nodeType":458},{},[1986],{"data":1987,"marks":1988,"value":1989,"nodeType":457},{},[],"In the case of attacks that target employees via the browser — using advanced phishing methods, commercial toolkits, abuse of OAuth, abuse of trusted services to deliver phishing lures, etc. — most security teams are also working without the right foundational visibility to even begin to mature their detection process against these TTPs.",{"data":1991,"content":1992,"nodeType":458},{},[1993],{"data":1994,"marks":1995,"value":1996,"nodeType":457},{},[],"The missing input is visibility at the layer where these attacks actually execute — the browser session. Without it, detection engineering for browser-based threats is painful guesswork.",{"data":1998,"content":1999,"nodeType":526},{},[],{"data":2001,"content":2002,"nodeType":535},{},[2003],{"data":2004,"marks":2005,"value":2006,"nodeType":457},{},[],"How Push operationalized best practices for hunting from TI using agents",{"data":2008,"content":2009,"nodeType":458},{},[2010],{"data":2011,"marks":2012,"value":2013,"nodeType":457},{},[],"In building our agentic threat hunting and detection engineering pipeline at Push, we set out to solve many of the same problems that any security team faces when maturing its processes:",{"data":2015,"content":2016,"nodeType":1440},{},[2017,2027,2037],{"data":2018,"content":2019,"nodeType":1444},{},[2020],{"data":2021,"content":2022,"nodeType":458},{},[2023],{"data":2024,"marks":2025,"value":2026,"nodeType":457},{},[],"How to transform TI into technique-level intel we could write durable detections for across a wide customer base at scale?",{"data":2028,"content":2029,"nodeType":1444},{},[2030],{"data":2031,"content":2032,"nodeType":458},{},[2033],{"data":2034,"marks":2035,"value":2036,"nodeType":457},{},[],"How to create structured internal knowledge to add context to our detection engineering process that validates the relevance of what we find?",{"data":2038,"content":2039,"nodeType":1444},{},[2040],{"data":2041,"content":2042,"nodeType":458},{},[2043],{"data":2044,"marks":2045,"value":2046,"nodeType":457},{},[],"How to verify what’s worthwhile to hunt for, remove false positives, and understand the value of a detection for a specific TTP across an install base of more than 3 million browsers?",{"data":2048,"content":2049,"nodeType":458},{},[2050,2054,2063],{"data":2051,"marks":2052,"value":2053,"nodeType":457},{},[],"The process we created looks a lot like the ",{"data":2055,"content":2057,"nodeType":481},{"uri":2056},"https:\u002F\u002Fmedium.com\u002Fanton-on-security\u002Fblueprint-for-threat-intel-to-detection-flow-part-7-088024be08dd",[2058],{"data":2059,"marks":2060,"value":2062,"nodeType":457},{},[2061],{"type":594},"best practices",{"data":2064,"marks":2065,"value":2066,"nodeType":457},{},[]," on how to turn intelligence into meaningful detections. The difference is that agents let us run this process continuously and at a scale that would be impossible to achieve with human analysts alone.",{"data":2068,"content":2069,"nodeType":458},{},[2070,2075],{"data":2071,"marks":2072,"value":2074,"nodeType":457},{},[2073],{"type":512},"It starts with ingestion. ",{"data":2076,"marks":2077,"value":2078,"nodeType":457},{},[],"An agent tasked with TI aggregation monitors multiple industry sources — vendor reports, researcher disclosures, campaign teardowns — and filters for intelligence relevant to browser-based attack techniques. ",{"data":2080,"content":2084,"nodeType":522},{"target":2081},{"sys":2082},{"id":2083,"type":519,"linkType":520},"7fsLEGUbOINll70ViNVVkI",[],{"data":2086,"content":2087,"nodeType":458},{},[2088],{"data":2089,"marks":2090,"value":2091,"nodeType":457},{},[],"Because this agent already understands the types of attacks and scenarios that matter to Push’s detection surface, it can distinguish signal from noise at the intake stage, flagging useful intel and proposing initial lightweight hunts based on the browser metadata Push can observe. When a potential hunt looks promising, the aggregation agent hands off to a deeper analysis agent to extract what’s actually huntable.",{"data":2093,"content":2097,"nodeType":522},{"target":2094},{"sys":2095},{"id":2096,"type":519,"linkType":520},"5vyeALIziHamJ0cLiGMdGk",[],{"data":2099,"content":2100,"nodeType":458},{},[2101,2106],{"data":2102,"marks":2103,"value":2105,"nodeType":457},{},[2104],{"type":512},"That extraction step is where a general TI feed becomes something you can build detections from. ",{"data":2107,"marks":2108,"value":2109,"nodeType":457},{},[],"Agents built on frontier models have a deep understanding of web programming languages and browser workflows can decompose the intelligence into its meaningful atomic units — the specific behavioral patterns that distinguish a malicious technique from normal browser activity. ",{"data":2111,"content":2112,"nodeType":458},{},[2113],{"data":2114,"marks":2115,"value":2116,"nodeType":457},{},[],"They compare those patterns against everything the Push browser agent can observe: tabs, windows, navigation events, downloads, network requests, DOM content, script execution. Then they discard anything too broad — observable events that are commonplace, even when connected to a malicious TTP — to avoid false positives. ",{"data":2118,"content":2119,"nodeType":458},{},[2120,2124,2133],{"data":2121,"marks":2122,"value":2123,"nodeType":457},{},[],"What survives is one or more huntable technique signatures that can be identified with a high true positive rate. This is the ",{"data":2125,"content":2127,"nodeType":481},{"uri":2126},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fthe-pyramid-of-pain-in-the-ai-era",[2128],{"data":2129,"marks":2130,"value":2132,"nodeType":457},{},[2131],{"type":594},"Pyramid of Pain principle",{"data":2134,"marks":2135,"value":2136,"nodeType":457},{},[]," operationalized at machine speed: Target the technique, not the indicator, because techniques are genuinely hard for attackers to change.",{"data":2138,"content":2142,"nodeType":522},{"target":2139},{"sys":2140},{"id":2141,"type":519,"linkType":520},"5j0mvdIMkaUwDgCu0nOqSm",[],{"data":2144,"content":2145,"nodeType":458},{},[2146,2151],{"data":2147,"marks":2148,"value":2150,"nodeType":457},{},[2149],{"type":512},"In parallel, the pipeline validates whether the identified technique is genuinely novel or a variant of something Push already detects. ",{"data":2152,"marks":2153,"value":2154,"nodeType":457},{},[],"This is where our internal knowledge base comes into play. Built over three years by Push’s in-house research team and augmented continuously by the pipeline itself, it represents what Push knows about browser-based attack behaviors — a structured corpus of TTPs that lets agents classify incoming intelligence as new territory, a known variant that needs a refined detection, or something already covered. That classification determines what happens next: A net-new technique triggers a full hunt; a known variant triggers a refinement cycle; and a duplicate gets deprioritized.",{"data":2156,"content":2157,"nodeType":458},{},[2158,2163],{"data":2159,"marks":2160,"value":2162,"nodeType":457},{},[2161],{"type":512},"The hunt itself is where hypothesis meets evidence.",{"data":2164,"marks":2165,"value":2166,"nodeType":457},{},[]," Agents develop a specific, testable prediction about what the technique looks like in browser telemetry, then validate that prediction across Push’s install base. The aim of the initial hunt is to identify any potential false positives — legitimate browser behavior that matches the pattern. Then the agents refine: adjusting the query, narrowing the behavioral fingerprints, testing again. Each iteration sharpens the detection until the false positive rate drops to a negligible, tolerable level. ",{"data":2168,"content":2169,"nodeType":458},{},[2170],{"data":2171,"marks":2172,"value":2173,"nodeType":457},{},[],"The hunts that produce relevant, high-confidence results become continuous queries — a kind of early warning system for emerging threats we’re actively watching for and learning about. The most useful and reliable of those queries become production detections that protect every Push customer in real time. ",{"data":2175,"content":2179,"nodeType":522},{"target":2176},{"sys":2177},{"id":2178,"type":519,"linkType":520},"h3MN5kaaGGuL4uvNsP9JZ",[],{"data":2181,"content":2182,"nodeType":458},{},[2183,2188],{"data":2184,"marks":2185,"value":2187,"nodeType":457},{},[2186],{"type":512},"This is what “detect what matters” looks like as an engineering discipline. ",{"data":2189,"marks":2190,"value":2191,"nodeType":457},{},[],"By the time the agents have whittled down millions or trillions of browser events into a good hunt query — where good means broad enough to cast a usefully wide net for variations — and then tuned that further into a high-fidelity detection, the result is fewer, sharper detections by design. And because Push detects at the browser session layer before a user can interact with a malicious page, almost all of those detections fire pre-compromise. ",{"data":2193,"content":2194,"nodeType":458},{},[2195,2199,2204],{"data":2196,"marks":2197,"value":2198,"nodeType":457},{},[],"The same 2026 SANS survey mentioned earlier found that ",{"data":2200,"marks":2201,"value":2203,"nodeType":457},{},[2202],{"type":512},"66% of SOC practitioners cite vendor-provided rules as their primary source of false positives",{"data":2205,"marks":2206,"value":2207,"nodeType":457},{},[]," — a structural problem that persists at every organization size. Push’s pipeline produces the opposite outcome: better detections, less noise.",{"data":2209,"content":2210,"nodeType":458},{},[2211,2216],{"data":2212,"marks":2213,"value":2215,"nodeType":457},{},[2214],{"type":512},"The result is a system with two learning loops.",{"data":2217,"marks":2218,"value":2219,"nodeType":457},{},[]," An inner loop handles real-time detection and response for known attacker techniques — the production detections already deployed across the customer base. An outer loop handles continuous discovery — agents hunting for new techniques, refining existing detections, and ingesting external intelligence. ",{"data":2221,"content":2222,"nodeType":458},{},[2223,2228],{"data":2224,"marks":2225,"value":2227,"nodeType":457},{},[2226],{"type":512},"Each loop feeds the other:",{"data":2229,"marks":2230,"value":2231,"nodeType":457},{},[]," The outer loop’s discoveries become the inner loop’s new production detections, and the inner loop’s blocked attacks become raw material for the outer loop to analyze for novel variants. The knowledge base that both loops draw on grows with every cycle, which means the pipeline's detection coverage compounds at roughly the rate the threat landscape grows more complex.",{"data":2233,"content":2237,"nodeType":522},{"target":2234},{"sys":2235},{"id":2236,"type":519,"linkType":520},"3xVLn9Ldk4cOP4uFYIYyM",[],{"data":2239,"content":2240,"nodeType":458},{},[2241],{"data":2242,"marks":2243,"value":2244,"nodeType":457},{},[],"And every validated detection produced by this process, whether it originated from a blocked attack in one customer’s environment, a proactive hunt across the telemetry corpus, or a vendor report about a campaign Push has never observed on customer estates, deploys to the entire customer base.",{"data":2246,"content":2247,"nodeType":526},{},[],{"data":2249,"content":2250,"nodeType":535},{},[2251],{"data":2252,"marks":2253,"value":2254,"nodeType":457},{},[],"Herd immunity, without all the breaches to get there",{"data":2256,"content":2257,"nodeType":458},{},[2258],{"data":2259,"marks":2260,"value":2261,"nodeType":457},{},[],"That last point is where Push’s idea of herd immunity diverges from the traditional definition.",{"data":2263,"content":2264,"nodeType":458},{},[2265,2269,2274],{"data":2266,"marks":2267,"value":2268,"nodeType":457},{},[],"Detection and response platforms and MDR services commonly describe a ",{"data":2270,"marks":2271,"value":2273,"nodeType":457},{},[2272],{"type":512},"herd immunity benefit",{"data":2275,"marks":2276,"value":2277,"nodeType":457},{},[],": What one customer encounters, every customer gets protection against. The mechanism is real, but the learning input is typically a breach or a compromise. Someone has to be the first victim.",{"data":2279,"content":2280,"nodeType":458},{},[2281],{"data":2282,"marks":2283,"value":2285,"nodeType":457},{},[2284],{"type":512},"Push’s approach is different. ",{"data":2287,"content":2288,"nodeType":458},{},[2289],{"data":2290,"marks":2291,"value":2292,"nodeType":457},{},[],"Modern browser-based attacks frequently rely on a series of techniques strung together to achieve a compromise. From its vantage point in the browser, Push catches many novel techniques with existing detections pre-compromise because it recognizes a portion of the attack techniques in the chain. The detection process then identifies what’s new about a previously unseen variation of a known TTP — perhaps an evasion technique the kit hadn’t used before, an unusual lure or infrastructure pattern, etc. ",{"data":2294,"content":2295,"nodeType":458},{},[2296],{"data":2297,"marks":2298,"value":2300,"nodeType":457},{},[2299],{"type":512},"The detection gets better for customers and no one was compromised to get there.",{"data":2302,"content":2303,"nodeType":458},{},[2304],{"data":2305,"marks":2306,"value":2307,"nodeType":457},{},[],"On the external intelligence side, the pipeline ingests published research about a campaign Push has never observed, extracts the durable behavioral characteristics, validates them against browser telemetry, refines the query to tune out false positives, and ships detections before the technique is ever used against a Push customer. The protection arrives ahead of the attack.",{"data":2309,"content":2310,"nodeType":458},{},[2311,2315,2324,2327,2336,2339,2348],{"data":2312,"marks":2313,"value":2314,"nodeType":457},{},[],"These are the processes behind Push’s identification of ",{"data":2316,"content":2318,"nodeType":481},{"uri":2317},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fconsentfix",[2319],{"data":2320,"marks":2321,"value":2323,"nodeType":457},{},[2322],{"type":594},"ConsentFix",{"data":2325,"marks":2326,"value":1213,"nodeType":457},{},[],{"data":2328,"content":2330,"nodeType":481},{"uri":2329},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Finstallfix",[2331],{"data":2332,"marks":2333,"value":2335,"nodeType":457},{},[2334],{"type":594},"InstallFix",{"data":2337,"marks":2338,"value":1238,"nodeType":457},{},[],{"data":2340,"content":2342,"nodeType":481},{"uri":2341},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fllmshare-malvertising-campaign",[2343],{"data":2344,"marks":2345,"value":2347,"nodeType":457},{},[2346],{"type":594},"LLMShare",{"data":2349,"marks":2350,"value":2351,"nodeType":457},{},[]," — three browser-based attack techniques Push's team discovered or documented for the first time. In several cases, detections were blocking active campaigns against Push customers before the technique had been publicly documented. Those detections rolled out to every customer within hours or days of first observation.",{"data":2353,"content":2354,"nodeType":526},{},[],{"data":2356,"content":2357,"nodeType":535},{},[2358],{"data":2359,"marks":2360,"value":2361,"nodeType":457},{},[],"Outcomes: By the numbers",{"data":2363,"content":2364,"nodeType":458},{},[2365],{"data":2366,"marks":2367,"value":2368,"nodeType":457},{},[],"Looking at the quantifiable outcomes of this agentic threat hunting capability over the last few months, the benefits for customers become clear.",{"data":2370,"content":2374,"nodeType":522},{"target":2371},{"sys":2372},{"id":2373,"type":519,"linkType":520},"7uNrNGUjjBiG9qEsfen7Xi",[],{"data":2376,"content":2377,"nodeType":2382},{},[2378],{"data":2379,"marks":2380,"value":2381,"nodeType":457},{},[],"Velocity","heading-2",{"data":2384,"content":2385,"nodeType":458},{},[2386],{"data":2387,"marks":2388,"value":2389,"nodeType":457},{},[],"Agents allow us to massively scale our research expertise, delivering detections for emerging threats or new variants much faster than humans alone can.",{"data":2391,"content":2392,"nodeType":458},{},[2393,2397,2402],{"data":2394,"marks":2395,"value":2396,"nodeType":457},{},[],"This year already, we’ve ",{"data":2398,"marks":2399,"value":2401,"nodeType":457},{},[2400],{"type":512},"tripled",{"data":2403,"marks":2404,"value":2405,"nodeType":457},{},[]," the number of new detections shipped to customers.",{"data":2407,"content":2408,"nodeType":458},{},[2409,2413,2418],{"data":2410,"marks":2411,"value":2412,"nodeType":457},{},[],"We’ve also reduced the time it takes to ship production-ready detections for new threats from weeks to ",{"data":2414,"marks":2415,"value":2417,"nodeType":457},{},[2416],{"type":512},"minutes",{"data":2419,"marks":2420,"value":643,"nodeType":457},{},[],{"data":2422,"content":2423,"nodeType":2382},{},[2424],{"data":2425,"marks":2426,"value":2427,"nodeType":457},{},[],"Detection coverage",{"data":2429,"content":2430,"nodeType":458},{},[2431,2435,2440],{"data":2432,"marks":2433,"value":2434,"nodeType":457},{},[],"With that scaled expertise comes broad coverage. We perform an average of ",{"data":2436,"marks":2437,"value":2439,"nodeType":457},{},[2438],{"type":512},"300+ hunts",{"data":2441,"marks":2442,"value":2443,"nodeType":457},{},[]," a month (a mix of live queries for identified TTPs we’re looking for, plus net-new hunts for emerging threats we identify in any given month).",{"data":2445,"content":2446,"nodeType":458},{},[2447],{"data":2448,"marks":2449,"value":2450,"nodeType":457},{},[],"A few other metrics that demonstrate the scale of our detection coverage:",{"data":2452,"content":2453,"nodeType":1440},{},[2454,2469,2484],{"data":2455,"content":2456,"nodeType":1444},{},[2457],{"data":2458,"content":2459,"nodeType":458},{},[2460,2465],{"data":2461,"marks":2462,"value":2464,"nodeType":457},{},[2463],{"type":512},"75+",{"data":2466,"marks":2467,"value":2468,"nodeType":457},{},[]," attacker tools documented in our KB so far",{"data":2470,"content":2471,"nodeType":1444},{},[2472],{"data":2473,"content":2474,"nodeType":458},{},[2475,2480],{"data":2476,"marks":2477,"value":2479,"nodeType":457},{},[2478],{"type":512},"25+",{"data":2481,"marks":2482,"value":2483,"nodeType":457},{},[]," variants of existing attacks we’ve identified and shipped detections for",{"data":2485,"content":2486,"nodeType":1444},{},[2487],{"data":2488,"content":2489,"nodeType":458},{},[2490,2495],{"data":2491,"marks":2492,"value":2494,"nodeType":457},{},[2493],{"type":512},"10,000+",{"data":2496,"marks":2497,"value":2498,"nodeType":457},{},[]," monthly sessions analyzed",{"data":2500,"content":2501,"nodeType":2382},{},[2502],{"data":2503,"marks":2504,"value":2505,"nodeType":457},{},[],"Protection from emerging threats",{"data":2507,"content":2508,"nodeType":458},{},[2509,2513,2518],{"data":2510,"marks":2511,"value":2512,"nodeType":457},{},[],"On the emerging threat side, our team was the first to identify or document ",{"data":2514,"marks":2515,"value":2517,"nodeType":457},{},[2516],{"type":512},"three new browser-based attack techniques",{"data":2519,"marks":2520,"value":2521,"nodeType":457},{},[]," — ConsentFix, InstallFix, and LLMShare — shipping detections to all customers quickly after identification.",{"data":2523,"content":2524,"nodeType":458},{},[2525],{"data":2526,"marks":2527,"value":2528,"nodeType":457},{},[],"In that same time frame, we’ve also:",{"data":2530,"content":2531,"nodeType":1440},{},[2532,2559],{"data":2533,"content":2534,"nodeType":1444},{},[2535],{"data":2536,"content":2537,"nodeType":458},{},[2538,2542,2547,2550,2555],{"data":2539,"marks":2540,"value":2541,"nodeType":457},{},[],"Protected ",{"data":2543,"marks":2544,"value":2546,"nodeType":457},{},[2545],{"type":512},"60+",{"data":2548,"marks":2549,"value":1179,"nodeType":457},{},[],{"data":2551,"marks":2552,"value":2554,"nodeType":457},{},[2553],{"type":512},"customers in the last 3 months",{"data":2556,"marks":2557,"value":2558,"nodeType":457},{},[]," who’ve been targeted with novel phishing techniques — identifying never-before-seen techniques, lures, delivery mechanisms, interactions, tools, or attack chains",{"data":2560,"content":2561,"nodeType":1444},{},[2562],{"data":2563,"content":2564,"nodeType":458},{},[2565,2569,2574],{"data":2566,"marks":2567,"value":2568,"nodeType":457},{},[],"Prevented ",{"data":2570,"marks":2571,"value":2573,"nodeType":457},{},[2572],{"type":512},"225+",{"data":2575,"marks":2576,"value":2577,"nodeType":457},{},[]," instances of threats pre-compromise for novel techniques",{"data":2579,"content":2580,"nodeType":458},{},[2581],{"data":2582,"marks":2583,"value":2584,"nodeType":457},{},[],"In all of the above situations, Push customers didn’t have to do anything — no combing through TI to find relevant details, no writing their own detections and tuning out false positives, or spending cycles to unpack a particularly knotty attack chain that used techniques they had never seen before. ",{"data":2586,"content":2587,"nodeType":458},{},[2588],{"data":2589,"marks":2590,"value":2592,"nodeType":457},{},[2591],{"type":512},"That’s what operationalized intelligence looks like at scale, delivered as a product, not a project.",{"data":2594,"content":2595,"nodeType":526},{},[],{"data":2597,"content":2598,"nodeType":535},{},[2599],{"data":2600,"marks":2601,"value":2602,"nodeType":457},{},[],"Learn more about Push",{"data":2604,"content":2605,"nodeType":458},{},[2606],{"data":2607,"marks":2608,"value":2609,"nodeType":457},{},[],"The same foundational capabilities that enable this agentic threat hunting pipeline also deliver other security outcomes for Push customers: gaining visibility and control over AI tool usage; hardening identities by surfacing credential reuse, SSO gaps, and shadow IT; and supporting data loss and insider investigations with browser-layer telemetry that other tools can’t see.",{"data":2611,"content":2612,"nodeType":458},{},[2613,2617,2625],{"data":2614,"marks":2615,"value":2616,"nodeType":457},{},[],"If you’d like to learn more, ",{"data":2618,"content":2619,"nodeType":481},{"uri":924},[2620],{"data":2621,"marks":2622,"value":2624,"nodeType":457},{},[2623],{"type":594},"book a demo",{"data":2626,"marks":2627,"value":2628,"nodeType":457},{},[]," with our team.","How Push’s agentic threat hunting in the browser benefits every customer","Security outcomes you can achieve when AI agents hunt in the browser, identify new threats, and ship detections that benefit everyone.","2026-07-23T00:00:00.000Z","agentic-threat-hunting-benefits-for-customers",{"items":2634},[2635,2639],{"sys":2636,"name":2638},{"id":2637},"4ksQNCFeBf8H4QIORqpRLw","Detection & response",{"sys":2640,"name":2642},{"id":2641},"6A5RXS31ZQx3PwryGb1IMy","Browser-based attacks",{"items":2644},[2645],{"fullName":2646,"firstName":2647,"jobTitle":441,"profilePicture":2648},"Kelly Davenport","Kelly",{"url":2649},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F1hi8bEuVfn5sF57LivAq6d\u002F9a3b82426c697d765e2e450e33a18424\u002Fkelly_profile_pic.jpeg",{"__typename":1702,"sys":2651,"content":2653,"title":3892,"synopsis":3893,"hashTags":59,"publishedDate":3894,"slug":3895,"tagsCollection":3896,"authorsCollection":3906},{"id":2652},"6MoHWfQlVildcFYKSbfMcE",{"json":2654},{"data":2655,"content":2656,"nodeType":934},{},[2657,2673,2679,2686,2693,2699,2702,2710,2718,2737,2783,2789,2804,2807,2815,2822,2850,2891,2898,2901,2909,2917,2924,2930,2937,2940,2948,2955,2997,3034,3041,3044,3052,3059,3084,3091,3137,3144,3147,3155,3163,3209,3216,3222,3225,3233,3241,3274,3281,3287,3294,3297,3305,3313,3342,3349,3356,3363,3366,3374,3382,3389,3395,3402,3425,3454,3457,3465,3473,3480,3487,3490,3498,3560,3563,3571,3578,3872,3875],{"data":2658,"content":2659,"nodeType":458},{},[2660,2664,2669],{"data":2661,"marks":2662,"value":2663,"nodeType":457},{},[],"Browser security solutions are one of the most significant additions to the enterprise security stack in recent years — and the data shows it. The browser is where ",{"data":2665,"marks":2666,"value":2668,"nodeType":457},{},[2667],{"type":512},"85% of work now happens",{"data":2670,"marks":2671,"value":2672,"nodeType":457},{},[],", where AI tools are accessed, and where attackers increasingly choose to strike.",{"data":2674,"content":2678,"nodeType":522},{"target":2675},{"sys":2676},{"id":2677,"type":519,"linkType":520},"5P6PyFbn4EakRNlIWtNzyL",[],{"data":2680,"content":2681,"nodeType":458},{},[2682],{"data":2683,"marks":2684,"value":2685,"nodeType":457},{},[],"But browser security is a nascent category. Getting a clear picture of which solution is right for your team, and how to get the most out of it, isn't straightforward. Current solutions on the market serve a wide range of IT and security use cases, with varying degrees of depth and differentiation across them. Not all use cases are equal in terms of their security value, and not all of them are best addressed in the browser.",{"data":2687,"content":2688,"nodeType":458},{},[2689],{"data":2690,"marks":2691,"value":2692,"nodeType":457},{},[],"This article ranks the security problems that browser security solutions can address by the value they deliver: a combination of the risk reduction on offer, and the degree to which the browser is genuinely the best (or only) layer to solve the problem. ",{"data":2694,"content":2698,"nodeType":522},{"target":2695},{"sys":2696},{"id":2697,"type":519,"linkType":520},"6SJPvEHizSYk29lEvVVNj",[],{"data":2700,"content":2701,"nodeType":526},{},[],{"data":2703,"content":2704,"nodeType":535},{},[2705],{"data":2706,"marks":2707,"value":2709,"nodeType":457},{},[2708],{"type":512},"#1 — Account takeover prevention: detecting credential attacks across all vectors",{"data":2711,"content":2712,"nodeType":458},{},[2713],{"data":2714,"marks":2715,"value":2717,"nodeType":457},{},[2716],{"type":512},"Security value: Very high | Browser fit: Uniquely suited",{"data":2719,"content":2720,"nodeType":458},{},[2721,2725,2733],{"data":2722,"marks":2723,"value":2724,"nodeType":457},{},[],"Account takeover (ATO) is the dominant entry point for enterprise breaches: ",{"data":2726,"content":2728,"nodeType":481},{"uri":2727},"https:\u002F\u002Fwww.crowdstrike.com\u002Fen-gb\u002Fresources\u002Finfographics\u002Fidentity-security-risk-review\u002F",[2729],{"data":2730,"marks":2731,"value":2732,"nodeType":457},{},[],"80% of all modern breaches involve compromised or stolen identities",{"data":2734,"marks":2735,"value":2736,"nodeType":457},{},[],". The attack surface is far wider than most identity tooling can see: credential stuffing, password spraying, ghost logins (password-based fallback authentication that persists after SSO is configured), weak or reused credentials on shadow SaaS apps, and accounts where MFA was never enforced.",{"data":2738,"content":2739,"nodeType":458},{},[2740,2743,2751,2754,2759,2762,2767,2771,2779],{"data":2741,"marks":2742,"value":1008,"nodeType":457},{},[],{"data":2744,"content":2746,"nodeType":481},{"uri":2745},"https:\u002F\u002Fcf-assets.www.cloudflare.com\u002Fslt3lc6tev37\u002FsWDBUMNVtEJB9ZFLt1dUU\u002F8d69e92de2edfb3bf59e7d21d57e7e1a\u002FCloudflare-2026-threat-report.pdf",[2747],{"data":2748,"marks":2749,"value":2750,"nodeType":457},{},[],"Cloudflare's 2026 Threat Report",{"data":2752,"marks":2753,"value":1213,"nodeType":457},{},[],{"data":2755,"marks":2756,"value":2758,"nodeType":457},{},[2757],{"type":512},"63% of all human logins involve credentials already compromised elsewhere",{"data":2760,"marks":2761,"value":1238,"nodeType":457},{},[],{"data":2763,"marks":2764,"value":2766,"nodeType":457},{},[2765],{"type":512},"94% of all login attempts originate from bots",{"data":2768,"marks":2769,"value":2770,"nodeType":457},{},[],". The ",{"data":2772,"content":2774,"nodeType":481},{"uri":2773},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fsnowflake-retro\u002F",[2775],{"data":2776,"marks":2777,"value":2778,"nodeType":457},{},[],"Snowflake breach",{"data":2780,"marks":2781,"value":2782,"nodeType":457},{},[]," — 165+ organizations compromised, 1 billion+ records stolen — was powered almost entirely by ghost logins: accounts missing MFA that were susceptible to credential stuffing. It's particularly telling that 80% of the accounts impacted had prior breach exposure.",{"data":2784,"content":2788,"nodeType":522},{"target":2785},{"sys":2786},{"id":2787,"type":519,"linkType":520},"HbZ66kp5DiAZtwNGFJK7d",[],{"data":2790,"content":2791,"nodeType":458},{},[2792,2796,2801],{"data":2793,"marks":2794,"value":2795,"nodeType":457},{},[],"For organizations with contractors and BYOD users, the browser extension is also the only enterprise control deployable on devices that can't be MDM-enrolled — extending ATO detection to exactly the place where, per Verizon DBIR 2025, ",{"data":2797,"marks":2798,"value":2800,"nodeType":457},{},[2799],{"type":512},"46% of infostealer infections originate",{"data":2802,"marks":2803,"value":643,"nodeType":457},{},[],{"data":2805,"content":2806,"nodeType":526},{},[],{"data":2808,"content":2809,"nodeType":535},{},[2810],{"data":2811,"marks":2812,"value":2814,"nodeType":457},{},[2813],{"type":512},"#2 — Detecting and stopping advanced phishing: AiTM, multi-channel delivery, and zero-day lures",{"data":2816,"content":2817,"nodeType":458},{},[2818],{"data":2819,"marks":2820,"value":2717,"nodeType":457},{},[2821],{"type":512},{"data":2823,"content":2824,"nodeType":458},{},[2825,2829,2837,2841,2846],{"data":2826,"marks":2827,"value":2828,"nodeType":457},{},[],"Adversary-in-the-Middle (AiTM) phishing — where an attacker's reverse proxy intercepts credentials and session tokens in real time — has become the standard technique for bypassing MFA at scale. ",{"data":2830,"content":2832,"nodeType":481},{"uri":2831},"https:\u002F\u002Fwww.esentire.com\u002Fresources\u002Flibrary\u002F2026-threat-report",[2833],{"data":2834,"marks":2835,"value":2836,"nodeType":457},{},[],"eSentire's 2026 Threat Report",{"data":2838,"marks":2839,"value":2840,"nodeType":457},{},[]," attributes ",{"data":2842,"marks":2843,"value":2845,"nodeType":457},{},[2844],{"type":512},"63% of account compromise incidents to PhaaS kits",{"data":2847,"marks":2848,"value":2849,"nodeType":457},{},[],", with account compromise surging 389% year-over-year.",{"data":2851,"content":2852,"nodeType":458},{},[2853,2857,2865,2869,2874,2878,2887],{"data":2854,"marks":2855,"value":2856,"nodeType":457},{},[],"Traditional phishing controls are also no longer in the right place to intercept these attacks. The delivery channel has shifted decisively away from email: ",{"data":2858,"content":2860,"nodeType":481},{"uri":2859},"https:\u002F\u002Fcloud.google.com\u002Fblog\u002Ftopics\u002Fthreat-intelligence\u002Fm-trends-2026",[2861],{"data":2862,"marks":2863,"value":2864,"nodeType":457},{},[],"Mandiant M-Trends 2026",{"data":2866,"marks":2867,"value":2868,"nodeType":457},{},[]," found email phishing dropped from 14% to 6% as an infection vector, and Push data shows ",{"data":2870,"marks":2871,"value":2873,"nodeType":457},{},[2872],{"type":512},"roughly 1 in 3 phishing payloads intercepted were delivered outside email entirely",{"data":2875,"marks":2876,"value":2877,"nodeType":457},{},[]," — via search engine malvertising, social platforms, and compromised websites. Meanwhile, ",{"data":2879,"content":2881,"nodeType":481},{"uri":2880},"https:\u002F\u002Fwww.spamhaus.com\u002Fresource-center\u002Fsupporting-researchers-with-passive-dns\u002F",[2882],{"data":2883,"marks":2884,"value":2886,"nodeType":457},{},[2885],{"type":512},"89% of phishing domains are active for less than two days",{"data":2888,"marks":2889,"value":2890,"nodeType":457},{},[],", making blocklist-based detection structurally too slow — attackers can spin up, tear down, and move on before blocklists can catch up.",{"data":2892,"content":2893,"nodeType":458},{},[2894],{"data":2895,"marks":2896,"value":2897,"nodeType":457},{},[],"Modern phishing plays out entirely inside the browser session. The only detection layer that can see the phishing page structure, the credential entry, and the anomalous token context is the browser itself. Browser-native detection analyses page behavior rather than matching known-bad domains, which means it fires on zero-day kits regardless of how recently the infrastructure was stood up. Controls like credential entry guardrails add an additional layer — blocking corporate passwords from being submitted to unauthorized domains independently of content and behavior-based detections.",{"data":2899,"content":2900,"nodeType":526},{},[],{"data":2902,"content":2903,"nodeType":535},{},[2904],{"data":2905,"marks":2906,"value":2908,"nodeType":457},{},[2907],{"type":512},"#3 — Identity posture hardening: enforcing security across the apps your IdP doesn't manage",{"data":2910,"content":2911,"nodeType":458},{},[2912],{"data":2913,"marks":2914,"value":2916,"nodeType":457},{},[2915],{"type":512},"Security value: High | Browser fit: Uniquely suited",{"data":2918,"content":2919,"nodeType":458},{},[2920],{"data":2921,"marks":2922,"value":2923,"nodeType":457},{},[],"The first challenge is knowing what you're protecting. Every identity an employee creates — every app they sign up to, every password they set, every login that bypasses SSO — is an authentication event that happens inside a browser session. The browser is the only layer that observes all of these events regardless of whether the app is sanctioned, managed, or even known to IT. Solutions that rely on API-level integrations with known apps, network traffic inspection, or email sign-up notifications can only ever build a partial picture, because they can only see apps they already know about. The browser sees the login itself, which means it discovers the identity at the moment it's created or used — authentication method, password strength, MFA status, and all.",{"data":2925,"content":2929,"nodeType":522},{"target":2926},{"sys":2927},{"id":2928,"type":519,"linkType":520},"HETvBCPsKGkqLVtaasXH0",[],{"data":2931,"content":2932,"nodeType":458},{},[2933],{"data":2934,"marks":2935,"value":2936,"nodeType":457},{},[],"But discovery without enforcement is just an inventory problem. Being in the browser means that you're in a great position to act on what it finds at the moment of authentication. Browser-native guardrails that prompt MFA enrollment, guide users toward stronger credentials, and redirect to SSO login paths close the gap at scale, on every app, including those the IdP has never seen. They also produce the continuous, auditable evidence of MFA coverage and credential hygiene across the full application estate that regulators, insurers, and auditors increasingly require — evidence that no IdP-centric tool can provide for apps outside its scope.",{"data":2938,"content":2939,"nodeType":526},{},[],{"data":2941,"content":2942,"nodeType":535},{},[2943],{"data":2944,"marks":2945,"value":2947,"nodeType":457},{},[2946],{"type":512},"#4 — Browser extension security",{"data":2949,"content":2950,"nodeType":458},{},[2951],{"data":2952,"marks":2953,"value":2916,"nodeType":457},{},[2954],{"type":512},{"data":2956,"content":2957,"nodeType":458},{},[2958,2962,2971,2974,2982,2985,2993],{"data":2959,"marks":2960,"value":2961,"nodeType":457},{},[],"Browser extensions have become one of the most talked-about attack surfaces in security over the past 18 months, and understandably so — a string of high-profile supply chain compromises have collectively impacted tens of millions of users since late 2024 (",{"data":2963,"content":2965,"nodeType":481},{"uri":2964},"https:\u002F\u002Fwww.cyberhaven.com\u002Fblog\u002Fcyberhavens-chrome-extension-security-incident-and-what-were-doing-about-it",[2966],{"data":2967,"marks":2968,"value":2970,"nodeType":457},{},[2969],{"type":594},"Cyberhaven",{"data":2972,"marks":2973,"value":1213,"nodeType":457},{},[],{"data":2975,"content":2977,"nodeType":481},{"uri":2976},"https:\u002F\u002Fthehackernews.com\u002F2025\u002F12\u002Fdarkspectre-browser-extension-campaigns.html",[2978],{"data":2979,"marks":2980,"value":2981,"nodeType":457},{},[],"DarkSpectre",{"data":2983,"marks":2984,"value":1213,"nodeType":457},{},[],{"data":2986,"content":2988,"nodeType":481},{"uri":2987},"https:\u002F\u002Fthehackernews.com\u002F2025\u002F12\u002Ftrust-wallet-chrome-extension-hack.html",[2989],{"data":2990,"marks":2991,"value":2992,"nodeType":457},{},[],"Trust Wallet",{"data":2994,"marks":2995,"value":2996,"nodeType":457},{},[],", among many others).",{"data":2998,"content":2999,"nodeType":458},{},[3000,3003,3012,3016,3021,3025,3030],{"data":3001,"marks":3002,"value":21,"nodeType":457},{},[],{"data":3004,"content":3006,"nodeType":481},{"uri":3005},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fwhy-browser-extension-risk-scoring-wont-predict-your-next-breach\u002F",[3007],{"data":3008,"marks":3009,"value":3011,"nodeType":457},{},[3010],{"type":594},"Analysis of 20,000+ extensions across Push customers",{"data":3013,"marks":3014,"value":3015,"nodeType":457},{},[]," found ",{"data":3017,"marks":3018,"value":3020,"nodeType":457},{},[3019],{"type":512},"46.76% have the permission combinations needed to perform account takeover with no user interaction",{"data":3022,"marks":3023,"value":3024,"nodeType":457},{},[],", making permissions-based risk scoring effectively useless as a triage tool. The real threat model is not malicious extensions at install time — it's legitimate extensions that ",{"data":3026,"marks":3027,"value":3029,"nodeType":457},{},[3028],{"type":1309},"become",{"data":3031,"marks":3032,"value":3033,"nodeType":457},{},[]," malicious after an ownership transfer, developer account compromise, or silent update push. Every major extension supply chain breach of the past 18 months scored as low-risk immediately before compromise.",{"data":3035,"content":3036,"nodeType":458},{},[3037],{"data":3038,"marks":3039,"value":3040,"nodeType":457},{},[],"SWGs and network tools are structurally blind to this attack surface: a malicious extension exfiltrating session tokens generates no anomalous network signal — its traffic is indistinguishable from normal browsing. Endpoint agents have no visibility into extension behavior at the session level. Extension inventory, supply chain change monitoring — ownership transfers, permission escalations, developer contact changes — and enforcement all require browser-layer access by definition.",{"data":3042,"content":3043,"nodeType":526},{},[],{"data":3045,"content":3046,"nodeType":535},{},[3047],{"data":3048,"marks":3049,"value":3051,"nodeType":457},{},[3050],{"type":512},"#5 — Shadow SaaS discovery and OAuth integration governance",{"data":3053,"content":3054,"nodeType":458},{},[3055],{"data":3056,"marks":3057,"value":2916,"nodeType":457},{},[3058],{"type":512},{"data":3060,"content":3061,"nodeType":458},{},[3062,3066,3071,3075,3080],{"data":3063,"marks":3064,"value":3065,"nodeType":457},{},[],"Shadow SaaS discovery shares DNA with identity posture hardening (#3) — both start with the same browser-native visibility into login events that no other layer can replicate. Where identity posture focuses on hardening ",{"data":3067,"marks":3068,"value":3070,"nodeType":457},{},[3069],{"type":1309},"how",{"data":3072,"marks":3073,"value":3074,"nodeType":457},{},[]," employees authenticate, shadow SaaS discovery focuses on ",{"data":3076,"marks":3077,"value":3079,"nodeType":457},{},[3078],{"type":1309},"what",{"data":3081,"marks":3082,"value":3083,"nodeType":457},{},[]," they authenticate to: surfacing the full estate of applications in use across the organization, including those that IT has never sanctioned or even heard of.",{"data":3085,"content":3086,"nodeType":458},{},[3087],{"data":3088,"marks":3089,"value":3090,"nodeType":457},{},[],"OAuth integration governance is the component of shadow SaaS that is both the most potentially damaging and the hardest to surface through other means. The SaaS-to-SaaS OAuth pivot is now an industrialized attack pattern.",{"data":3092,"content":3093,"nodeType":1440},{},[3094,3116],{"data":3095,"content":3096,"nodeType":1444},{},[3097],{"data":3098,"content":3099,"nodeType":458},{},[3100,3104,3112],{"data":3101,"marks":3102,"value":3103,"nodeType":457},{},[],"The ",{"data":3105,"content":3107,"nodeType":481},{"uri":3106},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fanalyzing-the-instructure-breach\u002F",[3108],{"data":3109,"marks":3110,"value":3111,"nodeType":457},{},[],"ShinyHunters",{"data":3113,"marks":3114,"value":3115,"nodeType":457},{},[]," Salesforce campaign — which compromised 1,000+ organizations and 1.5 billion records — demonstrated the full chain: the attacker didn't stop at stealing customer data but harvested OAuth tokens, AWS access keys, and Snowflake tokens from breached tenants and pivoted through connected services like Salesloft, Drift, and Gainsight to reach hundreds more organizations.",{"data":3117,"content":3118,"nodeType":1444},{},[3119],{"data":3120,"content":3121,"nodeType":458},{},[3122,3125,3133],{"data":3123,"marks":3124,"value":3103,"nodeType":457},{},[],{"data":3126,"content":3128,"nodeType":481},{"uri":3127},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Funpacking-the-vercel-breach\u002F",[3129],{"data":3130,"marks":3131,"value":3132,"nodeType":457},{},[],"Context.ai → Vercel",{"data":3134,"marks":3135,"value":3136,"nodeType":457},{},[]," chain followed the same logic — stored OAuth tokens from a forgotten AI app trial provided the bridge into Google Workspace, internal dashboards, and API keys. These are not isolated incidents; they are the repeatable playbook for extracting maximum value from a single compromise through the trust relationships that OAuth connections encode.",{"data":3138,"content":3139,"nodeType":458},{},[3140],{"data":3141,"marks":3142,"value":3143,"nodeType":457},{},[],"Every OAuth consent grant transits the browser — the authorization prompt, the scope disclosure, the user's approval click, and the redirect that completes the grant all happen inside a browser session — which makes the browser the only layer where an unwanted grant can be intercepted before the token is issued and the persistent access path is created. Once a token exists, the damage is done: it survives password resets, MFA changes, and session revocations, and revoking it after the fact requires first knowing it was granted, which most organizations do not.",{"data":3145,"content":3146,"nodeType":526},{},[],{"data":3148,"content":3149,"nodeType":535},{},[3150],{"data":3151,"marks":3152,"value":3154,"nodeType":457},{},[3153],{"type":512},"#6 — Blocking ClickFix and social engineering-based malware delivery",{"data":3156,"content":3157,"nodeType":458},{},[3158],{"data":3159,"marks":3160,"value":3162,"nodeType":457},{},[3161],{"type":512},"Security value: High | Browser fit: Strong for interception — shared with endpoint security for execution. ConsentFix is a browser-native exception that is T1-aligned.",{"data":3164,"content":3165,"nodeType":458},{},[3166,3170,3175,3179,3187,3191,3196,3200,3205],{"data":3167,"marks":3168,"value":3169,"nodeType":457},{},[],"ClickFix was the most common initial access vector reported by Microsoft in 2025, accounting for ",{"data":3171,"marks":3172,"value":3174,"nodeType":457},{},[3173],{"type":512},"47% of observed attacks",{"data":3176,"marks":3177,"value":3178,"nodeType":457},{},[],". CrowdStrike's ",{"data":3180,"content":3182,"nodeType":481},{"uri":3181},"https:\u002F\u002Fwww.crowdstrike.com\u002Fexplore\u002F2026-global-threat-report",[3183],{"data":3184,"marks":3185,"value":3186,"nodeType":457},{},[],"2026 Global Threat Report",{"data":3188,"marks":3189,"value":3190,"nodeType":457},{},[]," identified fake CAPTCHA lures as the most common malware download type, increasing ",{"data":3192,"marks":3193,"value":3195,"nodeType":457},{},[3194],{"type":512},"563% year-over-year",{"data":3197,"marks":3198,"value":3199,"nodeType":457},{},[],". The technique writes a malicious command to the victim's clipboard and social-engineers them into executing it. It is fileless (bypassing download scanning), user-executed (bypassing endpoint behavioral detections), and ",{"data":3201,"marks":3202,"value":3204,"nodeType":457},{},[3203],{"type":512},"4 in 5 ClickFix payloads intercepted by Push arrived via search engines",{"data":3206,"marks":3207,"value":3208,"nodeType":457},{},[]," — not email (bypassing email anti-phishing controls).",{"data":3210,"content":3211,"nodeType":458},{},[3212],{"data":3213,"marks":3214,"value":3215,"nodeType":457},{},[],"The browser is the earliest and most effective intervention point — detecting the clipboard injection and social engineering lure before anything reaches the endpoint in executable form. But the problem doesn't end at the browser boundary: once the command has been pasted and run, detection and remediation become endpoint problems, and a mature defense requires both layers. The broader *Fix family — FileFix, InstallFix, and similar derivatives — follows the same pattern, with the browser providing the critical early-warning layer within a defense that spans browser and endpoint.",{"data":3217,"content":3221,"nodeType":522},{"target":3218},{"sys":3219},{"id":3220,"type":519,"linkType":520},"39alMHtw9FPHbQINqbAgBN",[],{"data":3223,"content":3224,"nodeType":526},{},[],{"data":3226,"content":3227,"nodeType":535},{},[3228],{"data":3229,"marks":3230,"value":3232,"nodeType":457},{},[3231],{"type":512},"#7 — AI visibility and control: enforcing which AI tools employees can use and how",{"data":3234,"content":3235,"nodeType":458},{},[3236],{"data":3237,"marks":3238,"value":3240,"nodeType":457},{},[3239],{"type":512},"Security value: High | Browser fit: Strong for access enforcement — but AI governance is not a new security problem so much as a force multiplier on existing ones",{"data":3242,"content":3243,"nodeType":458},{},[3244,3248,3257,3261,3270],{"data":3245,"marks":3246,"value":3247,"nodeType":457},{},[],"AI adoption is outpacing security governance at nearly every organization, and ",{"data":3249,"content":3251,"nodeType":481},{"uri":3250},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002F7-things-omdias-latest-report-tells-us-about-the-secure-enterprise-browser-market\u002F",[3252],{"data":3253,"marks":3254,"value":3256,"nodeType":457},{},[3255],{"type":512},"71% of organizations are concerned about data leakage via unsanctioned AI apps",{"data":3258,"marks":3259,"value":3260,"nodeType":457},{},[],". But the security problems that AI creates are not, for the most part, novel — they are existing Tier 1 problems amplified by a new category of tooling. Shadow AI apps are shadow SaaS (#5). AI OAuth integrations are OAuth governance (#5). AI browser extensions are extension security (#4). The risk of employees using personal AI accounts — ",{"data":3262,"content":3264,"nodeType":481},{"uri":3263},"https:\u002F\u002Fkeepaware.com\u002Fblog\u002F46-of-sensitive-data-bypasses-your-dlp",[3265],{"data":3266,"marks":3267,"value":3269,"nodeType":457},{},[3268],{"type":512},"46% of sensitive inputs to AI tools are sent via personal accounts",{"data":3271,"marks":3272,"value":3273,"nodeType":457},{},[]," — is an identity posture problem (#3).",{"data":3275,"content":3276,"nodeType":458},{},[3277],{"data":3278,"marks":3279,"value":3280,"nodeType":457},{},[],"The component parts that allow you to govern AI are individually Tier 1 capabilities, and the browser is the best single layer for gaining visibility and control over AI usage — it sees the apps, the OAuth grants, the extensions, and the account context. But a complete end-to-end solution also requires a presence on the endpoint layer (for local AI tools, IDE-integrated agents, and API-level usage that never touches the browser), and prompt-level DLP on sanctioned tools is better handled by platform-native controls than by browser-layer observation.",{"data":3282,"content":3286,"nodeType":522},{"target":3283},{"sys":3284},{"id":3285,"type":519,"linkType":520},"6Py3z9VgjhKrchmYvhmbsq",[],{"data":3288,"content":3289,"nodeType":458},{},[3290],{"data":3291,"marks":3292,"value":3293,"nodeType":457},{},[],"The browser is what makes platform controls effective — if employees are using personal accounts, there are no enterprise audit logs to inspect. And for the growing category of AI agents, agentic browsers, and MCP-connected tools that operate through OAuth grants rather than direct user interaction, the browser is where the consent decisions that authorize those agents are made.",{"data":3295,"content":3296,"nodeType":526},{},[],{"data":3298,"content":3299,"nodeType":535},{},[3300],{"data":3301,"marks":3302,"value":3304,"nodeType":457},{},[3303],{"type":512},"#8 — Investigation acceleration and incident response: closing the missing middle",{"data":3306,"content":3307,"nodeType":458},{},[3308],{"data":3309,"marks":3310,"value":3312,"nodeType":457},{},[3311],{"type":512},"Security value: High | Browser fit: Strong — fills a structural gap complementary to endpoint, network, and identity telemetry",{"data":3314,"content":3315,"nodeType":458},{},[3316,3320,3325,3329,3338],{"data":3317,"marks":3318,"value":3319,"nodeType":457},{},[],"Endpoint logs show what processes executed. Network logs show traffic destinations. IdP logs show authentication events. None of them show what happened ",{"data":3321,"marks":3322,"value":3324,"nodeType":457},{},[3323],{"type":1309},"inside the browser session",{"data":3326,"marks":3327,"value":3328,"nodeType":457},{},[]," — the phishing page the user saw, the credentials they entered, the malicious OAuth consent grant, the data uploaded or pasted to an unsanctioned service. This is the missing middle of modern incident investigations, and for the ",{"data":3330,"content":3332,"nodeType":481},{"uri":3331},"https:\u002F\u002Fwww.paloaltonetworks.co.uk\u002Fresources\u002Fresearch\u002Funit-42-incident-response-report",[3333],{"data":3334,"marks":3335,"value":3337,"nodeType":457},{},[3336],{"type":512},"48% of intrusions involving browser-based activity",{"data":3339,"marks":3340,"value":3341,"nodeType":457},{},[],", the absence of browser telemetry is a significant investigative gap.",{"data":3343,"content":3344,"nodeType":458},{},[3345],{"data":3346,"marks":3347,"value":3348,"nodeType":457},{},[],"Browser-layer telemetry fills that gap with a fundamentally different quality of signal: what users actually clicked, what pages loaded and how they behaved, what credentials were entered, what session activity followed — structured, high-fidelity data from inside the session where the attack played out. That's the difference between inferring what happened and seeing it directly, and it determines scope, drives containment decisions, and provides the direct evidential record that neither endpoint DLP nor network monitoring can supply for browser-native attacks.",{"data":3350,"content":3351,"nodeType":458},{},[3352],{"data":3353,"marks":3354,"value":3355,"nodeType":457},{},[],"Browser telemetry is a key addition to the investigative picture. Investigations are inherently multi-source — without browser data, reconstructing an incident from EDR, network, and IdP logs won't tell you the full picture (particularly when attacks are increasingly delivered outside of email, intercepting users as they browse the internet normally).",{"data":3357,"content":3358,"nodeType":458},{},[3359],{"data":3360,"marks":3361,"value":3362,"nodeType":457},{},[],"The browser provides the causal link that other sources miss: the bridge between \"a user visited a URL\" and \"credentials were submitted to a phishing page that issued a session token now being replayed from an attacker-controlled browser.\" Integrated with SIEM and SOAR platforms, that signal enables automated response workflows to execute on high-confidence detections without waiting for manual triage.",{"data":3364,"content":3365,"nodeType":526},{},[],{"data":3367,"content":3368,"nodeType":535},{},[3369],{"data":3370,"marks":3371,"value":3373,"nodeType":457},{},[3372],{"type":512},"#9 — Infostealer defense: detecting exposure and blocking delivery",{"data":3375,"content":3376,"nodeType":458},{},[3377],{"data":3378,"marks":3379,"value":3381,"nodeType":457},{},[3380],{"type":512},"Security value: High | Browser fit: Strong for delivery interception and stolen factor detection — complementary to endpoint security for execution",{"data":3383,"content":3384,"nodeType":458},{},[3385],{"data":3386,"marks":3387,"value":3388,"nodeType":457},{},[],"Infostealers are the upstream supply chain for a disproportionate share of the most damaging enterprise attacks — harvesting credentials, session cookies, and browser profile data en masse from infected devices, then selling the outputs on infostealer markets for use in credential stuffing, ATO, and ransomware campaigns.",{"data":3390,"content":3394,"nodeType":522},{"target":3391},{"sys":3392},{"id":3393,"type":519,"linkType":520},"5NF1afwu3zFGThZTtStVQA",[],{"data":3396,"content":3397,"nodeType":458},{},[3398],{"data":3399,"marks":3400,"value":3401,"nodeType":457},{},[],"The browser is relevant at two points in the infostealer kill chain. First, delivery interception: ClickFix (covered in #6) is now the primary infostealer delivery mechanism, and the browser is the only layer that can intercept it before execution. Second, detecting stolen factors when attackers attempt to use them — and infostealers produce two categories of stolen factor that the browser can guard against.",{"data":3403,"content":3404,"nodeType":1440},{},[3405,3415],{"data":3406,"content":3407,"nodeType":1444},{},[3408],{"data":3409,"content":3410,"nodeType":458},{},[3411],{"data":3412,"marks":3413,"value":3414,"nodeType":457},{},[],"Stolen credentials can be identified at the point of login: browser-layer detection flags credentials that appear in known breach datasets, catching infostealer-harvested passwords being replayed in credential stuffing campaigns before the account is compromised.",{"data":3416,"content":3417,"nodeType":1444},{},[3418],{"data":3419,"content":3420,"nodeType":458},{},[3421],{"data":3422,"marks":3423,"value":3424,"nodeType":457},{},[],"Stolen session tokens are caught through a different mechanism: sessions originating in instrumented browsers carry a marker, and when a token subsequently appears in an un-instrumented browser it is a confirmed stolen session — catching infostealer-harvested cookies being replayed regardless of how or where the token was originally harvested.",{"data":3426,"content":3427,"nodeType":458},{},[3428,3432,3441,3445,3450],{"data":3429,"marks":3430,"value":3431,"nodeType":457},{},[],"This is particularly critical for the ",{"data":3433,"content":3435,"nodeType":481},{"uri":3434},"https:\u002F\u002Fwww.verizon.com\u002Fbusiness\u002Fen-gb\u002Fresources\u002Freports\u002Fdbir\u002F",[3436],{"data":3437,"marks":3438,"value":3440,"nodeType":457},{},[3439],{"type":512},"46% of infected devices that are unmanaged",{"data":3442,"marks":3443,"value":3444,"nodeType":457},{},[]," where EDR is absent and the stolen credentials and session tokens will never be detected at the endpoint. Infostealer ",{"data":3446,"marks":3447,"value":3449,"nodeType":457},{},[3448],{"type":1309},"execution",{"data":3451,"marks":3452,"value":3453,"nodeType":457},{},[]," remains an endpoint problem; the browser closes the delivery and replay gaps that endpoint tools miss.",{"data":3455,"content":3456,"nodeType":526},{},[],{"data":3458,"content":3459,"nodeType":535},{},[3460],{"data":3461,"marks":3462,"value":3464,"nodeType":457},{},[3463],{"type":512},"#10 — Data loss prevention: a key component of effective DLP, but not the full picture",{"data":3466,"content":3467,"nodeType":458},{},[3468],{"data":3469,"marks":3470,"value":3472,"nodeType":457},{},[3471],{"type":512},"Security value: Medium-high | Browser fit: Partial — complementary to dedicated DLP",{"data":3474,"content":3475,"nodeType":458},{},[3476],{"data":3477,"marks":3478,"value":3479,"nodeType":457},{},[],"File uploads to unsanctioned services, sensitive data pasted into AI tools, and exfiltration through personal accounts are genuine and growing risks that traditional email and endpoint-centric DLP tools were not designed to catch. Browser-layer controls provide real value here — particularly for BYOD users and contractors, where endpoint DLP agents cannot be deployed and the browser is the only available data loss visibility.",{"data":3481,"content":3482,"nodeType":458},{},[3483],{"data":3484,"marks":3485,"value":3486,"nodeType":457},{},[],"The honest scope: browser-layer DLP does not cover email-based loss, endpoint-to-endpoint transfers, or cloud API exfiltration. It closes specific and important gaps within a broader DLP strategy, not a replacement for one. A further distinction for organizations evaluating browser DLP for secure third-party access: full-stack enterprise browsers can enforce deeper output controls — watermarking, obfuscation, screenshot and print restrictions — at the OS rendering level that browser extensions cannot reliably replicate. Extension-based browser DLP is strongest for upload, input, and access control use cases rather than OS-level output restriction.",{"data":3488,"content":3489,"nodeType":526},{},[],{"data":3491,"content":3492,"nodeType":535},{},[3493],{"data":3494,"marks":3495,"value":3497,"nodeType":457},{},[3496],{"type":512},"Tier 3 — Lower Value: A problem best addressed outside of the browser",{"data":3499,"content":3500,"nodeType":1440},{},[3501,3516,3531,3546],{"data":3502,"content":3503,"nodeType":1444},{},[3504],{"data":3505,"content":3506,"nodeType":458},{},[3507,3512],{"data":3508,"marks":3509,"value":3511,"nodeType":457},{},[3510],{"type":512},"Browser exploit protection",{"data":3513,"marks":3514,"value":3515,"nodeType":457},{},[]," (narrow RCE\u002Fsandbox sense) ranks lower because browser zero-days represent just 9% of all zero-days reported to Google, and 82% of attack detections are now malware-free (CrowdStrike 2026). This is a problem for browser vendors to solve, and it's not a big enough problem to warrant enterprises investing in additional mitigating controls.",{"data":3517,"content":3518,"nodeType":1444},{},[3519],{"data":3520,"content":3521,"nodeType":458},{},[3522,3527],{"data":3523,"marks":3524,"value":3526,"nodeType":457},{},[3525],{"type":512},"Domain and URL category controls",{"data":3528,"marks":3529,"value":3530,"nodeType":457},{},[]," offer genuine browser-layer value but are commoditized by SWG and DNS filtering tools most organizations already operate. This can be provided in the browser, sure (and it's something we do at Push) but offers limited security value in terms of making a difference against modern attacks that quickly rotate these kinds of indicators and are designed to blend in.",{"data":3532,"content":3533,"nodeType":1444},{},[3534],{"data":3535,"content":3536,"nodeType":458},{},[3537,3542],{"data":3538,"marks":3539,"value":3541,"nodeType":457},{},[3540],{"type":512},"Access management",{"data":3543,"marks":3544,"value":3545,"nodeType":457},{},[]," — ZTNA, VPN replacement, PAM, BYOD access control — is an IT infrastructure and access architecture problem, not a security operations problem, and belongs to a different buyer with a different evaluation frame. There are numerous (typically full-stack) Enterprise Browser solutions on the market that address IT use cases like this well.",{"data":3547,"content":3548,"nodeType":1444},{},[3549],{"data":3550,"content":3551,"nodeType":458},{},[3552,3556],{"data":3553,"marks":3554,"value":368,"nodeType":457},{},[3555],{"type":512},{"data":3557,"marks":3558,"value":3559,"nodeType":457},{},[]," addresses browser exploit risk rather than the identity-first attacks that represent the majority of current enterprise browser risk, and introduces UX friction that limits deployment at scale. When it triggers, it introduces latency but still fails to detect and stop browser-native attacks.",{"data":3561,"content":3562,"nodeType":526},{},[],{"data":3564,"content":3565,"nodeType":535},{},[3566],{"data":3567,"marks":3568,"value":3570,"nodeType":457},{},[3569],{"type":512},"How Push Security maps to the highest-value security use cases",{"data":3572,"content":3573,"nodeType":458},{},[3574],{"data":3575,"marks":3576,"value":3577,"nodeType":457},{},[],"Push is purpose-built to address all of these problems using a flexible browser extension — plug into any browser with no migration, no host agent deployment, and no IT overhead — that delivers telemetry and control from day one, and extends coverage to every enrolled browser regardless of device ownership.",{"data":3579,"content":3580,"nodeType":3871},{},[3581,3608,3632,3656,3680,3704,3728,3752,3776,3800,3824,3848],{"data":3582,"content":3583,"nodeType":3607},{},[3584,3596],{"data":3585,"content":3586,"nodeType":3595},{},[3587],{"data":3588,"content":3589,"nodeType":458},{},[3590],{"data":3591,"marks":3592,"value":3594,"nodeType":457},{},[3593],{"type":512},"Security use case","table-cell",{"data":3597,"content":3598,"nodeType":3595},{},[3599],{"data":3600,"content":3601,"nodeType":458},{},[3602],{"data":3603,"marks":3604,"value":3606,"nodeType":457},{},[3605],{"type":512},"How Push addresses it","table-row",{"data":3609,"content":3610,"nodeType":3607},{},[3611,3622],{"data":3612,"content":3613,"nodeType":3595},{},[3614],{"data":3615,"content":3616,"nodeType":458},{},[3617],{"data":3618,"marks":3619,"value":3621,"nodeType":457},{},[3620],{"type":512},"Account takeover prevention",{"data":3623,"content":3624,"nodeType":3595},{},[3625],{"data":3626,"content":3627,"nodeType":458},{},[3628],{"data":3629,"marks":3630,"value":3631,"nodeType":457},{},[],"Surfaces and fixes ghost logins, weak and breached credentials and missing MFA controls across every app and device — including shadow SaaS and unmanaged devices invisible to the IdP. Push also detects and stops the attack techniques that typically lead to ATO early in the kill chain and before an account can be compromised.",{"data":3633,"content":3634,"nodeType":3607},{},[3635,3646],{"data":3636,"content":3637,"nodeType":3595},{},[3638],{"data":3639,"content":3640,"nodeType":458},{},[3641],{"data":3642,"marks":3643,"value":3645,"nodeType":457},{},[3644],{"type":512},"Advanced phishing detection",{"data":3647,"content":3648,"nodeType":3595},{},[3649],{"data":3650,"content":3651,"nodeType":458},{},[3652],{"data":3653,"marks":3654,"value":3655,"nodeType":457},{},[],"Behavioral page analysis detects phishing kits regardless of whether the domain is known-bad. Credential entry guardrails block corporate passwords from being submitted to unauthorized domains. TTP-based detection remains effective as attacker infrastructure rotates.",{"data":3657,"content":3658,"nodeType":3607},{},[3659,3670],{"data":3660,"content":3661,"nodeType":3595},{},[3662],{"data":3663,"content":3664,"nodeType":458},{},[3665],{"data":3666,"marks":3667,"value":3669,"nodeType":457},{},[3668],{"type":512},"Identity posture hardening",{"data":3671,"content":3672,"nodeType":3595},{},[3673],{"data":3674,"content":3675,"nodeType":458},{},[3676],{"data":3677,"marks":3678,"value":3679,"nodeType":457},{},[],"Enforces MFA, strong credentials, and SSO adoption across every app the IdP doesn't manage. Produces continuous, auditable MFA coverage and credential hygiene evidence across the full application and device estate.",{"data":3681,"content":3682,"nodeType":3607},{},[3683,3694],{"data":3684,"content":3685,"nodeType":3595},{},[3686],{"data":3687,"content":3688,"nodeType":458},{},[3689],{"data":3690,"marks":3691,"value":3693,"nodeType":457},{},[3692],{"type":512},"Browser extension security",{"data":3695,"content":3696,"nodeType":3595},{},[3697],{"data":3698,"content":3699,"nodeType":458},{},[3700],{"data":3701,"marks":3702,"value":3703,"nodeType":457},{},[],"Live extension inventory with supply chain change event monitoring — ownership transfers, permission escalations, developer contact changes — rather than static risk scoring. Supports default-deny allowlisting and remote extension removal. Blocks known-bad malicious extensions automatically.",{"data":3705,"content":3706,"nodeType":3607},{},[3707,3718],{"data":3708,"content":3709,"nodeType":3595},{},[3710],{"data":3711,"content":3712,"nodeType":458},{},[3713],{"data":3714,"marks":3715,"value":3717,"nodeType":457},{},[3716],{"type":512},"Shadow SaaS and OAuth governance",{"data":3719,"content":3720,"nodeType":3595},{},[3721],{"data":3722,"content":3723,"nodeType":458},{},[3724],{"data":3725,"marks":3726,"value":3727,"nodeType":457},{},[],"Discovers shadow SaaS from actual login events with full authentication context. Monitors and blocks OAuth consent flows — including AI and MCP integrations — in real time before persistent access paths are created.",{"data":3729,"content":3730,"nodeType":3607},{},[3731,3742],{"data":3732,"content":3733,"nodeType":3595},{},[3734],{"data":3735,"content":3736,"nodeType":458},{},[3737],{"data":3738,"marks":3739,"value":3741,"nodeType":457},{},[3740],{"type":512},"ClickFix and the *Fix family",{"data":3743,"content":3744,"nodeType":3595},{},[3745],{"data":3746,"content":3747,"nodeType":458},{},[3748],{"data":3749,"marks":3750,"value":3751,"nodeType":457},{},[],"Detects and blocks ClickFix lures, clipboard injection, and browser-native variants like ConsentFix in real time — before the payload executes or OAuth key material is captured.",{"data":3753,"content":3754,"nodeType":3607},{},[3755,3766],{"data":3756,"content":3757,"nodeType":3595},{},[3758],{"data":3759,"content":3760,"nodeType":458},{},[3761],{"data":3762,"marks":3763,"value":3765,"nodeType":457},{},[3764],{"type":512},"AI visibility & control",{"data":3767,"content":3768,"nodeType":3595},{},[3769],{"data":3770,"content":3771,"nodeType":458},{},[3772],{"data":3773,"marks":3774,"value":3775,"nodeType":457},{},[],"Enforces which AI tools employees can access and routes usage to corporate tenants. Governs AI browser extensions and blocks OAuth consent grants to unapproved AI applications — drawing on the same Tier 1 capabilities (OAuth governance, extension security, shadow SaaS discovery) that make this possible.",{"data":3777,"content":3778,"nodeType":3607},{},[3779,3790],{"data":3780,"content":3781,"nodeType":3595},{},[3782],{"data":3783,"content":3784,"nodeType":458},{},[3785],{"data":3786,"marks":3787,"value":3789,"nodeType":457},{},[3788],{"type":512},"Security investigations & incident response",{"data":3791,"content":3792,"nodeType":3595},{},[3793],{"data":3794,"content":3795,"nodeType":458},{},[3796],{"data":3797,"marks":3798,"value":3799,"nodeType":457},{},[],"High-fidelity session telemetry — page loads, credential entries, DOM changes, OAuth grants — fills the missing middle that endpoint, network, and IdP logs leave open. Feeds directly into SIEM and SOAR for automated response.",{"data":3801,"content":3802,"nodeType":3607},{},[3803,3814],{"data":3804,"content":3805,"nodeType":3595},{},[3806],{"data":3807,"content":3808,"nodeType":458},{},[3809],{"data":3810,"marks":3811,"value":3813,"nodeType":457},{},[3812],{"type":512},"Infostealer defense",{"data":3815,"content":3816,"nodeType":3595},{},[3817],{"data":3818,"content":3819,"nodeType":458},{},[3820],{"data":3821,"marks":3822,"value":3823,"nodeType":457},{},[],"Intercepts ClickFix-based infostealer delivery before execution. Detects token replay in unenrolled browser contexts — catching post-theft abuse from AiTM-sourced tokens and infostealer-harvested cookies, including from unmanaged devices.",{"data":3825,"content":3826,"nodeType":3607},{},[3827,3838],{"data":3828,"content":3829,"nodeType":3595},{},[3830],{"data":3831,"content":3832,"nodeType":458},{},[3833],{"data":3834,"marks":3835,"value":3837,"nodeType":457},{},[3836],{"type":512},"Data loss prevention",{"data":3839,"content":3840,"nodeType":3595},{},[3841],{"data":3842,"content":3843,"nodeType":458},{},[3844],{"data":3845,"marks":3846,"value":3847,"nodeType":457},{},[],"Observes file uploads, downloads, and sensitive data inputs across all applications. Extends data loss visibility to BYOD and contractor devices where endpoint DLP cannot reach.",{"data":3849,"content":3850,"nodeType":3607},{},[3851,3861],{"data":3852,"content":3853,"nodeType":3595},{},[3854],{"data":3855,"content":3856,"nodeType":458},{},[3857],{"data":3858,"marks":3859,"value":3526,"nodeType":457},{},[3860],{"type":512},{"data":3862,"content":3863,"nodeType":3595},{},[3864],{"data":3865,"content":3866,"nodeType":458},{},[3867],{"data":3868,"marks":3869,"value":3870,"nodeType":457},{},[],"Custom URL blocklists with wildcard support and REST API management for threat intelligence feed sync. Application category blocking restricts access to classes of apps (file-sharing, unsanctioned AI tools) configurable by user group. Domain categorization bringing SWG-style category blocking natively to the browser without a network proxy.","table",{"data":3873,"content":3874,"nodeType":526},{},[],{"data":3876,"content":3877,"nodeType":458},{},[3878,3882,3889],{"data":3879,"marks":3880,"value":3881,"nodeType":457},{},[],"Push Security is the most powerful AI-native security tool in the browser. Think EDR, but for the browser — high-fidelity telemetry and real-time control across every session, on every device, with no browser migration required. ",{"data":3883,"content":3884,"nodeType":481},{"uri":924},[3885],{"data":3886,"marks":3887,"value":3888,"nodeType":457},{},[],"Book a live demo to learn more.",{"data":3890,"marks":3891,"value":21,"nodeType":457},{},[],"The top 10 security problems you can solve in the browser — ranked by value","Ranking the security problems you can solve in the browser by security value and browser fit.","2026-05-14T00:00:00.000Z","the-top-10-security-problems-you-can-solve-in-the-browser-ranked-by-value",{"items":3897},[3898,3902],{"sys":3899,"name":3901},{"id":3900},"3pjES4THCIfSAwhGdNwBcy","Browser security",{"sys":3903,"name":3905},{"id":3904},"1gZi8NrRy2v9OqPV7C4dwD","Risk management",{"items":3907},[3908],{"fullName":439,"firstName":440,"jobTitle":441,"profilePicture":3909},{"url":445},{"__typename":1702,"sys":3911,"content":3913,"title":4681,"synopsis":4682,"hashTags":59,"publishedDate":4683,"slug":4684,"tagsCollection":4685,"authorsCollection":4691},{"id":3912},"2V130uMePtxAaefYQAKInb",{"json":3914},{"data":3915,"content":3916,"nodeType":934},{},[3917,3923,3930,3937,3944,3947,3955,3962,3974,3986,3992,3999,4002,4010,4017,4023,4030,4037,4146,4153,4156,4164,4171,4234,4250,4256,4263,4266,4274,4281,4289,4296,4303,4334,4341,4349,4356,4363,4370,4378,4385,4392,4399,4402,4410,4422,4429,4436,4444,4451,4458,4466,4473,4536,4552,4571,4579,4586,4594,4601,4608,4615,4621,4629,4636,4643,4648,4655,4662,4669,4675],{"data":3918,"content":3922,"nodeType":522},{"target":3919},{"sys":3920},{"id":3921,"type":519,"linkType":520},"5CPZ96xixlhgh6oqQ2rfmO",[],{"data":3924,"content":3925,"nodeType":458},{},[3926],{"data":3927,"marks":3928,"value":3929,"nodeType":457},{},[],"When a security team evaluates browser security solutions, they're usually asking the right question: “How do we protect our users as they work in the browser?”",{"data":3931,"content":3932,"nodeType":458},{},[3933],{"data":3934,"marks":3935,"value":3936,"nodeType":457},{},[],"But the answer they get from many vendors is shaped by a fundamentally different threat model — one that treats the browser as a piece of software to be hardened against exploitation, rather than as the arena where your users’ identities get stolen.",{"data":3938,"content":3939,"nodeType":458},{},[3940],{"data":3941,"marks":3942,"value":3943,"nodeType":457},{},[],"This distinction has enormous consequences for your security posture and the return you can expect from your investment in a new solution.",{"data":3945,"content":3946,"nodeType":526},{},[],{"data":3948,"content":3949,"nodeType":535},{},[3950],{"data":3951,"marks":3952,"value":3954,"nodeType":457},{},[3953],{"type":512},"Two different problems, dressed the same",{"data":3956,"content":3957,"nodeType":458},{},[3958],{"data":3959,"marks":3960,"value":3961,"nodeType":457},{},[],"When it comes to protecting users as they work in the browser, security tools typically fall into one of two camps:",{"data":3963,"content":3964,"nodeType":458},{},[3965,3970],{"data":3966,"marks":3967,"value":3969,"nodeType":457},{},[3968],{"type":512},"The first camp:",{"data":3971,"marks":3972,"value":3973,"nodeType":457},{},[]," represented by solutions like Seraphic (now CrowdStrike) — is built around the threat of attacking the browser itself. The architecture is designed to scramble the browser’s JavaScript runtime and prevent exploits from detonating and breaking out of the browser sandbox. This is browser hardening: defending the browser as software against exploitation by attackers who want to compromise the underlying device.",{"data":3975,"content":3976,"nodeType":458},{},[3977,3982],{"data":3978,"marks":3979,"value":3981,"nodeType":457},{},[3980],{"type":512},"The second camp:",{"data":3983,"marks":3984,"value":3985,"nodeType":457},{},[]," and the one Push Security occupies uniquely, focuses on what happens inside the browser when a user is working normally. Phishing pages harvesting credentials. Session tokens being stolen. Malicious OAuth applications being granted access through social engineering. Adversary-in-the-middle proxies intercepting authentication flows. These attacks don't exploit the browser. They exploit the human — and now agents — using it via the browser's legitimate capabilities (think of it as LOTL, browser edition).",{"data":3987,"content":3991,"nodeType":522},{"target":3988},{"sys":3989},{"id":3990,"type":519,"linkType":520},"5Kw2kSrL8u4VyslxK8HCtR",[],{"data":3993,"content":3994,"nodeType":458},{},[3995],{"data":3996,"marks":3997,"value":3998,"nodeType":457},{},[],"The question for any security team evaluating this space: which of these threat models presents the greatest risks to my organization?",{"data":4000,"content":4001,"nodeType":526},{},[],{"data":4003,"content":4004,"nodeType":535},{},[4005],{"data":4006,"marks":4007,"value":4009,"nodeType":457},{},[4008],{"type":512},"How organizations are actually being breached",{"data":4011,"content":4012,"nodeType":458},{},[4013],{"data":4014,"marks":4015,"value":4016,"nodeType":457},{},[],"Let's look at the major breach campaigns of the last three years without the marketing filter and a pattern emerges immediately. Scattered Spider and its successors breached MGM Resorts, Caesars, M&S, JLR, and Salesforce customers — not through browser exploits, but through social engineering, phishing and Adversary-in-the-Middle attacks that stole session tokens and SSO credentials. ",{"data":4018,"content":4022,"nodeType":522},{"target":4019},{"sys":4020},{"id":4021,"type":519,"linkType":520},"2qIMTiyyIsQFAyGJ9Ikyej",[],{"data":4024,"content":4025,"nodeType":458},{},[4026],{"data":4027,"marks":4028,"value":4029,"nodeType":457},{},[],"In every case, the attack happened in the browser — using stolen identities to log into legitimate cloud services — not on the browser through exploitation of the browser engine itself.",{"data":4031,"content":4032,"nodeType":458},{},[4033],{"data":4034,"marks":4035,"value":4036,"nodeType":457},{},[],"The data from major threat intelligence sources is unambiguous:",{"data":4038,"content":4039,"nodeType":1440},{},[4040,4059,4078,4097,4116,4131],{"data":4041,"content":4042,"nodeType":1444},{},[4043],{"data":4044,"content":4045,"nodeType":458},{},[4046,4050,4055],{"data":4047,"marks":4048,"value":4049,"nodeType":457},{},[],"Identity weaknesses played a material role in ",{"data":4051,"marks":4052,"value":4054,"nodeType":457},{},[4053],{"type":512},"almost 90% of Unit 42 incident response investigations",{"data":4056,"marks":4057,"value":4058,"nodeType":457},{},[]," (Palo Alto Networks Unit 42 IR Report)",{"data":4060,"content":4061,"nodeType":1444},{},[4062],{"data":4063,"content":4064,"nodeType":458},{},[4065,4069,4074],{"data":4066,"marks":4067,"value":4068,"nodeType":457},{},[],"Credential abuse and phishing combined accounted for ",{"data":4070,"marks":4071,"value":4073,"nodeType":457},{},[4072],{"type":512},"38% of all breaches",{"data":4075,"marks":4076,"value":4077,"nodeType":457},{},[],", making identity the single largest breach vector (Verizon DBIR 2025)",{"data":4079,"content":4080,"nodeType":1444},{},[4081],{"data":4082,"content":4083,"nodeType":458},{},[4084,4088,4093],{"data":4085,"marks":4086,"value":4087,"nodeType":457},{},[],"Cloud-conscious intrusions — attackers using stolen identities to access cloud services — rose ",{"data":4089,"marks":4090,"value":4092,"nodeType":457},{},[4091],{"type":512},"37% in 2025",{"data":4094,"marks":4095,"value":4096,"nodeType":457},{},[],", up 266% among state-nexus actors (CrowdStrike 2026 Global Threat Report)",{"data":4098,"content":4099,"nodeType":1444},{},[4100],{"data":4101,"content":4102,"nodeType":458},{},[4103,4107,4112],{"data":4104,"marks":4105,"value":4106,"nodeType":457},{},[],"In cloud-related incidents, identity issues drove initial access in ",{"data":4108,"marks":4109,"value":4111,"nodeType":457},{},[4110],{"type":512},"83% of cases",{"data":4113,"marks":4114,"value":4115,"nodeType":457},{},[]," (Mandiant \u002F Google Cloud Threat Horizons H1 2026)",{"data":4117,"content":4118,"nodeType":1444},{},[4119],{"data":4120,"content":4121,"nodeType":458},{},[4122,4127],{"data":4123,"marks":4124,"value":4126,"nodeType":457},{},[4125],{"type":512},"82% of attack detections are now malware-free",{"data":4128,"marks":4129,"value":4130,"nodeType":457},{},[]," — they don't touch the endpoint and abuse legitimate access and functionality (CrowdStrike 2026 Global Threat Report)",{"data":4132,"content":4133,"nodeType":1444},{},[4134],{"data":4135,"content":4136,"nodeType":458},{},[4137,4142],{"data":4138,"marks":4139,"value":4141,"nodeType":457},{},[4140],{"type":512},"49% of organizations",{"data":4143,"marks":4144,"value":4145,"nodeType":457},{},[]," suffered a successful browser-based attack in the last 12 months (Omdia 2026)",{"data":4147,"content":4148,"nodeType":458},{},[4149],{"data":4150,"marks":4151,"value":4152,"nodeType":457},{},[],"These aren't edge cases. This is now the primary attack playbook.",{"data":4154,"content":4155,"nodeType":526},{},[],{"data":4157,"content":4158,"nodeType":2382},{},[4159],{"data":4160,"marks":4161,"value":4163,"nodeType":457},{},[4162],{"type":512},"The economics of attack choice",{"data":4165,"content":4166,"nodeType":458},{},[4167],{"data":4168,"marks":4169,"value":4170,"nodeType":457},{},[],"Attackers are rational actors. They pick the cheapest, most reliable path to their objective. The economics of browser exploitation versus identity theft tell the whole story:",{"data":4172,"content":4173,"nodeType":1440},{},[4174,4189,4204,4219],{"data":4175,"content":4176,"nodeType":1444},{},[4177],{"data":4178,"content":4179,"nodeType":458},{},[4180,4184],{"data":4181,"marks":4182,"value":4183,"nodeType":457},{},[],"Chrome sandbox RCE exploit (bug bounty value): ",{"data":4185,"marks":4186,"value":4188,"nodeType":457},{},[4187],{"type":512},"$250,000",{"data":4190,"content":4191,"nodeType":1444},{},[4192],{"data":4193,"content":4194,"nodeType":458},{},[4195,4199],{"data":4196,"marks":4197,"value":4198,"nodeType":457},{},[],"IAB-provided IdP admin account: ",{"data":4200,"marks":4201,"value":4203,"nodeType":457},{},[4202],{"type":512},"~$3,000",{"data":4205,"content":4206,"nodeType":1444},{},[4207],{"data":4208,"content":4209,"nodeType":458},{},[4210,4214],{"data":4211,"marks":4212,"value":4213,"nodeType":457},{},[],"1-year phishing kit rental (PhaaS): ",{"data":4215,"marks":4216,"value":4218,"nodeType":457},{},[4217],{"type":512},"~$1,000",{"data":4220,"content":4221,"nodeType":1444},{},[4222],{"data":4223,"content":4224,"nodeType":458},{},[4225,4229],{"data":4226,"marks":4227,"value":4228,"nodeType":457},{},[],"Bulk stolen credential list: ",{"data":4230,"marks":4231,"value":4233,"nodeType":457},{},[4232],{"type":512},"~$15",{"data":4235,"content":4236,"nodeType":458},{},[4237,4241,4246],{"data":4238,"marks":4239,"value":4240,"nodeType":457},{},[],"Browser zero-days accounted for just ",{"data":4242,"marks":4243,"value":4245,"nodeType":457},{},[4244],{"type":512},"9% of all zero-days reported to Google in 2025",{"data":4247,"marks":4248,"value":4249,"nodeType":457},{},[]," — described by Google's own researchers as a \"historic low.\" Chrome's sandbox architecture, site isolation, and hardware-backed security features are the result of years of sustained hardening investment. When a browser vulnerability is discovered, Google typically deploys a patch within days.",{"data":4251,"content":4255,"nodeType":522},{"target":4252},{"sys":4253},{"id":4254,"type":519,"linkType":520},"5XWKHTT5J06yWcgZIOL95t",[],{"data":4257,"content":4258,"nodeType":458},{},[4259],{"data":4260,"marks":4261,"value":4262,"nodeType":457},{},[],"The bottom line: browser exploits are extraordinarily expensive to develop, increasingly difficult to execute reliably against a hardened modern browser, and patched rapidly when discovered. In sharp contrast, identity attacks are cheap to run, highly scalable, and have a low technical barrier to adoption — that’s why they’re responsible for the overwhelming majority of enterprise breaches. Attackers have voted with their resources.",{"data":4264,"content":4265,"nodeType":526},{},[],{"data":4267,"content":4268,"nodeType":535},{},[4269],{"data":4270,"marks":4271,"value":4273,"nodeType":457},{},[4272],{"type":512},"What you're actually buying with each vendor",{"data":4275,"content":4276,"nodeType":458},{},[4277],{"data":4278,"marks":4279,"value":4280,"nodeType":457},{},[],"Understanding the core architectural choice each vendor has made helps decode what their solution can and cannot protect you from.",{"data":4282,"content":4283,"nodeType":2382},{},[4284],{"data":4285,"marks":4286,"value":4288,"nodeType":457},{},[4287],{"type":512},"Seraphic (CrowdStrike)",{"data":4290,"content":4291,"nodeType":458},{},[4292],{"data":4293,"marks":4294,"value":4295,"nodeType":457},{},[],"Seraphic's architecture is built to inject into the browser's JavaScript runtime at the OS layer, scrambling browser internals to prevent exploits from executing. This is a technically sophisticated approach to a technically interesting problem that is, by every threat intelligence measure, not the problem causing enterprise breaches at scale.",{"data":4297,"content":4298,"nodeType":458},{},[4299],{"data":4300,"marks":4301,"value":4302,"nodeType":457},{},[],"Beyond the threat model mismatch, there are structural concerns with the approach itself. Injecting an agent into the browser's JS runtime is a technique with well-documented stability consequences. This is the same approach antivirus vendors have used for years, often at the cost of system stability. Seraphic now runs alongside the CrowdStrike Falcon sensor on managed devices, combining two heavyweight agents on the same machine. For any organization with CrowdStrike already deployed, the question isn't theoretical: how has that combination been validated in production environments?",{"data":4304,"content":4305,"nodeType":458},{},[4306,4310,4317,4321,4330],{"data":4307,"marks":4308,"value":4309,"nodeType":457},{},[],"There's also the managed-device limitation. Seraphic requires a kernel-level agent, which means it loses meaningful capability on unmanaged devices, BYOD machines, and contractor endpoints. This is not a niche concern: according to ",{"data":4311,"content":4312,"nodeType":481},{"uri":3250},[4313],{"data":4314,"marks":4315,"value":4316,"nodeType":457},{},[],"Omdia's 2026 browser security survey",{"data":4318,"marks":4319,"value":4320,"nodeType":457},{},[],", 32% of users access corporate applications from unmanaged devices at least occasionally. Agent-based solutions are blind to nearly a third of your actual attack surface by design. The Okta breach began on a support engineer's personal device, where ",{"data":4322,"content":4324,"nodeType":481},{"uri":4323},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fbrowser-sync-attacks-where-personal-account-hacks-lead-to-corporate-breaches\u002F",[4325],{"data":4326,"marks":4327,"value":4329,"nodeType":457},{},[4328],{"type":594},"corporate credentials had synced",{"data":4331,"marks":4332,"value":4333,"nodeType":457},{},[]," via Chrome's built-in profile sync. No agent, no visibility.",{"data":4335,"content":4336,"nodeType":458},{},[4337],{"data":4338,"marks":4339,"value":4340,"nodeType":457},{},[],"Teams evaluating Seraphic today are also buying into an integration roadmap, not a shipped capability. The acquisition by CrowdStrike closed in early 2026. The work of wiring browser telemetry into Falcon Fusion and correlating it with endpoint signals is currently a promise, not a production feature.",{"data":4342,"content":4343,"nodeType":2382},{},[4344],{"data":4345,"marks":4346,"value":4348,"nodeType":457},{},[4347],{"type":512},"SquareX (Zscaler)",{"data":4350,"content":4351,"nodeType":458},{},[4352],{"data":4353,"marks":4354,"value":4355,"nodeType":457},{},[],"SquareX's core capability is sandboxing suspicious file downloads inside disposable browser containers before they reach the endpoint. This is a legitimate approach to a real but declining problem. 82% of attack detections are now malware-free (CrowdStrike 2026 Global Threat Report) — attacks don't arrive as files to be sandboxed, they arrive as authenticated sessions. And the delivery channel shift makes the picture even starker: across Push's customer base, 1 in 3 phishing payloads are now delivered outside of email entirely — via social media, ads, and messaging platforms — and 4 in 5 ClickFix payloads arrive through search engines, not email. The threat that SquareX was architecturally designed to address is a shrinking share of the actual attack surface, and it's shrinking fast.",{"data":4357,"content":4358,"nodeType":458},{},[4359],{"data":4360,"marks":4361,"value":4362,"nodeType":457},{},[],"Zscaler already has sandboxing built into ZIA. For an existing Zscaler customer evaluating SquareX, the honest question is: what does this add beyond some extension analysis capability and what you already have? The AiTM phishing campaign that stole your user's credentials and accessed your cloud applications generates no malicious file, triggers no sandbox, and produces no network signal for Zscaler's traffic inspection to catch — because it happened entirely inside a browser session using legitimate authentication flows.",{"data":4364,"content":4365,"nodeType":458},{},[4366],{"data":4367,"marks":4368,"value":4369,"nodeType":457},{},[],"The acquisition also raises product focus questions. Being absorbed into a network-centric platform means SquareX is now optimized for Zscaler's priorities, not for standalone browser detection and response. Teams that care about investigation, threat hunting, and incident response should ask specifically what SquareX adds in those workflows under Zscaler ownership.",{"data":4371,"content":4372,"nodeType":2382},{},[4373],{"data":4374,"marks":4375,"value":4377,"nodeType":457},{},[4376],{"type":512},"LayerX",{"data":4379,"content":4380,"nodeType":458},{},[4381],{"data":4382,"marks":4383,"value":4384,"nodeType":457},{},[],"LayerX is primarily a policy enforcement and risk scoring platform focused on internal governance — controlling which applications employees access, what data moves through the browser, and whether behavior complies with internal rules.",{"data":4386,"content":4387,"nodeType":458},{},[4388],{"data":4389,"marks":4390,"value":4391,"nodeType":457},{},[],"Push Security covers that ground too. Push provides full visibility over AI tool usage, shadow SaaS, unmanaged identities, and data loss vectors — including sensitive data submitted through AI prompts, file uploads to personal cloud destinations, and OAuth grants to third-party applications. The same browser telemetry that detects external attacks also surfaces insider risks and powers DLP controls and compliance audit evidence, all from a single extension.",{"data":4393,"content":4394,"nodeType":458},{},[4395],{"data":4396,"marks":4397,"value":4398,"nodeType":457},{},[],"The critical difference is that Push goes significantly further. Where LayerX scores risk and enforces policy, Push detects active external attack techniques in real time: AiTM phishing kits as they execute, session tokens being stolen, ClickFix lures through behavioral analysis of page structure. These are the attacks causing the most damaging breaches today, and they don't surface on a risk score until after the damage is done. Push addresses both the governance problem and the external threat problem from the same platform. LayerX addresses only the first.",{"data":4400,"content":4401,"nodeType":526},{},[],{"data":4403,"content":4404,"nodeType":535},{},[4405],{"data":4406,"marks":4407,"value":4409,"nodeType":457},{},[4408],{"type":512},"Securing the organization via the browser: Push Security",{"data":4411,"content":4412,"nodeType":458},{},[4413,4418],{"data":4414,"marks":4415,"value":4417,"nodeType":457},{},[4416],{"type":512},"Push Security is built on a different architectural premise:",{"data":4419,"marks":4420,"value":4421,"nodeType":457},{},[]," the browser is not primarily a piece of software to harden against exploitation. It is the primary workplace, the primary SaaS access point, and the arena where the majority of modern identity attacks play out. The goal is to secure the organization via the browser — not just to secure the browser itself.",{"data":4423,"content":4424,"nodeType":458},{},[4425],{"data":4426,"marks":4427,"value":4428,"nodeType":457},{},[],"This means Push's detection surface is built around the attacks that are actually causing breaches: adversary-in-the-middle phishing, ClickFix and its many variants, credential stuffing against shadow identities, session token theft and replay, OAuth consent abuse, and the full spectrum of identity-based initial access techniques that dominate the modern threat landscape.",{"data":4430,"content":4431,"nodeType":458},{},[4432],{"data":4433,"marks":4434,"value":4435,"nodeType":457},{},[],"The deployment model reflects the threat model. Push deploys as a lightweight browser extension — no kernel-level agent, no device dependency, no migration to a new browser. It works on managed and unmanaged devices, across every traditional, enterprise and AI browser where employees are doing work and attackers are targeting them. The operational overhead is minimal by design: Push has been deployed to 100,000 users in under one hour during normal business hours.",{"data":4437,"content":4438,"nodeType":2382},{},[4439],{"data":4440,"marks":4441,"value":4443,"nodeType":457},{},[4442],{"type":512},"Detection philosophy: targeting what attackers can't change",{"data":4445,"content":4446,"nodeType":458},{},[4447],{"data":4448,"marks":4449,"value":4450,"nodeType":457},{},[],"Push's detection approach targets attacker TTPs rather than indicators of compromise that attackers can rotate in minutes. 95% of attacks detected by Push used some form of bot protection service — meaning the specific domain and IP were deliberately obscured. If your primary detection relies on blocklists, recent reports tell us that 89% of phishing domains will evade you: because they're active for less than two days, they can be spun up, down, and replaced faster than blocklists can keep up.",{"data":4452,"content":4453,"nodeType":458},{},[4454],{"data":4455,"marks":4456,"value":4457,"nodeType":457},{},[],"Behavioral detection of the attack technique — the AiTM relay structure, the credential entry on a cloned login page, the anomalous session context — remains valid regardless of what domain the attack is hosted on or which PhaaS kit was used to build it.",{"data":4459,"content":4460,"nodeType":2382},{},[4461],{"data":4462,"marks":4463,"value":4465,"nodeType":457},{},[4464],{"type":512},"Measuring the identity attack surface (it's bigger than you realize)",{"data":4467,"content":4468,"nodeType":458},{},[4469],{"data":4470,"marks":4471,"value":4472,"nodeType":457},{},[],"Because Push has visibility into actual login behavior across thousands of organizations, it can quantify the attack surface that identity-based attacks exploit. Of the last million logins observed by Push:",{"data":4474,"content":4475,"nodeType":1440},{},[4476,4491,4506,4521],{"data":4477,"content":4478,"nodeType":1444},{},[4479],{"data":4480,"content":4481,"nodeType":458},{},[4482,4487],{"data":4483,"marks":4484,"value":4486,"nodeType":457},{},[4485],{"type":512},"15 corporate identities were identified per employee",{"data":4488,"marks":4489,"value":4490,"nodeType":457},{},[]," used to access cloud apps",{"data":4492,"content":4493,"nodeType":1444},{},[4494],{"data":4495,"content":4496,"nodeType":458},{},[4497,4502],{"data":4498,"marks":4499,"value":4501,"nodeType":457},{},[4500],{"type":512},"1 in 4",{"data":4503,"marks":4504,"value":4505,"nodeType":457},{},[]," were password logins, not SSO",{"data":4507,"content":4508,"nodeType":1444},{},[4509],{"data":4510,"content":4511,"nodeType":458},{},[4512,4517],{"data":4513,"marks":4514,"value":4516,"nodeType":457},{},[4515],{"type":512},"2 in 5",{"data":4518,"marks":4519,"value":4520,"nodeType":457},{},[]," were not protected by MFA",{"data":4522,"content":4523,"nodeType":1444},{},[4524],{"data":4525,"content":4526,"nodeType":458},{},[4527,4532],{"data":4528,"marks":4529,"value":4531,"nodeType":457},{},[4530],{"type":512},"1 in 5",{"data":4533,"marks":4534,"value":4535,"nodeType":457},{},[]," used a weak, breached, or reused password",{"data":4537,"content":4538,"nodeType":458},{},[4539,4543,4548],{"data":4540,"marks":4541,"value":4542,"nodeType":457},{},[],"And it's not just login hygiene. Across Push's customer base, ",{"data":4544,"marks":4545,"value":4547,"nodeType":457},{},[4546],{"type":512},"46%+ of browser extensions in corporate environments have the permission combinations required for direct account takeover via session theft if they are malicious or compromised by an attacker",{"data":4549,"marks":4550,"value":4551,"nodeType":457},{},[],". Most organizations have no inventory of what's running in their employees' browsers, let alone visibility into what those extensions can access.",{"data":4553,"content":4554,"nodeType":458},{},[4555,4559,4567],{"data":4556,"marks":4557,"value":4558,"nodeType":457},{},[],"These aren't theoretical vulnerabilities. They're the specific weaknesses that browser-native identity attacks are designed to exploit. ",{"data":4560,"content":4562,"nodeType":481},{"uri":4561},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fthe-cisos-data-problem-and-how-browser-telemetry-can-help\u002F",[4563],{"data":4564,"marks":4565,"value":4566,"nodeType":457},{},[],"This visibility turns browser security from a reactive posture into a proactive one",{"data":4568,"marks":4569,"value":4570,"nodeType":457},{},[]," — you can see and remediate the identity weaknesses before an attacker exploits them, not just detect the attack while it's in progress.",{"data":4572,"content":4573,"nodeType":2382},{},[4574],{"data":4575,"marks":4576,"value":4578,"nodeType":457},{},[4577],{"type":512},"The ROI case",{"data":4580,"content":4581,"nodeType":458},{},[4582],{"data":4583,"marks":4584,"value":4585,"nodeType":457},{},[],"The ROI question for any security investment is: what quantum of real risk does this tool address, at what cost in money and operational friction?",{"data":4587,"content":4588,"nodeType":458},{},[4589],{"data":4590,"marks":4591,"value":4593,"nodeType":457},{},[4592],{"type":512},"That calculation looks very different depending on your threat model.",{"data":4595,"content":4596,"nodeType":458},{},[4597],{"data":4598,"marks":4599,"value":4600,"nodeType":457},{},[],"A solution focused on browser engine exploits and sandbox escapes is defending against an attack category that represents a tiny fraction of actual enterprise breaches, requires extraordinary attacker resources to execute, and is increasingly mitigated by browser vendors themselves through hardening and rapid patching. Chrome's automatic update cycle means that even when a browser vulnerability is discovered and disclosed, it is typically in front of users as a patch within days. The defenders here are Google, Mozilla, and Microsoft — with multi-billion dollar security teams and full access to the browser internals.",{"data":4602,"content":4603,"nodeType":458},{},[4604],{"data":4605,"marks":4606,"value":4607,"nodeType":457},{},[],"A solution focused on identity attacks via the browser — phishing, credential theft, session hijacking, OAuth abuse, malicious browser extensions — is defending against the primary cause of enterprise breaches, one that is accelerating (cloud-conscious intrusions up 37% in 2025, browser-based attacks increasing at 68% of organizations over the past two years per Omdia) and increasingly automated through PhaaS infrastructure that gives low-skill attackers enterprise-grade capability for $1,000 a year.",{"data":4609,"content":4610,"nodeType":458},{},[4611],{"data":4612,"marks":4613,"value":4614,"nodeType":457},{},[],"There's also a forward-looking dimension. The threat landscape isn't moving toward more browser exploitation. It's moving further into identity abuse. AI-powered phishing lowers the social engineering barrier. Agentic browsers will automate credential stuffing and account takeover at a scale that wasn't previously possible. And attackers are already adapting to authentication improvements: device code phishing has increased 37x since the start of 2026, a technique specifically designed to circumvent passkeys by bypassing the authentication flow entirely — the attacker never encounters a login page. The investment in identity-centric browser detection compounds over time as the attack surface evolves in the same direction.",{"data":4616,"content":4620,"nodeType":522},{"target":4617},{"sys":4618},{"id":4619,"type":519,"linkType":520},"cQ6WPV2NMYvDMZXifqzK1",[],{"data":4622,"content":4623,"nodeType":2382},{},[4624],{"data":4625,"marks":4626,"value":4628,"nodeType":457},{},[4627],{"type":512},"The verdict",{"data":4630,"content":4631,"nodeType":458},{},[4632],{"data":4633,"marks":4634,"value":4635,"nodeType":457},{},[],"Browser security is a real and growing priority — according to Omdia Research, it is now a top-five priority for 88% of security leaders and the top priority for 26% of them. 85% expect their browser security spending to increase over the next 12–24 months. The question isn't whether to invest. It's what to invest in.",{"data":4637,"content":4638,"nodeType":458},{},[4639],{"data":4640,"marks":4641,"value":4642,"nodeType":457},{},[],"The browser is where your users work, where attackers target them, and where the identity attacks causing the majority of enterprise breaches play out. But not all browser security investments address the same problem.",{"data":4644,"content":4647,"nodeType":522},{"target":4645},{"sys":4646},{"id":906,"type":519,"linkType":520},[],{"data":4649,"content":4650,"nodeType":458},{},[4651],{"data":4652,"marks":4653,"value":4654,"nodeType":457},{},[],"Solutions like Seraphic are built to defend against a browser being exploited by an attacker trying to break out of the sandbox — an attack that represents a historic low as a share of enterprise incidents, and one that Google's own hardening and rapid patching increasingly mitigates automatically. SquareX is built around malware sandboxing — a legitimate but declining share of the initial access landscape, and a capability Zscaler's existing customers already partially have. LayerX focuses on internal governance rather than external threats.",{"data":4656,"content":4657,"nodeType":458},{},[4658],{"data":4659,"marks":4660,"value":4661,"nodeType":457},{},[],"Push Security is built to defend against the attacks that are behind the major breaches hitting the headlines: identity theft, credential abuse, session hijacking, and the full identity attack kill chain that plays out inside the browser every time an attacker logs in as your user. Every major threat intelligence report points to these as the primary breach vectors. The economics of attack choice guarantee they'll remain so.",{"data":4663,"content":4664,"nodeType":458},{},[4665],{"data":4666,"marks":4667,"value":4668,"nodeType":457},{},[],"The security team that deploys Push gets the greatest coverage of the highest-impact threats, on managed and unmanaged devices, with the lightest operational footprint. That is the browser security investment that moves the needle on real organizational risk — not the browser security investment that defends the software nobody's actually attacking.",{"data":4670,"content":4674,"nodeType":522},{"target":4671},{"sys":4672},{"id":4673,"type":519,"linkType":520},"3a2sEWgWKZulGLCFfODwk0",[],{"data":4676,"content":4677,"nodeType":458},{},[4678],{"data":4679,"marks":4680,"value":21,"nodeType":457},{},[],"How to avoid the browser security buyer's trap","Securing the browser vs. securing the organization via the browser — what's the difference?","2026-05-13T00:00:00.000Z","how-to-avoid-the-browser-security-buyers-trap",{"items":4686},[4687,4689],{"sys":4688,"name":3901},{"id":3900},{"sys":4690,"name":3905},{"id":3904},{"items":4692},[4693],{"fullName":439,"firstName":440,"jobTitle":441,"profilePicture":4694},{"url":445},"the-top-10-browser-security-solutions-in-2026","blog\u002Fthe-top-10-browser-security-solutions-in-2026",{"json":4698},{"data":4699,"content":4700,"nodeType":934},{},[4701],{"data":4702,"content":4703,"nodeType":458},{},[4704],{"data":4705,"marks":4706,"value":4707,"nodeType":457},{},[],"Your guide to browser security vendors in 2026. Understand the different approaches to browser security and the vendors that are leading the respective categories, and how to know which one meets your requirements.","Browser security means a lot of different things depending on who's talking. Here's your guide to the browser security market from a vendor perspective in 2026.",{"id":4710,"publishedAt":4711},"ThcZepauVfA5fKossdkbm","2026-08-26T11:59:28.533Z",{"items":4713},[4714,4716],{"sys":4715,"name":3901},{"id":3900},{"sys":4717,"name":2638},{"id":2637},{"items":4719},[4720,4725,4730,4735],{"sys":4721,"name":4723,"slug":4724,"tier":45},{"id":4722},"topic-enterprise-browser","Enterprise browser","enterprise-browser",{"sys":4726,"name":4728,"slug":4729,"tier":45},{"id":4727},"topic-browser-extensions","Browser extensions","browser-extensions",{"sys":4731,"name":4733,"slug":4734,"tier":31},{"id":4732},"topic-browser-attacks","Browser attacks","browser-attacks",{"sys":4736,"name":3901,"slug":4738,"tier":31},{"id":4737},"topic-browser-security","browser-security","-Hg4gMALdKpPx8YlEIISzDWLW6601qgSiDLjq3smbXM",{"id":4741,"extension":1045,"items":4742,"meta":5148,"stem":5149,"__hash__":5150},"blogTopics\u002Fblogtopics.json",[4743,4752,4761,4770,4778,4787,4793,4799,4805,4814,4823,4832,4840,4848,4857,4865,4874,4883,4889,4897,4906,4915,4924,4933,4941,4950,4959,4968,4977,4986,4994,5003,5012,5020,5029,5037,5046,5054,5063,5071,5080,5088,5096,5104,5112,5121,5130,5139],{"sys":4744,"faqItemsCollection":4746,"name":4748,"slug":4749,"tier":31,"intro":4750,"faqTitle":59,"postCount":4751,"hasPage":19},{"id":4745},"topic-ai",{"items":4747},[],"AI","ai","AI is reshaping both sides of the security equation: employees adopt AI tools faster than security teams can track them, while attackers use AI to scale and automate campaigns. Shadow AI adoption may now outpace wider shadow SaaS, and attackers are already turning AI chatbot platforms into malware delivery channels. Push has researched the offensive potential of computer-using agents and now applies AI agents to its own threat hunting. This hub covers AI as risk, target, and defensive tool.",22,{"sys":4753,"faqItemsCollection":4755,"name":4757,"slug":4758,"tier":45,"intro":4759,"faqTitle":59,"postCount":4760,"hasPage":19},{"id":4754},"topic-ai-attacks",{"items":4756},[],"AI attacks","ai-attacks","AI attacks run in both directions: attackers using AI to scale phishing, malware delivery, and identity attacks, and AI platforms themselves becoming the attack surface. Push has researched how computer-using agents can automate identity attacks, and has seen the poisoned tenant technique it coined used against its own employees in the wild.",23,{"sys":4762,"faqItemsCollection":4764,"name":4766,"slug":4767,"tier":45,"intro":4768,"faqTitle":59,"postCount":4769,"hasPage":19},{"id":4763},"topic-ai-governance",{"items":4765},[],"AI governance","ai-governance","AI governance is how organizations set and enforce rules for workplace AI use — which tools are allowed, what data can enter them, and how to evidence it to regulators. With US, EU, and UK AI regulations converging on obligations most organizations can’t yet meet, Push’s research makes the case that enforcement starts in the browser, where AI tools are actually used.",9,{"sys":4771,"faqItemsCollection":4773,"name":1208,"slug":4775,"tier":45,"intro":4776,"faqTitle":59,"postCount":4777,"hasPage":19},{"id":4772},"topic-aitm",{"items":4774},[],"aitm","Adversary-in-the-middle (AiTM) phishing proxies a real login page through an attacker-controlled site, capturing credentials, MFA codes, and session tokens in real time to bypass multi-factor authentication. Push’s research into kits like Evilginx and Sneaky2FA documents how they evade URL- and signature-based detection — and why analyzing toolkit behavior in the browser catches attacks that blocklists miss.",78,{"sys":4779,"faqItemsCollection":4781,"name":4783,"slug":4784,"tier":45,"intro":4785,"faqTitle":59,"postCount":4786,"hasPage":6},{"id":4780},"topic-bec",{"items":4782},[],"BEC","bec","Business email compromise (BEC) turns a hijacked mailbox into a fraud tool: attackers use mail rules, auto-forwarding, and payment redirection to steal money while staying invisible to the account owner. Alongside a first-hand case study of a BEC attack that nearly cost an engineering firm millions, Push breaks down these mailbox persistence tricks and how to detect them.",4,{"sys":4788,"faqItemsCollection":4789,"name":4733,"slug":4734,"tier":31,"intro":4791,"faqTitle":59,"postCount":4792,"hasPage":19},{"id":4732},{"items":4790},[],"Browser attacks target users through the web pages, sessions, and extensions they rely on every day — bypassing endpoint and network defenses that never see inside the browser. Techniques like AiTM phishing kits, ClickFix-style copy-paste attacks, OAuth consent abuse, malvertising, and browser sync abuse have become a leading path to account takeover. Push researchers analyze these attacks in the wild, from infiltrating criminal phishing panels to dissecting toolkits like ConsentFix and Sneaky2FA. Use this hub to track how the techniques evolve and how to defend against them.",122,{"sys":4794,"faqItemsCollection":4795,"name":4728,"slug":4729,"tier":45,"intro":4797,"faqTitle":59,"postCount":4798,"hasPage":19},{"id":4727},{"items":4796},[],"Browser extensions cut both ways for security teams: malicious or compromised extensions are a growing attack vector, while an extension is also the lightest-weight way to deploy security controls into the browsers employees already use. These posts cover both sides — extension-borne risks like browser sync attacks and the limits of risk scoring, and how Push uses its extension to detect threats and block risky extensions.",31,{"sys":4800,"faqItemsCollection":4801,"name":3901,"slug":4738,"tier":31,"intro":4803,"faqTitle":59,"postCount":4804,"hasPage":19},{"id":4737},{"items":4802},[],"Work now happens in the browser, making browser security — visibility and control at the point where users meet the web — a core layer of enterprise defense. Endpoint, network, and email tools miss attacks that unfold inside the browser session, from AiTM phishing to risky extensions and shadow SaaS. Push has published extensively on choosing between enterprise browsers and browser extensions, using browser telemetry, and making the business case for browser security. Start here for both strategy and hands-on guidance.",129,{"sys":4806,"faqItemsCollection":4808,"name":4810,"slug":4811,"tier":45,"intro":4812,"faqTitle":59,"postCount":4813,"hasPage":19},{"id":4807},"topic-casb",{"items":4809},[],"CASB","casb","Cloud access security brokers (CASBs) govern cloud app usage through API integrations and network proxies — an approach that works for sanctioned apps but struggles with the long tail of shadow SaaS employees adopt on their own. Because every SaaS signup happens in a browser, Push captures that adoption in real time at the point of login, and these posts cover what proxy-based discovery misses.",12,{"sys":4815,"faqItemsCollection":4817,"name":4819,"slug":4820,"tier":45,"intro":4821,"faqTitle":59,"postCount":4822,"hasPage":19},{"id":4816},"topic-clickfix",{"items":4818},[],"ClickFix","clickfix","ClickFix attacks trick users into copying and running malicious commands themselves — typically through fake CAPTCHA, error, or fix-it prompts — so malware executes without a download for security tools to scan. Push researchers track the technique’s evolution in the wild and identified the ConsentFix and InstallFix variants, which extend it to OAuth consent grants and fake install guides.",40,{"sys":4824,"faqItemsCollection":4826,"name":4828,"slug":4829,"tier":45,"intro":4830,"faqTitle":59,"postCount":4831,"hasPage":19},{"id":4825},"topic-credential-phishing",{"items":4827},[],"Credential phishing","credential-phishing","Credential phishing steals usernames and passwords through fake login pages impersonating the services employees use, handing attackers direct access to corporate accounts. Attackers don’t hack in — they log in. Push’s browser extension analyzes login pages as users actually see them, blocking cloned pages and stopping employees from entering company passwords on lookalike sites.",90,{"sys":4833,"faqItemsCollection":4835,"name":308,"slug":4837,"tier":45,"intro":4838,"faqTitle":59,"postCount":4839,"hasPage":19},{"id":4834},"topic-credential-stuffing",{"items":4836},[],"credential-stuffing","Credential stuffing is an attack where criminals replay username-password pairs stolen from one breach against other services, exploiting password reuse to take over accounts. Major breaches have shown how far a single set of stolen credentials can travel. Push detects verified stolen credentials by comparing employee passwords against breach datasets and dark-web threat intelligence, eliminating false positives.",64,{"sys":4841,"faqItemsCollection":4843,"name":2638,"slug":4845,"tier":31,"intro":4846,"faqTitle":59,"postCount":4847,"hasPage":19},{"id":4842},"topic-detection-and-response",{"items":4844},[],"detection-and-response","Detection and response is being reshaped as attacks move into the browser, where EDR, SIEM, and network tools have limited visibility. Modern phishing kits evade signature-based detection, and most malicious pages have never been seen before — so technique-level, in-browser detection matters more than known-bad indicators. Push’s work here spans high-fidelity browser telemetry, session token theft detection, and agentic threat hunting, plus practical IR guidance for compromised SaaS accounts and malicious OAuth apps. These posts cover both the philosophy and the workflows.",102,{"sys":4849,"faqItemsCollection":4851,"name":4853,"slug":4854,"tier":45,"intro":4855,"faqTitle":59,"postCount":4856,"hasPage":19},{"id":4850},"topic-detection-engineering",{"items":4852},[],"Detection engineering","detection-engineering","Detection engineering turns threat research into reliable, high-fidelity detections — and as AI accelerates the churn of attacker infrastructure, indicator-based detection is collapsing in favor of technique-level approaches. Here you’ll find teardowns of AiTM kits, ClickFix pages, and malvertising campaigns, alongside Push’s own account of building an agentic threat hunting pipeline that turns hunts into shipped detections.",43,{"sys":4858,"faqItemsCollection":4860,"name":269,"slug":4862,"tier":45,"intro":4863,"faqTitle":59,"postCount":4864,"hasPage":19},{"id":4859},"topic-device-code-phishing",{"items":4861},[],"device-code-phishing","Device code phishing abuses the OAuth device authorization flow: attackers generate a legitimate sign-in code, trick the victim into entering it on the vendor’s real login page, and walk away with access tokens — no fake site or password capture required. Push research tracked a sharp spike in adoption during 2026 as attackers use the technique to sidestep standard access controls.",24,{"sys":4866,"faqItemsCollection":4868,"name":4870,"slug":4871,"tier":45,"intro":4872,"faqTitle":59,"postCount":4873,"hasPage":19},{"id":4867},"topic-dlp",{"items":4869},[],"DLP","dlp","Data loss prevention (DLP) is the practice of stopping sensitive data from leaving your control — a problem that has shifted from email and endpoints to the browser, where employees move data into SaaS and AI tools. Push applies controls at that point of use, from keeping corporate credentials out of personal password managers to governing what flows into unsanctioned apps.",15,{"sys":4875,"faqItemsCollection":4877,"name":4879,"slug":4880,"tier":45,"intro":4881,"faqTitle":59,"postCount":4882,"hasPage":19},{"id":4876},"topic-edr",{"items":4878},[],"EDR","edr","Endpoint detection and response (EDR) watches processes, files, and memory on the device — a vantage point that never sees the phishing pages, stolen sessions, and identity attacks playing out inside the browser. That’s not an EDR failure; attackers have simply moved where it can’t follow. These posts map that gap and show how Push pairs browser-level detection and response with endpoint security to close it.",25,{"sys":4884,"faqItemsCollection":4885,"name":4723,"slug":4724,"tier":45,"intro":4887,"faqTitle":59,"postCount":4888,"hasPage":19},{"id":4722},{"items":4886},[],"An enterprise browser is a standalone, security-hardened browser that organizations deploy in place of Chrome, Edge, or other defaults. The real buying question is whether replacing the browser beats securing the browsers employees already use — a trade-off these posts examine directly, alongside analysis of Omdia’s secure enterprise browser market report and Push’s framework for weighing full browsers against extension-based deployment.",8,{"sys":4890,"faqItemsCollection":4892,"name":298,"slug":4894,"tier":45,"intro":4895,"faqTitle":59,"postCount":4896,"hasPage":19},{"id":4891},"topic-ghost-logins",{"items":4893},[],"ghost-logins","Ghost logins are overlooked authentication routes into an account — like a password login lingering behind SSO, or a forgotten secondary auth method — that attackers exploit for account takeover and persistence. Push coined the term after research showing how these forgotten login paths let attackers sidestep the MFA and SSO controls guarding an account’s primary sign-in method.",48,{"sys":4898,"faqItemsCollection":4900,"name":4902,"slug":4903,"tier":45,"intro":4904,"faqTitle":59,"postCount":4905,"hasPage":19},{"id":4899},"topic-identity-attacks",{"items":4901},[],"Identity attacks","identity-attacks","Identity attacks target user accounts rather than infrastructure — phishing credentials, stealing sessions, abusing OAuth grants — because logging in is easier than hacking in. Identity-based techniques are now the leading cause of breaches. Push’s offensive research maps these techniques continuously, coining attacks like SAMLjacking and the poisoned tenant before they appeared in the wild.",58,{"sys":4907,"faqItemsCollection":4909,"name":4911,"slug":4912,"tier":31,"intro":4913,"faqTitle":59,"postCount":4914,"hasPage":19},{"id":4908},"topic-identity-security",{"items":4910},[],"Identity security","identity-security","Identity security is the practice of protecting workforce accounts, credentials, and sessions — the primary route attackers now use to breach organizations. Instead of hacking in, attackers log in: through phished credentials, stolen session tokens, MFA bypass, and forgotten ghost logins. Push’s research team documents these techniques continuously, from cross-IdP impersonation and SAMLjacking to analyses of major identity-driven breaches. This hub collects that research alongside practical guidance on MFA, SSO, and stopping account takeover.",154,{"sys":4916,"faqItemsCollection":4918,"name":4920,"slug":4921,"tier":45,"intro":4922,"faqTitle":59,"postCount":4923,"hasPage":19},{"id":4917},"topic-infostealer",{"items":4919},[],"Infostealer","infostealer","Infostealers are malware built to harvest saved passwords, cookies, and session tokens from infected devices, supplying the stolen credentials behind some of the most consequential breaches of recent years. Push traces the ecosystem trading this data and checks employee passwords against threat intel feeds, flagging verified stolen credentials before attackers can log in with them.",53,{"sys":4925,"faqItemsCollection":4927,"name":4929,"slug":4930,"tier":45,"intro":4931,"faqTitle":59,"postCount":4932,"hasPage":19},{"id":4926},"topic-legitimate-service-abuse",{"items":4928},[],"Legitimate service abuse","legitimate-service-abuse","Legitimate service abuse means staging attacks on trusted platforms — Google Ads, AI chatbot share pages, office.com links, Slack, SaaS tenants — so malicious content inherits the reputation of the service hosting it. Push research has documented the pattern repeatedly, from malvertising run through hijacked Google Ad Manager accounts to phishing links generated by Active Directory Federation Services.",29,{"sys":4934,"faqItemsCollection":4936,"name":4938,"slug":4939,"tier":45,"intro":4940,"faqTitle":59,"postCount":4798,"hasPage":19},{"id":4935},"topic-malvertising",{"items":4937},[],"Malvertising","malvertising","Malvertising uses paid search and display ads to put phishing pages and malware in front of users, often by impersonating trusted brands at the top of Google results. Push tracks these campaigns continuously — intercepting live attacks spoofing well-known brands — and has documented how criminals hijack Google Ads accounts to fund and run them.",{"sys":4942,"faqItemsCollection":4944,"name":4946,"slug":4947,"tier":45,"intro":4948,"faqTitle":59,"postCount":4949,"hasPage":19},{"id":4943},"topic-malware-delivery",{"items":4945},[],"Malware delivery","malware-delivery","Malware delivery has moved into the browser: rather than email attachments, attackers now rely on malvertising, fake install guides, and ClickFix-style copy-paste lures to get code running on endpoints. Push research on techniques like InstallFix maps the playbook, and in-browser detection of malicious copy and paste blocks these attacks before commands reach the endpoint.",14,{"sys":4951,"faqItemsCollection":4953,"name":4955,"slug":4956,"tier":45,"intro":4957,"faqTitle":59,"postCount":4958,"hasPage":19},{"id":4952},"topic-mfa",{"items":4954},[],"MFA","mfa","Multi-factor authentication (MFA) requires a second proof of identity beyond a password, and it remains one of the most effective controls against account takeover. Regulators from Cyber Essentials to NYDFS now mandate it across cloud services. Push enforces MFA in the browser on third-party apps — even those with no native enforcement option — and shows security teams where coverage gaps remain.",83,{"sys":4960,"faqItemsCollection":4962,"name":4964,"slug":4965,"tier":45,"intro":4966,"faqTitle":59,"postCount":4967,"hasPage":19},{"id":4961},"topic-mfa-bypass",{"items":4963},[],"MFA bypass","mfa-bypass","MFA bypass covers the techniques attackers use to defeat multi-factor authentication — AiTM phishing kits, consent phishing, device code phishing, and MFA downgrade attacks among them. None of these break the second factor; they route around it. Push researchers regularly get hands-on with phishing kits like Evilginx and Sneaky2FA, analyzing how these attacks work in the wild and how they evolve.",60,{"sys":4969,"faqItemsCollection":4971,"name":4973,"slug":4974,"tier":45,"intro":4975,"faqTitle":59,"postCount":4976,"hasPage":19},{"id":4970},"topic-non-email-phishing",{"items":4972},[],"Non-email phishing","non-email-phishing","Non-email phishing delivers malicious links through channels your secure email gateway never sees — social media messages, IM apps like Slack and Teams, search ads, and SMS. Push has intercepted live campaigns arriving via LinkedIn DMs, malvertising, and messaging platforms, which is why it detects phishing pages in the browser at the point of click, regardless of delivery channel.",52,{"sys":4978,"faqItemsCollection":4980,"name":4982,"slug":4983,"tier":45,"intro":4984,"faqTitle":59,"postCount":4985,"hasPage":19},{"id":4979},"topic-oauth-abuse",{"items":4981},[],"OAuth abuse","oauth-abuse","OAuth abuse is attackers exploiting app-to-app authorization — consent phishing, malicious OAuth apps, stolen tokens, and device code flows — to gain persistent access to cloud tenants without touching a password or MFA prompt. Push tracks these techniques continuously and discovered ConsentFix, a browser-native attack in the wild that pairs OAuth consent phishing with a ClickFix-style prompt.",70,{"sys":4987,"faqItemsCollection":4989,"name":4991,"slug":4992,"tier":45,"intro":4993,"faqTitle":59,"postCount":4760,"hasPage":19},{"id":4988},"topic-passkeys",{"items":4990},[],"Passkeys","passkeys","Passkeys are phishing-resistant credentials that replace passwords with cryptographic key pairs bound to a user’s device. They defeat conventional credential phishing, but attackers adapt: Push research has documented MFA downgrade, app-specific password phishing, and device code phishing being used in the wild to route around passkey-protected accounts. Deploying passkeys is step one; closing those fallback paths is step two.",{"sys":4995,"faqItemsCollection":4997,"name":4999,"slug":5000,"tier":45,"intro":5001,"faqTitle":59,"postCount":5002,"hasPage":19},{"id":4996},"topic-password-security",{"items":4998},[],"Password security","password-security","Password security is the practice of keeping workforce credentials strong, unique, and out of attackers’ hands — still a frontline defense while most SaaS logins depend on passwords. Expiration policies don’t fix weak or reused passwords; visibility does. Push observes real logins in the browser to flag weak, reused, and breached passwords and guide employees to reset them on any app.",80,{"sys":5004,"faqItemsCollection":5006,"name":5008,"slug":5009,"tier":45,"intro":5010,"faqTitle":59,"postCount":5011,"hasPage":19},{"id":5005},"topic-phaas",{"items":5007},[],"PhaaS","phaas","Phishing-as-a-service (PhaaS) platforms sell ready-made phishing kits, hosted infrastructure, and management panels on subscription, letting low-skill criminals run MFA-bypassing campaigns at scale. Kits like Evilginx, Tycoon2FA, Sneaky2FA, FlowerStorm, and EvilTokens each add their own evasion and session-theft capabilities, and new entrants appear regularly. Push researchers continuously get hands-on with these tools — investigating attacks in the wild, reverse-engineering kit behavior, and turning that research into detections.",41,{"sys":5013,"faqItemsCollection":5015,"name":254,"slug":5017,"tier":31,"intro":5018,"faqTitle":59,"postCount":5019,"hasPage":19},{"id":5014},"topic-phishing",{"items":5016},[],"phishing","Phishing remains the most common way attackers compromise business accounts — and it has moved far beyond suspicious emails. Modern campaigns use AiTM toolkits that bypass MFA, consent phishing against OAuth, device code phishing, and lures delivered through malvertising, LinkedIn, and Slack. Push detects and blocks these attacks in the browser, and its researchers publish teardowns of live campaigns and kits like Evilginx and Sneaky2FA. Read on for how phishing actually works today and what stops it.",93,{"sys":5021,"faqItemsCollection":5023,"name":5025,"slug":5026,"tier":45,"intro":5027,"faqTitle":59,"postCount":5028,"hasPage":19},{"id":5022},"topic-public-breach",{"items":5024},[],"Public breach","public-breach","Public breaches are the disclosed incidents that show how attacks actually unfold once the headlines fade. Push’s breach analyses keep finding identity at the entry point: stolen credentials, OAuth abuse, and missing MFA recur across the incidents analyzed here.",30,{"sys":5030,"faqItemsCollection":5032,"name":5034,"slug":5035,"tier":45,"intro":5036,"faqTitle":59,"postCount":4949,"hasPage":19},{"id":5031},"topic-ransomware",{"items":5033},[],"Ransomware","ransomware","Ransomware attacks increasingly begin with an identity, not an exploit: stolen credentials, MFA bypass, and help desk scams give operators their initial foothold. The analysis here follows that front end of the kill chain — how identity compromise leads to ransomware deployment, and the breaches driving regulators toward tighter MFA requirements.",{"sys":5038,"faqItemsCollection":5040,"name":5042,"slug":5043,"tier":31,"intro":5044,"faqTitle":59,"postCount":5045,"hasPage":19},{"id":5039},"topic-saas-security",{"items":5041},[],"SaaS security","saas-security","SaaS security means protecting the sprawl of cloud apps, accounts, and integrations your employees adopt — often without IT ever knowing. Shadow SaaS, risky OAuth grants, ghost logins, and unmanaged third-party access create attack paths traditional controls can’t see, as recent high-profile breaches have demonstrated. Building on the original SaaS attack matrix, Push continues to map SaaS-native attack techniques alongside practical guides for discovering and securing unsanctioned apps, and this hub gathers all of it.",97,{"sys":5047,"faqItemsCollection":5049,"name":5051,"slug":5052,"tier":45,"intro":5053,"faqTitle":59,"postCount":4786,"hasPage":6},{"id":5048},"topic-security-training",{"items":5050},[],"Security training","security-training","Security training aims to teach employees to recognize and avoid attacks — yet modern phishing routinely fools even seasoned security professionals. Push argues that training budgets work harder as real-time, in-browser intervention: guardrails and warnings at the moment of risk, rather than lessons employees must recall under pressure.",{"sys":5055,"faqItemsCollection":5057,"name":5059,"slug":5060,"tier":45,"intro":5061,"faqTitle":59,"postCount":5062,"hasPage":19},{"id":5056},"topic-seo-poisoning",{"items":5058},[],"SEO poisoning","seo-poisoning","SEO poisoning manipulates search engine results so malicious pages rank prominently for the software, tools, or services users are actively searching for, turning a routine search into an infection vector. It often pairs with malvertising and ClickFix-style payloads — Push has documented attackers abusing shared pages on legitimate AI chatbot domains to deliver malware from trusted infrastructure.",7,{"sys":5064,"faqItemsCollection":5066,"name":313,"slug":5068,"tier":45,"intro":5069,"faqTitle":59,"postCount":5070,"hasPage":19},{"id":5065},"topic-session-hijacking",{"items":5067},[],"session-hijacking","Session hijacking is the theft of an authenticated session — usually via stolen session cookies or tokens — letting attackers walk past passwords and MFA into a live account. AiTM phishing kits and infostealers have made it a mainstream attack technique across both criminal and targeted intrusions. Push’s browser agent detects session token theft by adding telemetry to the user agent string, creating a high-fidelity signal for security teams.",75,{"sys":5072,"faqItemsCollection":5074,"name":5076,"slug":5077,"tier":45,"intro":5078,"faqTitle":59,"postCount":5079,"hasPage":19},{"id":5073},"topic-shadow-ai",{"items":5075},[],"Shadow AI","shadow-ai","Shadow AI is employees’ unsanctioned use of AI tools at work, putting corporate data into chatbots and assistants that security teams never approved and can’t see. Push’s own browser telemetry shows AI adoption acting as a force multiplier for shadow IT — potentially now outscaling shadow SaaS — and this hub tracks that research, real-world breach examples, and practical controls.",20,{"sys":5081,"faqItemsCollection":5083,"name":5085,"slug":5086,"tier":45,"intro":5087,"faqTitle":59,"postCount":5070,"hasPage":19},{"id":5082},"topic-shadow-saas",{"items":5084},[],"Shadow SaaS","shadow-saas","Shadow SaaS is the cloud applications employees adopt for work without IT approval, each one creating unmanaged accounts, identities, and data outside your security controls. Push covers the problem end to end — from browser-based SaaS discovery to in-browser app banners and MFA enforcement — alongside breach analyses that show where unmanaged accounts lead.",{"sys":5089,"faqItemsCollection":5091,"name":5093,"slug":5094,"tier":45,"intro":5095,"faqTitle":59,"postCount":5079,"hasPage":19},{"id":5090},"topic-siem",{"items":5092},[],"SIEM","siem","A SIEM is only as good as the telemetry feeding it, and most log sources never see what happens inside the browser — where phishing, session token theft, and account takeover actually play out. Push streams browser-level detections and identity telemetry into SIEMs, and these posts show how that data improves detection fidelity and cuts alert fatigue.",{"sys":5097,"faqItemsCollection":5099,"name":5101,"slug":5102,"tier":45,"intro":5103,"faqTitle":59,"postCount":4967,"hasPage":19},{"id":5098},"topic-social-engineering",{"items":5100},[],"Social engineering","social-engineering","Social engineering is the manipulation of people — through phishing pages, help desk impersonation, vishing calls, and poisoned tenant invites — into handing over access that no exploit could take. Coverage here tracks how threat actors run these plays — drawing on Push’s ongoing investigation of live phishing infrastructure and criminal tooling.",{"sys":5105,"faqItemsCollection":5107,"name":5109,"slug":5110,"tier":31,"intro":5111,"faqTitle":59,"postCount":4786,"hasPage":6},{"id":5106},"topic-supply-chain-security",{"items":5108},[],"Supply chain security","supply-chain-security","Supply chain security extends beyond your own perimeter to the vendors, platforms, and browser extensions your organization depends on. A compromised third party can hand attackers legitimate access — as recent campaigns against SaaS providers have shown. Push’s research examines the browser-extension supply chain in particular: why extension risk scores fail to predict compromise, and how developers can harden extensions against takeover. These posts frame supply chain risk through a browser and identity lens.",{"sys":5113,"faqItemsCollection":5115,"name":5117,"slug":5118,"tier":45,"intro":5119,"faqTitle":59,"postCount":5120,"hasPage":19},{"id":5114},"topic-swg",{"items":5116},[],"SWG","swg","A secure web gateway (SWG) filters and inspects web traffic in transit, sitting in the network path between users and the internet. That position shows you the packet but not the session: Push’s research on AitM phishing kits documents how attackers break the signatures proxies rely on, and these posts explain why phishing detection is moving from the network path into the browser itself.",18,{"sys":5122,"faqItemsCollection":5124,"name":5126,"slug":5127,"tier":45,"intro":5128,"faqTitle":59,"postCount":5129,"hasPage":19},{"id":5123},"topic-third-party-risk",{"items":5125},[],"Third-party risk","third-party-risk","Third-party risk is the exposure your organization inherits from vendors, SaaS providers, and integrations that hold your data or access your tenants — a chain now extended one employee sign-up at a time. This hub collects Push’s breach analyses and guides for assessing OAuth integrations, managing browser extensions, and responding when a supplier is compromised.",44,{"sys":5131,"faqItemsCollection":5133,"name":5135,"slug":5136,"tier":31,"intro":5137,"faqTitle":59,"postCount":5138,"hasPage":19},{"id":5132},"topic-threat-landscape",{"items":5134},[],"Threat landscape","threat-landscape","The enterprise threat landscape is now defined by identity attacks: criminals log in with phished, stolen, or stuffed credentials rather than breaking infrastructure. Threat actors keep proving how effective help desk scams, MFA bypass, and session theft are against well-defended organizations. Drawing on breach analyses, annual phishing trend reviews, and in-the-wild campaign tracking, Push documents how attacker TTPs are shifting. This hub is where to follow those changes.",49,{"sys":5140,"faqItemsCollection":5142,"name":5144,"slug":5145,"tier":45,"intro":5146,"faqTitle":59,"postCount":5147,"hasPage":19},{"id":5141},"topic-vishing",{"items":5143},[],"Vishing","vishing","Vishing — voice phishing — uses phone calls to impersonate IT support, help desks, or employees, talking targets into password resets, MFA approvals, or opening attacker-controlled pages. Threat actors now routinely pair calls with AiTM phishing to hijack SSO accounts, a chain Push has analyzed across campaigns targeting hundreds of organizations.",16,{},"blogtopics","9aR-7_LhDkRRXRaED83WYgKvhxkN_ODLJNuDH339OG0",1789500287885]