The browser is where your people work. It's also where attackers have shifted — and where your existing security investments have their widest blind spot.
This report documents what Menlo Security blocked across enterprise customer environments in Q1 2026: 4,937 zero-day attacks stopped before reputation filters knew they existed, 52,185 threats launched from sites your stack already classified as safe, and 115,842 evasive phishing campaigns purpose-built to bypass legacy detection.
Inside, you'll find the attack techniques driving that number — ClickFix, AiTM, HTML smuggling, RMM tool abuse — documented with real case studies, named threat groups, and a five-question self-assessment framework you can run against your own security stack today.
Your tools aren't broken. The browser session layer was never covered. This report tells you exactly where that gap is, what's exploiting it, and what you need to close it.
Read the full report here!
