Why Are We Still Targeting Endpoints When Most Attacks Hit the Browser?

Presented by CloudMosa
As workplaces increasingly shift toward browser-based operations, the browser has become a significant target for cyberattacks. Reports indicate a marked increase in browser-related attacks over the past two years, and projections from Gartner suggest that over 85% of enterprise tasks will be conducted through browsers by 2027.
Despite this trend, many enterprise security frameworks still focus on protecting devices, neglecting the browser sessions where these digital vulnerabilities emerge. Shioupyn Shen, founder and CEO of CloudMosa—developer of Puffin Cloud Security—notes that the company’s initial goal was to enhance browser performance and accessibility in anticipation of this shift toward web-based work.
“Today, as AI-driven hacking becomes prevalent, our cloud structure not only boosts performance but also lays a solid foundation for contemporary enterprise security,” Shen remarks.
The Browser as the Core Operating Environment
Various cloud-based platforms, customer relationship management (CRM), enterprise resource planning (ERP) systems, and collaboration tools have transformed the browser into a key access point and central workspace for business operations. As workflows powered by large language models (LLMs) and AI agents increasingly utilize this environment, the nature of potential threats has evolved.
In a world centered around devices, security teams could primarily focus on endpoints and networks they could monitor and manage. However, with web code executing directly on users’ devices, every open browser tab is now a possible gateway for malicious scripts, credential theft, and other exploits.
Modern browsers interpret and run remote code, manage authenticated sessions for enterprise applications, and serve as execution layers for AI-driven workflows.
“The browser has evolved beyond simply being another application on the endpoint,” says Shen. “It now serves as the principal operating environment for today’s enterprise work, yet traditional browsers were not constructed to handle this level of responsibility. They were intended as local interpreters of remote code, lacking the isolation and policy enforcement necessary for enterprise-grade security.”
Challenges of Detection-First Security Against Browser-Based Threats
Detection-first security has a critical flaw: it generally activates only after risky code arrives at the device and begins executing within the browser. Modern browsers run dynamic and often obscured JavaScript and WebAssembly code locally, allowing attacks to act before endpoint security tools can respond. Quick, ephemeral attacks may breach defenses before a security team can react.
“The focus must shift from merely detecting a threat to preventing harmful code from ever reaching the device,” Shen advises.
AI’s Impact on Malware and Signature-Based Detection
AI enables attackers to automate the creation, mutation, and deployment of malware, overwhelming signature-based detection systems. This technology allows them to generate various malware versions with speed, making it harder for defenders to keep pace with necessary updates and analysis.
This has significant implications since polymorphic malware changes its code or behavior with each iteration, rendering known signatures less effective. Moreover, attacks leveraging legitimate tools or compromised sessions often do not leave behind detectable file signatures.
Organizations have experienced a staggering 89% increase in AI-powered attacks over the past year, highlighting the accelerated and adaptive nature of these threats.
“Defenders are not just contending with a greater number of threats; they’re combating automated systems that continuously produce new ones,” Shen states. “What was once adequate may soon be insufficient.”
Transforming Architecture to Reduce Vulnerabilities
Instead of merely refining detection methods, a more effective strategy involves altering where web code is permitted to execute.
“In a traditional browser framework, risks are directed toward the device,” explains Shen. “In a cloud-isolated model, those risks are mitigated.”
This principle is the foundation of Puffin Cloud Security. Rather than making incremental adjustments to the browser, the platform relocates browser execution to isolated cloud settings, thereby enhancing both performance and security.
By processing the original web session—including all JavaScript, WebAssembly, and executable payloads—within a disposable cloud environment, only a rendered image is streamed to the device. Users maintain interactive control, yet their device never interprets or stores the active original code.
According to CloudMosa, the rendering layer accounts for about 5% of total browsing tasks, with the more resource-intensive HTML rendering conducted in the cloud. This architecture prevents zero-day exploits and AI-generated malware from operating on the endpoint, while mitigating the impact of fileless attacks or supply chain vulnerabilities within SaaS applications.
“This approach is about transitioning from acceptable security on devices to robust cloud security,” Shen claims.
Integrating Browser Isolation within Security Frameworks
Puffin is designed to complement existing security infrastructures rather than replace them. Secure web gateways, cloud access security brokers, and zero-trust network access tools remain effective in monitoring traffic and enforcing policies. However, they cannot prevent local execution once risky content infiltrates the browser.
Puffin addresses this gap by guiding high-risk activities through isolated cloud environments, enforcing browser policies whether users connect via VPNs, personal networks, managed devices, or unmanaged devices.
“Organizations can begin with specific high-risk scenarios like SaaS access or AI workflows and gradually expand without disrupting established systems,” Shen mentions. “The goal is not to reverse existing investments but to enhance them.”
Choosing Between Faster Detection and Endpoint Isolation
While detection will remain a key component of enterprise security, a more pressing inquiry is whether attackers can even reach the endpoint. Recent surveys indicate that 92% of security experts are wary of the effects of AI agents, with nearly half identifying agentic AI as a primary attack vector for the coming year. Shen highlights the vulnerabilities faced by agents acting autonomously with user permissions, as they are especially prone to various forms of compromise.
In creating Puffin Cloud Security, CloudMosa has prioritized a security architecture capable of handling worst-case situations in an evolving threat landscape where endpoint security alone may fall short.
“This philosophy is deeply embedded in our architecture,” Shen explains. “We built our systems for a tougher threat model than most organizations, and as AI-driven attacks grow, this approach becomes more relevant.”
By segmenting the browsing experience into a minimal layer on the device and a more expansive layer in the cloud, CloudMosa has designed this strategy to bolster both performance and security: Puffin Cloud Security facilitates AI agent activities within isolated cloud environments. The endpoint only receives a pixel-rendered stream, preventing any malicious content from engaging directly with the device or its credentialed systems.
“AI-enhanced hacking signifies a profound transformation that rewards organizations willing to rethink their approach to web security,” Shen concludes. “Thus, security leaders face a pivotal decision: innovate proactively or face the consequences of delayed understanding.”
Sponsored articles are content produced by a company that is either paying for the post or has a business relationship with the publisher, and they are always clearly marked.



