business intelligence tools

The browser is the new frontline. Why security hasn't caught up.

The browser has become the enterprise's central operating environment, yet most security architecture still guards the device instead of the session where work, and attacks, actually happen.

4 min readVentureBeat
The browser is the new frontline. Why security hasn't caught up.

The endpoint was always a convenient place to draw the line. You could image a machine, patch it on a schedule, and assume that a clean device meant a clean session. That logic has quietly inverted as the browser became the enterprise's real operating system, and most security teams are still guarding the wrong layer. Gartner's projection that over 85% of enterprise workloads will live in the browser by 2027 is not a distant forecast; it is a deadline. And the surge in browser-based attacks over the past two years suggests the attackers read that projection before most defenders did. The honest take here is not that endpoint security is useless, but that it has become a rear-guard action. By the time malicious JavaScript executes locally, the damage is already inside the trust boundary. That is why Exploring Paragraph Structure: How LLMs Navigate Token Space and Bridging Retrieval and Action: A New Approach to AI Tasks matter in this conversation: both show how much of modern AI work happens as token manipulation and agentic action inside a browser-like execution layer. If that layer is compromised, the model's output is just another attack vector. Shioupyn Shen's argument is uncomfortable because it reframes the problem from "how do we detect faster" to "why are we letting untrusted code touch the device at all." Detection-first security has a timing problem, and AI-assisted hacking has turned that problem into a chasm. An 89% increase in attacks by AI-enabled adversaries is cited, and the reason is structural: signature-based tools are chasing a moving target that can mutate faster than a human analyst can update a rule. Polymorphic malware and fileless attacks do not need to be stealthy if they can execute and exfiltrate before a detection engine even wakes up. The practical consequence is that your SOC's mean time to respond is less relevant when the response starts after the session is already compromised. CloudMosa's bet is that isolation is the only honest answer to that asymmetry. Running the browser in a disposable cloud environment, streaming only a pixel render back to the device, is not a tweak to the endpoint model; it is a rejection of it. The endpoint becomes a dumb terminal again, which is less glamorous but considerably harder to exploit. What makes this worth paying attention to is not the product pitch but the architectural principle behind it. Shen is not claiming that detection is dead or that zero trust is obsolete. He is arguing that the browser has become a full execution environment for AI agents and SaaS workflows, and that no amount of policy enforcement on the device can prevent a malicious web page from abusing a legitimate session. The detail that matters is that display rasterization accounts for only 5% of the browser's workload: the heavy lifting happens in the cloud, so the device is simply not a viable target. For a security leader, this changes the question from "how do we stop every attack" to "how do we make sure the attack has nowhere to land." That is a more honest and more achievable goal. The takeaway to quote: "Defenders are no longer just chasing more threats, they are chasing a machine that can keep creating new ones." The only durable response is to remove the execution surface entirely. The open question is whether enterprises will treat browser isolation as a bolt-on for high-risk workflows or as the foundation for their next security architecture. Starting narrow, with high-risk SaaS access or AI agent workflows, and expanding from there is suggested. That is sensible, but it also means the conversation about browser security is really a conversation about where you draw the trust boundary in an AI-native world. If 92% of security professionals are worried about AI agents and 48% call agentic AI the top attack vector, then the browser is not just the new endpoint; it is the new network perimeter. The specific thing to watch is how quickly vendors integrate isolation with existing SWG, CASB, and ZTNA stacks without forcing a rip-and-replace.

From VentureBeat

Enterprise work now happens increasingly inside the browser, and that shift has made the browser a primary point of entry for cyberattacks as well. Browser-based attacks have surged over the past two years, according to industry reports, while Gartner projects that more than 85% of enterprise workloads will be accessed through the browser by 2027.

And yet most enterprise security architecture is still built to protect the device rather than the browser session where that work, and those attacks, actually take place, says Shioupyn Shen, founder and CEO of CloudMosa, the company behind Puffin Cloud Security.

Read the original at VentureBeat