[{"data":1,"prerenderedAt":25054},["ShallowReactive",2],{"application-flags":3,"navbar":7,"always-visible-banner":36,"navbar-about-highlight":108,"navbar-resource-highlight":182,"blog-topics":226,"trust-badges":657,"solution-nav":678,"fa-icon-sharp-regular-faFishingRod":813,"fa-icon-solid-faUserSecret":817,"fa-icon-sharp-regular-faLaptopCode":819,"fa-icon-solid-faTabletScreenButton":821,"fa-icon-solid-faThumbsUp":823,"fa-icon-solid-faPlugCircleXmark":825,"fa-icon-sharp-regular-faPuzzlePiece":827,"fa-icon-solid-faFileCircleXmark":829,"fa-icon-solid-faGhost":832,"fa-icon-solid-faQrcode":835,"fa-icon-solid-faCookieBite":837,"fa-icon-sharp-regular-faUserSecret":839,"fa-icon-sharp-regular-faRadar":841,"fa-icon-sharp-regular-faSatelliteDish":843,"fa-icon-sharp-regular-faShieldCheck":845,"fa-icon-sharp-regular-faBrainCircuit":847,"fa-icon-solid-faMobileScreenButton":849,"fa-icon-brands-faChrome":851,"fa-icon-solid-faDisplay":853,"fa-icon-solid-faFilter":855,"fa-icon-solid-faCloudArrowUp":857,"blog-topic-enterprise-browser":859},[4],{"name":5,"enabled":6},"maintenanceMode",false,[8],{"createdDate":9,"id":10,"name":11,"modelId":12,"published":13,"meta":14,"query":22,"data":23,"variations":28,"lastUpdated":29,"firstPublished":30,"testRatio":31,"createdBy":32,"lastUpdatedBy":33,"folders":34,"rev":35},1742208588866,"1c7a4e423bf54ac1a328bb4063459ef2","Banner","1c6207a5f24948ab82d4a0b17f251193","published",{"breakpoints":15,"hasAutosaves":19,"kind":20,"lastPreviewUrl":21},{"medium":16,"small":17,"xsmall":18},768,640,320,true,"data","",[],{"link":24,"text":25,"type":26,"url":27},{},"Get our latest report analyzing browser attack techniques in 2026","web-banner","https:\u002F\u002Fpushsecurity.com\u002Fresources\u002Fbrowser-attacks-report",{},1774258294825,1742208637545,1,"CydmZnOWU1XuAaLhEDCoYNM4Z8W2","jKjF9r5jcvXU8tzZEfFQm31Iyvr2",[],"brvjc1sslx8",{"createdBy":37,"createdDate":38,"data":39,"folders":94,"id":95,"lastUpdated":96,"lastUpdatedBy":97,"meta":98,"modelId":102,"name":103,"published":13,"query":104,"testRatio":31,"variations":105,"firstPublished":106,"stageModifiedSincePublish":6,"rev":107},"ST0tXQM8slWpFrmioqKHmENB2qe2",1774965361051,{"ctaText":40,"text":41,"url":21,"blocks":42,"state":90},"ewrererw","testrfesssssssssss",[43,70,78],{"@type":44,"@version":45,"id":46,"component":47,"responsiveStyles":60},"@builder.io\u002Fsdk:Element",2,"builder-ca12c06a52de41d7b8743da53118cd38",{"name":48,"tag":48,"options":49,"isRSC":59},"TopBannerContent",{"text":50,"ctaText":51,"url":52,"mainText":53,"cta":56},"New Webinar Series: Join John Hammond, Troy Hunt, and Matt Johansen for the State of Browser Attacks","Save Your Spot","https:\u002F\u002Fpushsecurity.com\u002Fwebinar\u002Fstate-of-browser-security",{"content":54,"fontSize":55},"\u003Cp class=\"\">Employees using shadow AI tools? Push blocks them in the browser and enforces your AI policy.\u003C\u002Fp>","text-base",{"content":57,"fontSize":55,"url":58},"\u003Cp class=\"\">Get a free trial →\u003C\u002Fp>","https:\u002F\u002Fpushsecurity.com\u002Flp\u002Fshadow-ai-trial",null,{"large":61},{"display":62,"flexDirection":63,"position":64,"flexShrink":65,"boxSizing":66,"marginTop":67,"marginBottom":67,"fontSize":68,"fontWeight":69},"flex","column","relative","0","border-box",".56rem","1.125rem","700",{"@type":44,"@version":45,"id":71,"component":72,"responsiveStyles":76},"builder-a2e1f4b9f30b464bb814d7f5de5b0aa7",{"name":73,"options":74,"isRSC":59},"Custom Code",{"code":75,"scriptsClientOnly":6},"\u003Cstyle>\n  .top-banner.bg-web-orange{background:rgb(114, 79, 255);}\n\u003C\u002Fstyle>\n",{"large":77},{"display":62,"flexDirection":63,"position":64,"flexShrink":65,"boxSizing":66},{"id":79,"@type":44,"tagName":80,"properties":81,"responsiveStyles":85},"builder-pixel-65og51xnky7","img",{"src":82,"aria-hidden":83,"alt":21,"role":84,"width":65,"height":65},"https:\u002F\u002Fcdn.builder.io\u002Fapi\u002Fv1\u002Fpixel?apiKey=f3a1111ff5be48cdbb123cd9f5795a05","true","presentation",{"large":86},{"height":65,"width":65,"display":87,"opacity":65,"overflow":88,"pointerEvents":89},"block","hidden","none",{"deviceSize":91,"location":92},"large",{"path":21,"query":93},{},[],"fd266d0172cc47429be7ad10f48c99ad",1787595768418,"tFqFyIzyczYOCRogcShKk6KBmEB2",{"breakpoints":99,"hasAutosaves":19,"hasErrors":6,"hasLinks":6,"kind":100,"lastPreviewUrl":101},{"medium":16,"small":17,"xsmall":18},"component","https:\u002F\u002Fpushsecurity.com\u002F?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CcreateProjects%2CsendPullRequests%2CfusionHostingPublish&builder.user.role.name=Designer&builder.user.role.id=creator&builder.cachebust=true&builder.preview=always-visible-banner&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.always-visible-banner=fd266d0172cc47429be7ad10f48c99ad&builder.overrides.fd266d0172cc47429be7ad10f48c99ad=fd266d0172cc47429be7ad10f48c99ad&builder.options.locale=Default","0678d178ec8b41efb8a23c09dba7874d","always visible banner",[],{},1774968080803,"y4fj9dbjb7k",[109,145],{"createdBy":32,"createdDate":110,"data":111,"folders":134,"id":135,"lastUpdated":136,"lastUpdatedBy":32,"meta":137,"modelId":139,"name":140,"published":13,"query":141,"stageModifiedSincePublish":6,"testRatio":31,"variations":142,"firstPublished":143,"rev":144},1776247359804,{"link":112,"testimonial":113,"testimonialLink":133,"type":116},{},{"@type":114,"id":115,"model":116,"value":117},"@builder.io\u002Fcore:Reference","f028f2b685bb47cd8bf9e82a26dd5a79","testimonial",{"query":118,"folders":119,"createdDate":120,"id":115,"name":121,"modelId":122,"published":13,"data":123,"variations":127,"lastUpdated":128,"firstPublished":129,"testRatio":31,"createdBy":37,"lastUpdatedBy":37,"meta":130,"rev":132},[],[],1735823466309,"We found Push to be more accurate when compared to competitors and the browser agent offered features that others couldn’t match.","42035571a56940ac98bff4544aa79aa5",{"author":124,"jobTitle":125,"quote":121,"image":126},"Jason Waits","\u003Cp>CISO at Inductive Automation\u003C\u002Fp>","https:\u002F\u002Fcdn.builder.io\u002Fapi\u002Fv1\u002Fimage\u002Fassets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Ff04c0c0689ce4a89ac0f0708d78c0a07",{},1735910703862,1735823501152,{"kind":20,"lastPreviewUrl":21,"breakpoints":131,"hasAutosaves":19},{"small":17,"medium":16},"8lr4aug0kgg","\u002Fcustomer-stories\u002Finductive-automation",[],"9136a8f18b3b4a6ba29b8653a99372b1",1776247404986,{"breakpoints":138,"hasAutosaves":6,"kind":20,"lastPreviewUrl":21},{"medium":16,"small":17,"xsmall":18},"20d9eaa352304613b3d1a794b400703d","testimonial-inductive-automation",[],{},1776247404973,"tmziibs9ga9",{"createdBy":32,"createdDate":146,"data":147,"folders":174,"id":175,"lastUpdated":176,"lastUpdatedBy":32,"meta":177,"modelId":139,"name":172,"published":13,"query":179,"stageModifiedSincePublish":6,"testRatio":31,"variations":180,"firstPublished":181,"rev":144},1776255761419,{"description":148,"image":149,"link":150,"testimonial":153,"title":172,"type":173},"Learn about the latest techniques being used in the wild.","https:\u002F\u002Fcdn.builder.io\u002Fapi\u002Fv1\u002Fimage\u002Fassets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F7b4a5ebf81d64e8c9d7fc35f6c96c4a9",{"text":151,"url":152},"Download now","\u002Fresources\u002Fbrowser-attacks-report",{"@type":114,"id":154,"model":116,"value":155},"192acbb1f9ca4cac918c0ec435a8bae3",{"query":156,"folders":157,"createdDate":158,"id":154,"name":159,"modelId":122,"published":13,"data":160,"variations":166,"lastUpdated":167,"firstPublished":168,"testRatio":31,"createdBy":37,"lastUpdatedBy":32,"meta":169,"rev":171},[],[],1728981467463,"Push does for identity what CrowdStrike did for the endpoint",{"video":161,"jobTitle":162,"author":163,"qoute":21,"quote":164,"image":165},"https:\u002F\u002Fcdn.builder.io\u002Fo\u002Fassets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F8b30e8ca50064058bbaef0f3c6164575%2Fcompressed?apiKey=f3a1111ff5be48cdbb123cd9f5795a05&token=8b30e8ca50064058bbaef0f3c6164575&alt=media&optimized=true","\u003Cp>Deputy CISO at Microsoft\u003C\u002Fp>\u003Cp>Former LinkedIn, Slack, Palantir\u003C\u002Fp>","Geoff Belknap","Push does for identity what CrowdStrike did for the endpoint.","https:\u002F\u002Fcdn.builder.io\u002Fapi\u002Fv1\u002Fimage\u002Fassets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F748f0ad0a5064a00a13f4721fcc8dea1",{},1742902158597,1728981782923,{"kind":20,"lastPreviewUrl":21,"breakpoints":170,"hasAutosaves":19},{"small":17,"medium":16},"w423t83vzcq","Report: 2026 Browser Attack Techniques","resource",[],"05a9322735fc427db12e2740e4302300",1776255810913,{"breakpoints":178,"hasAutosaves":6,"kind":20,"lastPreviewUrl":21},{"medium":16,"small":17,"xsmall":18},[],{},1776255810900,[183,205],{"createdBy":32,"createdDate":184,"data":185,"folders":195,"id":196,"lastUpdated":197,"lastUpdatedBy":32,"meta":198,"modelId":200,"name":172,"published":13,"query":201,"stageModifiedSincePublish":6,"testRatio":31,"variations":202,"firstPublished":203,"rev":204},1776256900280,{"description":148,"image":149,"link":186,"testimonial":187,"title":172,"type":173},{"text":151,"url":152},{"@type":114,"id":154,"model":116,"value":188},{"query":189,"folders":190,"createdDate":158,"id":154,"name":159,"modelId":122,"published":13,"data":191,"variations":192,"lastUpdated":167,"firstPublished":168,"testRatio":31,"createdBy":37,"lastUpdatedBy":32,"meta":193,"rev":171},[],[],{"video":161,"jobTitle":162,"author":163,"qoute":21,"quote":164,"image":165},{},{"kind":20,"lastPreviewUrl":21,"breakpoints":194,"hasAutosaves":19},{"small":17,"medium":16},[],"1f429607996e4e5fae8fe3f9b9610e55",1776256937553,{"breakpoints":199,"hasAutosaves":6,"kind":20,"lastPreviewUrl":21},{"medium":16,"small":17,"xsmall":18},"4829faa81e7c4ee8bd2d000e160e8d3c",[],{},1776256937540,"h00i46zz8yj",{"createdBy":32,"createdDate":206,"data":207,"folders":217,"id":218,"lastUpdated":219,"lastUpdatedBy":32,"meta":220,"modelId":200,"name":222,"published":13,"query":223,"stageModifiedSincePublish":6,"testRatio":31,"variations":224,"firstPublished":225,"rev":204},1776256949234,{"link":208,"testimonial":209,"testimonialLink":133,"type":116},{},{"@type":114,"id":115,"model":116,"value":210},{"query":211,"folders":212,"createdDate":120,"id":115,"name":121,"modelId":122,"published":13,"data":213,"variations":214,"lastUpdated":128,"firstPublished":129,"testRatio":31,"createdBy":37,"lastUpdatedBy":37,"meta":215,"rev":132},[],[],{"author":124,"jobTitle":125,"quote":121,"image":126},{},{"kind":20,"lastPreviewUrl":21,"breakpoints":216,"hasAutosaves":19},{"small":17,"medium":16},[],"ce043785b71b4ece98eac811ecf4ba10",1776256974140,{"breakpoints":221,"hasAutosaves":6,"kind":20,"lastPreviewUrl":21},{"medium":16,"small":17,"xsmall":18},"inductive-automation",[],{},1776256974130,{"id":227,"extension":228,"items":229,"meta":654,"stem":655,"__hash__":656},"blogTopics\u002Fblogtopics.json","json",[230,239,248,257,266,275,284,293,302,311,320,329,338,347,356,365,374,383,392,401,410,419,428,437,445,454,463,472,481,490,498,507,516,525,534,542,551,559,568,577,586,594,602,610,618,627,636,645],{"sys":231,"faqItemsCollection":233,"name":235,"slug":236,"tier":31,"intro":237,"faqTitle":59,"postCount":238,"hasPage":19},{"id":232},"topic-ai",{"items":234},[],"AI","ai","AI is reshaping both sides of the security equation: employees adopt AI tools faster than security teams can track them, while attackers use AI to scale and automate campaigns. Shadow AI adoption may now outpace wider shadow SaaS, and attackers are already turning AI chatbot platforms into malware delivery channels. Push has researched the offensive potential of computer-using agents and now applies AI agents to its own threat hunting. This hub covers AI as risk, target, and defensive tool.",22,{"sys":240,"faqItemsCollection":242,"name":244,"slug":245,"tier":45,"intro":246,"faqTitle":59,"postCount":247,"hasPage":19},{"id":241},"topic-ai-attacks",{"items":243},[],"AI attacks","ai-attacks","AI attacks run in both directions: attackers using AI to scale phishing, malware delivery, and identity attacks, and AI platforms themselves becoming the attack surface. Push has researched how computer-using agents can automate identity attacks, and has seen the poisoned tenant technique it coined used against its own employees in the wild.",23,{"sys":249,"faqItemsCollection":251,"name":253,"slug":254,"tier":45,"intro":255,"faqTitle":59,"postCount":256,"hasPage":19},{"id":250},"topic-ai-governance",{"items":252},[],"AI governance","ai-governance","AI governance is how organizations set and enforce rules for workplace AI use — which tools are allowed, what data can enter them, and how to evidence it to regulators. With US, EU, and UK AI regulations converging on obligations most organizations can’t yet meet, Push’s research makes the case that enforcement starts in the browser, where AI tools are actually used.",9,{"sys":258,"faqItemsCollection":260,"name":262,"slug":263,"tier":45,"intro":264,"faqTitle":59,"postCount":265,"hasPage":19},{"id":259},"topic-aitm",{"items":261},[],"AiTM phishing","aitm","Adversary-in-the-middle (AiTM) phishing proxies a real login page through an attacker-controlled site, capturing credentials, MFA codes, and session tokens in real time to bypass multi-factor authentication. Push’s research into kits like Evilginx and Sneaky2FA documents how they evade URL- and signature-based detection — and why analyzing toolkit behavior in the browser catches attacks that blocklists miss.",78,{"sys":267,"faqItemsCollection":269,"name":271,"slug":272,"tier":45,"intro":273,"faqTitle":59,"postCount":274,"hasPage":6},{"id":268},"topic-bec",{"items":270},[],"BEC","bec","Business email compromise (BEC) turns a hijacked mailbox into a fraud tool: attackers use mail rules, auto-forwarding, and payment redirection to steal money while staying invisible to the account owner. Alongside a first-hand case study of a BEC attack that nearly cost an engineering firm millions, Push breaks down these mailbox persistence tricks and how to detect them.",4,{"sys":276,"faqItemsCollection":278,"name":280,"slug":281,"tier":31,"intro":282,"faqTitle":59,"postCount":283,"hasPage":19},{"id":277},"topic-browser-attacks",{"items":279},[],"Browser attacks","browser-attacks","Browser attacks target users through the web pages, sessions, and extensions they rely on every day — bypassing endpoint and network defenses that never see inside the browser. Techniques like AiTM phishing kits, ClickFix-style copy-paste attacks, OAuth consent abuse, malvertising, and browser sync abuse have become a leading path to account takeover. Push researchers analyze these attacks in the wild, from infiltrating criminal phishing panels to dissecting toolkits like ConsentFix and Sneaky2FA. Use this hub to track how the techniques evolve and how to defend against them.",122,{"sys":285,"faqItemsCollection":287,"name":289,"slug":290,"tier":45,"intro":291,"faqTitle":59,"postCount":292,"hasPage":19},{"id":286},"topic-browser-extensions",{"items":288},[],"Browser extensions","browser-extensions","Browser extensions cut both ways for security teams: malicious or compromised extensions are a growing attack vector, while an extension is also the lightest-weight way to deploy security controls into the browsers employees already use. These posts cover both sides — extension-borne risks like browser sync attacks and the limits of risk scoring, and how Push uses its extension to detect threats and block risky extensions.",31,{"sys":294,"faqItemsCollection":296,"name":298,"slug":299,"tier":31,"intro":300,"faqTitle":59,"postCount":301,"hasPage":19},{"id":295},"topic-browser-security",{"items":297},[],"Browser security","browser-security","Work now happens in the browser, making browser security — visibility and control at the point where users meet the web — a core layer of enterprise defense. Endpoint, network, and email tools miss attacks that unfold inside the browser session, from AiTM phishing to risky extensions and shadow SaaS. Push has published extensively on choosing between enterprise browsers and browser extensions, using browser telemetry, and making the business case for browser security. Start here for both strategy and hands-on guidance.",129,{"sys":303,"faqItemsCollection":305,"name":307,"slug":308,"tier":45,"intro":309,"faqTitle":59,"postCount":310,"hasPage":19},{"id":304},"topic-casb",{"items":306},[],"CASB","casb","Cloud access security brokers (CASBs) govern cloud app usage through API integrations and network proxies — an approach that works for sanctioned apps but struggles with the long tail of shadow SaaS employees adopt on their own. Because every SaaS signup happens in a browser, Push captures that adoption in real time at the point of login, and these posts cover what proxy-based discovery misses.",12,{"sys":312,"faqItemsCollection":314,"name":316,"slug":317,"tier":45,"intro":318,"faqTitle":59,"postCount":319,"hasPage":19},{"id":313},"topic-clickfix",{"items":315},[],"ClickFix","clickfix","ClickFix attacks trick users into copying and running malicious commands themselves — typically through fake CAPTCHA, error, or fix-it prompts — so malware executes without a download for security tools to scan. Push researchers track the technique’s evolution in the wild and identified the ConsentFix and InstallFix variants, which extend it to OAuth consent grants and fake install guides.",40,{"sys":321,"faqItemsCollection":323,"name":325,"slug":326,"tier":45,"intro":327,"faqTitle":59,"postCount":328,"hasPage":19},{"id":322},"topic-credential-phishing",{"items":324},[],"Credential phishing","credential-phishing","Credential phishing steals usernames and passwords through fake login pages impersonating the services employees use, handing attackers direct access to corporate accounts. Attackers don’t hack in — they log in. Push’s browser extension analyzes login pages as users actually see them, blocking cloned pages and stopping employees from entering company passwords on lookalike sites.",90,{"sys":330,"faqItemsCollection":332,"name":334,"slug":335,"tier":45,"intro":336,"faqTitle":59,"postCount":337,"hasPage":19},{"id":331},"topic-credential-stuffing",{"items":333},[],"Credential stuffing","credential-stuffing","Credential stuffing is an attack where criminals replay username-password pairs stolen from one breach against other services, exploiting password reuse to take over accounts. Major breaches have shown how far a single set of stolen credentials can travel. Push detects verified stolen credentials by comparing employee passwords against breach datasets and dark-web threat intelligence, eliminating false positives.",64,{"sys":339,"faqItemsCollection":341,"name":343,"slug":344,"tier":31,"intro":345,"faqTitle":59,"postCount":346,"hasPage":19},{"id":340},"topic-detection-and-response",{"items":342},[],"Detection & response","detection-and-response","Detection and response is being reshaped as attacks move into the browser, where EDR, SIEM, and network tools have limited visibility. Modern phishing kits evade signature-based detection, and most malicious pages have never been seen before — so technique-level, in-browser detection matters more than known-bad indicators. Push’s work here spans high-fidelity browser telemetry, session token theft detection, and agentic threat hunting, plus practical IR guidance for compromised SaaS accounts and malicious OAuth apps. These posts cover both the philosophy and the workflows.",102,{"sys":348,"faqItemsCollection":350,"name":352,"slug":353,"tier":45,"intro":354,"faqTitle":59,"postCount":355,"hasPage":19},{"id":349},"topic-detection-engineering",{"items":351},[],"Detection engineering","detection-engineering","Detection engineering turns threat research into reliable, high-fidelity detections — and as AI accelerates the churn of attacker infrastructure, indicator-based detection is collapsing in favor of technique-level approaches. Here you’ll find teardowns of AiTM kits, ClickFix pages, and malvertising campaigns, alongside Push’s own account of building an agentic threat hunting pipeline that turns hunts into shipped detections.",43,{"sys":357,"faqItemsCollection":359,"name":361,"slug":362,"tier":45,"intro":363,"faqTitle":59,"postCount":364,"hasPage":19},{"id":358},"topic-device-code-phishing",{"items":360},[],"Device code phishing","device-code-phishing","Device code phishing abuses the OAuth device authorization flow: attackers generate a legitimate sign-in code, trick the victim into entering it on the vendor’s real login page, and walk away with access tokens — no fake site or password capture required. Push research tracked a sharp spike in adoption during 2026 as attackers use the technique to sidestep standard access controls.",24,{"sys":366,"faqItemsCollection":368,"name":370,"slug":371,"tier":45,"intro":372,"faqTitle":59,"postCount":373,"hasPage":19},{"id":367},"topic-dlp",{"items":369},[],"DLP","dlp","Data loss prevention (DLP) is the practice of stopping sensitive data from leaving your control — a problem that has shifted from email and endpoints to the browser, where employees move data into SaaS and AI tools. Push applies controls at that point of use, from keeping corporate credentials out of personal password managers to governing what flows into unsanctioned apps.",15,{"sys":375,"faqItemsCollection":377,"name":379,"slug":380,"tier":45,"intro":381,"faqTitle":59,"postCount":382,"hasPage":19},{"id":376},"topic-edr",{"items":378},[],"EDR","edr","Endpoint detection and response (EDR) watches processes, files, and memory on the device — a vantage point that never sees the phishing pages, stolen sessions, and identity attacks playing out inside the browser. That’s not an EDR failure; attackers have simply moved where it can’t follow. These posts map that gap and show how Push pairs browser-level detection and response with endpoint security to close it.",25,{"sys":384,"faqItemsCollection":386,"name":388,"slug":389,"tier":45,"intro":390,"faqTitle":59,"postCount":391,"hasPage":19},{"id":385},"topic-enterprise-browser",{"items":387},[],"Enterprise browser","enterprise-browser","An enterprise browser is a standalone, security-hardened browser that organizations deploy in place of Chrome, Edge, or other defaults. The real buying question is whether replacing the browser beats securing the browsers employees already use — a trade-off these posts examine directly, alongside analysis of Omdia’s secure enterprise browser market report and Push’s framework for weighing full browsers against extension-based deployment.",8,{"sys":393,"faqItemsCollection":395,"name":397,"slug":398,"tier":45,"intro":399,"faqTitle":59,"postCount":400,"hasPage":19},{"id":394},"topic-ghost-logins",{"items":396},[],"Ghost logins","ghost-logins","Ghost logins are overlooked authentication routes into an account — like a password login lingering behind SSO, or a forgotten secondary auth method — that attackers exploit for account takeover and persistence. Push coined the term after research showing how these forgotten login paths let attackers sidestep the MFA and SSO controls guarding an account’s primary sign-in method.",48,{"sys":402,"faqItemsCollection":404,"name":406,"slug":407,"tier":45,"intro":408,"faqTitle":59,"postCount":409,"hasPage":19},{"id":403},"topic-identity-attacks",{"items":405},[],"Identity attacks","identity-attacks","Identity attacks target user accounts rather than infrastructure — phishing credentials, stealing sessions, abusing OAuth grants — because logging in is easier than hacking in. Identity-based techniques are now the leading cause of breaches. Push’s offensive research maps these techniques continuously, coining attacks like SAMLjacking and the poisoned tenant before they appeared in the wild.",58,{"sys":411,"faqItemsCollection":413,"name":415,"slug":416,"tier":31,"intro":417,"faqTitle":59,"postCount":418,"hasPage":19},{"id":412},"topic-identity-security",{"items":414},[],"Identity security","identity-security","Identity security is the practice of protecting workforce accounts, credentials, and sessions — the primary route attackers now use to breach organizations. Instead of hacking in, attackers log in: through phished credentials, stolen session tokens, MFA bypass, and forgotten ghost logins. Push’s research team documents these techniques continuously, from cross-IdP impersonation and SAMLjacking to analyses of major identity-driven breaches. This hub collects that research alongside practical guidance on MFA, SSO, and stopping account takeover.",154,{"sys":420,"faqItemsCollection":422,"name":424,"slug":425,"tier":45,"intro":426,"faqTitle":59,"postCount":427,"hasPage":19},{"id":421},"topic-infostealer",{"items":423},[],"Infostealer","infostealer","Infostealers are malware built to harvest saved passwords, cookies, and session tokens from infected devices, supplying the stolen credentials behind some of the most consequential breaches of recent years. Push traces the ecosystem trading this data and checks employee passwords against threat intel feeds, flagging verified stolen credentials before attackers can log in with them.",53,{"sys":429,"faqItemsCollection":431,"name":433,"slug":434,"tier":45,"intro":435,"faqTitle":59,"postCount":436,"hasPage":19},{"id":430},"topic-legitimate-service-abuse",{"items":432},[],"Legitimate service abuse","legitimate-service-abuse","Legitimate service abuse means staging attacks on trusted platforms — Google Ads, AI chatbot share pages, office.com links, Slack, SaaS tenants — so malicious content inherits the reputation of the service hosting it. Push research has documented the pattern repeatedly, from malvertising run through hijacked Google Ad Manager accounts to phishing links generated by Active Directory Federation Services.",29,{"sys":438,"faqItemsCollection":440,"name":442,"slug":443,"tier":45,"intro":444,"faqTitle":59,"postCount":292,"hasPage":19},{"id":439},"topic-malvertising",{"items":441},[],"Malvertising","malvertising","Malvertising uses paid search and display ads to put phishing pages and malware in front of users, often by impersonating trusted brands at the top of Google results. Push tracks these campaigns continuously — intercepting live attacks spoofing well-known brands — and has documented how criminals hijack Google Ads accounts to fund and run them.",{"sys":446,"faqItemsCollection":448,"name":450,"slug":451,"tier":45,"intro":452,"faqTitle":59,"postCount":453,"hasPage":19},{"id":447},"topic-malware-delivery",{"items":449},[],"Malware delivery","malware-delivery","Malware delivery has moved into the browser: rather than email attachments, attackers now rely on malvertising, fake install guides, and ClickFix-style copy-paste lures to get code running on endpoints. Push research on techniques like InstallFix maps the playbook, and in-browser detection of malicious copy and paste blocks these attacks before commands reach the endpoint.",14,{"sys":455,"faqItemsCollection":457,"name":459,"slug":460,"tier":45,"intro":461,"faqTitle":59,"postCount":462,"hasPage":19},{"id":456},"topic-mfa",{"items":458},[],"MFA","mfa","Multi-factor authentication (MFA) requires a second proof of identity beyond a password, and it remains one of the most effective controls against account takeover. Regulators from Cyber Essentials to NYDFS now mandate it across cloud services. Push enforces MFA in the browser on third-party apps — even those with no native enforcement option — and shows security teams where coverage gaps remain.",83,{"sys":464,"faqItemsCollection":466,"name":468,"slug":469,"tier":45,"intro":470,"faqTitle":59,"postCount":471,"hasPage":19},{"id":465},"topic-mfa-bypass",{"items":467},[],"MFA bypass","mfa-bypass","MFA bypass covers the techniques attackers use to defeat multi-factor authentication — AiTM phishing kits, consent phishing, device code phishing, and MFA downgrade attacks among them. None of these break the second factor; they route around it. Push researchers regularly get hands-on with phishing kits like Evilginx and Sneaky2FA, analyzing how these attacks work in the wild and how they evolve.",60,{"sys":473,"faqItemsCollection":475,"name":477,"slug":478,"tier":45,"intro":479,"faqTitle":59,"postCount":480,"hasPage":19},{"id":474},"topic-non-email-phishing",{"items":476},[],"Non-email phishing","non-email-phishing","Non-email phishing delivers malicious links through channels your secure email gateway never sees — social media messages, IM apps like Slack and Teams, search ads, and SMS. Push has intercepted live campaigns arriving via LinkedIn DMs, malvertising, and messaging platforms, which is why it detects phishing pages in the browser at the point of click, regardless of delivery channel.",52,{"sys":482,"faqItemsCollection":484,"name":486,"slug":487,"tier":45,"intro":488,"faqTitle":59,"postCount":489,"hasPage":19},{"id":483},"topic-oauth-abuse",{"items":485},[],"OAuth abuse","oauth-abuse","OAuth abuse is attackers exploiting app-to-app authorization — consent phishing, malicious OAuth apps, stolen tokens, and device code flows — to gain persistent access to cloud tenants without touching a password or MFA prompt. Push tracks these techniques continuously and discovered ConsentFix, a browser-native attack in the wild that pairs OAuth consent phishing with a ClickFix-style prompt.",70,{"sys":491,"faqItemsCollection":493,"name":495,"slug":496,"tier":45,"intro":497,"faqTitle":59,"postCount":247,"hasPage":19},{"id":492},"topic-passkeys",{"items":494},[],"Passkeys","passkeys","Passkeys are phishing-resistant credentials that replace passwords with cryptographic key pairs bound to a user’s device. They defeat conventional credential phishing, but attackers adapt: Push research has documented MFA downgrade, app-specific password phishing, and device code phishing being used in the wild to route around passkey-protected accounts. Deploying passkeys is step one; closing those fallback paths is step two.",{"sys":499,"faqItemsCollection":501,"name":503,"slug":504,"tier":45,"intro":505,"faqTitle":59,"postCount":506,"hasPage":19},{"id":500},"topic-password-security",{"items":502},[],"Password security","password-security","Password security is the practice of keeping workforce credentials strong, unique, and out of attackers’ hands — still a frontline defense while most SaaS logins depend on passwords. Expiration policies don’t fix weak or reused passwords; visibility does. Push observes real logins in the browser to flag weak, reused, and breached passwords and guide employees to reset them on any app.",80,{"sys":508,"faqItemsCollection":510,"name":512,"slug":513,"tier":45,"intro":514,"faqTitle":59,"postCount":515,"hasPage":19},{"id":509},"topic-phaas",{"items":511},[],"PhaaS","phaas","Phishing-as-a-service (PhaaS) platforms sell ready-made phishing kits, hosted infrastructure, and management panels on subscription, letting low-skill criminals run MFA-bypassing campaigns at scale. Kits like Evilginx, Tycoon2FA, Sneaky2FA, FlowerStorm, and EvilTokens each add their own evasion and session-theft capabilities, and new entrants appear regularly. Push researchers continuously get hands-on with these tools — investigating attacks in the wild, reverse-engineering kit behavior, and turning that research into detections.",41,{"sys":517,"faqItemsCollection":519,"name":521,"slug":522,"tier":31,"intro":523,"faqTitle":59,"postCount":524,"hasPage":19},{"id":518},"topic-phishing",{"items":520},[],"Phishing","phishing","Phishing remains the most common way attackers compromise business accounts — and it has moved far beyond suspicious emails. Modern campaigns use AiTM toolkits that bypass MFA, consent phishing against OAuth, device code phishing, and lures delivered through malvertising, LinkedIn, and Slack. Push detects and blocks these attacks in the browser, and its researchers publish teardowns of live campaigns and kits like Evilginx and Sneaky2FA. Read on for how phishing actually works today and what stops it.",93,{"sys":526,"faqItemsCollection":528,"name":530,"slug":531,"tier":45,"intro":532,"faqTitle":59,"postCount":533,"hasPage":19},{"id":527},"topic-public-breach",{"items":529},[],"Public breach","public-breach","Public breaches are the disclosed incidents that show how attacks actually unfold once the headlines fade. Push’s breach analyses keep finding identity at the entry point: stolen credentials, OAuth abuse, and missing MFA recur across the incidents analyzed here.",30,{"sys":535,"faqItemsCollection":537,"name":539,"slug":540,"tier":45,"intro":541,"faqTitle":59,"postCount":453,"hasPage":19},{"id":536},"topic-ransomware",{"items":538},[],"Ransomware","ransomware","Ransomware attacks increasingly begin with an identity, not an exploit: stolen credentials, MFA bypass, and help desk scams give operators their initial foothold. The analysis here follows that front end of the kill chain — how identity compromise leads to ransomware deployment, and the breaches driving regulators toward tighter MFA requirements.",{"sys":543,"faqItemsCollection":545,"name":547,"slug":548,"tier":31,"intro":549,"faqTitle":59,"postCount":550,"hasPage":19},{"id":544},"topic-saas-security",{"items":546},[],"SaaS security","saas-security","SaaS security means protecting the sprawl of cloud apps, accounts, and integrations your employees adopt — often without IT ever knowing. Shadow SaaS, risky OAuth grants, ghost logins, and unmanaged third-party access create attack paths traditional controls can’t see, as recent high-profile breaches have demonstrated. Building on the original SaaS attack matrix, Push continues to map SaaS-native attack techniques alongside practical guides for discovering and securing unsanctioned apps, and this hub gathers all of it.",97,{"sys":552,"faqItemsCollection":554,"name":556,"slug":557,"tier":45,"intro":558,"faqTitle":59,"postCount":274,"hasPage":6},{"id":553},"topic-security-training",{"items":555},[],"Security training","security-training","Security training aims to teach employees to recognize and avoid attacks — yet modern phishing routinely fools even seasoned security professionals. Push argues that training budgets work harder as real-time, in-browser intervention: guardrails and warnings at the moment of risk, rather than lessons employees must recall under pressure.",{"sys":560,"faqItemsCollection":562,"name":564,"slug":565,"tier":45,"intro":566,"faqTitle":59,"postCount":567,"hasPage":19},{"id":561},"topic-seo-poisoning",{"items":563},[],"SEO poisoning","seo-poisoning","SEO poisoning manipulates search engine results so malicious pages rank prominently for the software, tools, or services users are actively searching for, turning a routine search into an infection vector. It often pairs with malvertising and ClickFix-style payloads — Push has documented attackers abusing shared pages on legitimate AI chatbot domains to deliver malware from trusted infrastructure.",7,{"sys":569,"faqItemsCollection":571,"name":573,"slug":574,"tier":45,"intro":575,"faqTitle":59,"postCount":576,"hasPage":19},{"id":570},"topic-session-hijacking",{"items":572},[],"Session hijacking","session-hijacking","Session hijacking is the theft of an authenticated session — usually via stolen session cookies or tokens — letting attackers walk past passwords and MFA into a live account. AiTM phishing kits and infostealers have made it a mainstream attack technique across both criminal and targeted intrusions. Push’s browser agent detects session token theft by adding telemetry to the user agent string, creating a high-fidelity signal for security teams.",75,{"sys":578,"faqItemsCollection":580,"name":582,"slug":583,"tier":45,"intro":584,"faqTitle":59,"postCount":585,"hasPage":19},{"id":579},"topic-shadow-ai",{"items":581},[],"Shadow AI","shadow-ai","Shadow AI is employees’ unsanctioned use of AI tools at work, putting corporate data into chatbots and assistants that security teams never approved and can’t see. Push’s own browser telemetry shows AI adoption acting as a force multiplier for shadow IT — potentially now outscaling shadow SaaS — and this hub tracks that research, real-world breach examples, and practical controls.",20,{"sys":587,"faqItemsCollection":589,"name":591,"slug":592,"tier":45,"intro":593,"faqTitle":59,"postCount":576,"hasPage":19},{"id":588},"topic-shadow-saas",{"items":590},[],"Shadow SaaS","shadow-saas","Shadow SaaS is the cloud applications employees adopt for work without IT approval, each one creating unmanaged accounts, identities, and data outside your security controls. Push covers the problem end to end — from browser-based SaaS discovery to in-browser app banners and MFA enforcement — alongside breach analyses that show where unmanaged accounts lead.",{"sys":595,"faqItemsCollection":597,"name":599,"slug":600,"tier":45,"intro":601,"faqTitle":59,"postCount":585,"hasPage":19},{"id":596},"topic-siem",{"items":598},[],"SIEM","siem","A SIEM is only as good as the telemetry feeding it, and most log sources never see what happens inside the browser — where phishing, session token theft, and account takeover actually play out. Push streams browser-level detections and identity telemetry into SIEMs, and these posts show how that data improves detection fidelity and cuts alert fatigue.",{"sys":603,"faqItemsCollection":605,"name":607,"slug":608,"tier":45,"intro":609,"faqTitle":59,"postCount":471,"hasPage":19},{"id":604},"topic-social-engineering",{"items":606},[],"Social engineering","social-engineering","Social engineering is the manipulation of people — through phishing pages, help desk impersonation, vishing calls, and poisoned tenant invites — into handing over access that no exploit could take. Coverage here tracks how threat actors run these plays — drawing on Push’s ongoing investigation of live phishing infrastructure and criminal tooling.",{"sys":611,"faqItemsCollection":613,"name":615,"slug":616,"tier":31,"intro":617,"faqTitle":59,"postCount":274,"hasPage":6},{"id":612},"topic-supply-chain-security",{"items":614},[],"Supply chain security","supply-chain-security","Supply chain security extends beyond your own perimeter to the vendors, platforms, and browser extensions your organization depends on. A compromised third party can hand attackers legitimate access — as recent campaigns against SaaS providers have shown. Push’s research examines the browser-extension supply chain in particular: why extension risk scores fail to predict compromise, and how developers can harden extensions against takeover. These posts frame supply chain risk through a browser and identity lens.",{"sys":619,"faqItemsCollection":621,"name":623,"slug":624,"tier":45,"intro":625,"faqTitle":59,"postCount":626,"hasPage":19},{"id":620},"topic-swg",{"items":622},[],"SWG","swg","A secure web gateway (SWG) filters and inspects web traffic in transit, sitting in the network path between users and the internet. That position shows you the packet but not the session: Push’s research on AitM phishing kits documents how attackers break the signatures proxies rely on, and these posts explain why phishing detection is moving from the network path into the browser itself.",18,{"sys":628,"faqItemsCollection":630,"name":632,"slug":633,"tier":45,"intro":634,"faqTitle":59,"postCount":635,"hasPage":19},{"id":629},"topic-third-party-risk",{"items":631},[],"Third-party risk","third-party-risk","Third-party risk is the exposure your organization inherits from vendors, SaaS providers, and integrations that hold your data or access your tenants — a chain now extended one employee sign-up at a time. This hub collects Push’s breach analyses and guides for assessing OAuth integrations, managing browser extensions, and responding when a supplier is compromised.",44,{"sys":637,"faqItemsCollection":639,"name":641,"slug":642,"tier":31,"intro":643,"faqTitle":59,"postCount":644,"hasPage":19},{"id":638},"topic-threat-landscape",{"items":640},[],"Threat landscape","threat-landscape","The enterprise threat landscape is now defined by identity attacks: criminals log in with phished, stolen, or stuffed credentials rather than breaking infrastructure. Threat actors keep proving how effective help desk scams, MFA bypass, and session theft are against well-defended organizations. Drawing on breach analyses, annual phishing trend reviews, and in-the-wild campaign tracking, Push documents how attacker TTPs are shifting. This hub is where to follow those changes.",49,{"sys":646,"faqItemsCollection":648,"name":650,"slug":651,"tier":45,"intro":652,"faqTitle":59,"postCount":653,"hasPage":19},{"id":647},"topic-vishing",{"items":649},[],"Vishing","vishing","Vishing — voice phishing — uses phone calls to impersonate IT support, help desks, or employees, talking targets into password resets, MFA approvals, or opening attacker-controlled pages. Threat actors now routinely pair calls with AiTM phishing to hijack SSO accounts, a chain Push has analyzed across campaigns targeting hundreds of organizations.",16,{},"blogtopics","9aR-7_LhDkRRXRaED83WYgKvhxkN_ODLJNuDH339OG0",[658,662,666,670,674],{"title":659,"logo":660,"createdDate":661},"SOC2","https:\u002F\u002Fcdn.builder.io\u002Fapi\u002Fv1\u002Fimage\u002Fassets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fb6727a5e00004d6e9e69fc3068b8b64c",1784291539953,{"title":663,"logo":664,"createdDate":665},"GDPR","https:\u002F\u002Fcdn.builder.io\u002Fapi\u002Fv1\u002Fimage\u002Fassets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Ffe49f53211674deaa5a6640d929cdf42?format=webp",1784291672535,{"title":667,"logo":668,"createdDate":669},"Cyber essentials","https:\u002F\u002Fcdn.builder.io\u002Fapi\u002Fv1\u002Fimage\u002Fassets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F53558c1045a342a7a28def960cd54ae7?format=webp",1784291702710,{"title":671,"logo":672,"createdDate":673},"ISO IEC 27001","https:\u002F\u002Fcdn.builder.io\u002Fapi\u002Fv1\u002Fimage\u002Fassets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F578a404a61cf45db951a41fe3554d12d",1784291766222,{"title":675,"logo":676,"createdDate":677},"ISO IEC 27701","https:\u002F\u002Fcdn.builder.io\u002Fapi\u002Fv1\u002Fimage\u002Fassets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fbe219844b13242fbba531959579a753c",1784291858848,[679,743,788],{"id":680,"label":681,"text":21,"navIcon":682,"items":683},"stop-browser-based-attacks","Stop browser-based attacks","solid:faShieldHalved",[684,688,693,698,702,707,712,717,722,726,730,735,739],{"title":521,"text":685,"url":686,"navIcon":687},"Detect phishing behaviorally in the browser, regardless of the payload or delivery channel.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fzero-day-phishing","sharp-regular:faFishingRod",{"title":689,"text":690,"url":691,"navIcon":692},"Adversary-in-the-Middle","Detect and block MFA-bypassing AiTM phishing pages in real-time.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fadversary-in-the-middle-attacks","solid:faUserSecret",{"title":694,"text":695,"url":696,"navIcon":697},"ClickFix (and variants)","Intercept malicious copy and paste attacks at the point of interaction.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fclickfix-fix-variants","sharp-regular:faLaptopCode",{"title":361,"text":699,"url":700,"navIcon":701},"Detect and block device code phishing kits designed to get around passkeys.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fdevice-code-phishing","solid:faTabletScreenButton",{"title":703,"text":704,"url":705,"navIcon":706},"Consent phishing","Detect and block malicious OAuth consent grants before access is authorized.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fconsent-phishing","solid:faThumbsUp",{"title":708,"text":709,"url":710,"navIcon":711},"Malicious OAuth integrations","Detect and block the root cause of SaaS supply chain attacks.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fmalicious-oauth-integrations","solid:faPlugCircleXmark",{"title":713,"text":714,"url":715,"navIcon":716},"Malicious browser extensions","Inventory, monitor, and block risky browser extensions.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fmalicious-browser-extensions","sharp-regular:faPuzzlePiece",{"title":718,"text":719,"url":720,"navIcon":721},"Malicious file downloads","Control which files users can download by type, source, and user group.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fmalicious-file-downloads","solid:faFileCircleXmark",{"title":723,"text":724,"url":725,"navIcon":721},"Infostealers","Detect infostealer delivery and respond to a compromise.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Finfostealer-malware",{"title":397,"text":727,"url":728,"navIcon":729},"Surface hidden login paths that bypass SSO and expose accounts.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fghost-logins","solid:faGhost",{"title":731,"text":732,"url":733,"navIcon":734},"Mobile phishing (QR & SMS)","Detect phishing regardless of whether it arrives via email, SMS, or QR code.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fmobile-phishing-qr-code-sms","solid:faQrcode",{"title":334,"text":736,"url":737,"navIcon":738},"Identify reused and compromised credentials across SaaS logins.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fcredential-stuffing","custom:credentialStuffing",{"title":573,"text":740,"url":741,"navIcon":742},"Detect and respond to stolen session token replay with browser session markers.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fsession-hijacking","solid:faCookieBite",{"id":744,"label":745,"text":21,"navIcon":746,"items":747},"achieve-security-outcomes","Achieve security outcomes","solid:faCheckToSlot",[748,753,758,763,768,773,778,783],{"title":749,"text":750,"url":751,"navIcon":752},"Stop account takeover","Stop ATO with stolen credential and compromised token detection.","\u002Fsolution\u002Fachieve-security-outcomes\u002Fstop-account-takeover","sharp-regular:faUserSecret",{"title":754,"text":755,"url":756,"navIcon":757},"Harden unmanaged identities","Harden access paths with visibility, detection, and guardrails.","\u002Fsolution\u002Fachieve-security-outcomes\u002Fharden-unmanaged-identities","sharp-regular:faRadar",{"title":759,"text":760,"url":761,"navIcon":762},"Investigate browser-related incidents","Investigate and respond faster with unique browser telemetry.","\u002Fsolution\u002Fachieve-security-outcomes\u002Finvestigate-browser-related-incidents","sharp-regular:faSatelliteDish",{"title":764,"text":765,"url":766,"navIcon":767},"Secure shadow SaaS","See and control shadow SaaS in the browser.","\u002Fsolution\u002Fachieve-security-outcomes\u002Fsecure-shadow-saas","sharp-regular:faShieldCheck",{"title":769,"text":770,"url":771,"navIcon":772},"Secure AI","See and control AI apps in the browser.","\u002Fsolution\u002Fachieve-security-outcomes\u002Fsecure-ai","sharp-regular:faBrainCircuit",{"title":774,"text":775,"url":776,"navIcon":777},"Secure BYOD","Extend consistent browser-based protection to unmanaged devices.","\u002Fsolution\u002Fachieve-security-outcomes\u002Fsecure-bring-your-own-device","solid:faMobileScreenButton",{"title":779,"text":780,"url":781,"navIcon":782},"Secure Chromebooks","Secure browser activity on Chromebooks without endpoint agents.","\u002Fsolution\u002Fachieve-security-outcomes\u002Fsecure-chromebooks","brands:faChrome",{"title":784,"text":785,"url":786,"navIcon":787},"Investigate and stop data loss","Detect and prevent data loss across AI tools, apps, and sessions.","\u002Fsolution\u002Fachieve-security-outcomes\u002Finvestigate-and-stop-data-loss","custom:investigateAndStopDataLoss",{"id":789,"label":790,"text":21,"navIcon":791,"items":792},"tool-replacements","Tool replacements","solid:faScrewdriverWrench",[793,798,803,808],{"title":794,"text":795,"url":796,"navIcon":797},"Remote browser isolation","Detect attacks that look like normal browsing.","\u002Fsolution\u002Ftool-replacements\u002Fremote-browser-isolation","solid:faDisplay",{"title":799,"text":800,"url":801,"navIcon":802},"Secure web gateways","Detect attacks inside the browser after SWGs allowed the connection.","\u002Fsolution\u002Ftool-replacements\u002Fsecure-web-gateways","solid:faFilter",{"title":804,"text":805,"url":806,"navIcon":807},"Cloud access security broker","Catch browser-based identity threats in real time, not after the fact.","\u002Fsolution\u002Ftool-replacements\u002Fcloud-access-security-broker","solid:faCloudArrowUp",{"title":809,"text":810,"url":811,"navIcon":812},"Security awareness training","Block real phishing instead of training users on simulations.","\u002Fsolution\u002Ftool-replacements\u002Fsecurity-awareness-training","custom:securityAwareness",{"w":814,"h":815,"d":816},448,512,"M284.6 0l91.4 0 0 160-48 0 0-112-36.6 0-203.4 58.1 0 181.9 40 0 0 224-128 0 0-224 40 0 0-218.1 17.4-5 224-64 3.2-.9zM80 336l-32 0 0 128 32 0 0-128zm176 8c0-76.8 64-136 96-152 32 16 96 75.2 96 152 0 32-16 80-64 112l32 40 0 16-128 0 0-16 32-40c-48-32-64-80-64-112zm128-32a24 24 0 1 0 -48 0 24 24 0 1 0 48 0z",{"w":814,"h":815,"d":818},"M171-16c-36.4 0-57.8 58.3-68.3 112L72 96c-13.3 0-24 10.7-24 24s10.7 24 24 24l24 0 0 32c0 17 3.3 33.2 9.3 48l-9.3 0 0 0-20.5 0c-15.2 0-27.5 12.3-27.5 27.5 0 3 .5 5.9 1.4 8.7l28.9 86.6C40.2 379.6 16 428.1 16 482.3 16 498.7 29.3 512 45.7 512l356.6 0c16.4 0 29.7-13.3 29.7-29.7 0-54.2-24.2-102.7-62.3-135.4l28.9-86.6c.9-2.8 1.4-5.7 1.4-8.7 0-15.2-12.3-27.5-27.5-27.5l-20.5 0 0 0-9.3 0c6-14.8 9.3-31 9.3-48l0-32 24 0c13.3 0 24-10.7 24-24s-10.7-24-24-24l-30.7 0c-10.4-53.7-31.9-112-68.3-112-9.6 0-19 3.9-27.5 8.2-8.2 4.1-18.4 7.8-25.5 7.8s-17.3-3.7-25.5-7.8C190-12.1 180.6-16 171-16zm93.7 484.4l-24.8-70.9 27.9-32.5c2.7-3.2 4.2-7.2 4.2-11.4 0-9.7-7.8-17.5-17.5-17.5l-61 0c-9.7 0-17.5 7.8-17.5 17.5 0 4.2 1.5 8.2 4.2 11.4l27.9 32.5-24.8 70.9-57-180.4 35.7 0c18.4 10.2 39.5 16 62 16s43.6-5.8 62-16l35.7 0-57 180.4zM224 256c-34.7 0-64.2-22.1-75.3-53 5.7 3.2 12.3 5 19.3 5l12.4 0c16.5 0 31.1-10.6 36.3-26.2 2.3-7 12.2-7 14.5 0 5.2 15.6 19.9 26.2 36.3 26.2l12.4 0c7 0 13.6-1.8 19.3-5-11.1 30.9-40.6 53-75.3 53z",{"w":17,"h":815,"d":820},"M112 80l416 0 0 224 48 0 0-272-512 0 0 272 48 0 0-224zM48 404.1l0-4.1 544 0 0 4.1-27.9 27.9-488.2 0-27.9-27.9zM592 352l-592 0 0 72 56 56 528 0 56-56 0-72-48 0zM281 169l17-17-33.9-33.9c-6.1 6.1-27.8 27.8-65 65l-17 17c6.1 6.1 27.8 27.8 65 65l17 17 33.9-33.9c-9-9-25-25-48-48l31-31zM393 135l-17-17-33.9 33.9c9 9 25 25 48 48-23 23-39 39-48 48L376 281.9c6.1-6.1 27.8-27.8 65-65l17-17c-6.1-6.1-27.8-27.8-65-65z",{"w":814,"h":815,"d":822},"M0 64C0 28.7 28.7 0 64 0L384 0c35.3 0 64 28.7 64 64l0 384c0 35.3-28.7 64-64 64L64 512c-35.3 0-64-28.7-64-64L0 64zM256 432a32 32 0 1 0 -64 0 32 32 0 1 0 64 0zM384 64l-320 0 0 288 320 0 0-288z",{"w":815,"h":815,"d":824},"M80 160c17.7 0 32 14.3 32 32l0 256c0 17.7-14.3 32-32 32l-48 0c-17.7 0-32-14.3-32-32L0 192c0-17.7 14.3-32 32-32l48 0zM270.6 16C297.9 16 320 38.1 320 65.4l0 4.2c0 6.8-1.3 13.6-3.8 19.9L288 160 448 160c26.5 0 48 21.5 48 48 0 19.7-11.9 36.6-28.9 44 17 7.4 28.9 24.3 28.9 44 0 23.4-16.8 42.9-39 47.1 4.4 7.3 7 15.8 7 24.9 0 22.2-15 40.8-35.4 46.3 2.2 5.5 3.4 11.5 3.4 17.7 0 26.5-21.5 48-48 48l-87.9 0c-36.3 0-71.6-12.4-99.9-35.1L184 435.2c-15.2-12.1-24-30.5-24-50l0-186.6c0-14.9 3.5-29.6 10.1-42.9L226.3 43.3C234.7 26.6 251.8 16 270.6 16z",{"w":17,"h":815,"d":826},"M192-32c17.7 0 32 14.3 32 32l0 96 128 0 0-96c0-17.7 14.3-32 32-32s32 14.3 32 32l0 96 64 0c17.7 0 32 14.3 32 32s-14.3 32-32 32l0 48.7c-98.6 8.1-176 90.7-176 191.3 0 27.3 5.7 53.3 16 76.9l0 3.1c0 17.7-14.3 32-32 32s-32-14.3-32-32l0-66.7C165.2 398.1 96 319.1 96 224l0-64c-17.7 0-32-14.3-32-32S78.3 96 96 96l64 0 0-96c0-17.7 14.3-32 32-32zM496 256a144 144 0 1 1 0 288 144 144 0 1 1 0-288zm59.3 107.3c6.2-6.2 6.2-16.4 0-22.6s-16.4-6.2-22.6 0l-36.7 36.7-36.7-36.7c-6.2-6.2-16.4-6.2-22.6 0s-6.2 16.4 0 22.6l36.7 36.7-36.7 36.7c-6.2 6.2-6.2 16.4 0 22.6s16.4 6.2 22.6 0l36.7-36.7 36.7 36.7c6.2 6.2 16.4 6.2 22.6 0s6.2-16.4 0-22.6l-36.7-36.7 36.7-36.7z",{"w":815,"h":815,"d":828},"M201.1 57.3c-7 5.3-9.1 10.7-9.1 14.7 0 4.5 2.8 11.2 12.4 16.9l11.6 7 0 48.1-168 0 0 60.5c7.4-2.9 15.5-4.5 24-4.5 43.1 0 72 39.4 72 80s-28.9 80-72 80c-8.5 0-16.6-1.6-24-4.5l0 108.5 108.5 0c-2.9-7.4-4.5-15.5-4.5-24 0-43.1 39.4-72 80-72s80 28.9 80 72c0 8.5-1.6 16.6-4.5 24l60.5 0 0-168 48.1 0 7 11.6c5.8 9.6 12.4 12.4 16.9 12.4 4 0 9.5-2.1 14.7-9.1s9.3-17.9 9.3-30.9-4-23.8-9.3-30.9-10.7-9.1-14.7-9.1c-4.5 0-11.2 2.8-16.9 12.4l-7 11.6-48.1 0 0-120-120 0 0-48.1 11.6-7c9.6-5.8 12.4-12.4 12.4-16.9 0-4-2.1-9.5-9.1-14.7S245 48 232 48 208.2 52 201.1 57.3zM172.3 18.9C188.5 6.8 209.6 0 232 0S275.5 6.8 291.7 18.9 320 49.5 320 72c0 8.6-1.8 16.7-4.9 24l100.9 0 0 100.9c7.3-3.1 15.4-4.9 24-4.9 22.5 0 41 12.2 53.1 28.3s18.9 37.3 18.9 59.7-6.8 43.5-18.9 59.7-30.6 28.3-53.1 28.3c-8.6 0-16.7-1.8-24-4.9l0 148.9-168 0 0-49.3 8.2-7.2c5.4-4.7 7.8-10.3 7.8-15.5 0-9.9-10.7-24-32-24s-32 14.1-32 24c0 5.3 2.4 10.8 7.8 15.5l8.2 7.2 0 49.3-216 0 0-216 49.3 0 7.2 8.2c4.7 5.4 10.3 7.8 15.5 7.8 9.9 0 24-10.7 24-32s-14.1-32-24-32c-5.3 0-10.8 2.4-15.5 7.8L49.3 264 0 264 0 96 148.9 96c-3.1-7.3-4.9-15.4-4.9-24 0-22.5 12.2-41 28.3-53.1z",{"w":830,"h":815,"d":831},576,"M96 0C60.7 0 32 28.7 32 64l0 384c0 35.3 28.7 64 64 64l180 0c-22.7-31.5-36-70.2-36-112 0-100.6 77.4-183.2 176-191.3l0-38.1c0-17-6.7-33.3-18.7-45.3L290.7 18.7C278.7 6.7 262.5 0 245.5 0L96 0zM357.5 176L264 176c-13.3 0-24-10.7-24-24L240 58.5 357.5 176zM432 544a144 144 0 1 0 0-288 144 144 0 1 0 0 288zm59.3-180.7l-36.7 36.7 36.7 36.7c6.2 6.2 6.2 16.4 0 22.6s-16.4 6.2-22.6 0l-36.7-36.7-36.7 36.7c-6.2 6.2-16.4 6.2-22.6 0s-6.2-16.4 0-22.6l36.7-36.7-36.7-36.7c-6.2-6.2-6.2-16.4 0-22.6s16.4-6.2 22.6 0l36.7 36.7 36.7-36.7c6.2-6.2 16.4-6.2 22.6 0s6.2 16.4 0 22.6z",{"w":833,"h":815,"d":834},384,"M40.1 467.1l-11.2 9C25.7 478.6 21.8 480 17.8 480 8 480 0 472 0 462.2L0 192C0 86 86 0 192 0S384 86 384 192l0 270.2c0 9.8-8 17.8-17.8 17.8-4 0-7.9-1.4-11.1-3.9l-11.2-9c-13.4-10.7-32.8-9-44.1 3.9L269.3 506c-3.3 3.8-8.2 6-13.3 6s-9.9-2.2-13.3-6l-26.6-30.5c-12.7-14.6-35.4-14.6-48.2 0L141.3 506c-3.3 3.8-8.2 6-13.3 6s-9.9-2.2-13.3-6L84.2 471c-11.3-12.9-30.7-14.6-44.1-3.9zM160 192a32 32 0 1 0 -64 0 32 32 0 1 0 64 0zm96 32a32 32 0 1 0 0-64 32 32 0 1 0 0 64z",{"w":814,"h":815,"d":836},"M64 160l64 0 0-64-64 0 0 64zM0 80C0 53.5 21.5 32 48 32l96 0c26.5 0 48 21.5 48 48l0 96c0 26.5-21.5 48-48 48l-96 0c-26.5 0-48-21.5-48-48L0 80zM64 416l64 0 0-64-64 0 0 64zM0 336c0-26.5 21.5-48 48-48l96 0c26.5 0 48 21.5 48 48l0 96c0 26.5-21.5 48-48 48l-96 0c-26.5 0-48-21.5-48-48l0-96zM320 96l0 64 64 0 0-64-64 0zM304 32l96 0c26.5 0 48 21.5 48 48l0 96c0 26.5-21.5 48-48 48l-96 0c-26.5 0-48-21.5-48-48l0-96c0-26.5 21.5-48 48-48zM288 352a32 32 0 1 1 0-64 32 32 0 1 1 0 64zm0 64c17.7 0 32 14.3 32 32s-14.3 32-32 32-32-14.3-32-32 14.3-32 32-32zm96 32c0-17.7 14.3-32 32-32s32 14.3 32 32-14.3 32-32 32-32-14.3-32-32zm32-96a32 32 0 1 1 0-64 32 32 0 1 1 0 64zm-32 32a32 32 0 1 1 -64 0 32 32 0 1 1 64 0z",{"w":815,"h":815,"d":838},"M257.5 27.6c-.8-5.4-4.9-9.8-10.3-10.6-22.1-3.1-44.6 .9-64.4 11.4l-74 39.5C89.1 78.4 73.2 94.9 63.4 115L26.7 190.6c-9.8 20.1-13 42.9-9.1 64.9l14.5 82.8c3.9 22.1 14.6 42.3 30.7 57.9l60.3 58.4c16.1 15.6 36.6 25.6 58.7 28.7l83 11.7c22.1 3.1 44.6-.9 64.4-11.4l74-39.5c19.7-10.5 35.6-27 45.4-47.2l36.7-75.5c9.8-20.1 13-42.9 9.1-64.9-.9-5.3-5.3-9.3-10.6-10.1-51.5-8.2-92.8-47.1-104.5-97.4-1.8-7.6-8-13.4-15.7-14.6-54.6-8.7-97.7-52-106.2-106.8zM208 144a32 32 0 1 1 0 64 32 32 0 1 1 0-64zM144 336a32 32 0 1 1 64 0 32 32 0 1 1 -64 0zm224-64a32 32 0 1 1 0 64 32 32 0 1 1 0-64z",{"w":814,"h":815,"d":840},"M144-16l-48 112-48 0 0 48 48 0 0 32c0 17 3.3 33.2 9.3 48l-73.3 0 0 32 5.3 16 26.7 80-64 160 51.7 0 56.9-142.2 6.5-16.3c-1-3.1-10.1-30.3-27.2-81.5l51.4 0c22.6 19.9 52.2 32 84.7 32s62.1-12.1 84.7-32l51.4 0c-17.1 51.2-26.1 78.4-27.2 81.5l6.5 16.3 56.9 142.2 51.7 0-64-160 26.7-80 5.3-16 0-32-73.3 0c6-14.8 9.3-31 9.3-48l0-32 48 0 0-48-48 0-48-112-32 0-48 32-48-32-32 0zm80 272c-32.8 0-61-19.7-73.3-48l57.3 0 16-40 16 40 57.3 0c-12.3 28.3-40.5 48-73.3 48zm17.5 139.6l30.5-35.6 0-24-96 0 0 24 30.5 35.6-46.5 116.4 128 0-46.5-116.4z",{"w":815,"h":815,"d":842},"M497.4 49l17-17-33.9-33.9C473.6 4.9 453.3 25.2 419.7 58.8 375.4 22.1 318.5 0 256.4 0 115.1 0 .4 114.6 .4 256s114.6 256 256 256 256-114.6 256-256l-48 0c0 114.9-93.1 208-208 208s-208-93.1-208-208 93.1-208 208-208c48.8 0 93.7 16.8 129.1 44.9l-45.7 45.7c-23.5-16.8-52.3-26.6-83.4-26.6-79.5 0-144 64.5-144 144s64.5 144 144 144 144-64.5 144-144l-48 0c0 53-43 96-96 96s-96-43-96-96 43-96 96-96c17.8 0 34.5 4.8 48.8 13.3-52 52-79.5 79.5-82.7 82.7l33.9 33.9 17-17 224-224z",{"w":815,"h":815,"d":844},"M208 0l24 0C386.6 0 512 125.4 512 280l0 24-48 0 0-24C464 151.9 360.1 48 232 48l-24 0 0-48zm24 96c101.6 0 184 82.4 184 184l0 24-48 0 0-24c0-75.1-60.9-136-136-136l-24 0 0-48 24 0zM48 256c0 114.9 93.1 208 208 208 22.9 0 45-3.7 65.6-10.5l-263-263C51.7 211 48 233.1 48 256zM0 256c0-36.5 7.6-71.3 21.4-102.7 6.7-15.3 14.9-29.9 24.4-43.5 7.7 7.7 61.5 61.5 161.2 161.2 30.5-30.5 49.5-49.5 57-57L297.9 248c-7.5 7.5-26.5 26.5-57 57 99.7 99.7 153.5 153.5 161.2 161.2-13.6 9.5-28.2 17.7-43.5 24.4-31.4 13.8-66.2 21.4-102.7 21.4-141.4 0-256-114.6-256-256z",{"w":815,"h":815,"d":846},"M267.6 4.5l207.5 80.5 19.2 7.4 1.2 20.5c2.9 50-4.9 126.3-37.3 200.9-32.7 75.2-91.1 150-189.4 192.5l-12.7 5.5-12.7-5.5C144.9 463.9 86.6 389.2 53.9 313.9 21.5 239.3 13.7 162.9 16.6 113L17.8 92.5 37 85 244.5 4.5 256 0 267.6 4.5zM64.1 126C63.1 169.5 71 232.9 97.9 294.8 126.1 359.7 175 422.4 256 459.6 337.1 422.4 385.9 359.7 414.2 294.8 441 232.9 449 169.5 448 126L256 51.5 64.1 126zm302.3 44.7L352.3 190.1 249.8 330.9 233 354c-8.8-9.1-30.9-32-66.2-68.6l-16.7-17.3 34.5-33.3c9.5 9.8 23.9 24.7 43.2 44.7l85.6-117.7 14.1-19.4 38.8 28.2z",{"w":815,"h":815,"d":848},"M192 48l40 0 0 108-12.4 0c-7.6-16.5-24.3-28-43.6-28-26.5 0-48 21.5-48 48s21.5 48 48 48c19.4 0 36.1-11.5 43.6-28l12.4 0 0 56-92 0 0 56.4c-16.5 7.6-28 24.3-28 43.6 0 26.5 21.5 48 48 48s48-21.5 48-48c0-19.4-11.5-36.1-28-43.6l0-16.4 52 0 0 172-40 0c-16.8 0-31.2-10.3-37.1-25.1l-6.4-16-17.2 1c-1.1 .1-2.2 .1-3.2 .1-30.9 0-56-25.1-56-56 0-9.5 2.4-18.5 6.5-26.3l8.7-16.2-13.4-12.6c-11-10.2-17.8-24.8-17.8-40.9 0-21.6 12.2-40.4 30.3-49.8l22.6-11.7-13.1-21.9c-5-8.4-7.9-18.1-7.9-28.6 0-30.9 25.1-56 56-56l24 0 0-32c0-13.3 10.7-24 24-24zm88 148l12.4 0c7.6 16.5 24.3 28 43.6 28 26.5 0 48-21.5 48-48s-21.5-48-48-48c-19.4 0-36.1 11.5-43.6 28l-12.4 0 0-108 40 0c13.3 0 24 10.7 24 24l0 32 24 0c30.9 0 56 25.1 56 56 0 10.5-2.9 20.3-7.9 28.6l-13.1 21.9 22.6 11.7c18 9.3 30.3 28.1 30.3 49.8 0 16.1-6.8 30.7-17.8 40.9l-13.4 12.6 8.7 16.2c4.2 7.8 6.5 16.7 6.5 26.3 0 30.9-25.1 56-56 56-1.1 0-2.2 0-3.2-.1l-17.2-1-6.4 16C351.2 453.7 336.8 464 320 464l-40 0 0-76 92 0 0-56.4c16.5-7.6 28-24.3 28-43.6 0-26.5-21.5-48-48-48s-48 21.5-48 48c0 19.4 11.5 36.1 28 43.6l0 16.4-52 0 0-152zM192 512l128 0c31.1 0 58.4-16.2 74.1-40.5 52.7-5.1 93.9-49.5 93.9-103.5 0-11.5-1.9-22.5-5.3-32.9 13.4-17.5 21.3-39.4 21.3-63.1 0-32-14.5-60.6-37.1-79.7 3.3-10.2 5.1-21.1 5.1-32.3 0-49.6-34.8-91.1-81.3-101.5-6.3-33.3-35.6-58.5-70.7-58.5L192 0c-35.1 0-64.4 25.2-70.7 58.5-46.5 10.4-81.3 51.9-81.3 101.5 0 11.3 1.8 22.2 5.1 32.3-22.7 19.1-37.1 47.7-37.1 79.7 0 23.7 8 45.6 21.3 63.1-3.5 10.4-5.3 21.4-5.3 32.9 0 54 41.2 98.5 93.9 103.5 15.6 24.3 42.9 40.5 74.1 40.5zM336 192a16 16 0 1 1 0-32 16 16 0 1 1 0 32zm32 96a16 16 0 1 1 -32 0 16 16 0 1 1 32 0zM176 352a16 16 0 1 1 -32 0 16 16 0 1 1 32 0zm16-176a16 16 0 1 1 -32 0 16 16 0 1 1 32 0z",{"w":833,"h":815,"d":850},"M16 64C16 28.7 44.7 0 80 0L304 0c35.3 0 64 28.7 64 64l0 384c0 35.3-28.7 64-64 64L80 512c-35.3 0-64-28.7-64-64L16 64zm64 0l0 304 224 0 0-304-224 0zM192 472c17.7 0 32-14.3 32-32s-14.3-32-32-32-32 14.3-32 32 14.3 32 32 32z",{"w":815,"h":815,"d":852},"M0 256c0-46.6 12.5-90.4 34.3-128.9L144.1 318.3c21.9 39.2 63.8 65.7 111.9 65.7 14.3 0 27.1-2.3 40.8-6.6L220.5 509.6C95.9 492.3 0 385.3 0 256zm365.1 65.6c12.3-19.2 18.9-42.5 18.9-65.6 0-38.2-16.8-72.5-43.3-96l152.7 0c12 29.6 18.6 62.1 18.6 96 0 141.4-114.6 255.1-256 256L365.1 321.6zM477.8 128L256 128c-62.9 0-113.7 44.1-125.5 102.7L54.2 98.5C101 38.5 174 0 256 0 350.8 0 433.5 51.5 477.8 128zM344 256a88 88 0 1 1 -176 0 88 88 0 1 1 176 0z",{"w":815,"h":815,"d":854},"M448 96l0 256-384 0 0-256 384 0zM64 32C28.7 32 0 60.7 0 96L0 352c0 35.3 28.7 64 64 64l144 0-16 48-72 0c-13.3 0-24 10.7-24 24s10.7 24 24 24l272 0c13.3 0 24-10.7 24-24s-10.7-24-24-24l-72 0-16-48 144 0c35.3 0 64-28.7 64-64l0-256c0-35.3-28.7-64-64-64L64 32z",{"w":815,"h":815,"d":856},"M32 64C19.1 64 7.4 71.8 2.4 83.8S.2 109.5 9.4 118.6L192 301.3 192 416c0 8.5 3.4 16.6 9.4 22.6l64 64c9.2 9.2 22.9 11.9 34.9 6.9S320 492.9 320 480l0-178.7 182.6-182.6c9.2-9.2 11.9-22.9 6.9-34.9S492.9 64 480 64L32 64z",{"w":830,"h":815,"d":858},"M144 480c-79.5 0-144-64.5-144-144 0-63.4 41-117.2 97.9-136.5-1.3-7.7-1.9-15.5-1.9-23.5 0-79.5 64.5-144 144-144 55.4 0 103.5 31.3 127.6 77.1 14.2-8.3 30.8-13.1 48.4-13.1 53 0 96 43 96 96 0 15.7-3.8 30.6-10.5 43.7 44 20.3 74.5 64.7 74.5 116.3 0 70.7-57.3 128-128 128l-304 0zM305 191c-9.4-9.4-24.6-9.4-33.9 0l-72 72c-9.4 9.4-9.4 24.6 0 33.9s24.6 9.4 33.9 0l31-31 0 102.1c0 13.3 10.7 24 24 24s24-10.7 24-24l0-102.1 31 31c9.4 9.4 24.6 9.4 33.9 0s9.4-24.6 0-33.9l-72-72z",[860,3958,8063,11803,14813,18029,20974,24055],{"id":861,"title":862,"authorsCollection":863,"content":871,"extension":228,"faqItemsCollection":1356,"faqTitle":59,"featured":6,"hashTags":59,"meta":1358,"metaTitle":1359,"ogImage":59,"postType":1360,"publishedDate":1361,"relatedBlogPostsCollection":1362,"slug":3916,"stem":3917,"subtitle":59,"summary":3918,"synopsis":3929,"sys":3930,"tagsCollection":3933,"topicsCollection":3939,"__hash__":3957},"blog\u002Fblog\u002Ffrom-iocs-to-ttps-an-agentic-threat-hunting-case-study.json","From IOCs to TTPs: An agentic threat hunting case study",{"items":864},[865],{"fullName":866,"firstName":867,"jobTitle":868,"socialLinks":59,"profilePicture":869},"Kelly Davenport","Kelly","Product Team",{"url":870},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F1hi8bEuVfn5sF57LivAq6d\u002F9a3b82426c697d765e2e450e33a18424\u002Fkelly_profile_pic.jpeg",{"json":872,"links":1295},{"data":873,"content":874,"nodeType":1294},{},[875,884,891,898,905,912,934,941,948,955,964,968,976,995,1001,1018,1034,1051,1067,1074,1081,1088,1094,1101,1108,1115,1122,1128,1148,1163,1170,1177,1184,1191,1198,1205,1211,1218,1225,1232,1239,1246,1253,1260,1267,1274],{"data":876,"content":877,"nodeType":883},{},[878],{"data":879,"marks":880,"value":881,"nodeType":882},{},[],"Every security engineer has a version of this ritual. ","text","paragraph",{"data":885,"content":886,"nodeType":883},{},[887],{"data":888,"marks":889,"value":890,"nodeType":882},{},[],"A new campaign hits the news, and you already hear the question coming, “Are we covered?”",{"data":892,"content":893,"nodeType":883},{},[894],{"data":895,"marks":896,"value":897,"nodeType":882},{},[],"So you read the writeup and quickly do the calculus on whether you can extract meaningful data, something to base a behavioral detection around — or not.",{"data":899,"content":900,"nodeType":883},{},[901],{"data":902,"marks":903,"value":904,"nodeType":882},{},[],"Then the choice is: Send the IOCs you can identify to your blocklists and move on for now, or try to dig deeper. The limitations of the first choice are clear; so are the challenges of the second.",{"data":906,"content":907,"nodeType":883},{},[908],{"data":909,"marks":910,"value":911,"nodeType":882},{},[],"That’s the uncomfortable gap between “We’re aware of this threat” and “We have strong detections around it.”",{"data":913,"content":914,"nodeType":883},{},[915,919,930],{"data":916,"marks":917,"value":918,"nodeType":882},{},[],"Because you already know that the IOCs for a novel browser-based attack are likely outdated the moment you block them. And in the case of a ",{"data":920,"content":922,"nodeType":929},{"uri":921},"https:\u002F\u002Fwww.microsoft.com\u002Fen-us\u002Fsecurity\u002Fblog\u002F2026\u002F03\u002F02\u002Foauth-redirection-abuse-enables-phishing-malware-delivery\u002F",[923],{"data":924,"marks":925,"value":928,"nodeType":882},{},[926],{"type":927},"underline","new technique observed by Microsoft","hyperlink",{"data":931,"marks":932,"value":933,"nodeType":882},{},[]," earlier this year, you’d be right.",{"data":935,"content":936,"nodeType":883},{},[937],{"data":938,"marks":939,"value":940,"nodeType":882},{},[],"In March, Push’s AI agents took a close look at that Microsoft intel, which details a discovered campaign built around a novel OAuth redirect abuse technique used to deliver users to phishing pages under the cover of trusted services’ OAuth flows. ",{"data":942,"content":943,"nodeType":883},{},[944],{"data":945,"marks":946,"value":947,"nodeType":882},{},[],"What we found was indicative of how these attacks rapidly evolve: No matches for the published IOCs across our install base. But a few months later, we got a true positive. Except it was for new lures, new variants, and different IOCs. What hadn’t changed was the underlying attack delivery technique, and that’s what we used to detect a new campaign on Push customer estates.",{"data":949,"content":950,"nodeType":883},{},[951],{"data":952,"marks":953,"value":954,"nodeType":882},{},[],"In this article, we’ll walk through this example as a case study of how agentic threat hunting helps us go beyond IOCs to extract durable behavioral indicators that close the gap between “We’re aware of this threat” and “We’re covered.”",{"data":956,"content":962,"nodeType":963},{"target":957},{"sys":958},{"id":959,"type":960,"linkType":961},"6X7yXNdchH1Qp2tNKRAyVP","Link","Entry",[],"embedded-entry-block",{"data":965,"content":966,"nodeType":967},{},[],"hr",{"data":969,"content":970,"nodeType":975},{},[971],{"data":972,"marks":973,"value":974,"nodeType":882},{},[],"The intel: Novel abuse of OAuth redirects as a phishing delivery mechanism","heading-1",{"data":977,"content":978,"nodeType":883},{},[979,983,991],{"data":980,"marks":981,"value":982,"nodeType":882},{},[],"The technique ",{"data":984,"content":985,"nodeType":929},{"uri":921},[986],{"data":987,"marks":988,"value":990,"nodeType":882},{},[989],{"type":927},"Microsoft documented",{"data":992,"marks":993,"value":994,"nodeType":882},{},[]," back in March is an interesting one. It doesn't steal tokens or abuse consent flows. Instead, it weaponizes the OAuth error-handling path itself — turning trusted identity provider domains into a delivery mechanism for phishing and malware.",{"data":996,"content":1000,"nodeType":963},{"target":997},{"sys":998},{"id":999,"type":960,"linkType":961},"486pfUpMxx15vJupxuiePn",[],{"data":1002,"content":1003,"nodeType":883},{},[1004,1008,1014],{"data":1005,"marks":1006,"value":1007,"nodeType":882},{},[],"Here's how it works. The attacker registers a malicious application in an actor-controlled tenant, pointing its redirect URI at attacker infrastructure. They craft an authorization URL using ",{"data":1009,"marks":1010,"value":1013,"nodeType":882},{},[1011],{"type":1012},"bold","prompt=none",{"data":1015,"marks":1016,"value":1017,"nodeType":882},{},[]," (forcing silent authentication) and an intentionally invalid scope, which guarantees an OAuth error. ",{"data":1019,"content":1020,"nodeType":883},{},[1021,1025,1030],{"data":1022,"marks":1023,"value":1024,"nodeType":882},{},[],"The identity provider — Microsoft Entra ID, Google Workspace, or any OAuth-compliant service — handles that error the way the spec says it should: By redirecting the browser to the application's registered redirect URI. The user clicks a link that begins at ",{"data":1026,"marks":1027,"value":1029,"nodeType":882},{},[1028],{"type":1012},"login.microsoftonline.com",{"data":1031,"marks":1032,"value":1033,"nodeType":882},{},[],", passes through a legitimate authentication endpoint, and lands on an attacker-controlled page.",{"data":1035,"content":1036,"nodeType":883},{},[1037,1041,1047],{"data":1038,"marks":1039,"value":1040,"nodeType":882},{},[],"Importantly, no token is stolen during the redirect. The OAuth flow is the delivery vehicle, not the compromise mechanism. What happens ",{"data":1042,"marks":1043,"value":1046,"nodeType":882},{},[1044],{"type":1045},"italic","after",{"data":1048,"marks":1049,"value":1050,"nodeType":882},{},[]," the redirect — phishing, malware download, credential harvesting — is where the actual attack occurs.",{"data":1052,"content":1053,"nodeType":883},{},[1054,1058,1063],{"data":1055,"marks":1056,"value":1057,"nodeType":882},{},[],"This technique is also successful because conventional URL filtering sees a legitimate authentication domain, not a phishing destination. The redirect is standards-compliant behavior, and the initial URL carries the domain reputation of a trusted identity provider — which means the usual defenses at the network layer don't fire. (No TI or domain-based detection service in the world would raise a ",{"data":1059,"marks":1060,"value":1062,"nodeType":882},{},[1061],{"type":1012},"microsoft.com",{"data":1064,"marks":1065,"value":1066,"nodeType":882},{},[]," domain as suspicious!)",{"data":1068,"content":1069,"nodeType":883},{},[1070],{"data":1071,"marks":1072,"value":1073,"nodeType":882},{},[],"With this intel, Push’s agents now had some useful fodder to hunt for.",{"data":1075,"content":1076,"nodeType":975},{},[1077],{"data":1078,"marks":1079,"value":1080,"nodeType":882},{},[],"Hunting from intel: How we developed a behavioral detection",{"data":1082,"content":1083,"nodeType":883},{},[1084],{"data":1085,"marks":1086,"value":1087,"nodeType":882},{},[],"It started with ingestion. When the Microsoft blog was published, Push's TI aggregation agent flagged it as relevant to our detection surface — the technique abuses OAuth redirect behavior observable in the browser, which maps directly to the metadata that Push's browser agent captures.",{"data":1089,"content":1093,"nodeType":963},{"target":1090},{"sys":1091},{"id":1092,"type":960,"linkType":961},"26saWWXsyFAZrsrfspGwaF",[],{"data":1095,"content":1096,"nodeType":883},{},[1097],{"data":1098,"marks":1099,"value":1100,"nodeType":882},{},[],"The Push intel agent understands not to hunt for IOCs, but rather to think in terms of durable behaviors. It understands the telemetry available to the Push browser extension, and then compares that to the telemetry it would expect to be able to extract for a given technique, before deciding what to hunt for.",{"data":1102,"content":1103,"nodeType":883},{},[1104],{"data":1105,"marks":1106,"value":1107,"nodeType":882},{},[],"In this case, the intel agent extracted two distinct behavioral elements from the research to look for: the OAuth redirect technique and the page users land on after the error.",{"data":1109,"content":1110,"nodeType":883},{},[1111],{"data":1112,"marks":1113,"value":1114,"nodeType":882},{},[],"That extraction step is where surface-level details can become technique-driven hunts. Microsoft's article listed specific client IDs, redirect URLs, and PowerShell command patterns — indicators that are useful for retrospective hunting but will rotate as the campaign evolves. ",{"data":1116,"content":1117,"nodeType":883},{},[1118],{"data":1119,"marks":1120,"value":1121,"nodeType":882},{},[],"The pipeline's job was to identify what wouldn't change: The behavioral mechanics of abusing the OAuth error redirect path as a delivery mechanism, independent of which domains, client IDs, or post-redirect payloads the attacker chose to use. This is the Pyramid of Pain principle in practice: Hunt for the technique, not the indicator, because techniques are genuinely hard for attackers to change.",{"data":1123,"content":1127,"nodeType":963},{"target":1124},{"sys":1125},{"id":1126,"type":960,"linkType":961},"7qUVlKVjHMkabu0MJ1S7gC",[],{"data":1129,"content":1130,"nodeType":883},{},[1131,1135,1144],{"data":1132,"marks":1133,"value":1134,"nodeType":882},{},[],"Next, the agents verified what they already knew from Push’s internal TTP knowledge base. In this case, the agents understood the well-known technique of ",{"data":1136,"content":1138,"nodeType":929},{"uri":1137},"https:\u002F\u002Fowasp.org\u002Fwww-community\u002Fattacks\u002Fopen_redirect",[1139],{"data":1140,"marks":1141,"value":1143,"nodeType":882},{},[1142],{"type":927},"open redirects",{"data":1145,"marks":1146,"value":1147,"nodeType":882},{},[],", where attackers leverage redirects to deliver users to a malicious page. The example originally published by Microsoft was a novel variation of that — abusing a trusted service and the open redirect technique via a legitimate OAuth error workflow to deliver a multi-stage phishing attack.",{"data":1149,"content":1150,"nodeType":883},{},[1151,1155,1159],{"data":1152,"marks":1153,"value":1154,"nodeType":882},{},[],"AI models’ deep knowledge of web programming and frameworks is a particular strength here, because they understand which OAuth redirect behavior is normal and common across diverse scenarios, and can pinpoint which elements will be the strongest signal to hunt for malicious behavior. The agents immediately recognized that hunting for ",{"data":1156,"marks":1157,"value":1013,"nodeType":882},{},[1158],{"type":1012},{"data":1160,"marks":1161,"value":1162,"nodeType":882},{},[]," would be too noisy, as legitimate apps regularly use silent token refresh.",{"data":1164,"content":1165,"nodeType":883},{},[1166],{"data":1167,"marks":1168,"value":1169,"nodeType":882},{},[],"In this case, the approach was simply to find all the instances where a user hit an OAuth error page, and then landed on a login page afterward. Normal behavior for error states would be to return an error response — not send the user on to a page with a password form field or a CAPTCHA. That’s highly suspicious.",{"data":1171,"content":1172,"nodeType":883},{},[1173],{"data":1174,"marks":1175,"value":1176,"nodeType":882},{},[],"The agents then built behavioral queries targeting both behavioral attributes of the attack, and validated them across Push's install base. ",{"data":1178,"content":1179,"nodeType":883},{},[1180],{"data":1181,"marks":1182,"value":1183,"nodeType":882},{},[],"When agents first looked in March, the hunts returned no true positives — the specific campaign Microsoft documented wasn’t active against Push customers at that time.",{"data":1185,"content":1186,"nodeType":883},{},[1187],{"data":1188,"marks":1189,"value":1190,"nodeType":882},{},[],"But the query logic was sound — precise enough to avoid false positives, broad enough to catch technique variants without relying on the specific IOCs that Microsoft documented. So the pipeline promoted it to a live query — a continuing detection that would surface any future instances of the technique across the customer base.",{"data":1192,"content":1193,"nodeType":975},{},[1194],{"data":1195,"marks":1196,"value":1197,"nodeType":882},{},[],"The hunt pays off: A new variant, completely different IOCs",{"data":1199,"content":1200,"nodeType":883},{},[1201],{"data":1202,"marks":1203,"value":1204,"nodeType":882},{},[],"In June, the query fired. A single user at a single customer had been targeted, but with a completely different scenario. ",{"data":1206,"content":1210,"nodeType":963},{"target":1207},{"sys":1208},{"id":1209,"type":960,"linkType":961},"7uXgOzxemy1PaJLhUa1txV",[],{"data":1212,"content":1213,"nodeType":883},{},[1214],{"data":1215,"marks":1216,"value":1217,"nodeType":882},{},[],"Where the Microsoft-documented example used lures presented as document-sharing links, Teams meeting recordings, or password resets, and the abused trusted service was a Microsoft login link used to trigger the OAuth error, the Push-observed attack chain used different elements. However, the behavioral technique at the core was the same.",{"data":1219,"content":1220,"nodeType":883},{},[1221],{"data":1222,"marks":1223,"value":1224,"nodeType":882},{},[],"In this case, the user clicked a link in a service desk ticket, triggering an OAuth flow that used a redirect URL with parameters designed to make it look like a Grammarly link. After hitting the OAuth error, the user was redirected to a page with a CAPTCHA, and then redirected again to a second page behind a Cloudflare Turnstile that was running a phish kit. While examining the phishing page, Push’s agents found a net-new phish kit that they later added additional detections for. ",{"data":1226,"content":1227,"nodeType":883},{},[1228],{"data":1229,"marks":1230,"value":1231,"nodeType":882},{},[],"Roughly a day after the Push detection fired, Google Safe Browsing flagged both domains as phishing domains. But when the user was first targeted, neither domain had been flagged. In this case, the user exited the redirect flow before entering any credentials.",{"data":1233,"content":1234,"nodeType":883},{},[1235],{"data":1236,"marks":1237,"value":1238,"nodeType":882},{},[],"It’s important to note that this phishing technique also bypasses other controls based on network content pattern analysis or domain-based detections. For example, a network proxy is designed to look for malicious webpages based on known-bad IOCs like domains or page content that contains known-bad script files. This technique uses a dynamic obfuscated Javascript blob that unpacks and loads the webpage on the client side after checking to see if it’s running in a live browser environment, evading proxy-based analysis.",{"data":1240,"content":1241,"nodeType":883},{},[1242],{"data":1243,"marks":1244,"value":1245,"nodeType":882},{},[],"The query now serves as another early-warning flag designed to be broad enough to catch other interesting new variants of this TTP.",{"data":1247,"content":1248,"nodeType":975},{},[1249],{"data":1250,"marks":1251,"value":1252,"nodeType":882},{},[],"Why technique-level detection pays dividends",{"data":1254,"content":1255,"nodeType":883},{},[1256],{"data":1257,"marks":1258,"value":1259,"nodeType":882},{},[],"This example demonstrates the value of behavioral detection. By focusing on technique extraction, we can stay a step ahead of attack evolution, identifying other contexts and campaigns that use the same behavioral technique, without relying on stale IOCs.",{"data":1261,"content":1262,"nodeType":883},{},[1263],{"data":1264,"marks":1265,"value":1266,"nodeType":882},{},[],"For customers, this means no one has to distil the threat intel report into behavioral elements, spend time crafting detections, or work to eliminate false positives. The Push agents do all that automatically, delivering a compounding benefit the more they learn. ",{"data":1268,"content":1269,"nodeType":883},{},[1270],{"data":1271,"marks":1272,"value":1273,"nodeType":882},{},[],"Customers get a fully operationalized threat-hunting and detection engineering capability; and the Push knowledge base itself expands with each new hunt, getting better at identifying emerging threats.",{"data":1275,"content":1276,"nodeType":883},{},[1277,1281,1290],{"data":1278,"marks":1279,"value":1280,"nodeType":882},{},[],"If you'd like to see how Push's detection pipeline would work in your environment, ",{"data":1282,"content":1284,"nodeType":929},{"uri":1283},"https:\u002F\u002Fpushsecurity.com\u002Fdemo",[1285],{"data":1286,"marks":1287,"value":1289,"nodeType":882},{},[1288],{"type":927},"book a demo",{"data":1291,"marks":1292,"value":1293,"nodeType":882},{},[]," with our team.","document",{"entries":1296},{"hyperlink":1297,"inline":1298,"block":1299},[],[],[1300,1327,1335,1342,1349],{"sys":1301,"__typename":1302,"content":1303,"name":1326,"title":59},{"id":959},"InsightTextBlockComponent",{"json":1304},{"data":1305,"content":1306,"nodeType":1294},{},[1307],{"data":1308,"content":1309,"nodeType":883},{},[1310,1314,1322],{"data":1311,"marks":1312,"value":1313,"nodeType":882},{},[],"Note: This is part 2 of a series. ",{"data":1315,"content":1317,"nodeType":929},{"uri":1316},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fagentic-threat-hunting-benefits-for-customers",[1318],{"data":1319,"marks":1320,"value":1321,"nodeType":882},{},[],"Part 1",{"data":1323,"marks":1324,"value":1325,"nodeType":882},{},[]," covers the pipeline’s detection engineering principles and the security outcomes we’re achieving for Push customers.","Agentic case study IB1",{"sys":1328,"__typename":1329,"title":1330,"caption":1330,"layoutMode":59,"file":1331},{"id":999},"Image","The original attack chain documented in March by Microsoft.",{"url":1332,"width":1333,"height":1334},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F1D3TRRoXR4Kyso7bX2ogiC\u002F4e17fd2c068195e9959da9b633ab5f48\u002Fmicrosoft-attack-chain.png",3224,2020,{"sys":1336,"__typename":1329,"title":1337,"caption":1337,"layoutMode":59,"file":1338},{"id":1092},"Push’s intel agent reasoning over some ingested TI on a novel OAuth redirect abuse technique.",{"url":1339,"width":1340,"height":1341},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F46ArhTRN2xiFHemmFIo1Y\u002F3976a9c6877f08810f2eea37d306de4e\u002Fimage4.png",1999,820,{"sys":1343,"__typename":1329,"title":1344,"caption":1344,"layoutMode":59,"file":1345},{"id":1126},"Push agents summarizing the behavioral techniques of the attack and proposing hunt queries.",{"url":1346,"width":1347,"height":1348},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F1knJksvSVjMoGKHyAMIN22\u002F5727ee7ce06ddb300355eec119bab885\u002Fimage3.png",1900,1466,{"sys":1350,"__typename":1329,"title":1351,"caption":1351,"layoutMode":59,"file":1352},{"id":1209},"Push observed the same technique with completely different IOCs a few months after first hunting for it based on Microsoft’s documented campaign example.",{"url":1353,"width":1354,"height":1355},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F4zGCbPJbfFXhSJMAPrssTX\u002F10759adf3d14f823209329b0c84fdea7\u002Foauth-redirect-technique-v2.png",3400,1860,{"items":1357},[],{},"How Push turns IOC-based intel into browser TTPs for hunting","thought-leadership","2026-07-31T00:00:00.000Z",{"items":1363},[1364,2313,3129],{"__typename":1365,"sys":1366,"content":1368,"title":2296,"synopsis":2297,"hashTags":59,"publishedDate":2298,"slug":2299,"tagsCollection":2300,"authorsCollection":2309},"BlogPosts",{"id":1367},"6dJUsirH3rrhy1Stnzkfqk",{"json":1369},{"data":1370,"content":1371,"nodeType":1294},{},[1372,1385,1401,1455,1462,1475,1495,1502,1508,1511,1518,1525,1554,1561,1568,1636,1643,1649,1656,1663,1666,1673,1680,1713,1733,1745,1751,1758,1764,1776,1783,1803,1809,1821,1833,1840,1846,1858,1874,1886,1898,1904,1911,1914,1921,1928,1944,1952,1959,1967,1974,2020,2023,2030,2037,2043,2051,2058,2074,2089,2096,2112,2119,2167,2174,2190,2197,2247,2254,2262,2265,2272,2279],{"data":1373,"content":1374,"nodeType":883},{},[1375,1379],{"data":1376,"marks":1377,"value":1378,"nodeType":882},{},[],"Hey all you security engineers, let’s play ",{"data":1380,"marks":1381,"value":1384,"nodeType":882},{},[1382,1383],{"type":1045},{"type":1012},"Would You Rather … ?",{"data":1386,"content":1387,"nodeType":883},{},[1388,1392,1397],{"data":1389,"marks":1390,"value":1391,"nodeType":882},{},[],"Would you rather spend time trying to write detections for ",{"data":1393,"marks":1394,"value":1396,"nodeType":882},{},[1395],{"type":1012},"modern browser-based attacks",{"data":1398,"marks":1399,"value":1400,"nodeType":882},{},[]," by …",{"data":1402,"content":1403,"nodeType":1454},{},[1404,1420,1439],{"data":1405,"content":1406,"nodeType":1419},{},[1407],{"data":1408,"content":1409,"nodeType":883},{},[1410,1414],{"data":1411,"marks":1412,"value":1413,"nodeType":882},{},[],"Combing through MITRE looking for techniques that you can write detections on, only to find you have",{"data":1415,"marks":1416,"value":1418,"nodeType":882},{},[1417],{"type":1012}," little useful telemetry from your typical sources.","list-item",{"data":1421,"content":1422,"nodeType":1419},{},[1423],{"data":1424,"content":1425,"nodeType":883},{},[1426,1430,1435],{"data":1427,"marks":1428,"value":1429,"nodeType":882},{},[],"Curating a list of malicious domain IOCs extracted from endless TI pieces, only to ",{"data":1431,"marks":1432,"value":1434,"nodeType":882},{},[1433],{"type":1012},"never see a single one of them match",{"data":1436,"marks":1437,"value":1438,"nodeType":882},{},[],".",{"data":1440,"content":1441,"nodeType":1419},{},[1442],{"data":1443,"content":1444,"nodeType":883},{},[1445,1450],{"data":1446,"marks":1447,"value":1449,"nodeType":882},{},[1448],{"type":1012},"Just giving up and blocking a bunch of domains or IPs",{"data":1451,"marks":1452,"value":1453,"nodeType":882},{},[]," from every TI feed you come across, while quietly weeping.","unordered-list",{"data":1456,"content":1457,"nodeType":883},{},[1458],{"data":1459,"marks":1460,"value":1461,"nodeType":882},{},[],"Or … ",{"data":1463,"content":1464,"nodeType":1454},{},[1465],{"data":1466,"content":1467,"nodeType":1419},{},[1468],{"data":1469,"content":1470,"nodeType":883},{},[1471],{"data":1472,"marks":1473,"value":1474,"nodeType":882},{},[],"Inherit constantly evolving detections validated across 3 million-plus browsers, tuned to remove false positives, informed by human threat researchers, and tailored to the known and not-yet-known threats that target account compromise and malware delivery via the browser.",{"data":1476,"content":1477,"nodeType":883},{},[1478,1482,1491],{"data":1479,"marks":1480,"value":1481,"nodeType":882},{},[],"At Push, we’ve built an ",{"data":1483,"content":1485,"nodeType":929},{"uri":1484},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fcan-ai-replace-a-threat-researcher-what-we-learned-building-an-agentic-threat-hunting-pipeline",[1486],{"data":1487,"marks":1488,"value":1490,"nodeType":882},{},[1489],{"type":927},"agentic threat hunting and detection engineering pipeline",{"data":1492,"marks":1493,"value":1494,"nodeType":882},{},[]," to take that first set of onerous tasks off your plate. The result is a process that looks a lot like the ideal described in detection engineering maturity models, achieved without any extra headcount or subject matter expertise on your team, and scaled to meet the speed and complexity of our current era of AI-enabled adversaries.",{"data":1496,"content":1497,"nodeType":883},{},[1498],{"data":1499,"marks":1500,"value":1501,"nodeType":882},{},[],"Let’s take a look at how the pipeline delivers a collective good by identifying emerging threats or new technique variants in a single customer environment and then delivering detections to everyone.",{"data":1503,"content":1507,"nodeType":963},{"target":1504},{"sys":1505},{"id":1506,"type":960,"linkType":961},"sN6q7oEwYyJTkXxyLb81m",[],{"data":1509,"content":1510,"nodeType":967},{},[],{"data":1512,"content":1513,"nodeType":975},{},[1514],{"data":1515,"marks":1516,"value":1517,"nodeType":882},{},[],"Why detection engineering from TI is hard — and why AI-enabled attacks are making it even harder",{"data":1519,"content":1520,"nodeType":883},{},[1521],{"data":1522,"marks":1523,"value":1524,"nodeType":882},{},[],"Detection engineers feel the pain that Beethoven must have felt when he got the critique: “There are just too many notes!”",{"data":1526,"content":1527,"nodeType":883},{},[1528,1532,1537,1541,1550],{"data":1529,"marks":1530,"value":1531,"nodeType":882},{},[],"Except where notes = threat intelligence, light on the ",{"data":1533,"marks":1534,"value":1536,"nodeType":882},{},[1535],{"type":1045},"intelligence",{"data":1538,"marks":1539,"value":1540,"nodeType":882},{},[],". (For a great unpacking of what’s hard about transforming TI into detections, check out this ",{"data":1542,"content":1544,"nodeType":929},{"uri":1543},"https:\u002F\u002Fmedium.com\u002Fanton-on-security\u002Fdetection-engineering-is-painful-and-it-shouldnt-be-part-1-3641d8740458",[1545],{"data":1546,"marks":1547,"value":1549,"nodeType":882},{},[1548],{"type":927},"blog series",{"data":1551,"marks":1552,"value":1553,"nodeType":882},{},[]," from Anton Chuvakin and his Google security colleagues from 2023. The challenge has only gotten harder since then!)",{"data":1555,"content":1556,"nodeType":883},{},[1557],{"data":1558,"marks":1559,"value":1560,"nodeType":882},{},[],"In short, there is too much potential TI, too little actionable detail, and a dearth of useful business-relevant context.",{"data":1562,"content":1563,"nodeType":883},{},[1564],{"data":1565,"marks":1566,"value":1567,"nodeType":882},{},[],"This often manifests as:",{"data":1569,"content":1570,"nodeType":1454},{},[1571,1599,1618],{"data":1572,"content":1573,"nodeType":1419},{},[1574],{"data":1575,"content":1576,"nodeType":883},{},[1577,1582,1586,1595],{"data":1578,"marks":1579,"value":1581,"nodeType":882},{},[1580],{"type":1012},"Feeling constantly behind the threat landscape. ",{"data":1583,"marks":1584,"value":1585,"nodeType":882},{},[],"SANS Institute’s ",{"data":1587,"content":1589,"nodeType":929},{"uri":1588},"https:\u002F\u002Fwww.sans.org\u002Fwhite-papers\u002Fstate-detection-engineering-2026",[1590],{"data":1591,"marks":1592,"value":1594,"nodeType":882},{},[1593],{"type":927},"State of Detection Engineering 2026",{"data":1596,"marks":1597,"value":1598,"nodeType":882},{},[]," report found that only 18% of practitioners feel like they’re staying ahead; 56% report barely keeping pace.",{"data":1600,"content":1601,"nodeType":1419},{},[1602],{"data":1603,"content":1604,"nodeType":883},{},[1605,1609,1614],{"data":1606,"marks":1607,"value":1608,"nodeType":882},{},[],"Access to a huge amount of potential TI, but ",{"data":1610,"marks":1611,"value":1613,"nodeType":882},{},[1612],{"type":1012},"lacking the time, context, and tools needed to parse the data",{"data":1615,"marks":1616,"value":1617,"nodeType":882},{},[]," for threats that matter to the business.",{"data":1619,"content":1620,"nodeType":1419},{},[1621],{"data":1622,"content":1623,"nodeType":883},{},[1624,1628,1633],{"data":1625,"marks":1626,"value":1627,"nodeType":882},{},[],"More information on IOCs than TTPs, leading to ",{"data":1629,"marks":1630,"value":1632,"nodeType":882},{},[1631],{"type":1012},"ever-growing blocklists and attacks that still slip through",{"data":1634,"marks":1635,"value":1438,"nodeType":882},{},[],{"data":1637,"content":1638,"nodeType":883},{},[1639],{"data":1640,"marks":1641,"value":1642,"nodeType":882},{},[],"As AI-enabled adversaries continue to make it increasingly trivial to rotate infrastructure or abuse trusted services and workflows to deliver modern attacks, the hill gets steeper. ",{"data":1644,"content":1648,"nodeType":963},{"target":1645},{"sys":1646},{"id":1647,"type":960,"linkType":961},"4xlCsISP3OT9MAj3wxw67D",[],{"data":1650,"content":1651,"nodeType":883},{},[1652],{"data":1653,"marks":1654,"value":1655,"nodeType":882},{},[],"In the case of attacks that target employees via the browser — using advanced phishing methods, commercial toolkits, abuse of OAuth, abuse of trusted services to deliver phishing lures, etc. — most security teams are also working without the right foundational visibility to even begin to mature their detection process against these TTPs.",{"data":1657,"content":1658,"nodeType":883},{},[1659],{"data":1660,"marks":1661,"value":1662,"nodeType":882},{},[],"The missing input is visibility at the layer where these attacks actually execute — the browser session. Without it, detection engineering for browser-based threats is painful guesswork.",{"data":1664,"content":1665,"nodeType":967},{},[],{"data":1667,"content":1668,"nodeType":975},{},[1669],{"data":1670,"marks":1671,"value":1672,"nodeType":882},{},[],"How Push operationalized best practices for hunting from TI using agents",{"data":1674,"content":1675,"nodeType":883},{},[1676],{"data":1677,"marks":1678,"value":1679,"nodeType":882},{},[],"In building our agentic threat hunting and detection engineering pipeline at Push, we set out to solve many of the same problems that any security team faces when maturing its processes:",{"data":1681,"content":1682,"nodeType":1454},{},[1683,1693,1703],{"data":1684,"content":1685,"nodeType":1419},{},[1686],{"data":1687,"content":1688,"nodeType":883},{},[1689],{"data":1690,"marks":1691,"value":1692,"nodeType":882},{},[],"How to transform TI into technique-level intel we could write durable detections for across a wide customer base at scale?",{"data":1694,"content":1695,"nodeType":1419},{},[1696],{"data":1697,"content":1698,"nodeType":883},{},[1699],{"data":1700,"marks":1701,"value":1702,"nodeType":882},{},[],"How to create structured internal knowledge to add context to our detection engineering process that validates the relevance of what we find?",{"data":1704,"content":1705,"nodeType":1419},{},[1706],{"data":1707,"content":1708,"nodeType":883},{},[1709],{"data":1710,"marks":1711,"value":1712,"nodeType":882},{},[],"How to verify what’s worthwhile to hunt for, remove false positives, and understand the value of a detection for a specific TTP across an install base of more than 3 million browsers?",{"data":1714,"content":1715,"nodeType":883},{},[1716,1720,1729],{"data":1717,"marks":1718,"value":1719,"nodeType":882},{},[],"The process we created looks a lot like the ",{"data":1721,"content":1723,"nodeType":929},{"uri":1722},"https:\u002F\u002Fmedium.com\u002Fanton-on-security\u002Fblueprint-for-threat-intel-to-detection-flow-part-7-088024be08dd",[1724],{"data":1725,"marks":1726,"value":1728,"nodeType":882},{},[1727],{"type":927},"best practices",{"data":1730,"marks":1731,"value":1732,"nodeType":882},{},[]," on how to turn intelligence into meaningful detections. The difference is that agents let us run this process continuously and at a scale that would be impossible to achieve with human analysts alone.",{"data":1734,"content":1735,"nodeType":883},{},[1736,1741],{"data":1737,"marks":1738,"value":1740,"nodeType":882},{},[1739],{"type":1012},"It starts with ingestion. ",{"data":1742,"marks":1743,"value":1744,"nodeType":882},{},[],"An agent tasked with TI aggregation monitors multiple industry sources — vendor reports, researcher disclosures, campaign teardowns — and filters for intelligence relevant to browser-based attack techniques. ",{"data":1746,"content":1750,"nodeType":963},{"target":1747},{"sys":1748},{"id":1749,"type":960,"linkType":961},"7fsLEGUbOINll70ViNVVkI",[],{"data":1752,"content":1753,"nodeType":883},{},[1754],{"data":1755,"marks":1756,"value":1757,"nodeType":882},{},[],"Because this agent already understands the types of attacks and scenarios that matter to Push’s detection surface, it can distinguish signal from noise at the intake stage, flagging useful intel and proposing initial lightweight hunts based on the browser metadata Push can observe. When a potential hunt looks promising, the aggregation agent hands off to a deeper analysis agent to extract what’s actually huntable.",{"data":1759,"content":1763,"nodeType":963},{"target":1760},{"sys":1761},{"id":1762,"type":960,"linkType":961},"5vyeALIziHamJ0cLiGMdGk",[],{"data":1765,"content":1766,"nodeType":883},{},[1767,1772],{"data":1768,"marks":1769,"value":1771,"nodeType":882},{},[1770],{"type":1012},"That extraction step is where a general TI feed becomes something you can build detections from. ",{"data":1773,"marks":1774,"value":1775,"nodeType":882},{},[],"Agents built on frontier models have a deep understanding of web programming languages and browser workflows can decompose the intelligence into its meaningful atomic units — the specific behavioral patterns that distinguish a malicious technique from normal browser activity. ",{"data":1777,"content":1778,"nodeType":883},{},[1779],{"data":1780,"marks":1781,"value":1782,"nodeType":882},{},[],"They compare those patterns against everything the Push browser agent can observe: tabs, windows, navigation events, downloads, network requests, DOM content, script execution. Then they discard anything too broad — observable events that are commonplace, even when connected to a malicious TTP — to avoid false positives. ",{"data":1784,"content":1785,"nodeType":883},{},[1786,1790,1799],{"data":1787,"marks":1788,"value":1789,"nodeType":882},{},[],"What survives is one or more huntable technique signatures that can be identified with a high true positive rate. This is the ",{"data":1791,"content":1793,"nodeType":929},{"uri":1792},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fthe-pyramid-of-pain-in-the-ai-era",[1794],{"data":1795,"marks":1796,"value":1798,"nodeType":882},{},[1797],{"type":927},"Pyramid of Pain principle",{"data":1800,"marks":1801,"value":1802,"nodeType":882},{},[]," operationalized at machine speed: Target the technique, not the indicator, because techniques are genuinely hard for attackers to change.",{"data":1804,"content":1808,"nodeType":963},{"target":1805},{"sys":1806},{"id":1807,"type":960,"linkType":961},"5j0mvdIMkaUwDgCu0nOqSm",[],{"data":1810,"content":1811,"nodeType":883},{},[1812,1817],{"data":1813,"marks":1814,"value":1816,"nodeType":882},{},[1815],{"type":1012},"In parallel, the pipeline validates whether the identified technique is genuinely novel or a variant of something Push already detects. ",{"data":1818,"marks":1819,"value":1820,"nodeType":882},{},[],"This is where our internal knowledge base comes into play. Built over three years by Push’s in-house research team and augmented continuously by the pipeline itself, it represents what Push knows about browser-based attack behaviors — a structured corpus of TTPs that lets agents classify incoming intelligence as new territory, a known variant that needs a refined detection, or something already covered. That classification determines what happens next: A net-new technique triggers a full hunt; a known variant triggers a refinement cycle; and a duplicate gets deprioritized.",{"data":1822,"content":1823,"nodeType":883},{},[1824,1829],{"data":1825,"marks":1826,"value":1828,"nodeType":882},{},[1827],{"type":1012},"The hunt itself is where hypothesis meets evidence.",{"data":1830,"marks":1831,"value":1832,"nodeType":882},{},[]," Agents develop a specific, testable prediction about what the technique looks like in browser telemetry, then validate that prediction across Push’s install base. The aim of the initial hunt is to identify any potential false positives — legitimate browser behavior that matches the pattern. Then the agents refine: adjusting the query, narrowing the behavioral fingerprints, testing again. Each iteration sharpens the detection until the false positive rate drops to a negligible, tolerable level. ",{"data":1834,"content":1835,"nodeType":883},{},[1836],{"data":1837,"marks":1838,"value":1839,"nodeType":882},{},[],"The hunts that produce relevant, high-confidence results become continuous queries — a kind of early warning system for emerging threats we’re actively watching for and learning about. The most useful and reliable of those queries become production detections that protect every Push customer in real time. ",{"data":1841,"content":1845,"nodeType":963},{"target":1842},{"sys":1843},{"id":1844,"type":960,"linkType":961},"h3MN5kaaGGuL4uvNsP9JZ",[],{"data":1847,"content":1848,"nodeType":883},{},[1849,1854],{"data":1850,"marks":1851,"value":1853,"nodeType":882},{},[1852],{"type":1012},"This is what “detect what matters” looks like as an engineering discipline. ",{"data":1855,"marks":1856,"value":1857,"nodeType":882},{},[],"By the time the agents have whittled down millions or trillions of browser events into a good hunt query — where good means broad enough to cast a usefully wide net for variations — and then tuned that further into a high-fidelity detection, the result is fewer, sharper detections by design. And because Push detects at the browser session layer before a user can interact with a malicious page, almost all of those detections fire pre-compromise. ",{"data":1859,"content":1860,"nodeType":883},{},[1861,1865,1870],{"data":1862,"marks":1863,"value":1864,"nodeType":882},{},[],"The same 2026 SANS survey mentioned earlier found that ",{"data":1866,"marks":1867,"value":1869,"nodeType":882},{},[1868],{"type":1012},"66% of SOC practitioners cite vendor-provided rules as their primary source of false positives",{"data":1871,"marks":1872,"value":1873,"nodeType":882},{},[]," — a structural problem that persists at every organization size. Push’s pipeline produces the opposite outcome: better detections, less noise.",{"data":1875,"content":1876,"nodeType":883},{},[1877,1882],{"data":1878,"marks":1879,"value":1881,"nodeType":882},{},[1880],{"type":1012},"The result is a system with two learning loops.",{"data":1883,"marks":1884,"value":1885,"nodeType":882},{},[]," An inner loop handles real-time detection and response for known attacker techniques — the production detections already deployed across the customer base. An outer loop handles continuous discovery — agents hunting for new techniques, refining existing detections, and ingesting external intelligence. ",{"data":1887,"content":1888,"nodeType":883},{},[1889,1894],{"data":1890,"marks":1891,"value":1893,"nodeType":882},{},[1892],{"type":1012},"Each loop feeds the other:",{"data":1895,"marks":1896,"value":1897,"nodeType":882},{},[]," The outer loop’s discoveries become the inner loop’s new production detections, and the inner loop’s blocked attacks become raw material for the outer loop to analyze for novel variants. The knowledge base that both loops draw on grows with every cycle, which means the pipeline's detection coverage compounds at roughly the rate the threat landscape grows more complex.",{"data":1899,"content":1903,"nodeType":963},{"target":1900},{"sys":1901},{"id":1902,"type":960,"linkType":961},"3xVLn9Ldk4cOP4uFYIYyM",[],{"data":1905,"content":1906,"nodeType":883},{},[1907],{"data":1908,"marks":1909,"value":1910,"nodeType":882},{},[],"And every validated detection produced by this process, whether it originated from a blocked attack in one customer’s environment, a proactive hunt across the telemetry corpus, or a vendor report about a campaign Push has never observed on customer estates, deploys to the entire customer base.",{"data":1912,"content":1913,"nodeType":967},{},[],{"data":1915,"content":1916,"nodeType":975},{},[1917],{"data":1918,"marks":1919,"value":1920,"nodeType":882},{},[],"Herd immunity, without all the breaches to get there",{"data":1922,"content":1923,"nodeType":883},{},[1924],{"data":1925,"marks":1926,"value":1927,"nodeType":882},{},[],"That last point is where Push’s idea of herd immunity diverges from the traditional definition.",{"data":1929,"content":1930,"nodeType":883},{},[1931,1935,1940],{"data":1932,"marks":1933,"value":1934,"nodeType":882},{},[],"Detection and response platforms and MDR services commonly describe a ",{"data":1936,"marks":1937,"value":1939,"nodeType":882},{},[1938],{"type":1012},"herd immunity benefit",{"data":1941,"marks":1942,"value":1943,"nodeType":882},{},[],": What one customer encounters, every customer gets protection against. The mechanism is real, but the learning input is typically a breach or a compromise. Someone has to be the first victim.",{"data":1945,"content":1946,"nodeType":883},{},[1947],{"data":1948,"marks":1949,"value":1951,"nodeType":882},{},[1950],{"type":1012},"Push’s approach is different. ",{"data":1953,"content":1954,"nodeType":883},{},[1955],{"data":1956,"marks":1957,"value":1958,"nodeType":882},{},[],"Modern browser-based attacks frequently rely on a series of techniques strung together to achieve a compromise. From its vantage point in the browser, Push catches many novel techniques with existing detections pre-compromise because it recognizes a portion of the attack techniques in the chain. The detection process then identifies what’s new about a previously unseen variation of a known TTP — perhaps an evasion technique the kit hadn’t used before, an unusual lure or infrastructure pattern, etc. ",{"data":1960,"content":1961,"nodeType":883},{},[1962],{"data":1963,"marks":1964,"value":1966,"nodeType":882},{},[1965],{"type":1012},"The detection gets better for customers and no one was compromised to get there.",{"data":1968,"content":1969,"nodeType":883},{},[1970],{"data":1971,"marks":1972,"value":1973,"nodeType":882},{},[],"On the external intelligence side, the pipeline ingests published research about a campaign Push has never observed, extracts the durable behavioral characteristics, validates them against browser telemetry, refines the query to tune out false positives, and ships detections before the technique is ever used against a Push customer. The protection arrives ahead of the attack.",{"data":1975,"content":1976,"nodeType":883},{},[1977,1981,1990,1994,2003,2007,2016],{"data":1978,"marks":1979,"value":1980,"nodeType":882},{},[],"These are the processes behind Push’s identification of ",{"data":1982,"content":1984,"nodeType":929},{"uri":1983},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fconsentfix",[1985],{"data":1986,"marks":1987,"value":1989,"nodeType":882},{},[1988],{"type":927},"ConsentFix",{"data":1991,"marks":1992,"value":1993,"nodeType":882},{},[],", ",{"data":1995,"content":1997,"nodeType":929},{"uri":1996},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Finstallfix",[1998],{"data":1999,"marks":2000,"value":2002,"nodeType":882},{},[2001],{"type":927},"InstallFix",{"data":2004,"marks":2005,"value":2006,"nodeType":882},{},[],", and ",{"data":2008,"content":2010,"nodeType":929},{"uri":2009},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fllmshare-malvertising-campaign",[2011],{"data":2012,"marks":2013,"value":2015,"nodeType":882},{},[2014],{"type":927},"LLMShare",{"data":2017,"marks":2018,"value":2019,"nodeType":882},{},[]," — three browser-based attack techniques Push's team discovered or documented for the first time. In several cases, detections were blocking active campaigns against Push customers before the technique had been publicly documented. Those detections rolled out to every customer within hours or days of first observation.",{"data":2021,"content":2022,"nodeType":967},{},[],{"data":2024,"content":2025,"nodeType":975},{},[2026],{"data":2027,"marks":2028,"value":2029,"nodeType":882},{},[],"Outcomes: By the numbers",{"data":2031,"content":2032,"nodeType":883},{},[2033],{"data":2034,"marks":2035,"value":2036,"nodeType":882},{},[],"Looking at the quantifiable outcomes of this agentic threat hunting capability over the last few months, the benefits for customers become clear.",{"data":2038,"content":2042,"nodeType":963},{"target":2039},{"sys":2040},{"id":2041,"type":960,"linkType":961},"7uNrNGUjjBiG9qEsfen7Xi",[],{"data":2044,"content":2045,"nodeType":2050},{},[2046],{"data":2047,"marks":2048,"value":2049,"nodeType":882},{},[],"Velocity","heading-2",{"data":2052,"content":2053,"nodeType":883},{},[2054],{"data":2055,"marks":2056,"value":2057,"nodeType":882},{},[],"Agents allow us to massively scale our research expertise, delivering detections for emerging threats or new variants much faster than humans alone can.",{"data":2059,"content":2060,"nodeType":883},{},[2061,2065,2070],{"data":2062,"marks":2063,"value":2064,"nodeType":882},{},[],"This year already, we’ve ",{"data":2066,"marks":2067,"value":2069,"nodeType":882},{},[2068],{"type":1012},"tripled",{"data":2071,"marks":2072,"value":2073,"nodeType":882},{},[]," the number of new detections shipped to customers.",{"data":2075,"content":2076,"nodeType":883},{},[2077,2081,2086],{"data":2078,"marks":2079,"value":2080,"nodeType":882},{},[],"We’ve also reduced the time it takes to ship production-ready detections for new threats from weeks to ",{"data":2082,"marks":2083,"value":2085,"nodeType":882},{},[2084],{"type":1012},"minutes",{"data":2087,"marks":2088,"value":1438,"nodeType":882},{},[],{"data":2090,"content":2091,"nodeType":2050},{},[2092],{"data":2093,"marks":2094,"value":2095,"nodeType":882},{},[],"Detection coverage",{"data":2097,"content":2098,"nodeType":883},{},[2099,2103,2108],{"data":2100,"marks":2101,"value":2102,"nodeType":882},{},[],"With that scaled expertise comes broad coverage. We perform an average of ",{"data":2104,"marks":2105,"value":2107,"nodeType":882},{},[2106],{"type":1012},"300+ hunts",{"data":2109,"marks":2110,"value":2111,"nodeType":882},{},[]," a month (a mix of live queries for identified TTPs we’re looking for, plus net-new hunts for emerging threats we identify in any given month).",{"data":2113,"content":2114,"nodeType":883},{},[2115],{"data":2116,"marks":2117,"value":2118,"nodeType":882},{},[],"A few other metrics that demonstrate the scale of our detection coverage:",{"data":2120,"content":2121,"nodeType":1454},{},[2122,2137,2152],{"data":2123,"content":2124,"nodeType":1419},{},[2125],{"data":2126,"content":2127,"nodeType":883},{},[2128,2133],{"data":2129,"marks":2130,"value":2132,"nodeType":882},{},[2131],{"type":1012},"75+",{"data":2134,"marks":2135,"value":2136,"nodeType":882},{},[]," attacker tools documented in our KB so far",{"data":2138,"content":2139,"nodeType":1419},{},[2140],{"data":2141,"content":2142,"nodeType":883},{},[2143,2148],{"data":2144,"marks":2145,"value":2147,"nodeType":882},{},[2146],{"type":1012},"25+",{"data":2149,"marks":2150,"value":2151,"nodeType":882},{},[]," variants of existing attacks we’ve identified and shipped detections for",{"data":2153,"content":2154,"nodeType":1419},{},[2155],{"data":2156,"content":2157,"nodeType":883},{},[2158,2163],{"data":2159,"marks":2160,"value":2162,"nodeType":882},{},[2161],{"type":1012},"10,000+",{"data":2164,"marks":2165,"value":2166,"nodeType":882},{},[]," monthly sessions analyzed",{"data":2168,"content":2169,"nodeType":2050},{},[2170],{"data":2171,"marks":2172,"value":2173,"nodeType":882},{},[],"Protection from emerging threats",{"data":2175,"content":2176,"nodeType":883},{},[2177,2181,2186],{"data":2178,"marks":2179,"value":2180,"nodeType":882},{},[],"On the emerging threat side, our team was the first to identify or document ",{"data":2182,"marks":2183,"value":2185,"nodeType":882},{},[2184],{"type":1012},"three new browser-based attack techniques",{"data":2187,"marks":2188,"value":2189,"nodeType":882},{},[]," — ConsentFix, InstallFix, and LLMShare — shipping detections to all customers quickly after identification.",{"data":2191,"content":2192,"nodeType":883},{},[2193],{"data":2194,"marks":2195,"value":2196,"nodeType":882},{},[],"In that same time frame, we’ve also:",{"data":2198,"content":2199,"nodeType":1454},{},[2200,2228],{"data":2201,"content":2202,"nodeType":1419},{},[2203],{"data":2204,"content":2205,"nodeType":883},{},[2206,2210,2215,2219,2224],{"data":2207,"marks":2208,"value":2209,"nodeType":882},{},[],"Protected ",{"data":2211,"marks":2212,"value":2214,"nodeType":882},{},[2213],{"type":1012},"60+",{"data":2216,"marks":2217,"value":2218,"nodeType":882},{},[]," ",{"data":2220,"marks":2221,"value":2223,"nodeType":882},{},[2222],{"type":1012},"customers in the last 3 months",{"data":2225,"marks":2226,"value":2227,"nodeType":882},{},[]," who’ve been targeted with novel phishing techniques — identifying never-before-seen techniques, lures, delivery mechanisms, interactions, tools, or attack chains",{"data":2229,"content":2230,"nodeType":1419},{},[2231],{"data":2232,"content":2233,"nodeType":883},{},[2234,2238,2243],{"data":2235,"marks":2236,"value":2237,"nodeType":882},{},[],"Prevented ",{"data":2239,"marks":2240,"value":2242,"nodeType":882},{},[2241],{"type":1012},"225+",{"data":2244,"marks":2245,"value":2246,"nodeType":882},{},[]," instances of threats pre-compromise for novel techniques",{"data":2248,"content":2249,"nodeType":883},{},[2250],{"data":2251,"marks":2252,"value":2253,"nodeType":882},{},[],"In all of the above situations, Push customers didn’t have to do anything — no combing through TI to find relevant details, no writing their own detections and tuning out false positives, or spending cycles to unpack a particularly knotty attack chain that used techniques they had never seen before. ",{"data":2255,"content":2256,"nodeType":883},{},[2257],{"data":2258,"marks":2259,"value":2261,"nodeType":882},{},[2260],{"type":1012},"That’s what operationalized intelligence looks like at scale, delivered as a product, not a project.",{"data":2263,"content":2264,"nodeType":967},{},[],{"data":2266,"content":2267,"nodeType":975},{},[2268],{"data":2269,"marks":2270,"value":2271,"nodeType":882},{},[],"Learn more about Push",{"data":2273,"content":2274,"nodeType":883},{},[2275],{"data":2276,"marks":2277,"value":2278,"nodeType":882},{},[],"The same foundational capabilities that enable this agentic threat hunting pipeline also deliver other security outcomes for Push customers: gaining visibility and control over AI tool usage; hardening identities by surfacing credential reuse, SSO gaps, and shadow IT; and supporting data loss and insider investigations with browser-layer telemetry that other tools can’t see.",{"data":2280,"content":2281,"nodeType":883},{},[2282,2286,2293],{"data":2283,"marks":2284,"value":2285,"nodeType":882},{},[],"If you’d like to learn more, ",{"data":2287,"content":2288,"nodeType":929},{"uri":1283},[2289],{"data":2290,"marks":2291,"value":1289,"nodeType":882},{},[2292],{"type":927},{"data":2294,"marks":2295,"value":1293,"nodeType":882},{},[],"How Push’s agentic threat hunting in the browser benefits every customer","Security outcomes you can achieve when AI agents hunt in the browser, identify new threats, and ship detections that benefit everyone.","2026-07-23T00:00:00.000Z","agentic-threat-hunting-benefits-for-customers",{"items":2301},[2302,2305],{"sys":2303,"name":343},{"id":2304},"4ksQNCFeBf8H4QIORqpRLw",{"sys":2306,"name":2308},{"id":2307},"6A5RXS31ZQx3PwryGb1IMy","Browser-based attacks",{"items":2310},[2311],{"fullName":866,"firstName":867,"jobTitle":868,"profilePicture":2312},{"url":870},{"__typename":1365,"sys":2314,"content":2316,"title":3111,"synopsis":3112,"hashTags":59,"publishedDate":3113,"slug":3114,"tagsCollection":3115,"authorsCollection":3121},{"id":2315},"Gcg7PGuICrlRcqq1QFXxH",{"json":2317},{"data":2318,"content":2319,"nodeType":1294},{},[2320,2327,2334,2365,2372,2378,2384,2396,2399,2407,2423,2430,2436,2443,2450,2456,2459,2467,2474,2480,2486,2493,2500,2518,2524,2527,2535,2553,2559,2566,2569,2577,2584,2591,2597,2603,2647,2654,2657,2665,2672,2679,2722,2729,2760,2767,2810,2817,2820,2828,2847,2854,2862,2877,2884,2903,2910,2913,2920,2927,2945,2948,2956,2975,2982,3105],{"data":2321,"content":2322,"nodeType":883},{},[2323],{"data":2324,"marks":2325,"value":2326,"nodeType":882},{},[],"Shared conversations on AI chatbot platforms have become the latest delivery mechanism for malware campaigns targeting macOS and Windows users. Attackers create content on platforms like ChatGPT and Claude that appears to offer installation guidance or service updates, then drive traffic to it via search engine results in the form of malvertising and SEO poisoning.  ",{"data":2328,"content":2329,"nodeType":883},{},[2330],{"data":2331,"marks":2332,"value":2333,"nodeType":882},{},[],"The content lives on chatgpt.com or claude.ai — domains that users and security tools trust implicitly — so the attack bypasses URL reputation checks before the victim even reaches the malicious payload.",{"data":2335,"content":2336,"nodeType":883},{},[2337,2341,2349,2353,2361],{"data":2338,"marks":2339,"value":2340,"nodeType":882},{},[],"Several variants of this technique have been ",{"data":2342,"content":2344,"nodeType":929},{"uri":2343},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fhackers-abuse-google-ads-claudeai-chats-to-push-mac-malware\u002F",[2345],{"data":2346,"marks":2347,"value":2348,"nodeType":882},{},[],"reported over the past few months",{"data":2350,"marks":2351,"value":2352,"nodeType":882},{},[],". The earliest examples used shared Claude.ai conversations disguised as installation guides — complete with fake \"Apple Support\" attribution — that walked users through opening a terminal and pasting a curl command that downloaded and executed an infostealer. ",{"data":2354,"content":2356,"nodeType":929},{"uri":2355},"https:\u002F\u002Fwww.kaspersky.com\u002Fblog\u002Fshare-chatgpt-chat-clickfix-macos-amos-infostealer\u002F54928\u002F",[2357],{"data":2358,"marks":2359,"value":2360,"nodeType":882},{},[],"Kaspersky documented a parallel campaign",{"data":2362,"marks":2363,"value":2364,"nodeType":882},{},[]," using shared ChatGPT conversations to deliver the AMOS (Atomic macOS Stealer) via the same paste-this-command social engineering pattern. ",{"data":2366,"content":2367,"nodeType":883},{},[2368],{"data":2369,"marks":2370,"value":2371,"nodeType":882},{},[],"Push has detected a new variant that goes beyond the previously reported technique of embedding terminal commands in shared conversations: the attacker has used ChatGPT's code rendering feature to build a fully designed fake page that mimics a ChatGPT service disruption, redirecting victims to a convincing clone of ChatGPT's download page that delivers a malicious executable. ",{"data":2373,"content":2377,"nodeType":963},{"target":2374},{"sys":2375},{"id":2376,"type":960,"linkType":961},"5lz9zt223pecGvdaqdvSTQ",[],{"data":2379,"content":2383,"nodeType":963},{"target":2380},{"sys":2381},{"id":2382,"type":960,"linkType":961},"51GomAj3VOjnbmgd1DWYu0",[],{"data":2385,"content":2386,"nodeType":883},{},[2387,2392],{"data":2388,"marks":2389,"value":2391,"nodeType":882},{},[2390],{"type":1012},"This is a live campaign which is still generating detections across our customer base at the time of writing. ",{"data":2393,"marks":2394,"value":2395,"nodeType":882},{},[],"Push customers are already protected and do not need to take further action. The malicious page URLs can be found at the end of this report but are not exhaustive and are liable to change. ",{"data":2397,"content":2398,"nodeType":967},{},[],{"data":2400,"content":2401,"nodeType":975},{},[2402],{"data":2403,"marks":2404,"value":2406,"nodeType":882},{},[2405],{"type":1012},"A fake page, not a fake conversation",{"data":2408,"content":2409,"nodeType":883},{},[2410,2414,2419],{"data":2411,"marks":2412,"value":2413,"nodeType":882},{},[],"Previously reported variants relied on shared ",{"data":2415,"marks":2416,"value":2418,"nodeType":882},{},[2417],{"type":1045},"conversations",{"data":2420,"marks":2421,"value":2422,"nodeType":882},{},[]," — the attacker created a chat that contained step-by-step instructions for the victim to follow, typically involving pasting a command into their terminal. The social engineering was conversational: the \"AI assistant\" appeared to be helpfully guiding the user through an installation process.",{"data":2424,"content":2425,"nodeType":883},{},[2426],{"data":2427,"marks":2428,"value":2429,"nodeType":882},{},[],"But now, rather than a shared conversation, the attacker has used ChatGPT's code rendering feature to create a fully designed, self-contained web page hosted at a chatgpt.com\u002Fs\u002F URL. It renders as what appears to be a ChatGPT service disruption notice:",{"data":2431,"content":2435,"nodeType":963},{"target":2432},{"sys":2433},{"id":2434,"type":960,"linkType":961},"1O9gyQab81SnbxhQp2aa5Z",[],{"data":2437,"content":2438,"nodeType":883},{},[2439],{"data":2440,"marks":2441,"value":2442,"nodeType":882},{},[],"A professional-looking error message reads: \"We're experiencing high traffic right now. Our website is temporarily unavailable due to a large number of users. Download our desktop app to continue.\" A prominent download button sits below.",{"data":2444,"content":2445,"nodeType":883},{},[2446],{"data":2447,"marks":2448,"value":2449,"nodeType":882},{},[],"The \"Show code\" toggle at the top of the page reveals what's actually happening — the entire thing is custom HTML and CSS, authored to mimic a ChatGPT system notice, rendered using ChatGPT's code output feature. A web page inside a web page, hosted on a domain that every URL reputation system in the world considers safe.",{"data":2451,"content":2455,"nodeType":963},{"target":2452},{"sys":2453},{"id":2454,"type":960,"linkType":961},"4kQTfxB3aVH9W9BeYOuljP",[],{"data":2457,"content":2458,"nodeType":967},{},[],{"data":2460,"content":2461,"nodeType":975},{},[2462],{"data":2463,"marks":2464,"value":2466,"nodeType":882},{},[2465],{"type":1012},"The download page",{"data":2468,"content":2469,"nodeType":883},{},[2470],{"data":2471,"marks":2472,"value":2473,"nodeType":882},{},[],"Clicking the download button redirects the user to openew[.]app, which presents a convincing clone of ChatGPT's official desktop application download page — complete with OpenAI branding, macOS and Windows download buttons, a Chrome extension link, and a mobile download section.",{"data":2475,"content":2479,"nodeType":963},{"target":2476},{"sys":2477},{"id":2478,"type":960,"linkType":961},"4MdFc4OB37ZihTGx506QJ6",[],{"data":2481,"content":2485,"nodeType":963},{"target":2482},{"sys":2483},{"id":2484,"type":960,"linkType":961},"LaPUy0zpIeY8s4PF2wkat",[],{"data":2487,"content":2488,"nodeType":883},{},[2489],{"data":2490,"marks":2491,"value":2492,"nodeType":882},{},[],"The site also displays differently depending on who visits it. When Push researchers examined the URL via URLScan, the scanner was redirected to a different page entirely — a generic AR\u002FVR company website with no obvious connection to ChatGPT. ",{"data":2494,"content":2495,"nodeType":883},{},[2496],{"data":2497,"marks":2498,"value":2499,"nodeType":882},{},[],"Real users in a browser see the fake download page; automated scanners and bots see something benign. This kind of conditional rendering is a well-established evasion technique in the malvertising ecosystem, and it makes the malicious infrastructure harder for security teams and threat intelligence services to identify and analyze.",{"data":2501,"content":2502,"nodeType":883},{},[2503,2507,2515],{"data":2504,"marks":2505,"value":2506,"nodeType":882},{},[],"The downloaded executable poses as \"ChatGPT for Desktop\" and is ",{"data":2508,"content":2510,"nodeType":929},{"uri":2509},"https:\u002F\u002Fwww.virustotal.com\u002Fgui\u002Ffile\u002Fde8c50e8ccd240ef9d10ec26c26eeb37a4d1cad7c1e0edf3bb6e5689ec2dde78",[2511],{"data":2512,"marks":2513,"value":2514,"nodeType":882},{},[],"flagged on VirusTotal",{"data":2516,"marks":2517,"value":1438,"nodeType":882},{},[],{"data":2519,"content":2523,"nodeType":963},{"target":2520},{"sys":2521},{"id":2522,"type":960,"linkType":961},"3FSbwoFJYQrcyo9uMsQIWI",[],{"data":2525,"content":2526,"nodeType":967},{},[],{"data":2528,"content":2529,"nodeType":975},{},[2530],{"data":2531,"marks":2532,"value":2534,"nodeType":882},{},[2533],{"type":1012},"The Claude variant: same campaign, different platform",{"data":2536,"content":2537,"nodeType":883},{},[2538,2542,2549],{"data":2539,"marks":2540,"value":2541,"nodeType":882},{},[],"Alongside the ChatGPT rendered-page variant, Push has also detected the previously reported style of attack using shared Claude.ai conversations. These follow the pattern documented by ",{"data":2543,"content":2544,"nodeType":929},{"uri":2343},[2545],{"data":2546,"marks":2547,"value":2548,"nodeType":882},{},[],"BleepingComputer",{"data":2550,"marks":2551,"value":2552,"nodeType":882},{},[],": a shared chat disguised as a \"Claude Code on Mac\" installation guide, attributed to \"Apple Support,\" containing a curl command that downloads and executes malware.",{"data":2554,"content":2558,"nodeType":963},{"target":2555},{"sys":2556},{"id":2557,"type":960,"linkType":961},"5sWayuTsVdiLSLoS4sv2Vc",[],{"data":2560,"content":2561,"nodeType":883},{},[2562],{"data":2563,"marks":2564,"value":2565,"nodeType":882},{},[],"The fact that both the ChatGPT and Claude variants are appearing in Push customer environments suggests a campaign — or at least a shared playbook — that is actively experimenting with different platforms and different social engineering approaches to find what converts best.",{"data":2567,"content":2568,"nodeType":967},{},[],{"data":2570,"content":2571,"nodeType":975},{},[2572],{"data":2573,"marks":2574,"value":2576,"nodeType":882},{},[2575],{"type":1012},"Malvertising remains one of the top phishing delivery channels",{"data":2578,"content":2579,"nodeType":883},{},[2580],{"data":2581,"marks":2582,"value":2583,"nodeType":882},{},[],"Push has detected this variant across multiple customer environments, with users arriving at these shared chat URLs after searching for terms including \"chatgpt,\" \"chatgpt free,\" \"chat gpt,\" and common typos like \"chatgo,\" \"chatgot,\" and \"cvhatgpt.\" ",{"data":2585,"content":2586,"nodeType":883},{},[2587],{"data":2588,"marks":2589,"value":2590,"nodeType":882},{},[],"You can see an example of this below: it's incredibly convincing, and uses the real ChatGPT domain — so even users that are paying attention are liable to fall for it. ",{"data":2592,"content":2596,"nodeType":963},{"target":2593},{"sys":2594},{"id":2595,"type":960,"linkType":961},"1GYWOyHpZT1rdTm6IGOKu8",[],{"data":2598,"content":2602,"nodeType":963},{"target":2599},{"sys":2600},{"id":2601,"type":960,"linkType":961},"4HpFJRAZH2lbygaEk2xOnN",[],{"data":2604,"content":2605,"nodeType":883},{},[2606,2610,2618,2622,2630,2634,2643],{"data":2607,"marks":2608,"value":2609,"nodeType":882},{},[],"This fits a pattern Push has tracked extensively. ",{"data":2611,"content":2613,"nodeType":929},{"uri":2612},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fverizon-dbir-2026-review\u002F",[2614],{"data":2615,"marks":2616,"value":2617,"nodeType":882},{},[],"Search-based delivery is now the dominant channel for malware distribution",{"data":2619,"marks":2620,"value":2621,"nodeType":882},{},[]," — our own data shows that ClickFix attacks are reached via search results rather than email in 4 of 5 cases, and Push's own research into ",{"data":2623,"content":2625,"nodeType":929},{"uri":2624},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fanalysing-a-sophisticated-google-malvertising-attack\u002F",[2626],{"data":2627,"marks":2628,"value":2629,"nodeType":882},{},[],"malvertising campaigns impersonating brands like TradingView",{"data":2631,"marks":2632,"value":2633,"nodeType":882},{},[]," and ",{"data":2635,"content":2637,"nodeType":929},{"uri":2636},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fgoogle-search-malvertising-campaign-continues-now-impersonating-ahrefs\u002F",[2638],{"data":2639,"marks":2640,"value":2642,"nodeType":882},{},[2641],{"type":927},"Ahrefs",{"data":2644,"marks":2645,"value":2646,"nodeType":882},{},[]," has demonstrated how effectively search ads can funnel victims to malicious pages. ",{"data":2648,"content":2649,"nodeType":883},{},[2650],{"data":2651,"marks":2652,"value":2653,"nodeType":882},{},[],"The shared-chat technique adds a new dimension: the destination URL itself is genuine (chatgpt.com, claude.ai), which means even a cautious user who checks the URL before clicking will see nothing suspicious.",{"data":2655,"content":2656,"nodeType":967},{},[],{"data":2658,"content":2659,"nodeType":975},{},[2660],{"data":2661,"marks":2662,"value":2664,"nodeType":882},{},[2663],{"type":1012},"Legitimate platform abuse is everywhere",{"data":2666,"content":2667,"nodeType":883},{},[2668],{"data":2669,"marks":2670,"value":2671,"nodeType":882},{},[],"This is one example of a much broader pattern that has become one of the defining characteristics of the 2026 threat landscape: attackers systematically abusing legitimate platforms as attack infrastructure. The scale and variety of this abuse in recent months alone is striking, and it spans every stage of the phishing chain.",{"data":2673,"content":2674,"nodeType":2050},{},[2675],{"data":2676,"marks":2677,"value":2678,"nodeType":882},{},[],"Legit platform abuse for delivery",{"data":2680,"content":2681,"nodeType":883},{},[2682,2686,2694,2698,2706,2710,2718],{"data":2683,"marks":2684,"value":2685,"nodeType":882},{},[],"On the delivery side, attackers have been ",{"data":2687,"content":2689,"nodeType":929},{"uri":2688},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Famazon-ses-increasingly-abused-in-phishing-to-evade-detection\u002F",[2690],{"data":2691,"marks":2692,"value":2693,"nodeType":882},{},[],"weaponizing stolen AWS credentials to send phishing through Amazon SES",{"data":2695,"marks":2696,"value":2697,"nodeType":882},{},[]," that passes SPF, DKIM, and DMARC validation because SES is a legitimate Amazon service. A Vietnamese operation dubbed ",{"data":2699,"content":2701,"nodeType":929},{"uri":2700},"https:\u002F\u002Fthehackernews.com\u002F2026\u002F05\u002F30000-facebook-accounts-hacked-via.html",[2702],{"data":2703,"marks":2704,"value":2705,"nodeType":882},{},[],"AccountDumpling used Google AppSheet's built-in email capability",{"data":2707,"marks":2708,"value":2709,"nodeType":882},{},[]," as a phishing relay to harvest 30,000 Facebook credentials. ",{"data":2711,"content":2713,"nodeType":929},{"uri":2712},"https:\u002F\u002Ftechcrunch.com\u002F2026\u002F05\u002F21\u002Fscammers-are-abusing-an-internal-microsoft-account-to-send-spam\u002F",[2714],{"data":2715,"marks":2716,"value":2717,"nodeType":882},{},[],"Scammers exploited Microsoft's own internal notification pipeline",{"data":2719,"marks":2720,"value":2721,"nodeType":882},{},[]," — sending phishing from the same msonlineservicesteam@microsoftonline.com address that delivers legitimate 2FA codes — with Spamhaus confirming months of ongoing abuse.",{"data":2723,"content":2724,"nodeType":2050},{},[2725],{"data":2726,"marks":2727,"value":2728,"nodeType":882},{},[],"Legit platform abuse for hosting",{"data":2730,"content":2731,"nodeType":883},{},[2732,2736,2744,2748,2756],{"data":2733,"marks":2734,"value":2735,"nodeType":882},{},[],"For hosting, the platforms being abused read like a who's who of modern web infrastructure. ",{"data":2737,"content":2739,"nodeType":929},{"uri":2738},"https:\u002F\u002Fwww.securityweek.com\u002Fover-500-organizations-hit-in-years-long-phishing-campaign\u002F",[2740],{"data":2741,"marks":2742,"value":2743,"nodeType":882},{},[],"Operation HookedWing ran for four years",{"data":2745,"marks":2746,"value":2747,"nodeType":882},{},[]," on GitHub Pages and Vercel, compromising 500+ organizations across more than 100 GitHub Pages domains before anyone documented it publicly. Cofense has separately ",{"data":2749,"content":2751,"nodeType":929},{"uri":2750},"https:\u002F\u002Fcofense.com\u002Fblog\u002Fsteal-smarter-not-harder-malicious-use-of-vercel-for-credential-phishing\u002F",[2752],{"data":2753,"marks":2754,"value":2755,"nodeType":882},{},[],"documented the growing abuse of Vercel",{"data":2757,"marks":2758,"value":2759,"nodeType":882},{},[]," for credential phishing hosting. Pixm's Q1 2026 phishing report tracked over 100 unique Azure Blob Storage subdomain variants hosting phishing content that carried Microsoft's own domain reputation, alongside abuse of Cloudflare CDN, Cloudflare Workers, Cloudflare R2, Backblaze B2, and Supabase. ",{"data":2761,"content":2762,"nodeType":2050},{},[2763],{"data":2764,"marks":2765,"value":2766,"nodeType":882},{},[],"Abuse of compromised websites that are otherwise legit",{"data":2768,"content":2769,"nodeType":883},{},[2770,2774,2782,2786,2794,2798,2806],{"data":2771,"marks":2772,"value":2773,"nodeType":882},{},[],"Compromised legitimate sites are also being repurposed at scale. A mass exploitation of a ",{"data":2775,"content":2777,"nodeType":929},{"uri":2776},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fghost-cms-sql-injection-flaw-exploited-in-large-scale-clickfix-campaign\u002F",[2778],{"data":2779,"marks":2780,"value":2781,"nodeType":882},{},[],"Ghost CMS vulnerability planted ClickFix pages across 700+ websites",{"data":2783,"marks":2784,"value":2785,"nodeType":882},{},[]," including Harvard, Oxford, and DuckDuckGo subdomains. Microsoft recently documented a campaign where ",{"data":2787,"content":2789,"nodeType":929},{"uri":2788},"https:\u002F\u002Fwww.microsoft.com\u002Fen-us\u002Fsecurity\u002Fblog\u002F2026\u002F05\u002F26\u002Fpoisoned-search-results-gpu-mining-cryptojacking-campaign-abusing-screenconnect-microsoft-net-utilities\u002F",[2790],{"data":2791,"marks":2792,"value":2793,"nodeType":882},{},[],"SEO poisoning was combined with AI chatbot recommendation manipulation",{"data":2795,"marks":2796,"value":2797,"nodeType":882},{},[]," to deliver GPU mining malware — extending the poisoning from traditional search results into AI-generated software recommendations. And ",{"data":2799,"content":2801,"nodeType":929},{"uri":2800},"https:\u002F\u002Fwww.helpnetsecurity.com\u002F2026\u002F05\u002F27\u002Fdeno-rat-malware-fake-chatgpt-claude-installers\u002F",[2802],{"data":2803,"marks":2804,"value":2805,"nodeType":882},{},[],"fake ChatGPT and Claude installers on GitHub and SourceForge",{"data":2807,"marks":2808,"value":2809,"nodeType":882},{},[]," have been delivering the DinDoor backdoor and a Deno-based RAT via repositories that mimic legitimate developer tool distributions.",{"data":2811,"content":2812,"nodeType":883},{},[2813],{"data":2814,"marks":2815,"value":2816,"nodeType":882},{},[],"The structural problem is that every one of these platforms is genuinely legitimate, and the security controls that evaluate them — domain reputation, email authentication, URL categorization — confirm them as trusted because they are trusted. This attack extends this pattern into new territory by weaponizing the content-sharing features of AI chatbot platforms specifically, but the underlying principles are the same. ",{"data":2818,"content":2819,"nodeType":967},{},[],{"data":2821,"content":2822,"nodeType":975},{},[2823],{"data":2824,"marks":2825,"value":2827,"nodeType":882},{},[2826],{"type":1012},"Impact analysis",{"data":2829,"content":2830,"nodeType":883},{},[2831,2835,2843],{"data":2832,"marks":2833,"value":2834,"nodeType":882},{},[],"Shared-chat malware delivery exploits a structural property of AI platforms that traditional security controls aren't designed to handle. Domain reputation, URL categorization, and safe browsing databases all treat chatgpt.com and claude.ai as trusted — because they are. Using these trusted pages to link off to further convincing-looking pages hosting malware allows the attacker to run campaigns that blend in, as well as rotate the phishing delivery pages later in the chain should they ever be flagged, allowing the campaign to continue without interruption (a well known ",{"data":2836,"content":2838,"nodeType":929},{"uri":2837},"https:\u002F\u002Fphishing-techniques.pushsecurity.com\u002F",[2839],{"data":2840,"marks":2841,"value":2842,"nodeType":882},{},[],"detection evasion technique",{"data":2844,"marks":2845,"value":2846,"nodeType":882},{},[],"). ",{"data":2848,"content":2849,"nodeType":883},{},[2850],{"data":2851,"marks":2852,"value":2853,"nodeType":882},{},[],"What makes the rendered-page variant particularly concerning is that it eliminates the most obvious red flag in the earlier attacks. The Claude.ai conversation variants required the victim to recognize that a shared chat instructing them to paste terminal commands might be suspicious — a tall order for many users, but at least the attack surface was visible. The rendered-page variant shows nothing that looks like an attack. It presents what appears to be a routine service disruption with a reasonable call to action: download the desktop app to continue using ChatGPT. ",{"data":2855,"content":2856,"nodeType":2050},{},[2857],{"data":2858,"marks":2859,"value":2861,"nodeType":882},{},[2860],{"type":1012},"How Push detected the attack",{"data":2863,"content":2864,"nodeType":883},{},[2865,2869,2873],{"data":2866,"marks":2867,"value":2868,"nodeType":882},{},[],"We've aligned our detection logic for this technique under the name ",{"data":2870,"marks":2871,"value":2015,"nodeType":882},{},[2872],{"type":1012},{"data":2874,"marks":2875,"value":2876,"nodeType":882},{},[]," — a technique-level detection that covers shared content abuse across LLM platforms, not tied to any single campaign or set of IOCs. ",{"data":2878,"content":2879,"nodeType":883},{},[2880],{"data":2881,"marks":2882,"value":2883,"nodeType":882},{},[],"Because Push sees the full context of how a user arrived at a page and what that page does once it renders, we can identify LLMShare attacks regardless of which AI platform is being abused or what social engineering wrapper the attacker has chosen. ",{"data":2885,"content":2886,"nodeType":883},{},[2887,2891,2899],{"data":2888,"marks":2889,"value":2890,"nodeType":882},{},[],"When we identified the initial instances of this campaign, we used our ",{"data":2892,"content":2894,"nodeType":929},{"uri":2893},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fcan-ai-replace-a-threat-researcher-what-we-learned-building-an-agentic-threat-hunting-pipeline\u002F",[2895],{"data":2896,"marks":2897,"value":2898,"nodeType":882},{},[],"agentic threat hunting pipeline",{"data":2900,"marks":2901,"value":2902,"nodeType":882},{},[]," to hunt for additional examples across our customer telemetry, develop the LLMShare detection, and rapidly deploy it to customers. Push blocks users from interacting with the page before any malicious activity can occur. ",{"data":2904,"content":2905,"nodeType":883},{},[2906],{"data":2907,"marks":2908,"value":2909,"nodeType":882},{},[],"Push customers do not need to take any further action.",{"data":2911,"content":2912,"nodeType":967},{},[],{"data":2914,"content":2915,"nodeType":883},{},[2916],{"data":2917,"marks":2918,"value":2919,"nodeType":882},{},[],"Push Security is the most powerful AI-native security tool in the browser. Think EDR, but for the browser — high-fidelity telemetry and real-time control across every session, on every device, with no browser migration required.",{"data":2921,"content":2922,"nodeType":883},{},[2923],{"data":2924,"marks":2925,"value":2926,"nodeType":882},{},[],"Security teams use Push to detect and stop advanced browser-based attacks like AiTM phishing, ClickFix, and session hijacking; gain visibility and control over AI tool usage across their workforce; harden identities by surfacing credential reuse, SSO gaps, and shadow IT; and support data loss and insider investigations with browser-layer telemetry that other tools can't see.",{"data":2928,"content":2929,"nodeType":883},{},[2930,2933,2942],{"data":2931,"marks":2932,"value":21,"nodeType":882},{},[],{"data":2934,"content":2936,"nodeType":929},{"uri":2935},"https:\u002F\u002Fpushsecurity.com\u002Fdemo\u002F",[2937],{"data":2938,"marks":2939,"value":2941,"nodeType":882},{},[2940],{"type":927},"Book a live demo to learn more.",{"data":2943,"marks":2944,"value":21,"nodeType":882},{},[],{"data":2946,"content":2947,"nodeType":967},{},[],{"data":2949,"content":2950,"nodeType":975},{},[2951],{"data":2952,"marks":2953,"value":2955,"nodeType":882},{},[2954],{"type":1012},"Indicators of compromise",{"data":2957,"content":2958,"nodeType":883},{},[2959,2963,2971],{"data":2960,"marks":2961,"value":2962,"nodeType":882},{},[],"As we always say, short-lived IoCs are of limited value when tackling modern phishing attacks due to the rate at which attackers are able to ",{"data":2964,"content":2966,"nodeType":929},{"uri":2965},"https:\u002F\u002Fphishing-techniques.pushsecurity.com\u002Ftechniques\u002Fdomain-rotation-redirection\u002F",[2967],{"data":2968,"marks":2969,"value":2970,"nodeType":882},{},[],"quickly spin up and rotate the sites used",{"data":2972,"marks":2973,"value":2974,"nodeType":882},{},[]," in the attack chain. IoC-based detections for campaigns like this are of limited value.",{"data":2976,"content":2977,"nodeType":883},{},[2978],{"data":2979,"marks":2980,"value":2981,"nodeType":882},{},[],"At the time of writing, the indicators observed were:",{"data":2983,"content":2984,"nodeType":3104},{},[2985,3012,3036,3058,3081],{"data":2986,"content":2987,"nodeType":3011},{},[2988,3000],{"data":2989,"content":2990,"nodeType":2999},{},[2991],{"data":2992,"content":2993,"nodeType":883},{},[2994],{"data":2995,"marks":2996,"value":2998,"nodeType":882},{},[2997],{"type":1012},"Indicator","table-header-cell",{"data":3001,"content":3002,"nodeType":2999},{},[3003],{"data":3004,"content":3005,"nodeType":883},{},[3006],{"data":3007,"marks":3008,"value":3010,"nodeType":882},{},[3009],{"type":1012},"Type","table-row",{"data":3013,"content":3014,"nodeType":3011},{},[3015,3026],{"data":3016,"content":3017,"nodeType":3025},{},[3018],{"data":3019,"content":3020,"nodeType":883},{},[3021],{"data":3022,"marks":3023,"value":3024,"nodeType":882},{},[],"hxxps:\u002F\u002Fclaude[.]ai\u002Fshare\u002F8e6401b5-4849-46c4-a3cb-29e1c3c49131","table-cell",{"data":3027,"content":3028,"nodeType":3025},{},[3029],{"data":3030,"content":3031,"nodeType":883},{},[3032],{"data":3033,"marks":3034,"value":3035,"nodeType":882},{},[],"URL",{"data":3037,"content":3038,"nodeType":3011},{},[3039,3049],{"data":3040,"content":3041,"nodeType":3025},{},[3042],{"data":3043,"content":3044,"nodeType":883},{},[3045],{"data":3046,"marks":3047,"value":3048,"nodeType":882},{},[],"hxxps:\u002F\u002Fchatgpt[.]com\u002Fs\u002Fcb_6a0f1e6bbec88191aa7fede27163f08d",{"data":3050,"content":3051,"nodeType":3025},{},[3052],{"data":3053,"content":3054,"nodeType":883},{},[3055],{"data":3056,"marks":3057,"value":3035,"nodeType":882},{},[],{"data":3059,"content":3060,"nodeType":3011},{},[3061,3071],{"data":3062,"content":3063,"nodeType":3025},{},[3064],{"data":3065,"content":3066,"nodeType":883},{},[3067],{"data":3068,"marks":3069,"value":3070,"nodeType":882},{},[],"openew[.]app",{"data":3072,"content":3073,"nodeType":3025},{},[3074],{"data":3075,"content":3076,"nodeType":883},{},[3077],{"data":3078,"marks":3079,"value":3080,"nodeType":882},{},[],"Domain",{"data":3082,"content":3083,"nodeType":3011},{},[3084,3094],{"data":3085,"content":3086,"nodeType":3025},{},[3087],{"data":3088,"content":3089,"nodeType":883},{},[3090],{"data":3091,"marks":3092,"value":3093,"nodeType":882},{},[],"de8c50e8ccd240ef9d10ec26c26eeb37a4d1cad7c1e0edf3bb6e5689ec2dde78",{"data":3095,"content":3096,"nodeType":3025},{},[3097],{"data":3098,"content":3099,"nodeType":883},{},[3100],{"data":3101,"marks":3102,"value":3103,"nodeType":882},{},[],"SHA256","table",{"data":3106,"content":3107,"nodeType":883},{},[3108],{"data":3109,"marks":3110,"value":21,"nodeType":882},{},[],"LLMShare: how attackers are turning AI chatbot pages into malware delivery platforms","How attackers are using shared content features on AI chatbot platforms to deliver malware via pages hosted on legitimate domains, sent via malvertising.","2026-05-29T00:00:00.000Z","llmshare-malvertising-campaign",{"items":3116},[3117,3119],{"sys":3118,"name":2308},{"id":2307},{"sys":3120,"name":343},{"id":2304},{"items":3122},[3123],{"fullName":3124,"firstName":3125,"jobTitle":3126,"profilePicture":3127},"Keanu Maharaj","Keanu","Senior Security Researcher",{"url":3128},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002FVCGOm62jiocjwngWTh32U\u002Fe9a30637b1c76bf988d2fec90f5b6c36\u002F1689361049351_1.png",{"__typename":1365,"sys":3130,"content":3132,"title":3898,"synopsis":3899,"hashTags":59,"publishedDate":3900,"slug":3901,"tagsCollection":3902,"authorsCollection":3908},{"id":3131},"5RDOpmzJolwT1hk0fNIxzf",{"json":3133},{"data":3134,"content":3135,"nodeType":1294},{},[3136,3155,3161,3168,3175,3178,3186,3205,3224,3231,3237,3244,3250,3257,3265,3272,3290,3322,3328,3334,3342,3349,3368,3399,3431,3438,3444,3452,3459,3470,3477,3518,3524,3565,3604,3610,3613,3621,3628,3634,3641,3648,3654,3661,3668,3696,3699,3707,3714,3722,3729,3736,3755,3762,3768,3775,3783,3790,3807,3814,3833,3836,3844,3851,3858,3865,3868,3874,3880],{"data":3137,"content":3138,"nodeType":883},{},[3139,3143,3151],{"data":3140,"marks":3141,"value":3142,"nodeType":882},{},[],"Back in 2024, we wrote about ",{"data":3144,"content":3146,"nodeType":929},{"uri":3145},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Four-design-philosophy-detecting-what-matters\u002F",[3147],{"data":3148,"marks":3149,"value":3150,"nodeType":882},{},[],"how the Pyramid of Pain shapes Push's detection philosophy",{"data":3152,"marks":3153,"value":3154,"nodeType":882},{},[]," — detections targeting indicators that are easy for attackers to change deliver diminishing returns, while detections targeting attacker techniques impose a cost that's hard to absorb. Two years on, every force that made IoC-based detection fragile has intensified.",{"data":3156,"content":3160,"nodeType":963},{"target":3157},{"sys":3158},{"id":3159,"type":960,"linkType":961},"1iuLYxwI8T1wDUIFSom0G0",[],{"data":3162,"content":3163,"nodeType":883},{},[3164],{"data":3165,"marks":3166,"value":3167,"nodeType":882},{},[],"AI hasn't introduced a new problem so much as it's compressed the timelines on an existing one — attackers can generate infrastructure, iterate on tooling, and industrialize newly discovered techniques faster than before. The bottom layers of the Pyramid are collapsing under the weight of machine-speed operations, and the middle layers are starting to buckle too.",{"data":3169,"content":3170,"nodeType":883},{},[3171],{"data":3172,"marks":3173,"value":3174,"nodeType":882},{},[],"These changes mean that technique-level detection is more important than ever. In this article, we’ll dig into how the Pyramid is changing, and what this means for our detection philosophy at Push (TL;DR — it reinforces the path we’re already on: building detections at the top of the Pyramid by harnessing browser visibility). ",{"data":3176,"content":3177,"nodeType":967},{},[],{"data":3179,"content":3180,"nodeType":975},{},[3181],{"data":3182,"marks":3183,"value":3185,"nodeType":882},{},[3184],{"type":1012},"The bottom of the Pyramid was already crumbling",{"data":3187,"content":3188,"nodeType":883},{},[3189,3193,3201],{"data":3190,"marks":3191,"value":3192,"nodeType":882},{},[],"The case against indicator-based detection didn't need AI to be compelling. ",{"data":3194,"content":3196,"nodeType":929},{"uri":3195},"https:\u002F\u002Fwww.spamhaus.org\u002F",[3197],{"data":3198,"marks":3199,"value":3200,"nodeType":882},{},[],"89% of phishing domains are active for fewer than two days",{"data":3202,"marks":3203,"value":3204,"nodeType":882},{},[],", with just 6.5% surviving past 15 days — by the time a domain makes it onto a blocklist, the campaign has moved on.",{"data":3206,"content":3207,"nodeType":883},{},[3208,3212,3220],{"data":3209,"marks":3210,"value":3211,"nodeType":882},{},[],"We've ",{"data":3213,"content":3215,"nodeType":929},{"uri":3214},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fwhy-most-phishing-attacks-feel-like-a-zero-day\u002F",[3216],{"data":3217,"marks":3218,"value":3219,"nodeType":882},{},[],"written before",{"data":3221,"marks":3222,"value":3223,"nodeType":882},{},[]," about how this makes every phishing attack effectively a zero-day for organizations relying on known-bad detection. The phishing kit's behavior — its page structure, script signatures, malicious payload mechanics — is the only detection target that outlasts a single campaign.",{"data":3225,"content":3226,"nodeType":883},{},[3227],{"data":3228,"marks":3229,"value":3230,"nodeType":882},{},[],"When we blogged about the Pyramid of Pain for modern attacks that happen predominantly over the internet, with minimal (or zero) endpoint contact, it first looked like this: ",{"data":3232,"content":3236,"nodeType":963},{"target":3233},{"sys":3234},{"id":3235,"type":960,"linkType":961},"2N04ycJ6RKGfHdX5X1TwU3",[],{"data":3238,"content":3239,"nodeType":883},{},[3240],{"data":3241,"marks":3242,"value":3243,"nodeType":882},{},[],"Now, it looks more like this:",{"data":3245,"content":3249,"nodeType":963},{"target":3246},{"sys":3247},{"id":3248,"type":960,"linkType":961},"mfhP4WToOQkrHnVkXU0tX",[],{"data":3251,"content":3252,"nodeType":883},{},[3253],{"data":3254,"marks":3255,"value":3256,"nodeType":882},{},[],"Let’s explore why. ",{"data":3258,"content":3259,"nodeType":2050},{},[3260],{"data":3261,"marks":3262,"value":3264,"nodeType":882},{},[3263],{"type":1012},"AI is accelerating phishing rotation and delivery",{"data":3266,"content":3267,"nodeType":883},{},[3268],{"data":3269,"marks":3270,"value":3271,"nodeType":882},{},[],"Attackers are harnessing AI at every stage, speeding up the process of creating, rotating, and replacing phishing infrastructure at every level, as well as capitalizing on AI adoption itself to enhance their lures. The operational signature is more domains, shorter lifespans, more variation, and fewer of the reuse patterns that blocklists depend on.",{"data":3273,"content":3274,"nodeType":883},{},[3275,3279,3286],{"data":3276,"marks":3277,"value":3278,"nodeType":882},{},[],"Attackers can ",{"data":3280,"content":3281,"nodeType":929},{"uri":2893},[3282],{"data":3283,"marks":3284,"value":3285,"nodeType":882},{},[],"vibe-code entire phishing pages in minutes",{"data":3287,"marks":3288,"value":3289,"nodeType":882},{},[]," — not just cloning legitimate login pages but vibe-cloning them, feeding an AI a screenshot and having it rebuild a convincing frontend with a completely unique backend. ",{"data":3291,"content":3292,"nodeType":883},{},[3293,3297,3306,3310,3318],{"data":3294,"marks":3295,"value":3296,"nodeType":882},{},[],"We've seen attackers clone free SaaS tools like background removers and PDF converters, then inject phishing components or ClickFix payloads into what looks like a functional utility. We’ve even seen attackers distributing malware using AI-generated pages shared using ",{"data":3298,"content":3300,"nodeType":929},{"uri":3299},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fllmshare-malvertising-campaign\u002F",[3301],{"data":3302,"marks":3303,"value":3305,"nodeType":882},{},[3304],{"type":927},"LLM tool sharing functionality",{"data":3307,"marks":3308,"value":3309,"nodeType":882},{},[],", resulting in phishing delivery pages hosted on real claude.ai and chatgpt.com. And legitimate cloud platforms like ",{"data":3311,"content":3313,"nodeType":929},{"uri":3312},"https:\u002F\u002Fwww.huntress.com\u002Fblog\u002Frailway-paas-m365-token-replay-campaign",[3314],{"data":3315,"marks":3316,"value":3317,"nodeType":882},{},[],"Railway",{"data":3319,"marks":3320,"value":3321,"nodeType":882},{},[],", Cloudflare Workers, and Vercel host and dynamically rotate attack infrastructure, so the domains feeding into blocklists often belong to reputable services that can't simply be blocked. ",{"data":3323,"content":3327,"nodeType":963},{"target":3324},{"sys":3325},{"id":3326,"type":960,"linkType":961},"5yoLmqysyQazfzLITCUTfc",[],{"data":3329,"content":3333,"nodeType":963},{"target":3330},{"sys":3331},{"id":3332,"type":960,"linkType":961},"5XK5qZMQU19xlA8L2T5y0Z",[],{"data":3335,"content":3336,"nodeType":2050},{},[3337],{"data":3338,"marks":3339,"value":3341,"nodeType":882},{},[3340],{"type":1012},"The kit ecosystem is fragmenting faster than anyone can track",{"data":3343,"content":3344,"nodeType":883},{},[3345],{"data":3346,"marks":3347,"value":3348,"nodeType":882},{},[],"What we see across our install base is a huge and growing variation in phishing kits — new kits, derivative kits of known platforms, derivatives of those derivatives — appearing on a weekly basis.",{"data":3350,"content":3351,"nodeType":883},{},[3352,3356,3364],{"data":3353,"marks":3354,"value":3355,"nodeType":882},{},[],"As we reported in our ",{"data":3357,"content":3359,"nodeType":929},{"uri":3358},"https:\u002F\u002Fpushsecurity.com\u002Fthank-you\u002Fbrowser-attacks-report",[3360],{"data":3361,"marks":3362,"value":3363,"nodeType":882},{},[],"Browser Attacks Report",{"data":3365,"marks":3366,"value":3367,"nodeType":882},{},[],", the most common AiTM kits we detected over the last year were Tycoon 2FA (59% of detections), followed by Sneaky 2FA, FlowerStorm, Evilginx (nominally a red team tool, but widely abused by attackers), NakedPages, Gabagool, and dozens more — but those established names are just the visible layer.",{"data":3369,"content":3370,"nodeType":883},{},[3371,3375,3383,3387,3395],{"data":3372,"marks":3373,"value":3374,"nodeType":882},{},[],"Code is forked, modified, and redeployed across kits in a pattern that ",{"data":3376,"content":3378,"nodeType":929},{"uri":3377},"https:\u002F\u002Fblog.barracuda.com\u002F2026\u002F04\u002F16\u002Fthreat-spotlight-tycoon-2fa-scattered-everywhere",[3379],{"data":3380,"marks":3381,"value":3382,"nodeType":882},{},[],"resembles open-source development",{"data":3384,"marks":3385,"value":3386,"nodeType":882},{},[]," more than traditional criminal enterprise, and the rate at which new variants appear is accelerating. The ",{"data":3388,"content":3390,"nodeType":929},{"uri":3389},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fdevice-code-phishing\u002F",[3391],{"data":3392,"marks":3393,"value":3394,"nodeType":882},{},[],"Venom kit",{"data":3396,"marks":3397,"value":3398,"nodeType":882},{},[]," reuses Sneaky 2FA's AiTM infrastructure but carries different branding and adds device code phishing — whether it's the same developers, stolen code, or a deliberate fork is unclear.",{"data":3400,"content":3401,"nodeType":883},{},[3402,3406,3414,3418,3427],{"data":3403,"marks":3404,"value":3405,"nodeType":882},{},[],"Tycoon 2FA illustrates the scale of the evolution. The kit evolves continuously, addingnew capabilities, new evasion techniques, and hybridizing with other platforms. Even when Sekoia and Microsoft seized 330+ Tycoon domains in March 2026, the techniques it popularized were already embedded across competitors, and the slack was taken up by rival platforms within days. And in any case, Tycoon was back to ",{"data":3407,"content":3409,"nodeType":929},{"uri":3408},"https:\u002F\u002Fwww.crowdstrike.com\u002Fen-us\u002Fblog\u002Ftycoon2fa-phishing-as-a-service-platform-persists-following-takedown\u002F",[3410],{"data":3411,"marks":3412,"value":3413,"nodeType":882},{},[],"normal levels of operation",{"data":3415,"marks":3416,"value":3417,"nodeType":882},{},[]," shortly after. It has also been observed ",{"data":3419,"content":3421,"nodeType":929},{"uri":3420},"https:\u002F\u002Fwww.okta.com\u002Fen-nl\u002Fblog\u002Fthreat-intelligence\u002Ftycoon_2fa_phishing_actors_scatter\u002F",[3422],{"data":3423,"marks":3424,"value":3426,"nodeType":882},{},[3425],{"type":927},"pivoting to add new device code phishing capabilities",{"data":3428,"marks":3429,"value":3430,"nodeType":882},{},[]," (more on that below). ",{"data":3432,"content":3433,"nodeType":883},{},[3434],{"data":3435,"marks":3436,"value":3437,"nodeType":882},{},[],"Tear one down and there are many more to take its place — and meanwhile the original is already evolving into something new.",{"data":3439,"content":3443,"nodeType":963},{"target":3440},{"sys":3441},{"id":3442,"type":960,"linkType":961},"3UDzUCCizPJhXp3SsoZuSK",[],{"data":3445,"content":3446,"nodeType":2050},{},[3447],{"data":3448,"marks":3449,"value":3451,"nodeType":882},{},[3450],{"type":1012},"New techniques are being industrialized faster than ever",{"data":3453,"content":3454,"nodeType":883},{},[3455],{"data":3456,"marks":3457,"value":3458,"nodeType":882},{},[],"As well as the fragmentation of existing kits, we’re seeing new techniques added at an accelerating rate. ",{"data":3460,"content":3461,"nodeType":883},{},[3462,3466],{"data":3463,"marks":3464,"value":361,"nodeType":882},{},[3465],{"type":1012},{"data":3467,"marks":3468,"value":3469,"nodeType":882},{},[]," is the clearest case study. From early nation state adoption in 2024, it took until 2026 for criminal adoption to really take off, but the take-up this year is unprecedented. The EvilTokens kit packaged device code phishing into a PhaaS offering with GPT-powered spear-phishing and adaptive landing pages, hitting 340+ organizations across five countries in March 2026. ",{"data":3471,"content":3472,"nodeType":883},{},[3473],{"data":3474,"marks":3475,"value":3476,"nodeType":882},{},[],"Now, device code functionality is now a core phish kit component. We’re tracking 18+ kits with device code phishing capabilities and a 37.5x increase in device code phishing detections this year alone, with the technique moving from state-sponsored exclusivity to something any PhaaS customer can rent.",{"data":3478,"content":3479,"nodeType":883},{},[3480,3484,3492,3496,3501,3505,3514],{"data":3481,"marks":3482,"value":3483,"nodeType":882},{},[],"Similarly, when we ",{"data":3485,"content":3487,"nodeType":929},{"uri":3486},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Finside-criminal-phishing-panel",[3488],{"data":3489,"marks":3490,"value":3491,"nodeType":882},{},[],"infiltrated Doko's Panel",{"data":3493,"marks":3494,"value":3495,"nodeType":882},{},[]," — a ",{"data":3497,"marks":3498,"value":3500,"nodeType":882},{},[3499],{"type":1012},"real-time vishing and AiTM platform",{"data":3502,"marks":3503,"value":3504,"nodeType":882},{},[]," used by ShinyHunters and affiliated groups — the codebase was full of LLM-generated artifacts. Multiple groups were using the templated vishing panel and spinning up their own variants, but the AI-generated indicators persisted throughout. This approach to real-time vishing + browser payload has been a ",{"data":3506,"content":3508,"nodeType":929},{"uri":3507},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fanalyzing-the-instructure-breach\u002F",[3509],{"data":3510,"marks":3511,"value":3513,"nodeType":882},{},[3512],{"type":927},"mainstay of the Com affiliates like ShinyHunters this year",{"data":3515,"marks":3516,"value":3517,"nodeType":882},{},[],". ",{"data":3519,"content":3523,"nodeType":963},{"target":3520},{"sys":3521},{"id":3522,"type":960,"linkType":961},"01mOiserRBXraawXwQyJNm",[],{"data":3525,"content":3526,"nodeType":883},{},[3527,3531,3535,3539,3548,3552,3561],{"data":3528,"marks":3529,"value":3530,"nodeType":882},{},[],"The broader ",{"data":3532,"marks":3533,"value":316,"nodeType":882},{},[3534],{"type":1012},{"data":3536,"marks":3537,"value":3538,"nodeType":882},{},[]," family shows the same acceleration: First reported in early 2024 and adopted by four nation-state groups within a single quarter. Fast forward and ",{"data":3540,"content":3542,"nodeType":929},{"uri":3541},"https:\u002F\u002Fwww.crowdstrike.com\u002Fen-us\u002Fglobal-threat-report\u002F",[3543],{"data":3544,"marks":3545,"value":3547,"nodeType":882},{},[3546],{"type":927},"CrowdStrike's data",{"data":3549,"marks":3550,"value":3551,"nodeType":882},{},[]," shows a 563% increase in fake CAPTCHA incidents (one of the more common ClickFix lure types), while ",{"data":3553,"content":3555,"nodeType":929},{"uri":3554},"https:\u002F\u002Fcdn-dynmedia-1.microsoft.com\u002Fis\u002Fcontent\u002Fmicrosoftcorp\u002Fmicrosoft\u002Fmsc\u002Fdocuments\u002Fpresentations\u002FCSR\u002FMicrosoft-Digital-Defense-Report-2025.pdf",[3556],{"data":3557,"marks":3558,"value":3560,"nodeType":882},{},[3559],{"type":927},"Microsoft reported",{"data":3562,"marks":3563,"value":3564,"nodeType":882},{},[]," it as making up 47% of observed attacks according to their Digital Defense Report.",{"data":3566,"content":3567,"nodeType":883},{},[3568,3572,3576,3580,3588,3592,3600],{"data":3569,"marks":3570,"value":3571,"nodeType":882},{},[],"And ",{"data":3573,"marks":3574,"value":1989,"nodeType":882},{},[3575],{"type":1012},{"data":3577,"marks":3578,"value":3579,"nodeType":882},{},[]," — a combination of ClickFix and OAuth consent phishing techniques — suggests the next compression is already underway. Push researchers ",{"data":3581,"content":3583,"nodeType":929},{"uri":3582},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fconsentfix\u002F",[3584],{"data":3585,"marks":3586,"value":3587,"nodeType":882},{},[],"discovered the technique",{"data":3589,"marks":3590,"value":3591,"nodeType":882},{},[]," in December 2025 — a browser-native ClickFix variant hijacking OAuth consent grants via Azure CLI's localhost redirect. It was later confirmed to be tied to APT29. By January 2026, a ",{"data":3593,"content":3595,"nodeType":929},{"uri":3594},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fconsentfix-v3-analyzing-a-new-toolkit\u002F",[3596],{"data":3597,"marks":3598,"value":3599,"nodeType":882},{},[],"criminal ConsentFix v3 toolkit",{"data":3601,"marks":3602,"value":3603,"nodeType":882},{},[]," had appeared on the XSS forum with Cloudflare Workers, ZoomInfo targeting, and automated exfiltration via Pipedream.",{"data":3605,"content":3609,"nodeType":963},{"target":3606},{"sys":3607},{"id":3608,"type":960,"linkType":961},"41FMif4T0y1maflzonWgL8",[],{"data":3611,"content":3612,"nodeType":967},{},[],{"data":3614,"content":3615,"nodeType":975},{},[3616],{"data":3617,"marks":3618,"value":3620,"nodeType":882},{},[3619],{"type":1012},"Why technique-level detection is the only layer that holds",{"data":3622,"content":3623,"nodeType":883},{},[3624],{"data":3625,"marks":3626,"value":3627,"nodeType":882},{},[],"The middle of the Pyramid — tool signatures and artifacts — used to offer much more durable detection than infrastructure indicators. Fingerprinting a specific phishing kit by its JavaScript structure or HTML patterns provided a detection target that survived across dozens or hundreds of campaigns, even as the underlying domains rotated. Tool level detections are still better, but not by quite the same margin.",{"data":3629,"content":3633,"nodeType":963},{"target":3630},{"sys":3631},{"id":3632,"type":960,"linkType":961},"5pxaYdCIFiFKLPhRaPoldX",[],{"data":3635,"content":3636,"nodeType":883},{},[3637],{"data":3638,"marks":3639,"value":3640,"nodeType":882},{},[],"When the kit landscape was dominated by a handful of platforms, you could write signatures for Tycoon, Sneaky2FA, EvilProxy, and so on, and cover the lion's share of attacks. With the ecosystem now producing new variants and entirely new kits on a weekly basis, detecting by kit fingerprint starts to look uncomfortably similar to detecting by domain.",{"data":3642,"content":3643,"nodeType":883},{},[3644],{"data":3645,"marks":3646,"value":3647,"nodeType":882},{},[],"But many of these proliferating kits do share behavioral patterns at a deeper level than their code signatures. For example, every device code phishing kit implements fundamentally the same flow: present a lure, generate a device code via the OAuth Device Authorization endpoint, get the user to enter it on the legitimate authorization page, and poll for the resulting tokens. The frontends vary, the infrastructure varies, but the behavioral pattern doesn't.",{"data":3649,"content":3653,"nodeType":963},{"target":3650},{"sys":3651},{"id":3652,"type":960,"linkType":961},"FyyHayQtsJTwoB1kluMOl",[],{"data":3655,"content":3656,"nodeType":883},{},[3657],{"data":3658,"marks":3659,"value":3660,"nodeType":882},{},[],"Genuinely new attack techniques still require human creativity — an attacker has to identify a gap in how a legitimate protocol or feature can be subverted. That kind of innovation hasn't been automated. But the window to discover a technique, build a detection, and then deploy it before it is adopted by criminals at scale is compressing with each generation.",{"data":3662,"content":3663,"nodeType":883},{},[3664],{"data":3665,"marks":3666,"value":3667,"nodeType":882},{},[],"Organizations that detect at the technique level and deploy before commoditization have a structural advantage that increases over time. Waiting for indicators — even tool-level indicators — means chasing a curve that's accelerating away from you. This is the challenge we grapple with every day as we strive for the most resilient detections possible. ",{"data":3669,"content":3670,"nodeType":3695},{},[3671],{"data":3672,"content":3673,"nodeType":883},{},[3674,3678,3686,3690],{"data":3675,"marks":3676,"value":3677,"nodeType":882},{},[],"As our CPO Jacques Louw put it on ",{"data":3679,"content":3681,"nodeType":929},{"uri":3680},"https:\u002F\u002Frisky.biz\u002FRBNEWSSI128\u002F",[3682],{"data":3683,"marks":3684,"value":3685,"nodeType":882},{},[],"Risky Business",{"data":3687,"marks":3688,"value":3689,"nodeType":882},{},[],": ",{"data":3691,"marks":3692,"value":3694,"nodeType":882},{},[3693],{"type":1045},"\"There's no list of bad domains anywhere in the product. It's a crutch — a false cheat code that stops you from doing the detection in the way that actually is resilient, because the next time you see it, it will be on a different domain.\"","blockquote",{"data":3697,"content":3698,"nodeType":967},{},[],{"data":3700,"content":3701,"nodeType":975},{},[3702],{"data":3703,"marks":3704,"value":3706,"nodeType":882},{},[3705],{"type":1012},"What it takes to detect at the top of the Pyramid",{"data":3708,"content":3709,"nodeType":883},{},[3710],{"data":3711,"marks":3712,"value":3713,"nodeType":882},{},[],"If technique-level detection is the only layer that holds, two things have to be true about your detection capability: You need the right vantage point, and you need the research velocity to stay ahead.",{"data":3715,"content":3716,"nodeType":2050},{},[3717],{"data":3718,"marks":3719,"value":3721,"nodeType":882},{},[3720],{"type":1012},"You need the right vantage point",{"data":3723,"content":3724,"nodeType":883},{},[3725],{"data":3726,"marks":3727,"value":3728,"nodeType":882},{},[],"Technique-level behaviors in browser-based identity attacks — how a phishing page orchestrates credential entry, how a device code flow presents its authorization prompt, how a ClickFix variant manipulates the clipboard — are visible in the browser session and nowhere else.",{"data":3730,"content":3731,"nodeType":883},{},[3732],{"data":3733,"marks":3734,"value":3735,"nodeType":882},{},[],"Network proxies see encrypted traffic and can attempt to reconstruct page behavior from metadata, but DOM manipulation, user interaction sequences, and script execution aren't visible from that vantage point. Email gateways see the delivery mechanism (or nothing at all in the increasing number of social media and search engine based attacks) but not the payload.",{"data":3737,"content":3738,"nodeType":883},{},[3739,3743,3751],{"data":3740,"marks":3741,"value":3742,"nodeType":882},{},[],"As we disclosed in our ",{"data":3744,"content":3745,"nodeType":929},{"uri":3358},[3746],{"data":3747,"marks":3748,"value":3750,"nodeType":882},{},[3749],{"type":927},"browser attacks report",{"data":3752,"marks":3753,"value":3754,"nodeType":882},{},[],", 95% of in-browser attacks we detect use some form of bot protection, often combined with conditional loading techniques like referrer and browser checks, reliably defeating automated analysis techniques. ",{"data":3756,"content":3757,"nodeType":883},{},[3758],{"data":3759,"marks":3760,"value":3761,"nodeType":882},{},[],"Behavioral detection at the technique level requires observing what happens on the page at the moment the user interacts with it — analyzing pages, not links. When you see the entire browsing flow — ad click, redirect chain, page render, credential prompt — an attack stands out immediately. Without that context, any detection system is forced to fill in gaps, and the gaps are where attacks hide.",{"data":3763,"content":3767,"nodeType":963},{"target":3764},{"sys":3765},{"id":3766,"type":960,"linkType":961},"4804g6u4POUDpL42bzP0EY",[],{"data":3769,"content":3770,"nodeType":883},{},[3771],{"data":3772,"marks":3773,"value":3774,"nodeType":882},{},[],"Push sits inside the browser session, observing this in real time. Its detections target the behavioral mechanics of techniques rather than the surface characteristics of individual kits or infrastructure.",{"data":3776,"content":3777,"nodeType":2050},{},[3778],{"data":3779,"marks":3780,"value":3782,"nodeType":882},{},[3781],{"type":1012},"You need the research expertise",{"data":3784,"content":3785,"nodeType":883},{},[3786],{"data":3787,"marks":3788,"value":3789,"nodeType":882},{},[],"When the window between technique discovery and industrialized exploitation is measured in weeks rather than years, the detection pipeline needs to operate on that same compressed timescale.",{"data":3791,"content":3792,"nodeType":883},{},[3793,3797,3803],{"data":3794,"marks":3795,"value":3796,"nodeType":882},{},[],"This is where our ",{"data":3798,"content":3799,"nodeType":929},{"uri":2893},[3800],{"data":3801,"marks":3802,"value":2898,"nodeType":882},{},[],{"data":3804,"marks":3805,"value":3806,"nodeType":882},{},[]," fits. It's tripled our monthly detection output — not by generating bigger blocklists, but by scaling the process of discovering behavioral patterns across the telemetry generated by 3+ million browser deployments.",{"data":3808,"content":3809,"nodeType":883},{},[3810],{"data":3811,"marks":3812,"value":3813,"nodeType":882},{},[],"The detections it produces are technique-class by design, targeting how attacks work rather than the infrastructure or specific tool that implements them. The goal is curation, not accumulation — hundreds of high-fidelity behavioral detections rather than the billions of signatures and domain entries that traditional approaches require.",{"data":3815,"content":3816,"nodeType":883},{},[3817,3821,3829],{"data":3818,"marks":3819,"value":3820,"nodeType":882},{},[],"When we detected the first in-the-wild ",{"data":3822,"content":3824,"nodeType":929},{"uri":3823},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Finstallfix\u002F",[3825],{"data":3826,"marks":3827,"value":3828,"nodeType":882},{},[],"InstallFix attack",{"data":3830,"marks":3831,"value":3832,"nodeType":882},{},[]," through the pipeline — a user had searched for NotebookLM, clicked a paid Google ad, and was redirected to a fake page with a WebAssembly C2 connector — the detection shipped to all customers within minutes. It didn't depend on knowing the domain, the ad creative, or the specific kit. It depended on recognizing the technique itself.",{"data":3834,"content":3835,"nodeType":967},{},[],{"data":3837,"content":3838,"nodeType":975},{},[3839],{"data":3840,"marks":3841,"value":3843,"nodeType":882},{},[3842],{"type":1012},"Technique-level detection is now the only option",{"data":3845,"content":3846,"nodeType":883},{},[3847],{"data":3848,"marks":3849,"value":3850,"nodeType":882},{},[],"As a framework for detection durability, the Pyramid of Pain is more relevant than ever. ",{"data":3852,"content":3853,"nodeType":883},{},[3854],{"data":3855,"marks":3856,"value":3857,"nodeType":882},{},[],"AI has made infrastructure indicators essentially disposable. The tools tier is compressing as criminal vendors vibe-code, fork, and clone tooling at machine speed. Technique-level detection is the layer that holds long-term to be able to proactively detect and block net-new attacks and the kits that power them. ",{"data":3859,"content":3860,"nodeType":883},{},[3861],{"data":3862,"marks":3863,"value":3864,"nodeType":882},{},[],"Novel attack techniques still require human creativity to discover, and detections built around how those techniques work can survive infrastructure rotation, tool proliferation, and kit fragmentation. Defending that layer requires a vantage point inside the browser session and a research pipeline fast enough to stay ahead of the accelerating path from discovery to industrialization.",{"data":3866,"content":3867,"nodeType":967},{},[],{"data":3869,"content":3870,"nodeType":883},{},[3871],{"data":3872,"marks":3873,"value":2919,"nodeType":882},{},[],{"data":3875,"content":3876,"nodeType":883},{},[3877],{"data":3878,"marks":3879,"value":2926,"nodeType":882},{},[],{"data":3881,"content":3882,"nodeType":883},{},[3883,3886,3894],{"data":3884,"marks":3885,"value":21,"nodeType":882},{},[],{"data":3887,"content":3888,"nodeType":929},{"uri":1283},[3889],{"data":3890,"marks":3891,"value":3893,"nodeType":882},{},[3892],{"type":927},"Book a live demo",{"data":3895,"marks":3896,"value":3897,"nodeType":882},{},[]," to learn more.","The Pyramid of Pain in the AI era: Why technique-level detection matters more than ever","AI is accelerating the collapse of indicator-based threat detection. Here's why you need technique-level detection to stay ahead.","2026-06-01T00:00:00.000Z","the-pyramid-of-pain-in-the-ai-era",{"items":3903},[3904,3906],{"sys":3905,"name":343},{"id":2304},{"sys":3907,"name":2308},{"id":2307},{"items":3909},[3910],{"fullName":3911,"firstName":3912,"jobTitle":3913,"profilePicture":3914},"Dan Green","Dan","Threat Research",{"url":3915},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F7jik1VhFgA3kgzXBXTm2Vw\u002Ffcd8c171da644903d0827eafcfbcaad0\u002FDan_Headshot_2025.png","from-iocs-to-ttps-an-agentic-threat-hunting-case-study","blog\u002Ffrom-iocs-to-ttps-an-agentic-threat-hunting-case-study",{"json":3919},{"data":3920,"content":3921,"nodeType":1294},{},[3922],{"data":3923,"content":3924,"nodeType":883},{},[3925],{"data":3926,"marks":3927,"value":3928,"nodeType":882},{},[],"Here’s how Push’s agentic detection pipeline turns intel into huntable characteristics of attacker behavior, deriving durable detections from a range of sources. In this case study, we’ll look at how we were able to raise an alert the first time a novel OAuth redirect abuse technique was observed in customer environments.","How Push’s agentic detection pipeline turns intel into huntable characteristics of attacker behavior, deriving durable detections from a range of sources.",{"id":3931,"publishedAt":3932},"4fUZAVpkaksHImeoT8jp0f","2026-08-26T11:58:15.300Z",{"items":3934},[3935,3937],{"sys":3936,"name":2308},{"id":2307},{"sys":3938,"name":343},{"id":2304},{"items":3940},[3941,3943,3945,3947,3949,3951,3953,3955],{"sys":3942,"name":352,"slug":353,"tier":45},{"id":349},{"sys":3944,"name":599,"slug":600,"tier":45},{"id":596},{"sys":3946,"name":379,"slug":380,"tier":45},{"id":376},{"sys":3948,"name":623,"slug":624,"tier":45},{"id":620},{"sys":3950,"name":388,"slug":389,"tier":45},{"id":385},{"sys":3952,"name":280,"slug":281,"tier":31},{"id":277},{"sys":3954,"name":298,"slug":299,"tier":31},{"id":295},{"sys":3956,"name":343,"slug":344,"tier":31},{"id":340},"bqRrjJoZ9alBHiGqx5wgBq-hDr1fk3FfxBhejsCjwv0",{"id":3959,"title":3960,"authorsCollection":3961,"content":3970,"extension":228,"faqItemsCollection":4549,"faqTitle":5188,"featured":6,"hashTags":59,"meta":5189,"metaTitle":5190,"ogImage":59,"postType":1360,"publishedDate":5191,"relatedBlogPostsCollection":5192,"slug":8029,"stem":8030,"subtitle":59,"summary":8031,"synopsis":8042,"sys":8043,"tagsCollection":8046,"topicsCollection":8052,"__hash__":8062},"blog\u002Fblog\u002Fthe-top-10-browser-security-solutions-in-2026.json","The top 10 browser security solutions: Push Security, Island, LayerX and more",{"items":3962},[3963],{"fullName":3964,"firstName":3965,"jobTitle":868,"socialLinks":3966,"profilePicture":3968},"Alex Henshall","Alex",[3967],"https:\u002F\u002Fwww.linkedin.com\u002Fin\u002Falexhenshall\u002F",{"url":3969},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F2rz3Pre3b1MexPIQ4hzPUe\u002F0ef8a092b7e7df00fbce3f7d1ccb96d1\u002FAlex_Henshall.jpeg",{"json":3971,"links":4442},{"data":3972,"content":3973,"nodeType":1294},{},[3974,3981,3988,4019,4026,4034,4040,4043,4051,4094,4113,4119,4122,4130,4137,4156,4159,4167,4174,4181,4184,4192,4199,4206,4209,4217,4224,4242,4245,4253,4260,4267,4270,4278,4285,4292,4295,4303,4322,4325,4333,4340,4347,4353,4356,4364,4371,4378,4381,4389,4395,4413,4419,4425],{"data":3975,"content":3976,"nodeType":883},{},[3977],{"data":3978,"marks":3979,"value":3980,"nodeType":882},{},[],"Ask a security team where most of their tools are and it's the endpoint, network, or cloud. But ask where their users spend most of their time and it's the browser.",{"data":3982,"content":3983,"nodeType":883},{},[3984],{"data":3985,"marks":3986,"value":3987,"nodeType":882},{},[],"So we got a category: browser security. And when it comes to the best browser security tools, there's a problem. Browser security means three different things depending on who's talking: enterprise browser extensions, enterprise browsers, and remote browser isolation (RBI).",{"data":3989,"content":3990,"nodeType":883},{},[3991,3995,4003,4007,4015],{"data":3992,"marks":3993,"value":3994,"nodeType":882},{},[],"The market reflects that confusion, but the momentum is real. According to ",{"data":3996,"content":3998,"nodeType":929},{"uri":3997},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002F7-things-omdias-latest-report-tells-us-about-the-secure-enterprise-browser-market",[3999],{"data":4000,"marks":4001,"value":4002,"nodeType":882},{},[],"Omdia's 2026 research",{"data":4004,"marks":4005,"value":4006,"nodeType":882},{},[],", browser security is already a top-five priority for 88% of organizations and the top priority for 26%, with 86% having meaningfully increased their browser security spending in response to emerging threats. ",{"data":4008,"content":4010,"nodeType":929},{"uri":4009},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fthe-case-for-best-of-breed-browser-security",[4011],{"data":4012,"marks":4013,"value":4014,"nodeType":882},{},[],"Three browser security startups were acquired",{"data":4016,"marks":4017,"value":4018,"nodeType":882},{},[]," by major platform vendors in 2026 alone — CrowdStrike bought Seraphic, Zscaler absorbed SquareX, and Akamai announced intent to acquire LayerX.",{"data":4020,"content":4021,"nodeType":883},{},[4022],{"data":4023,"marks":4024,"value":4025,"nodeType":882},{},[],"Here's what the browser security market looks like in 2026.",{"data":4027,"content":4028,"nodeType":883},{},[4029],{"data":4030,"marks":4031,"value":4033,"nodeType":882},{},[4032],{"type":1012},"The top enterprise browser solutions in 2026 include Push Security, Island, and LayerX.",{"data":4035,"content":4039,"nodeType":963},{"target":4036},{"sys":4037},{"id":4038,"type":960,"linkType":961},"5d35fpWpgIytQhhiABQray",[],{"data":4041,"content":4042,"nodeType":967},{},[],{"data":4044,"content":4045,"nodeType":975},{},[4046],{"data":4047,"marks":4048,"value":4050,"nodeType":882},{},[4049],{"type":1012},"1. Push Security – Enterprise browser extension",{"data":4052,"content":4053,"nodeType":883},{},[4054,4058,4066,4070,4078,4082,4090],{"data":4055,"marks":4056,"value":4057,"nodeType":882},{},[],"Push is a browser extension, not a browser, that turns whatever browser your people already use into a detection and response platform for the security team. With no migration, no user disruption, no new browser to manage. It covers ",{"data":4059,"content":4061,"nodeType":929},{"uri":4060},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fthe-top-10-security-problems-you-can-solve-in-the-browser-ranked-by-value",[4062],{"data":4063,"marks":4064,"value":4065,"nodeType":882},{},[],"four use cases from a single deployment",{"data":4067,"marks":4068,"value":4069,"nodeType":882},{},[],": detecting and stopping sophisticated browser-based attacks, AI visibility and control, identity and shadow IT security, and DLP and insider investigations. Detections are built on ",{"data":4071,"content":4073,"nodeType":929},{"uri":4072},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fhow-to-avoid-the-browser-security-buyers-trap",[4074],{"data":4075,"marks":4076,"value":4077,"nodeType":882},{},[],"in-house threat research",{"data":4079,"marks":4080,"value":4081,"nodeType":882},{},[]," and operationalized by autonomous agents, so what Push catches is based on attacker techniques and behaviors rather than a blocklist. It ",{"data":4083,"content":4085,"nodeType":929},{"uri":4084},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fmaking-the-business-case-for-a-browser-security-solution",[4086],{"data":4087,"marks":4088,"value":4089,"nodeType":882},{},[],"deploys in minutes",{"data":4091,"marks":4092,"value":4093,"nodeType":882},{},[]," across managed and unmanaged devices.",{"data":4095,"content":4096,"nodeType":883},{},[4097,4101,4109],{"data":4098,"marks":4099,"value":4100,"nodeType":882},{},[],"Push detects AiTM and device code phishing kits (",{"data":4102,"content":4103,"nodeType":929},{"uri":1316},[4104],{"data":4105,"marks":4106,"value":4108,"nodeType":882},{},[4107],{"type":927},"75+ across Tycoon 2FA, Sneaky 2FA, Evilginx, and many others",{"data":4110,"marks":4111,"value":4112,"nodeType":882},{},[],") behaviorally by analyzing page structure and script execution — so detection survives infrastructure rotation. It catches ClickFix-style clipboard injection before the payload executes, detects stolen session tokens via marker injection when they appear in uninstrumented browsers, and monitors OAuth consent flows across 20+ authorization servers. Push is deployed across 3 million browsers worldwide and has been rolled out to 100,000 users in under one hour during normal office hours.",{"data":4114,"content":4118,"nodeType":963},{"target":4115},{"sys":4116},{"id":4117,"type":960,"linkType":961},"ZmRwtfBPVptxTOE6wt1Yq",[],{"data":4120,"content":4121,"nodeType":967},{},[],{"data":4123,"content":4124,"nodeType":975},{},[4125],{"data":4126,"marks":4127,"value":4129,"nodeType":882},{},[4128],{"type":1012},"2. Island – Enterprise browser",{"data":4131,"content":4132,"nodeType":883},{},[4133],{"data":4134,"marks":4135,"value":4136,"nodeType":882},{},[],"Island was one of the first to market in the enterprise browser category and still defines it. It replaces current browsers with a managed Chromium fork that gives IT granular control over copy-paste, screenshots, downloads, session recording, and application access — all enforced at the browser level without routing traffic through a proxy. For highly regulated environments where that degree of governance is a requirement, it's a capable platform with real enterprise traction.",{"data":4138,"content":4139,"nodeType":883},{},[4140,4144,4153],{"data":4141,"marks":4142,"value":4143,"nodeType":882},{},[],"It's a full browser replacement, with primary use cases around VDI replacement, contractor access, BYOD governance, and zero-trust network access. Most organizations plan for a ",{"data":4145,"content":4147,"nodeType":929},{"uri":4146},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fenterprise-browser-vs-browser-extension-which-should-your-security-team-choose",[4148],{"data":4149,"marks":4150,"value":4152,"nodeType":882},{},[4151],{"type":927},"phased rollout",{"data":4154,"marks":4155,"value":1438,"nodeType":882},{},[],{"data":4157,"content":4158,"nodeType":967},{},[],{"data":4160,"content":4161,"nodeType":975},{},[4162],{"data":4163,"marks":4164,"value":4166,"nodeType":882},{},[4165],{"type":1012},"3. Prisma Browser – Enterprise browser",{"data":4168,"content":4169,"nodeType":883},{},[4170],{"data":4171,"marks":4172,"value":4173,"nodeType":882},{},[],"Formerly Talon, now Palo Alto Networks' enterprise browser and the last-mile enforcement layer of its SASE platform. Prisma Browser is a managed Chromium browser with DLP that inspects the rendered page and zero-trust access controls, designed primarily for contractor, BYOD, and remote worker populations accessing corporate apps from unmanaged devices.",{"data":4175,"content":4176,"nodeType":883},{},[4177],{"data":4178,"marks":4179,"value":4180,"nodeType":882},{},[],"Like Island, it's a browser replacement. It integrates natively with the broader Prisma Access and Cortex stack, feeding browser telemetry into Palo Alto Networks' existing correlation and response workflows.",{"data":4182,"content":4183,"nodeType":967},{},[],{"data":4185,"content":4186,"nodeType":975},{},[4187],{"data":4188,"marks":4189,"value":4191,"nodeType":882},{},[4190],{"type":1012},"4. Seraphic Security (CrowdStrike) – Enterprise browser extension",{"data":4193,"content":4194,"nodeType":883},{},[4195],{"data":4196,"marks":4197,"value":4198,"nodeType":882},{},[],"Seraphic works across any browser through an endpoint agent that adds enterprise security without replacing what's deployed. CrowdStrike acquired Seraphic in early 2026 to extend Falcon past the endpoint and into the browser layer, with the stated goal of correlating endpoint and browser telemetry in a single platform.",{"data":4200,"content":4201,"nodeType":883},{},[4202],{"data":4203,"marks":4204,"value":4205,"nodeType":882},{},[],"For existing CrowdStrike customers, the extension into the browser is a natural addition to the Falcon ecosystem. Cross-browser coverage remains a differentiator for mixed environments.",{"data":4207,"content":4208,"nodeType":967},{},[],{"data":4210,"content":4211,"nodeType":975},{},[4212],{"data":4213,"marks":4214,"value":4216,"nodeType":882},{},[4215],{"type":1012},"5. LayerX Security (Akamai) – Enterprise browser extension",{"data":4218,"content":4219,"nodeType":883},{},[4220],{"data":4221,"marks":4222,"value":4223,"nodeType":882},{},[],"LayerX is extension-based, focused on real-time DLP and AI governance which captures what happens inside AI tools, flagging sensitive data submissions, and enforcing policy, all without requiring a new browser. Low deployment friction and a growing AI visibility capability are the draw.",{"data":4225,"content":4226,"nodeType":883},{},[4227,4231,4238],{"data":4228,"marks":4229,"value":4230,"nodeType":882},{},[],"Akamai announced the intent to acquire LayerX in mid-2026 to complement its Zero Trust portfolio. For buyers evaluating LayerX as a long-term platform bet, the ",{"data":4232,"content":4233,"nodeType":929},{"uri":4009},[4234],{"data":4235,"marks":4236,"value":4237,"nodeType":882},{},[],"question is what the roadmap looks like 18 months post-close",{"data":4239,"marks":4240,"value":4241,"nodeType":882},{},[],", given Akamai's track record of absorbing acquisitions (Guardicore, Neosec, Inverse) into its broader platform.",{"data":4243,"content":4244,"nodeType":967},{},[],{"data":4246,"content":4247,"nodeType":975},{},[4248],{"data":4249,"marks":4250,"value":4252,"nodeType":882},{},[4251],{"type":1012},"6. SquareX (Zscaler) – Enterprise browser extension",{"data":4254,"content":4255,"nodeType":883},{},[4256],{"data":4257,"marks":4258,"value":4259,"nodeType":882},{},[],"SquareX takes a detection-minded posture, inspecting files and links while browsing, neutralizing malicious content before it reaches the endpoint, and offering disposable browser environments for high-risk activity. It was clearly built by people who think in attacker terms.",{"data":4261,"content":4262,"nodeType":883},{},[4263],{"data":4264,"marks":4265,"value":4266,"nodeType":882},{},[],"Zscaler acquired SquareX in early 2026, integrating it into the Zero Trust Exchange alongside its existing SSE capabilities.",{"data":4268,"content":4269,"nodeType":967},{},[],{"data":4271,"content":4272,"nodeType":975},{},[4273],{"data":4274,"marks":4275,"value":4277,"nodeType":882},{},[4276],{"type":1012},"7. Keep Aware – Enterprise browser extension",{"data":4279,"content":4280,"nodeType":883},{},[4281],{"data":4282,"marks":4283,"value":4284,"nodeType":882},{},[],"Keep Aware is an agentless extension built with security operations in mind. It's quick to deploy through MDM or group policy, and focused on surfacing browser threats, extension risk, and AI usage into existing SOC workflows. Detection and response is the throughline, with SIEM integration as a core part of the offering.",{"data":4286,"content":4287,"nodeType":883},{},[4288],{"data":4289,"marks":4290,"value":4291,"nodeType":882},{},[],"Founded in 2022, Keep Aware has been iterating quickly with a focused product roadmap around browser detection and response.",{"data":4293,"content":4294,"nodeType":967},{},[],{"data":4296,"content":4297,"nodeType":975},{},[4298],{"data":4299,"marks":4300,"value":4302,"nodeType":882},{},[4301],{"type":1012},"8. Menlo Security – Remote browser isolation",{"data":4304,"content":4305,"nodeType":883},{},[4306,4310,4318],{"data":4307,"marks":4308,"value":4309,"nodeType":882},{},[],"Menlo pioneered ",{"data":4311,"content":4313,"nodeType":929},{"uri":4312},"https:\u002F\u002Fpushsecurity.com\u002Fsolution\u002Ftool-replacements\u002Fremote-browser-isolation",[4314],{"data":4315,"marks":4316,"value":4317,"nodeType":882},{},[],"remote browser isolation",{"data":4319,"marks":4320,"value":4321,"nodeType":882},{},[],": web content renders in a disposable cloud container and the user receives a clean visual stream, so nothing malicious ever touches the endpoint. For zero-tolerance environments and third-party or contractor access where you don't fully trust the device, the approach has a solid track record. Cloud rendering introduces latency and the occasional site-compatibility issue, though Menlo has invested in reducing both over the years.",{"data":4323,"content":4324,"nodeType":967},{},[],{"data":4326,"content":4327,"nodeType":975},{},[4328],{"data":4329,"marks":4330,"value":4332,"nodeType":882},{},[4331],{"type":1012},"9. Chrome Enterprise \u002F Edge for Business – Enterprise browser",{"data":4334,"content":4335,"nodeType":883},{},[4336],{"data":4337,"marks":4338,"value":4339,"nodeType":882},{},[],"The security controls are already built into the browsers most of your people use. Chrome Enterprise offers centralized management, Safe Browsing, and identity tool integration across the fleet; Edge for Business adds work-and-personal separation, phishing protection, and tight integration with Microsoft 365 and Defender.",{"data":4341,"content":4342,"nodeType":883},{},[4343],{"data":4344,"marks":4345,"value":4346,"nodeType":882},{},[],"These are baseline controls, and for many organizations they're effectively free with what's already deployed. Most organizations treat them as the foundation that the rest of the tools on this list build on.",{"data":4348,"content":4352,"nodeType":963},{"target":4349},{"sys":4350},{"id":4351,"type":960,"linkType":961},"7Gbd8bBWa19gP5DMfeeB7J",[],{"data":4354,"content":4355,"nodeType":967},{},[],{"data":4357,"content":4358,"nodeType":975},{},[4359],{"data":4360,"marks":4361,"value":4363,"nodeType":882},{},[4362],{"type":1012},"10. SURF Security – Enterprise browser",{"data":4365,"content":4366,"nodeType":883},{},[4367],{"data":4368,"marks":4369,"value":4370,"nodeType":882},{},[],"SURF is a Chromium-based enterprise browser built zero-trust-first, with identity-based access controls, DLP, and session security inside a fully managed environment. Centralized, policy-driven control by default is the pitch, aimed at security-first organizations that want a locked-down browser from day one.",{"data":4372,"content":4373,"nodeType":883},{},[4374],{"data":4375,"marks":4376,"value":4377,"nodeType":882},{},[],"Like Island and Prisma, it's a browser replacement, so it follows the same deployment model — plan for a migration alongside the capabilities.",{"data":4379,"content":4380,"nodeType":967},{},[],{"data":4382,"content":4383,"nodeType":975},{},[4384],{"data":4385,"marks":4386,"value":4388,"nodeType":882},{},[4387],{"type":1012},"Learn more about Push Security",{"data":4390,"content":4391,"nodeType":883},{},[4392],{"data":4393,"marks":4394,"value":2919,"nodeType":882},{},[],{"data":4396,"content":4397,"nodeType":883},{},[4398,4402,4409],{"data":4399,"marks":4400,"value":4401,"nodeType":882},{},[],"Push is the best choice for organizations looking to ",{"data":4403,"content":4404,"nodeType":929},{"uri":4060},[4405],{"data":4406,"marks":4407,"value":4408,"nodeType":882},{},[],"solve the most impactful security problems in the browse",{"data":4410,"marks":4411,"value":4412,"nodeType":882},{},[],"r, with use cases including detecting and stopping advanced attacks, data loss and insider investigations, identity and shadow IT security, and AI visibility and control. ",{"data":4414,"content":4418,"nodeType":963},{"target":4415},{"sys":4416},{"id":4417,"type":960,"linkType":961},"4nGzT9cNG0Yid93uUCCuTt",[],{"data":4420,"content":4421,"nodeType":883},{},[4422],{"data":4423,"marks":4424,"value":2926,"nodeType":882},{},[],{"data":4426,"content":4427,"nodeType":883},{},[4428,4432,4439],{"data":4429,"marks":4430,"value":4431,"nodeType":882},{},[],"Book a ",{"data":4433,"content":4434,"nodeType":929},{"uri":1283},[4435],{"data":4436,"marks":4437,"value":4438,"nodeType":882},{},[],"live demo",{"data":4440,"marks":4441,"value":3897,"nodeType":882},{},[],{"entries":4443},{"hyperlink":4444,"inline":4445,"block":4446},[],[],[4447,4478,4503,4541],{"sys":4448,"__typename":1302,"content":4449,"name":4477,"title":59},{"id":4038},{"json":4450},{"data":4451,"content":4452,"nodeType":1294},{},[4453,4470],{"data":4454,"content":4455,"nodeType":883},{},[4456,4460,4467],{"data":4457,"marks":4458,"value":4459,"nodeType":882},{},[],"Enterprise browsers are also commonly referred to as Secure Enterprise Browsers (SEBs). These are functionally the same thing, but buyers looking specifically for Secure Enterprise Browsers tend to be focused more on security use-cases (protecting users, and by extension business, from external threats). But all enterprise browsers tend to cover security use cases to a ",{"data":4461,"content":4462,"nodeType":929},{"uri":4060},[4463],{"data":4464,"marks":4465,"value":4466,"nodeType":882},{},[],"lesser or greater degree",{"data":4468,"marks":4469,"value":3517,"nodeType":882},{},[],{"data":4471,"content":4472,"nodeType":883},{},[4473],{"data":4474,"marks":4475,"value":4476,"nodeType":882},{},[],"So, this list applies to Secure Enterprise Browsers too. ","Top 10 browser solutions IB3",{"sys":4479,"__typename":1302,"content":4480,"name":4502,"title":59},{"id":4117},{"json":4481},{"data":4482,"content":4483,"nodeType":1294},{},[4484],{"data":4485,"content":4486,"nodeType":883},{},[4487,4491,4499],{"data":4488,"marks":4489,"value":4490,"nodeType":882},{},[],"In a 30-day proof-of-value deployment at a ~4,500-employee financial services organization with a mature existing security stack, Push detected and blocked 6 ClickFix attacks and 10 AiTM phishing attempts — none of which were visible to any other tool in place. ",{"data":4492,"content":4494,"nodeType":929},{"uri":4493},"https:\u002F\u002Fpushsecurity.com\u002Fcustomer-stories",[4495],{"data":4496,"marks":4497,"value":4498,"nodeType":882},{},[],"You can read more customer stories here",{"data":4500,"marks":4501,"value":3517,"nodeType":882},{},[],"Top 10 browser solutions IB1",{"sys":4504,"__typename":1302,"content":4505,"name":4540,"title":59},{"id":4351},{"json":4506},{"nodeType":1294,"data":4507,"content":4508},{},[4509],{"nodeType":883,"data":4510,"content":4511},{},[4512,4516,4524,4528,4536],{"nodeType":882,"value":4513,"marks":4514,"data":4515},"According to ",[],{},{"nodeType":929,"data":4517,"content":4518},{"uri":3997},[4519],{"nodeType":882,"value":4520,"marks":4521,"data":4523},"Omdia",[4522],{"type":927},{},{"nodeType":882,"value":4525,"marks":4526,"data":4527},", 86% of organizations have meaningfully increased browser security investment in response to emerging threats — 85% expect to spend more over the next 12–24 months. The built-in controls in Chrome and Edge are a foundation, but they're ",[],{},{"nodeType":929,"data":4529,"content":4530},{"uri":4084},[4531],{"nodeType":882,"value":4532,"marks":4533,"data":4535},"insufficient against the current threat landscape",[4534],{"type":927},{},{"nodeType":882,"value":4537,"marks":4538,"data":4539}," on their own.",[],{},"Top 10 browser solutions IB2",{"sys":4542,"__typename":1329,"title":4543,"caption":4544,"layoutMode":59,"file":4545},{"id":4417},"Comparing ease of deployment x security value for browser security solutions","Comparing ease of deployment x security value for browser security solutions.",{"url":4546,"width":4547,"height":4548},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F4z1RAFROesqaBF4H3qR8yu\u002F1e21a68602402773bfa843fd0208d4ca\u002FScreenshot_2026-07-27_at_10.36.43.png",1408,952,{"items":4550},[4551,4575,4612,4635,4666,4693,4830,4865,4924,5027,5051,5105,5157],{"answer":4552,"question":4574},{"json":4553},{"nodeType":1294,"data":4554,"content":4555},{},[4556],{"nodeType":883,"data":4557,"content":4558},{},[4559,4563,4570],{"nodeType":882,"value":4560,"marks":4561,"data":4562},"Browser security refers to the tools and practices that protect users, data, and organizations from threats that originate inside the web browser. The browser is where modern work happens: employees access SaaS applications, interact with AI tools, and handle sensitive data — which makes it ",[],{},{"nodeType":929,"data":4564,"content":4565},{"uri":4060},[4566],{"nodeType":882,"value":4567,"marks":4568,"data":4569},"the most targeted attack surface in the enterprise",[],{},{"nodeType":882,"value":4571,"marks":4572,"data":4573},". When people discuss browser security solutions, they usually mean secure enterprise browser (SEB) extensions or full-stack enterprise browsers. Remote browser isolation (RBI) is a third category that is not really comparable to the other two, but comes up through virtue of sounding similar. ",[],{},"What is browser security?",{"answer":4576,"question":4611},{"json":4577},{"nodeType":1294,"data":4578,"content":4579},{},[4580,4587,4594],{"nodeType":883,"data":4581,"content":4582},{},[4583],{"nodeType":882,"value":4584,"marks":4585,"data":4586},"An enterprise browser extension deploys into whatever browser your users already have and adds security capabilities without changing the user experience or requiring a migration. An enterprise browser replaces the existing browser entirely with a managed application that embeds security controls at the browser level.",[],{},{"nodeType":883,"data":4588,"content":4589},{},[4590],{"nodeType":882,"value":4591,"marks":4592,"data":4593},"Extensions offer faster deployment with no migration required and are typically built for the security team's need to detect and respond to threats — Gartner explicitly notes that extensions have become the preferred deployment option in the category. Full-stack enterprise browsers offer deeper workspace controls (copy\u002Fpaste restrictions, watermarking, VDI replacement) and are typically built for the IT team's need to govern access. ",[],{},{"nodeType":883,"data":4595,"content":4596},{},[4597,4601,4608],{"nodeType":882,"value":4598,"marks":4599,"data":4600},"The two are not mutually exclusive — many organizations use an enterprise browser for contractors or regulated populations and an extension like Push across the rest of the workforce. We cover this in detail in ",[],{},{"nodeType":929,"data":4602,"content":4603},{"uri":4146},[4604],{"nodeType":882,"value":4605,"marks":4606,"data":4607},"Enterprise browser vs. browser extension: Which should your security team choose?",[],{},{"nodeType":882,"value":21,"marks":4609,"data":4610},[],{},"What is the difference between an enterprise browser extension and an enterprise browser?",{"answer":4613,"question":4634},{"json":4614},{"nodeType":1294,"data":4615,"content":4616},{},[4617],{"nodeType":883,"data":4618,"content":4619},{},[4620,4624,4630],{"nodeType":882,"value":4621,"marks":4622,"data":4623},"No. enterprise browser extensions like Push Security, Seraphic (CrowdStrike), LayerX (Akamai), SquareX (Zscaler), and Keep Aware deploy into existing browsers without requiring users to switch. Enterprise browsers like Island, Prisma Browser, and SURF do require browser replacement. According to ",[],{},{"nodeType":929,"data":4625,"content":4626},{"uri":3997},[4627],{"nodeType":882,"value":4002,"marks":4628,"data":4629},[],{},{"nodeType":882,"value":4631,"marks":4632,"data":4633},", 48% of organizations cite the ability to use their existing browsers as an important attribute in a secure browsing solution, and 80% expect to use browser security alongside existing tools rather than as a replacement.",[],{},"Do I need to replace my browser to use an enterprise browser?",{"answer":4636,"question":4665},{"json":4637},{"nodeType":1294,"data":4638,"content":4639},{},[4640,4647],{"nodeType":883,"data":4641,"content":4642},{},[4643],{"nodeType":882,"value":4644,"marks":4645,"data":4646},"CrowdStrike, Zscaler, and Akamai all acquired browser security startups in 2026. This is significant validation of the the browser security market that the browser is a gap that network and endpoint security vendors have acknowledged and are attempting to close. ",[],{},{"nodeType":883,"data":4648,"content":4649},{},[4650,4654,4662],{"nodeType":882,"value":4651,"marks":4652,"data":4653},"But whether acquired products retain their innovation velocity as they're absorbed into larger platforms is a ",[],{},{"nodeType":929,"data":4655,"content":4656},{"uri":4009},[4657],{"nodeType":882,"value":4658,"marks":4659,"data":4661},"legitimate concern for buyers evaluating long-term roadmaps",[4660],{"type":927},{},{"nodeType":882,"value":1438,"marks":4663,"data":4664},[],{},"What do browser security vendor acquisitions mean for buyers?",{"answer":4667,"question":4692},{"json":4668},{"nodeType":1294,"data":4669,"content":4670},{},[4671],{"nodeType":883,"data":4672,"content":4673},{},[4674,4678,4688],{"nodeType":882,"value":4675,"marks":4676,"data":4677},"Yes, but it depends on the approach and vendor. According to",[],{},{"nodeType":929,"data":4679,"content":4680},{"uri":3997},[4681,4684],{"nodeType":882,"value":2218,"marks":4682,"data":4683},[],{},{"nodeType":882,"value":4520,"marks":4685,"data":4687},[4686],{"type":927},{},{"nodeType":882,"value":4689,"marks":4690,"data":4691},", 32% of users access corporate applications from an unmanaged device at least occasionally. Enterprise browsers can be installed on unmanaged devices, but require the user to download and switch to a new browser application. Enterprise browser extensions like Push can be deployed to contractor and BYOD machines without MDM — via email or landing page self-enrollment — providing threat detection and policy enforcement without browser replacement or device management overhead.",[],{},"Can browser security be deployed to unmanaged or BYOD devices?",{"answer":4694,"question":4829},{"json":4695},{"nodeType":1294,"data":4696,"content":4697},{},[4698,4766,4784],{"nodeType":883,"data":4699,"content":4700},{},[4701,4705,4713,4716,4725,4728,4737,4740,4749,4753,4762],{"nodeType":882,"value":4702,"marks":4703,"data":4704},"The most common attacks include ",[],{},{"nodeType":929,"data":4706,"content":4708},{"uri":4707},"https:\u002F\u002Fpushsecurity.com\u002Fsolution\u002Fstop-browser-based-attacks\u002Fadversary-in-the-middle-attacks",[4709],{"nodeType":882,"value":262,"marks":4710,"data":4712},[4711],{"type":927},{},{"nodeType":882,"value":1993,"marks":4714,"data":4715},[],{},{"nodeType":929,"data":4717,"content":4719},{"uri":4718},"https:\u002F\u002Fpushsecurity.com\u002Fsolution\u002Fstop-browser-based-attacks\u002Fclickfix-fix-variants",[4720],{"nodeType":882,"value":4721,"marks":4722,"data":4724},"ClickFix-style social engineering",[4723],{"type":927},{},{"nodeType":882,"value":1993,"marks":4726,"data":4727},[],{},{"nodeType":929,"data":4729,"content":4731},{"uri":4730},"https:\u002F\u002Fpushsecurity.com\u002Fsolution\u002Fstop-browser-based-attacks\u002Fmalicious-browser-extensions",[4732],{"nodeType":882,"value":4733,"marks":4734,"data":4736},"malicious browser extensions",[4735],{"type":927},{},{"nodeType":882,"value":2006,"marks":4738,"data":4739},[],{},{"nodeType":929,"data":4741,"content":4743},{"uri":4742},"https:\u002F\u002Fpushsecurity.com\u002Fsolution\u002Fstop-browser-based-attacks\u002Fmalicious-oauth-integrations",[4744],{"nodeType":882,"value":4745,"marks":4746,"data":4748},"malicious OAuth consent grants",[4747],{"type":927},{},{"nodeType":882,"value":4750,"marks":4751,"data":4752},". In 2026, ",[],{},{"nodeType":929,"data":4754,"content":4756},{"uri":4755},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fdevice-code-phishing",[4757],{"nodeType":882,"value":4758,"marks":4759,"data":4761},"device code phishing",[4760],{"type":927},{},{"nodeType":882,"value":4763,"marks":4764,"data":4765}," has become a core part of the attacker’s arsenal too, with 25+ unique attacker kits now offering the technique. ",[],{},{"nodeType":883,"data":4767,"content":4768},{},[4769,4773,4780],{"nodeType":882,"value":4770,"marks":4771,"data":4772},"Among browser-based attack victims surveyed by ",[],{},{"nodeType":929,"data":4774,"content":4775},{"uri":3997},[4776],{"nodeType":882,"value":4520,"marks":4777,"data":4779},[4778],{"type":927},{},{"nodeType":882,"value":4781,"marks":4782,"data":4783},", phishing was the most common attack type (40%), followed by data loss or leakage (38%), malicious browser extensions (34%), and credential theft (28%). ",[],{},{"nodeType":883,"data":4785,"content":4786},{},[4787,4791,4825],{"nodeType":882,"value":4788,"marks":4789,"data":4790},"It's worth noting the distinction between",[],{},{"nodeType":929,"data":4792,"content":4794},{"uri":4793},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fwhy-modern-browser-attacks-evade-edr",[4795,4798,4803,4809,4814,4820],{"nodeType":882,"value":2218,"marks":4796,"data":4797},[],{},{"nodeType":882,"value":4799,"marks":4800,"data":4802},"attacks ",[4801],{"type":927},{},{"nodeType":882,"value":4804,"marks":4805,"data":4808},"on",[4806,4807],{"type":927},{"type":1045},{},{"nodeType":882,"value":4810,"marks":4811,"data":4813}," the browser and attacks ",[4812],{"type":927},{},{"nodeType":882,"value":4815,"marks":4816,"data":4819},"inside",[4817,4818],{"type":927},{"type":1045},{},{"nodeType":882,"value":4821,"marks":4822,"data":4824}," the browser",[4823],{"type":927},{},{"nodeType":882,"value":4826,"marks":4827,"data":4828},". A number of the solutions in this list were designed to stop browser exploitation and prevent sandbox escapes. But the vast majority of the attacks in the wild are identity based — they happen in the browser, not on it. ",[],{},"What are the most common browser-based attacks in 2026?",{"answer":4831,"question":4864},{"json":4832},{"nodeType":1294,"data":4833,"content":4834},{},[4835,4842],{"nodeType":883,"data":4836,"content":4837},{},[4838],{"nodeType":882,"value":4839,"marks":4840,"data":4841},"EDR monitors the operating system layer — processes, file system activity, registry changes, memory behavior. Browser security operates inside the browser session — observing the rendered page, credential entry, session tokens, and user interaction. ",[],{},{"nodeType":883,"data":4843,"content":4844},{},[4845,4849,4860],{"nodeType":882,"value":4846,"marks":4847,"data":4848},"The two are complementary:",[],{},{"nodeType":929,"data":4850,"content":4851},{"uri":4793},[4852,4855],{"nodeType":882,"value":2218,"marks":4853,"data":4854},[],{},{"nodeType":882,"value":4856,"marks":4857,"data":4859},"EDR catches malware execution and endpoint-level attacks, while browser security catches credential phishing, session hijacking, OAuth consent abuse, and browser-native social engineering",[4858],{"type":927},{},{"nodeType":882,"value":4861,"marks":4862,"data":4863}," like ClickFix that never touch the endpoint in ways EDR can observe. CrowdStrike's acquisition of Seraphic in 2026 reflects the industry recognition that endpoint and browser are separate detection layers that both need to be instrumented.",[],{},"Do I need browser security if I already have EDR?",{"answer":4866,"question":4923},{"json":4867},{"nodeType":1294,"data":4868,"content":4869},{},[4870,4877,4905],{"nodeType":883,"data":4871,"content":4872},{},[4873],{"nodeType":882,"value":4874,"marks":4875,"data":4876},"Yes, but the effectiveness depends on the tool and its detection approach. AiTM phishing kits relay credentials and MFA tokens in real time, so most forms of MFA are bypassed. Browser security tools with behavioral detection — analyzing page structure, script behavior, and credential-harvesting mechanics — can detect phishing kits regardless of which domain they're hosted on or how quickly the infrastructure rotates. ",[],{},{"nodeType":883,"data":4878,"content":4879},{},[4880,4884,4891,4895,4901],{"nodeType":882,"value":4881,"marks":4882,"data":4883},"Tools that rely primarily on URL blocklists or reputation scores are less effective because ",[],{},{"nodeType":929,"data":4885,"content":4887},{"uri":4886},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fverizon-dbir-2026-review",[4888],{"nodeType":882,"value":3200,"marks":4889,"data":4890},[],{},{"nodeType":882,"value":4892,"marks":4893,"data":4894},". It's also worth noting that not all MFA-bypass phishing works the same way. ",[],{},{"nodeType":929,"data":4896,"content":4897},{"uri":4755},[4898],{"nodeType":882,"value":361,"marks":4899,"data":4900},[],{},{"nodeType":882,"value":4902,"marks":4903,"data":4904}," sidesteps authentication entirely — the user authorizes a device on a legitimate identity provider page, and the attacker receives a valid token without ever touching the credential exchange. ",[],{},{"nodeType":883,"data":4906,"content":4907},{},[4908,4911,4919],{"nodeType":882,"value":21,"marks":4909,"data":4910},[],{},{"nodeType":929,"data":4912,"content":4913},{"uri":1316},[4914],{"nodeType":882,"value":4915,"marks":4916,"data":4918},"With attacks evolving so quickly, telemetry isn't enough on its own",[4917],{"type":927},{},{"nodeType":882,"value":4920,"marks":4921,"data":4922}," — the vendor needs dedicated threat research expertise to turn that visibility into detections that keep pace with attacker innovation. Push detects and blocks phishing including AiTM reverse-proxy kits, human-operated relay panels, and device code phishing flows, backed by an in-house research team that discovers and publishes new attack techniques as they emerge.",[],{},"Can browser security stop phishing that bypasses MFA?",{"answer":4925,"question":5026},{"json":4926},{"nodeType":1294,"data":4927,"content":4928},{},[4929,4936,4999],{"nodeType":883,"data":4930,"content":4931},{},[4932],{"nodeType":882,"value":4933,"marks":4934,"data":4935},"The criteria that matter most are: ",[],{},{"nodeType":1454,"data":4937,"content":4938},{},[4939,4949,4959,4969,4979,4989],{"nodeType":1419,"data":4940,"content":4941},{},[4942],{"nodeType":883,"data":4943,"content":4944},{},[4945],{"nodeType":882,"value":4946,"marks":4947,"data":4948},"Detection model — is the vendor detecting behavioral attacker techniques or relying on URL blocklists that attackers rotate in minutes?",[],{},{"nodeType":1419,"data":4950,"content":4951},{},[4952],{"nodeType":883,"data":4953,"content":4954},{},[4955],{"nodeType":882,"value":4956,"marks":4957,"data":4958},"Deployment model — does it deploy into existing browsers or require a migration? ",[],{},{"nodeType":1419,"data":4960,"content":4961},{},[4962],{"nodeType":883,"data":4963,"content":4964},{},[4965],{"nodeType":882,"value":4966,"marks":4967,"data":4968},"Coverage for unmanaged and BYOD devices — does it need MDM, an endpoint agent, or just a browser? ",[],{},{"nodeType":1419,"data":4970,"content":4971},{},[4972],{"nodeType":883,"data":4973,"content":4974},{},[4975],{"nodeType":882,"value":4976,"marks":4977,"data":4978},"Integration — does it feed telemetry into your SIEM, XDR, and identity tools or create a silo? ",[],{},{"nodeType":1419,"data":4980,"content":4981},{},[4982],{"nodeType":883,"data":4983,"content":4984},{},[4985],{"nodeType":882,"value":4986,"marks":4987,"data":4988},"AI visibility and governance — can it discover shadow AI apps and govern OAuth consent flows? ",[],{},{"nodeType":1419,"data":4990,"content":4991},{},[4992],{"nodeType":883,"data":4993,"content":4994},{},[4995],{"nodeType":882,"value":4996,"marks":4997,"data":4998},"Research depth — is the vendor discovering novel attack techniques or covering what others already documented? ",[],{},{"nodeType":883,"data":5000,"content":5001},{},[5002,5006,5013,5016,5023],{"nodeType":882,"value":5003,"marks":5004,"data":5005},"We've written a detailed guide on ",[],{},{"nodeType":929,"data":5007,"content":5008},{"uri":4072},[5009],{"nodeType":882,"value":5010,"marks":5011,"data":5012},"how to avoid the browser security buyer's trap",[],{},{"nodeType":882,"value":2633,"marks":5014,"data":5015},[],{},{"nodeType":929,"data":5017,"content":5018},{"uri":4084},[5019],{"nodeType":882,"value":5020,"marks":5021,"data":5022},"how to make the business case for browser security",[],{},{"nodeType":882,"value":1438,"marks":5024,"data":5025},[],{},"What should I look for when evaluating browser security solutions?",{"answer":5028,"question":5050},{"json":5029},{"nodeType":1294,"data":5030,"content":5031},{},[5032],{"nodeType":883,"data":5033,"content":5034},{},[5035,5039,5047],{"nodeType":882,"value":5036,"marks":5037,"data":5038},"RBI was designed to prevent malicious content from reaching the endpoint by rendering web pages in a remote container. The architecture is effective for that specific threat model, but the dominant browser-based attacks in 2026 — AiTM phishing, session hijacking, ClickFix, OAuth consent abuse — don't deliver payloads to the endpoint. They manipulate what the user sees, steal session tokens, and hijack authenticated state inside the browser session. There's nothing for RBI to isolate. RBI still has value in specific zero-tolerance environments and for managing untrusted third-party access, but for organizations looking to address the threats driving most browser-based breaches today, an ",[],{},{"nodeType":929,"data":5040,"content":5041},{"uri":4312},[5042],{"nodeType":882,"value":5043,"marks":5044,"data":5046},"enterprise browser extension is more appropriate",[5045],{"type":927},{},{"nodeType":882,"value":1438,"marks":5048,"data":5049},[],{},"Can remote browser isolation (RBI) stop the same attacks as an enterprise browser?",{"answer":5052,"question":5104},{"json":5053},{"nodeType":1294,"data":5054,"content":5055},{},[5056,5097],{"nodeType":883,"data":5057,"content":5058},{},[5059,5062,5070,5074,5080,5084,5093],{"nodeType":882,"value":21,"marks":5060,"data":5061},[],{},{"nodeType":929,"data":5063,"content":5065},{"uri":5064},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fwhy-you-cant-control-ai-without-being-in-the-browser",[5066],{"nodeType":882,"value":5067,"marks":5068,"data":5069},"AI usage is primarily browser-based",[],{},{"nodeType":882,"value":5071,"marks":5072,"data":5073}," — every LLM interaction, every prompt containing sensitive data, every AI agent authorization happens inside a browser session. Browser security tools can discover which AI tools are in use (including shadow AI), monitor what data users share with them, observe OAuth consent flows for AI agent permissions, and block access to unsanctioned AI applications. According to ",[],{},{"nodeType":929,"data":5075,"content":5076},{"uri":3997},[5077],{"nodeType":882,"value":4520,"marks":5078,"data":5079},[],{},{"nodeType":882,"value":5081,"marks":5082,"data":5083},", generative AI application security was the #1 capability organizations want from a secure browsing solution at 59%, ahead of data loss prevention and general web security. ",[],{},{"nodeType":929,"data":5085,"content":5087},{"uri":5086},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fwhat-push-data-reveals-about-the-state-of-shadow-ai",[5088],{"nodeType":882,"value":5089,"marks":5090,"data":5092},"Push data shows the average organization has 16 unique AI apps, 17 AI browser extensions, and 17 AI OAuth integrations",[5091],{"type":927},{},{"nodeType":882,"value":5094,"marks":5095,"data":5096}," in active use — most unapproved (or simply not known about).",[],{},{"nodeType":883,"data":5098,"content":5099},{},[5100],{"nodeType":882,"value":5101,"marks":5102,"data":5103},"\n",[],{},"How does browser security help with AI governance?",{"answer":5106,"question":5156},{"json":5107},{"nodeType":1294,"data":5108,"content":5109},{},[5110,5150],{"nodeType":883,"data":5111,"content":5112},{},[5113,5116,5125,5128,5136,5140,5147],{"nodeType":882,"value":21,"marks":5114,"data":5115},[],{},{"nodeType":929,"data":5117,"content":5119},{"uri":5118},"https:\u002F\u002Fpushsecurity.com\u002Fsolution\u002Ftool-replacements\u002Fsecure-web-gateways",[5120],{"nodeType":882,"value":5121,"marks":5122,"data":5124},"SWGs",[5123],{"type":927},{},{"nodeType":882,"value":2633,"marks":5126,"data":5127},[],{},{"nodeType":929,"data":5129,"content":5131},{"uri":5130},"https:\u002F\u002Fpushsecurity.com\u002Fsolution\u002Ftool-replacements\u002Fcloud-access-security-broker",[5132],{"nodeType":882,"value":5133,"marks":5134,"data":5135},"CASBs",[],{},{"nodeType":882,"value":5137,"marks":5138,"data":5139}," operate at the network\u002Fproxy layer, inspecting traffic metadata and URLs. Browser security operates inside the browser session, observing the rendered page, script behavior, credential entry, and user interaction. The key difference: network tools can tell you where data went, but browser security sees what the user actually saw and did. SWGs block known-bad URLs via blocklists — but phishing infrastructure rotates faster than blocklists update. Browser-native detection analyzes page behavior regardless of whether the URL is known-bad. The two are complementary, though browser-layer capabilities are ",[],{},{"nodeType":929,"data":5141,"content":5142},{"uri":4084},[5143],{"nodeType":882,"value":5144,"marks":5145,"data":5146},"increasingly making network-centric tools redundant for specific use cases",[],{},{"nodeType":882,"value":1438,"marks":5148,"data":5149},[],{},{"nodeType":883,"data":5151,"content":5152},{},[5153],{"nodeType":882,"value":5101,"marks":5154,"data":5155},[],{},"Do I still need a secure web gateway (SWG) or CASB if I have browser security?",{"answer":5158,"question":5187},{"json":5159},{"nodeType":1294,"data":5160,"content":5161},{},[5162,5169],{"nodeType":883,"data":5163,"content":5164},{},[5165],{"nodeType":882,"value":5166,"marks":5167,"data":5168},"If you're counting on user awareness as a meaningful defense layer, yes. Security awareness training is not a technical control — it depends on every user making the right call, every time, across every delivery channel. Browser-based attacks now arrive through email, search engines, SMS, QR codes, social media, and voice calls, each with different lure formats and social engineering mechanics. The volume and variation makes it impossible for users to keep up. ",[],{},{"nodeType":883,"data":5170,"content":5171},{},[5172,5176,5184],{"nodeType":882,"value":5173,"marks":5174,"data":5175},"Browser security detects and blocks attacks automatically at the point of risk regardless of the delivery channel, because the detection happens inside the browser session where the attack plays out — ",[],{},{"nodeType":929,"data":5177,"content":5179},{"uri":5178},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fwhy-your-training-budget-belongs-in-real-time-browser-security",[5180],{"nodeType":882,"value":5181,"marks":5182,"data":5183},"it should be the primary defense layer, not training",[],{},{"nodeType":882,"value":1438,"marks":5185,"data":5186},[],{},"Does browser security replace security awareness training?","Frequently asked questions",{},"The top 10 browser security solutions and tools in 2026","2026-07-27T00:00:00.000Z",{"items":5193},[5194,5990,7244],{"__typename":1365,"sys":5195,"content":5196,"title":2296,"synopsis":2297,"hashTags":59,"publishedDate":2298,"slug":2299,"tagsCollection":5980,"authorsCollection":5986},{"id":1367},{"json":5197},{"data":5198,"content":5199,"nodeType":1294},{},[5200,5211,5224,5269,5275,5287,5303,5309,5314,5317,5323,5329,5352,5358,5364,5422,5428,5433,5439,5445,5448,5454,5460,5490,5506,5516,5521,5527,5532,5542,5548,5564,5569,5579,5589,5595,5600,5610,5623,5633,5643,5648,5654,5657,5663,5669,5682,5689,5695,5702,5708,5744,5747,5753,5759,5764,5770,5776,5789,5802,5808,5821,5827,5869,5875,5888,5894,5936,5942,5949,5952,5958,5964],{"data":5201,"content":5202,"nodeType":883},{},[5203,5206],{"data":5204,"marks":5205,"value":1378,"nodeType":882},{},[],{"data":5207,"marks":5208,"value":1384,"nodeType":882},{},[5209,5210],{"type":1045},{"type":1012},{"data":5212,"content":5213,"nodeType":883},{},[5214,5217,5221],{"data":5215,"marks":5216,"value":1391,"nodeType":882},{},[],{"data":5218,"marks":5219,"value":1396,"nodeType":882},{},[5220],{"type":1012},{"data":5222,"marks":5223,"value":1400,"nodeType":882},{},[],{"data":5225,"content":5226,"nodeType":1454},{},[5227,5240,5256],{"data":5228,"content":5229,"nodeType":1419},{},[5230],{"data":5231,"content":5232,"nodeType":883},{},[5233,5236],{"data":5234,"marks":5235,"value":1413,"nodeType":882},{},[],{"data":5237,"marks":5238,"value":1418,"nodeType":882},{},[5239],{"type":1012},{"data":5241,"content":5242,"nodeType":1419},{},[5243],{"data":5244,"content":5245,"nodeType":883},{},[5246,5249,5253],{"data":5247,"marks":5248,"value":1429,"nodeType":882},{},[],{"data":5250,"marks":5251,"value":1434,"nodeType":882},{},[5252],{"type":1012},{"data":5254,"marks":5255,"value":1438,"nodeType":882},{},[],{"data":5257,"content":5258,"nodeType":1419},{},[5259],{"data":5260,"content":5261,"nodeType":883},{},[5262,5266],{"data":5263,"marks":5264,"value":1449,"nodeType":882},{},[5265],{"type":1012},{"data":5267,"marks":5268,"value":1453,"nodeType":882},{},[],{"data":5270,"content":5271,"nodeType":883},{},[5272],{"data":5273,"marks":5274,"value":1461,"nodeType":882},{},[],{"data":5276,"content":5277,"nodeType":1454},{},[5278],{"data":5279,"content":5280,"nodeType":1419},{},[5281],{"data":5282,"content":5283,"nodeType":883},{},[5284],{"data":5285,"marks":5286,"value":1474,"nodeType":882},{},[],{"data":5288,"content":5289,"nodeType":883},{},[5290,5293,5300],{"data":5291,"marks":5292,"value":1481,"nodeType":882},{},[],{"data":5294,"content":5295,"nodeType":929},{"uri":1484},[5296],{"data":5297,"marks":5298,"value":1490,"nodeType":882},{},[5299],{"type":927},{"data":5301,"marks":5302,"value":1494,"nodeType":882},{},[],{"data":5304,"content":5305,"nodeType":883},{},[5306],{"data":5307,"marks":5308,"value":1501,"nodeType":882},{},[],{"data":5310,"content":5313,"nodeType":963},{"target":5311},{"sys":5312},{"id":1506,"type":960,"linkType":961},[],{"data":5315,"content":5316,"nodeType":967},{},[],{"data":5318,"content":5319,"nodeType":975},{},[5320],{"data":5321,"marks":5322,"value":1517,"nodeType":882},{},[],{"data":5324,"content":5325,"nodeType":883},{},[5326],{"data":5327,"marks":5328,"value":1524,"nodeType":882},{},[],{"data":5330,"content":5331,"nodeType":883},{},[5332,5335,5339,5342,5349],{"data":5333,"marks":5334,"value":1531,"nodeType":882},{},[],{"data":5336,"marks":5337,"value":1536,"nodeType":882},{},[5338],{"type":1045},{"data":5340,"marks":5341,"value":1540,"nodeType":882},{},[],{"data":5343,"content":5344,"nodeType":929},{"uri":1543},[5345],{"data":5346,"marks":5347,"value":1549,"nodeType":882},{},[5348],{"type":927},{"data":5350,"marks":5351,"value":1553,"nodeType":882},{},[],{"data":5353,"content":5354,"nodeType":883},{},[5355],{"data":5356,"marks":5357,"value":1560,"nodeType":882},{},[],{"data":5359,"content":5360,"nodeType":883},{},[5361],{"data":5362,"marks":5363,"value":1567,"nodeType":882},{},[],{"data":5365,"content":5366,"nodeType":1454},{},[5367,5390,5406],{"data":5368,"content":5369,"nodeType":1419},{},[5370],{"data":5371,"content":5372,"nodeType":883},{},[5373,5377,5380,5387],{"data":5374,"marks":5375,"value":1581,"nodeType":882},{},[5376],{"type":1012},{"data":5378,"marks":5379,"value":1585,"nodeType":882},{},[],{"data":5381,"content":5382,"nodeType":929},{"uri":1588},[5383],{"data":5384,"marks":5385,"value":1594,"nodeType":882},{},[5386],{"type":927},{"data":5388,"marks":5389,"value":1598,"nodeType":882},{},[],{"data":5391,"content":5392,"nodeType":1419},{},[5393],{"data":5394,"content":5395,"nodeType":883},{},[5396,5399,5403],{"data":5397,"marks":5398,"value":1608,"nodeType":882},{},[],{"data":5400,"marks":5401,"value":1613,"nodeType":882},{},[5402],{"type":1012},{"data":5404,"marks":5405,"value":1617,"nodeType":882},{},[],{"data":5407,"content":5408,"nodeType":1419},{},[5409],{"data":5410,"content":5411,"nodeType":883},{},[5412,5415,5419],{"data":5413,"marks":5414,"value":1627,"nodeType":882},{},[],{"data":5416,"marks":5417,"value":1632,"nodeType":882},{},[5418],{"type":1012},{"data":5420,"marks":5421,"value":1438,"nodeType":882},{},[],{"data":5423,"content":5424,"nodeType":883},{},[5425],{"data":5426,"marks":5427,"value":1642,"nodeType":882},{},[],{"data":5429,"content":5432,"nodeType":963},{"target":5430},{"sys":5431},{"id":1647,"type":960,"linkType":961},[],{"data":5434,"content":5435,"nodeType":883},{},[5436],{"data":5437,"marks":5438,"value":1655,"nodeType":882},{},[],{"data":5440,"content":5441,"nodeType":883},{},[5442],{"data":5443,"marks":5444,"value":1662,"nodeType":882},{},[],{"data":5446,"content":5447,"nodeType":967},{},[],{"data":5449,"content":5450,"nodeType":975},{},[5451],{"data":5452,"marks":5453,"value":1672,"nodeType":882},{},[],{"data":5455,"content":5456,"nodeType":883},{},[5457],{"data":5458,"marks":5459,"value":1679,"nodeType":882},{},[],{"data":5461,"content":5462,"nodeType":1454},{},[5463,5472,5481],{"data":5464,"content":5465,"nodeType":1419},{},[5466],{"data":5467,"content":5468,"nodeType":883},{},[5469],{"data":5470,"marks":5471,"value":1692,"nodeType":882},{},[],{"data":5473,"content":5474,"nodeType":1419},{},[5475],{"data":5476,"content":5477,"nodeType":883},{},[5478],{"data":5479,"marks":5480,"value":1702,"nodeType":882},{},[],{"data":5482,"content":5483,"nodeType":1419},{},[5484],{"data":5485,"content":5486,"nodeType":883},{},[5487],{"data":5488,"marks":5489,"value":1712,"nodeType":882},{},[],{"data":5491,"content":5492,"nodeType":883},{},[5493,5496,5503],{"data":5494,"marks":5495,"value":1719,"nodeType":882},{},[],{"data":5497,"content":5498,"nodeType":929},{"uri":1722},[5499],{"data":5500,"marks":5501,"value":1728,"nodeType":882},{},[5502],{"type":927},{"data":5504,"marks":5505,"value":1732,"nodeType":882},{},[],{"data":5507,"content":5508,"nodeType":883},{},[5509,5513],{"data":5510,"marks":5511,"value":1740,"nodeType":882},{},[5512],{"type":1012},{"data":5514,"marks":5515,"value":1744,"nodeType":882},{},[],{"data":5517,"content":5520,"nodeType":963},{"target":5518},{"sys":5519},{"id":1749,"type":960,"linkType":961},[],{"data":5522,"content":5523,"nodeType":883},{},[5524],{"data":5525,"marks":5526,"value":1757,"nodeType":882},{},[],{"data":5528,"content":5531,"nodeType":963},{"target":5529},{"sys":5530},{"id":1762,"type":960,"linkType":961},[],{"data":5533,"content":5534,"nodeType":883},{},[5535,5539],{"data":5536,"marks":5537,"value":1771,"nodeType":882},{},[5538],{"type":1012},{"data":5540,"marks":5541,"value":1775,"nodeType":882},{},[],{"data":5543,"content":5544,"nodeType":883},{},[5545],{"data":5546,"marks":5547,"value":1782,"nodeType":882},{},[],{"data":5549,"content":5550,"nodeType":883},{},[5551,5554,5561],{"data":5552,"marks":5553,"value":1789,"nodeType":882},{},[],{"data":5555,"content":5556,"nodeType":929},{"uri":1792},[5557],{"data":5558,"marks":5559,"value":1798,"nodeType":882},{},[5560],{"type":927},{"data":5562,"marks":5563,"value":1802,"nodeType":882},{},[],{"data":5565,"content":5568,"nodeType":963},{"target":5566},{"sys":5567},{"id":1807,"type":960,"linkType":961},[],{"data":5570,"content":5571,"nodeType":883},{},[5572,5576],{"data":5573,"marks":5574,"value":1816,"nodeType":882},{},[5575],{"type":1012},{"data":5577,"marks":5578,"value":1820,"nodeType":882},{},[],{"data":5580,"content":5581,"nodeType":883},{},[5582,5586],{"data":5583,"marks":5584,"value":1828,"nodeType":882},{},[5585],{"type":1012},{"data":5587,"marks":5588,"value":1832,"nodeType":882},{},[],{"data":5590,"content":5591,"nodeType":883},{},[5592],{"data":5593,"marks":5594,"value":1839,"nodeType":882},{},[],{"data":5596,"content":5599,"nodeType":963},{"target":5597},{"sys":5598},{"id":1844,"type":960,"linkType":961},[],{"data":5601,"content":5602,"nodeType":883},{},[5603,5607],{"data":5604,"marks":5605,"value":1853,"nodeType":882},{},[5606],{"type":1012},{"data":5608,"marks":5609,"value":1857,"nodeType":882},{},[],{"data":5611,"content":5612,"nodeType":883},{},[5613,5616,5620],{"data":5614,"marks":5615,"value":1864,"nodeType":882},{},[],{"data":5617,"marks":5618,"value":1869,"nodeType":882},{},[5619],{"type":1012},{"data":5621,"marks":5622,"value":1873,"nodeType":882},{},[],{"data":5624,"content":5625,"nodeType":883},{},[5626,5630],{"data":5627,"marks":5628,"value":1881,"nodeType":882},{},[5629],{"type":1012},{"data":5631,"marks":5632,"value":1885,"nodeType":882},{},[],{"data":5634,"content":5635,"nodeType":883},{},[5636,5640],{"data":5637,"marks":5638,"value":1893,"nodeType":882},{},[5639],{"type":1012},{"data":5641,"marks":5642,"value":1897,"nodeType":882},{},[],{"data":5644,"content":5647,"nodeType":963},{"target":5645},{"sys":5646},{"id":1902,"type":960,"linkType":961},[],{"data":5649,"content":5650,"nodeType":883},{},[5651],{"data":5652,"marks":5653,"value":1910,"nodeType":882},{},[],{"data":5655,"content":5656,"nodeType":967},{},[],{"data":5658,"content":5659,"nodeType":975},{},[5660],{"data":5661,"marks":5662,"value":1920,"nodeType":882},{},[],{"data":5664,"content":5665,"nodeType":883},{},[5666],{"data":5667,"marks":5668,"value":1927,"nodeType":882},{},[],{"data":5670,"content":5671,"nodeType":883},{},[5672,5675,5679],{"data":5673,"marks":5674,"value":1934,"nodeType":882},{},[],{"data":5676,"marks":5677,"value":1939,"nodeType":882},{},[5678],{"type":1012},{"data":5680,"marks":5681,"value":1943,"nodeType":882},{},[],{"data":5683,"content":5684,"nodeType":883},{},[5685],{"data":5686,"marks":5687,"value":1951,"nodeType":882},{},[5688],{"type":1012},{"data":5690,"content":5691,"nodeType":883},{},[5692],{"data":5693,"marks":5694,"value":1958,"nodeType":882},{},[],{"data":5696,"content":5697,"nodeType":883},{},[5698],{"data":5699,"marks":5700,"value":1966,"nodeType":882},{},[5701],{"type":1012},{"data":5703,"content":5704,"nodeType":883},{},[5705],{"data":5706,"marks":5707,"value":1973,"nodeType":882},{},[],{"data":5709,"content":5710,"nodeType":883},{},[5711,5714,5721,5724,5731,5734,5741],{"data":5712,"marks":5713,"value":1980,"nodeType":882},{},[],{"data":5715,"content":5716,"nodeType":929},{"uri":1983},[5717],{"data":5718,"marks":5719,"value":1989,"nodeType":882},{},[5720],{"type":927},{"data":5722,"marks":5723,"value":1993,"nodeType":882},{},[],{"data":5725,"content":5726,"nodeType":929},{"uri":1996},[5727],{"data":5728,"marks":5729,"value":2002,"nodeType":882},{},[5730],{"type":927},{"data":5732,"marks":5733,"value":2006,"nodeType":882},{},[],{"data":5735,"content":5736,"nodeType":929},{"uri":2009},[5737],{"data":5738,"marks":5739,"value":2015,"nodeType":882},{},[5740],{"type":927},{"data":5742,"marks":5743,"value":2019,"nodeType":882},{},[],{"data":5745,"content":5746,"nodeType":967},{},[],{"data":5748,"content":5749,"nodeType":975},{},[5750],{"data":5751,"marks":5752,"value":2029,"nodeType":882},{},[],{"data":5754,"content":5755,"nodeType":883},{},[5756],{"data":5757,"marks":5758,"value":2036,"nodeType":882},{},[],{"data":5760,"content":5763,"nodeType":963},{"target":5761},{"sys":5762},{"id":2041,"type":960,"linkType":961},[],{"data":5765,"content":5766,"nodeType":2050},{},[5767],{"data":5768,"marks":5769,"value":2049,"nodeType":882},{},[],{"data":5771,"content":5772,"nodeType":883},{},[5773],{"data":5774,"marks":5775,"value":2057,"nodeType":882},{},[],{"data":5777,"content":5778,"nodeType":883},{},[5779,5782,5786],{"data":5780,"marks":5781,"value":2064,"nodeType":882},{},[],{"data":5783,"marks":5784,"value":2069,"nodeType":882},{},[5785],{"type":1012},{"data":5787,"marks":5788,"value":2073,"nodeType":882},{},[],{"data":5790,"content":5791,"nodeType":883},{},[5792,5795,5799],{"data":5793,"marks":5794,"value":2080,"nodeType":882},{},[],{"data":5796,"marks":5797,"value":2085,"nodeType":882},{},[5798],{"type":1012},{"data":5800,"marks":5801,"value":1438,"nodeType":882},{},[],{"data":5803,"content":5804,"nodeType":2050},{},[5805],{"data":5806,"marks":5807,"value":2095,"nodeType":882},{},[],{"data":5809,"content":5810,"nodeType":883},{},[5811,5814,5818],{"data":5812,"marks":5813,"value":2102,"nodeType":882},{},[],{"data":5815,"marks":5816,"value":2107,"nodeType":882},{},[5817],{"type":1012},{"data":5819,"marks":5820,"value":2111,"nodeType":882},{},[],{"data":5822,"content":5823,"nodeType":883},{},[5824],{"data":5825,"marks":5826,"value":2118,"nodeType":882},{},[],{"data":5828,"content":5829,"nodeType":1454},{},[5830,5843,5856],{"data":5831,"content":5832,"nodeType":1419},{},[5833],{"data":5834,"content":5835,"nodeType":883},{},[5836,5840],{"data":5837,"marks":5838,"value":2132,"nodeType":882},{},[5839],{"type":1012},{"data":5841,"marks":5842,"value":2136,"nodeType":882},{},[],{"data":5844,"content":5845,"nodeType":1419},{},[5846],{"data":5847,"content":5848,"nodeType":883},{},[5849,5853],{"data":5850,"marks":5851,"value":2147,"nodeType":882},{},[5852],{"type":1012},{"data":5854,"marks":5855,"value":2151,"nodeType":882},{},[],{"data":5857,"content":5858,"nodeType":1419},{},[5859],{"data":5860,"content":5861,"nodeType":883},{},[5862,5866],{"data":5863,"marks":5864,"value":2162,"nodeType":882},{},[5865],{"type":1012},{"data":5867,"marks":5868,"value":2166,"nodeType":882},{},[],{"data":5870,"content":5871,"nodeType":2050},{},[5872],{"data":5873,"marks":5874,"value":2173,"nodeType":882},{},[],{"data":5876,"content":5877,"nodeType":883},{},[5878,5881,5885],{"data":5879,"marks":5880,"value":2180,"nodeType":882},{},[],{"data":5882,"marks":5883,"value":2185,"nodeType":882},{},[5884],{"type":1012},{"data":5886,"marks":5887,"value":2189,"nodeType":882},{},[],{"data":5889,"content":5890,"nodeType":883},{},[5891],{"data":5892,"marks":5893,"value":2196,"nodeType":882},{},[],{"data":5895,"content":5896,"nodeType":1454},{},[5897,5920],{"data":5898,"content":5899,"nodeType":1419},{},[5900],{"data":5901,"content":5902,"nodeType":883},{},[5903,5906,5910,5913,5917],{"data":5904,"marks":5905,"value":2209,"nodeType":882},{},[],{"data":5907,"marks":5908,"value":2214,"nodeType":882},{},[5909],{"type":1012},{"data":5911,"marks":5912,"value":2218,"nodeType":882},{},[],{"data":5914,"marks":5915,"value":2223,"nodeType":882},{},[5916],{"type":1012},{"data":5918,"marks":5919,"value":2227,"nodeType":882},{},[],{"data":5921,"content":5922,"nodeType":1419},{},[5923],{"data":5924,"content":5925,"nodeType":883},{},[5926,5929,5933],{"data":5927,"marks":5928,"value":2237,"nodeType":882},{},[],{"data":5930,"marks":5931,"value":2242,"nodeType":882},{},[5932],{"type":1012},{"data":5934,"marks":5935,"value":2246,"nodeType":882},{},[],{"data":5937,"content":5938,"nodeType":883},{},[5939],{"data":5940,"marks":5941,"value":2253,"nodeType":882},{},[],{"data":5943,"content":5944,"nodeType":883},{},[5945],{"data":5946,"marks":5947,"value":2261,"nodeType":882},{},[5948],{"type":1012},{"data":5950,"content":5951,"nodeType":967},{},[],{"data":5953,"content":5954,"nodeType":975},{},[5955],{"data":5956,"marks":5957,"value":2271,"nodeType":882},{},[],{"data":5959,"content":5960,"nodeType":883},{},[5961],{"data":5962,"marks":5963,"value":2278,"nodeType":882},{},[],{"data":5965,"content":5966,"nodeType":883},{},[5967,5970,5977],{"data":5968,"marks":5969,"value":2285,"nodeType":882},{},[],{"data":5971,"content":5972,"nodeType":929},{"uri":1283},[5973],{"data":5974,"marks":5975,"value":1289,"nodeType":882},{},[5976],{"type":927},{"data":5978,"marks":5979,"value":1293,"nodeType":882},{},[],{"items":5981},[5982,5984],{"sys":5983,"name":343},{"id":2304},{"sys":5985,"name":2308},{"id":2307},{"items":5987},[5988],{"fullName":866,"firstName":867,"jobTitle":868,"profilePicture":5989},{"url":870},{"__typename":1365,"sys":5991,"content":5993,"title":7227,"synopsis":7228,"hashTags":59,"publishedDate":7229,"slug":7230,"tagsCollection":7231,"authorsCollection":7240},{"id":5992},"6MoHWfQlVildcFYKSbfMcE",{"json":5994},{"data":5995,"content":5996,"nodeType":1294},{},[5997,6013,6019,6026,6033,6039,6042,6050,6058,6077,6123,6129,6144,6147,6155,6162,6190,6231,6238,6241,6249,6257,6264,6270,6277,6280,6288,6295,6337,6374,6381,6384,6392,6399,6424,6431,6476,6483,6486,6494,6502,6548,6555,6561,6564,6572,6580,6613,6620,6626,6633,6636,6644,6652,6681,6688,6695,6702,6705,6713,6721,6728,6734,6741,6764,6793,6796,6804,6812,6819,6826,6829,6837,6899,6902,6910,6917,7208,7211],{"data":5998,"content":5999,"nodeType":883},{},[6000,6004,6009],{"data":6001,"marks":6002,"value":6003,"nodeType":882},{},[],"Browser security solutions are one of the most significant additions to the enterprise security stack in recent years — and the data shows it. The browser is where ",{"data":6005,"marks":6006,"value":6008,"nodeType":882},{},[6007],{"type":1012},"85% of work now happens",{"data":6010,"marks":6011,"value":6012,"nodeType":882},{},[],", where AI tools are accessed, and where attackers increasingly choose to strike.",{"data":6014,"content":6018,"nodeType":963},{"target":6015},{"sys":6016},{"id":6017,"type":960,"linkType":961},"5P6PyFbn4EakRNlIWtNzyL",[],{"data":6020,"content":6021,"nodeType":883},{},[6022],{"data":6023,"marks":6024,"value":6025,"nodeType":882},{},[],"But browser security is a nascent category. Getting a clear picture of which solution is right for your team, and how to get the most out of it, isn't straightforward. Current solutions on the market serve a wide range of IT and security use cases, with varying degrees of depth and differentiation across them. Not all use cases are equal in terms of their security value, and not all of them are best addressed in the browser.",{"data":6027,"content":6028,"nodeType":883},{},[6029],{"data":6030,"marks":6031,"value":6032,"nodeType":882},{},[],"This article ranks the security problems that browser security solutions can address by the value they deliver: a combination of the risk reduction on offer, and the degree to which the browser is genuinely the best (or only) layer to solve the problem. ",{"data":6034,"content":6038,"nodeType":963},{"target":6035},{"sys":6036},{"id":6037,"type":960,"linkType":961},"6SJPvEHizSYk29lEvVVNj",[],{"data":6040,"content":6041,"nodeType":967},{},[],{"data":6043,"content":6044,"nodeType":975},{},[6045],{"data":6046,"marks":6047,"value":6049,"nodeType":882},{},[6048],{"type":1012},"#1 — Account takeover prevention: detecting credential attacks across all vectors",{"data":6051,"content":6052,"nodeType":883},{},[6053],{"data":6054,"marks":6055,"value":6057,"nodeType":882},{},[6056],{"type":1012},"Security value: Very high | Browser fit: Uniquely suited",{"data":6059,"content":6060,"nodeType":883},{},[6061,6065,6073],{"data":6062,"marks":6063,"value":6064,"nodeType":882},{},[],"Account takeover (ATO) is the dominant entry point for enterprise breaches: ",{"data":6066,"content":6068,"nodeType":929},{"uri":6067},"https:\u002F\u002Fwww.crowdstrike.com\u002Fen-gb\u002Fresources\u002Finfographics\u002Fidentity-security-risk-review\u002F",[6069],{"data":6070,"marks":6071,"value":6072,"nodeType":882},{},[],"80% of all modern breaches involve compromised or stolen identities",{"data":6074,"marks":6075,"value":6076,"nodeType":882},{},[],". The attack surface is far wider than most identity tooling can see: credential stuffing, password spraying, ghost logins (password-based fallback authentication that persists after SSO is configured), weak or reused credentials on shadow SaaS apps, and accounts where MFA was never enforced.",{"data":6078,"content":6079,"nodeType":883},{},[6080,6083,6091,6094,6099,6102,6107,6111,6119],{"data":6081,"marks":6082,"value":4513,"nodeType":882},{},[],{"data":6084,"content":6086,"nodeType":929},{"uri":6085},"https:\u002F\u002Fcf-assets.www.cloudflare.com\u002Fslt3lc6tev37\u002FsWDBUMNVtEJB9ZFLt1dUU\u002F8d69e92de2edfb3bf59e7d21d57e7e1a\u002FCloudflare-2026-threat-report.pdf",[6087],{"data":6088,"marks":6089,"value":6090,"nodeType":882},{},[],"Cloudflare's 2026 Threat Report",{"data":6092,"marks":6093,"value":1993,"nodeType":882},{},[],{"data":6095,"marks":6096,"value":6098,"nodeType":882},{},[6097],{"type":1012},"63% of all human logins involve credentials already compromised elsewhere",{"data":6100,"marks":6101,"value":2006,"nodeType":882},{},[],{"data":6103,"marks":6104,"value":6106,"nodeType":882},{},[6105],{"type":1012},"94% of all login attempts originate from bots",{"data":6108,"marks":6109,"value":6110,"nodeType":882},{},[],". The ",{"data":6112,"content":6114,"nodeType":929},{"uri":6113},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fsnowflake-retro\u002F",[6115],{"data":6116,"marks":6117,"value":6118,"nodeType":882},{},[],"Snowflake breach",{"data":6120,"marks":6121,"value":6122,"nodeType":882},{},[]," — 165+ organizations compromised, 1 billion+ records stolen — was powered almost entirely by ghost logins: accounts missing MFA that were susceptible to credential stuffing. It's particularly telling that 80% of the accounts impacted had prior breach exposure.",{"data":6124,"content":6128,"nodeType":963},{"target":6125},{"sys":6126},{"id":6127,"type":960,"linkType":961},"HbZ66kp5DiAZtwNGFJK7d",[],{"data":6130,"content":6131,"nodeType":883},{},[6132,6136,6141],{"data":6133,"marks":6134,"value":6135,"nodeType":882},{},[],"For organizations with contractors and BYOD users, the browser extension is also the only enterprise control deployable on devices that can't be MDM-enrolled — extending ATO detection to exactly the place where, per Verizon DBIR 2025, ",{"data":6137,"marks":6138,"value":6140,"nodeType":882},{},[6139],{"type":1012},"46% of infostealer infections originate",{"data":6142,"marks":6143,"value":1438,"nodeType":882},{},[],{"data":6145,"content":6146,"nodeType":967},{},[],{"data":6148,"content":6149,"nodeType":975},{},[6150],{"data":6151,"marks":6152,"value":6154,"nodeType":882},{},[6153],{"type":1012},"#2 — Detecting and stopping advanced phishing: AiTM, multi-channel delivery, and zero-day lures",{"data":6156,"content":6157,"nodeType":883},{},[6158],{"data":6159,"marks":6160,"value":6057,"nodeType":882},{},[6161],{"type":1012},{"data":6163,"content":6164,"nodeType":883},{},[6165,6169,6177,6181,6186],{"data":6166,"marks":6167,"value":6168,"nodeType":882},{},[],"Adversary-in-the-Middle (AiTM) phishing — where an attacker's reverse proxy intercepts credentials and session tokens in real time — has become the standard technique for bypassing MFA at scale. ",{"data":6170,"content":6172,"nodeType":929},{"uri":6171},"https:\u002F\u002Fwww.esentire.com\u002Fresources\u002Flibrary\u002F2026-threat-report",[6173],{"data":6174,"marks":6175,"value":6176,"nodeType":882},{},[],"eSentire's 2026 Threat Report",{"data":6178,"marks":6179,"value":6180,"nodeType":882},{},[]," attributes ",{"data":6182,"marks":6183,"value":6185,"nodeType":882},{},[6184],{"type":1012},"63% of account compromise incidents to PhaaS kits",{"data":6187,"marks":6188,"value":6189,"nodeType":882},{},[],", with account compromise surging 389% year-over-year.",{"data":6191,"content":6192,"nodeType":883},{},[6193,6197,6205,6209,6214,6218,6227],{"data":6194,"marks":6195,"value":6196,"nodeType":882},{},[],"Traditional phishing controls are also no longer in the right place to intercept these attacks. The delivery channel has shifted decisively away from email: ",{"data":6198,"content":6200,"nodeType":929},{"uri":6199},"https:\u002F\u002Fcloud.google.com\u002Fblog\u002Ftopics\u002Fthreat-intelligence\u002Fm-trends-2026",[6201],{"data":6202,"marks":6203,"value":6204,"nodeType":882},{},[],"Mandiant M-Trends 2026",{"data":6206,"marks":6207,"value":6208,"nodeType":882},{},[]," found email phishing dropped from 14% to 6% as an infection vector, and Push data shows ",{"data":6210,"marks":6211,"value":6213,"nodeType":882},{},[6212],{"type":1012},"roughly 1 in 3 phishing payloads intercepted were delivered outside email entirely",{"data":6215,"marks":6216,"value":6217,"nodeType":882},{},[]," — via search engine malvertising, social platforms, and compromised websites. Meanwhile, ",{"data":6219,"content":6221,"nodeType":929},{"uri":6220},"https:\u002F\u002Fwww.spamhaus.com\u002Fresource-center\u002Fsupporting-researchers-with-passive-dns\u002F",[6222],{"data":6223,"marks":6224,"value":6226,"nodeType":882},{},[6225],{"type":1012},"89% of phishing domains are active for less than two days",{"data":6228,"marks":6229,"value":6230,"nodeType":882},{},[],", making blocklist-based detection structurally too slow — attackers can spin up, tear down, and move on before blocklists can catch up.",{"data":6232,"content":6233,"nodeType":883},{},[6234],{"data":6235,"marks":6236,"value":6237,"nodeType":882},{},[],"Modern phishing plays out entirely inside the browser session. The only detection layer that can see the phishing page structure, the credential entry, and the anomalous token context is the browser itself. Browser-native detection analyses page behavior rather than matching known-bad domains, which means it fires on zero-day kits regardless of how recently the infrastructure was stood up. Controls like credential entry guardrails add an additional layer — blocking corporate passwords from being submitted to unauthorized domains independently of content and behavior-based detections.",{"data":6239,"content":6240,"nodeType":967},{},[],{"data":6242,"content":6243,"nodeType":975},{},[6244],{"data":6245,"marks":6246,"value":6248,"nodeType":882},{},[6247],{"type":1012},"#3 — Identity posture hardening: enforcing security across the apps your IdP doesn't manage",{"data":6250,"content":6251,"nodeType":883},{},[6252],{"data":6253,"marks":6254,"value":6256,"nodeType":882},{},[6255],{"type":1012},"Security value: High | Browser fit: Uniquely suited",{"data":6258,"content":6259,"nodeType":883},{},[6260],{"data":6261,"marks":6262,"value":6263,"nodeType":882},{},[],"The first challenge is knowing what you're protecting. Every identity an employee creates — every app they sign up to, every password they set, every login that bypasses SSO — is an authentication event that happens inside a browser session. The browser is the only layer that observes all of these events regardless of whether the app is sanctioned, managed, or even known to IT. Solutions that rely on API-level integrations with known apps, network traffic inspection, or email sign-up notifications can only ever build a partial picture, because they can only see apps they already know about. The browser sees the login itself, which means it discovers the identity at the moment it's created or used — authentication method, password strength, MFA status, and all.",{"data":6265,"content":6269,"nodeType":963},{"target":6266},{"sys":6267},{"id":6268,"type":960,"linkType":961},"HETvBCPsKGkqLVtaasXH0",[],{"data":6271,"content":6272,"nodeType":883},{},[6273],{"data":6274,"marks":6275,"value":6276,"nodeType":882},{},[],"But discovery without enforcement is just an inventory problem. Being in the browser means that you're in a great position to act on what it finds at the moment of authentication. Browser-native guardrails that prompt MFA enrollment, guide users toward stronger credentials, and redirect to SSO login paths close the gap at scale, on every app, including those the IdP has never seen. They also produce the continuous, auditable evidence of MFA coverage and credential hygiene across the full application estate that regulators, insurers, and auditors increasingly require — evidence that no IdP-centric tool can provide for apps outside its scope.",{"data":6278,"content":6279,"nodeType":967},{},[],{"data":6281,"content":6282,"nodeType":975},{},[6283],{"data":6284,"marks":6285,"value":6287,"nodeType":882},{},[6286],{"type":1012},"#4 — Browser extension security",{"data":6289,"content":6290,"nodeType":883},{},[6291],{"data":6292,"marks":6293,"value":6256,"nodeType":882},{},[6294],{"type":1012},{"data":6296,"content":6297,"nodeType":883},{},[6298,6302,6311,6314,6322,6325,6333],{"data":6299,"marks":6300,"value":6301,"nodeType":882},{},[],"Browser extensions have become one of the most talked-about attack surfaces in security over the past 18 months, and understandably so — a string of high-profile supply chain compromises have collectively impacted tens of millions of users since late 2024 (",{"data":6303,"content":6305,"nodeType":929},{"uri":6304},"https:\u002F\u002Fwww.cyberhaven.com\u002Fblog\u002Fcyberhavens-chrome-extension-security-incident-and-what-were-doing-about-it",[6306],{"data":6307,"marks":6308,"value":6310,"nodeType":882},{},[6309],{"type":927},"Cyberhaven",{"data":6312,"marks":6313,"value":1993,"nodeType":882},{},[],{"data":6315,"content":6317,"nodeType":929},{"uri":6316},"https:\u002F\u002Fthehackernews.com\u002F2025\u002F12\u002Fdarkspectre-browser-extension-campaigns.html",[6318],{"data":6319,"marks":6320,"value":6321,"nodeType":882},{},[],"DarkSpectre",{"data":6323,"marks":6324,"value":1993,"nodeType":882},{},[],{"data":6326,"content":6328,"nodeType":929},{"uri":6327},"https:\u002F\u002Fthehackernews.com\u002F2025\u002F12\u002Ftrust-wallet-chrome-extension-hack.html",[6329],{"data":6330,"marks":6331,"value":6332,"nodeType":882},{},[],"Trust Wallet",{"data":6334,"marks":6335,"value":6336,"nodeType":882},{},[],", among many others).",{"data":6338,"content":6339,"nodeType":883},{},[6340,6343,6352,6356,6361,6365,6370],{"data":6341,"marks":6342,"value":21,"nodeType":882},{},[],{"data":6344,"content":6346,"nodeType":929},{"uri":6345},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fwhy-browser-extension-risk-scoring-wont-predict-your-next-breach\u002F",[6347],{"data":6348,"marks":6349,"value":6351,"nodeType":882},{},[6350],{"type":927},"Analysis of 20,000+ extensions across Push customers",{"data":6353,"marks":6354,"value":6355,"nodeType":882},{},[]," found ",{"data":6357,"marks":6358,"value":6360,"nodeType":882},{},[6359],{"type":1012},"46.76% have the permission combinations needed to perform account takeover with no user interaction",{"data":6362,"marks":6363,"value":6364,"nodeType":882},{},[],", making permissions-based risk scoring effectively useless as a triage tool. The real threat model is not malicious extensions at install time — it's legitimate extensions that ",{"data":6366,"marks":6367,"value":6369,"nodeType":882},{},[6368],{"type":1045},"become",{"data":6371,"marks":6372,"value":6373,"nodeType":882},{},[]," malicious after an ownership transfer, developer account compromise, or silent update push. Every major extension supply chain breach of the past 18 months scored as low-risk immediately before compromise.",{"data":6375,"content":6376,"nodeType":883},{},[6377],{"data":6378,"marks":6379,"value":6380,"nodeType":882},{},[],"SWGs and network tools are structurally blind to this attack surface: a malicious extension exfiltrating session tokens generates no anomalous network signal — its traffic is indistinguishable from normal browsing. Endpoint agents have no visibility into extension behavior at the session level. Extension inventory, supply chain change monitoring — ownership transfers, permission escalations, developer contact changes — and enforcement all require browser-layer access by definition.",{"data":6382,"content":6383,"nodeType":967},{},[],{"data":6385,"content":6386,"nodeType":975},{},[6387],{"data":6388,"marks":6389,"value":6391,"nodeType":882},{},[6390],{"type":1012},"#5 — Shadow SaaS discovery and OAuth integration governance",{"data":6393,"content":6394,"nodeType":883},{},[6395],{"data":6396,"marks":6397,"value":6256,"nodeType":882},{},[6398],{"type":1012},{"data":6400,"content":6401,"nodeType":883},{},[6402,6406,6411,6415,6420],{"data":6403,"marks":6404,"value":6405,"nodeType":882},{},[],"Shadow SaaS discovery shares DNA with identity posture hardening (#3) — both start with the same browser-native visibility into login events that no other layer can replicate. Where identity posture focuses on hardening ",{"data":6407,"marks":6408,"value":6410,"nodeType":882},{},[6409],{"type":1045},"how",{"data":6412,"marks":6413,"value":6414,"nodeType":882},{},[]," employees authenticate, shadow SaaS discovery focuses on ",{"data":6416,"marks":6417,"value":6419,"nodeType":882},{},[6418],{"type":1045},"what",{"data":6421,"marks":6422,"value":6423,"nodeType":882},{},[]," they authenticate to: surfacing the full estate of applications in use across the organization, including those that IT has never sanctioned or even heard of.",{"data":6425,"content":6426,"nodeType":883},{},[6427],{"data":6428,"marks":6429,"value":6430,"nodeType":882},{},[],"OAuth integration governance is the component of shadow SaaS that is both the most potentially damaging and the hardest to surface through other means. The SaaS-to-SaaS OAuth pivot is now an industrialized attack pattern.",{"data":6432,"content":6433,"nodeType":1454},{},[6434,6455],{"data":6435,"content":6436,"nodeType":1419},{},[6437],{"data":6438,"content":6439,"nodeType":883},{},[6440,6444,6451],{"data":6441,"marks":6442,"value":6443,"nodeType":882},{},[],"The ",{"data":6445,"content":6446,"nodeType":929},{"uri":3507},[6447],{"data":6448,"marks":6449,"value":6450,"nodeType":882},{},[],"ShinyHunters",{"data":6452,"marks":6453,"value":6454,"nodeType":882},{},[]," Salesforce campaign — which compromised 1,000+ organizations and 1.5 billion records — demonstrated the full chain: the attacker didn't stop at stealing customer data but harvested OAuth tokens, AWS access keys, and Snowflake tokens from breached tenants and pivoted through connected services like Salesloft, Drift, and Gainsight to reach hundreds more organizations.",{"data":6456,"content":6457,"nodeType":1419},{},[6458],{"data":6459,"content":6460,"nodeType":883},{},[6461,6464,6472],{"data":6462,"marks":6463,"value":6443,"nodeType":882},{},[],{"data":6465,"content":6467,"nodeType":929},{"uri":6466},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Funpacking-the-vercel-breach\u002F",[6468],{"data":6469,"marks":6470,"value":6471,"nodeType":882},{},[],"Context.ai → Vercel",{"data":6473,"marks":6474,"value":6475,"nodeType":882},{},[]," chain followed the same logic — stored OAuth tokens from a forgotten AI app trial provided the bridge into Google Workspace, internal dashboards, and API keys. These are not isolated incidents; they are the repeatable playbook for extracting maximum value from a single compromise through the trust relationships that OAuth connections encode.",{"data":6477,"content":6478,"nodeType":883},{},[6479],{"data":6480,"marks":6481,"value":6482,"nodeType":882},{},[],"Every OAuth consent grant transits the browser — the authorization prompt, the scope disclosure, the user's approval click, and the redirect that completes the grant all happen inside a browser session — which makes the browser the only layer where an unwanted grant can be intercepted before the token is issued and the persistent access path is created. Once a token exists, the damage is done: it survives password resets, MFA changes, and session revocations, and revoking it after the fact requires first knowing it was granted, which most organizations do not.",{"data":6484,"content":6485,"nodeType":967},{},[],{"data":6487,"content":6488,"nodeType":975},{},[6489],{"data":6490,"marks":6491,"value":6493,"nodeType":882},{},[6492],{"type":1012},"#6 — Blocking ClickFix and social engineering-based malware delivery",{"data":6495,"content":6496,"nodeType":883},{},[6497],{"data":6498,"marks":6499,"value":6501,"nodeType":882},{},[6500],{"type":1012},"Security value: High | Browser fit: Strong for interception — shared with endpoint security for execution. ConsentFix is a browser-native exception that is T1-aligned.",{"data":6503,"content":6504,"nodeType":883},{},[6505,6509,6514,6518,6526,6530,6535,6539,6544],{"data":6506,"marks":6507,"value":6508,"nodeType":882},{},[],"ClickFix was the most common initial access vector reported by Microsoft in 2025, accounting for ",{"data":6510,"marks":6511,"value":6513,"nodeType":882},{},[6512],{"type":1012},"47% of observed attacks",{"data":6515,"marks":6516,"value":6517,"nodeType":882},{},[],". CrowdStrike's ",{"data":6519,"content":6521,"nodeType":929},{"uri":6520},"https:\u002F\u002Fwww.crowdstrike.com\u002Fexplore\u002F2026-global-threat-report",[6522],{"data":6523,"marks":6524,"value":6525,"nodeType":882},{},[],"2026 Global Threat Report",{"data":6527,"marks":6528,"value":6529,"nodeType":882},{},[]," identified fake CAPTCHA lures as the most common malware download type, increasing ",{"data":6531,"marks":6532,"value":6534,"nodeType":882},{},[6533],{"type":1012},"563% year-over-year",{"data":6536,"marks":6537,"value":6538,"nodeType":882},{},[],". The technique writes a malicious command to the victim's clipboard and social-engineers them into executing it. It is fileless (bypassing download scanning), user-executed (bypassing endpoint behavioral detections), and ",{"data":6540,"marks":6541,"value":6543,"nodeType":882},{},[6542],{"type":1012},"4 in 5 ClickFix payloads intercepted by Push arrived via search engines",{"data":6545,"marks":6546,"value":6547,"nodeType":882},{},[]," — not email (bypassing email anti-phishing controls).",{"data":6549,"content":6550,"nodeType":883},{},[6551],{"data":6552,"marks":6553,"value":6554,"nodeType":882},{},[],"The browser is the earliest and most effective intervention point — detecting the clipboard injection and social engineering lure before anything reaches the endpoint in executable form. But the problem doesn't end at the browser boundary: once the command has been pasted and run, detection and remediation become endpoint problems, and a mature defense requires both layers. The broader *Fix family — FileFix, InstallFix, and similar derivatives — follows the same pattern, with the browser providing the critical early-warning layer within a defense that spans browser and endpoint.",{"data":6556,"content":6560,"nodeType":963},{"target":6557},{"sys":6558},{"id":6559,"type":960,"linkType":961},"39alMHtw9FPHbQINqbAgBN",[],{"data":6562,"content":6563,"nodeType":967},{},[],{"data":6565,"content":6566,"nodeType":975},{},[6567],{"data":6568,"marks":6569,"value":6571,"nodeType":882},{},[6570],{"type":1012},"#7 — AI visibility and control: enforcing which AI tools employees can use and how",{"data":6573,"content":6574,"nodeType":883},{},[6575],{"data":6576,"marks":6577,"value":6579,"nodeType":882},{},[6578],{"type":1012},"Security value: High | Browser fit: Strong for access enforcement — but AI governance is not a new security problem so much as a force multiplier on existing ones",{"data":6581,"content":6582,"nodeType":883},{},[6583,6587,6596,6600,6609],{"data":6584,"marks":6585,"value":6586,"nodeType":882},{},[],"AI adoption is outpacing security governance at nearly every organization, and ",{"data":6588,"content":6590,"nodeType":929},{"uri":6589},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002F7-things-omdias-latest-report-tells-us-about-the-secure-enterprise-browser-market\u002F",[6591],{"data":6592,"marks":6593,"value":6595,"nodeType":882},{},[6594],{"type":1012},"71% of organizations are concerned about data leakage via unsanctioned AI apps",{"data":6597,"marks":6598,"value":6599,"nodeType":882},{},[],". But the security problems that AI creates are not, for the most part, novel — they are existing Tier 1 problems amplified by a new category of tooling. Shadow AI apps are shadow SaaS (#5). AI OAuth integrations are OAuth governance (#5). AI browser extensions are extension security (#4). The risk of employees using personal AI accounts — ",{"data":6601,"content":6603,"nodeType":929},{"uri":6602},"https:\u002F\u002Fkeepaware.com\u002Fblog\u002F46-of-sensitive-data-bypasses-your-dlp",[6604],{"data":6605,"marks":6606,"value":6608,"nodeType":882},{},[6607],{"type":1012},"46% of sensitive inputs to AI tools are sent via personal accounts",{"data":6610,"marks":6611,"value":6612,"nodeType":882},{},[]," — is an identity posture problem (#3).",{"data":6614,"content":6615,"nodeType":883},{},[6616],{"data":6617,"marks":6618,"value":6619,"nodeType":882},{},[],"The component parts that allow you to govern AI are individually Tier 1 capabilities, and the browser is the best single layer for gaining visibility and control over AI usage — it sees the apps, the OAuth grants, the extensions, and the account context. But a complete end-to-end solution also requires a presence on the endpoint layer (for local AI tools, IDE-integrated agents, and API-level usage that never touches the browser), and prompt-level DLP on sanctioned tools is better handled by platform-native controls than by browser-layer observation.",{"data":6621,"content":6625,"nodeType":963},{"target":6622},{"sys":6623},{"id":6624,"type":960,"linkType":961},"6Py3z9VgjhKrchmYvhmbsq",[],{"data":6627,"content":6628,"nodeType":883},{},[6629],{"data":6630,"marks":6631,"value":6632,"nodeType":882},{},[],"The browser is what makes platform controls effective — if employees are using personal accounts, there are no enterprise audit logs to inspect. And for the growing category of AI agents, agentic browsers, and MCP-connected tools that operate through OAuth grants rather than direct user interaction, the browser is where the consent decisions that authorize those agents are made.",{"data":6634,"content":6635,"nodeType":967},{},[],{"data":6637,"content":6638,"nodeType":975},{},[6639],{"data":6640,"marks":6641,"value":6643,"nodeType":882},{},[6642],{"type":1012},"#8 — Investigation acceleration and incident response: closing the missing middle",{"data":6645,"content":6646,"nodeType":883},{},[6647],{"data":6648,"marks":6649,"value":6651,"nodeType":882},{},[6650],{"type":1012},"Security value: High | Browser fit: Strong — fills a structural gap complementary to endpoint, network, and identity telemetry",{"data":6653,"content":6654,"nodeType":883},{},[6655,6659,6664,6668,6677],{"data":6656,"marks":6657,"value":6658,"nodeType":882},{},[],"Endpoint logs show what processes executed. Network logs show traffic destinations. IdP logs show authentication events. None of them show what happened ",{"data":6660,"marks":6661,"value":6663,"nodeType":882},{},[6662],{"type":1045},"inside the browser session",{"data":6665,"marks":6666,"value":6667,"nodeType":882},{},[]," — the phishing page the user saw, the credentials they entered, the malicious OAuth consent grant, the data uploaded or pasted to an unsanctioned service. This is the missing middle of modern incident investigations, and for the ",{"data":6669,"content":6671,"nodeType":929},{"uri":6670},"https:\u002F\u002Fwww.paloaltonetworks.co.uk\u002Fresources\u002Fresearch\u002Funit-42-incident-response-report",[6672],{"data":6673,"marks":6674,"value":6676,"nodeType":882},{},[6675],{"type":1012},"48% of intrusions involving browser-based activity",{"data":6678,"marks":6679,"value":6680,"nodeType":882},{},[],", the absence of browser telemetry is a significant investigative gap.",{"data":6682,"content":6683,"nodeType":883},{},[6684],{"data":6685,"marks":6686,"value":6687,"nodeType":882},{},[],"Browser-layer telemetry fills that gap with a fundamentally different quality of signal: what users actually clicked, what pages loaded and how they behaved, what credentials were entered, what session activity followed — structured, high-fidelity data from inside the session where the attack played out. That's the difference between inferring what happened and seeing it directly, and it determines scope, drives containment decisions, and provides the direct evidential record that neither endpoint DLP nor network monitoring can supply for browser-native attacks.",{"data":6689,"content":6690,"nodeType":883},{},[6691],{"data":6692,"marks":6693,"value":6694,"nodeType":882},{},[],"Browser telemetry is a key addition to the investigative picture. Investigations are inherently multi-source — without browser data, reconstructing an incident from EDR, network, and IdP logs won't tell you the full picture (particularly when attacks are increasingly delivered outside of email, intercepting users as they browse the internet normally).",{"data":6696,"content":6697,"nodeType":883},{},[6698],{"data":6699,"marks":6700,"value":6701,"nodeType":882},{},[],"The browser provides the causal link that other sources miss: the bridge between \"a user visited a URL\" and \"credentials were submitted to a phishing page that issued a session token now being replayed from an attacker-controlled browser.\" Integrated with SIEM and SOAR platforms, that signal enables automated response workflows to execute on high-confidence detections without waiting for manual triage.",{"data":6703,"content":6704,"nodeType":967},{},[],{"data":6706,"content":6707,"nodeType":975},{},[6708],{"data":6709,"marks":6710,"value":6712,"nodeType":882},{},[6711],{"type":1012},"#9 — Infostealer defense: detecting exposure and blocking delivery",{"data":6714,"content":6715,"nodeType":883},{},[6716],{"data":6717,"marks":6718,"value":6720,"nodeType":882},{},[6719],{"type":1012},"Security value: High | Browser fit: Strong for delivery interception and stolen factor detection — complementary to endpoint security for execution",{"data":6722,"content":6723,"nodeType":883},{},[6724],{"data":6725,"marks":6726,"value":6727,"nodeType":882},{},[],"Infostealers are the upstream supply chain for a disproportionate share of the most damaging enterprise attacks — harvesting credentials, session cookies, and browser profile data en masse from infected devices, then selling the outputs on infostealer markets for use in credential stuffing, ATO, and ransomware campaigns.",{"data":6729,"content":6733,"nodeType":963},{"target":6730},{"sys":6731},{"id":6732,"type":960,"linkType":961},"5NF1afwu3zFGThZTtStVQA",[],{"data":6735,"content":6736,"nodeType":883},{},[6737],{"data":6738,"marks":6739,"value":6740,"nodeType":882},{},[],"The browser is relevant at two points in the infostealer kill chain. First, delivery interception: ClickFix (covered in #6) is now the primary infostealer delivery mechanism, and the browser is the only layer that can intercept it before execution. Second, detecting stolen factors when attackers attempt to use them — and infostealers produce two categories of stolen factor that the browser can guard against.",{"data":6742,"content":6743,"nodeType":1454},{},[6744,6754],{"data":6745,"content":6746,"nodeType":1419},{},[6747],{"data":6748,"content":6749,"nodeType":883},{},[6750],{"data":6751,"marks":6752,"value":6753,"nodeType":882},{},[],"Stolen credentials can be identified at the point of login: browser-layer detection flags credentials that appear in known breach datasets, catching infostealer-harvested passwords being replayed in credential stuffing campaigns before the account is compromised.",{"data":6755,"content":6756,"nodeType":1419},{},[6757],{"data":6758,"content":6759,"nodeType":883},{},[6760],{"data":6761,"marks":6762,"value":6763,"nodeType":882},{},[],"Stolen session tokens are caught through a different mechanism: sessions originating in instrumented browsers carry a marker, and when a token subsequently appears in an un-instrumented browser it is a confirmed stolen session — catching infostealer-harvested cookies being replayed regardless of how or where the token was originally harvested.",{"data":6765,"content":6766,"nodeType":883},{},[6767,6771,6780,6784,6789],{"data":6768,"marks":6769,"value":6770,"nodeType":882},{},[],"This is particularly critical for the ",{"data":6772,"content":6774,"nodeType":929},{"uri":6773},"https:\u002F\u002Fwww.verizon.com\u002Fbusiness\u002Fen-gb\u002Fresources\u002Freports\u002Fdbir\u002F",[6775],{"data":6776,"marks":6777,"value":6779,"nodeType":882},{},[6778],{"type":1012},"46% of infected devices that are unmanaged",{"data":6781,"marks":6782,"value":6783,"nodeType":882},{},[]," where EDR is absent and the stolen credentials and session tokens will never be detected at the endpoint. Infostealer ",{"data":6785,"marks":6786,"value":6788,"nodeType":882},{},[6787],{"type":1045},"execution",{"data":6790,"marks":6791,"value":6792,"nodeType":882},{},[]," remains an endpoint problem; the browser closes the delivery and replay gaps that endpoint tools miss.",{"data":6794,"content":6795,"nodeType":967},{},[],{"data":6797,"content":6798,"nodeType":975},{},[6799],{"data":6800,"marks":6801,"value":6803,"nodeType":882},{},[6802],{"type":1012},"#10 — Data loss prevention: a key component of effective DLP, but not the full picture",{"data":6805,"content":6806,"nodeType":883},{},[6807],{"data":6808,"marks":6809,"value":6811,"nodeType":882},{},[6810],{"type":1012},"Security value: Medium-high | Browser fit: Partial — complementary to dedicated DLP",{"data":6813,"content":6814,"nodeType":883},{},[6815],{"data":6816,"marks":6817,"value":6818,"nodeType":882},{},[],"File uploads to unsanctioned services, sensitive data pasted into AI tools, and exfiltration through personal accounts are genuine and growing risks that traditional email and endpoint-centric DLP tools were not designed to catch. Browser-layer controls provide real value here — particularly for BYOD users and contractors, where endpoint DLP agents cannot be deployed and the browser is the only available data loss visibility.",{"data":6820,"content":6821,"nodeType":883},{},[6822],{"data":6823,"marks":6824,"value":6825,"nodeType":882},{},[],"The honest scope: browser-layer DLP does not cover email-based loss, endpoint-to-endpoint transfers, or cloud API exfiltration. It closes specific and important gaps within a broader DLP strategy, not a replacement for one. A further distinction for organizations evaluating browser DLP for secure third-party access: full-stack enterprise browsers can enforce deeper output controls — watermarking, obfuscation, screenshot and print restrictions — at the OS rendering level that browser extensions cannot reliably replicate. Extension-based browser DLP is strongest for upload, input, and access control use cases rather than OS-level output restriction.",{"data":6827,"content":6828,"nodeType":967},{},[],{"data":6830,"content":6831,"nodeType":975},{},[6832],{"data":6833,"marks":6834,"value":6836,"nodeType":882},{},[6835],{"type":1012},"Tier 3 — Lower Value: A problem best addressed outside of the browser",{"data":6838,"content":6839,"nodeType":1454},{},[6840,6855,6870,6885],{"data":6841,"content":6842,"nodeType":1419},{},[6843],{"data":6844,"content":6845,"nodeType":883},{},[6846,6851],{"data":6847,"marks":6848,"value":6850,"nodeType":882},{},[6849],{"type":1012},"Browser exploit protection",{"data":6852,"marks":6853,"value":6854,"nodeType":882},{},[]," (narrow RCE\u002Fsandbox sense) ranks lower because browser zero-days represent just 9% of all zero-days reported to Google, and 82% of attack detections are now malware-free (CrowdStrike 2026). This is a problem for browser vendors to solve, and it's not a big enough problem to warrant enterprises investing in additional mitigating controls.",{"data":6856,"content":6857,"nodeType":1419},{},[6858],{"data":6859,"content":6860,"nodeType":883},{},[6861,6866],{"data":6862,"marks":6863,"value":6865,"nodeType":882},{},[6864],{"type":1012},"Domain and URL category controls",{"data":6867,"marks":6868,"value":6869,"nodeType":882},{},[]," offer genuine browser-layer value but are commoditized by SWG and DNS filtering tools most organizations already operate. This can be provided in the browser, sure (and it's something we do at Push) but offers limited security value in terms of making a difference against modern attacks that quickly rotate these kinds of indicators and are designed to blend in.",{"data":6871,"content":6872,"nodeType":1419},{},[6873],{"data":6874,"content":6875,"nodeType":883},{},[6876,6881],{"data":6877,"marks":6878,"value":6880,"nodeType":882},{},[6879],{"type":1012},"Access management",{"data":6882,"marks":6883,"value":6884,"nodeType":882},{},[]," — ZTNA, VPN replacement, PAM, BYOD access control — is an IT infrastructure and access architecture problem, not a security operations problem, and belongs to a different buyer with a different evaluation frame. There are numerous (typically full-stack) Enterprise Browser solutions on the market that address IT use cases like this well.",{"data":6886,"content":6887,"nodeType":1419},{},[6888],{"data":6889,"content":6890,"nodeType":883},{},[6891,6895],{"data":6892,"marks":6893,"value":794,"nodeType":882},{},[6894],{"type":1012},{"data":6896,"marks":6897,"value":6898,"nodeType":882},{},[]," addresses browser exploit risk rather than the identity-first attacks that represent the majority of current enterprise browser risk, and introduces UX friction that limits deployment at scale. When it triggers, it introduces latency but still fails to detect and stop browser-native attacks.",{"data":6900,"content":6901,"nodeType":967},{},[],{"data":6903,"content":6904,"nodeType":975},{},[6905],{"data":6906,"marks":6907,"value":6909,"nodeType":882},{},[6908],{"type":1012},"How Push Security maps to the highest-value security use cases",{"data":6911,"content":6912,"nodeType":883},{},[6913],{"data":6914,"marks":6915,"value":6916,"nodeType":882},{},[],"Push is purpose-built to address all of these problems using a flexible browser extension — plug into any browser with no migration, no host agent deployment, and no IT overhead — that delivers telemetry and control from day one, and extends coverage to every enrolled browser regardless of device ownership.",{"data":6918,"content":6919,"nodeType":3104},{},[6920,6945,6969,6993,7017,7041,7065,7089,7113,7137,7161,7185],{"data":6921,"content":6922,"nodeType":3011},{},[6923,6934],{"data":6924,"content":6925,"nodeType":3025},{},[6926],{"data":6927,"content":6928,"nodeType":883},{},[6929],{"data":6930,"marks":6931,"value":6933,"nodeType":882},{},[6932],{"type":1012},"Security use case",{"data":6935,"content":6936,"nodeType":3025},{},[6937],{"data":6938,"content":6939,"nodeType":883},{},[6940],{"data":6941,"marks":6942,"value":6944,"nodeType":882},{},[6943],{"type":1012},"How Push addresses it",{"data":6946,"content":6947,"nodeType":3011},{},[6948,6959],{"data":6949,"content":6950,"nodeType":3025},{},[6951],{"data":6952,"content":6953,"nodeType":883},{},[6954],{"data":6955,"marks":6956,"value":6958,"nodeType":882},{},[6957],{"type":1012},"Account takeover prevention",{"data":6960,"content":6961,"nodeType":3025},{},[6962],{"data":6963,"content":6964,"nodeType":883},{},[6965],{"data":6966,"marks":6967,"value":6968,"nodeType":882},{},[],"Surfaces and fixes ghost logins, weak and breached credentials and missing MFA controls across every app and device — including shadow SaaS and unmanaged devices invisible to the IdP. Push also detects and stops the attack techniques that typically lead to ATO early in the kill chain and before an account can be compromised.",{"data":6970,"content":6971,"nodeType":3011},{},[6972,6983],{"data":6973,"content":6974,"nodeType":3025},{},[6975],{"data":6976,"content":6977,"nodeType":883},{},[6978],{"data":6979,"marks":6980,"value":6982,"nodeType":882},{},[6981],{"type":1012},"Advanced phishing detection",{"data":6984,"content":6985,"nodeType":3025},{},[6986],{"data":6987,"content":6988,"nodeType":883},{},[6989],{"data":6990,"marks":6991,"value":6992,"nodeType":882},{},[],"Behavioral page analysis detects phishing kits regardless of whether the domain is known-bad. Credential entry guardrails block corporate passwords from being submitted to unauthorized domains. TTP-based detection remains effective as attacker infrastructure rotates.",{"data":6994,"content":6995,"nodeType":3011},{},[6996,7007],{"data":6997,"content":6998,"nodeType":3025},{},[6999],{"data":7000,"content":7001,"nodeType":883},{},[7002],{"data":7003,"marks":7004,"value":7006,"nodeType":882},{},[7005],{"type":1012},"Identity posture hardening",{"data":7008,"content":7009,"nodeType":3025},{},[7010],{"data":7011,"content":7012,"nodeType":883},{},[7013],{"data":7014,"marks":7015,"value":7016,"nodeType":882},{},[],"Enforces MFA, strong credentials, and SSO adoption across every app the IdP doesn't manage. Produces continuous, auditable MFA coverage and credential hygiene evidence across the full application and device estate.",{"data":7018,"content":7019,"nodeType":3011},{},[7020,7031],{"data":7021,"content":7022,"nodeType":3025},{},[7023],{"data":7024,"content":7025,"nodeType":883},{},[7026],{"data":7027,"marks":7028,"value":7030,"nodeType":882},{},[7029],{"type":1012},"Browser extension security",{"data":7032,"content":7033,"nodeType":3025},{},[7034],{"data":7035,"content":7036,"nodeType":883},{},[7037],{"data":7038,"marks":7039,"value":7040,"nodeType":882},{},[],"Live extension inventory with supply chain change event monitoring — ownership transfers, permission escalations, developer contact changes — rather than static risk scoring. Supports default-deny allowlisting and remote extension removal. Blocks known-bad malicious extensions automatically.",{"data":7042,"content":7043,"nodeType":3011},{},[7044,7055],{"data":7045,"content":7046,"nodeType":3025},{},[7047],{"data":7048,"content":7049,"nodeType":883},{},[7050],{"data":7051,"marks":7052,"value":7054,"nodeType":882},{},[7053],{"type":1012},"Shadow SaaS and OAuth governance",{"data":7056,"content":7057,"nodeType":3025},{},[7058],{"data":7059,"content":7060,"nodeType":883},{},[7061],{"data":7062,"marks":7063,"value":7064,"nodeType":882},{},[],"Discovers shadow SaaS from actual login events with full authentication context. Monitors and blocks OAuth consent flows — including AI and MCP integrations — in real time before persistent access paths are created.",{"data":7066,"content":7067,"nodeType":3011},{},[7068,7079],{"data":7069,"content":7070,"nodeType":3025},{},[7071],{"data":7072,"content":7073,"nodeType":883},{},[7074],{"data":7075,"marks":7076,"value":7078,"nodeType":882},{},[7077],{"type":1012},"ClickFix and the *Fix family",{"data":7080,"content":7081,"nodeType":3025},{},[7082],{"data":7083,"content":7084,"nodeType":883},{},[7085],{"data":7086,"marks":7087,"value":7088,"nodeType":882},{},[],"Detects and blocks ClickFix lures, clipboard injection, and browser-native variants like ConsentFix in real time — before the payload executes or OAuth key material is captured.",{"data":7090,"content":7091,"nodeType":3011},{},[7092,7103],{"data":7093,"content":7094,"nodeType":3025},{},[7095],{"data":7096,"content":7097,"nodeType":883},{},[7098],{"data":7099,"marks":7100,"value":7102,"nodeType":882},{},[7101],{"type":1012},"AI visibility & control",{"data":7104,"content":7105,"nodeType":3025},{},[7106],{"data":7107,"content":7108,"nodeType":883},{},[7109],{"data":7110,"marks":7111,"value":7112,"nodeType":882},{},[],"Enforces which AI tools employees can access and routes usage to corporate tenants. Governs AI browser extensions and blocks OAuth consent grants to unapproved AI applications — drawing on the same Tier 1 capabilities (OAuth governance, extension security, shadow SaaS discovery) that make this possible.",{"data":7114,"content":7115,"nodeType":3011},{},[7116,7127],{"data":7117,"content":7118,"nodeType":3025},{},[7119],{"data":7120,"content":7121,"nodeType":883},{},[7122],{"data":7123,"marks":7124,"value":7126,"nodeType":882},{},[7125],{"type":1012},"Security investigations & incident response",{"data":7128,"content":7129,"nodeType":3025},{},[7130],{"data":7131,"content":7132,"nodeType":883},{},[7133],{"data":7134,"marks":7135,"value":7136,"nodeType":882},{},[],"High-fidelity session telemetry — page loads, credential entries, DOM changes, OAuth grants — fills the missing middle that endpoint, network, and IdP logs leave open. Feeds directly into SIEM and SOAR for automated response.",{"data":7138,"content":7139,"nodeType":3011},{},[7140,7151],{"data":7141,"content":7142,"nodeType":3025},{},[7143],{"data":7144,"content":7145,"nodeType":883},{},[7146],{"data":7147,"marks":7148,"value":7150,"nodeType":882},{},[7149],{"type":1012},"Infostealer defense",{"data":7152,"content":7153,"nodeType":3025},{},[7154],{"data":7155,"content":7156,"nodeType":883},{},[7157],{"data":7158,"marks":7159,"value":7160,"nodeType":882},{},[],"Intercepts ClickFix-based infostealer delivery before execution. Detects token replay in unenrolled browser contexts — catching post-theft abuse from AiTM-sourced tokens and infostealer-harvested cookies, including from unmanaged devices.",{"data":7162,"content":7163,"nodeType":3011},{},[7164,7175],{"data":7165,"content":7166,"nodeType":3025},{},[7167],{"data":7168,"content":7169,"nodeType":883},{},[7170],{"data":7171,"marks":7172,"value":7174,"nodeType":882},{},[7173],{"type":1012},"Data loss prevention",{"data":7176,"content":7177,"nodeType":3025},{},[7178],{"data":7179,"content":7180,"nodeType":883},{},[7181],{"data":7182,"marks":7183,"value":7184,"nodeType":882},{},[],"Observes file uploads, downloads, and sensitive data inputs across all applications. Extends data loss visibility to BYOD and contractor devices where endpoint DLP cannot reach.",{"data":7186,"content":7187,"nodeType":3011},{},[7188,7198],{"data":7189,"content":7190,"nodeType":3025},{},[7191],{"data":7192,"content":7193,"nodeType":883},{},[7194],{"data":7195,"marks":7196,"value":6865,"nodeType":882},{},[7197],{"type":1012},{"data":7199,"content":7200,"nodeType":3025},{},[7201],{"data":7202,"content":7203,"nodeType":883},{},[7204],{"data":7205,"marks":7206,"value":7207,"nodeType":882},{},[],"Custom URL blocklists with wildcard support and REST API management for threat intelligence feed sync. Application category blocking restricts access to classes of apps (file-sharing, unsanctioned AI tools) configurable by user group. Domain categorization bringing SWG-style category blocking natively to the browser without a network proxy.",{"data":7209,"content":7210,"nodeType":967},{},[],{"data":7212,"content":7213,"nodeType":883},{},[7214,7218,7224],{"data":7215,"marks":7216,"value":7217,"nodeType":882},{},[],"Push Security is the most powerful AI-native security tool in the browser. Think EDR, but for the browser — high-fidelity telemetry and real-time control across every session, on every device, with no browser migration required. ",{"data":7219,"content":7220,"nodeType":929},{"uri":1283},[7221],{"data":7222,"marks":7223,"value":2941,"nodeType":882},{},[],{"data":7225,"marks":7226,"value":21,"nodeType":882},{},[],"The top 10 security problems you can solve in the browser — ranked by value","Ranking the security problems you can solve in the browser by security value and browser fit.","2026-05-14T00:00:00.000Z","the-top-10-security-problems-you-can-solve-in-the-browser-ranked-by-value",{"items":7232},[7233,7236],{"sys":7234,"name":298},{"id":7235},"3pjES4THCIfSAwhGdNwBcy",{"sys":7237,"name":7239},{"id":7238},"1gZi8NrRy2v9OqPV7C4dwD","Risk management",{"items":7241},[7242],{"fullName":3964,"firstName":3965,"jobTitle":868,"profilePicture":7243},{"url":3969},{"__typename":1365,"sys":7245,"content":7247,"title":8015,"synopsis":8016,"hashTags":59,"publishedDate":8017,"slug":8018,"tagsCollection":8019,"authorsCollection":8025},{"id":7246},"2V130uMePtxAaefYQAKInb",{"json":7248},{"data":7249,"content":7250,"nodeType":1294},{},[7251,7257,7264,7271,7278,7281,7289,7296,7308,7320,7326,7333,7336,7344,7351,7357,7364,7371,7480,7487,7490,7498,7505,7568,7584,7590,7597,7600,7608,7615,7623,7630,7637,7668,7675,7683,7690,7697,7704,7712,7719,7726,7733,7736,7744,7756,7763,7770,7778,7785,7792,7800,7807,7870,7886,7905,7913,7920,7928,7935,7942,7949,7955,7963,7970,7977,7982,7989,7996,8003,8009],{"data":7252,"content":7256,"nodeType":963},{"target":7253},{"sys":7254},{"id":7255,"type":960,"linkType":961},"5CPZ96xixlhgh6oqQ2rfmO",[],{"data":7258,"content":7259,"nodeType":883},{},[7260],{"data":7261,"marks":7262,"value":7263,"nodeType":882},{},[],"When a security team evaluates browser security solutions, they're usually asking the right question: “How do we protect our users as they work in the browser?”",{"data":7265,"content":7266,"nodeType":883},{},[7267],{"data":7268,"marks":7269,"value":7270,"nodeType":882},{},[],"But the answer they get from many vendors is shaped by a fundamentally different threat model — one that treats the browser as a piece of software to be hardened against exploitation, rather than as the arena where your users’ identities get stolen.",{"data":7272,"content":7273,"nodeType":883},{},[7274],{"data":7275,"marks":7276,"value":7277,"nodeType":882},{},[],"This distinction has enormous consequences for your security posture and the return you can expect from your investment in a new solution.",{"data":7279,"content":7280,"nodeType":967},{},[],{"data":7282,"content":7283,"nodeType":975},{},[7284],{"data":7285,"marks":7286,"value":7288,"nodeType":882},{},[7287],{"type":1012},"Two different problems, dressed the same",{"data":7290,"content":7291,"nodeType":883},{},[7292],{"data":7293,"marks":7294,"value":7295,"nodeType":882},{},[],"When it comes to protecting users as they work in the browser, security tools typically fall into one of two camps:",{"data":7297,"content":7298,"nodeType":883},{},[7299,7304],{"data":7300,"marks":7301,"value":7303,"nodeType":882},{},[7302],{"type":1012},"The first camp:",{"data":7305,"marks":7306,"value":7307,"nodeType":882},{},[]," represented by solutions like Seraphic (now CrowdStrike) — is built around the threat of attacking the browser itself. The architecture is designed to scramble the browser’s JavaScript runtime and prevent exploits from detonating and breaking out of the browser sandbox. This is browser hardening: defending the browser as software against exploitation by attackers who want to compromise the underlying device.",{"data":7309,"content":7310,"nodeType":883},{},[7311,7316],{"data":7312,"marks":7313,"value":7315,"nodeType":882},{},[7314],{"type":1012},"The second camp:",{"data":7317,"marks":7318,"value":7319,"nodeType":882},{},[]," and the one Push Security occupies uniquely, focuses on what happens inside the browser when a user is working normally. Phishing pages harvesting credentials. Session tokens being stolen. Malicious OAuth applications being granted access through social engineering. Adversary-in-the-middle proxies intercepting authentication flows. These attacks don't exploit the browser. They exploit the human — and now agents — using it via the browser's legitimate capabilities (think of it as LOTL, browser edition).",{"data":7321,"content":7325,"nodeType":963},{"target":7322},{"sys":7323},{"id":7324,"type":960,"linkType":961},"5Kw2kSrL8u4VyslxK8HCtR",[],{"data":7327,"content":7328,"nodeType":883},{},[7329],{"data":7330,"marks":7331,"value":7332,"nodeType":882},{},[],"The question for any security team evaluating this space: which of these threat models presents the greatest risks to my organization?",{"data":7334,"content":7335,"nodeType":967},{},[],{"data":7337,"content":7338,"nodeType":975},{},[7339],{"data":7340,"marks":7341,"value":7343,"nodeType":882},{},[7342],{"type":1012},"How organizations are actually being breached",{"data":7345,"content":7346,"nodeType":883},{},[7347],{"data":7348,"marks":7349,"value":7350,"nodeType":882},{},[],"Let's look at the major breach campaigns of the last three years without the marketing filter and a pattern emerges immediately. Scattered Spider and its successors breached MGM Resorts, Caesars, M&S, JLR, and Salesforce customers — not through browser exploits, but through social engineering, phishing and Adversary-in-the-Middle attacks that stole session tokens and SSO credentials. ",{"data":7352,"content":7356,"nodeType":963},{"target":7353},{"sys":7354},{"id":7355,"type":960,"linkType":961},"2qIMTiyyIsQFAyGJ9Ikyej",[],{"data":7358,"content":7359,"nodeType":883},{},[7360],{"data":7361,"marks":7362,"value":7363,"nodeType":882},{},[],"In every case, the attack happened in the browser — using stolen identities to log into legitimate cloud services — not on the browser through exploitation of the browser engine itself.",{"data":7365,"content":7366,"nodeType":883},{},[7367],{"data":7368,"marks":7369,"value":7370,"nodeType":882},{},[],"The data from major threat intelligence sources is unambiguous:",{"data":7372,"content":7373,"nodeType":1454},{},[7374,7393,7412,7431,7450,7465],{"data":7375,"content":7376,"nodeType":1419},{},[7377],{"data":7378,"content":7379,"nodeType":883},{},[7380,7384,7389],{"data":7381,"marks":7382,"value":7383,"nodeType":882},{},[],"Identity weaknesses played a material role in ",{"data":7385,"marks":7386,"value":7388,"nodeType":882},{},[7387],{"type":1012},"almost 90% of Unit 42 incident response investigations",{"data":7390,"marks":7391,"value":7392,"nodeType":882},{},[]," (Palo Alto Networks Unit 42 IR Report)",{"data":7394,"content":7395,"nodeType":1419},{},[7396],{"data":7397,"content":7398,"nodeType":883},{},[7399,7403,7408],{"data":7400,"marks":7401,"value":7402,"nodeType":882},{},[],"Credential abuse and phishing combined accounted for ",{"data":7404,"marks":7405,"value":7407,"nodeType":882},{},[7406],{"type":1012},"38% of all breaches",{"data":7409,"marks":7410,"value":7411,"nodeType":882},{},[],", making identity the single largest breach vector (Verizon DBIR 2025)",{"data":7413,"content":7414,"nodeType":1419},{},[7415],{"data":7416,"content":7417,"nodeType":883},{},[7418,7422,7427],{"data":7419,"marks":7420,"value":7421,"nodeType":882},{},[],"Cloud-conscious intrusions — attackers using stolen identities to access cloud services — rose ",{"data":7423,"marks":7424,"value":7426,"nodeType":882},{},[7425],{"type":1012},"37% in 2025",{"data":7428,"marks":7429,"value":7430,"nodeType":882},{},[],", up 266% among state-nexus actors (CrowdStrike 2026 Global Threat Report)",{"data":7432,"content":7433,"nodeType":1419},{},[7434],{"data":7435,"content":7436,"nodeType":883},{},[7437,7441,7446],{"data":7438,"marks":7439,"value":7440,"nodeType":882},{},[],"In cloud-related incidents, identity issues drove initial access in ",{"data":7442,"marks":7443,"value":7445,"nodeType":882},{},[7444],{"type":1012},"83% of cases",{"data":7447,"marks":7448,"value":7449,"nodeType":882},{},[]," (Mandiant \u002F Google Cloud Threat Horizons H1 2026)",{"data":7451,"content":7452,"nodeType":1419},{},[7453],{"data":7454,"content":7455,"nodeType":883},{},[7456,7461],{"data":7457,"marks":7458,"value":7460,"nodeType":882},{},[7459],{"type":1012},"82% of attack detections are now malware-free",{"data":7462,"marks":7463,"value":7464,"nodeType":882},{},[]," — they don't touch the endpoint and abuse legitimate access and functionality (CrowdStrike 2026 Global Threat Report)",{"data":7466,"content":7467,"nodeType":1419},{},[7468],{"data":7469,"content":7470,"nodeType":883},{},[7471,7476],{"data":7472,"marks":7473,"value":7475,"nodeType":882},{},[7474],{"type":1012},"49% of organizations",{"data":7477,"marks":7478,"value":7479,"nodeType":882},{},[]," suffered a successful browser-based attack in the last 12 months (Omdia 2026)",{"data":7481,"content":7482,"nodeType":883},{},[7483],{"data":7484,"marks":7485,"value":7486,"nodeType":882},{},[],"These aren't edge cases. This is now the primary attack playbook.",{"data":7488,"content":7489,"nodeType":967},{},[],{"data":7491,"content":7492,"nodeType":2050},{},[7493],{"data":7494,"marks":7495,"value":7497,"nodeType":882},{},[7496],{"type":1012},"The economics of attack choice",{"data":7499,"content":7500,"nodeType":883},{},[7501],{"data":7502,"marks":7503,"value":7504,"nodeType":882},{},[],"Attackers are rational actors. They pick the cheapest, most reliable path to their objective. The economics of browser exploitation versus identity theft tell the whole story:",{"data":7506,"content":7507,"nodeType":1454},{},[7508,7523,7538,7553],{"data":7509,"content":7510,"nodeType":1419},{},[7511],{"data":7512,"content":7513,"nodeType":883},{},[7514,7518],{"data":7515,"marks":7516,"value":7517,"nodeType":882},{},[],"Chrome sandbox RCE exploit (bug bounty value): ",{"data":7519,"marks":7520,"value":7522,"nodeType":882},{},[7521],{"type":1012},"$250,000",{"data":7524,"content":7525,"nodeType":1419},{},[7526],{"data":7527,"content":7528,"nodeType":883},{},[7529,7533],{"data":7530,"marks":7531,"value":7532,"nodeType":882},{},[],"IAB-provided IdP admin account: ",{"data":7534,"marks":7535,"value":7537,"nodeType":882},{},[7536],{"type":1012},"~$3,000",{"data":7539,"content":7540,"nodeType":1419},{},[7541],{"data":7542,"content":7543,"nodeType":883},{},[7544,7548],{"data":7545,"marks":7546,"value":7547,"nodeType":882},{},[],"1-year phishing kit rental (PhaaS): ",{"data":7549,"marks":7550,"value":7552,"nodeType":882},{},[7551],{"type":1012},"~$1,000",{"data":7554,"content":7555,"nodeType":1419},{},[7556],{"data":7557,"content":7558,"nodeType":883},{},[7559,7563],{"data":7560,"marks":7561,"value":7562,"nodeType":882},{},[],"Bulk stolen credential list: ",{"data":7564,"marks":7565,"value":7567,"nodeType":882},{},[7566],{"type":1012},"~$15",{"data":7569,"content":7570,"nodeType":883},{},[7571,7575,7580],{"data":7572,"marks":7573,"value":7574,"nodeType":882},{},[],"Browser zero-days accounted for just ",{"data":7576,"marks":7577,"value":7579,"nodeType":882},{},[7578],{"type":1012},"9% of all zero-days reported to Google in 2025",{"data":7581,"marks":7582,"value":7583,"nodeType":882},{},[]," — described by Google's own researchers as a \"historic low.\" Chrome's sandbox architecture, site isolation, and hardware-backed security features are the result of years of sustained hardening investment. When a browser vulnerability is discovered, Google typically deploys a patch within days.",{"data":7585,"content":7589,"nodeType":963},{"target":7586},{"sys":7587},{"id":7588,"type":960,"linkType":961},"5XWKHTT5J06yWcgZIOL95t",[],{"data":7591,"content":7592,"nodeType":883},{},[7593],{"data":7594,"marks":7595,"value":7596,"nodeType":882},{},[],"The bottom line: browser exploits are extraordinarily expensive to develop, increasingly difficult to execute reliably against a hardened modern browser, and patched rapidly when discovered. In sharp contrast, identity attacks are cheap to run, highly scalable, and have a low technical barrier to adoption — that’s why they’re responsible for the overwhelming majority of enterprise breaches. Attackers have voted with their resources.",{"data":7598,"content":7599,"nodeType":967},{},[],{"data":7601,"content":7602,"nodeType":975},{},[7603],{"data":7604,"marks":7605,"value":7607,"nodeType":882},{},[7606],{"type":1012},"What you're actually buying with each vendor",{"data":7609,"content":7610,"nodeType":883},{},[7611],{"data":7612,"marks":7613,"value":7614,"nodeType":882},{},[],"Understanding the core architectural choice each vendor has made helps decode what their solution can and cannot protect you from.",{"data":7616,"content":7617,"nodeType":2050},{},[7618],{"data":7619,"marks":7620,"value":7622,"nodeType":882},{},[7621],{"type":1012},"Seraphic (CrowdStrike)",{"data":7624,"content":7625,"nodeType":883},{},[7626],{"data":7627,"marks":7628,"value":7629,"nodeType":882},{},[],"Seraphic's architecture is built to inject into the browser's JavaScript runtime at the OS layer, scrambling browser internals to prevent exploits from executing. This is a technically sophisticated approach to a technically interesting problem that is, by every threat intelligence measure, not the problem causing enterprise breaches at scale.",{"data":7631,"content":7632,"nodeType":883},{},[7633],{"data":7634,"marks":7635,"value":7636,"nodeType":882},{},[],"Beyond the threat model mismatch, there are structural concerns with the approach itself. Injecting an agent into the browser's JS runtime is a technique with well-documented stability consequences. This is the same approach antivirus vendors have used for years, often at the cost of system stability. Seraphic now runs alongside the CrowdStrike Falcon sensor on managed devices, combining two heavyweight agents on the same machine. For any organization with CrowdStrike already deployed, the question isn't theoretical: how has that combination been validated in production environments?",{"data":7638,"content":7639,"nodeType":883},{},[7640,7644,7651,7655,7664],{"data":7641,"marks":7642,"value":7643,"nodeType":882},{},[],"There's also the managed-device limitation. Seraphic requires a kernel-level agent, which means it loses meaningful capability on unmanaged devices, BYOD machines, and contractor endpoints. This is not a niche concern: according to ",{"data":7645,"content":7646,"nodeType":929},{"uri":6589},[7647],{"data":7648,"marks":7649,"value":7650,"nodeType":882},{},[],"Omdia's 2026 browser security survey",{"data":7652,"marks":7653,"value":7654,"nodeType":882},{},[],", 32% of users access corporate applications from unmanaged devices at least occasionally. Agent-based solutions are blind to nearly a third of your actual attack surface by design. The Okta breach began on a support engineer's personal device, where ",{"data":7656,"content":7658,"nodeType":929},{"uri":7657},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fbrowser-sync-attacks-where-personal-account-hacks-lead-to-corporate-breaches\u002F",[7659],{"data":7660,"marks":7661,"value":7663,"nodeType":882},{},[7662],{"type":927},"corporate credentials had synced",{"data":7665,"marks":7666,"value":7667,"nodeType":882},{},[]," via Chrome's built-in profile sync. No agent, no visibility.",{"data":7669,"content":7670,"nodeType":883},{},[7671],{"data":7672,"marks":7673,"value":7674,"nodeType":882},{},[],"Teams evaluating Seraphic today are also buying into an integration roadmap, not a shipped capability. The acquisition by CrowdStrike closed in early 2026. The work of wiring browser telemetry into Falcon Fusion and correlating it with endpoint signals is currently a promise, not a production feature.",{"data":7676,"content":7677,"nodeType":2050},{},[7678],{"data":7679,"marks":7680,"value":7682,"nodeType":882},{},[7681],{"type":1012},"SquareX (Zscaler)",{"data":7684,"content":7685,"nodeType":883},{},[7686],{"data":7687,"marks":7688,"value":7689,"nodeType":882},{},[],"SquareX's core capability is sandboxing suspicious file downloads inside disposable browser containers before they reach the endpoint. This is a legitimate approach to a real but declining problem. 82% of attack detections are now malware-free (CrowdStrike 2026 Global Threat Report) — attacks don't arrive as files to be sandboxed, they arrive as authenticated sessions. And the delivery channel shift makes the picture even starker: across Push's customer base, 1 in 3 phishing payloads are now delivered outside of email entirely — via social media, ads, and messaging platforms — and 4 in 5 ClickFix payloads arrive through search engines, not email. The threat that SquareX was architecturally designed to address is a shrinking share of the actual attack surface, and it's shrinking fast.",{"data":7691,"content":7692,"nodeType":883},{},[7693],{"data":7694,"marks":7695,"value":7696,"nodeType":882},{},[],"Zscaler already has sandboxing built into ZIA. For an existing Zscaler customer evaluating SquareX, the honest question is: what does this add beyond some extension analysis capability and what you already have? The AiTM phishing campaign that stole your user's credentials and accessed your cloud applications generates no malicious file, triggers no sandbox, and produces no network signal for Zscaler's traffic inspection to catch — because it happened entirely inside a browser session using legitimate authentication flows.",{"data":7698,"content":7699,"nodeType":883},{},[7700],{"data":7701,"marks":7702,"value":7703,"nodeType":882},{},[],"The acquisition also raises product focus questions. Being absorbed into a network-centric platform means SquareX is now optimized for Zscaler's priorities, not for standalone browser detection and response. Teams that care about investigation, threat hunting, and incident response should ask specifically what SquareX adds in those workflows under Zscaler ownership.",{"data":7705,"content":7706,"nodeType":2050},{},[7707],{"data":7708,"marks":7709,"value":7711,"nodeType":882},{},[7710],{"type":1012},"LayerX",{"data":7713,"content":7714,"nodeType":883},{},[7715],{"data":7716,"marks":7717,"value":7718,"nodeType":882},{},[],"LayerX is primarily a policy enforcement and risk scoring platform focused on internal governance — controlling which applications employees access, what data moves through the browser, and whether behavior complies with internal rules.",{"data":7720,"content":7721,"nodeType":883},{},[7722],{"data":7723,"marks":7724,"value":7725,"nodeType":882},{},[],"Push Security covers that ground too. Push provides full visibility over AI tool usage, shadow SaaS, unmanaged identities, and data loss vectors — including sensitive data submitted through AI prompts, file uploads to personal cloud destinations, and OAuth grants to third-party applications. The same browser telemetry that detects external attacks also surfaces insider risks and powers DLP controls and compliance audit evidence, all from a single extension.",{"data":7727,"content":7728,"nodeType":883},{},[7729],{"data":7730,"marks":7731,"value":7732,"nodeType":882},{},[],"The critical difference is that Push goes significantly further. Where LayerX scores risk and enforces policy, Push detects active external attack techniques in real time: AiTM phishing kits as they execute, session tokens being stolen, ClickFix lures through behavioral analysis of page structure. These are the attacks causing the most damaging breaches today, and they don't surface on a risk score until after the damage is done. Push addresses both the governance problem and the external threat problem from the same platform. LayerX addresses only the first.",{"data":7734,"content":7735,"nodeType":967},{},[],{"data":7737,"content":7738,"nodeType":975},{},[7739],{"data":7740,"marks":7741,"value":7743,"nodeType":882},{},[7742],{"type":1012},"Securing the organization via the browser: Push Security",{"data":7745,"content":7746,"nodeType":883},{},[7747,7752],{"data":7748,"marks":7749,"value":7751,"nodeType":882},{},[7750],{"type":1012},"Push Security is built on a different architectural premise:",{"data":7753,"marks":7754,"value":7755,"nodeType":882},{},[]," the browser is not primarily a piece of software to harden against exploitation. It is the primary workplace, the primary SaaS access point, and the arena where the majority of modern identity attacks play out. The goal is to secure the organization via the browser — not just to secure the browser itself.",{"data":7757,"content":7758,"nodeType":883},{},[7759],{"data":7760,"marks":7761,"value":7762,"nodeType":882},{},[],"This means Push's detection surface is built around the attacks that are actually causing breaches: adversary-in-the-middle phishing, ClickFix and its many variants, credential stuffing against shadow identities, session token theft and replay, OAuth consent abuse, and the full spectrum of identity-based initial access techniques that dominate the modern threat landscape.",{"data":7764,"content":7765,"nodeType":883},{},[7766],{"data":7767,"marks":7768,"value":7769,"nodeType":882},{},[],"The deployment model reflects the threat model. Push deploys as a lightweight browser extension — no kernel-level agent, no device dependency, no migration to a new browser. It works on managed and unmanaged devices, across every traditional, enterprise and AI browser where employees are doing work and attackers are targeting them. The operational overhead is minimal by design: Push has been deployed to 100,000 users in under one hour during normal business hours.",{"data":7771,"content":7772,"nodeType":2050},{},[7773],{"data":7774,"marks":7775,"value":7777,"nodeType":882},{},[7776],{"type":1012},"Detection philosophy: targeting what attackers can't change",{"data":7779,"content":7780,"nodeType":883},{},[7781],{"data":7782,"marks":7783,"value":7784,"nodeType":882},{},[],"Push's detection approach targets attacker TTPs rather than indicators of compromise that attackers can rotate in minutes. 95% of attacks detected by Push used some form of bot protection service — meaning the specific domain and IP were deliberately obscured. If your primary detection relies on blocklists, recent reports tell us that 89% of phishing domains will evade you: because they're active for less than two days, they can be spun up, down, and replaced faster than blocklists can keep up.",{"data":7786,"content":7787,"nodeType":883},{},[7788],{"data":7789,"marks":7790,"value":7791,"nodeType":882},{},[],"Behavioral detection of the attack technique — the AiTM relay structure, the credential entry on a cloned login page, the anomalous session context — remains valid regardless of what domain the attack is hosted on or which PhaaS kit was used to build it.",{"data":7793,"content":7794,"nodeType":2050},{},[7795],{"data":7796,"marks":7797,"value":7799,"nodeType":882},{},[7798],{"type":1012},"Measuring the identity attack surface (it's bigger than you realize)",{"data":7801,"content":7802,"nodeType":883},{},[7803],{"data":7804,"marks":7805,"value":7806,"nodeType":882},{},[],"Because Push has visibility into actual login behavior across thousands of organizations, it can quantify the attack surface that identity-based attacks exploit. Of the last million logins observed by Push:",{"data":7808,"content":7809,"nodeType":1454},{},[7810,7825,7840,7855],{"data":7811,"content":7812,"nodeType":1419},{},[7813],{"data":7814,"content":7815,"nodeType":883},{},[7816,7821],{"data":7817,"marks":7818,"value":7820,"nodeType":882},{},[7819],{"type":1012},"15 corporate identities were identified per employee",{"data":7822,"marks":7823,"value":7824,"nodeType":882},{},[]," used to access cloud apps",{"data":7826,"content":7827,"nodeType":1419},{},[7828],{"data":7829,"content":7830,"nodeType":883},{},[7831,7836],{"data":7832,"marks":7833,"value":7835,"nodeType":882},{},[7834],{"type":1012},"1 in 4",{"data":7837,"marks":7838,"value":7839,"nodeType":882},{},[]," were password logins, not SSO",{"data":7841,"content":7842,"nodeType":1419},{},[7843],{"data":7844,"content":7845,"nodeType":883},{},[7846,7851],{"data":7847,"marks":7848,"value":7850,"nodeType":882},{},[7849],{"type":1012},"2 in 5",{"data":7852,"marks":7853,"value":7854,"nodeType":882},{},[]," were not protected by MFA",{"data":7856,"content":7857,"nodeType":1419},{},[7858],{"data":7859,"content":7860,"nodeType":883},{},[7861,7866],{"data":7862,"marks":7863,"value":7865,"nodeType":882},{},[7864],{"type":1012},"1 in 5",{"data":7867,"marks":7868,"value":7869,"nodeType":882},{},[]," used a weak, breached, or reused password",{"data":7871,"content":7872,"nodeType":883},{},[7873,7877,7882],{"data":7874,"marks":7875,"value":7876,"nodeType":882},{},[],"And it's not just login hygiene. Across Push's customer base, ",{"data":7878,"marks":7879,"value":7881,"nodeType":882},{},[7880],{"type":1012},"46%+ of browser extensions in corporate environments have the permission combinations required for direct account takeover via session theft if they are malicious or compromised by an attacker",{"data":7883,"marks":7884,"value":7885,"nodeType":882},{},[],". Most organizations have no inventory of what's running in their employees' browsers, let alone visibility into what those extensions can access.",{"data":7887,"content":7888,"nodeType":883},{},[7889,7893,7901],{"data":7890,"marks":7891,"value":7892,"nodeType":882},{},[],"These aren't theoretical vulnerabilities. They're the specific weaknesses that browser-native identity attacks are designed to exploit. ",{"data":7894,"content":7896,"nodeType":929},{"uri":7895},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fthe-cisos-data-problem-and-how-browser-telemetry-can-help\u002F",[7897],{"data":7898,"marks":7899,"value":7900,"nodeType":882},{},[],"This visibility turns browser security from a reactive posture into a proactive one",{"data":7902,"marks":7903,"value":7904,"nodeType":882},{},[]," — you can see and remediate the identity weaknesses before an attacker exploits them, not just detect the attack while it's in progress.",{"data":7906,"content":7907,"nodeType":2050},{},[7908],{"data":7909,"marks":7910,"value":7912,"nodeType":882},{},[7911],{"type":1012},"The ROI case",{"data":7914,"content":7915,"nodeType":883},{},[7916],{"data":7917,"marks":7918,"value":7919,"nodeType":882},{},[],"The ROI question for any security investment is: what quantum of real risk does this tool address, at what cost in money and operational friction?",{"data":7921,"content":7922,"nodeType":883},{},[7923],{"data":7924,"marks":7925,"value":7927,"nodeType":882},{},[7926],{"type":1012},"That calculation looks very different depending on your threat model.",{"data":7929,"content":7930,"nodeType":883},{},[7931],{"data":7932,"marks":7933,"value":7934,"nodeType":882},{},[],"A solution focused on browser engine exploits and sandbox escapes is defending against an attack category that represents a tiny fraction of actual enterprise breaches, requires extraordinary attacker resources to execute, and is increasingly mitigated by browser vendors themselves through hardening and rapid patching. Chrome's automatic update cycle means that even when a browser vulnerability is discovered and disclosed, it is typically in front of users as a patch within days. The defenders here are Google, Mozilla, and Microsoft — with multi-billion dollar security teams and full access to the browser internals.",{"data":7936,"content":7937,"nodeType":883},{},[7938],{"data":7939,"marks":7940,"value":7941,"nodeType":882},{},[],"A solution focused on identity attacks via the browser — phishing, credential theft, session hijacking, OAuth abuse, malicious browser extensions — is defending against the primary cause of enterprise breaches, one that is accelerating (cloud-conscious intrusions up 37% in 2025, browser-based attacks increasing at 68% of organizations over the past two years per Omdia) and increasingly automated through PhaaS infrastructure that gives low-skill attackers enterprise-grade capability for $1,000 a year.",{"data":7943,"content":7944,"nodeType":883},{},[7945],{"data":7946,"marks":7947,"value":7948,"nodeType":882},{},[],"There's also a forward-looking dimension. The threat landscape isn't moving toward more browser exploitation. It's moving further into identity abuse. AI-powered phishing lowers the social engineering barrier. Agentic browsers will automate credential stuffing and account takeover at a scale that wasn't previously possible. And attackers are already adapting to authentication improvements: device code phishing has increased 37x since the start of 2026, a technique specifically designed to circumvent passkeys by bypassing the authentication flow entirely — the attacker never encounters a login page. The investment in identity-centric browser detection compounds over time as the attack surface evolves in the same direction.",{"data":7950,"content":7954,"nodeType":963},{"target":7951},{"sys":7952},{"id":7953,"type":960,"linkType":961},"cQ6WPV2NMYvDMZXifqzK1",[],{"data":7956,"content":7957,"nodeType":2050},{},[7958],{"data":7959,"marks":7960,"value":7962,"nodeType":882},{},[7961],{"type":1012},"The verdict",{"data":7964,"content":7965,"nodeType":883},{},[7966],{"data":7967,"marks":7968,"value":7969,"nodeType":882},{},[],"Browser security is a real and growing priority — according to Omdia Research, it is now a top-five priority for 88% of security leaders and the top priority for 26% of them. 85% expect their browser security spending to increase over the next 12–24 months. The question isn't whether to invest. It's what to invest in.",{"data":7971,"content":7972,"nodeType":883},{},[7973],{"data":7974,"marks":7975,"value":7976,"nodeType":882},{},[],"The browser is where your users work, where attackers target them, and where the identity attacks causing the majority of enterprise breaches play out. But not all browser security investments address the same problem.",{"data":7978,"content":7981,"nodeType":963},{"target":7979},{"sys":7980},{"id":4417,"type":960,"linkType":961},[],{"data":7983,"content":7984,"nodeType":883},{},[7985],{"data":7986,"marks":7987,"value":7988,"nodeType":882},{},[],"Solutions like Seraphic are built to defend against a browser being exploited by an attacker trying to break out of the sandbox — an attack that represents a historic low as a share of enterprise incidents, and one that Google's own hardening and rapid patching increasingly mitigates automatically. SquareX is built around malware sandboxing — a legitimate but declining share of the initial access landscape, and a capability Zscaler's existing customers already partially have. LayerX focuses on internal governance rather than external threats.",{"data":7990,"content":7991,"nodeType":883},{},[7992],{"data":7993,"marks":7994,"value":7995,"nodeType":882},{},[],"Push Security is built to defend against the attacks that are behind the major breaches hitting the headlines: identity theft, credential abuse, session hijacking, and the full identity attack kill chain that plays out inside the browser every time an attacker logs in as your user. Every major threat intelligence report points to these as the primary breach vectors. The economics of attack choice guarantee they'll remain so.",{"data":7997,"content":7998,"nodeType":883},{},[7999],{"data":8000,"marks":8001,"value":8002,"nodeType":882},{},[],"The security team that deploys Push gets the greatest coverage of the highest-impact threats, on managed and unmanaged devices, with the lightest operational footprint. That is the browser security investment that moves the needle on real organizational risk — not the browser security investment that defends the software nobody's actually attacking.",{"data":8004,"content":8008,"nodeType":963},{"target":8005},{"sys":8006},{"id":8007,"type":960,"linkType":961},"3a2sEWgWKZulGLCFfODwk0",[],{"data":8010,"content":8011,"nodeType":883},{},[8012],{"data":8013,"marks":8014,"value":21,"nodeType":882},{},[],"How to avoid the browser security buyer's trap","Securing the browser vs. securing the organization via the browser — what's the difference?","2026-05-13T00:00:00.000Z","how-to-avoid-the-browser-security-buyers-trap",{"items":8020},[8021,8023],{"sys":8022,"name":298},{"id":7235},{"sys":8024,"name":7239},{"id":7238},{"items":8026},[8027],{"fullName":3964,"firstName":3965,"jobTitle":868,"profilePicture":8028},{"url":3969},"the-top-10-browser-security-solutions-in-2026","blog\u002Fthe-top-10-browser-security-solutions-in-2026",{"json":8032},{"data":8033,"content":8034,"nodeType":1294},{},[8035],{"data":8036,"content":8037,"nodeType":883},{},[8038],{"data":8039,"marks":8040,"value":8041,"nodeType":882},{},[],"Your guide to browser security vendors in 2026. Understand the different approaches to browser security and the vendors that are leading the respective categories, and how to know which one meets your requirements.","Browser security means a lot of different things depending on who's talking. Here's your guide to the browser security market from a vendor perspective in 2026.",{"id":8044,"publishedAt":8045},"ThcZepauVfA5fKossdkbm","2026-08-26T11:59:28.533Z",{"items":8047},[8048,8050],{"sys":8049,"name":298},{"id":7235},{"sys":8051,"name":343},{"id":2304},{"items":8053},[8054,8056,8058,8060],{"sys":8055,"name":388,"slug":389,"tier":45},{"id":385},{"sys":8057,"name":289,"slug":290,"tier":45},{"id":286},{"sys":8059,"name":280,"slug":281,"tier":31},{"id":277},{"sys":8061,"name":298,"slug":299,"tier":31},{"id":295},"-Hg4gMALdKpPx8YlEIISzDWLW6601qgSiDLjq3smbXM",{"id":8064,"title":8065,"authorsCollection":8066,"content":8071,"extension":228,"faqItemsCollection":9407,"faqTitle":59,"featured":6,"hashTags":59,"meta":9409,"metaTitle":9410,"ogImage":59,"postType":1360,"publishedDate":3113,"relatedBlogPostsCollection":9411,"slug":11745,"stem":11746,"subtitle":59,"summary":11747,"synopsis":11758,"sys":11759,"tagsCollection":11762,"topicsCollection":11768,"__hash__":11802},"blog\u002Fblog\u002Fmaking-the-business-case-for-a-browser-security-solution.json","How to make the business case for a browser security solution",{"items":8067},[8068],{"fullName":3964,"firstName":3965,"jobTitle":868,"socialLinks":8069,"profilePicture":8070},[3967],{"url":3969},{"json":8072,"links":9266},{"data":8073,"content":8074,"nodeType":1294},{},[8075,8092,8099,8106,8113,8120,8126,8129,8137,8144,8151,8170,8189,8196,8203,8210,8252,8259,8327,8339,8342,8350,8357,8363,8370,8377,8396,8403,8432,8465,8472,8478,8485,8492,8499,8590,8597,8604,8610,8617,8624,8648,8667,8690,8709,8728,8735,8742,8748,8755,8762,8793,8812,8818,8825,8844,8851,8858,8903,8910,8913,8921,8928,8935,8953,8960,9000,9018,9021,9029,9036,9170,9178,9197,9204,9211,9214,9222,9229,9236,9239,9245,9251],{"data":8076,"content":8077,"nodeType":883},{},[8078,8081,8088],{"data":8079,"marks":8080,"value":21,"nodeType":882},{},[],{"data":8082,"content":8083,"nodeType":929},{"uri":6589},[8084],{"data":8085,"marks":8086,"value":4002,"nodeType":882},{},[8087],{"type":927},{"data":8089,"marks":8090,"value":8091,"nodeType":882},{},[]," found that 86% of organizations have already increased browser security spending in response to emerging threats, and 85% expect to spend more over the next 12–24 months. ",{"data":8093,"content":8094,"nodeType":883},{},[8095],{"data":8096,"marks":8097,"value":8098,"nodeType":882},{},[],"But finding budget for browser security solutions can be harder than it is for other security tools. Both Gartner and Omdia independently confirm that browser security is predominantly additive; Gartner states explicitly that secure enterprise browsers augment rather than replace existing security controls, and Omdia found that 80% of organizations expect to deploy browser security alongside their current stack.",{"data":8100,"content":8101,"nodeType":883},{},[8102],{"data":8103,"marks":8104,"value":8105,"nodeType":882},{},[],"In practice, that means there's typically no legacy line item to redirect or renewal to swap out. Instead, security leaders are left needing to build a business case from scratch, creating more work on top of an already demanding role. Having a proven framework that other security leaders are already using successfully makes that process significantly faster.",{"data":8107,"content":8108,"nodeType":883},{},[8109],{"data":8110,"marks":8111,"value":8112,"nodeType":882},{},[],"Push helps security leaders build these business cases every day and we've seen firsthand what works and where the budget comes from. ",{"data":8114,"content":8115,"nodeType":883},{},[8116],{"data":8117,"marks":8118,"value":8119,"nodeType":882},{},[],"This article distills those patterns into a practical framework you can use to build your own investment case, as well as provides real-world examples of how Push's customers have found budget to make their own investments in browser security tooling:",{"data":8121,"content":8125,"nodeType":963},{"target":8122},{"sys":8123},{"id":8124,"type":960,"linkType":961},"3qR5t9Y5wgRfzGqcRNXfNa",[],{"data":8127,"content":8128,"nodeType":967},{},[],{"data":8130,"content":8131,"nodeType":975},{},[8132],{"data":8133,"marks":8134,"value":8136,"nodeType":882},{},[8135],{"type":1012},"The strategic imperatives that resonate with non-security executives",{"data":8138,"content":8139,"nodeType":883},{},[8140],{"data":8141,"marks":8142,"value":8143,"nodeType":882},{},[],"Two distinct strategic initiatives consistently prove to be effective in unlocking browser security budget. They come from different directions; one is driven by the board down to security, the other is driven by security up to the board. But both lead to the same investment and can be used in conjunction with one another.",{"data":8145,"content":8146,"nodeType":2050},{},[8147],{"data":8148,"marks":8149,"value":8150,"nodeType":882},{},[],"Option A | AI visibility and control: the mandate security teams are responding to",{"data":8152,"content":8153,"nodeType":883},{},[8154,8158,8166],{"data":8155,"marks":8156,"value":8157,"nodeType":882},{},[],"AI adoption isn't a security initiative; it's a business strategy decision that executives and boards are driving. They know the organization needs to harness AI to remain competitive, and most have already committed to accelerating its use. But they also know that ",{"data":8159,"content":8161,"nodeType":929},{"uri":8160},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fwhat-push-data-reveals-about-the-state-of-shadow-ai\u002F",[8162],{"data":8163,"marks":8164,"value":8165,"nodeType":882},{},[],"adoption without visibility creates risks they can't quantify or manage",{"data":8167,"marks":8168,"value":8169,"nodeType":882},{},[],", and they expect security to have the visibility and controls to close that gap.",{"data":8171,"content":8172,"nodeType":883},{},[8173,8177,8185],{"data":8174,"marks":8175,"value":8176,"nodeType":882},{},[],"The browser is the most practical place for security teams to get that visibility and control over AI usage. All AI tool usage — whether that's web apps, extensions, OAuth consent flows, data uploads — traverses the browser. A browser security platform like Push can ",{"data":8178,"content":8180,"nodeType":929},{"uri":8179},"https:\u002F\u002Fpushsecurity.com\u002Fsolution\u002Fachieve-security-outcomes\u002Fsecure-ai",[8181],{"data":8182,"marks":8183,"value":8184,"nodeType":882},{},[],"discover which AI tools employees are actually using",{"data":8186,"marks":8187,"value":8188,"nodeType":882},{},[],", monitor how they're being used, track which AI services have been granted access to corporate systems, and enforce policy in real time.",{"data":8190,"content":8191,"nodeType":883},{},[8192],{"data":8193,"marks":8194,"value":8195,"nodeType":882},{},[],"What makes this particularly effective in a budget conversation is that security teams don’t need to explain or sell a new security risk or initiative, instead they're responding to one their executive team has already identified. When security can demonstrate a concrete plan to deliver AI visibility and control, the funding conversation is significantly shorter. The investment addresses the executive mandate while simultaneously providing additional capabilities for the security team like threat protection, identity and shadow IT security, and investigation support.",{"data":8197,"content":8198,"nodeType":2050},{},[8199],{"data":8200,"marks":8201,"value":8202,"nodeType":882},{},[],"Option B | Modern breaches that originate in the browser: the gap the existing stack wasn't designed to cover",{"data":8204,"content":8205,"nodeType":883},{},[8206],{"data":8207,"marks":8208,"value":8209,"nodeType":882},{},[],"The second strategic imperative requires more educating on the part of the security leader.",{"data":8211,"content":8212,"nodeType":883},{},[8213,8217,8225,8229,8237,8241,8248],{"data":8214,"marks":8215,"value":8216,"nodeType":882},{},[],"The highest-profile breaches in recent years — MGM, Caesars, Ticketmaster, M&S, Jaguar Land Rover — were all carried out by threat groups like ",{"data":8218,"content":8220,"nodeType":929},{"uri":8219},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fscattered-lapsus-hunters\u002F",[8221],{"data":8222,"marks":8223,"value":8224,"nodeType":882},{},[],"Scattered Spider",{"data":8226,"marks":8227,"value":8228,"nodeType":882},{},[]," using cloud-native, ",{"data":8230,"content":8232,"nodeType":929},{"uri":8231},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fintroducing-the-browser-and-identity-attacks-matrix\u002F",[8233],{"data":8234,"marks":8235,"value":8236,"nodeType":882},{},[],"identity-based attack techniques",{"data":8238,"marks":8239,"value":8240,"nodeType":882},{},[],". They didn't compromise endpoints or exploit zero-day vulnerabilities. Instead, they compromised employees' cloud app accounts by targeting them with techniques that ",{"data":8242,"content":8243,"nodeType":929},{"uri":3358},[8244],{"data":8245,"marks":8246,"value":8247,"nodeType":882},{},[],"play out inside browser sessions",{"data":8249,"marks":8250,"value":8251,"nodeType":882},{},[]," where existing endpoint, network, and email controls have no visibility.",{"data":8253,"content":8254,"nodeType":883},{},[8255],{"data":8256,"marks":8257,"value":8258,"nodeType":882},{},[],"That doesn't mean your existing security investments are failing. Endpoint, network, and email controls have become effective enough that threat groups are now actively avoiding them by rerouting their attacks via the browser.",{"data":8260,"content":8261,"nodeType":1454},{},[8262,8283,8305],{"data":8263,"content":8264,"nodeType":1419},{},[8265],{"data":8266,"content":8267,"nodeType":883},{},[8268,8271,8279],{"data":8269,"marks":8270,"value":21,"nodeType":882},{},[],{"data":8272,"content":8273,"nodeType":929},{"uri":3541},[8274],{"data":8275,"marks":8276,"value":8278,"nodeType":882},{},[8277],{"type":927},"CrowdStrike's 2026 data",{"data":8280,"marks":8281,"value":8282,"nodeType":882},{},[]," shows 82% of attack detections are now malware-free. A new capability is needed to address this new playbook, and browser security closes that gap by detecting attacker behavior inside the session, where these attacks actually execute.",{"data":8284,"content":8285,"nodeType":1419},{},[8286],{"data":8287,"content":8288,"nodeType":883},{},[8289,8292,8301],{"data":8290,"marks":8291,"value":21,"nodeType":882},{},[],{"data":8293,"content":8295,"nodeType":929},{"uri":8294},"https:\u002F\u002Funit42.paloaltonetworks.com\u002F2025-unit-42-global-incident-response-report-social-engineering-edition\u002F",[8296],{"data":8297,"marks":8298,"value":8300,"nodeType":882},{},[8299],{"type":927},"Unit 42",{"data":8302,"marks":8303,"value":8304,"nodeType":882},{},[]," found that identity weaknesses played a material role in almost 90% of their investigations, and across more than 750 incident response engagements, 48% involved browser-based activity.",{"data":8306,"content":8307,"nodeType":1419},{},[8308],{"data":8309,"content":8310,"nodeType":883},{},[8311,8314,8323],{"data":8312,"marks":8313,"value":21,"nodeType":882},{},[],{"data":8315,"content":8317,"nodeType":929},{"uri":8316},"https:\u002F\u002Fservices.google.com\u002Ffh\u002Ffiles\u002Fmisc\u002Fm-trends-2025-en.pdf",[8318],{"data":8319,"marks":8320,"value":8322,"nodeType":882},{},[8321],{"type":927},"Mandiant's data",{"data":8324,"marks":8325,"value":8326,"nodeType":882},{},[]," tells a similar story: threat actors exploited identity issues to gain initial access in 83% of incidents involving cloud and SaaS environments.",{"data":8328,"content":8329,"nodeType":883},{},[8330,8335],{"data":8331,"marks":8332,"value":8334,"nodeType":882},{},[8333],{"type":1012},"Identity-based attacks executed via the browser are now the dominant attack pattern.",{"data":8336,"marks":8337,"value":8338,"nodeType":882},{},[]," That framing works in a budget conversation because it identifies a gap rather than asking to improve something that's already covered by an existing solution. It's also reinforced by the fact that the breaches and groups behind them like Scattered Spider were all reported on by the mainstream media, meaning non-security stakeholders are likely to already be somewhat aware of the risks and potential implications of them being realized.",{"data":8340,"content":8341,"nodeType":967},{},[],{"data":8343,"content":8344,"nodeType":975},{},[8345],{"data":8346,"marks":8347,"value":8349,"nodeType":882},{},[8348],{"type":1012},"The economic case: five value drivers",{"data":8351,"content":8352,"nodeType":883},{},[8353],{"data":8354,"marks":8355,"value":8356,"nodeType":882},{},[],"Those strategic imperatives establish why something needs to be done, but they don't quantify the cost of inaction or demonstrate how the investment pays for itself. A CFO wants to see where the money comes from, what existing spend it offsets, and what measurable return it delivers. The economic investment case draws on five distinct value drivers, each grounded in capabilities specific to operating inside the browser session.",{"data":8358,"content":8362,"nodeType":963},{"target":8359},{"sys":8360},{"id":8361,"type":960,"linkType":961},"2W1G5GZWXLbo2hi6bTxAVs",[],{"data":8364,"content":8365,"nodeType":2050},{},[8366],{"data":8367,"marks":8368,"value":8369,"nodeType":882},{},[],"1. Avoided breach costs",{"data":8371,"content":8372,"nodeType":883},{},[8373],{"data":8374,"marks":8375,"value":8376,"nodeType":882},{},[],"This is the largest single value driver, but it's also the hardest to measure because the return is defined by the absence of an event rather than the presence of a saving. That said, the methodology is well-established in risk management, and CFOs already accept this logic for insurance and business continuity investments.",{"data":8378,"content":8379,"nodeType":883},{},[8380,8384,8392],{"data":8381,"marks":8382,"value":8383,"nodeType":882},{},[],"The detection gap described above has a direct financial consequence: every attack that slips through undetected is a potential breach incurring significant direct and indirect costs. Push helps you avoid these costs by detecting ",{"data":8385,"content":8387,"nodeType":929},{"uri":8386},"https:\u002F\u002Fpushsecurity.com\u002Fsolution\u002Fachieve-security-outcomes\u002Fstop-account-takeover",[8388],{"data":8389,"marks":8390,"value":8391,"nodeType":882},{},[],"browser-native attack TTPs",{"data":8393,"marks":8394,"value":8395,"nodeType":882},{},[]," and blocking them in real-time to prevent breaches at the earliest opportunity.",{"data":8397,"content":8398,"nodeType":883},{},[8399],{"data":8400,"marks":8401,"value":8402,"nodeType":882},{},[],"Even though the breach itself is unrealized, there are tangible leading indicators of success: reduced MTTD\u002FMTTR, and fewer attacks progressing to account takeover or endpoint compromise; the stages at which incidents become more expensive to clean up.",{"data":8404,"content":8405,"nodeType":883},{},[8406,8410,8417,8420,8428],{"data":8407,"marks":8408,"value":8409,"nodeType":882},{},[],"Quantifying the savings generated by avoiding breaches requires an ",{"data":8411,"content":8412,"nodeType":929},{"uri":7895},[8413],{"data":8414,"marks":8415,"value":8416,"nodeType":882},{},[],"estimation of your organization's breach probability and likely cost",{"data":8418,"marks":8419,"value":1438,"nodeType":882},{},[],{"data":8421,"content":8423,"nodeType":929},{"uri":8422},"https:\u002F\u002Fwww.ibm.com\u002Freports\u002Fdata-breach",[8424],{"data":8425,"marks":8426,"value":8427,"nodeType":882},{},[]," IBM's cost of a data breach report",{"data":8429,"marks":8430,"value":8431,"nodeType":882},{},[]," provides industry-specific benchmarks, though a more grounded alternative is to look at the disclosed costs of the breaches mentioned above and assess your exposure to the same techniques:",{"data":8433,"content":8434,"nodeType":1454},{},[8435,8445,8455],{"data":8436,"content":8437,"nodeType":1419},{},[8438],{"data":8439,"content":8440,"nodeType":883},{},[8441],{"data":8442,"marks":8443,"value":8444,"nodeType":882},{},[],"MGM reported over $100M in direct impact plus a $45M class-action settlement.",{"data":8446,"content":8447,"nodeType":1419},{},[8448],{"data":8449,"content":8450,"nodeType":883},{},[8451],{"data":8452,"marks":8453,"value":8454,"nodeType":882},{},[],"M&S lost £300M in profits with almost £1B wiped off its market valuation.",{"data":8456,"content":8457,"nodeType":1419},{},[8458],{"data":8459,"content":8460,"nodeType":883},{},[8461],{"data":8462,"marks":8463,"value":8464,"nodeType":882},{},[],"The JLR breach was severe enough for the UK government to underwrite a $1.5B loan to mitigate supply chain damage.",{"data":8466,"content":8467,"nodeType":883},{},[8468],{"data":8469,"marks":8470,"value":8471,"nodeType":882},{},[],"Your own incident data, red team results, or phishing simulation outcomes will increase accuracy further.",{"data":8473,"content":8477,"nodeType":963},{"target":8474},{"sys":8475},{"id":8476,"type":960,"linkType":961},"3SgrdUcQnQsnNLIR9UgBB",[],{"data":8479,"content":8480,"nodeType":2050},{},[8481],{"data":8482,"marks":8483,"value":8484,"nodeType":882},{},[],"2. Accelerated and safe AI adoption",{"data":8486,"content":8487,"nodeType":883},{},[8488],{"data":8489,"marks":8490,"value":8491,"nodeType":882},{},[],"Without effective AI visibility and control tooling, your security team becomes either the bottleneck for AI adoption or allows the risks to go unchecked. Every month that adoption is restricted or ungoverned has a productivity cost that compounds.",{"data":8493,"content":8494,"nodeType":883},{},[8495],{"data":8496,"marks":8497,"value":8498,"nodeType":882},{},[],"There's been plenty of research into the productivity impact of AI:",{"data":8500,"content":8501,"nodeType":1454},{},[8502,8524,8546,8568],{"data":8503,"content":8504,"nodeType":1419},{},[8505],{"data":8506,"content":8507,"nodeType":883},{},[8508,8511,8520],{"data":8509,"marks":8510,"value":21,"nodeType":882},{},[],{"data":8512,"content":8514,"nodeType":929},{"uri":8513},"https:\u002F\u002Fwww.nber.org\u002Fsystem\u002Ffiles\u002Fworking_papers\u002Fw31161\u002Fw31161.pdf",[8515],{"data":8516,"marks":8517,"value":8519,"nodeType":882},{},[8518],{"type":927},"Stanford and MIT research",{"data":8521,"marks":8522,"value":8523,"nodeType":882},{},[]," found that workers with access to a generative AI assistant were 14% more productive on average, with novice workers seeing a 34% improvement.",{"data":8525,"content":8526,"nodeType":1419},{},[8527],{"data":8528,"content":8529,"nodeType":883},{},[8530,8533,8542],{"data":8531,"marks":8532,"value":21,"nodeType":882},{},[],{"data":8534,"content":8536,"nodeType":929},{"uri":8535},"https:\u002F\u002Fwww.accenture.com\u002Fus-en\u002Finsights\u002Fstrategy\u002Fproductivity-payoff",[8537],{"data":8538,"marks":8539,"value":8541,"nodeType":882},{},[8540],{"type":927},"Accenture's research",{"data":8543,"marks":8544,"value":8545,"nodeType":882},{},[]," estimates approximately $7,800 per employee per year in productivity value from generative AI for knowledge workers.",{"data":8547,"content":8548,"nodeType":1419},{},[8549],{"data":8550,"content":8551,"nodeType":883},{},[8552,8555,8564],{"data":8553,"marks":8554,"value":21,"nodeType":882},{},[],{"data":8556,"content":8558,"nodeType":929},{"uri":8557},"https:\u002F\u002Fwww.stlouisfed.org\u002Fon-the-economy\u002F2025\u002Ffeb\u002Fimpact-generative-ai-work-productivity",[8559],{"data":8560,"marks":8561,"value":8563,"nodeType":882},{},[8562],{"type":927},"The Federal Reserve",{"data":8565,"marks":8566,"value":8567,"nodeType":882},{},[]," independently quantified it at 5.4% of work hours saved, roughly one full working day reclaimed per month.",{"data":8569,"content":8570,"nodeType":1419},{},[8571],{"data":8572,"content":8573,"nodeType":883},{},[8574,8577,8586],{"data":8575,"marks":8576,"value":21,"nodeType":882},{},[],{"data":8578,"content":8580,"nodeType":929},{"uri":8579},"https:\u002F\u002Fwww.mckinsey.com\u002Fcapabilities\u002Fquantumblack\u002Four-insights\u002Fthe-state-of-ai",[8581],{"data":8582,"marks":8583,"value":8585,"nodeType":882},{},[8584],{"type":927},"McKinsey's 2025 data",{"data":8587,"marks":8588,"value":8589,"nodeType":882},{},[]," shows organizations leading on AI adoption report 5.8x average ROI within 14 months, and they outperform laggards in both profitability and revenue growth.",{"data":8591,"content":8592,"nodeType":883},{},[8593],{"data":8594,"marks":8595,"value":8596,"nodeType":882},{},[],"A browser security platform like Push removes the governance blocker. When you can see which AI tools employees are using, what data they're sharing, and what permissions they've granted, and enforce policy in real time, the answer to \"can our people use this?\" shifts from \"not yet, we need to assess the risk\" to \"yes, with our sensible guardrails.\"",{"data":8598,"content":8599,"nodeType":883},{},[8600],{"data":8601,"marks":8602,"value":8603,"nodeType":882},{},[],"Push delivers this by discovering every AI web app, browser, browser extension, and OAuth integration in use. It monitors data sharing through file uploads and clipboard activity, tracks OAuth consent flows where AI services request access to corporate tenants, and enforces policy at the point of action. This allows your team to very quickly get a handle on AI usage, mitigate risks and guide the business on how to best drive safe adoption.",{"data":8605,"content":8609,"nodeType":963},{"target":8606},{"sys":8607},{"id":8608,"type":960,"linkType":961},"6i7Z6jwFaztuoUCynXfrVH",[],{"data":8611,"content":8612,"nodeType":2050},{},[8613],{"data":8614,"marks":8615,"value":8616,"nodeType":882},{},[],"3. Greater return from existing security investments",{"data":8618,"content":8619,"nodeType":883},{},[8620],{"data":8621,"marks":8622,"value":8623,"nodeType":882},{},[],"Push generates direct labor savings in two ways that other tools can't replicate.",{"data":8625,"content":8626,"nodeType":883},{},[8627,8632,8636,8644],{"data":8628,"marks":8629,"value":8631,"nodeType":882},{},[8630],{"type":1012},"First, identity hygiene remediation at scale.",{"data":8633,"marks":8634,"value":8635,"nodeType":882},{},[]," Push's customer data shows that for every 1,000 employees, an organization will typically have just over ",{"data":8637,"content":8639,"nodeType":929},{"uri":8638},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fhow-many-vulnerable-identities-do-you-have\u002F",[8640],{"data":8641,"marks":8642,"value":8643,"nodeType":882},{},[],"2,500 identity security vulnerabilities",{"data":8645,"marks":8646,"value":8647,"nodeType":882},{},[]," (missing MFA or weak, breached, reused passwords, etc).",{"data":8649,"content":8650,"nodeType":883},{},[8651,8655,8663],{"data":8652,"marks":8653,"value":8654,"nodeType":882},{},[],"Without Push, you could conservatively estimate that each vulnerability takes 5–10 minutes to resolve manually (inclusive of project management and reporting time) which translates to between 26 and 52 FTE days per thousand employees. ",{"data":8656,"content":8658,"nodeType":929},{"uri":8657},"https:\u002F\u002Fpushsecurity.com\u002Fsolution\u002Fachieve-security-outcomes\u002Fharden-unmanaged-identities",[8659],{"data":8660,"marks":8661,"value":8662,"nodeType":882},{},[],"Push automates this through in-browser guardrails",{"data":8664,"marks":8665,"value":8666,"nodeType":882},{},[]," that prompt users to fix issues at the point of login. That's thousands of identity vulnerabilities resolved without a single ticket being filed, and weeks of analyst time recovered annually at fully burdened rates.",{"data":8668,"content":8669,"nodeType":883},{},[8670,8675,8679,8687],{"data":8671,"marks":8672,"value":8674,"nodeType":882},{},[8673],{"type":1012},"Second, investigation efficiency.",{"data":8676,"marks":8677,"value":8678,"nodeType":882},{},[]," Push detects attacks at the earliest and safest opportunity, as the attacker is attempting to gain initial access via the browser. The telemetry Push provides analysts with ",{"data":8680,"content":8682,"nodeType":929},{"uri":8681},"https:\u002F\u002Fpushsecurity.com\u002Fsolution\u002Fachieve-security-outcomes\u002Finvestigate-browser-related-incidents",[8683],{"data":8684,"marks":8685,"value":8686,"nodeType":882},{},[],"accelerates their investigations across both external and insider threats",{"data":8688,"marks":8689,"value":1438,"nodeType":882},{},[],{"data":8691,"content":8692,"nodeType":883},{},[8693,8697,8705],{"data":8694,"marks":8695,"value":8696,"nodeType":882},{},[],"Here’s one example of that in action: Push eliminates ",{"data":8698,"content":8700,"nodeType":929},{"uri":8699},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fverified-stolen-credential-detection\u002F",[8701],{"data":8702,"marks":8703,"value":8704,"nodeType":882},{},[],"over 99% of compromised credential false positives",{"data":8706,"marks":8707,"value":8708,"nodeType":882},{},[]," in common TI feeds by only surfacing credentials actively being used and observed in the browser. Much like the first direct labour saving, Push saves your team weeks of effort confirming false positives and investigating complex account compromise incidents. It also reduces the likelihood of an incident progressing to the stage where a (costly) external incident response provider is needed. ",{"data":8710,"content":8711,"nodeType":883},{},[8712,8716,8724],{"data":8713,"marks":8714,"value":8715,"nodeType":882},{},[],"By automatically remediating identity security issues at scale, and accelerating investigations, Push eliminates much of the work that analysts typically find tedious and frustrating: manually chasing password resets, triaging false positives, ",{"data":8717,"content":8719,"nodeType":929},{"uri":8718},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Ffixing-secops-alert-fatigue-with-browser-telemetry\u002F",[8720],{"data":8721,"marks":8722,"value":8723,"nodeType":882},{},[],"trawling through web proxy logs",{"data":8725,"marks":8726,"value":8727,"nodeType":882},{},[],". Removing that work means they can spend more time on the interesting, high-value aspects of their roles, which directly improves morale and retention.",{"data":8729,"content":8730,"nodeType":883},{},[8731],{"data":8732,"marks":8733,"value":8734,"nodeType":882},{},[],"In a market where replacing a fully ramped security analyst costs 80–150% of their annual salary and the new hire takes months to reach the same productivity, reduced attrition generates its own measurable saving in avoided recruitment, training, and lost productivity during the ramp-up period.",{"data":8736,"content":8737,"nodeType":883},{},[8738],{"data":8739,"marks":8740,"value":8741,"nodeType":882},{},[],"In addition to direct labor savings, Push improves the return on every other security investment in your stack. Browser-layer telemetry feeds into SIEM and SOAR platforms, enriching correlation rules and enabling custom detections that weren't previously possible, a multiplier on the value you're already getting from your existing security investments.",{"data":8743,"content":8747,"nodeType":963},{"target":8744},{"sys":8745},{"id":8746,"type":960,"linkType":961},"7EwWz1orX6QQtm5MHnaXDQ",[],{"data":8749,"content":8750,"nodeType":2050},{},[8751],{"data":8752,"marks":8753,"value":8754,"nodeType":882},{},[],"4. Reduced compliance and audit exposure",{"data":8756,"content":8757,"nodeType":883},{},[8758],{"data":8759,"marks":8760,"value":8761,"nodeType":882},{},[],"Every major security compliance framework — SOC 2, ISO 27001, HIPAA, PCI DSS, NIST, GDPR — requires MFA on accounts, strong and unique passwords, and visibility into which third-party applications are being entrusted with corporate data. These are foundational requirements and they apply across every application employees use, not just the ones IT has provisioned. Self-adopted Shadow IT and unmanaged identities create compliance gaps against these requirements that most organizations don't know they have until an auditor finds them.",{"data":8763,"content":8764,"nodeType":883},{},[8765,8768,8777,8781,8789],{"data":8766,"marks":8767,"value":21,"nodeType":882},{},[],{"data":8769,"content":8771,"nodeType":929},{"uri":8770},"https:\u002F\u002Fpushsecurity.com\u002Fresources\u002Fmfa-regulation-compliance",[8772],{"data":8773,"marks":8774,"value":8776,"nodeType":882},{},[8775],{"type":927},"The consequences of gaps in these controls are increasingly financial.",{"data":8778,"marks":8779,"value":8780,"nodeType":882},{},[]," The City of Hamilton had its $18.3M cyber insurance claim denied after a ransomware attack because MFA wasn't fully implemented. The insurer ruled that incomplete MFA coverage voided the policy. ",{"data":8782,"content":8784,"nodeType":929},{"uri":8783},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fwhat-the-expansion-of-nydfs-nycrr-part-500-means-for-mfa-compliance\u002F",[8785],{"data":8786,"marks":8787,"value":8788,"nodeType":882},{},[],"NYDFS has levied $14 million in fines",{"data":8790,"marks":8791,"value":8792,"nodeType":882},{},[]," from companies with inadequate MFA. These aren't hypothetical risks, and they apply to requirements that Push can help you meet continuously rather than scrambling to find evidence during an audit or after an incident.",{"data":8794,"content":8795,"nodeType":883},{},[8796,8800,8808],{"data":8797,"marks":8798,"value":8799,"nodeType":882},{},[],"Push addresses these compliance requirements directly. It ",{"data":8801,"content":8803,"nodeType":929},{"uri":8802},"https:\u002F\u002Fpushsecurity.com\u002Fsolution\u002Fachieve-security-outcomes\u002Fsecure-shadow-saas",[8804],{"data":8805,"marks":8806,"value":8807,"nodeType":882},{},[],"discovers every application employees actually use",{"data":8809,"marks":8810,"value":8811,"nodeType":882},{},[]," — directly from the login event in the browser, not from network traffic patterns. It also observes the authentication method, password strength, and MFA status for each account. The inventory provided by Push replaces weeks of manual spreadsheet work during audit preparation and gives your GRC team continuous evidence rather than a point-in-time snapshot assembled under pressure.",{"data":8813,"content":8817,"nodeType":963},{"target":8814},{"sys":8815},{"id":8816,"type":960,"linkType":961},"36lm2TMvlpEPrFfM8KEUqB",[],{"data":8819,"content":8820,"nodeType":2050},{},[8821],{"data":8822,"marks":8823,"value":8824,"nodeType":882},{},[],"5. Consolidated capability and reallocated spend",{"data":8826,"content":8827,"nodeType":883},{},[8828,8832,8840],{"data":8829,"marks":8830,"value":8831,"nodeType":882},{},[],"Push delivers against a ",{"data":8833,"content":8835,"nodeType":929},{"uri":8834},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fthe-top-10-security-problems-you-can-solve-in-the-browser-ranked-by-value\u002F",[8836],{"data":8837,"marks":8838,"value":8839,"nodeType":882},{},[],"wide range of use cases",{"data":8841,"marks":8842,"value":8843,"nodeType":882},{},[]," — threat detection, AI governance, identity security, investigation support — that would otherwise require separate point solutions to address. That breadth of coverage from a single platform and deployment creates natural opportunities to consolidate spend.",{"data":8845,"content":8846,"nodeType":883},{},[8847],{"data":8848,"marks":8849,"value":8850,"nodeType":882},{},[],"AI governance is the most immediate example. Nearly every enterprise is evaluating standalone AI monitoring tools right now, and the price tags are significant. If your browser security platform already delivers the AI visibility and control capabilities like Push's described above — app discovery, data sharing monitoring, OAuth consent tracking, real-time policy enforcement — the case for a separate AI governance purchase weakens considerably. Paying separately for a tool that only does AI governance, when your browser security platform delivers it alongside detection, identity security, and investigation capability, is a hard spend to justify.",{"data":8852,"content":8853,"nodeType":883},{},[8854],{"data":8855,"marks":8856,"value":8857,"nodeType":882},{},[],"There's also a broader resource reallocation opportunity. Platforms like Push represent a new generation of security tooling that addresses the challenges posed by modern work and cyber attacks. The ROI they provide is high now and is likely to increase as the platform evolves alongside the threats and risks it addresses. Meanwhile, much of the legacy stack is moving in the opposite direction.",{"data":8859,"content":8860,"nodeType":1454},{},[8861,8883,8893],{"data":8862,"content":8863,"nodeType":1419},{},[8864],{"data":8865,"content":8866,"nodeType":883},{},[8867,8871,8879],{"data":8868,"marks":8869,"value":8870,"nodeType":882},{},[],"Network-centric tools like ",{"data":8872,"content":8874,"nodeType":929},{"uri":8873},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fpush-plus-network-security\u002F",[8875],{"data":8876,"marks":8877,"value":8878,"nodeType":882},{},[],"SWGs and CASBs are becoming increasingly legacy",{"data":8880,"marks":8881,"value":8882,"nodeType":882},{},[]," as more activity moves off the traditional network and into the browser.",{"data":8884,"content":8885,"nodeType":1419},{},[8886],{"data":8887,"content":8888,"nodeType":883},{},[8889],{"data":8890,"marks":8891,"value":8892,"nodeType":882},{},[],"RBI deployments are difficult to justify when a browser extension achieves better security outcomes without the user experience penalty.",{"data":8894,"content":8895,"nodeType":1419},{},[8896],{"data":8897,"content":8898,"nodeType":883},{},[8899],{"data":8900,"marks":8901,"value":8902,"nodeType":882},{},[],"Phishing simulation programs — whose ROI has long been questioned by practitioners — are harder to justify when attackers are using AI to craft lures and pages that are indistinguishable from the real thing for even the most trained employees. If your browser security platform is already blocking real phishing attempts and delivering contextual security guidance at the actual point of risk, the marginal value of a simulation exercise weeks later diminishes considerably.",{"data":8904,"content":8905,"nodeType":883},{},[8906],{"data":8907,"marks":8908,"value":8909,"nodeType":882},{},[],"As legacy tooling becomes less relevant and more commoditized, you should expect to spend less on it. What you save can then be reallocated towards capabilities like Push that address the current threat landscape rather than the previous one legacy tools were designed for.",{"data":8911,"content":8912,"nodeType":967},{},[],{"data":8914,"content":8915,"nodeType":975},{},[8916],{"data":8917,"marks":8918,"value":8920,"nodeType":882},{},[8919],{"type":1012},"Investment risk management",{"data":8922,"content":8923,"nodeType":883},{},[8924],{"data":8925,"marks":8926,"value":8927,"nodeType":882},{},[],"The final component of the business case is assessing the investment risk. Given that browser security solutions are typically a new capability, and therefore a new form of investment, there will naturally be questions about how safe an investment it is.",{"data":8929,"content":8930,"nodeType":883},{},[8931],{"data":8932,"marks":8933,"value":8934,"nodeType":882},{},[],"Browser security takes many forms and approaches, so this section speaks specifically to Push and why it represents a low-risk investment to make.",{"data":8936,"content":8937,"nodeType":883},{},[8938,8942,8949],{"data":8939,"marks":8940,"value":8941,"nodeType":882},{},[],"Push is simple to deploy. It installs as a browser extension via existing MDM tooling — it works on the browsers employees already use, with no migration to a new browser, no user retraining, and no change to workflows. ",{"data":8943,"content":8944,"nodeType":929},{"uri":4493},[8945],{"data":8946,"marks":8947,"value":8948,"nodeType":882},{},[],"Customers have rolled Push out to over 100,000 users in under an hour",{"data":8950,"marks":8951,"value":8952,"nodeType":882},{},[]," during normal office hours with zero downtime.",{"data":8954,"content":8955,"nodeType":883},{},[8956],{"data":8957,"marks":8958,"value":8959,"nodeType":882},{},[],"You start seeing findings and detections from day one, not after a months-long implementation project. That compresses time-to-value to a matter of hours, which directly de-risks the investment from a finance perspective. Push's high-fidelity telemetry results in a negligible false positive rate, minimizing the operational cost of running the platform. Push integrates into your existing security workflows and tools, like your SIEM, SOAR, and IdP, and doesn't require a dedicated team to manage, so you gain a new capability without taking on a new operational burden.",{"data":8961,"content":8962,"nodeType":883},{},[8963,8967,8973,8977,8985,8988,8996],{"data":8964,"marks":8965,"value":8966,"nodeType":882},{},[],"Push supports advanced security teams in highly targeted and regulated industries, with over 3 million browsers deployed worldwide. As one of the first browser security extensions, launched in 2022, Push has one of the longest track records in the space, and its research team regularly discovers novel attack techniques, including ",{"data":8968,"content":8969,"nodeType":929},{"uri":3582},[8970],{"data":8971,"marks":8972,"value":1989,"nodeType":882},{},[],{"data":8974,"marks":8975,"value":8976,"nodeType":882},{},[],",",{"data":8978,"content":8980,"nodeType":929},{"uri":8979},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fghost-logins-when-forgotten-identities-come-back-to-haunt-you\u002F",[8981],{"data":8982,"marks":8983,"value":8984,"nodeType":882},{},[]," ghost logins",{"data":8986,"marks":8987,"value":8976,"nodeType":882},{},[],{"data":8989,"content":8991,"nodeType":929},{"uri":8990},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fsamljacking-a-poisoned-tenant\u002F",[8992],{"data":8993,"marks":8994,"value":8995,"nodeType":882},{},[]," SAMLjacking",{"data":8997,"marks":8998,"value":8999,"nodeType":882},{},[],", and regularly publishes campaign analysis referenced across the security community.",{"data":9001,"content":9002,"nodeType":883},{},[9003,9007,9014],{"data":9004,"marks":9005,"value":9006,"nodeType":882},{},[],"Finally, Push actively hunts for new and novel threats across your estate using its research and ",{"data":9008,"content":9009,"nodeType":929},{"uri":2893},[9010],{"data":9011,"marks":9012,"value":9013,"nodeType":882},{},[],"agentic detection pipeline",{"data":9015,"marks":9016,"value":9017,"nodeType":882},{},[],", with no customer input required. That means you remain protected as the threat landscape evolves, and the capability continues to advance and deliver recurring value over the full contract period without additional effort from your team.",{"data":9019,"content":9020,"nodeType":967},{},[],{"data":9022,"content":9023,"nodeType":975},{},[9024],{"data":9025,"marks":9026,"value":9028,"nodeType":882},{},[9027],{"type":1012},"Where has the budget actually come from for Push’s customers?",{"data":9030,"content":9031,"nodeType":883},{},[9032],{"data":9033,"marks":9034,"value":9035,"nodeType":882},{},[],"Push's customers have funded their browser security investment through several well-established routes:",{"data":9037,"content":9038,"nodeType":1454},{},[9039,9060,9093,9133,9155],{"data":9040,"content":9041,"nodeType":1419},{},[9042],{"data":9043,"content":9044,"nodeType":883},{},[9045,9049,9056],{"data":9046,"marks":9047,"value":9048,"nodeType":882},{},[],"Many teams had funded projects to increase their ",{"data":9050,"content":9051,"nodeType":929},{"uri":8179},[9052],{"data":9053,"marks":9054,"value":9055,"nodeType":882},{},[],"visibility and control over AI use",{"data":9057,"marks":9058,"value":9059,"nodeType":882},{},[]," in their organizations. Push gave them the instrumentation they needed to address their needs while also allowing them to address other valuable security use cases.",{"data":9061,"content":9062,"nodeType":1419},{},[9063],{"data":9064,"content":9065,"nodeType":883},{},[9066,9070,9077,9081,9089],{"data":9067,"marks":9068,"value":9069,"nodeType":882},{},[],"Push is frequently purchased following a security incident such as an ",{"data":9071,"content":9072,"nodeType":929},{"uri":4707},[9073],{"data":9074,"marks":9075,"value":9076,"nodeType":882},{},[],"AitM phishing breach",{"data":9078,"marks":9079,"value":9080,"nodeType":882},{},[]," or a ",{"data":9082,"content":9083,"nodeType":929},{"uri":4718},[9084],{"data":9085,"marks":9086,"value":9088,"nodeType":882},{},[9087],{"type":927},"ClickFix breach",{"data":9090,"marks":9091,"value":9092,"nodeType":882},{},[]," that existing tools failed to detect and stop.",{"data":9094,"content":9095,"nodeType":1419},{},[9096],{"data":9097,"content":9098,"nodeType":883},{},[9099,9103,9110,9113,9119,9122,9129],{"data":9100,"marks":9101,"value":9102,"nodeType":882},{},[],"Another leverage point has been ",{"data":9104,"content":9105,"nodeType":929},{"uri":5130},[9106],{"data":9107,"marks":9108,"value":307,"nodeType":882},{},[9109],{"type":927},{"data":9111,"marks":9112,"value":1993,"nodeType":882},{},[],{"data":9114,"content":9115,"nodeType":929},{"uri":5118},[9116],{"data":9117,"marks":9118,"value":623,"nodeType":882},{},[],{"data":9120,"marks":9121,"value":2006,"nodeType":882},{},[],{"data":9123,"content":9124,"nodeType":929},{"uri":4312},[9125],{"data":9126,"marks":9127,"value":9128,"nodeType":882},{},[],"RBI",{"data":9130,"marks":9131,"value":9132,"nodeType":882},{},[]," renewals. The browser-native capabilities of a tool like Push let you either replace or reduce the scope — and cost — on those contracts without losing coverage.",{"data":9134,"content":9135,"nodeType":1419},{},[9136],{"data":9137,"content":9138,"nodeType":883},{},[9139,9143,9151],{"data":9140,"marks":9141,"value":9142,"nodeType":882},{},[],"A number of Push customers rolled out ",{"data":9144,"content":9146,"nodeType":929},{"uri":9145},"https:\u002F\u002Fpushsecurity.com\u002Fsolution\u002Fachieve-security-outcomes\u002Fsecure-chromebooks",[9147],{"data":9148,"marks":9149,"value":9150,"nodeType":882},{},[],"Chromebooks",{"data":9152,"marks":9153,"value":9154,"nodeType":882},{},[]," to parts of their workforce and used the savings that generated to pay for Push. These devices fell outside of their standard EDR coverage and they found that Push provided all the visibility and protection they needed for Chromebook users.",{"data":9156,"content":9157,"nodeType":1419},{},[9158],{"data":9159,"content":9160,"nodeType":883},{},[9161,9165],{"data":9162,"marks":9163,"value":9164,"nodeType":882},{},[],"But overall, most customers choose to build the net-new case using ROI projections alone. Push customers see direct savings that cover the cost of deploying Push and indirect savings that run into the millions of dollars. ",{"data":9166,"marks":9167,"value":9169,"nodeType":882},{},[9168],{"type":1012},"For every $1 invested, Push generates a return of $5 - $15 through a mixture of direct and indirect savings aligned to the five economic value drivers.",{"data":9171,"content":9172,"nodeType":2050},{},[9173],{"data":9174,"marks":9175,"value":9177,"nodeType":882},{},[9176],{"type":1012},"Strengthening your case with PoV data",{"data":9179,"content":9180,"nodeType":883},{},[9181,9185,9193],{"data":9182,"marks":9183,"value":9184,"nodeType":882},{},[],"One practical step that strengthens any business case significantly is to ",{"data":9186,"content":9188,"nodeType":929},{"uri":9187},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fhow-to-avoid-the-browser-security-buyers-trap\u002F",[9189],{"data":9190,"marks":9191,"value":9192,"nodeType":882},{},[],"run a proof of value",{"data":9194,"marks":9195,"value":9196,"nodeType":882},{},[],". A PoV deployment generates findings specific to your organization: real instances of employees being targeted in their browsers, the actual scale of your identity attack surface, and concrete shadow SaaS and AI usage data.",{"data":9198,"content":9199,"nodeType":883},{},[9200],{"data":9201,"marks":9202,"value":9203,"nodeType":882},{},[],"That evidence can be far more compelling to a CFO than generic industry benchmarks, and it hones the projected value from the framework using real-world data taken from your own environment. ",{"data":9205,"content":9206,"nodeType":883},{},[9207],{"data":9208,"marks":9209,"value":9210,"nodeType":882},{},[],"The drawback is that the kind of PoV that generates this type of evidence requires more time and effort to run. Security teams typically opt for this approach when they know they'll encounter stronger resistance to budget being made available and they'll really need to evidence the need in absolutely concrete terms.",{"data":9212,"content":9213,"nodeType":967},{},[],{"data":9215,"content":9216,"nodeType":975},{},[9217],{"data":9218,"marks":9219,"value":9221,"nodeType":882},{},[9220],{"type":1012},"Closing thoughts: “nothing worth having comes easy”",{"data":9223,"content":9224,"nodeType":883},{},[9225],{"data":9226,"marks":9227,"value":9228,"nodeType":882},{},[],"The budget conversation for browser security takes more work than it does for a like-for-like tool replacement — but the security leaders who've been through it consistently find that the economic case is stronger than they expected going in. ",{"data":9230,"content":9231,"nodeType":883},{},[9232],{"data":9233,"marks":9234,"value":9235,"nodeType":882},{},[],"Both strategic imperatives are grounded in data any CFO can verify independently, the financial impact is quantifiable across multiple dimensions, and the routes to funding are well-established across organizations that have already made this investment.",{"data":9237,"content":9238,"nodeType":967},{},[],{"data":9240,"content":9241,"nodeType":883},{},[9242],{"data":9243,"marks":9244,"value":2919,"nodeType":882},{},[],{"data":9246,"content":9247,"nodeType":883},{},[9248],{"data":9249,"marks":9250,"value":2926,"nodeType":882},{},[],{"data":9252,"content":9253,"nodeType":883},{},[9254,9257,9263],{"data":9255,"marks":9256,"value":4431,"nodeType":882},{},[],{"data":9258,"content":9259,"nodeType":929},{"uri":2935},[9260],{"data":9261,"marks":9262,"value":4438,"nodeType":882},{},[],{"data":9264,"marks":9265,"value":3897,"nodeType":882},{},[],{"entries":9267},{"hyperlink":9268,"inline":9269,"block":9270},[],[],[9271,9278,9304,9328,9355,9381],{"sys":9272,"__typename":1329,"title":9273,"caption":59,"layoutMode":59,"file":9274},{"id":8124},"business case framework",{"url":9275,"width":9276,"height":9277},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F1TIwUkTfu8uJkxpF3vS8jS\u002Fe93b6ddfa432874452812c2566b5e031\u002Fbusiness_case_framework_2x__4_.png",3200,2302,{"sys":9279,"__typename":1302,"content":9280,"name":9303,"title":59},{"id":8361},{"json":9281},{"nodeType":1294,"data":9282,"content":9283},{},[9284,9291],{"nodeType":883,"data":9285,"content":9286},{},[9287],{"nodeType":882,"value":9288,"marks":9289,"data":9290},"To illustrate the potential economic impact, each value driver below includes an estimate for a hypothetical 1,000-employee US technology company called ACME. The assumptions used are conservative and the benchmarks are publicly available. And while your own numbers will differ, the methodology used is transferable. ",[],{},{"nodeType":883,"data":9292,"content":9293},{},[9294,9298],{"nodeType":882,"value":9295,"marks":9296,"data":9297},"Using these estimates, ACME can conservatively expect a return of ",[],{},{"nodeType":882,"value":9299,"marks":9300,"data":9302},"$435K–$925K in combined annual value from direct labor savings, risk-adjusted cost avoidance, and accelerated productivity gains.",[9301],{"type":1012},{},"Browser business case IB1",{"sys":9305,"__typename":1302,"content":9306,"name":9327,"title":59},{"id":8476},{"json":9307},{"nodeType":1294,"data":9308,"content":9309},{},[9310],{"nodeType":883,"data":9311,"content":9312},{},[9313,9318,9322],{"nodeType":882,"value":9314,"marks":9315,"data":9317},"ACME example: ",[9316],{"type":1012},{},{"nodeType":882,"value":9319,"marks":9320,"data":9321},"IBM's data puts the average breach cost for a technology company at approximately $4.9M. Assuming a conservative 5–8% annual breach probability, and given that 80% of breaches are now identity-based and execute via the browser, the question is how much of that exposure Push eliminates. Push detects and blocks browser-native, identity-based attacks in real time. Even using a conservative 80% effectiveness estimate ",[],{},{"nodeType":882,"value":9323,"marks":9324,"data":9326},"the expected annual value is $150K–$250K.",[9325],{"type":1012},{},"Browser business case IB2",{"sys":9329,"__typename":1302,"content":9330,"name":9354,"title":59},{"id":8608},{"json":9331},{"nodeType":1294,"data":9332,"content":9333},{},[9334],{"nodeType":883,"data":9335,"content":9336},{},[9337,9341,9345,9350],{"nodeType":882,"value":9314,"marks":9338,"data":9340},[9339],{"type":1012},{},{"nodeType":882,"value":9342,"marks":9343,"data":9344},"for a 1,000-employee technology company where 60% of the workforce are knowledge workers, accelerating safe AI adoption by three to six months for 25–40% of those workers captures ",[],{},{"nodeType":882,"value":9346,"marks":9347,"data":9349},"$150K–$400K",[9348],{"type":1012},{},{"nodeType":882,"value":9351,"marks":9352,"data":9353}," in productivity value.",[],{},"Browser business case IB3",{"sys":9356,"__typename":1302,"content":9357,"name":9380,"title":59},{"id":8746},{"json":9358},{"nodeType":1294,"data":9359,"content":9360},{},[9361],{"nodeType":883,"data":9362,"content":9363},{},[9364,9368,9372,9377],{"nodeType":882,"value":9314,"marks":9365,"data":9367},[9366],{"type":1012},{},{"nodeType":882,"value":9369,"marks":9370,"data":9371},"Automated identity remediation across approximately 2,500 vulnerabilities recovers $25K–$35K in analyst time annually. Investigation efficiency gains from earlier detection and the elimination of compromised credential false positives save a further $45K–$65K. Reduced analyst attrition, driven by the removal of tedious manual work, avoids $15K–$25K in recruitment and ramp-up costs. Combined, this value driver represents ",[],{},{"nodeType":882,"value":9373,"marks":9374,"data":9376},"$85K–$125K annually",[9375],{"type":1012},{},{"nodeType":882,"value":1438,"marks":9378,"data":9379},[],{},"Browser business case IB4",{"sys":9382,"__typename":1302,"content":9383,"name":9406,"title":59},{"id":8816},{"json":9384},{"nodeType":1294,"data":9385,"content":9386},{},[9387],{"nodeType":883,"data":9388,"content":9389},{},[9390,9394,9398,9403],{"nodeType":882,"value":9314,"marks":9391,"data":9393},[9392],{"type":1012},{},{"nodeType":882,"value":9395,"marks":9396,"data":9397},"Push's automated inventory and continuous compliance evidence replaces approximately 1,000 hours of annual audit preparation effort, generating $8K–$25K in direct savings. The larger value is in risk avoidance: assuming a conservative 3–5% annual probability of a compliance-related financial event (e.g. a denied insurance claim or a regulatory fine) and an average impact of $5–8M, even a 30% reduction in that exposure represents $45K–$120K in expected annual value. ",[],{},{"nodeType":882,"value":9399,"marks":9400,"data":9402},"Combined: $50K–$150K",[9401],{"type":1012},{},{"nodeType":882,"value":1438,"marks":9404,"data":9405},[],{},"Browser business case IB5",{"items":9408},[],{},"How to make the business case for browser security",{"items":9412},[9413,10113,10664],{"__typename":1365,"sys":9414,"content":9416,"title":4605,"synopsis":10100,"hashTags":59,"publishedDate":10101,"slug":10102,"tagsCollection":10103,"authorsCollection":10109},{"id":9415},"1ThCW6Cx8Zcq2flramQdoj",{"json":9417},{"data":9418,"content":9419,"nodeType":1294},{},[9420,9427,9434,9456,9463,9470,9477,9480,9488,9495,9514,9521,9528,9576,9583,9591,9598,9605,9612,9615,9623,9630,9642,9649,9657,9676,9682,9722,9727,9734,9746,9752,9759,9776,9784,9791,9810,9816,9824,9831,9985,9988,9996,10003,10010,10013,10021,10028,10040,10052,10064,10076,10083],{"data":9421,"content":9422,"nodeType":883},{},[9423],{"data":9424,"marks":9425,"value":9426,"nodeType":882},{},[],"At first, it may seem like an obvious choice, partly because the category name \"Secure Enterprise Browser\" implies the answer is a full-stack browser. Plus, the most visible vendors in the space have spent the past few years marketing that exact choice as the only one. ",{"data":9428,"content":9429,"nodeType":883},{},[9430],{"data":9431,"marks":9432,"value":9433,"nodeType":882},{},[],"But the market tells a different story. The majority of vendors Gartner places in the SEB category are now extensions rather than full browsers, and Gartner explicitly notes that extensions have become the preferred option. ",{"data":9435,"content":9436,"nodeType":3695},{},[9437],{"data":9438,"content":9439,"nodeType":883},{},[9440,9444,9452],{"data":9441,"marks":9442,"value":9443,"nodeType":882},{},[],"The buyer-side data tells the same story: In ",{"data":9445,"content":9446,"nodeType":929},{"uri":6589},[9447],{"data":9448,"marks":9449,"value":9451,"nodeType":882},{},[9450],{"type":927},"Omdia's 2026 survey of 400 IT and security professionals",{"data":9453,"marks":9454,"value":9455,"nodeType":882},{},[],", 48% of organizations cited the ability to use their existing browsers as an important attribute in a secure browsing solution.",{"data":9457,"content":9458,"nodeType":883},{},[9459],{"data":9460,"marks":9461,"value":9462,"nodeType":882},{},[],"The truth is: Full-stack enterprise browsers and browser security extensions like Push aren’t competing products. They serve different needs for different teams, though they often get evaluated against each other.",{"data":9464,"content":9465,"nodeType":883},{},[9466],{"data":9467,"marks":9468,"value":9469,"nodeType":882},{},[],"Full-stack enterprise browsers serve the IT team's need to control the workspace. Browser security extensions like Push meet the security team's need to protect their users as they work in their browsers — a fundamentally different problem. ",{"data":9471,"content":9472,"nodeType":883},{},[9473],{"data":9474,"marks":9475,"value":9476,"nodeType":882},{},[],"In this article, we’ll cover why a feature-by-feature checklist is the wrong approach when selecting a secure browser platform, and what questions to consider instead. We’ll also discuss what each type of solution excels at, where Push fits in, and how to map your needs to the right solution.",{"data":9478,"content":9479,"nodeType":967},{},[],{"data":9481,"content":9482,"nodeType":975},{},[9483],{"data":9484,"marks":9485,"value":9487,"nodeType":882},{},[9486],{"type":1012},"Full-stack enterprise browsers meet the IT team's need to control a workspace",{"data":9489,"content":9490,"nodeType":883},{},[9491],{"data":9492,"marks":9493,"value":9494,"nodeType":882},{},[],"Full-stack enterprise browsers like Island, Prisma Browser, and SURF Security are best understood as managed workspace platforms rather than browsers in the conventional sense. ",{"data":9496,"content":9497,"nodeType":3695},{},[9498],{"data":9499,"content":9500,"nodeType":883},{},[9501,9505,9510],{"data":9502,"marks":9503,"value":9504,"nodeType":882},{},[],"Island's own CEO Mike Fey has described the company's strategy as transforming the browser into ",{"data":9506,"marks":9507,"value":9509,"nodeType":882},{},[9508],{"type":1045},"\"a centralized, enterprise-grade platform, eliminating layers of legacy IT infrastructure by building more functionality in the browser.\"",{"data":9511,"marks":9512,"value":9513,"nodeType":882},{},[]," ",{"data":9515,"content":9516,"nodeType":883},{},[9517],{"data":9518,"marks":9519,"value":9520,"nodeType":882},{},[],"Chrome Enterprise and Edge for Business occupy a related space as productivity-suite browsers extended with native security controls, sold as part of the broader Google and Microsoft workplace stacks. Different products with different lineage, but all of them converge on the same owner: an IT organization solving for workspace control.",{"data":9522,"content":9523,"nodeType":883},{},[9524],{"data":9525,"marks":9526,"value":9527,"nodeType":882},{},[],"The IT team is trying to achieve workspace policy compliance and access governance. Their primary use case is typically reducing reliance on legacy IT tools like VDI, VPN, remote browser isolation, DaaS, web filtering, and CASBs. In this world, the use cases look like: ",{"data":9529,"content":9530,"nodeType":1454},{},[9531,9546,9561],{"data":9532,"content":9533,"nodeType":1419},{},[9534],{"data":9535,"content":9536,"nodeType":883},{},[9537,9542],{"data":9538,"marks":9539,"value":9541,"nodeType":882},{},[9540],{"type":1012},"Securing third-party contractors or BYOD",{"data":9543,"marks":9544,"value":9545,"nodeType":882},{},[]," where the workspace itself is the access control. ",{"data":9547,"content":9548,"nodeType":1419},{},[9549],{"data":9550,"content":9551,"nodeType":883},{},[9552,9557],{"data":9553,"marks":9554,"value":9556,"nodeType":882},{},[9555],{"type":1012},"Regulated populations",{"data":9558,"marks":9559,"value":9560,"nodeType":882},{},[]," like call centers, BPO workforces, finance teams handling sensitive material, where output controls like watermarking, screenshot restriction, and print blocking need to be enforced at the OS rendering layer. ",{"data":9562,"content":9563,"nodeType":1419},{},[9564],{"data":9565,"content":9566,"nodeType":883},{},[9567,9572],{"data":9568,"marks":9569,"value":9571,"nodeType":882},{},[9570],{"type":1012},"Legacy app support",{"data":9573,"marks":9574,"value":9575,"nodeType":882},{},[]," including IE-mode rendering for applications that have never been modernized. ",{"data":9577,"content":9578,"nodeType":883},{},[9579],{"data":9580,"marks":9581,"value":9582,"nodeType":882},{},[],"For these use cases, the architecture is well-suited, and there are numerous full-stack SEB solutions that address them well. Where the full-stack approach runs into trouble is in getting users to migrate onto a new browser and in justifying the cost of doing so. Both problems scale with the size of the workforce. ",{"data":9584,"content":9585,"nodeType":2050},{},[9586],{"data":9587,"marks":9588,"value":9590,"nodeType":882},{},[9589],{"type":1012},"Cost of deployment is a significant blocker for full-stack browsers",{"data":9592,"content":9593,"nodeType":883},{},[9594],{"data":9595,"marks":9596,"value":9597,"nodeType":882},{},[],"The migration costs are easy to predict: deployment and configuration effort, help desk volume and — biggest of all — user resistance. But it’s the license cost that limits deployments in many organizations going from a free consumer browser to a paid replacement for the first time. ",{"data":9599,"content":9600,"nodeType":883},{},[9601],{"data":9602,"marks":9603,"value":9604,"nodeType":882},{},[],"In fact, Gartner notes that most buyers start with a single use case like covering contractors and rarely pursue organization-wide deployment for a full-stack enterprise browser. ",{"data":9606,"content":9607,"nodeType":883},{},[9608],{"data":9609,"marks":9610,"value":9611,"nodeType":882},{},[],"For organizations that do achieve a full-coverage deployment for these full-stack browsers, the need to manage drift in employee behavior over time gets harder. Agentic browsers like Comet, Atlas, and Dia are already starting to pull users toward AI-native workflows that consumer browsers don’t offer and full-stack enterprise browsers don’t currently match.",{"data":9613,"content":9614,"nodeType":967},{},[],{"data":9616,"content":9617,"nodeType":975},{},[9618],{"data":9619,"marks":9620,"value":9622,"nodeType":882},{},[9621],{"type":1012},"What a browser security extension built for the security team looks like",{"data":9624,"content":9625,"nodeType":883},{},[9626],{"data":9627,"marks":9628,"value":9629,"nodeType":882},{},[],"Most browser security extensions on the market were built to address this migration hurdle. They attempt to take as many of the features of a full-stack browser as possible, but make it possible to deploy into users’ existing browsers, sidestepping a lot of the cost and rollout problems.",{"data":9631,"content":9632,"nodeType":883},{},[9633,9637],{"data":9634,"marks":9635,"value":9636,"nodeType":882},{},[],"LayerX, Seraphic, SquareX, and Keep Aware have all at some point echoed this approach in their product descriptions with the line ",{"data":9638,"marks":9639,"value":9641,"nodeType":882},{},[9640],{"type":1045},"\"make any browser an enterprise browser.\"",{"data":9643,"content":9644,"nodeType":883},{},[9645],{"data":9646,"marks":9647,"value":9648,"nodeType":882},{},[],"Ultimately, that approach is still aimed at solving problems for the IT team more than the security team.",{"data":9650,"content":9651,"nodeType":2050},{},[9652],{"data":9653,"marks":9654,"value":9656,"nodeType":882},{},[9655],{"type":1012},"Push is different — we built a browser extension to meet the security team's needs",{"data":9658,"content":9659,"nodeType":883},{},[9660,9664,9672],{"data":9661,"marks":9662,"value":9663,"nodeType":882},{},[],"Push set out to meet a different need. Our team's background has always been in defending organizations against advanced attacks. We spent our careers working in red and blue teams throughout the network and endpoint eras of cyber attacks. The mission we started with in 2022 was to defend organizations against the ",{"data":9665,"content":9666,"nodeType":929},{"uri":3358},[9667],{"data":9668,"marks":9669,"value":9671,"nodeType":882},{},[9670],{"type":927},"new era of damaging cyber attacks that originate in the browser",{"data":9673,"marks":9674,"value":9675,"nodeType":882},{},[],". ",{"data":9677,"content":9681,"nodeType":963},{"target":9678},{"sys":9679},{"id":9680,"type":960,"linkType":961},"6BwJl8ZkiMore2o1BKx2w6",[],{"data":9683,"content":9684,"nodeType":883},{},[9685,9689,9698,9702,9707,9711,9719],{"data":9686,"marks":9687,"value":9688,"nodeType":882},{},[],"We chose a browser extension as the approach for our solution, not because we wanted to build an easier-to-deploy enterprise browser, but so we could use it as a security agent to collect high-fidelity telemetry for TTP-based detections, and apply real-time controls to stop attacks at the earliest opportunity in the modern  — ",{"data":9690,"content":9692,"nodeType":929},{"uri":9691},"https:\u002F\u002Fpushsecurity.com\u002Fresources\u002Fbrowser-identity-attacks-matrix\u002F",[9693],{"data":9694,"marks":9695,"value":9697,"nodeType":882},{},[9696],{"type":927},"browser and identity native",{"data":9699,"marks":9700,"value":9701,"nodeType":882},{},[],"  — kill chain. ",{"data":9703,"marks":9704,"value":9706,"nodeType":882},{},[9705],{"type":1012},"In effect, we created EDR, but for the browser. ",{"data":9708,"marks":9709,"value":9710,"nodeType":882},{},[],"This is what gives Push the edge compared to other Secure Enterprise Browser solutions when it comes to tackling the highest priority threats in the browser — ",{"data":9712,"content":9713,"nodeType":929},{"uri":9187},[9714],{"data":9715,"marks":9716,"value":9718,"nodeType":882},{},[9717],{"type":927},"we’re optimized for this problem area",{"data":9720,"marks":9721,"value":9675,"nodeType":882},{},[],{"data":9723,"content":9726,"nodeType":963},{"target":9724},{"sys":9725},{"id":4417,"type":960,"linkType":961},[],{"data":9728,"content":9729,"nodeType":883},{},[9730],{"data":9731,"marks":9732,"value":9733,"nodeType":882},{},[],"For a security team using Push’s extension, this means attacks get stopped at the earliest opportunity in the kill chain and before they cause harm. ",{"data":9735,"content":9736,"nodeType":883},{},[9737,9741],{"data":9738,"marks":9739,"value":9740,"nodeType":882},{},[],"When a user lands on a phishing page built to harvest their credentials, Push sees the page rendering and the JavaScript executing inside the DOM, and can block the credential submission before the form posts. When a user is being walked through a ClickFix or ConsentFix social engineering flow, Push sees the clipboard writes and the OAuth consent flow parameters being prepared, and can intervene before the user completes the action. When a session token is stolen and replayed against a different device, Push sees the session activity and surfaces the compromise. ",{"data":9742,"marks":9743,"value":9745,"nodeType":882},{},[9744],{"type":1012},"Push does all of this from a browser extension, without needing to replace the user's browser. ",{"data":9747,"content":9751,"nodeType":963},{"target":9748},{"sys":9749},{"id":9750,"type":960,"linkType":961},"1FZEbn0K80d1jHRRTk7kL7",[],{"data":9753,"content":9754,"nodeType":883},{},[9755],{"data":9756,"marks":9757,"value":9758,"nodeType":882},{},[],"The same underlying technology also addresses other high-value security use cases: Visibility and control over AI usage; hardening identities and surfacing shadow IT; and supporting insider investigations and preventing data loss. ",{"data":9760,"content":9761,"nodeType":883},{},[9762,9765,9772],{"data":9763,"marks":9764,"value":6443,"nodeType":882},{},[],{"data":9766,"content":9767,"nodeType":929},{"uri":8834},[9768],{"data":9769,"marks":9770,"value":9771,"nodeType":882},{},[],"highest-value use cases",{"data":9773,"marks":9774,"value":9775,"nodeType":882},{},[]," the browser can address are all powered by the same underlying technical capability, which is why Push's single extension can address four major security use cases rather than four separate tools needing four separate deployments. The success metric for security teams using Push is attacks averted or stopped, cyber risk reduced, and security posture and resilience strengthened — not workspace policy compliance.",{"data":9777,"content":9778,"nodeType":2050},{},[9779],{"data":9780,"marks":9781,"value":9783,"nodeType":882},{},[9782],{"type":1012},"Proven at scale: What security leaders are saying",{"data":9785,"content":9786,"nodeType":883},{},[9787],{"data":9788,"marks":9789,"value":9790,"nodeType":882},{},[],"Push launched its browser extension in 2022, making it one of the first and longest-running browser security extensions in the category, and it is now deployed across more than three million browsers worldwide.",{"data":9792,"content":9793,"nodeType":883},{},[9794,9798,9806],{"data":9795,"marks":9796,"value":9797,"nodeType":882},{},[],"Many ",{"data":9799,"content":9800,"nodeType":929},{"uri":4493},[9801],{"data":9802,"marks":9803,"value":9805,"nodeType":882},{},[9804],{"type":927},"Push customers",{"data":9807,"marks":9808,"value":9809,"nodeType":882},{},[]," were initially considering full-stack enterprise browsers, but found that Push provided all the visibility and control they needed without the migration headache.",{"data":9811,"content":9815,"nodeType":963},{"target":9812},{"sys":9813},{"id":9814,"type":960,"linkType":961},"4RDIOAuVN10mZCtjltJCB4",[],{"data":9817,"content":9818,"nodeType":2050},{},[9819],{"data":9820,"marks":9821,"value":9823,"nodeType":882},{},[9822],{"type":1012},"The extension matters, but it's what we built around it that really counts",{"data":9825,"content":9826,"nodeType":883},{},[9827],{"data":9828,"marks":9829,"value":9830,"nodeType":882},{},[],"The extension is the most visible part of the Push platform, but what Push has built around it makes the solution the most powerful security tool in the browser:",{"data":9832,"content":9833,"nodeType":1454},{},[9834,9880,9917,9955,9970],{"data":9835,"content":9836,"nodeType":1419},{},[9837],{"data":9838,"content":9839,"nodeType":883},{},[9840,9845,9849,9855,9858,9865,9869,9876],{"data":9841,"marks":9842,"value":9844,"nodeType":882},{},[9843],{"type":1012},"In-house threat research that discovers attack techniques as they emerge.",{"data":9846,"marks":9847,"value":9848,"nodeType":882},{},[]," Push researchers track real-world adversary activity and discover new techniques as they appear, including ",{"data":9850,"content":9851,"nodeType":929},{"uri":3582},[9852],{"data":9853,"marks":9854,"value":1989,"nodeType":882},{},[],{"data":9856,"marks":9857,"value":8976,"nodeType":882},{},[],{"data":9859,"content":9860,"nodeType":929},{"uri":3823},[9861],{"data":9862,"marks":9863,"value":9864,"nodeType":882},{},[]," InstallFix",{"data":9866,"marks":9867,"value":9868,"nodeType":882},{},[],", and creating the ",{"data":9870,"content":9871,"nodeType":929},{"uri":8231},[9872],{"data":9873,"marks":9874,"value":9875,"nodeType":882},{},[],"Browser & Identity Attacks Matrix",{"data":9877,"marks":9878,"value":9879,"nodeType":882},{},[],". Detection is only as good as the threat understanding behind it, and research is what keeps that understanding ahead of what attackers are doing in the wild.",{"data":9881,"content":9882,"nodeType":1419},{},[9883],{"data":9884,"content":9885,"nodeType":883},{},[9886,9891,9895,9901,9905,9913],{"data":9887,"marks":9888,"value":9890,"nodeType":882},{},[9889],{"type":1012},"Agentic threat hunting and detection engineering at machine speed.",{"data":9892,"marks":9893,"value":9894,"nodeType":882},{},[]," Push's ",{"data":9896,"content":9897,"nodeType":929},{"uri":2893},[9898],{"data":9899,"marks":9900,"value":9013,"nodeType":882},{},[],{"data":9902,"marks":9903,"value":9904,"nodeType":882},{},[]," operationalizes the research, generating new behavioral detections in minutes rather than quarterly releases — covering the ",{"data":9906,"content":9908,"nodeType":929},{"uri":9907},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fhow-the-browser-became-the-main-cyber-battleground\u002F",[9909],{"data":9910,"marks":9911,"value":9912,"nodeType":882},{},[],"techniques behind the Scattered Spider, Scattered Lapsus$ Hunters, and ShinyHunters breaches",{"data":9914,"marks":9915,"value":9916,"nodeType":882},{},[]," of the past three years. Attackers are using AI to accelerate the pace at which they generate new lures, kits, and infrastructure; Push keeps security teams in front by advancing the capability at machine speed and scale.",{"data":9918,"content":9919,"nodeType":1419},{},[9920],{"data":9921,"content":9922,"nodeType":883},{},[9923,9928,9932,9939,9943,9951],{"data":9924,"marks":9925,"value":9927,"nodeType":882},{},[9926],{"type":1012},"Collecting the right telemetry to surface both attacker behavior and risky user action.",{"data":9929,"marks":9930,"value":9931,"nodeType":882},{},[]," Telemetry by itself is just data — the value comes from knowing what to collect, why it matters, and how to turn it into detections and controls. Push combines deep instrumentation of the browser with the expertise to use what we collect: the same browser-layer telemetry that detects AiTM kits, ClickFix and ConsentFix lures, and session token replay also surfaces what users are pasting into AI tools, which ",{"data":9933,"content":9934,"nodeType":929},{"uri":8979},[9935],{"data":9936,"marks":9937,"value":9938,"nodeType":882},{},[],"SaaS apps they're logging into outside the IdP",{"data":9940,"marks":9941,"value":9942,"nodeType":882},{},[],", which OAuth grants are being made, and which ",{"data":9944,"content":9946,"nodeType":929},{"uri":9945},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fbrowser-extension-management-guide\u002F",[9947],{"data":9948,"marks":9949,"value":9950,"nodeType":882},{},[],"extensions are running in their browsers",{"data":9952,"marks":9953,"value":9954,"nodeType":882},{},[],". The threat detection and the identity, AI, and DLP use cases are not separate features — they are different applications of the same underlying telemetry, surfaced because Push knows what to look for.",{"data":9956,"content":9957,"nodeType":1419},{},[9958],{"data":9959,"content":9960,"nodeType":883},{},[9961,9966],{"data":9962,"marks":9963,"value":9965,"nodeType":882},{},[9964],{"type":1012},"Enforcing the right controls at the right place at the right moment.",{"data":9967,"marks":9968,"value":9969,"nodeType":882},{},[]," Visibility without actionability is only half a solution. Push turns the browser into a strong control point for stopping attacks and risky user behaviors in real time — reusing passwords, intercepting credential submission to non-IdP domains, blocking ClickFix clipboard payloads before paste-execute, prompting MFA enrollment at the point of login, warning on weak or breached passwords at credential entry, and surfacing app banners that communicate policy at the moment of use. The same control surface that stops attackers stops the user's mistakes that lead to the next breach.",{"data":9971,"content":9972,"nodeType":1419},{},[9973],{"data":9974,"content":9975,"nodeType":883},{},[9976,9981],{"data":9977,"marks":9978,"value":9980,"nodeType":882},{},[9979],{"type":1012},"Balancing security and privacy.",{"data":9982,"marks":9983,"value":9984,"nodeType":882},{},[]," Push is designed to give security teams the telemetry they need without monitoring personal browsing. By default, only logins to configured corporate domains are observed; personal browsing is not collected. (Though administrators have the option to observe personal account logins to work apps, and identify where browsers are being synced to personal accounts, which can result in password loss.) Plaintext passwords and form inputs are never transmitted — passwords are analyzed locally using salted partial hashes. Broader browser metadata is stored on the device and only transmitted when it matches a detection rule. Push does not train AI models on customer telemetry.",{"data":9986,"content":9987,"nodeType":967},{},[],{"data":9989,"content":9990,"nodeType":975},{},[9991],{"data":9992,"marks":9993,"value":9995,"nodeType":882},{},[9994],{"type":1012},"Full-stack enterprise browsers and Push’s browser extension are not mutually exclusive",{"data":9997,"content":9998,"nodeType":883},{},[9999],{"data":10000,"marks":10001,"value":10002,"nodeType":882},{},[],"It’s worth pausing on a point that often gets lost in the way the market discusses this choice. Full-stack enterprise browsers and Push’s extension-based solution are not mutually exclusive. They do different things for different teams, and they run together. ",{"data":10004,"content":10005,"nodeType":883},{},[10006],{"data":10007,"marks":10008,"value":10009,"nodeType":882},{},[],"Push supports enterprise browsers like Island and Prisma Browser. Many of Push’s customers use a full-stack browser for the contractor population or regulated workload where the IT team needs workspace controls, and Push across the rest of the workforce to provide the deep security capabilities that the IT team is not measured on but the security team is. The right framing for many enterprises is not whether to choose full-stack or extension. It is full-stack for the IT use cases that need it, and Push everywhere else.",{"data":10011,"content":10012,"nodeType":967},{},[],{"data":10014,"content":10015,"nodeType":975},{},[10016],{"data":10017,"marks":10018,"value":10020,"nodeType":882},{},[10019],{"type":1012},"Which one is right for your security team?",{"data":10022,"content":10023,"nodeType":883},{},[10024],{"data":10025,"marks":10026,"value":10027,"nodeType":882},{},[],"The answer follows from the need you are trying to meet. The scenarios below cover the most common real-world situations and the approach that fits each.",{"data":10029,"content":10030,"nodeType":883},{},[10031,10036],{"data":10032,"marks":10033,"value":10035,"nodeType":882},{},[10034],{"type":1012},"Is your priority detecting and stopping attacks in the browser?",{"data":10037,"marks":10038,"value":10039,"nodeType":882},{},[]," Go with Push. Push detects and stops the threats actually breaching enterprises — AiTM phishing, ClickFix, OAuth abuse, malicious browser extensions. It also provides valuable additional insight during investigations to understand incidents better and decide how to respond to them. ",{"data":10041,"content":10042,"nodeType":883},{},[10043,10048],{"data":10044,"marks":10045,"value":10047,"nodeType":882},{},[10046],{"type":1012},"Do you have a large contractor or third-party population needing locked-down workspace controls?",{"data":10049,"marks":10050,"value":10051,"nodeType":882},{},[]," Use a full-stack enterprise browser for that population and Push for everyone else. Watermarking, screenshot blocking and print restriction are OS-level controls that extensions cannot reliably replicate.",{"data":10053,"content":10054,"nodeType":883},{},[10055,10060],{"data":10056,"marks":10057,"value":10059,"nodeType":882},{},[10058],{"type":1012},"Do you have a multi-browser estate including a mix of consumer and agentic browsers?",{"data":10061,"marks":10062,"value":10063,"nodeType":882},{},[]," Push will provide the coverage you need to secure users. The browser options are growing, and locking your workforce into a single corporate browser becomes harder every time a new productivity-shaping browser ships. Push regularly adds support for emerging browsers.",{"data":10065,"content":10066,"nodeType":883},{},[10067,10072],{"data":10068,"marks":10069,"value":10071,"nodeType":882},{},[10070],{"type":1012},"Is significant BYOD or unmanaged-device coverage required.",{"data":10073,"marks":10074,"value":10075,"nodeType":882},{},[]," Push is a great option, particularly if you also have Chromebooks that fall outside of your EDR coverage. The extension can easily be installed via email or landing page self-enrollment, with options to enforce coverage through conditional access policies. This provides full threat detection and policy enforcement on devices the organization does not own.",{"data":10077,"content":10078,"nodeType":883},{},[10079],{"data":10080,"marks":10081,"value":10082,"nodeType":882},{},[],"In short, if you are solving for workspace control, the right tool is a full-stack enterprise browser. If you’re solving for protecting users as they work in their browsers, Push is the tool built specifically for that need — with the research depth, detection engineering, and operational scale to do the job.",{"data":10084,"content":10085,"nodeType":883},{},[10086,10089,10097],{"data":10087,"marks":10088,"value":21,"nodeType":882},{},[],{"data":10090,"content":10091,"nodeType":929},{"uri":1283},[10092],{"data":10093,"marks":10094,"value":10096,"nodeType":882},{},[10095],{"type":927},"Book a live demo to learn more",{"data":10098,"marks":10099,"value":1438,"nodeType":882},{},[],"If you're building a shortlist of browser security vendors, do you need a full-stack enterprise browser, or browser security extension? ","2026-05-21T00:00:00.000Z","enterprise-browser-vs-browser-extension-which-should-your-security-team-choose",{"items":10104},[10105,10107],{"sys":10106,"name":298},{"id":7235},{"sys":10108,"name":7239},{"id":7238},{"items":10110},[10111],{"fullName":3964,"firstName":3965,"jobTitle":868,"profilePicture":10112},{"url":3969},{"__typename":1365,"sys":10114,"content":10116,"title":10646,"synopsis":10647,"hashTags":59,"publishedDate":10648,"slug":10649,"tagsCollection":10650,"authorsCollection":10656},{"id":10115},"7sZs2lHCTN8oYc2OIGCIQG",{"json":10117},{"data":10118,"content":10119,"nodeType":1294},{},[10120,10127,10130,10138,10154,10161,10168,10174,10182,10189,10196,10202,10219,10225,10241,10249,10265,10272,10279,10282,10290,10306,10312,10330,10336,10344,10368,10375,10378,10386,10393,10399,10406,10424,10432,10448,10451,10459,10475,10482,10489,10507,10510,10518,10525,10532,10539,10545,10553,10569,10576,10593,10596,10604,10611,10618,10624,10630],{"data":10121,"content":10122,"nodeType":883},{},[10123],{"data":10124,"marks":10125,"value":10126,"nodeType":882},{},[],"The headline finding getting the most airtime in 2026 is that vulnerability exploitation has overtaken credential abuse as the top single initial access vector, jumping to 31% from 20% the year before. The vulnerability management crisis driving this statistic is one of the most important stories in this year's data. But reading it as evidence that identity threats are receding would be a mistake, because the DBIR's own data tells a more complicated and more useful story when you look at the full picture.",{"data":10128,"content":10129,"nodeType":967},{},[],{"data":10131,"content":10132,"nodeType":975},{},[10133],{"data":10134,"marks":10135,"value":10137,"nodeType":882},{},[10136],{"type":1012},"Vulnerability exploitation has caught up with identity — not replaced it",{"data":10139,"content":10140,"nodeType":883},{},[10141,10145,10150],{"data":10142,"marks":10143,"value":10144,"nodeType":882},{},[],"The DBIR's headline comparison pits vulnerability exploitation (31%) against credential abuse (13%) as individual vectors. That comparison is accurate but incomplete, because the DBIR tracks identity-related initial access across ",{"data":10146,"marks":10147,"value":10149,"nodeType":882},{},[10148],{"type":1012},"three",{"data":10151,"marks":10152,"value":10153,"nodeType":882},{},[]," separate categories: phishing (16%), credential abuse (13%), and pretexting (6%). Before interpreting those numbers, there's a methodological wrinkle worth understanding.",{"data":10155,"content":10156,"nodeType":883},{},[10157],{"data":10158,"marks":10159,"value":10160,"nodeType":882},{},[],"This year's report added pretexting as a newly tracked initial access vector, reclassifying some incidents previously counted as credential abuse. The DBIR is transparent about the effect: without that change, credential abuse would have been 16% rather than 13%. On an apples-to-apples basis, identity-related initial access (phishing 16% + credential abuse 16%) comes to 32% — versus 31% for vulnerability exploitation.",{"data":10162,"content":10163,"nodeType":883},{},[10164],{"data":10165,"marks":10166,"value":10167,"nodeType":882},{},[],"To be precise about what moved: phishing held roughly flat year over year, but credential abuse saw a modest decline even on the adjusted basis (from 22% to 16%). Overall, the identity picture is broadly stable. The reason the two categories have converged is that vulnerability exploitation surged 55%, not that identity attacks meaningfully receded.",{"data":10169,"content":10173,"nodeType":963},{"target":10170},{"sys":10171},{"id":10172,"type":960,"linkType":961},"5GvSsSY4R6X34ZBMidZ54X",[],{"data":10175,"content":10176,"nodeType":2050},{},[10177],{"data":10178,"marks":10179,"value":10181,"nodeType":882},{},[10180],{"type":1012},"The taxonomy gap",{"data":10183,"content":10184,"nodeType":883},{},[10185],{"data":10186,"marks":10187,"value":10188,"nodeType":882},{},[],"It's also worth asking how much the DBIR's initial access taxonomy can tell us. The figure that everyone is citing — Figure 10 — is labelled \"select enumerations,\" and the four tracked vectors (vulnerability exploitation, phishing, credential abuse, pretexting) add up to only 66% of initial access. A third of the picture isn't represented in the headline breakdown at all.",{"data":10190,"content":10191,"nodeType":883},{},[10192],{"data":10193,"marks":10194,"value":10195,"nodeType":882},{},[],"The cluster boundaries and where you draw them also changes the story. The DBIR classifies ClickFix under \"baiting\" — a category that covers malicious downloads and SEO poisoning — rather than phishing, even though the end goal is often the same: getting a user to execute something they shouldn't. Pretexting absorbed incidents that were previously credential abuse, shifting the numbers between categories. These are useful analytical clusters, but they aren't clean divisions of a neatly partitioned attack surface.",{"data":10197,"content":10201,"nodeType":963},{"target":10198},{"sys":10199},{"id":10200,"type":960,"linkType":961},"7t6ZcHDycaPOyLstX4r8zl",[],{"data":10203,"content":10204,"nodeType":883},{},[10205,10209,10216],{"data":10206,"marks":10207,"value":10208,"nodeType":882},{},[],"These are identity attacks at scale, and it isn't clear where — or whether — they show up in the DBIR's initial access vectors. This lack of depth in identity and in-browser attack vectors is common in many defensive models, which is why we've created our own ",{"data":10210,"content":10211,"nodeType":929},{"uri":9691},[10212],{"data":10213,"marks":10214,"value":10215,"nodeType":882},{},[],"Browser and Identity Attacks Matrix",{"data":10217,"marks":10218,"value":1438,"nodeType":882},{},[],{"data":10220,"content":10224,"nodeType":963},{"target":10221},{"sys":10222},{"id":10223,"type":960,"linkType":961},"53U3LHhhHFYnEpShdLmDqs",[],{"data":10226,"content":10227,"nodeType":883},{},[10228,10232,10237],{"data":10229,"marks":10230,"value":10231,"nodeType":882},{},[],"That convergence at initial access also understates the role credentials play across full breach chains. The DBIR states plainly that credential abuse at any point in the breach progression — not just as the first action — appears in ",{"data":10233,"marks":10234,"value":10236,"nodeType":882},{},[10235],{"type":1012},"39% of all breaches",{"data":10238,"marks":10239,"value":10240,"nodeType":882},{},[],", making it the single most pervasive technique in the dataset. Credentials don't just open the front door; they unlock lateral movement, privilege escalation, and persistence throughout the attack chain.",{"data":10242,"content":10243,"nodeType":2050},{},[10244],{"data":10245,"marks":10246,"value":10248,"nodeType":882},{},[10247],{"type":1012},"The vulnerability treadmill",{"data":10250,"content":10251,"nodeType":883},{},[10252,10256,10261],{"data":10253,"marks":10254,"value":10255,"nodeType":882},{},[],"The vulnerability exploitation surge itself is driven by a structural capacity crisis rather than a shift in attacker preference. Edge devices and VPNs now account for 22% of vulnerability-exploitation breaches, up from 3% the prior year — a ",{"data":10257,"marks":10258,"value":10260,"nodeType":882},{},[10259],{"type":1045},"sevenfold",{"data":10262,"marks":10263,"value":10264,"nodeType":882},{},[]," increase. Organizations face 50% more CISA KEV vulnerabilities to remediate than a year ago, median remediation time has increased from 32 to 43 days, and the volume of vulnerability records in the dataset has grown roughly eightfold.",{"data":10266,"content":10267,"nodeType":883},{},[10268],{"data":10269,"marks":10270,"value":10271,"nodeType":882},{},[],"This trend was already visible in last year's DBIR, when vulnerability exploitation jumped from 15% to 20%. AI-assisted exploit development may be compounding the problem — the DBIR's own data shows 32% of AI-assisted initial access targeting vulnerability exploitation — but the structural capacity crisis was accelerating well before AI became a meaningful factor in the attacker toolkit.",{"data":10273,"content":10274,"nodeType":883},{},[10275],{"data":10276,"marks":10277,"value":10278,"nodeType":882},{},[],"The vulnerability treadmill is accelerating, and the DBIR's remediation data shows defenders losing ground. But this is an additive problem, not a substitution. Both attack surfaces are growing. ",{"data":10280,"content":10281,"nodeType":967},{},[],{"data":10283,"content":10284,"nodeType":975},{},[10285],{"data":10286,"marks":10287,"value":10289,"nodeType":882},{},[10288],{"type":1012},"Phishing has left the inbox",{"data":10291,"content":10292,"nodeType":883},{},[10293,10297,10302],{"data":10294,"marks":10295,"value":10296,"nodeType":882},{},[],"41% percent of social engineering breaches now involve vectors other than email, with approximately a quarter coming from social media or phone-based channels. Voice phishing simulations show a ",{"data":10298,"marks":10299,"value":10301,"nodeType":882},{},[10300],{"type":1012},"40% higher success rate",{"data":10303,"marks":10304,"value":10305,"nodeType":882},{},[]," than email phishing — a median click rate of 2% versus 1.4%.",{"data":10307,"content":10311,"nodeType":963},{"target":10308},{"sys":10309},{"id":10310,"type":960,"linkType":961},"7pK8qqIDDNmHmJmlcybNoe",[],{"data":10313,"content":10314,"nodeType":883},{},[10315,10319,10326],{"data":10316,"marks":10317,"value":10318,"nodeType":882},{},[],"Even within the email channel, the data confirms what ",{"data":10320,"content":10321,"nodeType":929},{"uri":8834},[10322],{"data":10323,"marks":10324,"value":10325,"nodeType":882},{},[],"browser-level detection data has been showing",{"data":10327,"marks":10328,"value":10329,"nodeType":882},{},[],": credential harvesting dominates. The DBIR's email security gateway breakdown shows 80% of blocked attacks are credential or session phishing, with only 10% involving malware delivery, 5% callback phishing, and 3% BEC. If you're running an email security gateway, the vast majority of what it catches is credential phishing — and 41% of social engineering is arriving through channels it can't see at all.",{"data":10331,"content":10335,"nodeType":963},{"target":10332},{"sys":10333},{"id":10334,"type":960,"linkType":961},"6CvwzQA3gJ8B3RFzLrH7Kp",[],{"data":10337,"content":10338,"nodeType":2050},{},[10339],{"data":10340,"marks":10341,"value":10343,"nodeType":882},{},[10342],{"type":1012},"The ClickFix detection gap",{"data":10345,"content":10346,"nodeType":883},{},[10347,10351,10359,10363],{"data":10348,"marks":10349,"value":10350,"nodeType":882},{},[],"The DBIR reports ClickFix at only 2.7% of attacks detected at the browser level. For context, ",{"data":10352,"content":10354,"nodeType":929},{"uri":10353},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fintroducing-malicious-copy-paste-detection\u002F",[10355],{"data":10356,"marks":10357,"value":10358,"nodeType":882},{},[],"CrowdStrike reported a 563% increase in ClickFix lures",{"data":10360,"marks":10361,"value":10362,"nodeType":882},{},[]," over the same period and Microsoft identified it as the most common initial access point at 47% of observed attacks. Push's own data shows ClickFix at a significantly higher proportion of browser-level detections, ",{"data":10364,"marks":10365,"value":10367,"nodeType":882},{},[10366],{"type":1012},"with 4 in 5 delivered via search engines specifically.",{"data":10369,"content":10370,"nodeType":883},{},[10371],{"data":10372,"marks":10373,"value":10374,"nodeType":882},{},[],"The gap is striking, and the most likely explanation is a visibility one. ClickFix attacks result in a malware download or script execution on the endpoint — and without browser-layer context, that execution looks like any other malware delivery. If a contributing organization doesn't have visibility into the browser session that preceded the payload, they'd attribute the incident to \"malware download\" or \"user execution\" rather than ClickFix specifically. The DBIR's 2.7% probably reflects how often contributors could trace the chain back to a ClickFix page, not how often ClickFix was actually the delivery mechanism.",{"data":10376,"content":10377,"nodeType":967},{},[],{"data":10379,"content":10380,"nodeType":975},{},[10381],{"data":10382,"marks":10383,"value":10385,"nodeType":882},{},[10384],{"type":1012},"Stolen credentials are the ransomware on-ramp",{"data":10387,"content":10388,"nodeType":883},{},[10389],{"data":10390,"marks":10391,"value":10392,"nodeType":882},{},[],"One of the most powerful findings in this year's DBIR is the quantification of the relationship between credential compromise and ransomware outcomes. Fifty percent of ransomware victims had a credential or infostealer event occur within 95 days prior to the ransomware attack, drawing a causal line from credential theft to ransomware deployment.",{"data":10394,"content":10398,"nodeType":963},{"target":10395},{"sys":10396},{"id":10397,"type":960,"linkType":961},"3ZwG5UiweFR4fYiDaxJJDm",[],{"data":10400,"content":10401,"nodeType":883},{},[10402],{"data":10403,"marks":10404,"value":10405,"nodeType":882},{},[],"The infostealer supply chain data reinforces the picture. Infostealers are surfacing an average of 2,362 breached corporate credentials per month from organizational email domains in stealer log datasets, and 54% of devices in Initial Access Broker logs had at least one infostealer installed. The 95-day median window is consistent with the known timeline from credential harvest to ransomware deployment.",{"data":10407,"content":10408,"nodeType":883},{},[10409,10413,10420],{"data":10410,"marks":10411,"value":10412,"nodeType":882},{},[],"That timeline reinforces an argument we've been making about ",{"data":10414,"content":10415,"nodeType":929},{"uri":7895},[10416],{"data":10417,"marks":10418,"value":10419,"nodeType":882},{},[],"where the intervention point needs to be",{"data":10421,"marks":10422,"value":10423,"nodeType":882},{},[],": detecting credential compromise upstream — at the point of credential entry, session creation, or stolen credential reuse — rather than waiting for the ransomware deployment that follows weeks or months later.",{"data":10425,"content":10426,"nodeType":2050},{},[10427],{"data":10428,"marks":10429,"value":10431,"nodeType":882},{},[10430],{"type":1012},"Post-compromise tradecraft is shifting",{"data":10433,"content":10434,"nodeType":883},{},[10435,10439,10444],{"data":10436,"marks":10437,"value":10438,"nodeType":882},{},[],"The DBIR's post-compromise data adds another dimension. RMM tool abuse by threat actors showed a ",{"data":10440,"marks":10441,"value":10443,"nodeType":882},{},[10442],{"type":1012},"240% increase",{"data":10445,"marks":10446,"value":10447,"nodeType":882},{},[]," over the prior year, while traditional backdoor and C2 malware usage fell 27%. Attackers are increasingly living off the land with the same remote access tools IT teams use. Post-compromise detection is getting harder, which makes catching the initial credential compromise upstream that much more valuable.",{"data":10449,"content":10450,"nodeType":967},{},[],{"data":10452,"content":10453,"nodeType":975},{},[10454],{"data":10455,"marks":10456,"value":10458,"nodeType":882},{},[10457],{"type":1012},"Your vendors are half the problem",{"data":10460,"content":10461,"nodeType":883},{},[10462,10466,10471],{"data":10463,"marks":10464,"value":10465,"nodeType":882},{},[],"Third-party involvement in breaches reached ",{"data":10467,"marks":10468,"value":10470,"nodeType":882},{},[10469],{"type":1012},"48%",{"data":10472,"marks":10473,"value":10474,"nodeType":882},{},[]," this year, up from 30% — a 60% increase that follows a prior year where the figure had already doubled.",{"data":10476,"content":10477,"nodeType":883},{},[10478],{"data":10479,"marks":10480,"value":10481,"nodeType":882},{},[],"The DBIR's root cause analysis maps directly to identity security: insecure authentication — absent MFA, improper credential rotation — and lack of least privilege enforcement account for a substantial share of cloud-based third-party incidents. Only 23% of third-party organizations fully remediated missing or improperly secured MFA on cloud accounts, and weak password and permission misconfigurations took a median of 8 months to resolve 50% of findings.",{"data":10483,"content":10484,"nodeType":883},{},[10485],{"data":10486,"marks":10487,"value":10488,"nodeType":882},{},[],"Eight months. That's the median timeline for third-party vendors to resolve the identity hygiene issues that create the attack surface in their environments — environments that your data lives in.",{"data":10490,"content":10491,"nodeType":883},{},[10492,10496,10503],{"data":10493,"marks":10494,"value":10495,"nodeType":882},{},[],"Extend that posture gap across every vendor and third-party integration, and you start to see why the third-party breach figure keeps climbing. Visibility into ",{"data":10497,"content":10498,"nodeType":929},{"uri":6466},[10499],{"data":10500,"marks":10501,"value":10502,"nodeType":882},{},[],"OAuth consent flows and third-party integration sprawl",{"data":10504,"marks":10505,"value":10506,"nodeType":882},{},[]," is the starting point for getting ahead of a supply chain problem that is structurally getting worse.",{"data":10508,"content":10509,"nodeType":967},{},[],{"data":10511,"content":10512,"nodeType":975},{},[10513],{"data":10514,"marks":10515,"value":10517,"nodeType":882},{},[10516],{"type":1012},"AI is scaling known techniques — and creating new blind spots from the inside",{"data":10519,"content":10520,"nodeType":883},{},[10521],{"data":10522,"marks":10523,"value":10524,"nodeType":882},{},[],"The DBIR's AI analysis this year is grounded in a collaboration with Anthropic covering 793 threat actors who received enforcement action for violating acceptable use policy between March 2025 and February 2026. The findings are measured rather than alarmist: in the median case, actors sought AI assistance across about 15 distinct ATT&CK techniques, 44% of AI-assisted initial access was phishing-related, and less than 2.5% of techniques observed were classified as rare.",{"data":10526,"content":10527,"nodeType":883},{},[10528],{"data":10529,"marks":10530,"value":10531,"nodeType":882},{},[],"AI is currently an operational tool for attackers — automating and scaling known techniques rather than unlocking novel ones. Despite heavy AI-assisted focus on phishing, the DBIR's own incident dataset shows phishing as an initial access vector has barely changed year over year — suggesting AI may be uplifting less-experienced attackers to a higher baseline of lure quality without meaningfully increasing success rates against organizations that already have detection in place.",{"data":10533,"content":10534,"nodeType":883},{},[10535],{"data":10536,"marks":10537,"value":10538,"nodeType":882},{},[],"The more concerning number is the 32% of AI-assisted initial access targeting vulnerability exploitation — compounding the patching capacity crisis discussed earlier in a trend that was already accelerating before AI entered the picture.",{"data":10540,"content":10544,"nodeType":963},{"target":10541},{"sys":10542},{"id":10543,"type":960,"linkType":961},"4bFTnVx1SXMQzZSaICCJOn",[],{"data":10546,"content":10547,"nodeType":2050},{},[10548],{"data":10549,"marks":10550,"value":10552,"nodeType":882},{},[10551],{"type":1012},"Shadow AI is the bigger problem",{"data":10554,"content":10555,"nodeType":883},{},[10556,10560,10565],{"data":10557,"marks":10558,"value":10559,"nodeType":882},{},[],"The sharper AI risk for most organizations, though, is internal. Forty-five percent of employees are now regular AI users on corporate devices — up from 15%, a threefold increase — and ",{"data":10561,"marks":10562,"value":10564,"nodeType":882},{},[10563],{"type":1012},"67% of them use non-corporate accounts",{"data":10566,"marks":10567,"value":10568,"nodeType":882},{},[],". Shadow AI has become the third most common non-malicious insider action in DLP data, a fourfold increase over the prior year, with source code as the leading data type submitted to unauthorized AI platforms by a wide margin.",{"data":10570,"content":10571,"nodeType":883},{},[10572],{"data":10573,"marks":10574,"value":10575,"nodeType":882},{},[],"The browser extension angle is particularly relevant. More than 15% of users had unauthorized AI browser extensions installed, and the DBIR specifically notes that these extensions collect and retain browsing context from internal sites — creating a data exfiltration pathway that operates independently of traditional DLP controls.",{"data":10577,"content":10578,"nodeType":883},{},[10579,10583,10590],{"data":10580,"marks":10581,"value":10582,"nodeType":882},{},[],"This is moving faster than any previous shadow IT wave, and the data loss vector is the browser — where users interact with AI tools, where extensions collect context, and where OAuth consent grants connect AI services to corporate data. Visibility and control at that layer isn't a nice-to-have for AI governance; ",{"data":10584,"content":10585,"nodeType":929},{"uri":9945},[10586],{"data":10587,"marks":10588,"value":10589,"nodeType":882},{},[],"it's the minimum viable starting point",{"data":10591,"marks":10592,"value":1438,"nodeType":882},{},[],{"data":10594,"content":10595,"nodeType":967},{},[],{"data":10597,"content":10598,"nodeType":975},{},[10599],{"data":10600,"marks":10601,"value":10603,"nodeType":882},{},[10602],{"type":1012},"What this means for defenders",{"data":10605,"content":10606,"nodeType":883},{},[10607],{"data":10608,"marks":10609,"value":10610,"nodeType":882},{},[],"The DBIR's 2026 data paints a picture of converging pressures rather than shifting priorities. Vulnerability exploitation surged, but identity-related initial access is broadly stable and credential abuse at 39% across full breach chains remains the single most pervasive technique in the dataset. Phishing is arriving through channels that email gateways can't see. The infostealer-to-ransomware pipeline now has longitudinal data behind it. Third-party involvement keeps climbing because vendor identity hygiene takes months to remediate. And shadow AI is creating data exposure pathways that most security stacks weren't designed to see.",{"data":10612,"content":10613,"nodeType":883},{},[10614],{"data":10615,"marks":10616,"value":10617,"nodeType":882},{},[],"The common thread across all of these findings is that the browser — where credentials are entered, sessions are created, OAuth consent is granted, AI tools are accessed, and extensions collect data — is the layer where these risks converge and where defenders need visibility and control if they're going to address them at the point of risk rather than after the fact.",{"data":10619,"content":10620,"nodeType":883},{},[10621],{"data":10622,"marks":10623,"value":2919,"nodeType":882},{},[],{"data":10625,"content":10626,"nodeType":883},{},[10627],{"data":10628,"marks":10629,"value":2926,"nodeType":882},{},[],{"data":10631,"content":10632,"nodeType":883},{},[10633,10636,10643],{"data":10634,"marks":10635,"value":21,"nodeType":882},{},[],{"data":10637,"content":10638,"nodeType":929},{"uri":1283},[10639],{"data":10640,"marks":10641,"value":2941,"nodeType":882},{},[10642],{"type":927},{"data":10644,"marks":10645,"value":21,"nodeType":882},{},[],"What the Verizon DBIR tells us about how breaches happen in 2026","What we can learn from 2026's installment of the Verizon Data Breach Investigations Report.","2026-05-20T00:00:00.000Z","verizon-dbir-2026-review",{"items":10651},[10652,10654],{"sys":10653,"name":298},{"id":7235},{"sys":10655,"name":2308},{"id":2307},{"items":10657},[10658],{"fullName":10659,"firstName":10660,"jobTitle":10661,"profilePicture":10662},"Mark Orlando","Mark","Field CTO",{"url":10663},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F592PMwIQQFaa24k5SKBEKF\u002Fa33090d0ad95d1e3081f5d16a46ba826\u002Fimage__68_.png",{"__typename":1365,"sys":10665,"content":10666,"title":7227,"synopsis":7228,"hashTags":59,"publishedDate":7229,"slug":7230,"tagsCollection":11735,"authorsCollection":11741},{"id":5992},{"json":10667},{"data":10668,"content":10669,"nodeType":1294},{},[10670,10683,10688,10694,10700,10705,10708,10715,10722,10737,10775,10780,10793,10796,10803,10810,10832,10864,10870,10873,10880,10887,10893,10898,10904,10907,10914,10921,10955,10985,10991,10994,11001,11008,11028,11034,11073,11079,11082,11089,11096,11132,11138,11143,11146,11153,11160,11186,11192,11197,11203,11206,11213,11220,11243,11249,11255,11261,11264,11271,11278,11284,11289,11295,11316,11339,11342,11349,11356,11362,11368,11371,11378,11433,11436,11443,11449,11717,11720],{"data":10671,"content":10672,"nodeType":883},{},[10673,10676,10680],{"data":10674,"marks":10675,"value":6003,"nodeType":882},{},[],{"data":10677,"marks":10678,"value":6008,"nodeType":882},{},[10679],{"type":1012},{"data":10681,"marks":10682,"value":6012,"nodeType":882},{},[],{"data":10684,"content":10687,"nodeType":963},{"target":10685},{"sys":10686},{"id":6017,"type":960,"linkType":961},[],{"data":10689,"content":10690,"nodeType":883},{},[10691],{"data":10692,"marks":10693,"value":6025,"nodeType":882},{},[],{"data":10695,"content":10696,"nodeType":883},{},[10697],{"data":10698,"marks":10699,"value":6032,"nodeType":882},{},[],{"data":10701,"content":10704,"nodeType":963},{"target":10702},{"sys":10703},{"id":6037,"type":960,"linkType":961},[],{"data":10706,"content":10707,"nodeType":967},{},[],{"data":10709,"content":10710,"nodeType":975},{},[10711],{"data":10712,"marks":10713,"value":6049,"nodeType":882},{},[10714],{"type":1012},{"data":10716,"content":10717,"nodeType":883},{},[10718],{"data":10719,"marks":10720,"value":6057,"nodeType":882},{},[10721],{"type":1012},{"data":10723,"content":10724,"nodeType":883},{},[10725,10728,10734],{"data":10726,"marks":10727,"value":6064,"nodeType":882},{},[],{"data":10729,"content":10730,"nodeType":929},{"uri":6067},[10731],{"data":10732,"marks":10733,"value":6072,"nodeType":882},{},[],{"data":10735,"marks":10736,"value":6076,"nodeType":882},{},[],{"data":10738,"content":10739,"nodeType":883},{},[10740,10743,10749,10752,10756,10759,10763,10766,10772],{"data":10741,"marks":10742,"value":4513,"nodeType":882},{},[],{"data":10744,"content":10745,"nodeType":929},{"uri":6085},[10746],{"data":10747,"marks":10748,"value":6090,"nodeType":882},{},[],{"data":10750,"marks":10751,"value":1993,"nodeType":882},{},[],{"data":10753,"marks":10754,"value":6098,"nodeType":882},{},[10755],{"type":1012},{"data":10757,"marks":10758,"value":2006,"nodeType":882},{},[],{"data":10760,"marks":10761,"value":6106,"nodeType":882},{},[10762],{"type":1012},{"data":10764,"marks":10765,"value":6110,"nodeType":882},{},[],{"data":10767,"content":10768,"nodeType":929},{"uri":6113},[10769],{"data":10770,"marks":10771,"value":6118,"nodeType":882},{},[],{"data":10773,"marks":10774,"value":6122,"nodeType":882},{},[],{"data":10776,"content":10779,"nodeType":963},{"target":10777},{"sys":10778},{"id":6127,"type":960,"linkType":961},[],{"data":10781,"content":10782,"nodeType":883},{},[10783,10786,10790],{"data":10784,"marks":10785,"value":6135,"nodeType":882},{},[],{"data":10787,"marks":10788,"value":6140,"nodeType":882},{},[10789],{"type":1012},{"data":10791,"marks":10792,"value":1438,"nodeType":882},{},[],{"data":10794,"content":10795,"nodeType":967},{},[],{"data":10797,"content":10798,"nodeType":975},{},[10799],{"data":10800,"marks":10801,"value":6154,"nodeType":882},{},[10802],{"type":1012},{"data":10804,"content":10805,"nodeType":883},{},[10806],{"data":10807,"marks":10808,"value":6057,"nodeType":882},{},[10809],{"type":1012},{"data":10811,"content":10812,"nodeType":883},{},[10813,10816,10822,10825,10829],{"data":10814,"marks":10815,"value":6168,"nodeType":882},{},[],{"data":10817,"content":10818,"nodeType":929},{"uri":6171},[10819],{"data":10820,"marks":10821,"value":6176,"nodeType":882},{},[],{"data":10823,"marks":10824,"value":6180,"nodeType":882},{},[],{"data":10826,"marks":10827,"value":6185,"nodeType":882},{},[10828],{"type":1012},{"data":10830,"marks":10831,"value":6189,"nodeType":882},{},[],{"data":10833,"content":10834,"nodeType":883},{},[10835,10838,10844,10847,10851,10854,10861],{"data":10836,"marks":10837,"value":6196,"nodeType":882},{},[],{"data":10839,"content":10840,"nodeType":929},{"uri":6199},[10841],{"data":10842,"marks":10843,"value":6204,"nodeType":882},{},[],{"data":10845,"marks":10846,"value":6208,"nodeType":882},{},[],{"data":10848,"marks":10849,"value":6213,"nodeType":882},{},[10850],{"type":1012},{"data":10852,"marks":10853,"value":6217,"nodeType":882},{},[],{"data":10855,"content":10856,"nodeType":929},{"uri":6220},[10857],{"data":10858,"marks":10859,"value":6226,"nodeType":882},{},[10860],{"type":1012},{"data":10862,"marks":10863,"value":6230,"nodeType":882},{},[],{"data":10865,"content":10866,"nodeType":883},{},[10867],{"data":10868,"marks":10869,"value":6237,"nodeType":882},{},[],{"data":10871,"content":10872,"nodeType":967},{},[],{"data":10874,"content":10875,"nodeType":975},{},[10876],{"data":10877,"marks":10878,"value":6248,"nodeType":882},{},[10879],{"type":1012},{"data":10881,"content":10882,"nodeType":883},{},[10883],{"data":10884,"marks":10885,"value":6256,"nodeType":882},{},[10886],{"type":1012},{"data":10888,"content":10889,"nodeType":883},{},[10890],{"data":10891,"marks":10892,"value":6263,"nodeType":882},{},[],{"data":10894,"content":10897,"nodeType":963},{"target":10895},{"sys":10896},{"id":6268,"type":960,"linkType":961},[],{"data":10899,"content":10900,"nodeType":883},{},[10901],{"data":10902,"marks":10903,"value":6276,"nodeType":882},{},[],{"data":10905,"content":10906,"nodeType":967},{},[],{"data":10908,"content":10909,"nodeType":975},{},[10910],{"data":10911,"marks":10912,"value":6287,"nodeType":882},{},[10913],{"type":1012},{"data":10915,"content":10916,"nodeType":883},{},[10917],{"data":10918,"marks":10919,"value":6256,"nodeType":882},{},[10920],{"type":1012},{"data":10922,"content":10923,"nodeType":883},{},[10924,10927,10934,10937,10943,10946,10952],{"data":10925,"marks":10926,"value":6301,"nodeType":882},{},[],{"data":10928,"content":10929,"nodeType":929},{"uri":6304},[10930],{"data":10931,"marks":10932,"value":6310,"nodeType":882},{},[10933],{"type":927},{"data":10935,"marks":10936,"value":1993,"nodeType":882},{},[],{"data":10938,"content":10939,"nodeType":929},{"uri":6316},[10940],{"data":10941,"marks":10942,"value":6321,"nodeType":882},{},[],{"data":10944,"marks":10945,"value":1993,"nodeType":882},{},[],{"data":10947,"content":10948,"nodeType":929},{"uri":6327},[10949],{"data":10950,"marks":10951,"value":6332,"nodeType":882},{},[],{"data":10953,"marks":10954,"value":6336,"nodeType":882},{},[],{"data":10956,"content":10957,"nodeType":883},{},[10958,10961,10968,10971,10975,10978,10982],{"data":10959,"marks":10960,"value":21,"nodeType":882},{},[],{"data":10962,"content":10963,"nodeType":929},{"uri":6345},[10964],{"data":10965,"marks":10966,"value":6351,"nodeType":882},{},[10967],{"type":927},{"data":10969,"marks":10970,"value":6355,"nodeType":882},{},[],{"data":10972,"marks":10973,"value":6360,"nodeType":882},{},[10974],{"type":1012},{"data":10976,"marks":10977,"value":6364,"nodeType":882},{},[],{"data":10979,"marks":10980,"value":6369,"nodeType":882},{},[10981],{"type":1045},{"data":10983,"marks":10984,"value":6373,"nodeType":882},{},[],{"data":10986,"content":10987,"nodeType":883},{},[10988],{"data":10989,"marks":10990,"value":6380,"nodeType":882},{},[],{"data":10992,"content":10993,"nodeType":967},{},[],{"data":10995,"content":10996,"nodeType":975},{},[10997],{"data":10998,"marks":10999,"value":6391,"nodeType":882},{},[11000],{"type":1012},{"data":11002,"content":11003,"nodeType":883},{},[11004],{"data":11005,"marks":11006,"value":6256,"nodeType":882},{},[11007],{"type":1012},{"data":11009,"content":11010,"nodeType":883},{},[11011,11014,11018,11021,11025],{"data":11012,"marks":11013,"value":6405,"nodeType":882},{},[],{"data":11015,"marks":11016,"value":6410,"nodeType":882},{},[11017],{"type":1045},{"data":11019,"marks":11020,"value":6414,"nodeType":882},{},[],{"data":11022,"marks":11023,"value":6419,"nodeType":882},{},[11024],{"type":1045},{"data":11026,"marks":11027,"value":6423,"nodeType":882},{},[],{"data":11029,"content":11030,"nodeType":883},{},[11031],{"data":11032,"marks":11033,"value":6430,"nodeType":882},{},[],{"data":11035,"content":11036,"nodeType":1454},{},[11037,11055],{"data":11038,"content":11039,"nodeType":1419},{},[11040],{"data":11041,"content":11042,"nodeType":883},{},[11043,11046,11052],{"data":11044,"marks":11045,"value":6443,"nodeType":882},{},[],{"data":11047,"content":11048,"nodeType":929},{"uri":3507},[11049],{"data":11050,"marks":11051,"value":6450,"nodeType":882},{},[],{"data":11053,"marks":11054,"value":6454,"nodeType":882},{},[],{"data":11056,"content":11057,"nodeType":1419},{},[11058],{"data":11059,"content":11060,"nodeType":883},{},[11061,11064,11070],{"data":11062,"marks":11063,"value":6443,"nodeType":882},{},[],{"data":11065,"content":11066,"nodeType":929},{"uri":6466},[11067],{"data":11068,"marks":11069,"value":6471,"nodeType":882},{},[],{"data":11071,"marks":11072,"value":6475,"nodeType":882},{},[],{"data":11074,"content":11075,"nodeType":883},{},[11076],{"data":11077,"marks":11078,"value":6482,"nodeType":882},{},[],{"data":11080,"content":11081,"nodeType":967},{},[],{"data":11083,"content":11084,"nodeType":975},{},[11085],{"data":11086,"marks":11087,"value":6493,"nodeType":882},{},[11088],{"type":1012},{"data":11090,"content":11091,"nodeType":883},{},[11092],{"data":11093,"marks":11094,"value":6501,"nodeType":882},{},[11095],{"type":1012},{"data":11097,"content":11098,"nodeType":883},{},[11099,11102,11106,11109,11115,11118,11122,11125,11129],{"data":11100,"marks":11101,"value":6508,"nodeType":882},{},[],{"data":11103,"marks":11104,"value":6513,"nodeType":882},{},[11105],{"type":1012},{"data":11107,"marks":11108,"value":6517,"nodeType":882},{},[],{"data":11110,"content":11111,"nodeType":929},{"uri":6520},[11112],{"data":11113,"marks":11114,"value":6525,"nodeType":882},{},[],{"data":11116,"marks":11117,"value":6529,"nodeType":882},{},[],{"data":11119,"marks":11120,"value":6534,"nodeType":882},{},[11121],{"type":1012},{"data":11123,"marks":11124,"value":6538,"nodeType":882},{},[],{"data":11126,"marks":11127,"value":6543,"nodeType":882},{},[11128],{"type":1012},{"data":11130,"marks":11131,"value":6547,"nodeType":882},{},[],{"data":11133,"content":11134,"nodeType":883},{},[11135],{"data":11136,"marks":11137,"value":6554,"nodeType":882},{},[],{"data":11139,"content":11142,"nodeType":963},{"target":11140},{"sys":11141},{"id":6559,"type":960,"linkType":961},[],{"data":11144,"content":11145,"nodeType":967},{},[],{"data":11147,"content":11148,"nodeType":975},{},[11149],{"data":11150,"marks":11151,"value":6571,"nodeType":882},{},[11152],{"type":1012},{"data":11154,"content":11155,"nodeType":883},{},[11156],{"data":11157,"marks":11158,"value":6579,"nodeType":882},{},[11159],{"type":1012},{"data":11161,"content":11162,"nodeType":883},{},[11163,11166,11173,11176,11183],{"data":11164,"marks":11165,"value":6586,"nodeType":882},{},[],{"data":11167,"content":11168,"nodeType":929},{"uri":6589},[11169],{"data":11170,"marks":11171,"value":6595,"nodeType":882},{},[11172],{"type":1012},{"data":11174,"marks":11175,"value":6599,"nodeType":882},{},[],{"data":11177,"content":11178,"nodeType":929},{"uri":6602},[11179],{"data":11180,"marks":11181,"value":6608,"nodeType":882},{},[11182],{"type":1012},{"data":11184,"marks":11185,"value":6612,"nodeType":882},{},[],{"data":11187,"content":11188,"nodeType":883},{},[11189],{"data":11190,"marks":11191,"value":6619,"nodeType":882},{},[],{"data":11193,"content":11196,"nodeType":963},{"target":11194},{"sys":11195},{"id":6624,"type":960,"linkType":961},[],{"data":11198,"content":11199,"nodeType":883},{},[11200],{"data":11201,"marks":11202,"value":6632,"nodeType":882},{},[],{"data":11204,"content":11205,"nodeType":967},{},[],{"data":11207,"content":11208,"nodeType":975},{},[11209],{"data":11210,"marks":11211,"value":6643,"nodeType":882},{},[11212],{"type":1012},{"data":11214,"content":11215,"nodeType":883},{},[11216],{"data":11217,"marks":11218,"value":6651,"nodeType":882},{},[11219],{"type":1012},{"data":11221,"content":11222,"nodeType":883},{},[11223,11226,11230,11233,11240],{"data":11224,"marks":11225,"value":6658,"nodeType":882},{},[],{"data":11227,"marks":11228,"value":6663,"nodeType":882},{},[11229],{"type":1045},{"data":11231,"marks":11232,"value":6667,"nodeType":882},{},[],{"data":11234,"content":11235,"nodeType":929},{"uri":6670},[11236],{"data":11237,"marks":11238,"value":6676,"nodeType":882},{},[11239],{"type":1012},{"data":11241,"marks":11242,"value":6680,"nodeType":882},{},[],{"data":11244,"content":11245,"nodeType":883},{},[11246],{"data":11247,"marks":11248,"value":6687,"nodeType":882},{},[],{"data":11250,"content":11251,"nodeType":883},{},[11252],{"data":11253,"marks":11254,"value":6694,"nodeType":882},{},[],{"data":11256,"content":11257,"nodeType":883},{},[11258],{"data":11259,"marks":11260,"value":6701,"nodeType":882},{},[],{"data":11262,"content":11263,"nodeType":967},{},[],{"data":11265,"content":11266,"nodeType":975},{},[11267],{"data":11268,"marks":11269,"value":6712,"nodeType":882},{},[11270],{"type":1012},{"data":11272,"content":11273,"nodeType":883},{},[11274],{"data":11275,"marks":11276,"value":6720,"nodeType":882},{},[11277],{"type":1012},{"data":11279,"content":11280,"nodeType":883},{},[11281],{"data":11282,"marks":11283,"value":6727,"nodeType":882},{},[],{"data":11285,"content":11288,"nodeType":963},{"target":11286},{"sys":11287},{"id":6732,"type":960,"linkType":961},[],{"data":11290,"content":11291,"nodeType":883},{},[11292],{"data":11293,"marks":11294,"value":6740,"nodeType":882},{},[],{"data":11296,"content":11297,"nodeType":1454},{},[11298,11307],{"data":11299,"content":11300,"nodeType":1419},{},[11301],{"data":11302,"content":11303,"nodeType":883},{},[11304],{"data":11305,"marks":11306,"value":6753,"nodeType":882},{},[],{"data":11308,"content":11309,"nodeType":1419},{},[11310],{"data":11311,"content":11312,"nodeType":883},{},[11313],{"data":11314,"marks":11315,"value":6763,"nodeType":882},{},[],{"data":11317,"content":11318,"nodeType":883},{},[11319,11322,11329,11332,11336],{"data":11320,"marks":11321,"value":6770,"nodeType":882},{},[],{"data":11323,"content":11324,"nodeType":929},{"uri":6773},[11325],{"data":11326,"marks":11327,"value":6779,"nodeType":882},{},[11328],{"type":1012},{"data":11330,"marks":11331,"value":6783,"nodeType":882},{},[],{"data":11333,"marks":11334,"value":6788,"nodeType":882},{},[11335],{"type":1045},{"data":11337,"marks":11338,"value":6792,"nodeType":882},{},[],{"data":11340,"content":11341,"nodeType":967},{},[],{"data":11343,"content":11344,"nodeType":975},{},[11345],{"data":11346,"marks":11347,"value":6803,"nodeType":882},{},[11348],{"type":1012},{"data":11350,"content":11351,"nodeType":883},{},[11352],{"data":11353,"marks":11354,"value":6811,"nodeType":882},{},[11355],{"type":1012},{"data":11357,"content":11358,"nodeType":883},{},[11359],{"data":11360,"marks":11361,"value":6818,"nodeType":882},{},[],{"data":11363,"content":11364,"nodeType":883},{},[11365],{"data":11366,"marks":11367,"value":6825,"nodeType":882},{},[],{"data":11369,"content":11370,"nodeType":967},{},[],{"data":11372,"content":11373,"nodeType":975},{},[11374],{"data":11375,"marks":11376,"value":6836,"nodeType":882},{},[11377],{"type":1012},{"data":11379,"content":11380,"nodeType":1454},{},[11381,11394,11407,11420],{"data":11382,"content":11383,"nodeType":1419},{},[11384],{"data":11385,"content":11386,"nodeType":883},{},[11387,11391],{"data":11388,"marks":11389,"value":6850,"nodeType":882},{},[11390],{"type":1012},{"data":11392,"marks":11393,"value":6854,"nodeType":882},{},[],{"data":11395,"content":11396,"nodeType":1419},{},[11397],{"data":11398,"content":11399,"nodeType":883},{},[11400,11404],{"data":11401,"marks":11402,"value":6865,"nodeType":882},{},[11403],{"type":1012},{"data":11405,"marks":11406,"value":6869,"nodeType":882},{},[],{"data":11408,"content":11409,"nodeType":1419},{},[11410],{"data":11411,"content":11412,"nodeType":883},{},[11413,11417],{"data":11414,"marks":11415,"value":6880,"nodeType":882},{},[11416],{"type":1012},{"data":11418,"marks":11419,"value":6884,"nodeType":882},{},[],{"data":11421,"content":11422,"nodeType":1419},{},[11423],{"data":11424,"content":11425,"nodeType":883},{},[11426,11430],{"data":11427,"marks":11428,"value":794,"nodeType":882},{},[11429],{"type":1012},{"data":11431,"marks":11432,"value":6898,"nodeType":882},{},[],{"data":11434,"content":11435,"nodeType":967},{},[],{"data":11437,"content":11438,"nodeType":975},{},[11439],{"data":11440,"marks":11441,"value":6909,"nodeType":882},{},[11442],{"type":1012},{"data":11444,"content":11445,"nodeType":883},{},[11446],{"data":11447,"marks":11448,"value":6916,"nodeType":882},{},[],{"data":11450,"content":11451,"nodeType":3104},{},[11452,11475,11497,11519,11541,11563,11585,11607,11629,11651,11673,11695],{"data":11453,"content":11454,"nodeType":3011},{},[11455,11465],{"data":11456,"content":11457,"nodeType":3025},{},[11458],{"data":11459,"content":11460,"nodeType":883},{},[11461],{"data":11462,"marks":11463,"value":6933,"nodeType":882},{},[11464],{"type":1012},{"data":11466,"content":11467,"nodeType":3025},{},[11468],{"data":11469,"content":11470,"nodeType":883},{},[11471],{"data":11472,"marks":11473,"value":6944,"nodeType":882},{},[11474],{"type":1012},{"data":11476,"content":11477,"nodeType":3011},{},[11478,11488],{"data":11479,"content":11480,"nodeType":3025},{},[11481],{"data":11482,"content":11483,"nodeType":883},{},[11484],{"data":11485,"marks":11486,"value":6958,"nodeType":882},{},[11487],{"type":1012},{"data":11489,"content":11490,"nodeType":3025},{},[11491],{"data":11492,"content":11493,"nodeType":883},{},[11494],{"data":11495,"marks":11496,"value":6968,"nodeType":882},{},[],{"data":11498,"content":11499,"nodeType":3011},{},[11500,11510],{"data":11501,"content":11502,"nodeType":3025},{},[11503],{"data":11504,"content":11505,"nodeType":883},{},[11506],{"data":11507,"marks":11508,"value":6982,"nodeType":882},{},[11509],{"type":1012},{"data":11511,"content":11512,"nodeType":3025},{},[11513],{"data":11514,"content":11515,"nodeType":883},{},[11516],{"data":11517,"marks":11518,"value":6992,"nodeType":882},{},[],{"data":11520,"content":11521,"nodeType":3011},{},[11522,11532],{"data":11523,"content":11524,"nodeType":3025},{},[11525],{"data":11526,"content":11527,"nodeType":883},{},[11528],{"data":11529,"marks":11530,"value":7006,"nodeType":882},{},[11531],{"type":1012},{"data":11533,"content":11534,"nodeType":3025},{},[11535],{"data":11536,"content":11537,"nodeType":883},{},[11538],{"data":11539,"marks":11540,"value":7016,"nodeType":882},{},[],{"data":11542,"content":11543,"nodeType":3011},{},[11544,11554],{"data":11545,"content":11546,"nodeType":3025},{},[11547],{"data":11548,"content":11549,"nodeType":883},{},[11550],{"data":11551,"marks":11552,"value":7030,"nodeType":882},{},[11553],{"type":1012},{"data":11555,"content":11556,"nodeType":3025},{},[11557],{"data":11558,"content":11559,"nodeType":883},{},[11560],{"data":11561,"marks":11562,"value":7040,"nodeType":882},{},[],{"data":11564,"content":11565,"nodeType":3011},{},[11566,11576],{"data":11567,"content":11568,"nodeType":3025},{},[11569],{"data":11570,"content":11571,"nodeType":883},{},[11572],{"data":11573,"marks":11574,"value":7054,"nodeType":882},{},[11575],{"type":1012},{"data":11577,"content":11578,"nodeType":3025},{},[11579],{"data":11580,"content":11581,"nodeType":883},{},[11582],{"data":11583,"marks":11584,"value":7064,"nodeType":882},{},[],{"data":11586,"content":11587,"nodeType":3011},{},[11588,11598],{"data":11589,"content":11590,"nodeType":3025},{},[11591],{"data":11592,"content":11593,"nodeType":883},{},[11594],{"data":11595,"marks":11596,"value":7078,"nodeType":882},{},[11597],{"type":1012},{"data":11599,"content":11600,"nodeType":3025},{},[11601],{"data":11602,"content":11603,"nodeType":883},{},[11604],{"data":11605,"marks":11606,"value":7088,"nodeType":882},{},[],{"data":11608,"content":11609,"nodeType":3011},{},[11610,11620],{"data":11611,"content":11612,"nodeType":3025},{},[11613],{"data":11614,"content":11615,"nodeType":883},{},[11616],{"data":11617,"marks":11618,"value":7102,"nodeType":882},{},[11619],{"type":1012},{"data":11621,"content":11622,"nodeType":3025},{},[11623],{"data":11624,"content":11625,"nodeType":883},{},[11626],{"data":11627,"marks":11628,"value":7112,"nodeType":882},{},[],{"data":11630,"content":11631,"nodeType":3011},{},[11632,11642],{"data":11633,"content":11634,"nodeType":3025},{},[11635],{"data":11636,"content":11637,"nodeType":883},{},[11638],{"data":11639,"marks":11640,"value":7126,"nodeType":882},{},[11641],{"type":1012},{"data":11643,"content":11644,"nodeType":3025},{},[11645],{"data":11646,"content":11647,"nodeType":883},{},[11648],{"data":11649,"marks":11650,"value":7136,"nodeType":882},{},[],{"data":11652,"content":11653,"nodeType":3011},{},[11654,11664],{"data":11655,"content":11656,"nodeType":3025},{},[11657],{"data":11658,"content":11659,"nodeType":883},{},[11660],{"data":11661,"marks":11662,"value":7150,"nodeType":882},{},[11663],{"type":1012},{"data":11665,"content":11666,"nodeType":3025},{},[11667],{"data":11668,"content":11669,"nodeType":883},{},[11670],{"data":11671,"marks":11672,"value":7160,"nodeType":882},{},[],{"data":11674,"content":11675,"nodeType":3011},{},[11676,11686],{"data":11677,"content":11678,"nodeType":3025},{},[11679],{"data":11680,"content":11681,"nodeType":883},{},[11682],{"data":11683,"marks":11684,"value":7174,"nodeType":882},{},[11685],{"type":1012},{"data":11687,"content":11688,"nodeType":3025},{},[11689],{"data":11690,"content":11691,"nodeType":883},{},[11692],{"data":11693,"marks":11694,"value":7184,"nodeType":882},{},[],{"data":11696,"content":11697,"nodeType":3011},{},[11698,11708],{"data":11699,"content":11700,"nodeType":3025},{},[11701],{"data":11702,"content":11703,"nodeType":883},{},[11704],{"data":11705,"marks":11706,"value":6865,"nodeType":882},{},[11707],{"type":1012},{"data":11709,"content":11710,"nodeType":3025},{},[11711],{"data":11712,"content":11713,"nodeType":883},{},[11714],{"data":11715,"marks":11716,"value":7207,"nodeType":882},{},[],{"data":11718,"content":11719,"nodeType":967},{},[],{"data":11721,"content":11722,"nodeType":883},{},[11723,11726,11732],{"data":11724,"marks":11725,"value":7217,"nodeType":882},{},[],{"data":11727,"content":11728,"nodeType":929},{"uri":1283},[11729],{"data":11730,"marks":11731,"value":2941,"nodeType":882},{},[],{"data":11733,"marks":11734,"value":21,"nodeType":882},{},[],{"items":11736},[11737,11739],{"sys":11738,"name":298},{"id":7235},{"sys":11740,"name":7239},{"id":7238},{"items":11742},[11743],{"fullName":3964,"firstName":3965,"jobTitle":868,"profilePicture":11744},{"url":3969},"making-the-business-case-for-a-browser-security-solution","blog\u002Fmaking-the-business-case-for-a-browser-security-solution",{"json":11748},{"data":11749,"content":11750,"nodeType":1294},{},[11751],{"data":11752,"content":11753,"nodeType":883},{},[11754],{"data":11755,"marks":11756,"value":11757,"nodeType":882},{},[],"Browser security is one of the fastest-growing investment areas in enterprise security. It's clear that security teams need browser security solutions, but the challenge is often figuring out how to fund it.","Browser security is one of the fastest-growing investment areas in enterprise security. Here's our proven framework to create budget for browser security tools.",{"id":11760,"publishedAt":11761},"3u4XQlYOFzwY1nKVFaovos","2026-08-12T12:00:51.400Z",{"items":11763},[11764,11766],{"sys":11765,"name":298},{"id":7235},{"sys":11767,"name":7239},{"id":7238},{"items":11769},[11770,11772,11774,11776,11778,11780,11782,11784,11786,11788,11790,11792,11794,11796,11798,11800],{"sys":11771,"name":298,"slug":299,"tier":31},{"id":295},{"sys":11773,"name":415,"slug":416,"tier":31},{"id":412},{"sys":11775,"name":235,"slug":236,"tier":31},{"id":232},{"sys":11777,"name":280,"slug":281,"tier":31},{"id":277},{"sys":11779,"name":623,"slug":624,"tier":45},{"id":620},{"sys":11781,"name":307,"slug":308,"tier":45},{"id":304},{"sys":11783,"name":379,"slug":380,"tier":45},{"id":376},{"sys":11785,"name":582,"slug":583,"tier":45},{"id":579},{"sys":11787,"name":253,"slug":254,"tier":45},{"id":250},{"sys":11789,"name":591,"slug":592,"tier":45},{"id":588},{"sys":11791,"name":262,"slug":263,"tier":45},{"id":259},{"sys":11793,"name":316,"slug":317,"tier":45},{"id":313},{"sys":11795,"name":459,"slug":460,"tier":45},{"id":456},{"sys":11797,"name":503,"slug":504,"tier":45},{"id":500},{"sys":11799,"name":632,"slug":633,"tier":45},{"id":629},{"sys":11801,"name":388,"slug":389,"tier":45},{"id":385},"bBKwW9E1rG-3LgBNn6aPFkmENwD8ArxqVXJcqXlDmIg",{"id":11804,"title":4605,"authorsCollection":11805,"content":11810,"extension":228,"faqItemsCollection":12425,"faqTitle":59,"featured":6,"hashTags":59,"meta":12427,"metaTitle":12428,"ogImage":59,"postType":1360,"publishedDate":10101,"relatedBlogPostsCollection":12429,"slug":10102,"stem":14766,"subtitle":59,"summary":14767,"synopsis":10100,"sys":14778,"tagsCollection":14780,"topicsCollection":14786,"__hash__":14812},"blog\u002Fblog\u002Fenterprise-browser-vs-browser-extension-which-should-your-security-team-choose.json",{"items":11806},[11807],{"fullName":3964,"firstName":3965,"jobTitle":868,"socialLinks":11808,"profilePicture":11809},[3967],{"url":3969},{"json":11811,"links":12398},{"data":11812,"content":11813,"nodeType":1294},{},[11814,11820,11826,11845,11851,11857,11863,11866,11873,11879,11895,11901,11907,11949,11955,11962,11968,11974,11980,11983,11990,11996,12006,12012,12019,12035,12040,12073,12078,12084,12094,12099,12105,12120,12127,12133,12149,12154,12161,12167,12298,12301,12308,12314,12320,12323,12330,12336,12346,12356,12366,12376,12382],{"data":11815,"content":11816,"nodeType":883},{},[11817],{"data":11818,"marks":11819,"value":9426,"nodeType":882},{},[],{"data":11821,"content":11822,"nodeType":883},{},[11823],{"data":11824,"marks":11825,"value":9433,"nodeType":882},{},[],{"data":11827,"content":11828,"nodeType":3695},{},[11829],{"data":11830,"content":11831,"nodeType":883},{},[11832,11835,11842],{"data":11833,"marks":11834,"value":9443,"nodeType":882},{},[],{"data":11836,"content":11837,"nodeType":929},{"uri":6589},[11838],{"data":11839,"marks":11840,"value":9451,"nodeType":882},{},[11841],{"type":927},{"data":11843,"marks":11844,"value":9455,"nodeType":882},{},[],{"data":11846,"content":11847,"nodeType":883},{},[11848],{"data":11849,"marks":11850,"value":9462,"nodeType":882},{},[],{"data":11852,"content":11853,"nodeType":883},{},[11854],{"data":11855,"marks":11856,"value":9469,"nodeType":882},{},[],{"data":11858,"content":11859,"nodeType":883},{},[11860],{"data":11861,"marks":11862,"value":9476,"nodeType":882},{},[],{"data":11864,"content":11865,"nodeType":967},{},[],{"data":11867,"content":11868,"nodeType":975},{},[11869],{"data":11870,"marks":11871,"value":9487,"nodeType":882},{},[11872],{"type":1012},{"data":11874,"content":11875,"nodeType":883},{},[11876],{"data":11877,"marks":11878,"value":9494,"nodeType":882},{},[],{"data":11880,"content":11881,"nodeType":3695},{},[11882],{"data":11883,"content":11884,"nodeType":883},{},[11885,11888,11892],{"data":11886,"marks":11887,"value":9504,"nodeType":882},{},[],{"data":11889,"marks":11890,"value":9509,"nodeType":882},{},[11891],{"type":1045},{"data":11893,"marks":11894,"value":9513,"nodeType":882},{},[],{"data":11896,"content":11897,"nodeType":883},{},[11898],{"data":11899,"marks":11900,"value":9520,"nodeType":882},{},[],{"data":11902,"content":11903,"nodeType":883},{},[11904],{"data":11905,"marks":11906,"value":9527,"nodeType":882},{},[],{"data":11908,"content":11909,"nodeType":1454},{},[11910,11923,11936],{"data":11911,"content":11912,"nodeType":1419},{},[11913],{"data":11914,"content":11915,"nodeType":883},{},[11916,11920],{"data":11917,"marks":11918,"value":9541,"nodeType":882},{},[11919],{"type":1012},{"data":11921,"marks":11922,"value":9545,"nodeType":882},{},[],{"data":11924,"content":11925,"nodeType":1419},{},[11926],{"data":11927,"content":11928,"nodeType":883},{},[11929,11933],{"data":11930,"marks":11931,"value":9556,"nodeType":882},{},[11932],{"type":1012},{"data":11934,"marks":11935,"value":9560,"nodeType":882},{},[],{"data":11937,"content":11938,"nodeType":1419},{},[11939],{"data":11940,"content":11941,"nodeType":883},{},[11942,11946],{"data":11943,"marks":11944,"value":9571,"nodeType":882},{},[11945],{"type":1012},{"data":11947,"marks":11948,"value":9575,"nodeType":882},{},[],{"data":11950,"content":11951,"nodeType":883},{},[11952],{"data":11953,"marks":11954,"value":9582,"nodeType":882},{},[],{"data":11956,"content":11957,"nodeType":2050},{},[11958],{"data":11959,"marks":11960,"value":9590,"nodeType":882},{},[11961],{"type":1012},{"data":11963,"content":11964,"nodeType":883},{},[11965],{"data":11966,"marks":11967,"value":9597,"nodeType":882},{},[],{"data":11969,"content":11970,"nodeType":883},{},[11971],{"data":11972,"marks":11973,"value":9604,"nodeType":882},{},[],{"data":11975,"content":11976,"nodeType":883},{},[11977],{"data":11978,"marks":11979,"value":9611,"nodeType":882},{},[],{"data":11981,"content":11982,"nodeType":967},{},[],{"data":11984,"content":11985,"nodeType":975},{},[11986],{"data":11987,"marks":11988,"value":9622,"nodeType":882},{},[11989],{"type":1012},{"data":11991,"content":11992,"nodeType":883},{},[11993],{"data":11994,"marks":11995,"value":9629,"nodeType":882},{},[],{"data":11997,"content":11998,"nodeType":883},{},[11999,12002],{"data":12000,"marks":12001,"value":9636,"nodeType":882},{},[],{"data":12003,"marks":12004,"value":9641,"nodeType":882},{},[12005],{"type":1045},{"data":12007,"content":12008,"nodeType":883},{},[12009],{"data":12010,"marks":12011,"value":9648,"nodeType":882},{},[],{"data":12013,"content":12014,"nodeType":2050},{},[12015],{"data":12016,"marks":12017,"value":9656,"nodeType":882},{},[12018],{"type":1012},{"data":12020,"content":12021,"nodeType":883},{},[12022,12025,12032],{"data":12023,"marks":12024,"value":9663,"nodeType":882},{},[],{"data":12026,"content":12027,"nodeType":929},{"uri":3358},[12028],{"data":12029,"marks":12030,"value":9671,"nodeType":882},{},[12031],{"type":927},{"data":12033,"marks":12034,"value":9675,"nodeType":882},{},[],{"data":12036,"content":12039,"nodeType":963},{"target":12037},{"sys":12038},{"id":9680,"type":960,"linkType":961},[],{"data":12041,"content":12042,"nodeType":883},{},[12043,12046,12053,12056,12060,12063,12070],{"data":12044,"marks":12045,"value":9688,"nodeType":882},{},[],{"data":12047,"content":12048,"nodeType":929},{"uri":9691},[12049],{"data":12050,"marks":12051,"value":9697,"nodeType":882},{},[12052],{"type":927},{"data":12054,"marks":12055,"value":9701,"nodeType":882},{},[],{"data":12057,"marks":12058,"value":9706,"nodeType":882},{},[12059],{"type":1012},{"data":12061,"marks":12062,"value":9710,"nodeType":882},{},[],{"data":12064,"content":12065,"nodeType":929},{"uri":9187},[12066],{"data":12067,"marks":12068,"value":9718,"nodeType":882},{},[12069],{"type":927},{"data":12071,"marks":12072,"value":9675,"nodeType":882},{},[],{"data":12074,"content":12077,"nodeType":963},{"target":12075},{"sys":12076},{"id":4417,"type":960,"linkType":961},[],{"data":12079,"content":12080,"nodeType":883},{},[12081],{"data":12082,"marks":12083,"value":9733,"nodeType":882},{},[],{"data":12085,"content":12086,"nodeType":883},{},[12087,12090],{"data":12088,"marks":12089,"value":9740,"nodeType":882},{},[],{"data":12091,"marks":12092,"value":9745,"nodeType":882},{},[12093],{"type":1012},{"data":12095,"content":12098,"nodeType":963},{"target":12096},{"sys":12097},{"id":9750,"type":960,"linkType":961},[],{"data":12100,"content":12101,"nodeType":883},{},[12102],{"data":12103,"marks":12104,"value":9758,"nodeType":882},{},[],{"data":12106,"content":12107,"nodeType":883},{},[12108,12111,12117],{"data":12109,"marks":12110,"value":6443,"nodeType":882},{},[],{"data":12112,"content":12113,"nodeType":929},{"uri":8834},[12114],{"data":12115,"marks":12116,"value":9771,"nodeType":882},{},[],{"data":12118,"marks":12119,"value":9775,"nodeType":882},{},[],{"data":12121,"content":12122,"nodeType":2050},{},[12123],{"data":12124,"marks":12125,"value":9783,"nodeType":882},{},[12126],{"type":1012},{"data":12128,"content":12129,"nodeType":883},{},[12130],{"data":12131,"marks":12132,"value":9790,"nodeType":882},{},[],{"data":12134,"content":12135,"nodeType":883},{},[12136,12139,12146],{"data":12137,"marks":12138,"value":9797,"nodeType":882},{},[],{"data":12140,"content":12141,"nodeType":929},{"uri":4493},[12142],{"data":12143,"marks":12144,"value":9805,"nodeType":882},{},[12145],{"type":927},{"data":12147,"marks":12148,"value":9809,"nodeType":882},{},[],{"data":12150,"content":12153,"nodeType":963},{"target":12151},{"sys":12152},{"id":9814,"type":960,"linkType":961},[],{"data":12155,"content":12156,"nodeType":2050},{},[12157],{"data":12158,"marks":12159,"value":9823,"nodeType":882},{},[12160],{"type":1012},{"data":12162,"content":12163,"nodeType":883},{},[12164],{"data":12165,"marks":12166,"value":9830,"nodeType":882},{},[],{"data":12168,"content":12169,"nodeType":1454},{},[12170,12210,12241,12272,12285],{"data":12171,"content":12172,"nodeType":1419},{},[12173],{"data":12174,"content":12175,"nodeType":883},{},[12176,12180,12183,12189,12192,12198,12201,12207],{"data":12177,"marks":12178,"value":9844,"nodeType":882},{},[12179],{"type":1012},{"data":12181,"marks":12182,"value":9848,"nodeType":882},{},[],{"data":12184,"content":12185,"nodeType":929},{"uri":3582},[12186],{"data":12187,"marks":12188,"value":1989,"nodeType":882},{},[],{"data":12190,"marks":12191,"value":8976,"nodeType":882},{},[],{"data":12193,"content":12194,"nodeType":929},{"uri":3823},[12195],{"data":12196,"marks":12197,"value":9864,"nodeType":882},{},[],{"data":12199,"marks":12200,"value":9868,"nodeType":882},{},[],{"data":12202,"content":12203,"nodeType":929},{"uri":8231},[12204],{"data":12205,"marks":12206,"value":9875,"nodeType":882},{},[],{"data":12208,"marks":12209,"value":9879,"nodeType":882},{},[],{"data":12211,"content":12212,"nodeType":1419},{},[12213],{"data":12214,"content":12215,"nodeType":883},{},[12216,12220,12223,12229,12232,12238],{"data":12217,"marks":12218,"value":9890,"nodeType":882},{},[12219],{"type":1012},{"data":12221,"marks":12222,"value":9894,"nodeType":882},{},[],{"data":12224,"content":12225,"nodeType":929},{"uri":2893},[12226],{"data":12227,"marks":12228,"value":9013,"nodeType":882},{},[],{"data":12230,"marks":12231,"value":9904,"nodeType":882},{},[],{"data":12233,"content":12234,"nodeType":929},{"uri":9907},[12235],{"data":12236,"marks":12237,"value":9912,"nodeType":882},{},[],{"data":12239,"marks":12240,"value":9916,"nodeType":882},{},[],{"data":12242,"content":12243,"nodeType":1419},{},[12244],{"data":12245,"content":12246,"nodeType":883},{},[12247,12251,12254,12260,12263,12269],{"data":12248,"marks":12249,"value":9927,"nodeType":882},{},[12250],{"type":1012},{"data":12252,"marks":12253,"value":9931,"nodeType":882},{},[],{"data":12255,"content":12256,"nodeType":929},{"uri":8979},[12257],{"data":12258,"marks":12259,"value":9938,"nodeType":882},{},[],{"data":12261,"marks":12262,"value":9942,"nodeType":882},{},[],{"data":12264,"content":12265,"nodeType":929},{"uri":9945},[12266],{"data":12267,"marks":12268,"value":9950,"nodeType":882},{},[],{"data":12270,"marks":12271,"value":9954,"nodeType":882},{},[],{"data":12273,"content":12274,"nodeType":1419},{},[12275],{"data":12276,"content":12277,"nodeType":883},{},[12278,12282],{"data":12279,"marks":12280,"value":9965,"nodeType":882},{},[12281],{"type":1012},{"data":12283,"marks":12284,"value":9969,"nodeType":882},{},[],{"data":12286,"content":12287,"nodeType":1419},{},[12288],{"data":12289,"content":12290,"nodeType":883},{},[12291,12295],{"data":12292,"marks":12293,"value":9980,"nodeType":882},{},[12294],{"type":1012},{"data":12296,"marks":12297,"value":9984,"nodeType":882},{},[],{"data":12299,"content":12300,"nodeType":967},{},[],{"data":12302,"content":12303,"nodeType":975},{},[12304],{"data":12305,"marks":12306,"value":9995,"nodeType":882},{},[12307],{"type":1012},{"data":12309,"content":12310,"nodeType":883},{},[12311],{"data":12312,"marks":12313,"value":10002,"nodeType":882},{},[],{"data":12315,"content":12316,"nodeType":883},{},[12317],{"data":12318,"marks":12319,"value":10009,"nodeType":882},{},[],{"data":12321,"content":12322,"nodeType":967},{},[],{"data":12324,"content":12325,"nodeType":975},{},[12326],{"data":12327,"marks":12328,"value":10020,"nodeType":882},{},[12329],{"type":1012},{"data":12331,"content":12332,"nodeType":883},{},[12333],{"data":12334,"marks":12335,"value":10027,"nodeType":882},{},[],{"data":12337,"content":12338,"nodeType":883},{},[12339,12343],{"data":12340,"marks":12341,"value":10035,"nodeType":882},{},[12342],{"type":1012},{"data":12344,"marks":12345,"value":10039,"nodeType":882},{},[],{"data":12347,"content":12348,"nodeType":883},{},[12349,12353],{"data":12350,"marks":12351,"value":10047,"nodeType":882},{},[12352],{"type":1012},{"data":12354,"marks":12355,"value":10051,"nodeType":882},{},[],{"data":12357,"content":12358,"nodeType":883},{},[12359,12363],{"data":12360,"marks":12361,"value":10059,"nodeType":882},{},[12362],{"type":1012},{"data":12364,"marks":12365,"value":10063,"nodeType":882},{},[],{"data":12367,"content":12368,"nodeType":883},{},[12369,12373],{"data":12370,"marks":12371,"value":10071,"nodeType":882},{},[12372],{"type":1012},{"data":12374,"marks":12375,"value":10075,"nodeType":882},{},[],{"data":12377,"content":12378,"nodeType":883},{},[12379],{"data":12380,"marks":12381,"value":10082,"nodeType":882},{},[],{"data":12383,"content":12384,"nodeType":883},{},[12385,12388,12395],{"data":12386,"marks":12387,"value":21,"nodeType":882},{},[],{"data":12389,"content":12390,"nodeType":929},{"uri":1283},[12391],{"data":12392,"marks":12393,"value":10096,"nodeType":882},{},[12394],{"type":927},{"data":12396,"marks":12397,"value":1438,"nodeType":882},{},[],{"entries":12399},{"hyperlink":12400,"inline":12401,"block":12402},[],[],[12403,12409,12412,12417],{"sys":12404,"__typename":12405,"type":12406,"ctaText":12407,"buttonLabel":151,"buttonColour":12408,"buttonUrl":3358},{"id":9680},"CtaWidget","Custom","Read our report on the browser attack techniques security teams need to contend with in 2026 (no gates!)","sunny orange",{"sys":12410,"__typename":1329,"title":4543,"caption":4544,"layoutMode":59,"file":12411},{"id":4417},{"url":4546,"width":4547,"height":4548},{"sys":12413,"__typename":12405,"type":12406,"ctaText":12414,"buttonLabel":12415,"buttonColour":12408,"buttonUrl":12416},{"id":9750},"Read our blog for a step-by-step guide to how Push protects against browser-based attacks. ","Read the blog","https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fguide-how-to-use-push-controls-to-protect-your-users-from-modern-attacks\u002F",{"sys":12418,"__typename":1329,"title":12419,"caption":12420,"layoutMode":59,"file":12421},{"id":9814},"SEB Blog Quote Callout","What security leaders have to say about Push.",{"url":12422,"width":12423,"height":12424},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F3puINxgWMVBvsieKSMxbcA\u002Fd68e403607ea8786de911f7c0bbdd1d3\u002FFrame_628075.png",1390,930,{"items":12426},[],{},"Enterprise browser vs. browser extension solution analysis",{"items":12430},[12431,13013,13685],{"__typename":1365,"sys":12432,"content":12434,"title":12999,"synopsis":13000,"hashTags":59,"publishedDate":13001,"slug":13002,"tagsCollection":13003,"authorsCollection":13009},{"id":12433},"LlTjdYp5ALHM3YIvsCibZ",{"json":12435},{"data":12436,"content":12437,"nodeType":1294},{},[12438,12445,12472,12479,12482,12490,12497,12504,12511,12519,12572,12579,12587,12594,12601,12609,12616,12623,12642,12673,12680,12683,12691,12699,12717,12725,12744,12752,12759,12767,12774,12782,12789,12792,12800,12807,12818,12836,12844,12851,12857,12865,12901,12907,12915,12932,12940,12958,12961,12969,12976,12983],{"data":12439,"content":12440,"nodeType":883},{},[12441],{"data":12442,"marks":12443,"value":12444,"nodeType":882},{},[],"Three browser security companies have been acquired by major security platforms in five months. CrowdStrike acquired Seraphic Security in January 2026. Zscaler absorbed SquareX in February. In May, Akamai announced the acquisition of LayerX. Add Palo Alto Networks' earlier acquisition of Talon, and the browser security market has consolidated faster than almost any adjacent security category before it.",{"data":12446,"content":12447,"nodeType":883},{},[12448,12452,12459,12462,12469],{"data":12449,"marks":12450,"value":12451,"nodeType":882},{},[],"These acquisitions recognize that the browser is now where employees work, where AI runs, and where the most damaging attacks on organizations originate. It’s telling that browser security already accounts for ",{"data":12453,"content":12454,"nodeType":929},{"uri":6589},[12455],{"data":12456,"marks":12457,"value":12458,"nodeType":882},{},[],"12.6% of the average security budget",{"data":12460,"marks":12461,"value":2006,"nodeType":882},{},[],{"data":12463,"content":12464,"nodeType":929},{"uri":6589},[12465],{"data":12466,"marks":12467,"value":12468,"nodeType":882},{},[],"85% of organizations expect to increase that spend over the next 12-24 months",{"data":12470,"marks":12471,"value":1438,"nodeType":882},{},[],{"data":12473,"content":12474,"nodeType":883},{},[12475],{"data":12476,"marks":12477,"value":12478,"nodeType":882},{},[],"But for security buyers, consolidation creates a risk as much as an opportunity. The question isn't whether your existing platform vendor now offers browser security — it's whether what they're offering can actually protect you as the threat landscape evolves.",{"data":12480,"content":12481,"nodeType":967},{},[],{"data":12483,"content":12484,"nodeType":975},{},[12485],{"data":12486,"marks":12487,"value":12489,"nodeType":882},{},[12488],{"type":1012},"Why \"good enough\" isn't good enough in the browser",{"data":12491,"content":12492,"nodeType":883},{},[12493],{"data":12494,"marks":12495,"value":12496,"nodeType":882},{},[],"The consolidation pitch is tempting. If you're already a CrowdStrike, Zscaler, or Palo Alto customer, adding browser security through an existing relationship means fewer vendors, fewer contracts, and a coherent narrative about platform consolidation that plays well internally. ",{"data":12498,"content":12499,"nodeType":883},{},[12500],{"data":12501,"marks":12502,"value":12503,"nodeType":882},{},[],"Security teams make these kinds of tradeoffs all the time — accepting that your SASE vendor's threat intelligence feed may not match a dedicated provider, or that your EDR vendor's vulnerability management module may not match a dedicated scanner — are reasonable decisions where the operational benefit of consolidation outweighs the capability difference.",{"data":12505,"content":12506,"nodeType":883},{},[12507],{"data":12508,"marks":12509,"value":12510,"nodeType":882},{},[],"But browser security is a category where the stakes are too high to accept a \"good enough\" solution. The majority of all reported breaches now originate in the browser and attacker tradecraft in this space is advancing at an unprecedented rate thanks to AI. These risks warrant the strongest form of defense. Here are three reasons that “good enough” solutions don't give you that:",{"data":12512,"content":12513,"nodeType":2050},{},[12514],{"data":12515,"marks":12516,"value":12518,"nodeType":882},{},[12517],{"type":1012},"1. Most platform browser solutions were built for the wrong problems",{"data":12520,"content":12521,"nodeType":883},{},[12522,12525,12534,12538,12545,12549,12557,12561,12568],{"data":12523,"marks":12524,"value":21,"nodeType":882},{},[],{"data":12526,"content":12528,"nodeType":929},{"uri":12527},"https:\u002F\u002Fwww.crowdstrike.com\u002Fen-us\u002Fresources\u002Finfographics\u002Fidentity-security-risk-review\u002F",[12529],{"data":12530,"marks":12531,"value":12533,"nodeType":882},{},[12532],{"type":927},"CrowdStrike's own research",{"data":12535,"marks":12536,"value":12537,"nodeType":882},{},[]," puts identity involvement in 80% of all modern breaches. Identity weaknesses played a material role in ",{"data":12539,"content":12541,"nodeType":929},{"uri":12540},"https:\u002F\u002Fwww.paloaltonetworks.com\u002Fresources\u002Fresearch\u002Funit-42-incident-response-report",[12542],{"data":12543,"marks":12544,"value":7388,"nodeType":882},{},[],{"data":12546,"marks":12547,"value":12548,"nodeType":882},{},[],". The breaches making headlines — 2024's ",{"data":12550,"content":12552,"nodeType":929},{"uri":12551},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fsnowflake-retro",[12553],{"data":12554,"marks":12555,"value":12556,"nodeType":882},{},[],"mass Snowflake account compromises",{"data":12558,"marks":12559,"value":12560,"nodeType":882},{},[],", 2025's wave of Salesforce-targeted attacks, and 2026's ",{"data":12562,"content":12563,"nodeType":929},{"uri":3507},[12564],{"data":12565,"marks":12566,"value":12567,"nodeType":882},{},[],"continued spree of data theft and extortion",{"data":12569,"marks":12570,"value":12571,"nodeType":882},{},[]," — all trace back to identity weaknesses exploited through the browser: credentials stuffed into login pages that lacked MFA, session tokens hijacked via AiTM phishing, OAuth consent abused to grant persistent access, and device code flows manipulated to bypass authentication entirely. ",{"data":12573,"content":12574,"nodeType":883},{},[12575],{"data":12576,"marks":12577,"value":12578,"nodeType":882},{},[],"Yet Seraphic was built for browser runtime exploit prevention, SquareX for file-based malware sandboxing, LayerX for access governance and AI usage policy. These are real use cases, but they're not the use cases behind headline breaches. If your browser security solution checks a box for \"phishing protection\" but can't detect the identity attack techniques that are actually being industrialized and deployed at scale, you have a gap — and the danger is that you don't know it's there.",{"data":12580,"content":12581,"nodeType":2050},{},[12582],{"data":12583,"marks":12584,"value":12586,"nodeType":882},{},[12585],{"type":1012},"2. Even solutions claiming the right capabilities often deliver them superficially",{"data":12588,"content":12589,"nodeType":883},{},[12590],{"data":12591,"marks":12592,"value":12593,"nodeType":882},{},[],"Every browser security vendor claims phishing detection, ClickFix protection, and session security. What varies enormously is whether those capabilities work against real, live, never-before-seen attacker infrastructure — or only against known-bad indicators that attackers rotate in minutes. 95% of in-browser attacks detected by Push used bot protection to evade blocklists; 89% of phishing domains are active for fewer than two days. ",{"data":12595,"content":12596,"nodeType":883},{},[12597],{"data":12598,"marks":12599,"value":12600,"nodeType":882},{},[],"A solution that appears comprehensive in a demo or PoV may leave significant gaps when tested against adversaries who understand exactly how security tools work and actively engineer around them. ",{"data":12602,"content":12603,"nodeType":2050},{},[12604],{"data":12605,"marks":12606,"value":12608,"nodeType":882},{},[12607],{"type":1012},"3. AI is only going to widen the gap between \"good enough\" and what you need",{"data":12610,"content":12611,"nodeType":883},{},[12612],{"data":12613,"marks":12614,"value":12615,"nodeType":882},{},[],"When a browser security product is acquired, engineering effort turns inwards towards integration with the parent platform, not advancing detection capability. ",{"data":12617,"content":12618,"nodeType":883},{},[12619],{"data":12620,"marks":12621,"value":12622,"nodeType":882},{},[],"That dynamic plays out differently for each acquisition, but in Seraphic's case it is expected to be particularly heightened. Seraphic works by injecting an agent into the browser's JavaScript runtime. This is the same approach antivirus vendors have used for years, with well-documented stability consequences. Stability is now a top priority for CrowdStrike, which means the Seraphic integration will proceed cautiously. For buyers, that translates directly into slower capability advancement, not faster.",{"data":12624,"content":12625,"nodeType":883},{},[12626,12630,12638],{"data":12627,"marks":12628,"value":12629,"nodeType":882},{},[],"But this is no time for engineering efforts to turn inward, as the threat landscape continues to evolve at an unprecedented rate. You only need to look at the rise of techniques like device code phishing, which have gone from ",{"data":12631,"content":12632,"nodeType":929},{"uri":3389},[12633],{"data":12634,"marks":12635,"value":12637,"nodeType":882},{},[12636],{"type":927},"research curiosity to industrialized exploitation",{"data":12639,"marks":12640,"value":12641,"nodeType":882},{},[]," in a matter of months — in large part enabled by AI-powered tools and AI-assisted development. Similarly, AI has compressed the time to generate a convincing phishing campaign from hours to minutes. ",{"data":12643,"content":12644,"nodeType":883},{},[12645,12649,12656,12660,12669],{"data":12646,"marks":12647,"value":12648,"nodeType":882},{},[],"But it's not only external threats: ",{"data":12650,"content":12651,"nodeType":929},{"uri":6589},[12652],{"data":12653,"marks":12654,"value":12655,"nodeType":882},{},[],"92% of organizations allow employees to use public GenAI applications",{"data":12657,"marks":12658,"value":12659,"nodeType":882},{},[]," — every one of them with unsanctioned AI use occurring by design — employees are routinely entering sensitive data into unapproved AI tools, and ",{"data":12661,"content":12663,"nodeType":929},{"uri":12662},"https:\u002F\u002Fwww.gartner.com\u002Fen\u002Fnewsroom\u002Fpress-releases\u002F2025-08-26-gartner-predicts-40-percent-of-enterprise-apps-will-feature-task-specific-ai-agents-by-2026-up-from-less-than-5-percent-in-2025",[12664],{"data":12665,"marks":12666,"value":12668,"nodeType":882},{},[12667],{"type":927},"Gartner predicts",{"data":12670,"marks":12671,"value":12672,"nodeType":882},{},[]," 40% of enterprise applications will feature AI agents by end of 2026, up from under 5% in 2025. ",{"data":12674,"content":12675,"nodeType":883},{},[12676],{"data":12677,"marks":12678,"value":12679,"nodeType":882},{},[],"The gap between an acquired product focused on integration and vendors whose single-minded focus is on stopping these emerging threats will continue to widen over time.",{"data":12681,"content":12682,"nodeType":967},{},[],{"data":12684,"content":12685,"nodeType":975},{},[12686],{"data":12687,"marks":12688,"value":12690,"nodeType":882},{},[12689],{"type":1012},"How to identify a genuinely best-of-breed solution",{"data":12692,"content":12693,"nodeType":2050},{},[12694],{"data":12695,"marks":12696,"value":12698,"nodeType":882},{},[12697],{"type":1012},"Start from your own requirements",{"data":12700,"content":12701,"nodeType":883},{},[12702,12706,12713],{"data":12703,"marks":12704,"value":12705,"nodeType":882},{},[],"Define the outcomes you need before speaking to any vendor. The ",{"data":12707,"content":12708,"nodeType":929},{"uri":8834},[12709],{"data":12710,"marks":12711,"value":12712,"nodeType":882},{},[],"highest-value browser security use cases",{"data":12714,"marks":12715,"value":12716,"nodeType":882},{},[]," are account takeover prevention, advanced phishing detection, identity posture hardening, browser extension security, and shadow SaaS and OAuth governance.",{"data":12718,"content":12719,"nodeType":2050},{},[12720],{"data":12721,"marks":12722,"value":12724,"nodeType":882},{},[12723],{"type":1012},"Understand how it detects, not just what it claims",{"data":12726,"content":12727,"nodeType":883},{},[12728,12732,12740],{"data":12729,"marks":12730,"value":12731,"nodeType":882},{},[],"Most solutions rely on IoCs — matching known-bad domains, URLs, and IPs against feeds that attackers rotate in minutes.  There’s a major shortcoming with this approach, though: attackers rotate infrastructure faster than any blocklist updates and use bot protection to stay off threat intelligence feeds, making every attack feel ",{"data":12733,"content":12734,"nodeType":929},{"uri":3214},[12735],{"data":12736,"marks":12737,"value":12739,"nodeType":882},{},[12738],{"type":927},"like a zero-day",{"data":12741,"marks":12742,"value":12743,"nodeType":882},{},[],". The only approach that reliably works is TTP-based behavioral detection. Ask every vendor: are you detecting a known-bad indicator or a behavioral technique?",{"data":12745,"content":12746,"nodeType":2050},{},[12747],{"data":12748,"marks":12749,"value":12751,"nodeType":882},{},[12750],{"type":1012},"Test against real attacker behavior",{"data":12753,"content":12754,"nodeType":883},{},[12755],{"data":12756,"marks":12757,"value":12758,"nodeType":882},{},[],"Don't evaluate phishing detection with old phishing URLs. By the time you’re running these tests their IoCs will already be on block-lists (see point above). Instead, deploy realistic testing scenarios and look for demonstrable evidence of stopping real-world phishing kits — Evilginx, Tycoon2FA, Sneaky2FA, and so on. ",{"data":12760,"content":12761,"nodeType":2050},{},[12762],{"data":12763,"marks":12764,"value":12766,"nodeType":882},{},[12765],{"type":1012},"Assess innovation velocity",{"data":12768,"content":12769,"nodeType":883},{},[12770],{"data":12771,"marks":12772,"value":12773,"nodeType":882},{},[],"Ask every vendor about their research output and feature release history over the past six months — are they discovering and publishing novel attack techniques, or covering what others already documented? Are new detections shipping continuously, or in quarterly cycles? For acquired products specifically, also ask how the roadmap has changed since acquisition. ",{"data":12775,"content":12776,"nodeType":2050},{},[12777],{"data":12778,"marks":12779,"value":12781,"nodeType":882},{},[12780],{"type":1012},"Consider operationalization, vendor focus, and lock-in",{"data":12783,"content":12784,"nodeType":883},{},[12785],{"data":12786,"marks":12787,"value":12788,"nodeType":882},{},[],"Many solutions demo well but create significant overhead at scale. Consider whether you want another agent on endpoints, and whether you have the resources to tune granular policies without drowning in false positives. Your requirements might not carry the same weight with a platform vendor with tens of thousands of customers across multiple product lines, versus a dedicated vendor whose entire roadmap exists to solve your problem. And factor in lock-in: every capability consolidated into an existing platform vendor reduces your ability to change direction later.",{"data":12790,"content":12791,"nodeType":967},{},[],{"data":12793,"content":12794,"nodeType":975},{},[12795],{"data":12796,"marks":12797,"value":12799,"nodeType":882},{},[12798],{"type":1012},"Why Push is the best-of-breed browser security solution",{"data":12801,"content":12802,"nodeType":883},{},[12803],{"data":12804,"marks":12805,"value":12806,"nodeType":882},{},[],"Think of Push as EDR, but for the browser — high-fidelity telemetry and real-time control across every session, on every device, with no browser migration required. Here’s why customers choose Push as a best-of-breed solution:",{"data":12808,"content":12809,"nodeType":2050},{},[12810,12815],{"data":12811,"marks":12812,"value":12814,"nodeType":882},{},[12813],{"type":1012},"Push is built for the security problems that actually cause breaches",{"data":12816,"marks":12817,"value":2218,"nodeType":882},{},[],{"data":12819,"content":12820,"nodeType":883},{},[12821,12825,12832],{"data":12822,"marks":12823,"value":12824,"nodeType":882},{},[],"The highest-value browser security problems — account takeover prevention, advanced phishing detection, identity posture hardening, browser extension security, shadow SaaS and OAuth governance — all require visibility inside the browser session. Push was built from the ground up for exactly that. The same foundational capability that detects AiTM phishing and ClickFix attacks also surfaces the exposure most security teams don't know they have: ",{"data":12826,"content":12827,"nodeType":929},{"uri":8638},[12828],{"data":12829,"marks":12830,"value":12831,"nodeType":882},{},[],"across Push's customer base",{"data":12833,"marks":12834,"value":12835,"nodeType":882},{},[],", 1 in 4 logins use passwords rather than SSO, 2 in 5 are unprotected by MFA, and 46.76% of browser extensions carry permissions sufficient to perform account takeover — none of it visible from the endpoint, network, or email layer.",{"data":12837,"content":12838,"nodeType":2050},{},[12839],{"data":12840,"marks":12841,"value":12843,"nodeType":882},{},[12842],{"type":1012},"Push detects high-fidelity attacker TTPs, not low-level IoCs",{"data":12845,"content":12846,"nodeType":883},{},[12847],{"data":12848,"marks":12849,"value":12850,"nodeType":882},{},[],"Push's browser extension operates as a flight recorder inside the session, capturing every page load, credential submission, OAuth consent flow, and user action in real time. That telemetry surfaces attacker behavior — the page structure and script signatures of AiTM kits, the clipboard mechanics of ClickFix, the OAuth flow characteristics of ConsentFix — rather than infrastructure indicators that attackers rotate in minutes. This is how Push intercepts “zero-day” phishing using fresh infrastructure and domains every time, while most solutions are stuck playing known-bad whac-a-mole. ",{"data":12852,"content":12856,"nodeType":963},{"target":12853},{"sys":12854},{"id":12855,"type":960,"linkType":961},"4ho5gOHl1loo9Jtv9nPoq1",[],{"data":12858,"content":12859,"nodeType":2050},{},[12860],{"data":12861,"marks":12862,"value":12864,"nodeType":882},{},[12863],{"type":1012},"Push’s research and agentic threat hunting keeps you ahead of attacker innovation",{"data":12866,"content":12867,"nodeType":883},{},[12868,12872,12878,12881,12887,12891,12897],{"data":12869,"marks":12870,"value":12871,"nodeType":882},{},[],"Push named ",{"data":12873,"content":12874,"nodeType":929},{"uri":3582},[12875],{"data":12876,"marks":12877,"value":1989,"nodeType":882},{},[],{"data":12879,"marks":12880,"value":2633,"nodeType":882},{},[],{"data":12882,"content":12883,"nodeType":929},{"uri":3823},[12884],{"data":12885,"marks":12886,"value":2002,"nodeType":882},{},[],{"data":12888,"marks":12889,"value":12890,"nodeType":882},{},[]," before any other vendor detected either in production. That research feeds an ",{"data":12892,"content":12893,"nodeType":929},{"uri":2893},[12894],{"data":12895,"marks":12896,"value":9013,"nodeType":882},{},[],{"data":12898,"marks":12899,"value":12900,"nodeType":882},{},[]," built on two learning loops — an inner loop for real-time detection of known techniques, and an outer loop where autonomous agents continuously hunt across 3 million deployed browsers for emerging threats, writing new detections and deploying them to customer environments in minutes. ",{"data":12902,"content":12906,"nodeType":963},{"target":12903},{"sys":12904},{"id":12905,"type":960,"linkType":961},"17y3jchoPysKQTf2ra59Bv",[],{"data":12908,"content":12909,"nodeType":2050},{},[12910],{"data":12911,"marks":12912,"value":12914,"nodeType":882},{},[12913],{"type":1012},"Push solves more use cases than just stopping advanced attacks",{"data":12916,"content":12917,"nodeType":883},{},[12918,12922,12929],{"data":12919,"marks":12920,"value":12921,"nodeType":882},{},[],"Push uses the same browser-layer visibility to surface every AI tool, agentic browser, extension, and OAuth integration in use across the organization — and enforce policy on what employees can do inside them in real time, including unsanctioned tools no other layer sees. The same technical capabilities provided by Push also harden the identity attack surface, prevent data loss, accelerate insider investigations, and let security teams write custom detections and policies for organization-specific risks. One extension, one deployment, ",{"data":12923,"content":12924,"nodeType":929},{"uri":8834},[12925],{"data":12926,"marks":12927,"value":12928,"nodeType":882},{},[],"multiple high-value use cases",{"data":12930,"marks":12931,"value":1438,"nodeType":882},{},[],{"data":12933,"content":12934,"nodeType":2050},{},[12935],{"data":12936,"marks":12937,"value":12939,"nodeType":882},{},[12938],{"type":1012},"Push is built to be operationalized at scale, not just demoed",{"data":12941,"content":12942,"nodeType":883},{},[12943,12947,12954],{"data":12944,"marks":12945,"value":12946,"nodeType":882},{},[],"Push deploys to ",{"data":12948,"content":12949,"nodeType":929},{"uri":4493},[12950],{"data":12951,"marks":12952,"value":12953,"nodeType":882},{},[],"100,000 users in under one hour on a normal workday",{"data":12955,"marks":12956,"value":12957,"nodeType":882},{},[]," — no migration overhead or performance impact. The false positive rate is negligible, meaning no alert noise and no policy tuning overhead. And because Push is independent, it integrates into open ecosystems — feeding browser-layer telemetry into your SIEM, XDR, SOAR, and identity tools alongside the rest of your stack, without adding to your platform lock-in.",{"data":12959,"content":12960,"nodeType":967},{},[],{"data":12962,"content":12963,"nodeType":975},{},[12964],{"data":12965,"marks":12966,"value":12968,"nodeType":882},{},[12967],{"type":1012},"Final thoughts",{"data":12970,"content":12971,"nodeType":883},{},[12972],{"data":12973,"marks":12974,"value":12975,"nodeType":882},{},[],"Three acquisitions in five months is a strong market signal, but a strong market signal about vendor interest in a category is not the same thing as a strong signal about capability. The attacker techniques and tooling behind breaches in 2026 are evolving faster than any acquired product with split engineering priorities can reasonably track. ",{"data":12977,"content":12978,"nodeType":883},{},[12979],{"data":12980,"marks":12981,"value":12982,"nodeType":882},{},[],"Security buyers who accept a bundled browser solution because it is included in an existing contract are making a procurement decision, not a security decision. The threats in the browser are serious and sophisticated enough to justify the investment in a tool built to stop them. If you agree, Push is worth a serious look.",{"data":12984,"content":12985,"nodeType":883},{},[12986,12989,12996],{"data":12987,"marks":12988,"value":21,"nodeType":882},{},[],{"data":12990,"content":12991,"nodeType":929},{"uri":1283},[12992],{"data":12993,"marks":12994,"value":2941,"nodeType":882},{},[12995],{"type":927},{"data":12997,"marks":12998,"value":21,"nodeType":882},{},[],"Why \"good enough\" isn’t enough: the case for best-of-breed browser security","Why \"good enough\" isn’t enough when it comes to browser security, and a best-of-breed approach is needed to tackle emerging threats.","2026-05-19T00:00:00.000Z","the-case-for-best-of-breed-browser-security",{"items":13004},[13005,13007],{"sys":13006,"name":298},{"id":7235},{"sys":13008,"name":2308},{"id":2307},{"items":13010},[13011],{"fullName":3964,"firstName":3965,"jobTitle":868,"profilePicture":13012},{"url":3969},{"__typename":1365,"sys":13014,"content":13015,"title":8015,"synopsis":8016,"hashTags":59,"publishedDate":8017,"slug":8018,"tagsCollection":13675,"authorsCollection":13681},{"id":7246},{"json":13016},{"data":13017,"content":13018,"nodeType":1294},{},[13019,13024,13030,13036,13042,13045,13052,13058,13068,13078,13083,13089,13092,13099,13105,13110,13116,13122,13215,13221,13224,13231,13237,13292,13305,13310,13316,13319,13326,13332,13339,13345,13351,13376,13382,13389,13395,13401,13407,13414,13420,13426,13432,13435,13442,13452,13458,13464,13471,13477,13483,13490,13496,13551,13564,13579,13586,13592,13599,13605,13611,13617,13622,13629,13635,13641,13646,13652,13658,13664,13669],{"data":13020,"content":13023,"nodeType":963},{"target":13021},{"sys":13022},{"id":7255,"type":960,"linkType":961},[],{"data":13025,"content":13026,"nodeType":883},{},[13027],{"data":13028,"marks":13029,"value":7263,"nodeType":882},{},[],{"data":13031,"content":13032,"nodeType":883},{},[13033],{"data":13034,"marks":13035,"value":7270,"nodeType":882},{},[],{"data":13037,"content":13038,"nodeType":883},{},[13039],{"data":13040,"marks":13041,"value":7277,"nodeType":882},{},[],{"data":13043,"content":13044,"nodeType":967},{},[],{"data":13046,"content":13047,"nodeType":975},{},[13048],{"data":13049,"marks":13050,"value":7288,"nodeType":882},{},[13051],{"type":1012},{"data":13053,"content":13054,"nodeType":883},{},[13055],{"data":13056,"marks":13057,"value":7295,"nodeType":882},{},[],{"data":13059,"content":13060,"nodeType":883},{},[13061,13065],{"data":13062,"marks":13063,"value":7303,"nodeType":882},{},[13064],{"type":1012},{"data":13066,"marks":13067,"value":7307,"nodeType":882},{},[],{"data":13069,"content":13070,"nodeType":883},{},[13071,13075],{"data":13072,"marks":13073,"value":7315,"nodeType":882},{},[13074],{"type":1012},{"data":13076,"marks":13077,"value":7319,"nodeType":882},{},[],{"data":13079,"content":13082,"nodeType":963},{"target":13080},{"sys":13081},{"id":7324,"type":960,"linkType":961},[],{"data":13084,"content":13085,"nodeType":883},{},[13086],{"data":13087,"marks":13088,"value":7332,"nodeType":882},{},[],{"data":13090,"content":13091,"nodeType":967},{},[],{"data":13093,"content":13094,"nodeType":975},{},[13095],{"data":13096,"marks":13097,"value":7343,"nodeType":882},{},[13098],{"type":1012},{"data":13100,"content":13101,"nodeType":883},{},[13102],{"data":13103,"marks":13104,"value":7350,"nodeType":882},{},[],{"data":13106,"content":13109,"nodeType":963},{"target":13107},{"sys":13108},{"id":7355,"type":960,"linkType":961},[],{"data":13111,"content":13112,"nodeType":883},{},[13113],{"data":13114,"marks":13115,"value":7363,"nodeType":882},{},[],{"data":13117,"content":13118,"nodeType":883},{},[13119],{"data":13120,"marks":13121,"value":7370,"nodeType":882},{},[],{"data":13123,"content":13124,"nodeType":1454},{},[13125,13141,13157,13173,13189,13202],{"data":13126,"content":13127,"nodeType":1419},{},[13128],{"data":13129,"content":13130,"nodeType":883},{},[13131,13134,13138],{"data":13132,"marks":13133,"value":7383,"nodeType":882},{},[],{"data":13135,"marks":13136,"value":7388,"nodeType":882},{},[13137],{"type":1012},{"data":13139,"marks":13140,"value":7392,"nodeType":882},{},[],{"data":13142,"content":13143,"nodeType":1419},{},[13144],{"data":13145,"content":13146,"nodeType":883},{},[13147,13150,13154],{"data":13148,"marks":13149,"value":7402,"nodeType":882},{},[],{"data":13151,"marks":13152,"value":7407,"nodeType":882},{},[13153],{"type":1012},{"data":13155,"marks":13156,"value":7411,"nodeType":882},{},[],{"data":13158,"content":13159,"nodeType":1419},{},[13160],{"data":13161,"content":13162,"nodeType":883},{},[13163,13166,13170],{"data":13164,"marks":13165,"value":7421,"nodeType":882},{},[],{"data":13167,"marks":13168,"value":7426,"nodeType":882},{},[13169],{"type":1012},{"data":13171,"marks":13172,"value":7430,"nodeType":882},{},[],{"data":13174,"content":13175,"nodeType":1419},{},[13176],{"data":13177,"content":13178,"nodeType":883},{},[13179,13182,13186],{"data":13180,"marks":13181,"value":7440,"nodeType":882},{},[],{"data":13183,"marks":13184,"value":7445,"nodeType":882},{},[13185],{"type":1012},{"data":13187,"marks":13188,"value":7449,"nodeType":882},{},[],{"data":13190,"content":13191,"nodeType":1419},{},[13192],{"data":13193,"content":13194,"nodeType":883},{},[13195,13199],{"data":13196,"marks":13197,"value":7460,"nodeType":882},{},[13198],{"type":1012},{"data":13200,"marks":13201,"value":7464,"nodeType":882},{},[],{"data":13203,"content":13204,"nodeType":1419},{},[13205],{"data":13206,"content":13207,"nodeType":883},{},[13208,13212],{"data":13209,"marks":13210,"value":7475,"nodeType":882},{},[13211],{"type":1012},{"data":13213,"marks":13214,"value":7479,"nodeType":882},{},[],{"data":13216,"content":13217,"nodeType":883},{},[13218],{"data":13219,"marks":13220,"value":7486,"nodeType":882},{},[],{"data":13222,"content":13223,"nodeType":967},{},[],{"data":13225,"content":13226,"nodeType":2050},{},[13227],{"data":13228,"marks":13229,"value":7497,"nodeType":882},{},[13230],{"type":1012},{"data":13232,"content":13233,"nodeType":883},{},[13234],{"data":13235,"marks":13236,"value":7504,"nodeType":882},{},[],{"data":13238,"content":13239,"nodeType":1454},{},[13240,13253,13266,13279],{"data":13241,"content":13242,"nodeType":1419},{},[13243],{"data":13244,"content":13245,"nodeType":883},{},[13246,13249],{"data":13247,"marks":13248,"value":7517,"nodeType":882},{},[],{"data":13250,"marks":13251,"value":7522,"nodeType":882},{},[13252],{"type":1012},{"data":13254,"content":13255,"nodeType":1419},{},[13256],{"data":13257,"content":13258,"nodeType":883},{},[13259,13262],{"data":13260,"marks":13261,"value":7532,"nodeType":882},{},[],{"data":13263,"marks":13264,"value":7537,"nodeType":882},{},[13265],{"type":1012},{"data":13267,"content":13268,"nodeType":1419},{},[13269],{"data":13270,"content":13271,"nodeType":883},{},[13272,13275],{"data":13273,"marks":13274,"value":7547,"nodeType":882},{},[],{"data":13276,"marks":13277,"value":7552,"nodeType":882},{},[13278],{"type":1012},{"data":13280,"content":13281,"nodeType":1419},{},[13282],{"data":13283,"content":13284,"nodeType":883},{},[13285,13288],{"data":13286,"marks":13287,"value":7562,"nodeType":882},{},[],{"data":13289,"marks":13290,"value":7567,"nodeType":882},{},[13291],{"type":1012},{"data":13293,"content":13294,"nodeType":883},{},[13295,13298,13302],{"data":13296,"marks":13297,"value":7574,"nodeType":882},{},[],{"data":13299,"marks":13300,"value":7579,"nodeType":882},{},[13301],{"type":1012},{"data":13303,"marks":13304,"value":7583,"nodeType":882},{},[],{"data":13306,"content":13309,"nodeType":963},{"target":13307},{"sys":13308},{"id":7588,"type":960,"linkType":961},[],{"data":13311,"content":13312,"nodeType":883},{},[13313],{"data":13314,"marks":13315,"value":7596,"nodeType":882},{},[],{"data":13317,"content":13318,"nodeType":967},{},[],{"data":13320,"content":13321,"nodeType":975},{},[13322],{"data":13323,"marks":13324,"value":7607,"nodeType":882},{},[13325],{"type":1012},{"data":13327,"content":13328,"nodeType":883},{},[13329],{"data":13330,"marks":13331,"value":7614,"nodeType":882},{},[],{"data":13333,"content":13334,"nodeType":2050},{},[13335],{"data":13336,"marks":13337,"value":7622,"nodeType":882},{},[13338],{"type":1012},{"data":13340,"content":13341,"nodeType":883},{},[13342],{"data":13343,"marks":13344,"value":7629,"nodeType":882},{},[],{"data":13346,"content":13347,"nodeType":883},{},[13348],{"data":13349,"marks":13350,"value":7636,"nodeType":882},{},[],{"data":13352,"content":13353,"nodeType":883},{},[13354,13357,13363,13366,13373],{"data":13355,"marks":13356,"value":7643,"nodeType":882},{},[],{"data":13358,"content":13359,"nodeType":929},{"uri":6589},[13360],{"data":13361,"marks":13362,"value":7650,"nodeType":882},{},[],{"data":13364,"marks":13365,"value":7654,"nodeType":882},{},[],{"data":13367,"content":13368,"nodeType":929},{"uri":7657},[13369],{"data":13370,"marks":13371,"value":7663,"nodeType":882},{},[13372],{"type":927},{"data":13374,"marks":13375,"value":7667,"nodeType":882},{},[],{"data":13377,"content":13378,"nodeType":883},{},[13379],{"data":13380,"marks":13381,"value":7674,"nodeType":882},{},[],{"data":13383,"content":13384,"nodeType":2050},{},[13385],{"data":13386,"marks":13387,"value":7682,"nodeType":882},{},[13388],{"type":1012},{"data":13390,"content":13391,"nodeType":883},{},[13392],{"data":13393,"marks":13394,"value":7689,"nodeType":882},{},[],{"data":13396,"content":13397,"nodeType":883},{},[13398],{"data":13399,"marks":13400,"value":7696,"nodeType":882},{},[],{"data":13402,"content":13403,"nodeType":883},{},[13404],{"data":13405,"marks":13406,"value":7703,"nodeType":882},{},[],{"data":13408,"content":13409,"nodeType":2050},{},[13410],{"data":13411,"marks":13412,"value":7711,"nodeType":882},{},[13413],{"type":1012},{"data":13415,"content":13416,"nodeType":883},{},[13417],{"data":13418,"marks":13419,"value":7718,"nodeType":882},{},[],{"data":13421,"content":13422,"nodeType":883},{},[13423],{"data":13424,"marks":13425,"value":7725,"nodeType":882},{},[],{"data":13427,"content":13428,"nodeType":883},{},[13429],{"data":13430,"marks":13431,"value":7732,"nodeType":882},{},[],{"data":13433,"content":13434,"nodeType":967},{},[],{"data":13436,"content":13437,"nodeType":975},{},[13438],{"data":13439,"marks":13440,"value":7743,"nodeType":882},{},[13441],{"type":1012},{"data":13443,"content":13444,"nodeType":883},{},[13445,13449],{"data":13446,"marks":13447,"value":7751,"nodeType":882},{},[13448],{"type":1012},{"data":13450,"marks":13451,"value":7755,"nodeType":882},{},[],{"data":13453,"content":13454,"nodeType":883},{},[13455],{"data":13456,"marks":13457,"value":7762,"nodeType":882},{},[],{"data":13459,"content":13460,"nodeType":883},{},[13461],{"data":13462,"marks":13463,"value":7769,"nodeType":882},{},[],{"data":13465,"content":13466,"nodeType":2050},{},[13467],{"data":13468,"marks":13469,"value":7777,"nodeType":882},{},[13470],{"type":1012},{"data":13472,"content":13473,"nodeType":883},{},[13474],{"data":13475,"marks":13476,"value":7784,"nodeType":882},{},[],{"data":13478,"content":13479,"nodeType":883},{},[13480],{"data":13481,"marks":13482,"value":7791,"nodeType":882},{},[],{"data":13484,"content":13485,"nodeType":2050},{},[13486],{"data":13487,"marks":13488,"value":7799,"nodeType":882},{},[13489],{"type":1012},{"data":13491,"content":13492,"nodeType":883},{},[13493],{"data":13494,"marks":13495,"value":7806,"nodeType":882},{},[],{"data":13497,"content":13498,"nodeType":1454},{},[13499,13512,13525,13538],{"data":13500,"content":13501,"nodeType":1419},{},[13502],{"data":13503,"content":13504,"nodeType":883},{},[13505,13509],{"data":13506,"marks":13507,"value":7820,"nodeType":882},{},[13508],{"type":1012},{"data":13510,"marks":13511,"value":7824,"nodeType":882},{},[],{"data":13513,"content":13514,"nodeType":1419},{},[13515],{"data":13516,"content":13517,"nodeType":883},{},[13518,13522],{"data":13519,"marks":13520,"value":7835,"nodeType":882},{},[13521],{"type":1012},{"data":13523,"marks":13524,"value":7839,"nodeType":882},{},[],{"data":13526,"content":13527,"nodeType":1419},{},[13528],{"data":13529,"content":13530,"nodeType":883},{},[13531,13535],{"data":13532,"marks":13533,"value":7850,"nodeType":882},{},[13534],{"type":1012},{"data":13536,"marks":13537,"value":7854,"nodeType":882},{},[],{"data":13539,"content":13540,"nodeType":1419},{},[13541],{"data":13542,"content":13543,"nodeType":883},{},[13544,13548],{"data":13545,"marks":13546,"value":7865,"nodeType":882},{},[13547],{"type":1012},{"data":13549,"marks":13550,"value":7869,"nodeType":882},{},[],{"data":13552,"content":13553,"nodeType":883},{},[13554,13557,13561],{"data":13555,"marks":13556,"value":7876,"nodeType":882},{},[],{"data":13558,"marks":13559,"value":7881,"nodeType":882},{},[13560],{"type":1012},{"data":13562,"marks":13563,"value":7885,"nodeType":882},{},[],{"data":13565,"content":13566,"nodeType":883},{},[13567,13570,13576],{"data":13568,"marks":13569,"value":7892,"nodeType":882},{},[],{"data":13571,"content":13572,"nodeType":929},{"uri":7895},[13573],{"data":13574,"marks":13575,"value":7900,"nodeType":882},{},[],{"data":13577,"marks":13578,"value":7904,"nodeType":882},{},[],{"data":13580,"content":13581,"nodeType":2050},{},[13582],{"data":13583,"marks":13584,"value":7912,"nodeType":882},{},[13585],{"type":1012},{"data":13587,"content":13588,"nodeType":883},{},[13589],{"data":13590,"marks":13591,"value":7919,"nodeType":882},{},[],{"data":13593,"content":13594,"nodeType":883},{},[13595],{"data":13596,"marks":13597,"value":7927,"nodeType":882},{},[13598],{"type":1012},{"data":13600,"content":13601,"nodeType":883},{},[13602],{"data":13603,"marks":13604,"value":7934,"nodeType":882},{},[],{"data":13606,"content":13607,"nodeType":883},{},[13608],{"data":13609,"marks":13610,"value":7941,"nodeType":882},{},[],{"data":13612,"content":13613,"nodeType":883},{},[13614],{"data":13615,"marks":13616,"value":7948,"nodeType":882},{},[],{"data":13618,"content":13621,"nodeType":963},{"target":13619},{"sys":13620},{"id":7953,"type":960,"linkType":961},[],{"data":13623,"content":13624,"nodeType":2050},{},[13625],{"data":13626,"marks":13627,"value":7962,"nodeType":882},{},[13628],{"type":1012},{"data":13630,"content":13631,"nodeType":883},{},[13632],{"data":13633,"marks":13634,"value":7969,"nodeType":882},{},[],{"data":13636,"content":13637,"nodeType":883},{},[13638],{"data":13639,"marks":13640,"value":7976,"nodeType":882},{},[],{"data":13642,"content":13645,"nodeType":963},{"target":13643},{"sys":13644},{"id":4417,"type":960,"linkType":961},[],{"data":13647,"content":13648,"nodeType":883},{},[13649],{"data":13650,"marks":13651,"value":7988,"nodeType":882},{},[],{"data":13653,"content":13654,"nodeType":883},{},[13655],{"data":13656,"marks":13657,"value":7995,"nodeType":882},{},[],{"data":13659,"content":13660,"nodeType":883},{},[13661],{"data":13662,"marks":13663,"value":8002,"nodeType":882},{},[],{"data":13665,"content":13668,"nodeType":963},{"target":13666},{"sys":13667},{"id":8007,"type":960,"linkType":961},[],{"data":13670,"content":13671,"nodeType":883},{},[13672],{"data":13673,"marks":13674,"value":21,"nodeType":882},{},[],{"items":13676},[13677,13679],{"sys":13678,"name":298},{"id":7235},{"sys":13680,"name":7239},{"id":7238},{"items":13682},[13683],{"fullName":3964,"firstName":3965,"jobTitle":868,"profilePicture":13684},{"url":3969},{"__typename":1365,"sys":13686,"content":13687,"title":7227,"synopsis":7228,"hashTags":59,"publishedDate":7229,"slug":7230,"tagsCollection":14756,"authorsCollection":14762},{"id":5992},{"json":13688},{"data":13689,"content":13690,"nodeType":1294},{},[13691,13704,13709,13715,13721,13726,13729,13736,13743,13758,13796,13801,13814,13817,13824,13831,13853,13885,13891,13894,13901,13908,13914,13919,13925,13928,13935,13942,13976,14006,14012,14015,14022,14029,14049,14055,14094,14100,14103,14110,14117,14153,14159,14164,14167,14174,14181,14207,14213,14218,14224,14227,14234,14241,14264,14270,14276,14282,14285,14292,14299,14305,14310,14316,14337,14360,14363,14370,14377,14383,14389,14392,14399,14454,14457,14464,14470,14738,14741],{"data":13692,"content":13693,"nodeType":883},{},[13694,13697,13701],{"data":13695,"marks":13696,"value":6003,"nodeType":882},{},[],{"data":13698,"marks":13699,"value":6008,"nodeType":882},{},[13700],{"type":1012},{"data":13702,"marks":13703,"value":6012,"nodeType":882},{},[],{"data":13705,"content":13708,"nodeType":963},{"target":13706},{"sys":13707},{"id":6017,"type":960,"linkType":961},[],{"data":13710,"content":13711,"nodeType":883},{},[13712],{"data":13713,"marks":13714,"value":6025,"nodeType":882},{},[],{"data":13716,"content":13717,"nodeType":883},{},[13718],{"data":13719,"marks":13720,"value":6032,"nodeType":882},{},[],{"data":13722,"content":13725,"nodeType":963},{"target":13723},{"sys":13724},{"id":6037,"type":960,"linkType":961},[],{"data":13727,"content":13728,"nodeType":967},{},[],{"data":13730,"content":13731,"nodeType":975},{},[13732],{"data":13733,"marks":13734,"value":6049,"nodeType":882},{},[13735],{"type":1012},{"data":13737,"content":13738,"nodeType":883},{},[13739],{"data":13740,"marks":13741,"value":6057,"nodeType":882},{},[13742],{"type":1012},{"data":13744,"content":13745,"nodeType":883},{},[13746,13749,13755],{"data":13747,"marks":13748,"value":6064,"nodeType":882},{},[],{"data":13750,"content":13751,"nodeType":929},{"uri":6067},[13752],{"data":13753,"marks":13754,"value":6072,"nodeType":882},{},[],{"data":13756,"marks":13757,"value":6076,"nodeType":882},{},[],{"data":13759,"content":13760,"nodeType":883},{},[13761,13764,13770,13773,13777,13780,13784,13787,13793],{"data":13762,"marks":13763,"value":4513,"nodeType":882},{},[],{"data":13765,"content":13766,"nodeType":929},{"uri":6085},[13767],{"data":13768,"marks":13769,"value":6090,"nodeType":882},{},[],{"data":13771,"marks":13772,"value":1993,"nodeType":882},{},[],{"data":13774,"marks":13775,"value":6098,"nodeType":882},{},[13776],{"type":1012},{"data":13778,"marks":13779,"value":2006,"nodeType":882},{},[],{"data":13781,"marks":13782,"value":6106,"nodeType":882},{},[13783],{"type":1012},{"data":13785,"marks":13786,"value":6110,"nodeType":882},{},[],{"data":13788,"content":13789,"nodeType":929},{"uri":6113},[13790],{"data":13791,"marks":13792,"value":6118,"nodeType":882},{},[],{"data":13794,"marks":13795,"value":6122,"nodeType":882},{},[],{"data":13797,"content":13800,"nodeType":963},{"target":13798},{"sys":13799},{"id":6127,"type":960,"linkType":961},[],{"data":13802,"content":13803,"nodeType":883},{},[13804,13807,13811],{"data":13805,"marks":13806,"value":6135,"nodeType":882},{},[],{"data":13808,"marks":13809,"value":6140,"nodeType":882},{},[13810],{"type":1012},{"data":13812,"marks":13813,"value":1438,"nodeType":882},{},[],{"data":13815,"content":13816,"nodeType":967},{},[],{"data":13818,"content":13819,"nodeType":975},{},[13820],{"data":13821,"marks":13822,"value":6154,"nodeType":882},{},[13823],{"type":1012},{"data":13825,"content":13826,"nodeType":883},{},[13827],{"data":13828,"marks":13829,"value":6057,"nodeType":882},{},[13830],{"type":1012},{"data":13832,"content":13833,"nodeType":883},{},[13834,13837,13843,13846,13850],{"data":13835,"marks":13836,"value":6168,"nodeType":882},{},[],{"data":13838,"content":13839,"nodeType":929},{"uri":6171},[13840],{"data":13841,"marks":13842,"value":6176,"nodeType":882},{},[],{"data":13844,"marks":13845,"value":6180,"nodeType":882},{},[],{"data":13847,"marks":13848,"value":6185,"nodeType":882},{},[13849],{"type":1012},{"data":13851,"marks":13852,"value":6189,"nodeType":882},{},[],{"data":13854,"content":13855,"nodeType":883},{},[13856,13859,13865,13868,13872,13875,13882],{"data":13857,"marks":13858,"value":6196,"nodeType":882},{},[],{"data":13860,"content":13861,"nodeType":929},{"uri":6199},[13862],{"data":13863,"marks":13864,"value":6204,"nodeType":882},{},[],{"data":13866,"marks":13867,"value":6208,"nodeType":882},{},[],{"data":13869,"marks":13870,"value":6213,"nodeType":882},{},[13871],{"type":1012},{"data":13873,"marks":13874,"value":6217,"nodeType":882},{},[],{"data":13876,"content":13877,"nodeType":929},{"uri":6220},[13878],{"data":13879,"marks":13880,"value":6226,"nodeType":882},{},[13881],{"type":1012},{"data":13883,"marks":13884,"value":6230,"nodeType":882},{},[],{"data":13886,"content":13887,"nodeType":883},{},[13888],{"data":13889,"marks":13890,"value":6237,"nodeType":882},{},[],{"data":13892,"content":13893,"nodeType":967},{},[],{"data":13895,"content":13896,"nodeType":975},{},[13897],{"data":13898,"marks":13899,"value":6248,"nodeType":882},{},[13900],{"type":1012},{"data":13902,"content":13903,"nodeType":883},{},[13904],{"data":13905,"marks":13906,"value":6256,"nodeType":882},{},[13907],{"type":1012},{"data":13909,"content":13910,"nodeType":883},{},[13911],{"data":13912,"marks":13913,"value":6263,"nodeType":882},{},[],{"data":13915,"content":13918,"nodeType":963},{"target":13916},{"sys":13917},{"id":6268,"type":960,"linkType":961},[],{"data":13920,"content":13921,"nodeType":883},{},[13922],{"data":13923,"marks":13924,"value":6276,"nodeType":882},{},[],{"data":13926,"content":13927,"nodeType":967},{},[],{"data":13929,"content":13930,"nodeType":975},{},[13931],{"data":13932,"marks":13933,"value":6287,"nodeType":882},{},[13934],{"type":1012},{"data":13936,"content":13937,"nodeType":883},{},[13938],{"data":13939,"marks":13940,"value":6256,"nodeType":882},{},[13941],{"type":1012},{"data":13943,"content":13944,"nodeType":883},{},[13945,13948,13955,13958,13964,13967,13973],{"data":13946,"marks":13947,"value":6301,"nodeType":882},{},[],{"data":13949,"content":13950,"nodeType":929},{"uri":6304},[13951],{"data":13952,"marks":13953,"value":6310,"nodeType":882},{},[13954],{"type":927},{"data":13956,"marks":13957,"value":1993,"nodeType":882},{},[],{"data":13959,"content":13960,"nodeType":929},{"uri":6316},[13961],{"data":13962,"marks":13963,"value":6321,"nodeType":882},{},[],{"data":13965,"marks":13966,"value":1993,"nodeType":882},{},[],{"data":13968,"content":13969,"nodeType":929},{"uri":6327},[13970],{"data":13971,"marks":13972,"value":6332,"nodeType":882},{},[],{"data":13974,"marks":13975,"value":6336,"nodeType":882},{},[],{"data":13977,"content":13978,"nodeType":883},{},[13979,13982,13989,13992,13996,13999,14003],{"data":13980,"marks":13981,"value":21,"nodeType":882},{},[],{"data":13983,"content":13984,"nodeType":929},{"uri":6345},[13985],{"data":13986,"marks":13987,"value":6351,"nodeType":882},{},[13988],{"type":927},{"data":13990,"marks":13991,"value":6355,"nodeType":882},{},[],{"data":13993,"marks":13994,"value":6360,"nodeType":882},{},[13995],{"type":1012},{"data":13997,"marks":13998,"value":6364,"nodeType":882},{},[],{"data":14000,"marks":14001,"value":6369,"nodeType":882},{},[14002],{"type":1045},{"data":14004,"marks":14005,"value":6373,"nodeType":882},{},[],{"data":14007,"content":14008,"nodeType":883},{},[14009],{"data":14010,"marks":14011,"value":6380,"nodeType":882},{},[],{"data":14013,"content":14014,"nodeType":967},{},[],{"data":14016,"content":14017,"nodeType":975},{},[14018],{"data":14019,"marks":14020,"value":6391,"nodeType":882},{},[14021],{"type":1012},{"data":14023,"content":14024,"nodeType":883},{},[14025],{"data":14026,"marks":14027,"value":6256,"nodeType":882},{},[14028],{"type":1012},{"data":14030,"content":14031,"nodeType":883},{},[14032,14035,14039,14042,14046],{"data":14033,"marks":14034,"value":6405,"nodeType":882},{},[],{"data":14036,"marks":14037,"value":6410,"nodeType":882},{},[14038],{"type":1045},{"data":14040,"marks":14041,"value":6414,"nodeType":882},{},[],{"data":14043,"marks":14044,"value":6419,"nodeType":882},{},[14045],{"type":1045},{"data":14047,"marks":14048,"value":6423,"nodeType":882},{},[],{"data":14050,"content":14051,"nodeType":883},{},[14052],{"data":14053,"marks":14054,"value":6430,"nodeType":882},{},[],{"data":14056,"content":14057,"nodeType":1454},{},[14058,14076],{"data":14059,"content":14060,"nodeType":1419},{},[14061],{"data":14062,"content":14063,"nodeType":883},{},[14064,14067,14073],{"data":14065,"marks":14066,"value":6443,"nodeType":882},{},[],{"data":14068,"content":14069,"nodeType":929},{"uri":3507},[14070],{"data":14071,"marks":14072,"value":6450,"nodeType":882},{},[],{"data":14074,"marks":14075,"value":6454,"nodeType":882},{},[],{"data":14077,"content":14078,"nodeType":1419},{},[14079],{"data":14080,"content":14081,"nodeType":883},{},[14082,14085,14091],{"data":14083,"marks":14084,"value":6443,"nodeType":882},{},[],{"data":14086,"content":14087,"nodeType":929},{"uri":6466},[14088],{"data":14089,"marks":14090,"value":6471,"nodeType":882},{},[],{"data":14092,"marks":14093,"value":6475,"nodeType":882},{},[],{"data":14095,"content":14096,"nodeType":883},{},[14097],{"data":14098,"marks":14099,"value":6482,"nodeType":882},{},[],{"data":14101,"content":14102,"nodeType":967},{},[],{"data":14104,"content":14105,"nodeType":975},{},[14106],{"data":14107,"marks":14108,"value":6493,"nodeType":882},{},[14109],{"type":1012},{"data":14111,"content":14112,"nodeType":883},{},[14113],{"data":14114,"marks":14115,"value":6501,"nodeType":882},{},[14116],{"type":1012},{"data":14118,"content":14119,"nodeType":883},{},[14120,14123,14127,14130,14136,14139,14143,14146,14150],{"data":14121,"marks":14122,"value":6508,"nodeType":882},{},[],{"data":14124,"marks":14125,"value":6513,"nodeType":882},{},[14126],{"type":1012},{"data":14128,"marks":14129,"value":6517,"nodeType":882},{},[],{"data":14131,"content":14132,"nodeType":929},{"uri":6520},[14133],{"data":14134,"marks":14135,"value":6525,"nodeType":882},{},[],{"data":14137,"marks":14138,"value":6529,"nodeType":882},{},[],{"data":14140,"marks":14141,"value":6534,"nodeType":882},{},[14142],{"type":1012},{"data":14144,"marks":14145,"value":6538,"nodeType":882},{},[],{"data":14147,"marks":14148,"value":6543,"nodeType":882},{},[14149],{"type":1012},{"data":14151,"marks":14152,"value":6547,"nodeType":882},{},[],{"data":14154,"content":14155,"nodeType":883},{},[14156],{"data":14157,"marks":14158,"value":6554,"nodeType":882},{},[],{"data":14160,"content":14163,"nodeType":963},{"target":14161},{"sys":14162},{"id":6559,"type":960,"linkType":961},[],{"data":14165,"content":14166,"nodeType":967},{},[],{"data":14168,"content":14169,"nodeType":975},{},[14170],{"data":14171,"marks":14172,"value":6571,"nodeType":882},{},[14173],{"type":1012},{"data":14175,"content":14176,"nodeType":883},{},[14177],{"data":14178,"marks":14179,"value":6579,"nodeType":882},{},[14180],{"type":1012},{"data":14182,"content":14183,"nodeType":883},{},[14184,14187,14194,14197,14204],{"data":14185,"marks":14186,"value":6586,"nodeType":882},{},[],{"data":14188,"content":14189,"nodeType":929},{"uri":6589},[14190],{"data":14191,"marks":14192,"value":6595,"nodeType":882},{},[14193],{"type":1012},{"data":14195,"marks":14196,"value":6599,"nodeType":882},{},[],{"data":14198,"content":14199,"nodeType":929},{"uri":6602},[14200],{"data":14201,"marks":14202,"value":6608,"nodeType":882},{},[14203],{"type":1012},{"data":14205,"marks":14206,"value":6612,"nodeType":882},{},[],{"data":14208,"content":14209,"nodeType":883},{},[14210],{"data":14211,"marks":14212,"value":6619,"nodeType":882},{},[],{"data":14214,"content":14217,"nodeType":963},{"target":14215},{"sys":14216},{"id":6624,"type":960,"linkType":961},[],{"data":14219,"content":14220,"nodeType":883},{},[14221],{"data":14222,"marks":14223,"value":6632,"nodeType":882},{},[],{"data":14225,"content":14226,"nodeType":967},{},[],{"data":14228,"content":14229,"nodeType":975},{},[14230],{"data":14231,"marks":14232,"value":6643,"nodeType":882},{},[14233],{"type":1012},{"data":14235,"content":14236,"nodeType":883},{},[14237],{"data":14238,"marks":14239,"value":6651,"nodeType":882},{},[14240],{"type":1012},{"data":14242,"content":14243,"nodeType":883},{},[14244,14247,14251,14254,14261],{"data":14245,"marks":14246,"value":6658,"nodeType":882},{},[],{"data":14248,"marks":14249,"value":6663,"nodeType":882},{},[14250],{"type":1045},{"data":14252,"marks":14253,"value":6667,"nodeType":882},{},[],{"data":14255,"content":14256,"nodeType":929},{"uri":6670},[14257],{"data":14258,"marks":14259,"value":6676,"nodeType":882},{},[14260],{"type":1012},{"data":14262,"marks":14263,"value":6680,"nodeType":882},{},[],{"data":14265,"content":14266,"nodeType":883},{},[14267],{"data":14268,"marks":14269,"value":6687,"nodeType":882},{},[],{"data":14271,"content":14272,"nodeType":883},{},[14273],{"data":14274,"marks":14275,"value":6694,"nodeType":882},{},[],{"data":14277,"content":14278,"nodeType":883},{},[14279],{"data":14280,"marks":14281,"value":6701,"nodeType":882},{},[],{"data":14283,"content":14284,"nodeType":967},{},[],{"data":14286,"content":14287,"nodeType":975},{},[14288],{"data":14289,"marks":14290,"value":6712,"nodeType":882},{},[14291],{"type":1012},{"data":14293,"content":14294,"nodeType":883},{},[14295],{"data":14296,"marks":14297,"value":6720,"nodeType":882},{},[14298],{"type":1012},{"data":14300,"content":14301,"nodeType":883},{},[14302],{"data":14303,"marks":14304,"value":6727,"nodeType":882},{},[],{"data":14306,"content":14309,"nodeType":963},{"target":14307},{"sys":14308},{"id":6732,"type":960,"linkType":961},[],{"data":14311,"content":14312,"nodeType":883},{},[14313],{"data":14314,"marks":14315,"value":6740,"nodeType":882},{},[],{"data":14317,"content":14318,"nodeType":1454},{},[14319,14328],{"data":14320,"content":14321,"nodeType":1419},{},[14322],{"data":14323,"content":14324,"nodeType":883},{},[14325],{"data":14326,"marks":14327,"value":6753,"nodeType":882},{},[],{"data":14329,"content":14330,"nodeType":1419},{},[14331],{"data":14332,"content":14333,"nodeType":883},{},[14334],{"data":14335,"marks":14336,"value":6763,"nodeType":882},{},[],{"data":14338,"content":14339,"nodeType":883},{},[14340,14343,14350,14353,14357],{"data":14341,"marks":14342,"value":6770,"nodeType":882},{},[],{"data":14344,"content":14345,"nodeType":929},{"uri":6773},[14346],{"data":14347,"marks":14348,"value":6779,"nodeType":882},{},[14349],{"type":1012},{"data":14351,"marks":14352,"value":6783,"nodeType":882},{},[],{"data":14354,"marks":14355,"value":6788,"nodeType":882},{},[14356],{"type":1045},{"data":14358,"marks":14359,"value":6792,"nodeType":882},{},[],{"data":14361,"content":14362,"nodeType":967},{},[],{"data":14364,"content":14365,"nodeType":975},{},[14366],{"data":14367,"marks":14368,"value":6803,"nodeType":882},{},[14369],{"type":1012},{"data":14371,"content":14372,"nodeType":883},{},[14373],{"data":14374,"marks":14375,"value":6811,"nodeType":882},{},[14376],{"type":1012},{"data":14378,"content":14379,"nodeType":883},{},[14380],{"data":14381,"marks":14382,"value":6818,"nodeType":882},{},[],{"data":14384,"content":14385,"nodeType":883},{},[14386],{"data":14387,"marks":14388,"value":6825,"nodeType":882},{},[],{"data":14390,"content":14391,"nodeType":967},{},[],{"data":14393,"content":14394,"nodeType":975},{},[14395],{"data":14396,"marks":14397,"value":6836,"nodeType":882},{},[14398],{"type":1012},{"data":14400,"content":14401,"nodeType":1454},{},[14402,14415,14428,14441],{"data":14403,"content":14404,"nodeType":1419},{},[14405],{"data":14406,"content":14407,"nodeType":883},{},[14408,14412],{"data":14409,"marks":14410,"value":6850,"nodeType":882},{},[14411],{"type":1012},{"data":14413,"marks":14414,"value":6854,"nodeType":882},{},[],{"data":14416,"content":14417,"nodeType":1419},{},[14418],{"data":14419,"content":14420,"nodeType":883},{},[14421,14425],{"data":14422,"marks":14423,"value":6865,"nodeType":882},{},[14424],{"type":1012},{"data":14426,"marks":14427,"value":6869,"nodeType":882},{},[],{"data":14429,"content":14430,"nodeType":1419},{},[14431],{"data":14432,"content":14433,"nodeType":883},{},[14434,14438],{"data":14435,"marks":14436,"value":6880,"nodeType":882},{},[14437],{"type":1012},{"data":14439,"marks":14440,"value":6884,"nodeType":882},{},[],{"data":14442,"content":14443,"nodeType":1419},{},[14444],{"data":14445,"content":14446,"nodeType":883},{},[14447,14451],{"data":14448,"marks":14449,"value":794,"nodeType":882},{},[14450],{"type":1012},{"data":14452,"marks":14453,"value":6898,"nodeType":882},{},[],{"data":14455,"content":14456,"nodeType":967},{},[],{"data":14458,"content":14459,"nodeType":975},{},[14460],{"data":14461,"marks":14462,"value":6909,"nodeType":882},{},[14463],{"type":1012},{"data":14465,"content":14466,"nodeType":883},{},[14467],{"data":14468,"marks":14469,"value":6916,"nodeType":882},{},[],{"data":14471,"content":14472,"nodeType":3104},{},[14473,14496,14518,14540,14562,14584,14606,14628,14650,14672,14694,14716],{"data":14474,"content":14475,"nodeType":3011},{},[14476,14486],{"data":14477,"content":14478,"nodeType":3025},{},[14479],{"data":14480,"content":14481,"nodeType":883},{},[14482],{"data":14483,"marks":14484,"value":6933,"nodeType":882},{},[14485],{"type":1012},{"data":14487,"content":14488,"nodeType":3025},{},[14489],{"data":14490,"content":14491,"nodeType":883},{},[14492],{"data":14493,"marks":14494,"value":6944,"nodeType":882},{},[14495],{"type":1012},{"data":14497,"content":14498,"nodeType":3011},{},[14499,14509],{"data":14500,"content":14501,"nodeType":3025},{},[14502],{"data":14503,"content":14504,"nodeType":883},{},[14505],{"data":14506,"marks":14507,"value":6958,"nodeType":882},{},[14508],{"type":1012},{"data":14510,"content":14511,"nodeType":3025},{},[14512],{"data":14513,"content":14514,"nodeType":883},{},[14515],{"data":14516,"marks":14517,"value":6968,"nodeType":882},{},[],{"data":14519,"content":14520,"nodeType":3011},{},[14521,14531],{"data":14522,"content":14523,"nodeType":3025},{},[14524],{"data":14525,"content":14526,"nodeType":883},{},[14527],{"data":14528,"marks":14529,"value":6982,"nodeType":882},{},[14530],{"type":1012},{"data":14532,"content":14533,"nodeType":3025},{},[14534],{"data":14535,"content":14536,"nodeType":883},{},[14537],{"data":14538,"marks":14539,"value":6992,"nodeType":882},{},[],{"data":14541,"content":14542,"nodeType":3011},{},[14543,14553],{"data":14544,"content":14545,"nodeType":3025},{},[14546],{"data":14547,"content":14548,"nodeType":883},{},[14549],{"data":14550,"marks":14551,"value":7006,"nodeType":882},{},[14552],{"type":1012},{"data":14554,"content":14555,"nodeType":3025},{},[14556],{"data":14557,"content":14558,"nodeType":883},{},[14559],{"data":14560,"marks":14561,"value":7016,"nodeType":882},{},[],{"data":14563,"content":14564,"nodeType":3011},{},[14565,14575],{"data":14566,"content":14567,"nodeType":3025},{},[14568],{"data":14569,"content":14570,"nodeType":883},{},[14571],{"data":14572,"marks":14573,"value":7030,"nodeType":882},{},[14574],{"type":1012},{"data":14576,"content":14577,"nodeType":3025},{},[14578],{"data":14579,"content":14580,"nodeType":883},{},[14581],{"data":14582,"marks":14583,"value":7040,"nodeType":882},{},[],{"data":14585,"content":14586,"nodeType":3011},{},[14587,14597],{"data":14588,"content":14589,"nodeType":3025},{},[14590],{"data":14591,"content":14592,"nodeType":883},{},[14593],{"data":14594,"marks":14595,"value":7054,"nodeType":882},{},[14596],{"type":1012},{"data":14598,"content":14599,"nodeType":3025},{},[14600],{"data":14601,"content":14602,"nodeType":883},{},[14603],{"data":14604,"marks":14605,"value":7064,"nodeType":882},{},[],{"data":14607,"content":14608,"nodeType":3011},{},[14609,14619],{"data":14610,"content":14611,"nodeType":3025},{},[14612],{"data":14613,"content":14614,"nodeType":883},{},[14615],{"data":14616,"marks":14617,"value":7078,"nodeType":882},{},[14618],{"type":1012},{"data":14620,"content":14621,"nodeType":3025},{},[14622],{"data":14623,"content":14624,"nodeType":883},{},[14625],{"data":14626,"marks":14627,"value":7088,"nodeType":882},{},[],{"data":14629,"content":14630,"nodeType":3011},{},[14631,14641],{"data":14632,"content":14633,"nodeType":3025},{},[14634],{"data":14635,"content":14636,"nodeType":883},{},[14637],{"data":14638,"marks":14639,"value":7102,"nodeType":882},{},[14640],{"type":1012},{"data":14642,"content":14643,"nodeType":3025},{},[14644],{"data":14645,"content":14646,"nodeType":883},{},[14647],{"data":14648,"marks":14649,"value":7112,"nodeType":882},{},[],{"data":14651,"content":14652,"nodeType":3011},{},[14653,14663],{"data":14654,"content":14655,"nodeType":3025},{},[14656],{"data":14657,"content":14658,"nodeType":883},{},[14659],{"data":14660,"marks":14661,"value":7126,"nodeType":882},{},[14662],{"type":1012},{"data":14664,"content":14665,"nodeType":3025},{},[14666],{"data":14667,"content":14668,"nodeType":883},{},[14669],{"data":14670,"marks":14671,"value":7136,"nodeType":882},{},[],{"data":14673,"content":14674,"nodeType":3011},{},[14675,14685],{"data":14676,"content":14677,"nodeType":3025},{},[14678],{"data":14679,"content":14680,"nodeType":883},{},[14681],{"data":14682,"marks":14683,"value":7150,"nodeType":882},{},[14684],{"type":1012},{"data":14686,"content":14687,"nodeType":3025},{},[14688],{"data":14689,"content":14690,"nodeType":883},{},[14691],{"data":14692,"marks":14693,"value":7160,"nodeType":882},{},[],{"data":14695,"content":14696,"nodeType":3011},{},[14697,14707],{"data":14698,"content":14699,"nodeType":3025},{},[14700],{"data":14701,"content":14702,"nodeType":883},{},[14703],{"data":14704,"marks":14705,"value":7174,"nodeType":882},{},[14706],{"type":1012},{"data":14708,"content":14709,"nodeType":3025},{},[14710],{"data":14711,"content":14712,"nodeType":883},{},[14713],{"data":14714,"marks":14715,"value":7184,"nodeType":882},{},[],{"data":14717,"content":14718,"nodeType":3011},{},[14719,14729],{"data":14720,"content":14721,"nodeType":3025},{},[14722],{"data":14723,"content":14724,"nodeType":883},{},[14725],{"data":14726,"marks":14727,"value":6865,"nodeType":882},{},[14728],{"type":1012},{"data":14730,"content":14731,"nodeType":3025},{},[14732],{"data":14733,"content":14734,"nodeType":883},{},[14735],{"data":14736,"marks":14737,"value":7207,"nodeType":882},{},[],{"data":14739,"content":14740,"nodeType":967},{},[],{"data":14742,"content":14743,"nodeType":883},{},[14744,14747,14753],{"data":14745,"marks":14746,"value":7217,"nodeType":882},{},[],{"data":14748,"content":14749,"nodeType":929},{"uri":1283},[14750],{"data":14751,"marks":14752,"value":2941,"nodeType":882},{},[],{"data":14754,"marks":14755,"value":21,"nodeType":882},{},[],{"items":14757},[14758,14760],{"sys":14759,"name":298},{"id":7235},{"sys":14761,"name":7239},{"id":7238},{"items":14763},[14764],{"fullName":3964,"firstName":3965,"jobTitle":868,"profilePicture":14765},{"url":3969},"blog\u002Fenterprise-browser-vs-browser-extension-which-should-your-security-team-choose",{"json":14768},{"data":14769,"content":14770,"nodeType":1294},{},[14771],{"data":14772,"content":14773,"nodeType":883},{},[14774],{"data":14775,"marks":14776,"value":14777,"nodeType":882},{},[],"If you're building a shortlist of browser security vendors, one of the first decisions you hit is an architectural one: full-stack enterprise browser, or browser security extension? ",{"id":9415,"publishedAt":14779},"2026-08-12T11:52:48.566Z",{"items":14781},[14782,14784],{"sys":14783,"name":298},{"id":7235},{"sys":14785,"name":7239},{"id":7238},{"items":14787},[14788,14790,14792,14794,14796,14798,14800,14802,14804,14806,14808,14810],{"sys":14789,"name":298,"slug":299,"tier":31},{"id":295},{"sys":14791,"name":280,"slug":281,"tier":31},{"id":277},{"sys":14793,"name":415,"slug":416,"tier":31},{"id":412},{"sys":14795,"name":388,"slug":389,"tier":45},{"id":385},{"sys":14797,"name":379,"slug":380,"tier":45},{"id":376},{"sys":14799,"name":262,"slug":263,"tier":45},{"id":259},{"sys":14801,"name":316,"slug":317,"tier":45},{"id":313},{"sys":14803,"name":486,"slug":487,"tier":45},{"id":483},{"sys":14805,"name":289,"slug":290,"tier":45},{"id":286},{"sys":14807,"name":623,"slug":624,"tier":45},{"id":620},{"sys":14809,"name":307,"slug":308,"tier":45},{"id":304},{"sys":14811,"name":591,"slug":592,"tier":45},{"id":588},"UhLNLgojmxTmt5rogpt-WncHPs8GJpCJ3gCXZJLR1EE",{"id":14814,"title":12999,"authorsCollection":14815,"content":14820,"extension":228,"faqItemsCollection":15365,"faqTitle":59,"featured":6,"hashTags":59,"meta":15367,"metaTitle":15368,"ogImage":59,"postType":1360,"publishedDate":13001,"relatedBlogPostsCollection":15369,"slug":13002,"stem":17967,"subtitle":59,"summary":17968,"synopsis":13000,"sys":17978,"tagsCollection":17980,"topicsCollection":17986,"__hash__":18028},"blog\u002Fblog\u002Fthe-case-for-best-of-breed-browser-security.json",{"items":14816},[14817],{"fullName":3964,"firstName":3965,"jobTitle":868,"socialLinks":14818,"profilePicture":14819},[3967],{"url":3969},{"json":14821,"links":15309},{"data":14822,"content":14823,"nodeType":1294},{},[14824,14830,14854,14860,14863,14870,14876,14882,14888,14895,14938,14944,14951,14957,14963,14970,14976,14982,14998,15023,15029,15032,15039,15046,15061,15068,15084,15091,15097,15104,15110,15117,15123,15126,15133,15139,15149,15164,15171,15177,15182,15189,15222,15227,15234,15249,15256,15271,15274,15281,15287,15293],{"data":14825,"content":14826,"nodeType":883},{},[14827],{"data":14828,"marks":14829,"value":12444,"nodeType":882},{},[],{"data":14831,"content":14832,"nodeType":883},{},[14833,14836,14842,14845,14851],{"data":14834,"marks":14835,"value":12451,"nodeType":882},{},[],{"data":14837,"content":14838,"nodeType":929},{"uri":6589},[14839],{"data":14840,"marks":14841,"value":12458,"nodeType":882},{},[],{"data":14843,"marks":14844,"value":2006,"nodeType":882},{},[],{"data":14846,"content":14847,"nodeType":929},{"uri":6589},[14848],{"data":14849,"marks":14850,"value":12468,"nodeType":882},{},[],{"data":14852,"marks":14853,"value":1438,"nodeType":882},{},[],{"data":14855,"content":14856,"nodeType":883},{},[14857],{"data":14858,"marks":14859,"value":12478,"nodeType":882},{},[],{"data":14861,"content":14862,"nodeType":967},{},[],{"data":14864,"content":14865,"nodeType":975},{},[14866],{"data":14867,"marks":14868,"value":12489,"nodeType":882},{},[14869],{"type":1012},{"data":14871,"content":14872,"nodeType":883},{},[14873],{"data":14874,"marks":14875,"value":12496,"nodeType":882},{},[],{"data":14877,"content":14878,"nodeType":883},{},[14879],{"data":14880,"marks":14881,"value":12503,"nodeType":882},{},[],{"data":14883,"content":14884,"nodeType":883},{},[14885],{"data":14886,"marks":14887,"value":12510,"nodeType":882},{},[],{"data":14889,"content":14890,"nodeType":2050},{},[14891],{"data":14892,"marks":14893,"value":12518,"nodeType":882},{},[14894],{"type":1012},{"data":14896,"content":14897,"nodeType":883},{},[14898,14901,14908,14911,14917,14920,14926,14929,14935],{"data":14899,"marks":14900,"value":21,"nodeType":882},{},[],{"data":14902,"content":14903,"nodeType":929},{"uri":12527},[14904],{"data":14905,"marks":14906,"value":12533,"nodeType":882},{},[14907],{"type":927},{"data":14909,"marks":14910,"value":12537,"nodeType":882},{},[],{"data":14912,"content":14913,"nodeType":929},{"uri":12540},[14914],{"data":14915,"marks":14916,"value":7388,"nodeType":882},{},[],{"data":14918,"marks":14919,"value":12548,"nodeType":882},{},[],{"data":14921,"content":14922,"nodeType":929},{"uri":12551},[14923],{"data":14924,"marks":14925,"value":12556,"nodeType":882},{},[],{"data":14927,"marks":14928,"value":12560,"nodeType":882},{},[],{"data":14930,"content":14931,"nodeType":929},{"uri":3507},[14932],{"data":14933,"marks":14934,"value":12567,"nodeType":882},{},[],{"data":14936,"marks":14937,"value":12571,"nodeType":882},{},[],{"data":14939,"content":14940,"nodeType":883},{},[14941],{"data":14942,"marks":14943,"value":12578,"nodeType":882},{},[],{"data":14945,"content":14946,"nodeType":2050},{},[14947],{"data":14948,"marks":14949,"value":12586,"nodeType":882},{},[14950],{"type":1012},{"data":14952,"content":14953,"nodeType":883},{},[14954],{"data":14955,"marks":14956,"value":12593,"nodeType":882},{},[],{"data":14958,"content":14959,"nodeType":883},{},[14960],{"data":14961,"marks":14962,"value":12600,"nodeType":882},{},[],{"data":14964,"content":14965,"nodeType":2050},{},[14966],{"data":14967,"marks":14968,"value":12608,"nodeType":882},{},[14969],{"type":1012},{"data":14971,"content":14972,"nodeType":883},{},[14973],{"data":14974,"marks":14975,"value":12615,"nodeType":882},{},[],{"data":14977,"content":14978,"nodeType":883},{},[14979],{"data":14980,"marks":14981,"value":12622,"nodeType":882},{},[],{"data":14983,"content":14984,"nodeType":883},{},[14985,14988,14995],{"data":14986,"marks":14987,"value":12629,"nodeType":882},{},[],{"data":14989,"content":14990,"nodeType":929},{"uri":3389},[14991],{"data":14992,"marks":14993,"value":12637,"nodeType":882},{},[14994],{"type":927},{"data":14996,"marks":14997,"value":12641,"nodeType":882},{},[],{"data":14999,"content":15000,"nodeType":883},{},[15001,15004,15010,15013,15020],{"data":15002,"marks":15003,"value":12648,"nodeType":882},{},[],{"data":15005,"content":15006,"nodeType":929},{"uri":6589},[15007],{"data":15008,"marks":15009,"value":12655,"nodeType":882},{},[],{"data":15011,"marks":15012,"value":12659,"nodeType":882},{},[],{"data":15014,"content":15015,"nodeType":929},{"uri":12662},[15016],{"data":15017,"marks":15018,"value":12668,"nodeType":882},{},[15019],{"type":927},{"data":15021,"marks":15022,"value":12672,"nodeType":882},{},[],{"data":15024,"content":15025,"nodeType":883},{},[15026],{"data":15027,"marks":15028,"value":12679,"nodeType":882},{},[],{"data":15030,"content":15031,"nodeType":967},{},[],{"data":15033,"content":15034,"nodeType":975},{},[15035],{"data":15036,"marks":15037,"value":12690,"nodeType":882},{},[15038],{"type":1012},{"data":15040,"content":15041,"nodeType":2050},{},[15042],{"data":15043,"marks":15044,"value":12698,"nodeType":882},{},[15045],{"type":1012},{"data":15047,"content":15048,"nodeType":883},{},[15049,15052,15058],{"data":15050,"marks":15051,"value":12705,"nodeType":882},{},[],{"data":15053,"content":15054,"nodeType":929},{"uri":8834},[15055],{"data":15056,"marks":15057,"value":12712,"nodeType":882},{},[],{"data":15059,"marks":15060,"value":12716,"nodeType":882},{},[],{"data":15062,"content":15063,"nodeType":2050},{},[15064],{"data":15065,"marks":15066,"value":12724,"nodeType":882},{},[15067],{"type":1012},{"data":15069,"content":15070,"nodeType":883},{},[15071,15074,15081],{"data":15072,"marks":15073,"value":12731,"nodeType":882},{},[],{"data":15075,"content":15076,"nodeType":929},{"uri":3214},[15077],{"data":15078,"marks":15079,"value":12739,"nodeType":882},{},[15080],{"type":927},{"data":15082,"marks":15083,"value":12743,"nodeType":882},{},[],{"data":15085,"content":15086,"nodeType":2050},{},[15087],{"data":15088,"marks":15089,"value":12751,"nodeType":882},{},[15090],{"type":1012},{"data":15092,"content":15093,"nodeType":883},{},[15094],{"data":15095,"marks":15096,"value":12758,"nodeType":882},{},[],{"data":15098,"content":15099,"nodeType":2050},{},[15100],{"data":15101,"marks":15102,"value":12766,"nodeType":882},{},[15103],{"type":1012},{"data":15105,"content":15106,"nodeType":883},{},[15107],{"data":15108,"marks":15109,"value":12773,"nodeType":882},{},[],{"data":15111,"content":15112,"nodeType":2050},{},[15113],{"data":15114,"marks":15115,"value":12781,"nodeType":882},{},[15116],{"type":1012},{"data":15118,"content":15119,"nodeType":883},{},[15120],{"data":15121,"marks":15122,"value":12788,"nodeType":882},{},[],{"data":15124,"content":15125,"nodeType":967},{},[],{"data":15127,"content":15128,"nodeType":975},{},[15129],{"data":15130,"marks":15131,"value":12799,"nodeType":882},{},[15132],{"type":1012},{"data":15134,"content":15135,"nodeType":883},{},[15136],{"data":15137,"marks":15138,"value":12806,"nodeType":882},{},[],{"data":15140,"content":15141,"nodeType":2050},{},[15142,15146],{"data":15143,"marks":15144,"value":12814,"nodeType":882},{},[15145],{"type":1012},{"data":15147,"marks":15148,"value":2218,"nodeType":882},{},[],{"data":15150,"content":15151,"nodeType":883},{},[15152,15155,15161],{"data":15153,"marks":15154,"value":12824,"nodeType":882},{},[],{"data":15156,"content":15157,"nodeType":929},{"uri":8638},[15158],{"data":15159,"marks":15160,"value":12831,"nodeType":882},{},[],{"data":15162,"marks":15163,"value":12835,"nodeType":882},{},[],{"data":15165,"content":15166,"nodeType":2050},{},[15167],{"data":15168,"marks":15169,"value":12843,"nodeType":882},{},[15170],{"type":1012},{"data":15172,"content":15173,"nodeType":883},{},[15174],{"data":15175,"marks":15176,"value":12850,"nodeType":882},{},[],{"data":15178,"content":15181,"nodeType":963},{"target":15179},{"sys":15180},{"id":12855,"type":960,"linkType":961},[],{"data":15183,"content":15184,"nodeType":2050},{},[15185],{"data":15186,"marks":15187,"value":12864,"nodeType":882},{},[15188],{"type":1012},{"data":15190,"content":15191,"nodeType":883},{},[15192,15195,15201,15204,15210,15213,15219],{"data":15193,"marks":15194,"value":12871,"nodeType":882},{},[],{"data":15196,"content":15197,"nodeType":929},{"uri":3582},[15198],{"data":15199,"marks":15200,"value":1989,"nodeType":882},{},[],{"data":15202,"marks":15203,"value":2633,"nodeType":882},{},[],{"data":15205,"content":15206,"nodeType":929},{"uri":3823},[15207],{"data":15208,"marks":15209,"value":2002,"nodeType":882},{},[],{"data":15211,"marks":15212,"value":12890,"nodeType":882},{},[],{"data":15214,"content":15215,"nodeType":929},{"uri":2893},[15216],{"data":15217,"marks":15218,"value":9013,"nodeType":882},{},[],{"data":15220,"marks":15221,"value":12900,"nodeType":882},{},[],{"data":15223,"content":15226,"nodeType":963},{"target":15224},{"sys":15225},{"id":12905,"type":960,"linkType":961},[],{"data":15228,"content":15229,"nodeType":2050},{},[15230],{"data":15231,"marks":15232,"value":12914,"nodeType":882},{},[15233],{"type":1012},{"data":15235,"content":15236,"nodeType":883},{},[15237,15240,15246],{"data":15238,"marks":15239,"value":12921,"nodeType":882},{},[],{"data":15241,"content":15242,"nodeType":929},{"uri":8834},[15243],{"data":15244,"marks":15245,"value":12928,"nodeType":882},{},[],{"data":15247,"marks":15248,"value":1438,"nodeType":882},{},[],{"data":15250,"content":15251,"nodeType":2050},{},[15252],{"data":15253,"marks":15254,"value":12939,"nodeType":882},{},[15255],{"type":1012},{"data":15257,"content":15258,"nodeType":883},{},[15259,15262,15268],{"data":15260,"marks":15261,"value":12946,"nodeType":882},{},[],{"data":15263,"content":15264,"nodeType":929},{"uri":4493},[15265],{"data":15266,"marks":15267,"value":12953,"nodeType":882},{},[],{"data":15269,"marks":15270,"value":12957,"nodeType":882},{},[],{"data":15272,"content":15273,"nodeType":967},{},[],{"data":15275,"content":15276,"nodeType":975},{},[15277],{"data":15278,"marks":15279,"value":12968,"nodeType":882},{},[15280],{"type":1012},{"data":15282,"content":15283,"nodeType":883},{},[15284],{"data":15285,"marks":15286,"value":12975,"nodeType":882},{},[],{"data":15288,"content":15289,"nodeType":883},{},[15290],{"data":15291,"marks":15292,"value":12982,"nodeType":882},{},[],{"data":15294,"content":15295,"nodeType":883},{},[15296,15299,15306],{"data":15297,"marks":15298,"value":21,"nodeType":882},{},[],{"data":15300,"content":15301,"nodeType":929},{"uri":1283},[15302],{"data":15303,"marks":15304,"value":2941,"nodeType":882},{},[15305],{"type":927},{"data":15307,"marks":15308,"value":21,"nodeType":882},{},[],{"entries":15310},{"hyperlink":15311,"inline":15312,"block":15313},[],[],[15314,15332],{"sys":15315,"__typename":1302,"content":15316,"name":15331,"title":59},{"id":12855},{"json":15317},{"nodeType":1294,"data":15318,"content":15319},{},[15320],{"nodeType":883,"data":15321,"content":15322},{},[15323,15328],{"nodeType":882,"value":15324,"marks":15325,"data":15327},"In a 30-day POV at a ~4,500-employee financial services organization with a mature existing stack, Push detected 6 ClickFix attacks and 10 AiTM phishing attempts that were invisible to every other tool in place",[15326],{"type":1012},{},{"nodeType":882,"value":1438,"marks":15329,"data":15330},[],{},"Best of breed blog IB1",{"sys":15333,"__typename":1302,"content":15334,"name":15364,"title":59},{"id":12905},{"json":15335},{"nodeType":1294,"data":15336,"content":15337},{},[15338],{"nodeType":883,"data":15339,"content":15340},{},[15341,15345,15351,15355,15360],{"nodeType":882,"value":15342,"marks":15343,"data":15344},"Our ",[],{},{"nodeType":929,"data":15346,"content":15347},{"uri":2893},[15348],{"nodeType":882,"value":2898,"marks":15349,"data":15350},[],{},{"nodeType":882,"value":15352,"marks":15353,"data":15354}," has ",[],{},{"nodeType":882,"value":15356,"marks":15357,"data":15359},"tripled the new detections shipped per month",[15358],{"type":1012},{},{"nodeType":882,"value":15361,"marks":15362,"data":15363}," — and as a dedicated browser security vendor, that's where every research dollar goes. When attackers are harnessing AI to develop tooling, deploy and tear-down infrastructure, and operate campaigns at scale, this capability is essential to stay ahead of the increased volume and variation in threats that users are encountering in the browser. ",[],{},"Best of breed blog IB2",{"items":15366},[],{},"The case for best-of-breed browser security",{"items":15370},[15371,16043,16886],{"__typename":1365,"sys":15372,"content":15373,"title":8015,"synopsis":8016,"hashTags":59,"publishedDate":8017,"slug":8018,"tagsCollection":16033,"authorsCollection":16039},{"id":7246},{"json":15374},{"data":15375,"content":15376,"nodeType":1294},{},[15377,15382,15388,15394,15400,15403,15410,15416,15426,15436,15441,15447,15450,15457,15463,15468,15474,15480,15573,15579,15582,15589,15595,15650,15663,15668,15674,15677,15684,15690,15697,15703,15709,15734,15740,15747,15753,15759,15765,15772,15778,15784,15790,15793,15800,15810,15816,15822,15829,15835,15841,15848,15854,15909,15922,15937,15944,15950,15957,15963,15969,15975,15980,15987,15993,15999,16004,16010,16016,16022,16027],{"data":15378,"content":15381,"nodeType":963},{"target":15379},{"sys":15380},{"id":7255,"type":960,"linkType":961},[],{"data":15383,"content":15384,"nodeType":883},{},[15385],{"data":15386,"marks":15387,"value":7263,"nodeType":882},{},[],{"data":15389,"content":15390,"nodeType":883},{},[15391],{"data":15392,"marks":15393,"value":7270,"nodeType":882},{},[],{"data":15395,"content":15396,"nodeType":883},{},[15397],{"data":15398,"marks":15399,"value":7277,"nodeType":882},{},[],{"data":15401,"content":15402,"nodeType":967},{},[],{"data":15404,"content":15405,"nodeType":975},{},[15406],{"data":15407,"marks":15408,"value":7288,"nodeType":882},{},[15409],{"type":1012},{"data":15411,"content":15412,"nodeType":883},{},[15413],{"data":15414,"marks":15415,"value":7295,"nodeType":882},{},[],{"data":15417,"content":15418,"nodeType":883},{},[15419,15423],{"data":15420,"marks":15421,"value":7303,"nodeType":882},{},[15422],{"type":1012},{"data":15424,"marks":15425,"value":7307,"nodeType":882},{},[],{"data":15427,"content":15428,"nodeType":883},{},[15429,15433],{"data":15430,"marks":15431,"value":7315,"nodeType":882},{},[15432],{"type":1012},{"data":15434,"marks":15435,"value":7319,"nodeType":882},{},[],{"data":15437,"content":15440,"nodeType":963},{"target":15438},{"sys":15439},{"id":7324,"type":960,"linkType":961},[],{"data":15442,"content":15443,"nodeType":883},{},[15444],{"data":15445,"marks":15446,"value":7332,"nodeType":882},{},[],{"data":15448,"content":15449,"nodeType":967},{},[],{"data":15451,"content":15452,"nodeType":975},{},[15453],{"data":15454,"marks":15455,"value":7343,"nodeType":882},{},[15456],{"type":1012},{"data":15458,"content":15459,"nodeType":883},{},[15460],{"data":15461,"marks":15462,"value":7350,"nodeType":882},{},[],{"data":15464,"content":15467,"nodeType":963},{"target":15465},{"sys":15466},{"id":7355,"type":960,"linkType":961},[],{"data":15469,"content":15470,"nodeType":883},{},[15471],{"data":15472,"marks":15473,"value":7363,"nodeType":882},{},[],{"data":15475,"content":15476,"nodeType":883},{},[15477],{"data":15478,"marks":15479,"value":7370,"nodeType":882},{},[],{"data":15481,"content":15482,"nodeType":1454},{},[15483,15499,15515,15531,15547,15560],{"data":15484,"content":15485,"nodeType":1419},{},[15486],{"data":15487,"content":15488,"nodeType":883},{},[15489,15492,15496],{"data":15490,"marks":15491,"value":7383,"nodeType":882},{},[],{"data":15493,"marks":15494,"value":7388,"nodeType":882},{},[15495],{"type":1012},{"data":15497,"marks":15498,"value":7392,"nodeType":882},{},[],{"data":15500,"content":15501,"nodeType":1419},{},[15502],{"data":15503,"content":15504,"nodeType":883},{},[15505,15508,15512],{"data":15506,"marks":15507,"value":7402,"nodeType":882},{},[],{"data":15509,"marks":15510,"value":7407,"nodeType":882},{},[15511],{"type":1012},{"data":15513,"marks":15514,"value":7411,"nodeType":882},{},[],{"data":15516,"content":15517,"nodeType":1419},{},[15518],{"data":15519,"content":15520,"nodeType":883},{},[15521,15524,15528],{"data":15522,"marks":15523,"value":7421,"nodeType":882},{},[],{"data":15525,"marks":15526,"value":7426,"nodeType":882},{},[15527],{"type":1012},{"data":15529,"marks":15530,"value":7430,"nodeType":882},{},[],{"data":15532,"content":15533,"nodeType":1419},{},[15534],{"data":15535,"content":15536,"nodeType":883},{},[15537,15540,15544],{"data":15538,"marks":15539,"value":7440,"nodeType":882},{},[],{"data":15541,"marks":15542,"value":7445,"nodeType":882},{},[15543],{"type":1012},{"data":15545,"marks":15546,"value":7449,"nodeType":882},{},[],{"data":15548,"content":15549,"nodeType":1419},{},[15550],{"data":15551,"content":15552,"nodeType":883},{},[15553,15557],{"data":15554,"marks":15555,"value":7460,"nodeType":882},{},[15556],{"type":1012},{"data":15558,"marks":15559,"value":7464,"nodeType":882},{},[],{"data":15561,"content":15562,"nodeType":1419},{},[15563],{"data":15564,"content":15565,"nodeType":883},{},[15566,15570],{"data":15567,"marks":15568,"value":7475,"nodeType":882},{},[15569],{"type":1012},{"data":15571,"marks":15572,"value":7479,"nodeType":882},{},[],{"data":15574,"content":15575,"nodeType":883},{},[15576],{"data":15577,"marks":15578,"value":7486,"nodeType":882},{},[],{"data":15580,"content":15581,"nodeType":967},{},[],{"data":15583,"content":15584,"nodeType":2050},{},[15585],{"data":15586,"marks":15587,"value":7497,"nodeType":882},{},[15588],{"type":1012},{"data":15590,"content":15591,"nodeType":883},{},[15592],{"data":15593,"marks":15594,"value":7504,"nodeType":882},{},[],{"data":15596,"content":15597,"nodeType":1454},{},[15598,15611,15624,15637],{"data":15599,"content":15600,"nodeType":1419},{},[15601],{"data":15602,"content":15603,"nodeType":883},{},[15604,15607],{"data":15605,"marks":15606,"value":7517,"nodeType":882},{},[],{"data":15608,"marks":15609,"value":7522,"nodeType":882},{},[15610],{"type":1012},{"data":15612,"content":15613,"nodeType":1419},{},[15614],{"data":15615,"content":15616,"nodeType":883},{},[15617,15620],{"data":15618,"marks":15619,"value":7532,"nodeType":882},{},[],{"data":15621,"marks":15622,"value":7537,"nodeType":882},{},[15623],{"type":1012},{"data":15625,"content":15626,"nodeType":1419},{},[15627],{"data":15628,"content":15629,"nodeType":883},{},[15630,15633],{"data":15631,"marks":15632,"value":7547,"nodeType":882},{},[],{"data":15634,"marks":15635,"value":7552,"nodeType":882},{},[15636],{"type":1012},{"data":15638,"content":15639,"nodeType":1419},{},[15640],{"data":15641,"content":15642,"nodeType":883},{},[15643,15646],{"data":15644,"marks":15645,"value":7562,"nodeType":882},{},[],{"data":15647,"marks":15648,"value":7567,"nodeType":882},{},[15649],{"type":1012},{"data":15651,"content":15652,"nodeType":883},{},[15653,15656,15660],{"data":15654,"marks":15655,"value":7574,"nodeType":882},{},[],{"data":15657,"marks":15658,"value":7579,"nodeType":882},{},[15659],{"type":1012},{"data":15661,"marks":15662,"value":7583,"nodeType":882},{},[],{"data":15664,"content":15667,"nodeType":963},{"target":15665},{"sys":15666},{"id":7588,"type":960,"linkType":961},[],{"data":15669,"content":15670,"nodeType":883},{},[15671],{"data":15672,"marks":15673,"value":7596,"nodeType":882},{},[],{"data":15675,"content":15676,"nodeType":967},{},[],{"data":15678,"content":15679,"nodeType":975},{},[15680],{"data":15681,"marks":15682,"value":7607,"nodeType":882},{},[15683],{"type":1012},{"data":15685,"content":15686,"nodeType":883},{},[15687],{"data":15688,"marks":15689,"value":7614,"nodeType":882},{},[],{"data":15691,"content":15692,"nodeType":2050},{},[15693],{"data":15694,"marks":15695,"value":7622,"nodeType":882},{},[15696],{"type":1012},{"data":15698,"content":15699,"nodeType":883},{},[15700],{"data":15701,"marks":15702,"value":7629,"nodeType":882},{},[],{"data":15704,"content":15705,"nodeType":883},{},[15706],{"data":15707,"marks":15708,"value":7636,"nodeType":882},{},[],{"data":15710,"content":15711,"nodeType":883},{},[15712,15715,15721,15724,15731],{"data":15713,"marks":15714,"value":7643,"nodeType":882},{},[],{"data":15716,"content":15717,"nodeType":929},{"uri":6589},[15718],{"data":15719,"marks":15720,"value":7650,"nodeType":882},{},[],{"data":15722,"marks":15723,"value":7654,"nodeType":882},{},[],{"data":15725,"content":15726,"nodeType":929},{"uri":7657},[15727],{"data":15728,"marks":15729,"value":7663,"nodeType":882},{},[15730],{"type":927},{"data":15732,"marks":15733,"value":7667,"nodeType":882},{},[],{"data":15735,"content":15736,"nodeType":883},{},[15737],{"data":15738,"marks":15739,"value":7674,"nodeType":882},{},[],{"data":15741,"content":15742,"nodeType":2050},{},[15743],{"data":15744,"marks":15745,"value":7682,"nodeType":882},{},[15746],{"type":1012},{"data":15748,"content":15749,"nodeType":883},{},[15750],{"data":15751,"marks":15752,"value":7689,"nodeType":882},{},[],{"data":15754,"content":15755,"nodeType":883},{},[15756],{"data":15757,"marks":15758,"value":7696,"nodeType":882},{},[],{"data":15760,"content":15761,"nodeType":883},{},[15762],{"data":15763,"marks":15764,"value":7703,"nodeType":882},{},[],{"data":15766,"content":15767,"nodeType":2050},{},[15768],{"data":15769,"marks":15770,"value":7711,"nodeType":882},{},[15771],{"type":1012},{"data":15773,"content":15774,"nodeType":883},{},[15775],{"data":15776,"marks":15777,"value":7718,"nodeType":882},{},[],{"data":15779,"content":15780,"nodeType":883},{},[15781],{"data":15782,"marks":15783,"value":7725,"nodeType":882},{},[],{"data":15785,"content":15786,"nodeType":883},{},[15787],{"data":15788,"marks":15789,"value":7732,"nodeType":882},{},[],{"data":15791,"content":15792,"nodeType":967},{},[],{"data":15794,"content":15795,"nodeType":975},{},[15796],{"data":15797,"marks":15798,"value":7743,"nodeType":882},{},[15799],{"type":1012},{"data":15801,"content":15802,"nodeType":883},{},[15803,15807],{"data":15804,"marks":15805,"value":7751,"nodeType":882},{},[15806],{"type":1012},{"data":15808,"marks":15809,"value":7755,"nodeType":882},{},[],{"data":15811,"content":15812,"nodeType":883},{},[15813],{"data":15814,"marks":15815,"value":7762,"nodeType":882},{},[],{"data":15817,"content":15818,"nodeType":883},{},[15819],{"data":15820,"marks":15821,"value":7769,"nodeType":882},{},[],{"data":15823,"content":15824,"nodeType":2050},{},[15825],{"data":15826,"marks":15827,"value":7777,"nodeType":882},{},[15828],{"type":1012},{"data":15830,"content":15831,"nodeType":883},{},[15832],{"data":15833,"marks":15834,"value":7784,"nodeType":882},{},[],{"data":15836,"content":15837,"nodeType":883},{},[15838],{"data":15839,"marks":15840,"value":7791,"nodeType":882},{},[],{"data":15842,"content":15843,"nodeType":2050},{},[15844],{"data":15845,"marks":15846,"value":7799,"nodeType":882},{},[15847],{"type":1012},{"data":15849,"content":15850,"nodeType":883},{},[15851],{"data":15852,"marks":15853,"value":7806,"nodeType":882},{},[],{"data":15855,"content":15856,"nodeType":1454},{},[15857,15870,15883,15896],{"data":15858,"content":15859,"nodeType":1419},{},[15860],{"data":15861,"content":15862,"nodeType":883},{},[15863,15867],{"data":15864,"marks":15865,"value":7820,"nodeType":882},{},[15866],{"type":1012},{"data":15868,"marks":15869,"value":7824,"nodeType":882},{},[],{"data":15871,"content":15872,"nodeType":1419},{},[15873],{"data":15874,"content":15875,"nodeType":883},{},[15876,15880],{"data":15877,"marks":15878,"value":7835,"nodeType":882},{},[15879],{"type":1012},{"data":15881,"marks":15882,"value":7839,"nodeType":882},{},[],{"data":15884,"content":15885,"nodeType":1419},{},[15886],{"data":15887,"content":15888,"nodeType":883},{},[15889,15893],{"data":15890,"marks":15891,"value":7850,"nodeType":882},{},[15892],{"type":1012},{"data":15894,"marks":15895,"value":7854,"nodeType":882},{},[],{"data":15897,"content":15898,"nodeType":1419},{},[15899],{"data":15900,"content":15901,"nodeType":883},{},[15902,15906],{"data":15903,"marks":15904,"value":7865,"nodeType":882},{},[15905],{"type":1012},{"data":15907,"marks":15908,"value":7869,"nodeType":882},{},[],{"data":15910,"content":15911,"nodeType":883},{},[15912,15915,15919],{"data":15913,"marks":15914,"value":7876,"nodeType":882},{},[],{"data":15916,"marks":15917,"value":7881,"nodeType":882},{},[15918],{"type":1012},{"data":15920,"marks":15921,"value":7885,"nodeType":882},{},[],{"data":15923,"content":15924,"nodeType":883},{},[15925,15928,15934],{"data":15926,"marks":15927,"value":7892,"nodeType":882},{},[],{"data":15929,"content":15930,"nodeType":929},{"uri":7895},[15931],{"data":15932,"marks":15933,"value":7900,"nodeType":882},{},[],{"data":15935,"marks":15936,"value":7904,"nodeType":882},{},[],{"data":15938,"content":15939,"nodeType":2050},{},[15940],{"data":15941,"marks":15942,"value":7912,"nodeType":882},{},[15943],{"type":1012},{"data":15945,"content":15946,"nodeType":883},{},[15947],{"data":15948,"marks":15949,"value":7919,"nodeType":882},{},[],{"data":15951,"content":15952,"nodeType":883},{},[15953],{"data":15954,"marks":15955,"value":7927,"nodeType":882},{},[15956],{"type":1012},{"data":15958,"content":15959,"nodeType":883},{},[15960],{"data":15961,"marks":15962,"value":7934,"nodeType":882},{},[],{"data":15964,"content":15965,"nodeType":883},{},[15966],{"data":15967,"marks":15968,"value":7941,"nodeType":882},{},[],{"data":15970,"content":15971,"nodeType":883},{},[15972],{"data":15973,"marks":15974,"value":7948,"nodeType":882},{},[],{"data":15976,"content":15979,"nodeType":963},{"target":15977},{"sys":15978},{"id":7953,"type":960,"linkType":961},[],{"data":15981,"content":15982,"nodeType":2050},{},[15983],{"data":15984,"marks":15985,"value":7962,"nodeType":882},{},[15986],{"type":1012},{"data":15988,"content":15989,"nodeType":883},{},[15990],{"data":15991,"marks":15992,"value":7969,"nodeType":882},{},[],{"data":15994,"content":15995,"nodeType":883},{},[15996],{"data":15997,"marks":15998,"value":7976,"nodeType":882},{},[],{"data":16000,"content":16003,"nodeType":963},{"target":16001},{"sys":16002},{"id":4417,"type":960,"linkType":961},[],{"data":16005,"content":16006,"nodeType":883},{},[16007],{"data":16008,"marks":16009,"value":7988,"nodeType":882},{},[],{"data":16011,"content":16012,"nodeType":883},{},[16013],{"data":16014,"marks":16015,"value":7995,"nodeType":882},{},[],{"data":16017,"content":16018,"nodeType":883},{},[16019],{"data":16020,"marks":16021,"value":8002,"nodeType":882},{},[],{"data":16023,"content":16026,"nodeType":963},{"target":16024},{"sys":16025},{"id":8007,"type":960,"linkType":961},[],{"data":16028,"content":16029,"nodeType":883},{},[16030],{"data":16031,"marks":16032,"value":21,"nodeType":882},{},[],{"items":16034},[16035,16037],{"sys":16036,"name":298},{"id":7235},{"sys":16038,"name":7239},{"id":7238},{"items":16040},[16041],{"fullName":3964,"firstName":3965,"jobTitle":868,"profilePicture":16042},{"url":3969},{"__typename":1365,"sys":16044,"content":16046,"title":16872,"synopsis":16873,"hashTags":59,"publishedDate":16874,"slug":16875,"tagsCollection":16876,"authorsCollection":16882},{"id":16045},"211Dd0EIrXPOFpvRgs0fEE",{"json":16047},{"data":16048,"content":16049,"nodeType":1294},{},[16050,16069,16088,16105,16111,16114,16122,16129,16136,16143,16150,16158,16161,16169,16176,16183,16190,16195,16203,16222,16229,16236,16252,16260,16289,16305,16312,16339,16347,16377,16384,16392,16410,16417,16424,16430,16437,16445,16463,16470,16489,16496,16499,16507,16514,16600,16607,16623,16626,16654,16673,16680,16687,16690,16698,16717,16724,16731,16748,16751,16759,16766,16799,16806,16823,16841,16847,16850,16857],{"data":16051,"content":16052,"nodeType":883},{},[16053,16057,16065],{"data":16054,"marks":16055,"value":16056,"nodeType":882},{},[],"When we released the ",{"data":16058,"content":16060,"nodeType":929},{"uri":16059},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fsaas-attack-techniques\u002F",[16061],{"data":16062,"marks":16063,"value":16064,"nodeType":882},{},[],"SaaS attack matrix",{"data":16066,"marks":16067,"value":16068,"nodeType":882},{},[]," in 2023, we were anticipating a shift that was just beginning to take shape. The techniques that attackers were using to compromise cloud applications and identities weren't well represented in existing frameworks, and many of the ones we documented hadn't yet been widely observed in the wild.",{"data":16070,"content":16071,"nodeType":883},{},[16072,16076,16084],{"data":16073,"marks":16074,"value":16075,"nodeType":882},{},[],"A year later, we ",{"data":16077,"content":16079,"nodeType":929},{"uri":16078},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fthe-saas-attack-matrix-one-year-on\u002F",[16080],{"data":16081,"marks":16082,"value":16083,"nodeType":882},{},[],"reviewed what had changed",{"data":16085,"marks":16086,"value":16087,"nodeType":882},{},[]," and found that the initial access phase — the techniques designed to compromise an identity in the first place — was where almost all of the attacker innovation was concentrated. And two years on, that trend has become the story of the modern threat landscape. ",{"data":16089,"content":16090,"nodeType":883},{},[16091,16095,16101],{"data":16092,"marks":16093,"value":16094,"nodeType":882},{},[],"Today, we're re-releasing the matrix as the ",{"data":16096,"content":16097,"nodeType":929},{"uri":9691},[16098],{"data":16099,"marks":16100,"value":9875,"nodeType":882},{},[],{"data":16102,"marks":16103,"value":16104,"nodeType":882},{},[],". The name change isn't cosmetic. It reflects that the attacks driving the most consequential breaches are browser-based and identity-first.",{"data":16106,"content":16110,"nodeType":963},{"target":16107},{"sys":16108},{"id":16109,"type":960,"linkType":961},"MSnrBRJtiQxpv2qxFLCVE",[],{"data":16112,"content":16113,"nodeType":967},{},[],{"data":16115,"content":16116,"nodeType":975},{},[16117],{"data":16118,"marks":16119,"value":16121,"nodeType":882},{},[16120],{"type":1012},"Why the scope needed to change",{"data":16123,"content":16124,"nodeType":883},{},[16125],{"data":16126,"marks":16127,"value":16128,"nodeType":882},{},[],"The original SaaS attack matrix was built around a specific insight: that attacks targeting modern business applications played out entirely over the internet, without touching endpoints or internal networks in any way that EDR or network detection tools would recognize.",{"data":16130,"content":16131,"nodeType":883},{},[16132],{"data":16133,"marks":16134,"value":16135,"nodeType":882},{},[],"That framing was useful, and it remains true. But it anchored the matrix to the post-access phase — what attackers do once they're inside a SaaS application — and didn't give enough weight to the initial access techniques that determine whether attackers get there in the first place.",{"data":16137,"content":16138,"nodeType":883},{},[16139],{"data":16140,"marks":16141,"value":16142,"nodeType":882},{},[],"The problem is that initial access is where the overwhelming majority of attacker innovation and investment is concentrated, and the techniques being used to achieve it are best understood as browser and identity attacks rather than SaaS-specific ones. AiTM phishing, ClickFix and its growing family of clipboard-injection variants, device code phishing, OAuth consent abuse, credential stuffing powered by infostealer supply chains, malicious browser extensions all happen in or via the browser.",{"data":16144,"content":16145,"nodeType":883},{},[16146],{"data":16147,"marks":16148,"value":16149,"nodeType":882},{},[],"Another issue is that \"SaaS\" has arguably ceased to be a meaningful category. When we consider that most organizations run the majority of their business on cloud applications, the difference between what constitutes \"SaaS\" versus cloud versus just \"business IT\" is pretty blurry (and feels like an academic rather than practical difference).",{"data":16151,"content":16152,"nodeType":883},{},[16153],{"data":16154,"marks":16155,"value":16157,"nodeType":882},{},[16156],{"type":1012},"So it's less about whether an attack is a \"SaaS attack\" and more about how these attacks actually play out. ",{"data":16159,"content":16160,"nodeType":967},{},[],{"data":16162,"content":16163,"nodeType":975},{},[16164],{"data":16165,"marks":16166,"value":16168,"nodeType":882},{},[16167],{"type":1012},"The technique landscape has transformed",{"data":16170,"content":16171,"nodeType":883},{},[16172],{"data":16173,"marks":16174,"value":16175,"nodeType":882},{},[],"The second part to the change is the fact that scale and speed of attacker innovation in the space justifies it.",{"data":16177,"content":16178,"nodeType":883},{},[16179],{"data":16180,"marks":16181,"value":16182,"nodeType":882},{},[],"When we launched the matrix in mid-2023, AiTM phishing was emerging as a serious concern but was far from ubiquitous. ClickFix didn't exist as a named technique. Device code phishing was a curiosity documented by a handful of researchers. ConsentFix was years away from being discovered. Browser extension supply chain attacks were rare enough to be individually notable.",{"data":16184,"content":16185,"nodeType":883},{},[16186],{"data":16187,"marks":16188,"value":16189,"nodeType":882},{},[],"In the two and a half years since, every one of these has become a mainstream, industrialized attack technique — and several have converged in ways that would have been hard to predict.",{"data":16191,"content":16194,"nodeType":963},{"target":16192},{"sys":16193},{"id":7324,"type":960,"linkType":961},[],{"data":16196,"content":16197,"nodeType":2050},{},[16198],{"data":16199,"marks":16200,"value":16202,"nodeType":882},{},[16201],{"type":1012},"AiTM phishing has become the default phishing method",{"data":16204,"content":16205,"nodeType":883},{},[16206,16210,16218],{"data":16207,"marks":16208,"value":16209,"nodeType":882},{},[],"AiTM phishing is now the standard, powered by Phishing-as-a-Service kits that operate with the release cycles and customer support of legitimate SaaS products. Tycoon 2FA alone accounted for ",{"data":16211,"content":16213,"nodeType":929},{"uri":16212},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002F2025-top-phishing-trends\u002F",[16214],{"data":16215,"marks":16216,"value":16217,"nodeType":882},{},[],"62% of phishing detected by Microsoft",{"data":16219,"marks":16220,"value":16221,"nodeType":882},{},[]," and over 64,000 confirmed incidents, with Sneaky2FA, FlowerStorm, Evilginx, and a growing roster of competitors filling out the marketplace.",{"data":16223,"content":16224,"nodeType":883},{},[16225],{"data":16226,"marks":16227,"value":16228,"nodeType":882},{},[],"AiTM is constantly evolving, with vendors adding new features, capabilities, detection evasion techniques, and so on. Abuse of legitimate platforms, and increasingly AI-assisted development means that it’s trivial for attackers to spin up and tear down infrastructure, scale their campaigns, target specific organizations with crafted pages and lures, and generally means that attackers can operate highly sophisticated attacks with minimal effort and complexity. This makes AiTM and other PhaaS-powered techniques extremely accessible to all kinds of criminals.  ",{"data":16230,"content":16231,"nodeType":883},{},[16232],{"data":16233,"marks":16234,"value":16235,"nodeType":882},{},[],"These kits are delivered across several browser-based channels — not just email. Push data consistently shows that roughly 1 in 3 phishing payloads we intercept arrive via social media, search ads, messaging apps, or other non-email vectors.",{"data":16237,"content":16238,"nodeType":883},{},[16239,16243,16248],{"data":16240,"marks":16241,"value":16242,"nodeType":882},{},[],"Vishing has also surged as a delivery channel — CrowdStrike documented a ",{"data":16244,"marks":16245,"value":16247,"nodeType":882},{},[16246],{"type":1012},"442% year-over-year increase",{"data":16249,"marks":16250,"value":16251,"nodeType":882},{},[],", and Mandiant found it was the single most common initial vector in cloud compromises at 23%. But the trend that matters isn't voice calls in isolation; it's voice calls combined with browser-based payloads, where a live operator guides the victim into an AiTM page or device code flow that the call alone could not execute.",{"data":16253,"content":16254,"nodeType":2050},{},[16255],{"data":16256,"marks":16257,"value":16259,"nodeType":882},{},[16258],{"type":1012},"ClickFix is the top reported initial access vector",{"data":16261,"content":16262,"nodeType":883},{},[16263,16267,16274,16278,16285],{"data":16264,"marks":16265,"value":16266,"nodeType":882},{},[],"ClickFix has gone from nonexistent to one of the most prevalent initial access techniques in under 18 months. Microsoft reported it as the ",{"data":16268,"content":16269,"nodeType":929},{"uri":3554},[16270],{"data":16271,"marks":16272,"value":16273,"nodeType":882},{},[],"most common initial access vector in 2025",{"data":16275,"marks":16276,"value":16277,"nodeType":882},{},[],", accounting for 47% of observed attacks, while CrowdStrike documented a ",{"data":16279,"content":16280,"nodeType":929},{"uri":6520},[16281],{"data":16282,"marks":16283,"value":16284,"nodeType":882},{},[],"563% increase",{"data":16286,"marks":16287,"value":16288,"nodeType":882},{},[]," in fake CAPTCHA lures (a top ClickFix style).",{"data":16290,"content":16291,"nodeType":883},{},[16292,16296,16301],{"data":16293,"marks":16294,"value":16295,"nodeType":882},{},[],"ClickFix is admittedly an outlier in a browser attacks matrix — the payload ultimately executes on the endpoint, not in the browser — but the delivery is overwhelmingly browser-based: ",{"data":16297,"marks":16298,"value":16300,"nodeType":882},{},[16299],{"type":1012},"4 in 5 ClickFix payloads",{"data":16302,"marks":16303,"value":16304,"nodeType":882},{},[]," intercepted by Push arrive via search engines as a result of malvertising or compromised web pages, not email, which means the browser is the only control point that actually sees the attack before the user pastes the malicious command.",{"data":16306,"content":16307,"nodeType":883},{},[16308],{"data":16309,"marks":16310,"value":16311,"nodeType":882},{},[],"ClickFix is now the primary delivery mechanism for infostealer malware, which is in turn the primary source of the stolen credentials and session tokens that power credential stuffing and session hijacking — which means the technique sits at the start of a cycle where one class of browser-delivered attack generates the raw material for the next.",{"data":16313,"content":16314,"nodeType":883},{},[16315,16319,16325,16329,16335],{"data":16316,"marks":16317,"value":16318,"nodeType":882},{},[],"The success of ClickFix has predictably spawned a growing family of derivatives — FileFix, CrashFix, ",{"data":16320,"content":16321,"nodeType":929},{"uri":3823},[16322],{"data":16323,"marks":16324,"value":2002,"nodeType":882},{},[],{"data":16326,"marks":16327,"value":16328,"nodeType":882},{},[]," — and much of the naming is marketing hype around variations on the same clipboard-injection mechanic. But ",{"data":16330,"content":16331,"nodeType":929},{"uri":3582},[16332],{"data":16333,"marks":16334,"value":1989,"nodeType":882},{},[],{"data":16336,"marks":16337,"value":16338,"nodeType":882},{},[]," was a genuinely novel development.",{"data":16340,"content":16341,"nodeType":2050},{},[16342],{"data":16343,"marks":16344,"value":16346,"nodeType":882},{},[16345],{"type":1012},"Browser-native ClickFix: ConsentFix",{"data":16348,"content":16349,"nodeType":883},{},[16350,16354,16362,16366,16373],{"data":16351,"marks":16352,"value":16353,"nodeType":882},{},[],"ConsentFix is a fully browser-native attack that merged ClickFix-style social engineering with OAuth consent abuse, compromising accounts through a legitimate Microsoft authorization flow with no endpoint component at all. ConsentFix was ",{"data":16355,"content":16357,"nodeType":929},{"uri":16356},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fconsentfix-debrief\u002F",[16358],{"data":16359,"marks":16360,"value":16361,"nodeType":882},{},[],"traced to APT29",{"data":16363,"marks":16364,"value":16365,"nodeType":882},{},[]," and has since been ",{"data":16367,"content":16368,"nodeType":929},{"uri":3594},[16369],{"data":16370,"marks":16371,"value":16372,"nodeType":882},{},[],"commercialized on criminal forums",{"data":16374,"marks":16375,"value":16376,"nodeType":882},{},[],", following the same path from state-sponsored technique to commodity criminal tooling that we've seen repeatedly in this space.",{"data":16378,"content":16379,"nodeType":883},{},[16380],{"data":16381,"marks":16382,"value":16383,"nodeType":882},{},[],"ConsentFix demonstrates that the clipboard-injection mechanic can evolve into something that operates entirely within the browser, eliminating the endpoint detection surface that traditional ClickFix still exposed.",{"data":16385,"content":16386,"nodeType":2050},{},[16387],{"data":16388,"marks":16389,"value":16391,"nodeType":882},{},[16390],{"type":1012},"Attackers have pivoted to authorization attacks to get around login controls",{"data":16393,"content":16394,"nodeType":883},{},[16395,16399,16406],{"data":16396,"marks":16397,"value":16398,"nodeType":882},{},[],"Authorization attacks like device code phishing have seen a ",{"data":16400,"content":16401,"nodeType":929},{"uri":3389},[16402],{"data":16403,"marks":16404,"value":16405,"nodeType":882},{},[],"37.5x increase",{"data":16407,"marks":16408,"value":16409,"nodeType":882},{},[]," since the start of 2026, with at least 12 distinct kits now offering the technique. It bypasses standard authentication controls — including passkeys — because the attack occurs through the OAuth device authorization flow rather than the standard login flow. ",{"data":16411,"content":16412,"nodeType":883},{},[16413],{"data":16414,"marks":16415,"value":16416,"nodeType":882},{},[],"The technique was first associated with nation-state actors like Storm-2372, but went from espionage-grade to commodity PhaaS tooling in roughly eighteen months, with kits like EvilTokens and Venom now offering turnkey device code phishing as a service.",{"data":16418,"content":16419,"nodeType":883},{},[16420],{"data":16421,"marks":16422,"value":16423,"nodeType":882},{},[],"The device code authorization is effectively performed post-authentication. If you already have an active session in your browser, entering the device code and selecting your account from a drop-down menu is all that's needed. No password or MFA required. You can see an example in the video below.",{"data":16425,"content":16429,"nodeType":963},{"target":16426},{"sys":16427},{"id":16428,"type":960,"linkType":961},"2WPb41lNRajdpt5pogQg8M",[],{"data":16431,"content":16432,"nodeType":883},{},[16433],{"data":16434,"marks":16435,"value":16436,"nodeType":882},{},[],"And the ecosystem is adapting to this opportunity: established AiTM vendors like Tycoon are adding authorization-focused options alongside their existing credential-harvesting capabilities, which points toward multi-technique platforms where operators pick the right tool for whatever defenses the target has in place.",{"data":16438,"content":16439,"nodeType":2050},{},[16440],{"data":16441,"marks":16442,"value":16444,"nodeType":882},{},[16443],{"type":1012},"Malicious and hacked browser extensions are one of the fastest growing threats",{"data":16446,"content":16447,"nodeType":883},{},[16448,16452,16459],{"data":16449,"marks":16450,"value":16451,"nodeType":882},{},[],"Malicious browser extensions have matured from an occasional nuisance into a scalable supply chain attack vector. The ",{"data":16453,"content":16454,"nodeType":929},{"uri":6345},[16455],{"data":16456,"marks":16457,"value":16458,"nodeType":882},{},[],"Cyberhaven compromise",{"data":16460,"marks":16461,"value":16462,"nodeType":882},{},[]," in December 2024 — where approximately 35 extensions were weaponized through a single OAuth phishing campaign targeting developers — impacted 2.6 million users and demonstrated that extension supply chain attacks can achieve the kind of reach that used to require a compromised software update server.",{"data":16464,"content":16465,"nodeType":883},{},[16466],{"data":16467,"marks":16468,"value":16469,"nodeType":882},{},[],"Since Cyberhaven, the pace has only accelerated. In 2026 alone, researchers have publicly disclosed at least 250 confirmed malicious browser extensions affecting roughly 1.75 million users, alongside a further 370+ extensions engaged in undisclosed or policy-disclosed data harvesting affecting an additional 44 million users. That doesn't count the extensions from late-2025 campaigns (DarkSpectre, AITOPIA, Trust Wallet) whose impacts carried into 2026.",{"data":16471,"content":16472,"nodeType":883},{},[16473,16477,16485],{"data":16474,"marks":16475,"value":16476,"nodeType":882},{},[],"The attack paths have also expanded. Beyond phishing developers for take over Web Store accounts (the Cyberhaven playbook), attackers are buying existing extensions from developers, waiting for ownership transfers or abandonments to take over, and increasingly vibe-coding their own functional extensions from scratch to build an audience that can later be weaponized. The common thread is that ",{"data":16478,"content":16479,"nodeType":929},{"uri":6345},[16480],{"data":16481,"marks":16482,"value":16484,"nodeType":882},{},[16483],{"type":927},"most malicious extensions didn't start out malicious",{"data":16486,"marks":16487,"value":16488,"nodeType":882},{},[]," — they started as legitimate tools and were turned into weapons after the fact.",{"data":16490,"content":16491,"nodeType":883},{},[16492],{"data":16493,"marks":16494,"value":16495,"nodeType":882},{},[],"None of this is happening in isolation. The threat landscape has reoriented around browser-based initial access and identity compromise — and the matrix needed to catch up.",{"data":16497,"content":16498,"nodeType":967},{},[],{"data":16500,"content":16501,"nodeType":975},{},[16502],{"data":16503,"marks":16504,"value":16506,"nodeType":882},{},[16505],{"type":1012},"The evolution is playing out in public breaches",{"data":16508,"content":16509,"nodeType":883},{},[16510],{"data":16511,"marks":16512,"value":16513,"nodeType":882},{},[],"It’s worth reinforcing that when the SaaS matrix was first released, many of these attacks hadn’t been seen in the wild. The change today is staggering:",{"data":16515,"content":16516,"nodeType":1454},{},[16517,16538,16560,16580],{"data":16518,"content":16519,"nodeType":1419},{},[16520],{"data":16521,"content":16522,"nodeType":883},{},[16523,16527,16534],{"data":16524,"marks":16525,"value":16526,"nodeType":882},{},[],"When ",{"data":16528,"content":16529,"nodeType":929},{"uri":8219},[16530],{"data":16531,"marks":16532,"value":16533,"nodeType":882},{},[],"Scattered Lapsus$ Hunters",{"data":16535,"marks":16536,"value":16537,"nodeType":882},{},[]," compromised over a thousand organizations' Salesforce tenants through device code phishing, the attack started with a phone call, moved through a browser-based authorization flow for the attacker’s app, and ended with mass data exfiltration via API.",{"data":16539,"content":16540,"nodeType":1419},{},[16541],{"data":16542,"content":16543,"nodeType":883},{},[16544,16548,16556],{"data":16545,"marks":16546,"value":16547,"nodeType":882},{},[],"When the same collective launched ",{"data":16549,"content":16551,"nodeType":929},{"uri":16550},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Funpacking-the-latest-slh-campaign\u002F",[16552],{"data":16553,"marks":16554,"value":16555,"nodeType":882},{},[],"AiTM phishing campaigns",{"data":16557,"marks":16558,"value":16559,"nodeType":882},{},[]," targeting Okta and Entra SSO, the phishing page was operated by a human in real time and delivered over a voice call — not email.",{"data":16561,"content":16562,"nodeType":1419},{},[16563],{"data":16564,"content":16565,"nodeType":883},{},[16566,16569,16576],{"data":16567,"marks":16568,"value":16526,"nodeType":882},{},[],{"data":16570,"content":16571,"nodeType":929},{"uri":3582},[16572],{"data":16573,"marks":16574,"value":16575,"nodeType":882},{},[],"APT29 deployed ConsentFix",{"data":16577,"marks":16578,"value":16579,"nodeType":882},{},[]," across dozens of compromised websites, the entire attack chain was browser-native, abusing a legitimate Microsoft OAuth flow to bypass MFA without proxying a single credential.",{"data":16581,"content":16582,"nodeType":1419},{},[16583],{"data":16584,"content":16585,"nodeType":883},{},[16586,16589,16596],{"data":16587,"marks":16588,"value":6443,"nodeType":882},{},[],{"data":16590,"content":16592,"nodeType":929},{"uri":16591},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fidentity-attacks-in-the-wild\u002F#id-snowflake-june-2024",[16593],{"data":16594,"marks":16595,"value":6118,"nodeType":882},{},[],{"data":16597,"marks":16598,"value":16599,"nodeType":882},{},[]," — arguably the most consequential credential-based campaign of the past several years — saw 165 organizations breached using credentials that had been sitting in infostealer dumps for years, replayed against Snowflake tenants that lacked mandatory MFA. The attack surface wasn't Snowflake's application logic; it was the identity hygiene gap that every organization carries across hundreds of apps.",{"data":16601,"content":16602,"nodeType":883},{},[16603],{"data":16604,"marks":16605,"value":16606,"nodeType":882},{},[],"And that’s just the big picture. Every month we’re tracking new public breaches involving browser and identity TTPs — which again, are just the tip of the iceberg when you consider that many breaches are settled quietly without hitting the headlines. ",{"data":16608,"content":16609,"nodeType":883},{},[16610,16614,16619],{"data":16611,"marks":16612,"value":16613,"nodeType":882},{},[],"One of the key drivers here is the shrinking time-to-exploit. CrowdStrike's average e-crime breakout time is down to ",{"data":16615,"marks":16616,"value":16618,"nodeType":882},{},[16617],{"type":1012},"29 minutes",{"data":16620,"marks":16621,"value":16622,"nodeType":882},{},[],", with the fastest recorded at 27 seconds. When attackers can move from initial access to data exfiltration within minutes, the window for post-compromise detection collapses to near zero. The best chance of stopping the attack is at the point of initial access before the identity is compromised.",{"data":16624,"content":16625,"nodeType":967},{},[],{"data":16627,"content":16628,"nodeType":975},{},[16629,16634,16640,16645,16650],{"data":16630,"marks":16631,"value":16633,"nodeType":882},{},[16632],{"type":1012},"Sidenote: why we're looking at attacks ",{"data":16635,"marks":16636,"value":16639,"nodeType":882},{},[16637,16638],{"type":1045},{"type":1012},"in",{"data":16641,"marks":16642,"value":16644,"nodeType":882},{},[16643],{"type":1012}," the browser, not ",{"data":16646,"marks":16647,"value":4804,"nodeType":882},{},[16648,16649],{"type":1045},{"type":1012},{"data":16651,"marks":16652,"value":4821,"nodeType":882},{},[16653],{"type":1012},{"data":16655,"content":16656,"nodeType":883},{},[16657,16661,16669],{"data":16658,"marks":16659,"value":16660,"nodeType":882},{},[],"Calling this a \"browser attacks\" matrix needs clarification. We're not talking about browser exploits — RCE vulnerabilities, sandbox escapes, memory corruption bugs. Those attacks target the browser itself, they're extraordinarily expensive to develop, and they're increasingly rare. Browser zero-days hit a ",{"data":16662,"content":16664,"nodeType":929},{"uri":16663},"https:\u002F\u002Fcloud.google.com\u002Fblog\u002Ftopics\u002Fthreat-intelligence\u002F2025-zero-day-review",[16665],{"data":16666,"marks":16667,"value":16668,"nodeType":882},{},[],"historic low of 9%",{"data":16670,"marks":16671,"value":16672,"nodeType":882},{},[]," of all zero-days reported to Google, and a Chrome RCE commands a $250,000 bug bounty.",{"data":16674,"content":16675,"nodeType":883},{},[16676],{"data":16677,"marks":16678,"value":16679,"nodeType":882},{},[],"In comparison, a one-year phishing kit rental costs $1,000. A bulk stolen credential list costs $15. An initial-access-broker-provided IdP admin account costs $3,000. When it costs orders of magnitude less to exploit the person using the browser than to exploit the browser itself, attackers will take the cheaper option every time.",{"data":16681,"content":16682,"nodeType":883},{},[16683],{"data":16684,"marks":16685,"value":16686,"nodeType":882},{},[],"It's worth heading off the obvious counterargument: won't AI-assisted vulnerability discovery eventually make browser exploits cheaper? Perhaps — but it will simultaneously make them easier for browser vendors to find and patch, and vendors like Google and Microsoft have the engineering capacity and financial incentive to scale AI-driven remediation far faster than attackers can scale exploit development.",{"data":16688,"content":16689,"nodeType":967},{},[],{"data":16691,"content":16692,"nodeType":975},{},[16693],{"data":16694,"marks":16695,"value":16697,"nodeType":882},{},[16696],{"type":1012},"What hasn't changed",{"data":16699,"content":16700,"nodeType":883},{},[16701,16705,16713],{"data":16702,"marks":16703,"value":16704,"nodeType":882},{},[],"The matrix remains open-source, community-maintained, and available on ",{"data":16706,"content":16708,"nodeType":929},{"uri":16707},"https:\u002F\u002Fgithub.com\u002Fpushsecurity\u002Fsaas-attacks",[16709],{"data":16710,"marks":16711,"value":16712,"nodeType":882},{},[],"GitHub",{"data":16714,"marks":16715,"value":16716,"nodeType":882},{},[],". The goal is the same as it was in 2023: to give offensive and defensive security teams a shared reference point for the techniques that matter most.",{"data":16718,"content":16719,"nodeType":883},{},[16720],{"data":16721,"marks":16722,"value":16723,"nodeType":882},{},[],"We built it because there was a gap in how the industry talked about these techniques, and that gap still exists — MITRE ATT&CK remains essential for endpoint and network TTPs, but the browser-based, identity-first techniques behind most modern breaches are still underrepresented in traditional frameworks.",{"data":16725,"content":16726,"nodeType":883},{},[16727],{"data":16728,"marks":16729,"value":16730,"nodeType":882},{},[],"We continue to maintain the matrix with input from red teams, detection engineers, and threat researchers across the community. Some of the most valuable additions over the past two years have come from practitioners who encountered a technique on an engagement or in an investigation and contributed it back to the repository.",{"data":16732,"content":16733,"nodeType":883},{},[16734,16738,16745],{"data":16735,"marks":16736,"value":16737,"nodeType":882},{},[],"If you're an offensive security professional using these techniques on engagements, or a defender building detections against them, we want to hear from you. Submit a PR, open a discussion, or flag a technique we've missed on ",{"data":16739,"content":16741,"nodeType":929},{"uri":16740},"https:\u002F\u002Fgithub.com\u002Fpushsecurity\u002Fbrowser-identity-attacks-matrix",[16742],{"data":16743,"marks":16744,"value":16712,"nodeType":882},{},[],{"data":16746,"marks":16747,"value":1438,"nodeType":882},{},[],{"data":16749,"content":16750,"nodeType":967},{},[],{"data":16752,"content":16753,"nodeType":975},{},[16754],{"data":16755,"marks":16756,"value":16758,"nodeType":882},{},[16757],{"type":1012},"Looking ahead",{"data":16760,"content":16761,"nodeType":883},{},[16762],{"data":16763,"marks":16764,"value":16765,"nodeType":882},{},[],"The pace of attacker innovation in browser-based initial access techniques over the past 18 months has been unlike anything we've tracked before — technique after technique moving from research curiosity to industrialized criminal tooling within months, not years.",{"data":16767,"content":16768,"nodeType":1454},{},[16769,16779,16789],{"data":16770,"content":16771,"nodeType":1419},{},[16772],{"data":16773,"content":16774,"nodeType":883},{},[16775],{"data":16776,"marks":16777,"value":16778,"nodeType":882},{},[],"AiTM platforms are adding authorization-based attack options alongside their credential-harvesting capabilities.",{"data":16780,"content":16781,"nodeType":1419},{},[16782],{"data":16783,"content":16784,"nodeType":883},{},[16785],{"data":16786,"marks":16787,"value":16788,"nodeType":882},{},[],"ClickFix has spawned fully browser-native variants.",{"data":16790,"content":16791,"nodeType":1419},{},[16792],{"data":16793,"content":16794,"nodeType":883},{},[16795],{"data":16796,"marks":16797,"value":16798,"nodeType":882},{},[],"AI is lowering the cost of producing convincing social engineering and phishing infrastructure at scale.",{"data":16800,"content":16801,"nodeType":883},{},[16802],{"data":16803,"marks":16804,"value":16805,"nodeType":882},{},[],"We don't see any of this slowing down, and that's exactly why thinking about these attacks as a browser problem instead of siloing them across email, endpoint, network, and cloud categories, each with a partial view of the picture (and still missing the whole when combined).",{"data":16807,"content":16808,"nodeType":883},{},[16809,16813,16820],{"data":16810,"marks":16811,"value":16812,"nodeType":882},{},[],"The Browser & Identity Attacks Matrix is our contribution to keeping that shared understanding current. You can ",{"data":16814,"content":16815,"nodeType":929},{"uri":9691},[16816],{"data":16817,"marks":16818,"value":16819,"nodeType":882},{},[],"explore the matrix here",{"data":16821,"marks":16822,"value":1438,"nodeType":882},{},[],{"data":16824,"content":16825,"nodeType":883},{},[16826,16830,16837],{"data":16827,"marks":16828,"value":16829,"nodeType":882},{},[],"You can also read our recent ",{"data":16831,"content":16832,"nodeType":929},{"uri":3358},[16833],{"data":16834,"marks":16835,"value":16836,"nodeType":882},{},[],"browser attack techniques report",{"data":16838,"marks":16839,"value":16840,"nodeType":882},{},[]," for more information.",{"data":16842,"content":16846,"nodeType":963},{"target":16843},{"sys":16844},{"id":16845,"type":960,"linkType":961},"1hx6sxpyEzxn4F4jc1RGQi",[],{"data":16848,"content":16849,"nodeType":967},{},[],{"data":16851,"content":16852,"nodeType":883},{},[16853],{"data":16854,"marks":16855,"value":16856,"nodeType":882},{},[],"Push Security is the most powerful AI-native security tool in the browser. Think EDR, but for the browser — high-fidelity telemetry and real-time control across every session, on every device, with no browser migration required. Security teams use Push to detect and stop advanced browser-based attacks like AiTM phishing, ClickFix, and session hijacking; gain visibility and control over AI tool usage across their workforce; harden identities by surfacing credential reuse, SSO gaps, and shadow IT; and support data loss and insider investigations with browser-layer telemetry that other tools can't see.",{"data":16858,"content":16859,"nodeType":883},{},[16860,16863,16869],{"data":16861,"marks":16862,"value":4431,"nodeType":882},{},[],{"data":16864,"content":16865,"nodeType":929},{"uri":1283},[16866],{"data":16867,"marks":16868,"value":4438,"nodeType":882},{},[],{"data":16870,"marks":16871,"value":3897,"nodeType":882},{},[],"Introducing the Browser & Identity Attacks Matrix","We're re-releasing the SaaS attack matrix as the Browser & Identity Attacks Matrix. Here's why we've decided to make the change and what it means.","2026-05-08T00:00:00.000Z","introducing-the-browser-and-identity-attacks-matrix",{"items":16877},[16878,16880],{"sys":16879,"name":2308},{"id":2307},{"sys":16881,"name":343},{"id":2304},{"items":16883},[16884],{"fullName":3911,"firstName":3912,"jobTitle":3913,"profilePicture":16885},{"url":3915},{"__typename":1365,"sys":16887,"content":16888,"title":7227,"synopsis":7228,"hashTags":59,"publishedDate":7229,"slug":7230,"tagsCollection":17957,"authorsCollection":17963},{"id":5992},{"json":16889},{"data":16890,"content":16891,"nodeType":1294},{},[16892,16905,16910,16916,16922,16927,16930,16937,16944,16959,16997,17002,17015,17018,17025,17032,17054,17086,17092,17095,17102,17109,17115,17120,17126,17129,17136,17143,17177,17207,17213,17216,17223,17230,17250,17256,17295,17301,17304,17311,17318,17354,17360,17365,17368,17375,17382,17408,17414,17419,17425,17428,17435,17442,17465,17471,17477,17483,17486,17493,17500,17506,17511,17517,17538,17561,17564,17571,17578,17584,17590,17593,17600,17655,17658,17665,17671,17939,17942],{"data":16893,"content":16894,"nodeType":883},{},[16895,16898,16902],{"data":16896,"marks":16897,"value":6003,"nodeType":882},{},[],{"data":16899,"marks":16900,"value":6008,"nodeType":882},{},[16901],{"type":1012},{"data":16903,"marks":16904,"value":6012,"nodeType":882},{},[],{"data":16906,"content":16909,"nodeType":963},{"target":16907},{"sys":16908},{"id":6017,"type":960,"linkType":961},[],{"data":16911,"content":16912,"nodeType":883},{},[16913],{"data":16914,"marks":16915,"value":6025,"nodeType":882},{},[],{"data":16917,"content":16918,"nodeType":883},{},[16919],{"data":16920,"marks":16921,"value":6032,"nodeType":882},{},[],{"data":16923,"content":16926,"nodeType":963},{"target":16924},{"sys":16925},{"id":6037,"type":960,"linkType":961},[],{"data":16928,"content":16929,"nodeType":967},{},[],{"data":16931,"content":16932,"nodeType":975},{},[16933],{"data":16934,"marks":16935,"value":6049,"nodeType":882},{},[16936],{"type":1012},{"data":16938,"content":16939,"nodeType":883},{},[16940],{"data":16941,"marks":16942,"value":6057,"nodeType":882},{},[16943],{"type":1012},{"data":16945,"content":16946,"nodeType":883},{},[16947,16950,16956],{"data":16948,"marks":16949,"value":6064,"nodeType":882},{},[],{"data":16951,"content":16952,"nodeType":929},{"uri":6067},[16953],{"data":16954,"marks":16955,"value":6072,"nodeType":882},{},[],{"data":16957,"marks":16958,"value":6076,"nodeType":882},{},[],{"data":16960,"content":16961,"nodeType":883},{},[16962,16965,16971,16974,16978,16981,16985,16988,16994],{"data":16963,"marks":16964,"value":4513,"nodeType":882},{},[],{"data":16966,"content":16967,"nodeType":929},{"uri":6085},[16968],{"data":16969,"marks":16970,"value":6090,"nodeType":882},{},[],{"data":16972,"marks":16973,"value":1993,"nodeType":882},{},[],{"data":16975,"marks":16976,"value":6098,"nodeType":882},{},[16977],{"type":1012},{"data":16979,"marks":16980,"value":2006,"nodeType":882},{},[],{"data":16982,"marks":16983,"value":6106,"nodeType":882},{},[16984],{"type":1012},{"data":16986,"marks":16987,"value":6110,"nodeType":882},{},[],{"data":16989,"content":16990,"nodeType":929},{"uri":6113},[16991],{"data":16992,"marks":16993,"value":6118,"nodeType":882},{},[],{"data":16995,"marks":16996,"value":6122,"nodeType":882},{},[],{"data":16998,"content":17001,"nodeType":963},{"target":16999},{"sys":17000},{"id":6127,"type":960,"linkType":961},[],{"data":17003,"content":17004,"nodeType":883},{},[17005,17008,17012],{"data":17006,"marks":17007,"value":6135,"nodeType":882},{},[],{"data":17009,"marks":17010,"value":6140,"nodeType":882},{},[17011],{"type":1012},{"data":17013,"marks":17014,"value":1438,"nodeType":882},{},[],{"data":17016,"content":17017,"nodeType":967},{},[],{"data":17019,"content":17020,"nodeType":975},{},[17021],{"data":17022,"marks":17023,"value":6154,"nodeType":882},{},[17024],{"type":1012},{"data":17026,"content":17027,"nodeType":883},{},[17028],{"data":17029,"marks":17030,"value":6057,"nodeType":882},{},[17031],{"type":1012},{"data":17033,"content":17034,"nodeType":883},{},[17035,17038,17044,17047,17051],{"data":17036,"marks":17037,"value":6168,"nodeType":882},{},[],{"data":17039,"content":17040,"nodeType":929},{"uri":6171},[17041],{"data":17042,"marks":17043,"value":6176,"nodeType":882},{},[],{"data":17045,"marks":17046,"value":6180,"nodeType":882},{},[],{"data":17048,"marks":17049,"value":6185,"nodeType":882},{},[17050],{"type":1012},{"data":17052,"marks":17053,"value":6189,"nodeType":882},{},[],{"data":17055,"content":17056,"nodeType":883},{},[17057,17060,17066,17069,17073,17076,17083],{"data":17058,"marks":17059,"value":6196,"nodeType":882},{},[],{"data":17061,"content":17062,"nodeType":929},{"uri":6199},[17063],{"data":17064,"marks":17065,"value":6204,"nodeType":882},{},[],{"data":17067,"marks":17068,"value":6208,"nodeType":882},{},[],{"data":17070,"marks":17071,"value":6213,"nodeType":882},{},[17072],{"type":1012},{"data":17074,"marks":17075,"value":6217,"nodeType":882},{},[],{"data":17077,"content":17078,"nodeType":929},{"uri":6220},[17079],{"data":17080,"marks":17081,"value":6226,"nodeType":882},{},[17082],{"type":1012},{"data":17084,"marks":17085,"value":6230,"nodeType":882},{},[],{"data":17087,"content":17088,"nodeType":883},{},[17089],{"data":17090,"marks":17091,"value":6237,"nodeType":882},{},[],{"data":17093,"content":17094,"nodeType":967},{},[],{"data":17096,"content":17097,"nodeType":975},{},[17098],{"data":17099,"marks":17100,"value":6248,"nodeType":882},{},[17101],{"type":1012},{"data":17103,"content":17104,"nodeType":883},{},[17105],{"data":17106,"marks":17107,"value":6256,"nodeType":882},{},[17108],{"type":1012},{"data":17110,"content":17111,"nodeType":883},{},[17112],{"data":17113,"marks":17114,"value":6263,"nodeType":882},{},[],{"data":17116,"content":17119,"nodeType":963},{"target":17117},{"sys":17118},{"id":6268,"type":960,"linkType":961},[],{"data":17121,"content":17122,"nodeType":883},{},[17123],{"data":17124,"marks":17125,"value":6276,"nodeType":882},{},[],{"data":17127,"content":17128,"nodeType":967},{},[],{"data":17130,"content":17131,"nodeType":975},{},[17132],{"data":17133,"marks":17134,"value":6287,"nodeType":882},{},[17135],{"type":1012},{"data":17137,"content":17138,"nodeType":883},{},[17139],{"data":17140,"marks":17141,"value":6256,"nodeType":882},{},[17142],{"type":1012},{"data":17144,"content":17145,"nodeType":883},{},[17146,17149,17156,17159,17165,17168,17174],{"data":17147,"marks":17148,"value":6301,"nodeType":882},{},[],{"data":17150,"content":17151,"nodeType":929},{"uri":6304},[17152],{"data":17153,"marks":17154,"value":6310,"nodeType":882},{},[17155],{"type":927},{"data":17157,"marks":17158,"value":1993,"nodeType":882},{},[],{"data":17160,"content":17161,"nodeType":929},{"uri":6316},[17162],{"data":17163,"marks":17164,"value":6321,"nodeType":882},{},[],{"data":17166,"marks":17167,"value":1993,"nodeType":882},{},[],{"data":17169,"content":17170,"nodeType":929},{"uri":6327},[17171],{"data":17172,"marks":17173,"value":6332,"nodeType":882},{},[],{"data":17175,"marks":17176,"value":6336,"nodeType":882},{},[],{"data":17178,"content":17179,"nodeType":883},{},[17180,17183,17190,17193,17197,17200,17204],{"data":17181,"marks":17182,"value":21,"nodeType":882},{},[],{"data":17184,"content":17185,"nodeType":929},{"uri":6345},[17186],{"data":17187,"marks":17188,"value":6351,"nodeType":882},{},[17189],{"type":927},{"data":17191,"marks":17192,"value":6355,"nodeType":882},{},[],{"data":17194,"marks":17195,"value":6360,"nodeType":882},{},[17196],{"type":1012},{"data":17198,"marks":17199,"value":6364,"nodeType":882},{},[],{"data":17201,"marks":17202,"value":6369,"nodeType":882},{},[17203],{"type":1045},{"data":17205,"marks":17206,"value":6373,"nodeType":882},{},[],{"data":17208,"content":17209,"nodeType":883},{},[17210],{"data":17211,"marks":17212,"value":6380,"nodeType":882},{},[],{"data":17214,"content":17215,"nodeType":967},{},[],{"data":17217,"content":17218,"nodeType":975},{},[17219],{"data":17220,"marks":17221,"value":6391,"nodeType":882},{},[17222],{"type":1012},{"data":17224,"content":17225,"nodeType":883},{},[17226],{"data":17227,"marks":17228,"value":6256,"nodeType":882},{},[17229],{"type":1012},{"data":17231,"content":17232,"nodeType":883},{},[17233,17236,17240,17243,17247],{"data":17234,"marks":17235,"value":6405,"nodeType":882},{},[],{"data":17237,"marks":17238,"value":6410,"nodeType":882},{},[17239],{"type":1045},{"data":17241,"marks":17242,"value":6414,"nodeType":882},{},[],{"data":17244,"marks":17245,"value":6419,"nodeType":882},{},[17246],{"type":1045},{"data":17248,"marks":17249,"value":6423,"nodeType":882},{},[],{"data":17251,"content":17252,"nodeType":883},{},[17253],{"data":17254,"marks":17255,"value":6430,"nodeType":882},{},[],{"data":17257,"content":17258,"nodeType":1454},{},[17259,17277],{"data":17260,"content":17261,"nodeType":1419},{},[17262],{"data":17263,"content":17264,"nodeType":883},{},[17265,17268,17274],{"data":17266,"marks":17267,"value":6443,"nodeType":882},{},[],{"data":17269,"content":17270,"nodeType":929},{"uri":3507},[17271],{"data":17272,"marks":17273,"value":6450,"nodeType":882},{},[],{"data":17275,"marks":17276,"value":6454,"nodeType":882},{},[],{"data":17278,"content":17279,"nodeType":1419},{},[17280],{"data":17281,"content":17282,"nodeType":883},{},[17283,17286,17292],{"data":17284,"marks":17285,"value":6443,"nodeType":882},{},[],{"data":17287,"content":17288,"nodeType":929},{"uri":6466},[17289],{"data":17290,"marks":17291,"value":6471,"nodeType":882},{},[],{"data":17293,"marks":17294,"value":6475,"nodeType":882},{},[],{"data":17296,"content":17297,"nodeType":883},{},[17298],{"data":17299,"marks":17300,"value":6482,"nodeType":882},{},[],{"data":17302,"content":17303,"nodeType":967},{},[],{"data":17305,"content":17306,"nodeType":975},{},[17307],{"data":17308,"marks":17309,"value":6493,"nodeType":882},{},[17310],{"type":1012},{"data":17312,"content":17313,"nodeType":883},{},[17314],{"data":17315,"marks":17316,"value":6501,"nodeType":882},{},[17317],{"type":1012},{"data":17319,"content":17320,"nodeType":883},{},[17321,17324,17328,17331,17337,17340,17344,17347,17351],{"data":17322,"marks":17323,"value":6508,"nodeType":882},{},[],{"data":17325,"marks":17326,"value":6513,"nodeType":882},{},[17327],{"type":1012},{"data":17329,"marks":17330,"value":6517,"nodeType":882},{},[],{"data":17332,"content":17333,"nodeType":929},{"uri":6520},[17334],{"data":17335,"marks":17336,"value":6525,"nodeType":882},{},[],{"data":17338,"marks":17339,"value":6529,"nodeType":882},{},[],{"data":17341,"marks":17342,"value":6534,"nodeType":882},{},[17343],{"type":1012},{"data":17345,"marks":17346,"value":6538,"nodeType":882},{},[],{"data":17348,"marks":17349,"value":6543,"nodeType":882},{},[17350],{"type":1012},{"data":17352,"marks":17353,"value":6547,"nodeType":882},{},[],{"data":17355,"content":17356,"nodeType":883},{},[17357],{"data":17358,"marks":17359,"value":6554,"nodeType":882},{},[],{"data":17361,"content":17364,"nodeType":963},{"target":17362},{"sys":17363},{"id":6559,"type":960,"linkType":961},[],{"data":17366,"content":17367,"nodeType":967},{},[],{"data":17369,"content":17370,"nodeType":975},{},[17371],{"data":17372,"marks":17373,"value":6571,"nodeType":882},{},[17374],{"type":1012},{"data":17376,"content":17377,"nodeType":883},{},[17378],{"data":17379,"marks":17380,"value":6579,"nodeType":882},{},[17381],{"type":1012},{"data":17383,"content":17384,"nodeType":883},{},[17385,17388,17395,17398,17405],{"data":17386,"marks":17387,"value":6586,"nodeType":882},{},[],{"data":17389,"content":17390,"nodeType":929},{"uri":6589},[17391],{"data":17392,"marks":17393,"value":6595,"nodeType":882},{},[17394],{"type":1012},{"data":17396,"marks":17397,"value":6599,"nodeType":882},{},[],{"data":17399,"content":17400,"nodeType":929},{"uri":6602},[17401],{"data":17402,"marks":17403,"value":6608,"nodeType":882},{},[17404],{"type":1012},{"data":17406,"marks":17407,"value":6612,"nodeType":882},{},[],{"data":17409,"content":17410,"nodeType":883},{},[17411],{"data":17412,"marks":17413,"value":6619,"nodeType":882},{},[],{"data":17415,"content":17418,"nodeType":963},{"target":17416},{"sys":17417},{"id":6624,"type":960,"linkType":961},[],{"data":17420,"content":17421,"nodeType":883},{},[17422],{"data":17423,"marks":17424,"value":6632,"nodeType":882},{},[],{"data":17426,"content":17427,"nodeType":967},{},[],{"data":17429,"content":17430,"nodeType":975},{},[17431],{"data":17432,"marks":17433,"value":6643,"nodeType":882},{},[17434],{"type":1012},{"data":17436,"content":17437,"nodeType":883},{},[17438],{"data":17439,"marks":17440,"value":6651,"nodeType":882},{},[17441],{"type":1012},{"data":17443,"content":17444,"nodeType":883},{},[17445,17448,17452,17455,17462],{"data":17446,"marks":17447,"value":6658,"nodeType":882},{},[],{"data":17449,"marks":17450,"value":6663,"nodeType":882},{},[17451],{"type":1045},{"data":17453,"marks":17454,"value":6667,"nodeType":882},{},[],{"data":17456,"content":17457,"nodeType":929},{"uri":6670},[17458],{"data":17459,"marks":17460,"value":6676,"nodeType":882},{},[17461],{"type":1012},{"data":17463,"marks":17464,"value":6680,"nodeType":882},{},[],{"data":17466,"content":17467,"nodeType":883},{},[17468],{"data":17469,"marks":17470,"value":6687,"nodeType":882},{},[],{"data":17472,"content":17473,"nodeType":883},{},[17474],{"data":17475,"marks":17476,"value":6694,"nodeType":882},{},[],{"data":17478,"content":17479,"nodeType":883},{},[17480],{"data":17481,"marks":17482,"value":6701,"nodeType":882},{},[],{"data":17484,"content":17485,"nodeType":967},{},[],{"data":17487,"content":17488,"nodeType":975},{},[17489],{"data":17490,"marks":17491,"value":6712,"nodeType":882},{},[17492],{"type":1012},{"data":17494,"content":17495,"nodeType":883},{},[17496],{"data":17497,"marks":17498,"value":6720,"nodeType":882},{},[17499],{"type":1012},{"data":17501,"content":17502,"nodeType":883},{},[17503],{"data":17504,"marks":17505,"value":6727,"nodeType":882},{},[],{"data":17507,"content":17510,"nodeType":963},{"target":17508},{"sys":17509},{"id":6732,"type":960,"linkType":961},[],{"data":17512,"content":17513,"nodeType":883},{},[17514],{"data":17515,"marks":17516,"value":6740,"nodeType":882},{},[],{"data":17518,"content":17519,"nodeType":1454},{},[17520,17529],{"data":17521,"content":17522,"nodeType":1419},{},[17523],{"data":17524,"content":17525,"nodeType":883},{},[17526],{"data":17527,"marks":17528,"value":6753,"nodeType":882},{},[],{"data":17530,"content":17531,"nodeType":1419},{},[17532],{"data":17533,"content":17534,"nodeType":883},{},[17535],{"data":17536,"marks":17537,"value":6763,"nodeType":882},{},[],{"data":17539,"content":17540,"nodeType":883},{},[17541,17544,17551,17554,17558],{"data":17542,"marks":17543,"value":6770,"nodeType":882},{},[],{"data":17545,"content":17546,"nodeType":929},{"uri":6773},[17547],{"data":17548,"marks":17549,"value":6779,"nodeType":882},{},[17550],{"type":1012},{"data":17552,"marks":17553,"value":6783,"nodeType":882},{},[],{"data":17555,"marks":17556,"value":6788,"nodeType":882},{},[17557],{"type":1045},{"data":17559,"marks":17560,"value":6792,"nodeType":882},{},[],{"data":17562,"content":17563,"nodeType":967},{},[],{"data":17565,"content":17566,"nodeType":975},{},[17567],{"data":17568,"marks":17569,"value":6803,"nodeType":882},{},[17570],{"type":1012},{"data":17572,"content":17573,"nodeType":883},{},[17574],{"data":17575,"marks":17576,"value":6811,"nodeType":882},{},[17577],{"type":1012},{"data":17579,"content":17580,"nodeType":883},{},[17581],{"data":17582,"marks":17583,"value":6818,"nodeType":882},{},[],{"data":17585,"content":17586,"nodeType":883},{},[17587],{"data":17588,"marks":17589,"value":6825,"nodeType":882},{},[],{"data":17591,"content":17592,"nodeType":967},{},[],{"data":17594,"content":17595,"nodeType":975},{},[17596],{"data":17597,"marks":17598,"value":6836,"nodeType":882},{},[17599],{"type":1012},{"data":17601,"content":17602,"nodeType":1454},{},[17603,17616,17629,17642],{"data":17604,"content":17605,"nodeType":1419},{},[17606],{"data":17607,"content":17608,"nodeType":883},{},[17609,17613],{"data":17610,"marks":17611,"value":6850,"nodeType":882},{},[17612],{"type":1012},{"data":17614,"marks":17615,"value":6854,"nodeType":882},{},[],{"data":17617,"content":17618,"nodeType":1419},{},[17619],{"data":17620,"content":17621,"nodeType":883},{},[17622,17626],{"data":17623,"marks":17624,"value":6865,"nodeType":882},{},[17625],{"type":1012},{"data":17627,"marks":17628,"value":6869,"nodeType":882},{},[],{"data":17630,"content":17631,"nodeType":1419},{},[17632],{"data":17633,"content":17634,"nodeType":883},{},[17635,17639],{"data":17636,"marks":17637,"value":6880,"nodeType":882},{},[17638],{"type":1012},{"data":17640,"marks":17641,"value":6884,"nodeType":882},{},[],{"data":17643,"content":17644,"nodeType":1419},{},[17645],{"data":17646,"content":17647,"nodeType":883},{},[17648,17652],{"data":17649,"marks":17650,"value":794,"nodeType":882},{},[17651],{"type":1012},{"data":17653,"marks":17654,"value":6898,"nodeType":882},{},[],{"data":17656,"content":17657,"nodeType":967},{},[],{"data":17659,"content":17660,"nodeType":975},{},[17661],{"data":17662,"marks":17663,"value":6909,"nodeType":882},{},[17664],{"type":1012},{"data":17666,"content":17667,"nodeType":883},{},[17668],{"data":17669,"marks":17670,"value":6916,"nodeType":882},{},[],{"data":17672,"content":17673,"nodeType":3104},{},[17674,17697,17719,17741,17763,17785,17807,17829,17851,17873,17895,17917],{"data":17675,"content":17676,"nodeType":3011},{},[17677,17687],{"data":17678,"content":17679,"nodeType":3025},{},[17680],{"data":17681,"content":17682,"nodeType":883},{},[17683],{"data":17684,"marks":17685,"value":6933,"nodeType":882},{},[17686],{"type":1012},{"data":17688,"content":17689,"nodeType":3025},{},[17690],{"data":17691,"content":17692,"nodeType":883},{},[17693],{"data":17694,"marks":17695,"value":6944,"nodeType":882},{},[17696],{"type":1012},{"data":17698,"content":17699,"nodeType":3011},{},[17700,17710],{"data":17701,"content":17702,"nodeType":3025},{},[17703],{"data":17704,"content":17705,"nodeType":883},{},[17706],{"data":17707,"marks":17708,"value":6958,"nodeType":882},{},[17709],{"type":1012},{"data":17711,"content":17712,"nodeType":3025},{},[17713],{"data":17714,"content":17715,"nodeType":883},{},[17716],{"data":17717,"marks":17718,"value":6968,"nodeType":882},{},[],{"data":17720,"content":17721,"nodeType":3011},{},[17722,17732],{"data":17723,"content":17724,"nodeType":3025},{},[17725],{"data":17726,"content":17727,"nodeType":883},{},[17728],{"data":17729,"marks":17730,"value":6982,"nodeType":882},{},[17731],{"type":1012},{"data":17733,"content":17734,"nodeType":3025},{},[17735],{"data":17736,"content":17737,"nodeType":883},{},[17738],{"data":17739,"marks":17740,"value":6992,"nodeType":882},{},[],{"data":17742,"content":17743,"nodeType":3011},{},[17744,17754],{"data":17745,"content":17746,"nodeType":3025},{},[17747],{"data":17748,"content":17749,"nodeType":883},{},[17750],{"data":17751,"marks":17752,"value":7006,"nodeType":882},{},[17753],{"type":1012},{"data":17755,"content":17756,"nodeType":3025},{},[17757],{"data":17758,"content":17759,"nodeType":883},{},[17760],{"data":17761,"marks":17762,"value":7016,"nodeType":882},{},[],{"data":17764,"content":17765,"nodeType":3011},{},[17766,17776],{"data":17767,"content":17768,"nodeType":3025},{},[17769],{"data":17770,"content":17771,"nodeType":883},{},[17772],{"data":17773,"marks":17774,"value":7030,"nodeType":882},{},[17775],{"type":1012},{"data":17777,"content":17778,"nodeType":3025},{},[17779],{"data":17780,"content":17781,"nodeType":883},{},[17782],{"data":17783,"marks":17784,"value":7040,"nodeType":882},{},[],{"data":17786,"content":17787,"nodeType":3011},{},[17788,17798],{"data":17789,"content":17790,"nodeType":3025},{},[17791],{"data":17792,"content":17793,"nodeType":883},{},[17794],{"data":17795,"marks":17796,"value":7054,"nodeType":882},{},[17797],{"type":1012},{"data":17799,"content":17800,"nodeType":3025},{},[17801],{"data":17802,"content":17803,"nodeType":883},{},[17804],{"data":17805,"marks":17806,"value":7064,"nodeType":882},{},[],{"data":17808,"content":17809,"nodeType":3011},{},[17810,17820],{"data":17811,"content":17812,"nodeType":3025},{},[17813],{"data":17814,"content":17815,"nodeType":883},{},[17816],{"data":17817,"marks":17818,"value":7078,"nodeType":882},{},[17819],{"type":1012},{"data":17821,"content":17822,"nodeType":3025},{},[17823],{"data":17824,"content":17825,"nodeType":883},{},[17826],{"data":17827,"marks":17828,"value":7088,"nodeType":882},{},[],{"data":17830,"content":17831,"nodeType":3011},{},[17832,17842],{"data":17833,"content":17834,"nodeType":3025},{},[17835],{"data":17836,"content":17837,"nodeType":883},{},[17838],{"data":17839,"marks":17840,"value":7102,"nodeType":882},{},[17841],{"type":1012},{"data":17843,"content":17844,"nodeType":3025},{},[17845],{"data":17846,"content":17847,"nodeType":883},{},[17848],{"data":17849,"marks":17850,"value":7112,"nodeType":882},{},[],{"data":17852,"content":17853,"nodeType":3011},{},[17854,17864],{"data":17855,"content":17856,"nodeType":3025},{},[17857],{"data":17858,"content":17859,"nodeType":883},{},[17860],{"data":17861,"marks":17862,"value":7126,"nodeType":882},{},[17863],{"type":1012},{"data":17865,"content":17866,"nodeType":3025},{},[17867],{"data":17868,"content":17869,"nodeType":883},{},[17870],{"data":17871,"marks":17872,"value":7136,"nodeType":882},{},[],{"data":17874,"content":17875,"nodeType":3011},{},[17876,17886],{"data":17877,"content":17878,"nodeType":3025},{},[17879],{"data":17880,"content":17881,"nodeType":883},{},[17882],{"data":17883,"marks":17884,"value":7150,"nodeType":882},{},[17885],{"type":1012},{"data":17887,"content":17888,"nodeType":3025},{},[17889],{"data":17890,"content":17891,"nodeType":883},{},[17892],{"data":17893,"marks":17894,"value":7160,"nodeType":882},{},[],{"data":17896,"content":17897,"nodeType":3011},{},[17898,17908],{"data":17899,"content":17900,"nodeType":3025},{},[17901],{"data":17902,"content":17903,"nodeType":883},{},[17904],{"data":17905,"marks":17906,"value":7174,"nodeType":882},{},[17907],{"type":1012},{"data":17909,"content":17910,"nodeType":3025},{},[17911],{"data":17912,"content":17913,"nodeType":883},{},[17914],{"data":17915,"marks":17916,"value":7184,"nodeType":882},{},[],{"data":17918,"content":17919,"nodeType":3011},{},[17920,17930],{"data":17921,"content":17922,"nodeType":3025},{},[17923],{"data":17924,"content":17925,"nodeType":883},{},[17926],{"data":17927,"marks":17928,"value":6865,"nodeType":882},{},[17929],{"type":1012},{"data":17931,"content":17932,"nodeType":3025},{},[17933],{"data":17934,"content":17935,"nodeType":883},{},[17936],{"data":17937,"marks":17938,"value":7207,"nodeType":882},{},[],{"data":17940,"content":17941,"nodeType":967},{},[],{"data":17943,"content":17944,"nodeType":883},{},[17945,17948,17954],{"data":17946,"marks":17947,"value":7217,"nodeType":882},{},[],{"data":17949,"content":17950,"nodeType":929},{"uri":1283},[17951],{"data":17952,"marks":17953,"value":2941,"nodeType":882},{},[],{"data":17955,"marks":17956,"value":21,"nodeType":882},{},[],{"items":17958},[17959,17961],{"sys":17960,"name":298},{"id":7235},{"sys":17962,"name":7239},{"id":7238},{"items":17964},[17965],{"fullName":3964,"firstName":3965,"jobTitle":868,"profilePicture":17966},{"url":3969},"blog\u002Fthe-case-for-best-of-breed-browser-security",{"json":17969},{"data":17970,"content":17971,"nodeType":1294},{},[17972],{"data":17973,"content":17974,"nodeType":883},{},[17975],{"data":17976,"marks":17977,"value":13000,"nodeType":882},{},[],{"id":12433,"publishedAt":17979},"2026-08-13T09:35:07.376Z",{"items":17981},[17982,17984],{"sys":17983,"name":298},{"id":7235},{"sys":17985,"name":2308},{"id":2307},{"items":17987},[17988,17990,17992,17994,17996,17998,18000,18002,18004,18006,18008,18010,18012,18014,18016,18018,18020,18022,18024,18026],{"sys":17989,"name":298,"slug":299,"tier":31},{"id":295},{"sys":17991,"name":280,"slug":281,"tier":31},{"id":277},{"sys":17993,"name":415,"slug":416,"tier":31},{"id":412},{"sys":17995,"name":521,"slug":522,"tier":31},{"id":518},{"sys":17997,"name":343,"slug":344,"tier":31},{"id":340},{"sys":17999,"name":235,"slug":236,"tier":31},{"id":232},{"sys":18001,"name":262,"slug":263,"tier":45},{"id":259},{"sys":18003,"name":316,"slug":317,"tier":45},{"id":313},{"sys":18005,"name":361,"slug":362,"tier":45},{"id":358},{"sys":18007,"name":388,"slug":389,"tier":45},{"id":385},{"sys":18009,"name":334,"slug":335,"tier":45},{"id":331},{"sys":18011,"name":573,"slug":574,"tier":45},{"id":570},{"sys":18013,"name":486,"slug":487,"tier":45},{"id":483},{"sys":18015,"name":397,"slug":398,"tier":45},{"id":394},{"sys":18017,"name":591,"slug":592,"tier":45},{"id":588},{"sys":18019,"name":289,"slug":290,"tier":45},{"id":286},{"sys":18021,"name":512,"slug":513,"tier":45},{"id":509},{"sys":18023,"name":325,"slug":326,"tier":45},{"id":322},{"sys":18025,"name":582,"slug":583,"tier":45},{"id":579},{"sys":18027,"name":244,"slug":245,"tier":45},{"id":241},"ZdRUl9m2-G3Z9CEGGjFodkTk-e0uWBoLuwQs6a2oEzo",{"id":18030,"title":18031,"authorsCollection":18032,"content":18038,"extension":228,"faqItemsCollection":18732,"faqTitle":59,"featured":6,"hashTags":59,"meta":18734,"metaTitle":18735,"ogImage":59,"postType":1360,"publishedDate":8017,"relatedBlogPostsCollection":18736,"slug":20910,"stem":20911,"subtitle":59,"summary":20912,"synopsis":20923,"sys":20924,"tagsCollection":20927,"topicsCollection":20933,"__hash__":20973},"blog\u002Fblog\u002F7-things-omdias-latest-report-tells-us-about-the-secure-enterprise-browser-market.json","7 things Omdia's latest report tells us about the secure enterprise browser market",{"items":18033},[18034],{"fullName":3911,"firstName":3912,"jobTitle":3913,"socialLinks":18035,"profilePicture":18037},[18036],"https:\u002F\u002Fwww.linkedin.com\u002Fin\u002Fdaniel-g-\u002F",{"url":3915},{"json":18039,"links":18610},{"data":18040,"content":18041,"nodeType":1294},{},[18042,18060,18067,18074,18080,18083,18091,18107,18114,18120,18127,18210,18217,18222,18229,18235,18238,18246,18258,18265,18277,18280,18288,18303,18310,18317,18320,18328,18335,18351,18357,18373,18380,18387,18394,18410,18417,18420,18428,18435,18451,18458,18461,18469,18485,18492,18511,18523,18526,18534,18550,18557,18564,18571,18578,18581,18588,18594],{"data":18043,"content":18044,"nodeType":883},{},[18045,18048,18056],{"data":18046,"marks":18047,"value":6443,"nodeType":882},{},[],{"data":18049,"content":18051,"nodeType":929},{"uri":18050},"https:\u002F\u002Fresearch.esg-global.com\u002Freportaction\u002F515202191\u002FMarketing",[18052],{"data":18053,"marks":18054,"value":18055,"nodeType":882},{},[],"Omdia Browser Management and Security report",{"data":18057,"marks":18058,"value":18059,"nodeType":882},{},[],", based on a survey of 400 IT and security professionals across North America fielded in late 2025, is the most comprehensive industry data to date on how organizations are experiencing, prioritizing, and investing in the secure enterprise browser (SEB) market. ",{"data":18061,"content":18062,"nodeType":883},{},[18063],{"data":18064,"marks":18065,"value":18066,"nodeType":882},{},[],"For us at Push, it externally validates what we've known to be true for some time — the browser is where work happens, where attacks land, and where defenders need to be if they want to detect and stop threats before damage is done.",{"data":18068,"content":18069,"nodeType":883},{},[18070],{"data":18071,"marks":18072,"value":18073,"nodeType":882},{},[],"We pulled out seven findings that matter most for security teams evaluating their approach.",{"data":18075,"content":18079,"nodeType":963},{"target":18076},{"sys":18077},{"id":18078,"type":960,"linkType":961},"4aM879egIFYmDvOhzyNI9A",[],{"data":18081,"content":18082,"nodeType":967},{},[],{"data":18084,"content":18085,"nodeType":975},{},[18086],{"data":18087,"marks":18088,"value":18090,"nodeType":882},{},[18089],{"type":1012},"1. The attacks driving concern are the ones happening inside the browser session",{"data":18092,"content":18093,"nodeType":883},{},[18094,18098,18103],{"data":18095,"marks":18096,"value":18097,"nodeType":882},{},[],"The threat picture is driving everything else in this report, so it's the right place to start. ",{"data":18099,"marks":18100,"value":18102,"nodeType":882},{},[18101],{"type":1012},"49% of organizations suffered a successful browser-based attack in the last 12 months.",{"data":18104,"marks":18105,"value":18106,"nodeType":882},{},[]," Among those affected, browser-originated incidents account for roughly 37% of all security incidents — and 68% say that share has grown over the past two years. ",{"data":18108,"content":18109,"nodeType":883},{},[18110],{"data":18111,"marks":18112,"value":18113,"nodeType":882},{},[],"The browser is not an emerging threat vector. It’s worth noting here that these numbers are also likely lower than the reality, since many are only identified later in the kill chain. Without browser-level telemetry they can be difficult to trace back their source — which in the vast majority of cases, even for malware-driven attacks, is the browser. ",{"data":18115,"content":18119,"nodeType":963},{"target":18116},{"sys":18117},{"id":18118,"type":960,"linkType":961},"6Kcz8oILKVHmhQIo5Du6V",[],{"data":18121,"content":18122,"nodeType":883},{},[18123],{"data":18124,"marks":18125,"value":18126,"nodeType":882},{},[],"What stands out is that every one of the top attack categories plays out inside the browser session itself — not against the browser as a piece of software, but within the sessions where users interact with applications:",{"data":18128,"content":18129,"nodeType":1454},{},[18130,18140,18150,18160,18170,18180,18190,18200],{"data":18131,"content":18132,"nodeType":1419},{},[18133],{"data":18134,"content":18135,"nodeType":883},{},[18136],{"data":18137,"marks":18138,"value":18139,"nodeType":882},{},[],"Phishing (40%)",{"data":18141,"content":18142,"nodeType":1419},{},[18143],{"data":18144,"content":18145,"nodeType":883},{},[18146],{"data":18147,"marks":18148,"value":18149,"nodeType":882},{},[],"Data loss or leakage (38%)",{"data":18151,"content":18152,"nodeType":1419},{},[18153],{"data":18154,"content":18155,"nodeType":883},{},[18156],{"data":18157,"marks":18158,"value":18159,"nodeType":882},{},[],"Malicious browser extensions (34%)",{"data":18161,"content":18162,"nodeType":1419},{},[18163],{"data":18164,"content":18165,"nodeType":883},{},[18166],{"data":18167,"marks":18168,"value":18169,"nodeType":882},{},[],"Vulnerable browser extensions (33%)",{"data":18171,"content":18172,"nodeType":1419},{},[18173],{"data":18174,"content":18175,"nodeType":883},{},[18176],{"data":18177,"marks":18178,"value":18179,"nodeType":882},{},[],"Malicious scripts (31%)",{"data":18181,"content":18182,"nodeType":1419},{},[18183],{"data":18184,"content":18185,"nodeType":883},{},[18186],{"data":18187,"marks":18188,"value":18189,"nodeType":882},{},[],"Credential theft via browser (28%)",{"data":18191,"content":18192,"nodeType":1419},{},[18193],{"data":18194,"content":18195,"nodeType":883},{},[18196],{"data":18197,"marks":18198,"value":18199,"nodeType":882},{},[],"Cookie theft (22%)",{"data":18201,"content":18202,"nodeType":1419},{},[18203],{"data":18204,"content":18205,"nodeType":883},{},[18206],{"data":18207,"marks":18208,"value":18209,"nodeType":882},{},[],"AiTM attacks (17%)",{"data":18211,"content":18212,"nodeType":883},{},[18213],{"data":18214,"marks":18215,"value":18216,"nodeType":882},{},[],"Phishing, credential theft, cookie theft, and AiTM are attacks that target the user's interaction with a web page — the credential entry, the session creation, the token exchange. Malicious and vulnerable extensions are supply chain risks that operate inside the browser's own execution environment. Data loss happens through the browser when employees upload files, paste data into AI tools, or share information with unsanctioned applications. ",{"data":18218,"content":18221,"nodeType":963},{"target":18219},{"sys":18220},{"id":7324,"type":960,"linkType":961},[],{"data":18223,"content":18224,"nodeType":883},{},[18225],{"data":18226,"marks":18227,"value":18228,"nodeType":882},{},[],"None of these are attacks where network-layer traffic inspection, endpoint monitoring, or email scanning provides complete coverage, because the attack surface is the browser session itself.",{"data":18230,"content":18234,"nodeType":963},{"target":18231},{"sys":18232},{"id":18233,"type":960,"linkType":961},"5kI5h4Z31ByD73er7voayF",[],{"data":18236,"content":18237,"nodeType":967},{},[],{"data":18239,"content":18240,"nodeType":975},{},[18241],{"data":18242,"marks":18243,"value":18245,"nodeType":882},{},[18244],{"type":1012},"2. Browser security is now a board-level priority",{"data":18247,"content":18248,"nodeType":883},{},[18249,18254],{"data":18250,"marks":18251,"value":18253,"nodeType":882},{},[18252],{"type":1012},"88% of respondents rank browser security as at least a top-five security priority",{"data":18255,"marks":18256,"value":18257,"nodeType":882},{},[],", with more than a quarter (26%) calling it their single top priority. For context, this is a survey that covers the full spectrum of security concerns — cloud, supply chain, AI, insider risk — and browser security has risen above most of them.",{"data":18259,"content":18260,"nodeType":883},{},[18261],{"data":18262,"marks":18263,"value":18264,"nodeType":882},{},[],"This is not aspirational interest. The correlation between priority level and investment is sharp: among those who rank browser security as their top priority, 72% have significantly increased their investment due to emerging threats. Among those who rank it in their top five, that figure is 26%. The organizations that care most are spending the most.",{"data":18266,"content":18267,"nodeType":883},{},[18268,18273],{"data":18269,"marks":18270,"value":18272,"nodeType":882},{},[18271],{"type":1012},"86% of respondents have increased their browser security investment in response to emerging threats",{"data":18274,"marks":18275,"value":18276,"nodeType":882},{},[],", with 36% saying the increase was significant. When you ask what's driving that spend, the answer is the threat landscape: the attacks cataloged in the previous section are the reason budgets are moving.",{"data":18278,"content":18279,"nodeType":967},{},[],{"data":18281,"content":18282,"nodeType":975},{},[18283],{"data":18284,"marks":18285,"value":18287,"nodeType":882},{},[18286],{"type":1012},"3. Real budget is being allocated — and it's growing",{"data":18289,"content":18290,"nodeType":883},{},[18291,18295,18299],{"data":18292,"marks":18293,"value":18294,"nodeType":882},{},[],"Secure enterprise browser solutions already take up ",{"data":18296,"marks":18297,"value":12458,"nodeType":882},{},[18298],{"type":1012},{"data":18300,"marks":18301,"value":18302,"nodeType":882},{},[]," — a substantial allocation for a category that didn't exist as a standalone line item a few years ago. And 85% of respondents expect to increase that spend over the next 12–24 months, with a quarter expecting significant increases.",{"data":18304,"content":18305,"nodeType":883},{},[18306],{"data":18307,"marks":18308,"value":18309,"nodeType":882},{},[],"Where the money comes from tells its own story. The most common funding model is a discrete line item within security program budgets (31%) or a dedicated secure browsing budget (30%). When organizations pull from an existing program budget, web security (26%) and endpoint security (21%) are the most common sources — while SASE\u002FSSE accounts for just 9%, despite SASE vendors being the second most popular vendor category. That disconnect between vendor preference and budget origin suggests the SASE-bundled buying motion may be more aspirational than operational.",{"data":18311,"content":18312,"nodeType":883},{},[18313],{"data":18314,"marks":18315,"value":18316,"nodeType":882},{},[],"IT operations leadership is the top stakeholder in 82% of evaluations, with CISO and security leadership at 64% and CIOs at 42%. Day-to-day management sits primarily with IT Ops (77%) and SecOps (50%). This dual stakeholder picture — IT operations driving evaluation, security leadership providing strategic direction — shapes the competitive landscape in ways we'll come back to.",{"data":18318,"content":18319,"nodeType":967},{},[],{"data":18321,"content":18322,"nodeType":975},{},[18323],{"data":18324,"marks":18325,"value":18327,"nodeType":882},{},[18326],{"type":1012},"4. AI is accelerating both the threat and the use case",{"data":18329,"content":18330,"nodeType":883},{},[18331],{"data":18332,"marks":18333,"value":18334,"nodeType":882},{},[],"AI shows up in this report from two directions, mirroring how it is reshaping the security landscape itself.",{"data":18336,"content":18337,"nodeType":883},{},[18338,18342,18347],{"data":18339,"marks":18340,"value":18341,"nodeType":882},{},[],"On the threat side, ",{"data":18343,"marks":18344,"value":18346,"nodeType":882},{},[18345],{"type":1012},"AI-powered targeted phishing and social engineering is the top emerging concern",{"data":18348,"marks":18349,"value":18350,"nodeType":882},{},[],", cited by 75% of respondents as either very concerning or concerning. Data leakage via unsanctioned AI applications comes second at 71%, followed by deepfake\u002FAI-generated malicious content at 69% and credential harvesting via fake AI or SaaS login pages at 66%. Every one of these threat categories involves the browser — AI-enhanced phishing lands in the browser, AI data leakage happens through browser-based AI tools, and fake AI login pages are browser-based credential harvesting.",{"data":18352,"content":18356,"nodeType":963},{"target":18353},{"sys":18354},{"id":18355,"type":960,"linkType":961},"2ajv2i5wn2GzKuyynQGlvq",[],{"data":18358,"content":18359,"nodeType":883},{},[18360,18364,18369],{"data":18361,"marks":18362,"value":18363,"nodeType":882},{},[],"On the adoption side, the picture is almost universal — and almost universally under-governed. ",{"data":18365,"marks":18366,"value":18368,"nodeType":882},{},[18367],{"type":1012},"92% of organizations now allow employees to use public GenAI applications",{"data":18370,"marks":18371,"value":18372,"nodeType":882},{},[],", and virtually every organization has some kind of policy position: 37% have sanctioned one public app (with everything else unsanctioned), 39% have sanctioned multiple public apps (with others unsanctioned), and 23% restrict employees to a corporate instance while the public versions are unsanctioned. ",{"data":18374,"content":18375,"nodeType":883},{},[18376],{"data":18377,"marks":18378,"value":18379,"nodeType":882},{},[],"Even the 8% who don't allow GenAI at all have taken a policy position. Essentially 100% of organizations have a GenAI policy — but for the vast majority, that policy designates a large portion of public AI tool usage as unsanctioned, which raises the immediate question of whether they have the tooling to actually enforce it.",{"data":18381,"content":18382,"nodeType":883},{},[18383],{"data":18384,"marks":18385,"value":18386,"nodeType":882},{},[],"The answer, based on the current tooling landscape, appears to be: not quite. When Omdia asked how organizations currently secure GenAI usage, 58% rely on secure web gateways — tools that see traffic metadata but cannot observe what a user actually does inside a GenAI session — while 57% use secure browsing solutions and 57% use SaaS security solutions. ",{"data":18388,"content":18389,"nodeType":883},{},[18390],{"data":18391,"marks":18392,"value":18393,"nodeType":882},{},[],"An SWG can tell you that a user visited ChatGPT, but it cannot tell you whether they pasted your company's source code into the prompt. That distinction — between knowing where data went and knowing what the user actually did — is the fundamental gap that browser-layer visibility exists to close, and it is exactly the gap that makes GenAI policies unenforceable without browser-layer tooling.",{"data":18395,"content":18396,"nodeType":883},{},[18397,18401,18406],{"data":18398,"marks":18399,"value":18400,"nodeType":882},{},[],"The use case data reflects this. When Omdia asked about the most important use cases for a secure browsing solution, ",{"data":18402,"marks":18403,"value":18405,"nodeType":882},{},[18404],{"type":1012},"generative AI application security came in first at 59%",{"data":18407,"marks":18408,"value":18409,"nodeType":882},{},[],", followed by data loss prevention at 51% and general web security enhancement at 42%. The feature priorities tell a consistent story: AI-powered threat detection and response (52%) and advanced GenAI usage controls and monitoring (41%) were the top two capabilities organizations said would be most important in a purchase decision. ",{"data":18411,"content":18412,"nodeType":883},{},[18413],{"data":18414,"marks":18415,"value":18416,"nodeType":882},{},[],"AI is both the top threat concern and the top use case for browser security — and it is a browser problem at both ends, because every LLM interaction, every prompt containing sensitive data, and every AI agent authorization happens inside a browser session.",{"data":18418,"content":18419,"nodeType":967},{},[],{"data":18421,"content":18422,"nodeType":975},{},[18423],{"data":18424,"marks":18425,"value":18427,"nodeType":882},{},[18426],{"type":1012},"5. Organizations that have deployed secure enterprise browser solutions are seeing real results",{"data":18429,"content":18430,"nodeType":883},{},[18431],{"data":18432,"marks":18433,"value":18434,"nodeType":882},{},[],"One of the most useful sections in Omdia's report is the benefits data — what organizations that have deployed SEB solutions are actually getting out of them.",{"data":18436,"content":18437,"nodeType":883},{},[18438,18442,18447],{"data":18439,"marks":18440,"value":18441,"nodeType":882},{},[],"The top realized benefit is ",{"data":18443,"marks":18444,"value":18446,"nodeType":882},{},[18445],{"type":1012},"improved data security, cited by 58% of respondents",{"data":18448,"marks":18449,"value":18450,"nodeType":882},{},[],", followed by fewer security incidents (49%), better visibility and auditing (47%), improved user experience (44%), and simplified configuration and policy management (41%). The picture that emerges is not just a security story but an operational one: organizations are seeing fewer incidents, better visibility, and simpler management alongside the security outcomes.",{"data":18452,"content":18453,"nodeType":883},{},[18454],{"data":18455,"marks":18456,"value":18457,"nodeType":882},{},[],"The 49% who cite fewer security incidents as a realized benefit is the number that matters most here, because it directly connects SEB deployment to measurable risk reduction. Organizations aren't just buying tools and hoping — they're deploying them and seeing fewer successful attacks as a result.",{"data":18459,"content":18460,"nodeType":967},{},[],{"data":18462,"content":18463,"nodeType":975},{},[18464],{"data":18465,"marks":18466,"value":18468,"nodeType":882},{},[18467],{"type":1012},"6. The market wants protection in existing browsers, not migration",{"data":18470,"content":18471,"nodeType":883},{},[18472,18476,18481],{"data":18473,"marks":18474,"value":18475,"nodeType":882},{},[],"When Omdia asked what attributes matter most in a secure enterprise browser solution, ",{"data":18477,"marks":18478,"value":18480,"nodeType":882},{},[18479],{"type":1012},"\"ability to use existing browsers\" ranked as the fourth most important attribute at 48%",{"data":18482,"marks":18483,"value":18484,"nodeType":882},{},[]," — behind only integration with other security tools (57%), controls over generative AI application usage (53%), and centralized policy enforcement (52%). ",{"data":18486,"content":18487,"nodeType":883},{},[18488],{"data":18489,"marks":18490,"value":18491,"nodeType":882},{},[],"That 48% figure, combined with 80% of respondents saying they expect to use an SEB solution as an integrated or alongside component rather than a replacement for existing tools, points to a clear market preference: organizations want browser security that works with their existing browser estate, not a migration to a new one.",{"data":18493,"content":18494,"nodeType":883},{},[18495,18499,18507],{"data":18496,"marks":18497,"value":18498,"nodeType":882},{},[],"This is consistent with what we hear from security leaders directly. As ",{"data":18500,"content":18501,"nodeType":929},{"uri":4493},[18502],{"data":18503,"marks":18504,"value":18506,"nodeType":882},{},[18505],{"type":927},"Josh Lemos put it: ",{"data":18508,"marks":18509,"value":18510,"nodeType":882},{},[],"\"We looked at the full-stack enterprise browser approach, but converging on a single platform was tough. Push gave me the security instrumentation and context I needed without onerous headwinds.\" The deployment model matters because it determines adoption velocity — and a tool that requires browser migration introduces friction that delays time to value.",{"data":18512,"content":18513,"nodeType":883},{},[18514,18518],{"data":18515,"marks":18516,"value":18517,"nodeType":882},{},[],"Push was built around this insight from day one. As the secure enterprise browser extension for security teams, Push turns any browser — managed or unmanaged, including agentic browsers — into a telemetry source and control point the moment it's installed. It has been rolled out to 100,000 users in under an hour during normal office hours with zero downtime. ",{"data":18519,"marks":18520,"value":18522,"nodeType":882},{},[18521],{"type":1012},"That is a deployment model that matches what Omdia's respondents are asking for.",{"data":18524,"content":18525,"nodeType":967},{},[],{"data":18527,"content":18528,"nodeType":975},{},[18529],{"data":18530,"marks":18531,"value":18533,"nodeType":882},{},[18532],{"type":1012},"7. Dedicated vendors lead over platform plays",{"data":18535,"content":18536,"nodeType":883},{},[18537,18541,18546],{"data":18538,"marks":18539,"value":18540,"nodeType":882},{},[],"When Omdia asked which category of vendor organizations primarily use or expect to use for secure enterprise browsing, ",{"data":18542,"marks":18543,"value":18545,"nodeType":882},{},[18544],{"type":1012},"36% chose a dedicated SEB vendor",{"data":18547,"marks":18548,"value":18549,"nodeType":882},{},[]," — the largest single category. SASE\u002Fnetwork security vendors came second at 29%, followed by traditional VDI\u002Fdesktop virtualization vendors at 19% and endpoint platform vendors at 15%.",{"data":18551,"content":18552,"nodeType":883},{},[18553],{"data":18554,"marks":18555,"value":18556,"nodeType":882},{},[],"The dedicated category leads, and the reason isn't just first-mover advantage — it's architectural. The alternative paths each come with structural constraints. SASE and SSE platforms are network-centric: they see traffic metadata and enforce URL categorization, but they can't observe the rendered page inside a browser tab — the DOM structure, the script behavior, the credential entry that distinguishes a legitimate login from an AiTM reverse-proxy kit. ",{"data":18558,"content":18559,"nodeType":883},{},[18560],{"data":18561,"marks":18562,"value":18563,"nodeType":882},{},[],"Endpoint platforms that bolt on browser visibility are still anchored to the OS layer, solving for browser exploit prevention rather than in-session behavioral detection of the attacks that actually dominate — phishing, credential theft, session hijacking, extension compromise. And when large platform vendors acquire browser security capabilities, the integration work takes years rather than months, during which detection depth sits in a transitional state. ",{"data":18565,"content":18566,"nodeType":883},{},[18567],{"data":18568,"marks":18569,"value":18570,"nodeType":882},{},[],"Dedicated browser-native vendors start from a different premise entirely: the browser isn't a supplementary signal feeding into someone else's SASE pipeline or XDR correlation engine — it is the telemetry source and the control point. The browser is the only place where you get simultaneous visibility into both the attacker's technique and the employee's action within the same session, because the phishing page, the credential submission, the token exchange, and the data exfiltration all happen inside the same tab. No network appliance, endpoint agent, or identity provider log can see all of that, because none of them are present where the interaction occurs.",{"data":18572,"content":18573,"nodeType":883},{},[18574],{"data":18575,"marks":18576,"value":18577,"nodeType":882},{},[],"For security teams evaluating SEB solutions, the architecture matters more than the vendor category label. The capabilities Omdia's respondents ranked highest — integration with existing tools, GenAI controls, centralized policy enforcement, and the ability to use existing browsers — all point toward solutions that deliver detection depth through a lightweight deployment model, without browser migration and without the integration debt of a platform acquisition.",{"data":18579,"content":18580,"nodeType":967},{},[],{"data":18582,"content":18583,"nodeType":883},{},[18584],{"data":18585,"marks":18586,"value":18587,"nodeType":882},{},[],"Push Security is the most powerful AI-native security tool in the browser. Think EDR, but for the browser — high-fidelity telemetry and real-time control across every session, on every device, with no browser migration required. ",{"data":18589,"content":18590,"nodeType":883},{},[18591],{"data":18592,"marks":18593,"value":2926,"nodeType":882},{},[],{"data":18595,"content":18596,"nodeType":883},{},[18597,18600,18607],{"data":18598,"marks":18599,"value":21,"nodeType":882},{},[],{"data":18601,"content":18602,"nodeType":929},{"uri":1283},[18603],{"data":18604,"marks":18605,"value":3893,"nodeType":882},{},[18606],{"type":927},{"data":18608,"marks":18609,"value":3897,"nodeType":882},{},[],{"entries":18611},{"hyperlink":18612,"inline":18613,"block":18614},[],[],[18615,18623,18660,18664,18693],{"sys":18616,"__typename":1329,"title":18617,"caption":18618,"layoutMode":59,"file":18619},{"id":18078},"Omdia report key stats infographic","Headline stats from the latest Omdia report.",{"url":18620,"width":18621,"height":18622},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F62TiADpvI65W2gT7RQwlOU\u002Fa4aaad376574b1cd963fc0afa5e2942d\u002Fomdia-browser-security-infographic_2x__2_.png",1700,1434,{"sys":18624,"__typename":1302,"content":18625,"name":18659,"title":59},{"id":18118},{"json":18626},{"nodeType":1294,"data":18627,"content":18628},{},[18629],{"nodeType":883,"data":18630,"content":18631},{},[18632,18636,18643,18647,18655],{"nodeType":882,"value":18633,"marks":18634,"data":18635},"The evidence here isn’t just statistics. The real-world breaches attributed to ",[],{},{"nodeType":929,"data":18637,"content":18638},{"uri":8219},[18639],{"nodeType":882,"value":16533,"marks":18640,"data":18642},[18641],{"type":927},{},{"nodeType":882,"value":18644,"marks":18645,"data":18646},", including the ",[],{},{"nodeType":929,"data":18648,"content":18649},{"uri":3507},[18650],{"nodeType":882,"value":18651,"marks":18652,"data":18654},"ShinyHunters-branded 2026 hacking spree",[18653],{"type":927},{},{"nodeType":882,"value":18656,"marks":18657,"data":18658},", clearly underline the real-world threat. ",[],{},"Omdia report IB1",{"sys":18661,"__typename":12405,"type":12406,"ctaText":18662,"buttonLabel":18663,"buttonColour":12408,"buttonUrl":3358},{"id":7324},"Get our latest technical whitepaper to learn about the state of browser-based attacks in 2026 (no sign-up required).","Download Now",{"sys":18665,"__typename":1302,"content":18666,"name":18692,"title":59},{"id":18233},{"json":18667},{"data":18668,"content":18669,"nodeType":1294},{},[18670],{"data":18671,"content":18672,"nodeType":883},{},[18673,18677,18688],{"data":18674,"marks":18675,"value":18676,"nodeType":882},{},[],"It's worth noting that AiTM — now the dominant phishing technique in the wild,",{"data":18678,"content":18679,"nodeType":929},{"uri":8231},[18680,18683],{"data":18681,"marks":18682,"value":2218,"nodeType":882},{},[],{"data":18684,"marks":18685,"value":18687,"nodeType":882},{},[18686],{"type":927},"responsible for 62% of phishing blocked by Microsoft",{"data":18689,"marks":18690,"value":18691,"nodeType":882},{},[]," — shows up at just 17% in Omdia's data. That likely reflects a recognition gap rather than low prevalence: most organizations lack the browser-layer visibility to distinguish an AiTM reverse-proxy attack from a conventional phishing page, which means the real AiTM figure is probably buried inside the 40% who reported phishing generally.","Omdia report IB2",{"sys":18694,"__typename":1302,"content":18695,"name":18731,"title":59},{"id":18355},{"json":18696},{"nodeType":1294,"data":18697,"content":18698},{},[18699],{"nodeType":883,"data":18700,"content":18701},{},[18702,18706,18715,18719,18727],{"nodeType":882,"value":18703,"marks":18704,"data":18705},"This is something we’re seeing extensively in the wild. Just about every phishing kit we encounter today is packed with signs of AI use. You can see our ",[],{},{"nodeType":929,"data":18707,"content":18709},{"uri":18708},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Finside-criminal-phishing-panel\u002F",[18710],{"nodeType":882,"value":18711,"marks":18712,"data":18714},"recent analysis of the Doko’s Panel real-time vishing + AitM kit",[18713],{"type":927},{},{"nodeType":882,"value":18716,"marks":18717,"data":18718}," for one example of this. AI development of kits and tools is rapidly driving down the time for attackers to adopt and scale new capabilities — the ",[],{},{"nodeType":929,"data":18720,"content":18721},{"uri":3389},[18722],{"nodeType":882,"value":18723,"marks":18724,"data":18726},"37x increase in device code phishing in 2026",[18725],{"type":927},{},{"nodeType":882,"value":18728,"marks":18729,"data":18730}," being another indicator of this (we've observed heavy AI tool use across multiple kits and campaigns, with the EvilTokens kit gaining particular notoriety for its abuse of the Railway platform's AI features).",[],{},"Omdia report IB3",{"items":18733},[],{},"7 things Omdia's latest report tells us about the SEB market",{"items":18737},[18738,19410,19931],{"__typename":1365,"sys":18739,"content":18740,"title":8015,"synopsis":8016,"hashTags":59,"publishedDate":8017,"slug":8018,"tagsCollection":19400,"authorsCollection":19406},{"id":7246},{"json":18741},{"data":18742,"content":18743,"nodeType":1294},{},[18744,18749,18755,18761,18767,18770,18777,18783,18793,18803,18808,18814,18817,18824,18830,18835,18841,18847,18940,18946,18949,18956,18962,19017,19030,19035,19041,19044,19051,19057,19064,19070,19076,19101,19107,19114,19120,19126,19132,19139,19145,19151,19157,19160,19167,19177,19183,19189,19196,19202,19208,19215,19221,19276,19289,19304,19311,19317,19324,19330,19336,19342,19347,19354,19360,19366,19371,19377,19383,19389,19394],{"data":18745,"content":18748,"nodeType":963},{"target":18746},{"sys":18747},{"id":7255,"type":960,"linkType":961},[],{"data":18750,"content":18751,"nodeType":883},{},[18752],{"data":18753,"marks":18754,"value":7263,"nodeType":882},{},[],{"data":18756,"content":18757,"nodeType":883},{},[18758],{"data":18759,"marks":18760,"value":7270,"nodeType":882},{},[],{"data":18762,"content":18763,"nodeType":883},{},[18764],{"data":18765,"marks":18766,"value":7277,"nodeType":882},{},[],{"data":18768,"content":18769,"nodeType":967},{},[],{"data":18771,"content":18772,"nodeType":975},{},[18773],{"data":18774,"marks":18775,"value":7288,"nodeType":882},{},[18776],{"type":1012},{"data":18778,"content":18779,"nodeType":883},{},[18780],{"data":18781,"marks":18782,"value":7295,"nodeType":882},{},[],{"data":18784,"content":18785,"nodeType":883},{},[18786,18790],{"data":18787,"marks":18788,"value":7303,"nodeType":882},{},[18789],{"type":1012},{"data":18791,"marks":18792,"value":7307,"nodeType":882},{},[],{"data":18794,"content":18795,"nodeType":883},{},[18796,18800],{"data":18797,"marks":18798,"value":7315,"nodeType":882},{},[18799],{"type":1012},{"data":18801,"marks":18802,"value":7319,"nodeType":882},{},[],{"data":18804,"content":18807,"nodeType":963},{"target":18805},{"sys":18806},{"id":7324,"type":960,"linkType":961},[],{"data":18809,"content":18810,"nodeType":883},{},[18811],{"data":18812,"marks":18813,"value":7332,"nodeType":882},{},[],{"data":18815,"content":18816,"nodeType":967},{},[],{"data":18818,"content":18819,"nodeType":975},{},[18820],{"data":18821,"marks":18822,"value":7343,"nodeType":882},{},[18823],{"type":1012},{"data":18825,"content":18826,"nodeType":883},{},[18827],{"data":18828,"marks":18829,"value":7350,"nodeType":882},{},[],{"data":18831,"content":18834,"nodeType":963},{"target":18832},{"sys":18833},{"id":7355,"type":960,"linkType":961},[],{"data":18836,"content":18837,"nodeType":883},{},[18838],{"data":18839,"marks":18840,"value":7363,"nodeType":882},{},[],{"data":18842,"content":18843,"nodeType":883},{},[18844],{"data":18845,"marks":18846,"value":7370,"nodeType":882},{},[],{"data":18848,"content":18849,"nodeType":1454},{},[18850,18866,18882,18898,18914,18927],{"data":18851,"content":18852,"nodeType":1419},{},[18853],{"data":18854,"content":18855,"nodeType":883},{},[18856,18859,18863],{"data":18857,"marks":18858,"value":7383,"nodeType":882},{},[],{"data":18860,"marks":18861,"value":7388,"nodeType":882},{},[18862],{"type":1012},{"data":18864,"marks":18865,"value":7392,"nodeType":882},{},[],{"data":18867,"content":18868,"nodeType":1419},{},[18869],{"data":18870,"content":18871,"nodeType":883},{},[18872,18875,18879],{"data":18873,"marks":18874,"value":7402,"nodeType":882},{},[],{"data":18876,"marks":18877,"value":7407,"nodeType":882},{},[18878],{"type":1012},{"data":18880,"marks":18881,"value":7411,"nodeType":882},{},[],{"data":18883,"content":18884,"nodeType":1419},{},[18885],{"data":18886,"content":18887,"nodeType":883},{},[18888,18891,18895],{"data":18889,"marks":18890,"value":7421,"nodeType":882},{},[],{"data":18892,"marks":18893,"value":7426,"nodeType":882},{},[18894],{"type":1012},{"data":18896,"marks":18897,"value":7430,"nodeType":882},{},[],{"data":18899,"content":18900,"nodeType":1419},{},[18901],{"data":18902,"content":18903,"nodeType":883},{},[18904,18907,18911],{"data":18905,"marks":18906,"value":7440,"nodeType":882},{},[],{"data":18908,"marks":18909,"value":7445,"nodeType":882},{},[18910],{"type":1012},{"data":18912,"marks":18913,"value":7449,"nodeType":882},{},[],{"data":18915,"content":18916,"nodeType":1419},{},[18917],{"data":18918,"content":18919,"nodeType":883},{},[18920,18924],{"data":18921,"marks":18922,"value":7460,"nodeType":882},{},[18923],{"type":1012},{"data":18925,"marks":18926,"value":7464,"nodeType":882},{},[],{"data":18928,"content":18929,"nodeType":1419},{},[18930],{"data":18931,"content":18932,"nodeType":883},{},[18933,18937],{"data":18934,"marks":18935,"value":7475,"nodeType":882},{},[18936],{"type":1012},{"data":18938,"marks":18939,"value":7479,"nodeType":882},{},[],{"data":18941,"content":18942,"nodeType":883},{},[18943],{"data":18944,"marks":18945,"value":7486,"nodeType":882},{},[],{"data":18947,"content":18948,"nodeType":967},{},[],{"data":18950,"content":18951,"nodeType":2050},{},[18952],{"data":18953,"marks":18954,"value":7497,"nodeType":882},{},[18955],{"type":1012},{"data":18957,"content":18958,"nodeType":883},{},[18959],{"data":18960,"marks":18961,"value":7504,"nodeType":882},{},[],{"data":18963,"content":18964,"nodeType":1454},{},[18965,18978,18991,19004],{"data":18966,"content":18967,"nodeType":1419},{},[18968],{"data":18969,"content":18970,"nodeType":883},{},[18971,18974],{"data":18972,"marks":18973,"value":7517,"nodeType":882},{},[],{"data":18975,"marks":18976,"value":7522,"nodeType":882},{},[18977],{"type":1012},{"data":18979,"content":18980,"nodeType":1419},{},[18981],{"data":18982,"content":18983,"nodeType":883},{},[18984,18987],{"data":18985,"marks":18986,"value":7532,"nodeType":882},{},[],{"data":18988,"marks":18989,"value":7537,"nodeType":882},{},[18990],{"type":1012},{"data":18992,"content":18993,"nodeType":1419},{},[18994],{"data":18995,"content":18996,"nodeType":883},{},[18997,19000],{"data":18998,"marks":18999,"value":7547,"nodeType":882},{},[],{"data":19001,"marks":19002,"value":7552,"nodeType":882},{},[19003],{"type":1012},{"data":19005,"content":19006,"nodeType":1419},{},[19007],{"data":19008,"content":19009,"nodeType":883},{},[19010,19013],{"data":19011,"marks":19012,"value":7562,"nodeType":882},{},[],{"data":19014,"marks":19015,"value":7567,"nodeType":882},{},[19016],{"type":1012},{"data":19018,"content":19019,"nodeType":883},{},[19020,19023,19027],{"data":19021,"marks":19022,"value":7574,"nodeType":882},{},[],{"data":19024,"marks":19025,"value":7579,"nodeType":882},{},[19026],{"type":1012},{"data":19028,"marks":19029,"value":7583,"nodeType":882},{},[],{"data":19031,"content":19034,"nodeType":963},{"target":19032},{"sys":19033},{"id":7588,"type":960,"linkType":961},[],{"data":19036,"content":19037,"nodeType":883},{},[19038],{"data":19039,"marks":19040,"value":7596,"nodeType":882},{},[],{"data":19042,"content":19043,"nodeType":967},{},[],{"data":19045,"content":19046,"nodeType":975},{},[19047],{"data":19048,"marks":19049,"value":7607,"nodeType":882},{},[19050],{"type":1012},{"data":19052,"content":19053,"nodeType":883},{},[19054],{"data":19055,"marks":19056,"value":7614,"nodeType":882},{},[],{"data":19058,"content":19059,"nodeType":2050},{},[19060],{"data":19061,"marks":19062,"value":7622,"nodeType":882},{},[19063],{"type":1012},{"data":19065,"content":19066,"nodeType":883},{},[19067],{"data":19068,"marks":19069,"value":7629,"nodeType":882},{},[],{"data":19071,"content":19072,"nodeType":883},{},[19073],{"data":19074,"marks":19075,"value":7636,"nodeType":882},{},[],{"data":19077,"content":19078,"nodeType":883},{},[19079,19082,19088,19091,19098],{"data":19080,"marks":19081,"value":7643,"nodeType":882},{},[],{"data":19083,"content":19084,"nodeType":929},{"uri":6589},[19085],{"data":19086,"marks":19087,"value":7650,"nodeType":882},{},[],{"data":19089,"marks":19090,"value":7654,"nodeType":882},{},[],{"data":19092,"content":19093,"nodeType":929},{"uri":7657},[19094],{"data":19095,"marks":19096,"value":7663,"nodeType":882},{},[19097],{"type":927},{"data":19099,"marks":19100,"value":7667,"nodeType":882},{},[],{"data":19102,"content":19103,"nodeType":883},{},[19104],{"data":19105,"marks":19106,"value":7674,"nodeType":882},{},[],{"data":19108,"content":19109,"nodeType":2050},{},[19110],{"data":19111,"marks":19112,"value":7682,"nodeType":882},{},[19113],{"type":1012},{"data":19115,"content":19116,"nodeType":883},{},[19117],{"data":19118,"marks":19119,"value":7689,"nodeType":882},{},[],{"data":19121,"content":19122,"nodeType":883},{},[19123],{"data":19124,"marks":19125,"value":7696,"nodeType":882},{},[],{"data":19127,"content":19128,"nodeType":883},{},[19129],{"data":19130,"marks":19131,"value":7703,"nodeType":882},{},[],{"data":19133,"content":19134,"nodeType":2050},{},[19135],{"data":19136,"marks":19137,"value":7711,"nodeType":882},{},[19138],{"type":1012},{"data":19140,"content":19141,"nodeType":883},{},[19142],{"data":19143,"marks":19144,"value":7718,"nodeType":882},{},[],{"data":19146,"content":19147,"nodeType":883},{},[19148],{"data":19149,"marks":19150,"value":7725,"nodeType":882},{},[],{"data":19152,"content":19153,"nodeType":883},{},[19154],{"data":19155,"marks":19156,"value":7732,"nodeType":882},{},[],{"data":19158,"content":19159,"nodeType":967},{},[],{"data":19161,"content":19162,"nodeType":975},{},[19163],{"data":19164,"marks":19165,"value":7743,"nodeType":882},{},[19166],{"type":1012},{"data":19168,"content":19169,"nodeType":883},{},[19170,19174],{"data":19171,"marks":19172,"value":7751,"nodeType":882},{},[19173],{"type":1012},{"data":19175,"marks":19176,"value":7755,"nodeType":882},{},[],{"data":19178,"content":19179,"nodeType":883},{},[19180],{"data":19181,"marks":19182,"value":7762,"nodeType":882},{},[],{"data":19184,"content":19185,"nodeType":883},{},[19186],{"data":19187,"marks":19188,"value":7769,"nodeType":882},{},[],{"data":19190,"content":19191,"nodeType":2050},{},[19192],{"data":19193,"marks":19194,"value":7777,"nodeType":882},{},[19195],{"type":1012},{"data":19197,"content":19198,"nodeType":883},{},[19199],{"data":19200,"marks":19201,"value":7784,"nodeType":882},{},[],{"data":19203,"content":19204,"nodeType":883},{},[19205],{"data":19206,"marks":19207,"value":7791,"nodeType":882},{},[],{"data":19209,"content":19210,"nodeType":2050},{},[19211],{"data":19212,"marks":19213,"value":7799,"nodeType":882},{},[19214],{"type":1012},{"data":19216,"content":19217,"nodeType":883},{},[19218],{"data":19219,"marks":19220,"value":7806,"nodeType":882},{},[],{"data":19222,"content":19223,"nodeType":1454},{},[19224,19237,19250,19263],{"data":19225,"content":19226,"nodeType":1419},{},[19227],{"data":19228,"content":19229,"nodeType":883},{},[19230,19234],{"data":19231,"marks":19232,"value":7820,"nodeType":882},{},[19233],{"type":1012},{"data":19235,"marks":19236,"value":7824,"nodeType":882},{},[],{"data":19238,"content":19239,"nodeType":1419},{},[19240],{"data":19241,"content":19242,"nodeType":883},{},[19243,19247],{"data":19244,"marks":19245,"value":7835,"nodeType":882},{},[19246],{"type":1012},{"data":19248,"marks":19249,"value":7839,"nodeType":882},{},[],{"data":19251,"content":19252,"nodeType":1419},{},[19253],{"data":19254,"content":19255,"nodeType":883},{},[19256,19260],{"data":19257,"marks":19258,"value":7850,"nodeType":882},{},[19259],{"type":1012},{"data":19261,"marks":19262,"value":7854,"nodeType":882},{},[],{"data":19264,"content":19265,"nodeType":1419},{},[19266],{"data":19267,"content":19268,"nodeType":883},{},[19269,19273],{"data":19270,"marks":19271,"value":7865,"nodeType":882},{},[19272],{"type":1012},{"data":19274,"marks":19275,"value":7869,"nodeType":882},{},[],{"data":19277,"content":19278,"nodeType":883},{},[19279,19282,19286],{"data":19280,"marks":19281,"value":7876,"nodeType":882},{},[],{"data":19283,"marks":19284,"value":7881,"nodeType":882},{},[19285],{"type":1012},{"data":19287,"marks":19288,"value":7885,"nodeType":882},{},[],{"data":19290,"content":19291,"nodeType":883},{},[19292,19295,19301],{"data":19293,"marks":19294,"value":7892,"nodeType":882},{},[],{"data":19296,"content":19297,"nodeType":929},{"uri":7895},[19298],{"data":19299,"marks":19300,"value":7900,"nodeType":882},{},[],{"data":19302,"marks":19303,"value":7904,"nodeType":882},{},[],{"data":19305,"content":19306,"nodeType":2050},{},[19307],{"data":19308,"marks":19309,"value":7912,"nodeType":882},{},[19310],{"type":1012},{"data":19312,"content":19313,"nodeType":883},{},[19314],{"data":19315,"marks":19316,"value":7919,"nodeType":882},{},[],{"data":19318,"content":19319,"nodeType":883},{},[19320],{"data":19321,"marks":19322,"value":7927,"nodeType":882},{},[19323],{"type":1012},{"data":19325,"content":19326,"nodeType":883},{},[19327],{"data":19328,"marks":19329,"value":7934,"nodeType":882},{},[],{"data":19331,"content":19332,"nodeType":883},{},[19333],{"data":19334,"marks":19335,"value":7941,"nodeType":882},{},[],{"data":19337,"content":19338,"nodeType":883},{},[19339],{"data":19340,"marks":19341,"value":7948,"nodeType":882},{},[],{"data":19343,"content":19346,"nodeType":963},{"target":19344},{"sys":19345},{"id":7953,"type":960,"linkType":961},[],{"data":19348,"content":19349,"nodeType":2050},{},[19350],{"data":19351,"marks":19352,"value":7962,"nodeType":882},{},[19353],{"type":1012},{"data":19355,"content":19356,"nodeType":883},{},[19357],{"data":19358,"marks":19359,"value":7969,"nodeType":882},{},[],{"data":19361,"content":19362,"nodeType":883},{},[19363],{"data":19364,"marks":19365,"value":7976,"nodeType":882},{},[],{"data":19367,"content":19370,"nodeType":963},{"target":19368},{"sys":19369},{"id":4417,"type":960,"linkType":961},[],{"data":19372,"content":19373,"nodeType":883},{},[19374],{"data":19375,"marks":19376,"value":7988,"nodeType":882},{},[],{"data":19378,"content":19379,"nodeType":883},{},[19380],{"data":19381,"marks":19382,"value":7995,"nodeType":882},{},[],{"data":19384,"content":19385,"nodeType":883},{},[19386],{"data":19387,"marks":19388,"value":8002,"nodeType":882},{},[],{"data":19390,"content":19393,"nodeType":963},{"target":19391},{"sys":19392},{"id":8007,"type":960,"linkType":961},[],{"data":19395,"content":19396,"nodeType":883},{},[19397],{"data":19398,"marks":19399,"value":21,"nodeType":882},{},[],{"items":19401},[19402,19404],{"sys":19403,"name":298},{"id":7235},{"sys":19405,"name":7239},{"id":7238},{"items":19407},[19408],{"fullName":3964,"firstName":3965,"jobTitle":868,"profilePicture":19409},{"url":3969},{"__typename":1365,"sys":19411,"content":19413,"title":19917,"synopsis":19918,"hashTags":59,"publishedDate":19919,"slug":19920,"tagsCollection":19921,"authorsCollection":19927},{"id":19412},"2MWicW07sNEBp59wxYtAiC",{"json":19414},{"data":19415,"content":19416,"nodeType":1294},{},[19417,19425,19456,19462,19469,19488,19503,19506,19514,19529,19548,19573,19579,19595,19623,19629,19635,19651,19654,19662,19669,19677,19695,19711,19718,19743,19750,19758,19787,19794,19802,19809,19815,19818,19826,19833,19841,19847,19850,19858,19865,19872,19879,19891,19894,19900],{"data":19418,"content":19419,"nodeType":975},{},[19420],{"data":19421,"marks":19422,"value":19424,"nodeType":882},{},[19423],{"type":1012},"The quantification problem nobody talks about",{"data":19426,"content":19427,"nodeType":883},{},[19428,19432,19440,19444,19452],{"data":19429,"marks":19430,"value":19431,"nodeType":882},{},[],"I was recently teaching ",{"data":19433,"content":19435,"nodeType":929},{"uri":19434},"https:\u002F\u002Fwww.sans.org\u002Fcyber-security-courses\u002Fcybersecurity-leaders\u002F",[19436],{"data":19437,"marks":19438,"value":19439,"nodeType":882},{},[],"SANS LDR551",{"data":19441,"marks":19442,"value":19443,"nodeType":882},{},[],", where we cover some of the flawed approaches used in risk measurement and prioritization — for example, presenting ordinal data in a risk matrix as ratio data, implying that the matrix represents quantitative analysis when it’s more of a best guess. We then look at modeling using ",{"data":19445,"content":19447,"nodeType":929},{"uri":19446},"https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FLoss_exceedance_curve",[19448],{"data":19449,"marks":19450,"value":19451,"nodeType":882},{},[],"Loss Exceedance Curves",{"data":19453,"marks":19454,"value":19455,"nodeType":882},{},[]," as a more accurate, if much more difficult, approach to quantitative risk assessment.",{"data":19457,"content":19461,"nodeType":963},{"target":19458},{"sys":19459},{"id":19460,"type":960,"linkType":961},"4S1wJUm6E1qvyZzwrl2DL",[],{"data":19463,"content":19464,"nodeType":883},{},[19465],{"data":19466,"marks":19467,"value":19468,"nodeType":882},{},[],"The only problem is, we rarely have the time or the data to construct such models. Ask a CISO how they measure risk for credential compromise and other account takeover attacks, and the answer will probably include one or more of the following: a risk assessment, a whiteboard, and a room full of smart people making educated guesses about attack frequency and control strength. ",{"data":19470,"content":19471,"nodeType":883},{},[19472,19476,19484],{"data":19473,"marks":19474,"value":19475,"nodeType":882},{},[],"That isn't a criticism — for most risk scenarios, expert elicitation is the best (and most convenient) available method. Breach cost data is sparse, threat actor behavior is unpredictable, and internal incident history is (ideally!) a limited sample. Quantitative risk frameworks like ",{"data":19477,"content":19479,"nodeType":929},{"uri":19478},"https:\u002F\u002Fwww.fairinstitute.org\u002F",[19480],{"data":19481,"marks":19482,"value":19483,"nodeType":882},{},[],"FAIR",{"data":19485,"marks":19486,"value":19487,"nodeType":882},{},[]," give structure to that uncertainty, but they can't conjure data that just doesn't exist.",{"data":19489,"content":19490,"nodeType":883},{},[19491,19495,19500],{"data":19492,"marks":19493,"value":19494,"nodeType":882},{},[],"The results are usually estimates with wide confidence intervals and loss distributions that appear precise, but are hard to defend to a CFO or a board. Finance leaders have seen Monte Carlo simulations before; the capable ones will challenge the quality of the outputs if they doubt the quality of the inputs. ",{"data":19496,"marks":19497,"value":19499,"nodeType":882},{},[19498],{"type":1012},"But with the right telemetry, we can get both",{"data":19501,"marks":19502,"value":1438,"nodeType":882},{},[],{"data":19504,"content":19505,"nodeType":967},{},[],{"data":19507,"content":19508,"nodeType":975},{},[19509],{"data":19510,"marks":19511,"value":19513,"nodeType":882},{},[19512],{"type":1012},"Why the identity attack surface is uniquely measurable",{"data":19515,"content":19516,"nodeType":883},{},[19517,19521,19526],{"data":19518,"marks":19519,"value":19520,"nodeType":882},{},[],"We've written extensively about the shift to identity as a primary attack vector — and the evidence continues to stack up. Credential phishing, device code phishing, ClickFix, adversary-in-the-middle attacks, session hijacking, and SaaS account compromise now account for the majority of breach entry points in most enterprise environments. But the silver lining here is that this shift has created something valuable for risk quantification: ",{"data":19522,"marks":19523,"value":19525,"nodeType":882},{},[19524],{"type":1045},"a highly observable threat surface",{"data":19527,"marks":19528,"value":1438,"nodeType":882},{},[],{"data":19530,"content":19531,"nodeType":883},{},[19532,19536,19544],{"data":19533,"marks":19534,"value":19535,"nodeType":882},{},[],"Identity attacks execute ",{"data":19537,"content":19538,"nodeType":929},{"uri":8231},[19539],{"data":19540,"marks":19541,"value":19543,"nodeType":882},{},[19542],{"type":927},"in the browser",{"data":19545,"marks":19546,"value":19547,"nodeType":882},{},[],". They leave traces in authentication flows, login behaviors, OAuth integrations, extension activity, and SaaS access patterns — all of which are captured in real time by the Push extension. Unlike network or endpoint attacks, where the signal is often binary and retroactive, browser-based identity threats generate continuous, high-frequency telemetry that maps directly onto the inputs that drive quantitative risk models.",{"data":19549,"content":19550,"nodeType":883},{},[19551,19555,19560,19564,19569],{"data":19552,"marks":19553,"value":19554,"nodeType":882},{},[],"This telemetry directly informs the hardest inputs in any quantitative risk model. One is ",{"data":19556,"marks":19557,"value":19559,"nodeType":882},{},[19558],{"type":1012},"Threat Event Frequency (TEF)",{"data":19561,"marks":19562,"value":19563,"nodeType":882},{},[],": how often a threat agent acts against an asset in a given period. For identity risks, this can be answered in how many credential phishing attempts reached your users across all delivery channels (social media, email, malvertising, etc.), or how frequently your users authorize malicious or compromised SaaS apps. Browser-level telemetry can answer these questions with ",{"data":19565,"marks":19566,"value":19568,"nodeType":882},{},[19567],{"type":1045},"observed",{"data":19570,"marks":19571,"value":19572,"nodeType":882},{},[]," data rather than industry lookups and general benchmarks. ",{"data":19574,"content":19578,"nodeType":963},{"target":19575},{"sys":19576},{"id":19577,"type":960,"linkType":961},"EvjT68MCWW7nz5q86xe8S",[],{"data":19580,"content":19581,"nodeType":883},{},[19582,19586,19591],{"data":19583,"marks":19584,"value":19585,"nodeType":882},{},[],"The other input to risk modeling that's difficult to express in concrete terms is ",{"data":19587,"marks":19588,"value":19590,"nodeType":882},{},[19589],{"type":1012},"vulnerability",{"data":19592,"marks":19593,"value":19594,"nodeType":882},{},[],": the probability a threat becomes a loss event or, more specifically, how likely it is that your controls will fail. ",{"data":19596,"content":19597,"nodeType":883},{},[19598,19602,19609,19613,19620],{"data":19599,"marks":19600,"value":19601,"nodeType":882},{},[],"This is where browser telemetry gets especially concrete. ",{"data":19603,"content":19604,"nodeType":929},{"uri":8638},[19605],{"data":19606,"marks":19607,"value":19608,"nodeType":882},{},[],"Analysis of login telemetry across Push-monitored environments",{"data":19610,"marks":19611,"value":19612,"nodeType":882},{},[]," shows that 1 in 4 logins are still password-only (not SSO), 2 in 5 are not protected by MFA, and 1 in 5 use a weak, breached, or reused password. Many of these logins occur outside the visibility of a central IdP platform like Microsoft, Google or Okta — the result of downstream ",{"data":19614,"content":19615,"nodeType":929},{"uri":8979},[19616],{"data":19617,"marks":19618,"value":19619,"nodeType":882},{},[],"ghost logins",{"data":19621,"marks":19622,"value":3517,"nodeType":882},{},[],{"data":19624,"content":19628,"nodeType":963},{"target":19625},{"sys":19626},{"id":19627,"type":960,"linkType":961},"5GctExdVGjHRwKifiP00Fp",[],{"data":19630,"content":19634,"nodeType":963},{"target":19631},{"sys":19632},{"id":19633,"type":960,"linkType":961},"2mWToHCJcuB9FMwxxzd67F",[],{"data":19636,"content":19637,"nodeType":883},{},[19638,19642,19647],{"data":19639,"marks":19640,"value":19641,"nodeType":882},{},[],"In a FAIR-based model, TEF and vulnerability together determine ",{"data":19643,"marks":19644,"value":19646,"nodeType":882},{},[19645],{"type":1012},"loss event frequency",{"data":19648,"marks":19649,"value":19650,"nodeType":882},{},[],": the foundational driver of the entire risk calculation. Using telemetry from your own environment as the basis for these calculations makes them far more accurate, and more likely to stand up to scrutiny.",{"data":19652,"content":19653,"nodeType":967},{},[],{"data":19655,"content":19656,"nodeType":975},{},[19657],{"data":19658,"marks":19659,"value":19661,"nodeType":882},{},[19660],{"type":1012},"The attack surface is bigger than most models assume",{"data":19663,"content":19664,"nodeType":883},{},[19665],{"data":19666,"marks":19667,"value":19668,"nodeType":882},{},[],"One of the consistent failures in identity risk modeling is the tendency to model risks defenders can see, and leave the rest off the balance sheet. These omissions create a systematic understatement of exposure that browser-based telemetry can offset.",{"data":19670,"content":19671,"nodeType":2050},{},[19672],{"data":19673,"marks":19674,"value":19676,"nodeType":882},{},[19675],{"type":1012},"Shadow AI and OAuth sprawl",{"data":19678,"content":19679,"nodeType":883},{},[19680,19683,19691],{"data":19681,"marks":19682,"value":21,"nodeType":882},{},[],{"data":19684,"content":19685,"nodeType":929},{"uri":6466},[19686],{"data":19687,"marks":19688,"value":19690,"nodeType":882},{},[19689],{"type":927},"The Vercel breach in April 2026",{"data":19692,"marks":19693,"value":19694,"nodeType":882},{},[]," was the result of an OAuth connection to a third-party AI SaaS tool a developer connected into the organization's Google Workspace tenant (without admin approval). When the AI vendor was compromised, the attacker leveraged stored OAuth tokens to access downstream accounts, ultimately reaching internal dashboards, API keys, and source code. ",{"data":19696,"content":19697,"nodeType":883},{},[19698,19702,19707],{"data":19699,"marks":19700,"value":19701,"nodeType":882},{},[],"Push telemetry across customer environments shows an average of ",{"data":19703,"marks":19704,"value":19706,"nodeType":882},{},[19705],{"type":1012},"17 unique AI app integrations per organization in Microsoft and Google alone",{"data":19708,"marks":19709,"value":19710,"nodeType":882},{},[],", most of which security teams would describe as unapproved. These generally don't appear in a conventional risk model that isn't looking for them.",{"data":19712,"content":19713,"nodeType":2050},{},[19714],{"data":19715,"marks":19716,"value":289,"nodeType":882},{},[19717],{"type":1012},{"data":19719,"content":19720,"nodeType":883},{},[19721,19725,19734,19739],{"data":19722,"marks":19723,"value":21,"nodeType":882},{},[19724],{"type":1012},{"data":19726,"content":19727,"nodeType":929},{"uri":6345},[19728],{"data":19729,"marks":19730,"value":19733,"nodeType":882},{},[19731,19732],{"type":927},{"type":1012},"Analysis of 20,000 unique extensions deployed across Push customer environments",{"data":19735,"marks":19736,"value":19738,"nodeType":882},{},[19737],{"type":1012}," found that 46.76% have the permission combinations required for account takeover without user interaction. ",{"data":19740,"marks":19741,"value":19742,"nodeType":882},{},[],"The extensions carrying these permissions aren't flagged by risk scoring systems because the same permissions are used by ad blockers, password managers, and translation tools (the downside of relying on tools that rely on dubious scoring to assess extensions, but I digress). ",{"data":19744,"content":19745,"nodeType":883},{},[19746],{"data":19747,"marks":19748,"value":19749,"nodeType":882},{},[],"What matters for risk quantification isn't the permission set or an arbitrary score assigned by a vendor; it's whether the monitoring exists to detect when a previously-clean extension changes ownership, escalates permissions, or behaves anomalously. Without that monitoring, the exposure is real but unquantified.",{"data":19751,"content":19752,"nodeType":2050},{},[19753],{"data":19754,"marks":19755,"value":19757,"nodeType":882},{},[19756],{"type":1012},"ClickFix and non-email delivery channels",{"data":19759,"content":19760,"nodeType":883},{},[19761,19765,19772,19776,19783],{"data":19762,"marks":19763,"value":19764,"nodeType":882},{},[],"ClickFix — where a malicious page silently writes a PowerShell or mshta command into the victim's clipboard and instructs them to paste it — was ",{"data":19766,"content":19767,"nodeType":929},{"uri":3554},[19768],{"data":19769,"marks":19770,"value":19771,"nodeType":882},{},[],"the most common initial access vector observed by Microsoft in 2025",{"data":19773,"marks":19774,"value":19775,"nodeType":882},{},[],", and CrowdStrike reported a",{"data":19777,"content":19778,"nodeType":929},{"uri":6520},[19779],{"data":19780,"marks":19781,"value":19782,"nodeType":882},{},[]," 563% increase in fake CAPTCHA lures",{"data":19784,"marks":19785,"value":19786,"nodeType":882},{},[]," (one of the most common ClickFix styles in which the user has to \"verify they're human\" by running a command on their machine). ",{"data":19788,"content":19789,"nodeType":883},{},[19790],{"data":19791,"marks":19792,"value":19793,"nodeType":882},{},[],"What makes this particularly relevant for risk quantification is the delivery channel: 4 in 5 ClickFix payloads intercepted by Push arrive via search engines, not email. A risk model that estimates threat event frequency from email-based phishing telemetry alone is structurally blind to an entire category of attack that has become one of the most prevalent initial access methods in the landscape.",{"data":19795,"content":19796,"nodeType":2050},{},[19797],{"data":19798,"marks":19799,"value":19801,"nodeType":882},{},[19800],{"type":1012},"Authorization attacks",{"data":19803,"content":19804,"nodeType":883},{},[19805],{"data":19806,"marks":19807,"value":19808,"nodeType":882},{},[],"Device code phishing and OAuth consent abuse represent a slightly separate category of identity attack that most risk models don't account for because they operate after the authentication flow has already completed — meaning password strength, MFA coverage, and SSO adoption are irrelevant to whether the attack succeeds. ",{"data":19810,"content":19814,"nodeType":963},{"target":19811},{"sys":19812},{"id":19813,"type":960,"linkType":961},"7qtHmxCzBm5664jD6HsCwN",[],{"data":19816,"content":19817,"nodeType":967},{},[],{"data":19819,"content":19820,"nodeType":975},{},[19821],{"data":19822,"marks":19823,"value":19825,"nodeType":882},{},[19824],{"type":1012},"The key lesson for CISOs",{"data":19827,"content":19828,"nodeType":883},{},[19829],{"data":19830,"marks":19831,"value":19832,"nodeType":882},{},[],"A risk model that measures identity vulnerability purely in terms of authentication hygiene at the IdP layer — how many accounts have MFA, how many use SSO — will correctly quantify one dimension of exposure while completely missing another that is growing faster and is structurally immune to the controls being measured.",{"data":19834,"content":19835,"nodeType":883},{},[19836],{"data":19837,"marks":19838,"value":19840,"nodeType":882},{},[19839],{"type":1012},"For a CISO building a risk model, these aren't edge cases. They represent a real attack surface that doesn't show up in models built on conventional network, endpoint, and cloud telemetry. We aren't just talking about better inputs to risk modeling — we're talking about entirely new risk scenarios that aren't being modeled at all, supported by live data.",{"data":19842,"content":19846,"nodeType":963},{"target":19843},{"sys":19844},{"id":19845,"type":960,"linkType":961},"2ObEcO1gqz8lrOLCZzfpNw",[],{"data":19848,"content":19849,"nodeType":967},{},[],{"data":19851,"content":19852,"nodeType":2050},{},[19853],{"data":19854,"marks":19855,"value":19857,"nodeType":882},{},[19856],{"type":1012},"Browser telemetry makes a CISO's life easier",{"data":19859,"content":19860,"nodeType":883},{},[19861],{"data":19862,"marks":19863,"value":19864,"nodeType":882},{},[],"Browser-based telemetry changes the conversation a CISO can have with a CFO or board. Instead of \"industry benchmarks suggest our expected annual loss from account compromise is somewhere in this range,\" the answer is, \"We can see how often these attacks are attempted against our users, and we can measure what percentage of our accounts have the controls in place to stop them,\" or \"We know how many shadow AI apps our users self-provision and share data with each month.\" ",{"data":19866,"content":19867,"nodeType":883},{},[19868],{"data":19869,"marks":19870,"value":19871,"nodeType":882},{},[],"Identity risk is only a piece of the quantification problem. Loss magnitude, regulatory exposure, and reputational impact are still extremely hard to estimate regardless of how good your frequency inputs are. ",{"data":19873,"content":19874,"nodeType":883},{},[19875],{"data":19876,"marks":19877,"value":19878,"nodeType":882},{},[],"But the identity attack surface is one of the few areas in security where measurement is genuinely achievable right now, and the gap between what most organizations are modeling and what's actually observable is significant. Shadow SaaS integrations, unapproved AI connections, browser extensions with excessive privileges — these are enumerable risks that don't appear in models built on network, endpoint, and cloud access telemetry alone. ",{"data":19880,"content":19881,"nodeType":883},{},[19882,19887],{"data":19883,"marks":19884,"value":19886,"nodeType":882},{},[19885],{"type":1012},"The lesson for CISOs serious about quantitative risk management is this: the frameworks exist, the talent is available, and the bottleneck is almost always data quality. ",{"data":19888,"marks":19889,"value":19890,"nodeType":882},{},[],"Browser telemetry is a good example of the kind of high-fidelity, environment-specific measurement that closes that gap.",{"data":19892,"content":19893,"nodeType":967},{},[],{"data":19895,"content":19896,"nodeType":883},{},[19897],{"data":19898,"marks":19899,"value":7217,"nodeType":882},{},[],{"data":19901,"content":19902,"nodeType":883},{},[19903,19907,19914],{"data":19904,"marks":19905,"value":19906,"nodeType":882},{},[],"Security teams use Push to detect and stop advanced browser-based attacks like AiTM phishing, ClickFix, and session hijacking; gain visibility and control over AI tool usage across their workforce; harden identities by surfacing credential reuse, SSO gaps, and shadow IT; and support data loss and insider investigations with browser-layer telemetry that other tools can't see. ",{"data":19908,"content":19910,"nodeType":929},{"uri":19909},"https:\u002F\u002Fpushsecurity.com\u002Fbook-demo\u002F",[19911],{"data":19912,"marks":19913,"value":3893,"nodeType":882},{},[],{"data":19915,"marks":19916,"value":3897,"nodeType":882},{},[],"The CISO's data problem (and how browser telemetry can help)","How CISOs can use browser telemetry to support cyber risk quantification in areas where traditional data points fall short. ","2026-05-11T00:00:00.000Z","the-cisos-data-problem-and-how-browser-telemetry-can-help",{"items":19922},[19923,19925],{"sys":19924,"name":7239},{"id":7238},{"sys":19926,"name":343},{"id":2304},{"items":19928},[19929],{"fullName":10659,"firstName":10660,"jobTitle":10661,"profilePicture":19930},{"url":10663},{"__typename":1365,"sys":19932,"content":19934,"title":20897,"synopsis":20898,"hashTags":59,"publishedDate":16874,"slug":20899,"tagsCollection":20900,"authorsCollection":20906},{"id":19933},"3jF1fypt08TNlSoWuoMWhj",{"json":19935},{"data":19936,"content":19937,"nodeType":1294},{},[19938,19964,19995,20038,20081,20087,20099,20102,20110,20161,20168,20191,20197,20200,20208,20236,20243,20251,20257,20260,20268,20275,20293,20300,20342,20349,20352,20360,20379,20434,20437,20445,20463,20481,20489,20496,20508,20520,20532,20544,20560,20568,20575,20578,20584,20590,20605,20608,20616,20634,20891],{"data":19939,"content":19940,"nodeType":883},{},[19941,19945,19951,19955,19960],{"data":19942,"marks":19943,"value":19944,"nodeType":882},{},[],"ShinyHunters and the broader SLH (",{"data":19946,"content":19947,"nodeType":929},{"uri":8219},[19948],{"data":19949,"marks":19950,"value":16533,"nodeType":882},{},[],{"data":19952,"marks":19953,"value":19954,"nodeType":882},{},[],") collective have claimed breaches at thousands of organizations over the past twelve months across retail, technology, aviation, financial services, media, gaming, and education, in what amounts to the most sustained data theft and extortion operation in recent cybercrime history. SLH's genealogy traces through a merger of Scattered Spider, Lapsus$, and ShinyHunters, all parts of ",{"data":19956,"marks":19957,"value":19959,"nodeType":882},{},[19958],{"type":1012},"the Com",{"data":19961,"marks":19962,"value":19963,"nodeType":882},{},[],", a broader community of English-speaking cybercriminals with international links. ",{"data":19965,"content":19966,"nodeType":883},{},[19967,19971,19979,19983,19991],{"data":19968,"marks":19969,"value":19970,"nodeType":882},{},[],"The confirmed victim list reads like a Fortune 500 directory: Coca-Cola, Cisco, Qantas, Coinbase, ADT, Aflac, SoundCloud, Rockstar Games, Charter Communications, and recently ",{"data":19972,"content":19974,"nodeType":929},{"uri":19973},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Finstructure-confirms-data-breach-shinyhunters-claims-attack\u002F",[19975],{"data":19976,"marks":19977,"value":19978,"nodeType":882},{},[],"Instructure",{"data":19980,"marks":19981,"value":19982,"nodeType":882},{},[]," — whose breach ",{"data":19984,"content":19986,"nodeType":929},{"uri":19985},"https:\u002F\u002Fkrebsonsecurity.com\u002F2026\u002F05\u002Fcanvas-breach-disrupts-schools-colleges-nationwide\u002F",[19987],{"data":19988,"marks":19989,"value":19990,"nodeType":882},{},[],"disrupted schools and universities nationwide",{"data":19992,"marks":19993,"value":19994,"nodeType":882},{},[]," during final exams — among dozens more named publicly and likely many more that haven't been (breaches settled quickly behind closed doors don't always make it into the public eye). ShinyHunters alone claimed over 1.5 billion stolen Salesforce records from a single campaign targeting more than 1,000 organizations.",{"data":19996,"content":19997,"nodeType":883},{},[19998,20002,20010,20014,20022,20026,20034],{"data":19999,"marks":20000,"value":20001,"nodeType":882},{},[],"Additional operating clusters, including Cordial Spider and Snarky Spider (which CrowdStrike ",{"data":20003,"content":20005,"nodeType":929},{"uri":20004},"https:\u002F\u002Fcyberscoop.com\u002Fcrowdstrike-cordial-spider-snarky-spider-extortion-attacks\u002F",[20006],{"data":20007,"marks":20008,"value":20009,"nodeType":882},{},[],"characterizes as the new generation of Scattered Spider",{"data":20011,"marks":20012,"value":20013,"nodeType":882},{},[],") run parallel campaigns against different target sectors, unified not by shared infrastructure but by a shared playbook of techniques that exploit the structural weakness in modern SaaS-first organizations. ",{"data":20015,"content":20017,"nodeType":929},{"uri":20016},"https:\u002F\u002Fgithub.com\u002FPaloAltoNetworks\u002FUnit42-timely-threat-intel\u002Fblob\u002Fmain\u002F2026-03-12-Vishing-Campaigns-Lead-to-Data-Theft-and-Extortion.txt",[20018],{"data":20019,"marks":20020,"value":20021,"nodeType":882},{},[],"Unit 42 documented",{"data":20023,"marks":20024,"value":20025,"nodeType":882},{},[]," these groups moving from initial compromise to complete data exfiltration in under an hour — faster than most organizations can even begin to respond. Newer groups with links to the SLH ecosystem like CoinbaseCartel have also continued the tradition of weaponizing stolen credentials from the infostealer economy at scale, as ShinyHunters did in the ",{"data":20027,"content":20029,"nodeType":929},{"uri":20028},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fshinyhunters-claims-15-billion-salesforce-records-stolen-in-drift-hacks\u002F",[20030],{"data":20031,"marks":20032,"value":20033,"nodeType":882},{},[],"2024 Snowflake breach",{"data":20035,"marks":20036,"value":20037,"nodeType":882},{},[]," that compromised over 165 customer environments (and claimed another billion-plus records).",{"data":20039,"content":20040,"nodeType":883},{},[20041,20045,20053,20057,20065,20069,20077],{"data":20042,"marks":20043,"value":20044,"nodeType":882},{},[],"Not every SLH breach is browser-based — the Instructure breach (275 million individuals, ~330 school login portals defaced) began with a Salesforce tenant compromise in September 2025, but resurfaced in May 2026 after attackers exploited a ",{"data":20046,"content":20048,"nodeType":929},{"uri":20047},"https:\u002F\u002Fwww.bitdefender.com\u002Fen-gb\u002Fblog\u002Fbusinessinsights\u002Ftechnical-advisory-shinyhunters-breach-instructure-canvas-lms",[20049],{"data":20050,"marks":20051,"value":20052,"nodeType":882},{},[],"vulnerability affecting Canvas's Free-For-Teacher program",{"data":20054,"marks":20055,"value":20056,"nodeType":882},{},[]," (it's now been confirmed that Instructure \"",{"data":20058,"content":20060,"nodeType":929},{"uri":20059},"https:\u002F\u002Fwww.instructure.com\u002Fincident_update",[20061],{"data":20062,"marks":20063,"value":20064,"nodeType":882},{},[],"reached a settlement",{"data":20066,"marks":20067,"value":20068,"nodeType":882},{},[],"\" for the deletion of the data, and shut down the free account tier), while the Coinbase breach cost ",{"data":20070,"content":20072,"nodeType":929},{"uri":20071},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fcoinbase-discloses-breach-faces-up-to-400-million-in-losses\u002F",[20073],{"data":20074,"marks":20075,"value":20076,"nodeType":882},{},[],"$180M–400M through insider bribery",{"data":20078,"marks":20079,"value":20080,"nodeType":882},{},[]," — but these are the exceptions that prove the rule. ",{"data":20082,"content":20086,"nodeType":963},{"target":20083},{"sys":20084},{"id":20085,"type":960,"linkType":961},"4qNrbDyMJIumQfdbh9YVkU",[],{"data":20088,"content":20089,"nodeType":883},{},[20090,20095],{"data":20091,"marks":20092,"value":20094,"nodeType":882},{},[20093],{"type":1012},"The vast majority of SLH campaigns over the past year converge on three browser-based attack vectors: vishing combined with AiTM phishing, device code phishing exploiting account authorization flows, and OAuth supply chain attacks through compromised third-party integrators.",{"data":20096,"marks":20097,"value":20098,"nodeType":882},{},[]," Each is well-documented, each has produced confirmed victims at scale, and each is detectable or preventable through browser-layer security controls.",{"data":20100,"content":20101,"nodeType":967},{},[],{"data":20103,"content":20104,"nodeType":975},{},[20105],{"data":20106,"marks":20107,"value":20109,"nodeType":882},{},[20108],{"type":1012},"Vector 1: Vishing combined with AiTM phishing",{"data":20111,"content":20112,"nodeType":883},{},[20113,20117,20125,20128,20136,20140,20147,20151,20158],{"data":20114,"marks":20115,"value":20116,"nodeType":882},{},[],"The most visible campaign right now pairs targeted voice calls with adversary-in-the-middle phishing pages — an approach that ",{"data":20118,"content":20120,"nodeType":929},{"uri":20119},"https:\u002F\u002Fcloud.google.com\u002Fblog\u002Ftopics\u002Fthreat-intelligence\u002Fexpansion-shinyhunters-saas-data-theft",[20121],{"data":20122,"marks":20123,"value":20124,"nodeType":882},{},[],"Mandiant",{"data":20126,"marks":20127,"value":8976,"nodeType":882},{},[],{"data":20129,"content":20131,"nodeType":929},{"uri":20130},"https:\u002F\u002Fwww.crowdstrike.com\u002Fen-us\u002Fblog\u002Fdefending-against-cordial-spider-and-snarky-spider-with-falcon-shield\u002F",[20132],{"data":20133,"marks":20134,"value":20135,"nodeType":882},{},[]," CrowdStrike",{"data":20137,"marks":20138,"value":20139,"nodeType":882},{},[],", and",{"data":20141,"content":20142,"nodeType":929},{"uri":20016},[20143],{"data":20144,"marks":20145,"value":20146,"nodeType":882},{},[]," Unit 42",{"data":20148,"marks":20149,"value":20150,"nodeType":882},{},[]," have all documented from the incident response side, and which Push has ",{"data":20152,"content":20153,"nodeType":929},{"uri":18708},[20154],{"data":20155,"marks":20156,"value":20157,"nodeType":882},{},[],"documented from inside the attacker's own operator panels",{"data":20159,"marks":20160,"value":1438,"nodeType":882},{},[],{"data":20162,"content":20163,"nodeType":883},{},[20164],{"data":20165,"marks":20166,"value":20167,"nodeType":882},{},[],"An attacker impersonating IT support calls the target employee, establishes urgency — often citing a \"mandatory passkey rollout\" or a \"security compliance update\" — and directs them to a victim-branded AiTM phishing page (typically at a domain like \u003Ccompany>sso.com or \u003Ccompany>internal.com). The attack is processed by a live human in real time, relaying credentials and MFA codes to the legitimate identity provider as they are entered, capturing the resulting session token, and granting the attacker an authenticated session. ",{"data":20169,"content":20170,"nodeType":883},{},[20171,20175,20182,20186],{"data":20172,"marks":20173,"value":20174,"nodeType":882},{},[],"One of the reasons that this method is becoming so widespread is the commoditization of effective tools. Push's ",{"data":20176,"content":20177,"nodeType":929},{"uri":18708},[20178],{"data":20179,"marks":20180,"value":20181,"nodeType":882},{},[],"infiltration of the criminal phishing panels",{"data":20183,"marks":20184,"value":20185,"nodeType":882},{},[]," identified over 400 linked domains across four distinct infrastructure clusters. ",{"data":20187,"marks":20188,"value":20190,"nodeType":882},{},[20189],{"type":1012},"This mirrors the pattern that turned AiTM phishing from a specialist capability into an industrialized market with competing PhaaS platforms, but with the added complication that voice phishing as the delivery vector makes the attack invisible to traditional anti-phishing controls at the email layer.",{"data":20192,"content":20196,"nodeType":963},{"target":20193},{"sys":20194},{"id":20195,"type":960,"linkType":961},"1Yhthl0PILGW7EmCcZUrNv",[],{"data":20198,"content":20199,"nodeType":967},{},[],{"data":20201,"content":20202,"nodeType":975},{},[20203],{"data":20204,"marks":20205,"value":20207,"nodeType":882},{},[20206],{"type":1012},"Vector 2: Vishing combined with device code phishing",{"data":20209,"content":20210,"nodeType":883},{},[20211,20214,20221,20225,20232],{"data":20212,"marks":20213,"value":6443,"nodeType":882},{},[],{"data":20215,"content":20216,"nodeType":929},{"uri":16550},[20217],{"data":20218,"marks":20219,"value":20220,"nodeType":882},{},[],"ShinyHunters Salesforce campaign",{"data":20222,"marks":20223,"value":20224,"nodeType":882},{},[]," that ran through 2025 and into 2026 used device code phishing as one of its core methods, ",{"data":20226,"content":20227,"nodeType":929},{"uri":20028},[20228],{"data":20229,"marks":20230,"value":20231,"nodeType":882},{},[],"compromising over 1,000 organizations and claiming 1.5 billion stolen records",{"data":20233,"marks":20234,"value":20235,"nodeType":882},{},[]," — including an attempted extortion of Salesforce itself. The attack involved registering an attacker-controlled \"DataLoader\" application mimicking a legitimate Salesforce tool, configuring it to request broad OAuth scopes including full API access and refresh token generation, and guiding victims through the device authorization flow via vishing calls.",{"data":20237,"content":20238,"nodeType":883},{},[20239],{"data":20240,"marks":20241,"value":20242,"nodeType":882},{},[],"Device code phishing exploits the OAuth 2.0 device authorization grant — a flow designed for devices without browsers, like smart TVs, but used in a wide range of scenarios including CLI logins — by tricking users into entering a code on Microsoft's (or another identity provider's) legitimate verification page. Since the victim is usually signed into the app in their browser, there’s no login at all. They simply navigate to the app’s device code login page and enter an attacker-provided code to grant the attacker an access token. ",{"data":20244,"content":20245,"nodeType":883},{},[20246],{"data":20247,"marks":20248,"value":20250,"nodeType":882},{},[20249],{"type":1012},"This is what makes device code phishing structurally different from AiTM: it defeats all MFA (including passkeys) because the attack doesn’t target the login, but the authorization layer instead.",{"data":20252,"content":20256,"nodeType":963},{"target":20253},{"sys":20254},{"id":20255,"type":960,"linkType":961},"3ElQz8sLATnR8RY5nVlBGM",[],{"data":20258,"content":20259,"nodeType":967},{},[],{"data":20261,"content":20262,"nodeType":975},{},[20263],{"data":20264,"marks":20265,"value":20267,"nodeType":882},{},[20266],{"type":1012},"Vector 3: OAuth supply chain attacks through compromised integrators",{"data":20269,"content":20270,"nodeType":883},{},[20271],{"data":20272,"marks":20273,"value":20274,"nodeType":882},{},[],"The third vector does not require the attacker to phish the victim organization's employees at all. Instead, it exploits the OAuth trust relationships that organizations create when they connect third-party SaaS vendors into their environments — and the consequence is that every organization that authorized one of these integrations effectively extended its security boundary to include the vendor's own security posture.",{"data":20276,"content":20277,"nodeType":883},{},[20278,20281,20289],{"data":20279,"marks":20280,"value":6443,"nodeType":882},{},[],{"data":20282,"content":20284,"nodeType":929},{"uri":20283},"https:\u002F\u002Fcloud.google.com\u002Fblog\u002Ftopics\u002Fthreat-intelligence\u002Fdata-theft-salesforce-instances-via-salesloft-drift",[20285],{"data":20286,"marks":20287,"value":20288,"nodeType":882},{},[],"Salesloft\u002FDrift supply chain attack",{"data":20290,"marks":20291,"value":20292,"nodeType":882},{},[]," demonstrated this at scale in 2025: in an extension of the previously mentioned device code phishing campaign, the attacker compromised Salesloft's GitHub environment, used TruffleHog to find secrets, stole Drift OAuth tokens, and used them to access downstream Salesforce environments. The same pattern was later repeated at Gainsight. ",{"data":20294,"content":20295,"nodeType":883},{},[20296],{"data":20297,"marks":20298,"value":20299,"nodeType":882},{},[],"Along with the previously mentioned device code phishing attacks,  more than 1000 organizations were breached. The attackers then harvested AWS keys, Snowflake credentials, and stored passwords from breached Salesforce instances, compounding the access into progressively wider reach.",{"data":20301,"content":20302,"nodeType":883},{},[20303,20307,20315,20319,20327,20331,20338],{"data":20304,"marks":20305,"value":20306,"nodeType":882},{},[],"The same structural pattern has continued into 2026 with the Anodot supply chain compromise, which has produced confirmed breaches at ",{"data":20308,"content":20310,"nodeType":929},{"uri":20309},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fvimeo-data-breach-exposes-personal-information-of-119-000-people\u002F",[20311],{"data":20312,"marks":20313,"value":20314,"nodeType":882},{},[],"Vimeo",{"data":20316,"marks":20317,"value":20318,"nodeType":882},{},[]," (119,000 users), Rockstar Games (78.6 million records), and ",{"data":20320,"content":20322,"nodeType":929},{"uri":20321},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fzara-data-breach-exposed-personal-information-of-197-000-people\u002F",[20323],{"data":20324,"marks":20325,"value":20326,"nodeType":882},{},[],"Zara\u002FInditex",{"data":20328,"marks":20329,"value":20330,"nodeType":882},{},[]," (197,000 people), with further downstream victims likely still emerging. The ",{"data":20332,"content":20333,"nodeType":929},{"uri":6466},[20334],{"data":20335,"marks":20336,"value":20337,"nodeType":882},{},[],"Vercel breach",{"data":20339,"marks":20340,"value":20341,"nodeType":882},{},[],", which involved compromised OAuth tokens from Context.ai cascading into Google Workspace, also reinforces the same attack pattern (though it was likely not a ShinyHunters operation despite being claimed by someone pretending to be them).",{"data":20343,"content":20344,"nodeType":883},{},[20345],{"data":20346,"marks":20347,"value":20348,"nodeType":882},{},[],"A forgotten SaaS integration can easily become the pivot point for downstream compromise. The moment you authorize a third-party integration, your security boundary extends to include that vendor. If the third-party is compromised, every downstream customer organization with an active integration is exposed.",{"data":20350,"content":20351,"nodeType":967},{},[],{"data":20353,"content":20354,"nodeType":975},{},[20355],{"data":20356,"marks":20357,"value":20359,"nodeType":882},{},[20358],{"type":1012},"The infostealer credential playbook sits alongside these attacks",{"data":20361,"content":20362,"nodeType":883},{},[20363,20367,20375],{"data":20364,"marks":20365,"value":20366,"nodeType":882},{},[],"Alongside the three vectors above, ShinyHunters has a track record of exploiting the infostealer credential economy at scale — and it predates any of them. The 2024 Snowflake campaign — 165+ customer environments compromised, over a billion records stolen from AT&T, Ticketmaster, Santander, and Advance Auto Parts among others — was built entirely on infostealer-harvested credentials replayed against MFA-less tenants, with ",{"data":20368,"content":20370,"nodeType":929},{"uri":20369},"https:\u002F\u002Fcloud.google.com\u002Fblog\u002Ftopics\u002Fthreat-intelligence\u002Func5537-snowflake-data-theft-extortion",[20371],{"data":20372,"marks":20373,"value":20374,"nodeType":882},{},[],"Mandiant's investigation",{"data":20376,"marks":20377,"value":20378,"nodeType":882},{},[]," finding that 80% of compromised accounts had prior breach exposure in datasets dating back to 2020. The credentials were already circulating in criminal marketplaces; ShinyHunters simply purchased and operationalized them at industrial scale.",{"data":20380,"content":20381,"nodeType":883},{},[20382,20386,20394,20398,20406,20410,20418,20422,20430],{"data":20383,"marks":20384,"value":20385,"nodeType":882},{},[],"The same methodology powered the ",{"data":20387,"content":20389,"nodeType":929},{"uri":20388},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fwhy-attackers-are-targeting-jira-with-stolen-credentials\u002F",[20390],{"data":20391,"marks":20392,"value":20393,"nodeType":882},{},[],"HellCat Jira campaign",{"data":20395,"marks":20396,"value":20397,"nodeType":882},{},[]," through 2024–2025, and has now been industrialized as a standalone operation by ",{"data":20399,"content":20401,"nodeType":929},{"uri":20400},"https:\u002F\u002Fwww.halcyon.ai\u002Fjp\u002Fthreat-group\u002Fcoinbasecartel",[20402],{"data":20403,"marks":20404,"value":20405,"nodeType":882},{},[],"CoinbaseCartel",{"data":20407,"marks":20408,"value":20409,"nodeType":882},{},[],", another criminal group reported to be an offshoot of SLH. CoinbaseCartel's model is familiar: purchase old infostealer credentials, use them to access cloud and development environments, exfiltrate data, and demand ransom. ",{"data":20411,"content":20413,"nodeType":929},{"uri":20412},"https:\u002F\u002Fwww.infostealers.com\u002Farticle\u002Finside-the-coinbase-cartel-how-infostealer-credentials-fueled-a-100-company-ransomware-spree\u002F",[20414],{"data":20415,"marks":20416,"value":20417,"nodeType":882},{},[],"Hudson Rock's analysis",{"data":20419,"marks":20420,"value":20421,"nodeType":882},{},[]," of the group's 170+ claimed victims confirms that roughly 80% had prior infostealer infections predating the attacks. The most recent named victim is ",{"data":20423,"content":20425,"nodeType":929},{"uri":20424},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fgrafana-says-stolen-github-token-let-hackers-steal-codebase\u002F",[20426],{"data":20427,"marks":20428,"value":20429,"nodeType":882},{},[],"Grafana",{"data":20431,"marks":20432,"value":20433,"nodeType":882},{},[],", where a GitHub token compromised via the TanStack npm supply chain attack and missed during credential rotation was used to download the codebase and attempt extortion. ",{"data":20435,"content":20436,"nodeType":967},{},[],{"data":20438,"content":20439,"nodeType":975},{},[20440],{"data":20441,"marks":20442,"value":20444,"nodeType":882},{},[20443],{"type":1012},"These attacks all happen in the browser",{"data":20446,"content":20447,"nodeType":883},{},[20448,20452,20459],{"data":20449,"marks":20450,"value":20451,"nodeType":882},{},[],"Every one of these attack chains is a browser-based attack that either occurs in the browser (AiTM phishing, device code phishing) or could have been prevented at the browser layer (OAuth consent governance). The techniques are interchangeable — the",{"data":20453,"content":20454,"nodeType":929},{"uri":3389},[20455],{"data":20456,"marks":20457,"value":20458,"nodeType":882},{},[]," same criminal kits now offer AiTM and device code phishing side by side",{"data":20460,"marks":20461,"value":20462,"nodeType":882},{},[],", and the same threat actor (ShinyHunters) has used all three vectors across different campaigns within the same twelve-month period.",{"data":20464,"content":20465,"nodeType":883},{},[20466,20470,20477],{"data":20467,"marks":20468,"value":20469,"nodeType":882},{},[],"Additionally, infostealer infections themselves are increasingly delivered through browser-based methods like ",{"data":20471,"content":20473,"nodeType":929},{"uri":20472},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fintroducing-malicious-copy-paste-detection",[20474],{"data":20475,"marks":20476,"value":316,"nodeType":882},{},[],{"data":20478,"marks":20479,"value":20480,"nodeType":882},{},[],", closing the loop between the credential supply side and the browser-layer detection point.",{"data":20482,"content":20483,"nodeType":2050},{},[20484],{"data":20485,"marks":20486,"value":20488,"nodeType":882},{},[20487],{"type":1012},"How Push can help",{"data":20490,"content":20491,"nodeType":883},{},[20492],{"data":20493,"marks":20494,"value":20495,"nodeType":882},{},[],"Push operates at the exact point in each of these attack chains where automated intervention can still prevent the compromise. ",{"data":20497,"content":20498,"nodeType":883},{},[20499,20504],{"data":20500,"marks":20501,"value":20503,"nodeType":882},{},[20502],{"type":1012},"For vishing + AiTM attacks, ",{"data":20505,"marks":20506,"value":20507,"nodeType":882},{},[],"Push's behavioral phishing detection analyzes and blocks the phishing page in real time by detecting it from the user's browser — regardless of the domains used, hosting infrastructure, or where the URL was delivered.  ",{"data":20509,"content":20510,"nodeType":883},{},[20511,20516],{"data":20512,"marks":20513,"value":20515,"nodeType":882},{},[20514],{"type":1012},"For device code phishing,",{"data":20517,"marks":20518,"value":20519,"nodeType":882},{},[]," Push detects the phishing pages associated with device code phishing kits — including generic, technique-class detections that catch new kits without requiring kit-specific signatures. Second, Push provides an additional layer of protection on the legitimate device code authentication pages themselves, preventing users from entering attacker-supplied codes into them. Together, these detections cover both the kit-operated phishing infrastructure and the legitimate auth pages that the attack flow depends on.",{"data":20521,"content":20522,"nodeType":883},{},[20523,20528],{"data":20524,"marks":20525,"value":20527,"nodeType":882},{},[20526],{"type":1012},"For OAuth supply chain attacks,",{"data":20529,"marks":20530,"value":20531,"nodeType":882},{},[]," Push's detects and controls OAuth consent flows at the browser layer — capturing which application is requesting access, what scopes it's requesting, and whether the grant should be permitted under organizational policy. Push customers can also block OAuth connection requests as they transit the browser, enabling security teams to stop unwanted integrations being added in the first place. ",{"data":20533,"content":20534,"nodeType":883},{},[20535,20540],{"data":20536,"marks":20537,"value":20539,"nodeType":882},{},[20538],{"type":1012},"For the infostealer credential playbook,",{"data":20541,"marks":20542,"value":20543,"nodeType":882},{},[]," Push's stolen credential detection identifies when employees are using credentials that have appeared in breach datasets or dark web feeds — catching the moment a dormant infostealer credential surfaces at a browser-based login, as well as surfacing insecure login methods missing mitigating controls like MFA and enforcing them through in-browser guardrails. And on the supply side, Push's ClickFix detection addresses the browser-based delivery vector that is now the primary method for distributing infostealer malware in the first place.",{"data":20545,"content":20546,"nodeType":883},{},[20547,20550,20557],{"data":20548,"marks":20549,"value":21,"nodeType":882},{},[],{"data":20551,"content":20552,"nodeType":929},{"uri":12416},[20553],{"data":20554,"marks":20555,"value":20556,"nodeType":882},{},[],"Learn more about how you can use Push controls to protect your users from in-browser threats here. ",{"data":20558,"marks":20559,"value":21,"nodeType":882},{},[],{"data":20561,"content":20562,"nodeType":2050},{},[20563],{"data":20564,"marks":20565,"value":20567,"nodeType":882},{},[20566],{"type":1012},"Closing thoughts",{"data":20569,"content":20570,"nodeType":883},{},[20571],{"data":20572,"marks":20573,"value":20574,"nodeType":882},{},[],"The campaigns documented in this post are not historical — they are ongoing, with new victims surfacing weekly and the underlying criminal infrastructure still actively developing. But the defensive strategy does not require anticipating which specific group, vector, or target sector comes next, because all of them converge on the same control point: the browser, where the attack begins or the integration decision is made. Organizations with browser-layer detection and OAuth governance in place have defense-in-depth against the full range of techniques these groups employ, regardless of which specific vector any given campaign uses.",{"data":20576,"content":20577,"nodeType":967},{},[],{"data":20579,"content":20580,"nodeType":883},{},[20581],{"data":20582,"marks":20583,"value":7217,"nodeType":882},{},[],{"data":20585,"content":20586,"nodeType":883},{},[20587],{"data":20588,"marks":20589,"value":2926,"nodeType":882},{},[],{"data":20591,"content":20592,"nodeType":883},{},[20593,20596,20602],{"data":20594,"marks":20595,"value":21,"nodeType":882},{},[],{"data":20597,"content":20598,"nodeType":929},{"uri":2935},[20599],{"data":20600,"marks":20601,"value":2941,"nodeType":882},{},[],{"data":20603,"marks":20604,"value":21,"nodeType":882},{},[],{"data":20606,"content":20607,"nodeType":967},{},[],{"data":20609,"content":20610,"nodeType":975},{},[20611],{"data":20612,"marks":20613,"value":20615,"nodeType":882},{},[20614],{"type":1012},"Appendix: named ShinyHunters victims since May 2025",{"data":20617,"content":20618,"nodeType":883},{},[20619,20623,20630],{"data":20620,"marks":20621,"value":20622,"nodeType":882},{},[],"To give an indication of the scale, the following table documents all publicly named victims attributed to ShinyHunters specifically since the Salesforce campaign began in May 2025. It is not exhaustive: ShinyHunters has claimed over 1,000 organizations in aggregate across its Salesforce campaigns alone, and many victims have not been publicly named. This list also doesn’t include the billion-plus records compromised in the 2024 Snowflake breaches. The major ransomware attacks executed against M&S, Co-op, and Jaguar Land Rover claimed by the ",{"data":20624,"content":20625,"nodeType":929},{"uri":8219},[20626],{"data":20627,"marks":20628,"value":20629,"nodeType":882},{},[],"Scattered Lapsus$ Hunters \"brand\"",{"data":20631,"marks":20632,"value":20633,"nodeType":882},{},[]," also aren't listed below. ",{"data":20635,"content":20636,"nodeType":3104},{},[20637,20684,20748,20796,20844],{"data":20638,"content":20639,"nodeType":3011},{},[20640,20651,20662,20673],{"data":20641,"content":20642,"nodeType":3025},{},[20643],{"data":20644,"content":20645,"nodeType":883},{},[20646],{"data":20647,"marks":20648,"value":20650,"nodeType":882},{},[20649],{"type":1012},"Campaign",{"data":20652,"content":20653,"nodeType":3025},{},[20654],{"data":20655,"content":20656,"nodeType":883},{},[20657],{"data":20658,"marks":20659,"value":20661,"nodeType":882},{},[20660],{"type":1012},"Began",{"data":20663,"content":20664,"nodeType":3025},{},[20665],{"data":20666,"content":20667,"nodeType":883},{},[20668],{"data":20669,"marks":20670,"value":20672,"nodeType":882},{},[20671],{"type":1012},"Named victims",{"data":20674,"content":20675,"nodeType":3025},{},[20676],{"data":20677,"content":20678,"nodeType":883},{},[20679],{"data":20680,"marks":20681,"value":20683,"nodeType":882},{},[20682],{"type":1012},"Confirmed impact",{"data":20685,"content":20686,"nodeType":3011},{},[20687,20711,20721,20731],{"data":20688,"content":20689,"nodeType":3025},{},[20690],{"data":20691,"content":20692,"nodeType":883},{},[20693,20698,20702,20707],{"data":20694,"marks":20695,"value":20697,"nodeType":882},{},[20696],{"type":1012},"ShinyHunters Salesforce Vishing",{"data":20699,"marks":20700,"value":20701,"nodeType":882},{},[]," (vishing + device code phishing → Salesforce connected app authorization) \n\n& ",{"data":20703,"marks":20704,"value":20706,"nodeType":882},{},[20705],{"type":1012},"Salesloft\u002FDrift Supply Chain",{"data":20708,"marks":20709,"value":20710,"nodeType":882},{},[]," (stolen OAuth tokens → downstream Salesforce access)",{"data":20712,"content":20713,"nodeType":3025},{},[20714],{"data":20715,"content":20716,"nodeType":883},{},[20717],{"data":20718,"marks":20719,"value":20720,"nodeType":882},{},[],"May 2025",{"data":20722,"content":20723,"nodeType":3025},{},[20724],{"data":20725,"content":20726,"nodeType":883},{},[20727],{"data":20728,"marks":20729,"value":20730,"nodeType":882},{},[],"Coca-Cola Europacific Partners, Cisco, Qantas, LVMH, Adidas, Google, Chanel, Pandora, Allianz Life, Air France-KLM, Farmers Insurance, Workday, TransUnion, Stellantis, Kering, Odido, Hallmark, Salesloft (origin), Toast, Avalara, Fastly, Cato Networks, Cloudflare, Palo Alto Networks, Zscaler, Tenable, Elastic, JFrog, CyberArk, Rubrik, BeyondTrust, Proofpoint, Workiva, Mercer Advisors, Beacon Pointe, Ameriprise, Kemper, Udemy, 7-Eleven, Mytheresa, Marcus & Millichap, Carnival, Pitney Bowes, Alert 360, Amtrak, McGraw-Hill, Canada Life, Charter Communications",{"data":20732,"content":20733,"nodeType":3025},{},[20734,20741],{"data":20735,"content":20736,"nodeType":883},{},[20737],{"data":20738,"marks":20739,"value":20740,"nodeType":882},{},[],"49 named victims. Confirmed individual impact includes 23M+ records (Coca-Cola), 5.7M records (Qantas), 6.2M customers (Odido), 4.4M consumers (TransUnion), up to 18M records (Stellantis), 13.5M emails (McGraw-Hill), 8.2M emails (Pitney Bowes), 7.5M emails (Carnival), 7-Eleven: 185K confirmed by HIBP (SSNs, driver's licenses; franchisee data), Charter Communications: millions of records claimed (company disputes scope). ",{"data":20742,"content":20743,"nodeType":883},{},[20744],{"data":20745,"marks":20746,"value":20747,"nodeType":882},{},[],"ShinyHunters claims 1.5B+ Salesforce records across 1,000+ organizations total.",{"data":20749,"content":20750,"nodeType":3011},{},[20751,20766,20776,20786],{"data":20752,"content":20753,"nodeType":3025},{},[20754],{"data":20755,"content":20756,"nodeType":883},{},[20757,20762],{"data":20758,"marks":20759,"value":20761,"nodeType":882},{},[20760],{"type":1012},"Vishing + AiTM SSO",{"data":20763,"marks":20764,"value":20765,"nodeType":882},{},[]," (vishing → AiTM phishing page → SSO session capture → SaaS data exfiltration)",{"data":20767,"content":20768,"nodeType":3025},{},[20769],{"data":20770,"content":20771,"nodeType":883},{},[20772],{"data":20773,"marks":20774,"value":20775,"nodeType":882},{},[],"Aug 2025",{"data":20777,"content":20778,"nodeType":3025},{},[20779],{"data":20780,"content":20781,"nodeType":883},{},[20782],{"data":20783,"marks":20784,"value":20785,"nodeType":882},{},[],"SoundCloud, GrubHub, Panera Bread, Match Group, Crunchbase, Betterment, CarMax, Edmunds, CarGurus, Hims & Hers, University of Pennsylvania, Harvard University, Optimizely, TELUS Digital, Crunchyroll, ADT",{"data":20787,"content":20788,"nodeType":3025},{},[20789],{"data":20790,"content":20791,"nodeType":883},{},[20792],{"data":20793,"marks":20794,"value":20795,"nodeType":882},{},[],"16 named victims. Confirmed individual impact includes ~30M records (SoundCloud), ~14M records (Panera), 10M+ records (Match Group), ~20M records (Betterment), 5.5M people (ADT), 1M+ records (UPenn), ~1PB stolen from TELUS Digital ($65M ransom refused).",{"data":20797,"content":20798,"nodeType":3011},{},[20799,20814,20824,20834],{"data":20800,"content":20801,"nodeType":3025},{},[20802],{"data":20803,"content":20804,"nodeType":883},{},[20805,20810],{"data":20806,"marks":20807,"value":20809,"nodeType":882},{},[20808],{"type":1012},"Anodot Supply Chain",{"data":20811,"marks":20812,"value":20813,"nodeType":882},{},[]," (stolen OAuth tokens → downstream Snowflake\u002FBigQuery access)",{"data":20815,"content":20816,"nodeType":3025},{},[20817],{"data":20818,"content":20819,"nodeType":883},{},[20820],{"data":20821,"marks":20822,"value":20823,"nodeType":882},{},[],"Apr 2026",{"data":20825,"content":20826,"nodeType":3025},{},[20827],{"data":20828,"content":20829,"nodeType":883},{},[20830],{"data":20831,"marks":20832,"value":20833,"nodeType":882},{},[],"Anodot\u002FGlassbox (origin), Rockstar Games, Vimeo, Zara\u002FInditex",{"data":20835,"content":20836,"nodeType":3025},{},[20837],{"data":20838,"content":20839,"nodeType":883},{},[20840],{"data":20841,"marks":20842,"value":20843,"nodeType":882},{},[],"4 named victims (12+ total claimed). 78.6M records (Rockstar Games), 197K individuals (Zara), 119K individuals (Vimeo).",{"data":20845,"content":20846,"nodeType":3011},{},[20847,20862,20871,20881],{"data":20848,"content":20849,"nodeType":3025},{},[20850],{"data":20851,"content":20852,"nodeType":883},{},[20853,20858],{"data":20854,"marks":20855,"value":20857,"nodeType":882},{},[20856],{"type":1012},"Other SLH-attributed",{"data":20859,"marks":20860,"value":20861,"nodeType":882},{},[]," (misc. vectors including infostealer chains, CI\u002FCD supply chain, SaaS platform compromise)",{"data":20863,"content":20864,"nodeType":3025},{},[20865],{"data":20866,"content":20867,"nodeType":883},{},[20868],{"data":20869,"marks":20870,"value":20720,"nodeType":882},{},[],{"data":20872,"content":20873,"nodeType":3025},{},[20874],{"data":20875,"content":20876,"nodeType":883},{},[20877],{"data":20878,"marks":20879,"value":20880,"nodeType":882},{},[],"UK Legal Aid Agency, Mixpanel, Wynn Resorts, Woflow, Vercel, European Commission, Mercor, Medtronic, Instructure",{"data":20882,"content":20883,"nodeType":3025},{},[20884],{"data":20885,"content":20886,"nodeType":883},{},[20887],{"data":20888,"marks":20889,"value":20890,"nodeType":882},{},[],"10 named victims across varied vectors. Notable: Vercel (Lumma Stealer → Context.ai OAuth app → Google Workspace), European Commission (poisoned Trivy GitHub Action → 340GB across 71 EU entities)",{"data":20892,"content":20893,"nodeType":883},{},[20894],{"data":20895,"marks":20896,"value":21,"nodeType":882},{},[],"The three attack techniques behind ShinyHunters' 2026 campaigns ","ShinyHunters' breach of Instructure is the latest in a long series of attacks. Here's our view of the big picture. ","analyzing-the-instructure-breach",{"items":20901},[20902,20904],{"sys":20903,"name":2308},{"id":2307},{"sys":20905,"name":343},{"id":2304},{"items":20907},[20908],{"fullName":3911,"firstName":3912,"jobTitle":3913,"profilePicture":20909},{"url":3915},"7-things-omdias-latest-report-tells-us-about-the-secure-enterprise-browser-market","blog\u002F7-things-omdias-latest-report-tells-us-about-the-secure-enterprise-browser-market",{"json":20913},{"data":20914,"content":20915,"nodeType":1294},{},[20916],{"data":20917,"content":20918,"nodeType":883},{},[20919],{"data":20920,"marks":20921,"value":20922,"nodeType":882},{},[],"New research from Omdia has put hard numbers behind something security teams have been feeling for the past two years: the browser has become the primary attack surface in the enterprise, organizations are investing accordingly, and the results are already measurable.","Unpacking the latest research report from Omdia and what it means for the secure enterprise browser market.",{"id":20925,"publishedAt":20926},"217s8zu5idSdX25TUgbPQ1","2026-08-12T11:52:51.573Z",{"items":20928},[20929,20931],{"sys":20930,"name":298},{"id":7235},{"sys":20932,"name":7239},{"id":7238},{"items":20934},[20935,20937,20939,20941,20943,20945,20947,20949,20951,20953,20955,20957,20959,20961,20963,20965,20967,20969,20971],{"sys":20936,"name":298,"slug":299,"tier":31},{"id":295},{"sys":20938,"name":641,"slug":642,"tier":31},{"id":638},{"sys":20940,"name":280,"slug":281,"tier":31},{"id":277},{"sys":20942,"name":521,"slug":522,"tier":31},{"id":518},{"sys":20944,"name":415,"slug":416,"tier":31},{"id":412},{"sys":20946,"name":235,"slug":236,"tier":31},{"id":232},{"sys":20948,"name":388,"slug":389,"tier":45},{"id":385},{"sys":20950,"name":582,"slug":583,"tier":45},{"id":579},{"sys":20952,"name":262,"slug":263,"tier":45},{"id":259},{"sys":20954,"name":325,"slug":326,"tier":45},{"id":322},{"sys":20956,"name":573,"slug":574,"tier":45},{"id":570},{"sys":20958,"name":289,"slug":290,"tier":45},{"id":286},{"sys":20960,"name":370,"slug":371,"tier":45},{"id":367},{"sys":20962,"name":316,"slug":317,"tier":45},{"id":313},{"sys":20964,"name":361,"slug":362,"tier":45},{"id":358},{"sys":20966,"name":253,"slug":254,"tier":45},{"id":250},{"sys":20968,"name":512,"slug":513,"tier":45},{"id":509},{"sys":20970,"name":623,"slug":624,"tier":45},{"id":620},{"sys":20972,"name":244,"slug":245,"tier":45},{"id":241},"R6qLSR-i1d8ltg2tNiiwocbWu7Y3b4pT4C_MTKlUwec",{"id":20975,"title":8015,"authorsCollection":20976,"content":20981,"extension":228,"faqItemsCollection":21753,"faqTitle":59,"featured":6,"hashTags":59,"meta":21755,"metaTitle":21756,"ogImage":59,"postType":1360,"publishedDate":8017,"relatedBlogPostsCollection":21757,"slug":8018,"stem":23986,"subtitle":59,"summary":23987,"synopsis":8016,"sys":23998,"tagsCollection":24000,"topicsCollection":24006,"__hash__":24054},"blog\u002Fblog\u002Fhow-to-avoid-the-browser-security-buyers-trap.json",{"items":20977},[20978],{"fullName":3964,"firstName":3965,"jobTitle":868,"socialLinks":20979,"profilePicture":20980},[3967],{"url":3969},{"json":20982,"links":21641},{"data":20983,"content":20984,"nodeType":1294},{},[20985,20990,20996,21002,21008,21011,21018,21024,21034,21044,21049,21055,21058,21065,21071,21076,21082,21088,21181,21187,21190,21197,21203,21258,21271,21276,21282,21285,21292,21298,21305,21311,21317,21342,21348,21355,21361,21367,21373,21380,21386,21392,21398,21401,21408,21418,21424,21430,21437,21443,21449,21456,21462,21517,21530,21545,21552,21558,21565,21571,21577,21583,21588,21595,21601,21607,21612,21618,21624,21630,21635],{"data":20986,"content":20989,"nodeType":963},{"target":20987},{"sys":20988},{"id":7255,"type":960,"linkType":961},[],{"data":20991,"content":20992,"nodeType":883},{},[20993],{"data":20994,"marks":20995,"value":7263,"nodeType":882},{},[],{"data":20997,"content":20998,"nodeType":883},{},[20999],{"data":21000,"marks":21001,"value":7270,"nodeType":882},{},[],{"data":21003,"content":21004,"nodeType":883},{},[21005],{"data":21006,"marks":21007,"value":7277,"nodeType":882},{},[],{"data":21009,"content":21010,"nodeType":967},{},[],{"data":21012,"content":21013,"nodeType":975},{},[21014],{"data":21015,"marks":21016,"value":7288,"nodeType":882},{},[21017],{"type":1012},{"data":21019,"content":21020,"nodeType":883},{},[21021],{"data":21022,"marks":21023,"value":7295,"nodeType":882},{},[],{"data":21025,"content":21026,"nodeType":883},{},[21027,21031],{"data":21028,"marks":21029,"value":7303,"nodeType":882},{},[21030],{"type":1012},{"data":21032,"marks":21033,"value":7307,"nodeType":882},{},[],{"data":21035,"content":21036,"nodeType":883},{},[21037,21041],{"data":21038,"marks":21039,"value":7315,"nodeType":882},{},[21040],{"type":1012},{"data":21042,"marks":21043,"value":7319,"nodeType":882},{},[],{"data":21045,"content":21048,"nodeType":963},{"target":21046},{"sys":21047},{"id":7324,"type":960,"linkType":961},[],{"data":21050,"content":21051,"nodeType":883},{},[21052],{"data":21053,"marks":21054,"value":7332,"nodeType":882},{},[],{"data":21056,"content":21057,"nodeType":967},{},[],{"data":21059,"content":21060,"nodeType":975},{},[21061],{"data":21062,"marks":21063,"value":7343,"nodeType":882},{},[21064],{"type":1012},{"data":21066,"content":21067,"nodeType":883},{},[21068],{"data":21069,"marks":21070,"value":7350,"nodeType":882},{},[],{"data":21072,"content":21075,"nodeType":963},{"target":21073},{"sys":21074},{"id":7355,"type":960,"linkType":961},[],{"data":21077,"content":21078,"nodeType":883},{},[21079],{"data":21080,"marks":21081,"value":7363,"nodeType":882},{},[],{"data":21083,"content":21084,"nodeType":883},{},[21085],{"data":21086,"marks":21087,"value":7370,"nodeType":882},{},[],{"data":21089,"content":21090,"nodeType":1454},{},[21091,21107,21123,21139,21155,21168],{"data":21092,"content":21093,"nodeType":1419},{},[21094],{"data":21095,"content":21096,"nodeType":883},{},[21097,21100,21104],{"data":21098,"marks":21099,"value":7383,"nodeType":882},{},[],{"data":21101,"marks":21102,"value":7388,"nodeType":882},{},[21103],{"type":1012},{"data":21105,"marks":21106,"value":7392,"nodeType":882},{},[],{"data":21108,"content":21109,"nodeType":1419},{},[21110],{"data":21111,"content":21112,"nodeType":883},{},[21113,21116,21120],{"data":21114,"marks":21115,"value":7402,"nodeType":882},{},[],{"data":21117,"marks":21118,"value":7407,"nodeType":882},{},[21119],{"type":1012},{"data":21121,"marks":21122,"value":7411,"nodeType":882},{},[],{"data":21124,"content":21125,"nodeType":1419},{},[21126],{"data":21127,"content":21128,"nodeType":883},{},[21129,21132,21136],{"data":21130,"marks":21131,"value":7421,"nodeType":882},{},[],{"data":21133,"marks":21134,"value":7426,"nodeType":882},{},[21135],{"type":1012},{"data":21137,"marks":21138,"value":7430,"nodeType":882},{},[],{"data":21140,"content":21141,"nodeType":1419},{},[21142],{"data":21143,"content":21144,"nodeType":883},{},[21145,21148,21152],{"data":21146,"marks":21147,"value":7440,"nodeType":882},{},[],{"data":21149,"marks":21150,"value":7445,"nodeType":882},{},[21151],{"type":1012},{"data":21153,"marks":21154,"value":7449,"nodeType":882},{},[],{"data":21156,"content":21157,"nodeType":1419},{},[21158],{"data":21159,"content":21160,"nodeType":883},{},[21161,21165],{"data":21162,"marks":21163,"value":7460,"nodeType":882},{},[21164],{"type":1012},{"data":21166,"marks":21167,"value":7464,"nodeType":882},{},[],{"data":21169,"content":21170,"nodeType":1419},{},[21171],{"data":21172,"content":21173,"nodeType":883},{},[21174,21178],{"data":21175,"marks":21176,"value":7475,"nodeType":882},{},[21177],{"type":1012},{"data":21179,"marks":21180,"value":7479,"nodeType":882},{},[],{"data":21182,"content":21183,"nodeType":883},{},[21184],{"data":21185,"marks":21186,"value":7486,"nodeType":882},{},[],{"data":21188,"content":21189,"nodeType":967},{},[],{"data":21191,"content":21192,"nodeType":2050},{},[21193],{"data":21194,"marks":21195,"value":7497,"nodeType":882},{},[21196],{"type":1012},{"data":21198,"content":21199,"nodeType":883},{},[21200],{"data":21201,"marks":21202,"value":7504,"nodeType":882},{},[],{"data":21204,"content":21205,"nodeType":1454},{},[21206,21219,21232,21245],{"data":21207,"content":21208,"nodeType":1419},{},[21209],{"data":21210,"content":21211,"nodeType":883},{},[21212,21215],{"data":21213,"marks":21214,"value":7517,"nodeType":882},{},[],{"data":21216,"marks":21217,"value":7522,"nodeType":882},{},[21218],{"type":1012},{"data":21220,"content":21221,"nodeType":1419},{},[21222],{"data":21223,"content":21224,"nodeType":883},{},[21225,21228],{"data":21226,"marks":21227,"value":7532,"nodeType":882},{},[],{"data":21229,"marks":21230,"value":7537,"nodeType":882},{},[21231],{"type":1012},{"data":21233,"content":21234,"nodeType":1419},{},[21235],{"data":21236,"content":21237,"nodeType":883},{},[21238,21241],{"data":21239,"marks":21240,"value":7547,"nodeType":882},{},[],{"data":21242,"marks":21243,"value":7552,"nodeType":882},{},[21244],{"type":1012},{"data":21246,"content":21247,"nodeType":1419},{},[21248],{"data":21249,"content":21250,"nodeType":883},{},[21251,21254],{"data":21252,"marks":21253,"value":7562,"nodeType":882},{},[],{"data":21255,"marks":21256,"value":7567,"nodeType":882},{},[21257],{"type":1012},{"data":21259,"content":21260,"nodeType":883},{},[21261,21264,21268],{"data":21262,"marks":21263,"value":7574,"nodeType":882},{},[],{"data":21265,"marks":21266,"value":7579,"nodeType":882},{},[21267],{"type":1012},{"data":21269,"marks":21270,"value":7583,"nodeType":882},{},[],{"data":21272,"content":21275,"nodeType":963},{"target":21273},{"sys":21274},{"id":7588,"type":960,"linkType":961},[],{"data":21277,"content":21278,"nodeType":883},{},[21279],{"data":21280,"marks":21281,"value":7596,"nodeType":882},{},[],{"data":21283,"content":21284,"nodeType":967},{},[],{"data":21286,"content":21287,"nodeType":975},{},[21288],{"data":21289,"marks":21290,"value":7607,"nodeType":882},{},[21291],{"type":1012},{"data":21293,"content":21294,"nodeType":883},{},[21295],{"data":21296,"marks":21297,"value":7614,"nodeType":882},{},[],{"data":21299,"content":21300,"nodeType":2050},{},[21301],{"data":21302,"marks":21303,"value":7622,"nodeType":882},{},[21304],{"type":1012},{"data":21306,"content":21307,"nodeType":883},{},[21308],{"data":21309,"marks":21310,"value":7629,"nodeType":882},{},[],{"data":21312,"content":21313,"nodeType":883},{},[21314],{"data":21315,"marks":21316,"value":7636,"nodeType":882},{},[],{"data":21318,"content":21319,"nodeType":883},{},[21320,21323,21329,21332,21339],{"data":21321,"marks":21322,"value":7643,"nodeType":882},{},[],{"data":21324,"content":21325,"nodeType":929},{"uri":6589},[21326],{"data":21327,"marks":21328,"value":7650,"nodeType":882},{},[],{"data":21330,"marks":21331,"value":7654,"nodeType":882},{},[],{"data":21333,"content":21334,"nodeType":929},{"uri":7657},[21335],{"data":21336,"marks":21337,"value":7663,"nodeType":882},{},[21338],{"type":927},{"data":21340,"marks":21341,"value":7667,"nodeType":882},{},[],{"data":21343,"content":21344,"nodeType":883},{},[21345],{"data":21346,"marks":21347,"value":7674,"nodeType":882},{},[],{"data":21349,"content":21350,"nodeType":2050},{},[21351],{"data":21352,"marks":21353,"value":7682,"nodeType":882},{},[21354],{"type":1012},{"data":21356,"content":21357,"nodeType":883},{},[21358],{"data":21359,"marks":21360,"value":7689,"nodeType":882},{},[],{"data":21362,"content":21363,"nodeType":883},{},[21364],{"data":21365,"marks":21366,"value":7696,"nodeType":882},{},[],{"data":21368,"content":21369,"nodeType":883},{},[21370],{"data":21371,"marks":21372,"value":7703,"nodeType":882},{},[],{"data":21374,"content":21375,"nodeType":2050},{},[21376],{"data":21377,"marks":21378,"value":7711,"nodeType":882},{},[21379],{"type":1012},{"data":21381,"content":21382,"nodeType":883},{},[21383],{"data":21384,"marks":21385,"value":7718,"nodeType":882},{},[],{"data":21387,"content":21388,"nodeType":883},{},[21389],{"data":21390,"marks":21391,"value":7725,"nodeType":882},{},[],{"data":21393,"content":21394,"nodeType":883},{},[21395],{"data":21396,"marks":21397,"value":7732,"nodeType":882},{},[],{"data":21399,"content":21400,"nodeType":967},{},[],{"data":21402,"content":21403,"nodeType":975},{},[21404],{"data":21405,"marks":21406,"value":7743,"nodeType":882},{},[21407],{"type":1012},{"data":21409,"content":21410,"nodeType":883},{},[21411,21415],{"data":21412,"marks":21413,"value":7751,"nodeType":882},{},[21414],{"type":1012},{"data":21416,"marks":21417,"value":7755,"nodeType":882},{},[],{"data":21419,"content":21420,"nodeType":883},{},[21421],{"data":21422,"marks":21423,"value":7762,"nodeType":882},{},[],{"data":21425,"content":21426,"nodeType":883},{},[21427],{"data":21428,"marks":21429,"value":7769,"nodeType":882},{},[],{"data":21431,"content":21432,"nodeType":2050},{},[21433],{"data":21434,"marks":21435,"value":7777,"nodeType":882},{},[21436],{"type":1012},{"data":21438,"content":21439,"nodeType":883},{},[21440],{"data":21441,"marks":21442,"value":7784,"nodeType":882},{},[],{"data":21444,"content":21445,"nodeType":883},{},[21446],{"data":21447,"marks":21448,"value":7791,"nodeType":882},{},[],{"data":21450,"content":21451,"nodeType":2050},{},[21452],{"data":21453,"marks":21454,"value":7799,"nodeType":882},{},[21455],{"type":1012},{"data":21457,"content":21458,"nodeType":883},{},[21459],{"data":21460,"marks":21461,"value":7806,"nodeType":882},{},[],{"data":21463,"content":21464,"nodeType":1454},{},[21465,21478,21491,21504],{"data":21466,"content":21467,"nodeType":1419},{},[21468],{"data":21469,"content":21470,"nodeType":883},{},[21471,21475],{"data":21472,"marks":21473,"value":7820,"nodeType":882},{},[21474],{"type":1012},{"data":21476,"marks":21477,"value":7824,"nodeType":882},{},[],{"data":21479,"content":21480,"nodeType":1419},{},[21481],{"data":21482,"content":21483,"nodeType":883},{},[21484,21488],{"data":21485,"marks":21486,"value":7835,"nodeType":882},{},[21487],{"type":1012},{"data":21489,"marks":21490,"value":7839,"nodeType":882},{},[],{"data":21492,"content":21493,"nodeType":1419},{},[21494],{"data":21495,"content":21496,"nodeType":883},{},[21497,21501],{"data":21498,"marks":21499,"value":7850,"nodeType":882},{},[21500],{"type":1012},{"data":21502,"marks":21503,"value":7854,"nodeType":882},{},[],{"data":21505,"content":21506,"nodeType":1419},{},[21507],{"data":21508,"content":21509,"nodeType":883},{},[21510,21514],{"data":21511,"marks":21512,"value":7865,"nodeType":882},{},[21513],{"type":1012},{"data":21515,"marks":21516,"value":7869,"nodeType":882},{},[],{"data":21518,"content":21519,"nodeType":883},{},[21520,21523,21527],{"data":21521,"marks":21522,"value":7876,"nodeType":882},{},[],{"data":21524,"marks":21525,"value":7881,"nodeType":882},{},[21526],{"type":1012},{"data":21528,"marks":21529,"value":7885,"nodeType":882},{},[],{"data":21531,"content":21532,"nodeType":883},{},[21533,21536,21542],{"data":21534,"marks":21535,"value":7892,"nodeType":882},{},[],{"data":21537,"content":21538,"nodeType":929},{"uri":7895},[21539],{"data":21540,"marks":21541,"value":7900,"nodeType":882},{},[],{"data":21543,"marks":21544,"value":7904,"nodeType":882},{},[],{"data":21546,"content":21547,"nodeType":2050},{},[21548],{"data":21549,"marks":21550,"value":7912,"nodeType":882},{},[21551],{"type":1012},{"data":21553,"content":21554,"nodeType":883},{},[21555],{"data":21556,"marks":21557,"value":7919,"nodeType":882},{},[],{"data":21559,"content":21560,"nodeType":883},{},[21561],{"data":21562,"marks":21563,"value":7927,"nodeType":882},{},[21564],{"type":1012},{"data":21566,"content":21567,"nodeType":883},{},[21568],{"data":21569,"marks":21570,"value":7934,"nodeType":882},{},[],{"data":21572,"content":21573,"nodeType":883},{},[21574],{"data":21575,"marks":21576,"value":7941,"nodeType":882},{},[],{"data":21578,"content":21579,"nodeType":883},{},[21580],{"data":21581,"marks":21582,"value":7948,"nodeType":882},{},[],{"data":21584,"content":21587,"nodeType":963},{"target":21585},{"sys":21586},{"id":7953,"type":960,"linkType":961},[],{"data":21589,"content":21590,"nodeType":2050},{},[21591],{"data":21592,"marks":21593,"value":7962,"nodeType":882},{},[21594],{"type":1012},{"data":21596,"content":21597,"nodeType":883},{},[21598],{"data":21599,"marks":21600,"value":7969,"nodeType":882},{},[],{"data":21602,"content":21603,"nodeType":883},{},[21604],{"data":21605,"marks":21606,"value":7976,"nodeType":882},{},[],{"data":21608,"content":21611,"nodeType":963},{"target":21609},{"sys":21610},{"id":4417,"type":960,"linkType":961},[],{"data":21613,"content":21614,"nodeType":883},{},[21615],{"data":21616,"marks":21617,"value":7988,"nodeType":882},{},[],{"data":21619,"content":21620,"nodeType":883},{},[21621],{"data":21622,"marks":21623,"value":7995,"nodeType":882},{},[],{"data":21625,"content":21626,"nodeType":883},{},[21627],{"data":21628,"marks":21629,"value":8002,"nodeType":882},{},[],{"data":21631,"content":21634,"nodeType":963},{"target":21632},{"sys":21633},{"id":8007,"type":960,"linkType":961},[],{"data":21636,"content":21637,"nodeType":883},{},[21638],{"data":21639,"marks":21640,"value":21,"nodeType":882},{},[],{"entries":21642},{"hyperlink":21643,"inline":21644,"block":21645},[],[],[21646,21671,21673,21709,21732,21746,21749],{"sys":21647,"__typename":1302,"content":21648,"name":21670,"title":59},{"id":7255},{"json":21649},{"nodeType":1294,"data":21650,"content":21651},{},[21652,21664],{"nodeType":883,"data":21653,"content":21654},{},[21655,21660],{"nodeType":882,"value":21656,"marks":21657,"data":21659},"TL;DR:",[21658],{"type":1012},{},{"nodeType":882,"value":21661,"marks":21662,"data":21663}," Not all browser security investments address the same threat. Seraphic (Crowdstrike) focuses on browser exploitation, SquareX (ZScaler) on malware sandboxing, LayerX on internal governance. None of these address the attacks that are actually causing the most damaging breaches today: identity theft, credential abuse, and session hijacking that play out entirely inside the browser using legitimate authentication flows. Push Security is built specifically for that threat model — delivering the greatest coverage against the most damaging attacks, without the user friction, operational management burden, or stability risks associated with other solutions.",[],{},{"nodeType":883,"data":21665,"content":21666},{},[21667],{"nodeType":882,"value":5101,"marks":21668,"data":21669},[],{},"Browser security buyer's trap IB1",{"sys":21672,"__typename":12405,"type":12406,"ctaText":18662,"buttonLabel":18663,"buttonColour":12408,"buttonUrl":3358},{"id":7324},{"sys":21674,"__typename":1302,"content":21675,"name":21708,"title":59},{"id":7355},{"json":21676},{"data":21677,"content":21678,"nodeType":1294},{},[21679],{"data":21680,"content":21681,"nodeType":883},{},[21682,21686,21693,21696,21704],{"data":21683,"marks":21684,"value":21685,"nodeType":882},{},[],"You can read about ",{"data":21687,"content":21688,"nodeType":929},{"uri":8219},[21689],{"data":21690,"marks":21691,"value":16533,"nodeType":882},{},[21692],{"type":927},{"data":21694,"marks":21695,"value":2633,"nodeType":882},{},[],{"data":21697,"content":21698,"nodeType":929},{"uri":3507},[21699],{"data":21700,"marks":21701,"value":21703,"nodeType":882},{},[21702],{"type":927},"ShinyHunters’ 2026 campaigns and TTPs",{"data":21705,"marks":21706,"value":21707,"nodeType":882},{},[]," in our dedicated blog posts. ","Browser security buyer's trap IB2",{"sys":21710,"__typename":1302,"content":21711,"name":21731,"title":59},{"id":7588},{"json":21712},{"data":21713,"content":21714,"nodeType":1294},{},[21715],{"data":21716,"content":21717,"nodeType":883},{},[21718,21722,21727],{"data":21719,"marks":21720,"value":21721,"nodeType":882},{},[],"It's worth heading off the obvious counterargument: ",{"data":21723,"marks":21724,"value":21726,"nodeType":882},{},[21725],{"type":1012},"won't AI-assisted vulnerability discovery eventually make browser exploits cheaper? ",{"data":21728,"marks":21729,"value":21730,"nodeType":882},{},[],"Perhaps — but it will simultaneously make them easier for browser vendors to find and patch, and vendors like Google and Microsoft have the engineering capacity and financial incentive to scale AI-driven remediation far faster than attackers can scale exploit development. ","Browser security buyer's trap IB3",{"sys":21733,"__typename":1302,"content":21734,"name":21745,"title":59},{"id":7953},{"json":21735},{"nodeType":1294,"data":21736,"content":21737},{},[21738],{"nodeType":883,"data":21739,"content":21740},{},[21741],{"nodeType":882,"value":21742,"marks":21743,"data":21744},"Solutions optimized for browser exploitation are defending against a shrinking attack category. Browser vendors are very good at closing those vulnerabilities, quickly. The ROI trajectory points the wrong way.",[],{},"Browser security buyer's trap IB4",{"sys":21747,"__typename":1329,"title":4543,"caption":4544,"layoutMode":59,"file":21748},{"id":4417},{"url":4546,"width":4547,"height":4548},{"sys":21750,"__typename":12405,"type":12406,"ctaText":21751,"buttonLabel":21752,"buttonColour":12408,"buttonUrl":2935},{"id":8007},"Ready to learn more about Push? Book a demo with one of our team. ","Book a Demo",{"items":21754},[],{},"Solving for attacks that happen in, not on the browser",{"items":21758},[21759,22711,23544],{"__typename":1365,"sys":21760,"content":21762,"title":22697,"synopsis":22698,"hashTags":59,"publishedDate":22699,"slug":22700,"tagsCollection":22701,"authorsCollection":22707},{"id":21761},"1jfqiWQlL6qkn3i9yjNbFB",{"json":21763},{"data":21764,"content":21765,"nodeType":1294},{},[21766,21773,21794,21806,21813,21821,21828,21850,21857,21864,21871,21883,21889,21892,21900,21915,21934,22045,22050,22057,22063,22071,22078,22090,22097,22103,22110,22134,22141,22148,22154,22157,22165,22172,22180,22187,22203,22210,22217,22225,22232,22239,22247,22254,22261,22264,22272,22279,22287,22294,22301,22308,22315,22323,22330,22362,22369,22376,22382,22389,22397,22404,22482,22488,22496,22512,22519,22525,22532,22548,22551,22559,22566,22573,22579,22586,22631,22638,22645,22652,22658,22661,22669,22675,22681],{"data":21767,"content":21768,"nodeType":883},{},[21769],{"data":21770,"marks":21771,"value":21772,"nodeType":882},{},[],"In March, our threat hunting engine flagged something it hadn’t seen before.",{"data":21774,"content":21775,"nodeType":883},{},[21776,21780,21790],{"data":21777,"marks":21778,"value":21779,"nodeType":882},{},[],"Our research team had already been tracking the growing use of ",{"data":21781,"content":21785,"nodeType":21789},{"target":21782},{"sys":21783},{"id":21784,"type":960,"linkType":961},"2U6QpQ9rkY8x5ES48okHZB",[21786],{"data":21787,"marks":21788,"value":443,"nodeType":882},{},[],"entry-hyperlink",{"data":21791,"marks":21792,"value":21793,"nodeType":882},{},[]," tied to phishing campaigns. Malvertising frequently targets users via Google Search results, inserting malicious ads or redirects in place of legitimate ads, and using the familiar context of the search results page to trick users into clicking.",{"data":21795,"content":21796,"nodeType":883},{},[21797,21801],{"data":21798,"marks":21799,"value":21800,"nodeType":882},{},[],"To defend Push customers against this threat, we needed a way to spot malicious activity arising from clicking on Google ads. ",{"data":21802,"marks":21803,"value":21805,"nodeType":882},{},[21804],{"type":1045},"But how to separate signal from noise?",{"data":21807,"content":21808,"nodeType":883},{},[21809],{"data":21810,"marks":21811,"value":21812,"nodeType":882},{},[],"Our hunt combined the skills of human researchers and AI agents to find 12 meaningful results from trillions of browser events visible to the Push extension across our install base.",{"data":21814,"content":21815,"nodeType":883},{},[21816],{"data":21817,"marks":21818,"value":21820,"nodeType":882},{},[21819],{"type":1012},"Of those, one was novel. ",{"data":21822,"content":21823,"nodeType":883},{},[21824],{"data":21825,"marks":21826,"value":21827,"nodeType":882},{},[],"A user had searched for NotebookLM, clicked a paid Google ad, and gotten redirected to a page impersonating NotebookLM. The page itself was just a facade fronting a Cloudflare Pages-hosted phishing kit with a WebAssembly C2 connector. To the user, it looked like a completely on-brand NotebookLM page, and if they had run the fake install prompt, they would have installed malware. (Note: NotebookLM doesn’t even require a local install, but the page was convincing enough — and AI platforms are changing so quickly — that the lure was extremely believable.)",{"data":21829,"content":21830,"nodeType":883},{},[21831,21836,21846],{"data":21832,"marks":21833,"value":21835,"nodeType":882},{},[21834],{"type":1012},"We had found our first in-the-wild ",{"data":21837,"content":21841,"nodeType":21789},{"target":21838},{"sys":21839},{"id":21840,"type":960,"linkType":961},"7bG71Eo43crbIHKzczooVS",[21842],{"data":21843,"marks":21844,"value":3828,"nodeType":882},{},[21845],{"type":1012},{"data":21847,"marks":21848,"value":1438,"nodeType":882},{},[21849],{"type":1012},{"data":21851,"content":21852,"nodeType":883},{},[21853],{"data":21854,"marks":21855,"value":21856,"nodeType":882},{},[],"Within minutes, our analysis agents created detections, and researchers shipped a new detection to every Push customer. ",{"data":21858,"content":21859,"nodeType":883},{},[21860],{"data":21861,"marks":21862,"value":21863,"nodeType":882},{},[],"Eighteen months ago, it would have taken a human analyst days or even weeks to unpack the attack, comb through web requests, de-obfuscate web code, trace JavaScript execution, and extract signals of tactics, techniques, and procedures (TTPs) beyond short-lived single-use IOCs like domain name, then get their work coded up as a detection and deployed to customers. ",{"data":21865,"content":21866,"nodeType":883},{},[21867],{"data":21868,"marks":21869,"value":21870,"nodeType":882},{},[],"That was viable when new tools or techniques showed up once or twice a quarter. It doesn’t stand a chance when attack evolutions occur weekly or even daily. That’s the reality now with AI-generated adversary tools.",{"data":21872,"content":21873,"nodeType":883},{},[21874,21879],{"data":21875,"marks":21876,"value":21878,"nodeType":882},{},[21877],{"type":1012},"So, can AI agents replace human threat researchers?",{"data":21880,"marks":21881,"value":21882,"nodeType":882},{},[]," That’s the wrong question. Can AI agents massively scale the expertise of a seasoned human threat hunter without getting bored of repetitive tasks, missing pertinent but easily overlooked details, or creating operational siloes dependent on one person’s knowledge — and do its work continuously across trillions of data points? Yes, absolutely.",{"data":21884,"content":21888,"nodeType":963},{"target":21885},{"sys":21886},{"id":21887,"type":960,"linkType":961},"3OiZ7BrViCTTMmHUAbloEt",[],{"data":21890,"content":21891,"nodeType":967},{},[],{"data":21893,"content":21894,"nodeType":975},{},[21895],{"data":21896,"marks":21897,"value":21899,"nodeType":882},{},[21898],{"type":1012},"Why scaling browser threat detection requires more than more analysts",{"data":21901,"content":21902,"nodeType":883},{},[21903,21907,21911],{"data":21904,"marks":21905,"value":21906,"nodeType":882},{},[],"Already this year, we’ve ",{"data":21908,"marks":21909,"value":2069,"nodeType":882},{},[21910],{"type":1012},{"data":21912,"marks":21913,"value":21914,"nodeType":882},{},[]," the cumulative number of detections shipped to Push customers using this pipeline. That output points to the first problem we set out to solve by employing AI agents: Scaling our research team’s considerable expertise.",{"data":21916,"content":21917,"nodeType":883},{},[21918,21922,21930],{"data":21919,"marks":21920,"value":21921,"nodeType":882},{},[],"Push’s R&D team are experts at understanding and unpacking modern browser-based attacks. This is essential when you consider how quickly attacks themselves are evolving. When we created the ",{"data":21923,"content":21926,"nodeType":21789},{"target":21924},{"sys":21925},{"id":16045,"type":960,"linkType":961},[21927],{"data":21928,"marks":21929,"value":9875,"nodeType":882},{},[],{"data":21931,"marks":21932,"value":21933,"nodeType":882},{},[]," in 2023 (then called the SaaS Attacks Matrix), many of the ideas in it were theoretical. Not anymore. ",{"data":21935,"content":21936,"nodeType":1454},{},[21937,21947,21971],{"data":21938,"content":21939,"nodeType":1419},{},[21940],{"data":21941,"content":21942,"nodeType":883},{},[21943],{"data":21944,"marks":21945,"value":21946,"nodeType":882},{},[],"We’ve tracked the rise of AiTM phish kits from their status as MFA-bypassing novelties to the emergence of an entire criminal ecosystem built around increasingly sophisticated Phishing-as-a-Service tools. ",{"data":21948,"content":21949,"nodeType":1419},{},[21950],{"data":21951,"content":21952,"nodeType":883},{},[21953,21957,21967],{"data":21954,"marks":21955,"value":21956,"nodeType":882},{},[],"We imagined the simple but effective power of using device code authorization for phishing three years ago; in the last few months, we’ve detected a 37x increase in ",{"data":21958,"content":21962,"nodeType":21789},{"target":21959},{"sys":21960},{"id":21961,"type":960,"linkType":961},"5DmCqTU2Tg4adYScA5vT2x",[21963],{"data":21964,"marks":21965,"value":21966,"nodeType":882},{},[],"device code phishing attacks",{"data":21968,"marks":21969,"value":21970,"nodeType":882},{},[]," across our install base. ",{"data":21972,"content":21973,"nodeType":1419},{},[21974],{"data":21975,"content":21976,"nodeType":883},{},[21977,21981,21990,21994,22003,22007,22017,22020,22028,22031,22041],{"data":21978,"marks":21979,"value":21980,"nodeType":882},{},[],"We were also the first to detect a novel post-authorization attack we dubbed ",{"data":21982,"content":21986,"nodeType":21789},{"target":21983},{"sys":21984},{"id":21985,"type":960,"linkType":961},"71EaaK7lfl6bQBbkAU0qjv",[21987],{"data":21988,"marks":21989,"value":1989,"nodeType":882},{},[],{"data":21991,"marks":21992,"value":21993,"nodeType":882},{},[]," that combines OAuth consent phishing and ClickFix-style user prompts; reported on the rise of the ridiculously simple yet effective ",{"data":21995,"content":21998,"nodeType":21789},{"target":21996},{"sys":21997},{"id":21840,"type":960,"linkType":961},[21999],{"data":22000,"marks":22001,"value":22002,"nodeType":882},{},[],"InstallFix technique",{"data":22004,"marks":22005,"value":22006,"nodeType":882},{},[]," described earlier; and detected an array of other ",{"data":22008,"content":22012,"nodeType":21789},{"target":22009},{"sys":22010},{"id":22011,"type":960,"linkType":961},"2YmiesBvJHGw4wiKEKzLUq",[22013],{"data":22014,"marks":22015,"value":22016,"nodeType":882},{},[],"creative",{"data":22018,"marks":22019,"value":2218,"nodeType":882},{},[],{"data":22021,"content":22024,"nodeType":21789},{"target":22022},{"sys":22023},{"id":21784,"type":960,"linkType":961},[22025],{"data":22026,"marks":22027,"value":522,"nodeType":882},{},[],{"data":22029,"marks":22030,"value":2218,"nodeType":882},{},[],{"data":22032,"content":22036,"nodeType":21789},{"target":22033},{"sys":22034},{"id":22035,"type":960,"linkType":961},"6Zosy4SU0LpjlaSWX75peb",[22037],{"data":22038,"marks":22039,"value":22040,"nodeType":882},{},[],"campaigns",{"data":22042,"marks":22043,"value":22044,"nodeType":882},{},[]," tied to malvertising scams.",{"data":22046,"content":22049,"nodeType":963},{"target":22047},{"sys":22048},{"id":10223,"type":960,"linkType":961},[],{"data":22051,"content":22052,"nodeType":883},{},[22053],{"data":22054,"marks":22055,"value":22056,"nodeType":882},{},[],"With an agentic approach, we could scale this expertise and reduce the time it takes to go from technique discovery to production-ready detection. This speed is critical now because adversaries are also using AI tools to do their work, exploding the number of trivial-to-rotate indicators of compromise and overwhelming existing detection workflows that lack an equivalent machine speed.",{"data":22058,"content":22062,"nodeType":963},{"target":22059},{"sys":22060},{"id":22061,"type":960,"linkType":961},"1u00uFbC4xsvP9lqahXbgD",[],{"data":22064,"content":22065,"nodeType":2050},{},[22066],{"data":22067,"marks":22068,"value":22070,"nodeType":882},{},[22069],{"type":1012},"Scaling behavioral detections, not just making bigger blocklists",{"data":22072,"content":22073,"nodeType":883},{},[22074],{"data":22075,"marks":22076,"value":22077,"nodeType":882},{},[],"But output numbers alone don’t tell the story of successful detections. That’s the other problem we set out to solve at scale: Most secure browser solutions rely on detection logic based on blocking known-bad indicators like domains, IPs, and URLs.",{"data":22079,"content":22080,"nodeType":883},{},[22081,22086],{"data":22082,"marks":22083,"value":22085,"nodeType":882},{},[22084],{"type":1012},"If your solution offers 1,000 detections, and they’re all based on known-bad indicators that are easily rotated, then you’ve got 1,000 detections that worked once and will likely never fire again. ",{"data":22087,"marks":22088,"value":22089,"nodeType":882},{},[],"They certainly won’t catch subtle adaptations in adversary techniques that don’t rely on infrastructure changes, which are easy for attackers to swap anyway. ",{"data":22091,"content":22092,"nodeType":883},{},[22093],{"data":22094,"marks":22095,"value":22096,"nodeType":882},{},[],"Push does it differently. Our detection engine is focused on hunting for tactics, techniques, and procedures: the behavioral fingerprints of an attack, not just the infrastructure it runs on. ",{"data":22098,"content":22102,"nodeType":963},{"target":22099},{"sys":22100},{"id":22101,"type":960,"linkType":961},"5jR3YVUiusHGnXDOyrgYpr",[],{"data":22104,"content":22105,"nodeType":883},{},[22106],{"data":22107,"marks":22108,"value":22109,"nodeType":882},{},[],"Instead of blocking based on known-bad domains, URLs, and IPs, our detections are built around user-level and page-level behaviors like what scripts load, how redirects behave, what events fire, what actions a user takes and what happens next, etc. (In fact, Push detections don’t even use any infrastructure-based IOCs, though customers can write their own custom detections if they have a specific IOC they’re keeping an eye on.)",{"data":22111,"content":22112,"nodeType":883},{},[22113,22118,22129],{"data":22114,"marks":22115,"value":22117,"nodeType":882},{},[22116],{"type":1012},"All the detections we write would survive infrastructure rotation by adversaries, and many of our existing detections have caught never-before-seen evolutions in TTPs. That’s because we focus on the top of the ",{"data":22119,"content":22123,"nodeType":21789},{"target":22120},{"sys":22121},{"id":22122,"type":960,"linkType":961},"1qegIy4rMdm5XZXnIEoKpE",[22124],{"data":22125,"marks":22126,"value":22128,"nodeType":882},{},[22127],{"type":1012},"Pyramid of Pain",{"data":22130,"marks":22131,"value":22133,"nodeType":882},{},[22132],{"type":1012},", the indicators that are hardest for attackers to change.",{"data":22135,"content":22136,"nodeType":883},{},[22137],{"data":22138,"marks":22139,"value":22140,"nodeType":882},{},[],"This focus on detecting TTPs has always been our approach. But with the acceleration in both attack types and the ease with which adversaries rotate infrastructure, we needed to build capabilities that scaled our knowledge. ",{"data":22142,"content":22143,"nodeType":883},{},[22144],{"data":22145,"marks":22146,"value":22147,"nodeType":882},{},[],"We did this not by replacing researchers, but by continuously activating their expertise. You can hear what our CEO and Co-founder Adam had to say about this below. ",{"data":22149,"content":22153,"nodeType":963},{"target":22150},{"sys":22151},{"id":22152,"type":960,"linkType":961},"C9gr4nF3f6CW45Aol9xij",[],{"data":22155,"content":22156,"nodeType":967},{},[],{"data":22158,"content":22159,"nodeType":975},{},[22160],{"data":22161,"marks":22162,"value":22164,"nodeType":882},{},[22163],{"type":1012},"Core principles for agentic threat hunting",{"data":22166,"content":22167,"nodeType":883},{},[22168],{"data":22169,"marks":22170,"value":22171,"nodeType":882},{},[],"Three principles make Push's agentic threat hunting and detection engineering pipeline work:",{"data":22173,"content":22174,"nodeType":2050},{},[22175],{"data":22176,"marks":22177,"value":22179,"nodeType":882},{},[22178],{"type":1012},"Context matters more than custom models",{"data":22181,"content":22182,"nodeType":883},{},[22183],{"data":22184,"marks":22185,"value":22186,"nodeType":882},{},[],"We’re not AI researchers; we’re security researchers — we aren't trying to compete in building the most intelligent models. And in our view, AI models are quickly becoming commoditized like cloud infrastructure, anyway. Luckily, the commercial models today already excel at understanding web code. We just need to harness their power with our expertise.",{"data":22188,"content":22189,"nodeType":883},{},[22190,22194,22199],{"data":22191,"marks":22192,"value":22193,"nodeType":882},{},[],"So at Push, we use a variety of commercial AI models and tools in complementary ways. What matters most is the telemetry they analyze, and that’s where Push’s existing product infrastructure shines: We’re already deployed into over ",{"data":22195,"marks":22196,"value":22198,"nodeType":882},{},[22197],{"type":1012},"3 million browsers worldwide",{"data":22200,"marks":22201,"value":22202,"nodeType":882},{},[],", and the Push browser extension includes a component that operates as a flight recorder to locally record everything that matters inside a browser session.",{"data":22204,"content":22205,"nodeType":883},{},[22206],{"data":22207,"marks":22208,"value":22209,"nodeType":882},{},[],"This universe of metadata — DOM elements, tab context, script execution, network traffic, user actions, credential entry, etc. — becomes the searchable corpus for hunts. Metadata is stored locally in users’ browsers and only queried during targeted threat hunts. ",{"data":22211,"content":22212,"nodeType":883},{},[22213],{"data":22214,"marks":22215,"value":22216,"nodeType":882},{},[],"This approach avoids dragnet collection of sensitive data. Instead, we focus on collecting metadata and distilling that into patterns and insights that provide context for agents to perform their analysis. This means that Push also does not train or fine-tune models on customer data.",{"data":22218,"content":22219,"nodeType":2050},{},[22220],{"data":22221,"marks":22222,"value":22224,"nodeType":882},{},[22223],{"type":1012},"Agents are only as good as the context you give them. Good context is researcher-led",{"data":22226,"content":22227,"nodeType":883},{},[22228],{"data":22229,"marks":22230,"value":22231,"nodeType":882},{},[],"AI agents don’t know how to identify the TTPs of browser-based attacks until you give them the right context, and Push researchers have spent years unpacking these techniques and tools. Agents at Push consume our internal knowledge base of identified TTPs, and both humans and agents perform meta-analyses to check their work. The agents have access to large libraries of traces of human interactions with real phishing kits. This is a powerful dataset to build on.",{"data":22233,"content":22234,"nodeType":883},{},[22235],{"data":22236,"marks":22237,"value":22238,"nodeType":882},{},[],"When we don’t get the results we want from AI models, the question is “What context is it missing? What does our human team know that the agents don’t, and how can we give them that context — do they need data, tools, better workflows?” That closes the gap in performance and keeps quality high.",{"data":22240,"content":22241,"nodeType":2050},{},[22242],{"data":22243,"marks":22244,"value":22246,"nodeType":882},{},[22245],{"type":1012},"Integrated architecture that makes agentic AI the throughput layer, not a bolt-on",{"data":22248,"content":22249,"nodeType":883},{},[22250],{"data":22251,"marks":22252,"value":22253,"nodeType":882},{},[],"The constraint we’re trying to break by using AI isn’t knowledge, it’s throughput. Our researchers deeply understand the techniques and tools. An agentic pipeline can apply that understanding continuously across millions of browsers and trillions of events, ingest new external signals, generate hunt hypotheses, triage results, and return only the findings that warrant escalation.",{"data":22255,"content":22256,"nodeType":883},{},[22257],{"data":22258,"marks":22259,"value":22260,"nodeType":882},{},[],"This approach relies on tight integration of our product and our agentic workflows. We’ll take a closer look at that in the next section.",{"data":22262,"content":22263,"nodeType":967},{},[],{"data":22265,"content":22266,"nodeType":975},{},[22267],{"data":22268,"marks":22269,"value":22271,"nodeType":882},{},[22270],{"type":1012},"How the agentic detection pipeline runs",{"data":22273,"content":22274,"nodeType":883},{},[22275],{"data":22276,"marks":22277,"value":22278,"nodeType":882},{},[],"Now let’s look at how agentic threat detection actually works, and some of the emerging best practices we’ve identified. We'll cover two example hunts, one initiated autonomously by the agents themselves, and one by our research team. ",{"data":22280,"content":22281,"nodeType":2050},{},[22282],{"data":22283,"marks":22284,"value":22286,"nodeType":882},{},[22285],{"type":1012},"Example 1: Autonomous threat hunt",{"data":22288,"content":22289,"nodeType":883},{},[22290],{"data":22291,"marks":22292,"value":22293,"nodeType":882},{},[],"Push’s threat hunting pipeline ingested context from research articles describing a new attack technique, and an agent developed hypotheses on what to hunt for across Push’s install base to identify instances of this attack. ",{"data":22295,"content":22296,"nodeType":883},{},[22297],{"data":22298,"marks":22299,"value":22300,"nodeType":882},{},[],"The agent crafted detection queries and then refined them to reduce false positives. The successful query ran across stored metadata and returned results, validating that there were zero false positives. ",{"data":22302,"content":22303,"nodeType":883},{},[22304],{"data":22305,"marks":22306,"value":22307,"nodeType":882},{},[],"The validated query became a scheduled job that runs on a regular cadence to monitor for potentially malicious signals. A triage agent then received any matches, did an initial analysis, and passed anything that looked suspicious to another agent to perform deeper analysis. This deep analysis agent wields the full investigative toolkit that a human researcher would — using Push’s internal knowledge base, domain age and registration analysis, URLScan and whois lookups, DOM image analysis, and contextual analysis of page-level and user-level behaviors, etc.",{"data":22309,"content":22310,"nodeType":883},{},[22311],{"data":22312,"marks":22313,"value":22314,"nodeType":882},{},[],"Within a few minutes, it can filter a thousand or more signals in a hunt trace down to a handful with meaning and provide an actionable assessment. Then, once the TTP was well-understood, other agents wrote and refined detections that can raise alerts for customers when an event of this type is seen. The Push platform immediately applies the customer’s configured security controls, such as blocking users from interacting with malicious pages.",{"data":22316,"content":22317,"nodeType":2050},{},[22318],{"data":22319,"marks":22320,"value":22322,"nodeType":882},{},[22321],{"type":1012},"Example 2: Human-initiated threat hunt",{"data":22324,"content":22325,"nodeType":883},{},[22326],{"data":22327,"marks":22328,"value":22329,"nodeType":882},{},[],"Now, going back to the example from the beginning of the article: InstallFix. This hunt started with a thorny problem our research team needed to solve: How to detect bad things downstream of a user interacting with a Google ad? We needed a way to pinpoint the bad links from the good ones.",{"data":22331,"content":22332,"nodeType":883},{},[22333,22337,22342,22345,22350,22353,22358],{"data":22334,"marks":22335,"value":22336,"nodeType":882},{},[],"Our researchers collaborated with agents to formulate the right parameters for hunt queries, taking into account that good ads are normally bought by companies with marketing budgets, so therefore ads will be expected to redirect to pages hosted on custom domains, not shared domains like ",{"data":22338,"marks":22339,"value":22341,"nodeType":882},{},[22340],{"type":1012},"*pages.dev",{"data":22343,"marks":22344,"value":1993,"nodeType":882},{},[],{"data":22346,"marks":22347,"value":22349,"nodeType":882},{},[22348],{"type":1012},"*workers.dev",{"data":22351,"marks":22352,"value":1993,"nodeType":882},{},[],{"data":22354,"marks":22355,"value":22357,"nodeType":882},{},[22356],{"type":1012},"*squarespace.com",{"data":22359,"marks":22360,"value":22361,"nodeType":882},{},[],", etc.",{"data":22363,"content":22364,"nodeType":883},{},[22365],{"data":22366,"marks":22367,"value":22368,"nodeType":882},{},[],"Our AI agents already understood key TTPs that indicated potential maliciousness on a page: password prompts, file downloads, OAuth integrations, clipboard copies, and similar user prompts that are frequently abused.",{"data":22370,"content":22371,"nodeType":883},{},[22372],{"data":22373,"marks":22374,"value":22375,"nodeType":882},{},[],"The agent ran several queries that returned matching browsing traces — the term we use for sequences of events in a session or tab context — where the user clicked a Google ad, was redirected to a page on a shared hosting domain, and then clicked a button to copy content to their clipboard.",{"data":22377,"content":22381,"nodeType":963},{"target":22378},{"sys":22379},{"id":22380,"type":960,"linkType":961},"4IWOrWuvbwzWRJUkINiwKH",[],{"data":22383,"content":22384,"nodeType":883},{},[22385],{"data":22386,"marks":22387,"value":22388,"nodeType":882},{},[],"We got back high-fidelity findings and then tuned the query into a continuous detection that leveraged existing detection logic around related techniques. This process also effectively back-tests new detections, so we know we’re not going to generate a lot of false positives. Result: A new detection against a new technique, plus several improvements to existing detections.",{"data":22390,"content":22391,"nodeType":2050},{},[22392],{"data":22393,"marks":22394,"value":22396,"nodeType":882},{},[22395],{"type":1012},"What infrastructure is needed for agentic threat hunting?",{"data":22398,"content":22399,"nodeType":883},{},[22400],{"data":22401,"marks":22402,"value":22403,"nodeType":882},{},[],"Both of these examples illustrate the end-to-end workflows supported by this pipeline. From an infrastructure perspective, you can think about the pipeline as composed of:",{"data":22405,"content":22406,"nodeType":1454},{},[22407,22422,22437,22452,22467],{"data":22408,"content":22409,"nodeType":1419},{},[22410],{"data":22411,"content":22412,"nodeType":883},{},[22413,22418],{"data":22414,"marks":22415,"value":22417,"nodeType":882},{},[22416],{"type":1012},"A flight recorder: ",{"data":22419,"marks":22420,"value":22421,"nodeType":882},{},[],"The Push extension-powered capability that collects and locally stores browser event metadata from users’ browsers.",{"data":22423,"content":22424,"nodeType":1419},{},[22425],{"data":22426,"content":22427,"nodeType":883},{},[22428,22433],{"data":22429,"marks":22430,"value":22432,"nodeType":882},{},[22431],{"type":1012},"A knowledge base:",{"data":22434,"marks":22435,"value":22436,"nodeType":882},{},[]," Structured knowledge about what Push knows about TTPs and its existing body of detection logic, as well as externally sourced signals of new attack trends.",{"data":22438,"content":22439,"nodeType":1419},{},[22440],{"data":22441,"content":22442,"nodeType":883},{},[22443,22448],{"data":22444,"marks":22445,"value":22447,"nodeType":882},{},[22446],{"type":1012},"Agents as tools: ",{"data":22449,"marks":22450,"value":22451,"nodeType":882},{},[],"Role-segmented agents that work as a team to triage, investigate, develop hunt queries, return analyses, write detections, and review each others’ work for completeness and accuracy.",{"data":22453,"content":22454,"nodeType":1419},{},[22455],{"data":22456,"content":22457,"nodeType":883},{},[22458,22463],{"data":22459,"marks":22460,"value":22462,"nodeType":882},{},[22461],{"type":1012},"Humans in the loop: ",{"data":22464,"marks":22465,"value":22466,"nodeType":882},{},[],"Human researchers who collaborate with agents to initiate hunts and tune detections.",{"data":22468,"content":22469,"nodeType":1419},{},[22470],{"data":22471,"content":22472,"nodeType":883},{},[22473,22478],{"data":22474,"marks":22475,"value":22477,"nodeType":882},{},[22476],{"type":1012},"Platform controls: ",{"data":22479,"marks":22480,"value":22481,"nodeType":882},{},[],"The Push administrator-configured controls that specify how to respond to detected events like AiTM phishing, tuneable by scope, user groups, browser profiles, apps, etc.",{"data":22483,"content":22487,"nodeType":963},{"target":22484},{"sys":22485},{"id":22486,"type":960,"linkType":961},"7FY0vCBUXOt4vnudFuKALC",[],{"data":22489,"content":22490,"nodeType":2050},{},[22491],{"data":22492,"marks":22493,"value":22495,"nodeType":882},{},[22494],{"type":1012},"What are the best practices for agentic threat detection?",{"data":22497,"content":22498,"nodeType":883},{},[22499,22503,22508],{"data":22500,"marks":22501,"value":22502,"nodeType":882},{},[],"To be effective, agents must specialize and focus. This is the ",{"data":22504,"marks":22505,"value":22507,"nodeType":882},{},[22506],{"type":1012},"agents as tools",{"data":22509,"marks":22510,"value":22511,"nodeType":882},{},[]," concept. When we’re asking AI agents to take massive amounts of data and make a high-level decision about a signal in observed browser events, they must work as a team, finding intelligent ways to condense information without losing important context or hallucinating.",{"data":22513,"content":22514,"nodeType":883},{},[22515],{"data":22516,"marks":22517,"value":22518,"nodeType":882},{},[],"Creating a hierarchy of agent jobs — including agents to perform meta-analyses to catch mistakes and verify conclusions — makes the agents effective by giving them a manageable focus that controls the size of context windows.",{"data":22520,"content":22524,"nodeType":963},{"target":22521},{"sys":22522},{"id":22523,"type":960,"linkType":961},"3fzJCknMUmh4Z7YnhBSbsT",[],{"data":22526,"content":22527,"nodeType":883},{},[22528],{"data":22529,"marks":22530,"value":22531,"nodeType":882},{},[],"Creating an agentic workflow requires operationalizing your internal knowledge in a repeatable and trustworthy way. Sharing rich context from human discoveries is the key to getting the best results out of agents. ",{"data":22533,"content":22534,"nodeType":883},{},[22535,22539,22544],{"data":22536,"marks":22537,"value":22538,"nodeType":882},{},[],"It's vital too that the agent uses ",{"data":22540,"marks":22541,"value":22543,"nodeType":882},{},[22542],{"type":1012},"privacy-preserving methods and infrastructure.",{"data":22545,"marks":22546,"value":22547,"nodeType":882},{},[]," The Push agent is designed to respect customer and user privacy while enabling high-fidelity detections. We do this by collecting broad browser metadata but storing it locally in users’ browsers and only querying that metadata during active threat hunting investigations.",{"data":22549,"content":22550,"nodeType":967},{},[],{"data":22552,"content":22553,"nodeType":975},{},[22554],{"data":22555,"marks":22556,"value":22558,"nodeType":882},{},[22557],{"type":1012},"The compounding effect and how it benefits Push customers",{"data":22560,"content":22561,"nodeType":883},{},[22562],{"data":22563,"marks":22564,"value":22565,"nodeType":882},{},[],"At Push, we think about our detection capability as two learning loops with a compounding effect: An inner loop that serves as our real-time detection and response engine for known attacker techniques, and an outer loop that is the continuous learning our agents do as they hunt for new threats, analyze emerging behaviors, and create new detections. ",{"data":22567,"content":22568,"nodeType":883},{},[22569],{"data":22570,"marks":22571,"value":22572,"nodeType":882},{},[],"The outer loop feeds the inner loop, and vice versa.",{"data":22574,"content":22578,"nodeType":963},{"target":22575},{"sys":22576},{"id":22577,"type":960,"linkType":961},"1Jjqll7IIX2QRxN37gjFMH",[],{"data":22580,"content":22581,"nodeType":883},{},[22582],{"data":22583,"marks":22584,"value":22585,"nodeType":882},{},[],"Customers benefit from this approach because it means they:",{"data":22587,"content":22588,"nodeType":1454},{},[22589,22611,22621],{"data":22590,"content":22591,"nodeType":1419},{},[22592],{"data":22593,"content":22594,"nodeType":883},{},[22595,22599,22607],{"data":22596,"marks":22597,"value":22598,"nodeType":882},{},[],"Regularly receive ready-made detections against both known and emerging browser-based threats, without having to write their own detections. (Push also provides the ability to write your own ",{"data":22600,"content":22602,"nodeType":929},{"uri":22601},"\u002Fhelp\u002Faudience\u002Fengineering\u002Fresources\u002Fcustom-detections",[22603],{"data":22604,"marks":22605,"value":22606,"nodeType":882},{},[],"custom detections",{"data":22608,"marks":22609,"value":22610,"nodeType":882},{},[],", too, for environment-specific use cases.)",{"data":22612,"content":22613,"nodeType":1419},{},[22614],{"data":22615,"content":22616,"nodeType":883},{},[22617],{"data":22618,"marks":22619,"value":22620,"nodeType":882},{},[],"Can configure Push’s response actions based on their security goals and environment. Agents act as the threat-hunting and detection engineering team; Push customers set the thresholds for how they want to respond. For example, customers can use Push controls to block all AiTM phishing attacks (or even carve out exceptions for their own incident responders to be able to visit malicious pages with just a warning), and agents continually feed new indicators into detection logic for that class of attack.",{"data":22622,"content":22623,"nodeType":1419},{},[22624],{"data":22625,"content":22626,"nodeType":883},{},[22627],{"data":22628,"marks":22629,"value":22630,"nodeType":882},{},[],"Get pre-digested and actionable intelligence from every detection, with extremely high fidelity.",{"data":22632,"content":22633,"nodeType":883},{},[22634],{"data":22635,"marks":22636,"value":22637,"nodeType":882},{},[],"This all equates to your own advanced browser threat protection, without requiring the specialized in-house expertise we’ve spent years building.",{"data":22639,"content":22640,"nodeType":883},{},[22641],{"data":22642,"marks":22643,"value":22644,"nodeType":882},{},[],"If you’re a Push customer, you already know that we regularly collaborate with security teams to identify and refine detection use cases, and assist with investigations. In the past few months alone, we’ve worked closely with teams targeted by device code phishing, and InstallFix and ClickFix campaigns, among others. ",{"data":22646,"content":22647,"nodeType":883},{},[22648],{"data":22649,"marks":22650,"value":22651,"nodeType":882},{},[],"If you’re not a customer and are curious about how Push’s agentic threat hunting and detection engineering capabilities can address your use cases, please get in touch.",{"data":22653,"content":22657,"nodeType":963},{"target":22654},{"sys":22655},{"id":22656,"type":960,"linkType":961},"607jrBjlD1vtcbkDfD04DE",[],{"data":22659,"content":22660,"nodeType":967},{},[],{"data":22662,"content":22663,"nodeType":975},{},[22664],{"data":22665,"marks":22666,"value":22668,"nodeType":882},{},[22667],{"type":1012},"Learn more",{"data":22670,"content":22671,"nodeType":883},{},[22672],{"data":22673,"marks":22674,"value":2919,"nodeType":882},{},[],{"data":22676,"content":22677,"nodeType":883},{},[22678],{"data":22679,"marks":22680,"value":2926,"nodeType":882},{},[],{"data":22682,"content":22683,"nodeType":883},{},[22684,22687,22694],{"data":22685,"marks":22686,"value":4431,"nodeType":882},{},[],{"data":22688,"content":22690,"nodeType":929},{"uri":22689},"\u002Fdemo",[22691],{"data":22692,"marks":22693,"value":4438,"nodeType":882},{},[],{"data":22695,"marks":22696,"value":3897,"nodeType":882},{},[],"Can AI replace a threat researcher? What we learned building an agentic threat hunting pipeline","How we built an end-to-end threat hunting and detection engineering capability at Push that uses AI agents as a force multiplier.","2026-05-12T00:00:00.000Z","can-ai-replace-a-threat-researcher-what-we-learned-building-an-agentic-threat-hunting-pipeline",{"items":22702},[22703,22705],{"sys":22704,"name":2308},{"id":2307},{"sys":22706,"name":343},{"id":2304},{"items":22708},[22709],{"fullName":866,"firstName":867,"jobTitle":868,"profilePicture":22710},{"url":870},{"__typename":1365,"sys":22712,"content":22713,"title":20897,"synopsis":20898,"hashTags":59,"publishedDate":16874,"slug":20899,"tagsCollection":23534,"authorsCollection":23540},{"id":19933},{"json":22714},{"data":22715,"content":22716,"nodeType":1294},{},[22717,22739,22763,22796,22829,22834,22844,22847,22854,22896,22902,22921,22926,22929,22936,22960,22966,22973,22978,22981,22988,22994,23009,23015,23048,23054,23057,23064,23079,23121,23124,23131,23146,23161,23168,23174,23184,23194,23204,23214,23229,23236,23242,23245,23251,23257,23272,23275,23282,23297,23528],{"data":22718,"content":22719,"nodeType":883},{},[22720,22723,22729,22732,22736],{"data":22721,"marks":22722,"value":19944,"nodeType":882},{},[],{"data":22724,"content":22725,"nodeType":929},{"uri":8219},[22726],{"data":22727,"marks":22728,"value":16533,"nodeType":882},{},[],{"data":22730,"marks":22731,"value":19954,"nodeType":882},{},[],{"data":22733,"marks":22734,"value":19959,"nodeType":882},{},[22735],{"type":1012},{"data":22737,"marks":22738,"value":19963,"nodeType":882},{},[],{"data":22740,"content":22741,"nodeType":883},{},[22742,22745,22751,22754,22760],{"data":22743,"marks":22744,"value":19970,"nodeType":882},{},[],{"data":22746,"content":22747,"nodeType":929},{"uri":19973},[22748],{"data":22749,"marks":22750,"value":19978,"nodeType":882},{},[],{"data":22752,"marks":22753,"value":19982,"nodeType":882},{},[],{"data":22755,"content":22756,"nodeType":929},{"uri":19985},[22757],{"data":22758,"marks":22759,"value":19990,"nodeType":882},{},[],{"data":22761,"marks":22762,"value":19994,"nodeType":882},{},[],{"data":22764,"content":22765,"nodeType":883},{},[22766,22769,22775,22778,22784,22787,22793],{"data":22767,"marks":22768,"value":20001,"nodeType":882},{},[],{"data":22770,"content":22771,"nodeType":929},{"uri":20004},[22772],{"data":22773,"marks":22774,"value":20009,"nodeType":882},{},[],{"data":22776,"marks":22777,"value":20013,"nodeType":882},{},[],{"data":22779,"content":22780,"nodeType":929},{"uri":20016},[22781],{"data":22782,"marks":22783,"value":20021,"nodeType":882},{},[],{"data":22785,"marks":22786,"value":20025,"nodeType":882},{},[],{"data":22788,"content":22789,"nodeType":929},{"uri":20028},[22790],{"data":22791,"marks":22792,"value":20033,"nodeType":882},{},[],{"data":22794,"marks":22795,"value":20037,"nodeType":882},{},[],{"data":22797,"content":22798,"nodeType":883},{},[22799,22802,22808,22811,22817,22820,22826],{"data":22800,"marks":22801,"value":20044,"nodeType":882},{},[],{"data":22803,"content":22804,"nodeType":929},{"uri":20047},[22805],{"data":22806,"marks":22807,"value":20052,"nodeType":882},{},[],{"data":22809,"marks":22810,"value":20056,"nodeType":882},{},[],{"data":22812,"content":22813,"nodeType":929},{"uri":20059},[22814],{"data":22815,"marks":22816,"value":20064,"nodeType":882},{},[],{"data":22818,"marks":22819,"value":20068,"nodeType":882},{},[],{"data":22821,"content":22822,"nodeType":929},{"uri":20071},[22823],{"data":22824,"marks":22825,"value":20076,"nodeType":882},{},[],{"data":22827,"marks":22828,"value":20080,"nodeType":882},{},[],{"data":22830,"content":22833,"nodeType":963},{"target":22831},{"sys":22832},{"id":20085,"type":960,"linkType":961},[],{"data":22835,"content":22836,"nodeType":883},{},[22837,22841],{"data":22838,"marks":22839,"value":20094,"nodeType":882},{},[22840],{"type":1012},{"data":22842,"marks":22843,"value":20098,"nodeType":882},{},[],{"data":22845,"content":22846,"nodeType":967},{},[],{"data":22848,"content":22849,"nodeType":975},{},[22850],{"data":22851,"marks":22852,"value":20109,"nodeType":882},{},[22853],{"type":1012},{"data":22855,"content":22856,"nodeType":883},{},[22857,22860,22866,22869,22875,22878,22884,22887,22893],{"data":22858,"marks":22859,"value":20116,"nodeType":882},{},[],{"data":22861,"content":22862,"nodeType":929},{"uri":20119},[22863],{"data":22864,"marks":22865,"value":20124,"nodeType":882},{},[],{"data":22867,"marks":22868,"value":8976,"nodeType":882},{},[],{"data":22870,"content":22871,"nodeType":929},{"uri":20130},[22872],{"data":22873,"marks":22874,"value":20135,"nodeType":882},{},[],{"data":22876,"marks":22877,"value":20139,"nodeType":882},{},[],{"data":22879,"content":22880,"nodeType":929},{"uri":20016},[22881],{"data":22882,"marks":22883,"value":20146,"nodeType":882},{},[],{"data":22885,"marks":22886,"value":20150,"nodeType":882},{},[],{"data":22888,"content":22889,"nodeType":929},{"uri":18708},[22890],{"data":22891,"marks":22892,"value":20157,"nodeType":882},{},[],{"data":22894,"marks":22895,"value":1438,"nodeType":882},{},[],{"data":22897,"content":22898,"nodeType":883},{},[22899],{"data":22900,"marks":22901,"value":20167,"nodeType":882},{},[],{"data":22903,"content":22904,"nodeType":883},{},[22905,22908,22914,22917],{"data":22906,"marks":22907,"value":20174,"nodeType":882},{},[],{"data":22909,"content":22910,"nodeType":929},{"uri":18708},[22911],{"data":22912,"marks":22913,"value":20181,"nodeType":882},{},[],{"data":22915,"marks":22916,"value":20185,"nodeType":882},{},[],{"data":22918,"marks":22919,"value":20190,"nodeType":882},{},[22920],{"type":1012},{"data":22922,"content":22925,"nodeType":963},{"target":22923},{"sys":22924},{"id":20195,"type":960,"linkType":961},[],{"data":22927,"content":22928,"nodeType":967},{},[],{"data":22930,"content":22931,"nodeType":975},{},[22932],{"data":22933,"marks":22934,"value":20207,"nodeType":882},{},[22935],{"type":1012},{"data":22937,"content":22938,"nodeType":883},{},[22939,22942,22948,22951,22957],{"data":22940,"marks":22941,"value":6443,"nodeType":882},{},[],{"data":22943,"content":22944,"nodeType":929},{"uri":16550},[22945],{"data":22946,"marks":22947,"value":20220,"nodeType":882},{},[],{"data":22949,"marks":22950,"value":20224,"nodeType":882},{},[],{"data":22952,"content":22953,"nodeType":929},{"uri":20028},[22954],{"data":22955,"marks":22956,"value":20231,"nodeType":882},{},[],{"data":22958,"marks":22959,"value":20235,"nodeType":882},{},[],{"data":22961,"content":22962,"nodeType":883},{},[22963],{"data":22964,"marks":22965,"value":20242,"nodeType":882},{},[],{"data":22967,"content":22968,"nodeType":883},{},[22969],{"data":22970,"marks":22971,"value":20250,"nodeType":882},{},[22972],{"type":1012},{"data":22974,"content":22977,"nodeType":963},{"target":22975},{"sys":22976},{"id":20255,"type":960,"linkType":961},[],{"data":22979,"content":22980,"nodeType":967},{},[],{"data":22982,"content":22983,"nodeType":975},{},[22984],{"data":22985,"marks":22986,"value":20267,"nodeType":882},{},[22987],{"type":1012},{"data":22989,"content":22990,"nodeType":883},{},[22991],{"data":22992,"marks":22993,"value":20274,"nodeType":882},{},[],{"data":22995,"content":22996,"nodeType":883},{},[22997,23000,23006],{"data":22998,"marks":22999,"value":6443,"nodeType":882},{},[],{"data":23001,"content":23002,"nodeType":929},{"uri":20283},[23003],{"data":23004,"marks":23005,"value":20288,"nodeType":882},{},[],{"data":23007,"marks":23008,"value":20292,"nodeType":882},{},[],{"data":23010,"content":23011,"nodeType":883},{},[23012],{"data":23013,"marks":23014,"value":20299,"nodeType":882},{},[],{"data":23016,"content":23017,"nodeType":883},{},[23018,23021,23027,23030,23036,23039,23045],{"data":23019,"marks":23020,"value":20306,"nodeType":882},{},[],{"data":23022,"content":23023,"nodeType":929},{"uri":20309},[23024],{"data":23025,"marks":23026,"value":20314,"nodeType":882},{},[],{"data":23028,"marks":23029,"value":20318,"nodeType":882},{},[],{"data":23031,"content":23032,"nodeType":929},{"uri":20321},[23033],{"data":23034,"marks":23035,"value":20326,"nodeType":882},{},[],{"data":23037,"marks":23038,"value":20330,"nodeType":882},{},[],{"data":23040,"content":23041,"nodeType":929},{"uri":6466},[23042],{"data":23043,"marks":23044,"value":20337,"nodeType":882},{},[],{"data":23046,"marks":23047,"value":20341,"nodeType":882},{},[],{"data":23049,"content":23050,"nodeType":883},{},[23051],{"data":23052,"marks":23053,"value":20348,"nodeType":882},{},[],{"data":23055,"content":23056,"nodeType":967},{},[],{"data":23058,"content":23059,"nodeType":975},{},[23060],{"data":23061,"marks":23062,"value":20359,"nodeType":882},{},[23063],{"type":1012},{"data":23065,"content":23066,"nodeType":883},{},[23067,23070,23076],{"data":23068,"marks":23069,"value":20366,"nodeType":882},{},[],{"data":23071,"content":23072,"nodeType":929},{"uri":20369},[23073],{"data":23074,"marks":23075,"value":20374,"nodeType":882},{},[],{"data":23077,"marks":23078,"value":20378,"nodeType":882},{},[],{"data":23080,"content":23081,"nodeType":883},{},[23082,23085,23091,23094,23100,23103,23109,23112,23118],{"data":23083,"marks":23084,"value":20385,"nodeType":882},{},[],{"data":23086,"content":23087,"nodeType":929},{"uri":20388},[23088],{"data":23089,"marks":23090,"value":20393,"nodeType":882},{},[],{"data":23092,"marks":23093,"value":20397,"nodeType":882},{},[],{"data":23095,"content":23096,"nodeType":929},{"uri":20400},[23097],{"data":23098,"marks":23099,"value":20405,"nodeType":882},{},[],{"data":23101,"marks":23102,"value":20409,"nodeType":882},{},[],{"data":23104,"content":23105,"nodeType":929},{"uri":20412},[23106],{"data":23107,"marks":23108,"value":20417,"nodeType":882},{},[],{"data":23110,"marks":23111,"value":20421,"nodeType":882},{},[],{"data":23113,"content":23114,"nodeType":929},{"uri":20424},[23115],{"data":23116,"marks":23117,"value":20429,"nodeType":882},{},[],{"data":23119,"marks":23120,"value":20433,"nodeType":882},{},[],{"data":23122,"content":23123,"nodeType":967},{},[],{"data":23125,"content":23126,"nodeType":975},{},[23127],{"data":23128,"marks":23129,"value":20444,"nodeType":882},{},[23130],{"type":1012},{"data":23132,"content":23133,"nodeType":883},{},[23134,23137,23143],{"data":23135,"marks":23136,"value":20451,"nodeType":882},{},[],{"data":23138,"content":23139,"nodeType":929},{"uri":3389},[23140],{"data":23141,"marks":23142,"value":20458,"nodeType":882},{},[],{"data":23144,"marks":23145,"value":20462,"nodeType":882},{},[],{"data":23147,"content":23148,"nodeType":883},{},[23149,23152,23158],{"data":23150,"marks":23151,"value":20469,"nodeType":882},{},[],{"data":23153,"content":23154,"nodeType":929},{"uri":20472},[23155],{"data":23156,"marks":23157,"value":316,"nodeType":882},{},[],{"data":23159,"marks":23160,"value":20480,"nodeType":882},{},[],{"data":23162,"content":23163,"nodeType":2050},{},[23164],{"data":23165,"marks":23166,"value":20488,"nodeType":882},{},[23167],{"type":1012},{"data":23169,"content":23170,"nodeType":883},{},[23171],{"data":23172,"marks":23173,"value":20495,"nodeType":882},{},[],{"data":23175,"content":23176,"nodeType":883},{},[23177,23181],{"data":23178,"marks":23179,"value":20503,"nodeType":882},{},[23180],{"type":1012},{"data":23182,"marks":23183,"value":20507,"nodeType":882},{},[],{"data":23185,"content":23186,"nodeType":883},{},[23187,23191],{"data":23188,"marks":23189,"value":20515,"nodeType":882},{},[23190],{"type":1012},{"data":23192,"marks":23193,"value":20519,"nodeType":882},{},[],{"data":23195,"content":23196,"nodeType":883},{},[23197,23201],{"data":23198,"marks":23199,"value":20527,"nodeType":882},{},[23200],{"type":1012},{"data":23202,"marks":23203,"value":20531,"nodeType":882},{},[],{"data":23205,"content":23206,"nodeType":883},{},[23207,23211],{"data":23208,"marks":23209,"value":20539,"nodeType":882},{},[23210],{"type":1012},{"data":23212,"marks":23213,"value":20543,"nodeType":882},{},[],{"data":23215,"content":23216,"nodeType":883},{},[23217,23220,23226],{"data":23218,"marks":23219,"value":21,"nodeType":882},{},[],{"data":23221,"content":23222,"nodeType":929},{"uri":12416},[23223],{"data":23224,"marks":23225,"value":20556,"nodeType":882},{},[],{"data":23227,"marks":23228,"value":21,"nodeType":882},{},[],{"data":23230,"content":23231,"nodeType":2050},{},[23232],{"data":23233,"marks":23234,"value":20567,"nodeType":882},{},[23235],{"type":1012},{"data":23237,"content":23238,"nodeType":883},{},[23239],{"data":23240,"marks":23241,"value":20574,"nodeType":882},{},[],{"data":23243,"content":23244,"nodeType":967},{},[],{"data":23246,"content":23247,"nodeType":883},{},[23248],{"data":23249,"marks":23250,"value":7217,"nodeType":882},{},[],{"data":23252,"content":23253,"nodeType":883},{},[23254],{"data":23255,"marks":23256,"value":2926,"nodeType":882},{},[],{"data":23258,"content":23259,"nodeType":883},{},[23260,23263,23269],{"data":23261,"marks":23262,"value":21,"nodeType":882},{},[],{"data":23264,"content":23265,"nodeType":929},{"uri":2935},[23266],{"data":23267,"marks":23268,"value":2941,"nodeType":882},{},[],{"data":23270,"marks":23271,"value":21,"nodeType":882},{},[],{"data":23273,"content":23274,"nodeType":967},{},[],{"data":23276,"content":23277,"nodeType":975},{},[23278],{"data":23279,"marks":23280,"value":20615,"nodeType":882},{},[23281],{"type":1012},{"data":23283,"content":23284,"nodeType":883},{},[23285,23288,23294],{"data":23286,"marks":23287,"value":20622,"nodeType":882},{},[],{"data":23289,"content":23290,"nodeType":929},{"uri":8219},[23291],{"data":23292,"marks":23293,"value":20629,"nodeType":882},{},[],{"data":23295,"marks":23296,"value":20633,"nodeType":882},{},[],{"data":23298,"content":23299,"nodeType":3104},{},[23300,23343,23399,23442,23485],{"data":23301,"content":23302,"nodeType":3011},{},[23303,23313,23323,23333],{"data":23304,"content":23305,"nodeType":3025},{},[23306],{"data":23307,"content":23308,"nodeType":883},{},[23309],{"data":23310,"marks":23311,"value":20650,"nodeType":882},{},[23312],{"type":1012},{"data":23314,"content":23315,"nodeType":3025},{},[23316],{"data":23317,"content":23318,"nodeType":883},{},[23319],{"data":23320,"marks":23321,"value":20661,"nodeType":882},{},[23322],{"type":1012},{"data":23324,"content":23325,"nodeType":3025},{},[23326],{"data":23327,"content":23328,"nodeType":883},{},[23329],{"data":23330,"marks":23331,"value":20672,"nodeType":882},{},[23332],{"type":1012},{"data":23334,"content":23335,"nodeType":3025},{},[23336],{"data":23337,"content":23338,"nodeType":883},{},[23339],{"data":23340,"marks":23341,"value":20683,"nodeType":882},{},[23342],{"type":1012},{"data":23344,"content":23345,"nodeType":3011},{},[23346,23366,23375,23384],{"data":23347,"content":23348,"nodeType":3025},{},[23349],{"data":23350,"content":23351,"nodeType":883},{},[23352,23356,23359,23363],{"data":23353,"marks":23354,"value":20697,"nodeType":882},{},[23355],{"type":1012},{"data":23357,"marks":23358,"value":20701,"nodeType":882},{},[],{"data":23360,"marks":23361,"value":20706,"nodeType":882},{},[23362],{"type":1012},{"data":23364,"marks":23365,"value":20710,"nodeType":882},{},[],{"data":23367,"content":23368,"nodeType":3025},{},[23369],{"data":23370,"content":23371,"nodeType":883},{},[23372],{"data":23373,"marks":23374,"value":20720,"nodeType":882},{},[],{"data":23376,"content":23377,"nodeType":3025},{},[23378],{"data":23379,"content":23380,"nodeType":883},{},[23381],{"data":23382,"marks":23383,"value":20730,"nodeType":882},{},[],{"data":23385,"content":23386,"nodeType":3025},{},[23387,23393],{"data":23388,"content":23389,"nodeType":883},{},[23390],{"data":23391,"marks":23392,"value":20740,"nodeType":882},{},[],{"data":23394,"content":23395,"nodeType":883},{},[23396],{"data":23397,"marks":23398,"value":20747,"nodeType":882},{},[],{"data":23400,"content":23401,"nodeType":3011},{},[23402,23415,23424,23433],{"data":23403,"content":23404,"nodeType":3025},{},[23405],{"data":23406,"content":23407,"nodeType":883},{},[23408,23412],{"data":23409,"marks":23410,"value":20761,"nodeType":882},{},[23411],{"type":1012},{"data":23413,"marks":23414,"value":20765,"nodeType":882},{},[],{"data":23416,"content":23417,"nodeType":3025},{},[23418],{"data":23419,"content":23420,"nodeType":883},{},[23421],{"data":23422,"marks":23423,"value":20775,"nodeType":882},{},[],{"data":23425,"content":23426,"nodeType":3025},{},[23427],{"data":23428,"content":23429,"nodeType":883},{},[23430],{"data":23431,"marks":23432,"value":20785,"nodeType":882},{},[],{"data":23434,"content":23435,"nodeType":3025},{},[23436],{"data":23437,"content":23438,"nodeType":883},{},[23439],{"data":23440,"marks":23441,"value":20795,"nodeType":882},{},[],{"data":23443,"content":23444,"nodeType":3011},{},[23445,23458,23467,23476],{"data":23446,"content":23447,"nodeType":3025},{},[23448],{"data":23449,"content":23450,"nodeType":883},{},[23451,23455],{"data":23452,"marks":23453,"value":20809,"nodeType":882},{},[23454],{"type":1012},{"data":23456,"marks":23457,"value":20813,"nodeType":882},{},[],{"data":23459,"content":23460,"nodeType":3025},{},[23461],{"data":23462,"content":23463,"nodeType":883},{},[23464],{"data":23465,"marks":23466,"value":20823,"nodeType":882},{},[],{"data":23468,"content":23469,"nodeType":3025},{},[23470],{"data":23471,"content":23472,"nodeType":883},{},[23473],{"data":23474,"marks":23475,"value":20833,"nodeType":882},{},[],{"data":23477,"content":23478,"nodeType":3025},{},[23479],{"data":23480,"content":23481,"nodeType":883},{},[23482],{"data":23483,"marks":23484,"value":20843,"nodeType":882},{},[],{"data":23486,"content":23487,"nodeType":3011},{},[23488,23501,23510,23519],{"data":23489,"content":23490,"nodeType":3025},{},[23491],{"data":23492,"content":23493,"nodeType":883},{},[23494,23498],{"data":23495,"marks":23496,"value":20857,"nodeType":882},{},[23497],{"type":1012},{"data":23499,"marks":23500,"value":20861,"nodeType":882},{},[],{"data":23502,"content":23503,"nodeType":3025},{},[23504],{"data":23505,"content":23506,"nodeType":883},{},[23507],{"data":23508,"marks":23509,"value":20720,"nodeType":882},{},[],{"data":23511,"content":23512,"nodeType":3025},{},[23513],{"data":23514,"content":23515,"nodeType":883},{},[23516],{"data":23517,"marks":23518,"value":20880,"nodeType":882},{},[],{"data":23520,"content":23521,"nodeType":3025},{},[23522],{"data":23523,"content":23524,"nodeType":883},{},[23525],{"data":23526,"marks":23527,"value":20890,"nodeType":882},{},[],{"data":23529,"content":23530,"nodeType":883},{},[23531],{"data":23532,"marks":23533,"value":21,"nodeType":882},{},[],{"items":23535},[23536,23538],{"sys":23537,"name":2308},{"id":2307},{"sys":23539,"name":343},{"id":2304},{"items":23541},[23542],{"fullName":3911,"firstName":3912,"jobTitle":3913,"profilePicture":23543},{"url":3915},{"__typename":1365,"sys":23545,"content":23546,"title":19917,"synopsis":19918,"hashTags":59,"publishedDate":19919,"slug":19920,"tagsCollection":23976,"authorsCollection":23982},{"id":19412},{"json":23547},{"data":23548,"content":23549,"nodeType":1294},{},[23550,23557,23581,23586,23592,23607,23620,23623,23630,23643,23659,23679,23684,23697,23721,23726,23731,23744,23747,23754,23760,23767,23783,23796,23803,23825,23831,23838,23862,23868,23875,23881,23886,23889,23896,23902,23909,23914,23917,23924,23930,23936,23942,23952,23955,23961],{"data":23551,"content":23552,"nodeType":975},{},[23553],{"data":23554,"marks":23555,"value":19424,"nodeType":882},{},[23556],{"type":1012},{"data":23558,"content":23559,"nodeType":883},{},[23560,23563,23569,23572,23578],{"data":23561,"marks":23562,"value":19431,"nodeType":882},{},[],{"data":23564,"content":23565,"nodeType":929},{"uri":19434},[23566],{"data":23567,"marks":23568,"value":19439,"nodeType":882},{},[],{"data":23570,"marks":23571,"value":19443,"nodeType":882},{},[],{"data":23573,"content":23574,"nodeType":929},{"uri":19446},[23575],{"data":23576,"marks":23577,"value":19451,"nodeType":882},{},[],{"data":23579,"marks":23580,"value":19455,"nodeType":882},{},[],{"data":23582,"content":23585,"nodeType":963},{"target":23583},{"sys":23584},{"id":19460,"type":960,"linkType":961},[],{"data":23587,"content":23588,"nodeType":883},{},[23589],{"data":23590,"marks":23591,"value":19468,"nodeType":882},{},[],{"data":23593,"content":23594,"nodeType":883},{},[23595,23598,23604],{"data":23596,"marks":23597,"value":19475,"nodeType":882},{},[],{"data":23599,"content":23600,"nodeType":929},{"uri":19478},[23601],{"data":23602,"marks":23603,"value":19483,"nodeType":882},{},[],{"data":23605,"marks":23606,"value":19487,"nodeType":882},{},[],{"data":23608,"content":23609,"nodeType":883},{},[23610,23613,23617],{"data":23611,"marks":23612,"value":19494,"nodeType":882},{},[],{"data":23614,"marks":23615,"value":19499,"nodeType":882},{},[23616],{"type":1012},{"data":23618,"marks":23619,"value":1438,"nodeType":882},{},[],{"data":23621,"content":23622,"nodeType":967},{},[],{"data":23624,"content":23625,"nodeType":975},{},[23626],{"data":23627,"marks":23628,"value":19513,"nodeType":882},{},[23629],{"type":1012},{"data":23631,"content":23632,"nodeType":883},{},[23633,23636,23640],{"data":23634,"marks":23635,"value":19520,"nodeType":882},{},[],{"data":23637,"marks":23638,"value":19525,"nodeType":882},{},[23639],{"type":1045},{"data":23641,"marks":23642,"value":1438,"nodeType":882},{},[],{"data":23644,"content":23645,"nodeType":883},{},[23646,23649,23656],{"data":23647,"marks":23648,"value":19535,"nodeType":882},{},[],{"data":23650,"content":23651,"nodeType":929},{"uri":8231},[23652],{"data":23653,"marks":23654,"value":19543,"nodeType":882},{},[23655],{"type":927},{"data":23657,"marks":23658,"value":19547,"nodeType":882},{},[],{"data":23660,"content":23661,"nodeType":883},{},[23662,23665,23669,23672,23676],{"data":23663,"marks":23664,"value":19554,"nodeType":882},{},[],{"data":23666,"marks":23667,"value":19559,"nodeType":882},{},[23668],{"type":1012},{"data":23670,"marks":23671,"value":19563,"nodeType":882},{},[],{"data":23673,"marks":23674,"value":19568,"nodeType":882},{},[23675],{"type":1045},{"data":23677,"marks":23678,"value":19572,"nodeType":882},{},[],{"data":23680,"content":23683,"nodeType":963},{"target":23681},{"sys":23682},{"id":19577,"type":960,"linkType":961},[],{"data":23685,"content":23686,"nodeType":883},{},[23687,23690,23694],{"data":23688,"marks":23689,"value":19585,"nodeType":882},{},[],{"data":23691,"marks":23692,"value":19590,"nodeType":882},{},[23693],{"type":1012},{"data":23695,"marks":23696,"value":19594,"nodeType":882},{},[],{"data":23698,"content":23699,"nodeType":883},{},[23700,23703,23709,23712,23718],{"data":23701,"marks":23702,"value":19601,"nodeType":882},{},[],{"data":23704,"content":23705,"nodeType":929},{"uri":8638},[23706],{"data":23707,"marks":23708,"value":19608,"nodeType":882},{},[],{"data":23710,"marks":23711,"value":19612,"nodeType":882},{},[],{"data":23713,"content":23714,"nodeType":929},{"uri":8979},[23715],{"data":23716,"marks":23717,"value":19619,"nodeType":882},{},[],{"data":23719,"marks":23720,"value":3517,"nodeType":882},{},[],{"data":23722,"content":23725,"nodeType":963},{"target":23723},{"sys":23724},{"id":19627,"type":960,"linkType":961},[],{"data":23727,"content":23730,"nodeType":963},{"target":23728},{"sys":23729},{"id":19633,"type":960,"linkType":961},[],{"data":23732,"content":23733,"nodeType":883},{},[23734,23737,23741],{"data":23735,"marks":23736,"value":19641,"nodeType":882},{},[],{"data":23738,"marks":23739,"value":19646,"nodeType":882},{},[23740],{"type":1012},{"data":23742,"marks":23743,"value":19650,"nodeType":882},{},[],{"data":23745,"content":23746,"nodeType":967},{},[],{"data":23748,"content":23749,"nodeType":975},{},[23750],{"data":23751,"marks":23752,"value":19661,"nodeType":882},{},[23753],{"type":1012},{"data":23755,"content":23756,"nodeType":883},{},[23757],{"data":23758,"marks":23759,"value":19668,"nodeType":882},{},[],{"data":23761,"content":23762,"nodeType":2050},{},[23763],{"data":23764,"marks":23765,"value":19676,"nodeType":882},{},[23766],{"type":1012},{"data":23768,"content":23769,"nodeType":883},{},[23770,23773,23780],{"data":23771,"marks":23772,"value":21,"nodeType":882},{},[],{"data":23774,"content":23775,"nodeType":929},{"uri":6466},[23776],{"data":23777,"marks":23778,"value":19690,"nodeType":882},{},[23779],{"type":927},{"data":23781,"marks":23782,"value":19694,"nodeType":882},{},[],{"data":23784,"content":23785,"nodeType":883},{},[23786,23789,23793],{"data":23787,"marks":23788,"value":19701,"nodeType":882},{},[],{"data":23790,"marks":23791,"value":19706,"nodeType":882},{},[23792],{"type":1012},{"data":23794,"marks":23795,"value":19710,"nodeType":882},{},[],{"data":23797,"content":23798,"nodeType":2050},{},[23799],{"data":23800,"marks":23801,"value":289,"nodeType":882},{},[23802],{"type":1012},{"data":23804,"content":23805,"nodeType":883},{},[23806,23810,23818,23822],{"data":23807,"marks":23808,"value":21,"nodeType":882},{},[23809],{"type":1012},{"data":23811,"content":23812,"nodeType":929},{"uri":6345},[23813],{"data":23814,"marks":23815,"value":19733,"nodeType":882},{},[23816,23817],{"type":927},{"type":1012},{"data":23819,"marks":23820,"value":19738,"nodeType":882},{},[23821],{"type":1012},{"data":23823,"marks":23824,"value":19742,"nodeType":882},{},[],{"data":23826,"content":23827,"nodeType":883},{},[23828],{"data":23829,"marks":23830,"value":19749,"nodeType":882},{},[],{"data":23832,"content":23833,"nodeType":2050},{},[23834],{"data":23835,"marks":23836,"value":19757,"nodeType":882},{},[23837],{"type":1012},{"data":23839,"content":23840,"nodeType":883},{},[23841,23844,23850,23853,23859],{"data":23842,"marks":23843,"value":19764,"nodeType":882},{},[],{"data":23845,"content":23846,"nodeType":929},{"uri":3554},[23847],{"data":23848,"marks":23849,"value":19771,"nodeType":882},{},[],{"data":23851,"marks":23852,"value":19775,"nodeType":882},{},[],{"data":23854,"content":23855,"nodeType":929},{"uri":6520},[23856],{"data":23857,"marks":23858,"value":19782,"nodeType":882},{},[],{"data":23860,"marks":23861,"value":19786,"nodeType":882},{},[],{"data":23863,"content":23864,"nodeType":883},{},[23865],{"data":23866,"marks":23867,"value":19793,"nodeType":882},{},[],{"data":23869,"content":23870,"nodeType":2050},{},[23871],{"data":23872,"marks":23873,"value":19801,"nodeType":882},{},[23874],{"type":1012},{"data":23876,"content":23877,"nodeType":883},{},[23878],{"data":23879,"marks":23880,"value":19808,"nodeType":882},{},[],{"data":23882,"content":23885,"nodeType":963},{"target":23883},{"sys":23884},{"id":19813,"type":960,"linkType":961},[],{"data":23887,"content":23888,"nodeType":967},{},[],{"data":23890,"content":23891,"nodeType":975},{},[23892],{"data":23893,"marks":23894,"value":19825,"nodeType":882},{},[23895],{"type":1012},{"data":23897,"content":23898,"nodeType":883},{},[23899],{"data":23900,"marks":23901,"value":19832,"nodeType":882},{},[],{"data":23903,"content":23904,"nodeType":883},{},[23905],{"data":23906,"marks":23907,"value":19840,"nodeType":882},{},[23908],{"type":1012},{"data":23910,"content":23913,"nodeType":963},{"target":23911},{"sys":23912},{"id":19845,"type":960,"linkType":961},[],{"data":23915,"content":23916,"nodeType":967},{},[],{"data":23918,"content":23919,"nodeType":2050},{},[23920],{"data":23921,"marks":23922,"value":19857,"nodeType":882},{},[23923],{"type":1012},{"data":23925,"content":23926,"nodeType":883},{},[23927],{"data":23928,"marks":23929,"value":19864,"nodeType":882},{},[],{"data":23931,"content":23932,"nodeType":883},{},[23933],{"data":23934,"marks":23935,"value":19871,"nodeType":882},{},[],{"data":23937,"content":23938,"nodeType":883},{},[23939],{"data":23940,"marks":23941,"value":19878,"nodeType":882},{},[],{"data":23943,"content":23944,"nodeType":883},{},[23945,23949],{"data":23946,"marks":23947,"value":19886,"nodeType":882},{},[23948],{"type":1012},{"data":23950,"marks":23951,"value":19890,"nodeType":882},{},[],{"data":23953,"content":23954,"nodeType":967},{},[],{"data":23956,"content":23957,"nodeType":883},{},[23958],{"data":23959,"marks":23960,"value":7217,"nodeType":882},{},[],{"data":23962,"content":23963,"nodeType":883},{},[23964,23967,23973],{"data":23965,"marks":23966,"value":19906,"nodeType":882},{},[],{"data":23968,"content":23969,"nodeType":929},{"uri":19909},[23970],{"data":23971,"marks":23972,"value":3893,"nodeType":882},{},[],{"data":23974,"marks":23975,"value":3897,"nodeType":882},{},[],{"items":23977},[23978,23980],{"sys":23979,"name":7239},{"id":7238},{"sys":23981,"name":343},{"id":2304},{"items":23983},[23984],{"fullName":10659,"firstName":10660,"jobTitle":10661,"profilePicture":23985},{"url":10663},"blog\u002Fhow-to-avoid-the-browser-security-buyers-trap",{"json":23988},{"data":23989,"content":23990,"nodeType":1294},{},[23991],{"data":23992,"content":23993,"nodeType":883},{},[23994],{"data":23995,"marks":23996,"value":23997,"nodeType":882},{},[],"Securing the browser vs. securing the organization via the browser — what's the difference? Most browser security solutions defend against the browser being hacked, but these aren't the attacks that are actually leading to major breaches. ",{"id":7246,"publishedAt":23999},"2026-08-13T09:35:09.806Z",{"items":24001},[24002,24004],{"sys":24003,"name":298},{"id":7235},{"sys":24005,"name":7239},{"id":7238},{"items":24007},[24008,24010,24012,24014,24016,24018,24020,24022,24024,24026,24028,24030,24032,24034,24036,24038,24040,24042,24044,24046,24048,24050,24052],{"sys":24009,"name":298,"slug":299,"tier":31},{"id":295},{"sys":24011,"name":280,"slug":281,"tier":31},{"id":277},{"sys":24013,"name":415,"slug":416,"tier":31},{"id":412},{"sys":24015,"name":521,"slug":522,"tier":31},{"id":518},{"sys":24017,"name":343,"slug":344,"tier":31},{"id":340},{"sys":24019,"name":388,"slug":389,"tier":45},{"id":385},{"sys":24021,"name":512,"slug":513,"tier":45},{"id":509},{"sys":24023,"name":262,"slug":263,"tier":45},{"id":259},{"sys":24025,"name":573,"slug":574,"tier":45},{"id":570},{"sys":24027,"name":334,"slug":335,"tier":45},{"id":331},{"sys":24029,"name":325,"slug":326,"tier":45},{"id":322},{"sys":24031,"name":486,"slug":487,"tier":45},{"id":483},{"sys":24033,"name":316,"slug":317,"tier":45},{"id":313},{"sys":24035,"name":361,"slug":362,"tier":45},{"id":358},{"sys":24037,"name":397,"slug":398,"tier":45},{"id":394},{"sys":24039,"name":591,"slug":592,"tier":45},{"id":588},{"sys":24041,"name":289,"slug":290,"tier":45},{"id":286},{"sys":24043,"name":503,"slug":504,"tier":45},{"id":500},{"sys":24045,"name":459,"slug":460,"tier":45},{"id":456},{"sys":24047,"name":379,"slug":380,"tier":45},{"id":376},{"sys":24049,"name":623,"slug":624,"tier":45},{"id":620},{"sys":24051,"name":370,"slug":371,"tier":45},{"id":367},{"sys":24053,"name":244,"slug":245,"tier":45},{"id":241},"5C3_54ldAqXGDnFfNyrEkB5PAE-NWpPCxwC0yi4pkDk",{"id":24056,"title":24057,"authorsCollection":24058,"content":24066,"extension":228,"faqItemsCollection":24600,"faqTitle":59,"featured":6,"hashTags":59,"meta":24602,"metaTitle":24603,"ogImage":59,"postType":24604,"publishedDate":24605,"relatedBlogPostsCollection":24606,"slug":25022,"stem":25023,"subtitle":59,"summary":25024,"synopsis":25035,"sys":25036,"tagsCollection":25039,"topicsCollection":25043,"__hash__":25053},"blog\u002Fblog\u002Fproduct-release-march-2025.json","Product release: March 2025",{"items":24059},[24060],{"fullName":24061,"firstName":24062,"jobTitle":24063,"socialLinks":59,"profilePicture":24064},"Andy Waugh","Andy","VP Product",{"url":24065},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F3Rf76rJn6S9inMb4dUnAIJ\u002F0a787f8141d05b95300e2fe77c4493fa\u002FDSC_6868.jpg",{"json":24067,"links":24555},{"data":24068,"content":24069,"nodeType":1294},{},[24070,24077,24130,24136,24152,24159,24228,24234,24252,24259,24275,24291,24297,24304,24322,24329,24344,24359,24366,24384,24391,24415,24422,24438,24444,24460,24500,24543,24549],{"data":24071,"content":24072,"nodeType":975},{},[24073],{"data":24074,"marks":24075,"value":24076,"nodeType":882},{},[],"What's new this month:",{"data":24078,"content":24079,"nodeType":1454},{},[24080,24090,24100,24110,24120],{"data":24081,"content":24082,"nodeType":1419},{},[24083],{"data":24084,"content":24085,"nodeType":883},{},[24086],{"data":24087,"marks":24088,"value":24089,"nodeType":882},{},[],"Add app banners to custom URLs",{"data":24091,"content":24092,"nodeType":1419},{},[24093],{"data":24094,"content":24095,"nodeType":883},{},[24096],{"data":24097,"marks":24098,"value":24099,"nodeType":882},{},[],"Self-service SAML for the Push platform",{"data":24101,"content":24102,"nodeType":1419},{},[24103],{"data":24104,"content":24105,"nodeType":883},{},[24106],{"data":24107,"marks":24108,"value":24109,"nodeType":882},{},[],"Support for Island enterprise browser",{"data":24111,"content":24112,"nodeType":1419},{},[24113],{"data":24114,"content":24115,"nodeType":883},{},[24116],{"data":24117,"marks":24118,"value":24119,"nodeType":882},{},[],"Landing page browser enrollment option",{"data":24121,"content":24122,"nodeType":1419},{},[24123],{"data":24124,"content":24125,"nodeType":883},{},[24126],{"data":24127,"marks":24128,"value":24129,"nodeType":882},{},[],"Improved filters for apps, accounts, and more",{"data":24131,"content":24132,"nodeType":975},{},[24133],{"data":24134,"marks":24135,"value":24089,"nodeType":882},{},[],{"data":24137,"content":24138,"nodeType":883},{},[24139,24143,24148],{"data":24140,"marks":24141,"value":24142,"nodeType":882},{},[],"You can now ",{"data":24144,"marks":24145,"value":24147,"nodeType":882},{},[24146],{"type":1012},"add app banners to a custom-defined URL or URL pattern",{"data":24149,"marks":24150,"value":24151,"nodeType":882},{},[],". Previously, app banners displayed only on login and signup pages for configured apps. With this update, you can put them on any page you like. ",{"data":24153,"content":24154,"nodeType":883},{},[24155],{"data":24156,"marks":24157,"value":24158,"nodeType":882},{},[],"That means you can:",{"data":24160,"content":24161,"nodeType":1454},{},[24162,24181,24199,24218],{"data":24163,"content":24164,"nodeType":1419},{},[24165],{"data":24166,"content":24167,"nodeType":883},{},[24168,24172,24177],{"data":24169,"marks":24170,"value":24171,"nodeType":882},{},[],"Remind employees ",{"data":24173,"marks":24174,"value":24176,"nodeType":882},{},[24175],{"type":1012},"not to store credentials",{"data":24178,"marks":24179,"value":24180,"nodeType":882},{},[]," or sensitive information on internal wikis.",{"data":24182,"content":24183,"nodeType":1419},{},[24184],{"data":24185,"content":24186,"nodeType":883},{},[24187,24191,24196],{"data":24188,"marks":24189,"value":24190,"nodeType":882},{},[],"Require acknowledgement of your security policies when using ",{"data":24192,"marks":24193,"value":24195,"nodeType":882},{},[24194],{"type":1012},"high-value GitHub repos",{"data":24197,"marks":24198,"value":1438,"nodeType":882},{},[],{"data":24200,"content":24201,"nodeType":1419},{},[24202],{"data":24203,"content":24204,"nodeType":883},{},[24205,24209,24214],{"data":24206,"marks":24207,"value":24208,"nodeType":882},{},[],"Ask employees not to share sensitive information when using ",{"data":24210,"marks":24211,"value":24213,"nodeType":882},{},[24212],{"type":1012},"GenAI tools",{"data":24215,"marks":24216,"value":24217,"nodeType":882},{},[]," during an unauthenticated session.",{"data":24219,"content":24220,"nodeType":1419},{},[24221],{"data":24222,"content":24223,"nodeType":883},{},[24224],{"data":24225,"marks":24226,"value":24227,"nodeType":882},{},[],"Or anything else you can think of!",{"data":24229,"content":24233,"nodeType":963},{"target":24230},{"sys":24231},{"id":24232,"type":960,"linkType":961},"6Jq3wMNCf1ns8zH6Z8tvGX",[],{"data":24235,"content":24236,"nodeType":883},{},[24237,24240,24249],{"data":24238,"marks":24239,"value":21,"nodeType":882},{},[],{"data":24241,"content":24245,"nodeType":21789},{"target":24242},{"sys":24243},{"id":24244,"type":960,"linkType":961},"2ti5f4Eh4teqnVkKDgztcm",[24246],{"data":24247,"marks":24248,"value":22668,"nodeType":882},{},[],{"data":24250,"marks":24251,"value":21,"nodeType":882},{},[],{"data":24253,"content":24254,"nodeType":975},{},[24255],{"data":24256,"marks":24257,"value":24258,"nodeType":882},{},[],"Self-service SAML for the Push admin console",{"data":24260,"content":24261,"nodeType":883},{},[24262,24266,24271],{"data":24263,"marks":24264,"value":24265,"nodeType":882},{},[],"It’s now ",{"data":24267,"marks":24268,"value":24270,"nodeType":882},{},[24269],{"type":1012},"easier to set up SAML for the Push admin console",{"data":24272,"marks":24273,"value":24274,"nodeType":882},{},[]," so your Push admins can log in using your SSO provider, such as Okta or Microsoft Entra ID. Once you’ve created the Push app in your identity provider, you can manage admin access via your IdP.",{"data":24276,"content":24277,"nodeType":883},{},[24278,24282,24287],{"data":24279,"marks":24280,"value":24281,"nodeType":882},{},[],"You can set up SAML yourself from the admin console by going to the ",{"data":24283,"marks":24284,"value":24286,"nodeType":882},{},[24285],{"type":1012},"Settings",{"data":24288,"marks":24289,"value":24290,"nodeType":882},{},[]," page and following the steps in the setup wizard.",{"data":24292,"content":24296,"nodeType":963},{"target":24293},{"sys":24294},{"id":24295,"type":960,"linkType":961},"23nEc3hEVCjENod1xpLW97",[],{"data":24298,"content":24299,"nodeType":883},{},[24300],{"data":24301,"marks":24302,"value":24303,"nodeType":882},{},[],"SAML for the Push platform is available at no additional cost.",{"data":24305,"content":24306,"nodeType":883},{},[24307,24310,24319],{"data":24308,"marks":24309,"value":21,"nodeType":882},{},[],{"data":24311,"content":24315,"nodeType":21789},{"target":24312},{"sys":24313},{"id":24314,"type":960,"linkType":961},"2SRHVwdI7xMYdyrMifgqog",[24316],{"data":24317,"marks":24318,"value":22668,"nodeType":882},{},[],{"data":24320,"marks":24321,"value":21,"nodeType":882},{},[],{"data":24323,"content":24324,"nodeType":975},{},[24325],{"data":24326,"marks":24327,"value":24328,"nodeType":882},{},[],"Push now supports Island enterprise browser",{"data":24330,"content":24331,"nodeType":883},{},[24332,24335,24340],{"data":24333,"marks":24334,"value":24142,"nodeType":882},{},[],{"data":24336,"marks":24337,"value":24339,"nodeType":882},{},[24338],{"type":1012},"install the Push browser agent on Island",{"data":24341,"marks":24342,"value":24343,"nodeType":882},{},[],", adding a powerful, complementary set of identity security controls to the enterprise browser.",{"data":24345,"content":24346,"nodeType":883},{},[24347,24351,24356],{"data":24348,"marks":24349,"value":24350,"nodeType":882},{},[],"With Island, you can deploy and activate the Push agent seamlessly ",{"data":24352,"marks":24353,"value":24355,"nodeType":882},{},[24354],{"type":1012},"without any end-user interaction",{"data":24357,"marks":24358,"value":1438,"nodeType":882},{},[],{"data":24360,"content":24361,"nodeType":883},{},[24362],{"data":24363,"marks":24364,"value":24365,"nodeType":882},{},[],"Push already provides managed deployment support for other major browsers, including Chrome, Edge, Firefox, Brave, Safari, and Arc. ",{"data":24367,"content":24368,"nodeType":883},{},[24369,24372,24381],{"data":24370,"marks":24371,"value":21,"nodeType":882},{},[],{"data":24373,"content":24377,"nodeType":21789},{"target":24374},{"sys":24375},{"id":24376,"type":960,"linkType":961},"3mUYngymmVLnXaRZSmii5Q",[24378],{"data":24379,"marks":24380,"value":22668,"nodeType":882},{},[],{"data":24382,"marks":24383,"value":21,"nodeType":882},{},[],{"data":24385,"content":24386,"nodeType":975},{},[24387],{"data":24388,"marks":24389,"value":24390,"nodeType":882},{},[],"New landing page browser enrollment option",{"data":24392,"content":24393,"nodeType":883},{},[24394,24398,24403,24407,24412],{"data":24395,"marks":24396,"value":24397,"nodeType":882},{},[],"As an alternative to Push’s email self-enrollment option for end-users, you can now invite employees to ",{"data":24399,"marks":24400,"value":24402,"nodeType":882},{},[24401],{"type":1012},"self-enroll and install the Push browser extension",{"data":24404,"marks":24405,"value":24406,"nodeType":882},{},[]," themselves by directing them to a ",{"data":24408,"marks":24409,"value":24411,"nodeType":882},{},[24410],{"type":1012},"landing page",{"data":24413,"marks":24414,"value":3517,"nodeType":882},{},[],{"data":24416,"content":24417,"nodeType":883},{},[24418],{"data":24419,"marks":24420,"value":24421,"nodeType":882},{},[],"Once employees visit the page, they’ll be prompted to verify their identity via OIDC login using your identity provider. Once confirmed, they’ll be prompted to install the Push extension and enrolled in Push.",{"data":24423,"content":24424,"nodeType":883},{},[24425,24428,24435],{"data":24426,"marks":24427,"value":21,"nodeType":882},{},[],{"data":24429,"content":24431,"nodeType":929},{"uri":24430},"\u002Fhelp\u002Faudience\u002Fadministrators\u002Fdocs\u002Finstall-the-browser-extension\u002F#self-enrollment-via-landing-page",[24432],{"data":24433,"marks":24434,"value":22668,"nodeType":882},{},[],{"data":24436,"marks":24437,"value":21,"nodeType":882},{},[],{"data":24439,"content":24440,"nodeType":975},{},[24441],{"data":24442,"marks":24443,"value":24129,"nodeType":882},{},[],{"data":24445,"content":24446,"nodeType":883},{},[24447,24451,24456],{"data":24448,"marks":24449,"value":24450,"nodeType":882},{},[],"We’ve improved the ",{"data":24452,"marks":24453,"value":24455,"nodeType":882},{},[24454],{"type":1012},"visibility and function of filters",{"data":24457,"marks":24458,"value":24459,"nodeType":882},{},[]," on pages in the Push admin console that help you explore and manage employees, apps, and accounts. You can also pin the filters you use the most and Push will remember your selection.",{"data":24461,"content":24462,"nodeType":883},{},[24463,24467,24472,24475,24480,24483,24488,24491,24496],{"data":24464,"marks":24465,"value":24466,"nodeType":882},{},[],"You’ll find the new filters under the keyword search on all the data tables in Push, including the ",{"data":24468,"marks":24469,"value":24471,"nodeType":882},{},[24470],{"type":1012},"Employees",{"data":24473,"marks":24474,"value":1993,"nodeType":882},{},[],{"data":24476,"marks":24477,"value":24479,"nodeType":882},{},[24478],{"type":1012},"Apps",{"data":24481,"marks":24482,"value":1993,"nodeType":882},{},[],{"data":24484,"marks":24485,"value":24487,"nodeType":882},{},[24486],{"type":1012},"Accounts",{"data":24489,"marks":24490,"value":2006,"nodeType":882},{},[],{"data":24492,"marks":24493,"value":24495,"nodeType":882},{},[24494],{"type":1012},"OAuth apps",{"data":24497,"marks":24498,"value":24499,"nodeType":882},{},[]," pages. Combine multiple filters to pinpoint useful data trends, such as:",{"data":24501,"content":24502,"nodeType":1454},{},[24503,24513,24523,24533],{"data":24504,"content":24505,"nodeType":1419},{},[24506],{"data":24507,"content":24508,"nodeType":883},{},[24509],{"data":24510,"marks":24511,"value":24512,"nodeType":882},{},[],"Which accounts are accessing SAML apps using passwords.",{"data":24514,"content":24515,"nodeType":1419},{},[24516],{"data":24517,"content":24518,"nodeType":883},{},[24519],{"data":24520,"marks":24521,"value":24522,"nodeType":882},{},[],"Which accounts are using verified stolen credentials.",{"data":24524,"content":24525,"nodeType":1419},{},[24526],{"data":24527,"content":24528,"nodeType":883},{},[24529],{"data":24530,"marks":24531,"value":24532,"nodeType":882},{},[],"Which employees do not have the Push browser extension.",{"data":24534,"content":24535,"nodeType":1419},{},[24536],{"data":24537,"content":24538,"nodeType":883},{},[24539],{"data":24540,"marks":24541,"value":24542,"nodeType":882},{},[],"And many more.",{"data":24544,"content":24548,"nodeType":963},{"target":24545},{"sys":24546},{"id":24547,"type":960,"linkType":961},"OAXAnXKt4TcLOlUpdQP3X",[],{"data":24550,"content":24551,"nodeType":883},{},[24552],{"data":24553,"marks":24554,"value":21,"nodeType":882},{},[],{"entries":24556},{"inline":24557,"hyperlink":24558,"block":24578},[],[24559,24565,24570],{"sys":24560,"__typename":24561,"title":24562,"slug":24563,"articleId":24564},{"id":24244},"HelpArticle","How to create a rule for app banners","how-to-create-a-configuration-rule-for-app-banners",10125,{"sys":24566,"__typename":24561,"title":24567,"slug":24568,"articleId":24569},{"id":24314},"Does the Push admin console support SAML login?","does-the-push-admin-console-support-saml-login",10123,{"sys":24571,"__typename":24572,"title":24573,"slug":24574,"audience":24575,"linkedFromParent":24576},{"id":24376},"DocumentationPage","Managed deployment with Island","managed-deployment-with-island","administrators",{"slug":24577},"install-the-browser-extension",[24579,24586,24593],{"sys":24580,"__typename":1329,"title":24581,"caption":59,"layoutMode":59,"file":24582},{"id":24232},"URL patterns - release notes - app banner example",{"url":24583,"width":24584,"height":24585},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F70271nJ74cjBb75HFbucYe\u002F49197f7b72610184fbf8fa99716a71a6\u002Furl_pattern_banner_example_github.png",1212,816,{"sys":24587,"__typename":1329,"title":24588,"caption":59,"layoutMode":59,"file":24589},{"id":24295},"SAML configuration - Settings page - KB 10123",{"url":24590,"width":24591,"height":24592},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F4eV1Lj4F6lHWgnReKc5r4j\u002Fb258219c4387d2a5168b75fa2a83be03\u002Fsaml_config_settings_page.png",1271,815,{"sys":24594,"__typename":1329,"title":24595,"caption":59,"layoutMode":59,"file":24596},{"id":24547},"Improved filters - release notes - March 2025",{"url":24597,"width":24598,"height":24599},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F3pSxsYhmPOGyulCgvKYQbr\u002F0beea438e1da6f787123178d5667147d\u002Fnew_filters_20250303.png",854,312,{"items":24601},[],{},"Push Security new product features for March 2025","release-notes","2025-03-11T00:00:00.000Z",{"items":24607},[24608],{"__typename":1365,"sys":24609,"content":24611,"title":25008,"synopsis":25009,"hashTags":59,"publishedDate":25010,"slug":25011,"tagsCollection":25012,"authorsCollection":25018},{"id":24610},"4Q2pQJXxzthIPAb79RtAML",{"json":24612},{"data":24613,"content":24614,"nodeType":1294},{},[24615,24621,24664,24671,24687,24703,24724,24730,24755,24775,24781,24797,24813,24819,24841,24860,24866,24882,24906,24939,24957,24963,24978,24985,24992],{"data":24616,"content":24617,"nodeType":975},{},[24618],{"data":24619,"marks":24620,"value":24076,"nodeType":882},{},[],{"data":24622,"content":24623,"nodeType":1454},{},[24624,24634,24644,24654],{"data":24625,"content":24626,"nodeType":1419},{},[24627],{"data":24628,"content":24629,"nodeType":883},{},[24630],{"data":24631,"marks":24632,"value":24633,"nodeType":882},{},[],"Detect verified stolen credentials without false positives",{"data":24635,"content":24636,"nodeType":1419},{},[24637],{"data":24638,"content":24639,"nodeType":883},{},[24640],{"data":24641,"marks":24642,"value":24643,"nodeType":882},{},[],"Enforce MFA directly in the browser",{"data":24645,"content":24646,"nodeType":1419},{},[24647],{"data":24648,"content":24649,"nodeType":883},{},[24650],{"data":24651,"marks":24652,"value":24653,"nodeType":882},{},[],"Detect internal apps and request support for unrecognized apps",{"data":24655,"content":24656,"nodeType":1419},{},[24657],{"data":24658,"content":24659,"nodeType":883},{},[24660],{"data":24661,"marks":24662,"value":24663,"nodeType":882},{},[],"Managed deployment support for Safari",{"data":24665,"content":24666,"nodeType":975},{},[24667],{"data":24668,"marks":24669,"value":24670,"nodeType":882},{},[],"Cut through false positives and find verified stolen credentials",{"data":24672,"content":24673,"nodeType":883},{},[24674,24678,24683],{"data":24675,"marks":24676,"value":24677,"nodeType":882},{},[],"Push now ",{"data":24679,"marks":24680,"value":24682,"nodeType":882},{},[24681],{"type":1012},"flags verified stolen credentials",{"data":24684,"marks":24685,"value":24686,"nodeType":882},{},[]," in use across your workforce identities by comparing threat intelligence data to fingerprints of passwords actively in use. ",{"data":24688,"content":24689,"nodeType":883},{},[24690,24694,24699],{"data":24691,"marks":24692,"value":24693,"nodeType":882},{},[],"This comparison allows us to ",{"data":24695,"marks":24696,"value":24698,"nodeType":882},{},[24697],{"type":1012},"discard all false positives",{"data":24700,"marks":24701,"value":24702,"nodeType":882},{},[]," from the TI sources, leaving you just with the verified true positives. ",{"data":24704,"content":24705,"nodeType":883},{},[24706,24710,24720],{"data":24707,"marks":24708,"value":24709,"nodeType":882},{},[],"With the rise in identity attacks stemming from ",{"data":24711,"content":24715,"nodeType":21789},{"target":24712},{"sys":24713},{"id":24714,"type":960,"linkType":961},"4OrixXXLxRmSDxa7PF9gfM",[24716],{"data":24717,"marks":24718,"value":24719,"nodeType":882},{},[],"stolen credentials",{"data":24721,"marks":24722,"value":24723,"nodeType":882},{},[],", we’re especially excited to get this feature into your hands to provide a reliable and high-fidelity source of information about which accounts are at critical risk of account takeover.",{"data":24725,"content":24729,"nodeType":963},{"target":24726},{"sys":24727},{"id":24728,"type":960,"linkType":961},"150dE4aTzofOwFXJCtGkJF",[],{"data":24731,"content":24732,"nodeType":883},{},[24733,24737,24742,24746,24751],{"data":24734,"marks":24735,"value":24736,"nodeType":882},{},[],"You can enable ",{"data":24738,"marks":24739,"value":24741,"nodeType":882},{},[24740],{"type":1012},"Stolen credential detection",{"data":24743,"marks":24744,"value":24745,"nodeType":882},{},[]," on the ",{"data":24747,"marks":24748,"value":24750,"nodeType":882},{},[24749],{"type":1012},"Controls",{"data":24752,"marks":24753,"value":24754,"nodeType":882},{},[]," page of the Push admin console. Get alerted to findings via ChatOps notification, webhook event, or in the UI.",{"data":24756,"content":24757,"nodeType":883},{},[24758,24762,24772],{"data":24759,"marks":24760,"value":24761,"nodeType":882},{},[],"To learn more about how we securely compare stolen cred reports to your employee credentials, check out our ",{"data":24763,"content":24767,"nodeType":21789},{"target":24764},{"sys":24765},{"id":24766,"type":960,"linkType":961},"6vCr4d3R1XA1E8dU883l7N",[24768],{"data":24769,"marks":24770,"value":24771,"nodeType":882},{},[],"blog post",{"data":24773,"marks":24774,"value":1438,"nodeType":882},{},[],{"data":24776,"content":24777,"nodeType":975},{},[24778],{"data":24779,"marks":24780,"value":24643,"nodeType":882},{},[],{"data":24782,"content":24783,"nodeType":883},{},[24784,24788,24793],{"data":24785,"marks":24786,"value":24787,"nodeType":882},{},[],"You can now use Push to prompt employees to register for MFA using our new ",{"data":24789,"marks":24790,"value":24792,"nodeType":882},{},[24791],{"type":1012},"MFA enforcement",{"data":24794,"marks":24795,"value":24796,"nodeType":882},{},[]," control.",{"data":24798,"content":24799,"nodeType":883},{},[24800,24804,24809],{"data":24801,"marks":24802,"value":24803,"nodeType":882},{},[],"End-users will see a banner in their browser ",{"data":24805,"marks":24806,"value":24808,"nodeType":882},{},[24807],{"type":1012},"when they use accounts that lack MFA protection",{"data":24810,"marks":24811,"value":24812,"nodeType":882},{},[],". As an administrator, you can select which apps you want to enforce MFA on, including apps not on SSO — or unmanaged apps you don’t even know about.",{"data":24814,"content":24818,"nodeType":963},{"target":24815},{"sys":24816},{"id":24817,"type":960,"linkType":961},"3XH0hnnhcZNI47PhdiD4q0",[],{"data":24820,"content":24821,"nodeType":883},{},[24822,24826,24830,24833,24837],{"data":24823,"marks":24824,"value":24825,"nodeType":882},{},[],"You can configure ",{"data":24827,"marks":24828,"value":24792,"nodeType":882},{},[24829],{"type":1012},{"data":24831,"marks":24832,"value":24745,"nodeType":882},{},[],{"data":24834,"marks":24835,"value":24750,"nodeType":882},{},[24836],{"type":1012},{"data":24838,"marks":24839,"value":24840,"nodeType":882},{},[]," page of the admin console.",{"data":24842,"content":24843,"nodeType":883},{},[24844,24847,24857],{"data":24845,"marks":24846,"value":21,"nodeType":882},{},[],{"data":24848,"content":24852,"nodeType":21789},{"target":24849},{"sys":24850},{"id":24851,"type":960,"linkType":961},"2WAc5HflKonFN7Jc53ROgj",[24853],{"data":24854,"marks":24855,"value":24856,"nodeType":882},{},[],"See how it works",{"data":24858,"marks":24859,"value":21,"nodeType":882},{},[],{"data":24861,"content":24862,"nodeType":975},{},[24863],{"data":24864,"marks":24865,"value":24653,"nodeType":882},{},[],{"data":24867,"content":24868,"nodeType":883},{},[24869,24873,24878],{"data":24870,"marks":24871,"value":24872,"nodeType":882},{},[],"Push can now ",{"data":24874,"marks":24875,"value":24877,"nodeType":882},{},[24876],{"type":1012},"detect internal corporate apps",{"data":24879,"marks":24880,"value":24881,"nodeType":882},{},[]," on non-publicly-accessible domains, such as apps with a domain of “.internal,” “.intranet,” or “.corp.” ",{"data":24883,"content":24884,"nodeType":883},{},[24885,24889,24894,24898,24902],{"data":24886,"marks":24887,"value":24888,"nodeType":882},{},[],"You can find internal apps listed in the ",{"data":24890,"marks":24891,"value":24893,"nodeType":882},{},[24892],{"type":1012},"Other apps",{"data":24895,"marks":24896,"value":24897,"nodeType":882},{},[]," slideout on the ",{"data":24899,"marks":24900,"value":24479,"nodeType":882},{},[24901],{"type":1012},{"data":24903,"marks":24904,"value":24905,"nodeType":882},{},[]," page in the Push admin console.",{"data":24907,"content":24908,"nodeType":883},{},[24909,24913,24918,24922,24926,24930,24935],{"data":24910,"marks":24911,"value":24912,"nodeType":882},{},[],"You can also now ",{"data":24914,"marks":24915,"value":24917,"nodeType":882},{},[24916],{"type":1012},"request support for any apps",{"data":24919,"marks":24920,"value":24921,"nodeType":882},{},[]," in the ",{"data":24923,"marks":24924,"value":24893,"nodeType":882},{},[24925],{"type":1012},{"data":24927,"marks":24928,"value":24929,"nodeType":882},{},[]," list that you use for work but which Push doesn’t immediately recognize as a commonly used work app. From the slideout, select ",{"data":24931,"marks":24932,"value":24934,"nodeType":882},{},[24933],{"type":1012},"Request app review",{"data":24936,"marks":24937,"value":24938,"nodeType":882},{},[],". Our team will take a look and add support as soon as possible.",{"data":24940,"content":24941,"nodeType":883},{},[24942,24945,24954],{"data":24943,"marks":24944,"value":21,"nodeType":882},{},[],{"data":24946,"content":24950,"nodeType":21789},{"target":24947},{"sys":24948},{"id":24949,"type":960,"linkType":961},"WciLKam7PCkbAASOdfiEw",[24951],{"data":24952,"marks":24953,"value":22668,"nodeType":882},{},[],{"data":24955,"marks":24956,"value":21,"nodeType":882},{},[],{"data":24958,"content":24959,"nodeType":975},{},[24960],{"data":24961,"marks":24962,"value":24663,"nodeType":882},{},[],{"data":24964,"content":24965,"nodeType":883},{},[24966,24970,24975],{"data":24967,"marks":24968,"value":24969,"nodeType":882},{},[],"With the release of macOS 15, Push now supports ",{"data":24971,"marks":24972,"value":24974,"nodeType":882},{},[24973],{"type":1012},"managed deployment of the Push browser extension on Safari",{"data":24976,"marks":24977,"value":1438,"nodeType":882},{},[],{"data":24979,"content":24980,"nodeType":883},{},[24981],{"data":24982,"marks":24983,"value":24984,"nodeType":882},{},[],"Using your MDM, you can now deploy and activate the Push agent seamlessly without any end-user interaction.",{"data":24986,"content":24987,"nodeType":883},{},[24988],{"data":24989,"marks":24990,"value":24991,"nodeType":882},{},[],"Push already provides managed deployment support for other major browsers, including Chrome, Edge, Firefox, Brave, and Arc. ",{"data":24993,"content":24994,"nodeType":883},{},[24995,24998,25005],{"data":24996,"marks":24997,"value":21,"nodeType":882},{},[],{"data":24999,"content":25001,"nodeType":929},{"uri":25000},"\u002Fhelp\u002Faudience\u002Fadministrators\u002Fdocs\u002Finstall-the-browser-extension\u002Fmanaged-deployment-using-an-mdm-on-macos\u002F#instructions-for-safari",[25002],{"data":25003,"marks":25004,"value":22668,"nodeType":882},{},[],{"data":25006,"marks":25007,"value":21,"nodeType":882},{},[],"Product release: December 2024","Here’s what’s new on the Push platform for December 2024.","2024-12-19T00:00:00.000Z","product-release-december-2024",{"items":25013},[25014],{"sys":25015,"name":25017},{"id":25016},"5jk0kqjSdSK2L0YiistQjY","Release notes",{"items":25019},[25020],{"fullName":24061,"firstName":24062,"jobTitle":24063,"profilePicture":25021},{"url":24065},"product-release-march-2025","blog\u002Fproduct-release-march-2025",{"json":25025},{"data":25026,"content":25027,"nodeType":1294},{},[25028],{"data":25029,"content":25030,"nodeType":883},{},[25031],{"data":25032,"marks":25033,"value":25034,"nodeType":882},{},[],"Add app banners to custom URLs, self-service SAML, and more","Here’s what’s new on the Push platform for March 2025.",{"id":25037,"publishedAt":25038},"4Aln4tyCmoffCEg6yiUO4J","2026-08-12T11:54:28.526Z",{"items":25040},[25041],{"sys":25042,"name":25017},{"id":25016},{"items":25044},[25045,25047,25049,25051],{"sys":25046,"name":298,"slug":299,"tier":31},{"id":295},{"sys":25048,"name":591,"slug":592,"tier":45},{"id":588},{"sys":25050,"name":582,"slug":583,"tier":45},{"id":579},{"sys":25052,"name":388,"slug":389,"tier":45},{"id":385},"dsCHv-29nQggNgMg_KRgn2NpSBc2OhgCH93lp_dch6M",1789500338284]