share_log

SquareX Discovers New Cybersecurity Attacks That Completely Bypass Secure Web Gateways (SWG), Leaving Most Enterprises Vulnerable.

SquareX Discovers New Cybersecurity Attacks That Completely Bypass Secure Web Gateways (SWG), Leaving Most Enterprises Vulnerable.

SquareX發現新的網絡安全概念攻擊,完全繞過安全網關(SWG),使大多數企業易受攻擊。
PR Newswire ·  08/06 11:00

SINGAPORE, Aug. 6, 2024 /PRNewswire/ -- SquareX Founder, Vivek Ramachandran, cybersecurity veteran with over 20 years of experience and founder/ex-CEO of Pentester Academy (acquired by INE), together with the security research team, will be delivering their latest findings in an upcoming main stage talk, titled Breaking Secure Web Gateways (SWG) for Fun and Profit! at DEF CON 32 on Friday, August 9, 2024 at 5pm PT.
The talk will unveil "Last Mile Reassembly Attacks", a new class of attacks that completely evade Secure Web Gateways (SWGs), a crucial component of modern Secure Access Service Edge (SASE) and Security Service Edge (SSE) solutions.
The web browser is the most used application within the enterprise but also the least protected. Bad actors are now increasingly targeting the weakest link: employees and consultants.
Unfortunately, most of these attacks happen online when the employee or consultant is going about his daily work. Existing security solutions like SWGs as part of SASE/SSE solutions are unable to protect users against modern web threats that happen on the client side. This makes it currently impossible for enterprise security teams to detect, mitigate and threat hunt these attacks.
Vivek Ramachandran and the SquareX team have conceptualized and identified a new class of attacks against SWG and cloud-based intercepting proxies, converting traditional attacks like malware downloads and malicious websites into something undetectable by all existing vendors in the Gartner Magic Quadrant.
This class of attack is called "Last Mile Reassembly Attacks". The vulnerabilities the team discovered are architectural and vendor-agnostic, meaning there is no specific way to fix them.

新加坡,2024年8月6日/美通社/-- SquareX Vivek Ramachandran,具有超過20年網絡安全經驗的網絡安全專家和Pentester Academy的創始人/前CE(INE收購),以及他的安全研究團隊將在DEF CON 32上進行一次主場演講,題爲 Vivek Ramachandran,將在2024年8月9日星期五下午5點(太平洋標準時間)發佈他們的最新發現。 該演講將揭示一種新型攻擊“Last Mile Reassembly Attacks”,這是一種可以完全規避Secure Web Gateways (SWGs)的攻擊,SWGs是現代Secure Access Service Edge (SASE)和Security Service Edge (SSE)解決方案的重要組成部分。 此類攻擊發生在客戶端而不是服務端,由於現有的安全解決方案無法保護用戶免受現代網絡威脅,所以在企業安全團隊檢測、緩解和威脅獵捕這些攻擊時存在挑戰。
SquareX的研究人員爲此類攻擊找到了一種全新的攻擊方法,使傳統攻擊如惡意軟件下載和惡意網站等在現有供應商中無法被檢測到,無論供應商是否存在於Gartner Magic Quadrant中,都存在漏洞。
這將對SASE產生重大影響,因爲它是一個價值400億美元的市場,而每個大型安全供應商都有一個SWG產品存在漏洞。
這項研究提供了首個可在客戶端檢測、緩解攻擊的解決方案。
Vivek RamachandranSquareX Gartner Magic Quadrant.
該攻擊類別稱爲“Last Mile Reassembly Attacks”。研究人員發現的漏洞是建築上的,無關特定供應商,這意味着沒有特定的方法來修復問題。

These attacks will have a massive impact on SASE, as it is a $40 billion market, and every large security vendor has an SWG product vulnerable to this new class of attacks. This is an industry-first research highlighting attacks that we suspect may have been circulating in the wild for some time. As these client-side attacks are fundamentally different in nature to the attacks that SWGs typically detect, they have remained unnoticed. Upon revealing these attacks and the release of the accompanying toolkit, enterprise vendors can assess their security posture and build countermeasures.

這些攻擊將對SASE產生巨大影響,因爲它是一個400億美元的市場,而每個大型安全供應商都有一個SWG產品易受這個新的攻擊類別的攻擊。這是行業第一次研究,重點研究了我們猜測已經在野外流傳了一段時間的攻擊。由於這些客戶端攻擊在本質上與SWGs通常檢測到的攻擊不同,它們一直沒有被發現。發佈此攻擊和伴隨工具包,企業供應商可以評估其安全局勢並構建反制措施。

During the main stage talk, Vivek will shed light on this "Last Mile Reassembly Attacks" - where a file download, upload or site rendering never actually happens on the server side. Instead, the attack is assembled directly in the user's browser using various techniques, which will be explained in detail during the talk. This way, malicious files can evade triggering SWGs, leaving many enterprises across the globe vulnerable to being attacked.

在主場演講上,Vivek將揭示這種“Last Mile Reassembly Attacks”-- 其中文件下載、上傳或站點渲染實際上從未發生在服務器端。相反,攻擊是直接在用戶的瀏覽器中使用各種技術組裝的,在演講中將詳細解釋這些技術。這樣,惡意文件就可以逃避觸發SWG,留下全球許多企業易受攻擊。

Researchers at SquareX will also demonstrate over 25 plus bypass methods-, including chunking attacks, WASM payloads, and others.

SquareX的研究人員還將展示25多種繞過方法,包括分塊攻擊、WASm有效負載等。

"The research team and I are excited to be presenting the talk at DEF CON 32. This talk will challenge SASE, SSE vendors in the current space. We hope that vendors will rethink their reliance on cloud-based web attack detection models and understand the need for a client-side (either endpoint or browser-based) security agent and browser-hardening to work in tandem with the SWG for accurate detection-mitigation of attacks," says Vivek Ramachandran, Founder & CEO of SquareX.
Web attacks have far advanced and evolved in today's world and if enterprises do not change the way they protect their users, they will essentially be vulnerable to these web threats and attacks. SquareX is dedicated to enhancing online security for enterprises. By bringing these vulnerabilities to light and advocating for a more comprehensive approach to browser security, the team's research serves as a critical alert to the cybersecurity community.
The revealing of "Last Mile Reassembly Attacks" and the release of the accompanying toolkit are poised to challenge the way enterprise security teams think and will prompt enterprises to reassess their methods for protecting employees from browser-based attacks.
About SquareX:
SquareX helps organizations detect, mitigate and threat-hunt web attacks happening against their users in real time. With our innovative browser-native security product, SquareX safeguards enterprise users from a spectrum of web-based threats, encompassing malicious files, websites, scripts, and compromised networks.
About Vivek Ramachandran:
Vivek Ramachandran is a security researcher, book author, speaker-trainer, and serial entrepreneur with over two decades of experience in offensive cybersecurity. He is currently the founder of SquareX, building a browser-native security product focused on detecting, mitigating, and threat-hunting web attacks against enterprise users and consumers. Prior to that, he was the founder of Pentester Academy (acquired in 2021), which has trained thousands of customers from government agencies, Fortune 500 companies, and enterprises from over 140+ countries. Before that, Vivek's company built an 802.11ac monitoring product sold exclusively to defense agencies.
Vivek discovered the Caffe Latte attack, broke WEP Cloaking, conceptualized enterprise Wi-Fi Backdoors, and created Chellam (Wi-Fi Firewall), WiMonitor Enterprise (802.11ac monitoring), Chigula (Wi-Fi traffic analysis via SQL), Deceptacon (IoT Honeypots), among others. He is the author of multiple five-star-rated books in offensive cybersecurity, which have sold thousands of copies worldwide and have been translated into multiple languages.
He has been a speaker/trainer at top security conferences such as Blackhat USA, Europe and Abu Dhabi, DEFCON, Nullcon, Brucon, HITB, Hacktivity, and others. Vivek's work in cybersecurity has been covered in Forbes, TechCrunch, and other popular media outlets.
In a past life, he was one of the programmers of the 802.1x protocol and Port Security in Cisco's 6500 Catalyst series of switches. He was also one of the winners of the Microsoft Security Shootout contest held in India among a reported 65,000 participants. He has also published multiple research papers in the field of DDoS, ARP Spoofing Detection, and Anomaly-based Intrusion Detection Systems. In 2021, he was awarded an honorary title of Regional Director of Cybersecurity by Microsoft for a period of three years, and in 2024 he joined the BlackHat Arsenal Review Board.

Web攻擊在今天的世界中已經遠遠超出和發展。如果企業不改變他們保護用戶的方式,他們將理所當然地容易受到這些網絡威脅和攻擊的威脅。SquareX致力於增強企業的在線安全性。通過揭示這些漏洞並倡導更全面的瀏覽器安全方法,該團隊的研究爲網絡安全社區提供了關鍵警報。
在今天的世界中,Web攻擊已經遠遠超越並演變了,如果企業不改變其保護其用戶的方式,它們將基本上容易受到這些Web威脅和攻擊的威脅。SquareX致力於增強企業的在線安全。通過揭示這些漏洞並倡導更全面的瀏覽器安全性方法,該團隊的研究作爲對網絡安全社區的重要警告。
“最後一英里復組攻擊”發佈及其附帶工具的揭示已經挑戰企業安全團隊的思維方式,將促使企業重新評估其保護員工免受基於瀏覽器的攻擊的方法。
關於SquareX:
SquareX可幫助組織在實時監測中檢測、減輕並追蹤針對其用戶發生的Web攻擊。通過我們創新的瀏覽器本地安全產品,SquareX保護企業用戶免受一系列基於Web的威脅的侵害,包括惡意文件、網站、腳本和被攻擊的網絡。
關於Vivek Ramachandran:
Vivek Ramachandran 是一位安全研究員、書籍作者、演講培訓師和連續創業者,擁有20多年的攻擊性網絡安全經驗。他目前是SquareX的創始人,致力於構建一個面向企業用戶和消費者,能夠檢測、減輕和追蹤基於Web的攻擊的瀏覽器本地安全產品。在此之前,他是Pentester Academy的創始人(2021年被收購),該公司已經培訓了來自政府機構、財富500強公司和來自140多個國家的企業數千名客戶。在此之前,Vivek的公司構建了一個802.11ac監控產品,僅銷售給國防機構。 SquareX,構建瀏覽器本地安全產品,專注於檢測、減輕和追蹤針對企業用戶和消費者的Web攻擊。
Vivek發現了Caffe Latte攻擊、打破了WEP隱身模式、構思了企業Wi-Fi後門,並創建了Chellam(Wi-Fi防火牆)、WiMonitor Enterprise(802.11ac監測)、Chigula(通過SQL的Wi-Fi流量分析)、Deceptacon(Iot蜜罐)等。他是攻擊性網絡安全領域中多本五星評級書籍的作者,這些書籍在全球銷售了數千本,並被翻譯成多種語言。
他曾經是Blackhat USA、Blackhat歐洲和阿布扎比、DEFCON、Nullcon、Brucon、HITb、Hacktivity等頂級安全會議的演講者/培訓師。Vivek在網絡安全領域的工作曾被Forbes、TechCrunch和其他流行媒體報道。
在過去的生活中,他是思科6500 Catalyst系列交換機的802.1x協議和端口安全的程序員之一。他還是印度舉辦的Microsoft安全槍戰大賽的獲勝者之一,報告稱共有約65,000名參賽者。他還在DDoS、ARP欺騙檢測和基於異常的入侵檢測系統等領域發表了多篇研究論文。2021年,他被微軟授予網絡安全區域總監榮譽稱號,任期爲三年,2024年他加入了BlackHat Arsenal評審委員會。

SOURCE SquareX

來源SquareX

声明:本內容僅用作提供資訊及教育之目的,不構成對任何特定投資或投資策略的推薦或認可。 更多信息
    搶先評論