Ask Runable forDesign-Driven General AI AgentTry Runable For Free
Runable
Back to Blog
Technology7 min read

Cyber attackers have a new favorite, the browser | TechRadar

Browser attacks surge as AI expands threat landscape Discover insights about cyber attackers have a new favorite, the browser | techradar.............

TechnologyInnovationBest PracticesGuideTutorial
Cyber attackers have a new favorite, the browser | TechRadar
Listen to Article
0:00
0:00
0:00

Cyber attackers have a new favorite, the browser | Tech Radar

Overview

News, deals, reviews, guides and more on the newest computing gadgets

Start exploring exclusive deals, expert advice and more

Details

Unlock and manage exclusive Techradar member rewards.

Unlock instant access to exclusive member features.

Get full access to premium articles, exclusive features and a growing list of member rewards.

Browser attacks surge as AI expands threat landscape

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works.

Browsers have become the go-to choice for hybrid workers who relish the flexibility of using multiple devices to access everything from collaborative meetings to cloud-stored files, all via a browser.

The dominant use has also attracted a different persona, the cyber attacker. The sheer volume of browser-based work presents a target-rich opportunity, and enterprises are feeling the results.

A newly released browser security survey of IT and cybersecurity professionals found 68% of organizations report an increase in browser-related security incidents over the past two years.

Friend or foe? AI: The new cybersecurity threat and solutions

New Nord Layer browser looks to help boost SMB security like never before

Organizations are recognizing this growing threat, with 62% of respondents elevating browser security to one of their top five security priorities.

They’re reflecting this concern (85%) in larger investments in browser security solutions like remote browser isolation, secure extensions, and enterprise browsers.

AI Adding to the Many Flavors of Browser Attacks

Defending against web or browser threats must be a multi-varied approach since today’s cyber-attackers are using an assortment of entrance points. The top five methods organizations are seeing are data loss or leakage, malicious browser extensions, vulnerable browser extensions and plugins, and malicious scripts.

AI has entered the arena, adding to IT and security teams’ concerns about protecting against this ever-increasing volume of new threats. Targeted phishing, social engineering, data leakage via unsanctioned AI applications or browsers, deepfake or AI generated malicious content are top culprits.

Another AI security threat is the overwhelming popularity of public Gen AI platforms. How to manage secure use of these platforms by employees is another challenge IT faces. Omdia research found that secure browser solutions are becoming increasingly relied on to help secure or restrict access to Gen AI applications.

Other popular methods are using a secure web gateway (SWG), a Saa S security solution or dedicated Gen AI security tools. This challenge is often associated with “shadow AI,” or the uncontrolled use of public Gen AI platforms by employees, which many CISOs view as a material security risk due to the potential data exposure, policy circumvention, and compliance concerns.

Thwarting Cyber Attackers with Browser Isolation

Among available browser security solutions, browser isolation is gaining favor as organizations look to decouple endpoints from browser-borne risk, which shows no signs of slowing down. Increased use of public Gen AI applications, access from unmanaged or personal devices, and human error are all driving attack-surface growth and raising the likelihood that threats will enter through browser activity.

AI powers innovation – but it’s also powering the next wave of cyber attacks

76% of UK organizations have faced deepfake attacks. Most weren’t ready

The Human Risk Reckoning: Why security must evolve for an AI-augmented workforce

The era of remote/hybrid work has increased exposure risk across these multiple fronts as remote workers use personal and unsecured devices to conduct browser activity, adding to Shadow IT and Shadow AI risks.

Organizations, mindful of browsers’ dominance, are adding more budget to improve security. The browser isolation market is projected to grow from

2.53billionin2026to2.53 billion in 2026 to
7.65 billion by 2031 at 24.74% CAGR over 2026-2031. As the Omdia survey notes, almost half of the organizations want their browser isolation choice to integrate well with other security solutions as a ‘better together’ strategy.

Browsers isolation will continue to gain in deployment as organizations look for a way to contain threats in an expanding attack surface. It answers this need by running web-based applications in isolated browser sessions, helping contain web-borne threats and creating logical separation with an “air gap” approach between the browsing session and the enterprise network reducing the attack surface and creating an ‘air gap’ between the browsing session and the enterprise network.

Hybrid workers can use their web browser of choice to securely access web applications including Software as a Service (Saa S) and other cloud applications. IT staff can manage policy controls via web-based console to ensure the activity meets security access guidelines.

Organizations looking for an economical alternative to VPN and to stabilize infrastructure subscription costs have the option of self-hosted browsers and can use a browser isolation solution tailored to on-premises or private cloud secure workflows. In these models, sandboxed browser containers are hosted on-premises or in a private cloud to secure access to Saa S, internal web applications, and privately hosted services without exposing the enterprise network.

IT staff can save time with centralized policy controls and by automating the compliance reporting process and logs to support meeting regulatory standards.

Secure browsing solutions are highly effective in reducing attack surfaces and lowering risk. To strengthen risk prevention, it’s still smart strategy to remember the individual’s role in security. AI targeted phishing, social engineering, and unsanctioned AI applications all thrive in part because human action remains a common entry point.

Communicating with a dispersed remote workforce is challenging but reinforcing the need to always be aware of threats, like phishing, will have concrete benefits when paired with robust browsing isolation and other secure solutions.

Omdia surveyed organizations on the effects of attacks caused by employee web browsing or access to corporate applications. After impacting IT and security teams, the negative results included having to purchase or replace security tools, downtime, compliance and litigation issues and loss of revenue.

The survey also recorded a negative impact to brand management and shareholder value, underscoring the broader organizational impact of human-enabled security incidents.

The data shows organizations want to use AI for positive benefits like threat detection and response. They are also keenly aware of the many ways in which cyber-attacks are using AI to launch a new generation of threats.

In practice, tactics, like phishing and social engineering and exploiting the vulnerabilities of unsecured applications do have practical and enforceable remedies. IT and security teams can impose controls on public AI platforms, on authorized websites and on unauthorized applications. They already have shown a willingness to increase investment in secure browser solutions including browser isolation.

The threat future may be AI, but the secure future will belong to organizations which counterattack with a full array of browser and application defense technologies.

We list the best small and medium business (SMB) firewall software.

This article was produced as part of Tech Radar Pro Perspectives, our channel to feature the best and brightest minds in the technology industry today.

The views expressed here are those of the author and are not necessarily those of Tech Radar Pro or Future plc. If you are interested in contributing find out more here: https://www.techradar.com/pro/perspectives-how-to-submit

You must confirm your public display name before commenting

1 Want to feel more hands-on with your files and spreadsheets? You're in luck - Microsoft and Logitech bring extra haptics to your daily work, via your mouse

2 The Samsung Galaxy S26 Ultra is 'the best Android phone ever' — and it's just hit a new record-low price at the official Samsung Store

3 This controller is one of the best I’ve ever reviewed, and works across PC, Switch, and phones — and it has a unique feature I haven’t seen bettered

4 Microsoft is fixing one of the most baffling things about Windows 11 — 'spam' in search results

5 Elon Musk's legal war with Open AI ends in utter defeat

Tech Radar is part of Future US Inc, an international media group and leading digital publisher. Visit our corporate site.

© Future US, Inc. Full 7th Floor, 130 West 42nd Street, New York, NY 10036.

Key Takeaways

  • News, deals, reviews, guides and more on the newest computing gadgets
  • Start exploring exclusive deals, expert advice and more
  • Unlock and manage exclusive Techradar member rewards
  • Unlock instant access to exclusive member features
  • Get full access to premium articles, exclusive features and a growing list of member rewards

Cut Costs with Runable

Cost savings are based on average monthly price per user for each app.

Which apps do you use?

Apps to replace

ChatGPTChatGPT
$20 / month
LovableLovable
$25 / month
Gamma AIGamma AI
$25 / month
HiggsFieldHiggsField
$49 / month
Leonardo AILeonardo AI
$12 / month
TOTAL$131 / month

Runable price = $9 / month

Saves $122 / month

Runable can save upto $1464 per year compared to the non-enterprise price of your apps.