{"id":21397,"date":"2026-09-05T16:57:26","date_gmt":"2026-09-05T16:57:26","guid":{"rendered":"https:\/\/8657085.xyz\/?p=21397"},"modified":"2026-09-05T16:57:26","modified_gmt":"2026-09-05T16:57:26","slug":"browser-based-work-is-creating-a-new-cybersecurity-battleground","status":"publish","type":"post","link":"https:\/\/8657085.xyz\/?p=21397","title":{"rendered":"Browser-based work is creating a new cybersecurity battleground"},"content":{"rendered":"<p> <div style=\"display: grid; grid-template-columns: 300px 160px; gap: 2px; width: 460px; background: #eee; padding: 2px;\">\r\n\r\n  <!-- \u6574\u884c\u5bbd\u5e7f\u544a -->\r\n  <div style=\"grid-column: 1\/-1; width: 460px; height: 250px; background: #ccc; display: grid; place-items: center;\">\r\n  <script async type=\"application\/javascript\" src=\"https:\/\/a.magsrv.com\/ad-provider.js\"><\/script> \r\n <ins class=\"eas6a97888e2\" data-zoneid=\"5876674\"><\/ins> \r\n <script>(AdProvider = window.AdProvider || []).push({\"serve\": {}});<\/script>\r\n  <\/div>\r\n  <div style=\"grid-column: 1\/-1; width: 460px; height: 90px; background: #ccc; display: grid; place-items: center;\">\r\n  <script async type=\"application\/javascript\" src=\"https:\/\/a.magsrv.com\/ad-provider.js\"><\/script> \r\n <ins class=\"eas6a97888e2\" data-zoneid=\"5876676\"><\/ins> \r\n <script>(AdProvider = window.AdProvider || []).push({\"serve\": {}});<\/script>\r\n  <\/div>\r\n\r\n  <!-- \u5de6\u4fa7\u7ad6\u6392 -->\r\n  <div style=\"height: 250px; background: #ccc; display: grid; place-items: center;\">\r\n  <script async type=\"application\/javascript\" src=\"https:\/\/a.magsrv.com\/ad-provider.js\"><\/script> \r\n <ins class=\"eas6a97888e2\" data-zoneid=\"5876672\"><\/ins> \r\n <script>(AdProvider = window.AdProvider || []).push({\"serve\": {}});<\/script>\r\n  <\/div>\r\n  <div style=\"height: 500px; background: #ccc; display: grid; place-items: center;\">\r\n  <script async type=\"application\/javascript\" src=\"https:\/\/a.magsrv.com\/ad-provider.js\"><\/script> \r\n <ins class=\"eas6a97888e2\" data-zoneid=\"5876680\"><\/ins> \r\n <script>(AdProvider = window.AdProvider || []).push({\"serve\": {}});<\/script>\r\n  <\/div>\r\n\r\n  <!-- \u53f3\u4fa7\u6469\u5929\u697c\uff08\u548c\u5de6\u4fa7\u5b8c\u5168\u5bf9\u9f50\uff09 -->\r\n  <div style=\"grid-row: 3\/5; height: 750px; background: #ccc; display: grid; place-items: center;\">\r\n  <script async type=\"application\/javascript\" src=\"https:\/\/a.magsrv.com\/ad-provider.js\"><\/script> \r\n <ins class=\"eas6a97888e2\" data-zoneid=\"5876678\"><\/ins> \r\n <script>(AdProvider = window.AdProvider || []).push({\"serve\": {}});<\/script>\r\n  <\/div>\r\n  \r\n  <script async type=\"application\/javascript\" src=\"https:\/\/a.magsrv.com\/ad-provider.js\"><\/script> \r\n <ins class=\"eas6a97888e6\" data-zoneid=\"5876682\"><\/ins> \r\n <script>(AdProvider = window.AdProvider || []).push({\"serve\": {}});<\/script>\r\n<\/div><br \/>\n<\/p>\n<div style=\"padding-right:0;padding-left:0\">\n<p class=\"wp-block-paragraph\">The web browser has quietly become the operating system of modern work. From customer relationship management platforms and project collaboration tools to finance systems and artificial intelligence applications, business processes increasingly run through a browser window rather than installed software.<\/p>\n<p class=\"wp-block-paragraph\">According to a new report from cybersecurity firm NordLayer, web-based attacks are becoming one of the most significant risks facing organizations, with 82 percent of surveyed IT professionals reporting their organization experienced a browser-related security incident during the past year. Half of those affected described the impact as moderate or severe. The findings point to a growing mismatch between how companies work today and how many still approach cybersecurity.<\/p>\n<p class=\"wp-block-paragraph\">One of the report\u2019s most striking findings is that almost all modern business applications are now accessible through a browser. NordLayer\u2019s analysis of 504 highly rated workplace applications found that 100 percent could be accessed via a web browser, while nearly 79 percent were browser-only services. This reflects a world increasingly dependent on software-as-a-service (SaaS) platforms.<\/p>\n<p class=\"wp-block-paragraph\">The shift has clear business advantages. Cloud-based platforms are easier to deploy, support remote workers, and simplify software updates. However, they also create a larger attack surface. As organizations adopt more SaaS products, employees spend more time operating within browsers, making them attractive targets for attackers seeking credentials, session cookies, and access tokens.<\/p>\n<h2 id=\"h-remote-work-and-byod-heighten-the-risks\" class=\"wp-block-heading\"><strong>Remote work and BYOD heighten the risks<\/strong><\/h2>\n<p class=\"wp-block-paragraph\">The research identified several common characteristics among organizations suffering the most severe web-based incidents. These organizations were more likely to allow employees to use personal devices for work (BYOD). Furthermore, such firms depend heavily on SaaS applications and to operate remote or hybrid work arrangements.<\/p>\n<p class=\"wp-block-paragraph\">According to NordLayer cybersecurity expert Andrius Buinovskis, these trends deliver flexibility and scalability but also introduce additional risks. \u201cBYOD, remote work, and extensive SaaS use expand the company\u2019s attack surface and increase shadow IT,\u201d Buinovskis notes. Without appropriate controls, environments can become vulnerable to malware infections, phishing attacks, insider threats, and accidental data leakage. The challenge is particularly relevant as many organizations continue to support distributed workforces established during the pandemic period.<\/p>\n<h2 id=\"h-a-confidence-gap-emerges\" class=\"wp-block-heading\"><strong>A confidence gap emerges<\/strong><\/h2>\n<p class=\"wp-block-paragraph\">Despite the frequency of attacks, many organizations appear confident in their ability to defend themselves. The survey found that 73 percent of IT professionals believe their organization is well prepared to manage web-based threats. Yet the same respondents reported relatively modest deployment of browser-focused security controls. Even data loss prevention (DLP) technologies, the most widely used protection measure, were implemented by only 53 percent of organizations.<\/p>\n<p class=\"wp-block-paragraph\">Almost all respondents expressed concern about browser-based threats, while 81 percent expect attacks to become increasingly sophisticated and 73 percent anticipate a growing volume of incidents over the coming years. \u00a0This suggests many organizations understand the problem but have yet to fully adapt their security strategies.<\/p>\n<h2 id=\"h-hackers-don-t-hack-anymore\" class=\"wp-block-heading\"><strong>\u201cHackers don\u2019t hack anymore\u201d<\/strong><\/h2>\n<p class=\"wp-block-paragraph\">Perhaps the most alarming finding concerns credential theft. Data analysed by NordLayer and threat exposure management platform NordStellar indicates that infostealer malware harvested approximately 1.8 million credentials and nearly 68.8 billion cookies during 2025 alone. Activity reached its highest levels during November.<\/p>\n<p class=\"wp-block-paragraph\">Traditional cyberattacks often involve exploiting vulnerabilities or bypassing security defences. Credential theft changes the equation by allowing attackers to simply log in using valid credentials. As Buinovskis observes: \u201cHackers don\u2019t hack anymore, they just log in.\u201d<\/p>\n<p class=\"wp-block-paragraph\">When attackers possess legitimate credentials or active session cookies, malicious activity can appear indistinguishable from normal user behaviour. This makes detection considerably more difficult and increases the likelihood of successful compromise. Historically, cybersecurity focused heavily on protecting networks, endpoints, and data centres. Today\u2019s cloud-first environments require a different perspective. Since business applications increasingly reside within browsers, organizations may need to treat the browser itself as a critical security boundary. NordLayer recommends three priorities:<\/p>\n<p class=\"wp-block-paragraph\"><em>Improve visibility<\/em>: Organizations need a clear understanding of what applications employees use, which browser extensions are installed, and whether users are visiting potentially risky websites. Improved visibility can reduce shadow IT and identify unauthorized software before it creates security problems.<\/p>\n<ol class=\"wp-block-list\"\/>\n<p class=\"wp-block-paragraph\"><strong><em>Proactively block threats: <\/em><\/strong>The report recommends technologies such as DNS filtering to prevent access to malicious domains and category-based restrictions where appropriate. Data loss prevention controls can also help prevent sensitive information from being uploaded, downloaded, or copied without authorization.<\/p>\n<p class=\"wp-block-paragraph\"><em>Adopt zero-trust security<\/em>: Zero-trust models assume that no user or device should be automatically trusted. Instead, every access request requires verification and authorization. Applying zero-trust principles at the browser level can help limit the damage caused by compromised accounts or stolen credentials.<\/p>\n<\/div>\n<p><!-- \u603b\u5bb9\u5668\uff1a\u6700\u5927\u5bbd908px Grid\u7d27\u51d1\u5e03\u5c40 -->\r\n<div style=\"display: grid; grid-template-columns: 728px 160px; gap:2px; width:908px; background:#eee; padding:2px;\">\r\n\r\n  <!-- \u901a\u680f\u9876\u90e8\uff1a\u6700\u5927\u6a2a\u5e45 908x258 \u8de8\u6574\u884c -->\r\n  <div style=\"grid-column:1\/-1; height:258px; background:#ff6b6b; display:grid; place-items:center;\">\r\n    <!-- JuicyAds v3.0 -->\r\n<script type=\"text\/javascript\" data-cfasync=\"false\" async src=\"https:\/\/poweredby.jads.co\/js\/jads.js\"><\/script>\r\n<ins id=\"1114307\" data-width=\"908\" data-height=\"258\"><\/ins>\r\n<script type=\"text\/javascript\" data-cfasync=\"false\" async>(adsbyjuicy = window.adsbyjuicy || []).push({'adzone':1114307});<\/script>\r\n<!--JuicyAds END-->\r\n  <\/div>\r\n\r\n  <!-- \u7b2c\u4e8c\u901a\u680f\uff1a728\u00d790 \u901a\u680f -->\r\n  <div style=\"grid-column:1\/-1; height:90px; background:#4ecdc4; display:grid; place-items:center;\">\r\n    <!-- JuicyAds v3.0 -->\r\n<script type=\"text\/javascript\" data-cfasync=\"false\" async src=\"https:\/\/poweredby.jads.co\/js\/jads.js\"><\/script>\r\n<ins id=\"1114300\" data-width=\"728\" data-height=\"90\"><\/ins>\r\n<script type=\"text\/javascript\" data-cfasync=\"false\" async>(adsbyjuicy = window.adsbyjuicy || []).push({'adzone':1114300});<\/script>\r\n<!--JuicyAds END-->\r\n  <\/div>\r\n\r\n  <!-- \u5de6\u4fa7\u4e3b\u680f\uff1a\u591a\u5e7f\u544a\u5806\u53e0 -->\r\n  <div style=\"display:grid; gap:2px;\">\r\n    <div style=\"height:60px; background:#45b7d1; display:grid; place-items:center;\">\r\n\t<!-- JuicyAds v3.0 -->\r\n<script type=\"text\/javascript\" data-cfasync=\"false\" async src=\"https:\/\/poweredby.jads.co\/js\/jads.js\"><\/script>\r\n<ins id=\"1114308\" data-width=\"468\" data-height=\"60\"><\/ins>\r\n<script type=\"text\/javascript\" data-cfasync=\"false\" async>(adsbyjuicy = window.adsbyjuicy || []).push({'adzone':1114308});<\/script>\r\n<!--JuicyAds END-->\r\n\t<\/div>\r\n    <div style=\"height:250px; background:#ffe066; display:grid; place-items:center;\">\r\n\t<!-- JuicyAds v3.0 -->\r\n<script type=\"text\/javascript\" data-cfasync=\"false\" async src=\"https:\/\/poweredby.jads.co\/js\/jads.js\"><\/script>\r\n<ins id=\"1114299\" data-width=\"300\" data-height=\"250\"><\/ins>\r\n<script type=\"text\/javascript\" data-cfasync=\"false\" async>(adsbyjuicy = window.adsbyjuicy || []).push({'adzone':1114299});<\/script>\r\n<!--JuicyAds END-->\r\n\t<\/div>\r\n    <div style=\"height:250px; background:#ff9ecd; display:grid; place-items:center;\">\r\n\t<!-- JuicyAds v3.0 -->\r\n<script type=\"text\/javascript\" data-cfasync=\"false\" async src=\"https:\/\/poweredby.jads.co\/js\/jads.js\"><\/script>\r\n<ins id=\"1114305\" data-width=\"250\" data-height=\"250\"><\/ins>\r\n<script type=\"text\/javascript\" data-cfasync=\"false\" async>(adsbyjuicy = window.adsbyjuicy || []).push({'adzone':1114305});<\/script>\r\n<!--JuicyAds END-->\r\n\t<\/div>\r\n    <div style=\"height:139px; background:#c792ea; display:grid; place-items:center;\">\r\n\t<!-- JuicyAds v3.0 -->\r\n<script type=\"text\/javascript\" data-cfasync=\"false\" async src=\"https:\/\/poweredby.jads.co\/js\/jads.js\"><\/script>\r\n<ins id=\"1114302\" data-width=\"133\" data-height=\"139\"><\/ins>\r\n<script type=\"text\/javascript\" data-cfasync=\"false\" async>(adsbyjuicy = window.adsbyjuicy || []).push({'adzone':1114302});<\/script>\r\n<!--JuicyAds END-->\r\n\t<\/div>\r\n    <div style=\"height:125px; background:#91e7ac; display:grid; place-items:center;\">\r\n\t\r\n<!-- JuicyAds v3.0 -->\r\n<script type=\"text\/javascript\" data-cfasync=\"false\" async src=\"https:\/\/poweredby.jads.co\/js\/jads.js\"><\/script>\r\n<ins id=\"1114303\" data-width=\"125\" data-height=\"125\"><\/ins>\r\n<script type=\"text\/javascript\" data-cfasync=\"false\" async>(adsbyjuicy = window.adsbyjuicy || []).push({'adzone':1114303});<\/script>\r\n<!--JuicyAds END-->\r\n\t<\/div>\r\n  <\/div>\r\n\r\n  <!-- \u53f3\u4fa7\u7ad6\u680f\uff1a160\u00d7600 \u6574\u5217\u9ad8\u5e7f\u544a -->\r\n  <div style=\"grid-row:3\/8; height:600px;  display:grid; place-items:center;\">\r\n    <!-- JuicyAds v3.0 -->\r\n<script type=\"text\/javascript\" data-cfasync=\"false\" async src=\"https:\/\/poweredby.jads.co\/js\/jads.js\"><\/script>\r\n<ins id=\"1114301\" data-width=\"160\" data-height=\"600\"><\/ins>\r\n<script type=\"text\/javascript\" data-cfasync=\"false\" async>(adsbyjuicy = window.adsbyjuicy || []).push({'adzone':1114301});<\/script>\r\n<!--JuicyAds END-->\r\n  <\/div>\r\n\r\n<\/div><br \/>\n<br \/> Browser-based work is creating a new cybersecurity battleground<br \/>\n<br \/>#Browserbased #work #creating #cybersecurity #battleground<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The web browser has quietly become the operating system of modern work. From customer relationship&#8230;<\/p>\n","protected":false},"author":1,"featured_media":21398,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[7],"tags":[13736,15802,7778,6341,771],"class_list":["post-21397","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-stories","tag-battleground","tag-browserbased","tag-creating","tag-cybersecurity","tag-work"],"featured_image_urls":{"full":["https:\/\/8657085.xyz\/wp-content\/uploads\/2026\/09\/CyberAttacks-AFP-1K.jpg",1024,682,false],"thumbnail":["https:\/\/8657085.xyz\/wp-content\/uploads\/2026\/09\/CyberAttacks-AFP-1K-150x150.jpg",150,150,true],"medium":["https:\/\/8657085.xyz\/wp-content\/uploads\/2026\/09\/CyberAttacks-AFP-1K-300x200.jpg",300,200,true],"medium_large":["https:\/\/8657085.xyz\/wp-content\/uploads\/2026\/09\/CyberAttacks-AFP-1K-768x512.jpg",640,427,true],"large":["https:\/\/8657085.xyz\/wp-content\/uploads\/2026\/09\/CyberAttacks-AFP-1K.jpg",640,426,false],"1536x1536":["https:\/\/8657085.xyz\/wp-content\/uploads\/2026\/09\/CyberAttacks-AFP-1K.jpg",1024,682,false],"2048x2048":["https:\/\/8657085.xyz\/wp-content\/uploads\/2026\/09\/CyberAttacks-AFP-1K.jpg",1024,682,false],"covernews-slider-full":["https:\/\/8657085.xyz\/wp-content\/uploads\/2026\/09\/CyberAttacks-AFP-1K.jpg",1024,682,false],"covernews-slider-center":["https:\/\/8657085.xyz\/wp-content\/uploads\/2026\/09\/CyberAttacks-AFP-1K-800x500.jpg",800,500,true],"covernews-featured":["https:\/\/8657085.xyz\/wp-content\/uploads\/2026\/09\/CyberAttacks-AFP-1K.jpg",1024,682,false],"covernews-medium":["https:\/\/8657085.xyz\/wp-content\/uploads\/2026\/09\/CyberAttacks-AFP-1K-540x340.jpg",540,340,true],"covernews-medium-square":["https:\/\/8657085.xyz\/wp-content\/uploads\/2026\/09\/CyberAttacks-AFP-1K-400x250.jpg",400,250,true]},"author_info":{"display_name":"admin","author_link":"https:\/\/8657085.xyz\/?author=1"},"category_info":"<a href=\"https:\/\/8657085.xyz\/?cat=7\" rel=\"category\">Stories<\/a>","tag_info":"Stories","comment_count":"0","_links":{"self":[{"href":"https:\/\/8657085.xyz\/index.php?rest_route=\/wp\/v2\/posts\/21397","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/8657085.xyz\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/8657085.xyz\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/8657085.xyz\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/8657085.xyz\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=21397"}],"version-history":[{"count":0,"href":"https:\/\/8657085.xyz\/index.php?rest_route=\/wp\/v2\/posts\/21397\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/8657085.xyz\/index.php?rest_route=\/wp\/v2\/media\/21398"}],"wp:attachment":[{"href":"https:\/\/8657085.xyz\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=21397"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/8657085.xyz\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=21397"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/8657085.xyz\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=21397"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}