By 2027, Gartner projects 85% of enterprise workloads will run through the browser. Attacks have followed. Browser-based exploits, credential theft, fileless malware, and AI-generated polymorphic code now execute locally inside browser tabs before endpoint tools can respond. CrowdStrike data shows an 89% increase in AI-enabled adversary attacks in the past year alone. Yet most enterprise security architecture still protects the device, not the session where the work and the attack actually happen.
CloudMosa's Puffin Cloud Security takes a structural approach rather than a detection one. The platform runs the full browser session, including JavaScript, WebAssembly, and other executable payloads, inside a disposable cloud environment, then streams only a rendered pixel view to the device. The device never parses or executes the original code. CloudMosa says display rasterization, the only layer that reaches the endpoint, accounts for roughly 5% of total browser workload. Zero-days and polymorphic malware have nothing to run on. The argument worth reading in full is not the product pitch but the architectural logic: detection-first security has a timing problem, and AI-assisted mutation is making that window shorter, not longer.
The piece is sponsored by CloudMosa, so read it with that in mind. But the underlying tension is real and the numbers are not theirs. A 2026 Darktrace survey found 92% of security professionals are concerned about AI agent threats, with 48% naming agentic AI the top attack vector of the year. As autonomous agents operate with user-level privileges inside the same browser environment, session hijacking and prompt injection become infrastructure problems, not just endpoint ones. The full article details how Puffin layers onto existing SWG, CASB, and ZTNA stacks without replacing them, which is the practical question any security architect will actually need answered.
[READ ORIGINAL →]