The persistent reliance on Endpoint Detection and Response (EDR) solutions for comprehensive cybersecurity, while vital for identifying malicious code execution on host devices, is increasingly insufficient in today’s Software-as-a-Service (SaaS)-dominated digital environments. As attackers pivot their strategies to exploit the pervasive use of cloud-based applications accessed primarily through web browsers, organizations face a growing blind spot that traditional endpoint defenses struggle to illuminate. This shift necessitates a reevaluation of security architectures, emphasizing the critical need for robust browser-level controls to complement existing EDR capabilities.
The fundamental challenge arises when attackers bypass the traditional attack vectors that EDR is designed to detect. In SaaS-heavy infrastructures, employees frequently interact with cloud applications through their web browsers. This interaction can involve routine yet sensitive actions such as authenticating to critical business systems, approving OAuth requests for third-party integrations, accessing and manipulating sensitive files, or uploading proprietary data. These actions, from the perspective of the endpoint, can appear as normal user activity within a legitimate browser session, failing to trigger the process-level anomalies or executable file detections that EDR systems are engineered to flag.
A stark illustration of this vulnerability was observed in the 2025 Salesloft Drift incident, a sophisticated attack campaign meticulously detailed in a Google Cloud security report. Threat actors, identified as UNC6395, successfully obtained OAuth tokens that were intrinsically linked to Drift’s integration capabilities. By leveraging these compromised tokens, the attackers launched a barrage of high-volume API calls directly against the Salesforce environments of affected customers. This allowed for significant data exfiltration without the deployment of any malware or the initiation of suspicious processes that would typically alert an EDR system. The attack underscored how authenticated access to SaaS platforms, when compromised, can become a potent weapon for data theft, operating entirely beneath the radar of traditional endpoint monitoring.
The browser has unequivocally emerged as the primary gateway to a vast array of corporate resources. From sensitive SaaS applications and identity management workflows to collaborative document repositories and administrative consoles, nearly every facet of modern business operations is now accessible via a web browser. Data from NordLayer’s 2026 Browser Security Report, which analyzed 504 distinct applications, revealed that browser access is ubiquitous, with an overwhelming 79% of surveyed tools being exclusively accessible through a web browser. This pervasive reliance means that browser sessions are not merely a conduit but a critical locus of user activity, often generating minimal endpoint artifacts that EDR was originally designed to scrutinize.
While EDR continues to excel at detecting host-based execution, malware deployment, persistence mechanisms, and suspicious process behaviors, its efficacy diminishes when attacks are orchestrated through browser and identity workflows that circumvent these detection methods. This includes sophisticated phishing schemes, the exploitation of malicious browser extensions, unauthorized data uploads facilitated through web interfaces, and social engineering tactics that leverage clipboard manipulation. In these scenarios, the decisive actions and critical data compromise occur within the confines of the browser session or the cloud application itself, leaving endpoint defenses at a significant disadvantage.
Adversary-in-the-Middle (AiTM) Phishing: A Sophisticated Session Hijacking Tactic
A prominent and increasingly dangerous attack vector exploiting browser vulnerabilities is Adversary-in-the-Middle (AiTM) phishing. In 2026, Microsoft security researchers detailed an incident involving a threat actor designated as Storm-2755, also known as "Payroll Pirate." This group targeted Canadian employees through a malicious campaign that leveraged search engine poisoning and deceptive advertisements. Individuals searching for legitimate services, such as "Office 365," were redirected to meticulously crafted, attacker-controlled Microsoft 365 login pages.
The sophistication of this attack lay in its AiTM infrastructure, which acted as a real-time proxy for the authentication flow. As users entered their credentials and proceeded through multi-factor authentication (MFA), the attacker’s proxy intercepted not only the username and password but crucially, the session cookies and OAuth access tokens issued upon successful authentication. This allowed Storm-2755 to replay the captured, legitimate user session, effectively hijacking it. Microsoft observed telemetry indicating a seamless transition of session IDs from the victim’s browser to an attacker-controlled Axios user agent, confirming the reuse of authentication tokens from an unauthorized infrastructure.
The ramifications of such a compromise were severe. Attackers gained access to Microsoft services, enabling them to meticulously search for sensitive payroll and HR information. They further employed tactics such as creating hidden inbox rules to prevent employees from receiving alerts about banking changes and, in some instances, accessed critical systems like Workday, a human resources management platform.
The mechanics of AiTM phishing are designed to circumvent traditional security measures by inserting a malicious intermediary between the user and the legitimate identity provider. The phishing page captures credentials and relays legitimate MFA challenges, passing the user’s response back to the real service. Crucially, the attacker can then capture the authenticated session material, including tokens that grant access for an extended period. From the perspective of standard endpoint process telemetry, the authentication flow may appear entirely legitimate. The endpoint itself often fails to reveal that an AiTM proxy has intercepted the session, though a combination of other security signals—including identity, network, and Extended Detection and Response (XDR) telemetry—can potentially expose such attacks.
The most robust defense against many AiTM attacks involves the adoption of phishing-resistant authentication methods, such as FIDO2 WebAuthn. This technology cryptographically binds the authentication response to the legitimate origin of the website, rendering stolen credentials and session tokens significantly less valuable to attackers. Complementary browser controls can further enhance security by blocking known phishing destinations, restricting access to unapproved web applications, and proactively halting attacks before they can progress.
Compromised Browser Extensions: A Stealthy Infiltration Vector
Browser extensions, while offering enhanced functionality and user experience, present another significant visibility challenge for security teams. These extensions store files within the browser profile and execute their code within the context of browser processes. While EDR solutions might detect a suspicious extension or unusual network activity originating from the browser, the extension’s internal behavior can often appear innocuous at the host level.
A malicious browser extension can leverage standard browser APIs to perform actions such as reading page content, monitoring visited URLs, interacting with form fields, and transmitting data over HTTPS. Crucially, these actions do not typically necessitate the creation of new processes or the execution of distinct, suspicious executables, thus evading typical EDR alerts. Without browser-specific context, security teams might observe the browser traffic but lack the crucial insight to identify which extension initiated the activity, what specific data was accessed, or whether the extension was even an approved component of the organization’s software stack.
A recent and concerning example emerged in March 2026 when Microsoft reported on a wave of malicious Chromium-based extensions masquerading as AI assistants. These extensions were installed approximately 900,000 times, with confirmed malicious activity spanning over 20,000 enterprise tenants. The primary function of these extensions was to harvest sensitive data, including visited URLs and conversation histories from popular Large Language Model (LLM) platforms like ChatGPT and DeepSeek. This stolen data was then periodically exfiltrated to attacker-controlled infrastructure.
In such cases, the host system might exhibit normal behavior, with the browser process establishing standard HTTPS connections. However, the truly security-relevant action—the unauthorized reading and exfiltration of sensitive content—is carried out by the extension operating within the browser’s privileged environment. While endpoint tools might detect parts of this activity, a comprehensive understanding requires context derived from extension inventory, explicit permission reviews, and policy enforcement. Without this browser-centric visibility, distinguishing legitimate activity from malicious data harvesting becomes exceptionally difficult.
To effectively counter threats posed by compromised browser extensions, security teams must adopt a proactive approach by directly controlling the extension layer. This involves establishing explicit extension allowlists, implementing robust installation controls, and conducting regular permission reviews for any extension capable of reading or modifying web content. Relying solely on detecting malicious domains, malware signatures, or endpoint alerts is insufficient when the threat resides within an authorized, yet compromised, browser component.

Browser Attacks Preceding Endpoint Execution: The New Frontier
A growing category of browser-based attacks achieves its objectives entirely within the web session, often before any malicious activity registers on the endpoint’s telemetry. This can occur through various means, including compromised websites, malicious advertisements, or injected scripts. These elements can manipulate rendered content, access sensitive page-accessible data, redirect user sessions, or compromise the system’s clipboard. These actions are frequently executed within the permissions already granted to the browser and do not necessitate writing files, launching malware, or creating new processes. Furthermore, users can inadvertently upload sensitive files or paste confidential text into unauthorized SaaS or AI services without any malware being installed on their devices.
While these actions can lead to significant data breaches or operational disruptions, they often fail to generate the distinct artifacts that EDR systems are designed to detect. A prime example is the "ClickFix" attack methodology, which employs deceptive verification prompts or other malicious web content to trick victims into copying and executing a command.
Microsoft observed a sophisticated variant of this technique in its August 2026 TerminalFix campaign. This multi-stage intrusion campaign involved compromised websites displaying fake Cloudflare CAPTCHA prompts. Upon clicking the deceptive verification step, a malicious PowerShell command was copied to the user’s clipboard. The compromised page then instructed the victim to open a terminal application, such as Windows Terminal or PowerShell, and paste the command.
Up to this point, the attacker’s reliance was on manipulating browser content, exploiting clipboard functionality, and leveraging user interaction. The execution of the copied command marked a critical transition, as it began to generate endpoint telemetry. This subsequent activity included PowerShell execution, the download and extraction of a ZIP archive, DLL side-loading, the establishment of persistence through registry modifications and scheduled tasks, Active Directory discovery, and the creation of a reverse tunnel back to the attacker’s infrastructure.
Browser controls can effectively neutralize these attacks at their nascent stage, before host execution even occurs. By blocking malicious pages, restricting clipboard access, or limiting risky browser actions, organizations can prevent the initial compromise. Should a user proceed to execute a copied command, the subsequent activity then enters the realm of endpoint telemetry, where EDR can indeed play its crucial role in inspecting PowerShell execution, downloaded files, persistence mechanisms, discovery activities, and outbound network connections.
The Imperative for Layered Security: Matching Controls to Actions
The stark reality in today’s SaaS-centric operational landscape is that EDR solutions, by themselves, cannot comprehensively address every high-risk action. The expectation that endpoint telemetry alone will flag every malicious login, every OAuth approval, every browser-based upload, or every suspicious extension action is a flawed premise that can lead to significant blind spots, particularly when attacks remain confined to the browser session without ever manifesting as host execution.
To effectively secure modern organizations, a layered security approach is indispensable, integrating controls across three interconnected domains: endpoint, identity, and browser.
Endpoint Security (EDR): Continues to be a foundational element, crucial for detecting and responding to threats that involve direct execution of malicious code on devices, malware deployment, and established persistence mechanisms.
Identity and Access Management (IAM): Robust identity controls are paramount for verifying user authenticity, managing access privileges, and detecting anomalous login patterns. This includes implementing multi-factor authentication (MFA) and employing conditional access policies that adapt security based on context.
Browser Security Controls: This is the critical layer that has historically been underserved but is now indispensable. Browser controls are needed to intercept threats before sensitive data reaches unauthorized SaaS or AI services. Once a user uploads a file, pastes confidential text, or grants excessive browser permissions, the endpoint telemetry may not provide sufficient context to fully understand or mitigate the action. Web threat protection capabilities can proactively block phishing attempts and malicious websites. Granular extension policies can prevent unapproved or malicious code from accessing and manipulating web content. Browser Data Loss Prevention (DLP) policies can impose restrictions on uploads, downloads, and copy-and-paste actions based on the destination, thereby safeguarding sensitive information.
In SaaS-heavy environments, the browser is not merely another application to monitor; it is the primary access layer for an organization’s most critical assets: corporate data, identity providers, and essential administrative workflows. Therefore, security controls must operate at this fundamental layer. Malicious logins, unauthorized OAuth grants, compromised extension access, illicit uploads, and insidious clipboard actions often occur without generating the tell-tale endpoint artifacts that traditional EDR systems are built to detect. While EDR remains vital for host execution scenarios, when an attack remains contained within a browser session, the browser itself transforms from a passive conduit into an active and significant attack surface.
For organizations seeking to understand the extent of their browser-related security exposure and evaluate their capacity to address these evolving threats, NordLayer’s comprehensive Web-based Threats Report offers valuable data and insights.
To experience firsthand how managed browser controls can fortify your organization’s security posture, identify the use of unapproved applications, and enforce access policies across teams, NordLayer Browser offers a 30-minute demonstration. This session will showcase how to deploy these critical browser-level defenses.
About the Author:
Andrius Buinovskis, VP of Product Strategy at NordLayer, brings over two decades of experience in the IT sector, with a focused passion for cybersecurity ignited in 2015. In his current role, he spearheads the product development agenda at NordLayer, a network security platform designed for businesses. His strategic direction is informed by extensive market research, a deep understanding of client needs, and a thorough assessment of technical capabilities. Buinovskis is committed to fostering confidence within his product team, empowering them to tackle complex security challenges and translate innovative discoveries into enhanced protection for NordLayer’s clientele.
This article was sponsored and written by NordLayer Browser.







