Connect with us

Technology

BTR: Understanding the Critical 2FA Vulnerability in QR Code Enrollment Processes Uncovered by Silent Sector – Lauro Chavez

Published

on

SILVER SPRING, Md., Oct. 1, 2024 /PRNewswire/ — Silent Sector, a leading cybersecurity firm specializing in protecting mid-market businesses, has discovered a major flaw in the two-factor authentication (2FA) enrollment process that could leave millions of organizations vulnerable to cyberattacks. The vulnerability lies in the use of QR codes for 2FA, a common security practice across industries, and poses an urgent threat to the security of organizations that rely on this method to protect sensitive accounts.

The vulnerability Silent Sector identified is related to the secret key embedded in QR codes used for 2FA enrollment. When users scan a QR code to link their authentication apps, such as Google Authenticator or Microsoft Authenticator, to access their accounts, the secret key that allows this link never expires. This creates a critical security risk: if a QR code was sent via email, saved to a device, or stored in a repository, hackers could potentially access that code, re-enroll in the 2FA process, and bypass account security measures.

“Many organizations trust QR codes as part of their authentication systems, but this discovery shows a significant gap in security,” said Lauro Chavez, Partner and Head of Research at Silent Sector. “The issue is that these QR codes, and the secret keys they contain, can be reused indefinitely. That’s a massive risk if they fall into the wrong hands.”

The Scale of the Threat

Two-factor authentication, or 2FA, is widely used by businesses and individuals to add an extra layer of security to account logins. The process typically requires users to enter not just a password but also a one-time passcode (OTP), which is generated by an authentication app on a user’s phone. This is typically performed after enrolling in the multi-factor authentication process. This process is frequently enabled by scanning a QR code during the initial setup.

Indeed, for the better part of a decade, QR code-based 2FA has been considered a highly secure method because it was believed that the secret key embedded in the code expired after the initial setup. However, Silent Sector’s discovery reveals that this is not the case. The secret key embedded in the QR code remains valid indefinitely, allowing a malicious actor to use it to re-enroll and gain access to accounts even if the original user is unaware.

“This vulnerability has the potential to impact millions of businesses worldwide, especially those in the mid-market, which may not have the resources or expertise to deal with such sophisticated threats,” Chavez explained. “The ability to reuse these codes without expiration is particularly concerning, as many organizations may not even realize the risk.”

To read the remainder of the interview, please visit:
https://bit.ly/3zEuqTs

Contact:
***@biztechreports.com

Photo(s):
https://www.prlog.org/13041242

Press release distributed by PRLog

View original content:https://www.prnewswire.com/news-releases/btr-understanding-the-critical-2fa-vulnerability-in-qr-code-enrollment-processes-uncovered-by-silent-sector–lauro-chavez-302264722.html

SOURCE Silent Sector

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Technology

Sunlighten Introduces PulseIQ™: The Intelligent Platform Redefining Infrared Wellness

Published

on

By

PulseIQ™ delivers four distinct wavelengths independently, adapting each session to support recovery, relaxation, and performance. 

OVERLAND PARK, Kan., April 21, 2026 /PRNewswire/ — Sunlighten, the global leader in infrared sauna innovation, today announced the launch of PulseIQ™, its proprietary intelligent wellness platform. This breakthrough sets a new standard for how infrared energy is delivered, absorbed, and translated into personalized wellness outcomes.

For decades, the sauna category has remained largely unchanged. Traditional saunas deliver heat. Most infrared saunas claim “full spectrum,” but in reality blend wavelengths together into a single, undifferentiated output.

The result is a one-dimensional experience. The sauna turns on, heat increases, and the body is exposed to inconsistent energy with no control over how it is delivered or absorbed.

PulseIQ™ changes that.

PulseIQ™ redefines how infrared works by delivering red light, near-, mid-, and far-infrared separately and intelligently. Instead of blending wavelengths and losing their effectiveness, PulseIQ™ isolates and controls each wavelength so your body receives the right type of infrared energy at the right time.

This is infrared intelligence. This is PulseIQ™.

A Category Built on Heat. Reimagined Around Outcomes.

Most saunas today operate with a simple on and off experience. As heat rises, there is no control over the wavelengths being delivered. The distinct benefits of each wavelength are lost, reducing the experience to heat rather than targeted infrared energy.

The difference is not just how many wavelengths are present. It is how they are delivered.

Your body responds to each wavelength differently. When they are blended together, your body cannot fully use them. You are not truly receiving distinct infrared light energy.

PulseIQ™ changes that by isolating each wavelength and delivering it with precision. This allows your body to absorb more usable energy, driving better outcomes based on what your body needs that day.

Because wellness is not static. Your body’s needs change daily. Your sauna should adapt with you.

From One-Dimensional Heat to Personalized Infrared Therapy

PulseIQ™ transforms the sauna experience from passive heat to an intelligent, outcome-driven wellness solution.

Powered by Sunlighten’s infrared intelligence platform, PulseIQ™ delivers:

Four distinct wavelengths delivered independently so each can perform its specific role in the bodySix science-backed wellness programs designed around goals like recovery, detoxification, relaxation, and performancePrecision control of energy delivery and temperature to eliminate peaks and valleys and keep the body within optimal therapeutic ranges

Each wavelength is delivered at the intensity and depth your body can absorb, ensuring the energy is not just produced but used effectively.

Red light supports skin health and surface-level repairNear-infrared supports cellular energy and recoveryMid-infrared supports circulation and muscle recoveryFar-infrared supports core temperature and detoxification

By controlling how this energy is delivered, PulseIQ™ helps your body achieve the specific wellness outcomes you are seeking, whether that is faster recovery, deeper relaxation, improved circulation, or daily restoration.

An Intelligent Sauna That Evolves With You

PulseIQ™ is designed not just for today, but for the future of personalized wellness.

“Infrared has never been about heat alone. It is about how the body responds to light,” said Connie Zack, Co-Founder of Sunlighten. “With PulseIQ™, we control the light your body is receiving so it can absorb more of what it needs. That leads to better outcomes, whether you are focused on recovery, relaxation, or long-term wellness.”

PulseIQ™ introduces an intelligent platform that evolves with you, helping you get more personalized results from every session.

“We are building the next generation of sauna technology,” said Aaron Zack, CEO of Sunlighten. “Our bodies are complex and constantly changing, yet most saunas offer a one-dimensional on and off experience. With PulseIQ™, we’re measuring data every day and using it to advance our technology. In the future, your sauna will be able to guide you. If your body needs recovery or support, it will recommend the right program for you. The sauna you buy today should grow with you, adapting to your needs and helping you achieve better wellness outcomes over time.”

Engineering the Future of Infrared Wellness

For more than 25 years, Sunlighten has led the industry through science, innovation, and a deep understanding of how the body responds to infrared energy.

PulseIQ™ builds on that foundation with a clear focus on what matters most to consumers.

Not just heat.
Not just presence of wavelengths.
But how effectively that energy is delivered and absorbed by the body.

PulseIQ™ delivers the most usable infrared energy at precise wavelengths your body can absorb, giving you greater confidence that every session is working toward your wellness goals.

Redefining What Infrared Should Deliver

PulseIQ™ reframes the conversation around infrared saunas.

This is not about turning heat on and off.
This is about controlling the energy your body receives.

With PulseIQ™, Sunlighten introduces:

1 intelligent sauna platform4 precisely controlled, distinct wavelengths6 guided, science-backed wellness programsA system designed to evolve and personalize over time

Better delivery leads to greater absorption.
Greater absorption leads to better wellness outcomes.

This is infrared intelligence. This is PulseIQ™.

About Sunlighten

Sunlighten is the global leader in infrared sauna and light-based wellness innovation. With more than 25 years of expertise, patented technologies, and a commitment to science-backed performance, Sunlighten designs products that help the body perform, recover, and thrive.

Contact:

Maria Dolgetta

mdolgetta@sunlighten.com

View original content to download multimedia:https://www.prnewswire.com/news-releases/sunlighten-introduces-pulseiq-the-intelligent-platform-redefining-infrared-wellness-302748918.html

SOURCE Sunlighten

Continue Reading

Technology

Novita AI Ranked as the Best Performing & Reliable Inference Layer

Published

on

By

120+ LLMs through a single API, with day-0 model availability, OpenAI and Anthropic compatibility, and top-ranked performance validated by Artificial Analysis.

SAN FRANCISCO, April 21, 2026 /PRNewswire/ — As demand for open-source AI infrastructure grows, Novita AI is establishing itself as the inference provider for developers and engineering teams that need fast and affordable inference for production AI. The platform covers more than 120 large language models through a single OpenAI-compatible and Anthropic-compatible API, makes every new model available on release day, and ranked #1 for scientific reasoning accuracy across all major inference providers, according to independent benchmarking by Artificial Analysis.

Novita AI is trusted by leading teams across the AI ecosystem, including Hugging Face, Quora, OpenRouter, Vercel, Kilo Code, and Genspark.

“Open-source AI moves at a pace that most infrastructure hasn’t kept up with,” said Junyu Huang, COO of Novita AI. “We built Novita to close that gap. When a new model ships, developers can be in production with it the same day, on infrastructure they can actually rely on.”

Artificial Analysis provides comparison and analysis of AI models and API hosting providers, with independent benchmarks across key performance metrics including quality, price, and output speed. In its GPT-OSS 120B assessment covering all major inference providers, Novita AI ranked as follows (April 2026):

GPQA Diamond (scientific reasoning): #1 among all providers, scoring 79.0% across 16 runs

AIME 2025 (advanced mathematics): 93.3% across 32 runs, at the level of the top providers

IFBench (instruction following): #5, scoring 68.9%, within 0.8 points of the top provider

Source: Artificial Analysis GPT-OSS-120B Provider Benchmarks, April 2026.

New models ship constantly. Novita AI makes each one available through its API on release day, without exception. For engineering teams running evaluation pipelines or production systems that depend on current models, access is never the bottleneck.

Novita AI hosts more than 120 LLMs across every major model family, including Qwen, DeepSeek, LLaMA, Mistral, Gemma, GLM, Phi, and more. All models share the same API format, authentication, and SDK. Teams on the OpenAI or Anthropic SDK can switch to Novita by changing the base URL.

Novita’s API works out of the box with Claude Code, OpenClaw, Codex CLI, and OpenCode.

Novita AI delivers fast inference with the full feature set production AI teams depend on, with no tiered restrictions or add-ons.

Tool calling: compliant with OpenAI and Anthropic function-calling specifications, supporting multi-turn agent workflows

Structured outputs: JSON responses that conform to a specified schema, no parsing wrappers needed

Prompt caching: lower latency and token costs for RAG pipelines and agent sessions with repeated context

Novita AI is an AI and agent cloud platform helping developers and startups build, deploy, and scale models and agentic applications with high performance, reliability, and cost efficiency. The platform delivers fast inference across 120+ LLMs and multimodal models through a single API, alongside GPU Instances, Bare Metal, and Agent Sandbox infrastructure built for production AI.

For more information, visit novita.ai.

View original content to download multimedia:https://www.prnewswire.com/news-releases/novita-ai-ranked-as-the-best-performing–reliable-inference-layer-302748913.html

SOURCE Novita AI

Continue Reading

Technology

Arasan acheives the Industrys First ASIL-D Certification for its CAN XL IP Core

Published

on

By

Arasan announces the industry’s first ASIL-D Certification for its CAN XL IP. The certification also covers Arasan’s CAN FD IP and CAN 2.0 IP.

SAN JOSE, Calif., Apr. 21, 2026 /PRNewswire/ — Arasan Chip Systems, the industry’s leading provider of IP for Mobile and Automobile SoC’s, announced today that its CAN XL IP has achieved the ASIL-D Certification. The CAN  XL IP has been independently certified by SGS-TÜV Saar as ASIL-D, the highest safety level of functional safety defined in ISO 26262, the international standard for functional safety in road vehicles.  

The CAN XL IP is backward compatible with the CAN FD and CAN 2.0 standards.  The ASIL-D certification also covers Arasan’s CAN FD IP and CAN 2.0 IP which will continue to be sold as ASIL-D certified independent products. 

Arasan is offering a free upgrade to its CAN XL IP for customers interested in licensing CAN FD until June 30, 2026. The gate count increase from CAN FD to CAN XL is minimal and customers are encouraged to leverage this promotion to adopt the latest version of the CAN Specification, CAN XL. 

“Arasan’s IP have been used extensively in mission critical and life endangering applications in defense, nuclear, aerospace, medical and automotive ADAS SoC’s ” said Ron Mabry, VP of Sales at Arasan. “The ASIL-D Certification attests to our fail safe design philosophy”.

Arasan’s has an extensive portfolio of ASIL-B, ASIL-C and ASIL-D certified products including the MIPI DSI-2 IP for Display, MIPI CSI-2 IP for Camera both of which are seamlessly integrated with the  MIPI D-PHY IP or the MIPI C-PHY IP, JEDEC eMMC IP for storage and UNH Certified automotive grade Ethernet IP when high speed automotive connectivity is required.

For more information, please visit: https://www.arasan.com/product/can-bus-controller-ip/

Availability

ASIL-D certified CAN IP products, including the CAN XL IP, CAN FD IP and CAN 2.0 IP, are available to license immediately from Arasan. Please contact sales@arasan.com to license our CAN IP.

Arasan Chip Systems, founded in 1995 is a provider of IP solutions for mobile storage and connectivity interfaces. Arasan’s focus lies in mobile SoCs, which have evolved to encompass a wide range of applications, from PDAs in the mid-’90s to today’s automobiles, drones, and IoT devices. Arasan remains at the forefront of this “Mobile” evolution, providing standards-based IP that forms the foundation of Mobile SoCs. Over a billion chips have been shipped with Arasan’s IP.

View original content:https://www.prnewswire.com/apac/news-releases/arasan-acheives-the-industrys-first-asil-d-certification-for-its-can-xl-ip-core-302746283.html

SOURCE Arasan Chip Systems, Inc.

Continue Reading

Trending