
Introduced by CloudMosa
Enterprise work now occurs more and more inside the browser, and that shift has made the browser a major level of entry for cyberattacks as nicely. Browser-based assaults have surged over the previous two years, in accordance to business reviews, whereas Gartner initiatives that greater than 85% of enterprise workloads shall be accessed by means of the browser by 2027.
And but most enterprise safety structure is nonetheless constructed to defend the gadget moderately than the browser session the place that work, and people assaults, really happen, says Shioupyn Shen, founder and CEO of CloudMosa, the firm behind Puffin Cloud Safety.
“CloudMosa initially constructed its cloud structure to enhance browser efficiency and accessibility, with the expectation that enterprise work would more and more transfer into the browser,” Shen says. “As we speak’s AI-assisted hacking has validated that structure, demonstrating that what was designed for efficiency additionally supplies a robust basis for contemporary enterprise safety.”
The browser as the enterprise’s working setting
SaaS platforms, CRM and ERP programs, and collaboration instruments have made the browser the major gateway, and sometimes the central workspace, for enterprise operations. As LLM-powered workflows and autonomous AI brokers more and more function by means of that very same setting, this shift has additionally redefined what a risk seems like.
In a device-centric world, safety groups may focus a lot of their consideration on endpoints and networks they might monitor, handle and patch on schedule. However as a result of internet code now executes regionally on the person’s gadget, each open browser tab can develop into a possible entry level for malicious scripts, credential theft, provide chain compromise and different browser-based exploits.
The browser now interprets and executes distant code, manages authenticated classes throughout enterprise functions, and more and more serves as the execution layer for AI workflows and brokers.
“The browser is not simply one other utility operating on the endpoint,” Shen says. “In follow, it has develop into the central working setting for contemporary enterprise work. Conventional browsers had been by no means designed to carry this degree of enterprise duty. They had been constructed as native interpreters of distant code, not as enterprise-grade execution environments with sturdy isolation and coverage enforcement.”
Why detection-first safety fails in opposition to browser-based assaults
Detection-first safety has a timing downside: it usually begins solely after dangerous code has reached the gadget and began executing inside the browser. As a result of trendy browsers execute dynamic, usually obfuscated JavaScript and WebAssembly regionally, assaults can act on the gadget before endpoint instruments have time to reply. Quick-lived or fileless assaults could steal credentials, exfiltrate information or full their goal before a safety group can intervene.
“It is not ample to ask solely whether or not a risk might be detected,” Shen says. “The stronger method is to stop dangerous or malicious code from ever reaching the gadget in the first place.”
AI-generated malware strains signature-based detection
AI is a pressure multiplier that lets attackers automate the creation, mutation and deployment of malware at a scale signature-based instruments had been by no means designed to deal with. It might probably generate giant volumes of malware variants and assist attackers adapt fileless and browser-delivered strategies sooner than defenders can analyze them and replace signatures.
That issues as a result of polymorphic malware can alter its code or conduct from one occasion to the subsequent, making a identified signature much less dependable. And when assaults are malware-free — relying as an alternative on reputable instruments, compromised classes or malicious internet content material — there could also be no standard file signature to detect in any respect.
Enterprises have seen an 89% increase in attacks by AI-enabled adversaries over the previous 12 months, as more and more automated and adaptive assaults compress the window out there for detection and response.
“Defenders are not simply chasing extra threats, they are chasing a machine that may hold creating new ones,” Shen says. “What was adequate in the previous 10 years will not be ample in the subsequent six months,” he provides.
Constructing structure that removes the assault floor
Slightly than persevering with to refine detection, the extra sturdy response is to change the place internet code is allowed to execute in the first place.
“In a traditional browser, the danger comes to the gadget,” Shen says. “In an remoted cloud mannequin, the danger is stored away from it.”
That precept underlies Puffin Cloud Safety. Slightly than incrementally bettering the browser itself, the platform shifts browser execution into remoted cloud environments. That architectural change improves each efficiency and safety.
The platform runs the authentic internet session, together with its JavaScript, WebAssembly, and different executable payloads, inside a disposable cloud setting and streams solely a rendered pixel view to the gadget. Customers hold full interactive management over clicking, typing, and scrolling, however the gadget itself by no means parses, executes, or shops the authentic energetic code.
CloudMosa says show rasterization — the layer answerable for the pixel stream — accounts for roughly 5% of the browser’s total workload, whereas the extra compute-intensive HTML rendering stays remoted in the cloud. In consequence, zero-day exploits and AI-generated polymorphic malware don’t have any executable code to run on the endpoint, whereas fileless assaults or provide chain compromises inside SaaS instruments stay contained in the cloud.
“In CloudMosa’s view, which means transferring from good-enough safety on the gadget to hermetic safety in the cloud,” Shen says.
Becoming browser isolation into SWG, CASB and ZTNA stacks
Puffin is designed to prolong present safety infrastructure moderately than exchange it. Safe internet gateways, cloud entry safety dealer platforms, and nil belief community entry instruments stay efficient at routing visitors, imposing coverage, and controlling entry. However none can totally cease native execution as soon as dangerous content material reaches the browser.
Puffin closes that hole by routing high-risk classes by means of remoted cloud environments and imposing browser-level coverage, whether or not a person connects over a VPN, a house community, a managed gadget or an unmanaged, bring-your-own-device setup.
“Organizations can begin with slender use instances, equivalent to high-risk SaaS entry or AI agent workflows, and develop with out disrupting instruments already in place,” Shen says. “The aim is not to undo present investments, however to make them extra full.”
The selection between sooner detection or endpoint isolation
Detection will all the time have a job in enterprise safety, however the extra consequential query is not how rapidly a risk might be caught, however whether or not attackers can attain the endpoint in any respect. Current 2026 surveys discovered 92% of security professionals are involved about the impression of AI brokers, with 48% naming agentic AI the top attack vector of the year. Shen famous that brokers performing autonomously with user-level privileges are particularly uncovered to immediate injection, session hijacking, and oblique compromise by means of compromised internet content material.
In designing Puffin Cloud Safety, CloudMosa has been “paranoid by design,” which means it invested in an structure constructed for worst-case situations and for a risk setting the place endpoint safety and detection alone could not be sufficient.
“This is not only a philosophy, however one thing that is mirrored immediately in the structure itself,” Shen says. “CloudMosa constructed earlier for a harsher risk mannequin than most different organizations did, however at the moment’s AI-assisted assaults are now making that posture really feel more and more related.”
By dividing a full browser into a really small layer on the gadget and a a lot bigger layer in the cloud, CloudMosa designed this method to enhance each efficiency and safety at the identical time: In Puffin Cloud Safety’s structure, an AI agent’s browser exercise takes place inside remoted cloud sandboxes. The endpoint receives solely a pixel stream, not the authentic energetic code, stopping malicious internet content material from interacting immediately with the gadget, its credentials or linked programs.
“AI-assisted hacking represents the form of structural shift that rewards firms prepared to rethink browser from the floor up,” Shen says. “And so safety leaders now have a selection: redesign for foresight, or wait till hindsight makes the lesson unavoidable.”
Sponsored articles are content material produced by an organization that is both paying for the submit or has a enterprise relationship with VentureBeat, and so they’re all the time clearly marked. For extra information, contact [email protected].
Disclaimer: This article is sourced from external platforms. OverBeta has not independently verified the information. Readers are advised to verify details before relying on them.