The images in this article were generated with artificial intelligence. How we publish
Every year Verizon's report on data violations functions as a must-see point of comparison for industry; its real value is often at the signal convergence: when multiple independent sources, from browser telemetry to DLP data sets, point to the same structural changes in attackers' tactics. In 2026 this convergence is clear: the attack surface was moved decisively to the browser and to the IA services accessible from it, with practical implications that many security teams were not prepared to manage.
One of the most striking findings is the boom of what is called "Shadow AI": the unauthorized use of IA services by employees who resort to personal or ungoverned accounts to solve immediate tasks. According to the aggregated data, a large majority of IA access in corporate devices come from personal accounts and a significant percentage of prompts with sensitive data circulates outside the scope of DLP corporate policies. That transforms productivity tools into data leakage channels and requires controls other than traditional network or endpoint controls.

Listed to the above is the persistent problem of the theft of credentials. The DBIR 2026 reports that a relevant portion of gaps originated in credentials abuse, and browser telemetry shows that many attempts at theft occur completely invisible for proxys, DNS filters and endpoints agents. If the malicious page is rendered and the user interacts in the browser, that is the only point where the attack usually leaves reliable signals.
The browser extensions appear as a critical and poorly governed vector: they can read and modify page content and exfilter data without being detected by traditional tools. The fact that most reputable extensions are labelled as "productivity" in markplaces shows that category-based policies are insufficient. The governance of extensions and the ability to assess permissions and reputation must no longer be ad- hoc tasks and become systematic controls within security policies.
An emerging mode of native social engineering of the browser, called ClickFix, also emerges that starts on the web but moves quickly to the host to run malicious code or install info-stealers. Although today it represents a low fraction of all detected attacks, its evolution is worrying because it explores user confidence in the browser as a working environment. Protecting human interaction in the browser is, in many cases, the difference between detecting a deception or reacting after the host was already compromised.
What practical lessons do I draw from this convergence? First, that depending exclusively on network telemetry, endpoint or identity, the security program is blind to many of the current techniques. Second, that solutions should incorporate detection and control in the browser layer: record the exfiltration of prompts to IA services, inspect extension behaviors, and analyse DOM interactions that precede local downloads or executions.
In operational terms this involves combining governance and technology: imposing corporate authentication and SSO for IA access, implementing data loss prevention policies that work within the browser (not only in transit), auditioning and limiting extensions for permission and reputation, and deploying sensors that correlate navigation events with endpoint activity. None of these measures alone eliminate the risk, but together reduce the exposure windows where attackers have learned to operate.

It is also essential to reassess training and processes. The "human problem" remains present, but it is not just a question of awareness: attackers design pages that dodge automated scanners and manipulate real workflows. Training must be accompanied by technical controls that reduce the need for risky decisions by users, for example by allowing approved IA services and blocking charges to personal accounts from corporate devices.
For those who manage corporate security programs, start by instructing and auditing: conducting an evaluation that includes browser visibility, checking how many high-risk extensions are deployed and measuring how much sensitive information is sent to ungoverned IA services. A good starting point is to contrast data with external sources such as Verizon's report on data violations ( DBIR from Verizon) and to complement this picture with analysis of browser telemetry (e.g., specialized reports available in browser security status 2026). Another useful reference to understand file and domain detection is VirusTotal ( VirusTotal), which exemplifies why many malicious sites are not visible to all suppliers at the same time.
The conclusion is clear: the browser has ceased to be a mere customer application and has become the main working environment for most users. If you don't monitor, control and audit what happens within the browser sessions, you will have a collection of blind spots that the attackers will exploit regularly.. The good news is that the industry already has signals and tools to act; the decision is whether to apply these controls now or wait for the next incident to force change.
Related
More news on the same subject.

GitLab critical alert: emergency patch fixes CVE-2026-19478 allowing to modify or eliminate public projects without credentials
GitLab published an emergency patch on August 17, 2026 to correct critical vulnerability in its self-hosted software (Community and Enterprise Edition) which, under certain cond...

When the MCP server keeps your credentials: the silent attack vector of the IA in production
The incorporation of IA agents into business processes has opened a practical way for production systems and data to be accessible from models: it is called Model Context Protoc...

Critical alert: CVE-2026-58231 in SAP Commerce Cloud could allow remote code execution; patch and urgent mitigation
A critical vulnerability that affects SAP Commerce Cloud, registered as CVE-2026-58231 and with maximum score 10.0 on the CVSS scale, it is being exploited attempts shortly afte...

The massive purchase of expired domains drives fraud, malware and streaming pirate: the business behind the dropcatch
An intelligence report on DNS published by Infoblox and disseminated by specialized media confirms that criminals are buying large-scale expired domains - the so-called dropcatc...

HoneyMyte updates CoolClient with a signed kernel driver to hide processes and protect the C2 channel
Kaspersky has published an analysis that attributes to the actor known as HoneyMyte (also Mustang Panda) an updated version of the CoolClient backdoor that incorporates a signed...

GeoServer on zero-day vulnerability alert in jsonArrayContains with real risk of remote execution
The GeoServer open source project has a zero-day vulnerability that is being actively explored by attackers, according to researchers' public alerts and the watchTowr intelligen...

AmnesiaStealer MacOS malware that steals credentials and controls real-time browser sessions
Security researchers have documented a new malware family aimed at macOS - called AmnesiaStealer - that combines a dropper in shell, an infostealer written in Rust and a remote ...