SquareX researchers Jeswin Mathai and Audrey Adeline will present data splicing attack techniques at BSides San Francisco 2025, bypassing major DLP vendors through browser vulnerabilities.
Data breaches can lead to IP loss, fines, and reputational damage, with browsers being a prime target due to the shift of data storage to the cloud.
Browser-related challenges include data lineage management, multiple SaaS apps, and unauthorized software installations by employees.
Data splicing attacks exploit newer browser features, evading traditional DLP solutions and posing serious threats to organizations using browsers.
SquareX will release an open-source toolkit, 'Angry Magpie', for testing DLP stacks against data splicing attacks after the BSides San Francisco presentation.
The research aims to raise awareness about browser vulnerabilities and prompt enterprises and vendors to enhance their data loss protection strategies.
Speakers Jeswin Mathai and Audrey Adeline will also present at RSAC 2025 and offer further insights at Booth S-2361, South Expo.
SquareX's Chief Architect Jeswin Mathai has a history of presenting at renowned cybersecurity events and creating popular open-source projects.
Researcher Audrey Adeline heads the Year of Browser Bugs project at SquareX, focusing on disclosing critical browser vulnerabilities.
SquareX's Browser Detection and Response (BDR) helps organizations defend against web attacks targeting employees in real-time.