Urgent.News

the world's headlines, one feed

Editions

Tech

The browser is where attacks land. Why is security still focused on the endpoint?

Presented by CloudMosa Enterprise work now happens increasingly inside the browser, and that shift has made the browser a primary point of entry for cyberattacks as well. Browser-based attacks have surged over the past two years, according to industry reports, while Gartner projects that more than 85% of enterprise workloads will be accessed through the browser by 2027. And yet most enterprise…

The browser is where attacks land. Why is security still focused on the endpoint?

Modern enterprise work increasingly occurs within the browser, making it a primary target for cyberattacks. Browser-based attacks have risen over the past two years, with Gartner predicting over 85% of enterprise workloads will be accessed through the browser by 2027. However, most enterprise security architecture remains focused on protecting devices rather than the browser sessions where work and attacks take place.

CloudMosa's founder and CEO, Shioupyn Shen, explains that the company initially built its cloud architecture to enhance browser performance and accessibility, anticipating a shift towards browser-based work. Today, AI-assisted hacking has validated this approach, demonstrating that the architecture also provides a strong foundation for modern enterprise security.

As SaaS platforms, CRM and ERP systems, and collaboration tools dominate enterprise operations, the browser has become the primary gateway and central workspace for enterprise activities. With AI-assisted threat actors leveraging AI to create, mutate, and deploy malware at scale, the browser has become the central operating environment for modern enterprise work.

Traditional browsers are not designed to handle this level of enterprise responsibility, serving as local interpreters of remote code, not enterprise-grade execution environments. Browser isolation is a crucial security approach that prevents risky code from reaching the device in the first place. By running web sessions in isolated cloud environments and streaming only a rendered pixel view to the device, the attack surface is significantly reduced, containing fileless attacks and supply chain compromises within the cloud.

This shift in architecture focuses on removing the attack surface rather than refining detection methods, ensuring airtight security in the cloud.

Written by urgent.news from VentureBeat's reporting — not their text. Machine-written — it may contain errors, so check the original before relying on it.

Read the original at venturebeat.com →

More in Tech