share_log

SquareX Discovers New Cybersecurity Attacks That Completely Bypass Secure Web Gateways (SWG), Leaving Most Enterprises Vulnerable.

SquareX Discovers New Cybersecurity Attacks That Completely Bypass Secure Web Gateways (SWG), Leaving Most Enterprises Vulnerable.

SquareX发现新的网络安全概念攻击,完全绕过安全网关(SWG),使大多数企业易受攻击。
PR Newswire ·  08/06 11:00

SINGAPORE, Aug. 6, 2024 /PRNewswire/ -- SquareX Founder, Vivek Ramachandran, cybersecurity veteran with over 20 years of experience and founder/ex-CEO of Pentester Academy (acquired by INE), together with the security research team, will be delivering their latest findings in an upcoming main stage talk, titled Breaking Secure Web Gateways (SWG) for Fun and Profit! at DEF CON 32 on Friday, August 9, 2024 at 5pm PT.
The talk will unveil "Last Mile Reassembly Attacks", a new class of attacks that completely evade Secure Web Gateways (SWGs), a crucial component of modern Secure Access Service Edge (SASE) and Security Service Edge (SSE) solutions.
The web browser is the most used application within the enterprise but also the least protected. Bad actors are now increasingly targeting the weakest link: employees and consultants.
Unfortunately, most of these attacks happen online when the employee or consultant is going about his daily work. Existing security solutions like SWGs as part of SASE/SSE solutions are unable to protect users against modern web threats that happen on the client side. This makes it currently impossible for enterprise security teams to detect, mitigate and threat hunt these attacks.
Vivek Ramachandran and the SquareX team have conceptualized and identified a new class of attacks against SWG and cloud-based intercepting proxies, converting traditional attacks like malware downloads and malicious websites into something undetectable by all existing vendors in the Gartner Magic Quadrant.
This class of attack is called "Last Mile Reassembly Attacks". The vulnerabilities the team discovered are architectural and vendor-agnostic, meaning there is no specific way to fix them.

新加坡,2024年8月6日/美通社/-- SquareX Vivek Ramachandran,具有超过20年网络安全经验的网络安全专家和Pentester Academy的创始人/前CE(INE收购),以及他的安全研究团队将在DEF CON 32上进行一次主场演讲,题为 Vivek Ramachandran,将在2024年8月9日星期五下午5点(太平洋标准时间)发布他们的最新发现。 该演讲将揭示一种新型攻击“Last Mile Reassembly Attacks”,这是一种可以完全规避Secure Web Gateways (SWGs)的攻击,SWGs是现代Secure Access Service Edge (SASE)和Security Service Edge (SSE)解决方案的重要组成部分。 此类攻击发生在客户端而不是服务端,由于现有的安全解决方案无法保护用户免受现代网络威胁,所以在企业安全团队检测、缓解和威胁猎捕这些攻击时存在挑战。
SquareX的研究人员为此类攻击找到了一种全新的攻击方法,使传统攻击如恶意软件下载和恶意网站等在现有供应商中无法被检测到,无论供应商是否存在于Gartner Magic Quadrant中,都存在漏洞。
这将对SASE产生重大影响,因为它是一个价值400亿美元的市场,而每个大型安全供应商都有一个SWG产品存在漏洞。
这项研究提供了首个可在客户端检测、缓解攻击的解决方案。
Vivek RamachandranSquareX Gartner Magic Quadrant.
该攻击类别称为“Last Mile Reassembly Attacks”。研究人员发现的漏洞是建筑上的,无关特定供应商,这意味着没有特定的方法来修复问题。

These attacks will have a massive impact on SASE, as it is a $40 billion market, and every large security vendor has an SWG product vulnerable to this new class of attacks. This is an industry-first research highlighting attacks that we suspect may have been circulating in the wild for some time. As these client-side attacks are fundamentally different in nature to the attacks that SWGs typically detect, they have remained unnoticed. Upon revealing these attacks and the release of the accompanying toolkit, enterprise vendors can assess their security posture and build countermeasures.

这些攻击将对SASE产生巨大影响,因为它是一个400亿美元的市场,而每个大型安全供应商都有一个SWG产品易受这个新的攻击类别的攻击。这是行业第一次研究,重点研究了我们猜测已经在野外流传了一段时间的攻击。由于这些客户端攻击在本质上与SWGs通常检测到的攻击不同,它们一直没有被发现。发布此攻击和伴随工具包,企业供应商可以评估其安全局势并构建反制措施。

During the main stage talk, Vivek will shed light on this "Last Mile Reassembly Attacks" - where a file download, upload or site rendering never actually happens on the server side. Instead, the attack is assembled directly in the user's browser using various techniques, which will be explained in detail during the talk. This way, malicious files can evade triggering SWGs, leaving many enterprises across the globe vulnerable to being attacked.

在主场演讲上,Vivek将揭示这种“Last Mile Reassembly Attacks”-- 其中文件下载、上传或站点渲染实际上从未发生在服务器端。相反,攻击是直接在用户的浏览器中使用各种技术组装的,在演讲中将详细解释这些技术。这样,恶意文件就可以逃避触发SWG,留下全球许多企业易受攻击。

Researchers at SquareX will also demonstrate over 25 plus bypass methods-, including chunking attacks, WASM payloads, and others.

SquareX的研究人员还将展示25多种绕过方法,包括分块攻击、WASm有效负载等。

"The research team and I are excited to be presenting the talk at DEF CON 32. This talk will challenge SASE, SSE vendors in the current space. We hope that vendors will rethink their reliance on cloud-based web attack detection models and understand the need for a client-side (either endpoint or browser-based) security agent and browser-hardening to work in tandem with the SWG for accurate detection-mitigation of attacks," says Vivek Ramachandran, Founder & CEO of SquareX.
Web attacks have far advanced and evolved in today's world and if enterprises do not change the way they protect their users, they will essentially be vulnerable to these web threats and attacks. SquareX is dedicated to enhancing online security for enterprises. By bringing these vulnerabilities to light and advocating for a more comprehensive approach to browser security, the team's research serves as a critical alert to the cybersecurity community.
The revealing of "Last Mile Reassembly Attacks" and the release of the accompanying toolkit are poised to challenge the way enterprise security teams think and will prompt enterprises to reassess their methods for protecting employees from browser-based attacks.
About SquareX:
SquareX helps organizations detect, mitigate and threat-hunt web attacks happening against their users in real time. With our innovative browser-native security product, SquareX safeguards enterprise users from a spectrum of web-based threats, encompassing malicious files, websites, scripts, and compromised networks.
About Vivek Ramachandran:
Vivek Ramachandran is a security researcher, book author, speaker-trainer, and serial entrepreneur with over two decades of experience in offensive cybersecurity. He is currently the founder of SquareX, building a browser-native security product focused on detecting, mitigating, and threat-hunting web attacks against enterprise users and consumers. Prior to that, he was the founder of Pentester Academy (acquired in 2021), which has trained thousands of customers from government agencies, Fortune 500 companies, and enterprises from over 140+ countries. Before that, Vivek's company built an 802.11ac monitoring product sold exclusively to defense agencies.
Vivek discovered the Caffe Latte attack, broke WEP Cloaking, conceptualized enterprise Wi-Fi Backdoors, and created Chellam (Wi-Fi Firewall), WiMonitor Enterprise (802.11ac monitoring), Chigula (Wi-Fi traffic analysis via SQL), Deceptacon (IoT Honeypots), among others. He is the author of multiple five-star-rated books in offensive cybersecurity, which have sold thousands of copies worldwide and have been translated into multiple languages.
He has been a speaker/trainer at top security conferences such as Blackhat USA, Europe and Abu Dhabi, DEFCON, Nullcon, Brucon, HITB, Hacktivity, and others. Vivek's work in cybersecurity has been covered in Forbes, TechCrunch, and other popular media outlets.
In a past life, he was one of the programmers of the 802.1x protocol and Port Security in Cisco's 6500 Catalyst series of switches. He was also one of the winners of the Microsoft Security Shootout contest held in India among a reported 65,000 participants. He has also published multiple research papers in the field of DDoS, ARP Spoofing Detection, and Anomaly-based Intrusion Detection Systems. In 2021, he was awarded an honorary title of Regional Director of Cybersecurity by Microsoft for a period of three years, and in 2024 he joined the BlackHat Arsenal Review Board.

Web攻击在今天的世界中已经远远超出和发展。如果企业不改变他们保护用户的方式,他们将理所当然地容易受到这些网络威胁和攻击的威胁。SquareX致力于增强企业的在线安全性。通过揭示这些漏洞并倡导更全面的浏览器安全方法,该团队的研究为网络安全社区提供了关键警报。
在今天的世界中,Web攻击已经远远超越并演变了,如果企业不改变其保护其用户的方式,它们将基本上容易受到这些Web威胁和攻击的威胁。SquareX致力于增强企业的在线安全。通过揭示这些漏洞并倡导更全面的浏览器安全性方法,该团队的研究作为对网络安全社区的重要警告。
“最后一英里复组攻击”发布及其附带工具的揭示已经挑战企业安全团队的思维方式,将促使企业重新评估其保护员工免受基于浏览器的攻击的方法。
关于SquareX:
SquareX可帮助组织在实时监测中检测、减轻并追踪针对其用户发生的Web攻击。通过我们创新的浏览器本地安全产品,SquareX保护企业用户免受一系列基于Web的威胁的侵害,包括恶意文件、网站、脚本和被攻击的网络。
关于Vivek Ramachandran:
Vivek Ramachandran 是一位安全研究员、书籍作者、演讲培训师和连续创业者,拥有20多年的攻击性网络安全经验。他目前是SquareX的创始人,致力于构建一个面向企业用户和消费者,能够检测、减轻和追踪基于Web的攻击的浏览器本地安全产品。在此之前,他是Pentester Academy的创始人(2021年被收购),该公司已经培训了来自政府机构、财富500强公司和来自140多个国家的企业数千名客户。在此之前,Vivek的公司构建了一个802.11ac监控产品,仅销售给国防机构。 SquareX,构建浏览器本地安全产品,专注于检测、减轻和追踪针对企业用户和消费者的Web攻击。
Vivek发现了Caffe Latte攻击、打破了WEP隐身模式、构思了企业Wi-Fi后门,并创建了Chellam(Wi-Fi防火墙)、WiMonitor Enterprise(802.11ac监测)、Chigula(通过SQL的Wi-Fi流量分析)、Deceptacon(Iot蜜罐)等。他是攻击性网络安全领域中多本五星评级书籍的作者,这些书籍在全球销售了数千本,并被翻译成多种语言。
他曾经是Blackhat USA、Blackhat欧洲和阿布扎比、DEFCON、Nullcon、Brucon、HITb、Hacktivity等顶级安全会议的演讲者/培训师。Vivek在网络安全领域的工作曾被Forbes、TechCrunch和其他流行媒体报道。
在过去的生活中,他是思科6500 Catalyst系列交换机的802.1x协议和端口安全的程序员之一。他还是印度举办的Microsoft安全枪战大赛的获胜者之一,报告称共有约65,000名参赛者。他还在DDoS、ARP欺骗检测和基于异常的入侵检测系统等领域发表了多篇研究论文。2021年,他被微软授予网络安全区域总监荣誉称号,任期为三年,2024年他加入了BlackHat Arsenal评审委员会。

SOURCE SquareX

来源SquareX

声明:本内容仅用作提供资讯及教育之目的,不构成对任何特定投资或投资策略的推荐或认可。 更多信息
    抢沙发