Browser Security
A Cyber SaaS Analysis 2026Threat Context
Why the browser is now the front door for attackers in Australia.
Security Outcomes Video
What Australian IT leaders prioritise when choosing a browser security solution.
Product Landscape
13 leading vendors benchmarked on The Tekspace Cyber Continuum™.
Conclusion
Key takeaways, future outlook, and how to act on this research.
Work moved to the browser. Most security controls didn't follow it there.
Tekspace has spent years inside the systems that keep Australian businesses secure. As work shifted to SaaS and GenAI, data began flowing through tools organisations never provisioned. Exposed sessions, sensitive prompts, credentials leaving on unmanaged extensions, all in the one place endpoint and network controls cannot see. We know the outcomes that matter.
This report changes that. We map the visibility problem at the browser layer, study what businesses actually need to enable AI without adding exposure, and evaluate the leading vendors in the space, finding an architecture that delivers enablement and protection at once.
Thank you to Stacy Gurrie at Byte and Mathew Jose at CodeBlue New Zealand and the team behind the scenes (see Addendum for credits). Together, this work helps us deliver on our focus to protect people and data with simple, impactful cybersecurity.
The browser is the primary work surface for Australian organisations, yet most security controls have zero visibility.
The average Okta customer now runs 101 apps1 and staff access those apps through the browser, in sessions outside the view of security.
That increased exposure has made businesses vulnerable.
In FY2024-25, ASD responded to 11% more cyber incidents, and the average self-reported cost of a business cybercrime report rose 50% to $80,850, with compromised accounts or credentials a factor in 42% of the incidents ASD rated C3 or higher.2
Credential theft pays threat actors who sell the data on the dark web to large syndicates.
The browser is now the front door
-
82%
Of detections were malware free
In 2025, 82% of the detections CrowdStrike observed were malware free, as attackers log in and use legitimate tools instead.9
-
55%
Personal AI app use in Australia and New Zealand
Personal AI app use still sits at 55%, down from 76% a year earlier.6
-
46%
Of infostealer-infected systems with corporate logins were unmanaged
Among infostealer-infected systems holding corporate logins, 46% were unmanaged devices, outside the reach of endpoint agents.10
-
42%
Of incidents ASD rated C3 or higher involved compromised credentials
Compromised accounts or credentials featured in 42% of the incidents ASD rated C3 or higher in 2024 to 2025.2
Bars are drawn to scale, on a 0 to 100% axis.
From session data to sold on the dark web
The browser is where attackers steal credentials and active session tokens. The dark web is where they profit. IBM X-Force’s 2025 Threat Intelligence Index describes a thriving dark web trade in stolen credentials.3
Session hijacking kits are also sold to exploit the browser. Attackers buy adversary-in-the-middle phishing kits4 to steal valid tokens. Once an attacker holds a valid session token, they inherit all that user's access without triggering any further authentication challenge.
What "stolen browser data" looks like in practice: In April 2026, Vercel disclosed a breach that began at Context.ai, a third party AI tool one of its staff had trialled. A Context.ai employee’s computer was infected with the Lumma infostealer after they downloaded Roblox cheat scripts, which took Google Workspace, Supabase, Datadog and AuthKit credentials. Context.ai says an attacker then reached its AWS environment and likely took OAuth tokens. One belonged to a Vercel employee who had signed up with a corporate Google account and granted “Allow All” access. The attacker used it to take over the account and move into Vercel’s systems. Nobody broke through Vercel’s perimeter. The same weekend, a seller offered the data for about USD $2 million.5
A supply chain you don't control
Stolen browser cookies linked to Australia, listed for sale on dark web forums and Telegram channels.11
Nearly 25 million of those Australian cookies were still active when listed for sale.11
What a seller asked for the Vercel data, the same weekend Vercel disclosed a breach that began one vendor away, at Context.ai.5
Of the incidents ASD rated C3 or higher in 2024 to 2025 featured compromised accounts or credentials.2
AI is reshaping what "trust the browser" means
Enabling staff with AI is now urgent, and most organisations are already behind it: three in four workers in Australia and New Zealand now actively use AI apps, up from 53% a year earlier.6
Attackers exploit that gap by cloning popular AI assistant extensions: in January 2026, two fake AI sidebar extensions, one carrying Google’s Featured badge, were found stealing ChatGPT and DeepSeek chats from about 900,000 users. Some legitimate extensions have added similar collection as a product feature: Secure Annex found the Similarweb extension, used by over a million people, began capturing AI prompts and responses after a May 2025 update, disclosed in its privacy policy.7 Detection means watching extension behaviour over time, not just at install.
Agentic browsers, the kind that take actions on a user's behalf, read untrusted webpage content as if it were a user instruction. A staff member asks the agent to summarise a Reddit thread. Hidden text in a comment tells it to collect the user’s email address and a one-time login code from Gmail and post them back to Reddit, handing the attacker the account. There is no phishing click and no malware, just the user’s own signed-in session doing the attacker’s work.8
Traditional security models assume a clean separation between user instructions and untrusted content. Agentic browsers collapse it, turning any AI tool with session access into a privileged insider whose decisions are shaped by the content the user is viewing.
No clean technical fix
-
Aug 2025 Brave Security
Shows Perplexity Comet can be hijacked by hidden instructions in a web page, and finds Perplexity’s first fix incomplete.
-
Oct 2025 LayerX: CometJacking
A single crafted link can make Comet’s assistant send a user’s connected Gmail and Calendar data to an attacker.
-
Oct 2025 Brave Security
Near-invisible instructions in screenshots and web pages can hijack Comet, Fellou and other AI browsers.
-
Oct 2025 OpenAI: ChatGPT Atlas
Launches with a logged-out mode to limit the agent’s access. By December, says prompt injection is unlikely ever to be fully solved.
-
Mar 2026 Zenity Labs: PleaseFix
Attacker content such as a calendar invite can silently hijack Comet to steal local files and take over a user’s 1Password account.
Four research teams published agentic browser hijacks between August 2025 and March 2026, and Brave found Perplexity’s first fix incomplete. OpenAI says prompt injection is unlikely ever to be fully solved. Events are evenly spaced, not to scale.8
Blocking creates an internal risk
Many businesses don't consider the additional risk they create by blocking AI tools.
When the IT team locks down AI tools or restricts SaaS access overnight without guidance, staff route around it, moving to personal devices, personal accounts, or personal subscriptions.
When a user moves from a managed device to an unmanaged personal computer control is lost. It's no surprise attackers are engineering attacks that take advantage of this tension.9 Among infostealer-infected systems holding corporate logins, 46% were unmanaged devices, outside the reach of corporate endpoint tools.10
Browser security stays in the session, the reliable control for the productivity vs exposure uncertainty. It's the layer that enables staff productivity, while giving leadership the confidence that staff are using those tools correctly.
Security Outcomes
With the threat context as a backdrop, what do information technology professionals prioritise when considering a browser security solution?
- Frank De Pasquale, Chief Executive Officer at Tekspace
- Stacy Gurrie, Chief Executive Officer at Byte
- Mathew Jose, Chief Information Security Officer at CodeBlue NZ
What matters in your assessment? Whatever the domain, a security product earns its place against the same four outcomes. Expand each to see how we assess the browser security category.
Efficacy
- Intervention inside the browser session itself, not at the network edge
- Credential theft, malicious extensions and zero-day web content stopped in place
- Generative AI and unsanctioned SaaS use governed at the point of interaction
Operational Efficiency
- Agentless deployment across managed, unmanaged and BYOD devices
- Policy enforcement accurate enough to avoid a parallel exceptions process
- Automated response and SIEM or SOAR handoff for confirmed events
Reporting and Analytics
- Session telemetry beyond connection logs, including prompts submitted to AI tools
- Shadow SaaS and extension inventory maintained as a standing view
- Dashboards showing where enforcement is holding and where it is bypassed
User Experience
- No measurable impact on browsing performance
- Existing browsers and workflows preserved rather than replaced
- Friction introduced only when a user's own action meets a policy
Product Landscape
Comparing browser security products is complex. Solutions overlap and differ in approach; browser extensions, enterprise browsers and cloud-hosted isolation platforms. Tekspace's Cyber Continuum™ ranks 13 of the best browser security products in one transparent, measurable spectrum.
Focused
See Vendors and FeaturesFocused
- Check PointHarmony
- ManageEngine
- SquareX
Features
- Phishing Detection & Prevention
- Web Filtering & Application Control
- Credential Theft Protection
- Agentless Deployment
- Data Loss Prevention
- Multi-Browser Support
- Shadow AI Usage Detection
- File Upload/Download Control
- BYOD/Unmanaged Device Access
- Browser Session Telemetry
- Extension Risk Management
- Malware & Zero-Day Protection
- Remote Browser Isolation
Broad
See Vendors and FeaturesBroad
- AkamaiLayerX
- Apozy
- Conceal
- Acium
- KeepAware
- Red Access
Features
- Zero Trust Browser Security
- SIEM/SOAR Integration
- VPN Replacement via ZTNA
- Shadow IT Detection & Control
- Human Risk Management
- Vendor Deployment Integrations
- Advanced DNS Protection
- Prompt Recording & Capturing
- AI-Powered Threat Detection
- Reporting & Dashboard
- Content Disarm & Reconstruction
- Identity & SSO Management
- Policy Enforcement & Governance
- Threat Intelligence Integration
- MSP Multi-Tenancy
- Zero Trust Files
- Zero Trust Credentials
Comprehensive
See Vendors and FeaturesComprehensive
- CrowdStrikeSeraphic
- Push Security
- Menlo Security
- DefensX
Features
- Browser Detection & Response
- SaaS Security Posture Management
- Password Hygiene & Enforcement
- Adware & Ad Blocking
- Screen & Print DLP
- Automated Threat Response
- One-Click LLM Security Hardening
- Sensitive Data Protection via Regex Pattern Matching
- OAuth & Token Security
- Compliance Certification
We understood 400+ disparate features across the thirteen vendors, normalising them down to 40 scored features in 12 capability groups, each group sitting under one of the four outcomes above and each feature ranked by its technical depth.
Want to know which of these fits your environment? We help with that.
A logo on a chart does not tell you whether the tool covers the unmanaged devices your contractors are on, or the AI tools your people have already adopted.
Book your sessionConclusion
Browser security is an architectural shift, and your last line of defence when every other control has failed.
It can replace VPN and VDI with a single, faster enforced path, but its real value is what no other layer offers: visibility inside the session. That is what tells an approved tool apart from sensitive data being pasted into a personal account, letting teams unlock productivity without adding exposure.
Match the architecture to your risk; you may not need every capability on day one. We hope this research helps you make a deliberate, not reactive, choice.
We're hearing this exact question from IT leaders right now, as GenAI rollouts move from pilot to policy this quarter. When you're ready to pressure-test that choice against your own environment, you can book time with Tekspace directly.
Addendum
Credits
In launching this report, the Tekspace would like to acknowledge contributions from the following teams and individuals.
Contributors
- Lead Analysts — Frank De Pasquale, CEO at Tekspace.
- Threat Context — Martin Dybalski, Director; Stuart Shanahan, Director of Technical Services; and Kris Bowen, Senior Offensive Security Consultant, all at Parabellum.
- Security Outcomes — Mathew Jose, Chief Information Security Officer at CodeBlue New Zealand; and Stacy Gurrie, Chief Executive Officer at Byte.
- Research and analysis by the Tekspace Research team.
References
- Okta, Businesses at Work 2025, March 2025. Okta customers deployed an average of 101 apps each in 2024, up 9% year on year and above 100 for the first time.
- ASD, ACSC Annual Cyber Threat Report 2024-25, October 2025. 1,253 incidents (11% increase); compromised accounts or credentials in 42% of incidents rated C3 or higher; average self-reported cost of a business cybercrime report $80,850, up 50%; $202,700 average cost per report for large businesses, up 219%.
- IBM, X-Force Threat Intelligence Index 2025, April 2025. 84% increase in emails delivering infostealers in 2024 compared with 2023; early 2025 data showed a 180% increase over 2023.
- Microsoft, Digital Defense Report 2025, 16 October 2025. Token theft listed as a key user impersonation tactic; adversary-in-the-middle (AiTM) phishing named among methods used to bypass MFA.
- Vercel, security bulletin, 19 April 2026 (updated 24 April); Hudson Rock, 20 April 2026; BleepingComputer, April 2026. Breach via Context.ai: Lumma infostealer on a Context.ai employee’s computer, OAuth token for a Vercel employee’s corporate Google account, data offered for about USD $2 million the same weekend Vercel disclosed.
- Netskope, Threat Labs Report: Australia & New Zealand 2026, September 2026. Users actively using AI apps rose from 53% to 75%; personal AI app use fell from 76% to 55%.
- OX Security via Dark Reading, 8 January 2026; Secure Annex (John Tuckner), 29 December 2025.
- Brave, 20 August 2025 and 21 October 2025; LayerX, 4 October 2025; OpenAI, 21 October 2025 and 22 December 2025; Zenity Labs, 3 March 2026. Agentic browser prompt injection disclosures (Perplexity Comet, Fellou, ChatGPT Atlas), including Brave’s Reddit one-time code account takeover demonstration.
- CrowdStrike, Global Threat Report 2026. 82% of detections in 2025 were malware free.
- Verizon, Data Breach Investigations Report 2025, April 2025. Among infostealer-infected systems holding corporate logins, 46% were unmanaged devices; edge devices and VPNs were the target in 22% of vulnerability exploitation breaches, up from 3%; about 54% of those edge vulnerabilities were fully remediated, taking a median of 32 days.
- NordVPN with NordStellar, Sticky fingers in the cookie jar, 27 May 2025. 307,941,945 cookies linked to Australia listed for sale; 24,800,956 (8.05%) active.
Browser Security category
What this report does and doesn’t claim to cover, how we compare products fairly, and what to do if you still have questions.
Scope
This report evaluates browser-native edge security platforms delivering web threat prevention, browser-based data loss protection, SaaS access governance, and GenAI usage controls. It does not cover traditional network security products (SASE, SD-WAN, secure web gateways operating at the network layer), standalone endpoint detection and response platforms, or broader governance/risk/compliance tools.
Feature Granularity Model
We compare products at what we call Level 2: The Functional Group: specific enough to be meaningful, broad enough to compare very different products fairly, without losing sight of how they’re meaningfully different.
Further questions
Why isn't a secure web gateway, CASB, or the browser's own built-in protection enough on its own?
Built-in browser protections, secure web gateways and CASBs are all built to catch known-bad sites and traffic in transit, not to see inside a session after a user has already authenticated. As this report's threat context shows, most initial access today arrives without malware at all, using stolen credentials and hijacked session tokens that those tools were never designed to catch, which is why a dedicated browser-layer control exists.
How is this different from a traditional secure web gateway (SWG)?
A traditional SWG sits at the network layer, routing traffic through a gateway to catch known-bad destinations, which leaves it blind to what happens inside an authenticated SaaS or GenAI session running in the tab. The platforms in this report operate at the browser and DNS layer instead, giving them visibility into that session activity a network-layer gateway cannot see, along with genuine Zero Trust Network Access rather than a bolt-on VPN replacement.
How were the 13 vendors in this report actually compared?
We normalised the market down to 40 scored features and assessed each vendor at what we call the Functional Group level: specific enough to be meaningful, broad enough to compare very different products fairly. See Feature Granularity Model above for how that scale works.
Two of these vendors have been acquired since publication. Does that change the findings?
Seraphic was acquired by CrowdStrike and is now sold as Falcon Seraphic Enterprise Browser. LayerX was acquired by Akamai and still sells under its own name. Both were assessed as standalone products and neither has been reassessed since. What changes is how you buy them, not what they were found to do. Where a product has been folded into a larger platform, check the packaging and commercial terms before comparing it against a standalone tool.
What happens if I want another vendor assessed?
Get in touch. This report focuses on solutions widely regarded as market leaders or strong emerging players, not every product on the market, and we are glad to look at ones we have not yet covered.
Disclaimers
All assessments reflect Tekspace’s independent professional judgement based on structured product research.
This report is intended as a decision-support tool and does not constitute professional advice. Organisations should conduct their own due diligence appropriate to their specific requirements, risk profile, and regulatory obligations.
If you believe any information in this report requires correction, or if you would like your product assessed for inclusion, contact Tekspace Research at hello@tekspace.com.au.
Contact our teamWe'll connect you with the right people
Vendors see your organisation's size and industry, never your name or contact details.
By making an enquiry you agree to Tekspace contacting you about it and sending related research. Unsubscribe any time. Privacy