The browser has become the primary workspace for modern enterprises, yet it remains the least visible part of the security stack. Traditional tools such as Secure Web Gateways (SWG) and Endpoint Detection and Response (EDR) were designed for a different era and struggle to see what actually happens inside the browser. This session examines how that visibility gap exposes organizations to real attacks in the wild, including malicious extensions, phishing and OAuth consent attacks. We will discuss what these incidents reveal about today’s threat landscape and how browser security helps regain control and visibility through browser-native security controls, telemetry, and policy frameworks. This talk will give an understanding of how to make the browser a measurable part of their enterprise defense strategy.
Shourya Pratap Singh is the Principal Software Engineer at SquareX, where he leads the development of security-focused browser extensions and conducts research on methods to mitigate web security risks. He has presented his research at prominent conferences such as DEFCON and Black Hat Arsenal EU and has conducted workshops at events like the Texas Cyber Summit. Shourya holds a bachelor’s degree from IIIT Bhubaneswar and is a patent holder. His professional passions are centered on advancing the security of browser extensions and web applications.
Model Context Protocol was released in Dec 2025. Since that time, it has become the de facto standard for AI client systems to connect to AI powered servers. But the protocol itself provides very limited security guardrails. And studies are showing that greater than 40% MCP servers are vulnerable to various security attacks such as prompt injection, rug pull attacks, etc. In this talk, we cover what is MCP and then demonstrate some MCP attacks and discuss guardrails.
KK Mookhey is the founder and CEO of Network Intelligence. He started the company in 2001 as a pen-testing outfit and grew it to a 500+ people firm with operations across the globe. Last year, KK co-founded a new company – Transilience – to develop AI-powered solutions for cybersecurity. He is a CISA, CISSP and AZ-500 and an avid mountaineer. He also has a YouTube channel on AI & Cybersecurity found HERE.