VMTech
Discuss a project →

Six browser attack techniques security teams must track in 2026

Six browser attack techniques security teams must track in 2026

Browser-based attacks are increasingly concentrating the full breach chain in a single user session, from initial access to data exfiltration. Push Security identifies six techniques for security teams to track in 2026: credential and session phishing, ClickFix copy-and-paste lures, authorization phishing, malicious extensions, credential stuffing and ghost logins, and session hijacking.

ClickFix became Push's dominant detection category for the first time in the second quarter of 2026, reaching 52% of total detections. Microsoft's Digital Defense Report identified the technique as the most common initial-access vector in observed attacks, accounting for 47%. It typically presents a fake CAPTCHA or verification prompt that persuades a user to copy and execute a malicious command locally.

Phishing is moving beyond passwords and email

Modern adversary-in-the-middle phishing kits, including Tycoon2FA, Sneaky2FA and Evilginx, can relay credentials and live session tokens in real time. That allows an attacker to bypass many MFA protections through session replay. These kits are offered as Phishing-as-a-Service products with features such as anti-bot controls, dynamic lures and automated replay.

Delivery channels also extend beyond email to instant messaging, social media, SMS, malicious advertising and in-app messages. Push reports that roughly one in two phishing attacks arrives outside email, while 89% of phishing domains remain active for fewer than two days. Those figures highlight the limits of blocklists that depend on domains remaining available long enough to be identified and blocked.

ClickFix lures lead users to run malware, often remote-access tools or infostealers, on their devices. Push says four in five intercepted ClickFix payloads are reached through search engines, compromised websites, malvertising or SEO poisoning. InstallFix has used fake developer-tool installation pages for Claude Code and NotebookLM, while the LLMShare campaign used shared AI chatbot conversations hosted on trusted domains.

OAuth, extensions and alternative login paths broaden exposure

Authorization phishing targets access granted after a user signs in rather than the authentication process itself. Consent phishing persuades a victim to approve a malicious third-party OAuth application. Device code phishing abuses the RFC 8628 device authorization grant, and Push tracks more than 30 distinct kits offering the technique. ConsentFix combines ClickFix with OAuth abuse and was first observed in Russian APT29 campaigns before becoming available in criminal tooling.

Malicious browser extensions can log keystrokes and intercept data, credentials and tokens. Attackers may acquire legitimate extensions and issue a harmful update after the install base grows. Push's analysis found that 46.76% of extensions had permission combinations sufficient for account takeover without user interaction. Verizon's DBIR 2026 found unauthorized AI browser extensions on more than 15% of corporate users, and Push recorded an average of 17 unique AI extensions per company.

Tokens and passwords can bypass established controls

SSO does not eliminate password exposure when applications retain alternative sign-in methods. Push describes these residual credentials as ghost logins: accounts created during adoption that remain outside identity-provider logs unless they are explicitly disabled. In the last million logins observed by Push, one in four used passwords rather than SSO, two in five lacked MFA, and one in five used a weak, breached or reused password. Cloudflare's 2026 Threat Report found that 63% of human logins involve credentials compromised elsewhere.

Session hijacking takes a stolen token and replays it in another browser, bypassing authentication because the original sign-in has already occurred. Infostealer malware is a prominent source of such tokens, and ClickFix is now its primary delivery mechanism. The Verizon DBIR 2025 found that 46% of infostealer infections leading to corporate breaches originated on unmanaged devices, including personal machines, developer workstations and contractor laptops.

For businesses, the practical implication is to treat the browser as its own security layer: monitor extension changes and AI tool use, identify login methods outside SSO, and address browser-delivered prompts that can expose credentials, OAuth tokens or active sessions.

#cybersecurity#browsersecurity#phishing#identitysecurity
Open analytics
On the site 0 views
min read 5 30.09.2026
Instagram

Six browser attack techniques security teams must track in 2026

Open the post on Instagram ↗