Friday, 29 May 2026
  • Contact
  • Privacy Policy
  • Terms & Conditions
  • DMCA
logo logo
  • World
  • Politics
  • Crime
  • Economy
  • Tech & Science
  • Sports
  • Entertainment
  • More
    • Education
    • Celebrities
    • Culture and Arts
    • Environment
    • Health and Wellness
    • Lifestyle
  • 🔥
  • Trump
  • House
  • ScienceAlert
  • White
  • VIDEO
  • man
  • Trumps
  • Season
  • star
  • Years
Font ResizerAa
American FocusAmerican Focus
Search
  • World
  • Politics
  • Crime
  • Economy
  • Tech & Science
  • Sports
  • Entertainment
  • More
    • Education
    • Celebrities
    • Culture and Arts
    • Environment
    • Health and Wellness
    • Lifestyle
Follow US
© 2024 americanfocus.online – All Rights Reserved.
American Focus > Blog > Tech and Science > Browser-based attacks hit 95% of enterprises — and traditional security tools never saw them coming
Tech and Science

Browser-based attacks hit 95% of enterprises — and traditional security tools never saw them coming

Last updated: January 26, 2026 11:40 am
Share
Browser-based attacks hit 95% of enterprises — and traditional security tools never saw them coming
SHARE

The cybersecurity landscape is evolving rapidly, with browser-based attacks becoming increasingly prevalent. A recent Omdia study revealed that 95% of organizations experienced browser-based attacks last year, despite having robust security measures in place. Three high-profile campaigns in the past year have shed light on the severity of the threat posed by browser-based attacks.

ShadyPanda, Cyberhaven, and Trust Wallet are just a few examples of how attackers are exploiting vulnerabilities within browsers to infiltrate organizations and steal sensitive data. These attacks are not triggered by traditional security alerts, making them difficult to detect using conventional security tools.

According to Sam Evans, the CISO of Clearwater Analytics, the majority of employees spend a significant portion of their day using a web browser. This makes the browser a high-risk execution environment that is often overlooked as an attack surface. Modern adversaries are leveraging trusted browser sessions to bypass traditional security controls and gain access to sensitive information.

Elia Zaitsev, the CTO of CrowdStrike, highlights the shift in attacker tactics, noting that attackers are now focusing on exploiting valid identities, tokens, and access within trusted browser sessions. Traditional security architectures are ill-equipped to detect and prevent these types of attacks, as they were designed to inspect traffic before authentication, not behavior after access is granted.

The Omdia research underscores the limitations of traditional security stacks, with a significant percentage of encrypted traffic going uninspected and organizations lacking control over data shared in AI tools. The proliferation of browser extensions further complicates the security landscape, with many users unknowingly granting high-level permissions to extensions that can compromise their data.

See also  'Big Balls' is Back! - Now Working at the Social Security Administration |

Browser isolation solutions offered by companies like Menlo Security, Cloudflare, and Symantec aim to address rendering threats by executing web content in remote containers. However, these solutions do not protect against locally-run extensions with privileged access or session-based attacks that hijack authenticated tokens.

Three distinct attack patterns have emerged in recent years, including the long game, credential hijack, and API key leak. These attacks exploit vulnerabilities in browser extensions, auto-update mechanisms, and control planes to gain unauthorized access to sensitive data.

To combat these evolving threats, organizations must adopt browser-layer controls that provide visibility and control inside live browser sessions. By correlating browser behavior with identity posture, endpoint signals, and threat intelligence, organizations can detect and prevent session hijacking and data exfiltration in real-time.

Ultimately, the key to mitigating browser-based attacks lies in understanding the unique challenges posed by the modern browser environment and implementing proactive security measures that prioritize visibility and control. By treating the browser as the primary execution environment for enterprise work, organizations can enhance their cybersecurity posture and protect against emerging threats.

TAGGED:attacksBrowserbasedComingenterpriseshitSecuritytoolsTraditional
Share This Article
Twitter Email Copy Link Print
Previous Article Endometriosis, flu updates, autism research: Morning Rounds Endometriosis, flu updates, autism research: Morning Rounds
Next Article Women Who Defined Last Week’s Fashion Moments Women Who Defined Last Week’s Fashion Moments
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *


The reCAPTCHA verification period has expired. Please reload the page.

Popular Posts

5 aerospace breakthroughs of 2024

However, the X-59 aims to change that narrative by designing an aircraft that minimizes the…

December 31, 2024

Mickey Rourke ‘Ashamed’ of Behavior on Celebrity Big Brother UK

Mickey Rourke Apologizes for Controversial Behavior on Celebrity Big Brother UK Veteran actor Mickey Rourke…

April 14, 2025

George Morrison Painted a Different Picture of Abstract Expressionism 

The remarkable exhibition The Magical City: George Morrison’s New York at the Metropolitan Museum of…

October 7, 2025

Year 8 reading test plan splits teachers and heads

New polling data reveals that more educators endorse the government's initiative to implement a mandatory…

October 2, 2025

‘Newport Beach Film Festival Honors’ to Air Tonight on PBS SoCal

The 26th Annual Newport Beach Film Festival Honors, which showcased Variety’s 10 Actors to Watch…

January 12, 2026

You Might Also Like

Blue Origin’s New Glenn rocket explodes during testing in Florida
Tech and Science

Blue Origin’s New Glenn rocket explodes during testing in Florida

May 29, 2026
When The Dinosaur-Killing Asteroid Hit, This Life-Form Feasted On The Death : ScienceAlert
Tech and Science

When The Dinosaur-Killing Asteroid Hit, This Life-Form Feasted On The Death : ScienceAlert

May 29, 2026
Samsung Galaxy Z Fold Wide Dummy Unit Leaks
Tech and Science

Samsung Galaxy Z Fold Wide Dummy Unit Leaks

May 28, 2026
White House proposes new rules giving political appointees final approval on research grants
Tech and Science

White House proposes new rules giving political appointees final approval on research grants

May 28, 2026
logo logo
Facebook Twitter Youtube

About US


Explore global affairs, political insights, and linguistic origins. Stay informed with our comprehensive coverage of world news, politics, and Lifestyle.

Top Categories
  • Crime
  • Environment
  • Sports
  • Tech and Science
Usefull Links
  • Contact
  • Privacy Policy
  • Terms & Conditions
  • DMCA

© 2024 americanfocus.online –  All Rights Reserved.

Welcome Back!

Sign in to your account

Lost your password?