BSides Kerala 2026 Speakers

Kabilan Sakthivel

Security Researcher at Zscaler (squareX)

Speaker
Speaker Bio

Security Researcher at Zscaler (squareX)

Kabilan Sakthivel, a vulnerability researcher at Zscaler, focuses on discovering emerging browser attack surfaces, developing exploitation research, and strengthening the security of the browser and extension ecosystem through proactive threat analysis.

Talk at BSides Kerala 2026

Technical Talk

Breaking AI Browsers: Hidden APIs, Agentic Chaos, and the Race Toward Secure Architecture.

Hacker Ground Intermediate 30 Minutes

AI browsers have evolved from simple LLM sidebars into fully agentic, automation-driven environments but their security architecture has not always kept pace. This talk examines how emerging AI browsers weaken long-standing security guarantees through privileged extension surfaces, opaque capabilities, and loosely governed agent execution. We talk about how hidden/fake extensions can impersonate trusted UI components, and spoof AI panels to trigger OAuth compromise, phishing workflows, and persistent session hijacking with minimal permissions.

As browsers introduce autonomous agents that click, type, and authenticate on behalf of users, a deeper gap appears: there is no architectural distinction between human intent and agent execution. Enterprise controls and browser defenses cannot reliably differentiate the two. This enables prompt injection, workflow poisoning, and UI deception attacks that manipulate agents while appearing legitimate.

We also assess how vendors are making improvements to tackle the security issues highlighted by the security researchers.

The talk concludes with a roadmap for securing AI browsers: agent-identity separation, hardened permission boundaries, transparent extension ecosystems, and clear isolation between model, automation engine, and browser runtime.

Date
9 May 2026
Time
11:00 AM - 11:30 AM IST
Venue
Hacker Ground
Format
Technical Talk
BSides Kerala 2026