Tech Talks Daily

3411: Why The Browser Is The New Security Perimeter

Sep 6, 2025
Or Eshed, CEO and co-founder of LayerX Security, dives into the vital yet overlooked world of browser security. He highlights the emerging threats posed by malicious browser extensions that can intercept cookies and meddle with AI chats, urging businesses to rethink their security strategies. With tools like Extensionpedia, users can assess the risks of various extensions, fostering safer online interactions. Or also discusses his team’s collaboration with Google to analyze extensions at scale, emphasizing that effective security must adapt to how people actually work.
Ask episode
AI Snips
Chapters
Transcript
Episode notes
INSIGHT

Browser As A Separate Attack Surface

  • The browser functions as a distinct operating system where identities, payments, and AI interactions converge.
  • Malicious extensions can intercept passwords, cookies, and AI chats to perform identity theft without traditional malware.
ANECDOTE

Cyberhaven Extension Hijack Sparked Wake-Up

  • Cyberhaven's Google admin was hijacked and their extension replaced with malware, exposing many organizations.
  • That incident helped raise market awareness and accelerated Extensionpedia's creation.
INSIGHT

Hidden Dual Behavior In Malicious Extensions

  • Malicious extensions often present benign features while hiding obfuscated, dynamic payloads that activate on specific sites.
  • Detection needs combined static analysis, permission checks, reputation signals, and dynamic sandboxing to reveal hidden behavior.
Get the Snipd Podcast app to discover more snips from this episode
Get the app