Close Menu
    Trending
    • In this Canadian city, rent gobbles up 95% of a full-time, minimum-wage earner's working hours
    • TRON’s USDT Hits $87.9B as Q2 Transfers Reach $2.1T and Fees Jump 15.9%
    • SharpLink posts $1B loss as its $1.7B Ethereum treasury could take 90 days to fully convert to cash
    • Blockstream Debuts Bitcoin Swaps For Moving Between Lightning
    • Apple May Introduce A Photo Authentication Tool In iOS 27
    • NA pros and coaches aren’t worried about the East, they’re worried about fixing the path to pro first
    • Pre-Surgical Complications (Part 1) – The Health Care Blog
    • books from lately – The Fitnessista
    FreshUsNews
    • Home
    • World News
    • Latest News
      • World Economy
      • Opinions
    • Politics
    • Crypto
      • Blockchain
      • Ethereum
    • US News
    • Sports
      • Sports Trends
      • eSports
      • Cricket
      • Formula 1
      • NBA
      • Football
    • More
      • Finance
      • Health
      • Mindful Wellness
      • Weight Loss
      • Tech
      • Tech Analysis
      • Tech Updates
    FreshUsNews
    Home » The browser is where attacks land. Why is security still focused on the endpoint?
    Tech Updates

    The browser is where attacks land. Why is security still focused on the endpoint?

    FreshUsNewsBy FreshUsNewsAugust 6, 2026No Comments7 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Introduced by CloudMosa


    Enterprise work now occurs more and more contained in the browser, and that shift has made the browser a main level of entry for cyberattacks as effectively. Browser-based assaults have surged over the previous two years, in line with trade stories, whereas Gartner tasks that greater than 85% of enterprise workloads might be accessed by the browser by 2027.

    And but most enterprise safety structure remains to be constructed to guard the system fairly than the browser session the place that work, and people assaults, really happen, says Shioupyn Shen, founder and CEO of CloudMosa, the corporate behind Puffin Cloud Safety.

    “CloudMosa initially constructed its cloud structure to enhance browser efficiency and accessibility, with the expectation that enterprise work would more and more transfer into the browser,” Shen says. “Right this moment’s AI-assisted hacking has validated that structure, demonstrating that what was designed for efficiency additionally gives a powerful basis for contemporary enterprise safety.”

    The browser because the enterprise's working atmosphere

    SaaS platforms, CRM and ERP techniques, and collaboration instruments have made the browser the first gateway, and infrequently the central workspace, for enterprise operations. As LLM-powered workflows and autonomous AI brokers more and more function by that very same atmosphere, this shift has additionally redefined what a menace seems like.

    In a device-centric world, safety groups might focus a lot of their consideration on endpoints and networks they might monitor, handle and patch on schedule. However as a result of net code now executes regionally on the consumer’s system, each open browser tab can turn out to be a possible entry level for malicious scripts, credential theft, provide chain compromise and different browser-based exploits.

    The browser now interprets and executes distant code, manages authenticated periods throughout enterprise purposes, and more and more serves because the execution layer for AI workflows and brokers.

    "The browser is not simply one other software working on the endpoint," Shen says. "In observe, it has turn out to be the central working atmosphere for contemporary enterprise work. Conventional browsers have been by no means designed to hold this degree of enterprise accountability. They have been constructed as native interpreters of distant code, not as enterprise-grade execution environments with sturdy isolation and coverage enforcement."

    Why detection-first safety fails in opposition to browser-based assaults

    Detection-first safety has a timing downside: it usually begins solely after dangerous code has reached the system and began executing contained in the browser. As a result of fashionable browsers execute dynamic, usually obfuscated JavaScript and WebAssembly regionally, assaults can act on the system earlier than endpoint instruments have time to reply. Quick-lived or fileless assaults could steal credentials, exfiltrate information or full their goal earlier than a safety crew can intervene.

    "It’s not enough to ask solely whether or not a menace will be detected," Shen says. "The stronger method is to stop dangerous or malicious code from ever reaching the system within the first place."

    AI-generated malware strains signature-based detection

    AI is a power multiplier that lets attackers automate the creation, mutation and deployment of malware at a scale signature-based instruments have been by no means designed to deal with. It may generate massive volumes of malware variants and assist attackers adapt fileless and browser-delivered methods quicker than defenders can analyze them and replace signatures.

    That issues as a result of polymorphic malware can alter its code or habits from one occasion to the subsequent, making a identified signature much less dependable. And when assaults are malware-free — relying as a substitute on professional instruments, compromised periods or malicious net content material — there could also be no typical file signature to detect in any respect.

    Enterprises have seen an 89% increase in attacks by AI-enabled adversaries over the previous 12 months, as more and more automated and adaptive assaults compress the window obtainable for detection and response.

    "Defenders are not simply chasing extra threats, they’re chasing a machine that may maintain creating new ones," Shen says. "What was ok previously 10 years won’t be enough within the subsequent six months," he provides.

    Constructing structure that removes the assault floor

    Somewhat than persevering with to refine detection, the extra sturdy response is to alter the place net code is allowed to execute within the first place.

    "In a standard browser, the danger involves the system," Shen says. "In an remoted cloud mannequin, the danger is refrained from it."

    That precept underlies Puffin Cloud Safety. Somewhat than incrementally enhancing the browser itself, the platform shifts browser execution into remoted cloud environments. That architectural change improves each efficiency and safety.

    The platform runs the unique net session, together with its JavaScript, WebAssembly, and different executable payloads, inside a disposable cloud atmosphere and streams solely a rendered pixel view to the system. Customers maintain full interactive management over clicking, typing, and scrolling, however the system itself by no means parses, executes, or shops the unique lively code.

    CloudMosa says show rasterization — the layer answerable for the pixel stream — accounts for roughly 5% of the browser’s total workload, whereas the extra compute-intensive HTML rendering stays remoted within the cloud. Because of this, zero-day exploits and AI-generated polymorphic malware haven’t any executable code to run on the endpoint, whereas fileless assaults or provide chain compromises inside SaaS instruments stay contained within the cloud.

    "In CloudMosa's view, meaning transferring from good-enough safety on the system to hermetic safety within the cloud," Shen says.

    Becoming browser isolation into SWG, CASB and ZTNA stacks

    Puffin is designed to increase present safety infrastructure fairly than exchange it. Safe net gateways, cloud entry safety dealer platforms, and 0 belief community entry instruments stay efficient at routing site visitors, implementing coverage, and controlling entry. However none can absolutely cease native execution as soon as dangerous content material reaches the browser.

    Puffin closes that hole by routing high-risk periods by remoted cloud environments and implementing browser-level coverage, whether or not a consumer connects over a VPN, a house community, a managed system or an unmanaged, bring-your-own-device setup.

    "Organizations can begin with slender use circumstances, equivalent to high-risk SaaS entry or AI agent workflows, and increase with out disrupting instruments already in place," Shen says. "The purpose is to not undo present investments, however to make them extra full."

    The selection between quicker detection or endpoint isolation

    Detection will at all times have a job in enterprise safety, however the extra consequential query is not how rapidly a menace will be caught, however whether or not attackers can attain the endpoint in any respect. Latest 2026 surveys discovered 92% of security professionals are involved in regards to the impression of AI brokers, with 48% naming agentic AI the top attack vector of the year. Shen famous that brokers appearing autonomously with user-level privileges are particularly uncovered to immediate injection, session hijacking, and oblique compromise by compromised net content material.

    In designing Puffin Cloud Safety, CloudMosa has been “paranoid by design,” that means it invested in an structure constructed for worst-case situations and for a menace atmosphere the place endpoint safety and detection alone will not be sufficient.

    "This isn’t only a philosophy, however one thing that’s mirrored immediately within the structure itself," Shen says. "CloudMosa constructed earlier for a harsher menace mannequin than most different organizations did, however in the present day's AI-assisted assaults are actually making that posture really feel more and more related."

    By dividing a full browser into a really small layer on the system and a a lot bigger layer within the cloud, CloudMosa designed this method to enhance each efficiency and safety on the identical time: In Puffin Cloud Safety’s structure, an AI agent’s browser exercise takes place inside remoted cloud sandboxes. The endpoint receives solely a pixel stream, not the unique lively code, stopping malicious net content material from interacting immediately with the system, its credentials or linked techniques.

    "AI-assisted hacking represents the sort of structural shift that rewards corporations prepared to rethink browser from the bottom up," Shen says. "And so safety leaders now have a alternative: redesign for foresight, or wait till hindsight makes the lesson unavoidable."


    Sponsored articles are content material produced by an organization that’s both paying for the put up or has a enterprise relationship with VentureBeat, they usually’re at all times clearly marked. For extra data, contact sales@venturebeat.com.



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleFirst OpenAI, now Meta – why do AI hacks keep happening?
    Next Article Bitcoin ETF Inflows Surge Following $130M Coldcard Hack
    FreshUsNews
    • Website

    Related Posts

    Tech Updates

    Apple May Introduce A Photo Authentication Tool In iOS 27

    August 11, 2026
    Tech Updates

    Your agent didn’t hallucinate; it exceeded its authority

    August 10, 2026
    Tech Updates

    AI agents are part of your team now. Here’s how to secure all of them.

    August 9, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    Transgender Lady Liberty Stirs Debate At Smithsonian

    July 29, 2025

    Affirmations vs. Meditation: Unraveling the Differences

    July 23, 2025

    What you need to know about CPP, OAS and tax planning if you want to work past 65

    July 6, 2025

    IBM’s Quantum Computing Vision for the Future

    December 1, 2025

    Punk’s proposal (and teabagging), Supernova’s Steve ruling, Arslan’s Ash fall from the top: FGC’s sweaty weekend

    May 6, 2026
    Categories
    • Bitcoin News
    • Blockchain
    • Cricket
    • eSports
    • Ethereum
    • Finance
    • Football
    • Formula 1
    • Healthy Habits
    • Latest News
    • Mindful Wellness
    • NBA
    • Opinions
    • Politics
    • Sports
    • Sports Trends
    • Tech Analysis
    • Tech News
    • Tech Updates
    • US News
    • Weight Loss
    • World Economy
    • World News
    Most Popular

    In this Canadian city, rent gobbles up 95% of a full-time, minimum-wage earner's working hours

    August 11, 2026

    TRON’s USDT Hits $87.9B as Q2 Transfers Reach $2.1T and Fees Jump 15.9%

    August 11, 2026

    SharpLink posts $1B loss as its $1.7B Ethereum treasury could take 90 days to fully convert to cash

    August 11, 2026

    Blockstream Debuts Bitcoin Swaps For Moving Between Lightning

    August 11, 2026

    Apple May Introduce A Photo Authentication Tool In iOS 27

    August 11, 2026

    NA pros and coaches aren’t worried about the East, they’re worried about fixing the path to pro first

    August 11, 2026

    Pre-Surgical Complications (Part 1) – The Health Care Blog

    August 11, 2026
    Our Picks

    Send In The Clowns. Don’t Bother – They Are Here.

    September 15, 2025

    How the viral Baby Shark video created a $400m business

    November 19, 2025

    Russell Westbrook Kings Sign One Year $36M Deal

    October 15, 2025

    Bitcoin Market Caution Rises After Failed Breakout: Glassnode Data

    March 21, 2026

    Trump says new call for regime change in Iran justified by ‘imminent threats’ to US

    February 28, 2026

    Befriend Vulnerability With A 12-Minute Meditation

    August 5, 2026

    DMND And RootstockLabs Partner To Bring Stratum V2 To Merge-mining

    May 18, 2026
    Categories
    • Bitcoin News
    • Blockchain
    • Cricket
    • eSports
    • Ethereum
    • Finance
    • Football
    • Formula 1
    • Healthy Habits
    • Latest News
    • Mindful Wellness
    • NBA
    • Opinions
    • Politics
    • Sports
    • Sports Trends
    • Tech Analysis
    • Tech News
    • Tech Updates
    • US News
    • Weight Loss
    • World Economy
    • World News
    • Privacy Policy
    • Disclaimer
    • Terms and Conditions
    • About us
    • Contact us
    Copyright © 2025 Freshusnews.com All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.