Connect with us

Technology

SquareX Discovers New Cybersecurity Attacks that Completely Bypass Secure Web Gateways (SWG), Leaving Most Enterprises Vulnerable.

Published

on

SINGAPORE, Aug. 6, 2024 /PRNewswire/ — SquareX Founder, Vivek Ramachandran, cybersecurity veteran with over 20 years of experience and founder/ex-CEO of Pentester Academy (acquired by INE), together with the security research team, will be delivering their latest findings in an upcoming main stage talk, titled Breaking Secure Web Gateways (SWG) for Fun and Profit! at DEF CON 32 on Friday, August 9, 2024 at 5pm PT.

The talk will unveil “Last Mile Reassembly Attacks”, a new class of attacks that completely evade Secure Web Gateways (SWGs), a crucial component of modern Secure Access Service Edge (SASE) and Security Service Edge (SSE) solutions.

The web browser is the most used application within the enterprise but also the least protected. Bad actors are now increasingly targeting the weakest link: employees and consultants.

Unfortunately, most of these attacks happen online when the employee or consultant is going about his daily work. Existing security solutions like SWGs as part of SASE/SSE solutions are unable to protect users against modern web threats that happen on the client side. This makes it currently impossible for enterprise security teams to detect, mitigate and threat hunt these attacks.

Vivek Ramachandran and the SquareX team have conceptualized and identified a new class of attacks against SWG and cloud-based intercepting proxies, converting traditional attacks like malware downloads and malicious websites into something undetectable by all existing vendors in the Gartner Magic Quadrant.

This class of attack is called “Last Mile Reassembly Attacks”. The vulnerabilities the team discovered are architectural and vendor-agnostic, meaning there is no specific way to fix them.

These attacks will have a massive impact on SASE, as it is a $40 billion market, and every large security vendor has an SWG product vulnerable to this new class of attacks. This is an industry-first research highlighting attacks that we suspect may have been circulating in the wild for some time. As these client-side attacks are fundamentally different in nature to the attacks that SWGs typically detect, they have remained unnoticed. Upon revealing these attacks and the release of the accompanying toolkit, enterprise vendors can assess their security posture and build countermeasures.

During the main stage talk, Vivek will shed light on this “Last Mile Reassembly Attacks” – where a file download, upload or site rendering never actually happens on the server side. Instead, the attack is assembled directly in the user’s browser using various techniques, which will be explained in detail during the talk. This way, malicious files can evade triggering SWGs, leaving many enterprises across the globe vulnerable to being attacked.

Researchers at SquareX will also demonstrate over 25 plus bypass methods-, including chunking attacks, WASM payloads, and others.

“The research team and I are excited to be presenting the talk at DEF CON 32. This talk will challenge SASE, SSE vendors in the current space. We hope that vendors will rethink their reliance on cloud-based web attack detection models and understand the need for a client-side (either endpoint or browser-based) security agent and browser-hardening to work in tandem with the SWG for accurate detection-mitigation of attacks,” says Vivek Ramachandran, Founder & CEO of SquareX.

Web attacks have far advanced and evolved in today’s world and if enterprises do not change the way they protect their users, they will essentially be vulnerable to these web threats and attacks. SquareX is dedicated to enhancing online security for enterprises. By bringing these vulnerabilities to light and advocating for a more comprehensive approach to browser security, the team’s research serves as a critical alert to the cybersecurity community.

The revealing of “Last Mile Reassembly Attacks” and the release of the accompanying toolkit are poised to challenge the way enterprise security teams think and will prompt enterprises to reassess their methods for protecting employees from browser-based attacks.

About SquareX:
SquareX helps organizations detect, mitigate and threat-hunt web attacks happening against their users in real time. With our innovative browser-native security product, SquareX safeguards enterprise users from a spectrum of web-based threats, encompassing malicious files, websites, scripts, and compromised networks.

About Vivek Ramachandran:
Vivek Ramachandran is a security researcher, book author, speaker-trainer, and serial entrepreneur with over two decades of experience in offensive cybersecurity. He is currently the founder of SquareX, building a browser-native security product focused on detecting, mitigating, and threat-hunting web attacks against enterprise users and consumers. Prior to that, he was the founder of Pentester Academy (acquired in 2021), which has trained thousands of customers from government agencies, Fortune 500 companies, and enterprises from over 140+ countries. Before that, Vivek’s company built an 802.11ac monitoring product sold exclusively to defense agencies.

Vivek discovered the Caffe Latte attack, broke WEP Cloaking, conceptualized enterprise Wi-Fi Backdoors, and created Chellam (Wi-Fi Firewall), WiMonitor Enterprise (802.11ac monitoring), Chigula (Wi-Fi traffic analysis via SQL), Deceptacon (IoT Honeypots), among others. He is the author of multiple five-star-rated books in offensive cybersecurity, which have sold thousands of copies worldwide and have been translated into multiple languages.

He has been a speaker/trainer at top security conferences such as Blackhat USA, Europe and Abu Dhabi, DEFCON, Nullcon, Brucon, HITB, Hacktivity, and others. Vivek’s work in cybersecurity has been covered in Forbes, TechCrunch, and other popular media outlets.

In a past life, he was one of the programmers of the 802.1x protocol and Port Security in Cisco’s 6500 Catalyst series of switches. He was also one of the winners of the Microsoft Security Shootout contest held in India among a reported 65,000 participants. He has also published multiple research papers in the field of DDoS, ARP Spoofing Detection, and Anomaly-based Intrusion Detection Systems. In 2021, he was awarded an honorary title of Regional Director of Cybersecurity by Microsoft for a period of three years, and in 2024 he joined the BlackHat Arsenal Review Board.
 

View original content to download multimedia:https://www.prnewswire.com/news-releases/squarex-discovers-new-cybersecurity-attacks-that-completely-bypass-secure-web-gateways-swg-leaving-most-enterprises-vulnerable-302214112.html

SOURCE SquareX

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Technology

Financial Crime Compliance Expert Tracy Angulo Joins Treliant as Managing Director for Financial Crimes and Fraud Solutions

Published

on

By

WASHINGTON, Jan. 8, 2025 /PRNewswire/ — Treliant, an essential consulting partner to the global financial services industry, has named Tracy Angulo as Managing Director with the firm’s Financial Crimes and Fraud Solutions team. Her appointment reflects Treliant’s commitment to helping financial institutions, fintechs, and cryptocurrency businesses prevent money laundering and terrorist financing, establish risk resilience in their programs and preserve operational efficiency.

Tracy has over 20 years’ experience in financial crime compliance, most recently as a Director at Guidehouse Inc. There, she served in critical roles guiding clients in building and enhancing their Bank Secrecy Act/Anti-Money Laundering (BSA/AML) obligations. She has also served as the Acting Global KYC/Customer Onboarding Director for a top cryptocurrency exchange, the Acting Deputy BSA/AML Officer for a U.S. based fintech, and Acting Manager of the financial intelligence unit for a large trust company and broker-dealer. Tracy also was a Principal Attorney Investigator with the Financial Industry Regulatory Authority (FINRA) where she led complex financial crime investigations into AML violations, securities fraud, Ponzi schemes, insider trading, market manipulation, and fraudulent securities offerings.

“Our clients are under relentless pressure to stay ahead of evolving financial crimes, with bad actors continuously targeting financial institutions, fintechs, and digital asset companies,” said John Arvanitis, Senior Managing Director, Financial Crimes and Fraud Solutions. “Tracy’s unmatched expertise—combining frontline experience, advisory insight, and a regulator’s precision—equips our clients to tackle threats head-on and protect their enterprises with confidence.”

“Our industry is at a turning point, with financial crimes growing in scale and sophistication, putting businesses and their reputations at greater risk,” said Tracy. “My focus is on helping our clients build resilient, future-ready programs that not only meet regulatory expectations but also instill trust and confidence in their stakeholders. By leveraging deep industry knowledge and a proactive approach, we can equip organizations to stay ahead of threats and succeed in an increasingly complex landscape.”

About Treliant

Treliant is an essential consulting firm serving banks, fintechs, mortgage originators, and servicers, and other companies providing financial services globally. We are led by practitioners from the industry and the regulatory community who bring deep domain knowledge to help our clients drive business change and address the most pressing compliance, regulatory, and operational challenges.

We provide data-driven, technology-enabled consulting, implementation, staffing, and managed services solutions to the financial crimes, regulatory compliance, risk, credit, and capital markets functions of our clients.

Founded in 2005, Treliant is headquartered in Washington, DC, with offices across the United States, Europe, and Asia. To learn more visit www.treliant.com.

View original content to download multimedia:https://www.prnewswire.com/news-releases/financial-crime-compliance-expert-tracy-angulo-joins-treliant-as-managing-director-for-financial-crimes-and-fraud-solutions-302346185.html

SOURCE Treliant

Continue Reading

Technology

Duda Among the 100 Best Startups and Tech Companies to Work For in the U.S.

Published

on

By

The web building platform for digital agencies, SaaS platforms, and web professionals was recognized by Built In’s 2025 Best Places to Work Awards.

BOULDER, Colo., Jan. 8, 2025 /PRNewswire/ — Built In today announced that Duda, the leading white label website building platform for agencies and web professionals serving small and medium-sized businesses (SMBs), was honored in its 2025 Best Places To Work Awards. Duda earned a place on the following lists:

100 Best U.S. Companies to Work For in 2025100 Best U.S. Midsize Companies to Work For in 2025100 Best Places to Work in Colorado in 2025100 Best Midsize Places to Work in Colorado in 2025

The annual awards program includes companies of all sizes, from startups to those in the enterprise, and honors both remote-first employers as well as companies in large tech markets across the U.S.

“We’re thrilled to be named one of the best places to work in the U.S. by Built In,” says Itai Sadan, co-founder and CEO of Duda. “By promoting company values such as openness, care and growth, and providing employees with opportunities to work on cutting-edge innovation, including AI for digital web presence generation, we cultivate a strong work culture and environment where employees feel constantly challenged, inspired, and able to grow their careers.”

Built In determines the winners of Best Places to Work based on an algorithm, using company data about compensation and benefits. To reflect the benefits candidates are searching for more frequently on Built In, the program also weighs criteria like remote and flexible work opportunities, programs for DEI and other people-first cultural offerings. 

As a global company with teams in the U.S., Israel, Canada, UK, Brazil, and the Philippines, Duda strives to provide an encouraging, collaborative, and fulfilling culture for all team members. Employees thrive in a hybrid environment that combines remote and on-site work and promotes connection, teamwork, and personal growth. “At Duda, our team members are empowered to make a meaningful impact by working closely with customers, solving complex challenges, and driving innovation. This meaningful work, coupled with our commitment to career development, enables our people to excel while maintaining a healthy work-life balance and overall wellbeing,” says Steven Carroll, VP of People & Talent at Duda.

“Being recognized as a Best Place to Work is a testament to these companies’ commitment to building a workplace where individuals and innovation thrive,” says Built In CEO and Founder, Maria Christopoulos Katris. “At Built In, we understand that great companies are powered by great teams, and this achievement showcases their dedication to fostering a culture of growth, inclusivity, and excellence. Congratulations on this well-deserved honor.”

About Duda   
Duda is a leading white label web building platform for digital agencies, SaaS platforms, and web professionals offering web design services to SMBs. From its industry-leading AI Assistant to advanced API-driven automation workflows, Duda offers web professionals a comprehensive suite of tools to build pixel-perfect, feature-rich websites efficiently and at scale–all on a flexible platform that can be fully customized to match their go-to-market strategy and ideal customer experience. As the top platform for Core Web Vitals, a critical metric for SEO performance, Duda makes it easy for web professionals to deliver a superior digital presence and outstanding performance to their customers under their own brand. More than 20,000 organizations have trusted Duda to build 1 million active websites. For more information, visit www.duda.co.

About Built In   
Built In is the “always on” recruiting platform that reaches the tech professionals that other leading recruiting platforms don’t. Designed to help companies hire expert tech talent, Built In continuously drives brand awareness with content. Monthly, millions of the industry’s most in-demand global tech professionals visit our site to stay ahead of tech trends and news, learn skills to accelerate their careers, find the right job opportunities and get hired. Thousands of companies, from fast-growing startups to the largest enterprises rely on Built In. By putting their stories in front of our uniquely engaged audience, we help them hire otherwise hard-to-reach technical and expert talent. www.builtin.com

About Built In’s Best Places to Work   
Built In’s annual Best Places to Work program honors companies with the best total rewards packages across the U.S. and in the following tech hubs: Atlanta, Austin, Boston, Chicago, Colorado, Dallas, Houston, Los Angeles, Miami, New York, San Diego, San Francisco, Seattle and Washington DC. Best Places to Work is distinct because its algorithm selects tech companies that build their offerings specifically around what tech professionals value in a workplace. https://employers.builtin.com/best-places-to-work

View original content to download multimedia:https://www.prnewswire.com/news-releases/duda-among-the-100-best-startups-and-tech-companies-to-work-for-in-the-us-302346192.html

SOURCE Duda

Continue Reading

Technology

AIMA Unveils Game-Changing 2025 eBike Lineup at CES: Better Performance, More Freedom

Published

on

By

LAS VEGAS, Jan. 8, 2025 /PRNewswire/ — AIMA Technology Group (https://www.aimatech.com/), a global leader in sustainable mobility, is proud to unveil its groundbreaking 2025 eBike lineup at CES 2025. This launch represents a pivotal step in the evolution of sustainable transportation, with a collection designed to redefine performance, style, and freedom for riders worldwide.

AIMA’s New Brand Proposition: “Better Performance, More Freedom”

AIMA’s 2025 strategy is defined by its new brand proposition: “Better Performance, More Freedom.” This philosophy underscores the company’s commitment to delivering innovative products, empowering riders, and fostering stronger dealer partnerships.

Better Performance: Engineered for advanced functionality, exceptional durability, and effortless usability, AIMA’s eBikes ensure every ride exceeds expectations.More Freedom: Riders enjoy seamless exploration and sustainable living, while dealers benefit from unparalleled growth opportunities.

AIMA’s Vision for 2025

AIMA’s 2025 roadmap focuses on four strategic pillars to elevate the eMobility experience:

Continuing dealer-focusing strategy and expanding the Dealer Network: Partnering with independent bike shops to bring premium eBikes closer to communities.Strengthening Product Competitiveness: Leading the sub $2,000 eBike category with innovative, affordable offerings.Enhancing Customer Engagement: Creating interactive experiences such as demo rides and Ebike educational material.Unveiling New Models: Launching diverse eBikes for urban commuters and off-road adventurers alike.

The Lexus of eBikes 

AIMA has earned the title “The Lexus of E-Bikes” for its premium design and unmatched performance. Clint Hough of Trick Ebikes in California praises AIMA’s seamless blend of manufacturing expertise, stringent quality control, and forward-thinking innovation.

2025 Product Highlights

AIMA’s 2025 lineup introduces eight new models and three upgraded designs, each tailored to meet diverse rider needs:

Key West: Sleek and ergonomic, perfect for city commuters.Venice: A Rizoma collaboration featuring futuristic aesthetics and practicality.Manhattan: A folding eBike designed for seamless urban mobility.Rocky: A rugged eMTB for outdoor enthusiasts.Also a new key model to be unveiled on January 8 at the CES: Built with unmatched durability and power, this all-terrain eBike lives up to the slogan “Built Like a Tank.”

Angela Zheng, CEO of AIMA E-Bike, shared, “Our 2025 eBike lineup blends performance, functionality, and commuter elegance. These eBikes are designed for everyone—from urban commuters to weekend adventurers—highlighting our commitment to innovation, quality, and sustainability. Collaborations with pioneers like Rizoma, Bafang, and Rob Janoff have ensured that every model offers a unique, premium experience.”

Pioneering collaborations:

Rizoma: Known for precision engineering and premium materials, Rizoma brought innovative Italian design concepts to the Venice eBike.Bafang: A leader in e-mobility electrical system, Bafang’s motors power AIMA’s eBikes with unmatched efficiency and reliability.Rob Janoff: The iconic designer behind the Apple logo crafted AIMA’s modern and sleek brand identity, reinforcing its premium image.

Innovative Features

AIMA’s eBikes deliver an unparalleled riding experience with cutting-edge advancements:

Enhanced Battery Technology: Lightweight, long-range batteries provide greater freedom for exploration.High-Performance Motors: Powered by AIMA’s trusted partner, Bafang, these efficient and reliable motors ensure smooth and effortless rides, even on challenging terrains.Safety First: Equipped with hydraulic disc brakes and intelligent torque sensors, AIMA eBikes offer superior control and stability.Ergonomic Design: Rider-centric designs prioritize comfort and accessibility for an exceptional experience.

Shaping the Future of Electric Mobility 

From the rugged versatility of the Rocky to the sleek sophistication of the Manhattan, AIMA’s 2025 eBike lineup reflects a commitment to creating a greener, connected future. Every model empowers riders to explore confidently and sustainably. In 2025, NBDA recognizes AIMA as the “Best IBD Partner” as its dealer-first approach is a game-changer for independent bike shops, fostering trust and expertise in communities.

Visit AIMA at CES 2025 

Join AIMA at Booth 10947 in the North Hall of the Las Vegas Convention Center to experience the 2025 lineup firsthand. Discover why AIMA sets the gold standard in eMobility and paves the way for sustainable transportation.

Special Invitation: January 8 Product Launch Event Don’t miss AIMA’s exclusive product launch event on January 8, 2025, at 11:00 AM. Be among the first to witness the unveiling of our latest groundbreaking eBike model and explore the future of sustainable mobility.

About AIMA E-Bike

AIMA E-Bike leads the industry in sustainable electric mobility, delivering high-quality eBikes tailored to riders seeking style, performance, and reliability. Through continuous innovation and collaboration, AIMA is transforming the way people move, making mobility greener, smarter, and more connected.

View original content to download multimedia:https://www.prnewswire.com/news-releases/aima-unveils-game-changing-2025-ebike-lineup-at-ces-better-performance-more-freedom-302346194.html

SOURCE AIMA EBikes

Continue Reading

Trending