The Latest


Photo: Bertrand Guay (Getty Images)

If you’re having second thoughts about your gym lately, maybe because of the recent swarm of resolution-havers, it might be time to call it quits—and find a new gym.

Of course, finding the right gym for you can feel a lot like a Goldilocks problem. One gym might seem too far, another might be too expensive, and your last option might seem perfect at first, up until the moment you witness the unhygienic state of its locker rooms. And then there are other gym-goers to consider!

Here’s an important step you should take before signing up for any gym: Always make an effort to visit a prospective gym during your usual workout hours. It’s simple enough advice, but when you take a tour of a gym on, say, a Saturday afternoon or any other time you aren’t ordinarily at the gym, it’s hard to gauge how busy it will be when you do work out.

Take my current gym; it’s empty on weekends, yet on a Tuesday at 6pm, you’d be lucky to stretch a limb and not accidentally hit someone in the face. Of course, having visited on a weekend, I was under the false impression that it would remain crowd-free throughout the week, and greatly regretted signing up so quickly.

To avoid a similar fate, ask for a guest pass that might allow you a chance to visit this gym at different times and on different days (and ideally, for at least a week). From experience, a guest pass is significantly better than opting into a trial period that some gyms offer (ie. Equinox); usually, you’re forced to give hand over your credit card to participate in a trial and if you decide not to sign up in the end, you must cancel before the period ends.

We all know just how difficult it is to cancel a gym membership, so try to circumvent this by obtaining a guest pass that doesn’t require your card. (And if they don’t offer a pass and you’re forced into a trial, well, here’s how to successfully cancel a membership. From experience, however, even crappy gyms will permit you at least one day to try out the facility.)

From this point, you can decide whether that gym is worth your money. Maybe at this prospective gym in question, the weekends are busy because of the number of personal trainers and their clients. Or maybe mornings are the worst for crowds. You won’t know if it’s the right gym for you unless you visit at just the right time.

What else should you consider before signing up? Well, that depends on your goals and personal preferences. Some people prefer a no-frills gym without the perks of a sauna or cavernous locker room. Others might sign up specifically because of those amenities. We’d suggest a few things, generally speaking:

  • If you work out at odd times, consider the gym’s operating hours.
  • If you’re a lifter, consider the number of squat racks available.
  • If you’re keen on getting in some cardio time, take a look at the state of its treadmills, bikes, and ellipticals.
  • If you’re into group classes, take a look at the gym’s calendar for its class offerings.

And lastly, price should be a huge determinant in your decision-making process. Do some research and look into other gyms in your area and their monthly fees to see if they’re comparable and let this inform your ultimate decision.

Of course, before signing up, you should also know there’s a negotiation process involved. Gyms want your business, after all, and they might extra incentives to get you in the doors (and to stay there). Here’s how to drive an effective bargain.


from Lifehacker https://ift.tt/2RClmFN

In summer 2019, hackers broke into over 40 (and possibly more) UN servers in offices in Geneva and Vienna and downloaded “sensitive data that could have far-reaching repercussions for staff, individuals, and organizations communicating with and doing business with the UN,” The New Humanitarian reported on Wednesday.

UN hacked

The UN, unfortunately, did not share that discovery with the authorities, the public, or even the potentially affected staff, and we now know about it only because TNH reporters got their hands on a confidential report by the UN.

How was the UN hacked?

According to the report, the attack started in July 2019, when the attackers managed to compromise a server located at the UN Office in Vienna through CVE-2019-0604, a security hole in Microsoft SharePoint patched by Microsoft in February 2019 and subsequently widely exploited by attackers to hit a variety of targets worldwide.

The hole should have been patched by the UN IT staff within a month of the release of the patch, but wasn’t.

The attackers then moved through UN’s networks and ultimately reached systems at the UN Office in Geneva and the UN Office of the High Commissioner for Human Rights (OHCHR), also in Geneva.

“The compromised servers included 33 in the UN Office at Geneva, three at OHCHR in Geneva, and at least four in the Vienna office,” TNH reported.

“According to the report, the breach also grabbed ‘active directories’, with each likely to list hundreds of users as well as human resources and health insurance systems, other databases, and network resources. The three affected offices have in total about 4,000 staff.”

The affected staff wasn’t notified that their data might have been compromised, but were just instructed to change their passwords.

The breach might not have happened if the SharePoint security vulnerability had been patched, but it’s possible and likely that the attackers would have found another way in.

After all, UN officials are targeted by attackers daily and some attacks are bound to be successful – especially when past security audits of UN systems, websites, applications, policies, etc. found them full of holes.

Why hasn’t the UN notified anyone about this?

The UN has confirmed that it had decided not to publicly disclose the breach because “the exact nature and scope of the incident could not be determined.”

As a matter of fact, the UN – as an international organization that is above national laws – does not have to report data breaches to anyone.

It is still unknown who’s behind the attack.

“In a tense geo-political climate, nation-state attacks are on the rise, and this comes as no surprise,” commented Craig Hinkley, CEO of WhiteHat Security.

“While security teams investigate which country may have launched this attack, our job as security professionals is to recognize that the threats are bigger than just one country. This is a global problem that we’re contending with, and staying ahead of nation-state attacks is fundamentally a matter of proactively taking steps and using vigilance to limit the impact of an attack.”

Oz Alashe, CEO of CybSafe, says that the unintentional disclosure of this cyber attack on such an important institution last year is concerning.

“This delay, and the fact that the UN did not report this attack to any governing authority – or even their own staff – may have put victims at unnecessary risk. Not only were staff passwords stolen, system controls and security firewalls were compromised too which could have led to the critical confidential reports falling into criminal hands,” he pointed out.

This attack could end up undermining trust in the UN – trust that they are able to keep sensitive information safe and trust that they will notify affected individuals when they fail.


from Help Net Security https://ift.tt/2RF41Mo

You’ve got two choices, employee: a) let us slide a syringe between your thumb and index finger so we can inject a rice-sized microchip into your hand that can be used as a swipe card to open doors, clock in, operate printers or buy junk out of the snack machine, or b) find another job.

An improbable scenario? Yes. It doesn’t happen – at least not if employees say no… For now. And the US state of Indiana wants to make sure it stays that way.

Last week, the state House of Representatives unanimously passed legislation – House Bill 1143 – stipulating that employers can’t force their employees to have an ID or tracking chip implanted in their bodies as a condition of employment. The bill passed the House 96-0 and is now heading to the Senate for consideration.

The bill’s sponsor, Rep. Alan Morrison, acknowledged that there aren’t any companies in Indiana – or anywhere, for that matter – currently forcing workers to be chipped if they want to keep their jobs, but there are businesses using the technology on a voluntary basis. As the Indiana Lawyer reports, Morrison said that he wants to be sure employers don’t “overstep their bounds” by imposing mandatory employee microchipping.

Privacy is an important thing. I don’t think there’s anything wrong with us being a little out in front of something.

Sure thing, said State Rep. Karlee Macer, who voted for the bill. On the other hand, we could spend our time legislating about issues that actually exist. NWI quoted her:

Think of the hundreds of bills that are sitting and waiting and never getting a hearing. There are a lot of important things we need to be doing in the state of Indiana.

But it’s so convenient!

There are at least two businesses that are using optional microchipping in their employees: Swedish startup hub Epicenter and Wisconsin-based Three Market Square.

At Epicenter, the injections have become so popular, they have parties for employees willing to undergo the procedure, as CNBC reported about three years ago (it’s been going on for years, in other words). It sounds kind of like a bris, except something gets added instead of snipped off.

CNBC quoted Patrick Mesterton, Epicenter’s co-founder and CEO, who said – while unlocking a nearby door by waving his hand at it – that it beats a bunch of pocket-stuffers:

The biggest benefit I think is convenience. It basically replaces a lot of things you have, other communication devices, whether it be credit cards or keys.

Mesterton said that even he had his doubts initially. The technology does raise security and privacy issues: the chips are safe biologically, but they generate data about how often employees come to work or what they buy. While you can stifle company swipe cards or mobile phones, it’s quite another prospect to rip a chip out of your flesh.

And as far as squeamishness goes, Mesterton compared the microchip to all the medical gadgets we’re putting in our bodies these days:

I mean, people have been implanting things into their body, like pacemakers and stuff to control your heart. That’s a way, way more serious thing than having a small chip that can actually communicate with devices.

For what it’s worth, Wisconsin-based Three Market Square also had a chipping party for willing employees back in August 2017. Their feedback: it was “just a little prick.”

According to the Chicago Tribune, officials said that the data in the microchip is encrypted and doesn’t use GPS, so it can’t be used to track employees or obtain their private information.

Hey, we’ve been microchipping our dogs and cats for years. What do you think, readers: ready to hold out your paws?


Latest Naked Security podcast

LISTEN NOW

Click-and-drag on the soundwaves below to skip to any point in the podcast.


from Naked Security https://ift.tt/36KdO8p

Cybertech Tel Aviv is one of the largest B2B networking events in the cyber industry, outside of the United States. Every year, the event attracts thousands of attendees, mainly C-level executives, investors, professionals, and government officials from all over the world.

Help Net Security is on-site this year, and here’s a look at the event.

Photos Cybertech Tel Aviv 2020

Cybertech Tel Aviv entrance

Photos Cybertech Tel Aviv 2020

Waterfall Security Solutions

Photos Cybertech Tel Aviv 2020

SecBI

Photos Cybertech Tel Aviv 2020

IBM Security

Photos Cybertech Tel Aviv 2020

Roee Laufer, Division Head, Cyber Security at Israel Airports Authority

Photos Cybertech Tel Aviv 2020

Perimeter 81, Q.Rity

Photos Cybertech Tel Aviv 2020

CyberArk

Photos Cybertech Tel Aviv 2020

Booths


from Help Net Security https://ift.tt/2GzCwh5

In March 2019, researchers with a group called Security Without Borders – a non-profit that often investigates threats against dissidents and human rights defenders – identified more than 20 government spyware apps squatting in plain sight, pretending to be harmless, vanilla apps on Google’s Play store.

Those apps – which were just a decoy through which government spyware called Exodus was installed on targets’ phones – were anything but harmless. In a two-stage process, they snorted up lists of installed apps, browsing history, contact lists from numerous apps, text messages – including encrypted texts – location data, and app and Wi-Fi passwords. The malware could also activate cameras and microphones to capture both audio and video, as well as take screenshots of apps as they were being used.

That spyware came from an Italian surveillance company called eSurv, and though it was good at hacking people’s phones, it stunk at securing its own data. The spyware opened up a remote command shell on infected phones, but it failed to use any sort of encryption or authentication, so that anyone on the same Wi-Fi network as an infected device could wander in and hack it.

But it was that shoddy security that’s led authorities to a stunning discovery: as Bloomberg reported earlier this month, eSurv employees have allegedly spied on unwitting, innocent Italian citizens with the powerful surveillance technology.

They allegedly did it with a lot of brass: according to court documents seen by Bloomberg: eSurv employees would play aloud secretly recorded phone conversations in the office. And while it was selling its spyware to law enforcement agencies, it also allegedly struck a deal with a company – ‘Ndrangheta – that’s said to be linked to the Mafia.

Unearthing the snooping apps

The man behind Exodus is Italian developer Diego Fasano. After successfully creating an app for doctors to view medical records, a friend told him that he should get into the surveillance business, where investigators have been clamoring for help in penetrating communications encrypted by messaging apps such as WhatsApp and Signal. In 2014, he founded eSurv, which sells surveillance technology to police and intelligence agencies.

How it worked: with the help of Italy’s telecoms, the company would dupe people into downloading what appeared to be an innocuous app that would ostensibly fix network errors on their phone. Fasano said that police, in cooperation with mobile phone networks, would shut down a targeted person’s data service. Next, they’d send instructions to use Wi-Fi to download an app to restore service. The app was designed to look like it was associated with telecom providers, with names such as “Operator Italia.”

The real purpose: to give law enforcement access to a device’s microphone, camera, stored files and encrypted messages. Fasano sold Exodus to prosecutors’ offices across the country, including to the country’s foreign intelligence agency, L’Agenzia Informazioni e Sicurezza Esterna.

A security blunder led to Exodus’s undoing, however. According to authorities, in 2018, a prosecutor’s office in the city of Benevento was using Exodus to hack the phones of suspects in an investigation. In October, a technician noticed that the network connection kept dropping out.

After doing some sleuthing, the tech found that Exodus wasn’t working off a secure internal server accessible only to the Benevento prosecutor’s office, as it was supposed to do. Rather, it was connecting to a server accessible to anyone on the internet, protected only by a username and password.

That meant that data covertly collected by Italian prosecutors from suspects’ phones in the course of some of the country’s most sensitive investigations – of Mafia cases, terrorist cases, and corruption cases – were at risk of interception by hackers. That included thousands of photos, recordings of conversations, private messages and emails, videos, and other files gathered from hacked phones and computers – a total of about 80 terabytes of data, or roughly 40,000 hours of HD video, stored in unencrypted form on what turned out to be an Amazon Web Services server in Oregon.

Authorities don’t know if that server was ever hacked.

Prosecutors filed criminal charges against eSurv for unlawfully collecting and storing private communications, transferring them overseas, and failing to keep secure “sensitive personal data of a judicial nature.”

Naples prosecutors expect the investigation to be completed later this year. Meanwhile, Fasano and another eSurv executive, Salvatore Ansani, have been charged with fraud, unauthorized access to a computer system, illicit interception and illicit data processing. Kept under house arrest for three months, they’ve been released and are now awaiting the next stage of their legal proceedings, which will likely result in a trial.

Further investigation found that a subset of eSurv’s 20 employees – devoted to working on Exodus and led by Ansani, they called themselves The Black Team – used the spyware to target law-abiding Italian citizens who were never named as suspects in investigations. Nonetheless, those citizens’ phones were bugged, and their private conversations were recorded, for reasons that authorities say are still unknown.

According to police documents, the Black Team spied on more than 230 people whom police weren’t authorized to surveil. Some of those people were referred to in eSurv’s internal files as “The Volunteers” – in other words, they may have been unwitting guinea pigs.

Investigators are still combing through the vast amount of data they seized from eSurv as they try to figure out the purpose for the illegal data collection. Was it intended for blackmail? For fun? For spying? For illegal surveillance on behalf of the Mafia?

At this point, one prosecutor – Eugenio Facciolla, who’s at the center of a corruption scandal – has been charged with forging documents in an effort to obstruct or mislead a police investigation into an ‘Ndrangheta-led illegal logging operation that involved chopping down thousands of trees in some of Italy’s national parks.

In November, the agency that handles prosecutor appointments said that it was removing Facciolla from his office in Castrovillari, on the grounds that he had “abused his functions.” Facciolla is appealing the decision. Yes, he says, he supplied Exodus to other companies, but, according to his lawyer, Vincenzo Ioppoli, the spyware is “like a gun.”

Once you have sold it, you don’t know how it will be used.


Latest Naked Security podcast

LISTEN NOW

Click-and-drag on the soundwaves below to skip to any point in the podcast.


from Naked Security https://ift.tt/2U7KplD

Adobe-owned Magento has plugged multiple critical vulnerabilities in its eponymous content management system, the most severe of which could be exploited by attackers to achieve arbitrary code execution.

Magento critical vulnerabilities

About the fixed vulnerabilities

According to the newest Magento-themed security bulletin (now published as an Adobe security bulletin), three of the six fixed flaws are critical and three are important.

In the “critical” category are a deserialization of untrusted data (CVE-2020-3716) and a security bypass (CVE-2020-3718) that could lead to arbitrary code execution, and an SQL injection (CVE-2020-3719) that could be exploited to leak sensitive information.

In the “important” category are two stored cross-site scripting flaws (CVE-2020-3715, CVE-2020-3758) and a path traversal (CVE-2020-3717) vulnerability, all of which could lead to sensitive information disclosure.

All of these have been patched in:

  • Magento Commerce versions 2.3.4 and 2.2.11
  • Magento Open Source versions 2.3.4 and 2.2.11
  • Magento Enterprise Edition (EE) version 1.14.4.4
  • Magento Community Edition (CE) version 1.9.4.4

At the moment, there is no indication that any of these might be actively exploited by attackers. Nevertheless, users/admins are advised to update their installations as soon as possible.

Magento shops are a major target

Magento is one of the most popular open-source e-commerce platforms out there, but web stores running it have unfortunately become a prime – though not exclusive – target for card-skimming cybercriminals (aka Magecart attackers).

Vulnerabilities in the Magento core are just one vector through which attackers can gain access to online shops to insert card-skimming code into them. Other avenues of attack include bugs in popular extensions and plug-ins, phishing emails lobbed at site admins, and compromise of third parties that serve scripts on the target site(s).


from Help Net Security https://ift.tt/2uNOjW5

If you’re an IT security professional, you’re almost certainly familiar with that sinking feeling you experience when presented with an overwhelming number of security issues to remediate. It’s enough to make you throw your hands up and wonder where to even begin.

prioritize IT security projects

This is the crux of the problem that develops in the absence of effective security prioritization. If you aren’t prioritizing cybersecurity risks effectively, you’re not only creating a lot of extra work for your team and yourself – you’re also needlessly exposing your organization to IT security attacks.

For better, faster and more robust protection, smart prioritization is an absolute must. Unfortunately, prevailing conditions in the IT space have long worked against this goal.

Why prioritization metrics are lacking

For many years, IT security attacks have been enabled by a haphazard approach toward prioritization. Here’s what we mean: IT security is highly complex and perpetually changing; given the extraordinary number of variables and the dynamic nature of the landscape, it’s difficult for security personnel to make optimal decisions – or to even understand the best processes for making those decisions.

Compounding this problem is the fact that prioritization metrics have historically been under-emphasized. Organizational security leaders are bombarded with marketing messages touting the virtues of one product over another, yet they receive much less assistance with the task of prioritization. Additionally, prioritization metrics are not uniform across the industry, so IT staff will often hear contradictory information.

Making this problem even more acute are the conventional challenges that accompany any IT security team. Resources are limited, decisions must be made about where to apply those resources, and team members are typically overworked and moving in a dozen directions.

How should IT teams prioritize risk?

The simplest way to implement an effective prioritization strategy is to develop a basic framework that can be followed and adjusted as needed. The following is one such example:

  • Risk identification.
  • You can’t prioritize effectively if you don’t understand what makes you vulnerable. Control risks, systemic risks, integration risks – all of these categories (and more) must be accounted for.

  • Risk assessment.
  • Once you’ve identified all potential risks, it’s time to assess the likelihood and probable impact of these risks. Risks that fall into the high likelihood, high probable impact bucket should obviously move to the front of the remediation list. It’s possible to define these risks in both qualitative and quantitative terms, and organizations often choose to create a ranking matrix based on a numerical scoring model.

  • Risk management.
  • With risks identified and assessed, the next step is developing processes to address existing vulnerabilities and protect against future risks. This may include more frequent training and improved IT hygiene, vulnerability scans, penetration testing etc.

Harnessing the power of automation for prioritization

The state of IT security has never been more precarious. Advanced Persistent Threats (APTs), often state-sponsored, can embed themselves in a security environment, move laterally, and steal an organization’s critical assets without being detected for months. Cloud migration – and the challenges of handling on prem/cloud risks in an integrated manner – has created new attack paths while greatly increasing the demands placed on modern organizational security teams.

These developments exacerbate the already tough mandate for IT security pros: they must be right every time, and the attackers need only be successful once. This doesn’t mean that hackers can operate with an entirely free hand; they, too, must pick and prioritize their spots. If your security is robust enough relative to other targets, attackers may judge it to be more trouble than it is worth, especially when there are so many other lightly guarded networks, devices, etc.

Automation is the critical weapon in this game of attack and defend, as it allows attackers to maximize their resources and probe for the most vulnerable targets at scale. For defenders, automation plays an equally essential role. IT security penetration testing does an excellent job of uncovering weak spots, yet it’s also highly manual and episodic. When you aren’t actively red teaming IT security, your environments are exposed. An automated solution – such as a modern Breach and Attack Simulation (BAS) platform – can help ensure 24/7, 365 security.

These automated solutions also come with another added benefit: they make effective prioritization simple in an industry that struggles with the practice. A fully automated BAS solution can identify all attack vectors can exploit and protect critical assets, whether on prem or in the cloud. These solutions work by launching controlled simulations that mimic the likeliest attack path hackers will take, making them an invaluable tool in APT IT security. Breach and attack simulations run continuously, using automation to provide non-stop protection. In essence, it’s like having a highly skilled red team that never takes a moment off.

Equally important, advanced BAS solutions offer prioritized remediation of security gaps. As we’ve seen above, this is a critical feature for today’s security teams, who are facing extraordinary challenges – and need all the help they can get.

The takeaway

Given the enormity of the threat posed by APTs, IT prioritization should be a key organizational mandate. By following the steps outlined above, you can put your security team in the best possible position to win.


from Help Net Security https://ift.tt/36Cm3Dd