As modern organizations migrate core workflows to cloud-hosted platforms, the threat landscape has shifted decisively toward the web browser. While Endpoint Detection and Response (EDR) solutions remain foundational for identifying malicious host execution, they possess inherent blind spots when attacks occur entirely within identity and web application layers. As detailed in a report by NordLayer (according to BleepingComputer), modern campaigns frequently bypass host-based telemetry by weaponising legitimate browser features, compromised SaaS sessions, and rogue extensions.
Understanding Browser-Based EDR Blind Spots
Traditional endpoint telemetry relies on process creation, file modifications, and kernel-level visibility to flag anomalous activity. However, in enterprise environments where applications run predominantly inside the browser, high-impact actions like OAuth token abuse, data exfiltration, and session hijacking do not generate malicious executables.
For instance, during the 2025 Salesloft Drift incident, threat actor UNC6395 acquired OAuth tokens tied to Drift integrations, issuing high-api volume requests against target Salesforce tenants without triggering host-level malware alerts. Because the interactions occurred through authenticated SaaS channels, standard endpoint monitoring treated the activity as normal user behavior.
Adversary-in-the-Middle Phishing and Session Hijacking
Adversary-in-the-middle (AiTM) phishing frameworks present another severe challenge for conventional security architectures. In 2026, threat actors tracked by Microsoft as Storm-2755 targeted Canadian personnel via search engine poisoning and malicious advertisements. Victims navigated to lookalike Microsoft 365 login portals that successfully proxied real-time authentication flows.
The AiTM infrastructure harvested valid credentials, multi-factor authentication responses, and session cookies. Attackers subsequently performed session replay attacks, shifting the valid session identifier from a victim’s endpoint to an external Axios user agent. With active tokens in hand, the operators accessed internal resources, manipulated inbox rules, and searched through enterprise HR systems without tripping endpoint process monitoring.
Malicious Browser Extensions
Browser extensions introduce unique visibility challenges. Because their code executes natively inside browser processes and leverages standard web APIs, malicious extensions can read page contents, observe active URLs, and scrape form data over encrypted HTTPS connections without creating suspicious host artifacts.
In March 2026, Microsoft identified malicious Chromium extensions masquerading as artificial intelligence assistants. Installed approximately 900,000 times across more than 20,000 enterprise tenants, these extensions quietly harvested user interactions from ChatGPT and DeepSeek sessions, exfiltrating conversational data to external attacker-controlled servers while the host environment displayed routine browser network traffic.
Actionable Defences and Mitigations
To bridge the gap left by traditional telemetry, security teams must implement defense-in-depth strategies tailored specifically to the web layer:
- Deploy Phishing-Resistant Authentication: Implement FIDO2 WebAuthn authentication. Cryptographically tying the authentication response to the legitimate origin neutralises credential harvesting and AiTM proxy frameworks.
- Enforce Browser Controls: Utilize dedicated enterprise browser security solutions to govern web access, restrict unapproved SaaS applications, and route traffic through dedicated IP addresses for granular identity policy enforcement.
- Establish Extension Inventories: Implement strict extension allowlists, installation controls, and continuous permission reviews, paying close attention to any add-ons capable of reading or modifying page content.
Related: UNC6671 Rebrands: Multi-Brand Vishing and Cloud Extortion, 39 Methods Compromise Passkey Authentication: Threat Analysis