Tekspace Cyber Lab Presents

Browser Security

A Cyber SaaS Analysis 2026
Get future research sooner. We never share or sell your data.

Work moved to the browser. Most security controls didn't follow it there.

Tekspace has spent years inside the systems that keep Australian businesses secure. As work shifted to SaaS and GenAI, data began flowing through tools organisations never provisioned. Exposed sessions, sensitive prompts, credentials leaving on unmanaged extensions, all in the one place endpoint and network controls cannot see. We know the outcomes that matter.

This report changes that. We map the visibility problem at the browser layer, study what businesses actually need to enable AI without adding exposure, and evaluate the leading vendors in the space, finding an architecture that delivers enablement and protection at once.

Thank you to Stacy Gurrie at Byte and Mathew Jose at CodeBlue New Zealand and the team behind the scenes (see Addendum for credits). Together, this work helps us deliver on our focus to protect people and data with simple, impactful cybersecurity.

Portrait photo of Frank De Pasquale
Frank De Pasquale
CEO at Tekspace

Threat Context

Insights from Parabellum Logo

CREST Pen Test certification badge. OffSec OSCE3 certification badge OffSec OSCE certification badge OffSec OSCP certification badge OffSec OSEP certification badge OffSec OSWE certification badge OffSec OSED certification badge OffSec OSWP certification badge

The browser is the primary work surface for Australian organisations, yet most security controls have zero visibility.

The average organisation now runs over 1001 web-based apps and staff access those apps through the browser, in sessions outside the view of security.

The increased exposure is visible; in FY2024-25, ASD reported 11% more cyber incidents while self-reported business losses rose 50%, with compromised accounts or credentials a factor in 42% of the most serious cases.2 In APAC broadly, 69% of breaches across the region involved compromised creds.

Credential theft is fast becoming the goal of smaller scammers, who can sell the data to larger threat groups.

What today's controls miss

The browser is now the front door

75%

Initial access attempts arrive malware-free

Three-quarters of intrusions in 2024 left nothing for endpoint tools to detect. Attackers logged in with stolen browser credentials instead.9

 
50%+

GenAI adoption happens without IT

Over half of current GenAI use is shadow AI: running in browser tabs, on unmanaged accounts, outside any policy.6

 
46%

Compromised corporate logins came from non-managed devices

Nearly half of credential-driven breaches in 2025 originated on devices no endpoint agent ever sees.10

 
42%

Of Australia's most serious incidents involved compromised credentials

ASD's C3 category, the highest impact band, is now dominated by stolen accounts rather than malware.2

 

From session data to sold on the dark web

The browser is where attackers steal credentials and active session tokens. The dark web is where they profit. An IBM Study investigated a maturing ecosystem where stolen credentials were sold as a service.3

Session hijacking kits are also sold to exploit the browser. Attackers buy adversary-in-the-middle phishing kits4 to steal valid tokens. Once an attacker holds a valid session token, they inherit all that user's access without triggering any further authentication challenge.

What "stolen browser data" looks like in practice: In April 2026, an infostealer infection at a small AI productivity vendor cascaded into Vercel through an OAuth-permissioned Chrome extension a Vercel employee had installed at onboarding; ShinyHunters listed the resulting Vercel database for sale at USD $2 million.5 MFA at Vercel didn't block it because authentication was already complete. The attacker inherited an authorised browser session.

In Australia today, there's an estimated 25 million live access session tokens for sale on dark web marketplaces.

The browser data commodity · Australia 2026

A supply chain you don't control

Live AU session tokens for sale 25M

Active session tokens listed on dark web marketplaces. Each one inherits a user's authenticated access without triggering MFA.

Australian cookies on the dark web 308M

Browser cookies harvested by infostealers and resold to initial access brokers. The supply chain feeds ransomware operators downstream.

Vercel listing · April 2026 $2M

ShinyHunters' asking price for the Vercel database after a single OAuth-permissioned Chrome extension cascaded a third-party infostealer in.

ASD ACSC · FY2024-25 42%

Of Australia's most serious cyber incidents (C3) involved compromised accounts or credentials, the dominant impact pattern recorded by ASD this year.

The unprecedented scale of AI-related exposure

Enabling staff with AI has become an urgent requirement for many businesses. Forcing IT teams to write policies that govern how AI is used safely in conjunction with work data.

And if they're not rushing to catch up, they still don't realise how exposed the data is.

More than half of all GenAI adoption is estimated to be without IT knowledge or approval.6 In Australia, 87% of organisations have staff accessing GenAI apps monthly.

As AI integrates further into our workflows the governance gets murkier. Attackers exploit the gap by cloning popular browser extensions for AI assistants. The same data-exfiltration behaviour is now showing up in legitimate, highly rated extensions whose vendors have quietly added it as a product feature. In January 2026, Similarweb (1M+ users) and Stayfocusd (600K+ users) were found scraping every ChatGPT, Claude, Gemini and Perplexity conversation their users had, with the change technically disclosed in updated terms users never read7. Two AITOPIA-clone extensions affected roughly 900,000 users, harvesting LLM transcripts every thirty minutes. Detection requires watching extension behaviour over time, not just at install.

Agentic AI is reshaping what "trust the browser" means

Agentic browsers (those that take actions on the user's behalf) read untrusted webpage content as if it were user instructions. A staff member asks the agent to summarise a Reddit thread; embedded text in a comment tells the agent to open Gmail and exfiltrate financial emails, and the agent silently obeys. There is no phishing click. There is no malware. The user is inside an authenticated session they initiated, with MFA already satisfied8.

This is not a single bug to patch. Brave Security disclosed the issue in August 2025 and a second wave of "unseeable" injection variants in October. LayerX disclosed CometJacking the same month… a single click hijacks an authenticated session to extract email, calendar and connector-granted data. Zenity Labs disclosed the PleaseFix family in March 2026, including calendar-invite triggered password manager takeover. Perplexity's patches were bypassed twice. OpenAI shipped ChatGPT Atlas with a "logged-out mode" as explicit acknowledgement that the problem has no clean technical fix.

Traditional security models assume a clean separation between "user instructions" and "untrusted content." Agentic browsers collapse it. Any agentic AI tool given access to authenticated sessions becomes a privileged insider whose decisions are influenced by content the user is viewing.

Agentic AI · Aug 2025 – 2026

No clean technical fix

  1. Aug 2025 Brave Security

    Discloses prompt injection in agentic browsers (Comet).

  2. Oct 2025 Brave: “unseeable” variants

    Second-wave injections evade the first round of patches.

  3. Oct 2025 LayerX: CometJacking

    Single click hijacks an authenticated session.

  4. Mar 2026 Zenity Labs: PleaseFix

    Calendar-invite triggered password manager takeover.

  5. 2026 ChatGPT Atlas

    OpenAI ships “logged-out mode” as acknowledgement.

Five public disclosures in nine months. Two patch bypasses. OpenAI's "logged-out mode" treats the problem as architectural, not bug-fixable.

Blocking creates an internal risk

Many businesses don't consider the additional risk they create by blocking AI tools.

When the IT team locks down AI tools or restricts SaaS access overnight without guidance, staff route around it, moving to personal devices, personal accounts, or personal subscriptions.

When a user moves from a managed device to an unmanaged personal computer control is lost. It's no surprise attackers are engineering attacks that take advantage of this tension.9 Nearly half of all compromised corporate logins were taken from non-managed devices10 with a majority leaving no malware for an endpoint tool to detect.

Browser security stays in the session, the reliable control for the productivity vs exposure uncertainty. It's the layer that enables staff productivity, while giving leadership the confidence that staff are using those tools correctly.

Security Outcomes

With the threat context as a backdrop, what do information technology professionals prioritise when considering a browser security solution?

  • Frank De Pasquale, Chief Executive Officer at Tekspace
  • Stacy Gurrie, Chief Executive Officer at Byte
  • Mathew Jose, Chief Information Security Officer at CodeBlue NZ

The Top 4

More than features, these four security outcomes are central to protecting staff activity and work data. Informed by findings from client environments and in collaboration with Byte and CodeBlue New Zealand.

1

Efficacy

The platform can intervene inside the browser session; stops credential theft, detects malicious extensions and governs GenAI interactions at the session layer.

2

Operational Efficiency

Browser deployed controls that can enforce policy, does not generate false positives and operates across managed and unmanaged devices without requiring separate workflows.

3

Reporting and Analytics

Visibility extends beyond connection logs, security and leadership able to review AI transcripts, shadow SaaS, browser extensions. Teams can see where policy enforcement is working.

4

User Experience

Browser performance is unaffected, familiar workflows are preserved, and users encounter friction only when their behaviour triggers a policy.

Product Landscape

Comparing browser security products is complex. Solutions overlap and differ in approach; browser extensions, enterprise browsers and cloud-hosted isolation platforms.

Tekspace's Cyber Continuum™ ranks 13 of the best browser security products in one transparent, measurable spectrum. We understood 400+ disparate features, normalising the marketing jargon or vendor framing to 40 capabilities, each ranked by its technical depth.

Focused

  • ManageEngine Icon
    ManageEngine
  • Check Point Harmony Icon
    Harmony
  • SquareX Icon
    SquareX

Features

  • Phishing Detection & Prevention
  • Web Filtering & Application Control
  • Credential Theft Protection
  • Agentless Deployment
  • Data Loss Prevention
  • Multi-Browser Support
  • Shadow AI Usage Detection
  • File Upload/Download Control
  • BYOD/Unmanaged Device Access
  • Browser Session Telemetry
  • Extension Risk Management
  • Malware & Zero-Day Protection
  • Remote Browser Isolation

Broad

  • LayerX Icon
    LayerX
  • Apozy Icon
    Apozy
  • Conceal Icon
    Conceal
  • Acium Icon
    Acium
  • Red Access Icon
    Red Access
  • KeepAware Icon
    KeepAware

Features

  • Zero Trust Browser Security
  • SIEM/SOAR Integration
  • VPN Replacement via ZTNA
  • Shadow IT Detection & Control
  • Human Risk Management
  • Vendor Deployment Integrations
  • Advanced DNS Protection
  • Prompt Recording & Capturing
  • AI-Powered Threat Detection
  • Reporting & Dashboard
  • Content Disarm & Reconstruction
  • Identity & SSO Management
  • Policy Enforcement & Governance
  • Threat Intelligence Integration
  • MSP Multi-Tenancy
  • Zero Trust Files
  • Zero Trust Credentials

Comprehensive

See Vendors and Features
Push Security Icon
Seraphic Icon
Menlo Security Icon
DefensX Icon

Comprehensive

  • Push Security Icon
    PushSecurity
  • Seraphic Icon
    Seraphic
  • Menlo Security Icon
    Menlo Security
  • DefensX Icon
    DefensX

Features

  • Browser Detection & Response
  • SaaS Security Posture Management
  • Password Hygiene & Enforcement
  • Adware & Ad Blocking
  • Screen & Print DLP
  • Automated Threat Response
  • One-Click LLM Security Hardening
  • Sensitive Data Protection via Regex Pattern Matching
  • OAuth & Token Security
  • Compliance Certification

Conclusion

Browser security is an architectural shift, and your last line of defence when every other control has failed.

It can replace VPN and VDI with a single, faster enforced path, but its real value is what no other layer offers: visibility inside the session. That is what tells an approved tool apart from sensitive data being pasted into a personal account, letting teams unlock productivity without adding exposure.

Match the architecture to your risk; you may not need every capability on day one. We hope this research helps you make a deliberate, not reactive, choice.

Want a tailored short-list? We help with that.

A logo on a chart is not a reflection of how a product truly fits your environment with your team.

Book a session Free. If we can't find a match, we exit your journey.

Addendum

Credits

In launching this report, the Tekspace would like to acknowledge contributions from the following teams and individuals.

Prepared by

  • Frank De Pasquale, CEO at Tekspace
  • George Hagivassilis, CCO at Tekspace
  • Finn Astle, Marketing Specialist at Tekspace

Contributions from

  • Martin Dybalski, Director, Parabellum
  • Stuart Shanahan, Director of Technical Services, Parabellum
  • Kris Bowen, Senior Offensive Security Consultant, Parabellum
  • Mathew Jose, Chief Information Security Officer at CodeBlue New Zealand
  • Stacy Gurrie, Cheif Executive Officer at Byte
  • Alison Bourke, Fractional CMO at The Launch Project
  • Romain Pondard, Founder at Klippable

References

  1. Okta, Businesses at Work 2025, March 2025. Average 101 apps per organisation, 9% YoY growth.
  2. ASD, ACSC Annual Cyber Threat Report 2024-25, October 2025. 1,253 incidents (11% increase); compromised accounts or credentials in 42% of C3 incidents; $80,850 avg business cost; $202,700 large org cost.
  3. IBM, X-Force Threat Intelligence Index 2025, April 2025. 84% increase in infostealer delivery via phishing 2024 vs 2023; early 2025 data suggests ~180% jump over 2023.
  4. Microsoft, Digital Defense Report 2025, November 2025. Token theft listed as key user impersonation tactic; AiTM phishing proxy interception of sessions.
  5. Cyber Lab and Parabellum case file, April 2026. Vercel x Context.ai supply chain compromise: infostealer infection at a third-party AI vendor cascaded through an OAuth-permissioned Chrome extension into Vercel's Workspace; ShinyHunters listed the Vercel database for sale at USD $2M on BreachForums.
  6. Netskope, Shadow AI and Agentic AI 2025, August 2025. Over half of all current genAI app adoption estimated to be shadow AI; avg 15 genAI apps per org.
  7. Secure Annex (John Tuckner), January 2026; reported via TechCrunch and DarkReading.
  8. Brave Security and LayerX, August - October 2025. Comet prompt injection and CometJacking disclosures: malicious page content executed as agent instructions; single-click hijack of an authenticated agentic browser session to extract email, calendar and connector data. Brave: “a systemic challenge facing the entire category of AI-powered browsers.”
  9. CrowdStrike, Global Threat Report 2025, February 2025. 75% of initial access attempts malware-free; access broker advertisements surged 50% YoY.
  10. Verizon, Data Breach Investigations Report 2025, May 2025. 46% of compromised systems with corporate logins were non-managed devices; only ~54% of edge device vulnerabilities fully remediated; edge device exploitation grew ~8x YoY.

Scope

This report evaluates browser-native edge security platforms delivering web threat prevention, browser-based data loss protection, SaaS access governance, and GenAI usage controls. It does not cover traditional network security products (SASE, SD-WAN, secure web gateways operating at the network layer), standalone endpoint detection and response platforms, or broader governance/risk/compliance tools. The evaluation methodology and vendor data are documented separately in the Tekspace Cyber Lab product landscape workbook.

Scoring Methodology

Features were classified into three maturity bands based on how many of the 13 evaluated vendors offer each capability across 40 normalised features. Comprehensive features (offered by the majority of vendors) represent table stakes. Broad features (moderate vendor coverage) represent strong market presence. Focused features (limited vendor coverage) represent specialist capabilities. A weighted scoring model assigns higher value to features that require greater technical depth, producing a single maturity score per vendor. Full scoring methodology is available on request.

Feature Granuality Model

At the outset, we aimed to produce an analysis that is both strategic and practical. It needs to be useful to all IT leaders, regardless of how familiar they are with a given product domain.

In doing so, we gave consideration to how products are compared against one another.

Comparison at a superficial level is too shallow and doesn't give insight as to differentiation between products. At the same time, diving into technical minutiae can often mean losing focus of how products are meaningfully differnt.

As such, we conduct our evaluation at what we call, Level 2: The Functional Group.

In doing so, we can consistently assess whether a product's capabilities are more or less likely to help IT leaders achieve their desired outcomes.

Domain Level 1
The Module
Level 2
The Functional Group
Level 3
The Micro-Feature
Grocery Fruit Banana Sold in bunches of 5
Automotive Car Wheels 5 spokes, 5 lug nuts
Education Course Mathematics Weekly problem sets
Healthcare Clinic GP Consultations 15 Minute Standard Appointment

Disclaimers

Tekspace maintains commercial relationships with vendors across the cybersecurity industry. These relationships do not influence the research methodology, vendor scoring, or maturity tier placement documented in this report. All assessments reflect Tekspace's independent professional judgement based on hands-on product evaluation.

This report is intended as a decision-support tool and does not constitute professional advice. Organisations should conduct their own due diligence appropriate to their specific requirements, risk profile, and regulatory obligations.

If you believe any information in this report requires correction, or if you would like your product assessed for inclusion, contact the Tekspace Cyber Lab at lab@tekspace.com.au.

Contact our team
Close

Focused

  • ManageEngine Icon
    ManageEngine
  • Check Point Harmony Icon
    Harmony
  • SquareX Icon
    SquareX

Features

  • Phishing Detection & Prevention
  • Web Filtering & Application Control
  • Credential Theft Protection
  • Agentless Deployment
  • Data Loss Prevention
  • Multi-Browser Support
  • Shadow AI Usage Detection
  • File Upload/Download Control
  • BYOD/Unmanaged Device Access
  • Browser Session Telemetry
  • Extension Risk Management
  • Malware & Zero-Day Protection
  • Remote Browser Isolation
Close

Broad

  • LayerX Icon
    LayerX
  • Apozy Icon
    Apozy
  • Conceal Icon
    Conceal
  • Acium Icon
    Acium
  • Red Access Icon
    Red Access
  • KeepAware Icon
    KeepAware

Features

  • Zero Trust Browser Security
  • SIEM/SOAR Integration
  • VPN Replacement via ZTNA
  • Shadow IT Detection & Control
  • Human Risk Management
  • Vendor Deployment Integrations
  • Advanced DNS Protection
  • Prompt Recording & Capturing
  • AI-Powered Threat Detection
  • Reporting & Dashboard
  • Content Disarm & Reconstruction
  • Identity & SSO Management
  • Policy Enforcement & Governance
  • Threat Intelligence Integration
  • MSP Multi-Tenancy
  • Zero Trust Files
  • Zero Trust Credentials
Close

Comprehensive

  • Push Security Icon
    PushSecurity
  • Seraphic Icon
    Seraphic
  • Menlo Security Icon
    Menlo Security
  • DefensX Icon
    DefensX

Features

  • Browser Detection & Response
  • SaaS Security Posture Management
  • Password Hygiene & Enforcement
  • Adware & Ad Blocking
  • Screen & Print DLP
  • Automated Threat Response
  • One-Click LLM Security Hardening
  • Sensitive Data Protection via Regex Pattern Matching
  • OAuth & Token Security
  • Compliance Certification
Get future research