Close Menu
    Trending
    • Announcing a Trillion Dollar Security grant for WEBCAT
    • Bitcoin ETF Inflows Surge Following $130M Coldcard Hack
    • The browser is where attacks land. Why is security still focused on the endpoint?
    • First OpenAI, now Meta – why do AI hacks keep happening?
    • T1 CEO Joe Marsh talks entering Riftbound, T1 bundle cards, and grassroots communities
    • A digital health company became an insurance carrier under the thin veil of a product launch – The Health Care Blog
    • Hampshire’s John Turner retires from professional cricket
    • FIA EDRC returns to action at Sweden’s Tierp Arena
    FreshUsNews
    • Home
    • World News
    • Latest News
      • World Economy
      • Opinions
    • Politics
    • Crypto
      • Blockchain
      • Ethereum
    • US News
    • Sports
      • Sports Trends
      • eSports
      • Cricket
      • Formula 1
      • NBA
      • Football
    • More
      • Finance
      • Health
      • Mindful Wellness
      • Weight Loss
      • Tech
      • Tech Analysis
      • Tech Updates
    FreshUsNews
    Home » The browser is where attacks land. Why is security still focused on the endpoint?
    Tech Updates

    The browser is where attacks land. Why is security still focused on the endpoint?

    FreshUsNewsBy FreshUsNewsAugust 6, 2026No Comments7 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Introduced by CloudMosa


    Enterprise work now occurs more and more contained in the browser, and that shift has made the browser a main level of entry for cyberattacks as effectively. Browser-based assaults have surged over the previous two years, in line with trade stories, whereas Gartner tasks that greater than 85% of enterprise workloads might be accessed by the browser by 2027.

    And but most enterprise safety structure remains to be constructed to guard the system fairly than the browser session the place that work, and people assaults, really happen, says Shioupyn Shen, founder and CEO of CloudMosa, the corporate behind Puffin Cloud Safety.

    “CloudMosa initially constructed its cloud structure to enhance browser efficiency and accessibility, with the expectation that enterprise work would more and more transfer into the browser,” Shen says. “Right this moment’s AI-assisted hacking has validated that structure, demonstrating that what was designed for efficiency additionally gives a powerful basis for contemporary enterprise safety.”

    The browser because the enterprise's working atmosphere

    SaaS platforms, CRM and ERP techniques, and collaboration instruments have made the browser the first gateway, and infrequently the central workspace, for enterprise operations. As LLM-powered workflows and autonomous AI brokers more and more function by that very same atmosphere, this shift has additionally redefined what a menace seems like.

    In a device-centric world, safety groups might focus a lot of their consideration on endpoints and networks they might monitor, handle and patch on schedule. However as a result of net code now executes regionally on the consumer’s system, each open browser tab can turn out to be a possible entry level for malicious scripts, credential theft, provide chain compromise and different browser-based exploits.

    The browser now interprets and executes distant code, manages authenticated periods throughout enterprise purposes, and more and more serves because the execution layer for AI workflows and brokers.

    "The browser is not simply one other software working on the endpoint," Shen says. "In observe, it has turn out to be the central working atmosphere for contemporary enterprise work. Conventional browsers have been by no means designed to hold this degree of enterprise accountability. They have been constructed as native interpreters of distant code, not as enterprise-grade execution environments with sturdy isolation and coverage enforcement."

    Why detection-first safety fails in opposition to browser-based assaults

    Detection-first safety has a timing downside: it usually begins solely after dangerous code has reached the system and began executing contained in the browser. As a result of fashionable browsers execute dynamic, usually obfuscated JavaScript and WebAssembly regionally, assaults can act on the system earlier than endpoint instruments have time to reply. Quick-lived or fileless assaults could steal credentials, exfiltrate information or full their goal earlier than a safety crew can intervene.

    "It’s not enough to ask solely whether or not a menace will be detected," Shen says. "The stronger method is to stop dangerous or malicious code from ever reaching the system within the first place."

    AI-generated malware strains signature-based detection

    AI is a power multiplier that lets attackers automate the creation, mutation and deployment of malware at a scale signature-based instruments have been by no means designed to deal with. It may generate massive volumes of malware variants and assist attackers adapt fileless and browser-delivered methods quicker than defenders can analyze them and replace signatures.

    That issues as a result of polymorphic malware can alter its code or habits from one occasion to the subsequent, making a identified signature much less dependable. And when assaults are malware-free — relying as a substitute on professional instruments, compromised periods or malicious net content material — there could also be no typical file signature to detect in any respect.

    Enterprises have seen an 89% increase in attacks by AI-enabled adversaries over the previous 12 months, as more and more automated and adaptive assaults compress the window obtainable for detection and response.

    "Defenders are not simply chasing extra threats, they’re chasing a machine that may maintain creating new ones," Shen says. "What was ok previously 10 years won’t be enough within the subsequent six months," he provides.

    Constructing structure that removes the assault floor

    Somewhat than persevering with to refine detection, the extra sturdy response is to alter the place net code is allowed to execute within the first place.

    "In a standard browser, the danger involves the system," Shen says. "In an remoted cloud mannequin, the danger is refrained from it."

    That precept underlies Puffin Cloud Safety. Somewhat than incrementally enhancing the browser itself, the platform shifts browser execution into remoted cloud environments. That architectural change improves each efficiency and safety.

    The platform runs the unique net session, together with its JavaScript, WebAssembly, and different executable payloads, inside a disposable cloud atmosphere and streams solely a rendered pixel view to the system. Customers maintain full interactive management over clicking, typing, and scrolling, however the system itself by no means parses, executes, or shops the unique lively code.

    CloudMosa says show rasterization — the layer answerable for the pixel stream — accounts for roughly 5% of the browser’s total workload, whereas the extra compute-intensive HTML rendering stays remoted within the cloud. Because of this, zero-day exploits and AI-generated polymorphic malware haven’t any executable code to run on the endpoint, whereas fileless assaults or provide chain compromises inside SaaS instruments stay contained within the cloud.

    "In CloudMosa's view, meaning transferring from good-enough safety on the system to hermetic safety within the cloud," Shen says.

    Becoming browser isolation into SWG, CASB and ZTNA stacks

    Puffin is designed to increase present safety infrastructure fairly than exchange it. Safe net gateways, cloud entry safety dealer platforms, and 0 belief community entry instruments stay efficient at routing site visitors, implementing coverage, and controlling entry. However none can absolutely cease native execution as soon as dangerous content material reaches the browser.

    Puffin closes that hole by routing high-risk periods by remoted cloud environments and implementing browser-level coverage, whether or not a consumer connects over a VPN, a house community, a managed system or an unmanaged, bring-your-own-device setup.

    "Organizations can begin with slender use circumstances, equivalent to high-risk SaaS entry or AI agent workflows, and increase with out disrupting instruments already in place," Shen says. "The purpose is to not undo present investments, however to make them extra full."

    The selection between quicker detection or endpoint isolation

    Detection will at all times have a job in enterprise safety, however the extra consequential query is not how rapidly a menace will be caught, however whether or not attackers can attain the endpoint in any respect. Latest 2026 surveys discovered 92% of security professionals are involved in regards to the impression of AI brokers, with 48% naming agentic AI the top attack vector of the year. Shen famous that brokers appearing autonomously with user-level privileges are particularly uncovered to immediate injection, session hijacking, and oblique compromise by compromised net content material.

    In designing Puffin Cloud Safety, CloudMosa has been “paranoid by design,” that means it invested in an structure constructed for worst-case situations and for a menace atmosphere the place endpoint safety and detection alone will not be sufficient.

    "This isn’t only a philosophy, however one thing that’s mirrored immediately within the structure itself," Shen says. "CloudMosa constructed earlier for a harsher menace mannequin than most different organizations did, however in the present day's AI-assisted assaults are actually making that posture really feel more and more related."

    By dividing a full browser into a really small layer on the system and a a lot bigger layer within the cloud, CloudMosa designed this method to enhance each efficiency and safety on the identical time: In Puffin Cloud Safety’s structure, an AI agent’s browser exercise takes place inside remoted cloud sandboxes. The endpoint receives solely a pixel stream, not the unique lively code, stopping malicious net content material from interacting immediately with the system, its credentials or linked techniques.

    "AI-assisted hacking represents the sort of structural shift that rewards corporations prepared to rethink browser from the bottom up," Shen says. "And so safety leaders now have a alternative: redesign for foresight, or wait till hindsight makes the lesson unavoidable."


    Sponsored articles are content material produced by an organization that’s both paying for the put up or has a enterprise relationship with VentureBeat, they usually’re at all times clearly marked. For extra data, contact sales@venturebeat.com.



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleFirst OpenAI, now Meta – why do AI hacks keep happening?
    Next Article Bitcoin ETF Inflows Surge Following $130M Coldcard Hack
    FreshUsNews
    • Website

    Related Posts

    Tech Updates

    Meta enters the AI coding wars with Muse Spark 1.2 and Muse Code with persistent async background agents

    August 6, 2026
    Tech Updates

    AI is exposing the limits of traditional network architecture

    August 5, 2026
    Tech Updates

    AI coding agents are blowing through budgets — Replit, Kilo Code, and Symbotic explain how they're managing it

    August 5, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    Ethereum Price Move To $20,000: The Accumulation Zone That Shows The Time To Buy

    April 6, 2026

    Newcastle Champions League fixtures, schedule, squad 2025/26

    January 29, 2026

    US politicians react to Trump’s Iran ceasefire with caution, relief | US-Israel war on Iran News

    April 8, 2026

    The ’35-passing-TD NFL seasons’ quiz

    March 10, 2026

    2026 NFL Draft Sleepers: Where Did Our 5 Underrated Non-1st Round Prospects Land?

    April 25, 2026
    Categories
    • Bitcoin News
    • Blockchain
    • Cricket
    • eSports
    • Ethereum
    • Finance
    • Football
    • Formula 1
    • Healthy Habits
    • Latest News
    • Mindful Wellness
    • NBA
    • Opinions
    • Politics
    • Sports
    • Sports Trends
    • Tech Analysis
    • Tech News
    • Tech Updates
    • US News
    • Weight Loss
    • World Economy
    • World News
    Most Popular

    Announcing a Trillion Dollar Security grant for WEBCAT

    August 6, 2026

    Bitcoin ETF Inflows Surge Following $130M Coldcard Hack

    August 6, 2026

    The browser is where attacks land. Why is security still focused on the endpoint?

    August 6, 2026

    First OpenAI, now Meta – why do AI hacks keep happening?

    August 6, 2026

    T1 CEO Joe Marsh talks entering Riftbound, T1 bundle cards, and grassroots communities

    August 6, 2026

    A digital health company became an insurance carrier under the thin veil of a product launch – The Health Care Blog

    August 6, 2026

    Hampshire’s John Turner retires from professional cricket

    August 6, 2026
    Our Picks

    Xbox head Phil Spencer is leaving Microsoft

    February 20, 2026

    California’s Proposed Billionaire Tax | Armstrong Economics

    January 9, 2026

    New York Jets @ Miami Dolphins: Preview, prediction and odds

    September 28, 2025

    Craig Overton determined to add more T20 success for Somerset

    September 13, 2025

    ENG vs IND 2025: Old Trafford’s Weather Forecast for the fourth Test | England vs India

    July 23, 2025

    Why has Venezuela banned six international airlines amid US tensions? | Aviation News

    November 28, 2025

    Opinion | This Is Why I Find Pema Chödrön So Essential

    May 15, 2026
    Categories
    • Bitcoin News
    • Blockchain
    • Cricket
    • eSports
    • Ethereum
    • Finance
    • Football
    • Formula 1
    • Healthy Habits
    • Latest News
    • Mindful Wellness
    • NBA
    • Opinions
    • Politics
    • Sports
    • Sports Trends
    • Tech Analysis
    • Tech News
    • Tech Updates
    • US News
    • Weight Loss
    • World Economy
    • World News
    • Privacy Policy
    • Disclaimer
    • Terms and Conditions
    • About us
    • Contact us
    Copyright © 2025 Freshusnews.com All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.