Connect with us

Technology

SquareX Discovers New Cybersecurity Attacks that Completely Bypass Secure Web Gateways (SWG), Leaving Most Enterprises Vulnerable.

Published

on

SINGAPORE, Aug 6, 2024 – SquareX Founder, Vivek Ramachandran, cybersecurity veteran with over 20 years of experience and founder/ex-CEO of Pentester Academy (acquired by INE), together with the security research team, will be delivering their latest findings in an upcoming main stage talk, titled Breaking Secure Web Gateways (SWG) for Fun and Profit! at DEF CON 32’ on Friday, August 9, 2024 at 5pm PT.

The talk will unveil ‘Last Mile Reassembly Attacks’, a new class of attacks that completely evade Secure Web Gateways (SWGs), a crucial component of modern Secure Access Service Edge (SASE) and Security Service Edge (SSE) solutions.

The web browser is the most used application within the enterprise but also the least protected. Bad actors are now increasingly targeting the weakest link: employees and consultants.

Unfortunately, most of these attacks happen online when the employee or consultant is going about his daily work. Existing security solutions like SWGs as part of SASE/SSE solutions are unable to protect users against modern web threats that happen on the client side. This makes it currently impossible for enterprise security teams to detect, mitigate and threat hunt these attacks.

Vivek Ramachandran and the SquareX team have conceptualized and identified a new class of attacks against SWG and cloud-based intercepting proxies, converting traditional attacks like malware downloads and malicious websites into something undetectable by all existing vendors in the Gartner Magic Quadrant.

This class of attack is called “Last Mile Reassembly Attacks”. The vulnerabilities the team discovered are architectural and vendor-agnostic, meaning there is no specific way to fix them.

These attacks will have a massive impact on SASE, as it is a $40 billion market, and every large security vendor has an SWG product vulnerable to this new class of attacks. This is an industry-first research highlighting attacks that we suspect may have been circulating in the wild for some time. As these client-side attacks are fundamentally different in nature to the attacks that SWGs typically detect, they have remained unnoticed. Upon revealing these attacks and the release of the accompanying toolkit, enterprise vendors can assess their security posture and build countermeasures.

During the main stage talk, Vivek will shed light on this Last Mile Reassembly Attacks” – where a file download, upload or site rendering never actually happens on the server side. Instead, the attack is assembled directly in the user’s browser using various techniques, which will be explained in detail during the talk. This way, malicious files can evade triggering SWGs, leaving many enterprises across the globe vulnerable to being attacked.

Researchers at SquareX will also demonstrate over 25 plus bypass methods, including chunking attacks, WASM payloads, and others.

“The research team and I are excited to be presenting the talk at DEF CON 32. This talk will challenge SASE, SSE vendors in the current space. We hope that vendors will rethink their reliance on cloud-based web attack detection models and understand the need for a client-side (either endpoint or browser-bjhased) security agent and browser-hardening to work in tandem with the SWG for accurate detection-mitigation of attacks,” says Vivek Ramachandran, Founder & CEO of SquareX.

Web attacks have far advanced and evolved in today’s world and if enterprises do not change the way they protect their users, they will essentially be vulnerable to these web threats and attacks. SquareX is dedicated to enhancing online security for enterprises. By bringing these vulnerabilities to light and advocating for a more comprehensive approach to browser security, the team’s research serves as a critical alert to the cybersecurity community.

The revealing of “Last Mile Reassembly Attacks” and the release of the accompanying toolkit are poised to challenge the way enterprise security teams think and will prompt enterprises to reassess their methods for protecting employees from browser-based attacks.

About SquareX:
SquareX helps organizations detect, mitigate and threat-hunt web attacks happening against their users in real time. With our innovative browser-native security product, SquareX safeguards enterprise users from a spectrum of web-based threats, encompassing malicious files, websites, scripts, and compromised networks.

About Vivek Ramachandran:
Vivek Ramachandran is a security researcher, book author, speaker-trainer, and serial entrepreneur with over two decades of experience in offensive cybersecurity. He is currently the founder of SquareX, building a browser-native security product focused on detecting, mitigating, and threat-hunting web attacks against enterprise users and consumers. Prior to that, he was the founder of Pentester Academy (acquired in 2021), which has trained thousands of customers from government agencies, Fortune 500 companies, and enterprises from over 140+ countries. Before that, Vivek’s company built an 802.11ac monitoring product sold exclusively to defense agencies.

Vivek discovered the Caffe Latte attack, broke WEP Cloaking, conceptualized enterprise Wi-Fi Backdoors, and created Chellam (Wi-Fi Firewall), WiMonitor Enterprise (802.11ac monitoring), Chigula (Wi-Fi traffic analysis via SQL), Deceptacon (IoT Honeypots), among others. He is the author of multiple five-star-rated books in offensive cybersecurity, which have sold thousands of copies worldwide and have been translated into multiple languages.

He has been a speaker/trainer at top security conferences such as Blackhat USA, Europe and Abu Dhabi, DEFCON, Nullcon, Brucon, HITB, Hacktivity, and others. Vivek’s work in cybersecurity has been covered in Forbes, TechCrunch, and other popular media outlets.

In a past life, he was one of the programmers of the 802.1x protocol and Port Security in Cisco’s 6500 Catalyst series of switches. He was also one of the winners of the Microsoft Security Shootout contest held in India among a reported 65,000 participants. He has also published multiple research papers in the field of DDoS, ARP Spoofing Detection, and Anomaly-based Intrusion Detection Systems. In 2021, he was awarded an honorary title of Regional Director of Cybersecurity by Microsoft for a period of three years, and in 2024 he joined the BlackHat Arsenal Review Board.

Technology

India’s First FinTech Startup Simplifying Provident Fund Challenges for India’s workforce

Published

on

Launched in October 2023, FinRight Technologies, a Mumbai-based fintech startup founded by CRED and Amazon professionals, addresses personal finance challenges uniquely. With a vision to address some of the most challenging pain points in personal finance, FinRight has chosen Employee Provident Fund (EPF) as its first major focus area as accessing this retirement corpus has become increasingly complicated.

In FY23, over 5.21 crore PF withdrawal and transfer claims were filed, but a staggering 25.8% of them–around 1.34 crore of PF claims–were rejected. For final PF withdrawal claims, the PF claim rejection rate hit a five-year high of 34%. These numbers reveal the deep-rooted challenges employees face when dealing with their Provident Fund claims, making it one of the biggest financial hurdles in India today.

Since its launch in 2023, FinRight has assisted over 5,000 customers on their PF withdrawals and online PF claims, offering a unique combination of tech-driven and human support around intricate rules and processes to provide personalised guidance and assistance. Individuals seeking to withdraw their EPF or resolve issues with EPF transfers can now turn to FinRight for seamless support. By visiting www.finright.in, users can access expert assistance powered by FinRight’s cutting-edge platform. The fintech startup ensures that EPF withdrawal requests initiated through its platform receive dedicated attention, significantly reducing the risk of rejection and simplifying the process for India’s workforce.

“Most people find understanding rules & processes around PF transfers and PF withdrawals daunting. The market is crowded with unorganized PF agents and PF consultants who lack expertise, provide inconsistent service, and often charge exorbitant fees. We saw an opportunity to deliver professional, transparent, and affordable solutions to simplify Provident Fund claims for everyone. Our goal is to empower individuals to access their money without stress or delays” said Amey Kanekar, Co-founder of Finright Technologies Pvt. Ltd.

FinRight is gearing up to introduce digital automation to tackle EPF issues seamlessly by integrating EPFO APIs and employing AI, the founder revealed. “8/10 people discover problems with their EPF only when they need funds, and that’s a challenge we aim to address head-on,” he said. As part of this initiative, FinRight will soon launch a “Get Your EPF Reviewed” online service, empowering users to identify discrepancies instantly in their EPF accounts with just a few clicks.

FinRight’s impact is best demonstrated through the experiences of its customers, who have successfully navigated complex online PF withdrawals issues with the platform’s help:

* Vikas K., Tech Professional in Delhi: “After leaving a tech company where I worked for eight years, I struggled to withdraw my Rs37 lakh EPF due to a mismatch in my father’s name and errors from a subsidiary transfer. My claims were rejected 16 times. FinRight stepped in with a joint declaration and rigorous follow-ups with EPFO, resolving the discrepancies and enabling a successful PF withdrawal within a month. Their expertise in handling Provident Fund withdrawal was a huge relief.”

* Ganesh R., Healthcare Professional in Chennai: “After 20 years across 3 organizations, my online PF withdrawal claim was rejected, citing ‘insufficient service.’ This PF claim rejection occurred because the employer had failed to correctly update my service. Despite seeking help from multiple PF consultants and PF agents, the issue persisted. That’s when FinRight came to my rescue. They helped me navigate the complex process between employers & EPFO, ensuring my service records were updated. This enabled me to access Rs75 lakhs of my PF balance”.

Angel Funding:

FinRight, driven by its mission to simplify personal finance challenges, has secured seed funding from investors. The startup aims to broaden its offerings to tackle additional personal finance pain points, including insurance claims, taxation, and estate planning. Simultaneously, it plans to scale its operations to major Indian cities, reinforcing its position as a trusted leader in financial assistance and provident fund services.

Continue Reading

Technology

AI-Powered WhatsApp Bot to Simplify Solar Consultations by Bigwit Energy

Published

on

The new WhatsApp bot from Bigwit Energy streamlines the solar consultation process, offering personalized guidance, detailed proposals, and easy scheduling for site visits.

Bigwit Energy Pvt. Ltd., a trailblazer in solar energy solutions, has unveiled its latest innovation: an AI-powered WhatsApp bot designed to streamline the solar consultation process. This revolutionary tool offers personalized guidance, detailed proposals, and seamless scheduling for site visits, making solar energy adoption more accessible than ever.

The WhatsApp bot is a one-stop solution for customers exploring solar energy options. It addresses queries about solar power systems, explains the benefits of solar installations, and provides tailored advice on system configurations. By leveraging AI, the bot ensures precise, personalized and unbiased interactions, catering to the unique requirements of every user.

Key Features of the WhatsApp Bot:

  • Instant Guidance: Customers can ask questions such as:
    • “What solar plant size is suitable for my home?”
    • “Whats the difference between an off-grid and hybrid system?”
    • “Which system matches my energy needs?”
  • Custom Proposals: After analyzing customer inputs, the bot generates a comprehensive proposal detailing the recommended solar plant size, estimated energy savings, and potential return on investment.
  • Easy Scheduling: Customers can book site visits directly through the bot, allowing Bigwit Energy’s technical experts to assess locations for optimal solar installations.

How to Access the Bot: To connect with the solar bot, customers can send a WhatsApp message to +91 9325449627 or click here to start a chat. The platform offers quick, accurate responses and personalized recommendations, making the transition to solar energy simple and stress-free.

Bigwit Energy is enhancing the bot with additional capabilities, including a quotation comparison tool. Soon, customers will be able to upload multiple vendor quotations to receive an “apple-to-apple” comparison. This feature will provide unbiased insights, simplifying decision-making and ensuring customers choose the best value solution.

Future Developments: The company is also developing a support bot integrated with online inverters. This tool will assist customers in diagnosing technical issues, optimizing solar plant performance, and scheduling maintenance. Whether addressing system errors or maximizing power output, the support bot will act as a 24/7 virtual assistant for post-installation support.

“Our mission is to make solar energy accessible and hassle-free for everyone,” said Subodh Mahajan, Founder of Bigwit Energy Pvt. Ltd. “This WhatsApp bot represents a significant step forward in delivering transparency and efficiency, from consultation to installation. It embodies our commitment to customer empowerment and sustainable energy solutions.”

By automating and optimizing the consultation process, Bigwit Energy reinforces its position as a leader in innovative solar solutions. The WhatsApp bot not only saves time but also empowers customers to make informed decisions, paving the way for a greener, more sustainable future.

Continue Reading

Technology

ProAce and Star Navigation Systems Launch ProAce Star India, Revolutionizing Aviation and Railway Safety in India

Published

on

New Delhi [India], December 5: In a groundbreaking collaboration, ProAce Business Solutions Inc. and Star Navigation Systems Group Ltd. have announced the launch of ProAce Star India Private Limited. This joint venture aims to transform India’s aviation and railway sectors by enhancing safety and operational efficiency through state-of-the-art technology.

The initiative introduces the In-Flight Safety Monitoring System (ISMS), featuring a proprietary Identical Twin System and real-time monitoring capabilities, seamlessly integrated with Artificial Intelligence (AI) and Augmented Reality (AR). These advancements are tailored to meet the unique demands of the Indian aviation market while aligning with the country’s “Make in India” initiative.

Cutting-Edge Technology for Enhanced Safety

Star Navigation, a global leader in real-time monitoring technology, has revolutionized aviation with its innovative systems. Their patented technology relays data seamlessly from aircraft to satellite and then to customer ground stations, powered by an advanced graphical user interface integrating AI and AR. Dubbed the “identical twin” by Star, the system provides unprecedented real-time analytics and insights.

ProAce Business Solutions Inc., renowned for its success in introducing high-impact technologies to global markets, brings its strategic expertise to help Star Navigation penetrate the Indian market. Together, the two companies have joined forces under ProAce Star India to implement these advanced solutions, enhancing aviation safety and efficiency across the country.

Driving Profits and Efficiency in Aviation

ProAce Star India is set to deliver transformative benefits across the aviation sector:

Continue Reading

Technology

TalentGenius Launches TalentAgent in India: AI-Powered Career Success Platform for Tech Professionals

Published

on

Thousands of New India-based Tech Opportunities Available.  

San Francisco, CA – November 19, 2024 — TalentGenius, the leading career management and job search platform for tech professionals, announces the expansion of its job listings to include India. The platform now offers tens of thousands of career opportunities specifically for the country’s tech professionals, with a focus on global system integrators (GSIs) and global capability centers (GCCs). 

The TalentGenius TalentAgent™ tool goes beyond traditional job search filters by AI-powering users to find precisely the jobs they’re looking for with unmatched accuracy. By analysing user preferences, skills, and career goals, TalentAgent presents perfectly tailored matches, making the process of finding the right job faster and easier. 

“We’re excited to bring our career success platform to Indian technology professionals with this significant expansion,” said Malcolm Frank, CEO of TalentGenius. “Our mission is to empower our users to thrive in the AI economy. TalentAgent puts the power of AI on the side of talent, giving job seekers greater control and precision by cutting through irrelevant listings and delivering top-quality matches that align perfectly with their skills and ambitions.”

As part of this commitment, TalentGenius offers several advanced tools to equip tech professionals in India with powerful, career-advancing insights:

  • AIX – AI Exposure Score: A personalized AI Exposure Score helps users understand how AI is shaping their current role and influencing their career path. This tool empowers professionals to take a proactive approach to their AI-readiness.
  • Skills Analysis: Allows users to analyse their existing skills against their peers, and gives a quick snapshot of which skills are in demand and which ones are less competitive. From here users can build a plan to increase their marketability and earning potential. 
  • AI Tools Recommendations – Using individual profiles, TalentAgent matches AI tools to each user, giving them what they need to use and learn in order to do their job better and upskill themselves in an AI-powered environment. 

TalentGenius is designed to be more than just a job search site. The platform empowers tech professionals to adapt and thrive in an evolving job market. “We’re setting a new standard in how candidates find and build careers,” added Frank. “Our tools enable professionals not only to find the right role but to continuously grow in their field with the latest insights in AI-driven job readiness.”

About TalentGenius

TalentGenius provides career management and job search solutions for technology professionals, alongside advanced talent sourcing and AI assessment  tools for businesses. With its AI-driven job-matching tool, TalentAgent, and powerful features like the AI Exposure Score (AIX) and Skills Analysis modules, TalentGenius simplifies the job search process for users and supports companies in finding and evaluating top talent inside and outside their organisations. TalentGenius’s global reach now includes tens of thousands of tech job listings in India, with more expansions on the horizon.  

For more information, please visit TalentGenius.io/Signup or contact:  

Crystal Parra  

Marketing Director  

crystal@talentgenius.io

Continue Reading

Technology

Chery PHEVs’ 1700+ KM Challenging Test Tour Global KOCs Praise the Power and Range

Published

on

From October 14th to October 16th, Chery’s two PHEV models embarked on a 1,700+ KM journey, starting from a tour of Guangzhou’s Hua’e Lou, followed by the driving challenge at Mount Longhu, and concluding with the ecological protection experience at Poyang Lake, before arriving at Chery’s headquarters in Wuhu, China. With their impressive power, extended range, and efficient charging technologies, the vehicles garnered unanimous praise from invited KOCs.

During the driving challenge at Mount Longhu, the Tiggo 9 PHEV and Arrizo 8 PHEV became the center of attention thanks to their remarkable power performance and intelligent control systems. Faced with the winding roads of Mount Longhu, the Tiggo 9 PHEV’s 1.5T engine paired with the third-generation DHT hybrid transmission proved its prowess. The 4WD version boasted an output power of up to 450 kW and a peak torque of 915 N·m, effortlessly handling steep slopes and complex terrain, allowing drivers to experience the thrill of driving fully.

The Arrizo 8 PHEV has an advanced 1.5TGDI fifth-generation hybrid engine, a market highlight due to its ultra-low fuel consumption and high performance. The engine demonstrates outstanding energy utilization with a thermal efficiency of up to 44.5%. It also delivers a maximum power of 115 kW and a peak torque of 220 N·m, ensuring a powerful and smooth driving experience.

The intelligent control systems of both models played a crucial role in the driving challenge. The Tiggo 9 PHEV features an all-dimensional intelligent driving safety system equipped with 30 active safety configurations, including L2.9-level ADAS, highway navigation, and memory parking, offering comprehensive safety for drivers. Meanwhile, the Arrizo 8 PHEV, with its advanced intelligent control system, provides real-time vehicle monitoring and precise adjustments, allowing drivers to enjoy driving fun while feeling secure.

During the Poyang Lake ecological protection experience, the Tiggo 9 PHEV and Arrizo 8 PHEV showcased their long-range capabilities, low energy consumption, and external power supply functions. The vehicles’ range capabilities were fully displayed against Poyang Lake’s expansive waters and surrounding natural scenery. The Tiggo 9 PHEV, depending on configuration, offers an all-electric range of 100/170 km, with a total range exceeding 1,400 km. The Arrizo 8 PHEV also provides a total range of over 1,400 km when fully charged, with an all-electric range exceeding 127 km. This range capability allows drivers to enjoy the natural beauty while handling long-distance travel needs easily.

In the Poyang Lake ecological protection experience, both models’ external power supply functions were also put to good use. Whether for outdoor camping or other power-requiring scenarios, the vehicles’ external power supply functions provide stable electricity for various devices, allowing drivers to enjoy the natural surroundings with practical and convenient power solutions.

Through these immersive activities, the Tiggo 9 PHEV and Arrizo 8 PHEV once again demonstrated Chery’s leading position in PHEV technology with their excellent power performance, intelligent control systems, long-range capabilities, low energy consumption, and external power functions. Looking ahead, Chery will continue to uphold its brand values of green mobility, technological innovation, and family companionship, delivering more premium and eco-friendly automotive products to consumers.

Company: Chery Automobile Co., Ltd.

Contact Person: Chery Automobile

Email: cherybrand@mychery.com

Website: https://www.cheryinternational.com/

Country: China

City: AnHui

Continue Reading

Trending