Security Researchers Identify Critical Gaps in Endpoint Detection Against Browser-Based Attacks

Endpoint Detection and Response systems may miss attacks conducted through web browsers and cloud applications that do not generate the traditional malware signatures or process-level artifacts these tools are designed to detect. Adversaries exploit this blind spot by conducting session hijacking, deploying malicious browser extensions, and conducting phishing attacks that capture OAuth tokens and authentication credentials without triggering endpoint security alerts. The research highlights that as organizations increasingly rely on browser-based SaaS applications, defenders must implement additional browser-level security controls alongside traditional endpoint protection.
Modern enterprise environments have shifted dramatically toward cloud-based software delivered through web browsers, with research indicating that 79% of organizational applications now operate exclusively in this manner. This architectural change means that critical business functions—file access, identity verification, data transfers, and administrative tasks—occur within browser sessions rather than through traditional desktop software, fundamentally altering the threat landscape that security tools were originally designed to address.
Attackers have adapted to exploit this gap by targeting authentication mechanisms and session management at the browser level. The 2025 Salesloft incident exemplified this approach, where threat actors obtained valid OAuth tokens through compromised integrations and used them to conduct extensive data theft operations. Because these actions authenticated legitimately through the browser, they generated minimal suspicious activity at the endpoint level where traditional detection systems focus their monitoring.
Organizations relying heavily on endpoint detection tools may face increased vulnerability to credential theft and unauthorized access if they do not implement complementary browser-level security measures. This could particularly affect enterprises managing sensitive data through cloud applications, where the current tooling may leave substantial detection gaps. The findings suggest that security budgets and architectural decisions in coming years may need rebalancing to address browser-based risks alongside traditional host-based threats, potentially requiring additional investment in identity protection and web access controls.