Connect with us

Technology

SquareX Discovers New Cybersecurity Attacks that Completely Bypass Secure Web Gateways (SWG), Leaving Most Enterprises Vulnerable.

Published

on

SINGAPORE, Aug. 6, 2024 /PRNewswire/ — SquareX Founder, Vivek Ramachandran, cybersecurity veteran with over 20 years of experience and founder/ex-CEO of Pentester Academy (acquired by INE), together with the security research team, will be delivering their latest findings in an upcoming main stage talk, titled Breaking Secure Web Gateways (SWG) for Fun and Profit! at DEF CON 32 on Friday, August 9, 2024 at 5pm PT.

The talk will unveil “Last Mile Reassembly Attacks”, a new class of attacks that completely evade Secure Web Gateways (SWGs), a crucial component of modern Secure Access Service Edge (SASE) and Security Service Edge (SSE) solutions.

The web browser is the most used application within the enterprise but also the least protected. Bad actors are now increasingly targeting the weakest link: employees and consultants.

Unfortunately, most of these attacks happen online when the employee or consultant is going about his daily work. Existing security solutions like SWGs as part of SASE/SSE solutions are unable to protect users against modern web threats that happen on the client side. This makes it currently impossible for enterprise security teams to detect, mitigate and threat hunt these attacks.

Vivek Ramachandran and the SquareX team have conceptualized and identified a new class of attacks against SWG and cloud-based intercepting proxies, converting traditional attacks like malware downloads and malicious websites into something undetectable by all existing vendors in the Gartner Magic Quadrant.

This class of attack is called “Last Mile Reassembly Attacks”. The vulnerabilities the team discovered are architectural and vendor-agnostic, meaning there is no specific way to fix them.

These attacks will have a massive impact on SASE, as it is a $40 billion market, and every large security vendor has an SWG product vulnerable to this new class of attacks. This is an industry-first research highlighting attacks that we suspect may have been circulating in the wild for some time. As these client-side attacks are fundamentally different in nature to the attacks that SWGs typically detect, they have remained unnoticed. Upon revealing these attacks and the release of the accompanying toolkit, enterprise vendors can assess their security posture and build countermeasures.

During the main stage talk, Vivek will shed light on this “Last Mile Reassembly Attacks” – where a file download, upload or site rendering never actually happens on the server side. Instead, the attack is assembled directly in the user’s browser using various techniques, which will be explained in detail during the talk. This way, malicious files can evade triggering SWGs, leaving many enterprises across the globe vulnerable to being attacked.

Researchers at SquareX will also demonstrate over 25 plus bypass methods-, including chunking attacks, WASM payloads, and others.

“The research team and I are excited to be presenting the talk at DEF CON 32. This talk will challenge SASE, SSE vendors in the current space. We hope that vendors will rethink their reliance on cloud-based web attack detection models and understand the need for a client-side (either endpoint or browser-based) security agent and browser-hardening to work in tandem with the SWG for accurate detection-mitigation of attacks,” says Vivek Ramachandran, Founder & CEO of SquareX.

Web attacks have far advanced and evolved in today’s world and if enterprises do not change the way they protect their users, they will essentially be vulnerable to these web threats and attacks. SquareX is dedicated to enhancing online security for enterprises. By bringing these vulnerabilities to light and advocating for a more comprehensive approach to browser security, the team’s research serves as a critical alert to the cybersecurity community.

The revealing of “Last Mile Reassembly Attacks” and the release of the accompanying toolkit are poised to challenge the way enterprise security teams think and will prompt enterprises to reassess their methods for protecting employees from browser-based attacks.

About SquareX:
SquareX helps organizations detect, mitigate and threat-hunt web attacks happening against their users in real time. With our innovative browser-native security product, SquareX safeguards enterprise users from a spectrum of web-based threats, encompassing malicious files, websites, scripts, and compromised networks.

About Vivek Ramachandran:
Vivek Ramachandran is a security researcher, book author, speaker-trainer, and serial entrepreneur with over two decades of experience in offensive cybersecurity. He is currently the founder of SquareX, building a browser-native security product focused on detecting, mitigating, and threat-hunting web attacks against enterprise users and consumers. Prior to that, he was the founder of Pentester Academy (acquired in 2021), which has trained thousands of customers from government agencies, Fortune 500 companies, and enterprises from over 140+ countries. Before that, Vivek’s company built an 802.11ac monitoring product sold exclusively to defense agencies.

Vivek discovered the Caffe Latte attack, broke WEP Cloaking, conceptualized enterprise Wi-Fi Backdoors, and created Chellam (Wi-Fi Firewall), WiMonitor Enterprise (802.11ac monitoring), Chigula (Wi-Fi traffic analysis via SQL), Deceptacon (IoT Honeypots), among others. He is the author of multiple five-star-rated books in offensive cybersecurity, which have sold thousands of copies worldwide and have been translated into multiple languages.

He has been a speaker/trainer at top security conferences such as Blackhat USA, Europe and Abu Dhabi, DEFCON, Nullcon, Brucon, HITB, Hacktivity, and others. Vivek’s work in cybersecurity has been covered in Forbes, TechCrunch, and other popular media outlets.

In a past life, he was one of the programmers of the 802.1x protocol and Port Security in Cisco’s 6500 Catalyst series of switches. He was also one of the winners of the Microsoft Security Shootout contest held in India among a reported 65,000 participants. He has also published multiple research papers in the field of DDoS, ARP Spoofing Detection, and Anomaly-based Intrusion Detection Systems. In 2021, he was awarded an honorary title of Regional Director of Cybersecurity by Microsoft for a period of three years, and in 2024 he joined the BlackHat Arsenal Review Board.
 

View original content to download multimedia:https://www.prnewswire.com/news-releases/squarex-discovers-new-cybersecurity-attacks-that-completely-bypass-secure-web-gateways-swg-leaving-most-enterprises-vulnerable-302214112.html

SOURCE SquareX

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Technology

HelloNation Article Highlights Sterile Compounding and Medication Safety With Insights From Compounding Pharmacist Expert Laura Temple

Published

on

By

The article explains how sterile compounded medications are prepared to reduce the risk of contamination and support safe, customized treatments.

AZLE, Texas, July 21, 2026 /PRNewswire/ — What does sterile compounding mean for medication safety? HelloNation has published an article explaining how sterile compounding helps pharmacies prepare highly specialized medications while adhering to strict contamination-prevention procedures.

The article features insights from Laura Temple, Compounding Pharmacist Expert and Owner of Laura’s Pharmacy in Azle, Texas. It explains that sterile compounding is a specialized process for preparing medications in carefully controlled environments designed to reduce the risk of contamination. Sterile compounded medications are often used for injections, eye drops, IV medications, and other therapies that require the highest levels of cleanliness and precision.

The HelloNation article explains that sterile compounded medications differ from commercially manufactured drugs because they are prepared individually for a patient’s unique medical needs. Physicians may prescribe compounded prescriptions when a patient requires a customized dosage, a combination medication, or a treatment not commercially available. Because these medications often bypass the body’s natural defenses, medication safety depends on strict preparation standards throughout the compounding process.

The article describes how pharmacies that provide sterile compounding rely on cleanroom environments equipped with filtered-air systems, specialized equipment, and contamination-prevention protocols. Pharmacists and technicians follow detailed gowning, sterilization, and handwashing procedures before handling medication ingredients. These measures are designed to support medication safety by limiting exposure to bacteria, particles, and other contaminants.

According to the article, environmental monitoring also plays a critical role in sterile compounding. Temperature control, air quality testing, and routine equipment inspections help maintain consistent preparation standards. The article notes that sterile compounded medications may undergo additional quality assurance checks before being dispensed to patients. These procedures help support both treatment effectiveness and patient safety.

The HelloNation article also explains that pharmacies performing sterile compounding are expected to follow USP guidelines established for sterile preparation. These USP guidelines outline requirements for cleanroom pharmacy operations, environmental testing, employee training, and quality assurance practices. The article emphasizes that maintaining compliance with USP guidelines helps reinforce contamination prevention and consistent preparation standards for compounded prescriptions.

Patients seeking sterile compounded medications may also look for pharmacies that participate in accreditation programs or are overseen by state boards. The article explains that these programs review safety procedures, documentation practices, and facility standards to help maintain medication safety. Regular environmental monitoring and staff competency evaluations are also identified as important safeguards in sterile compounding operations.

The article further explains that communication between pharmacists, healthcare providers, and patients remains an important part of safe compounded prescriptions. Compounding pharmacists review prescriptions carefully, confirm dosing instructions, and evaluate ingredient compatibility before preparation begins. This collaborative approach supports medication safety by reducing the risk of errors and ensuring treatments meet individual patient needs.

The article concludes that sterile compounding continues to play an important role in healthcare, particularly for patients requiring customized therapies that are unavailable through traditional manufacturing channels. Whether preparing IV medications, injectable therapies, or other sterile compounded medications, pharmacies rely on contamination prevention procedures and strict preparation standards to support patient care. The article notes that understanding how sterile compounding works can help patients feel more informed about the safety measures involved in preparing specialized medications.

What Sterile Compounding Means for Medication Safety features insights from Laura Temple, a compounding pharmacist expert at Laura’s Pharmacy in Azle, Texas, on HelloNation.

About HelloNation

HelloNation is America’s Good News Network, a premier media platform built on the idea that good news travels faster when real people tell real stories. Through its community-focused publications and innovative “edvertising” approach, HelloNation delivers content that informs, inspires, and spotlights the leaders making a meaningful impact in their communities.

View original content to download multimedia:https://www.prnewswire.com/news-releases/hellonation-article-highlights-sterile-compounding-and-medication-safety-with-insights-from-compounding-pharmacist-expert-laura-temple-302831275.html

SOURCE HelloNation

Continue Reading

Technology

CIOs Forced to Rethink Manual Compliance Processes as Regulatory Complexity Rises, Says Info-Tech Research Group

Published

on

By

Regulatory demands are increasing in volume, complexity, and speed, leaving many organizations reliant on fragmented, manual approaches that slow response times and increase risk. New insights from Info-Tech Research Group show that organizations need to adopt more structured and scalable approaches to keep pace with regulatory change. The firm’s recently published blueprint, Build a Regulatory IT Response Engine, provides frameworks, tools, and step-by-step guidance to help organizations translate regulatory requirements into actionable IT controls and prioritized initiatives.

ARLINGTON, Va., July 21, 2026 /PRNewswire/ — Growing regulatory pressure across jurisdictions is forcing organizations to rethink how they interpret, prioritize, and execute compliance requirements. Many IT teams continue to operate with inconsistent processes and limited coordination, resulting in delayed initiatives and increased exposure to financial and reputational risk. Info-Tech’s blueprint, Build a Regulatory IT Response Engine, introduces a coordinated and repeatable approach to help IT leaders operationalize compliance and improve execution outcomes.

Info-Tech’s findings indicate that while organizations recognize the need for faster and more consistent regulatory response, they continue to face barriers such as fragmented interpretation of requirements, weak prioritization, and limited scalability. AI-enabled tools can help streamline analysis and accelerate response planning, but without a coordinated approach grounded in governance and human oversight, those benefits are difficult to realize.

“Regulatory response is becoming too complex to manage through disconnected, manual processes,” says Ahmad Jowhar, senior research analyst at Info-Tech Research Group. “IT leaders need a repeatable way to interpret requirements, prioritize action, and use AI to accelerate planning without losing the governance and oversight needed to execute effectively.”

Key Challenges IT Leaders Face in Regulatory Response

Despite ongoing investments in compliance, organizations continue to face systemic challenges that hinder effective execution. Info-Tech’s blueprint highlights several areas where IT and compliance leaders struggle most:

Fragmented and manual processes that slow regulatory interpretation and response.Inconsistent application of regulatory requirements across teams and jurisdictions.Poor prioritization of IT initiatives, leading to missed deadlines and duplicated effort.Limited scalability to manage increasing regulatory volume and complexity.Misalignment between compliance activities and broader business priorities.

Info-Tech’s Framework for Building a Regulatory IT Response Engine

To address these challenges, Info-Tech recommends a structured, AI-enabled approach that improves consistency, speed, and scalability. The firm’s Build a Regulatory IT Response Engine blueprint outlines the following key priorities for IT leaders:

Define the regulatory landscape: Establish organizational context, governance structures, and a centralized inventory of applicable regulations.Translate requirements into IT controls: Use AI-enabled analysis and structured assessments to convert regulatory obligations into actionable controls.Prioritize IT initiatives: Align initiatives based on cost, effort, impact, and regulatory timelines to reduce execution risk.Build and communicate a roadmap: Develop a clear, resource-aligned roadmap to guide execution and stakeholder alignment.Establish a repeatable process: Continuously monitor, adapt, and refine regulatory response capabilities to maintain compliance over time.

Organizations that adopt this structured approach can move from reactive compliance efforts to a more proactive and scalable model that shortens response timelines, reduces manual effort, and strengthens execution.

The firm’s Build a Regulatory IT Response Engine blueprint includes practical tools such as a Regulation Inventory Tool, a Regulatory Response IT Action Plan Tool, a Communication Deck Template, and a Compliance Program Framework. By applying these resources, IT leaders can standardize regulatory responses, improve prioritization, and help ensure compliance initiatives are executed on time and in alignment with business priorities.

For exclusive and timely commentary from Info-Tech’s experts, including Ahmad Jowhar, and access to the complete Build a Regulatory IT Response Engine blueprint, please contact pr@infotech.com.

About Info-Tech Research Group

Info-Tech Research Group is the “get things done” partner for over 30,000 IT, HR, and marketing leaders worldwide. The fastest growing research and advisory firm, Info-Tech enables leaders to make well-informed decisions and transform their organizations through AI, strategic foresight, step-by-step methodologies, practical tools, industry-leading advisory, and training programs. For nearly 30 years, tens of thousands of private and public organizations have trusted Info-Tech to lead their most important initiatives through periods of change and deliver outcomes that truly matter.

To learn more about Info-Tech’s HR research and advisory services, visit McLean & Company, and for data-driven software buying insights and vendor evaluations, visit the firm’s SoftwareReviews platform.

Media professionals can register for unrestricted access to research across IT, HR, and software and hundreds of industry analysts through the firm’s Media Insiders program. To gain access, contact pr@infotech.com.

For information about Info-Tech Research Group or to access the latest research, visit infotech.com and connect via LinkedIn and X.

View original content to download multimedia:https://www.prnewswire.com/news-releases/cios-forced-to-rethink-manual-compliance-processes-as-regulatory-complexity-rises-says-info-tech-research-group-302831286.html

SOURCE Info-Tech Research Group

Continue Reading

Technology

Atomera to Announce Second Quarter 2026 Financial Results and Host Webinar on Tuesday, August 4, 2026

Published

on

By

LOS GATOS, Calif., July 21, 2026 /PRNewswire/ — Atomera Incorporated (NASDAQ: ATOM), a semiconductor materials and technology licensing company, announced today that it plans to release its second quarter 2026 financial results after the market closes on Tuesday, Aug. 4, 2026.

The company will host a live video Zoom webinar at 2:00 p.m. Pacific Time (5:00 p.m. Eastern Time) on Tuesday, Aug. 4, 2026, to discuss the results. The live webinar can be accessed through Atomera’s investor relations website at https://ir.atomera.com. A replay of the webcast will be available for 12 months. To pre-register for the webinar, use the following link.

https://atomera.zoom.us/webinar/register/WN_OJFbTWe1SIyV69LLdDadCw

About Atomera

Atomera Incorporated is a semiconductor materials and technology licensing company focused on deploying its proprietary, silicon-proven technology into the semiconductor industry. Atomera has developed Mears Silicon Technology™ (MST®), which increases performance and power efficiency in semiconductor transistors. MST can be implemented using equipment already deployed in semiconductor manufacturing facilities and is complementary to other nano-scaling technologies already in the semiconductor industry roadmap.  More information can be found at www.atomera.com 

 

View original content to download multimedia:https://www.prnewswire.com/news-releases/atomera-to-announce-second-quarter-2026-financial-results-and-host-webinar-on-tuesday-august-4-2026-302830602.html

SOURCE Atomera Incorporated

Continue Reading

Trending