Category: News

Serious IT incidents in Canadian financial sector almost tripled in 2023

Canadian federal financial institutions suffered almost three times as many serious reportable IT incidents in 2023 as in the year before, a parliamentary committee debating proposed cybersecurity legislation for overseeing the country’s critical infrastructure providers was told Monday.

In 2023, there were 28 Priority 1 incidents reported to the Office of the Superintendent of Financial Institutions (OSFI), compared to 2022, when there were only 10 Priority 1 incidents reported.

Priority 1 covers “high impact incidents that cause disruption of service or leakage of data,” Tolga Yalkin, an assistant superintendent at the OFSI, told MPs. The agency later clarified to IT World Canada that a Priority 1 incident covers various sources of potential technology disruption, including but not limited to cyber-attacks.

The OSFI oversees 400 federally-regulated institutions, including 80 banks and 43 trust companies, as well as insurance companies,

The release of the two numbers is a rare view into the extent of serious IT incidents suffered by federally regulated Canadian banks, trust companies, and insurance firms.

“We are concerned with that number growing,” Yalkin told MPs. “We are tracking it very carefully. We are eagerly watching to see whether or not the trajectory continues to grow. This [cybersecurity] is an area of risk for financial institutions.”

Yalkin was testifying before the House of Commons national security committee looking into Bill C-26, which would force designated banks, telecommunications companies, and interprovincial transportation and energy firms to meet certain cybersecurity standards to protect their IT networks and report incidents to the government.

The legislation would impose some obligations on Canadian banks. But, Yalkin said, banks already have to follow OFSI cybersecurity risk management guidelines.

Bill C-26 has two parts: One would amend the Telecommunications Act to give the federal cabinet and the Minister of Industry the power to order designated telecom providers to do “anything” to secure their systems against a range of threats.

The bill would also create the Critical Cyber Systems Protection Act (CCSPA), which would apply to other critical infrastructure providers. Initially, these would be limited to banking, financial clearing firms, interprovincial transport and energy companies, and nuclear power operators. Similar to the Telecommunications Act changes, it would create a cyber security compliance regime for designated firms. Included would be a requirement to report cyber incidents “immediately” to the Canadian Security Establishment (CSE), the branch of the Defence Department responsible for government cybersecurity.

Industry witnesses have worried about having to report serious incidents immediately, preferring the law or regulations follow the American practice of reporting to government regulators within 72 hours. The U.S. Federal Communications Commission just modified its data breach notification rules for telcos there to 30 days.

Also at Monday’s committee meeting, a University of Toronto IT professor emeritus called C-26 “a very one-sided bill” that allows CSE to gather too much sensitive information.

CSE has a “boundless appetite for data collection,” Andrew Clement told the committee.

The proposed legislation needs “substantial” amendments to ensure the “sweeping and secretive powers it grants the government do not override other equally vital values such as privacy, freedom of expression, judicial transparency and government accountability.”

Eric Smith, senior vice-president of the Canadian Telecommunications Association (CTA), which represents the country’s major telcos, said the legislation allowing the Industry minister to order telcos to do — or not do — anything in the name of security “could be broadly interpreted.”

That could range from cutting off service to an organization or individual, he said, or putting equipment on a telco’s network that would weaken encryption or intercept communications. The CTA is asking MPs to amend C-26 to give the government only the power to issue “reasonably necessary’” orders to telcos. The law should also say compliance orders can only be made after the Industry minister has consulted with a list of experts — some of whom may be in the government — to ensure the orders are proportionate to the risk. An order should only have a limited impact on a telco’s service availability, the CTA says, and should be economically and operationally feasible for affected service providers

Even without C-26, in 2022 the government ordered telcos to remove some equipment from specific companies, Smith noted. That was a reference to the removal of equipment made by China’s Huawei and ZTE.

The CTA is asking C-26 be amended so carriers can at least ask the government for compensation if it has to remove or add networking gear.

It is also asking that the legislation allow a carrier a due diligence defence – that it tried to protect its IT network in good faith – if the government alleges the carrier violated an order. A due diligence defence is allowed for other critical infrastructure providers, Smith noted.

Federal privacy commissioner Philippe Dufresne asked for several changes to C-26, including limiting the ability of the government to share sensitive information that critical infrastructure providers would have to hand over to CSE with other departments or foreign governments; and that the government would have to report to him or Parliament the number and purpose of secret orders it issues under the law to a critical infrastructure provider.

Angelina Mason, general counsel and senior vice-president of the Canadian Bankers Association, which represents 60 of the country’s banks, asked MPs to add greater safeguards for the protection of confidential information banks would have to give the government; protect banks from civil and criminal prosecution for good faith compliance with the act’s reporting requirements and cybersecurity directives; and make the government share its cybersecurity information with the private sector.

The post Serious IT incidents in Canadian financial sector almost tripled in 2023 first appeared on IT World Canada.

Federal government procurement has massive overruns: Hashtag Trending, Tuesday February 13, 2024

Once again, Canadian federal government procurement has massive overruns, a driverless Waymo taxi is attacked by a mob, the CEO of Mozilla steps down in the face of Firefox’s decline to irrelevance…

All this and more on this oh my gawd, I hope this isn’t too preachy edition of Hashtag Trending. I’m your host Jim Love, CIO of IT World Canada and TechNewsDay in the US.

In a revealing audit, Canada’s Auditor General Karen Hogan has cast a spotlight on the mismanagement surrounding the ArriveCAN app, a digital tool developed to streamline the entry process into Canada during the COVID-19 pandemic. The report uncovers a series of failures by three federal government agencies: Canada Border Services Agency, the Public Health Agency of Canada, and Public Services and Procurement Canada, highlighting a disregard for good management practices in the app’s contracting, development, and implementation, which amounted to a staggering $59.5 million expenditure.

The audit paints a picture of a project marred by poor financial record-keeping, making it nearly impossible to ascertain the full cost of the ArriveCAN application. This lack of transparency and accountability has raised significant concerns about the value delivered for the taxpayer dollars spent. The report details how the agencies’ reliance on external resources, beyond the initial crisis of the pandemic, not only inflated costs but also brought into question the overall value achieved for the money spent.

One of the most alarming findings is the “disregard for policies, controls, and transparency” in the contracting process, particularly how the initial ArriveCAN contract was awarded to GC Strategies, an IT staffing company, through a non-competitive process without adequate documentation. This process limited competition opportunities and undermined the value for money, raising concerns about the integrity of the contracting practices.

The audit also highlighted the Canada Border Services Agency’s poor management of contracts, with essential information missing from contracts and routine approval of invoices that lacked detail on the work completed. This lack of diligence and oversight has compromised the accountability for public spending on the ArriveCAN project.

In response to these findings, the Auditor General has made several recommendations, including the need for accurate financial records, full documentation of interactions with potential contractors, and ensuring compliance with contracting policies. The government has acknowledged these “unacceptable gaps in management processes” and has taken steps to improve oversight and procurement practices.

That’s the official line – and none of this will make any difference. Nor will it keep this from happening. Why? Government procurement is broken and it’s time to fix it.

And talking about “transparency” and all those platitudes will not fix a thing. In fact, here’s my prediction – the next round of “improvements” will just make it worse.

I’ve been a procurement consultant for the federal government and it’s a joke. The crazy rules that are in place are not designed to give the best value for the taxpayer, they are part of Kafkaesque bureaucratic bungling that is guaranteed to yield the worst possible results.

When I worked on one major purchasing, we were not allowed to ask questions that might actually find out who knew what they were doing and who didn’t. And there was a “fairness” commissioner representative, that was actually a real paid job, and they were there to make sure we didn’t ask any question that would show who knew their stuff and who didn’t.

I want to emphasize that this is NOT the fault of the individual employees. We have a lot of people on our payroll who come to work every day and work hard to do their job.

The problem is with the leadership and the processes driven by people who have no accountability for the results of their actions.

This has nothing to do with political parties. Steven Harper’s conservatives screwed things up just as royally as Justin Trudeau’s Liberals. And the Poilievre’s Conservatives or Jagmeet Singh’s NDP will continue to screw it up. Do not listen to the politicians – they have no idea.

But this is not going to be fixed until someone has the courage to say that this is fundamentally broken and bring in some people who actually understand procurement and technology – and get out of the way while they do their job.

We need accountability for the people who drive the process. They don’t need a mass of bureaucrats and “fairness commissioners” – they need clear objectives, accountability for those, and for the rest of the system to just get out of the way.

Apologies for editorializing but if private companies do this, we can just choose to not buy their products. When the government does it, we have to pay, regardless.

My standing offer to take 5 other CIOs into any area and fix it once and for all still stands if anyone is interested.

Sources include: IT World Canada

In a startling incident in San Francisco’s Chinatown, a Waymo driverless taxi became the target of vandalism that escalated into a full-blown arson attack. The event unfolded around 9 PM PT, starting with an individual jumping onto the vehicle’s hood and smashing its windshield. This act of destruction quickly garnered applause, leading to a crowd forming around the car. The group proceeded to cover the vehicle in spray paint, break its windows, and, in a dramatic finale, set it ablaze. By the time the fire department arrived, the autonomous car was already engulfed in flames.

The motive behind this aggressive act remains unclear, with no reports suggesting why the Waymo car was targeted. Waymo, a leading name in the autonomous vehicle industry, confirmed that the car was operating without any passengers at the time of the attack. The incident was marked by the throwing of fireworks into the car, which ignited the fire. San Francisco Police Department responded to the scene to find the vehicle already in flames, fortunately with no injuries reported.

This incident occurs against a backdrop of growing tension between San Francisco residents and the operators of automated vehicles. Previous incidents involving robotaxis, including a pedestrian being struck and traffic disruptions, have fueled public debate over the safety and regulation of autonomous vehicles in the city. Just last year, city officials and residents expressed strong opposition to granting 24/7 operation licenses to these vehicles, with some going as far as to physically block the cars in protest.

The destruction of the Waymo taxi in Chinatown highlights the broader challenges tech companies face as they integrate their innovations into public spaces. Acts of vandalism and defiance against technology, from scooters thrown into lakes to cars being punched, underscore the friction between technological advancement and public acceptance.

As the investigation into the incident continues, the event serves as a stark reminder of the complexities surrounding the deployment of autonomous vehicles in urban environments. It raises critical questions about safety, regulation, and the societal impacts of rapidly advancing automotive technologies.

Sources include: The Verge and official statements from Waymo and the San Francisco Police Department.

In a move that has stirred the tech community, Mitchell Baker, CEO of Mozilla Corp, has announced her resignation. This decision comes at a time when Firefox, once the darling of the web browser world, continues its descent into what many fear could be obscurity. Steven J. Vaughan-Nichols, in his opinion piece for The Register, delves into the implications of Baker’s departure and the current state of Mozilla and its flagship product, Firefox.

Firefox’s journey from a pioneering web browser to its current position reflects a broader narrative of change and challenge within the tech industry. In the early 2000s, Firefox was celebrated for its innovation and security, offering a refreshing alternative to Internet Explorer. However, the landscape has dramatically shifted since then, with Firefox’s user base dwindling to a mere 2.2 percent of US government website visitors, as reported by the Digital Analytics Program (DAP).

The decline of Firefox is not a sudden phenomenon but a gradual erosion of market share, primarily to Google’s Chrome, which now dominates the browser space. This shift raises questions about Firefox’s relevance in today’s tech ecosystem and the strategic decisions that have led to its current state. Vaughan-Nichols points out that even Mozilla has recognized the challenge posed by Chrome, with former CEO Chris Beard acknowledging in 2017 that Firefox had failed to keep pace with market demands.

The article also highlights the financial and operational complexities within Mozilla, particularly concerning its funding model. Despite positioning itself as a champion of privacy and the open web, Mozilla’s financial sustainability heavily relies on royalties from Google, a fact that sits uncomfortably with its public mission. Baker’s compensation, amidst declining revenues and Firefox’s shrinking user base, further complicates the narrative around Mozilla’s priorities and management practices.

As Baker steps down, Laura Chambers has been named interim CEO, tasked with refining Mozilla’s vision and doubling down on core products like Firefox. Yet, the future direction of Mozilla and Firefox remains uncertain, with Vaughan-Nichols expressing skepticism about the possibility of a significant turnaround.

Baker’s new role will focus on representing Mozilla in public forums, emphasizing policy, open source, and community engagement. However, the connection between these activities and the revitalization of Firefox is not immediately clear. The overarching challenge for Mozilla is not just about leadership changes but finding a sustainable path forward in an internet landscape that has evolved beyond its early vision.

This episode raises critical questions about the viability of Firefox as a web browser, the strategic direction of Mozilla, and the broader implications for the tech industry’s commitment to open standards and user privacy.

And at the risk of making this edition totally opinionated, I think you only have to look at Perplexity to see how sadly irrelevant Firefox has become. I get the open source piece. I love open source. I get privacy idea. Love it. But for heaven’s sake, let’s learn one lesson if we want to compete – “we’re not the other guys” is not a unique value proposition. Understanding the needs and desires of your customer and trying to fulfil them – that’s where you take market share.

Sources include: The Register

And that’s our show for today.

And I don’t know why or how, but I scan a lot of stories to produce this podcast and on some days, they just seem to have a theme.

If I’m straying far too much into opinion, I’m trusting that you’ll let me know.

Hashtag Trending goes to air five days a week with daily news cast and a weekend interview show that we creatively called – the weekend edition.

We love to hear from you. Send us a note at jlove@itwc.ca or drop us a comment under the show notes at itworldcanada.com/podcasts – look for Hashtag Trending.

Thanks for listening and have a Terrific Tuesday.

 

 

 

 

 

 

 

 

The post Federal government procurement has massive overruns: Hashtag Trending, Tuesday February 13, 2024 first appeared on IT World Canada.

Montreal duo launch free cybersecurity training platform

Two childhood friends, both of whom are entrepreneurs based in Montreal, today launched Cyber101, a platform that offers organizations a chance to educate their employees about cybersecurity best practices free of charge, in both English and French. It is the brainchild of Benjamin Beauregard, the chief executive officer (CEO) of video production agency divisionX  and Guillaume Belanger, president of Exosource, an IT services company.

With Cyber101, according to a release, “business and individuals can immediately improve their cybersecurity posture in less than an hour.

By taking the course, the two said, organizations stand to:

Reduce the risks of fraud, data breaches, and disruptions
Meet the requirements of insurers and privacy laws
Improve employees’ technological skills
Demonstrate a serious commitment to cybersecurity to clients and staff.

The release went on to say that Statistics Canada estimated that the proportion of Canadians victimized by cybersecurity incidents increased from 58 per cent in 2020 to 70 per cent in 2022. The most commonly reported incidents were receiving unsolicited emails and fraudulent content.

“When teaching at the McGill Executive Institute, cybersecurity consistently emerges as a critical issue,” said Beauregard. “Guillaume and I created this platform because we believe that education is the key to effectively countering cyber threats.”

Belanger said the Cyber101 platform provides “essential tools to help you stay on top of threats in an increasingly hostile environment.”

Those tools are contained in nine mini-modules taking, the site said, “five minutes or less” and once completed, anyone who successfully answers a series of questions based on each module will then receive what the company calls “a personalized completion certificate.”

The Cyber101 website notes that “millions of businesses and individuals fall victim to cybercrime every year and the consequences can be catastrophic (identity theft, confidential data breaches, extortion ….)

“Cybersecurity awareness has become an absolute necessity for individuals and businesses. Yet, quality content remains out of reach for most. We have decided to produce quality training and to offer it for free.”

The post Montreal duo launch free cybersecurity training platform first appeared on IT World Canada.

Government departments ignored management practices, failed to oversee ArriveCan app: Auditor General

Three federal government agencies failed to follow good management practices in the contracting, development, and implementation of the $59.5 million ArriveCAN application, Canada’s auditor general said today.

As a result, concluded Auditor General Karen Hogan, it did not deliver the best value for taxpayer dollars spent.

But Hogan also said the lack of documentation makes it almost impossible to find out the exact cost of all the work paid for the app.

Canada Border Services Agency, the Public Health Agency of Canada, and Public Services and Procurement Canada were faulted by Hogan in the report filed in Parliament this morning.

The application was created in 2020 to digitally collect traveller contact and health information when they entered Canada during the COVID‑19 pandemic, so information could easily be presented to border authorities. The audit estimated that the ArriveCAN application cost approximately $59.5 million but emphasized that the exact cost was impossible to calculate because of the Canada Border Services Agency’s poor financial record keeping.

“The agency’s decision to continue relying on external resources throughout the application’s development, launch and updates, beyond the initial pandemic crisis, increased costs and brings into question the value achieved for money spent,” the auditor general’s office said in a statement.

The lack of documentation and controls extended to contracting practices, the statement says. The audit found that the Canada Border Services Agency’s “disregard for policies, controls, and transparency in the contracting process limited opportunities for competition and undermined value for money. There was little documentation to support how and why  a company called GC Strategies was awarded the initial ArriveCAN contract through a non‑competitive process.”

GC Strategies is an IT staffing company — that is, it hires, or subcontracts, developers to do work for organizations it contracts with.

The report says evidence shows GC Strategies was involved in setting the requirements that the Canada Border Services Agency later used to tender a competitive contract.

The audit found that Canada Border Services Agency managed contracts poorly, which raised concerns about value for money. Essential information, such as clear deliverables and required qualifications, was missing from contracts. Canada Border Services Agency routinely approved and paid invoices that contained little or no details on the work completed.

“Public servants must always be transparent and accountable to Canadians for their use of public funds”, said Hogan. “Many questions that Parliamentarians and Canadians are asking cannot be answered. The lack of information to support ArriveCAN spending and decisions has compromised accountability.”

The report says

18 per cent of invoices submitted by contractors that Hogan’s office tested did not provide enough information to determine whether expenses related to ArriveCAN or another information technology project. This made it impossible to accurately attribute costs to projects;
the AG’s office estimated that the average per diem cost for the ArriveCAN external resources was $1,090, whereas the average daily cost for equivalent IT positions in the Government of Canada was $675. The Canada Border Services Agency continued to rely on external resources, increasing the cost of the application;
between April 2020 and October 2022, the Canada Border Services Agency released 177 versions of ArriveCAN, with often little to no documentation of testing. In one update, in June 2022, around 10,000 travelers were wrongly instructed to quarantine.

As a result of that incident, the federal Privacy Commissioner found that the Canada Border Services Agency (CBSA) contravened the Privacy Act by not taking all reasonable steps to ensure that information about individuals recorded in the app was accurate;

there was no formal agreement between the Public Health Agency of Canada and the Canada Border Services Agency from April 2020 to July 2021 to clarify roles and responsibilities, the report says. “Each agency believed that its counterpart was responsible for establishing a governance structure. In our view, the Public Health Agency of Canada, as the business owner, was responsible for establishing the governance structure.
“As a result of the missing governance structure, good project management practices were not developed and implemented,” the report says. “For example, the Public Health Agency of Canada did not develop project objectives and goals, budgets and cost estimates, assessments of resource needs, or risk management activities.” It was only in July 2021, when a letter of intent was signed, that responsibilities for funding the development, implementation, management, and support of ArriveCAN was clarified;
the AG’s office found no evidence to show that some Canada Border Services Agency employees complied with the agency’s Code of Conduct by disclosing that they had been invited to dinners and other activities by contractors;
one reason the cost of the app went up: The Canada Border Services Agency added a digital customs and immigration declaration form into the ArriveCAN application at a cost of about $6.2 million, to replace a paper-based system. The new digital declaration form remained in use after government requirements to collect travellers’ contact and health information stopped in October 2022.

The Canada Border Services Agency was responsible for developing and managing the ArriveCAN application on the basis of the Public Health Agency of Canada’s health requirements. These requirements were implemented to meet Covid-19 emergency orders. The Public Health Agency of Canada assists the federal Minister of Health. The agency was the business owner of ArriveCAN until April 1, 2022. Public Services and Procurement Canada is the government’s central purchasing and contracting authority, and was responsible for issuing and administering contracts on the agencies’ behalf when the contract value exceeded their delegated authority to procure.

While the Treasury Board of Canada Secretariat introduced some flexibility into the procurement and contract processes during the pandemic to achieve results quickly, the report notes, it still required government organizations to demonstrate due diligence and controls around expenditures and to document their decisions.

Hogan recommends:

the Canada Border Services Agency maintain accurate financial records by correctly allocating expenses to projects. To better support these actions, the agency should work with contractors to obtain invoices that accurately detail the work completed by each resource by project, contract, and task authorization;
the Canada Border Services Agency and the Public Health Agency of Canada fully document interactions with potential contractors and the reasons for decisions made during non‑competitive procurement processes and should put in place a process to ensure compliance with the requirements of the contracting policies;
the Canada Border Services Agency should ensure that potential bidders are not involved in developing or preparing any part of a request for proposal, and should put in place controls that will prevent this from occurring.

In response to the AG report, the government issued a statement admitting there were “unacceptable gaps in management processes.”

CBSA has already created an Executive Procurement Review Committee to approve contracts and task authorizations, the government said, “which is already providing additional oversight on all contracting activities, focusing on delivering value for money.” CBSA has also established a procurement centre of expertise to help employees fully understand their obligations and authorities. The agency also now requires employees to disclose all interactions with potential vendors.

Public Services and Procurement Canada “will continue to strengthen all aspects of the federal procurement regime and will use the findings from this report to improve the way the Government of Canada does business with its suppliers,” the statement says. New measures have already been added to ensure that tasks and deliverables are clearly defined in professional services contracts, the government says, and the policy and guidance documentation used by procurement officials to ensure consistency has been updated.

The post Government departments ignored management practices, failed to oversee ArriveCan app: Auditor General first appeared on IT World Canada.

Cyber Security Today, Feb. 12, 2024 – US seizes a website selling the Warzone malware

The U.S. seizes a website selling the Warzone malware.

Welcome to Cyber Security Today. It’s Monday, February 12th, 2024. I’m Howard Solomon, contributing reporter on cybersecurity for ITWorldCanada.com and TechNewsday.com in the U.S.



American authorities have seized a website and several domains that sold the Warzone remote access trojan to threat actors. The malware takes screenshots, records keystrokes, turns on computer video cameras and steals data. As part of the operation the U.S. also indicted individuals in Malta and Nigeria for alleged computer crimes. Both have been arrested. American authorities are trying to extradite the man in Malta for trial in the U.S. The U.S. credited Canada, Croatia, Finland, Germany, the Netherlands and Romania with helping in the takedown of the Warzone servers.

Cyber investigators in France are still looking into data breaches at two supplementary health insurance companies two weeks ago which saw the theft of data of more than 33 million people. That’s about half the country. The country’s privacy commission said data stolen on policyholders included people’s names, date of birth and their social security number. No banking or health data was stolen.

Separately, the France Info radio network reports that a ransomware attack forced a hospital in northern France to take its IT systems offline Sunday. It also had to temporarily close its emergency department.

Personal data on over 13 million Americans was stolen last spring from a company that provides medical transcription services to healthcare organizations. The company is Perry Johnson & Associates. Among its clients is Concentra Health Services, which has clinics across the U.S. Perry Johnson said the attacker accessed the IT system that held data on Concentra patients in April. Notification of the millions of victims started in November. We’re learning about it now because Perry Johnson filed a description of the data breach notification letters last week with Maine’s attorney general’s office.

Planet Home Lending, an American loan provider, has updated the number of victims involved in a data breach that took advantage of a Citrix vulnerability in its servers. Last month it said data on just under 200,000 customers was stolen in November. In an updated filing with Maine’s attorney general the company now says the number is almost 285,000 people.

A new backdoor targeting Mac computers has been discovered. Researchers at Bitdefender say the malware seems to impersonal an update for Microsoft Video Studio. So Mac users should be wary of emails or popups claiming to be a patch for this application. This malware may have been circulating since last November. Bitdefender suspects it may have been created by a ransomware gang.

The U.S. Federal Communications Commission won’t allow anyone in the U.S. to use artificial intelligence software to create voice-cloned automated phone calls. The regulator said last week calls recorded with AI-generated voices are forbidden on the Telephone Consumer Protection Act. Crooks are sending out robocalls that imitate the voices of celebrities and politicians for scams or misinformation. They are even using the technology to imitate family members for extortion. Not only will police go after crooks for robocalls for fraud, they will now be able to prosecute for illegal use of AI.

Last November news emerged that a Pennsylvania water authority’s water pressure regulating system was hacked by an Iranian threat group. The group planted a message on the system’s interface. The entry point was the system’s Unitronics internet-connected controller. As a result of that attack researchers at Censys did some internet scanning and found 149 internet-exposed Unitronics devices and services in the U.S. Interestingly, a number of them are honeypots. That is they are designed to lure hackers. However, Censys said many operators of the web control panels of Unitronics PLCs are still using the default password of 1111. Censys warns IT and OT administrators to a) make sure the default password is changed and b) that if these devices do have to be connected to the internet they should be protected by a VPN or firewall.

Want to start the day with more news? IT World Canada’s Jim Love has a daily general IT news podcast. It’s called Hashtag Trending. It can be found here or where Cyber Security Today is: on Apple Podcasts and Google Podcasts.

The post Cyber Security Today, Feb. 12, 2024 – US seizes a website selling the Warzone malware first appeared on IT World Canada.

AI agents will transform AI usage in the coming months: Hashtag Trending for Monday February 12, 2024

Forget about Artificial General Intelligence, AI agents are going to rock your world in the coming weeks and months, if fewer companies are paying ransoms, why has the total amount paid almost doubled over last year, a testing device called Flipper is banned in Canada and a viral story about toothbrushes being compromised by malware is revealed to be an error in translation.

All this and more on this slip of the tongue edition of Hashtag Trending. I’m your host Jim Love, CIO of IT World Canada and TechNewsDay in the US.

OpenAI has hinted that they are on the brink of releasing AI agents, that will transform the way we handle complex tasks on our devices.

These agents, still under wraps regarding their launch timeline, promise to automate tasks that have traditionally required human intervention, could be the thing that reshapes the job landscapes in certain sectors.

Imagine an AI capable of transferring data from documents to spreadsheets, filling out and processing expense reports, or managing entries into accounting software.

That level of automation and more already exists. It allows the AI to perform tasks just like a human – mouse clicks, cursor movements, and text input across various applications.

Up until this point, communication between AI and other applications has been by programmatically developed functions and structured Application Program Interfaces (APIs).

This new breed of agents wouldn’t need that. It can simply learn and navigate through the web, autonomously devising and executing strategies to achieve result for the end user.

This is going to raise all kinds of issues. How to get and secure permission for the AI to take control of devices. As these devices store huge amounts of private data, the issues of privacy and data security, where the files are stored, and how much of this private interaction can be used to train future AI models.

While the world awaits what OpenAI will do, this is not theoretical. There are actual working applications using agents already in the marketplace, one of which is the Rabbit R1 unveiled at CES this year.

I’ll be doing a special piece on this in ITWorldCanada.com as part of my Best of YouTube series. Watch for it in the next day or two.

Sources include: Android Authority

In 2023, ransomware attacks not only intensified but also demonstrated a strategic shift towards high-profile targets, including critical infrastructure sectors such as healthcare, education, and government. All this according to a new report from a firm called Chainanalysis.

The year saw a notable surge in ransomware activity, with attackers exploiting vulnerabilities in widely used software like MOVEit, affecting organizations from the BBC to British Airways.

This aggressive approach led ransomware gangs to amass over $1 billion in cryptocurrency payments from their victims, marking a record-breaking year for ransomware revenue.

The resurgence of ransomware in 2023, following a brief decline in 2022, underscores the adaptable and resilient nature of cybercriminals.

Despite efforts to curb their activities, and reports that fewer companies are paying ransoms, it appears that ransomware gangs have refined their strategies, focusing on more lucrative and impactful attacks. This shift has not only increased the financial stakes but also highlighted the significant operational and reputational risks for affected organizations.

Other key insights from the Chainalysis report include:

– The economic impact of ransomware extends beyond the ransom payments, with companies like MGM Resorts facing over $100 million in damages despite not paying the ransom.

– Law enforcement interventions, such as the FBI’s infiltration of the Hive ransomware operation, have shown some success in mitigating the impact of ransomware by preventing millions in payments.

– The ransomware ecosystem is evolving, with a rise in Ransomware as a Service (RaaS) models and initial access brokers facilitating easier entry for cybercriminals and expanding the threat landscape.

In 2024, the ransomware threat persists, with new variants and tactics emerging. The continued innovation by ransomware actors, coupled with the lucrative returns from their activities, suggests that ransomware will remain a significant challenge. The insights from 2023 highlight the importance of proactive cybersecurity measures, international cooperation, and the development of strategies to disrupt the economic incentives driving ransomware attacks.

Sources include: Chainalysis

In a decisive move to curb the rising tide of car thefts, the Canadian government has announced plans to ban the importation, sale, and use of the Flipper Zero device, along with similar gadgets identified as tools for vehicle theft. The Flipper Zero, a versatile pen-testing tool designed for experimenting with and debugging various hardware and digital devices, has been under scrutiny due to its ability to conduct replay attacks that can unlock cars, open garage doors, and clone digital keys.

Canadian Industry Minister François-Philippe Champagne highlighted the government’s concern over the sophisticated tools criminals use to steal cars, prompting this regulatory action. This announcement followed a national summit on combating auto theft, reflecting the government’s commitment to addressing the issue head-on.

Statistics Canada reports approximately 90,000 vehicles stolen annually, translating to a car theft every six minutes and resulting in $1 billion in annual losses, including insurance costs. The surge in car thefts has significantly impacted the national Crime Severity Index, with motor vehicle theft being a major contributing factor to its increase in 2022.

The government’s Innovation, Science and Economic Development (ISED) department is set to collaborate with law enforcement agencies to remove devices like the Flipper Zero from the Canadian market. However, Flipper Devices, the company behind Flipper Zero, argues that their device cannot be used to steal vehicles built after the 1990s due to modern security systems employing rolling codes. They assert that the Flipper Zero is intended for security testing and development, with precautions taken to prevent its misuse.

This ban comes amidst broader concerns over the use of technology in criminal activities, with Amazon banning the sale of Flipper Zero since April 2023 for being a card skimming device, following actions by the Brazilian National Telecommunications Agency to seize incoming purchases due to alleged criminal use.

Sources include: BleepingComputer

In a world increasingly filled with smart devices, a recent story from the Swiss outlet Aargauer Zeitung caused quite a stir with claims that hackers had launched a distributed denial-of-service (DDoS) attack on approximately 3 million internet-connected toothbrushes. This story, which quickly went viral, suggested damages amounting to millions of euros. However, the cybersecurity firm Fortinet, cited as the source of this information, clarified that the attack scenario was purely hypothetical, presented during an interview to illustrate a type of cyberattack. The confusion was attributed to a translation error.

Mainstream publications, including ZDNet, Tom’s Hardware, and The Sun, reported on the incident, demonstrating how easily a hypothetical scenario can be misconstrued as a real event.

It’s not fanciful. Smart devices are vulnerable and often not well protected and there have been documented cases of attacks on smart devices.

But in retrospect, one could ask if we all should have been more skeptical.

I saw this story and didn’t run with it, but not because of my journalistic genius.  I just didn’t see it as the best story to run with – it was a little sensationalist and I already had a better story with a humorous twist to end with.

So, I gave it the brush off.

So, I’m not going to question the journalists who did run with the story. I hope, however, that it will cause us all to be more alert, but at the same time, I also struck that we live in a world, where this story is actually believable.

Sources include: Axios and several others

Hashtag Trending goes to air five days a week with daily news and a weekend interview show that we creatively called – the weekend edition.

We love to hear from you. Send us a note at jlove@itwc.ca or drop us a comment under the show notes at itworldcanada.com/podcasts – look for Hashtag Trending.

Thanks for listening and have a Marvelous Monday.

The post AI agents will transform AI usage in the coming months: Hashtag Trending for Monday February 12, 2024 first appeared on IT World Canada.

AI in cybersecurity from a hands on tech pro: Hashtag Trending, the Weekend Edition features Greg Statton from Cohesity

AI in cybersecurity is not a new concept. Almost every security vendor has been working on it for years. In fact, AI was a godsend for cybersecurity.

In the olden days, like 5 years ago, you pretty much needed to know what a threat was, what it did – what it’s “signature” was to be able to detect it and deal with it.

Vendors set up intricate traps – honey pots – they monitored traffic, did everything to stay on top of all the threats.  And frankly, they did a pretty good job of it.

But the sheer volume of new attacks and methods is simply overwhelming. According to a Forrester Research report I found online for 2019, 80% of cybersecurity decision-makers expected AI to increase the scale and speed of attacks and 66% expected AI “to conduct attacks that no human could conceive of.”

Well, if you listen to my sister podcast, CyberSecurity Today, that’s one prediction that came true. The host, my colleague Howard Solomon has no problem finding new threats to talk about – and he goes to air four times a week.

So at one point, this idea that we can know everything that’s out there and detect it breaks down.

And then there’s another problem – the sheer volume of attacks is astonishing. 20 years ago, a security expert at one of the major banks told me that if their firewall went down for 10 minutes, they’d be overwhelmed with attacks. Can you imagine what it’s like today?

And not just volume, it’s the speed of the attacks. If they get in to your system, they often take their time and set up an attack, spreading throughout your network, so that when they do mount the attack, it’s massive, fast and overwhelming.

People can’t move or think that fast.

Tech sector navigating layoffs while riding GenAI wave, says GlobalData

The technology industry, says GlobaData, has already witnessed substantial changes in 2024, including layoffs by big companies such as Google, Amazon and Meta, a trend, it adds, that began last year, affecting over 191,000 employees, driven by factors like post-COVID-19 pandemic adjustments and a focus on emerging tech like artificial intelligence (AI).

Despite these and other challenges, the data and analytics firm says there is a “positive outlook for AI roles, especially those in customized generative AI solutions and machine learning operations (MLOps). This underscores the dynamic nature of the employment landscape within the technology sector.”

Kiran Raj, practice head of Disruptive Tech at GlobalData, said, “in the context of AI jobs, this trend represents a dual narrative. While layoffs create challenges within the tech industry, there is also a growing demand for specialized AI and machine learning talent as these technologies become increasingly integrated into business operations.”

This demand, added Raj, is “particularly for generative AI-powered custom applications, catering to specific market needs while enhancing privacy and security.”

According to Saurabh Daga, associate project manager of Disruptive Tech, “the shift towards tailored generative AI tools is increasingly evident, catering to the specific market niches and user needs. This approach is particularly advantageous in sectors like healthcare, finance, and legal, enhancing efficiency and privacy.”

A release issued this week points out that recent analysis of Global Data’s Job Analytics database “underscores these trends where the job postings related to generative AI (GenAI) have grown by 42 per cent from Q3 2023 to Q4 2023. Moreover, the data points towards a much lower five per cent increase in overall AI-related jobs in the same period. This emphasizes the importance that enterprises are placing on transformative outcomes through generative AI.”

In 2024, said Daga, the tech industry stands at a crossroads of transformation and adaptation: “The employment landscape is being shaped by a combination of macroeconomic and technological changes. This dynamic landscape underscores the need for workforce development, hiring, and reskilling to meet the industry’s evolving demands.”

The post Tech sector navigating layoffs while riding GenAI wave, says GlobalData first appeared on IT World Canada.

Cyber Security Today, Week in Review for week ending Friday, Feb. 9, 2024

Welcome to Cyber Security Today. This is the Week in Review for the week ending Friday, Feb. 9th, 2024. I’m Howard Solomon, contributing reporter on cybersecurity for ITWorldCanada.com and TechNewsday.com in the U.S.



In few minutes Terry Cutler of Montreal’s Cyology Labs will be here to discuss recent news. That includes how a deepfake video conference call fooled an employee of a Hong Kong company into wiring US$25 million to crooks, why the U.S. Federal Trade Commission called the cybersecurity of a company “shoddy,” details about a hack at Cloudflare and promises by some countries to get tougher on the abuse of commercial spyware.

Before we get to to discussion I want to do a quick review of other headlines this week:

Remember that deepfake video conference call that I said Terry and I will talk about? One of the ways fake content can be spotted is if it doesn’t have a label or watermark attesting to its legitimacy. There’s a group of tech companies called the Coalition for Content Provenance and Authentication that’s trying to do that. In the latest news Google joined the coalition this week. The goal is to create tamper-resistant metadata that can be attached to any digital content — a photo, a video or an audio file — that shows how and when the content was created or modified.

Remember I said in the discussion Terry and I will also talk about countries promising to take action against the abuse of commercial spyware? The spyware comes from developers who find holes in applications and exploit them. How big a problem is it? Google issued a report this week saying commercial spyware is behind half of the known zero-day exploits targeting Google products and Android devices.

Separately, Google said it is about to start a pilot project in Singapore that blocks the loading of financial fraud apps on Android devices. If it’s successful the effort could spread to other jurisdictions.

A New York City medical centre will pay US$4.75 million to settle allegations by the U.S. Department of Health and Human Services that potential data security failures led to an employee stealing and selling health information on 12,000 patients. The hospital didn’t know about the theft until alerted by police. Problems included failing to monitor and safeguard the hospital’s health information system.

Two big data breach notifications in the U.S. took place this week: Verizon Communications said a staff member stole the personal information of over 63,000 employees last September. And Bayer Heritage Federal Credit Union of West Virginia said personal information on just over 61,000 customers was taken in a cyber attack last fall.

Finally, JetBrains, Cisco Systems, Fortinet and VMware this week released security fixes. JetBrains says there is a critical vulnerability in TeamCity server that needs to be patched. The Cisco patches fix critical holes in Cisco’s secure remote access Expressway Series. Fortinet released updates for its FortSIEM system event manager to plug holes. And VMware released patches for Aria Operations for Networks to close five vulnerabilities.

(The following is a transcript of the first of four topics discussed. To hear the full conversation play the podcast)

Howard: Topic One: An employee was recently suckered into transferring millions to crooks based on a sophisticated deepfake video call.

Hong Kong police say the employee, who worked in the finance department of an unnamed multinational company, was tricked into sending $25 million to crooks by what appeared to be the company’s chief financial officer on a video conference call. The employee got an email message asking them to get on the call, which was about a secret transaction. And there on the video call was the CFO and other people the staffer recognized. So he followed instructions.

This is an example of the sophistication of fake video calls, perhaps helped with artificial intelligence. But the big question is did this company have no business process rules? Like “transfers over $1 million must have double authorization?”

Terry Cutler: This is going to require a multifaceted approach. If you’re dealing with a CFO used to transferring this large amount of money it’s going to be a bit more tricky than just saying, ‘Oh, they didn’t have the proper processes.’ But they’re going to start bringing in more AI-based detection and prevention solutions. What’s going to be happening now is because these deepfakes are so difficult to find it’s going to be having like a detection system on steroids. It’s going to come down to ‘My AI bot just beat your AI bot.’ That’s going to get really tricky. You think humans are eventually going to lose control because they can’t keep up with what’s going on behind the scenes with AI. But have to start looking at something more — maybe more advanced authentication and verification methods. For example, signing their payments with digital signature algorithms either from RSA or ECDSA, which is the elliptic curve digital signature algorithm. These are all tactics that can help.

As for awareness training, we’re seeing a big problem because users are so used to templated training which is very, very, very boring. Employees are not engaging with it. They don’t see a need for cyber security because it doesn’t concern them, but they need to understand that this is everyone’s responsibility. So we need to have other types of training that’s more edutainment. That will help educate them on why it’s so important to stay up-to-date with cyber security, and not just that because they’re a victim of a scam. We [also] need proper incident response plans for what happens when this type of thing goes wrong, especially around deepfakes. It’s getting so difficult to spot them And, of course, they should be sharing information of how this [scam] occurred so other companies don’t fall victim.

Howard: One tip for the employee was the email that that invited him onto this video conference call was, ‘This is a secret transaction.’ In awareness training one of the things you’re warned is to look for little signs like, ‘Please treat this as confidential’ or ‘This is a matter of urgency and you’ve got to transfer this money quickly.’ To be fair to the employee, according to the police, initially was suspicious. But all of the people on this video call looked real and looked like they were people he knew.

Terry: That’s what’s going to be tricky. Imagine you wake up one morning and your bank account is drained and you call up your bank and it says this was an authorized transaction. Your your colleagues were on the call. It was voice-verified. It was email signature verified. Everything was verified — and you’re left with an empty bank account. It’s very very scary what’s coming up.

Howard: I appreciate that this was a big company and presumably was used to transferring large amounts of money — and I assume that the employee was someone who had authorization to transfer large amounts of money. But $25 million is big cash. You need verification controls.

Terry: I agree, and I think this is something they’re going to put in place now. We’re going to have multiple members [of the company] that have to sign off on this [large transfers]. More than just dual authentication. Maybe it’s going to be better to have other people that are responsible for the transaction to be actually on the call. as well as a separate call to make sure it was really them — implement a hierarchical approval workflow. Maybe have some independent channels that can verify via a phone call. Maybe also set up transaction limits.

I’ll give you an example. One of my friends was defrauded of $445,000 from his company. Originally he was never wiring more than $50,000. But when he got hacked the scammers took control of his bank account and started wiring large amounts to Mexico. The banks never stepped in because his accounts were preauthorized for half a million dollars. Because the the threshold was set to to that the [crooks’] transaction went through. So I think they [banks] are going to start looking at transaction limits before giving approvals.

Howard: And as you said, this incident speaks to the sophistication of fake voice and video these days.

Terry: This is really scary stuff, because it’s very difficult to know if it’s fake. We’re going to need help from third-party vendors, maybe some telecoms that can trace the signature see where if it came from.

Howard: In related news, this week Meta announced that it will soon label all AI-generated images that are posted on Facebook and Instagram to help people be aware of fake pictures. It won’t matter whether the images were created with Meta’s AI tool or another company’s tool. There will be some sort of label or watermark. Right now Meta marks photos on Facebook and Instagram that use its tool. It says beside the picture ‘Imagined with AI.’ Hopefully there will soon be a capability to tag not only AI-generated still photos but also videos and audio files. Meta says that if it determines that a digitally created or altered image video or audio has a high risk of deceiving the public on a matter of importance the label may be more prominent than the label that it gives to other images. This watermarking wouldn’t have helped in the deepfake video call case that we just discussed, because that was a private call. But it shows that industry players are thinking about this and trying to find solutions.

Terry: It’s going to be interesting to see, because AI is heavily used for marketing as well. And since since the rise of ChatGPT we see all these so-called marketers that are coming in with new methods to sell their products. There’s a heavy reliance on AI. It’ll be interesting to see social media platforms saying, ‘This was created with ChatGPT and is not original.’

The post Cyber Security Today, Week in Review for week ending Friday, Feb. 9, 2024 first appeared on IT World Canada.

Canada falling behind G7 peers in cybersecurity oversight, warns BlackBerry

Opposing viewpoints on the Liberal government’s proposed cybersecurity law for critical infrastructure providers highlighted a Parliamentary committee hearing on Thursday.

A BlackBerry official urged MPs on the House of Commons national security committee to pass Bill-26, because other countries have laws putting legal cybersecurity responsibilities on the private sector.

“Canada is out of step with its closest allies, and this legislation will help close the gap,” said John de Boer, the company’s senior director of government affairs and public policy for Canada.

Jennifer Quaid, executive director of the Canadian Cyber Threat Exchange, a threat information co-operative, said that with “a few small modifications” the bill will help strengthen cybersecurity among critical infrastructure providers.

And Chris Loewen, executive vice-president for regulatory affairs at the Canadian Energy Regulator (CER), which regulates interprovincial pipeline and electricity operators, said the bill’s mechanisms for regulators would be similar to the way CER currently works.

But Francis Bradley, CEO of Electricity Canada, an association of power providers, warned that the proposed legislation could put Canadian energy producers offside with the cybersecurity requirements of the North American Electric Reliability Corp. (NERC), which oversees U.S. and Canadian companies.

Leila Wright, executive director for telecommunications at the Canadian Radio-Television and Telecommunications Commission (CRTC), said that C-26 would give her agency a new mandate to promote cybersecurity among telecom providers and ensure carriers comply with government cybernetics-related orders. But she wouldn’t comment on omissions or ways the bill could be improved, because it’s a proposed law. The commission’s job, she explained, is to implement legislation that has been passed.

To emphasize the importance of action, de Boer noted that in the last four months of 2023, BlackBerry stopped 5.2 million cyber attacks on behalf of customers; 62 per cent of them targeted critical infrastructure (CI) providers like banks and government departments.

A Five Eyes report this week on the China-backed Volt Typhoon threat group said it had compromised several critical infrastructure providers in the U.S., he noted, including some in the communications, energy, transportation and water sectors. A U.S. official, he added, fears the report is just “the tip of the iceberg.”

Aside from data privacy protection requirements in the Personal Information Protection and Electronic Data Act (PIPEDA), Canada has no legislation to make critical infrastructure providers report, prepare for, or prevent cyber attacks, he said.

By contrast, in 2022 the U.S. passed the Cyber Incident Reporting for Critical Infrastructure Act, requiring CI providers to report cybersecurity incidents to the government within 72 hours. Also in 2022, the European Union passed legislation forcing providers to implement baseline cyber security and to notify national cybersecurity authorities of serious incidents within 72 hours.

“Canada is falling behind our G7 peers in cybersecurity,” de Boer said.

Bill C-26 has two parts: One would amend the Telecommunications Act to give the federal cabinet and the Minister of Industry the power to order designated telecom providers to do “anything” to secure their systems against a range of threats. The CRTC would have a role in ensuring telecom providers comply with the act.

The other part of C-26, creating the CCSPA, would apply to other critical infrastructure providers. Initially, these would be limited to banking, financial clearing firms, interprovincial transport and energy companies, and nuclear power operators. Similar to the Telecommunications Act changes, it would create a cyber security compliance regime for designated firms. Included would be a requirement to report cyber incidents “immediately” to the Canadian Security Establishment (CSE), the branch of the Defence Department responsible for government cybersecurity.

The CCSPA will help governments and the private sector quickly share cyber attack information, de Boer said, warn and protect other potential victims, and rapidly deploy assistance to contain damage from attacks.

The proposed CCSPA isn’t perfect, he said. He recommended three changes:

— the obligation for CI providers to report cyber events immediately should be changed to within 72 hours;

— there should be guarantees that companies can’t be sued or prosecuted for cyber-related information reported to the government;

— and the bill should make it clear firms won’t be punished if they put good faith efforts into cybersecurity, but their firm suffered a breach of security controls or is believed to be offside the law.

Quaid said CCSPA’s preamble should encourage all Canadian public and private organizations to share their cyber threat information; should allow CI providers to share threat information through cyber exchanges as well as with government; and should allow CI providers to join any cyber security threat information sharing association.

Bradley complained the bill doesn’t recognize established security standards and expertise within the Canadian power sector. Among other problems, he said, the bill leaves the definition of a cybersecurity incident that has to be reported to yet-to-be-announced regulations. Our definition must be the same as NERC’s, he said.

Click here to see Electricity Canada’s written submission

NERC’s cybersecurity requirements — which Electricity Canada members have to follow — are higher than the CCSPA, he added, which is why he believes the bill won’t improve cybersecurity among his members on this side of the border.

But Bradley did say that while the cybersecurity of the energy providers here is higher than in other sectors, the CCSPA would help fill the gap.

He doesn’t want to see the passage of the bill delayed, but thinks it should be amended in some areas.

Hearings resume Monday, with testimony from federal Privacy Commissioner Philippe Dufresne, the Office of the Superintendent of Financial Institutions, the Canadian Bankers Association and the Canadian Telecommunications Association.

The post Canada falling behind G7 peers in cybersecurity oversight, warns BlackBerry first appeared on IT World Canada.