Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

Browser and identity attacks matrix: are your controls keeping up?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 3789
Topic starter  

TL;DR: Attacker innovation is now concentrated in browser-based initial access techniques, with AiTM phishing, ClickFix, device code phishing, OAuth consent abuse, and malicious extensions increasingly driving SaaS and cloud compromise, according to Push Security. The old SaaS framing is giving way to browser-and-identity governance, where access review cycles and endpoint-only controls no longer match how compromise starts.

NHIMG editorial — based on content published by Push Security: Browser & Identity Attacks Matrix

By the numbers:

Questions worth separating out

Q: How should security teams govern browser-based identity attacks in cloud environments?

A: Treat the browser as part of the identity control plane.

Q: Why do browser attacks create more risk than traditional phishing for IAM teams?

A: Browser attacks often capture valid sessions, consents, or device-code approvals instead of passwords, so they bypass some classic authentication controls.

Q: What do security teams get wrong about device code phishing?

A: They often treat it like a niche phishing variant, when it is really an authorization abuse pattern.

Practitioner guidance

  • Map browser-mediated identity entry points Inventory where users authenticate, consent, approve device codes, and install extensions, then tie those paths to the identity provider rather than to endpoint tooling alone.
  • Constrain device authorization and consent flows Restrict device code flows to approved use cases, log every authorization grant, and alert on unusual consent patterns or unfamiliar client applications.
  • Govern browser extensions as supply chain assets Require approval for extension installs, track ownership changes, and continuously assess post-install behaviour for access to sessions, web content, and identity tokens.

What's in the full article

Push Security's full technical whitepaper covers the operational detail this post intentionally leaves for the source:

  • Browser attack family breakdowns for AiTM, ClickFix, ConsentFix, device code phishing, and malicious extensions
  • Observed delivery channels beyond email, including search, social media, messaging, and voice-assisted lures
  • Real-world technique timelines showing how browser-based initial access has industrialised over the last two years
  • Examples of how attackers chain browser identity abuse into SaaS access, token replay, and mass exfiltration

👉 Read Push Security's analysis of browser and identity attacks in SaaS compromise →

Browser and identity attacks matrix: are your controls keeping up?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 4 weeks ago
Posts: 2127
 

Browser identity attacks are now the organising layer for modern cloud compromise. The article is right to move beyond a SaaS-only label because the decisive action happens before the application layer is reached. Identity, not application logic, is where attackers now concentrate effort. Practitioners should interpret this as a shift in how attack surfaces are framed, measured, and defended.

A few things that frame the scale:

  • 80% of identity breaches involved compromised non-human identities such as service accounts and API keys, according to Ultimate Guide to NHIs.
  • 71% of NHIs are not rotated within recommended time frames, increasing the risk of compromise over time.

A question worth separating out:

Q: What should teams do when browser extensions can access identity workflows?

A: They should manage extensions like third-party software with identity reach, not like harmless productivity add-ons. That means approving what can be installed, tracking ownership changes, and reviewing whether an extension can read or modify authenticated web sessions. If an extension touches identity flows, it belongs in governance and monitoring scope.

👉 Read our full editorial: Browser and identity attacks now define modern SaaS compromise



   
ReplyQuote
Share: