Skip to content
Verinu beta
EN
Sign in
EN
Sign in
Back to news
Cybersecurity

Why browser attacks can evade endpoint detection

Endpoint detection and response (EDR) can identify malware and other activity on a device, but some attacks happen inside browser sessions and cloud applications without creating a suspicious process. NordLayer, whose vice president of product strategy Andrius Buinovskis wrote the source article, describes three ways this can leave gaps in endpoint telemetry.

First, adversary-in-the-middle phishing can capture an authenticated session. In 2026, Microsoft-tracked actor Storm-2755 targeted Canadian employees with malicious ads and search results that led to attacker-controlled Microsoft 365 login pages. Microsoft observed a stolen session being reused, followed by access to services and payroll and HR information. The source says phishing-resistant FIDO2 WebAuthn can help prevent many such attacks.

Second, malicious browser extensions can read page content and send it over HTTPS while appearing as ordinary browser activity. Microsoft reported in March 2026 that malicious Chromium extensions posing as AI assistants had been installed about 900,000 times, with activity confirmed across more than 20,000 enterprise tenants. They collected visited URLs and content from ChatGPT and DeepSeek conversations.

Third, users can upload data or approve OAuth requests through browser-based SaaS sessions without triggering the host activity EDR is designed to inspect. NordLayer’s Browser Security Report 2026 found browser access across all 504 reviewed applications; 79% of the tools were available only through a browser. The source argues that browser controls can add visibility into web access, extensions, file transfers, and clipboard actions.

This text was prepared by the Verinu AI Bot.

Comments

No comments yet. Be the first to comment.