Six Browser-Based Attack Techniques Every Australian SMB Should Watch in 2026
Security researchers warn that most cyber breaches now begin, and often stay, inside a web browser. Because staff use browsers to access nearly every business application, attackers have shifted their focus there too, using techniques that can slip past email filters and multi-factor authentication.
One major threat is adversary-in-the-middle phishing kits such as Tycoon2FA, Sneaky2FA and Evilginx. These tools intercept live login sessions in real time, stealing not just passwords but active session tokens, effectively bypassing MFA. Sold as ready-made Phishing-as-a-Service kits, they include anti-bot protection and automated lure generation, making sophisticated phishing available to almost anyone. Delivery has also moved beyond email: about half of phishing attacks now arrive via messaging apps, social media, SMS or malicious ads, and most phishing domains are only active for a day or two, making blocklists largely ineffective.
Another fast-growing technique, known as ClickFix, tricks users into copying and running malicious commands themselves, often disguised as a fix for a fake CAPTCHA or verification prompt. Microsoft data shows ClickFix behind nearly half of observed initial access attacks, and it has become the most common technique detected by researchers at Push in 2026. Most ClickFix payloads are encountered through compromised websites, malicious ads or manipulated search results rather than email, meaning it often bypasses traditional email security entirely.