Introduced by CloudMosa
Enterprise work now occurs more and more contained in the browser, and that shift has made the browser a main level of entry for cyberattacks as effectively. Browser-based assaults have surged over the previous two years, in line with trade stories, whereas Gartner tasks that greater than 85% of enterprise workloads might be accessed by the browser by 2027.
And but most enterprise safety structure remains to be constructed to guard the system fairly than the browser session the place that work, and people assaults, really happen, says Shioupyn Shen, founder and CEO of CloudMosa, the corporate behind Puffin Cloud Safety.
“CloudMosa initially constructed its cloud structure to enhance browser efficiency and accessibility, with the expectation that enterprise work would more and more transfer into the browser,” Shen says. “Right this moment’s AI-assisted hacking has validated that structure, demonstrating that what was designed for efficiency additionally gives a powerful basis for contemporary enterprise safety.”
The browser because the enterprise's working atmosphere
SaaS platforms, CRM and ERP techniques, and collaboration instruments have made the browser the first gateway, and infrequently the central workspace, for enterprise operations. As LLM-powered workflows and autonomous AI brokers more and more function by that very same atmosphere, this shift has additionally redefined what a menace seems like.
In a device-centric world, safety groups might focus a lot of their consideration on endpoints and networks they might monitor, handle and patch on schedule. However as a result of net code now executes regionally on the consumer’s system, each open browser tab can turn out to be a possible entry level for malicious scripts, credential theft, provide chain compromise and different browser-based exploits.
The browser now interprets and executes distant code, manages authenticated periods throughout enterprise purposes, and more and more serves because the execution layer for AI workflows and brokers.
"The browser is not simply one other software working on the endpoint," Shen says. "In observe, it has turn out to be the central working atmosphere for contemporary enterprise work. Conventional browsers have been by no means designed to hold this degree of enterprise accountability. They have been constructed as native interpreters of distant code, not as enterprise-grade execution environments with sturdy isolation and coverage enforcement."
Why detection-first safety fails in opposition to browser-based assaults
Detection-first safety has a timing downside: it usually begins solely after dangerous code has reached the system and began executing contained in the browser. As a result of fashionable browsers execute dynamic, usually obfuscated JavaScript and WebAssembly regionally, assaults can act on the system earlier than endpoint instruments have time to reply. Quick-lived or fileless assaults could steal credentials, exfiltrate information or full their goal earlier than a safety crew can intervene.
"It’s not enough to ask solely whether or not a menace will be detected," Shen says. "The stronger method is to stop dangerous or malicious code from ever reaching the system within the first place."
AI-generated malware strains signature-based detection
AI is a power multiplier that lets attackers automate the creation, mutation and deployment of malware at a scale signature-based instruments have been by no means designed to deal with. It may generate massive volumes of malware variants and assist attackers adapt fileless and browser-delivered methods quicker than defenders can analyze them and replace signatures.
That issues as a result of polymorphic malware can alter its code or habits from one occasion to the subsequent, making a identified signature much less dependable. And when assaults are malware-free — relying as a substitute on professional instruments, compromised periods or malicious net content material — there could also be no typical file signature to detect in any respect.
Enterprises have seen an 89% increase in attacks by AI-enabled adversaries over the previous 12 months, as more and more automated and adaptive assaults compress the window obtainable for detection and response.
"Defenders are not simply chasing extra threats, they’re chasing a machine that may maintain creating new ones," Shen says. "What was ok previously 10 years won’t be enough within the subsequent six months," he provides.
Constructing structure that removes the assault floor
Somewhat than persevering with to refine detection, the extra sturdy response is to alter the place net code is allowed to execute within the first place.
"In a standard browser, the danger involves the system," Shen says. "In an remoted cloud mannequin, the danger is refrained from it."
That precept underlies Puffin Cloud Safety. Somewhat than incrementally enhancing the browser itself, the platform shifts browser execution into remoted cloud environments. That architectural change improves each efficiency and safety.
The platform runs the unique net session, together with its JavaScript, WebAssembly, and different executable payloads, inside a disposable cloud atmosphere and streams solely a rendered pixel view to the system. Customers maintain full interactive management over clicking, typing, and scrolling, however the system itself by no means parses, executes, or shops the unique lively code.
CloudMosa says show rasterization — the layer answerable for the pixel stream — accounts for roughly 5% of the browser’s total workload, whereas the extra compute-intensive HTML rendering stays remoted within the cloud. Because of this, zero-day exploits and AI-generated polymorphic malware haven’t any executable code to run on the endpoint, whereas fileless assaults or provide chain compromises inside SaaS instruments stay contained within the cloud.
"In CloudMosa's view, meaning transferring from good-enough safety on the system to hermetic safety within the cloud," Shen says.
Becoming browser isolation into SWG, CASB and ZTNA stacks
Puffin is designed to increase present safety infrastructure fairly than exchange it. Safe net gateways, cloud entry safety dealer platforms, and 0 belief community entry instruments stay efficient at routing site visitors, implementing coverage, and controlling entry. However none can absolutely cease native execution as soon as dangerous content material reaches the browser.
Puffin closes that hole by routing high-risk periods by remoted cloud environments and implementing browser-level coverage, whether or not a consumer connects over a VPN, a house community, a managed system or an unmanaged, bring-your-own-device setup.
"Organizations can begin with slender use circumstances, equivalent to high-risk SaaS entry or AI agent workflows, and increase with out disrupting instruments already in place," Shen says. "The purpose is to not undo present investments, however to make them extra full."
The selection between quicker detection or endpoint isolation
Detection will at all times have a job in enterprise safety, however the extra consequential query is not how rapidly a menace will be caught, however whether or not attackers can attain the endpoint in any respect. Latest 2026 surveys discovered 92% of security professionals are involved in regards to the impression of AI brokers, with 48% naming agentic AI the top attack vector of the year. Shen famous that brokers appearing autonomously with user-level privileges are particularly uncovered to immediate injection, session hijacking, and oblique compromise by compromised net content material.
In designing Puffin Cloud Safety, CloudMosa has been “paranoid by design,” that means it invested in an structure constructed for worst-case situations and for a menace atmosphere the place endpoint safety and detection alone will not be sufficient.
"This isn’t only a philosophy, however one thing that’s mirrored immediately within the structure itself," Shen says. "CloudMosa constructed earlier for a harsher menace mannequin than most different organizations did, however in the present day's AI-assisted assaults are actually making that posture really feel more and more related."
By dividing a full browser into a really small layer on the system and a a lot bigger layer within the cloud, CloudMosa designed this method to enhance each efficiency and safety on the identical time: In Puffin Cloud Safety’s structure, an AI agent’s browser exercise takes place inside remoted cloud sandboxes. The endpoint receives solely a pixel stream, not the unique lively code, stopping malicious net content material from interacting immediately with the system, its credentials or linked techniques.
"AI-assisted hacking represents the sort of structural shift that rewards corporations prepared to rethink browser from the bottom up," Shen says. "And so safety leaders now have a alternative: redesign for foresight, or wait till hindsight makes the lesson unavoidable."
Sponsored articles are content material produced by an organization that’s both paying for the put up or has a enterprise relationship with VentureBeat, they usually’re at all times clearly marked. For extra data, contact sales@venturebeat.com.
