Connect with us

Technology

SquareX Discovers New Cybersecurity Attacks that Completely Bypass Secure Web Gateways (SWG), Leaving Most Enterprises Vulnerable.

Published

on

SINGAPORE, Aug 6, 2024 – SquareX Founder, Vivek Ramachandran, cybersecurity veteran with over 20 years of experience and founder/ex-CEO of Pentester Academy (acquired by INE), together with the security research team, will be delivering their latest findings in an upcoming main stage talk, titled Breaking Secure Web Gateways (SWG) for Fun and Profit! at DEF CON 32’ on Friday, August 9, 2024 at 5pm PT.

The talk will unveil ‘Last Mile Reassembly Attacks’, a new class of attacks that completely evade Secure Web Gateways (SWGs), a crucial component of modern Secure Access Service Edge (SASE) and Security Service Edge (SSE) solutions.

The web browser is the most used application within the enterprise but also the least protected. Bad actors are now increasingly targeting the weakest link: employees and consultants.

Unfortunately, most of these attacks happen online when the employee or consultant is going about his daily work. Existing security solutions like SWGs as part of SASE/SSE solutions are unable to protect users against modern web threats that happen on the client side. This makes it currently impossible for enterprise security teams to detect, mitigate and threat hunt these attacks.

Vivek Ramachandran and the SquareX team have conceptualized and identified a new class of attacks against SWG and cloud-based intercepting proxies, converting traditional attacks like malware downloads and malicious websites into something undetectable by all existing vendors in the Gartner Magic Quadrant.

This class of attack is called “Last Mile Reassembly Attacks”. The vulnerabilities the team discovered are architectural and vendor-agnostic, meaning there is no specific way to fix them.

These attacks will have a massive impact on SASE, as it is a $40 billion market, and every large security vendor has an SWG product vulnerable to this new class of attacks. This is an industry-first research highlighting attacks that we suspect may have been circulating in the wild for some time. As these client-side attacks are fundamentally different in nature to the attacks that SWGs typically detect, they have remained unnoticed. Upon revealing these attacks and the release of the accompanying toolkit, enterprise vendors can assess their security posture and build countermeasures.

During the main stage talk, Vivek will shed light on this Last Mile Reassembly Attacks” – where a file download, upload or site rendering never actually happens on the server side. Instead, the attack is assembled directly in the user’s browser using various techniques, which will be explained in detail during the talk. This way, malicious files can evade triggering SWGs, leaving many enterprises across the globe vulnerable to being attacked.

Researchers at SquareX will also demonstrate over 25 plus bypass methods, including chunking attacks, WASM payloads, and others.

“The research team and I are excited to be presenting the talk at DEF CON 32. This talk will challenge SASE, SSE vendors in the current space. We hope that vendors will rethink their reliance on cloud-based web attack detection models and understand the need for a client-side (either endpoint or browser-bjhased) security agent and browser-hardening to work in tandem with the SWG for accurate detection-mitigation of attacks,” says Vivek Ramachandran, Founder & CEO of SquareX.

Web attacks have far advanced and evolved in today’s world and if enterprises do not change the way they protect their users, they will essentially be vulnerable to these web threats and attacks. SquareX is dedicated to enhancing online security for enterprises. By bringing these vulnerabilities to light and advocating for a more comprehensive approach to browser security, the team’s research serves as a critical alert to the cybersecurity community.

The revealing of “Last Mile Reassembly Attacks” and the release of the accompanying toolkit are poised to challenge the way enterprise security teams think and will prompt enterprises to reassess their methods for protecting employees from browser-based attacks.

About SquareX:
SquareX helps organizations detect, mitigate and threat-hunt web attacks happening against their users in real time. With our innovative browser-native security product, SquareX safeguards enterprise users from a spectrum of web-based threats, encompassing malicious files, websites, scripts, and compromised networks.

About Vivek Ramachandran:
Vivek Ramachandran is a security researcher, book author, speaker-trainer, and serial entrepreneur with over two decades of experience in offensive cybersecurity. He is currently the founder of SquareX, building a browser-native security product focused on detecting, mitigating, and threat-hunting web attacks against enterprise users and consumers. Prior to that, he was the founder of Pentester Academy (acquired in 2021), which has trained thousands of customers from government agencies, Fortune 500 companies, and enterprises from over 140+ countries. Before that, Vivek’s company built an 802.11ac monitoring product sold exclusively to defense agencies.

Vivek discovered the Caffe Latte attack, broke WEP Cloaking, conceptualized enterprise Wi-Fi Backdoors, and created Chellam (Wi-Fi Firewall), WiMonitor Enterprise (802.11ac monitoring), Chigula (Wi-Fi traffic analysis via SQL), Deceptacon (IoT Honeypots), among others. He is the author of multiple five-star-rated books in offensive cybersecurity, which have sold thousands of copies worldwide and have been translated into multiple languages.

He has been a speaker/trainer at top security conferences such as Blackhat USA, Europe and Abu Dhabi, DEFCON, Nullcon, Brucon, HITB, Hacktivity, and others. Vivek’s work in cybersecurity has been covered in Forbes, TechCrunch, and other popular media outlets.

In a past life, he was one of the programmers of the 802.1x protocol and Port Security in Cisco’s 6500 Catalyst series of switches. He was also one of the winners of the Microsoft Security Shootout contest held in India among a reported 65,000 participants. He has also published multiple research papers in the field of DDoS, ARP Spoofing Detection, and Anomaly-based Intrusion Detection Systems. In 2021, he was awarded an honorary title of Regional Director of Cybersecurity by Microsoft for a period of three years, and in 2024 he joined the BlackHat Arsenal Review Board.

Technology

MiCoB, SEPL and Kamnath Hospitality Redefine Coastal Luxury with 3DCP Cottages at Nagoa Beach

Published

on

Blending Tradition with Innovation using MiCoB’s 3D Concrete Printing Technology

MiCoB has transformed the landscape of Nagoa Beach, Diu, with its innovative 3D Concrete Printing (3DCP) technology in collaboration with SEPL, and M/S Kamnath Hospitality. The project features 30 3D-printed cottages inspired by the traditional bhunga huts of Gujarat’s Kutch region. Known for their circular design and resilience, these structures seamlessly blend Gujarat’s cultural heritage with cutting-edge construction techniques, creating a unique sustainable hospitality experience.

Designed to meet the demands of coastal hospitality, the cottages address challenges like environmental sensitivity, building insulation and corrosion. Moreover, their design allows for flexibility in compliance with environmental and regulatory considerations for coastal construction, making them a sustainable investment for the future.

“Our 3DCP technology has enabled us to reduce construction time from 8 months to 3 months  while maintaining the highest quality standards,” explains Rishabh Mathur, Cofounder and Chief Technology Officer at MiCoB.

By combining tradition with innovation, MiCoB delivered structures that are not only efficient and cost-effective but also environmentally conscious. Faster construction timelines, reduced material waste, and reduced total cost of ownership further highlight the advantages of 3DCP.These cottages stand as a testament to how modern technology can elevate traditional designs while enhancing the guest experience.

For Kamnath Hospitality, this project represents a step forward in redefining coastal hospitality, offering visitors the perfect mix of comfort and sustainability.

“Partnering with MiCoB for India’s first 3D-printed resort project has been an exceptional experience. Their cutting-edge technology and expertise allowed us to construct a state-of-the-art, 40-room luxury resort with 5-star amenities, setting a benchmark in sustainable and innovative construction. The attention to detail in addressing the challenges posed by the nearby coastline, including the impact of salty weather, was remarkable. Their team designed and implemented solutions that ensured the resort’s durability and structural integrity, maintaining its elegance and functionality over time.  This collaboration has redefined possibilities in the construction industry, and we couldn’t be more proud of the result. We highly recommend MiCoB to anyone seeking innovation, precision, and unmatched quality in their projects.” – Luv Mehta, CEO – SEPL

Guests at Nagoa Beach now can enjoy an experience that embodies the best of tradition, technology, and the serene beauty of the coast.

For more information, reach out to MiCoB at ankita@micob.in or

+91 8780379232

Continue Reading

Technology

Hikigai Inc. and Amrita Vishwa Vidyapeetham Join Forces to Pioneer AI in Healthcare: A Groundbreaking Partnership Set to Revolutionize the Sector

Published

on

In a pioneering move that underscores the evolving intersection of technology and healthcare, Hikigai Inc. has teamed up with Amrita Vishwa Vidyapeetham, Coimbatore, to establish a Joint Research Center for Artificial Intelligence in Healthcare. This strategic collaboration is set to catalyze transformative changes in the healthcare landscape, leveraging the power of AI and cutting-edge research to address some of the most pressing challenges in medical science today. The partnership was formalized with the signing of a Memorandum of Understanding (MoU), in a ceremony attended by key leaders from both organizations. Lalitha R, CEO of Hikigai, Krish Subramanian, CTO, Shubham Giri, Engineering Lead, and Madhumita Selvan from Hikigai were present alongside Prof. Parameswaran, Principal Director, Corporate and Industry Relations, Mr. Suresh Kodoor. Director – Academia Industry Partnership, Dr. K. P. Soman, Dean, School of AI, Dr. Prem J, Assistant Professor, School of AI, Dr. Sundaresan, Assistant Professor, School of AI, Mr. Sai Sundarakrishna, Chief Innovation Officer, CIR and Mr. Kiran Subramanian, Senior Manager, CIR from Amrita Vishwa Vidyapeetham, whose efforts have been instrumental in bringing this collaboration to fruition.

The Power of Collaboration: A Perfect Convergence of Innovation and Academia

This partnership is not just a meeting of minds but a fusion of academic excellence and industry innovation. Hikigai Inc., known for its cutting-edge AI solutions and robust technological expertise, joins hands with Amrita Vishwa Vidyapeetham, a leading institution with a reputation for groundbreaking research and a deep commitment to social relevance in healthcare. The collaboration leverages the synergies between the two entities—Hikigai’s deep technological prowess and Amrita’s world-class research capabilities—to address the most complex healthcare challenges. The newly established Joint Research Center will serve as a hub for AI-driven healthcare innovations, focusing on developing technologies that can dramatically improve healthcare delivery and patient outcomes.

A Glimpse into the Future: Personalized and Precision Medicine with AI

Healthcare is evolving toward a future where treatments are tailored to each patient’s unique needs. Breakthroughs in AI, nanotechnology, and automation are making this vision a reality.
  1. 🔹 AI for Personalized Care – Advanced AI models analyze vast medical data to enable earlier diagnoses and precision treatment plans, improving accuracy and patient.
  2. 🔹 Nanotechnology for Targeted Treatments – Microscopic medical tools deliver therapies directly to affected cells, minimizing side effects and accelerating.
  3. 🔹 AI-Powered Efficiency – Intelligent systems streamline clinical workflows, reduce administrative burdens, and enhance patient care.
This transformation is moving healthcare from a one-size-fits-all approach to truly individualized medicine—where every patient gets the right treatment at the right time. This collaboration will accelerate this future and transform healthcare.

Why This Partnership is Critical for the Future of Healthcare

This collaboration represents more than just technological advancement—it’s a critical step toward redefining the future of healthcare. Both organizations bring unique strengths to the table. Hikigai Inc. is at the forefront of AI innovation, with expertise in artificial intelligence, machine learning, and data analytics, making it an ideal partner for implementing the latest AI techniques in healthcare. Meanwhile, Amrita Vishwa Vidyapeetham, with its long history of research excellence, offers the academic rigor and interdisciplinary approach necessary for creating AI solutions that are not only effective but also socially responsible. Together, Hikigai and Amrita represent the ideal blend of industry expertise and academic depth, creating an ecosystem of collaboration that will shape the future of healthcare. The focus on AI and nanotechnology in this partnership is particularly timely, as both fields hold the key to solving many of the global healthcare challenges we face today, from escalating medical costs to the need for personalized and precision treatments. This partnership is more than just a collaboration; it’s a critical convergence that promises to unlock the next generation of healthcare solutions. With AI’s ability to process vast amounts of data and nanobots’ potential to deliver treatment on a cellular level, the research center is poised to make significant breakthroughs that will impact patient care, treatment outcomes, and healthcare delivery systems worldwide.

The Road Ahead: A Vision of Cutting-Edge Healthcare

As both Hikigai and Amrita Vishwa Vidyapeetham embark on this transformative venture, the world can expect to see a flurry of innovative healthcare solutions in the coming years. From AI-powered diagnostics to nanobots revolutionizing surgeries, the potential applications are boundless. As they work together, these two organizations will undoubtedly play a pivotal role in shaping the future of healthcare, turning their shared vision into reality and paving the way for a healthier, more efficient, and technology-driven world. For more information, contact us at pr@hikigai.ai

Continue Reading

Technology

India’s First FinTech Startup Simplifying Provident Fund Challenges for India’s workforce

Published

on

Launched in October 2023, FinRight Technologies, a Mumbai-based fintech startup founded by CRED and Amazon professionals, addresses personal finance challenges uniquely. With a vision to address some of the most challenging pain points in personal finance, FinRight has chosen Employee Provident Fund (EPF) as its first major focus area as accessing this retirement corpus has become increasingly complicated.

In FY23, over 5.21 crore PF withdrawal and transfer claims were filed, but a staggering 25.8% of them–around 1.34 crore of PF claims–were rejected. For final PF withdrawal claims, the PF claim rejection rate hit a five-year high of 34%. These numbers reveal the deep-rooted challenges employees face when dealing with their Provident Fund claims, making it one of the biggest financial hurdles in India today.

Since its launch in 2023, FinRight has assisted over 5,000 customers on their PF withdrawals and online PF claims, offering a unique combination of tech-driven and human support around intricate rules and processes to provide personalised guidance and assistance. Individuals seeking to withdraw their EPF or resolve issues with EPF transfers can now turn to FinRight for seamless support. By visiting www.finright.in, users can access expert assistance powered by FinRight’s cutting-edge platform. The fintech startup ensures that EPF withdrawal requests initiated through its platform receive dedicated attention, significantly reducing the risk of rejection and simplifying the process for India’s workforce.

“Most people find understanding rules & processes around PF transfers and PF withdrawals daunting. The market is crowded with unorganized PF agents and PF consultants who lack expertise, provide inconsistent service, and often charge exorbitant fees. We saw an opportunity to deliver professional, transparent, and affordable solutions to simplify Provident Fund claims for everyone. Our goal is to empower individuals to access their money without stress or delays” said Amey Kanekar, Co-founder of Finright Technologies Pvt. Ltd.

FinRight is gearing up to introduce digital automation to tackle EPF issues seamlessly by integrating EPFO APIs and employing AI, the founder revealed. “8/10 people discover problems with their EPF only when they need funds, and that’s a challenge we aim to address head-on,” he said. As part of this initiative, FinRight will soon launch a “Get Your EPF Reviewed” online service, empowering users to identify discrepancies instantly in their EPF accounts with just a few clicks.

FinRight’s impact is best demonstrated through the experiences of its customers, who have successfully navigated complex online PF withdrawals issues with the platform’s help:

* Vikas K., Tech Professional in Delhi: “After leaving a tech company where I worked for eight years, I struggled to withdraw my Rs37 lakh EPF due to a mismatch in my father’s name and errors from a subsidiary transfer. My claims were rejected 16 times. FinRight stepped in with a joint declaration and rigorous follow-ups with EPFO, resolving the discrepancies and enabling a successful PF withdrawal within a month. Their expertise in handling Provident Fund withdrawal was a huge relief.”

* Ganesh R., Healthcare Professional in Chennai: “After 20 years across 3 organizations, my online PF withdrawal claim was rejected, citing ‘insufficient service.’ This PF claim rejection occurred because the employer had failed to correctly update my service. Despite seeking help from multiple PF consultants and PF agents, the issue persisted. That’s when FinRight came to my rescue. They helped me navigate the complex process between employers & EPFO, ensuring my service records were updated. This enabled me to access Rs75 lakhs of my PF balance”.

Angel Funding:

FinRight, driven by its mission to simplify personal finance challenges, has secured seed funding from investors. The startup aims to broaden its offerings to tackle additional personal finance pain points, including insurance claims, taxation, and estate planning. Simultaneously, it plans to scale its operations to major Indian cities, reinforcing its position as a trusted leader in financial assistance and provident fund services.

Continue Reading

Technology

AI-Powered WhatsApp Bot to Simplify Solar Consultations by Bigwit Energy

Published

on

The new WhatsApp bot from Bigwit Energy streamlines the solar consultation process, offering personalized guidance, detailed proposals, and easy scheduling for site visits.

Bigwit Energy Pvt. Ltd., a trailblazer in solar energy solutions, has unveiled its latest innovation: an AI-powered WhatsApp bot designed to streamline the solar consultation process. This revolutionary tool offers personalized guidance, detailed proposals, and seamless scheduling for site visits, making solar energy adoption more accessible than ever.

The WhatsApp bot is a one-stop solution for customers exploring solar energy options. It addresses queries about solar power systems, explains the benefits of solar installations, and provides tailored advice on system configurations. By leveraging AI, the bot ensures precise, personalized and unbiased interactions, catering to the unique requirements of every user.

Key Features of the WhatsApp Bot:

  • Instant Guidance: Customers can ask questions such as:
    • “What solar plant size is suitable for my home?”
    • “Whats the difference between an off-grid and hybrid system?”
    • “Which system matches my energy needs?”
  • Custom Proposals: After analyzing customer inputs, the bot generates a comprehensive proposal detailing the recommended solar plant size, estimated energy savings, and potential return on investment.
  • Easy Scheduling: Customers can book site visits directly through the bot, allowing Bigwit Energy’s technical experts to assess locations for optimal solar installations.

How to Access the Bot: To connect with the solar bot, customers can send a WhatsApp message to +91 9325449627 or click here to start a chat. The platform offers quick, accurate responses and personalized recommendations, making the transition to solar energy simple and stress-free.

Bigwit Energy is enhancing the bot with additional capabilities, including a quotation comparison tool. Soon, customers will be able to upload multiple vendor quotations to receive an “apple-to-apple” comparison. This feature will provide unbiased insights, simplifying decision-making and ensuring customers choose the best value solution.

Future Developments: The company is also developing a support bot integrated with online inverters. This tool will assist customers in diagnosing technical issues, optimizing solar plant performance, and scheduling maintenance. Whether addressing system errors or maximizing power output, the support bot will act as a 24/7 virtual assistant for post-installation support.

“Our mission is to make solar energy accessible and hassle-free for everyone,” said Subodh Mahajan, Founder of Bigwit Energy Pvt. Ltd. “This WhatsApp bot represents a significant step forward in delivering transparency and efficiency, from consultation to installation. It embodies our commitment to customer empowerment and sustainable energy solutions.”

By automating and optimizing the consultation process, Bigwit Energy reinforces its position as a leader in innovative solar solutions. The WhatsApp bot not only saves time but also empowers customers to make informed decisions, paving the way for a greener, more sustainable future.

Continue Reading

Technology

ProAce and Star Navigation Systems Launch ProAce Star India, Revolutionizing Aviation and Railway Safety in India

Published

on

New Delhi [India], December 5: In a groundbreaking collaboration, ProAce Business Solutions Inc. and Star Navigation Systems Group Ltd. have announced the launch of ProAce Star India Private Limited. This joint venture aims to transform India’s aviation and railway sectors by enhancing safety and operational efficiency through state-of-the-art technology.

The initiative introduces the In-Flight Safety Monitoring System (ISMS), featuring a proprietary Identical Twin System and real-time monitoring capabilities, seamlessly integrated with Artificial Intelligence (AI) and Augmented Reality (AR). These advancements are tailored to meet the unique demands of the Indian aviation market while aligning with the country’s “Make in India” initiative.

Cutting-Edge Technology for Enhanced Safety

Star Navigation, a global leader in real-time monitoring technology, has revolutionized aviation with its innovative systems. Their patented technology relays data seamlessly from aircraft to satellite and then to customer ground stations, powered by an advanced graphical user interface integrating AI and AR. Dubbed the “identical twin” by Star, the system provides unprecedented real-time analytics and insights.

ProAce Business Solutions Inc., renowned for its success in introducing high-impact technologies to global markets, brings its strategic expertise to help Star Navigation penetrate the Indian market. Together, the two companies have joined forces under ProAce Star India to implement these advanced solutions, enhancing aviation safety and efficiency across the country.

Driving Profits and Efficiency in Aviation

ProAce Star India is set to deliver transformative benefits across the aviation sector:

Continue Reading

Trending