Connect with us

Technology

SquareX Discovers New Cybersecurity Attacks that Completely Bypass Secure Web Gateways (SWG), Leaving Most Enterprises Vulnerable.

Published

on

SINGAPORE, Aug 6, 2024 – SquareX Founder, Vivek Ramachandran, cybersecurity veteran with over 20 years of experience and founder/ex-CEO of Pentester Academy (acquired by INE), together with the security research team, will be delivering their latest findings in an upcoming main stage talk, titled Breaking Secure Web Gateways (SWG) for Fun and Profit! at DEF CON 32’ on Friday, August 9, 2024 at 5pm PT.

The talk will unveil ‘Last Mile Reassembly Attacks’, a new class of attacks that completely evade Secure Web Gateways (SWGs), a crucial component of modern Secure Access Service Edge (SASE) and Security Service Edge (SSE) solutions.

The web browser is the most used application within the enterprise but also the least protected. Bad actors are now increasingly targeting the weakest link: employees and consultants.

Unfortunately, most of these attacks happen online when the employee or consultant is going about his daily work. Existing security solutions like SWGs as part of SASE/SSE solutions are unable to protect users against modern web threats that happen on the client side. This makes it currently impossible for enterprise security teams to detect, mitigate and threat hunt these attacks.

Vivek Ramachandran and the SquareX team have conceptualized and identified a new class of attacks against SWG and cloud-based intercepting proxies, converting traditional attacks like malware downloads and malicious websites into something undetectable by all existing vendors in the Gartner Magic Quadrant.

This class of attack is called “Last Mile Reassembly Attacks”. The vulnerabilities the team discovered are architectural and vendor-agnostic, meaning there is no specific way to fix them.

These attacks will have a massive impact on SASE, as it is a $40 billion market, and every large security vendor has an SWG product vulnerable to this new class of attacks. This is an industry-first research highlighting attacks that we suspect may have been circulating in the wild for some time. As these client-side attacks are fundamentally different in nature to the attacks that SWGs typically detect, they have remained unnoticed. Upon revealing these attacks and the release of the accompanying toolkit, enterprise vendors can assess their security posture and build countermeasures.

During the main stage talk, Vivek will shed light on this Last Mile Reassembly Attacks” – where a file download, upload or site rendering never actually happens on the server side. Instead, the attack is assembled directly in the user’s browser using various techniques, which will be explained in detail during the talk. This way, malicious files can evade triggering SWGs, leaving many enterprises across the globe vulnerable to being attacked.

Researchers at SquareX will also demonstrate over 25 plus bypass methods, including chunking attacks, WASM payloads, and others.

“The research team and I are excited to be presenting the talk at DEF CON 32. This talk will challenge SASE, SSE vendors in the current space. We hope that vendors will rethink their reliance on cloud-based web attack detection models and understand the need for a client-side (either endpoint or browser-bjhased) security agent and browser-hardening to work in tandem with the SWG for accurate detection-mitigation of attacks,” says Vivek Ramachandran, Founder & CEO of SquareX.

Web attacks have far advanced and evolved in today’s world and if enterprises do not change the way they protect their users, they will essentially be vulnerable to these web threats and attacks. SquareX is dedicated to enhancing online security for enterprises. By bringing these vulnerabilities to light and advocating for a more comprehensive approach to browser security, the team’s research serves as a critical alert to the cybersecurity community.

The revealing of “Last Mile Reassembly Attacks” and the release of the accompanying toolkit are poised to challenge the way enterprise security teams think and will prompt enterprises to reassess their methods for protecting employees from browser-based attacks.

About SquareX:
SquareX helps organizations detect, mitigate and threat-hunt web attacks happening against their users in real time. With our innovative browser-native security product, SquareX safeguards enterprise users from a spectrum of web-based threats, encompassing malicious files, websites, scripts, and compromised networks.

About Vivek Ramachandran:
Vivek Ramachandran is a security researcher, book author, speaker-trainer, and serial entrepreneur with over two decades of experience in offensive cybersecurity. He is currently the founder of SquareX, building a browser-native security product focused on detecting, mitigating, and threat-hunting web attacks against enterprise users and consumers. Prior to that, he was the founder of Pentester Academy (acquired in 2021), which has trained thousands of customers from government agencies, Fortune 500 companies, and enterprises from over 140+ countries. Before that, Vivek’s company built an 802.11ac monitoring product sold exclusively to defense agencies.

Vivek discovered the Caffe Latte attack, broke WEP Cloaking, conceptualized enterprise Wi-Fi Backdoors, and created Chellam (Wi-Fi Firewall), WiMonitor Enterprise (802.11ac monitoring), Chigula (Wi-Fi traffic analysis via SQL), Deceptacon (IoT Honeypots), among others. He is the author of multiple five-star-rated books in offensive cybersecurity, which have sold thousands of copies worldwide and have been translated into multiple languages.

He has been a speaker/trainer at top security conferences such as Blackhat USA, Europe and Abu Dhabi, DEFCON, Nullcon, Brucon, HITB, Hacktivity, and others. Vivek’s work in cybersecurity has been covered in Forbes, TechCrunch, and other popular media outlets.

In a past life, he was one of the programmers of the 802.1x protocol and Port Security in Cisco’s 6500 Catalyst series of switches. He was also one of the winners of the Microsoft Security Shootout contest held in India among a reported 65,000 participants. He has also published multiple research papers in the field of DDoS, ARP Spoofing Detection, and Anomaly-based Intrusion Detection Systems. In 2021, he was awarded an honorary title of Regional Director of Cybersecurity by Microsoft for a period of three years, and in 2024 he joined the BlackHat Arsenal Review Board.

Technology

AI-Powered WhatsApp Bot to Simplify Solar Consultations by Bigwit Energy

Published

on

The new WhatsApp bot from Bigwit Energy streamlines the solar consultation process, offering personalized guidance, detailed proposals, and easy scheduling for site visits.

Bigwit Energy Pvt. Ltd., a trailblazer in solar energy solutions, has unveiled its latest innovation: an AI-powered WhatsApp bot designed to streamline the solar consultation process. This revolutionary tool offers personalized guidance, detailed proposals, and seamless scheduling for site visits, making solar energy adoption more accessible than ever.

The WhatsApp bot is a one-stop solution for customers exploring solar energy options. It addresses queries about solar power systems, explains the benefits of solar installations, and provides tailored advice on system configurations. By leveraging AI, the bot ensures precise, personalized and unbiased interactions, catering to the unique requirements of every user.

Key Features of the WhatsApp Bot:

  • Instant Guidance: Customers can ask questions such as:
    • “What solar plant size is suitable for my home?”
    • “Whats the difference between an off-grid and hybrid system?”
    • “Which system matches my energy needs?”
  • Custom Proposals: After analyzing customer inputs, the bot generates a comprehensive proposal detailing the recommended solar plant size, estimated energy savings, and potential return on investment.
  • Easy Scheduling: Customers can book site visits directly through the bot, allowing Bigwit Energy’s technical experts to assess locations for optimal solar installations.

How to Access the Bot: To connect with the solar bot, customers can send a WhatsApp message to +91 9325449627 or click here to start a chat. The platform offers quick, accurate responses and personalized recommendations, making the transition to solar energy simple and stress-free.

Bigwit Energy is enhancing the bot with additional capabilities, including a quotation comparison tool. Soon, customers will be able to upload multiple vendor quotations to receive an “apple-to-apple” comparison. This feature will provide unbiased insights, simplifying decision-making and ensuring customers choose the best value solution.

Future Developments: The company is also developing a support bot integrated with online inverters. This tool will assist customers in diagnosing technical issues, optimizing solar plant performance, and scheduling maintenance. Whether addressing system errors or maximizing power output, the support bot will act as a 24/7 virtual assistant for post-installation support.

“Our mission is to make solar energy accessible and hassle-free for everyone,” said Subodh Mahajan, Founder of Bigwit Energy Pvt. Ltd. “This WhatsApp bot represents a significant step forward in delivering transparency and efficiency, from consultation to installation. It embodies our commitment to customer empowerment and sustainable energy solutions.”

By automating and optimizing the consultation process, Bigwit Energy reinforces its position as a leader in innovative solar solutions. The WhatsApp bot not only saves time but also empowers customers to make informed decisions, paving the way for a greener, more sustainable future.

Continue Reading

Technology

ProAce and Star Navigation Systems Launch ProAce Star India, Revolutionizing Aviation and Railway Safety in India

Published

on

New Delhi [India], December 5: In a groundbreaking collaboration, ProAce Business Solutions Inc. and Star Navigation Systems Group Ltd. have announced the launch of ProAce Star India Private Limited. This joint venture aims to transform India’s aviation and railway sectors by enhancing safety and operational efficiency through state-of-the-art technology.

The initiative introduces the In-Flight Safety Monitoring System (ISMS), featuring a proprietary Identical Twin System and real-time monitoring capabilities, seamlessly integrated with Artificial Intelligence (AI) and Augmented Reality (AR). These advancements are tailored to meet the unique demands of the Indian aviation market while aligning with the country’s “Make in India” initiative.

Cutting-Edge Technology for Enhanced Safety

Star Navigation, a global leader in real-time monitoring technology, has revolutionized aviation with its innovative systems. Their patented technology relays data seamlessly from aircraft to satellite and then to customer ground stations, powered by an advanced graphical user interface integrating AI and AR. Dubbed the “identical twin” by Star, the system provides unprecedented real-time analytics and insights.

ProAce Business Solutions Inc., renowned for its success in introducing high-impact technologies to global markets, brings its strategic expertise to help Star Navigation penetrate the Indian market. Together, the two companies have joined forces under ProAce Star India to implement these advanced solutions, enhancing aviation safety and efficiency across the country.

Driving Profits and Efficiency in Aviation

ProAce Star India is set to deliver transformative benefits across the aviation sector:

Continue Reading

Technology

TalentGenius Launches TalentAgent in India: AI-Powered Career Success Platform for Tech Professionals

Published

on

Thousands of New India-based Tech Opportunities Available.  

San Francisco, CA – November 19, 2024 — TalentGenius, the leading career management and job search platform for tech professionals, announces the expansion of its job listings to include India. The platform now offers tens of thousands of career opportunities specifically for the country’s tech professionals, with a focus on global system integrators (GSIs) and global capability centers (GCCs). 

The TalentGenius TalentAgent™ tool goes beyond traditional job search filters by AI-powering users to find precisely the jobs they’re looking for with unmatched accuracy. By analysing user preferences, skills, and career goals, TalentAgent presents perfectly tailored matches, making the process of finding the right job faster and easier. 

“We’re excited to bring our career success platform to Indian technology professionals with this significant expansion,” said Malcolm Frank, CEO of TalentGenius. “Our mission is to empower our users to thrive in the AI economy. TalentAgent puts the power of AI on the side of talent, giving job seekers greater control and precision by cutting through irrelevant listings and delivering top-quality matches that align perfectly with their skills and ambitions.”

As part of this commitment, TalentGenius offers several advanced tools to equip tech professionals in India with powerful, career-advancing insights:

  • AIX – AI Exposure Score: A personalized AI Exposure Score helps users understand how AI is shaping their current role and influencing their career path. This tool empowers professionals to take a proactive approach to their AI-readiness.
  • Skills Analysis: Allows users to analyse their existing skills against their peers, and gives a quick snapshot of which skills are in demand and which ones are less competitive. From here users can build a plan to increase their marketability and earning potential. 
  • AI Tools Recommendations – Using individual profiles, TalentAgent matches AI tools to each user, giving them what they need to use and learn in order to do their job better and upskill themselves in an AI-powered environment. 

TalentGenius is designed to be more than just a job search site. The platform empowers tech professionals to adapt and thrive in an evolving job market. “We’re setting a new standard in how candidates find and build careers,” added Frank. “Our tools enable professionals not only to find the right role but to continuously grow in their field with the latest insights in AI-driven job readiness.”

About TalentGenius

TalentGenius provides career management and job search solutions for technology professionals, alongside advanced talent sourcing and AI assessment  tools for businesses. With its AI-driven job-matching tool, TalentAgent, and powerful features like the AI Exposure Score (AIX) and Skills Analysis modules, TalentGenius simplifies the job search process for users and supports companies in finding and evaluating top talent inside and outside their organisations. TalentGenius’s global reach now includes tens of thousands of tech job listings in India, with more expansions on the horizon.  

For more information, please visit TalentGenius.io/Signup or contact:  

Crystal Parra  

Marketing Director  

crystal@talentgenius.io

Continue Reading

Technology

Chery PHEVs’ 1700+ KM Challenging Test Tour Global KOCs Praise the Power and Range

Published

on

From October 14th to October 16th, Chery’s two PHEV models embarked on a 1,700+ KM journey, starting from a tour of Guangzhou’s Hua’e Lou, followed by the driving challenge at Mount Longhu, and concluding with the ecological protection experience at Poyang Lake, before arriving at Chery’s headquarters in Wuhu, China. With their impressive power, extended range, and efficient charging technologies, the vehicles garnered unanimous praise from invited KOCs.

During the driving challenge at Mount Longhu, the Tiggo 9 PHEV and Arrizo 8 PHEV became the center of attention thanks to their remarkable power performance and intelligent control systems. Faced with the winding roads of Mount Longhu, the Tiggo 9 PHEV’s 1.5T engine paired with the third-generation DHT hybrid transmission proved its prowess. The 4WD version boasted an output power of up to 450 kW and a peak torque of 915 N·m, effortlessly handling steep slopes and complex terrain, allowing drivers to experience the thrill of driving fully.

The Arrizo 8 PHEV has an advanced 1.5TGDI fifth-generation hybrid engine, a market highlight due to its ultra-low fuel consumption and high performance. The engine demonstrates outstanding energy utilization with a thermal efficiency of up to 44.5%. It also delivers a maximum power of 115 kW and a peak torque of 220 N·m, ensuring a powerful and smooth driving experience.

The intelligent control systems of both models played a crucial role in the driving challenge. The Tiggo 9 PHEV features an all-dimensional intelligent driving safety system equipped with 30 active safety configurations, including L2.9-level ADAS, highway navigation, and memory parking, offering comprehensive safety for drivers. Meanwhile, the Arrizo 8 PHEV, with its advanced intelligent control system, provides real-time vehicle monitoring and precise adjustments, allowing drivers to enjoy driving fun while feeling secure.

During the Poyang Lake ecological protection experience, the Tiggo 9 PHEV and Arrizo 8 PHEV showcased their long-range capabilities, low energy consumption, and external power supply functions. The vehicles’ range capabilities were fully displayed against Poyang Lake’s expansive waters and surrounding natural scenery. The Tiggo 9 PHEV, depending on configuration, offers an all-electric range of 100/170 km, with a total range exceeding 1,400 km. The Arrizo 8 PHEV also provides a total range of over 1,400 km when fully charged, with an all-electric range exceeding 127 km. This range capability allows drivers to enjoy the natural beauty while handling long-distance travel needs easily.

In the Poyang Lake ecological protection experience, both models’ external power supply functions were also put to good use. Whether for outdoor camping or other power-requiring scenarios, the vehicles’ external power supply functions provide stable electricity for various devices, allowing drivers to enjoy the natural surroundings with practical and convenient power solutions.

Through these immersive activities, the Tiggo 9 PHEV and Arrizo 8 PHEV once again demonstrated Chery’s leading position in PHEV technology with their excellent power performance, intelligent control systems, long-range capabilities, low energy consumption, and external power functions. Looking ahead, Chery will continue to uphold its brand values of green mobility, technological innovation, and family companionship, delivering more premium and eco-friendly automotive products to consumers.

Company: Chery Automobile Co., Ltd.

Contact Person: Chery Automobile

Email: cherybrand@mychery.com

Website: https://www.cheryinternational.com/

Country: China

City: AnHui

Continue Reading

Technology

VRAD Co. Launches Korean VR Simulators for Nursing & Trauma Training in Global Markets

Published

on

VRAD Co., Ltd. is launching two widely recognized Korean-developed virtual reality-based simulators, NS_Core, a nursing skills education simulator, and IP_Trauma, a trauma patient care simulator, for international markets. These products support a broad range of languages, including Korean, English, Vietnamese, Thai, Indonesian, Chinese, Japanese, Kazakh, and German, with Spanish and French language support anticipated by the end of the year.

NS_Core is an immersive clinical simulation solution designed for nursing skill training using Meta’s virtual reality headset. It allows users to perform a variety of clinical exercises in a VR environment with simulated patients. This solution offers an innovative approach to addressing the challenges of hands-on medical training within nursing school curricula by providing a metaverse-based virtual training space.

Developed through a collaboration between general hospitals and university nursing departments, NS_Core enables intensive, repetitive practice on 20 essential nursing skills, significantly enhancing clinical performance among nursing students.

IP_Trauma offers a comprehensive VR training environment for medical personnel to acquire and refine essential trauma care skills. This includes learning various medical procedures, equipment handling, situational assessment, and decision-making, as well as fostering teamwork and real-time communication—areas traditionally challenging to practice effectively.

IP_Trauma is an immersive clinical simulation platform featuring reactive scenario simulations, where outcomes vary based on the user’s choices and actions. Developed in partnership with several prominent Korean universities and hospitals, it adheres to the globally recognized Advanced Trauma Life Support (ATLS) protocol standards.

Within the IP_Trauma simulator, multiple users can communicate in real time, practicing critical decision-making and trauma care techniques in a virtual environment. The simulation covers over 40 procedural steps, from pre-hospital preparation to patient transfer to the operating room. Simulation managers can utilize a control console to assign real-time scenarios, provide additional instructions, and directly guide participants, effectively managing the simulation’s progress.

Currently recognized as a leading VR medical technology provider in Korea, VRAD’s products are actively used in over 90 medical and educational institutions, both domestically and internationally.

Website: https://vrad.one/

Media Contact: VRAD in Gyeonggi-Do, South Korea

Media Inquiries Contact: wsheo@vrad.one

Phone: +82 2-869-4789

Email: info@vrad.one

Continue Reading

Trending