Category: News

Cyber Security Today, Feb. 9, 2024 – A record US$1 billion paid to ransomware gangs last year, and more

A record US$1 billion paid to ransomware gangs last year, and more.

Welcome to Cyber Security Today. It’s Friday, February 9th, 2024. I’m Howard Solomon, contributing reporter on cybersecurity for ITWorldCanada.com and TechNewsday.com in the U.S.



Organizations paid out more than $1 billion to ransomware gangs last year. That’s according to numbers compiled by Chainalysis. And that’s just the cash. It doesn’t include the clean-up costs victims paid — and, the report notes, victims who didn’t pay had to cover those business and recovery costs as well. The willingness of organizations to pay is the main reason why ransomware gangs survive and expand, despite arrests, convictions and the takedowns of some gangs’ IT infrastructure. One strategy of many gangs: Fewer attacks but targeting big organizations that can afford to pay big money to get access back to stolen or scrambled data.

One ransomware gang pulled in an estimated US$100 million by not executing ransomware: That was the Cl0p group, which exploited a vulnerability in the MOVEit file transfer application to steal data from over 1,000 organizations. At that scale data theft was more efficient than running ransomware.

According to a separate report this week issued by the NCC Group, three new ransomware groups were detected in December alone. The number of successful ransomware attacks in 2023 rose to a record 4.667 cases.

Meanwhile on Thursday the U.S. State Department announced a US$10 million reward for information leading to the identification of key members of the Hive ransomware gang. It’s also offering US$5 million for information leading to the arrest or conviction of anyone linked to the Hive gang. The FBI took down the gang’s IT infrastructure 12 months ago.

Ivanti has found another vulnerability in its Connect Secure and Policy Secure gateways, as well as its ZTA gateway. The patch was quietly released for customers on January 31st and is only publicly being announced now. IT administrators that haven’t plugged this hole by now had better get cracking.

Want to download the LastPass password manager for your iPhone? Beware of an app impersonating the real one on the Apple App Store. Despite Apple’s attempts to keep malware out of the store, this one snuck in. The fake can be identified by its name: LassPass, instead of LastPass.

The U.S, has created an Artificial Intelligence Safety Institute Consortium. Its goal is to unite AI creators and users, academics, industry researchers and others to help develop and deploy trustworthy AI applications. This follows President Joe Biden’s Executive Order of last October requiring developers of the most powerful AI systems to share their safety test results with the federal government.

Later today the Week in Review podcast will be out. Terry Cutler of Cyology Labs and I will discuss some news headlines from the past seven days.

Follow Cyber Security Today on Apple Podcasts, Google Podcasts or add us to your Flash Briefing on your smart speaker.

The post Cyber Security Today, Feb. 9, 2024 – A record US$1 billion paid to ransomware gangs last year, and more first appeared on IT World Canada.

Superbowl ad from Microsoft tries to make peace between artists and AI: Hashtag Trending for Friday, February 9th, 2024

Microsoft’s Superbowl ad tries to make peace with artists. Google giveth – bringing Gemini to Canada and Meta threatens to taketh away with a veiled threat against their Montreal workforce if the government regulates AI in a way they don’t like.

All this and more on the “nice economy you got there, shame if something should happen to it” edition of Hashtag Trending. I’m your host Jim Love, CIO of IT World Canada and TechNewsDay in the US.

I was about to do a story asking if Google was punishing Canada for our government’s insistence that they actually pay Canadian publishers for the news they use and make money from, but then the folks at Google made me eat my (almost) words.

Google has announced the launch of its generative artificial intelligence (GenAI) chatbot, Bard, now available in Canada and rebranded as Gemini.

So not only are we getting the latest in Google’s AI, but we get in in Canada – no more VPN to pretend we’re American.

And Google is offering this to both English and French-speaking Canadians.

The rebranding to Gemini seems to indicate that Google is trying to turn a new page and give OpenAI a run for our money.

There are various versions to cater to different devices and use cases, including Gemini Nano for smartphone processing and Gemini Ultra for more complex tasks like coding and logical reasoning.

And Gemini Advanced is part of the new Google One AI Premium Plan, priced at $26.99 per month CANADIAN.

It offers subscribers an integrated AI experience across Google Workspace applications, including Gmail, Docs, Slides, and Sheets. This integration, formerly known as Duet AI, embeds AI into everyday digital experiences, making sophisticated AI tools more accessible to a wider audience.

Mobile apps are coming soon, but initially only in English, we hope that French will be coming soon.

Sources include: IT World Canada,

Meta, the parent company of Facebook, has expressed concerns over Canada’s proposed Artificial Intelligence and Data Act (AIDA). During a parliamentary hearing, Rachel Curran, head of public policy for Meta Platforms in Canada, voiced that Meta might reconsider launching some of its products in Canada if the proposed AI law remains unchanged.

More than that, she said, “Our global AI research is based in Montreal. The wrong regulatory framework, over-reach, or over-regulation by the government would drive that kind of activity out of the country. And I would hate to see that because we are leaders in AI research.”

AIDA, part of Bill-C-26, seeks to regulate AI systems by categorizing them into three classes based on their potential impact.

The legislation aims to mitigate risks of harm or biased outputs from AI systems, a move that has been met with both support and criticism from the tech industry.

While some provisions of AIDA are applauded for their intent to maintain public trust in AI applications, tech leaders, including those from Amazon, Google, and Microsoft, have called for more clarity and flexibility in the law.

They argue that overly stringent regulations could stifle innovation and place an undue burden on the Canadian AI industry.

As Canada strives to align its AI legislation with international standards, the outcome of these discussions will be crucial in shaping its position as a leader in AI research and development.

But as a Canadian, I must say that this “nice economy you got there, be a shame if something should happen to it” sounds a little thuggish from Meta.

Sources include: IT World Canada

Two quick stories for this week that we want to make sure you catch. First, in response to the AI Deep Fake calls that have happened which have faked Joe Biden’s voice and are spreading what Biden would call  “malarkey” – the Federal Communications Commission in the US is outlawing robocalls that have AI generated voices.

Telemarketers in the US cannot use automated dialers or artificial or pre-recorded voice messages to call cellphones, and they cannot make such calls to landlines without prior written consent from the call recipient. And if they use Deep Fakes, there will be penalties.

Sources include: AP News

And I know Howard Solomon has covered this on our sister podcast, CyberSecurity Today, but this week it was discovered that a Chinese Hacker Volt Typhoon had infiltrated US infrastructure and had been there for more than 5 years. I wouldn’t bet against them having a similar foothold in Canada.

Check out Howard’s podcast or stories for me news. But ITWC also will be doing a look at civic infrastructure in Canada in our Technicity event series – watch for it.

And yes, even we have a mandatory SuperBowl story.

Microsoft has recently unveiled a significant update to its Copilot AI search and chatbot experience, introducing a new AI image creation and editing functionality alongside a fresh AI model named Deucalion.

This move not only enhances the capabilities of Copilot and not also signals Microsoft’s deepening commitment to integrating generative AI technologies into everyday digital tools, but it says – hey, we’re not ceding the digital image space to anyone.

But they are also doing some brilliant PR on this one.  Microsoft’s has a new Super Bowl ad, which positions Copilot and AI as empowering tools for innovation and creativity, challenging the narrative around AI as a threat to creative professions.

This is one time when an audio podcast is a bit of a disadvantage, because the ad is really well done and describing it won’t do it justice.

But we’ll put a link in the show notes for those of your who may not catch the Swift Bowl, I mean the SuperBowl.

Link to the YouTube version of the ad.

Sources include: VentureBeat

Hashtag Trending goes to air five days a week with daily news and a weekend interview show that we creatively called – the weekend edition.

We love to hear from you. Send us a note at jlove@itwc.ca or drop us a comment under the show notes at itworldcanada.com/podcasts – look for Hashtag Trending.

Thanks for listening and have a Fabulous Friday and a Swifty Superbowl weekend.

The post Superbowl ad from Microsoft tries to make peace between artists and AI: Hashtag Trending for Friday, February 9th, 2024 first appeared on IT World Canada.

Google launches Bard GenAI in Canada, rebrands it to Gemini

Google today announced that its generative artificial intelligence (GenAI) chatbot, Bard, is now available to Canadians, in both English and French. At the same time, it announced that Bard has been renamed Gemini.

Sissie Hsiao, vice president and general manager, Gemini experiences and Google Assistant, explained the name change: “Our mission with Bard has always been to give you direct access to our AI models, and Gemini represents our most capable family of models. To reflect this, Bard will now simply be known as Gemini.”

Google’s group product manager, Gemini experiences Jules Walter said Gemini is, a “much more powerful model,” which the company launched in December in three flavours of various sizes to accommodate different devices and use cases.

Gemini Nano was released to handle on-device smartphone processing, Gemini Pro for Bard, and Gemini Ultra, an even more powerful model capable of coding and logical reasoning, is available in Gemini Advanced, a premium subscription service.

Gemini Advanced is part of the new Google One AI Premium Plan, launched today at C$26.99 per month, with a two month free trial.

According to Jack Krawczyk, product lead, Gemini experiences, the plan includes all of the features of the Google One Premium Plan, plus what he called “the best of Google AI”, and, in addition, subscribers will soon be able to use Gemini in Gmail, Docs, Slides, and Sheets. This functionality was formerly known as Duet AI, but is now called Gemini for Google Workspace.

Also coming soon are mobile apps, but only in English to begin with. Android will receive a new Gemini app, while iOS users will access Gemini through the Google app.

For now, Gemini access is via its website.

The post Google launches Bard GenAI in Canada, rebrands it to Gemini first appeared on IT World Canada.

Meta may not bring some products to Canada unless proposed AI law changed, Parliament told

Officials from four of the biggest tech companies in the world — Amazon, Google, Microsoft and Meta — largely offered polite criticism of the country’s proposed artificial intelligence law to Canadian parliamentarians for over an hour at a hearing Wednesday.

Several agreed the Artificial Intelligence and Data Act (AIDA) legislation should be passed quickly, but with certain provisions more clearly defined, and allowing more rules to be set in regulations than in the law so it will be flexible.

And then it was like a mask dropped.

It came after Microsoft Canada’s Amanda Craig, the company’s senior director of public policy in the office of responsible AI, gave a lengthy explanation of things that could be improved.

Then Rachel Curran, head of public policy for Meta Platforms in Canada, was asked to comment.

“I think Amanda is being very diplomatic,” she told the House of Commons industry committee.

“AIDA in a number of respects goes well beyond the most stringent proposal out there internationally, which is the EU Act — which is already the subject of a lot of debate amongst [European Union] member states. It doesn’t have the support of countries like France, for instance, who want to make sure their own domestic industry is given a chance to flourish. So AIDA has created a standard that doesn’t exist anywhere else in the world.”

If AIDA passes as is, Meta could meet its requirements for regulating AI systems, she said. But, Curran added “the compliance costs are incredibly high. Would that mean certain [Meta] products would not be launched in Canada? Maybe. But all of us work for companies that are able to meet very high [regulatory] thresholds because we have the resources and money to do that.” On the other hand, “it’s going to have a significant impact on the Canadian AI industry and on innovation in Canada.

“Canada should make sure it aligns itself [in AI legislation] with other jurisdictions. We’re a relatively small market. The EU is setting a benchmark that is world-leading. We should at the very least not exceed that.”

Passing AI legislation fast is important, Curran said, if only to maintain public trust in artificial intelligence applications. But, she added, it’s also important to get the legislation right. AIDA is “a pretty good bill,” she said at one point. “It’s just a question of whether we can get the good details right.”

But, at another point, she said this: “Our global AI research is based in Montreal. The wrong regulatory framework, over-reach, or over-regulation by the government would drive that kind of activity out of the country. And I would hate to see that because we are leaders in AI research.”

Nicole Foster, director of Amazon Web Services’ global artificial intelligence and Canada public policy, agreed with Curran on the need to not get ahead of other countries. At the very least, she added, MPs should hear the opinions on the impact of AIDA from Canadian firms who are, or will be, using AI applications.

AIDA is part of Bill-C-26, which includes a proposed Consumer Privacy Protection Act (CPPA).

AIDA would oversee three classes of AI systems — high-impact, general impact, and machine learning systems — used in areas such as employment, providing services to an individual, processing biometric information for identification, moderating content on a search engine or social media platform, and more. It would be illegal to deploy an AI system likely to cause serious physical, psychological, or economic harm to an individual. Persons responsible for high-impact systems would have to establish measures to identify, assess, and mitigate the risks of harm or biased output that could result from the use of the AI system.

In its initial version, AIDA left a lot of grey areas — such as defining a “high impact” AI system — to be filled in by regulations proclaimed by the government. Those regulations would be set after consultations with experts, including the tech industry. The approach would allow flexibility to meet the challenges of fast-moving AI technology. But some worried about passing vague legislation. So Innovation Minister Champagne sent the committee a letter outlining amendments and clarifications the government is willing to make to the legislation.

However, Curran believes the original version — leaving a lot to regulations — was better. “The minister’s proposed amendments, if accepted by this committee, are going to box Canada into a regulatory framework that may look very different than the one that emerges from international discussions,” she said.

In addition, Curran objected to AIDA covering the moderation of content on social media platforms like Meta. Controls over social media would be better put in the government’s long-promised online harms bill, she said.

Several of the witnesses Wednesday also objected to AIDA’s proposal to give a new AI and Data Commissioner power to enter a firm’s premises, access systems, copy data, and conduct testing of AI systems if the commissioner has reasonable grounds to believe that an organization has contravened or is likely to contravene their obligations under AIDA.

There were also objections over the proposal that employees could be convicted of a criminal offence for mishandling personal data from an AI system. And there were suggestions that some enforcement of AIDA should be put in the hands of regulators that already look after specific industries.

“I’m a bit confused,” Bloc Quebecois MP Jean-Denis Garon admitted late in the session. “You say Parliament needs to regulate AI,” he said to the four witnesses, “then you say C-27 is trying to cover too much, and one suggests it may be better to regulate AI by amending existing legislation covering regulated sectors.” That, he said would require “un-ending legislative work …and bottom line, we’d end up with no regulation … Is this your way of telling us you don’t want regulation?”

“We support good regulatory frameworks,” replied AWS’s Foster. “All of us do.” But if acting fast is the issue, potentially the government can move faster by amending existing legislation.

The U.K. has decided for the time being to let regulators such as the Information Commissioner and the Competition and Market Authority to issue regulations for AI oversight.

The post Meta may not bring some products to Canada unless proposed AI law changed, Parliament told first appeared on IT World Canada.

CIO Association of Canada turns 20: Hashtag Trending for Thursday, Feb 8, 2024

Tesla’s stock is the biggest loser on the S&P 500. YouTube is hailed as one of the most engaging social media sites, LinkedIn introduces AI tools to save time managing your network, Vision Pro headsets may be a hazard and the CIO Association of Canada turns 20.

All this and more on the “my how the years have flown” edition of Hashtag Trending. I’m your host Jim Love, CIO of IT World Canada and TechNewsDay in the US.

This month marks the 20th Anniversary of the CIO Association of Canada (CIOCAN).

Founded in 2004, with its roots tracing back to Vancouver in 1998, CIOCAN emerged from a collective aspiration to forge a unified platform for Chief Information Officers (CIOs) and technology leaders. This platform was envisioned as a space for sharing ideas, insights, and best practices among the brightest minds in what was at the time still a C level job that was all too often struggling for recognition.

As CIOCAN celebrates this landmark anniversary, few would question how important technology is today, but it wasn’t too long ago that technology was thought of as something like plumbing or heating – we needed it, but we weren’t looking to use it strategically. In many companies, the CIO reported into Finance where they were treated like an expense to be kept under tight management.

Today, as the cloud and AI accelerate the digital transformation of every aspect of business and our lives, the role of the CIO is often respected and in most successful companies, the head of technology, is thought of as a true C level strategic business leader.

Over the years, we CIOs have had to change and the support of our association and our peers has been essential.

Full disclosure – I am a member of the CIOCAN, and it is still the place where technology leadership can gather and discuss our mutual concerns, issues and opportunities with our peers. There are chapters all across the country where they have regular meetings and every year there is an annual Peer Forum, this year it’s in Calgary.

If you’ve been around for a few years, and what to think about how we got here, my friend and colleague Philippe Johnston shares his reflections and the journey of the CIO Association of Canada on the association’s website.

If you want to learn more about the role of the CIO, look for our annual CIO Census coming out in the next month or so or join us in one of the local or even the national events.

And if you work for a great CIO or an up-and-coming tech leader, why not nominate them for the Canadian CIO of the Year award – sponsored by CIOCAN and IT World Canada.

As always there are links in the show notes or just check ITWorld Canada.com

Sources include: CIO Association of Canada, https://www.ciocan.ca/20th-anniversary

A recent story from DigitalSilk.com analyzed data from SimilarWeb and came up with a rating of social media sites in terms of user engagement – taking metrics like the average number of pages visited per user and duration of visits.

Topping the charts is YouTube, hailed as the most engaging social media site.

YouTube’s dominance is attributed to its impressive average visit duration of 19 minutes and 35 seconds coupled with users navigating through 11.08 pages per visit.

Following closely are Reddit and Snapchat, securing the second and third spots, respectively, with Reddit users spending about 15 minutes and 55 seconds and Snapchat users 14 minutes and 10 seconds per visit.

X.com, the platform formerly known as Twitter, and Instagram round out the top five.

There’s a table on the show notes with a link to DigitalSilk.com

Interestingly, despite the buzz around TikTok, it didn’t crack the top ten, suggesting that engagement metrics may not be catching mobile usage or some other measurement issue. I’ve put a message out to DigitalSilk, but haven’t heard back as of the time of recording of today’s episode.

Sources include: DigitalSilk.com

 

Rank
Social media site
Pages per visit average
Average visit duration (mins)

1
YouTube
11.08
19:35

2
Reddit
10.49
15:55

3
Snapchat
8.34
14:10

4
X.com
10.19
10:53

5
Instagram
11.53
08:19

6
Facebook
9.15
10:36

7
BlueSky
6.30
09:37

8
LinkedIn
7.98
07:42

9
Tumblr
6.84
08:44

10
Pinterest
7.74
07:05

 

In a recent LinkedIn article, Naman Goel, Senior Director of Product at LinkedIn, talked about the evolving landscape of professional networking in 2024. With an astonishing 85% of professionals contemplating a job change this year, the significance of networking has never been more pronounced.

However, the challenge of nurturing a professional network is time consuming, taking over 300 hours annually for nearly a quarter of individuals who dedicate 6-10 hours weekly to this endeavor.

LinkedIn’s response to this is a revamp of the Network Tab, now featuring two distinct sections: “Grow” and “Catch Up.”

The “Grow” tab aims to simplify the expansion and management of your network by offering personalized recommendations through LinkedIn’s sophisticated AI algorithms.

On the other hand, the “Catch Up” tab provides users with timely prompts to reconnect with your network, celebrating milestones like new jobs, work anniversaries, or birthdays, thereby fostering meaningful engagements.

LinkedIn is also tackling the “blank page problem” head-on with a new Premium feature that employs AI to assist users in crafting initial messages to potential connections. This tool suggests drafts based on the profiles of both the sender and the recipient, encouraging personalized and relevant communication.

As I said in my comments on LinkedIn, the tools to help manage our networks and help us be more efficient at keeping track of people are welcome. But if you need an AI program to help you send me a message, I’d say don’t bother.

By all means use AI to help you with all kinds of writing tasks, brainstorming, outlining and yes, please – proofreading. But when it comes to personal messages?  If you don’t know what you want to say, you probably don’t really want to talk to me.

I can talk to ChatGPT directly and cut out the middleman.

Sources include: Naman Goel’s LinkedIn article (search for it on Linked In)

Tesla’s stock performance makes it as the worst-performing stock in the S&P 500 this year, with a 24% decline.

This downturn is attributed to a number of factors.

Key among these challenges are the numerous recalls that have plagued Tesla, raising concerns about the reliability and safety of its vehicles.

Additionally, CEO Elon Musk’s erratic behavior has been well documented in terms of its impact on Twitter, but now at Tesla, his behaviour has again come under scrutiny, with reports of alleged drug use so concerning that it’s rumored his board has suggested rehab.

But Musk alone isn’t the total cause of Tesla’s stock woes. There is also increased competition from both domestic and international automakers, which are rapidly expanding their electric vehicle offerings. This competitive pressure is intensifying at a time when Tesla needs to solidify its market leadership and innovate to maintain its edge.

In that light, investor sentiment has been further dampened by Musk’s outsized influence on the company. While Musk’s visionary leadership has been a key driver of Tesla’s past success, his recent actions and the controversies surrounding him have led to significant shareholder value erosion.

The company’s annual report acknowledges its heavy dependence on Musk, highlighting the risk that his less favorable antics pose to investor confidence and the company’s market valuation.

Sources include: Quartz

A recent trend has emerged that even in an age of social media stunts, seems particularly inane – people wearing Apple Vision Pro headsets in inappropriate and unsafe places.

The Vision Pro headsets, released by Apple on February 2, 2024, promise an immersive experience that blends digital applications with the user’s physical environment. However, the allure of this new gadgetry has led to a spate of social media stunts, including videos of individuals navigating the roads in Teslas, their vision obscured by the headsets.

These videos, while not widespread, have been alarming enough to prompt a public response from figures like Transportation Secretary Pete Buttigieg and the National Highway Traffic Safety Administration (NHTSA). Their message is clear: the act of driving demands undivided attention, a principle seemingly forgotten by those chasing viral fame.

If we have reached a point where officials must explicitly warn against driving while watching virtual reality, what does it say about our collective judgment in the digital age?

Content creators like Dante Lentini, whose video of driving while wearing the Vision Pro went viral, claim their actions are purely for entertainment.

Yet, the implications of such stunts ripple far beyond their intended comedic value, highlighting a disturbing trend of prioritizing online engagement over real-world consequences.

Lentini’s admission that the video was staged and that police presence was coincidental does little to mitigate the potential risks such content glorifies.

As we navigate the complexities of a world increasingly augmented by digital innovations, we may be in danger of losing the distinction between the virtual and the real, which sadly can have tragic consequences in situations as critical as driving.

We worry about artificial intelligence dooming the human race, when lack of intelligence may be a bigger concern.

Sources include: New York Times article by Jesus Jiménez, February 6, 2024

Hashtag Trending goes to air five days a week with daily news and a weekend interview show that we creatively called – the weekend edition.

We love to hear from you. Send us a note at jlove@itwc.ca or drop us a comment under the show notes at itworldcanada.com/podcasts – look for Hashtag Trending.

Thanks for listening and have a Thrilling Thursday.

The post CIO Association of Canada turns 20: Hashtag Trending for Thursday, Feb 8, 2024 first appeared on IT World Canada.

Info-Tech report outlines 5 GenAI initiatives CIOs must key in on

As generative artificial intelligence (GenAI) continues to reshape the digital landscape, CIOs and IT leaders are at a pivotal point, tasked with navigating the profound opportunities and challenges this disruptive technology presents, a new report from Info-Tech Research Group concludes.

To help guide CIOs who wish to take advantage of what the technology can offer, the CIO Priorities 2024 report outlines what the research firm describes as “five key initiatives poised to drive significant value across diverse organizational contexts in 2024.”

The five revolve around:

Augmenting the business with GenAI: Survey findings indicate a “cautious approach toward adopting new GenAI features among organizations, particularly those with lower IT maturity possibly due to vendor risk or intellectual property concerns. In contrast, high IT maturity firms are more proactive, with more than half reporting either planning to apply for beta access to new features or planning to move ahead upon their general availability.” CIOs and IT leaders, a release states, need to strategically integrate GenAI capabilities into business processes, deciding whether to develop in-house solutions or procure them.

Right-sizing AI governance: According to the report, organizations are facing a “balancing act with risk management and fostering innovation. When asked about who is responsible for AI governance, 30 per cent of respondents from both high and low IT maturity organizations reported that it is the role of the CIO. This year, CIOs and IT leaders must design and establish AI governance frameworks that provide necessary oversight and specific policies that align with existing risk management practices without imposing bureaucracy and auditing that stifles innovation.”

Updating vendor risk assessments: The research, Info-Tech maintains, “underscores the increasing threat of supply chain attacks, where cybercriminals exploit vulnerabilities in the software tools and services used by organizations. This threat makes companies susceptible to the risks of their vendors. To mitigate these threats, especially those related to AI, Info-Tech advises that CIOs and IT leaders establish or update their vendor risk assessment programs to include AI-specific considerations.”

Exponentially increasing innovation: According to the report, CIOs identified innovation as a key driver for maintaining competitiveness and enhancing customer and employee experiences. It notes that “despite AI being earmarked as a primary area for new investment in 2024, many organizations report not having conducted proofs of concept or pilots with AI to validate business cases. To harness AI’s full potential, CIOs and IT leaders must prioritize expanding their exploration of AI use cases, moving from ideation to pilot testing more rapidly.”

Exponentially improving customer experience: Analysis of the survey data reveals that IT leaders are “moderately concerned about potential disruptions to their organizations due to changing customer behaviors, second only to cybersecurity incidents. By embedding AI into customer journey interactions, CIOs and IT leaders can automate, augment, and reduce friction at every point of the customer journey, accelerating service delivery and enhancing overall satisfaction.”

Brian Jackson, principal research director with Info-Tech and lead analyst for the report, said, “in our assessment of the 2024 IT landscape, GenAI emerged as the clear trend, a focal point of our Tech Trends 2024 report.

“This technology introduces significant opportunities and challenges. The critical question for CIOs and IT leaders is which capabilities need enhancement to leverage these opportunities and which initiatives should be prioritized to navigate the accompanying enterprise risks effectively.”

This year, he added, GenAI is “like an elephant in the C-suite office, trumpeting its demands to be addressed. Whether through internal build efforts or through new vendor features, generative AI must be addressed by CIOs and IT leaders. This technology is the next wave lifting the expectations of customers and business stakeholders.”

The post Info-Tech report outlines 5 GenAI initiatives CIOs must key in on first appeared on IT World Canada.

China group may have been hiding in IT networks for five years, says Five Eyes warning

Following recent American warnings of China’s efforts to secretly plant itself on critical infrastructure for future cyber attacks, Canada and other members of Five Eyes intelligence co-operative today issued a joint advisory so firms in all countries in the group will be on alert — and other nations watching their actions will hear as well.

“People’s Republic of China (PRC) state-sponsored cyber actors are seeking to pre-position themselves on IT networks for disruptive or destructive cyberattacks against critical infrastructure in the event of a major crisis or conflict,” the warning says.

In fact, it notes, the U.S. has evidence Volt Typhoon has been maintaining access and footholds within some victim IT environments for at least five years.

The partners — including Canada, the U.S., Australia, the U.K., and New Zealand — released the advisory to warn critical infrastructure organizations about the assessment by American cyber authorities, based on incident response activities at critical infrastructure organizations.

In particular, the warning urges infosec pros to watch for activity from the PRC state-sponsored cyber group known to researchers as Volt Typhoon (also called Vanguard Panda, Bronze Silhoutte, Dev-0391, UNC3236, Voltzite, and Insidious Taurus by different researchers).

“The U.S. authoring agencies have confirmed that Volt Typhoon has compromised the IT environments of multiple critical infrastructure organizations—primarily in communications, energy, transportation systems, and water and wastewater systems sectors—in the continental and non-continental United States and its territories, including Guam.” the warning says.

“Volt Typhoon’s choice of targets and pattern of behavior is not consistent with traditional cyber espionage or intelligence gathering operations, and the U.S. authoring agencies assess with high confidence that Volt Typhoon actors are pre-positioning themselves on IT networks to enable lateral movement to OT assets to disrupt functions. The U.S. authoring agencies are concerned about the potential for these actors to use their network access for disruptive effects in the event of potential geopolitical tensions and/or military conflicts.”

The Canadian Centre for Cyber Security believes that the direct threat to Canada’s critical infrastructure from PRC state-sponsored actors is likely lower than that to U.S. infrastructure, the warning says. But, it adds, should U.S. infrastructure be disrupted, Canada would likely be affected as well, due to cross-border integration of critical infrastructure providers.

Public warnings of Volt Typhoon emerged last May in a report from Microsoft. It said the group has targeted critical infrastructure organizations in Guam and elsewhere in the United States since 2021, probably for espionage. Its tools include the KV botnet for distributing malware.

Then, in December, researchers at Lumen Technologies reported details about the KV botnet. Researchers at SecurityScorecard followed up with a report that Volt Typhoon had compromised two models of vulnerable end-of-life routers from Cisco Systems in December.

Fighting back, last month the U.S. disabled Volt Typhoon’s botnet of hundreds of U.S.-based small office/home office (SOHO) routers that were distributing malware.

Volt Typhoon will compromise a network in various ways, including password cracking, leveraging stolen credentials, and exploiting hardware or software vulnerabilities. In one confirmed compromise, the report says, Volt Typhoon actors likely obtained initial access by exploiting CVE-2022-42475 in a network perimeter FortiGate 300D firewall that was not patched.

After establishing a foothold, a favoured tactic is to use common tools already on a victim’s IT or OT network (also called living-off-the-land) to hide and maintain persistence on the network. “Evidence of their meticulous approach is seen in instances where they repeatedly exfiltrate domain credentials, ensuring access to current and valid accounts,” says the warning.

The warning also links to mitigations that critical infrastructure providers — including utilities, financial institutions, transportation firms, hospitals and others — should act on.

The post China group may have been hiding in IT networks for five years, says Five Eyes warning first appeared on IT World Canada.

Few infosec pros think higher ed prepared them for their jobs: Survey

Infosec pros don’t have much respect for the cybersecurity or information security courses offered in colleges and universities, a new survey suggests.

Half of the respondents to a new survey done for Kaspersky said the availability of cybersecurity or information security courses in formal higher education is either poor, or very poor. This number increased to 83 per cent for professionals with two to five years of work experience.

One in two respondents doubted that their educational experience prepared them for their real-life role. Further, less than half of respondents said their college or university program offered them hands-on experience in real-life cybersecurity scenarios, and that they have since had to personally invest in additional training to keep up with the evolving threat landscape.

“How useful was your higher education in your day-to-day infosec work?” Source: Kaspersky report

The survey questioned 1,012 infosec professionals in 29 countries, including the U.S., the U.K., Japan, China, and Russia. It hopes to analyze the causes of the current cybersecurity talent and skills gap.

Fifty-three per cent of respondents didn’t have post-graduate or higher degrees.

Nearly 40 per cent of respondents said their college trainers and teachers didn’t have real-life experience in the cybersecurity industry.

“The lack of teaching personnel with real-world experience in cybersecurity might be one of the biggest reasons explaining traditional education’s detachment from the industry and respondents hesitating to call their formal studies useful,” says the report.

“Of the infosec professionals with two to five years’ experience, just 19 per cent feel their formal education was extremely useful or very useful in their day-to-day work, while three-quarters of these young professionals say the theoretical knowledge they got was not useful in helping them fulfill their responsibilities. However, this trend is skewed towards mid and senior-level professionals.”

To tackle the cybersecurity skills shortage, Kaspersky suggests:
— higher education institutions upgrade their curriculums by partnering with cybersecurity vendors;
— students supplement their academic training with internships in an organization’s infosec department;
— infosec pros participate in international hacking competitions to hone their skills;
— infosec pros adopt a continuous learning attitude.

The post Few infosec pros think higher ed prepared them for their jobs: Survey first appeared on IT World Canada.

Defence department upbraided for not doing PIAs on data extraction tools

Senior Canadian Defence Department IT officials have been rebuked by an MP for not doing a privacy impact assessment on software that can extract personal data from military members’ government-issued computing devices.

Parliament’s privacy and ethics committee has been looking into a news report that 13 federal departments — including defence — have access to data extraction software, but haven’t completed privacy impact assessments (PIAs) as required by government policy.

According to the Office of the Privacy Commissioner, a PIA is a risk management tool that helps ensure the privacy impacts of technologies handling personal information are either addressed or minimized before a problem occurs.

On Tuesday, officials from five of the departments appeared before the committee, with some saying they were in varying stages now of doing PIAs on their applications.

Department of National Defence (DND) IT officials said they have an unnamed application and that it has been used.

Asked by MP Larry Brock if DND completed a PIA assessment before using it, the officials weren’t in alignment.

“I’m not sure, to be honest,” replied Sophie Martel, DND’s acting chief information officer.

“We did not,” said Brig-Gen. Dave Yarker, director general for the defence department’s Cyber Command and control information systems operations.

“Why do you think you don’t have to do it?” Brock demanded.

“Your members are Canadian citizens … Your failure to do a PIA is a failure to safeguard and protect the privacy of your members.”

The hearing was sparked by a Radio-Canada report late last year that “spyware normally associated with the intelligence world is being used by 13 federal departments and agencies,” including products from Cellebrite and Magnet Forensics.

None of the departments did a software privacy impact statement, the news story said. That was partly confirmed in testimony last week from federal privacy commissioner Philippe Dufresne. He found three departments had submitted PIAs on the software, but eight had only started the work, or were considering doing a new assessment or updating an existing one. One department believes a PIA isn’t required, while another said it bought the software but hasn’t used it, so hasn’t done a PIA.

That department would appear to be Natural Resources, whose staff testified Tuesday that if its tool has to be used, a PIA would immediately be filled out.

Witnesses — and some MPs — strove to make it clear there’s a difference between spyware — applications inserted surreptitiously on a mobile device to monitor communications — and forensic tools like Cellebrite or Magnet Forensics that are used to pull data from devices a department may have seized.

“We’re not surveilling Canadians,” Martel said. “We’re here to support Canadians. We’re here to keep them safe. We’re monitoring (DND) networks. We’re not monitoring people.”

“We would not be called upon to surveil Canadians,” added Yarker. “It’s not within our mandate.”

RCMP Deputy Commissioner Bryan Larkin confirmed the Mounties do use digital extraction tools including Cellebrite and Magnet Forensics. “These tools are not used for surveillance or mass surveillance,” he said.

PIAs for RCMP applications will be done by the middle of the year, he added.

The committee also heard Tuesday from officials from the Correctional Service of Canada and the Canadian Border Services Agency (CBSA).

Aaron McCrorie, vice-president of the border agency’s intelligence and enforcement unit, said data extraction tools are used to unlock mobile devices seized from people trying to enter Canada, under court orders.

France Gratton, assistant commissioner for correctional operations and programs at Corrections Canada, said the data extraction tool is used only on mobile devices seized from prisoners, which they aren’t allowed to have.

Officials from other departments are scheduled to testify Thursday. However, MPs appeared to be convinced there is no outbreak of spyware being used against Canadians by government departments. Instead, they seemed to agree upcoming hearings should focus on asking officials of Treasury Board why its policy that PIAs have to be done for all applications used by federal departments isn’t being followed, and asking unions representing federal employees if they have concerns about possible electronic surveillance in the workplace.

According to the federal privacy commissioner, a PIA should include:

a description of the planned program or activity and its objectives;
an assessment of the program’s privacy compliance as well as its potential impacts on individuals’ privacy;
the measures planned to minimize impacts and to comply with the Privacy Act (the privacy legislation federal departments and agencies must follow), applicable Treasury Board policies, directives, and guidelines, as well as best practices.
The post Defence department upbraided for not doing PIAs on data extraction tools first appeared on IT World Canada.

Coffee Briefing Feb. 6 – AWS and University of Alberta collaborate to launch AI centre; Cisco survey reveals data privacy trends; ISED seeks to give Indigenous applicants priority access to spectrum; and more

Coffee Briefings are timely deliveries of the latest ITWC headlines, interviews, and podcasts. Today’s Coffee Briefing is delivered by IT World Canada’s editorial team! 

Missed the last Coffee Briefing? We’ve got you covered.

AWS and University of Alberta team up to launch new AI centre

Amazon Web Services (AWS) and the University of Alberta have teamed up to launch a new centre: the Artificial Intelligence Discovery Place.

Located in U of A’s downtown Enterprise Square campus, the centre seeks to accelerate the speed of discovery for researchers and make artificial intelligence more accessible to Edmonton’s tech scene.

“To unlock the full potential of AI to tackle the world’s most challenging problems, we need to make AI education and services accessible to anyone,” said Coral Kennett, AWS Canada Education Lead. “With the Artificial Intelligence Discovery Place, AWS and the University of Alberta are working together to democratize access to AI technology. We cannot wait to see how faculty, students, and industry use AWS cloud services to advance groundbreaking research in all areas of society.”

The two organizations have been working together since 2016. The U of A was one of the first Canadian universities to sign on with AWS to innovate faster with the cloud.

Businesses recognize they need to do more to reassure customers on data privacy: Cisco

 

 

Ninety-one per cent of businesses acknowledge they need to do more to reassure customers that their data is used for intended and legitimate purposes in artificial intelligence, Cisco revealed in a survey of 2,600 privacy and security professionals across 12 geographies.

More than 90 per cent of respondents believe GenAI requires new techniques to manage data and risk; 63 per cent have established limitations on what data can be entered; 61 per cent  have limits on which GenAI tools can be used by employees; and 27 per cent said their organization had banned GenAI applications altogether.

A whopping 98 per cent of organizations are also touting the importance of external privacy certifications as a factor in buying decisions, which Cisco said is the highest they’ve seen over the years.

“94 per cent of respondents said their customers would not buy from them if they did not adequately protect data,” explained Harvey Jang, Cisco vice president and chief privacy officer. “They are looking for hard evidence that the organization can be trusted. Privacy has become inextricably tied to customer trust and loyalty. This is even more true in the era of AI, where investing in privacy better positions organizations to leverage AI ethically and responsibly.”

Accordingly, over the past five years, privacy spending has more than doubled, benefits have gone up, and returns remained strong, with 95 per cent of organizations indicating that privacy’s benefits exceed its costs.

Eighty per cent of respondents even claimed that privacy laws have had a positive impact on them, despite the costs and requirements that come along with regulation, notably as they cited compliance with privacy laws and avoiding data breaches as some of their top priorities.

Toronto quantum company introduces a PhD fellowship in quantum machine learning in partnership with Qatar-based university

Photonic quantum computing company Xanadu has announced that it will collaborate with Hamad Bin Khalifa University’s (HBKU) Qatar Center for Quantum Computing (QC2) on a PhD fellowship in quantum machine learning.

This collaboration is an extension of the partnership established in November 2023 which aims to train and educate a quantum-ready workforce in Qatar.

HBKU’s QC2 offers several PhD fellowships to students focused on theoretical and experimental research related to quantum information science. Fellowship recipients may also receive a fully funded scholarship. However, this year, students have a unique opportunity to travel to Xanadu HQ in Toronto, Canada, for a 1-2 month internship.

“We look forward to welcoming HBKU students to Xanadu and continuing to work alongside the university to offer training and educational materials and grow the quantum workforce in Qatar,” said Christian Weedbrook, Xanadu founder and chief executive officer.

ISED to give indigenous applicants priority access to spectrum

 

Innovation, Science, and Economic Development (ISED) has published a draft of the Indigenous Priority Window (IPW) spectrum policy framework tasked to give Indigenous applicants priority access to unused spectrum.

The new framework is a proposed time-limited window during which Indigenous applicants have priority access to available spectrum. This is an important part of the government’s “use it or lose it” approach to spectrum policy — a series of measures that require telecom companies to use their spectrum to serve Canadians in a timely manner or risk losing it to others who will.

ISED has initiated a six-month engagement period on the draft IPW framework. Following this engagement, ISED will publish a decision on the final framework and its timing.

“Access to reliable, high-speed internet is a necessity for small, remote and Indigenous communities,” said Gudie Hutchings, minister of Rural Economic Development. “Broadband internet helps small businesses find new customers and makes it easier for people to connect with their loved ones and health care providers.”

GSMA and IBM team up to support AI adoption and skills in the telecom industry 

GSMA, a non-profit industry organization representing the interests of mobile network operators, has partnered with IBM to launch GSMA Advance’s AI Training program and the GSMA Foundry Generative AI program.

The AI training program seeks to prepare telco leaders for the AI era and bridge skills gaps in the telecom industry by teaching members to leverage Gen AI technologies. Training sessions will take place at IBM offices in five locations around the world in 2024, including Dubai, London, Mexico, New Yorkand Seoul, and an online training program will be available in multiple languages.

In addition, the GSMA Foundry Generative AI program will provide GSMA members with access to watsonx, IBM’s AI and data platform.

“Artificial Intelligence provides the telecoms industry, and the societies it serves, with huge opportunities to launch new services, improve connectivity and customer experience. Overall, it’s estimated that AI could contribute US$15.7 trillion to the global economy by 2030,” said Alex Sinclair, chief technology officer at the GSMA. “However, it’s critical that AI is democratized to ensure that all parts of the connectivity industry and their customers, wherever they are in the world, benefit. Bringing operators access to AI tools and knowledge, alongside the necessary skills, access and training, is key to achieving this.”

More to explore

Canadian government investigating another hack at Global Affairs

The Canadian government is investigating what could be a major data breach at its foreign affairs department.

Retailers at critical juncture due to severe tech gaps: SOTI study

A new study released today reveals that the retail industry in Canada and elsewhere around the world faces major challenges as a result of consumers experiencing a major “disconnect between their shopping expectations and the in-store reality.”

Canadian CEOs worried about economic outlook, but expect turnaround with AI: Report

Over the past year, an increasing number of companies have worried that they will not survive amid rapid technological change and growing economic uncertainties unless they reinvent themselves, PwC’s 27th annual global CEO survey found.

Industrial firms must pay more attention to OT cybersecurity, says vendor

American providers of critical infrastructure services still aren’t spending enough to protect their operational technology (OT) systems, says the head of a company that protects industrial internet-connected systems.

Federal government launches new platform to recruit digital talent

The government of Canada has launched the Digital Talent Platform, an online recruitment site for digital and IT professionals.

A C4-Alludo look at the importance of MDFs

Mark Collins, the president of the Canadian Channel Chiefs Council (C4) recently sat down with Michelle Chiantera, the chief revenue officer at Alludo (formerly Corel), about the importance of market development funds (MDFs).

Listen to the latest episode of Hashtag Trending

Mozilla steps up the move to protect privacy: Hashtag Trending, Wednesday, February 7th, 2024

Listen to the latest episode of Cybersecurity Today

Cyber Security Today, Feb. 7, 2024 – Deepfake video costs company US$25 million



The post Coffee Briefing Feb. 6 – AWS and University of Alberta collaborate to launch AI centre; Cisco survey reveals data privacy trends; ISED seeks to give Indigenous applicants priority access to spectrum; and more first appeared on IT World Canada.