TL;DR: Attackers are increasingly bypassing exploit-based entry and using logins, stolen sessions, MFA gaps, and browser-based social engineering instead, according to Push Security’s recap of its conversation with Matt Johansen. The control problem is no longer just preventing compromise; it is governing identity, sessions, and browser trust assumptions that conventional perimeter tooling was not built to handle.
Editorial analysis by NHI Mgmt Group, based on content published by Push Security: “What we learned from 'Security Theater vs. Security That Works' with Matt Johansen”.
By the numbers:
- 82% of attack detections are now malware-free, according to CrowdStrike's 2026 Global Threat Report cited by Push Security.
- Identity issues were the initial access vector in 83% of cloud-related incidents, according to Google/Mandiant research cited by Push Security.
- A PhaaS kit rental runs about $1,000 per year, according to Push Security's article.
Key questions
Q: What breaks when browser attacks rely on logins instead of exploits?
A: The control model breaks because traditional prevention assumes intrusion begins with a technical vulnerability.
Q: Why do MFA and phishing-resistant login methods still leave browser risk behind?
A: They reduce the chance of credential capture, but they do not automatically govern OAuth tokens, consent grants, or active browser sessions.
Q: What are the signs that identity controls are not working as intended in the browser?
A: Common warning signs include false positives that users cannot distinguish from real warnings, high volumes of ignored alerts, repeated use of password logins where SSO should apply, and accounts that still show weak or reused credentials after remediation efforts.
Practitioner guidance
- Harden post-authentication controls Map every path where a successful login still leaves an attacker with usable access, including OAuth grants, session cookies, device code flows, and delegated consent.
- Inventory browser session dependencies Document which SaaS and cloud applications accept independent session tokens after IdP logout, because identity revocation is not effective if downstream sessions persist.
- Build browser-layer telemetry into detection Collect visibility into extension installations, consent grants, token use, and unusual browser session behaviour so the SOC can investigate identity abuse before it becomes lateral movement.
Bottom line: Browser attacks are increasingly identity-led, which means exploit prevention alone no longer matches the threat model.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Identity trust has shifted from the network edge into the browser session. That matters because the browser now mediates authentication, consent, extensions, and downstream SaaS access in one place. Security programmes that still treat the browser as a client rather than an identity control plane miss the point. The practitioner conclusion is that browser-layer identity telemetry belongs in IAM governance, not only in endpoint operations.
A few things that frame the scale:
- 98% of companies plan to deploy even more AI agents within the next 12 months, despite documented rogue behaviour in 80% of current deployments, according to AI Agents: The New Attack Surface report.
- Only 52% of companies can track and audit the data their AI agents access, leaving 48% with a complete blind spot for compliance and breach investigation.
A question worth separating out:
Q: What is the difference between MFA coverage and session control?
A: MFA controls how a user proves identity at login, while session control governs what happens after that login. If session tokens, OAuth grants, or browser cookies remain valid after revocation, MFA may be strong while the real access path stays open.
👉 Read our full editorial: Browser identity attacks are outpacing legacy security controls
Identity trust has shifted from the network edge into the browser session. That matters because the browser now mediates authentication, consent, extensions, and downstream SaaS access in one place. Security programmes that still treat the browser as a client rather than an identity control plane miss the point. The practitioner conclusion is that browser-layer identity telemetry belongs in IAM governance, not only in endpoint operations.
A few things that frame the scale:
- 98% of companies plan to deploy even more AI agents within the next 12 months, despite documented rogue behaviour in 80% of current deployments, according to AI Agents: The New Attack Surface report.
- Only 52% of companies can track and audit the data their AI agents access, leaving 48% with a complete blind spot for compliance and breach investigation.
A question worth separating out:
Q: What is the difference between MFA coverage and session control?
A: MFA controls how a user proves identity at login, while session control governs what happens after that login. If session tokens, OAuth grants, or browser cookies remain valid after revocation, MFA may be strong while the real access path stays open.
👉 Read our full editorial: Browser identity attacks are outpacing legacy security controls
Browser identity attacks are now an access governance problem, not just an anti-phishing problem: The central failure is that too many programmes still treat the browser as an endpoint issue while the real abuse happens in identity, session, and consent layers. Once access is granted, the attacker can operate inside trusted workflows without forcing a new security decision. Practitioners need to reframe browser activity as part of identity control, not merely user behaviour.
A question worth separating out:
Q: What should teams do when a stolen browser session is suspected?
A: Contain the session before the attacker can reuse it. Revoke or invalidate the token, review recent consent grants and browser activity, check for extension abuse, and examine whether the account was used to access administrative or data-heavy applications. The goal is to stop replay and identify what the session already touched.
👉 Read our full editorial: Browser identity attacks are outpacing legacy security controls