Connect with us

Technology

SquareX Discovers New Cybersecurity Attacks that Completely Bypass Secure Web Gateways (SWG), Leaving Most Enterprises Vulnerable.

Published

on

SINGAPORE, Aug. 6, 2024 /PRNewswire/ — SquareX Founder, Vivek Ramachandran, cybersecurity veteran with over 20 years of experience and founder/ex-CEO of Pentester Academy (acquired by INE), together with the security research team, will be delivering their latest findings in an upcoming main stage talk, titled Breaking Secure Web Gateways (SWG) for Fun and Profit! at DEF CON 32 on Friday, August 9, 2024 at 5pm PT.

The talk will unveil “Last Mile Reassembly Attacks”, a new class of attacks that completely evade Secure Web Gateways (SWGs), a crucial component of modern Secure Access Service Edge (SASE) and Security Service Edge (SSE) solutions.

The web browser is the most used application within the enterprise but also the least protected. Bad actors are now increasingly targeting the weakest link: employees and consultants.

Unfortunately, most of these attacks happen online when the employee or consultant is going about his daily work. Existing security solutions like SWGs as part of SASE/SSE solutions are unable to protect users against modern web threats that happen on the client side. This makes it currently impossible for enterprise security teams to detect, mitigate and threat hunt these attacks.

Vivek Ramachandran and the SquareX team have conceptualized and identified a new class of attacks against SWG and cloud-based intercepting proxies, converting traditional attacks like malware downloads and malicious websites into something undetectable by all existing vendors in the Gartner Magic Quadrant.

This class of attack is called “Last Mile Reassembly Attacks”. The vulnerabilities the team discovered are architectural and vendor-agnostic, meaning there is no specific way to fix them.

These attacks will have a massive impact on SASE, as it is a $40 billion market, and every large security vendor has an SWG product vulnerable to this new class of attacks. This is an industry-first research highlighting attacks that we suspect may have been circulating in the wild for some time. As these client-side attacks are fundamentally different in nature to the attacks that SWGs typically detect, they have remained unnoticed. Upon revealing these attacks and the release of the accompanying toolkit, enterprise vendors can assess their security posture and build countermeasures.

During the main stage talk, Vivek will shed light on this “Last Mile Reassembly Attacks” – where a file download, upload or site rendering never actually happens on the server side. Instead, the attack is assembled directly in the user’s browser using various techniques, which will be explained in detail during the talk. This way, malicious files can evade triggering SWGs, leaving many enterprises across the globe vulnerable to being attacked.

Researchers at SquareX will also demonstrate over 25 plus bypass methods-, including chunking attacks, WASM payloads, and others.

“The research team and I are excited to be presenting the talk at DEF CON 32. This talk will challenge SASE, SSE vendors in the current space. We hope that vendors will rethink their reliance on cloud-based web attack detection models and understand the need for a client-side (either endpoint or browser-based) security agent and browser-hardening to work in tandem with the SWG for accurate detection-mitigation of attacks,” says Vivek Ramachandran, Founder & CEO of SquareX.

Web attacks have far advanced and evolved in today’s world and if enterprises do not change the way they protect their users, they will essentially be vulnerable to these web threats and attacks. SquareX is dedicated to enhancing online security for enterprises. By bringing these vulnerabilities to light and advocating for a more comprehensive approach to browser security, the team’s research serves as a critical alert to the cybersecurity community.

The revealing of “Last Mile Reassembly Attacks” and the release of the accompanying toolkit are poised to challenge the way enterprise security teams think and will prompt enterprises to reassess their methods for protecting employees from browser-based attacks.

About SquareX:
SquareX helps organizations detect, mitigate and threat-hunt web attacks happening against their users in real time. With our innovative browser-native security product, SquareX safeguards enterprise users from a spectrum of web-based threats, encompassing malicious files, websites, scripts, and compromised networks.

About Vivek Ramachandran:
Vivek Ramachandran is a security researcher, book author, speaker-trainer, and serial entrepreneur with over two decades of experience in offensive cybersecurity. He is currently the founder of SquareX, building a browser-native security product focused on detecting, mitigating, and threat-hunting web attacks against enterprise users and consumers. Prior to that, he was the founder of Pentester Academy (acquired in 2021), which has trained thousands of customers from government agencies, Fortune 500 companies, and enterprises from over 140+ countries. Before that, Vivek’s company built an 802.11ac monitoring product sold exclusively to defense agencies.

Vivek discovered the Caffe Latte attack, broke WEP Cloaking, conceptualized enterprise Wi-Fi Backdoors, and created Chellam (Wi-Fi Firewall), WiMonitor Enterprise (802.11ac monitoring), Chigula (Wi-Fi traffic analysis via SQL), Deceptacon (IoT Honeypots), among others. He is the author of multiple five-star-rated books in offensive cybersecurity, which have sold thousands of copies worldwide and have been translated into multiple languages.

He has been a speaker/trainer at top security conferences such as Blackhat USA, Europe and Abu Dhabi, DEFCON, Nullcon, Brucon, HITB, Hacktivity, and others. Vivek’s work in cybersecurity has been covered in Forbes, TechCrunch, and other popular media outlets.

In a past life, he was one of the programmers of the 802.1x protocol and Port Security in Cisco’s 6500 Catalyst series of switches. He was also one of the winners of the Microsoft Security Shootout contest held in India among a reported 65,000 participants. He has also published multiple research papers in the field of DDoS, ARP Spoofing Detection, and Anomaly-based Intrusion Detection Systems. In 2021, he was awarded an honorary title of Regional Director of Cybersecurity by Microsoft for a period of three years, and in 2024 he joined the BlackHat Arsenal Review Board.
 

View original content to download multimedia:https://www.prnewswire.com/news-releases/squarex-discovers-new-cybersecurity-attacks-that-completely-bypass-secure-web-gateways-swg-leaving-most-enterprises-vulnerable-302214112.html

SOURCE SquareX

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Technology

Students to Develop Urban Mobility Solutions Using AI

Published

on

By

In Otis’ Made to Move Communities™ global competition, students will apply Artificial Intelligence to enable more inclusive and sustainable mobility solutions.A student team from the Hong Kong Baptist University Affiliated School Wong Kam Fai Secondary and Primary School is representing Hong Kong in this competition

HONG KONG, Nov. 13, 2024 /PRNewswire/ — Artificial Intelligence is revolutionizing the speed, accuracy and scale at which complex challenges are addressed. Over the next several months, more than 250 students from dozens of schools representing more than 15 countries and territories around the world will participate in the Made to Move Communities challenge to propose innovative ways AI can improve urban mobility. They’ll be guided by volunteer mentors from Otis (NYSE: OTIS), the world’s leading elevator and escalator manufacturing, installation and service company.

“We believe that the next generation of innovation will use AI to make moving in and around cities easier and more efficient for all,” said Randi Tanguay, Otis Senior Vice President & Chief Communications Officer. “Today’s students are growing up as AI technology matures. They are actively engaged and quickly developing the skills to effectively use and apply it. With their innate curiosity and imagination, combined with the guidance of expert Otis volunteer mentors, I can’t wait to see the solutions these students come up with.”

Why AI

According to the World Bank, more than 56% of the world population currently lives in cities, and that number is expected to grow to nearly 70% by 2050. The current pace of rapid urbanization and global population growth has the potential to strain urban infrastructure, resulting in increased congestion, pollution, and inadequate public transit. These challenges can be even more acute in underserved neighborhoods and for people with special needs.

“AI is already reshaping transportation. It’s enabling self-driving cars, optimizing traffic flows, and even helping drones deliver packages and medicines to those in need,” said Ezhil Nanjappan, Otis Senior Vice President and Chief Technology Officer. “As we stand on the brink of the AI revolution, I’m excited to bring this transformational technology to the Made to Move Communities program – to brainstorm solutions to the mobility issues of today and tomorrow, while inspiring young minds and helping to close the STEM skills gap.”

For the first time – a global winner

Since 2020, Otis’ annual Made to Move Communities global student competition has engaged over 750 students and hundreds of Otis colleagues with the goal of addressing urban mobility challenges while sparking a lifelong interest in STEM. Participating schools have received nearly $1 million (USD) in grants from Otis to further STEM learning and programs in their schools.

Until now, students used to compete regionally, with a winning team selected in each of the four Otis regions. This year, for the first time, the four regional winning teams will compete in a final round to determine a global team champion. Student teams will need to share how their solutions to local challenges can be scaled globally, and the global team champion will receive an additional grant for their school.

Seven students from the Hong Kong Baptist University Affiliated School Wong Kam Fai Secondary and Primary School will take part. This is the second time the school will represent Hong Kong. “We are pleased to once again have the opportunity to represent Hong Kong in the competition. This platform allows our students to harness the power of Artificial Intelligence to tackle real-world urban mobility challenges. We are eager to see how their innovative ideas will transform into practical solutions and showcase their talents on a global stage.” Said by Ms. Jacqui KOO, Acting Deputy Principal cum Director of International Division, Hong Kong Baptist University Affiliated School Wong Kam Fai Secondary and Primary School.

Watch this video to learn more about Made to Move Communities and this year’s challenge: https://youtu.be/c1FwYeGhLp4

Visit otis.com/mtmc to learn more and follow Otis for updates from participating student teams.

About Otis

Otis gives people freedom to connect and thrive in a taller, faster, smarter world. The global leader in the manufacture, installation and servicing of elevators and escalators, we move 2.3 billion people a day and maintain approximately 2.3 million customer units worldwide – the industry’s largest Service portfolio. You’ll find us in the world’s most iconic structures, as well as residential and commercial buildings, transportation hubs and everywhere people are on the move. Headquartered in Connecticut, USA, Otis is 71,000 people strong, including 42,000 field professionals, all committed to meeting the diverse needs of our customers and passengers in more than 200 countries and territories. To learn more, visit www.otis.com and follow us on LinkedIn, Instagram and Facebook @OtisElevatorCo.

Media Enquiries: 

Michelle Mak
michelle.mak@otis.com  
852-9865 5331

 

View original content to download multimedia:https://www.prnewswire.com/apac/news-releases/students-to-develop-urban-mobility-solutions-using-ai-302303880.html

SOURCE Otis Elevator Company (H.K.) Limited

Continue Reading

Technology

New order for Alfa Laval to unlock potential of biofuels in aviation

Published

on

By

LUND, Sweden, Nov. 13, 2024 /PRNewswire/ — Driving the global energy transition towards biofuels, Alfa Laval has secured two contracts worth 350 million SEK to supply cutting-edge HVO pre-treatment technology to Europe’s largest biofuel facility. The facility, a joint venture between Cepsa Bioenergia San Roque S.L. (CSBR), and Bio-Oils Energy, part of the Apical Group, will produce 500,000 tonnes of sustainable aviation fuel (SAF) and renewable diesel annually, addressing the growing demand for cleaner, renewable energy sources.

Biofuels are crucial in the decarbonization of our societies, providing a low-carbon solution for existing technologies. In the transportation sector, they play a significant role in the shift towards net-zero emissions. However, the current demand for biofuels far exceeds the available supply, highlighting the need for increased production and innovation to meet this growing need.

“The biggest challenge in the biofuel industry is to triple the capacity by 2030. The volume increase is essential, and we are excited for Alfa Laval to play an important role in this transition,” says Sammy Hulpiau, President, Food & Water Division. “The trust placed in us by CBSR ensures that Alfa Laval significantly contributes to the necessary increase of biofuels in aviation, and the transformation of the entire industry.”

Alfa Laval’s Food & Water Division will supply two different pre-treatment units to CBSR’s 1.2-billion-euro project. The construction of the plant is an important step on the journey towards decarbonizing the global transportation sector and will double CBSR’s total renewable fuels production capacity to one million tonnes a year. The plant is designed to emit 75 percent less CO2 than a traditional biofuel plant.

The facility, planned to be up and running during 2026, is currently under construction in Huelva, Spain.

Did you know… that road travel, flights, and shipping account for nearly a quarter of the world’s greenhouse gas emissions? Biofuels offer a promising solution to keeping transportation efficient while reducing emissions.

CONTACTS
Johan Lundin
Head of Investor Relations, Alfa Laval
Mobile: +46 730 46 30 90
johan.lundin@alfalaval.com

Anna Droben
Head of External Communications, Alfa Laval
Mobile: +46 730899621
anna.droben@alfalaval.com

This is Alfa Laval   

The ability to make the most of what we have is more important than ever. Together with our customers, we’re innovating the industries that society depends on and creating lasting positive impact. Alfa Laval is a leading global provider of first-rate products in the areas of heat transfer, separation and fluid handling. We’re set on helping billions of people to get the energy, food, and clean water they need.  And, at the same time, we’re decarbonizing the marine fleet that’s the backbone of global trade.

We pioneer technologies and solutions that  free our customers to unlock the true potential of resources. As our customers’ businesses grow stronger, the goal of a truly sustainable world edges closer. The company is committed to optimizing processes, creating responsible growth, and driving progress to support customers in achieving their business goals and sustainability targets. Together, we’re pioneering positive impact.

Alfa Laval was founded 140 years ago, has customers in some 100 countries, employs more than 22,000 people, and annual sales were SEK 63.6 billion (5.5 BEUR) in 2023. The company is listed on Nasdaq Stockholm. 

www.alfalaval.com

This information was brought to you by Cision http://news.cision.com.

https://news.cision.com/alfa-laval/r/new-order-for-alfa-laval-to-unlock-potential-of-biofuels-in-aviation,c4065660

The following files are available for download:

https://mb.cision.com/Public/905/4065660/ac1f7576cdec81f2.pdf

New order for Alfa Laval to unlock potential of biofuels in aviation Alfa Laval press release 20241113

https://news.cision.com/alfa-laval/i/alfa-laval-biofuel-order-cepsa-2024-airplane-fuel,c3351404

Alfa Laval Biofuel order Cepsa 2024 Airplane fuel

 

View original content:https://www.prnewswire.com/news-releases/new-order-for-alfa-laval-to-unlock-potential-of-biofuels-in-aviation-302303881.html

SOURCE Alfa Laval

Continue Reading

Technology

Teleperformance named among top 15 Best Companies to Work For™ in Europe

Published

on

By

BRISTOL, England, Nov. 13, 2024 /PRNewswire/ — Fortune and Great Place To Work® have ranked global business services leader Teleperformance (TP) among the top 100 Best Companies to Work For™ in Europe for the second consecutive year, ranking 12th among multinational companies. TP is the only company in the customer experience management industry to rank within the top 25 Best Companies to Work For™ in Europe.

In particular, TP’s operations in thee United Kingdom have been named to the list, which recognises the best companies to work for in Europe on an annual basis.

Companies on the 100 Best Companies to Work For™ list dramatically outperform the typical workplace in Europe by creating consistently great work experiences, according to Great Place to Work®. Earning a spot on the list is an indicator of high levels of trust across the organisation, with more employees from companies on the list reporting a consistently positive experience at work.

“Our people are at the heart of everything we do at TP,” said Alan Winters, TP Chief People Officer. “With a large diverse workforce, we hire and train for emotional intelligence and help employees grow to their full potential by sharing, listening and innovating – and a common thread through all of this is trust. We are encouraged and humbled by this feedback from our people across Europe who rated us so highly as a great employer. As the global leader in our industry, our goal is to continually be a great place to work in Europe and everywhere we operate.”

TP’s ranking on the Fortune 100 Best Companies to Work For™ in Europe 2024 list is based on an analysis of confidential survey responses from TP employees across Europe compared to confidential employee survey responses from employees in the region. TP employees overwhelmingly reported being treated fairly, regardless of their social and socio-economic status, gender, race or sexual orientation, and that TP provided a safe place to work.

Earlier this year TP received Great Place to Work® certifications in 69 countries, including 26 countries in Europe. Today, 97% of TP employees work in a Great Place to Work®-certified location1.

Great Place to Work® is the global authority on workplace culture and employee experience. Its annual certification program is based on a rigorous methodology and independent employee feedback. 

Visit the group at www.teleperformance.com.

Logo – https://mma.prnewswire.com/media/2555852/Teleperformance_Logo.jpg

View original content to download multimedia:https://www.prnewswire.co.uk/news-releases/teleperformance-named-among-top-15-best-companies-to-work-for-in-europe-302303349.html

Continue Reading

Trending