Category: News

Slack ads AI to increase productivity and crush information overload: Hashtag Trending, Thursday, February 15, 2024

Slack adds AI features to combat information overload, Akamai bets on edge computing to compete with the giant public cloud players. Google uses AI to launch a devastating attack on fake reviews, an update on our Mozilla story and AI is used to have the voices of victims lobbying legislators.

All this and more on this “sometimes the good guys win using AI” edition of Hashtag Trending. I’m your host Jim Love, CIO of IT World Canada and TechNewsDay in the US.

Slack has introduced a suite of AI-powered tools aimed at streamlining communication and information management for its users. Announced on Wednesday, these features are designed to help both new and overwhelmed employees by summarizing threads and providing recaps of channel activities.

Slack’s new AI capabilities include summarizing long discussion threads and offering recaps of what has transpired in channels over a specified period. This is particularly beneficial for catching up on unread messages, making it easier for employees returning from vacations or parental leave to stay informed.

The platform will now utilize AI to respond to search queries with answers drawn from accessible messages and channels, enhancing the search experience with more intuitive and relevant results.

Slack has taken a different approach to pricing. Microsoft’s Copilot, bills for users who opt-in to the service, but Slack will required an additional monthly fee for all users within a company to access these AI features, a move that could challenge organizations looking to evaluate the benefits before a full-scale implementation.

Slack promises competitive pricing, although specific rates will vary based on customer size.

Early reports from users indicate a significant time saving, with an average of 95 minutes per week reclaimed through the use of these AI features.

There’s an added benefit in that applications like this may to unlock years of institutional knowledge, transforming how businesses communicate and manage information internally.

But leveraging AI tools raises privacy and security concerns, especially regarding the handling of sensitive business data and channel permissions. Slack assures that AI will not access information beyond a worker’s permitted channels, but the broader implications for data privacy remain a critical consideration.

Sources include: Axios

Akamai Technologies is ramping up its infrastructure with a significant emphasis on edge computing to challenge the dominance of cloud giants like AWS, Azure, and Google Cloud by leveraging Akamai’s extensive content delivery network (CDN) to integrate cloud computing capabilities directly at the edge.

Akamai has announced ambitious plans to establish 25 new edge locations by the end of the month, aiming for 100 by year’s end, and scaling to thousands in the forthcoming years. By bringing computing closer to customers, Akamai aims to enhance performance, and reduce latency.

Dubbed as generalised edge compute or Gecko, Akamai’s strategy blends cloud and edge computing. They hope this will bring substantial advantages in terms of price performance, security, and reduced latency.

To bolster its edge computing capabilities, Akamai has acquired Linode, an infrastructure-as-a-service (IaaS) platform, for approximately $900 million in 2022. Additionally, Akamai is forging strategic partnerships with telcos, IT solutions, and local cloud service providers worldwide.

 

Akamai’s pivot to edge computing represents a significant shift from traditional cloud computing models, which are predominantly centralized. By decentralizing computing resources and placing them closer to end-users, Akamai aims to address the growing demand for low-latency and high-security applications. However, this transition poses challenges, particularly in migrating workloads from existing cloud services, which has prompted Akamai to present this as a multi-cloud solution.

As Akamai continues to expand its edge computing infrastructure, the company is set to embark on the next phases of its Gecko platform, which will include incorporating containers and automated workload orchestration. This evolution reflects a broader industry trend towards leveraging edge computing to meet the demands of the next generation of internet applications, including those powered by generative AI.

Who knows if this strategy will be effective against the cloud giants, but it does create what everyone calls a “unique value proposition.”

 

Sources include: Analytics India Magazine

We talk a lot about AI creating fake content, but it can also be used to combat fake content.

Google has implemented a new machine learning algorithm that has dramatically increased the efficiency of detecting fake reviews on Maps and Search. This advancement led to the removal of over 170 million fake reviews in 2023, a big victory for the integrity of user-contributed content.

Google’s new algorithm is designed to identify suspicious review patterns more rapidly, including the detection of repeated content across multiple businesses or unusual spikes in ratings. This system scrutinizes reviews before publication and continuously monitors for questionable activity.

The implementation of this machine learning technology resulted in a 45% increase in the removal of fake reviews compared to the previous year, as mentioned with a 170 million reviews being deleted for policy violations. Additionally, Google identified and removed 12 million fake business profiles and doubled the removal of policy-violating videos to 14 million in 2023.

Google has taken legal measures against individuals attempting to manipulate its review system. One notable lawsuit was filed against a scammer responsible for creating over 350 fraudulent business profiles and attempting to enhance them with more than 14,000 fake reviews.

The ongoing battle against fake reviews presents continuous challenges, but just like in the old westerns – sometimes the good guys win.

Sources include: TechSpot

In a notable legal development, a US district judge in California has predominantly sided with OpenAI, dismissing the bulk of copyright infringement claims filed by authors against the AI company. The authors had accused OpenAI’s ChatGPT of being trained on pirated copies of their books without permission, labeling the chatbot’s outputs as a form of high-tech “grift” that infringed on copyright laws and other related statutes.

The court dismissed several claims, the only claim that was not dismissed pertains to direct copyright infringement. OpenAI had previously expressed confidence in defeating this claim at a later stage of the proceedings.

The authors have been ordered to consolidate their complaints and may amend their arguments to continue pursuing the dismissed claims.

 

Sources include: Ars Technica

And in an update to our story on Mozilla, a number of you wrote to me expressing sadness for what has happened to Firefox.

As if they had heard this collective sigh, the company has announced a strategic shift to focus more on its core product, Firefox, and the integration of trustworthy AI technologies. This pivot comes with the decision to scale back investment in several products, including its VPN, Relay, and Online Footprint Scrubber, and to shut down Hubs, its 3D virtual world launched in 2018. Additionally, Mozilla will scale back its investment in its mozilla.social Mastodon instance. These changes will result in the layoff of approximately 60 employees.

Mozilla aims to enhance Firefox by integrating trustworthy AI, leveraging the teams working on Pocket, Content, and AI/ML.

They plans to reduce investments in several products, including VPN, Relay, and Online Footprint Scrubber, and will shut down Hubs.

And sadly, approximately 60 employees will be affected by the layoffs as Mozilla aims to optimize its organizational structure.

 

By refocusing on Firefox and AI, Mozilla is betting on its strengths and the growing importance of AI in enhancing user experiences.

This move is likely to please long-time Firefox enthusiasts and could position Mozilla as a key player in the development of AI-enhanced browsing experiences. However, the layoffs and product discontinuations underscore the tough choices the company must make to stay competitive.

Sources include: TechCrunch

In a poignant campaign launched on the sixth anniversary of the Parkland shooting, families of gun violence victims are using artificial intelligence to bring the voices of their lost loved ones back to life. These AI-generated voices are being used to call federal lawmakers who oppose tighter gun regulations, urging them to reconsider their stance.

The campaign utilizes artificial intelligence to recreate the voices of victims. These voices are robocalling senators and House members who support the National Rifle Association (NRA) and oppose tougher gun laws.

I have to say, I’m not sure at the time of going to air how they are getting around the recent regulations that make using AI in robocalls illegal.

But it is a powerful way to get their message across.

The choice of Valentine’s Day for the campaign’s launch is symbolic, marking the anniversary of the Parkland shooting that claimed 17 lives, including students and staff members.

The campaign reflects a broader trend of leveraging technology for activism and social change. As AI technology becomes more accessible and sophisticated, it’s likely that we’ll see more creative and impactful uses in various advocacy efforts.

Sources include: AP News

Hashtag Trending goes to air five days a week with daily newscast and a weekend interview show that we creatively called – the weekend edition.

We love to hear from you. Send us a note at jlove@itwc.ca or drop us a comment under the show notes at itworldcanada.com/podcasts – look for Hashtag Trending.

Thanks for listening and have a Thrilling Thursday.

 

 

 

 

 

 

 

 

The post Slack ads AI to increase productivity and crush information overload: Hashtag Trending, Thursday, February 15, 2024 first appeared on IT World Canada.

Breaking news: Cisco to cut roughly 4,250 from its payroll

Cisco late this afternoon released its second quarter results, as well as announcing a reduction of its payroll by five per cent, which in terms of head count means an estimated 4,250  employees will be receiving termination notices.

According to a Reuters report, the company “lowered its annual revenue target as (it) navigates a tough economy that has led to thousands of layoffs by tech firms this year. Shares of the networking equipment maker fell more than five per cent in extended trading on Wednesday after Cisco cut the forecast to US$51.5 billion to US$52.5 billion, from US$53.8 billion to US$55 billion that it projected earlier.”

The company, according to the report, “will incur a charge of US$800 million on the layoffs, before tax, consisting of severance and other costs.”

A release issued by Cisco this afternoon stated that the company reported second quarter revenue of US$12.8 billion, net income on a generally accepted accounting principles (GAAP) basis of US$2.6 billion or US$0.65 per share, and non-GAAP net income of US$3.5 billion or US$0.87 a share.

During an earnings call, company chair and chief executive officer (CEO) Chuck Robbins said that there were three factors impacting what he described as the “demand environment,” which ultimately led to the decision to reduce staff.

“First, in terms of the macro environment, we’re seeing a greater degree of caution and scrutiny of deals given the high level of uncertainty,” he said. “As we’re hearing this from our customers, it’s leading us to be more cautious with our forecast and expectations.

“Second, as we discussed last quarter, and subsequently saw in other technology provider results, customers have been taking time since the start of our fiscal 2024 to deploy the elevated levels of products shipped to them in recent quarters, and this has taken longer than our initial expectations.

“Third, we also continue to see weak demand with our telco and cable service provider customers. This industry has seen significant pressure, and they are adjusting deployment phasing, which is weighing on our business outlook. Given these factors, we’re adjusting our expenses and investments to reflect the current environment.”

The post Breaking news: Cisco to cut roughly 4,250 from its payroll first appeared on IT World Canada.

EY Canada, Microsoft launch climate stress testing initiative for FIs

Consulting and accounting firm EY Canada today launched the EY Climate Stress Testing and Scenario Analysis solution, a service running on Microsoft Azure which it said is designed to help safeguard Canada’s financial sector against the impacts of climate change.

Mario Schlener, EY Canada risk consulting leader, said a key reason for the system’s development is that “our clients recognize the need for reliable systems to effectively manage and report environmental, social, and governance (ESG) data, but finding such systems proves challenging.”

The initiative, according to a release, “combines data analytics, artificial intelligence (AI), cloud technology and top-tier risk models to further Canada’s transition to a low-carbon economy.”

The release went on to say that “disclosure requirements established by the Office of the Superintendent of Financial Institutions (OSFI), along with regulations imposed by other global authorities, are compelling financial institutions to prioritize climate reporting and transparency.

“Through collaboration with the Canadian financial services sector, this solution not only evaluates the impact of transition risk across various sectors of the economy, but also provides valuable insights to assist financial institutions in strategizing for client engagement initiatives and refining their decarbonization strategies based on scenario results.”

Katerina Kindyni, financial institutions sustainability leader with EY Canada, said, “operational readiness, resource constraints, and the evolving regulatory landscape pose significant challenges to the seamless execution of climate scenario analysis and stress testing programs.”

The new initiative, she said, is a “centralized tool that enables FIs (financial institutions) to efficiently identify, measure and monitor risks associated with the transition to a net-zero economy, while seamlessly integrating market intelligence into an organization’s infrastructure.”

According to the release, the tool covers three key areas:

Loan portfolio assessment: Helps financial institutions evaluate the transition risk of their loan portfolio by leveraging a spectrum of Network for Greening the Financial System (NGFS) scenarios. It also performs sector-specific modeling of transition risk and estimates the financial impact across the balance sheet, as well as income and cash flow statements of counterparties.
Risk assessment: The solution is configured with a climate risk management module that measures the impact on key risk metrics such as Probability of Default (PD), Rating Migrations (RM), and Capital Adequacy Ratio (CAR). It also evaluates the impact of transition risk on the portfolio and provides valuable insights that inform overall decarbonization strategies and mitigation actions.
Long-term growth enablement: Addresses an organization’s core capacity and capability gaps from a continuous improvement perspective. This allows clients to identify themes, track progress against goals, and identify market opportunities, while minimizing downside risk from carbon intensive sectors.

Jacqueline O’Flanagan, Microsoft Canada’s financial services industry lead, said the company is “dedicated to promoting sustainability in financial services through our cloud, data, and AI (offerings) that address ESG priorities.

“By joining forces with EY to address regulatory compliance needs, we’re accelerating and magnifying our impact and commitment to advancing innovation in climate technology.”

The post EY Canada, Microsoft launch climate stress testing initiative for FIs first appeared on IT World Canada.

NRC announces funding for quantum collaborations

The National Research Council of Canada (NRC) today announced that 11 Canadian companies have been selected to receive funding to collaborate on projects with partners in the U.K., following a joint Canada-U.K. call for proposals by the NRC and UK Research and Innovation (UKRI).

The projects, NRC said in a release, “focus on developing real-world quantum technologies for commercial use in networking, sensing and scalable solutions to quantum computing as well as developing the supply chain.”

“Government and businesses in the United Kingdom and Canada alike share a vision to develop resilient quantum ready economies for realizing better industry and social welfare outcomes,” said Abhinav Sharma, lead, Quantum Industry Fund, Innovate UK.

“This joint funding program between UKRI and the National Research Council of Canada is creating very promising partnerships which will greatly help to advance talent and technology value in the supply chain for many industries.”

The NRC is providing advisory services and research and development funding up to $5.1 million through the Industrial Research Assistance Program (NRC IRAP) and the Collaborative Science, Technology and Innovation Program (CSTIP) to support the projects.

CSTIP funding was provided under the NRC’s Quantum Sensors Challenge program, which “seeks to develop revolutionary sensors that could be engineered and commercialized for applications in the environment, natural resources, health care, and defence.”

“The NRC is excited to partner with UK Research and Innovation to stimulate co-innovation between small and medium-sized enterprises in Canada and the United Kingdom,” said Mitch Davies, president, National Research Council of Canada. “These collaborative projects allow us to leverage leading capabilities in our countries to drive quantum technology development and commercialization. We go farther and faster when we work together”

Three companies in Ontario, four in Quebec, three in B.C., and one in Alberta will benefit from the funding, receiving amounts ranging from up to $144,000 to up to almost $700,000, according to a release.

“Building partnerships between companies in Canada and the United Kingdom is a great way to capitalize on our shared strengths,” said François-Philippe Champagne, minister of innovation, science and industry. “By investing in our innovative Canadian companies that are working to turn quantum science and research into commercial innovations, we’re helping create new jobs and drive economic growth while positioning Canada as a leader in the rapidly evolving landscape of quantum technology.”

The post NRC announces funding for quantum collaborations first appeared on IT World Canada.

Security priorities for 2024: Skills development, AI and more, says report

Developing and optimizing cybersecurity staff has been listed by a research firm as the top security priority for organizations over the next 12 months for the second year in a row.

The recommendation came in the release this week of Info-Tech Research Group’s Security Priorities 2024 report.

The five priorities were chosen from a combination of the results of surveys and interviews with leaders, plus Info-Tech Research’s decisions.

The other priorities that management, IT, and infosec leaders should set this year are:

— securing the AI revolution;

— embedding security risk management with the enterprise;

— putting a zero trust strategy into operation;

— and automating security processes.

The choice to make talent development and hiring the number one priority should come as no surprise. It topped the cybersecurity concerns named by 573 leaders surveyed last year — the third year in a row it led the survey.

This year it was closely followed by the rising cost and high requirements of cyber insurance, vulnerabilities in the IT systems of suppliers and executives or boards not sufficiently aware of cyber risks.

“Security leaders still emphasize the priority of spending on training and development, but there’s still a shortage of workers in the industry,” Ahmad Jowhar, lead analyst for the report, said in an interview.

“Investing in your employees will yield long-term cost savings.”

The report concedes that there has been some progress for organizations in finding the right security talent. However, it adds, “the constant concern indicates the need for an innovative approach that organizations should adopt to assist in mitigating the talent shortage gap.”

The right talent could be closer than you think, the report notes, Many organizations have employees whose skills and interests equip them to be developed into cybersecurity professionals.

The report points out that a recent survey of more than 14,000 infosec pros by ISC2 (the International Information System Security Certification Consortium) found 52 per cent of respondents said they began their careers in a non-cybersecurity IT position.

“This indicates an opportunity to leverage those transferable skills in a security role, which would enable organizations to stay competitive while also enabling continuous personal development for their employees,” the report says.

The report estimates 58 per cent of worker shortages can be mitigated by upskilling competency gaps.

To help with the talent shortage the report says organizations should:

• define the competencies needed to support the security program;

• assess employees’ current proficiency levels across defined competencies;

• prioritize competencies against known organizational priorities;

• acquire competencies through available learning and development tools and resources;

• and enable continuous improvement of employee proficiency by periodically reviewing competency gaps.

Asked why some organizations may not yet have a zero-trust strategy although the approach is several years old, Jowhar said these firms may feel a lot of work is needed to make the concept reality. That’s why Info-Tech recommends IT leaders break up the work into four manageable chunks, he said.

The purpose of the report is to give organizations a high-level idea of where their security investments should go this year, Jowhar said.

Infosec leaders could also take the recommendations to their stakeholders to either obtain some buy-in or give them an idea of what an advisory firm says should be their priorities, he added.

The full report is available here Registration is required.

The post Security priorities for 2024: Skills development, AI and more, says report first appeared on IT World Canada.

Cyber Security Today, Feb. 14, 2024 – Get cracking on Patch Tuesday security fixes

Get cracking on Patch Tuesday security fixes.

Welcome to Cyber Security Today. It’s Wednesday, February 14th, 2024. I’m Howard Solomon, contributing reporter on cybersecurity for ITWorldCanada.com and TechNewsday.com in the U.S.

 



 

Yesterday was Microsoft’s Patch Tuesday for February. Patches for 80 vulnerabilities were released, including five critical ones. And of those, two are being exploited right now. One of the critical holes is in Microsoft Exchange Server and allows an escalation of privileges. The second is in Microsoft Outlook and allows an attacker to bypass the Office Protected View and open a document in editing mode rather than protected mode. The vulnerabilities being currently exploited are in Windows.

According to researchers at Trend Micro, one of them is being used by a group it calls Water Hydra. Other researchers call it DarkCasino. The group uses the vulnerability to bypass Microsoft Defender SmartScreen to infect victims with the DarkMe malware. Typical targets of this group are banks, foreign currency exchanges, stock trading platforms, online casinos and cryptocurrency platforms.

Also releasing security patches was Adobe. They close critical holes in Acrobat and Acrobat Reader, Adobe Commerce, Magento Open Source, Substance 3D Painter and FrameMaker.

Siemens published 15 security advisories for its industrial products. According to SecurityWeek they cover 270 vulnerabilities. More than half of them are in models of Scalance switches.

It’s not been a good month for insurers so far. Insurance provider Prudential Financial says it suffered a breach of security controls last week. In a filing with the U.S. Securities and Exchange Commission the company said the attacker accessed company administrative and user data, including information on employees and contractors.

And the Canadian branch of a French global insurance brokerage suffered a cybersecurity incident. According to CBC News, MSH International Canada detected the attack February 9th. Among its customers is the Public Service Health Care Plan, which offers extra health coverage to Canadian federal employees, including members of Parliament and judges.

All hospitals in Romania unplugged from the internet at the beginning of the week after 21 institutions were hit by ransomware over the weekend. According to the country’s cyber directorate, the attacks started being discovered on Saturday. The malware is a strain of the Phobos ransomware family. Most of the affected hospitals have data backups, the government says.

ExpressVPN has temporarily stopped the ability of administrators to enable split tunneling, or running multiple VPNs at a time. This affects the Windows version of the app. Split tunneling will remain disabled until a vulnerability is fixed. The problem began with a version of the app released almost two years ago. The SANS Institute notes that split tunneling is always dangerous.

Finally, how do threat actors leverage remote monitoring and management tools like AnyDesk, Atera and Splashtop? By tricking employees into downloading them. They send messages pretending to be from IT support saying the employee needs to download an application to help them. This week Malwarebytes published a blog outlining how it works. Security teams may find it useful.

Follow Cyber Security Today on Apple Podcasts, Google Podcasts or add us to to your Flash Briefing on your smart speaker

The post Cyber Security Today, Feb. 14, 2024 – Get cracking on Patch Tuesday security fixes first appeared on IT World Canada.

Google warns that Gemini AI conversations are not private: Hashtag Trending, Wednesday, February 14th, 2024

Google advises you to be careful about what you say to its new AI model Gemini, ChatGPT is getting a memory, burglars have found a way to easily jam cloud based alarm systems and more from the X files – the Musk is out there.

All this and more on this – this ain’t Vegas – what happens in AI doesn’t stay in AI – edition of Hashtag Trending. I’m your host Jim Love, CIO of IT World Canada and TechNewsDay in the US.

Google is warning users of its new Gemini app that their conversations with the app may not be as private as you might think.  It turns out, while you’re chatting away, seeking help or maybe just killing time, there are human eyes that might see those conversations. And here’s the part that might make you pause: even if you hit delete, those chats could hang around for up to three years.

So, what’s Google’s advice? Pretty straightforward – don’t spill your secrets to Gemini. Google’s being upfront about it, which is good. They’re saying, “Hey, we’re using some of this chat to make Gemini smarter, and just so you know, real people might get a glimpse.”

And for anyone thinking, “No big deal, I’ll just delete my chat if I say something I shouldn’t,” well, Google’s got news for you. Even if you delete the chat, Google doesn’t delete it. It’s stored away from your Google account but it’s not deleted.

And it’s not just your chat information, if you check the Gemini Apps Privacy Hub you will see that Gemini is keeping conversations, but also locations, feedback and usage information.

In this age where AI is becoming more predominant in our lives, Google’s warning is a reminder to think before we speak and to ask before we trust.

So next time you’re about to share something with Gemini, maybe ask yourself: would I want someone else reading this? If not, maybe keep that thought offline.

 

Sources include: ZDNET

And in another story about AI remembering, OpenAI is rolling out a new feature for ChatGPT – it’s giving it a memory.

This isn’t just about ChatGPT remembering your name or your favorite color. It’s about tailoring responses based on your previous interactions, making each conversation more relevant and personalized than the last.

This new feature is being tested on a select group of both casual and paid users, but is planned to be rolled out to all users in the future.

You can now ask ChatGPT to remember specific details or preferences, and it’ll carry that knowledge into future chats. It’s like custom instructions but stored conversationally.

If you’re worried about privacy, OpenAI claims you will have full visibility into what ChatGPT remembers, with the option to delete anything you’re not comfortable with, or even wipe the slate clean.

You can also switch off the memory feature anytime, a kind of incognito mode, ensuring your queries stay off the record.

OpenAI is also trying to ensure that ChatGPT steers clear of remembering sensitive info, like health details, unless you explicitly say it’s okay.

This is another step into the the future of AI interactions, more personalized and perhaps more meaningful conversations, further bridging the gap between human and machine communication. As ChatGPT gets smarter, our chats are set to become more insightful, more personal, and even more human.

 

Sources include: Axios

And it seemed like the EU had gotten one up on Apple, forcing the company to open its app store but Apple’s answer is what some are calling “malicious compliance.”

Apple will allow alternative app stores and perhaps even “side-loading” or adding apps without going through an app store, but at a cost that’s causing a stir among developers.

While technically adhering to the new regulations, Apple plans to impose hefty commission fees on developers who operate outside its own App Store.

For developers, the new policy is a double-edged sword. Apps that gain significant traction, exceeding 1 million downloads, will be subject to a “Core Technology Fee” of about half a Euro for every first download. That’s about 53 cents US and almost 75 cents Canadian.

And app updates are considered new installations.

As one developer who did a feature on this on YouTube pointed out, his first Chrome extension went viral and got several million downloads. If that had been under this arrangement, he would have owed Apple millions of dollars.

So Epic Games may have the deep pockets to invest so that they can finally get their own Fortnite game out there after they were thrown out of the app store for refusing to use Apple’s payment system, but smaller developers may not be able to pay or to take the risks. And even though Apple will be forced to let games use their own payment methods, they apparently will be levying a fee for that which might end up being as costly using Apple Pay.

 

This has pointed out the big difference between Google and Apple’s ecosystems. Android has long supported alternative means of app installation, offering developers and users more freedom. Platforms like F-Droid and the Aurora store provide avenues for app distribution without the hefty fees and restrictions Apple is imposing.

While Apple argues its policies are in place to protect users, critics see them as a means to preserve market dominance and profit margins.

The EU Commission plans to review Apple’s compliance in March 2024, and given the reaction from the tech community, one thing is clear: the clash between regulation and corporate strategy is far from over.

Sources include: Tutanota Blog

In a concerning trend burglars have upped their game by employing Wi-Fi jammers to disable home security systems, marking a sophisticated evolution in residential burglary tactics. Over the past six months, nine robberies in a town in Minnesota have been attributed to this method, targeting affluent neighborhoods and specifically choosing homes when they are unoccupied to avoid any confrontations.

These Wi-Fi jammers, which can be purchased online for $40 to $1,000, don’t just block signals; they flood the network with noise, making it impossible for legitimate traffic to reach connected devices like surveillance cameras. This tactic allows thieves to enter homes undetected, making off with safes, jewelry, and other valuables.

The use of such jammers is illegal under federal law, but, as they interfere with authorized radio communications, including emergency services and GPS. But that’s unlikely to deter criminals and the availability of these devices from international sellers makes them readily available despite being banned.

Cybersecurity experts suggest several measures to counteract the threat posed by Wi-Fi jammer burglaries. Homeowners are advised to use hardline cameras that connect to local storage, install non-wireless security alarms and lights, and leave lights or a TV on when away to make their homes appear occupied.

I think having a nosey neighbour might be another low tech alternative to be considered.

Sources include: TechSpot

Broadcom has officially ended the era of free VMware ESXi hypervisor, removing all doubt that the company is not interested in the small business market. This decision, revealed in a recent knowledge base article, removes the free version of ESXi from VMware’s website.

The free ESXi version, known for its limitations on core usage, memory, and lack of management features, has been a staple for testing, tinkering, and educational purposes. It served as a gateway for many IT professionals and enthusiasts into the VMware ecosystem, often leading to full production deployments.

VMware continues to offer trialware versions and maintains the VMware User Group (VMUG) “advantage” licensing, providing some avenues for users to access the hypervisor without the full cost.

 

While some industry analysts see this as a minor adjustment, given the availability of trial editions and alternative free hypervisors in the market, others interpret it as a clear message from Broadcom, that they are not interested in smaller customers and hobbyist users.

This strategy aligns with Broadcom’s broader goals to increase VMware’s profitability, with recent decisions such as the requirement for operating a minimum of 3,500 cores for inclusion in its cloud partner program.

The focus on larger, more lucrative engagements, is at the expense of the broader, community-driven support that has fueled VMware’s growth over the years.

The end of free ESXi and the shift towards subscription-based and core-count licensing models may reshape VMware’s market position, pushing smaller customers to alternatives such as Nutanix, Scale Computing, Microsoft or Red Hat.

Sources include: The Register

Journalist and author Séamas O’Reilly experienced what he describes as a “surreal” turn of events when his X account (formerly Twitter) was suspended hours after he critiqued the platform in an article for the Irish Examiner. O’Reilly, whose account boasted over 100,000 followers and had been active for around 14 years, pinpointed the suspension to his commentary on the platform’s bot issue, labeling it as “unusable.”

In his article, O’Reilly highlighted the irony of a scam bot carrying a blue check mark, indicating it paid monthly fees to X, under the ownership of Elon Musk. He suggested that the financial model disincentivizes the platform from taking action against such bots. The suspension notice cited “platform manipulation and spam” as reasons, charges O’Reilly contests.

Some might find the ironic, given Musk’s proclaimed commitment to the principle of free speech. In fact, Musk has kept people on the platform whose statements are so offensive that sponsors fled the platform in droves.

O’Reilly, who uses the platform for his journalism, has appealed for reinstatement but that appeal has, so far, gone unanswered.

Source: The Irish Times

 

Hashtag Trending goes to air five days a week with daily news and a weekend interview show that we creatively called – the weekend edition.

We love to hear from you. Send us a note at jlove@itwc.ca or drop us a comment under the show notes at itworldcanada.com/podcasts – look for Hashtag Trending.

Thanks for listening and have a wonderful Wednesday.

The post Google warns that Gemini AI conversations are not private: Hashtag Trending, Wednesday, February 14th, 2024 first appeared on IT World Canada.

Ransomware gang claims it hit Canadian oil pipeline operator

The AlphV ransomware gang claims it has hit Canadian oil transmission operator Trans-Northern Pipeline, which operates pipelines in three provinces.

Brett Callow, a B.C.-based threat researcher with Emsisoft, first broke the news earlier today in a tweet on the X social media platform.

The gang claims 190 GB of data was recently stolen, all of which is now publicly available.

In an email statement, Trans-Northern said the company “experienced a cybersecurity incident in November 2023 impacting a limited number of internal computer systems. We have worked with third-party cybersecurity experts and the incident was quickly contained. We continue to safely operate our pipeline systems. We are aware of posts on the dark web claiming to contain company information, and we are investigating those claims.”

There were no unusual or unplanned interruptions of pipeline operations, said Lisa Dornan, the company’s communications team leader.

The company didn’t answer emailed questions about how much, if any, data was stolen, how much, if any, data was encrypted and if any information involved the data of employees or customers.

Trans-Northern operates two lines: An oil pipeline between Calgary and Edmonton, and a separate line that roughly runs from Nanticoke, Ont. through Toronto to Montreal.

Separately, AlphV also listed as a victim the Canadian electronics retail chain The Source, which is owned by BCE, the parent company of Bell Canada.

The AlphV/BlackCat ransomware gang has been in the crosshairs of governments for some time. In December, the U.S. Justice Department said it had disrupted the gang’s operations after the FBI created and distributed a decryption tool to over 500 victim organizations. The U.S. also seized several websites the group operates.

Threat researchers differ on whether ransomware victims are targeted, or end up being hit because crooks find application vulnerabilities or take advantage of stolen passwords. AlphV is a ransomware-as-a-service operation, which means it uses affiliates who specialize in finding ways to initially break into a corporate network.

Certainly pipelines are a juicy target for extortion. When the U.S. Colonial Pipeline was hit by ransomware in 2021, the unprepared company stopped all pipeline operations to contain the attack. According to CNN, the shutdown was also because the attack impacted Colonial’s ability to bill customers. Regardless of the reason, one result was temporary long lineups for gasoline on the east coast of the U.S..

Experts said at the time that one mistake in attacking a critical infrastructure provider was that it brought in the weight of U.S. authorities. While Colonial paid a US$4.5 million ransom to the DarkSide ransomware gang, about half was recovered by the U.S. government.

During a Congressional hearing, the head of Colonial Pipeline told U.S. senators that hackers were able to get into its IT system by stealing a single password to a legacy Virtual Private Network (VPN) that did not have multifactor authentication.

The post Ransomware gang claims it hit Canadian oil pipeline operator first appeared on IT World Canada.

Warning: Phishing campaign aimed at senior executives

Accounts of hundreds of Microsoft Office and Azure user accounts — including those of senior executives — have been compromised recently in ongoing targeted phishing attacks, say researchers at Proofpoint.

“As part of this campaign, which is still active, threat actors target users with individualized phishing lures within shared documents,” the warning says. For example, some weaponized documents include embedded links to “View document” which, in turn, redirect users to a malicious phishing webpage upon clicking the URL.

“Threat actors seemingly direct their focus toward a wide range of individuals holding diverse titles across different organizations, impacting hundreds of users globally,” Proofpoint says.

“The affected user base encompasses a wide spectrum of positions, with frequent targets including Sales Directors, Account Managers, and Finance Managers. Individuals holding executive positions such as ‘Vice President, Operations’, ‘Chief Financial Officer & Treasurer’ and ‘President & CEO’ were also among those targeted.

“The varied selection of targeted roles indicates a practical strategy by threat actors, aiming to compromise accounts with various levels of access to valuable resources and responsibilities across organizational functions.”

Those behind this campaign are using this agent — which defenders should be watching for — during the access phase of the attack chain: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36 

Attackers predominantly utilize this user-agent to access the ‘OfficeHome’ sign-in application, says Proofpoint, along with unauthorized access to additional native Microsoft 365 apps, such as:

‘Office365 Shell WCSS-Client’ (indicative of browser access to Office 365 applications);
‘Office 365 Exchange Online’ (indicative of post-compromise mailbox abuse, data exfiltration and email threats proliferation);
‘My Signins’ (used by attackers for MFA manipulation)’
‘My Apps’
‘My Profile’

Successful initial access often leads to a sequence of unauthorized post-compromise activities, including multifactor authentication (MFA) manipulation so the attackers can maintain persistent access. Proofpoint has seen attackers choosing different authentication methods, including registering alternative phone numbers for MFA authentication via SMS or phone call. However, in most cases the attackers preferred to add a mobile authenticator app with notification and code.

From there, the attackers may access and download sensitive files, ravage email boxes, send fraudulent email messages to human resources and financial departments and, to hide their tracks, create dedicated obfuscation email rules.

Proofpoint urges IT and infosec leaders to:

monitor for the specific user agent string and source domains in your organization’s logs to detect and mitigate potential threats;
enforce immediate change of credentials for compromised and targeted users, and enforce periodic password change for all users;
identify account takeover (ATO) and potentially unauthorized access to sensitive resources in your cloud environment. Security solutions should provide accurate and timely detection for both initial account compromise and post-compromise activities, including visibility into abused services and applications;
identify initial threat vectors, including email borne threats (e.g. phishing, malware, impersonation, etc.), brute-force attacks, and password spraying attempts;
employ auto-remediation policies to reduce attackers’ dwell time and minimize potential damages.
The post Warning: Phishing campaign aimed at senior executives first appeared on IT World Canada.

AI in network orchestration spend to reach US$20B by 2028: Juniper

A new report from Juniper Research indicates that global network operator spend on artificial intelligence (AI) for network orchestration will generate US$20 billion by 2028; rising 240 per cent from the US$6 billion expected to be generated this year.

Authors of the report are predicting that “enterprises’ increasing use of cellular networks, including for smart manufacturing and autonomous vehicles, will necessitate further investment into AI that automates key network processes.

“These use cases require various degrees of high throughput, low latency and geographical coverage. Therefore, to maximize networks’ efficiency and reduce operational expenditure, the report urged operators to accelerate the incorporation of AI into core networks.”

Findings revealed that as operators expand established 5G networks and build future 6G networks, AI must play an essential role, with performance optimization and network security being the most important use cases. They are expected to account for over 50 per cent of global operator spend on AI by 2028.

“Additionally, ever-increasing virtualization of network functions and demand for cellular data will drive operators to implement AI to decrease operational costs,” a Juniper release stated. “The ability to automate real-time network analysis and adjust network conditions accordingly will be crucial to minimizing the costs associated with network management and service provision.”

Report author Frederick Savage said, “as operators compete on the quality of their networks, AI will be essential to maximizing the value of using a cellular network for connectivity. High-spending users will gravitate to those networks that can provide the best service conditions.”

The post AI in network orchestration spend to reach US$20B by 2028: Juniper first appeared on IT World Canada.