Push Security and Proofpoint Partner to Unify Threat Protection From Inbox to Browser Session

ⓘ This article is third-party content and does not represent the views of this site. We make no guarantees regarding its accuracy or completeness.

Push enables Proofpoint's Advanced Browser Protection capabilities with browser-native detection and response that stops browser-borne attacks targeting organizations today

Push Security today announced a partnership with Proofpoint to power new investigation, detection and response capabilities in Proofpoint Advanced Browser Protection. Push supplies real-time behavioral detection, in-session blocking and high-fidelity browser telemetry, with detections and session context feeding directly into Proofpoint's Threat Protection Workbench, Security Graph and Investigation Agent.

Proofpoint Advanced Browser Protection is a new addition to Proofpoint's collaboration security platform, extending protection from the inbox to the browser session.

The unification of browser and email security capabilities as part of the Push-Proofpoint collaboration reflects the evolution of modern attacks, which increasingly span both email and the browser.

As enterprises continue to shore up email defenses, attackers are adapting their delivery techniques. Push data shows a growing number of malicious payloads now arrive outside of email entirely—via messaging apps, social media, search results, and malvertising—making the browser an increasingly important control point for detecting and stopping attacks.

This pivot in attacker behavior demonstrates the critical need for browser security tools that can directly combat these techniques.

A detection engine, not another intelligence feed

Most tooling that claims browser coverage checks user navigation against indicators supplied from a feed: domains, URLs, IPs and file hashes. Attackers defeat this by rotating infrastructure faster than any feed can update. A phishing page that is spun up, used and torn down inside an hour is never on a blocklist while it's live.

Push detects attacks by their behavior instead. Because Push operates inside the session and sees the fully rendered page, it analyzes page structure, script execution, credential-harvesting mechanics and user interaction to identify an attack on how it behaves rather than where it's hosted.

This approach allows Push to detect MFA-bypassing phishing kits, both adversary-in-the-middle (AiTM) and device code phishing, based on toolkit behavior, as well as techniques like cloned login pages, browser-in-the-browser attacks, and the malicious copy-and-paste family of attacks – ClickFix, FileFix, ConsentFix and InstallFix, and many more – that manipulate users into executing malicious commands. These attacks are detected regardless of infrastructure rotation because the detection is built on technique, not domain.

What Push brings to Advanced Browser Protection

Push contributes a browser-layer detection and response surface built by an in-house red and blue team whose research feeds directly into detection logic, including the ConsentFix and InstallFix attack classes Push discovered and named.

Push product capabilities include:

  • Behavioral phishing detection and real-time blocking at the rendered page, regardless of the domain serving it or the channel that delivered the link, across authentication phishing techniques like AiTM and authorization phishing techniques like device code phishing.
  • Malicious copy-and-paste detection covering the x-Fix technique family, identifying the clipboard payload and the social engineering wrapper that delivers it.
  • Session hijacking detection through marker injection, which confirms a stolen session when a token created in a protected browser is replayed somewhere else.
  • OAuth consent controls, capturing client IDs, authorization servers and requested scopes, with the ability to remove unwanted or malicious OAuth connections.
  • Malicious browser extension detection, blocking and removal, plus supply chain monitoring for the ownership transfers and permission escalations that precede an extension being weaponized.
  • Forensic session reconstruction, assembling page loads, credential entry, clicks and token activity into a timeline an analyst can follow end to end.

Closing the gap between the inbox and the endpoint

According to Omdia's 2026 Browser Management and Security report, 49% of organizations had suffered a confirmed successful browser-based attack in the preceding 12 months, and 88% ranked browser security among their top five security priorities.

Those organizations are not short of security controls. Email security inspects the message before it reaches the inbox, and endpoint security inspects processes and files once something runs on the device. However, the browser session between those two points is covered by neither.

"Attackers have been forced to adapt to modern email security by moving the attack into the browser – they now send phishing emails with benign links that only turn malicious after the user clicks." said Adam Bateman, CEO of Push Security. "Proofpoint was one of the first to recognize this shift, and we're excited to partner on an industry-first solution that covers the full attack chain, from inbox to browser."

“The browser has become a critical control point for collaboration security, where attacks can continue after an email is delivered or originate outside email entirely,” said Tom Corn, executive vice president and general manager, Threat Protection Group at Proofpoint. “By combining Push Security’s browser expertise with Proofpoint’s threat intelligence and detection capabilities, we’re extending protection to the browser, giving security teams greater context to detect, investigate and respond to attacks.”

Availability: Proofpoint Advanced Browser Protection with Push Security detection capabilities is expected to be available in early 2027. Existing Push customers retain the full Push platform independently of the integration.

About Push Security

Push Security is the secure enterprise browser extension for security teams. Founded by red team and blue team experts, Push combines high-fidelity browser telemetry, real-time control, and autonomous agents to stop advanced attacks, secure AI usage, harden identities, and prevent data loss – all from users' existing browsers, no migration required. Push is backed by Decibel, GV (Google Ventures), Redpoint Ventures, Datadog Ventures, B3 Capital and other notable angel investors. For more information, visit pushsecurity.com or follow @pushsecurity.

"Attackers have been forced to adapt to modern email security by moving the attack into the browser. Proofpoint was one of the first to recognize this shift, and we're excited to partner." — Adam Bateman, Push CEO and co-founder

Contacts

Report this content

If you believe this article contains misleading, harmful, or spam content, please let us know.

Report this article

More News

View More

Recent Quotes

View More
Symbol Price Change (%)
AMZN  246.44
+0.29 (0.12%)
AAPL  331.80
-6.60 (-1.95%)
AMD  616.63
+8.76 (1.44%)
BAC  55.27
-0.20 (-0.35%)
GOOG  335.96
-3.20 (-0.94%)
META  722.95
+7.33 (1.02%)
MSFT  512.46
+3.24 (0.64%)
NVDA  230.81
+1.95 (0.85%)
ORCL  143.03
+10.43 (7.87%)
TSLA  354.91
-2.54 (-0.71%)
Stock Quote API & Stock News API supplied by www.cloudquote.io
Quotes delayed at least 20 minutes.
By accessing this page, you agree to the Privacy Policy and Terms Of Service.