Friday, 7 Aug 2026
  • Contact
  • Privacy Policy
  • Terms & Conditions
  • DMCA
logo logo
  • World
  • Politics
  • Crime
  • Economy
  • Tech & Science
  • Sports
  • Entertainment
  • More
    • Education
    • Celebrities
    • Culture and Arts
    • Environment
    • Health and Wellness
    • Lifestyle
  • đŸ”„
  • Trump
  • House
  • White
  • ScienceAlert
  • VIDEO
  • man
  • Trumps
  • Season
  • star
  • Years
Font ResizerAa
American FocusAmerican Focus
Search
  • World
  • Politics
  • Crime
  • Economy
  • Tech & Science
  • Sports
  • Entertainment
  • More
    • Education
    • Celebrities
    • Culture and Arts
    • Environment
    • Health and Wellness
    • Lifestyle
Follow US
© 2024 americanfocus.online – All Rights Reserved.
American Focus > Blog > Tech and Science > The browser is where attacks land. Why is security still focused on the endpoint?
Tech and Science

The browser is where attacks land. Why is security still focused on the endpoint?

Last updated: August 7, 2026 10:45 pm
Share
The browser is where attacks land. Why is security still focused on the endpoint?
SHARE

Contents
The Browser as the Enterprise’s Operating EnvironmentWhy Detection-First Security Falls Short Against Browser-Based AttacksAI-Generated Malware Challenges Signature-Based DetectionDeveloping Architecture to Eliminate the Attack SurfaceIntegrating Browser Isolation into SWG, CASB, and ZTNA StacksThe Decision Between Faster Detection and Endpoint Isolation

Presented by CloudMosa


The shift towards conducting enterprise operations within web browsers has positioned them as a major target for cyberattacks. Industry reports highlight a significant increase in browser-based attacks over the past two years, with Gartner forecasting that by 2027, more than 85% of enterprise workloads will be accessed through browsers. Despite this shift, many enterprise security systems remain focused on safeguarding devices rather than the browser sessions where both work and attacks occur, says Shioupyn Shen, founder and CEO of CloudMosa, the developer of Puffin Cloud Security.

“CloudMosa’s initial cloud architecture aimed to enhance browser performance and accessibility, anticipating the transition of enterprise work into the browser,” Shen explains. “The evolution of AI-assisted hacking has validated our architecture, showing that what was built for performance also underpins modern enterprise security.”

The Browser as the Enterprise’s Operating Environment

With SaaS platforms, CRM and ERP systems, and collaboration tools centralizing operations in browsers, they have become the primary gateways for enterprise activities. As LLM-powered workflows and autonomous AI agents increasingly operate within this framework, the nature of threats has evolved.

In a device-focused environment, security teams concentrated on monitoring and managing endpoints, but the local execution of web code on user devices means every browser tab could potentially invite malicious scripts, credential theft, or other browser-based exploits. The browser now plays a crucial role, interpreting remote code, managing authenticated sessions, and serving as the execution layer for AI workflows.

See also  Forget the iPad - These are the top Android tablets to buy instead

“The browser has transitioned from being just another application on the endpoint to the core operating environment for contemporary enterprise work,” Shen asserts. “Traditional browsers weren’t designed for such enterprise-grade responsibilities, which demand strong isolation and policy enforcement.”

Why Detection-First Security Falls Short Against Browser-Based Attacks

Detection-first security faces a timing issue: it typically activates only after risky code reaches the device and starts executing in the browser. Modern browsers execute dynamic, often obfuscated JavaScript and WebAssembly locally, allowing attacks to act before endpoint tools can respond. Short-lived or fileless attacks might achieve their goals before security teams can react.

“It’s not enough to ask if a threat can be detected,” Shen emphasizes. “A stronger method is to stop risky or malicious code from ever reaching the device.”

AI-Generated Malware Challenges Signature-Based Detection

AI enables attackers to automate the creation and deployment of malware at a scale that signature-based tools cannot manage. It can rapidly generate numerous malware variants and help attackers adapt fileless and browser-delivered techniques faster than defenders can analyze them.

This is significant because polymorphic malware changes its code or behavior frequently, reducing the reliability of known signatures. With malware-free attacks relying on legitimate tools or malicious web content, there might be no conventional file signature to detect.

Enterprises have witnessed an 89% increase in AI-enabled attacks in the past year, as automated and adaptive attacks shorten the time available for detection and response.

“Defenders aren’t just dealing with more threats; they’re facing machines that can continually create new ones,” Shen observes. “What sufficed in the past decade won’t be enough in the coming months.”

Developing Architecture to Eliminate the Attack Surface

Rather than refining detection methods, a more sustainable solution is to change where web code can execute initially.

See also  We’ve spotted a huge asteroid spinning impossibly fast

“In a conventional browser, the risk comes to the device,” Shen says. “In an isolated cloud model, the risk is kept away.”

This concept is central to Puffin Cloud Security. Instead of enhancing the browser itself, the platform moves browser execution to isolated cloud environments, boosting both performance and security.

The platform runs web sessions, including JavaScript, WebAssembly, and other executable payloads, in disposable cloud environments, streaming only a rendered pixel view to the device. Users maintain full interactive control, but the device never processes or stores the original active code.

CloudMosa claims that display rasterization accounts for about 5% of the browser’s total workload, while the more demanding HTML rendering stays isolated in the cloud. As a result, zero-day exploits and AI-generated polymorphic malware have no executable code on the endpoint, and fileless attacks within SaaS tools remain contained in the cloud.

“CloudMosa believes this shift moves security from being just adequate on the device to being airtight in the cloud,” Shen states.

Integrating Browser Isolation into SWG, CASB, and ZTNA Stacks

Puffin is designed to enhance, not replace, existing security infrastructures. Secure web gateways, cloud access security brokers, and zero trust network access tools remain effective for routing traffic and enforcing policies. However, they cannot completely prevent local execution once risky content reaches the browser.

Puffin addresses this by routing high-risk sessions through isolated cloud environments and enforcing browser-level policies, regardless of whether a user connects via a VPN, home network, managed device, or bring-your-own-device setup.

“Organizations can begin with specific use cases, like high-risk SaaS access or AI agent workflows, and expand without disrupting existing tools,” Shen suggests. “The aim is not to undo current investments but to make them more comprehensive.”

See also  Does National Security Justify Trade Restrictions?

The Decision Between Faster Detection and Endpoint Isolation

Detection will always play a role in enterprise security, but the more critical question is whether attackers can reach the endpoint at all. Recent 2026 surveys show 92% of security professionals worry about AI agents, with 48% identifying agentic AI as the top attack vector of the year. Shen notes that agents with user-level privileges are particularly vulnerable to prompt injection, session hijacking, and indirect compromises through malicious web content.

In developing Puffin Cloud Security, CloudMosa took a “paranoid by design” approach, investing in an architecture for worst-case scenarios where endpoint security and detection alone may not suffice.

“This isn’t just a philosophy; it’s reflected directly in the architecture,” Shen explains. “CloudMosa prepared for a tougher threat model than most organizations, and today’s AI-assisted attacks make that stance increasingly relevant.”

By dividing the browser into a small layer on the device and a larger layer in the cloud, CloudMosa designed this approach to enhance both performance and security simultaneously. In Puffin Cloud Security’s framework, an AI agent’s browser activity occurs within isolated cloud sandboxes. The endpoint only receives a pixel stream, preventing malicious web content from directly interacting with the device, its credentials, or connected systems.

“AI-assisted hacking represents a fundamental shift that benefits companies willing to rethink the browser from the ground up,” Shen asserts. “Security leaders now face a choice: redesign with foresight or learn the hard way later on.”


Sponsored articles are content produced by a company that is either paying for the post or has a business relationship with VentureBeat, and they’re always clearly marked. For more information, contact sales@venturebeat.com.

TAGGED:attacksBrowserEndpointfocusedlandSecurity
Share This Article
Twitter Email Copy Link Print
Previous Article mRNA flu shot, measles status, Covid-19 : Morning Rounds mRNA flu shot, measles status, Covid-19 : Morning Rounds
Next Article 7 Celebrity Outfit Inspiration Ideas to Recreate This Summer 7 Celebrity Outfit Inspiration Ideas to Recreate This Summer

Popular Posts

MLB Power Rankings: Rangers, Yankees on the rise; Dodgers are right where you think they are

The first weekend of the baseball season brought plenty of excitement and surprises across the…

April 1, 2025

Derrick Rose’s complicated legacy needs to reconcile the brilliant with the brutal

Former NBA player Derrick Rose announced his retirement from professional basketball on Thursday, marking the…

September 27, 2024

More progress on inflation needed before more rate cuts

Federal Reserve Governor Michelle Bowman recently addressed a conference held by the American Bankers Association,…

February 17, 2025

Rushed Medicaid work requirements create a lobbyist scramble

WASHINGTON — Patient advocacy groups are actively seeking exemptions from the new Medicaid work requirements,…

May 12, 2026

Maniac subway shover sentenced to 10 years as victim details how her life has become an ‘invisible cage’ since attack

In a tragic reminder of the dangers lurking in everyday life, a married mother has…

September 29, 2025

You Might Also Like

Latest Pentagon UFO files release includes video of mysterious ‘cold orbs’
Tech and Science

Latest Pentagon UFO files release includes video of mysterious ‘cold orbs’

August 7, 2026
Samsung Announces New 200Mp Camera but the Galaxy S27 Won’t Get It – Tech Advisor
Tech and Science

Samsung Announces New 200Mp Camera but the Galaxy S27 Won’t Get It – Tech Advisor

August 7, 2026
Gemini and Lockscreen Upgrades Coming to Pixel Phones – Tech Advisor
Tech and Science

Gemini and Lockscreen Upgrades Coming to Pixel Phones – Tech Advisor

August 7, 2026
President Donald J. Trump Bolsters National Security and Strengthens U.S. Supply Chains by Imposing Tariffs on Polysilicon and its Derivatives – The White House
The White House

President Donald J. Trump Bolsters National Security and Strengthens U.S. Supply Chains by Imposing Tariffs on Polysilicon and its Derivatives – The White House

August 7, 2026
logo logo
Facebook Twitter Youtube

About US


Explore global affairs, political insights, and linguistic origins. Stay informed with our comprehensive coverage of world news, politics, and Lifestyle.

Top Categories
  • Crime
  • Environment
  • Sports
  • Tech and Science
Usefull Links
  • Contact
  • Privacy Policy
  • Terms & Conditions
  • DMCA

© 2024 americanfocus.online –  All Rights Reserved.

Welcome Back!

Sign in to your account

Lost your password?