Connect with us

Technology

SquareX Discovers New Cybersecurity Attacks that Completely Bypass Secure Web Gateways (SWG), Leaving Most Enterprises Vulnerable.

Published

on

SINGAPORE, Aug. 6, 2024 /PRNewswire/ — SquareX Founder, Vivek Ramachandran, cybersecurity veteran with over 20 years of experience and founder/ex-CEO of Pentester Academy (acquired by INE), together with the security research team, will be delivering their latest findings in an upcoming main stage talk, titled Breaking Secure Web Gateways (SWG) for Fun and Profit! at DEF CON 32 on Friday, August 9, 2024 at 5pm PT.

The talk will unveil “Last Mile Reassembly Attacks”, a new class of attacks that completely evade Secure Web Gateways (SWGs), a crucial component of modern Secure Access Service Edge (SASE) and Security Service Edge (SSE) solutions.

The web browser is the most used application within the enterprise but also the least protected. Bad actors are now increasingly targeting the weakest link: employees and consultants.

Unfortunately, most of these attacks happen online when the employee or consultant is going about his daily work. Existing security solutions like SWGs as part of SASE/SSE solutions are unable to protect users against modern web threats that happen on the client side. This makes it currently impossible for enterprise security teams to detect, mitigate and threat hunt these attacks.

Vivek Ramachandran and the SquareX team have conceptualized and identified a new class of attacks against SWG and cloud-based intercepting proxies, converting traditional attacks like malware downloads and malicious websites into something undetectable by all existing vendors in the Gartner Magic Quadrant.

This class of attack is called “Last Mile Reassembly Attacks”. The vulnerabilities the team discovered are architectural and vendor-agnostic, meaning there is no specific way to fix them.

These attacks will have a massive impact on SASE, as it is a $40 billion market, and every large security vendor has an SWG product vulnerable to this new class of attacks. This is an industry-first research highlighting attacks that we suspect may have been circulating in the wild for some time. As these client-side attacks are fundamentally different in nature to the attacks that SWGs typically detect, they have remained unnoticed. Upon revealing these attacks and the release of the accompanying toolkit, enterprise vendors can assess their security posture and build countermeasures.

During the main stage talk, Vivek will shed light on this “Last Mile Reassembly Attacks” – where a file download, upload or site rendering never actually happens on the server side. Instead, the attack is assembled directly in the user’s browser using various techniques, which will be explained in detail during the talk. This way, malicious files can evade triggering SWGs, leaving many enterprises across the globe vulnerable to being attacked.

Researchers at SquareX will also demonstrate over 25 plus bypass methods-, including chunking attacks, WASM payloads, and others.

“The research team and I are excited to be presenting the talk at DEF CON 32. This talk will challenge SASE, SSE vendors in the current space. We hope that vendors will rethink their reliance on cloud-based web attack detection models and understand the need for a client-side (either endpoint or browser-based) security agent and browser-hardening to work in tandem with the SWG for accurate detection-mitigation of attacks,” says Vivek Ramachandran, Founder & CEO of SquareX.

Web attacks have far advanced and evolved in today’s world and if enterprises do not change the way they protect their users, they will essentially be vulnerable to these web threats and attacks. SquareX is dedicated to enhancing online security for enterprises. By bringing these vulnerabilities to light and advocating for a more comprehensive approach to browser security, the team’s research serves as a critical alert to the cybersecurity community.

The revealing of “Last Mile Reassembly Attacks” and the release of the accompanying toolkit are poised to challenge the way enterprise security teams think and will prompt enterprises to reassess their methods for protecting employees from browser-based attacks.

About SquareX:
SquareX helps organizations detect, mitigate and threat-hunt web attacks happening against their users in real time. With our innovative browser-native security product, SquareX safeguards enterprise users from a spectrum of web-based threats, encompassing malicious files, websites, scripts, and compromised networks.

About Vivek Ramachandran:
Vivek Ramachandran is a security researcher, book author, speaker-trainer, and serial entrepreneur with over two decades of experience in offensive cybersecurity. He is currently the founder of SquareX, building a browser-native security product focused on detecting, mitigating, and threat-hunting web attacks against enterprise users and consumers. Prior to that, he was the founder of Pentester Academy (acquired in 2021), which has trained thousands of customers from government agencies, Fortune 500 companies, and enterprises from over 140+ countries. Before that, Vivek’s company built an 802.11ac monitoring product sold exclusively to defense agencies.

Vivek discovered the Caffe Latte attack, broke WEP Cloaking, conceptualized enterprise Wi-Fi Backdoors, and created Chellam (Wi-Fi Firewall), WiMonitor Enterprise (802.11ac monitoring), Chigula (Wi-Fi traffic analysis via SQL), Deceptacon (IoT Honeypots), among others. He is the author of multiple five-star-rated books in offensive cybersecurity, which have sold thousands of copies worldwide and have been translated into multiple languages.

He has been a speaker/trainer at top security conferences such as Blackhat USA, Europe and Abu Dhabi, DEFCON, Nullcon, Brucon, HITB, Hacktivity, and others. Vivek’s work in cybersecurity has been covered in Forbes, TechCrunch, and other popular media outlets.

In a past life, he was one of the programmers of the 802.1x protocol and Port Security in Cisco’s 6500 Catalyst series of switches. He was also one of the winners of the Microsoft Security Shootout contest held in India among a reported 65,000 participants. He has also published multiple research papers in the field of DDoS, ARP Spoofing Detection, and Anomaly-based Intrusion Detection Systems. In 2021, he was awarded an honorary title of Regional Director of Cybersecurity by Microsoft for a period of three years, and in 2024 he joined the BlackHat Arsenal Review Board.
 

View original content to download multimedia:https://www.prnewswire.com/news-releases/squarex-discovers-new-cybersecurity-attacks-that-completely-bypass-secure-web-gateways-swg-leaving-most-enterprises-vulnerable-302214112.html

SOURCE SquareX

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Technology

Supreme Court Justice Michelle O’Bonsawin Joins Elementary Students for Live Virtual Q&A and Chapter One Storybook Reading on Sep. 24

Published

on

By

The Honourable Justice Michelle O’Bonsawin, the first Indigenous person appointed to the Supreme Court of Canada, will join elementary students in a live virtual Q&A on September 24, from 1:00-2:15 pm ET, following a reading of the children’s storybook, “Daanis the Judge.” This event is hosted by Chapter One, a children’s literacy charity, to commemorate the National Day for Truth and Reconciliation. Lawyer Victoria Perrie, writer of “Daanis the Judge,” will read aloud the inspiring story, which is based on Justice O’Bonsawin’s remarkable journey. Illustrator EJ Miller-Larson will join Justice O’Bonsawin and Perrie in a moderated Q&A session with over 1900 elementary students.

TORONTO, Sept. 21, 2024 /PRNewswire-PRWeb/ — The Honourable Justice Michelle O’Bonsawin, the first Indigenous person to be appointed to the Supreme Court of Canada, will join elementary students in a live virtual Q&A following a live online reading of the original children’s storybook “Daanis the Judge,” on September 24, from 1:00-2:15 pm ET. The event will be hosted by Chapter One to mark the National Day for Truth and Reconciliation. Chapter One is a children’s literacy charity that provides 1:1 high-impact reading tutoring and co-creates original storybooks with participating communities nationwide.

“I am very humbled and proud to be a part of the book, “Daanis the Judge.” My hope is that this book will inspire youth to dream big and know that anything is possible. I am evidence of that!” – Justice Michelle O’Bonsawin

Métis-Cree lawyer Victoria Perrie, who wrote “Daanis the Judge,” will lead the live reading. Students will ask questions during a moderated Q&A with Justice O’Bonsawin, Perrie, and illustrator EJ Miller-Larson, of the Fond du Lac Band and Oneida Nation.

“Daanis the Judge” was inspired by Justice O’Bonsawin’s trailblazing career. It tells the story of a young student, Daanis, who dreams of becoming a judge after learning about Justice O’Bonsawin’s achievements.

The story is part of Chapter One’s growing collection of original children’s e-storybooks, co-created with Indigenous writers, illustrators and communities. The e-storybooks celebrate Indigenous experiences and perspectives, and feature audio clips of Elders pronouncing foundational words in their communities’ first languages. All e-storybooks are provided for free through the Global Free Library.

About Chapter One

Chapter One (chapterone.org/ca) is a global nonprofit and registered Canadian charity that provides one-on-one early literacy tutoring programs to 2,300 children in eight provinces and territories across Canada. Its proven “short burst” high-impact tutoring approach—five-minute sessions, three to five times a week—is ideally suited to young children’s attention spans and aligns with the Science of Reading. In one of the largest randomized control trials conducted on early literacy instruction, researchers from Stanford University found that 7 out of 10 students receiving Chapter One high impact tutoring achieved phonics benchmarks by the end of Kindergarten, compared to 32% in the control group.

Children at risk of reading failure receive 1:1 reading support from trained, paid paraprofessional tutors through Chapter One’s online reading platform and custom software. Programs are delivered in-person and virtually in classrooms through agreements with schools and school boards, and at home on families’ smartphones, connecting struggling readers with individualized reading support—regardless of location and circumstance, even in some of the most geographically remote communities in Canada.

In addition to its tutoring programs, Chapter One collaborates with Indigenous communities to co-create children’s stories that represent the communities’ priorities and experiences and advance language revitalization efforts. The e-storybooks are provided for free online, as part of the Global Free Library.

Event details

The Live Virtual Q&A and Reading of “Daanis the Judge” with the Honourable Justice O’Bonsawin takes place on Tuesday, September 24, from 1:00-2:15 pm ET via Zoom. The event is open to elementary classes (Grades 1-6). Teachers/principals must register their classes in advance using this link.

Media Contact

Denise Orosa, Chapter One Canada, 1 4374224825, denise.orosa@chapterone.org, chapterone.org/ca

View original content to download multimedia:https://www.prweb.com/releases/supreme-court-justice-michelle-obonsawin-joins-elementary-students-for-live-virtual-qa-and-chapter-one-storybook-reading-on-sep-24-302254639.html

SOURCE Chapter One Canada

Continue Reading

Technology

PEAC Institute Launches “24 Hour Pause for Peace: A Global Concert”

Published

on

By

24 Hour Pause for Peace Will Be the Largest Peace Initiative Ever Worldwide, Unifying 96 Countries on Six Continents Through Music

MONTCLAIR, N.J., Sept. 21, 2024 /PRNewswire-PRWeb/ — On this International Day of Peace, PEAC Institute, part of the 2017 Nobel Peace Prize winning team, has launched “24 Hour Pause for Peace: A Global Concert,” the largest peace initiative ever organized worldwide through music.

“Now, we need companies, government entities, other nonprofits and donors who care about our cause for peace to join us in lifting up the biggest event of this generation.”

On October 4, 2025, this ground-breaking program will activate a massive network of youth ensembles that spans 96 countries and territories across six continents and host two 24-hour commercial festivals featuring some of the biggest acts in music and entertainment. This extraordinary day-long event will be live-streamed globally, allowing millions to participate simultaneously.

“It has been 40 years since Live Aid and We Are the World historically unified and changed the world through music,” said Rebecca Irby, president and CEO of PEAC Institute. “With our planet riddled with post-pandemic fatigue, climate chaos, unsettling wars and more, we believe it is time to create a new trajectory for humanity by inviting everyone around the globe to a 24 hour pause for peace to enjoy the sounds of music and feel the transformative power of human connection,” Irby explained.

Additionally, 24 Hour Pause for Peace plans to amass more than 100 million ambassadors to sign an appeal to the United Nations calling for a 24 hour ceasefire during the children’s concerts and commercial music events. All countries are welcome to participate with no exceptions. One of Pause for Peace’s core beliefs is everyone has the right to be equally respected and heard, particularly in collectively calling for peace.

“Achieving this ambitious global endeavor requires the support and participation from the most impactful brands, organizations, and influential leaders, artists and celebrities,” said Jennifer McKenna, 24 Hour Pause for Peace CEO.

Pause for Peace is a $165 million global initiative. Currently, it is in its first phase of raising seed capital through consumer brand-aligned sponsorships and private donors. Funding for the program is tax-deductible through PEAC’s 501(c)(3) status.

“We have assembled an exceptional executive team of change agents in entertainment, production, consumer marketing, charitable development and global security to make this extraordinary, worldwide peace event happen.” McKenna added. “Now, we need companies, government entities, other nonprofits and donors who care about our cause for peace to join us in lifting up the biggest event of this generation.” To become involved in 24 Hour Pause for Peace: A Global Concert as a sponsor, partner or donor, sign up to be an Ambassador, or for more information, go to www.24hourpauseforpeace.org.

About PEAC Institute

PEAC Institute is a 501(c)(3) nonprofit organization based in the United States. PEAC stands for peace, education, art and communication. It was formed in 2016 through a campaign with partner organization, International Campaign to Abolish Nuclear Weapons (ICAN), which garnered a 2017 Nobel Peace Prize. PEAC now holds special consultative status with the Economic and Social Council of the United Nations and has a global presence working with countries and territories worldwide to reach the most marginalized youth through art and communication activities to help them explore and express. For more information on PEAC Institute, go to www.peacinstitute.org.

Media Contact

Chadwick Boyd, Pause for Peace, 1 4046060611, chadwick@24hourpauseforpeace.org, www.24hourpauseforpeace.org

View original content to download multimedia:https://www.prweb.com/releases/peac-institute-launches-24-hour-pause-for-peace-a-global-concert-302254527.html

SOURCE Pause for Peace

Continue Reading

Technology

Global Times: China opens 12 nuclear research facilities to global scientists

Published

on

By

The involved facilities span areas such as basic nuclear research, isotope production, nuclear environment simulation, equipment testing, and radioactive waste treatment and disposal.

VIENNA, Sept. 21, 2024 /PRNewswire/ — China will open 12 nuclear research facilities and testing platforms to international scientists and institutions to enhance global cooperation, a senior Chinese official said here on Monday.

These include the China Advanced Research Reactor, the new-generation tokamak device Huanliu-3, and the Beishan Underground Research Laboratory, Liu Jing, vice chairman of the China Atomic Energy Authority (CAEA), said at a meeting on the sidelines of the International Atomic Energy Agency’s (IAEA) annual general conference.

The facilities span areas such as basic nuclear research, isotope production, nuclear environment simulation, equipment testing, and radioactive waste treatment and disposal.

Monday’s meeting, themed “Share for Development,” was organized by the CAEA to promote international cooperation in nuclear technology research and development, as China marks the 40th anniversary of its accession to the IAEA.

Yu Jianfeng, chairman of China National Nuclear Corporation, said at the event that the company aims to deepen cooperation with the IAEA and expand international collaboration. He expressed hope that opening China’s nuclear research facilities will contribute to advancing nuclear technology globally.

IAEA’s Deputy Director General Mikhail Chudakov commended China’s remarkable achievements in nuclear energy development and highlighted the long-standing, fruitful relationship between the IAEA and the CAEA.

Welcoming China’s decision to open up more of its nuclear research and development facilities, Chudakov said the move will further strengthen the agency’s technical capacity to support its member states.

On Monday evening, the CAEA and China’s permanent mission to the United Nations (UN) and other international organizations in Vienna jointly held a reception at the UN headquarters in Vienna to celebrate the 40th anniversary of China’s accession to the IAEA. More than 200 participants, including IAEA representatives and foreign envoys to Vienna, attended the event.

Li Song, China’s permanent representative to the UN and other international organizations in Vienna, said at the reception that China and the IAEA have expanded practical cooperation and jointly promoted the development of nuclear energy over the past 40 years.

China, he said, will continue to strengthen collaboration with the IAEA and its member states to address emerging challenges in international security, safeguard the global non-proliferation regime, and promote the use of nuclear energy and technology for the benefit of the Global South.

At the reception, Liu, Li and IAEA Director General Rafael Grossi jointly unveiled a bronze statue of Qian Sanqiang, a renowned Chinese nuclear physicist and one of the founders of China’s nuclear industry.

The statue, donated by China, will be permanently displayed at the IAEA headquarters, alongside sculptures of Polish-French physicist Marie Curie and other prominent figures who have made significant contributions to the peaceful use of nuclear energy.

Contact: xutianshu@globaltimes.com.cn

View original content:https://www.prnewswire.com/news-releases/global-times-china-opens-12-nuclear-research-facilities-to-global-scientists-302254830.html

SOURCE Global Times

Continue Reading

Trending