Report: browser-based SaaS attacks slip past EDR tools, NordLayer finds
NordLayer, citing its Browser Security Report 2026, says attackers increasingly compromise SaaS accounts via browser sessions—OAuth token theft, adversary-in-the-middle phishing, malicious extensions—without triggering endpoint detection and response (EDR) alerts because no malicious process or executable touches the host. It cites the 2025 Salesloft Drift breach, where group UNC6395 used stolen OAuth tokens to pull data from Salesforce via API calls, and a 2026 Microsoft-tracked campaign by Storm-2755 using search ads to phish Canadian employees. NordLayer's report found browser access present in all 504 reviewed applications, with 79% accessible only via browser.
GoKawiil's interpretation of the reporting above, not reported fact.
The analysis suggests that as SaaS and identity workflows move almost entirely into the browser, security teams relying solely on endpoint telemetry may have a structural blind spot for account-takeover and data-theft techniques that never touch the host filesystem. This could push enterprises toward browser-native security tools or stronger session/OAuth monitoring, according to the vendor's framing, though the claims originate from a company selling such solutions.
- OAuth token theft and AiTM phishing can bypass EDR because no host-level executable is involved.
- NordLayer reports 79% of 504 surveyed SaaS tools are browser-only.
- The Salesloft Drift and Storm-2755 incidents are cited as real-world examples of browser-based compromise evading endpoint detection.
NordLayer Business VPN Security Suite — Since browser-based SaaS access is now the primary attack surface, securing network and identity layers around that browser activity matters as much as endpoint detection. NordLayer offers business-focused network security tools like secure remote access and traffic monitoring that complement EDR gaps described in the article. It's a practical step for IT teams looking to close visibility gaps around SaaS and cloud app access.
See NordLayer Business VPN Security Suite on Amazon → Affiliate link — we may earn a commission on purchases, at no extra cost to you. Product picked by AI based on this article; it is not a tested recommendation.Source: bleepingcomputer.com, 2026-10-02
Published there as: “The EDR blind spot: 3 ways browser attacks evade endpoint telemetry”
Read the original report → The summary and analysis above are GoKawiil's own, written from reporting by the source above. Facts and quotes belong to the original publisher.