Menlo Security

Browser Attacks Prompt Menlo to Link Detection and Response

Browser Attacks Prompt Menlo to Link Detection and Response

The modern workplace lives inside a browser tab, and so does the modern threat. Employees do nearly everything there - email, file sharing, customer records, internal tools - and now AI agents are doing it too, logging into systems, filling forms, and moving data on behalf of the people who deployed them. Attackers have noticed, shifting their efforts toward the browser precisely because it has become the place where the most sensitive work, human or automated, actually happens.

That shift has exposed a structural weakness in how security teams operate. Detection tools flag suspicious activity, but the authority to act on that activity often sits in a completely different system, forcing analysts to manually relay instructions between a security operations center and whatever console actually enforces the fix. In practice, that lag can mean the difference between a contained incident and a breach that spreads before anyone pulls the plug. The same browser-centric reality shapes everyday consumer habits too, including workarounds people use for things like how to watch your home streaming service from abroad, where routing and session handling quietly determine whether access works at all - a reminder that the browser has become the control point for nearly everything, not just corporate workflows.

Menlo Security's newly announced integration with Google Security Operations is a direct response to that gap. Ramin Farassat, the company's Chief Product Officer, described the problem plainly: security teams have spent years manually relaying decisions between investigation and enforcement. The new setup collapses that relay. An analyst reviews an alert inside Google Security Operations, approves a response, and Menlo's infrastructure carries it out inside the browser without a human having to switch tools or re-enter commands.

How detection and enforcement finally meet

At the center of the integration is Menlo's HEAT Shield Agent, which inspects live page content using Google's Gemini models rather than waiting for a malicious site to appear on a reputation blocklist. That distinction matters: reputation-based filtering only works once a threat has already been cataloged somewhere, which means zero-day phishing pages - sites built and deployed before any security vendor has seen them - routinely slip past older defenses. By analyzing content at the moment a user clicks, HEAT Shield Agent aims to stop that class of attack before it does any damage, rather than cleaning up after the fact.

Each detection can now stream directly into Google Security Operations, where a customer's own playbook correlates the event against other telemetry already sitting in the system - login patterns, network activity, prior alerts - and proposes a response. Once a SecOps analyst signs off, the instruction flows back to Menlo's control plane, which executes it automatically. That could mean a policy change, a blocklist update, containment of an active browser session, or any other action exposed through Menlo's API. The point is that the decision and the enforcement now happen in a single, continuous motion instead of two disconnected steps.

Extending protection to AI agents

The integration also addresses a newer and less understood risk surface: AI agents operating inside the browser on a company's behalf. Menlo's MARS system applies the same real-time inspection to these agents as they authenticate, browse, and handle files within the Menlo Cloud, stripping out hidden prompt injection attempts, sanitizing documents through Level 3 content disarm and reconstruction, and enforcing data loss prevention rules as the agent works. Prompt injection - malicious instructions buried inside a web page or file meant to hijack an AI agent's behavior - is an emerging threat category with no long track record, which makes real-time filtering more important than retrospective cleanup. MARS detections already feed into Google Security Operations alongside every other Menlo signal, giving security teams one unified view regardless of whether the activity in question involved a person or an autonomous agent.

Lowering the barrier to response

Rounding out the release is the Menlo Orchestrator Agent, bundled with HEAT Shield Agent and built on Google Cloud's Gemini Enterprise. It gives administrators a conversational interface for forensic work that once required navigating a dedicated admin console: asking what happened during an incident, identifying who else may have been exposed, and applying a fix without first learning Menlo's traditional interface. For security teams already stretched thin, removing that learning curve may matter almost as much as the underlying detection technology itself, since the fastest defense is useless if it takes too long to operate correctly under pressure.