Push Security’s cover photo
Push Security

Push Security

Computer and Network Security

Boston, Massachusetts 9,426 followers

The Secure Enterprise Browser Extension Built for the AI era

About us

Push Security is the secure enterprise browser extension for the AI era. Founded by red team and blue team experts, Push combines high-fidelity browser telemetry, real-time control, and autonomous agents to stop advanced attacks, secure AI usage, harden identities, and prevent data loss — all from your users’ existing browsers, no migration required.

Website
https://pushsecurity.com
Industry
Computer and Network Security
Company size
51-200 employees
Headquarters
Boston, Massachusetts
Type
Privately Held
Founded
2021
Specialties
Cyber security, SaaS, Enterprise software, Identity security, ISPM, ITDR, Detection, Response, Targeted attacks, IAM, and Phishing

Employees at Push Security

View 95 employees at Push Security

or

By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.

See all employees

Locations

Updates

  • Push gives you everything you need to ensure your employees use AI securely without killing productivity or driving usage into the shadows. 🔍 Discover all AI apps, extensions, and integrations 💬 Identify login methods and stop personal account/tenant use ⚠️ Guide employees to use approved tools and block unapproved ones 👥 Tailor rules to user groups to give them the access they need for their role 📁 Stop risky interactions with clipboard, file upload and download controls 🚫 Block unapproved agent connections via MCP servers 🔑 Revoke OAuth grants that give AI tools persistent access to your systems 🆕 New tools automatically inherit existing governance rules 📊 Stream AI interactions and chat telemetry to your SIEM Find and secure shadow AI in your environment using Push's free 30-day trial  👉 pushsecurity.com/shadowai

  • Push Security reposted this

    I’ve trawled my way through the latest Microsoft Digital Defense report so you don’t have to. Here’s what stood out to me (and some complaints about conflicting data sets): My main takeaway is that 𝐡𝐮𝐦𝐚𝐧 𝐚𝐧𝐝 𝐢𝐝𝐞𝐧𝐭𝐢𝐭𝐲 𝐟𝐨𝐜𝐮𝐬𝐞𝐝 𝐚𝐭𝐭𝐚𝐜𝐤𝐬 𝐦𝐚𝐝𝐞 𝐮𝐩 𝟕𝟑.𝟖% 𝐨𝐟 𝐚𝐥𝐥 𝐢𝐧𝐭𝐫𝐮𝐬𝐢𝐨𝐧𝐬, when you add up user execution (user tricked into running or downloading something) valid accounts (stolen creds and tokens), malicious copy-and-paste (ClickFix), and phishing (credential and session stealing attacks like AITM, device code, and so on). Every one of them involves social engineering a user to do something (valid accounts is a downstream consequence of the others). AiTM phishing is now the dominant phishing technique at 44.6% of all identified phishing techniques. Standard cred harvesting sits at 33.6% and traditional malicious attachments at just 12.9%. And actually, 89–96% of attachments then directed users to phishing pages. ClickFix attacks dropped from 47% of initial access activity to 13%. But at the same time, the number of ClickFix attacks increased 8x, and had a 96.3% conversion rate to successful malware delivery. So ClickFix hasn’t gone down: threats have diversified, and the overall volume of attacks is increasing. Arguably, ClickFix is more effective than ever. Device code phishing is acknowledged as a “preferred credential threat method” for both criminals and nation-state actors. But the scale shown is that device code phishing triggered 896 alerts over 180 days, compared to password spray at 124 million and AiTM at 151,000. There are definitely orders of magnitude here but given what we’re seeing about AiTM kits pivoting to device code, and our overall detection breakdown at Push, this probably shows a detection gap in the data set rather than a true representation of the scale. 𝐀𝐧𝐝 𝐧𝐨𝐰 𝐟𝐨𝐫 𝐦𝐲 𝐜𝐨𝐦𝐩𝐥𝐚𝐢𝐧𝐭𝐬: There are at least 4x different data sources that I can see and limited explanation of how to read each source. Example: you’ve got two charts that reference initial access techniques. One has phishing at 13%, the other at 23%. One comes from Microsoft Defender Experts, the other from Microsoft Threat Intelligence. But they don’t acknowledge that the other exists or why there’s a difference. The first source is basically what Microsoft detected. The second is from IR findings — i.e. what resulted in an actual breach. So i’d personally rate the fact that phishing went up from 7% to 23% in actual breach data as significant — it’s becoming more effective. But if you read the first chart alone, it looks like phishing is a middle-of-the-road issue. Cynically, I know that the point of these things is to mean something to everyone and be as quotable as possible. I think my 2024 meme still holds up... Link in the comments.

    • No alternative text description for this image
    • No alternative text description for this image
  • Push Security reposted this

    Big news: We've partnered with Proofpoint to power their new Advanced Browser Protection product. 🎉 As email security got better and better, attackers adapted. They send links that look harmless on delivery and turn malicious after the click, once you're in the browser. In the last 6 months, 47% of the phishing we've blocked came through other channels, like malvertising and search results. A year ago it was around 15%. So we're teaming up with Proofpoint to cover the whole attack: before, in, and after the inbox. More in our blog: https://lnkd.in/eieNv666

  • View organization page for Push Security

    9,426 followers

    We’re thrilled to announce a new partnership with Proofpoint, extending threat protection from the inbox to the browser session for Proofpoint customers. This partnership is a direct response to the evolution in how and where attackers target people as they work online. Phishing no longer stops at the inbox, so security can’t either. Learn more in the announcement from Adam Bateman 🔗 https://lnkd.in/eNgMuy9K

  • In Q2 2026, ClickFix attacks became the dominant attack type in our detections for the first time, at 52% of total detections. In August, it hit 67%. ClickFix-style malicious copy and paste attacks are incredibly simple: trick the victim into running a malicious command on your behalf. And its popularity with both criminal groups and nation-state threats tells you everything you need to know about how effective it is. Because we see the page and payload in the browser, Push intercepts ClickFix attacks before the malicious command reaches the user or touches the endpoint. Check out the report for our latest stats and intel: 🔗 https://lnkd.in/evR98Qbn

  • Push Security reposted this

    Shadow AI is really just Shadow IT. It shows up as unapproved apps, personal accounts, browser extensions, and OAuth integrations - most of it invisible to your network and endpoint tools. Push Security discovers all of it from real browser activity, governs usage with policies tailored to each team, and gives you the controls to intervene. Get a FREE trial of Push now and get a live look at the AI tools already running across your organization - plus the ability to enforce policy on the spot. Get your trial here >> https://lnkd.in/eFiXgha8

    • No alternative text description for this image
  • When we’re not shipping shadow AI inspired arcade games, we’re solving real shadow AI. In fact, tackling shadow AI with Push couldn’t be simpler. It’s probably easier than the game … If you want to discover, govern, and control shadow AI in your environment, you can try Push for free today using the link below. 🔗 https://lnkd.in/e7HtFSvp And if you missed the announcement yesterday, check out our 8-bit arcade game! 🕹️ https://lnkd.in/eR3Ugwb4 𝙒𝙚 𝙬𝙤𝙣’𝙩 𝙗𝙚 𝙝𝙚𝙡𝙙 𝙧𝙚𝙨𝙥𝙤𝙣𝙨𝙞𝙗𝙡𝙚 𝙛𝙤𝙧 𝙖𝙣𝙮 𝙡𝙤𝙨𝙨 𝙞𝙣 𝙥𝙧𝙤𝙙𝙪𝙘𝙩𝙞𝙫𝙞𝙩𝙮 𝙩𝙝𝙖𝙩 𝙢𝙖𝙮 𝙤𝙘𝙘𝙪𝙧 ... 

  • View organization page for Push Security

    9,426 followers

    Shadow AI is just Shadow IT. So we built a retro arcade game for this retro problem. We give you... 🥁 🥁 👻 SHADOW AI BUSTERS 🔦 Use your trusty Push Security flashlight to find AI risks lurking in the shadows. Shadow AI apps, risky AI extensions and connections, sensitive data uploads. They’re all out there and they need busting. Is this important security work? No. Is it fun? Yes. Treat yourself for once. 🕹️ Check it out 👉 pushsecurity.com/busters

    • No alternative text description for this image

Similar pages

Browse jobs