As reported by BleepingComputer, a NordLayer-sponsored analysis highlights a structural gap in endpoint detection and response coverage: attacks conducted entirely through browser sessions and identity workflows frequently produce no host-level artifacts for EDR to inspect. This is not a product deficiency — it's a detection paradigm mismatch that security leaders need to address deliberately.

Cloud Security Alert: As reported by BleepingComputer, a NordLayer-sponsored analysis highlights a structural gap in endpoint detection and response coverage: attacks conducted entirely through browser sessions and identity workflows frequently produce no host-level artifacts for EDR to inspect.

The Detection Paradigm Shift

EDR was architected for a world where attackers needed to execute code on the endpoint to achieve their objectives. Process creation, memory injection, persistence mechanisms, and filesystem writes were the telemetry anchors. That model still holds for traditional malware — but it breaks down when the attack surface moves to the identity and application layers.

The browser is now the dominant corporate access layer. When an attacker steals a session token via adversary-in-the-middle phishing, abuses an OAuth grant, or leverages a malicious extension, the resulting activity flows through an authenticated browser session that looks functionally identical to a legitimate user's. There's no payload to detonate, no suspicious process tree to analyze, no persistence mechanism to flag. EDR telemetry simply has nothing to correlate against.

The most damaging attacks in SaaS-heavy environments are increasingly identity-bound, not host-bound — and detection tools built for host compromise cannot close that gap alone.

Who Is Most Exposed

Organizations with heavy SaaS dependence — CRM platforms, HRIS systems, collaboration suites, and cloud-delivered productivity tools — face the greatest exposure. The referenced Storm-2755 campaign targeting Canadian employees demonstrates how session token theft enables access to payroll systems, HR data, and sensitive email without ever touching the endpoint in a detectable way. Mid-market enterprises that have invested heavily in EDR but underinvested in identity and SaaS security controls are particularly vulnerable to this blind spot.

The Three Attack Vectors That Matter Most

Who Is Most Exposed
Adversary-in-the-middle phishing: Real-time credential and session token capture that bypasses MFA because the session itself is stolen post-authentication
Malicious or hijacked browser extensions: Code running with user permissions inside the browser context, often invisible to endpoint tooling
OAuth and API token abuse: Stolen or over-privileged tokens enabling programmatic data access without endpoint interaction

Shield53 Recommendations

Defenders should stop treating EDR as a comprehensive control and instead architect detection across three complementary layers:

  • Layer 1 — Identity: Deploy conditional access policies that evaluate device posture, location anomalies, and session risk signals. Enforce token revocation on suspicious session activity and implement session lifetime controls for high-privilege accounts.
  • Layer 2 — SaaS visibility: Implement Cloud Access Security Broker or SaaS Security Posture Management tooling to detect anomalous API usage, unusual data exfiltration patterns, and suspicious OAuth grants. The 2025 UNC6395/Drift incident demonstrates that high-volume API calls against SaaS platforms are a detectable signal — but only if you're looking at the right layer.
  • Layer 3 — Browser-level controls: Evaluate managed browser solutions or browser security extensions that can inspect and control in-browser activity, block known malicious extensions, and enforce data handling policies on SaaS sessions where EDR has no visibility.
  • Detection engineering: Build detection rules for session token reuse across IP addresses, user agents, and geographies. Alert on impossible travel scenarios tied to SaaS access, not just identity provider login events.
  • Threat hunting: Proactively audit OAuth application grants across your SaaS estate — stale integrations and over-scoped permissions are the soft underbelly of most organizations' SaaS security posture.

The fundamental lesson here is architectural: in a world where the browser is the primary attack surface, detection must meet the adversary where they operate. EDR remains essential for host-based threats — but it cannot be your only line of defense against attacks that never touch the host.