Join our Newsletter — 33% off our NHI Course

Browser extension controls and ClickFix blocking: what changes for IAM teams

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20739
Topic starter  

TL;DR: Browser activity is being treated as a governed identity surface, not just a user interface, according to Push Security. The monthly update adds malicious browser extension detection, browser extension blocklists and allowlists, ClickFix-style attack blocking with payload capture, richer browser telemetry, and branding and RBAC changes, all aimed at improving browser-layer detection and control for end-user environments.

Editorial analysis by NHI Mgmt Group, based on content published by Push Security: “Product release: March 2026”.

Key questions

Q: What breaks when browser extensions are not governed in enterprise environments?

A: The main failure is that the browser becomes an unmanaged privilege zone.

Q: Why do ClickFix-style attacks matter for identity security teams?

A: They matter because they shift abuse into the user interaction layer, where the browser is used to persuade the user to paste or run malicious content.

Q: How do browser telemetry and payload capture help security investigations?

A: Telemetry provides the surrounding context that helps distinguish routine browser activity from attacker behaviour, while payload capture preserves the exact malicious content for analysis.

Practitioner guidance

  • Create browser extension allowlists and blocklists Define approved extension sets for managed endpoints, then block installation and enablement of all other extensions unless a documented exception exists.
  • Enable malicious extension detection with automatic enforcement Use malicious extension detections to warn or block when a known bad extension ID appears in the environment, and make sure the control maps to a documented triage workflow so detections are not left as passive alerts.
  • Treat ClickFix as a browser attack pattern Add copy-and-paste attack blocking for browser sessions, and route any captured payloads into investigation workflows so analysts can see the malicious instructions that users were asked to run.

Bottom line: Browser extensions are no longer just user convenience features. They can act as governed client-side capabilities that need explicit visibility and control.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 20 hours ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21545
 

Browser policy is becoming identity policy. Once extensions, banners, telemetry, and copy-and-paste controls all sit inside the browser, the browser becomes part of the trust boundary for human access. That matters because many identity programmes still treat the browser as a neutral access layer rather than an enforceable execution environment. The practitioner implication is that session governance now needs to include what the browser can load, paste, and persist.

A few things that frame the scale:

  • When AWS credentials are exposed publicly, attackers attempt access within an average of 17 minutes and as quickly as 9 minutes in some cases, according to LLMjacking: How Attackers Hijack AI Using Compromised NHIs.
  • DeepSeek accidentally embedded over 11,000 secrets in its training data and left a database exposed online, revealing more than one million sensitive records including chat histories, backend credentials, and API keys.

A question worth separating out:

Q: Who should own browser security controls that affect user access and investigation?

A: Ownership should sit with identity and security operations together, because browser controls now influence both enforcement and evidence collection. IAM teams should define policy and exception logic, while SOC or detection engineering teams tune the alerting and payload review. That split avoids leaving browser governance fragmented across endpoint, web, and identity functions.

👉 Read our full editorial: Browser extension controls and ClickFix blocking tighten IAM visibility



   
ReplyQuote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21545
 

Browser-layer governance is now part of identity control, not a separate endpoint concern. Extension install, enable, and execution choices change the trust profile of a user session just as much as an authentication event does. If IAM teams do not govern the browser surface, they leave a major part of identity behaviour outside policy enforcement. The practitioner conclusion is that browser controls belong in identity governance design, not only in endpoint tooling.

A question worth separating out:

Q: When should organisations disable or block browser extensions?

A: Block extensions when they have no clear business purpose, request broad access to content or sessions, or come from publishers that cannot be verified. Organisations should also disable extensions in high-risk roles and sensitive SaaS workflows where token theft would create immediate blast radius. The decision should be based on privilege, not convenience.

👉 Read our full editorial: Browser extension controls and ClickFix blocking tighten IAM visibility


This post was modified 20 hours ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.