Author profile
Ameya Lambat
Security Research Contributor, Legba
Ameya Lambat contributes research-backed writing on browser threats, AI misuse patterns, and practical controls that reduce exposure in web workflows.
Published articles
Browser isolation for law firms
Shield moves page execution off-device. See how that fits law-firm work. Review remaining risks, provider access, and retention.
Security Research · 2026-09-03
Browser isolation for AI agents: why the old playbook fits the new problem
Browser isolation was built for human browsing. AI agents need a different delivery model that isolates browser execution, task identity, and session lifetime.
Security Research · 2026-09-01
The EU AI Act gets teeth. What browser-agent teams need
The EU AI Act reaches its next major application date on August 2, 2026. Review what browser-agent teams should inventory, minimize, isolate, log, and prove.
Security Research · 2026-09-01
What is browser fingerprinting? How tracking persists
Browser fingerprinting identifies devices through hardware and software signals. See what forms a fingerprint and why no single control erases every signal.
Security Research · 2026-09-01
What is shadow AI? Why the browser tab matters
Employees can expose company data through unsanctioned AI tools. This guide explains the risks and the limited role of browser isolation.
Security Research · 2026-09-01
Browser Isolation vs Incognito Mode vs Private Browsing: What's Actually Private?
Compare incognito mode, private browsing, and remote browser isolation across local cleanup, execution, routing, tracking, and phishing limits.
Security Research · 2026-09-01
VPN vs proxy vs browser isolation: How to choose
VPNs route device traffic. Proxies route selected app traffic. Browser isolation changes where web content runs. Compare scope, encryption, and fit.
Security Research · 2026-09-01
Why privacy in crypto wallets matters in 2026
A crypto wallet touches public ledgers, RPC providers, browser surfaces, and identity checkpoints. Learn what each layer can reveal and how to assess privacy claims.
Privacy Engineering · 2026-09-01
Your Encrypted AI Conversations Aren't as Private as You Think: Inside the Whisper Leak Attack
Microsoft researchers reveal Whisper Leak, a side-channel attack identifying AI chatbot conversations with 99.9% accuracy despite encryption.
Security Research · 2026-09-01
Your Data Is Already Out There: Why Even Security Experts Aren't Safe
24 billion credentials are circulating on the dark web. Learn how exposure happens and where isolated page execution changes the risk.
Security Research · 2026-09-01
The cookie conspiracy: how websites track you and what isolation changes
The truth about cookie tracking, price discrimination myths, and how isolated browser state changes cross-session tracking.
Privacy Engineering · 2026-09-01
How Legba browser isolation works
Shield runs the page in an isolated browser. That browser is off your device. See what happens when you open the tab. See what ends when you close it.
Security Research · 2026-09-01
What is remote browser isolation (RBI)?
Remote browser isolation runs websites away from your device. Your browser receives rendered output. See RBI delivery models, benefits, and limits.
Security Research · 2026-08-27
The VPN Ban Is Coming: Here's What You Stand to Lose
1.8 billion people rely on VPNs daily. Now governments want them gone. Here's what that means for your streaming, travel, privacy, and freedom.
Privacy Engineering · 2026-07-24
Stop Using Incognito Mode for Security. It Doesn't Work.
Incognito mode doesn't protect you from malware, phishing, or tracking. Here's what it actually does, and what you need instead for real browser security.
Security Research · 2026-07-24
Exposed Secrets in the AI Era: .env Files, Hardcoded Keys, and the Breaches That Follow
A field guide to how API keys and credentials leak through .env files and frontend code, the validated breaches that followed, and how to find your own exposed secrets before an attacker does.
Security Research · 2026-05-28
External Attack Surface Management (EASM) in 2026: The Complete Methodology
A practitioner's guide to External Attack Surface Management: what it is, the full discovery-to-validation lifecycle, and why a confirmed exposure beats a thousand scanner alerts.
Security Research · 2026-05-28
From Scanner Noise to Validated Findings: Killing False Positives in External Recon
Why external attack surface scanners over-report, the real operational cost of false positives, and a repeatable discipline for validating findings before they reach a remediation queue.
Security Research · 2026-05-28
The Vibe-Coding Security Crisis: How AI-Generated Apps Ship Critical Vulnerabilities
A balanced, evidence-led look at why AI-generated applications keep shipping critical exposures, anchored to the documented Lovable RLS incident (CVE-2025-48757), and how attack surface monitoring catches these flaws before attackers do.
Security Research · 2026-05-28