Presented by CloudMosa
The shift towards conducting enterprise operations within web browsers has positioned them as a major target for cyberattacks. Industry reports highlight a significant increase in browser-based attacks over the past two years, with Gartner forecasting that by 2027, more than 85% of enterprise workloads will be accessed through browsers. Despite this shift, many enterprise security systems remain focused on safeguarding devices rather than the browser sessions where both work and attacks occur, says Shioupyn Shen, founder and CEO of CloudMosa, the developer of Puffin Cloud Security.
âCloudMosaâs initial cloud architecture aimed to enhance browser performance and accessibility, anticipating the transition of enterprise work into the browser,â Shen explains. âThe evolution of AI-assisted hacking has validated our architecture, showing that what was built for performance also underpins modern enterprise security.â
The Browser as the Enterpriseâs Operating Environment
With SaaS platforms, CRM and ERP systems, and collaboration tools centralizing operations in browsers, they have become the primary gateways for enterprise activities. As LLM-powered workflows and autonomous AI agents increasingly operate within this framework, the nature of threats has evolved.
In a device-focused environment, security teams concentrated on monitoring and managing endpoints, but the local execution of web code on user devices means every browser tab could potentially invite malicious scripts, credential theft, or other browser-based exploits. The browser now plays a crucial role, interpreting remote code, managing authenticated sessions, and serving as the execution layer for AI workflows.
âThe browser has transitioned from being just another application on the endpoint to the core operating environment for contemporary enterprise work,â Shen asserts. âTraditional browsers werenât designed for such enterprise-grade responsibilities, which demand strong isolation and policy enforcement.â
Why Detection-First Security Falls Short Against Browser-Based Attacks
Detection-first security faces a timing issue: it typically activates only after risky code reaches the device and starts executing in the browser. Modern browsers execute dynamic, often obfuscated JavaScript and WebAssembly locally, allowing attacks to act before endpoint tools can respond. Short-lived or fileless attacks might achieve their goals before security teams can react.
âItâs not enough to ask if a threat can be detected,â Shen emphasizes. âA stronger method is to stop risky or malicious code from ever reaching the device.â
AI-Generated Malware Challenges Signature-Based Detection
AI enables attackers to automate the creation and deployment of malware at a scale that signature-based tools cannot manage. It can rapidly generate numerous malware variants and help attackers adapt fileless and browser-delivered techniques faster than defenders can analyze them.
This is significant because polymorphic malware changes its code or behavior frequently, reducing the reliability of known signatures. With malware-free attacks relying on legitimate tools or malicious web content, there might be no conventional file signature to detect.
Enterprises have witnessed an 89% increase in AI-enabled attacks in the past year, as automated and adaptive attacks shorten the time available for detection and response.
âDefenders arenât just dealing with more threats; theyâre facing machines that can continually create new ones,â Shen observes. âWhat sufficed in the past decade wonât be enough in the coming months.â
Developing Architecture to Eliminate the Attack Surface
Rather than refining detection methods, a more sustainable solution is to change where web code can execute initially.
âIn a conventional browser, the risk comes to the device,â Shen says. âIn an isolated cloud model, the risk is kept away.â
This concept is central to Puffin Cloud Security. Instead of enhancing the browser itself, the platform moves browser execution to isolated cloud environments, boosting both performance and security.
The platform runs web sessions, including JavaScript, WebAssembly, and other executable payloads, in disposable cloud environments, streaming only a rendered pixel view to the device. Users maintain full interactive control, but the device never processes or stores the original active code.
CloudMosa claims that display rasterization accounts for about 5% of the browserâs total workload, while the more demanding HTML rendering stays isolated in the cloud. As a result, zero-day exploits and AI-generated polymorphic malware have no executable code on the endpoint, and fileless attacks within SaaS tools remain contained in the cloud.
âCloudMosa believes this shift moves security from being just adequate on the device to being airtight in the cloud,â Shen states.
Integrating Browser Isolation into SWG, CASB, and ZTNA Stacks
Puffin is designed to enhance, not replace, existing security infrastructures. Secure web gateways, cloud access security brokers, and zero trust network access tools remain effective for routing traffic and enforcing policies. However, they cannot completely prevent local execution once risky content reaches the browser.
Puffin addresses this by routing high-risk sessions through isolated cloud environments and enforcing browser-level policies, regardless of whether a user connects via a VPN, home network, managed device, or bring-your-own-device setup.
âOrganizations can begin with specific use cases, like high-risk SaaS access or AI agent workflows, and expand without disrupting existing tools,â Shen suggests. âThe aim is not to undo current investments but to make them more comprehensive.â
The Decision Between Faster Detection and Endpoint Isolation
Detection will always play a role in enterprise security, but the more critical question is whether attackers can reach the endpoint at all. Recent 2026 surveys show 92% of security professionals worry about AI agents, with 48% identifying agentic AI as the top attack vector of the year. Shen notes that agents with user-level privileges are particularly vulnerable to prompt injection, session hijacking, and indirect compromises through malicious web content.
In developing Puffin Cloud Security, CloudMosa took a âparanoid by designâ approach, investing in an architecture for worst-case scenarios where endpoint security and detection alone may not suffice.
âThis isnât just a philosophy; itâs reflected directly in the architecture,â Shen explains. âCloudMosa prepared for a tougher threat model than most organizations, and todayâs AI-assisted attacks make that stance increasingly relevant.â
By dividing the browser into a small layer on the device and a larger layer in the cloud, CloudMosa designed this approach to enhance both performance and security simultaneously. In Puffin Cloud Securityâs framework, an AI agentâs browser activity occurs within isolated cloud sandboxes. The endpoint only receives a pixel stream, preventing malicious web content from directly interacting with the device, its credentials, or connected systems.
âAI-assisted hacking represents a fundamental shift that benefits companies willing to rethink the browser from the ground up,â Shen asserts. âSecurity leaders now face a choice: redesign with foresight or learn the hard way later on.â
Sponsored articles are content produced by a company that is either paying for the post or has a business relationship with VentureBeat, and theyâre always clearly marked. For more information, contact sales@venturebeat.com.

