Report by Push Security
2026 Browser Attack Techniques
6 FINDINGSPublished Mar 10, 2026
View Original Report →Key Findings
1 in 3 payloads intercepted by Push in 2025 were sent outside of email.
Payload
95% of in-browser attacks detected by Push used some form of bot protection service.
In-Browser AttackBot Protection Service
Of the last million logins Push saw, 1 in 4 were password logins, not SSO.
LoginPasswordSSO
Of the last million logins Push saw, 2 in 5 were not protected by MFA.
LoginMFA
Of the last million logins Push saw, 1 in 5 used a weak, breached, or reused password.
LoginPassword
4 in 5 ClickFix payloads intercepted by Push were accessed via search engines as the result of malvertising or infected webpages.
Payload MalvertisingInfected Webpages