Connect with us

Technology

SquareX Discovers New Cybersecurity Attacks that Completely Bypass Secure Web Gateways (SWG), Leaving Most Enterprises Vulnerable.

Published

on

SINGAPORE, Aug. 6, 2024 /PRNewswire/ — SquareX Founder, Vivek Ramachandran, cybersecurity veteran with over 20 years of experience and founder/ex-CEO of Pentester Academy (acquired by INE), together with the security research team, will be delivering their latest findings in an upcoming main stage talk, titled Breaking Secure Web Gateways (SWG) for Fun and Profit! at DEF CON 32 on Friday, August 9, 2024 at 5pm PT.

The talk will unveil “Last Mile Reassembly Attacks”, a new class of attacks that completely evade Secure Web Gateways (SWGs), a crucial component of modern Secure Access Service Edge (SASE) and Security Service Edge (SSE) solutions.

The web browser is the most used application within the enterprise but also the least protected. Bad actors are now increasingly targeting the weakest link: employees and consultants.

Unfortunately, most of these attacks happen online when the employee or consultant is going about his daily work. Existing security solutions like SWGs as part of SASE/SSE solutions are unable to protect users against modern web threats that happen on the client side. This makes it currently impossible for enterprise security teams to detect, mitigate and threat hunt these attacks.

Vivek Ramachandran and the SquareX team have conceptualized and identified a new class of attacks against SWG and cloud-based intercepting proxies, converting traditional attacks like malware downloads and malicious websites into something undetectable by all existing vendors in the Gartner Magic Quadrant.

This class of attack is called “Last Mile Reassembly Attacks”. The vulnerabilities the team discovered are architectural and vendor-agnostic, meaning there is no specific way to fix them.

These attacks will have a massive impact on SASE, as it is a $40 billion market, and every large security vendor has an SWG product vulnerable to this new class of attacks. This is an industry-first research highlighting attacks that we suspect may have been circulating in the wild for some time. As these client-side attacks are fundamentally different in nature to the attacks that SWGs typically detect, they have remained unnoticed. Upon revealing these attacks and the release of the accompanying toolkit, enterprise vendors can assess their security posture and build countermeasures.

During the main stage talk, Vivek will shed light on this “Last Mile Reassembly Attacks” – where a file download, upload or site rendering never actually happens on the server side. Instead, the attack is assembled directly in the user’s browser using various techniques, which will be explained in detail during the talk. This way, malicious files can evade triggering SWGs, leaving many enterprises across the globe vulnerable to being attacked.

Researchers at SquareX will also demonstrate over 25 plus bypass methods-, including chunking attacks, WASM payloads, and others.

“The research team and I are excited to be presenting the talk at DEF CON 32. This talk will challenge SASE, SSE vendors in the current space. We hope that vendors will rethink their reliance on cloud-based web attack detection models and understand the need for a client-side (either endpoint or browser-based) security agent and browser-hardening to work in tandem with the SWG for accurate detection-mitigation of attacks,” says Vivek Ramachandran, Founder & CEO of SquareX.

Web attacks have far advanced and evolved in today’s world and if enterprises do not change the way they protect their users, they will essentially be vulnerable to these web threats and attacks. SquareX is dedicated to enhancing online security for enterprises. By bringing these vulnerabilities to light and advocating for a more comprehensive approach to browser security, the team’s research serves as a critical alert to the cybersecurity community.

The revealing of “Last Mile Reassembly Attacks” and the release of the accompanying toolkit are poised to challenge the way enterprise security teams think and will prompt enterprises to reassess their methods for protecting employees from browser-based attacks.

About SquareX:
SquareX helps organizations detect, mitigate and threat-hunt web attacks happening against their users in real time. With our innovative browser-native security product, SquareX safeguards enterprise users from a spectrum of web-based threats, encompassing malicious files, websites, scripts, and compromised networks.

About Vivek Ramachandran:
Vivek Ramachandran is a security researcher, book author, speaker-trainer, and serial entrepreneur with over two decades of experience in offensive cybersecurity. He is currently the founder of SquareX, building a browser-native security product focused on detecting, mitigating, and threat-hunting web attacks against enterprise users and consumers. Prior to that, he was the founder of Pentester Academy (acquired in 2021), which has trained thousands of customers from government agencies, Fortune 500 companies, and enterprises from over 140+ countries. Before that, Vivek’s company built an 802.11ac monitoring product sold exclusively to defense agencies.

Vivek discovered the Caffe Latte attack, broke WEP Cloaking, conceptualized enterprise Wi-Fi Backdoors, and created Chellam (Wi-Fi Firewall), WiMonitor Enterprise (802.11ac monitoring), Chigula (Wi-Fi traffic analysis via SQL), Deceptacon (IoT Honeypots), among others. He is the author of multiple five-star-rated books in offensive cybersecurity, which have sold thousands of copies worldwide and have been translated into multiple languages.

He has been a speaker/trainer at top security conferences such as Blackhat USA, Europe and Abu Dhabi, DEFCON, Nullcon, Brucon, HITB, Hacktivity, and others. Vivek’s work in cybersecurity has been covered in Forbes, TechCrunch, and other popular media outlets.

In a past life, he was one of the programmers of the 802.1x protocol and Port Security in Cisco’s 6500 Catalyst series of switches. He was also one of the winners of the Microsoft Security Shootout contest held in India among a reported 65,000 participants. He has also published multiple research papers in the field of DDoS, ARP Spoofing Detection, and Anomaly-based Intrusion Detection Systems. In 2021, he was awarded an honorary title of Regional Director of Cybersecurity by Microsoft for a period of three years, and in 2024 he joined the BlackHat Arsenal Review Board.
 

View original content to download multimedia:https://www.prnewswire.com/news-releases/squarex-discovers-new-cybersecurity-attacks-that-completely-bypass-secure-web-gateways-swg-leaving-most-enterprises-vulnerable-302214112.html

SOURCE SquareX

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Technology

Zoomlion Smart Industrial City Achieves Full Solar Integration, Setting a Green Benchmark for the Industry

Published

on

By

CHANGSHA, China, Jan. 9, 2025 /PRNewswire/ — Zoomlion Heavy Industry Science & Technology Co., Ltd. (“Zoomlion”, 1157.HK) announced that the rooftop distributed photovoltaic (PV) project at the Mobile Crane Machinery Park of Zoomlion Smart Industrial City has successfully connected to the grid, marking the achievement of full-capacity solar power integration. With this milestone, all parks within the Smart Industrial City now operate entirely on green energy, setting a new benchmark for sustainability in the industry.

The distributed PV system at Zoomlion Smart Industrial City spans across four major parks: Concrete, Mobile Crane, Earthmoving Machinery and Aerial Work Platform. Covering a total installation area of 400,000 square meters, the solar power system now boasts a total capacity of 85 MWp, with an annual electricity output of 65.6 million kWh. This is equivalent to saving 21,500 tons of standard coal and reducing carbon dioxide emissions by 65,400 tons annually, underscoring Zoomlion’s commitment to energy conservation and low-carbon development.

The rooftop PV system at Zoomlion Smart Industrial City is one of the largest in the industry, generating clean energy that not only lowers operating costs but also supports the company’s high-quality development goals. Moreover, the project enables Zoomlion to apply for more than 6,500 green certificates annually, enhancing the export potential of its products by aligning with international green standards.

Zoomlion has taken a leadership role in promoting green development across its operations. Beyond its industrial parks, Zoomlion has embedded sustainability into its core technological development strategy, advancing foundational research in green technologies. Through green design, manufacturing, management, and standardization, the company is contributing to global sustainable development initiatives.

In 2024, the company implemented comprehensive energy-saving and emission-reduction measures, achieving green transformation from production to product delivery. Zoomlion has significantly expanded its lineup of new energy products to meet diverse market demands. The Aerial Work Platform product line now features over 90% coverage in new energy models.

By leveraging advanced digital and intelligent technologies, Zoomlion has also propelled green transformations across its supply chain and industry ecosystem. The company continues to lead the establishment of green standards, driving the machinery industry towards sustainable and circular growth.

With its ongoing efforts to enhance productivity and empower intelligent manufacturing, Zoomlion is paving the way for a greener future in the machinery industry.

View original content:https://www.prnewswire.com/news-releases/zoomlion-smart-industrial-city-achieves-full-solar-integration-setting-a-green-benchmark-for-the-industry-302346830.html

SOURCE Zoomlion

Continue Reading

Technology

LIVE from CES 2025: FOSSiBOT Unveils Disruptive Energy Storage and Rugged Smartphones

Published

on

By

LAS VEGAS, Jan. 9, 2025 /PRNewswire/ — CES 2025 is in full swing in Las Vegas, and FOSSiBOT, a rising star in portable power and rugged devices, is making waves with its latest innovations. A standout product is their high-capacity 5kWh home energy storage system, poised to revolutionize the home energy landscape and redefine industry standards.

CES 2025 Floor: FOSSiBOT’s 7200W Home Energy System Steals the Show

FOSSiBOT is showcasing a powerful 7200W home energy storage system with a substantial 5kWh capacity at CES 2025. Designed to provide reliable backup power, reduce reliance on the traditional grid, and even enable energy self-sufficiency, this system is drawing crowds at the global tech event.

The Significance of 7200W and 5kWh:

7200W Power: This robust output can simultaneously power high-demand appliances like air conditioners, induction cooktops, and electric water heaters, ensuring essential needs are met during power outages. This is a significant power level for the home energy market.5kWh Capacity: This is a key differentiator. In a market dominated by 1-3kWh systems, 5kWh offers significantly extended runtime. For instance, it can power a 90W refrigerator for over 55 hours or a 700W air conditioner for over 7 hours. This capacity sets a new benchmark for home energy storage.

Looking Ahead: FOSSiBOT Developing Balcony Solar Solutions

According to FOSSiBOT, the company is actively developing integrated balcony solar solutions designed to enable users to harvest and store solar energy for greater energy independence. While not on display at CES, FOSSiBOT states this technology is a key focus for future development.

FOSSiBOT’s existing portable power station lineup is also on display, including the F1200 (emphasizing portability), the F2400 (offering increased capacity and higher output), and the flagship F3600 Pro (with advanced features and expandability), showcasing the company’s expertise in portable energy solutions and laying the groundwork for its expansion into the home energy market.

Smartphone Highlights at CES 2025: The S3 Pro Makes a Splash

In the smartphone arena, the recently launched S3 Pro, featuring a vibrant AMOLED display, is making a strong impression at CES 2025, offering attendees a premium visual experience. The unique rear display is also attracting considerable attention. The S3 Pro is available at a competitive price on the FOSSiBOT website.

Existing models like the F106 Pro (combining a large speaker with a 3W camping light) and the F109 (a 5G rugged phone) are also garnering attention at CES 2025 for their reliable performance and distinct features.

The Upcoming F112 Pro: Style Meets Ruggedness Takes Center Stage at CES 2025

The highly anticipated F112 Pro has made its official debut at CES 2025. Blending portability, ruggedness, and stylish design, it features a 6.88-inch HD+ waterdrop display and multiple color options, quickly becoming a focal point on the show floor.

CES 2025: FOSSiBOT Showcases Innovation and Seeks Partnerships

FOSSiBOT’s presence at CES 2025 underscores its commitment to innovation in both the energy storage and smartphone sectors, as the company actively seeks partnerships with global retailers, distributors, and resellers.

FOSSiBOT’s showing at CES 2025 is impressive, and its 5kWh home energy system and new smartphones are poised to make a significant impact on the market.

 

View original content to download multimedia:https://www.prnewswire.com/news-releases/live-from-ces-2025-fossibot-unveils-disruptive-energy-storage-and-rugged-smartphones-302346845.html

SOURCE FOSSiBOT

Continue Reading

Technology

Persistent Introduces Pi-OmniKG with Google Cloud

Published

on

By

Accelerating biomedical research with AI-driven solutions

SANTA CLARA, Calif. and PUNE, India, Jan. 9, 2025 /PRNewswire/ — Persistent Systems (BSE: 533179) (NSE: PERSISTENT), a global leader in Digital Engineering and Enterprise Modernization, today announced the launch of Pi-OmniKG, an advanced AI-driven knowledge graph solution developed with Google Cloud technology. ‘Omni’ signifies the ability to universally handle diverse data, and ‘KG’ stands for Knowledge Graphs powered by GenAI. This innovative solution empowers healthcare and life sciences (HCLS) organizations to accelerate biomedical research, streamline data mining processes, and deliver insights with greater speed and accuracy.

Biomedical research is often hindered by time-consuming and labor-intensive data mining workflows. Legacy systems struggle to incorporate and analyze diverse datasets effectively, delaying the generation of actionable insights critical for HCLS enterprises. Pi-OmniKG addresses these challenges by modernizing data integration processes, creating a holistic knowledge base to decipher complex relationships, allowing researchers to make faster, evidence-based decisions by unlocking hidden insights. Furthermore, Pi-OmniKG enables direct querying of structured and unstructured internal data assets, alone or in combination with external data.

Key benefits of the solution include:

Reducing hypothesis generation time, empowering researchers to make faster, evidence-based decisions.Speeding up data processing, leading to improved research efficiency.Seamlessly integrating diverse data types, files, and sources from public and private datasets, creating a unified knowledge base.Incorporating reusable components with built-in flexibility to meet specific client needs for smart decision support.

Pi-OmniKG is built using Google Cloud’s advanced technologies — including the Vertex AI platform, BigQuery, and Cloud SQL — leveraging GenAI capabilities to streamline workflows, standardize data, and enable seamless integration of structured and unstructured datasets. Its intuitive interface allows researchers to query and visualize data, uncovering novel relationships and delivering high-quality insights backed by authentic citations. 

Persistent has been working with Google Cloud’s cutting-edge AI and cloud technologies for over a decade to deliver transformative solutions that address complex industry challenges. The launch of Pi-OmniKG builds on the Strategic Partnership Agreement Persistent announced in June 2024, which strengthens the collaboration between the two organizations to support Persistent’s development of AI-driven solutions across industries. It exemplifies Persistent’s vision of providing a smarter, faster, and more accessible way for HCLS organizations to process biomedical data and drive innovation.

Ganesh Nathella, Senior Vice President and General Manager – HCLS Business, Persistent

“In an era where data-driven insights are vital to accelerating drug discovery, clinical research, and patient-centric care, the challenges of managing vast and complex datasets often impede progress in biomedical R&D. At the intersection of technology and life sciences, our collaboration with Google Cloud enables us to deliver transformative solutions tailored to this industry’s unique needs with a data-first approach. Pi-OmniKG enables life sciences organizations to streamline workflows, leverage data, and drive breakthroughs with precision. Together, we are advancing the capabilities of researchers and research organizations to address critical challenges and accelerate progress across the healthcare and life sciences ecosystem.”

Shweta Maniar, Global Leader, Healthcare & Life Sciences Solutions & Strategy, Google Cloud

“As the volume and complexity of biomedical data continue to grow, researchers need smarter tools that unlock the true potential of this data. Pi-OmniKG, powered by Google Cloud’s GenAI capabilities, showcases how AI can empower organizations to drive faster discoveries, bring therapies to market sooner, and advance global healthcare innovation. This collaboration with Persistent underscores our shared commitment to enabling breakthroughs in life sciences.”

About Persistent

Persistent Systems (BSE & NSE: PERSISTENT) is a global services and solutions company delivering Digital Engineering and Enterprise Modernization to businesses across industries. With over 23,200 employees located in 19 countries, the Company is committed to innovation and client success. Persistent offers a comprehensive suite of services, including AI-enabled software engineering, product development, data and analytics, CX transformation, cloud computing, and intelligent automation. The Company has been recognized as the “Most Promising Company” of the Year by CNBC-TV18 at the 2023 India Business Leader Awards. Persistent has achieved carbon neutrality, reinforcing its commitment to sustainability and responsible business practices. As a participant of the United Nations Global Compact, the Company is committed to aligning strategies and operations with universal principles on human rights, labor, environment, and anti-corruption, as well as take actions that advance societal goals. With 327% growth in brand value since 2020, Persistent is the fastest-growing IT services brand in the 2024 Brand Finance India 100 Report.

www.persistent.com

Forward-looking and Cautionary Statements

For risks and uncertainties relating to forward-looking statements, please visit persistent.com/flcs

Logo: https://mma.prnewswire.com/media/1022385/Persistent_Systems_Logo.jpg

View original content:https://www.prnewswire.com/news-releases/persistent-introduces-pi-omnikg-with-google-cloud-302346848.html

SOURCE Persistent Systems

Continue Reading

Trending