Cybercriminals are using AI to launch sophisticated browser attacks that can be difficult to detect and can put a financial institution’s network at risk if it does not have modern safeguards.
Traditional security platforms can fail against some browser attack techniques, such as open redirects that take users to malicious sites and hidden payloads carrying invasive codes in seemingly safe files, Karthik Vaidyalingam, field chief technology officer at data and AI security platform Varonis, said in a Sept. 1 webinar.
Part 1: Read about different types of browser attacks here.
“Defenses like URL filtering or even user training exercises are insufficient,” he said. “Organizations need AI-powered browser security and continuous domain monitoring to counter these evolving threats.”
Organizations must stay current on the latest technologies to detect browser-based attacks because cybercriminals continue to pivot and launch new attacks, Vaidyalingam said.
“As quickly as one campaign is impeded or a domain is flagged, the attacker spins up another domain with slightly altered language,” he said. “It’s a constant game of whack-a-mole at that point.”
Proxy browsers
Institutions can protect themselves by setting up proxy browsers — a browser setup that routes internet traffic through an intermediary proxy server rather than connecting an institution’s network directly to the internet — and applying controls on browser behavior. For example, browser security company Menlo Security offers a customized cloud platform through which users can browse the web with company-implemented controls in place.

“We can enforce controls to both protect your users and also protect your enterprise to do things like data-leak prevention,” Lionel Litty, chief information security officer at Menlo Security, told FinAi News.
“That cloud browser works with your existing browser, so users don’t need to install any different software,” he said. “You just end up configuring a proxy so that the traffic gets routed through the menu platform.”
If a user visits a malicious website through the cloud browser, the company’s assets are not connected and therefore not exposed.
The cloud browser can also be customized to prevent certain behaviors.
“We can, for example, make websites read-only, so you can visit the website, you can click around, but if you try to do any kind of user input, that will be prevented,” Litty said.
“For an analyst-type use case where you go and visit some website that may be questionable, most of the time you’re just seeking information. You don’t need to type anything.”
Customization can also block file uploads and prevent copy-and-paste capabilities.
Limit internet-accessible systems
Companies should also routinely reexamine their internet-accessible assets, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) said in an Aug. 25 release. Internet-accessible assets include:
- Industrial Internet of Things;
- Supervisory control and data acquisition systems;
- Industrial control systems; and
- Remote access technologies.
CISA last month updated its internet exposure reduction guidance to recommend that organizations routinely scan their public IP address ranges to identify ports and services that are accessible from the internet. They should remove internet access for services that do not need it.
For services that do, companies should verify third-party remote access and implement access management solutions such as multifactor authentication and firewalls, according to CISA.
While browser attacks can target any industry, CISA observed malicious cyber activity targeting more than 100 internet-exposed systems in the water and wastewater systems sector in July.
FinAi Lending Summit, set for Oct. 7-8 in Las Vegas, will include speakers from Fifth Third and Capital One as well as a fireside chat with Piermont Bank founder and Chief Executive Wendy Cai-Lee. To learn more about the 2026 event and register for early-bird pricing through today, visit here.






