Join our Newsletter — 33% off our NHI Course

Browser blind spots and identity attacks: are your controls keeping up?

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 21730
Topic starter  

TL;DR: Browser-based identity attacks now exploit the gap between endpoint telemetry and what happens inside the session layer, according to Push Security, while its analysis cites a 389% year-over-year surge in PhaaS-driven account compromise and a 37x increase in device code phishing. The governance problem has moved from endpoint visibility to session-level control over authentication, tokens, and response.

Editorial analysis by NHI Mgmt Group, based on content published by Push Security: “Your EDR is working exactly as intended. Attackers are getting around it anyway.”.

By the numbers:

  • 82% of attack detections are now malware-free, according to CrowdStrike's 2026 Global Threat Report cited by Push Security.
  • PhaaS-driven account compromise surged 389% year-over-year, according to eSentire research cited by Push Security.
  • Fake CAPTCHA lures used in ClickFix attacks increased 563% in 2025, according to CrowdStrike research cited by Push Security.

Key questions

Q: What breaks when identity controls stop at the endpoint and ignore the browser session?

A: Browser-native attacks can complete authentication, steal tokens, and trigger consent without host-level malware or suspicious process activity.

Q: Why do adversary-in-the-middle attacks still work when MFA is enabled?

A: Because the attacker does not need to defeat MFA directly.

Q: How do security teams know whether browser-layer identity detection is working?

A: Look for whether the programme can distinguish a normal page visit from a proxied login, a cloned form, a suspicious consent grant, or a token leaving the expected trust boundary.

Practitioner guidance

  • Map browser-resident identity flows Identify which authentication, consent, and admin workflows complete inside the browser rather than in a managed desktop control path.
  • Instrument session-layer detection Collect telemetry on page behaviour, form structure, script activity, and suspicious token issuance so that phishing and relay attacks can be detected where they occur.
  • Review browser extension risk Inventory extensions that can read pages, intercept input, or handle tokens, then verify which ones have permissions that could support account takeover or session theft.

Bottom line: Browser-native attacks succeed because they operate where identity is actually used, not where endpoint tools are strongest.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 1 day ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21566
 

Browser-layer identity attacks expose a visibility gap, not just a detection gap. The core problem is that EDR observes the host while attackers now operate in the session, where authentication, token issuance, and application access converge. That makes browser telemetry a governance requirement for identity programmes, not an optional enhancement. Practitioners should treat browser visibility as part of identity control design, not a separate security tool category.

A few things that frame the scale:

  • 1 in 4 organisations are already investing in dedicated NHI security capabilities, with an additional 60% planning to do so within the next twelve months, according to The State of Non-Human Identity Security.
  • 85% of organisations lack full visibility into third-party vendors connected via OAuth apps, with 38% reporting no or low visibility and 47% only partial visibility.

A question worth separating out:

Q: How can teams decide whether they need browser-native controls or more network filtering?

A: Teams should use browser-native controls when the risk is inside the session, such as credential relay, token theft, or malicious clipboard execution. Network filtering helps with known-bad destinations, but it cannot reliably see what happens after the page loads. If the attack is identity-driven, inspection must move into the browser.

👉 Read our full editorial: Browser blind spots are where modern identity attacks succeed



   
ReplyQuote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21566
 

Browser-layer identity attacks expose a visibility gap, not just a detection gap. The core problem is that EDR observes the host while attackers now operate in the session, where authentication, token issuance, and application access converge. That makes browser telemetry a governance requirement for identity programmes, not an optional enhancement. Practitioners should treat browser visibility as part of identity control design, not a separate security tool category.

A few things that frame the scale:

  • 1 in 4 organisations are already investing in dedicated NHI security capabilities, with an additional 60% planning to do so within the next twelve months, according to The State of Non-Human Identity Security.
  • 85% of organisations lack full visibility into third-party vendors connected via OAuth apps, with 38% reporting no or low visibility and 47% only partial visibility.

A question worth separating out:

Q: How can teams decide whether they need browser-native controls or more network filtering?

A: Teams should use browser-native controls when the risk is inside the session, such as credential relay, token theft, or malicious clipboard execution. Network filtering helps with known-bad destinations, but it cannot reliably see what happens after the page loads. If the attack is identity-driven, inspection must move into the browser.

👉 Read our full editorial: Browser blind spots are where modern identity attacks succeed



   
ReplyQuote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21566
 

Browser-layer identity control is now a governance boundary, not a visibility enhancement. The article shows that endpoint security can still be effective while the identity attack succeeds entirely inside the browser session. That means identity programmes need to govern where authentication is completed, not only where the device is monitored. The practical conclusion is that session-layer control has become part of core identity architecture, not a niche detection add-on.

A question worth separating out:

Q: What should teams do when a stolen browser session is suspected?

A: Contain the session before the attacker can reuse it. Revoke or invalidate the token, review recent consent grants and browser activity, check for extension abuse, and examine whether the account was used to access administrative or data-heavy applications. The goal is to stop replay and identify what the session already touched.

👉 Read our full editorial: Browser blind spots are where modern identity attacks succeed


This post was modified 1 day ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.