TMCnet News
Push Security and Proofpoint Partner to Unify Threat Protection From Inbox to Browser SessionPush Security today announced a partnership with Proofpoint to power new investigation, detection and response capabilities in Proofpoint Advanced Browser Protection. Push supplies real-time behavioral detection, in-session blocking and high-fidelity browser telemetry, with detections and session context feeding directly into Proofpoint's Threat Protection Workbench, Security Graph and Investigation Agent. Proofpoint Advanced Browser Protection is a new addition to Proofpoint's collaboration security platform, extending protection from the inbox to the browser session. The unification of browser and email security capabilities as part of the Push-Proofpoint collaboration reflects the evolution of modern attacks, which increasingly span both email and the browser. As enterprises continue to shore up email defenses, attackers are adapting their delivery techniques. Push data shows a growing number of malicious payloads now arrive outside of email entirely-via messaging apps, social media, search results, and malvertising-making the browser an increasingly important control point for detecting and stopping attacks. This pivot in attacker behavior demonstrates the critical need for browser security tools that can directly combat these techniques. A detection engine, not another intelligence feed Most tooling that claims browser coverage checks user navigation against indicators supplied from a feed: domains, URLs, IPs and file hashes. Attackers defeat this by rotating infrastructure faster than any feed can update. A phishing page that is spun up, used and torn down inside an hour is never on a blocklist while it's live. Push detects attacks by their behavior instead. Because Push operates inside the session and sees the fully rendered page, it analyzes page structure, script execution, credential-harvesting mechanics and user interaction to identify an attack on how it behaves rather than where it's hosted. This approach allows Push to detect MFA-bypassing phishing kits, both adversary-in-the-middle (AiTM) and device code phishing, based on toolkit behavior, as well as techniques like cloned login pages, browser-in-the-browser attacks, and the malicious copy-and-paste family of attacks - ClickFix, FileFix, ConsentFix nd InstallFix, and many more - that manipulate users into executing malicious commands. These attacks are detected regardless of infrastructure rotation because the detection is built on technique, not domain. What Push brings to Advanced Browser Protection Push contributes a browser-layer detection and response surface built by an in-house red and blue team whose research feeds directly into detection logic, including the ConsentFix and InstallFix attack classes Push discovered and named. Push product capabilities include:
Closing the gap between the inbox and the endpoint According to Omdia's 2026 Browser Management and Security report, 49% of organizations had suffered a confirmed successful browser-based attack in the preceding 12 months, and 88% ranked browser security among their top five security priorities. Those organizations are not short of security controls. Email security inspects the message before it reaches the inbox, and endpoint security inspects processes and files once something runs on the device. However, the browser session between those two points is covered by neither. "Attackers have been forced to adapt to modern email security by moving the attack into the browser - they now send phishing emails with benign links that only turn malicious after the user clicks." said Adam Bateman, CEO of Push Security. "Proofpoint was one of the first to recognize this shift, and we're excited to partner on an industry-first solution that covers the full attack chain, from inbox to browser." "The browser has become a critical control point for collaboration security, where attacks can continue after an email is delivered or originate outside email entirely," said Tom Corn, executive vice president and general manager, Threat Protection Group at Proofpoint. "By combining Push Security's browser expertise with Proofpoint's threat intelligence and detection capabilities, we're extending protection to the browser, giving security teams greater context to detect, investigate and respond to attacks." Availability: Proofpoint Advanced Browser Protection with Push Security detection capabilities is expected to be available in early 2027. Existing Push customers retain the full Push platform independently of the integration. About Push Security Push Security is the secure enterprise browser extension for security teams. Founded by red team and blue team experts, Push combines high-fidelity browser telemetry, real-time control, and autonomous agents to stop advanced attacks, secure AI usage, harden identities, and prevent data loss - all from users' existing browsers, no migration required. Push is backed by Decibel, GV (Google Ventures), Redpoint Ventures, Datadog Ventures, B3 Capital and other notable angel investors. For more information, visit pushsecurity.com or follow @pushsecurity.
View source version on businesswire.com: https://www.businesswire.com/news/home/20260929960549/en/ |

