Endpoint Detection and Response (EDR) systems, while crucial for detecting host-level code execution, may not fully address the evolving landscape of browser-based attacks, according to recent analysis. Many modern threats leverage browser sessions and cloud applications, performing malicious actions that do not generate the typical endpoint artifacts EDR solutions are designed to monitor. This creates a "blind spot" for organizations heavily reliant on SaaS environments.
One significant area of concern is adversary-in-the-middle (AiTM) phishing. In 2026, a threat actor designated Storm-2755 by Microsoft targeted Canadian employees through search engine poisoning and malicious advertisements. Victims searching for terms like "Office 365" were redirected to attacker-controlled Microsoft 365 login pages. The AiTM infrastructure then proxied the authentication flow, capturing credentials, session cookies, and OAuth access tokens in real time. Storm-2755 subsequently replayed these stolen sessions, with Microsoft observing session ID switches from victim browsers to an Axios user agent, indicating token reuse from attacker infrastructure. This allowed attackers to access Microsoft services, search for payroll and HR information, create inbox rules to hide banking-related messages, and in some cases, access Workday. From an ordinary endpoint perspective, the authentication flow might appear legitimate, as the decisive action of interception occurs within the browser and the proxy, not through a new malicious process on the host.
Compromised browser extensions represent another vector that can evade traditional EDR. These extensions reside within browser profiles and execute code within browser processes. While EDR might flag suspicious extensions or unusual network activity, the extension's behavior can often mimic normal host-level operations. Malicious extensions can utilize standard browser APIs to read page content, monitor URLs, interact with forms, and transmit data over HTTPS without initiating new processes or suspicious executables. Without specific browser context, security teams might observe browser traffic but lack the ability to identify which extension initiated it, what data was accessed, or if the extension was approved. For instance, in March 2026, Microsoft reported on malicious Chromium extensions disguised as AI assistants, which were installed approximately 900,000 times across more than 20,000 enterprise tenants. These extensions collected visited URLs and content from ChatGPT and DeepSeek conversations, periodically exfiltrating this data to attacker-controlled infrastructure. The host telemetry would simply show a browser process making HTTPS connections, while the critical security event—data exfiltration—occurs within the extension's context.
Finally, some browser attacks complete entirely within the web session, prior to any endpoint execution. A compromised website, malicious advertisement, or injected script can alter rendered content, read page-accessible data, redirect the session, or manipulate the clipboard. These actions often operate within browser-granted permissions and do not require writing files, launching malware, or creating new processes. Users can also inadvertently upload sensitive files or paste confidential information into unauthorized SaaS or AI services without any malware installation. While potentially damaging, such actions do not generate the artifacts EDR is designed to detect. An example is the "ClickFix" attack, which uses fake verification prompts to trick victims into copying and executing malicious commands. Microsoft observed a variant, "TerminalFix," in August 2026, where compromised websites displayed fake Cloudflare CAPTCHA prompts. Clicking the fake verification step copied a malicious PowerShell command to the clipboard, with instructions for the victim to paste and execute it in Windows Terminal or PowerShell. Until the command execution, the attack relied solely on browser content, clipboard manipulation, and user interaction, remaining outside typical endpoint telemetry. Once the command is executed, however, EDR can then detect PowerShell activity, file downloads, persistence mechanisms, and outbound connections.
These examples highlight that while EDR remains a vital component of cybersecurity, its effectiveness can be limited when attacks primarily exploit browser functionality, identity workflows, and cloud applications without triggering host-level malware execution.






