NordLayer’s Browser Security Report 2026 reviewed 504 applications and found browser access present across all of them — and 79% of those tools were available only through the browser. That single fact frames the problem: a majority of modern business apps live at the browser layer, and many high‑risk actions generate no new executable or suspicious process for endpoint detection and response (EDR) to inspect.
How Storm‑2755’s AiTM phishing bypassed endpoint telemetry
Microsoft observed a 2026 campaign tracked as Storm‑2755 that used search engine poisoning and malicious ads to redirect Canadian employees searching for terms such as “Office 365” to a Microsoft 365 login page controlled by the attacker. The adversary’s adversary‑in‑the‑middle (AiTM) proxy relayed the legitimate MFA challenge, captured credentials, session cookies and OAuth access tokens, and then replayed the authenticated session.
Microsoft recorded a session ID switch from the victim’s browser to an Axios user agent, demonstrating reuse of the authentication token from attacker‑controlled infrastructure. Using those tokens, the attackers accessed Microsoft services, searched payroll and HR information, created inbox rules to hide banking‑change messages, and in some cases accessed Workday. From ordinary endpoint process telemetry the authentication flow can appear legitimate; the decisive interception happens between the user and the identity provider.
The source identifies phishing‑resistant FIDO2 WebAuthn as the best way to prevent many AiTM attacks, because the authentication response is cryptographically tied to the legitimate origin. The source also notes that browser controls — for blocking phishing destinations, restricting unapproved web apps, and enforcing identity policies — can stop these flows earlier.
Malicious Chromium extensions in March 2026: code that hides inside browser processes
Browser extensions run inside browser processes and leave files in browser profiles, which creates an observability gap. EDR can see a browser process making HTTPS connections but without browser‑specific context it may not reveal which extension read page content or exported it.
Microsoft reported in March 2026 on malicious Chromium extensions disguised as AI assistants. Those extensions were installed roughly 900,000 times and showed activity across more than 20,000 enterprise tenants. They collected visited URLs and content from ChatGPT and DeepSeek conversations and periodically sent the data to attacker‑controlled infrastructure.
The remedy offered in the source is managerial and technical: control the extension layer directly through allowlists, installation controls and permission reviews that limit extensions that can read or modify web content. NordLayer’s Browser product is presented as providing extension policies to allow or block specific Chrome extensions.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleTerminalFix (August 2026): clipboard tricks that lead to full host compromise
Not all browser attacks stop inside the browser. The source describes a ClickFix variant Microsoft observed in August 2026, called TerminalFix. Compromised websites displayed fake Cloudflare CAPTCHA prompts; clicking a fake verification step copied a malicious PowerShell command to the clipboard while the page instructed the victim to open Windows Terminal or PowerShell and paste it.
Until the user pasted and executed the command, the attack relied on rendered web content, clipboard manipulation and user interaction — none of which necessarily produced endpoint artifacts EDR was designed to flag. Once executed, however, the sequence generated classic host telemetry: PowerShell ran, a ZIP archive was downloaded and extracted, DLL side‑loading occurred, registry and scheduled‑task persistence were created, Active Directory discovery began, and the host established a reverse tunnel.
Browser controls — blocking the malicious page, restricting clipboard access, or limiting risky browser actions — are described as the way to stop the chain before it produces endpoint artifacts that EDR can inspect.
Three connected layers of control: browser, identity and endpoint
The source frames the solution as a three‑layer requirement for SaaS‑heavy environments: browser, identity and SaaS, and endpoint. EDR remains necessary to detect host execution, malware and process‑level behavior, but it cannot reliably surface high‑risk actions that live only in browser or identity workflows.
- Browser: web threat protection to block phishing and malicious sites; extension policies to prevent unapproved code from reading web content; browser DLP to restrict uploads, downloads and clipboard actions by destination.
- Identity and SaaS: block or condition OAuth grants, use allowlisted network locations, and prefer phishing‑resistant authentication such as FIDO2 WebAuthn where available.
- Endpoint: preserve EDR for runtime detections — PowerShell activity, downloaded artifacts, persistence mechanisms and outbound connections — once an attack moves off the page and onto the host.
The source also notes operational controls such as routing browser traffic through a dedicated IP that organizations can allowlist for SaaS access or use as a network condition in identity policies where identity providers support it. NordLayer’s Browser is presented as a managed way to centralize control over web access, extensions, file transfers and clipboard actions.
What this means for security teams, procurement leaders, and employees
- Security teams: Do not rely on EDR alone. Prioritize extension inventory and permission reviews, browser DLP, web threat protection and identity‑level controls to catch activity that never becomes a new executable or process.
- Procurement and IT buyers: Evaluate tools that apply policies at the browser layer — extension allowlists, dedicated IP routing for SaaS, and managed browser controls — in addition to endpoint detections.
- Employees and end users: Be wary of search results and ads that redirect to login pages, treat unexpected copy‑and‑paste requests with suspicion, and where possible use phishing‑resistant FIDO2 WebAuthn for authentication.
The takeaway in plain terms: in environments where most apps live in the browser, the browser is not merely another application to monitor — it is the primary access layer and a distinct attack surface. EDR will catch host execution; it will not, by itself, reveal or prevent credential interception, malicious extensions harvesting page content, or clipboard‑based social engineering inside a browser session. Organizations that treat the browser as a first‑class control point — combined with identity safeguards and traditional endpoint sensing — will be best positioned to close the visibility gap.




