Learn how they’re bypassing cybersecurity controls and what security teams can do it.
Many modern breaches happen entirely in the web browser. Attackers target your users as they go their work, intercepting them as they access legitimate, trusted websites.
Where we used to talk novel software exploits and advanced endpoint malware, in 2026 we’re instead talking cloud apps and identities as the “patient zero” of modern breaches.
Attackers in 2026 are using a wide (and growing) range of browser-based techniques to achieve a common goal: compromise cloud applications and services accessed over the internet, and ultimately profit from data theft, disruption, and extortion. This is now the primary attack path.
We break down all of the major techniques, analysing in-the-wild use of AITM phishing, malicious OAuth apps, malicious browser extensions, credential stuffing (& ghost logins), ClickFix (and the family of *fix variants), and session hijacking.
Browser-based attacks are so effective because they find ways around many traditional control points and security tools.
It’s essential that blue teamers leave “list thinking” behind and re-evaluate whether their controls are providing the protection they thought they did.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
