The Latest

Photo: BlueOrange Studio (Shutterstock)

My mother never cared for cheap Easter candy, but she loved to eat the dyed eggs. As a child, this shocked and perplexed me, and not just because I preferred chocolate. It simply did not seem sanitary to me, the child who had found the eggs and picked them up with her sticky little child hands. But Easter eggs can be safe to consume, as long as you time it right.

The window for eating a room-temperature hard-boiled egg is two hours, which leaves you plenty of time to decorate—but people don’t usually boil eggs, decorate them, and immediately hide and hunt for them. At least in my childhood home, eggs were cooked and decorated the day before, then stored in the fridge until Easter morning, at which point my parents would hide them.

This is where things get a little complicated. According to the USDA, the safety of the eggs hinges on where you hide them, how quickly they’re found, and how gently they’re handled:

Hunting Eggs: We do not recommend using hard cooked eggs that have been lying on the ground, because they can pick up bacteria, especially if the shells are cracked. If the shells crack, bacteria could contaminate the inside. Eggs should be hidden in places that are protected from dirt, moisture, pets, and other sources of bacteria. The total time for hiding and hunting eggs should not exceed 2 hours. The “found” eggs must be washed, re-refrigerated and eaten within 7 days of cooking.

G/O Media may get a commission

In addition to hiding eggs in fairly clean spots, washing them, and discarding any that are cracked, make sure you use a food-safe dye—or use actual food to dye them—if you plan to snack on the found eggs. Or you can just use those plastic eggs, put candy inside them, and eat the candy instead. You’ve got a lot of good options, is what I’m saying.


from Lifehacker https://ift.tt/2OgI87k

Two vulnerabilities (CVE-2021-21975, CVE-2021-21983) recently patched by VMware in its vRealize Operations platform can be chained together to achieve unauthenticated remote code execution (RCE) on the underlying operating system, Positive Technologies researchers have found.

VMware vRealize Operations RCE

There is no PoC currently available and no mention of the vulnerabilities being exploited in the wild. Nevertheless, administrators are advised to implement provided security patches or temporary workarounds as soon as possible.

VMware vRealize Operations vulnerabilities could lead to RCE

VMware vRealize Operations is a unified, AI-powered platform for IT operations management for private, hybrid, and multi-cloud environments. It is available on premises and as SaaS.

Both vulnerabilities are in the vRealize Operations Manager API.

CVE-2021-21975 is a Server Side Request Forgery (SSRF) flaw that could be exploited remotely by an unauthenticated attacker to steal administrative credentials, and CVE-2021-21983 is an arbitrary file write vulnerability that could allow an authenticated remote attacker to write files to arbitrary locations on the underlying operating system.

They have been deemed to be high-risk, but chained together they can lead to unauthenticated remote code execution.

The vulnerabilities are present in vRealize Operations Manager 7.5.0, 8.0.1, 8.0.0, 8.1.1, 8.1.0, 8.2.0, and 8.3.0, and also impact VMware Cloud Foundation versions 3.x and 4.x and vRealize Suite Lifecycle Manager v8.x.

Security updates

Security updates are available and so are workarounds, which don’t have an impact on the system’s functionality.

Security researcher Egor Dimitrenko of Positive Technologies has been credited with discovering and reporting the vulnerabilities to VMware.


from Help Net Security https://ift.tt/3cDnFTo
Latest episode - listen now!
from Naked Security https://ift.tt/3sHyI3H

Shopping or booking an appointment online can seem increasingly like busywork. Please prove that you’re not a bot: select all the photos that show traffic lights. Do some light arithmetic. Squint and retype these increasingly indecipherable letters (“Is that a lowercase H or a lowercase B?”).

get around CAPTCHA

With over half of web traffic automated, it’s increasingly important for businesses to tell which of their online visitors are real and which are bots. Not every bot that visits a website is there to cause trouble, but many are—scraping the content, trying to buy limited-edition goods before genuine customers can, or using card gateways to check if stolen credit card details are still valid. Even those bots that aren’t bad actors can cause problems when businesses use web analytics skewed by bots to make decisions.

CAPTCHAs are the most visible technique used by online businesses to differentiate between real customers and bots. Unfortunately, it’s a technology that’s under threat from a very old technology: outsourced manual labor.

The economics of CAPTCHA farms

If you are a bot operator and are faced with the problem of small repetitive tasks getting in the way of making serious money, then you have a couple of choices. One is to seek out or even build a bot that is capable of solving these CAPTCHAs, continuing the ongoing arms race. The other is to hire humans to solve tasks designed to be solved by humans.

CAPTCHA farms have been around for over a decade, pretty much since CAPTCHAs first became a way to protect against bots. CAPTCHA requests will be sent from the bot to the farm through an API, and at the other end a human will be available to solve the test.

It’s important to understand that these farms are not small organizations operating in shabby basements. They are established, well-run businesses akin to contact centers, with full employee training. They do, however, rely on inequality to thrive, as it is only lucrative when they are based in emerging markets and are, effectively, a digital sweatshop.

At the time of our most recent research, we found that employees earn around $0.18 for every 1,000 CAPTCHAs solved. Bot operators buy these services at around $0.94 for every 1,000 solved. This is a business model where the employees are doing lots of repetitive work for very little, and where bot operators are by comparison paying pennies to have their CAPTCHA problem solved. The farm owners need to operate at scale to be profitable—and they do.

The end result is that bot operators can see CAPTCHA as more of a speed bump than a barrier to achieving their aim.

An arms race with multiple weapons

Businesses and bots are in an escalating battle—but there are two fronts. As bots get more sophisticated, so do the techniques to identify and prevent bot attacks. And as bots get less effective, work will go into making them circumvent the new barriers erected to slow them down.

At the same time, businesses will rely on CAPTCHA to try and block bots – but when this becomes too much for bots to handle, outsourced labor will solve the problem.

Businesses are not helpless in the face of CAPTCHA farms, though admittedly it can seem like they are facing an impossible task. If bot operators can pose as ordinary users simply by spending some money, can they really be stopped at all? The answer lies in asking a new question. Businesses should still ask of their visitors “Is this a bot or a human?” but also ask “What does this visitor intend to do?”

All users, whether real or human, provide far more signals that can be analyzed than whether or not they have passed a CAPTCHA test. Where did they arrive from? How did they navigate through the site? What are they using to access the site? Is their behavior truly human-like, or simply trying to mimic that of a human?

For example, one way to mitigate against bots is rate-limiting, simply setting a maximum number of requests that a visitor can make in a certain amount of time. Sophisticated bots will figure out this limit and stay just below it, in a very inhuman way.

Analysis of behaviors like these will be key to sifting out the bad actors from the genuine users in the future. CAPTCHA will still have a place, but it’s important to remember that it will only deter those unwilling to spend a few extra pennies.


from Help Net Security https://ift.tt/3doPez1

Before the pandemic, most modern organizations had recognized the need to innovate to support developers’ evolving workflows.

CI/CD pipelines

Today, rapid digitalization has placed a significant burden on software developers supporting remote business operations. Developers are facing continuous pressure to push out software at high velocity. As a result, security is continuously overlooked, as it doesn’t fit into existing development workflows.

The way we build software is increasingly automated and integrated. CI/CD pipelines have become the backbone of modern DevOps environments and a crucial component of most software companies’ operations. CI/CD has the ability to automate secure software development with scheduled updates and built-in security checks.

Developers can build code, run tests, and deploy new versions of software swiftly and securely. While this approach is efficient, major data breaches have demonstrated a significant and growing risk to the CI/CD pipeline in recent months.

Theoretical threats are becoming reality

Despite increasing awareness around the need for securing code, securing the software build processes is often an afterthought. But high-profile supply chain attacks over the past year and a 430% surge in such attacks overall have underscored just how vulnerable software supply chains can be. Just recently, the UK’s National Cyber Security Center (NCSC) issued a warning about software build pipelines.

Organizations must be mindful of insider actors with access to source code. Verizon’s 2020 Data Breach Investigations Report found that one-third of data breaches originate from insider actors. These insider actors can include privileged IT administrators, disgruntled former employees, and managerial employees with the ability to commit code without review.

Malicious or not, insider threat is a tremendous risk to organizations’ overall security. 79% of security leaders worry that now, with remote work, users are more likely than ever to ignore security policies, thus making the organization more vulnerable to threats.

Another significant threat to the software supply chain is unpatched vulnerabilities in code. Attackers search for vulnerabilities in open-source code that they can use to attack any application that relies on that code. This is a considerable concern, as 99% of organizations use some open-source code in their software, and 91% of codebases contain components that were out of date or that had not seen developer attention in years.

Taking steps to CI/CD security

Supply chain attacks are growing in scale and frequency at an alarming rate. Organizations must consider the security of their CI/CD pipelines in addition to the security of their code. By hardening CI/CD pipelines and addressing security early in the development process, developers can deliver software faster and more securely.

It is crucial to maintain builds’ independence from one another to ensure that in the case of a compromise, uncompromised builds are not impacted by the affected ones. Organizations must conduct security checks frequently and make sure that the software shipped is the software developed. By inserting insider attack detection into the software supply chain, organizations can establish non-repudiation of the software shipped at every stage, eliminating the blind spot around the risk of software consumption that exists today.

Developers must secure pipelines by locking repository host systems, configuration managers, and build servers. Additionally, organizations should audit pipeline tools and repository access at random and make regular updates to limit potential internal or external threats. Builds should be scanned while the code is still fresh in the developer’s mind to guarantee any vulnerabilities found are quickly remediated before an application is off to production.

Organizations must maintain comprehensive visibility across various services to accurately identify anomalies and determine if an insider attack has occurred. This ensures they know what and where to monitor within their unique application architecture moving forward.


from Help Net Security https://ift.tt/3ufmHCG

(ISC)² has published the results of an online survey of 303 cybersecurity professionals from around the globe in which respondents compared their perception of the severity of the SolarWinds Orion software breach between when it was first reported and several weeks later as more information was revealed.

SolarWinds perception

Respondents also relayed how the breach has impacted their jobs, recommended changes to organizational security practices and provided lessons learned.

The survey seeks to shed light on the complexities of supply chain security by gathering insights directly from cybersecurity practitioners who most often are responsible for mitigating the risk of third party security stacks in their organizations.

An increase in SolarWinds incident severity perception

86% of respondents said they would have rated the breach “very” or “extremely severe” when they first learned about it. However, roughly six weeks after the incident was reported, as more details emerged, the number of respondents who indicated that the breach was “severe” increased from 51% to 55%.

On a scale from 1 to 5, the perception of the severity of the breach also increased over time, from an average of 4.34 initially up to 4.37.

SolarWinds perception

Prompting reviews of security tools and protocols

The incident has prompted reviews of security tools and protocols by many cybersecurity teams. Cybersecurity professionals said they have stepped up activities such as forensic analyses, re-architecting of systems, and making sure all patches are up to date.

Many respondents reported getting questions from their executive teams about their own security protocols, prompting time-consuming due diligence and reporting activities.


from Help Net Security https://ift.tt/2PmzOmQ

Transmit Security has released a state of customer authentication report that includes customer experience insights based on its survey of 600 U.S. consumers. According to the report findings, organizations are losing potential customers and a substantial amount of revenue due to their dependency on traditional password systems and outdated customer authentication models.

password systems

Challenges connected to password-sharing habits

The report also underscores the challenges connected to password-sharing habits. More than 50% of the survey participants admit they have shared a password to, at least, one of their online accounts with someone else and 41% say they share their passwords often.

Not only does password-sharing pose a severe security risk, it impacts businesses in a number of ways, from the amount of revenue they’re able to generate to their ability to monitor usage and personalize services.

Traditional passwords also significantly impact customer experiences. The report revealed 55% of consumers have stopped using a website because the login process was too complex, and that 87.5% of consumers have found themselves locked out of an online account after too many failed login attempts. Worse, 92% of users will leave a website instead of recovering or resetting their login credentials.

Complicated, error-ridden password systems

In fact, for most customers the problems with passwords begin long before a failure. Data shows that 66% of users will leave a website if the registration process is too complex. And 64.5% will abandon the site if they are simply asked to create a username and login.

“The number of consumers getting blocked from their online accounts because of poor password experiences is staggering. Customers are dropping out of transaction processes – or failing to use a site at all – due to overly complicated, and oftentimes error-ridden, password systems,” says Transmit Security CEO Mickey Boodaei.

password systems

“These horrible customer experiences are costing businesses an unimaginable amount of money, not to mention the revenue that’s lost due to password-sharing between consumers. The market is ready for change. It’s time to eliminate our dependency on outdated password technology and evolve to a place where passwords are no longer necessary.”


from Help Net Security https://ift.tt/3rFXQX5