Menlo Security Launches Browser Security Platform to Govern AI Agents and Prevent Data Exfiltration
What Happened – Menlo Security introduced a Browser Security Platform designed to extend zero‑trust controls into web‑browser sessions used by both human users and autonomous AI agents. The solution provides a unified governance plane that can enforce policy, prevent prompt‑injection attacks, and stop data exfiltration at machine speed.
Why It Matters for TPRM –
- AI‑driven agents are rapidly becoming a third‑party attack surface that traditional security tools often miss.
- Compromised agents can move laterally, steal data, or execute fraudulent transactions without human oversight.
- Vendors that embed browser‑based AI agents into their services must be evaluated for this emerging risk.
Who Is Affected – Enterprises deploying AI agents, SaaS providers offering browser‑based services, and any organization that relies on web‑based workflows (technology, finance, healthcare, etc.).
Recommended Actions –
- Review contracts and security questionnaires for any vendor that uses AI agents or headless browsers.
- Verify that the vendor employs browser‑level zero‑trust controls or comparable governance.
- Incorporate AI‑agent risk assessments into your third‑party risk program and require continuous monitoring.
Technical Notes – The platform inserts security controls directly into the browser session, protecting against prompt‑injection, credential leakage, and lateral movement by AI agents. It leverages Menlo’s elastic cloud infrastructure and integrates with Google’s least‑privileged remote‑access solution. No specific CVEs are disclosed. Source: Help Net Security