TL;DR: Browser activity is being treated as a governed identity surface, not just a user interface, according to Push Security. The monthly update adds malicious browser extension detection, browser extension blocklists and allowlists, ClickFix-style attack blocking with payload capture, richer browser telemetry, and branding and RBAC changes, all aimed at improving browser-layer detection and control for end-user environments.
At a glance
What this is: This monthly update adds browser extension detection and blocking, ClickFix-style attack controls, telemetry enrichment, and branding and RBAC changes to Push Security's browser-layer governance model.
Why it matters: It matters because IAM teams increasingly have to govern browser behaviour as part of identity visibility, especially when extensions and copy-and-paste attack paths can bypass traditional perimeter assumptions.
Context
The browser has become a governed identity surface because attackers increasingly use extensions, copy-and-paste workflows, and in-browser prompts to bypass standard security controls. When those paths are unmanaged, the identity programme loses visibility into what users install, approve, and execute inside the browser.
For IAM and NHI teams, the practical issue is not just detection but control placement. Browser-layer policy now sits alongside identity governance, because extension permissions, user-facing blocks, and telemetry collection all affect how much trust the programme can safely assign to an endpoint session.
Key questions
Q: What breaks when browser extensions are not governed in enterprise environments?
A: The main failure is that the browser becomes an unmanaged privilege zone. Extensions can read cookies, session tokens, page content, and tabs, which means they may access authenticated workflows without appearing in IAM or PAM reports. Once permission drift is added, the original approval no longer describes actual risk.
Q: Why do ClickFix-style attacks matter for identity security teams?
A: They matter because they shift abuse into the user interaction layer, where the browser is used to persuade the user to paste or run malicious content. That bypasses many conventional malware assumptions and turns social engineering into a control problem. Identity teams need to treat that browser interaction as part of session risk, not just a user awareness issue.
Q: How do browser telemetry and payload capture help security investigations?
A: Telemetry provides the surrounding context that helps distinguish routine browser activity from attacker behaviour, while payload capture preserves the exact malicious content for analysis. Together they improve attribution, reduce ambiguity, and give investigators evidence they can use to understand how the attack entered and what it tried to do next.
Q: When should organisations disable or block browser extensions?
A: Block extensions when they have no clear business purpose, request broad access to content or sessions, or come from publishers that cannot be verified. Organisations should also disable extensions in high-risk roles and sensitive SaaS workflows where token theft would create immediate blast radius. The decision should be based on privilege, not convenience.
Technical breakdown
Malicious browser extension detection and enforcement
Browser extensions are effectively privileged client-side code. If an extension ID matches a known malicious signature, the control can raise a detection, warn the user, or block execution before the extension becomes active in the environment. This shifts the control plane from post-incident review to pre-use enforcement. The important mechanism is that blocklists and allowlists are enforced against extension identity, not just user behaviour, so the organisation can define which browser capabilities are acceptable at install or enable time.
Practical implication: govern browser extension identity the same way you govern other high-risk client-side software.
ClickFix-style attacks and payload capture
ClickFix-style attacks exploit user trust by presenting malicious instructions that lead the user to paste or run payloads in the browser context. Blocking these attacks requires recognising the interaction pattern, not only the final payload. Payload capture adds evidentiary value because it preserves the malicious content for triage and hunt operations. That turns a user-led social engineering path into something security teams can investigate as a repeatable browser-based attack pattern rather than an isolated user mistake.
Practical implication: pair browser blocking with payload preservation so investigations have artefacts, not just alerts.
Telemetry retention and detection fidelity
Additional browser metadata improves detection precision because many browser-based attacks are ambiguous until the surrounding context is available. Local storage for up to 30 days gives the control a short-lived evidence window that can support richer detection logic without sending every detail upstream immediately. The trade-off is governance: more metadata increases investigative value, but it also creates retention and scope questions that must be aligned with policy. Monitor-only detections are useful here, but only if teams know which signals can safely escalate to enforcement.
Practical implication: define retention and escalation rules before turning on higher-fidelity browser telemetry.
Threat narrative
Attacker objective: The attacker wants to turn the browser into a trusted execution and deception layer that supports persistence, credential harvesting, or user-driven payload execution.
- Entry occurs when a user is exposed to a malicious browser extension or a ClickFix-style browser prompt that looks legitimate enough to trigger interaction.
- Credential or control abuse follows when the extension or pasted payload gains browser-level execution context and uses that trust to alter user actions or session behaviour.
- Impact lands in the browser layer, where attackers gain persistence, broaden visibility into user activity, or trigger follow-on phishing and data theft attempts through a trusted client-side surface.
Breaches seen in the wild
- GlassWorm campaign 2025: GlassWorm hid in VS Code extensions with invisible Unicode and stole npm, GitHub and Open VSX publishing tokens to spread.
Read and download The State of NHI & AI Agent Breach Report 2026, covering 200+ breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Browser-layer governance is now part of identity control, not a separate endpoint concern. Extension install, enable, and execution choices change the trust profile of a user session just as much as an authentication event does. If IAM teams do not govern the browser surface, they leave a major part of identity behaviour outside policy enforcement. The practitioner conclusion is that browser controls belong in identity governance design, not only in endpoint tooling.
Browser extensions behave like unmanaged client-side identities when their lifecycle is not controlled. A malicious extension is not simply software in the abstract; it is a durable capability that can act inside a user session with more persistence than the user realises. That makes extension allowlists, blocklists, and detection rules a practical control boundary for NHI-adjacent governance. The conclusion is that extension identity needs inventory, approval, and revocation semantics.
ClickFix changes the control problem from malware detection to interaction governance. The attack does not depend on a classic payload path in the same way as traditional malware, so the security team has to recognise a copy-and-paste prompt as an attack vector in its own right. That widens the scope of browser defence from content filtering to behavioural control. The practitioner conclusion is that social engineering in the browser must be treated as an enforceable policy domain.
Browser telemetry becomes more valuable when it can support attribution and containment, not just alerting. Richer metadata, retained for a bounded period, helps separate routine browsing from attacker tradecraft that would otherwise look similar. That also creates a governance requirement around what is stored, how long it lives, and who can use it. The conclusion is that browser telemetry should be designed for investigation quality, not only detection volume.
What this signals
Browser extension governance is now a lifecycle issue. Allowlisting, blocking, and exception handling only work if ownership and review are explicit. That means the browser extension estate should be treated like any other controlled identity-adjacent asset, with approval, revocation, and ongoing visibility in one programme.
ClickFix is a reminder that user interaction can be a security primitive. Security teams often separate authentication events from what users do after login, but browser-based attacks exploit the space in between. The practical signal is that session protection needs policy on user interaction paths, not only on login and endpoint state.
For practitioners
- Create browser extension allowlists and blocklists Define approved extension sets for managed endpoints, then block installation and enablement of all other extensions unless a documented exception exists. Keep the policy tied to browser and user group scope so high-risk teams can be treated differently from low-risk roles.
- Enable malicious extension detection with automatic enforcement Use malicious extension detections to warn or block when a known bad extension ID appears in the environment, and make sure the control maps to a documented triage workflow so detections are not left as passive alerts.
- Treat ClickFix as a browser attack pattern Add copy-and-paste attack blocking for browser sessions, and route any captured payloads into investigation workflows so analysts can see the malicious instructions that users were asked to run.
- Set metadata retention and escalation rules If browser event storage is enabled, decide which metadata fields support detection, how long local retention is acceptable, and which detections remain monitor-only versus blocked.
Key takeaways
- Browser extensions are no longer just user convenience features. They can act as governed client-side capabilities that need explicit visibility and control.
- ClickFix-style attacks push identity teams to look at browser interaction paths as attack surfaces. That changes where policy enforcement and evidence collection need to happen.
- The operational answer is to combine extension governance, browser telemetry, and enforcement rules in one browser-layer control model.
Key terms
- Browser Extension Allowlist: A browser extension allowlist is the approved set of extensions that are allowed to run in an organisation. It replaces broad trust with explicit approval, so every other extension is blocked by default and only tools with a declared business purpose are permitted.
- ClickFix-Style Attack: A ClickFix-style attack uses social engineering to persuade a user to copy and paste malicious content into a browser or application workflow. The danger is not the prompt alone but the execution path it triggers, which can bypass traditional email and login controls.
- Browser telemetry: Browser telemetry is the event data produced by enterprise browser activity, including logins, profile changes, downloads, session starts, and extension or site interactions. In identity governance, it becomes useful when those events are correlated with account state and privilege context rather than treated as generic activity logs.
- Identity-Adjacent Control: A security control that is not itself IAM, but directly affects authentication, access, or recovery outcomes. Email security often functions this way because mailbox compromise can trigger resets, approvals, and session abuse.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are responsible for identity security strategy or NHI governance in your organisation, it is worth exploring.
Published by the NHIMG editorial team on June 9, 2026.
Updated on October 10, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org