Sunkugari Tejeswara Reddy
Software Engineer at Zscaler
Specializing in browser security, cloud computing, and full-stack development. IIT Tirupati graduate passionate about building scalable, impactful software.

About Me
Specializing in browser security, cloud computing, and full-stack development. IIT Tirupati graduate passionate about building scalable, impactful software.
Education
Featured
ResearchBrowser Syncjacking: New Attack Technique
SquareX Discloses 'Browser Syncjacking' - a New Attack Technique that Provides Full Browser and Device Control Putting Millions at Risk.
Learn More
ConferenceBlackHat MEA 2025 Speaker
Had the opportunity to present SquareX at BlackHat Middle East & Africa, held in Riyadh, Saudi Arabia πΈπ¦
Learn More
LeadershipStudents' Placement Head at IIT Tirupati
My journey as the Students' Placement Head at Indian Institute of Technology, Tirupati (Career Development Centre - IIT Tirupati)
Learn More
ConferenceDEF CON 33 Demo Labs
Extension at DEF CON 33 Demo Labs: Copycat is a red team browser extension that simulates 10+ in-browser identity attacks.
Learn More
WorkshopNullcon Goa 2026 β Workshop Speaker
Inside the Browser β Exploiting, Detecting & Containing Malicious Extensions in Modern Web Ecosystems. A 2-hour hands-on workshop on browser extension attacks.
Learn MoreExperience

- Developed 'Dhrishti' mobile app using Flutter for patient care with full DevOps lifecycle.
- Configured iOS deployment using Xcode and published to App Store.
- Built REST APIs for patient registration system with efficient data management.

- Developed Department of Computer Science and Engineering website at IIT Tirupati.
- Ensured responsive design, functionality, and enhanced user experience.
- Collaborated with faculty for requirements and content integration.

- Built browser extension analysis pipeline with static scanning, sandboxing, and risk scoring for malicious extension detection.
- Discovered critical browser vulnerabilities including syncjacking, polymorphic extensions, and browser-native ransomware.
- Developed Data Splicing Attack PoC presented at BSidesSF and Identity Attack Simulator for DEF CON 33.

- Joined Zscaler following their acquisition of SquareX, continuing work on browser security and cloud infrastructure.
- Contributing to enterprise-scale security solutions and threat intelligence platforms.
- Working on integrating SquareX's browser security technology into Zscaler's product ecosystem.

- Developed 'Dhrishti' mobile app using Flutter for patient care with full DevOps lifecycle.
- Configured iOS deployment using Xcode and published to App Store.
- Built REST APIs for patient registration system with efficient data management.

- Developed Department of Computer Science and Engineering website at IIT Tirupati.
- Ensured responsive design, functionality, and enhanced user experience.
- Collaborated with faculty for requirements and content integration.

- Built browser extension analysis pipeline with static scanning, sandboxing, and risk scoring for malicious extension detection.
- Discovered critical browser vulnerabilities including syncjacking, polymorphic extensions, and browser-native ransomware.
- Developed Data Splicing Attack PoC presented at BSidesSF and Identity Attack Simulator for DEF CON 33.

- Joined Zscaler following their acquisition of SquareX, continuing work on browser security and cloud infrastructure.
- Contributing to enterprise-scale security solutions and threat intelligence platforms.
- Working on integrating SquareX's browser security technology into Zscaler's product ecosystem.
Featured Projects
Browser Extension Analysis
Distributed multi-layer browser extension analysis pipeline for detecting malicious extensions at scale. Integrates static scanning, dynamic sandboxing, and semantic analysis with multi-signal risk scoring.
- Designed distributed analysis pipeline with metadata intelligence, static scanning, and dynamic sandbox execution.
- Integrated Semgrep, RetireJS, and custom AST parsers to detect unsafe APIs and obfuscation patterns.
- Built Kubernetes-based cluster enabling horizontally scalable and fault-tolerant extension analysis.
Year of Browser Bugs (YOBB)
Research initiative uncovering critical browser vulnerabilities and emerging attack vectors. Developed PoC exploits for syncjacking, polymorphic extensions, and browser-native ransomware.
- Discovered and developed PoC exploits for browser syncjacking, polymorphic extensions, and native ransomware.
- Researched AI browser agent vulnerabilities revealing expanded attack surfaces through automation.
- Produced technical reports with exploitation methodology and defensive recommendations for vendors.
IdentityAttackSimulator
Chrome extension simulating 10 identity-based cyberattacks for security awareness and education. Demonstrates credential stuffing, phishing, cookie theft, and session hijacking scenarios.
- Developed Chrome extension simulating 10 identity attack scenarios including credential stuffing and session hijacking.
- Designed for red teaming, security training, and demonstrating identity theft risks.
- Selected for presentation at DEF CON 33 and BlackHat Middle East & Africa conferences.
Angry Magpie: DLP Bypass Toolkit
Open-source browser extension demonstrating Data Splicing Attacks bypassing enterprise DLP systems. Implements five attack vectors including data transcoding, sharding, and channel smuggling.
- Developed browser extension with five DLP bypass techniques: transcoding, sharding, and channel smuggling.
- Demonstrated architectural blind spots in proxy-based and endpoint DLP solutions.
- Presented at BSides San Francisco 2025 and published toolkit on GitHub for security testing.
Smooth Functional Actor-Critic (SFAC)
Reinforcement learning algorithm using smoothed gradient estimators for improved policy optimization. Achieved superior reward stability on Atari environments compared to standard Policy Gradient methods.
- Developed SFAC algorithm with smoothed gradient estimators using randomized perturbations.
- Trained agents on Atari environments achieving superior reward stability versus Policy Gradient.
- Designed adaptive Ξ²-annealing strategy dynamically tuning smoothing based on reward trends.
CommuniConnect
Full-stack MERN web application for community engagement within geographical areas. Features interactive maps, real-time chat, posts, polls, and AI chatbot integration.
- Built full-stack platform with interactive maps, real-time chat, and weekly analytics using MERN stack.
- Integrated AI chatbot and polling features to enhance community interaction and engagement.
- Developed companion mobile application with React3fiber for 3D map visualizations.
SmellSweep
Data quality tool detecting 26 prevalent data smells affecting dataset integrity and usability. Provides visualization with interactive charts and histograms for identified anomalies.
- Developed tool detecting 26 common data smells affecting data integrity across datasets.
- Implemented interactive visualization with charts and histograms for anomaly analysis.
- Built full-stack application using Python Flask backend and React frontend interface.
ThreatDetector
Static analysis tool detecting OWASP-defined vulnerabilities in PHP codebases. Features visual comparison dashboard with interactive graphs showing vulnerability distribution.
- Built static analysis tool identifying standard OWASP vulnerabilities in PHP applications.
- Implemented visual dashboard with interactive graphs for vulnerability comparison and analysis.
- Won Bronze Medal among all IITs at Inter IIT TechMeet 12.0 cybersecurity competition.
Dhrishti
Healthcare mobile app for patient care with EMR integration and real-time appointment tracking. Features family profile management, medical report viewing, and prescription notifications.
- Built patient care app with EMR integration for real-time appointment and medical data tracking.
- Implemented family profile management, self-declarations, and automated prescription reminders.
- Published updated version on both App Store and Google Play Store using Flutter.
Achievements

BlackHat Middle East & Africa
Selected to present original offensive security research: Identity Attack Simulator (identity attack simulation extension) and Angry Magpie (DLP bypass tool) at BlackHat MEA 2025.

Bronze Medal - Inter IIT TechMeet 12.0
Achieved 3rd Position among all other IITs in Inter IIT Techmeet 12.0 and won Bronze Medal in low-cert cybersecurity problem statement given by CERT-IN Organization held at IIT Madras.

Academic Excellence
Secured Department Rank 1 in first year at IIT Tirupati, leading to branch change to Computer Science and Engineering. Also ranked in Top 1% in JEE Advanced, Top 1.7% in JEE Mains (among 1M+ candidates).

Leadership
Honored with a recognition award from Dr. Satyanarayana, Director of IIT Tirupati, for spearheading the institution's Placement Season 2024β25 and representing 450+ graduating students.
Leadership
Students' Placement Head
- Represented 450+ Students from the 2025 Graduating Batch as a Placement Coordinator, involved in resolving Students queries in all the Placement Processes
- Led a team of 30 Placement Representatives ensuring smooth communication between Students and the placement officers

Department of Computer Science and Engineering - Representative
- Acted as a bridge between faculty and students, communicating academic concerns, suggestions, and facilitating effective dialogue to improve the academic environment.
- Coordinated with faculty to address student issues related to curriculum, exam schedules, and other academic matters, ensuring timely resolution.
- Involved in Class Committee Meetings with the Head Of Dept. and CSE Faculty discussing about Academic Related Things