Connect with us

Technology

SquareX Discovers New Cybersecurity Attacks that Completely Bypass Secure Web Gateways (SWG), Leaving Most Enterprises Vulnerable.

Published

on

SINGAPORE, Aug. 6, 2024 /PRNewswire/ — SquareX Founder, Vivek Ramachandran, cybersecurity veteran with over 20 years of experience and founder/ex-CEO of Pentester Academy (acquired by INE), together with the security research team, will be delivering their latest findings in an upcoming main stage talk, titled Breaking Secure Web Gateways (SWG) for Fun and Profit! at DEF CON 32 on Friday, August 9, 2024 at 5pm PT.

The talk will unveil “Last Mile Reassembly Attacks”, a new class of attacks that completely evade Secure Web Gateways (SWGs), a crucial component of modern Secure Access Service Edge (SASE) and Security Service Edge (SSE) solutions.

The web browser is the most used application within the enterprise but also the least protected. Bad actors are now increasingly targeting the weakest link: employees and consultants.

Unfortunately, most of these attacks happen online when the employee or consultant is going about his daily work. Existing security solutions like SWGs as part of SASE/SSE solutions are unable to protect users against modern web threats that happen on the client side. This makes it currently impossible for enterprise security teams to detect, mitigate and threat hunt these attacks.

Vivek Ramachandran and the SquareX team have conceptualized and identified a new class of attacks against SWG and cloud-based intercepting proxies, converting traditional attacks like malware downloads and malicious websites into something undetectable by all existing vendors in the Gartner Magic Quadrant.

This class of attack is called “Last Mile Reassembly Attacks”. The vulnerabilities the team discovered are architectural and vendor-agnostic, meaning there is no specific way to fix them.

These attacks will have a massive impact on SASE, as it is a $40 billion market, and every large security vendor has an SWG product vulnerable to this new class of attacks. This is an industry-first research highlighting attacks that we suspect may have been circulating in the wild for some time. As these client-side attacks are fundamentally different in nature to the attacks that SWGs typically detect, they have remained unnoticed. Upon revealing these attacks and the release of the accompanying toolkit, enterprise vendors can assess their security posture and build countermeasures.

During the main stage talk, Vivek will shed light on this “Last Mile Reassembly Attacks” – where a file download, upload or site rendering never actually happens on the server side. Instead, the attack is assembled directly in the user’s browser using various techniques, which will be explained in detail during the talk. This way, malicious files can evade triggering SWGs, leaving many enterprises across the globe vulnerable to being attacked.

Researchers at SquareX will also demonstrate over 25 plus bypass methods-, including chunking attacks, WASM payloads, and others.

“The research team and I are excited to be presenting the talk at DEF CON 32. This talk will challenge SASE, SSE vendors in the current space. We hope that vendors will rethink their reliance on cloud-based web attack detection models and understand the need for a client-side (either endpoint or browser-based) security agent and browser-hardening to work in tandem with the SWG for accurate detection-mitigation of attacks,” says Vivek Ramachandran, Founder & CEO of SquareX.

Web attacks have far advanced and evolved in today’s world and if enterprises do not change the way they protect their users, they will essentially be vulnerable to these web threats and attacks. SquareX is dedicated to enhancing online security for enterprises. By bringing these vulnerabilities to light and advocating for a more comprehensive approach to browser security, the team’s research serves as a critical alert to the cybersecurity community.

The revealing of “Last Mile Reassembly Attacks” and the release of the accompanying toolkit are poised to challenge the way enterprise security teams think and will prompt enterprises to reassess their methods for protecting employees from browser-based attacks.

About SquareX:
SquareX helps organizations detect, mitigate and threat-hunt web attacks happening against their users in real time. With our innovative browser-native security product, SquareX safeguards enterprise users from a spectrum of web-based threats, encompassing malicious files, websites, scripts, and compromised networks.

About Vivek Ramachandran:
Vivek Ramachandran is a security researcher, book author, speaker-trainer, and serial entrepreneur with over two decades of experience in offensive cybersecurity. He is currently the founder of SquareX, building a browser-native security product focused on detecting, mitigating, and threat-hunting web attacks against enterprise users and consumers. Prior to that, he was the founder of Pentester Academy (acquired in 2021), which has trained thousands of customers from government agencies, Fortune 500 companies, and enterprises from over 140+ countries. Before that, Vivek’s company built an 802.11ac monitoring product sold exclusively to defense agencies.

Vivek discovered the Caffe Latte attack, broke WEP Cloaking, conceptualized enterprise Wi-Fi Backdoors, and created Chellam (Wi-Fi Firewall), WiMonitor Enterprise (802.11ac monitoring), Chigula (Wi-Fi traffic analysis via SQL), Deceptacon (IoT Honeypots), among others. He is the author of multiple five-star-rated books in offensive cybersecurity, which have sold thousands of copies worldwide and have been translated into multiple languages.

He has been a speaker/trainer at top security conferences such as Blackhat USA, Europe and Abu Dhabi, DEFCON, Nullcon, Brucon, HITB, Hacktivity, and others. Vivek’s work in cybersecurity has been covered in Forbes, TechCrunch, and other popular media outlets.

In a past life, he was one of the programmers of the 802.1x protocol and Port Security in Cisco’s 6500 Catalyst series of switches. He was also one of the winners of the Microsoft Security Shootout contest held in India among a reported 65,000 participants. He has also published multiple research papers in the field of DDoS, ARP Spoofing Detection, and Anomaly-based Intrusion Detection Systems. In 2021, he was awarded an honorary title of Regional Director of Cybersecurity by Microsoft for a period of three years, and in 2024 he joined the BlackHat Arsenal Review Board.
 

View original content to download multimedia:https://www.prnewswire.com/news-releases/squarex-discovers-new-cybersecurity-attacks-that-completely-bypass-secure-web-gateways-swg-leaving-most-enterprises-vulnerable-302214112.html

SOURCE SquareX

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Technology

Changhong Spotlights AI Innovations at CES 2025, Asserting Global Leadership in Intelligent Technologies

Published

on

By

LAS VEGAS, Jan. 9, 2025 /PRNewswire/ — Changhong is thrilled to join CES 2025 in Las Vegas on January 7-10, showcasing an array of Al-enabled products, including smart TVs, refrigerators, air conditioners, a washer-dryer pair, and comprehensive smart home solutions. These innovations demonstrate the company’s commitment to merging cutting-edge technology with enhanced lifestyle features, highlighting its robust technical expertise and dedication to expanding its international presence.

Changhong Introduces Next-Generation Smart Home Appliances

At the exhibition, Changhong’s AI TV models, featuring the innovative Canghai Intelligent Agent, drew significant attention for their advanced interactivity, superior search functionality, and personalized services. The AI refrigerators impressed the visitors with their ability to reduce noise levels based on user proximity as well as to maintain optimal freshness and prevent frost build-up. The air conditioners equipped with AI-driven temperature and humidity controls ensure optimal comfort while reducing energy usage by up to 40%. Changhong’s Ozone Supreme Care Washer & Dryer Pair utilizes cutting-edge washing and drying technologies to ensure top-tier performance.

The company’s smart home system, customized to individual family needs, integrates proactive services, energy efficiency, security, privacy, and AI capabilities. This innovative solution enables families to achieve up to 20% in annual energy savings.

On January 8, during a concurrent event, Changhong’s premium brand CHiQ was awarded the prestigious “Global Smart Home Brands Top 10” by International Data Group (IDG), further cementing Changhong’s leadership in the global consumer electronics sector.

Accelerated International Expansion: Changhong Thrives in the World of Winter Sports

Changhong has embraced the growing popularity of winter sports, with its premium brand CHiQ partnering since 2023 with the International Ski Federation (FIS) Ski Jumping World Cup and the Deutscher Skiverband e.V. (DSV). In November 2024, Changhong announced its sponsorship of the FIS Snowboard and Freeski Big Air World Cup, reinforcing its vibrant and international brand image.

In June 2024, World Brand Lab valued the Changhong brand at 236.876 billion yuan (approx. USD 32.5 billion) in its list of China’s 500 Most Valuable Brands. Changhong ranked 53rd in Asia’s 500 Most Valuable Brands in September, and 283rd in the World’s 500 Most Valuable Brands in December.

Changhong’s leadership is deeply committed to advancing its technological foundation and continuously pushing the boundaries of innovation. The company aims to further enhance the global consumer experience by providing even more convenient, comfortable, and intelligent lifestyle solutions.

Photo – https://mma.prnewswire.com/media/2594487/1.jpg

View original content:https://www.prnewswire.co.uk/news-releases/changhong-spotlights-ai-innovations-at-ces-2025-asserting-global-leadership-in-intelligent-technologies-302346874.html

Continue Reading

Technology

Minati Mohapatra Cycling Velodrome Inaugurated at KIIT-KISS Campus by Union Minister Mansukh Mandaviya

Published

on

By

BHUBANESWAR, India, Jan. 9, 2025 /PRNewswire/ — The Minati Mohapatra Cycling Velodrome was inaugurated today at the KIIT-KISS campus by the Union Minister of Youth Affairs and Sports, Mansukh Mandaviya. The velodrome is named in honor of Minati Mohapatra – Odisha’s first Arjuna Awardee in cycling.

Inaugurating the Velodrome, the Union Minister reflected on the significance of the occasion. “Today is an important day for me,” he said, what I witnessed aligns with the dream of Prime Minister Narendra Modi – a nation where education and sports go hand in hand.”

Quoting Acharya Chanakya, the minister emphasized the importance of education in shaping a nation’s future. “I am satisfied that the country’s future is in the capable hands of educationists like Dr. Samanta. KIIT, KISS, and KIMS are nurturing students who will grow into responsible citizens. Wherever I go, I will share the best practices I observed here,” Mandaviya added.

Dr Samanta, Founder of KIIT (https://kiit.ac.in/), KISS (https://kiss.ac.in/), and KIMS (https://kims.kiit.ac.in/), expressed his gratitude for the minister’s visit and highlighted plans to double the sports infrastructure at KIIT and KISS in the coming years. “With the minister’s blessings, we aim to expand our facilities further and provide more opportunities for budding athletes,” he remarked.

Maninder Pal Singh, Secretary General of the Cycling Federation of India, lauded the minister’s passion for sports. “The minister is a cycling enthusiast himself, and his contribution to promoting sports across the country is remarkable,” he said.

Minati Mohapatra, visibly moved by the honour, expressed her gratitude. “I am speechless. People say Dr. Samanta is like a god to us. This is the greatest honor of my life,” she said.

KIIT Vice Chancellor Prof. Saranjit Singh highlighted the minister’s achievements during his tenure as Union Health Minister, and KISS Vice Chancellor Prof. Deepak Kumar Behera delivered the vote of thanks.

https://www.facebook.com/share/v/1AnQaQYZTn/

https://x.com/achyuta_samanta/status/1877011676085584240?t=6xAws1Tqjcoscx2vTR5LEw&s=08

Photo: https://mma.prnewswire.com/media/2594540/KIIT_Inauguration.jpg
Logo: https://mma.prnewswire.com/media/2234144/4867564/KIIT_Logo.jpg

 

View original content to download multimedia:https://www.prnewswire.com/in/news-releases/minati-mohapatra-cycling-velodrome-inaugurated-at-kiit-kiss-campus-by-union-minister-mansukh-mandaviya-302346876.html

Continue Reading

Technology

CHiQ Named Among the Global Smart Home Brands Top 10

Published

on

By

LAS VEGAS, Jan. 9, 2025 /PRNewswire/ — On January 8th, at a concurrent event during the CES 2025 in Las Vegas, CHiQ was honored as one of the Global Smart Home Brands Top 10 by International Data Group (IDG). This accolade highlights CHiQ’s outstanding performance in the smart home sector.

James Wu, General Manager of CHiQ International Brand Business Center said, “Being named one of the ‘Global Smart Home Brands Top 10’ is a significant acknowledgment of CHiQ’s international market standing. Looking ahead, CHiQ remains committed to delivering high-quality products and services globally.”

At CES, CHiQ showcased a range of AI-driven products, featuring its first AI TV and the 100-inch CHiQ AI Wallpaper TV, both offering personalized services via the advanced CHiQ Canghai Intelligent Agent. It also introduced an AI refrigerator that reduces noise and defrost issues, and an AI air conditioner that enhances comfort while cutting energy use by 40%. Additionally, the CHiQ Ozone Supreme Care Washer & Dryer Pair offers efficient washing and instant drying with advanced care features. The CHiQ Smart Home System integrates proactive service, energy efficiency, enhanced security, and AI technology, enabling users to save up to 20% on energy bills.

Since entering the international market in 2017, CHiQ has embodied the slogan “Smart with Style” in 2023, showcasing its dedication to innovative, stylish products. Now present in over 40 countries, CHiQ offers a diverse range, including TVs, refrigerators, air conditioners, and washing machines.

CHiQ has energized its brand through strategic partnerships with renowned athletes like Olympic skiing champion Andreas Wellinger and through sponsoring high-profile international sports events. The brand’s participation in the FIS Ski World Cup events and sponsorships of regional sports teams and events including Australia’s St. George Illawarra Dragons, South Korea’s Daegu FC, and the Terra Wortmann Open, have significantly boosted its global visibility. These initiatives have elevated CHiQ’s global presence and strengthened consumer engagement.

In 2024, CHiQ experienced remarkable growth, with European sales up over 30%. Australia saw a 40% increase, and Indonesia an impressive 55%. Meanwhile, Malaysia, Thailand, the Philippines, Latin America, and the Middle East, all reported significant revenue growth.

Looking to the future, CHiQ will continue to prioritize innovation, leveraging its exceptional products and services to deepen global consumer connections. The brand aims to usher in a new era of smart homes and set new benchmarks for smart living.

View original content to download multimedia:https://www.prnewswire.com/news-releases/chiq-named-among-the-global-smart-home-brands-top-10-302346878.html

SOURCE CHiQ

Continue Reading

Trending