Join our Newsletter — 33% off our NHI Course

Browser session attacks are rising fast, but are controls keeping up?

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 21730
Topic starter  

TL;DR: 49% of organisations suffered a successful browser-based attack in the last 12 months, according to Push Security and Omdia, with browser-originated incidents now accounting for roughly 37% of all security incidents among affected organisations. Browser controls built around visibility outside the session no longer match where phishing, credential theft, token abuse, and data loss actually occur.

Editorial analysis by NHI Mgmt Group, based on content published by Push Security: “7 things Omdia's latest report tells us about the secure enterprise browser market”.

By the numbers:

  • 49% of organisations suffered a successful browser-based attack in the last 12 months.
  • Browser-originated incidents account for roughly 37% of all security incidents among affected organisations.
  • 88% of respondents rank browser security as at least a top-five security priority.

Key questions

Q: What breaks when browser security is treated as just web filtering?

A: Visibility breaks first.

Q: Why do browser sessions increase phishing and AiTM risk?

A: Because the browser session is where the user authenticates, the token is minted, and the attacker can capture the live interaction.

Q: How should teams enforce GenAI policy in the browser?

A: They should enforce it at the session layer, where they can see the prompt, the destination, and the data entered by the user.

Practitioner guidance

  • Instrument browser sessions as a control boundary Capture session-level events for credential entry, prompt use, extension behaviour, and file movement so the programme can see what happens after authentication.
  • Enforce GenAI policy where users actually work Move from policy statements to browser-layer controls that can distinguish sanctioned from unsanctioned AI usage and identify prompt-time data exposure.
  • Review browser extensions as part of access governance Inventory extension permissions, execution behaviour, and exposure to authenticated applications because extensions operate inside the trusted session.

Bottom line: Browser security has shifted from an edge concern to a session governance problem because the attack, the identity action, and the data loss now happen inside the browser.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 1 day ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21566
 

Browser-layer visibility is now an identity governance requirement, not a convenience feature. The report shows that the decisive security event increasingly occurs inside the session where authentication, data handling, and application use converge. That breaks the old assumption that network logs, endpoint data, and IAM logs together provide enough context to understand abuse. Practitioners should treat browser telemetry as part of the identity control plane.

A few things that frame the scale:

  • 85% of organisations lack full visibility into third-party vendors connected via OAuth apps, according to The State of Non-Human Identity Security.
  • Only 1.5 out of 10 organisations are highly confident in their ability to secure NHIs, compared to nearly 1 in 4 for securing human identities.

A question worth separating out:

Q: What is the difference between browser security and secure web gateway controls?

A: Secure web gateways primarily inspect and filter traffic, while browser security can observe and govern what happens inside the session itself. That difference matters for GenAI, credential theft, and session hijacking because the relevant action often occurs after the page loads. Browser-layer controls provide the contextual evidence SWGs cannot.

👉 Read our full editorial: Browser security is now the enterprise attack surface teams must govern



   
ReplyQuote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21566
 

Browser-layer visibility is now an identity governance requirement, not a convenience feature. The report shows that the decisive security event increasingly occurs inside the session where authentication, data handling, and application use converge. That breaks the old assumption that network logs, endpoint data, and IAM logs together provide enough context to understand abuse. Practitioners should treat browser telemetry as part of the identity control plane.

A few things that frame the scale:

  • 85% of organisations lack full visibility into third-party vendors connected via OAuth apps, according to The State of Non-Human Identity Security.
  • Only 1.5 out of 10 organisations are highly confident in their ability to secure NHIs, compared to nearly 1 in 4 for securing human identities.

A question worth separating out:

Q: What is the difference between browser security and secure web gateway controls?

A: Secure web gateways primarily inspect and filter traffic, while browser security can observe and govern what happens inside the session itself. That difference matters for GenAI, credential theft, and session hijacking because the relevant action often occurs after the page loads. Browser-layer controls provide the contextual evidence SWGs cannot.

👉 Read our full editorial: Browser security is now the enterprise attack surface teams must govern



   
ReplyQuote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21566
 

Browser security has become a session governance problem, not a web filtering problem. The article’s strongest signal is not simply that attacks are rising, but that the attack, the identity action, and the data loss now happen inside the same browser session. That collapses the old separation between access control and content control. Practitioners should read this as a boundary shift: the browser is now where governance must observe and intervene.

A question worth separating out:

Q: Should security teams treat browser extensions like third-party access?

A: Yes. A browser extension can function like delegated third-party code because it inherits access to the user session and can change behaviour after initial approval. That makes lifecycle control important. Teams should evaluate who publishes the extension, what permissions it requests, and how quickly it can be removed if the trust relationship changes.

👉 Read our full editorial: Browser security is now the enterprise attack surface teams must govern


This post was modified 1 day ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.