{"type":"rich","version":"1.0","provider_name":"Transistor","provider_url":"https://transistor.fm","author_name":"The Professional CISO","title":"From GenAI Prompts to OAuth Phishing: The Hidden Browser Risks - with Tommy Perniciaro","html":"<iframe width=\"100%\" height=\"180\" frameborder=\"no\" scrolling=\"no\" seamless src=\"https://share.transistor.fm/e/26679914\"></iframe>","width":"100%","height":180,"duration":1220,"description":"Episode Summary\nRecorded live at HOU.SEC.CON, The Professional CISO Show welcomes Tommy Perniciaro, Director of Solutions Architecture at LayerX, to explore why the browser has become the least-instrumented layer in the modern security stack — and how CISOs can finally gain visibility and control over it.\n \nDavid and Tommy discuss everything from malicious browser extensions and OAuth-based phishing to AI prompt leakage and the emergence of “AI browsers.” Listeners will walk away with a new appreciation for the browser as the enforcement point of the future — and practical insights on deploying LayerX to close this growing gap.\n \nKey Takeaways\nThe browser is now a primary attack surface for enterprise users.\nLayerX gives security teams visibility and control without replacing browsers.\nGenAI tools and prompts can leak sensitive data if not monitored at the DOM level.\nOAuth-based phishing is bypassing traditional email and network defenses.\nSecure enterprise browsers struggle with user adoption — LayerX works inside the browsers you already have.\nAI browsers are emerging as the next battleground for identity and data protection.\nPost-quantum cryptography will further challenge network-layer inspection.\nNotable Quotes\n“The browser is where all the work is happening — SaaS, AI, identity — but it’s the least instrumented control plane we have.” – Tommy Perniciaro\n \n“Without visibility at the DOM level, you’re flying blind to what extensions, prompts, and identities are doing inside your environment.” – David Malicoat\n \n“Phishing doesn’t need your password anymore. OAuth grants and browser-based attacks are where it’s moving.” – Tommy Perniciaro\n \n“LayerX turns the browsers your people already use into secure browsers — no new deployment, no friction.” – David Malicoat\n \n“Post-quantum encryption will change inspection forever. The browser may become the new enforcement point.” – Tommy Perniciaro\n \nListener Benefits\nUnderstand why browser visibility is critical in...","thumbnail_url":"https://img.transistorcdn.com/ug-fdoDtb-XHe_KV42kTMgyIR-0A0-pVyy6kAU5aDd0/rs:fill:0:0:1/w:400/h:400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS83YTZi/YjBjZDcwZGU5Zjcz/M2E1ZWJkY2QxMTFk/MjkyZC5wbmc.webp","thumbnail_width":300,"thumbnail_height":300}