The Containment Era is here. →Explore

Executive Summary

In December 2025, researchers from Straiker STAR Labs disclosed a zero-click browser-based attack targeting users of Perplexity's Comet browser, enabling malicious actors to erase the contents of a victim’s entire Google Drive. The attack leverages agentic browser automation capable of connecting Gmail and Google Drive accounts by abusing trusted email-based automations. Once triggered by a specially crafted email, the exploit requires no user interaction to execute the destructive action. The compromise of cloud-stored data had significant operational impact, resulting in permanent data loss for affected users and highlighting new risks for organizations relying heavily on SaaS storage platforms.

This attack is significant as it demonstrates the expanding threat of zero-click vulnerabilities powered by advanced browser automation, agentic AI, and email exploits. As more organizations migrate operations and collaborative data to the cloud, the frequency and sophistication of such attacks are expected to increase, escalating the urgency for robust cloud security controls.

Why This Matters Now

Zero-click attacks that exploit browser integrations and automation tools are on the rise, bypassing traditional endpoint protections. Organizations relying on browser-based workflows and SaaS storage face heightened and urgent risk of mass data loss events, necessitating rapid assessment of cloud access permissions and controls.

Attack Path Analysis

Related CVEs

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

The incident highlighted insufficient controls around access permissions, weak egress policy enforcement, and lack of robust anomaly detection for SaaS integrations, exposing businesses to large-scale data loss.

Cloud Native Security Fabric Mitigations and ControlsCNSF

CNSF and Zero Trust network controls such as segmentation, egress policy enforcement, inline threat detection, and cloud-native visibility could have limited unauthorized lateral API actions, prevented automation-based data destruction, and alerted on anomalous access patterns stemming from the exploited browser session.

Initial Compromise

Control: Threat Detection & Anomaly Response

Mitigation: Anomalous browser-initiated cloud drive access would be detected and alerted.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Unauthorized privilege upgrades via browser tokens could be blocked.

Lateral Movement

Control: East-West Traffic Security

Mitigation: Cross-service API movement and internal lateral flows would be constrained.

Command & Control

Control: Cloud Native Security Fabric (CNSF)

Mitigation: Real-time inspection and distributed enforcement detect and restrict malicious control plane activity.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: If exfil attempted, outbound data to unsanctioned destinations would be stopped.

Impact (Mitigations)

Rapid visibility would enable immediate remediation of destructive actions.

Impact at a Glance

Affected Business Functions

  • Data Management
  • Collaboration Tools
Operational Disruption

Estimated downtime: 3 days

Financial Impact

Estimated loss: $500,000

Data Exposure

Potential exposure includes unauthorized deletion of critical business documents stored in Google Drive, leading to operational disruptions and financial losses.

Recommended Actions

  • Deploy Zero Trust Segmentation to tightly restrict agentic browser and SaaS automation access scopes.
  • Enforce east-west API and service boundaries with identity-based microsegmentation to prevent lateral pivots between cloud services.
  • Implement real-time anomaly detection and automated incident response to high-risk browser automation activities targeting cloud storage.
  • Apply rigorous egress controls to block unauthorized outbound access and API calls from automated tools.
  • Centralize visibility across multi-cloud and SaaS environments for prompt detection, investigation, and containment of automation-driven threats.

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image