LIVE · cybersecurity feed
Live wire
CVE-2026-88779 · Citrix NetScaler Flaw Exploited Before CVE PublicationCVE-2026-88779 · NetScaler CVE-2026-88779 Exploited Before PublicationCVE-2022-28368 · dompdf_project dompdf XSS flaw added to VulnCheck KEVCVE-2026-88771 · Week in review: Researcher breaks into Microsoft analytics service, NetScaler RCE 0-day exploitedWarlock Ransomware Still Exploits Year-Old SharePoint Flaws to Hit Critical InfrastructureShinyHunters Suspect Rey Reportedly Detained in Jordan, Helping FBI Identify Group MembersChina-Aligned TA419 Targets U.S. AI Policy Experts With Microsoft AitM PhishingCVE-2026-7273 · Zyxel GS1900 Switch Flaw Exploited, Now in EU CatalogueCVE-2026-102489 · Zammad Session Fixation Vulnerability Exploited Same Day as DisclosureCVE-2026-102490 · Zammad GmbH Zammad Vulnerability Exploited Same Day as Publication
browser securityhigh

The EDR blind spot: 3 ways browser attacks evade endpoint telemetry

Endpoint Detection and Response (EDR) systems, while crucial for detecting host-level code execution, may not fully address the evolving landscape of browser-based attacks, according to recent analysis. Many modern threats leverage browser sessions and cloud applications, performing malicious actions that do not generate the typical endpoint artifacts EDR solutions are designed to monitor.…

ZeroDay News ·

Source: BleepingComputer

Endpoint Detection and Response (EDR) systems, while crucial for detecting host-level code execution, may not fully address the evolving landscape of browser-based attacks, according to recent analysis. Many modern threats leverage browser sessions and cloud applications, performing malicious actions that do not generate the typical endpoint artifacts EDR solutions are designed to monitor. This creates a "blind spot" for organizations heavily reliant on SaaS environments.

One significant area of concern is adversary-in-the-middle (AiTM) phishing. In 2026, a threat actor designated Storm-2755 by Microsoft targeted Canadian employees through search engine poisoning and malicious advertisements. Victims searching for terms like "Office 365" were redirected to attacker-controlled Microsoft 365 login pages. The AiTM infrastructure then proxied the authentication flow, capturing credentials, session cookies, and OAuth access tokens in real time. Storm-2755 subsequently replayed these stolen sessions, with Microsoft observing session ID switches from victim browsers to an Axios user agent, indicating token reuse from attacker infrastructure. This allowed attackers to access Microsoft services, search for payroll and HR information, create inbox rules to hide banking-related messages, and in some cases, access Workday. From an ordinary endpoint perspective, the authentication flow might appear legitimate, as the decisive action of interception occurs within the browser and the proxy, not through a new malicious process on the host.

Compromised browser extensions represent another vector that can evade traditional EDR. These extensions reside within browser profiles and execute code within browser processes. While EDR might flag suspicious extensions or unusual network activity, the extension's behavior can often mimic normal host-level operations. Malicious extensions can utilize standard browser APIs to read page content, monitor URLs, interact with forms, and transmit data over HTTPS without initiating new processes or suspicious executables. Without specific browser context, security teams might observe browser traffic but lack the ability to identify which extension initiated it, what data was accessed, or if the extension was approved. For instance, in March 2026, Microsoft reported on malicious Chromium extensions disguised as AI assistants, which were installed approximately 900,000 times across more than 20,000 enterprise tenants. These extensions collected visited URLs and content from ChatGPT and DeepSeek conversations, periodically exfiltrating this data to attacker-controlled infrastructure. The host telemetry would simply show a browser process making HTTPS connections, while the critical security event—data exfiltration—occurs within the extension's context.

Finally, some browser attacks complete entirely within the web session, prior to any endpoint execution. A compromised website, malicious advertisement, or injected script can alter rendered content, read page-accessible data, redirect the session, or manipulate the clipboard. These actions often operate within browser-granted permissions and do not require writing files, launching malware, or creating new processes. Users can also inadvertently upload sensitive files or paste confidential information into unauthorized SaaS or AI services without any malware installation. While potentially damaging, such actions do not generate the artifacts EDR is designed to detect. An example is the "ClickFix" attack, which uses fake verification prompts to trick victims into copying and executing malicious commands. Microsoft observed a variant, "TerminalFix," in August 2026, where compromised websites displayed fake Cloudflare CAPTCHA prompts. Clicking the fake verification step copied a malicious PowerShell command to the clipboard, with instructions for the victim to paste and execute it in Windows Terminal or PowerShell. Until the command execution, the attack relied solely on browser content, clipboard manipulation, and user interaction, remaining outside typical endpoint telemetry. Once the command is executed, however, EDR can then detect PowerShell activity, file downloads, persistence mechanisms, and outbound connections.

These examples highlight that while EDR remains a vital component of cybersecurity, its effectiveness can be limited when attacks primarily exploit browser functionality, identity workflows, and cloud applications without triggering host-level malware execution.

browser securityedrsaas securityphishingmalware
ShareXLinkedInWhatsAppFacebook

More News

view all →
breach

Frontline Education Breach Impacts K-12 School District Staff

Frontline Education, a prominent software provider for K-12 school districts in the United States, has confirmed a data breach that exposed the personal information of school staff. The incident, which was discovered on August 14, 2026, stemmed from a vulnerability in a third-party software product utilized by the company.

vulnerability

Google halts open-source bug bounty program amid AI spam surge

Google has temporarily suspended submissions for product vulnerabilities to its Open Source Software Vulnerability Rewards Program (OSS VRP), effective October 1, 2026. The company cited a significant increase in automated submissions, most of which were deemed invalid, as the reason for the pause.

ai

Apple tightens macOS disk access as AI agents become more powerful

Apple is implementing stricter controls for Full Disk Access in macOS, citing an increased risk to user privacy from increasingly capable and autonomous AI agents. The company indicated that future macOS versions will require users to take explicit steps to grant applications this permission. A specific rollout date and the precise mechanics of these new controls have not yet been detailed.

nation-state

doxx.net opens Agentic Defined Networking public beta, raises $38 million

doxx.net has launched the public beta of its Agentic Defined Networking (ADN) platform, which enables users and their AI agents to establish private, secure networks and communicate without intermediary servers. The company also announced it has secured $38 million in Series A funding, led by Andreessen Horowitz, with additional participation from Animo Ventures and Focal.vc. As part of the…

vulnerability

AI slop submissions force Google to freeze its open-source bug bounty

Google has temporarily halted its Open Source Software Vulnerability Reward Program (OSS VRP) for new product vulnerability submissions, effective October 1, 2026. The company cited a substantial increase in automated, AI-generated reports, most of which were invalid, as the reason for the pause. This influx of low-quality submissions overwhelmed the engineers and open-source maintainers…

nation-state

Another OpenAI Safety Expert Quits and Raises New AI Safety Concerns

David Robinson, a veteran safety expert at OpenAI, has resigned from the company, citing concerns about its culture and rapid AI development model. Robinson, who was instrumental in authoring safety reports accompanying major product launches during his three-and-a-half-year tenure, stated that he believes the company's current trajectory is unacceptable.