Category: News

Cyber Security Today, Feb. 7, 2024 – Deepfake video scam costs a company US$25 million

A deepfake video scam costs a company US$25 million, and more.

Welcome to Cyber Security Today. It’s Wednesday, February 7th, 2024. I’m Howard Solomon, contributing reporter on cybersecurity for ITWorldCanada.com and TechNewsday.com in the U.S.



A multinational firm is out US$25 million after an employee fell for a deepfake video impersonating the firm’s chief financial officer. According to CNN, Hong Kong police say the employee, who worked in the finance department, was convinced the video call with the CFO and others was real so unwittingly wired the money to crooks. However, the email setting up the video call had a tell-tale sign of potential fraud: It told the employee the session would be about a secret transaction. Threat actors often trick employees into acting fast and transferring funds by saying the request is urgent. Police said the employee had doubts, but the people on the video call looked and sounded like colleagues he recognized.

The incident is another reminder that managers have to train staff with permission to transfer corporate funds to independently verify money transfer requests — especially if the request involves large amounts of money. This may not be as easy as going to an official’s office in the same building if the organization is spread across a city, a country or around the globe. In this case, the employee appeared to be in Hong Kong and the chief financial officer was based in Britain. Still, there have to be processes for verifying large money transfers.

Here’s another report of a fake call: Last month someone created an automated phone message sounding like President Joe Biden telling New Hampshire voters not to bother voting in the state’s primary. Yesterday the state’s attorney general said the calls have been linked to two Texas companies. Cease and desist orders have been issued.

I’ve reported before about threat actors tricking people into scanning QR codes that lead to the downloading of malware. In a new report researchers at Abnormal Security say this trend shows no sign of slowing down. Interestingly, C-suite executives were 42 times more likely than ordinary employees to receive QR code attacks. The scanned code often takes victims to a seemingly legitimate website that prompts them to enter login credentials — including their two-factor authentication code — or enter sensitive personal data.

Facebook job ads are being used to spread malware that steals data from victims’ computers. That’s according to researchers at Trustwave. The ads say an organization is looking for an account manager or digital marketing specialist. But the included link goes to an infected website that leads to the victim’s computer being compromised by malware. It steals information like passwords, cookies, credit card information, documents and more — stuff that threat actors love to use or sell. This is the latest in a long line of job ads that are used to trick people. Be careful with any job ad that doesn’t directly show what qualifications are needed and describes the job in detail.

In European news, Politico says the European Parliament’s chief cybersecurity official will leave his job just before this June’s elections. This is because of concern that Parliament’s cybersecurity isn’t as good as it should be.

The Netherlands has accused China of hacking into a Dutch military network last year. According to the Reuters news agency the hackers planted malware inside an armed forces network used for unclassified research.

If you want to put 2023 behind you, fine. If you want to ponder cyber trends two companies have published year-end analyses. Malwarebytes just released its annual State of Malware report. Among the data: The biggest target for ransomware gangs was the services sector, followed by manufacturing and IT services. And Darktrace looked at the last six months of 2023 and found threat actors are increasingly leveraging rental tools such as malware-as-a-service and ransomware-as-a-service.

Finally, Canon issued updates to close several vulnerabilities in some models of small office multi-function printers and laser printers. Devices directly connected to the internet without a router could be hacked. Check your Canon printer’s specifications page to see if a firmware update is available.

Follow Cyber Security Today on Apple Podcasts, Google Podcasts or add us to your Flash Briefing on your smart speaker.

The post Cyber Security Today, Feb. 7, 2024 – Deepfake video scam costs a company US$25 million first appeared on IT World Canada.

More countries to act against misuse of spyware

Canada, the United States, France and the U.K. are among 25 countries, as well as groups representing nations, vowing today to take action on the abuse of commercial spyware by certain governments and law enforcement agencies.

What is called the Pall Mall Process — after the initial two-day meeting in London — promised to create principles for governments and the IT industry to oversee the development and use of these applications.

Also participating in the conference were IT giants such as Google, Microsoft and Meta. Also signing the declaration were the African Union, representing 55 countries, and the Gulf Co-operation Council, representing six countries including Saudi Arabia.

Among the weapons that countries with developers that create spyware could use are export controls that deny the selling of spyware to certain countries. Another could be rules limiting government departments’ or police departments’ use of spyware. For example, last year U.S. President Joe Biden issued an executive order limiting federal agencies from using commercial spyware unless they have approval from the White House.

Separate from the Pall Mall Process announcement, the U.S. announced on Monday that visa restrictions will be imposed on anyone trying to enter the country who is known to misuse commercial spyware.

Commercial spyware, typically installed surreptitiously on mobile devices through a victim clicking on a link or visiting an infected website, is often marketed as only to be sold and used by police departments or intelligence agencies for use against crooks or foreign spies. However, some countries use it to spy on activists and reporters.

Spyware aimed at consumers can also be found in mobile app stores, marketed as tools employers can use to snoop on staff, or a way a person can keep tabs on their partner.

Unspecified actions should be taken to hold states accountable whose activity is inconsistent with international human rights law, and to hold non-state actors to account in domestic systems, the Pall Mall Declaration says in part.

“The growing commercial market enabling the development, facilitation, purchase, and use of commercially available cyber intrusion capabilities raises questions and concerns over its impact on national security, human rights and fundamental freedoms, international peace and security, and a free, open, peaceful, stable, and secure cyberspace,” participants agreed in the declaration.

“Without international and meaningful multi-stakeholder action, the growth, diversification, and insufficient oversight of this market raises the likelihood of increased targeting for profit, or to compromise a wider range of targets, including journalists, activists, human rights defenders, and government officials,” the declaration says. “It also risks facilitating the spread of potentially destructive or disruptive cyber capabilities to a wider range of actors, including cyber criminals. Uncontrolled dissemination may increase the breadth of access to sophisticated capabilities and, as a consequence, the complexity of incidents for cyber defence to detect and mitigate. This trend risks contributing to unintentional escalation in cyberspace.

“We recognize that, across the breadth of this market, many of these tools and services can be used for legitimate purposes, but they should not be developed or used in ways that threaten the stability of cyberspace or human rights and fundamental freedoms, or in a manner inconsistent with applicable international law, including international humanitarian law and international human rights law. Nor should they be used without appropriate safeguards and oversight in place. We resolve to explore the parameters of both legitimate and responsible use.”

A follow-up conference will be held next year in France.

The conference comes after groups including the University of Toronto’s Citizen Lab published investigations into the use of software like Pegasus, presumably by governments.

In the latest report Citizen Lab and Access Now say iPhones of certain reporters and lawyers in Jordan were targeted or infected with Pegasus.

“Generally speaking, this process is a positive step, albeit incomplete,” Citizen Lab director Ron Deibert said in an email. “It is good that governments recognize the serious harms caused by the mercenary spyware and hack-for-hire industry and are pledging to take action to mitigate those harms. It is now important that governments translate those words into action. Many governments are still very much in the hacking business, and the agencies that employ these tools are notoriously shrouded in secrecy and lacking public accountability, including Canada.”

This isn’t the first action some governments have taken to try to rein in the use of spyware. Last March, 11 countries, including Canada and the U.S., issued a joint statement on the misuse of commercial spyware,

The post More countries to act against misuse of spyware first appeared on IT World Canada.

Mozilla steps up the move to protect privacy: Hashtag Trending, Wednesday, February 7th, 2024

Mozilla is now stepping into the privacy protection game, Meta is insisting that AI images be labelled on Facebook and other platforms, IBM introduces a Linux mainframe and a new cancer treatment that is “out of this world.” Literally.

All this and more on the “you do know those pictures aren’t real, don’t you” edition of Hashtag Trending. I’m your host Jim Love, CIO of IT World Canada and TechNewsDay in the US.

Mozilla is stepping up its privacy game with a new subscription service aimed at tackling the pervasive issue of personal data being sold on the web. Through its Mozilla Monitor platform, the tech giant now offers a way for users to not only detect but also remove their sensitive information from data broker sites automatically. This service, an extension of the previously free Firefox Monitor, is designed to simplify the complex and often opaque process of reclaiming one’s digital footprint.

For a monthly fee, Mozilla Monitor Plus will scour over 190 data broker sites for your personal details—like your phone number, email, and home address—and initiate removal requests on your behalf. This proactive approach is a game-changer in the fight against data brokers, who profit from selling personal information without the explicit consent of individuals.

The significance of this service cannot be overstated. In an era where data breaches are all too common, affecting millions annually, having the ability to automatically remove personal information from potentially harmful sites is a substantial step towards enhancing online privacy and security. Mozilla’s commitment to privacy is further underscored by their encryption and privacy policy adherence, ensuring users’ data is handled with the utmost care.

In conclusion, Mozilla Monitor Plus represents a critical advancement in personal data protection, offering users peace of mind and control over their online presence. As we navigate the digital age, such tools are indispensable in safeguarding our personal information against unauthorized use and sale.

Sources include: TechCrunch, [https://techcrunch.com/2024/02/06/mozilla-monitors-new-service-removes-your-personal-info-from-data-broker-sites-automatically/](https://techcrunch.com/2024/02/06/mozilla-monitors-new-service-removes-your-personal-info-from-data-broker-sites-automatically/).

Meta is taking a significant step forward in the realm of digital authenticity by announcing its plan to label AI-generated images across its platforms, including Facebook, Instagram, and Threads. This move comes as a response to the growing concern over the proliferation of “deepfakes” and other realistically altered media, which pose a challenge to discerning truth in the digital age.

The initiative is particularly timely, given the anticipation of numerous global elections in 2024, where the integrity of information is paramount. Meta’s approach involves using metadata to identify AI-generated content from major tech entities like Google, OpenAI, and Adobe, among others. This is a stopgap measure until Meta’s technical solution for automatic labeling is operational in the coming months.

Meta’s decision aligns with recommendations from its own Oversight Board, which recently critiqued the company’s manipulated media policy for lacking coherence and justification. The board’s feedback underscores the necessity of policies that address content manipulation transparently, regardless of the technology used to create it.

By requiring users to disclose when they share photorealistic AI-generated or digitally altered content, Meta is setting a new standard for content authenticity online. This policy not only aims to enhance transparency but also holds users accountable for the content they share, marking a pivotal moment in the fight against digital misinformation.

Sources include: Axios

IBM is democratizing enterprise-grade Linux capabilities with its latest LinuxONE 4 Express, targeting small and medium-sized businesses (SMBs) with everything but price.

These little beauties are priced at a steep $135,000 for the base hardware configuration, but for that amount you do get the robustness of IBM’s mainframe technology, specifically the Telum processor used in the z16 family, to a more compact and accessible format.

Despite the high entry cost, which does not include maintenance, operating system, or additional software, the LinuxONE 4 Express boasts an impressive promise of 99.999999 (eight nines) percent availability. This level of reliability translates to less than a second of downtime per year, catering to businesses with critical workloads that demand unparalleld resiliency.

IBM’s pitch emphasizes the system’s AI and hybrid cloud capabilities, leveraging on-chip acceleration for AI inferencing to support growing AI use cases within SMBs. The LinuxONE 4 Express is designed to scale with businesses, offering up to 16 configurable cores and 1 TB of memory, making it potentially the smallest LinuxONE system yet.

The support from major Linux distributions such as Canonical, Red Hat, and SUSE, coupled with endorsements from entities like University College London, underscores the system’s suitability for high-performance and scalable research computing environments.

IBM also highlights the cost-saving potential of the LinuxONE 4 Express, suggesting that customers transitioning Linux workloads from an x86 server setup could see over 52 percent savings in total cost of ownership over five years. Set to be available from February 20, the LinuxONE 4 Express represents IBM’s commitment to extending enterprise-grade performance and reliability to a broader market.

Sources include: The Register

 

Meta’s decision to discontinue third-party access to Facebook Groups has sent shockwaves through the developer and business communities.

On January 23, alongside the release of Facebook Graph API v19.0, Meta announced the deprecation of the Facebook Groups API, a tool crucial for scheduling posts to Facebook Groups. This change, set to take effect within 90 days, has left many developers and businesses scrambling to adapt.

The Groups API has been instrumental for businesses in automating and scheduling social media posts, particularly for small businesses and social media marketers who rely on these capabilities to engage with their communities and manage their online presence efficiently. The closure of this API threatens to disrupt the operations of companies like VipeCloud, which serves around 5,000 Facebook accounts, many of which belong to female entrepreneurs. For these businesses, the API’s shutdown not only impacts their ability to communicate within private groups but also poses a significant threat to their revenue and operational model.

The ripple effects extend beyond individual businesses to the broader ecosystem of developers and service providers who have built their offerings around Facebook’s APIs. Companies like PostMyParty, which facilitates the scheduling and automation of online parties, face existential threats, with the potential loss of years of work and thousands of customers.

As businesses and developers voice their concerns and seek clarity, the situation underscores the inherent risks of building services dependent on third-party platforms. The decision by Meta to cut off access to the Facebook Groups API serves as a stark reminder of the volatile nature of digital platforms and the need for businesses to remain adaptable in the face of changing technological landscapes.

Sources include: TechCrunch

California scientists have partnered with Axiom 3 astronauts to pioneer cancer research in the microgravity environment of space. This collaboration has led to the discovery of a potential “kill switch” for cancer, leveraging the unique conditions of space to accelerate the aging of cells and, consequently, the progression of cancer.

The mission, which launched from Kennedy Space Center on January 18, carried not only four crew members but also miniature tumor organoids. These organoids, derived from the cells of cancer patients and cultivated by researchers at the University of California San Diego, were subjected to the stress of microgravity. This stress causes cells to age more rapidly, offering scientists a faster track to observe cancer growth and the efficacy of treatments.

Dr. Catriona H.M. Jamieson, the lead researcher and a figurehead in the field of hematology and stem cell research, has previously observed pre-leukemic changes in stem cells sent to space. This prompted the question: would cancer worsen under the same conditions? The answer was a resounding yes, with the ADAR1 gene playing a pivotal role in the cancer’s accelerated growth.

The latest mission tested an experimental drug, rebecsinib, designed to block the activation of ADAR1, thereby inhibiting the cancer’s ability to clone itself. Preliminary results from space have shown that rebecsinib significantly curtails cancer growth, outperforming other treatments and hinting at its potential as a cancer “kill switch.”

This research not only opens new avenues for cancer treatment but also exemplifies the innovative use of space for medical advancements. With plans to bring rebecsinib to clinical trials on Earth by the year’s end, the team is not slowing down, driven by the responsibility to translate their groundbreaking findings into real-world solutions.

Sources include: Fortune

A cancer kill switch from research in space. Out of this world.

Hashtag Trending goes to air five days a week with daily news and a weekend interview show that we creatively called – the weekend edition.

We love to hear from you. Send us a note at jlove@itwc.ca or drop us a comment under the show notes at itworldcanada.com/podcasts – look for Hashtag Trending.

Thanks for listening and have a Wonderful Wednesday

The post Mozilla steps up the move to protect privacy: Hashtag Trending, Wednesday, February 7th, 2024 first appeared on IT World Canada.

Who is YOUR candidate for Canadian CIO of the Year?

Nominations are now open for the Canadian CIO of the Year Awards  

It’s that time again. IT World Canada (ITWC) and the CIO Association of Canada are once again looking to recognize Canada’s technology leadership in their annual CIO of the Year awards.

These awards look to recognize the accomplishments of technology leaders in the public, private and not for profit sectors. In addition, we have a separate award to recognize up and coming talent in a “next generation” award.

Our panel of judges, representing past winners and distinguished CIOs from across the country evaluate candidates based on leadership ability, strategic thinking, challenges and results achieved. The judging panel is headed by Gary Davenport, an icon in the CIO world, and includes:

 

Philippe Johnston

President, CIO Association of Canada

 

Debbie Lewis

CIO, Royal Canadian Mint

 

Jim Love
CIO, ITWC
Julie Levesque

Executive Vice-President Technology and Operations, National Bank of Canada

 

Shaun Guthrie

SVP, Peavey Technology & ECommerce

 

Wendy Murphy, ICD.D

Chief Technology and Information Officer, Vancity

 

Nastaran Bisheban

Chief Technology Officer, KFC Canada

 

Judging Chair

Gary Davenport

Past President, CIOCAN

 

 

“Of all of the various awards recognizing technology leadership, the CanadianCIO of the Year was the first of its kind, and it remains a much-coveted award,” said Philippe Johnston, National President of the CIO Association of Canada.

“With the passing of Fawn Annan, who spearheaded these awards for decades, this is going to be a special bittersweet year for these awards,” said Gary Davenport. Gary, the former CIO of Hudson’s Bay, has headed the judging of this event for many years, and was a close friend of Fawn Annan. “Let’s make this the best year ever in her honour.”

Winners will receive their awards at a special presentation during ITWC’s Digital Transformation Awards held later this year. They will also be placed in the CIO Hall of Fame

Jim Love, CIO of ITWC and host of the popular podcasts Hashtag Trending and Leadership in the Digital Era, spoke about the need for recognition for Canadian CIOs. “Our success needs to be celebrated,” said Love, “not to serve our egos, which is really un-Canadian, but to inspire future leadership and help advance Canada as a digital leader to make a better future for all Canadians.”

Think you know someone who is deserving of this recognition? Nominating them is easy. Everything you need to start the process can be found on our CIO of the Year nominations page.

Thinking about nominating someone but don’t know where to start? Just go to the nomination page and submit the name of the person you are considering, and someone will be in touch to help you.

Don’t wait – time flies by faster than you think. Get your nomination in today!

The post Who is YOUR candidate for Canadian CIO of the Year? first appeared on IT World Canada.

Cisco launches AI features, Nvidia partnership in Amsterdam

Today, at Cisco Live Amsterdam, Cisco made a series of announcements designed to add more artificial intelligence (AI) power and capabilities across the organization’s portfolio.

“The opportunity to power progress has never been greater,” said Oliver Tuszik, senior vice president and president of Europe, Middle East and Africa at Cisco. “In an unpredictable world, technology is at the forefront of solving whatever challenges we may face. With AI, we see infinite possibilities and a future that’s more efficient, more innovative and benefits everyone.”

Announcements include:

A partnership with Nvidia, which the two companies said will help enterprises deploy and manage secure AI infrastructure, delivering AI infrastructure offerings for the data centre that are easy to deploy and manage, to enable the massive computing power that enterprises need to succeed in the AI era.
New features for Cisco Security Cloud, that include AI-backed analytics for Cisco Identity Intelligence as well as the recently unveiled Cisco AI Assistant for Security that, Cisco said, helps customers make informed decisions, augment tool capabilities and automate complex tasks.
Cisco Observability Platform, which the firm said now offers a natural language interface for simplified troubleshooting. In addition, the new Cisco AIOps application now simplifies real-time business health monitoring to automate IT processes and keep operations teams productive and responsive.
Cisco’s first SaaS product that allows for trustworthy GenAI deployments in organizations, Motific, provides a central view across the entire GenAI journey, empowering central IT and security teams to rapidly deliver trustworthy GenAI capabilities across their organizations with control over sensitive data, security, and cost.
New technologies to help businesses develop and optimize infrastructure to support AI, including the new Cisco X-Series Direct, which is designed for environments where customers need connectivity and compute power at the edge to support more applications with less infrastructure, and the expanded offering of converged and hyperconverged validated designs that build on the recently announced Cisco Validated Solutions and AI/ML blueprint for data centre networks.
The release (some in general availability, some in beta) of several AI features, including Cisco AI Assistant features across the Webex Suite and Contact Center: Meeting and Vidcast Summaries, Change Message Tone, message translation, agent burnout detection, and conversation summaries.
The post Cisco launches AI features, Nvidia partnership in Amsterdam first appeared on IT World Canada.

Bell, Mila to embark on joint deep learning AI initiative

Artificial intelligence research institute Mila and Bell Canada have announced an 18-month collaborative project that, the two said, will apply deep learning neural network algorithms to Bell’s systems and data.

The lab, which specializes in artificial intelligence (AI) advances, was founded in 1993 by Yoshua Bengio, a professor at the University of Montreal, and today has an estimated 1,200 researchers. Two years ago, Bengio was ranked third on the list of the most recognized and influential researchers in any field published by Stanford University.

Bell said in a release that it has made “significant investments to develop extensive data analytics capabilities and AI applications in multiple areas of its operations, and this collaboration is the latest step in advancing its AI expertise.”

Plans, it said, call for Mila researchers to work alongside Bell’s Machine Learning and AI teams to “build on those investments by using cutting-edge deep learning neural network techniques to identify opportunities for improving business performance and customer experience.

“These neural network deep learning models, inspired by the human brain, teach computers to recognize complex patterns in pictures, text, sounds and other data to produce accurate insights and predictions.”

By advancing its understanding of deep learning AI techniques, Bell said it “will continue to enhance its customer experience and accelerate its transition from a traditional telecommunications company to a technology services leader.”

As part of the collaboration, the two organizations are scheduled to write a paper highlighting their technical findings in support of global AI advancement.

Stephane Letourneau, executive vice president of Mila, said that through the collaboration, “we look forward to combining Mila’s research capabilities with Bell’s extensive industry knowledge in order to highlight and harness AI’s potential in this evolving field.”

The post Bell, Mila to embark on joint deep learning AI initiative first appeared on IT World Canada.

Sam Altman admits that ChatGPT has gotten lazy: Hashtag Trending, Tuesday February 6th, 2024

Sam Altman admits what we all knew and promises to fix the laziness that has affected ChatGPT.  Some companies may still be sitting on a fortune in – classic IP addresses. IBM is the leader in AI patents, but does it really matter? And you can slow global warming with AI, a robot and a new kind of asphalt.

All this and more on the springtime in Winnipeg, axle wrecking edition of Hashtag Trending. I’m your host Jim Love, CIO of IT World Canada and TechNewsDay in the US.

Sam Altman, CEO of OpenAI, admitted to what we’ve all known as he addressed user complaints about ChatGPT’s performance by announcing an update designed to make the AI less “lazy.”

Following reports of the chatbot failing to complete tasks and offering lackluster responses, the update aims to get ChatGPT to be more responsive.

This adjustment follows observations from users and developers about the AI’s inconsistent behavior, including an instance where it gave shorter answers based on the perceived time of year.

In some cases, the responses from ChatGPT were – if you want more information visit this website, in other words – do it yourself.

Interestingly, my own experimentation showed that when you used Bing as the search engine, responses were shorter and less interesting than if you used WebPilot, the app that first gave ChatGPT the ability to access the web directly.

I also had promised to give the results of my testing on the weekend, but there were real problems with ChatGPT breaking down every few minutes, so it might be a few more days before we are done.

Sources include: Business Insider

And do you mind if we nerd out for minute here.

IPv4, or Internet Protocol version 4, is the fourth version of the Internet Protocol (IP), which is a set of rules that define how data is sent and received over the Internet. It was first deployed for production within the ARPANET in 1983 and is still used to route most Internet traffic today, despite the ongoing deployment of its successor, IPv6.

IPv4 uses 32-bit addresses, allowing for approximately 4.3 billion unique addresses, but its address supply is depleted, leading to the gradual transition to IPv6, which has a much larger address space. IPv4 is an essential part of the internet’s internetworking methods and is supported on all network devices. It is known for its simplicity, ease of setup, and widespread compatibility with devices. However, due to the limited number of available addresses, the transition to IPv6 is necessary to accommodate the growing number of devices and networks.

I’m not that articulate, I pulled that off Perplexity, a new AI search app that you might want to check out.

But that’s the general wisdom. But it turns out that IP advisory boutique Kalorama Group has quietly been selling IPv4 addresses to the tune of $1.2 billion as of the end of 2023.The firm specializes in handling large-scale transactions of this type of IP address — facilitating deals involving 1 million addresses.

Apparently, some large companies had stockpiled IP addresses and are selling them for literally millions of dollars.

So forget looking through the attic and going to those antique roadshows. It turns out you should check those servers out there and see if your company has a stockpile of classic IP addresses. Seems they could be worth a lot of money.

There’s a link to the Kalorama Group in the show notes. Remember me when you strike it big.

It turns out that IBM has emerged as the leader in AI-related patent applications in the U.S., surpassing tech giants such as Microsoft, Google, and even OpenAI.

With 1,591 applications over the last five years, IBM’s results show a deep commitment to AI research and innovation. But despite that, and its early successes with its Watson AI winning at Jeopardy, the company doesn’t have a high profile in the world of generative AI.

But the number of patents may not be the issue in the world of AI. OpenAI has only one patent, but that might not indicate a lack of innovation.

The findings might hint at a nuanced approach to intellectual property, where companies like OpenAI might prioritize trade secrets over patents, reflecting diverse strategies in protecting and commercializing AI advancements.

As Meta’s recent loss of in a copyright protection case shows, it’s difficult to find unique patentable developments in AI models, since they are based on developments that are widely shared in academic literature and grow by absorbing information from the world around them.

Sources include: Axios

Okay, now it’s serious. Climate change is not only wreaking havoc with wildfires and extreme weather – but it’s also leading to an increase in – and severity of – potholes.

In the UK in 2023, there were nearly 630,000 potholes reported, which marked a five-year high. In the United States, about 44 million drivers reported damage to their vehicles from potholes in 2022, a 57% increase over 2021according to data from AAA.

But it turns out, AI driven robots may be a solution to this critical problem.

A UK startup Robotiz3d has developed what they call ARRES PREVENT, an AI-driven robot designed to detect and repair potholes efficiently.

These robots patrol, find potholes, analyze the geometry of the holes and collects measurement data. This allows local officials to identify where road maintenance is most urgently needed.

This is not just a significant leap in infrastructure maintenance. It’s also providing a market for carbon capture. It turns out that the solid carbon from carbon capture can be processed into asphalt, strengthening road surfaces as well as providing a market for carbon removal.

My only question was – forget the UK as a market. Have you guys ever seen Winnipeg in springtime?

Sources include: BBC

Hashtag Trending goes to air five days a week with daily news and a weekend interview show that we creatively called – the weekend edition.

We love to hear from you. Send us a note at jlove@itwc.ca or drop us a comment under the show notes at itworldcanada.com/podcasts – look for Hashtag Trending.

Thanks for listening and have a Terrific Tuesday.

 

 

 

 

 

 

 

 

The post Sam Altman admits that ChatGPT has gotten lazy: Hashtag Trending, Tuesday February 6th, 2024 first appeared on IT World Canada.

Critical infrastructure cyber law needed ‘more than ever,’ Parliament told

The Canadian government’s proposed law forcing critical infrastructure providers to toughen their cybersecurity is “needed now more than ever,” an expert told a parliamentary committee on Monday.

“We are far behind our allies” in protecting critical infrastructure firms, David Shipley, CEO of New Brunswick’s Beauceron Security and co-chair of the Canadian Chamber of Commerce’s cyber committee, told the House of Commons national security committee.

“And,” he added, “we are risking the safety and prosperity of Canadians every day we delay.”

However, again delaying and reducing the amount of time witnesses could testify on Bill C-26, which would create the Critical Cyber Systems Protection Act (CCSPA), is exactly what MPs on the committee did.

For the second meeting in a row, MPs bickered about allowing a Conservative motion to have sessions examining current and former cabinet ministers, to justify invoking the Emergency Act a year ago to break up protests in Ottawa. It was the third meeting on C-26 that a proposed Conservative motion on a different topic interrupted witness testimony. In contrast, an industry committee meeting Monday dealt with a Conservative motion at the end of the session, so witness time wasn’t cut.

At least 30 minutes of the two hours set aside Monday to hear witnesses testify on the  proposed cybersecurity law Monday was chewed up as Conservative Glen Motz — in the middle of the experts’ testimony — tried to continue debate on his motion last week calling for witnesses and government legal documents justifying use of the Emergency Act. Later, he interrupted testimony by introducing a second, slightly different, motion to do the same thing.

Motz thought he had a “gentleman’s agreement” to introduce that motion last week. But under protests for the length of time he was taking — and the fact that witnesses had flown to Ottawa to testify at the taxpayer’s expense — he agreed to adjourn his motion for Monday’s committee meeting.

Eventually things got testy, with Liberal Jennifer O’Connell verbally fencing with meeting chair Conservative Doug Shipley [no relation to David Shipley]. Shipley told her to stop interrupting him, then abruptly adjourned the meeting.

Bill C-26 has two parts: One would amend the Telecommunications Act to give the federal cabinet and the Minister of Industry the power to order designated telecom providers to do “anything” to secure their systems against a range of threats. The other part, creating the CCSPA, would apply to other critical infrastructure providers. Initially, these would be limited to banking, financial clearing firms, interprovincial transport and energy companies, and nuclear power operators. Similar to the Telecommunications Act changes, it would create a cyber security compliance regime for designated federally regulated firms. Included would be a requirement to report cyber incidents “immediately” to the Canadian Security Establishment (CSE), the branch of the Defence Department responsible for government cybersecurity.

Related content: What C-26 requires of companies

In his opening remarks, David Shipley of Beauceron Security — a regular guest on IT World Canada’s Cyber Security Today Week in Review podcast — said C-26 needs some “fine-tuning,” including the following:

— companies should be allowed to raise the defence of “due diligence” (essentially, ‘We did our best’) if faced with administrative fines under C-26 for not keeping their IT networks secure;

— MPs should remove C-26’s ability to hold employees, directors, and officers to be held personally liable for committing or directing violations of the act. That puts “a target on their heads” and will discourage people from choosing a career in IT, Shipley said;

— the government should ensure in C-26 that regulators who will have to enforce the CCSPA have the cybersecurity skills to do it.

— and MPs should change the bill to limit the amount of sensitive data regulators can collect about cybersecurity defences of critical infrastructure firms. That information would be a “one-stop shop” for cyber crooks looking for ways to cripple those firms, Shipley said.

In their presentations Monday, the Canadian Chamber of Commerce and IBM said C-26 should be changed to allow designated firms up to 72 hours to report cyber events to regulators. They also called on MPs to clarify in the proposed law details such as what has to be reported, and not leave it up to the government to declare those details in regulations after the law passes.

Todd Warnell, chief information security officer at Bruce Power, an Ontario nuclear power generator, said C-26 “is of vital importance.”

The post Critical infrastructure cyber law needed ‘more than ever,’ Parliament told first appeared on IT World Canada.

Global tablet market ends tough 2023 with 11% decline in Q4: Canalys

According to the latest data from Canalys released today, global tablet shipments experienced a drop of 11 per cent year-on-year in Q4 2023, to a total of 37.8 million units. The findings resulted in a full-year 2023 figure of 135.3 million tablets shipped, a 10 per cent decrease from 2022.

“The latest holiday season saw a significant surge in tablet promotions and bundled offers, but this was not enough to reverse the market’s fortunes, “said Himani Mukka, research manager at Canalys.

Mukka added, “with healthier inventory levels and further scope for government and commercial deployments, tablet sell-in is expected to rebound in 2024. New models announced by TCL and Lenovo at CES 2024 and anticipated updates to Apple’s iPad portfolio early this year will help provide a boost to the tablet refresh opportunity.”

Kieran Jessop, an analyst with the firm, said that a key element that tablet vendors need to pay attention to is the “innovation gap between tablets and other personal computing devices.

“Plans around on-device AI integration in tablets trail behind those in PCs and smartphones. Bringing this functionality across devices will be crucial for vendors aiming to deliver a unified and seamless experience on ecosystems. Elsewhere, this year will see a greater focus on foldable tablet form factors. Although shipment volumes will likely remain restricted due to the premium pricing of these models, they will provide an opportunity for vendors to showcase user-experience benefits for content consumption, learning and productivity.”

Apple maintained its leading position in shipments despite a 24 per cent year-on-year decline, shipping 14.8 million iPads in the quarter, while Samsung secured second spot with 6.8 million units shipped, posting an 11 per cent annual decrease.

Huawei landed in third, with 2.8 million units shipped following healthy growth, and Lenovo, Canalys said, “dropped to fourth place but posted healthy shipment growth of 15 per cent, gaining over two points of market share year-on-year. Amazon rounded out the top five, with a 44 per cent annual decline and two million tablets shipped globally.”

The news is much brighter when it comes to PC shipments. Canalys is predicting that full-year 2024 shipments will hit 267 million units, an eight per cent rise from 2023, helped, it said, by “tailwinds including the Windows refresh cycle and emergence of AI-capable and Arm-based devices.”

In a forecast released late last year, Canalys analyst Ben Yeh said the global PC market is on a recovery path, and set to return to 2019 shipment levels in 2024: “The impact of AI on the PC industry will be profound, with leading players across OEMs, processor manufacturers, and operating system providers focused on delivering new AI-capable models in 2024. These initiatives will bolster refresh demand, particularly in the commercial sector,” he said.

The total shipment share of AI-capable PCs, he added, “is expected to be about 19 per cent in 2024. This accounts for all M-series Mac products alongside the nascent offerings expected in the Windows ecosystem. However, as more compelling use-cases emerge and AI functionality becomes an expected feature, Canalys anticipates a fast ramp up in the development and adoption of AI-capable PCs.”

The post Global tablet market ends tough 2023 with 11% decline in Q4: Canalys first appeared on IT World Canada.

Pass Canadian AI law as soon as possible, expert tells Parliament

A Canadian who is one of the world’s leading thinkers on artificial intelligence says Canada’s proposed AI law needs to be passed as soon as possible.

“We urgently need agile AI legislation, and I think this law is moving in right direction,” Yoshua Bengio, scientific director of Mila, Quebec’s Artificial Intelligence Institute, told the House of Commons industry committee studying the proposed Artificial Intelligence and Data Act (AIDA) on Monday.

While other experts have told the committee that AIDA should be withdrawn for a complete redrafting or until more public consultation has been held, Bengio urged Parliament to pass AIDA soon — although with some amendments.

“An imperfect law with regulations to be adopted later is better than no law, or postponing it,” he said.

In fact, Bengio added, it’s so critical to oversee AI that some rules should come into effect as soon as AIDA is signed, rather than wait the expected two years or so while regulations with details about how some things in the bill will work are being written by the government.

For example, he said, as soon as the bill is signed into law, businesses would have to list AI systems above a set capacity, showing information about the system’s safety, security measures, and security assessments. The AI regulator — at the moment proposed to be an official of the Innovation ministry — would be able to use that information to create best-in-class requirements for future permits to continue developing and deploying advanced systems.

“This would put burden of demonstrating safety on developers with the billions required to build these advanced systems, rather than taxpayers,” Bengio said.

Computing systems that are as smart as humans (what he called “superhuman AI”) with the capacity for what experts call artificial general intelligence (AGI) may be online within two decades and “possibly in the next few years,” he said. But, he added, society isn’t ready.

“The current AI trajectory poses serious risk of major societal harms even before AGI is reached,” he said.

RELATED CONTENT: Government updates proposed AI, privacy laws

While progress in AI has opened what he called “exciting opportunities for numerous beneficial applications,” he noted, “it is urgent to establish the necessary guardrails to foster innovation while mitigating risks and harms.”

Briefly, AIDA would oversee classes of “high-impact” AI systems — such as those covering employment, providing services to an individual, processing biometric information for identification, moderating content on a search engine or social media platform, or being used by police. It would be illegal to deploy an AI system likely to cause serious physical, psychological or economic harm to an individual. Persons responsible for high-impact systems would have to establish measures to identify, assess and mitigate the risks of harm or biased output that could result from the use of the AI system.

In addition to amending the legislation so the registry would come into immediate effect, before regulations are set, Bengio also said there should be two other additions:

— the definition of a high-impact AI system should include “national security risks and societal threats,”

— and an AI developer should be required to show its safety and security before the system is fully trained and deployed. “We need to identify risks early in an AI lifecycle,” he explained.

The post Pass Canadian AI law as soon as possible, expert tells Parliament first appeared on IT World Canada.