The browser is where attacks land. Why is security still focused on the endpoint?

Presented by CloudMosa


Enterprise work is increasingly shifting to the browser, making it a major target for cyberattacks. According to industry reports, browser-based attacks have been on the rise in recent years, and Gartner predicts that over 85% of enterprise workloads will be accessed through the browser by 2027.

Despite this trend, most enterprise security strategies focus on protecting the device rather than securing the browser session where these attacks occur. Shioupyn Shen, founder and CEO of CloudMosa, the company behind Puffin Cloud Security, highlights the need to shift focus towards securing the browser environment.

CloudMosa initially developed its cloud architecture to enhance browser performance and accessibility, anticipating the growing importance of the browser in enterprise operations. Shen emphasizes that this architecture, designed for performance, also provides a robust foundation for modern enterprise security.

The Browser as the Operating Environment for Enterprises

With SaaS platforms, CRM systems, and collaboration tools driving enterprise activities, the browser has become the primary access point for many tasks. As AI-driven workflows and agents operate within the browser environment, the definition of threats has evolved.

In the past, security teams focused on securing endpoints and networks that could be monitored and managed. However, with web code now executing locally on user devices, each open browser tab presents a potential entry point for malicious activities such as credential theft and supply chain compromises.

Shen notes that the browser now executes remote code, manages authenticated sessions across enterprise applications, and serves as the execution layer for AI workflows and agents.

“The browser is no longer just another application on the endpoint,” Shen explains. “It has become the central operating environment for modern enterprise work, requiring a different approach to security.”

Challenges of Detection-First Security Against Browser-Based Attacks

Detection-first security faces challenges due to the dynamic nature of modern browsers, which execute complex code locally. As a result, attacks can exploit vulnerabilities before endpoint security tools can respond effectively.

Shen emphasizes the need to prevent risky or malicious code from reaching devices in the first place, rather than relying solely on detection mechanisms.

The Impact of AI-Generated Malware on Traditional Security Measures

AI has enabled attackers to automate the creation and deployment of malware at a scale that traditional signature-based tools struggle to handle. This adaptability allows attackers to generate numerous malware variants and employ fileless techniques that evade conventional detection methods.

Enterprises have witnessed a significant increase in attacks by AI-enabled adversaries, highlighting the need for more advanced security measures.

“Defenders are facing a machine that can continuously create new threats, requiring a proactive security approach,” Shen states.

Building a Secure Architecture Through Browser Isolation

CloudMosa’s approach focuses on isolating browser execution in cloud environments to prevent threats from reaching endpoints. By shifting browser execution to the cloud, the platform enhances both performance and security.

Puffin Cloud Security runs web sessions, including JavaScript and WebAssembly payloads, in disposable cloud environments, streaming only a rendered view to devices. This approach prevents malicious code from running on endpoints, offering protection against zero-day exploits and AI-generated malware.

“Moving from device-centric security to cloud-based security is essential in today’s threat landscape,” Shen emphasizes.

Integrating Browser Isolation into Existing Security Infrastructures

Puffin complements existing security tools such as secure web gateways and zero trust network access solutions by enforcing browser-level policies and isolating high-risk sessions in cloud environments.

Organizations can gradually implement browser isolation for specific use cases without disrupting existing security measures, ultimately enhancing overall security posture.

Choosing Between Detection and Endpoint Isolation

While detection remains crucial, preventing attackers from reaching endpoints is becoming increasingly important. CloudMosa’s proactive approach to security, through browser isolation, offers a comprehensive solution to protect against evolving threats.

Shen emphasizes the need for security leaders to rethink their security strategies in light of AI-assisted attacks, highlighting the importance of proactive measures to safeguard enterprise operations.


Sponsored content is produced by companies with a business relationship with VentureBeat. Contact sales@venturebeat.com for more information.