browser security news
2 stories
browser securityhigh
The EDR blind spot: 3 ways browser attacks evade endpoint telemetry
Endpoint Detection and Response (EDR) systems, while crucial for detecting host-level code execution, may not fully address the evolving landscape of browser-based attacks, according to recent analysis. Many modern threats leverage browser sessions and cloud applications, performing malicious actions that do not generate the typical endpoint artifacts EDR solutions are designed to monitor.…

ransomwarehigh
Browser-Only Ransomware: From LLM Hallucinations to a Practical Attack Technique
Check Point Research has identified a novel ransomware technique that operates entirely within a web browser, bypassing the need for native malware installation or exploits. This "browser-only" ransomware leverages the File System Access API in Google Chrome, particularly on Android devices, to encrypt user files after tricking them into granting access.