TL;DR: Browser-based attacks such as AiTM phishing, ClickFix, ConsentFix, and device code phishing are moving faster than defenses, with ClickFix becoming Microsoft’s most common initial access vector in about a year and device code phishing jumping from near-zero to at least 12 kits, according to Push Security. Traditional email, endpoint, and network controls are losing coverage because the attack and the identity workflow now happen inside the browser.
Editorial analysis by NHI Mgmt Group, based on content published by Push Security: “7 things we learned from âWhy the browser is the new battlegroundâ with John Hammond”.
By the numbers:
- Device code phishing went from near-zero to at least 12 distinct kits in a matter of months.
Key questions
Q: What breaks when identity controls stop at the endpoint and ignore the browser session?
A: Browser-native attacks can complete authentication, steal tokens, and trigger consent without host-level malware or suspicious process activity.
Q: Why do phishing frameworks that bypass MFA remain such a serious threat to identity security?
A: Phishing frameworks that bypass MFA are dangerous because they defeat a control many teams treat as a final barrier.
Q: What signs show that endpoint or email controls are missing browser-delivered identity attacks?
A: A common indicator is a clean mail queue paired with suspicious browser activity, unexpected OAuth grants, or sign-ins that originate from normal-looking web interactions.
Practitioner guidance
- Instrument browser-layer detections Add telemetry for browser-side redirects, consent prompts, clipboard injection, and device-code behaviour so identity abuse is visible before token issuance or command execution completes.
- Review OAuth consent exposure Tighten governance around consent grants, especially for user-driven app approvals and device-code workflows that can complete without a password or phishing-resistant factor challenge.
- Harden executive and developer workflows Assume high-value users will be targeted through search, messaging, and compromised websites, and tune monitoring for browser-delivered lures that never touch the mail gateway.
Bottom line: Browser-native attacks compress delivery and identity abuse into one surface, which reduces the value of controls that only inspect email, network, or endpoint artefacts.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Browser-first identity compromise has become the governance gap that IAM programmes keep underestimating. Traditional identity controls were built around login events, MFA prompts, and endpoint-visible execution, but these browser attacks exploit the space between them. The browser is now the control plane where authentication, consent, and session theft converge. Practitioners should treat browser-mediated identity abuse as a core IAM problem, not a peripheral phishing issue.
A few things that frame the scale:
- 1 in 4 organisations are already investing in dedicated NHI security capabilities, with an additional 60% planning to do so within the next twelve months, according to The State of Non-Human Identity Security.
- 45% of organisations cite lack of credential rotation as the top cause of NHI-related attacks, followed by inadequate monitoring and logging at 37% and over-privileged accounts at 37%.
A question worth separating out:
Q: How do organisations reduce the impact of stolen browser sessions?
A: Organisations reduce the impact of stolen browser sessions by shortening session lifetime, revoking tokens quickly, and watching for reuse across impossible locations or unusual devices. They should also separate high-risk administrative access from ordinary browser-based SaaS use so a stolen session does not unlock everything.
👉 Read our full editorial: Browser attacks are bypassing identity controls through the browser
Browser-first identity compromise has become the governance gap that IAM programmes keep underestimating. Traditional identity controls were built around login events, MFA prompts, and endpoint-visible execution, but these browser attacks exploit the space between them. The browser is now the control plane where authentication, consent, and session theft converge. Practitioners should treat browser-mediated identity abuse as a core IAM problem, not a peripheral phishing issue.
A few things that frame the scale:
- 1 in 4 organisations are already investing in dedicated NHI security capabilities, with an additional 60% planning to do so within the next twelve months, according to The State of Non-Human Identity Security.
- 45% of organisations cite lack of credential rotation as the top cause of NHI-related attacks, followed by inadequate monitoring and logging at 37% and over-privileged accounts at 37%.
A question worth separating out:
Q: How do organisations reduce the impact of stolen browser sessions?
A: Organisations reduce the impact of stolen browser sessions by shortening session lifetime, revoking tokens quickly, and watching for reuse across impossible locations or unusual devices. They should also separate high-risk administrative access from ordinary browser-based SaaS use so a stolen session does not unlock everything.
👉 Read our full editorial: Browser attacks are bypassing identity controls through the browser
Browser-mediated identity trust is now the primary control boundary: The browser is no longer just a delivery channel for identity events. It is where the lure, the user action, the authentication exchange, and the token handoff now converge. That changes the control boundary for IAM teams, because browser behaviour has become part of the trust decision itself. Practitioners should treat browser-layer observability as identity governance, not just endpoint hardening.
A question worth separating out:
Q: How should teams govern OAuth consent and device-code authentication safely?
A: Treat both as privileged identity pathways, not convenience features. Limit who can grant consent, monitor high-risk app approvals, and decide when device-code flow is acceptable in the enterprise. The goal is to govern the browser-mediated trust decision itself, because the attack succeeds when the user interaction looks legitimate but the resulting token is not.
👉 Read our full editorial: Browser attacks are bypassing identity controls through the browser