Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

Elon Musk is serious about orbiting data centers

OpenAI launches a way for enterprises to build and manage AI agents

Anthropic releases Opus 4.6 with new “Agent Teams”

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » Squarex discloses browsers and native ransomware that put millions at risk
Tech

Squarex discloses browsers and native ransomware that put millions at risk

userBy userMarch 28, 2025No Comments4 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

Palo Alto, USA, March 28, 2025, Cybernaise Sweep

From Wannacry to MGM Resorts Hack, ransomware is one of the most harmful cyber threats that put businesses in the epidemic. Chainalysis estimates that businesses spend nearly $1 billion each year on ransom, but in many cases it costs more than a lot of money from reputational damage and operational disruptions from attacks.

Ransomware attacks usually involve victims suppressing ransomware downloads and installations. Ransomware copies, encrypts, and/or deletes important data on your device, but is only restored upon ransom payment. Traditionally, the main target for ransomware has been victim devices. However, thanks to the surge in cloud and SaaS services, devices no longer retain keys to the kingdom. Instead, browsers have become the primary way for employees to do their jobs and interact with the Internet. In other words, browsers are becoming new endpoints.

Squarex discloses major browser vulnerabilities such as polymorphism extensions and browser SyncJacking, and issues powerful warnings regarding the emergence of browser native ransomware.

Squarex founder Vivek Ramachandran said, “The recent surge in identity attacks in browser-based identity attacks seen in the Chrome Store Oauth Attack has led to the viewing of evidence that the “components” of browser-native ransomware is being used by enemies. Play an unquestionable and important role in protecting against traditional ransomware. The future of ransomware will no longer involve file downloads, making browsers and native solutions what they need to combat browsers and native ransomware. ”

Unlike traditional ransomware, browser native ransomware does not require file downloads and is therefore completely undiscoverable by endpoint security solutions. Rather, the attack takes advantage of the widespread shift towards cloud-based enterprise storage and the fact that browser-based authentication is the primary gateway for accessing these resources, targeting the digital identity of victims. In the case studies demonstrated by Squarex, these attacks leverage AI agents to automate most of the attack sequence, requiring minimal social engineering and interference from attackers.

One potential scenario involves social engineering to allow users to access fake productivity tools to email, allowing them to identify all SaaS applications on which the victim is registered. You can then systematically reset the passwords for these apps with an AI agent, log users out on their own, and keep the enterprise data stored in these applications.

Similarly, attackers can target file sharing services such as Google Drive, Dropbox, and OneDrive to use the victim’s identity to copy and delete all files stored under their account. Seriously, attackers can access all shared drives, including those shared by colleagues, customers, and other third parties. This greatly expands the attack surface of browsers and native ransomware. With the most traditional ransomware impact limited to a single device, there is only one employee mistake to ensure that attackers have full access to resources across the enterprise.

With fewer files downloaded, it is inevitable that attackers will trace where work and valuable data are created and stored. When browsers become new endpoints, it is important for businesses to rethink their browser’s security strategies. Just as EDR is important for protecting file-based ransomware, browser-native solutions with a deep understanding of client-side application layer identity attacks will become essential in the fight against next-generation ransomware attacks.

For more information about this security investigation, users can visit https://sqrx.com/browser-native-ransomware

About squarex

Squarex’s industry-first browser detection and response (BDR) solution helps organizations detect, mitigate, and threaten real-time client-side web attacks to users. In addition to browser ransomware, SquareX also protects against a variety of browser threats, including identity attacks, malicious extensions, advanced spears, Genai DLP, and insider threats.

Browser and native ransomware disclosures are part of the browser bugs project year. Each month, Squarex research team releases major web attacks focusing on limiting the architecture of browsers and current security solutions. Previously disclosed attacks include sync jacking and polymorphism extensions in the browser.

For more information about Squarex’s BDR, users can contact fund@sqrx.com.

For inquiries regarding this disclosure or reporting years of browser bugs, users can email junice@sqrx.com.

contact

PR manager
Junice Liew
squarex
junice@sqrx.com

Disclaimer: This is a paid press release published through CyberNewswire, a PR newswire syndication platform for cybersecurity businesses.

🚀Want to introduce the story?

Submit your stories to TechStartUps.com in front of thousands of founders, investors, PE companies, tech executives, decision makers and tech leaders.

Please attract attention


Source link

Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleCoffeeloader uses GPU-based armory packer to avoid EDR and antivirus detection
Next Article Google launches user-selection billing on Google Play in the UK
user
  • Website

Related Posts

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

December 10, 2025

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

November 26, 2025

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

November 25, 2025
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Elon Musk is serious about orbiting data centers

OpenAI launches a way for enterprises to build and manage AI agents

Anthropic releases Opus 4.6 with new “Agent Teams”

AISURU/Kimwolf botnet launches record 31.4 Tbps DDoS attack

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2026 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.