Category: News

Cyber Security Today, Jan. 22, 2024 – LockBit ransomware gang hits the Subway fast food chain, and Data Privacy Week starts

The LockBit ransomware gang hit the Subway fast food chain, and this is the start of Data Privacy Week

Welcome to Cyber Security Today. It’s Monday, January 22nd, 2024. I’m Howard Solomon, contributing reporter on cybersecurity for ITWorldCanada.com and TechNewsday.com in the U.S.



The LockBit ransomware gang says it compromised the Subway fast food chain. It’s threatening to leak hundreds of gigabytes of stolen data on February 2nd. According to the news site SecurtyAffairs.com, that data allegedly includes employee salaries, franchise royalty payments, master franchise commission payments, numbers on restaurant turnovers and more.

A data centre provider in Sweden called Tietoevry says one of its facilities was partially hit by a ransomware attack Friday night. Service to some customers has been affected.

A Russian state-sponsored group used a password spray attack last November to get into a Microsoft legacy non-production test account and then pivot to steal corporate emails. The attack, by a group Microsoft used to call Nobelium and now it calls Midnight Blizzard, was only detected earlier this month. The group used their initial access to get into the email accounts and stole attachments of a “very small percentage” of executives and employees in the cybersecurity, legal and other departments. Microsoft said the attack was not the result of a vulnerability in its products or services.

Last October VMware patched an out-of-bounds write vulnerability in its vCenter Server. However, researchers at Mandiant now say a Chinese-based threat group was exploiting that unknown hole for a year and a half before the patch was released. The discovery comes from Mandiant’s continued research into the group it calls UNC3886, which goes after VMware and Windows virtualized hosts. IT administrators with VMware systems that experienced unexplained crashes since 2021 should look for backdoors and signs of compromise — and, if they haven’t already done, so update to the latest version of vCenter.

The operator of the BreachForums marketplace for hacked and stolen data has been sentenced to 20 years of supervised release. Conor Brian Fitzpatrick received that sentence last week from a Virginia judge after pleading guilty to conspiracy to commit access device fraud, possession of child porn and other charges. According to Cyberscoop.com the 20-year-old will serve the first two years of the sentence as home confinement, won’t have access to a computer for a year and will have to register with state sex offender registries.

The maker of the MOVEit file transfer service hasn’t lost many customers despite the exploitation of a vulnerability last year that saw the personal information of over 90 million people stolen from over 2,000 firms using the application. Progress Software said last week customer retention levels remained steady in the second half of 2023. One cybersecurity analyst told Cybersecurity Dive customers may be sticking with the product because the vulnerability was a zero-day, so they don’t see the developer as negligent.

Finally, today starts Data Privacy Week, when IT, data privacy and organization leaders should think about their data collection and protection policies. They may want to consider a just-released study by Consumer Reports. It says Facebook is a great receiver of personal information from firms that collect individuals’ shopping information. These include big brands (like Amazon), retailers (like Home Depot, Walmart and Macy’s), data brokers and political service firms. This is how Facebook targets ads to its users. One finding: more than 2,000 companies had data on a group of over 2,000 volunteer Facebook users in the study group — but many of those people didn’t directly interact with all those firms. Is all this data collection and selling bad for your business’s reputation? The report says many consumers will be concerned about the extent to which their activity is tracked by Facebook and other companies. It suggests governments demand firms only collect data they need, and that governments improve the ability of consumers to opt out of data collection from several companies at once through automation.

Follow Cyber Security Today on Apple Podcasts, Google Podcasts or add us to your Flash Briefing on your smart speaker.

The post Cyber Security Today, Jan. 22, 2024 – LockBit ransomware gang hits the Subway fast food chain, and Data Privacy Week starts first appeared on IT World Canada.

Hashtag Trending Jan.22-Zuckerberg commits to developing AGI; CIOs worried about Broadcom’s changes to VMware; Apple’s Vision Pro fails to sell out on launch day

Mark Zuckerberg causes a storm with his commitment to developing Artificial General Intelligence, CIOs are sounding worried about Broadcom’s changes to VMWare, tax changes in the U.S. are having an impact on startups and – in what can only be described as a sign of the apocalypse, a new Apple product failed to sell out on its first day. 



 

Welcome to the end of the world as we know in this edition of Hashtag Trending.  I’m your host, Jim Love, CIO of IT World Canada and TechNewsDay in the US. 

Mark Zuckerberg, CEO of Meta, has stirred controversy with his commitment to developing an Artificial General Intelligence (AGI) system, potentially on par with human intelligence. This ambitious project, which he also suggested might be made open source, has raised alarms among experts and academics.

Zuckerberg envisions this next-generation technology as a key driver for tech services, even though the concept of AGI still remains largely theoretical. Even Sam Altman – although he has talked about huge advancements in the upcoming version 5 of ChatGPT – is not yet ready to announce AGI has been achieved.

AGI refers to an AI system capable of performing a wide range of tasks at human-level intelligence or beyond. The prospect of achieving such a breakthrough, and more so, making it publicly accessible, has sparked fears about its potential to escape human control and pose significant threats.

Dame Wendy Hall, a prominent computer science professor and member of the UN’s AI advisory body, labeled the idea of open source AGI as “really very scary” and criticized Zuckerberg’s approach as irresponsible. She emphasized the urgent need for regulatory frameworks to ensure public safety in the face of such powerful technologies.

Meta’s previous decision to open source its Llama 2 AI model was met with criticism, drawing parallels to “giving people a template to build a nuclear bomb.” The debate extends beyond Meta, with other tech giants like OpenAI and Google’s DeepMind also pursuing AGI, each with their own definitions and timelines.

Sources include: The Guardian

Broadcom’s recent acquisition of VMware, a virtualization pioneer, for $69 billion has led to significant changes in VMware’s product and pricing strategies, drawing the attention of chief information officers (CIOs) across various industries.

Since the acquisition’s completion in November, Broadcom has streamlined VMware’s product offerings from nearly 1,000 to just two bundles and shifted from perpetual license sales to a full subscription payment model. This move aligns with Broadcom’s history of acquiring companies and leveraging pricing power but has raised concerns among VMware’s customers. Additionally, Broadcom has laid off hundreds of VMware workers, although the company declined to comment on these layoffs.

With around 330,000 customers, VMware’s changes under Broadcom are closely monitored by CIOs, who are considering alternatives due to potential price increases and concerns about support levels.

CIOs like Todd Florence of Estes Express Lines and Suvajit Basu of Goya Foods express apprehension about their future with VMware, especially given Broadcom’s strategy of focusing on a core base of around 600 business customers. This approach, while successful in Broadcom’s chip business, is less common in software and raises questions about support and pricing for the broader customer base.

Analysts from Forrester Research note that moving away from VMware could be costly and time-consuming for customers, but also see potential benefits in the changes, such as simplified product portfolios and more focused customer engagement.

This overhaul by Broadcom signifies a pivotal shift in VMware’s strategy, impacting the broader IT and cloud computing landscape, with CIOs and companies reevaluating their reliance on VMware’s virtualization services.

Sources include: The Wall Street Journal

American legislators are rushing to clean up a mess created in a 2017 revision to the U.S. tax laws.

Previously, a company with $1.5 million in revenue and $1 million in R&D expenses would pay taxes on $500,000 profit. Now, the same company can only deduct one-fifth of its R&D expenses annually, resulting in a higher taxable profit. This shift is causing some startups to face unsustainable tax bills.

The impact is particularly felt among bootstrapped companies that are being penalized for generating profits sooner. Venture-backed startups, typically pre-revenue, are less affected for now. But even those companies are changing their planning, with some slowing down hiring due to budget constraints.

This taxation change also affects large corporations, especially those with overseas R&D activities. In late 2022, CFOs from major companies like Ford and Netflix appealed to Congress for a repeal of this change.

Currently, there’s bipartisan support to address this issue. The Tax Relief for American Families and Workers Act of 2024 proposes to delay the change to Section 174 until January 1, 2026, and apply it retroactively. However, it’s still early in the legislative process, and the outcome remains uncertain.

Meanwhile the Canadian government is moving to…. Just kidding. They’ve got bigger things to do that worry about technical innovation and its impact on the Canadian economy.

Sources include: Axios

 

Apple continues to take a beating from the EU and has proposed to allow third-party mobile wallet and payment providers to access the iPhone’s NFC (Near Field Communication) capabilities. 

This move is a response to a European Commission antitrust investigation, which has been ongoing for nearly four years. The investigation accused Apple of using its iOS policies to unfairly restrict competition in the mobile payments market, benefiting its own solution, Apple Pay.

Previously, while third-party developers could use the iPhone’s NFC features for reading electronic tags, they were restricted from making NFC payments, which was exclusively reserved for Apple Pay. Apple’s new commitment, if accepted, would enable users in the European Economic Area (EEA) to make NFC contactless payments from within third-party iOS apps, separate from Apple Pay and Apple Wallet.

This change marks a shift in Apple’s tightly controlled ecosystem. The proposed commitments would last for 10 years and could lead to a fine of up to 10 per cent of Apple’s worldwide annual turnover if not honored. 

The decision to open up NFC payments to third-party developers could have significant implications for the mobile payments market, particularly in the EU.

Sources include: The Verge

And this wouldn’t be news for any other company, but  Apple’s Vision Pro did not sell out on its launch day, despite limited initial availability estimated between 60,000 and 80,000 units. 

The Vision Pro, priced at $3,500 to $3,899 U.S. depending on storage capacity, saw its 256GB model quickly backordered, but the 512GB and 1TB models remained available for in-store pickup the day after launch. 

For Apple, that’s amazing given its reputation for creating hype around new products and typically seeing rapid sell-outs. 

The Vision Pro, marketed as a device ushering in the “era of spatial computing,” seems to have encountered challenges in gaining immediate traction, similar to competing AR and VR headsets.

Concerns have been raised about the Vision Pro’s weight, comparable to a 12.9-inch iPad Pro, and the limited number of spatialized apps available at launch. Apple developed only 15 stock apps for the device, and major third-party platforms like Netflix, YouTube, and Spotify have no immediate plans to create spatialized versions of their apps for it.

This situation suggests that even with Apple’s brand and marketing strength, success in the AR and VR market may not be guaranteed.

Sources include: Notebook 

And finally, two bits of news from OpenAI from last week. Open AI announced its first partnership with a university.  Arizona State University is going to use OpenAI’s Enterprise offering for its coursework and to build a personalized AI tutor for students.  

Enterprise offers a secure environment that will supposedly protect the university and student  data.

It also means that students will no longer have usage caps. Given that the course on AI prompts is one of the most popular courses on the university’s calendar, this could be a bonus in student recruitment. As well as the fact that presumably, there’s no penalty for using AI to assist in your assignments. 

And a second OpenAI story has been circulating on YouTube. Last month one YouTuber showed how he had gotten access to the main prompt for ChatGPT. I didn’t try it, but it looked credible. Now, with the advent of the store, there is at least one more video making the rounds showing how easy it is to expose the prompt that drives any custom GPT.  That one I can tell does work. 

We are moving exceptionally quickly into this new world – but sometimes it makes you wonder if at the speeds we are moving, if we are doing this in the safest and smartest way possible.

And that’s Hashtag Trending for today.  

I’d like to once again thank all of you who are new listeners and all of you that have helped us grow by sending this to a friend or by giving us a great review on the Apple store. While the listener base grew by 20 per cent thanks to you – and I’m keeping to my goal to double our listeners this year, with your help.  So please, invite a friend to join our Hashtag Trending family.

I’m your host, Jim Love, thanks for listening and have a Marvelous Monday.

The post Hashtag Trending Jan.22-Zuckerberg commits to developing AGI; CIOs worried about Broadcom’s changes to VMware; Apple’s Vision Pro fails to sell out on launch day first appeared on IT World Canada.

Samsung launches AI-powered Galaxy S24 series

For the first half hour of Samsung’s Galaxy Unpacked event Wednesday, one could be forgiven for thinking that it was a software launch, as speaker after speaker touted Galaxy AI, the company’s new set of artificial intelligence (AI) tools driving the Galaxy S24 series of devices.

“Artificial intelligence will bring about great change in the mobile industry, and in the way we live,” noted TM Roh, president and head of mobile experience (MX) business at Samsung, during his keynote address. “We believe Samsung Galaxy will democratize this change. Samsung Galaxy AI is the spark that ignites new possibilities.”

Circle to Search
Credit: Samsung Electronics

Samsung-developed AI features include simultaneous on-device two-way voice and text translation for calls on the new Galaxy S24 series devices (with a ton of fine print saying accuracy is not guaranteed). Partnerships with companies such as Google are providing cloud-based functionality like Circle to Search with Google, a new feature that allows users to circle, tap, or scribble on something on the screen, such as a piece of clothing or a landmark, and get search results about it without having to leave the app they’re viewing it in.

Image editing tools are all AI assisted – but Samsung adds a watermark and info in the metadata when a photo has been manipulated, as in the example it showed transforming a mundane basketball jump shot to a spectacular one, by shifting the player’s position in the photo.

Original image. Credit: Samsung Electronics
Edited image. Note the watermark at bottom left. Credit: Samsung Electronics

 

There will also be AI enhancements to Lens, but Samsung said they will not be available in Canada.

The AI goodies appear impressive – we’ll know better how they work after trying the devices. However, there is a caveat in the fine print, which says: “Galaxy AI features will be provided for free until the end of 2025 on supported Samsung Galaxy devices. Different terms may apply for AI features provided by third parties.”

Now for the phones. As in previous years, the Galaxy S24 phones come in three flavours: the Galaxy S24, Galaxy S24+, and Galaxy S24 Ultra. All three models feature the new Qualcomm Snapdragon 8 Gen 3 chip, with its AI engine that handles on-device AI processing.

The Galaxy S24 and Galaxy S24+ are pretty much the same, save screen size (6.2 inches vs 6.7 inches) and battery size (4000 mAh vs 4900 mAh). The Galaxy S24+ also comes with 12 GB of memory, vs the Galaxy S24’s 8 GB.

The Galaxy S24 Ultra is where Samsung pulled out all the stops, and it was the device featured during all of the demos at Unpacked. Its display is 6.8 inches, it has a 5000 mAh battery, 12 GB of memory and up to 1 TB of storage, two wide and two telephoto cameras on the rear, and has a titanium frame rather than the aluminum of the other models. The display uses Corning Gorilla Armor, a new, tougher glass that Corning said is also anti-reflective, where the other models offer Gorilla Glass Victus 2. And it comes with an S Pen.

All three devices are available for pre-order now, with availability in retail outlets and from carriers on Jan. 31. The Galaxy S24 starts at C$1,099.99, the Galaxy S24+ at C$1,399.99, and the Galaxy S24 Ultra is priced starting from C$1,799.99, topping out at C$2,279.99 for a model with 1 TB of storage.

The post Samsung launches AI-powered Galaxy S24 series first appeared on IT World Canada.

Cyber Security Today, Week in Review for the week ending Friday, Jan. 19, 2024

Welcome to Cyber Security Today. From Toronto this is the Week in Review for the week ending Friday, January 19th, 2024. I’m Howard Solomon, contributing reporter on cybersecurity for ITWorldCanada.com and TechNewsday.com in the U.S.



 

In a few minutes David Shipley, head of Beauceron Security, will be here to discuss recent news. But first a recap of some of the news from the past seven days:

Cryptocurrency scammers this month have been hacking the X accounts of companies or of well-known people. One of the latest was the city of Peterborough, Ont. David and I will discuss this trend.

We’ll also talk about the arrest in Ukraine of a resident for using hacked cloud accounts to create 1 million virtual servers for mining cryptocurrency.

We’ll discuss how an accounting firm employee falling for a phishing scam led to disclosure of the names of some customers of an American laptop maker.

And while it happened earlier this month, David will have thoughts about the genetic testing service 23andMe blaming some poor users’ password practices for a huge data breach.

Also in the news this week, Atlassian, Ivanti, Citrix, SonicWall and Juniper Networks were among companies that issued security updates to fix major vulnerabilities in their applications.

The ‘Have I Been Pwned’ website, where you can check if your credentials have been stolen, has added millions of unique email addresses to its data store. This is from a huge credentials-stuffing database called Naz.API that someone has been pedaling on the dark web. Not all of the stolen credentials on this list are new. But researcher Troy Hunt, who maintains the site, said about one-third of the email addresses are new to the millions of stolen credentials he has collected so far from other sources.

American home loan provider Academy Mortgage Corp. said it is notifying over 248,000 people that some of their personal data was stolen last March. An attacker accessed and disabled some IT systems, the company says. Information stolen included names, dates of birth and Social Security numbers stored for payroll and organizational purposes.

Google has updated its explanation of what the Chrome browser’s Incognito mode does and doesn’t protect users from. This comes as Google reportedly has reached a settlement on a class action lawsuit over alleged tracking of users’ activity in Incognito mode. According to the website MSPowerUser, the disclaimer now clearly states Incognito doesn’t change how data is collected by websites users visit, including Google.

The Governor of New Jersey this week signed data privacy and breach notification legislation. Starting next January companies doing business in the state can only collect personal data that is necessary for the business. And they’ll have to tell consumers what collected data is being used for.

Consumer Reports says nine of 10 American health-related websites it recently studied raised at least one data privacy concern, including sharing consumer data with a long list of third parties. Two websites that claimed they don’t sell or share covered data appeared to allow third party marketing cookies, which might legally constitute a data sale. Despite new health privacy protections in state laws, the report says, many health-related sites shared data with third parties.

Finally, a cybercrime syndicate has been creating a huge botnet by compromising smart TVs and set-top boxes running the Android and eCos operating systems for the last eight years. That’s according to researchers at a Chinese cybersecurity company called XLab. They call the bot Bigpanzi. Not only can it launch distributed denial of service attacks, it can also substitute content on victim’s TVs. One way homeowners can avoid being victims is by refusing to download apps that promise access to pirated movies and TV shows. Those apps are likely infected.

(The following is an edited transcript of part of the discussion. To hear the full conversation play the podcast)

Howard: There have been several high-profile hacks of prominent accounts on the X social media platforms, with many of the attackers renaming accounts and promoting links to cryptocurrency scams before the real owners regain control. One victim this week was the city of Peterborough, Ont. Recent victims have included security firm Mandiant and the U.S. Securities and Exchange Commission. The group that hacked the SEC account claimed the regulator had announced a change in policy for bitcoin exchange-traded funds. We’re not sure if this is one group or several copycats. David, what’s going on?

David Shipley: Thankfully, for the most part it looks like it’s just the usual crypto scammers. I’ll speak up about the SEC separately because I think there’s some unique twists about it. But for the other ones, for Mandiant the the city of Peterborough this could have been so much worse. If it was someone doing it for the lulls, as the hacker kids like to say, imagine one of those accounts pumping out deep fake intimate images and you can get a sense of how off the rails this could have gone. Or, on the other side, hacking the Mandiant account to hit key folks who follow it like security professionals, researchers, CISOs and hitting them with malicious links or malware. That could have been far more damaging than promoting crypto scams. So I think we dodged a bullet on this one.

The X/ Twitter hack — I just can’t get over calling it Twitter — is fascinating because it did move the market for a short time, particularly for bitcoin, and that could have made somebody millions of dollars. On top of that a few days later the actual announcement did come out that the SEC authorized bitcoin ETFs. I’ve often thought about how hacks and social media takeovers could be used to move entire industries or markets in a way that would be hard for authorities to trace manipulation of stocks or commodities …

Howard: One thing these X takeovers have in common is weak security — easily guessed passwords or a security weakness or an account user is falling for a trick and giving up their password. This last is the allegation by X itself in the hack of the SEC’s account. X tweeted that the cause was a hacker getting control over a phone number associated with the SEC account through what they said was a third party. It sounds like either a wireless carrier or an outside support company was tricked into giving an attacker control over an employee’s phone and that employee uses that phone tor the SEC tweets.

David: It screams SIM swap attack. One of the questions I had is was the SIM swap tied to bypassing MFA? Because, ironically, phone-based SMS-based multifactor authentication is a premium feature if you pay for X/Twitter. Was that how they bypassed MFA? Which makes me wonder if they [the attackers] used an old feature where you could send an SMS text and it would create a tweet for you. If you are planning a market-moving event and if you were going to poke the SEC, using burner phones would probably not be a bad idea: Get a burner phone, SIM swap it, do the tweet and ditch the phone. That could make investigating it even harder.

Howard: In the case of the Mandiant hack, the company said employees are supposed to have two-factor authentication enabled on any account that they use for logins. However, it said in this case due to some team transmission transitions one person’s account was open and it fell to a brute-force password attack.

David: For all the technological tools we have to secure accounts things like MFA and conditional access et cetra, it always always comes down to people and processes. So the interesting question for enterprises is how do you monitor compliance for third-party SaaS platforms like X and others when it comes to making sure accounts have turned on MFA? At my firm every single quarter we have to do a full review of all the applications that we use as part of our ISO 27001 process. We have to provide evidence of not only who has access and what access they have, but are appropriate controls in place as dictated by the risk impact [assessment] — even for a 40-person company. That’s a lot of work. We estimate that that we probably spend about $5,000 to $6,000 a year in staff time [on that]. That’s just a direct cost. That’s not the productivity cost to review around a hundred applications quarterly. Imagine a large enterprise that has tens of thousands of applications: How do they stay on top of these things? The only thing I would say is that we’re learning from this experience. I think it’s good to have a learning attitude from this [the X account takeovers]: How could we avoid something like this?

Howard: What are the lessons learned from these recent hacks of X?

David: There are a couple of different pieces: First, we need a standard way for SaaS [software-as-a-service] customers to automatically be able to query [accounts] for compliance with basic hacking mitigations and controls like multifactor authentication. You should be able to just plug into your SaaS provider with some kind of a trusted feed setup so that it can send alerts to other security tools when there’s a rogue account created or an account that doesn’t have basic control like MFA. This standard needs to be mandated by regulators for platforms once they reach a certain size, whether that’s revenue or user base. And you should prohibit vendors from selling this specific set of functionality as a premium — ie. an extra cost service. This API access should allow for systems to query for access compliance and should send alerts in a standard format when accounts don’t have the proper control set up now. That’s the technology side. Ironically, that’s not that hard to do, but making it happen is going to require policy and regulation –and a mindshift miracle.

Part two, regulators should mandate mandatory multifactor authentication for platforms of certain size and scale — like big tech social media firms, major cloud providers. At the same time industry best practices standards and certifications — I’m looking at you SOC 2, ISO 27001 — should require companies provide this to their customers as well. Maybe we can see that before 2030.

Part 3 is the importance of measuring security culture, not just compliance. I mentioned earlier how my firm measures compliance and how we’d see a higher cost for unclear gains. Maybe if we did it more often. But if folks believe in the importance of doing what’s right and being secure as part of their job and as part of the right thing to do, that could potentially make all the difference in the world. Getting people to that point takes more than Cyber Security Awareness Month and a platform. But it can have huge ROI, and that’s what building a security culture can do.

The post Cyber Security Today, Week in Review for the week ending Friday, Jan. 19, 2024 first appeared on IT World Canada.

Toronto to integrate IT systems after ransomware attacks on zoo, public library

After suffering serious ransomware attacks on its zoo and public library system, the city Toronto has decided to integrate its IT systems for better cybersecurity, the Toronto Star reports.

“The city of Toronto’s main system is one of the most secure in North America, second to New York,” the news agency quotes Mayor Olivia Chow saying at a press conference. Bringing all the city-linked organizations under the city’s umbrella would make them “far more secure,” she said.

City agencies like the library, zoo, and the Toronto Transit Commission (TTC), have their own IT systems.

The decision to merge systems comes after the Toronto Zoo was hit earlier this month and the Toronto Public Library was hit in October. The library attackers stole information on current and former staff, including their names, social insurance numbers, date of birth, and home address. Copies of government-issued identification documents provided to the library by staff were also likely taken.

The library still hasn’t fully restored its systems. In an update today, it said the home page of its website will be restored by the end of the month. However, online access to the full catalogue and users accounts won’t be restored until February.

“We recently restored network connectivity to more than 3,000 staff computers,” the statement says. “This needed to happen before reconnecting our 2,000 public computers to the network.”

Use of public computers in branches for connecting to the internet will return early in February. However, a date for restoring the ability of users to print documents from public computers hasn’t been set.

The post Toronto to integrate IT systems after ransomware attacks on zoo, public library first appeared on IT World Canada.

Lock down TeamViewer or pay a price

IT administrators allow remote access software like Zoho Assist, TeamViewer VNC Connect, Windows RDP and AnyDesk to help employees do their work away from the office.

Unfortunately, those products can also be useful to hackers, who try to leverage poorly-secured applications like these on computers to also get (unapproved) access into enterprise networks. Which is why these utilities have to be locked down.

The latest example of failing to do that comes in a report from researchers at Huntress, who recently discovered that two endpoints at unnamed organizations had been encrypted with ransomware through compromised TeamViewer software.

Logs suggest the attacker in each case was the same, Huntress staff said in a blog. On both endpoints, the initial ransomware deployment started with a DOS batch file run from the hacked user’s desktop.

Fortunately, security software on one computer limited the number of files that were encrypted. And in neither instance was there any indication the threat actor conducted reconnaissance beyond the impacted endpoint, nor attempted to move laterally to other endpoints within the infrastructure.

There have been several reports of attackers using TeamViewer and other remote access tools to their advantage. In December, Microsoft disabled Windows App Installer because threat actors were using it to trick people trying to download legitimate versions of TeamView, AnyDesk and other utilities.

Last summer, cybersecurity agencies from seven countries warned that the LockBit ransomware gang either leveraged existing installations of TeamViewer and other tools or added them to compromised IT systems.

“Threat actors look for any available means of access to individual endpoints to wreak havoc and possibly extend their reach further into the infrastructure,” Huntress warned, which is why IT administrators need a thorough inventory of software under their control so they can apply security policies.

The post Lock down TeamViewer or pay a price first appeared on IT World Canada.

Cyber Security Today, Jan. 19, 2024 – Vulnerabilities found in server firmware, a warning to Docker administrators, and more

Vulnerabilities found in server firmware, a warning to Docker administrators, and more.

Welcome to Cyber Security Today. It’s Friday, January 19th, 2024. I’m Howard Solomon, contributing reporter on cybersecurity for ITWorldCanada.com and TechNewsday.com in the U.S.



 

Nine vulnerabilities have been found in an open-source reference implementation of a protocol that allows enterprise computers and data centre servers to boot across a network. If exploited these holes could lead to data theft, denial of service attacks and other ugly things. Researchers at Quarkslab say the problems are in TCP/IP stack specification maintained by Tianocore TEE-AN-O-CoRE, a community of developers from software vendors including Microsoft, ARM, American Megatrends, Phoenix Technologies and others that use the project for their firmware implementations. Carnegie Mellon University’s Computer Emergency Response Team (CERT) says IT leaders should look for and install firmware updates from their equipment manufacturers. They should also consider disabling a capability called PXE boot, sometimes called Pixie boot.

Separately, the Carnegie CERT issued a warning that general-purpose graphic processors from AMD, Apple and Qualcomm have a memory leak vulnerability. The hole, discovered by researchers at Trail of Bits, means at attacker with access to a GPU programmable interface can dump local memory. IT managers should watch for security updates from their hardware makers.

Button up your Docker containers. That’s the advice from researchers at Cado Security. Their honeypot recently attracted a piece of malware hunting for vulnerable Docker services. It installs a cryptominer as well as an application called 9hits that threat actors can use to run their attacks from the compromised container. It isn’t clear how this Docker malware is being spread. But the report makes it clear that exposed Docker hosts are a risk to organizations that use them.

American cybersecurity authorities have issued an advisory to help defenders fight the Androxgh0st malware. A threat group has used this malware to create a botnet to steal login credentials for Amazon Web Services, Microsoft Office 365, SendGrid, Twilio and more. Targets also include websites that use the Laravel LARA-VEL web application framework and web servers running certain versions of Apache HTTP Server. The advisory includes indicators of compromise defenders should watch for.

The pressure on IT security leaders in the financial services sector won’t let up this year. That’s according to researchers at Abnormal Security. They note in a report this week that firms in this sector get about 200 advanced phishing attacks per 1,000 mailboxes each week. One of the most common tactics used by threat actors is impersonating a business provider, like a supplier or a software company, and demanding payment for an invoice. Last year that type of attack went up 137 per cent compared to 2022.

Finally, Middle Eastern affairs experts at universities and think tanks should be careful replying to emails. According to Microsoft, they’re being targeted by an Iranian-based threat group it calls Mint Sandstorm. Typically the gang uses custom phishing lures to trick targets into downloading malicious files and gain access to their computers through a backdoor.

Later today the Week in Review podcast will be available. On this show guest commentator David Shipley and I will discuss the recent takeovers of poorly secured accounts on the X platform, and more.

Follow Cyber Security Today on Apple Podcasts, Google Podcasts or add us to your Flash Briefing on your smart speaker.

The post Cyber Security Today, Jan. 19, 2024 – Vulnerabilities found in server firmware, a warning to Docker administrators, and more first appeared on IT World Canada.

Hashtag Trending Jan.19-Impact of AI on employment headlines at Davos; New study shows how much data is shared with Facebook; Starlink announces pricey Gigabit internet

Where does Open Source fit into the global AI picture? Davos is abuzz with concerns about AI. A new study shows just how much data is shared with Facebook, Starlink announces Gigabit internet but it comes with a steep price, and your smart headphones might be raising eyebrows – literally.



 

All this and more in this edition of Hashtag Trending. I’m your host Jim Love, CIO of IT World Canada and Tech News Day in the US.

At this year’s World Economic Forum in Davos, a crucial question looms large: Will AI reshape the future of employment? The discussions, drawing top academics, business leaders, and government representatives, are centered on the potential impact of generative AI on job markets.

OpenAI CEO Sam Altman reassures that AI, in its current state, isn’t replacing jobs but enhancing productivity. It’s viewed more as a powerful tool that magnifies human capabilities, allowing people to perform their jobs better.

A PwC survey of over 4,700 CEOs reveals a split in perception. While 45 per cent believe their business models might not survive the rise of AI in the next decade, 60 per cent expect AI to make their companies more efficient, especially in tasks like email response, report analysis, and presentation drafting.

The International Monetary Fund predicts that up to 60 per cent of jobs in developed countries may be impacted by AI, with both high and low-skilled positions affected. While AI integration could enhance productivity for half of these jobs, the rest may see reduced labour demand, lower wages, and even job disappearance.

The discussions at Davos reflect a global concern about AI’s disruptive potential. While some, like Bill Gates, see AI as a path to greater productivity and reduced work hours, others, including the United Nations Secretary-General, warn of the technology’s social and human rights implications.

Sources include: The Register

Analytics India published a list of the top 7 AI apps on Hugging Face. 

For those who don’t know it, Hugging Face is an open-source data science and machine learning platform that serves as a hub for AI experts and enthusiasts. It allows users to host, collaborate on, and deploy machine learning models, as well as to train and run AI applications. Often referred to as the “GitHub of machine learning. 

The top 7 applications on the platform are an impressive showing of what is available as open source AI. 

Three of the top seven are what some might see as novelties. One is for the generation of 3D shapes. Another transforms pictures into Anime. Another generates comic books. 

But some of these are more serious and potentially powerful tools which are available to anyone. 

IP-Adapter-FaceID ensures consistent and accurate face generation by utilising a face recognition model to extract a unique face ID embedding from a provided portrait photo.

Int float/e5-mistral-7b-instruct is built on the European Mistal AI model, an impressive open source model that rivals results from ChatGPT. This application is used for creative writing tasks like composing poems, code, scripts, musical pieces, emails, and letters. 

Pharma Clip uses CLIP models, natural language predictor models, to help you investigate chemical compounds and their properties. It’s a tool for drug discovery and research.

Open Voice is purportedly a very sophisticated text to speech generator.

The point is that while we spend a great deal of time focused on proprietary models from OpenAI, Google and others, there is an increasingly, I can only call it, sophisticated set of open source offerings that are making their way into usage and Hugging Face is increasingly becoming a place to watch for open source AI development.

Sources include: Analytics India

A study by Consumer Reports and The Markup has unveiled the sheer magnitude of data sharing with Facebook by companies. For the average solo Facebook user an AVERAGE of 2,230 companies, and sometimes over 7,000, are involved in handing over personal information.

This research, involving 709 volunteers over three years, revealed that more than 186,000 organizations passed data about individuals to Facebook’s parent company, Meta.

It’s not just a handful of companies; it’s thousands, each contributing to the vast pool of information that Facebook collects.

For many users, the extent of this data sharing remains unseen and often unacknowledged.

The study does provide a link to a tool that I didn’t know about that allows you to download the information that Facebook has on you.  It might be interesting to see. 

There’s a link to the full study and the tool in the show notes at itworldcanada.com/podcasts.  And remarkably, you can download the study without giving up your personal information. 

Sources include: Consumer Reports

SpaceX’s Starlink is taking internet connectivity to new heights with its latest offering, the “Community Gateways.” Designed for internet service providers (ISPs), this program promises to deliver gigabit speeds to remote areas, albeit with a hefty price tag.

The program requires a substantial upfront investment of $1.25 million. In exchange, SpaceX provides not just a satellite dish but an entire facility capable of receiving up to 10Gbps broadband speeds from its fleet of satellites.

The ‘Community Gateways’ aren’t for average consumers; they’re aimed at ISPs seeking to expand high-speed broadband access in hard-to-reach areas. This business program is a strategic move to bridge the digital divide in remote locations.

Starlink’s first Community Gateway, built for the residents of Unalaska, an island near Alaska, is a testament to the program’s potential. Local ISP OptimERA is using the gateway to significantly enhance broadband for its customers, providing 10 gigabits of symmetric uplink and downlink throughput and maintaining over 99 per cent uptime.

By offering fiber-like speeds through satellite connectivity, Starlink’s Community Gateways represent a significant leap in providing internet access to underserved regions. While the cost is high, the impact on remote communities could be transformative.

Sources include: PC Magazine

Smart headphones might be playing a surprising role in what can only be called eyebrow transformations. A study by the International Beauty and Wellness Council (IBWC) found that 80 per cent of respondents reported significant changes in eyebrow shape and density, sparking curiosity and extensive research.

It turns out, the secret to fuller brows might just be sitting on your ears. The infrared sensors in smart headphones are suspected to stimulate hair growth, thanks to their proximity to the eyebrow area.

Josh Gordon from Geonode explains that the infrared light emitted by these headphones could be increasing blood circulation and stimulating cell activity in dormant hair follicles, leading to lush, full eyebrows.

While the survey suggests a fascinating correlation, it’s crucial to remember that more research is needed to establish a definitive cause-and-effect relationship. But just to be sure I’ll be wearing my headphones on the top of my head for a while – just in case.

Credit: Geonode

And that’s our show for today. Join us tomorrow for a great weekend interview.  I have the author of a new book called the Algorithm with award winning journalist and NYU professor Hilke Schellmann. It’s one of the most thought provoking books on AI that I’ve read. I hope you’ll like the conversation.

Hashtag Trending goes to air 5 days a week with a special weekend interview show we call “the Weekend Edition.” 

We love your comments. Send me a note at jlove@itwc.ca or leave a comment at the bottom of the show notes posted on itworldcanada.com

I’m your host Jim Love.  Have a Fantastic Friday.

The post Hashtag Trending Jan.19-Impact of AI on employment headlines at Davos; New study shows how much data is shared with Facebook; Starlink announces pricey Gigabit internet first appeared on IT World Canada.

A Q&A with Rubrik CEO and venture capitalist Bipul Sinha

Bipul Sinha did not become a successful entrepreneur, engineer and venture capitalist by following staid career moves and adhering to traditional business strategies or pursuing cool ideas. Instead, taking the opposite approach has allowed him to profitably carve out a career that combines all three vocations.

His assortment of skill sets no doubt played a role in Microsoft’s announcement in August 2021 that it had signed a strategic agreement with the data security firm that Sinha helped fund, co-founded and now runs as its chief executive officer (CEO), Palo Alto, Calif.-based Rubrik.

The agreement, which included an undisclosed equity investment in the company by Microsoft, saw the two organizations pledge to address what a release stated as “the rising customer needs to protect against surging ransomware attacks, which are growing 150 per cent annually.”

“Rubrik takes a Zero Trust approach to data management which follows the NIST principles of Zero Trust for everyone interacting with data,” it went on to explain. “This means operating with the assumption that no person, application, or device is trustworthy. To meet this standard, data must be natively immutable so that it is not modified, encrypted, or deleted by ransomware.

“Together, Rubrik and Microsoft will help enterprises manage hybrid and multi-cloud data security and defend against escalating ransomware threats.”

During a visit to Toronto last week, Sinha sat down with IT World Canada at Microsoft Canada’s downtown head office to discuss issues ranging from the importance of the Canadian market to the impact the generative artificial intelligence (GenAI) movement is and will have when it comes to combating the myriad of cybersecurity issues and challenges that exist.

“We have a special relationship with Microsoft, but we work with other hyperscalers, and we have partnerships with them as well,” he said. “But with Microsoft, we have really aligned our engineering teams, our product teams to doing joint product development and driving this vision of secure computation, secure applications.”

Below is an edited version of the rest of the conversation

ITWC:  First, what is the purpose of your trip?

Sinha: I am here to meet with our customers and partners and understand what is driving their priorities and how do we align our vision of cyber recovery and cyber resilience with them. As you know, prevention strategy around cyber is not working. You cannot prevent the unpreventable. Businesses have to have a strategy around how do they recover when the inevitable cyber attack happened and how do they continue to operate the business in the presence of cyberattacks and breaches?

ITWC: How important is the Canadian market to the company?

Sinha: In terms of the Canadian market, it is a developed economy with deep digital transformation that has happened. But with digital transformation, you have security issues. Security is like a tax to your digital economy. Whether it is nation-state actors, whether it is a bored teenager sitting in the basement and swinging the middle finger to large corporation, you could have many different scenarios. Businesses have to be ready for all scenarios to ensure that their services are up all up and running.

At the end of the day, digital economies’ success depends upon digital trust. Digital trust means that whenever I go to a business to access services, those services are up and running, otherwise I lose trust. Having data integrity, cyber recovery and cyber resilience helps businesses enhance and enforce their cyber trust and service their customers better.

ITWC: How big of a game changer is the AI juggernaut in your mind?

Sinha: Computing is all about productivity gains, and GenAI is the next generation of a platform that is evolving around productivity gains. And we see a clear cut productivity gain for an IT operations team to do the cyber work without being an expert on cyber. As you know, in North America, there are  over a million cybersecurity jobs open and there are not enough trained people on cybersecurity to fill those jobs.

So how do you increase the productivity of the operations team so that they can do cyber work? That was our vision of bringing the IT operations team and security operations teams together on a common platform.

We built Ruby, which is the generative AI companion for our Rubrik security cloud. And it helps the IT operations team identify a malware or a threat, is able to do threat hunting, quarantining, and do a successful cyber recovery, using a natural language interface where you do not have to know the nitty gritty of cybersecurity.

ITWC: The company history is an interesting one. How did it come about?

Sinha: As a venture capitalist, I always believed in going after a market that the cool kids were not paying attention to, which essentially means that you want to bet on a non-consensus market. If everybody knows that this market is going to be lucrative, there will be a lot of companies getting started, which means that the value creation will get diluted.

The cool kids were not thinking about backup and recovery. And there was an opportunity to reframe, re-platform backup and recovery into a data security platform to deliver cyber resilience.

The post A Q&A with Rubrik CEO and venture capitalist Bipul Sinha first appeared on IT World Canada.

Should the CIO be solely responsible for keeping AI in check? Info-Tech weighs in

In a recent webinar, research director at Info-Tech Research Group Brian Jackson explained how he thought it was surprising that IT workers think that the CIO should be solely responsible for AI.

The next most popular answer after that, he added, was “well, nobody.”

The research company surveyed 894 respondents who either work in IT or direct IT for its 2024 Tech Trends report.

“It’s early days for many organizations who are deploying AI, and that’s probably why we’re seeing these types of responses. But making the CIO solely accountable is likely not what you want to do,” said Jackson. “If AI is being deployed to drive business outcomes, then you have to get the business leaders involved.”

Info-Tech also examined how organizations that have already invested in AI or plan to invest in AI, which it refers to as “AI adopters”, compare to organizations that either do not plan to invest in AI or don’t plan to invest until after 2024, referred to as “AI skeptics”.

Only one in six AI adopters are going to be creating a committee that will be accountable, and one in 10 share accountability across two or more executives.

Jackson advises organizations to think about three key concepts when implementing a responsible AI model:

Trustworthy AI – Do people understand how it works, how it generates output, or what data goes into its training?
Explainable AI – Ability to explain how an AI model makes its predictions, its anticipated impact, and its potential biases
Transparent AI – Can we communicate the impacts of the decisions that are being made regarding AI, can we monitor the results and report on them, show people the negative aspects, and adjust accordingly.

Having guardrails in place would be even more critical as AI starts creating customer value directly, Info-Tech said.

AI will no longer be just complimentary to the core value of an e-commerce business or an entertainment business, such as when Netflix predicts what you’re going to watch next, explained Jackson.

“We’re seeing business models created where AI is the value that the customer gets out of the service,” he affirmed.

 OpenAI is a perfect example of that, but we also see firms like Intuit, which is retooling its whole platform around generative AI. Specifically, it released a custom-trained financial large language model it calls GenOS that sits at the center of the company’s operating system, and solves tax, accounting, marketing, cashflow, and many other personal finance challenges.

However, as much as it is valid to hold executives accountable for regulating AI, security by design would be equally critical, explained Jackson.

Every year, organizations are investing more in cybersecurity, and yet they continue to face more attacks than ever before.

“Somehow, we’ve created this industry where software vendors create the risk, yet the customers bear the cost mitigating it,” Jackson noted.

He added, “It’s becoming everybody’s job. I bet you’ve been through some sort of phishing, email testing or cybersecurity training from your own organization, no matter what your job title is. So how do we get out of the cycle of always spending more on cybersecurity? How do we start to shift the accountability for security back away from the users to the builders?”

In 2024, he pointed out, we will see the White House and the new National Cybersecurity Strategy put the onus on technology makers to prioritize security or mandate, for instance, internal and external testing of AI systems before release.

“The bottom line is – if you’re making new AI models, you don’t have a choice,” said Jackson. “We can’t afford to build fast and cheap today and pay the cost of vulnerability later. We need to build with security by design now. And if you’re on the other side of it – you’re a customer of these AI providers, you have more leverage.”

Another key trend that organizations looking to mitigate AI risks need to think about is their digital sovereignty, Jackson said.

Organizations can, for instance, update their robots.txt file if they do not want their website data to be used to train an AI model. 

However, you’ll need a lot more, he added, to keep your data locked down, with people using data to train open source models. Artists have been especially at the receiving end of the widespread mimicry by AI.

Many artists and organizations have already sought to protect their intellectual property with tools like Glaze from the University of Chicago, which puts images through a filter tasked to protect the style from being interpreted by an AI algorithm. 

The university is also developing another project called Nightshade which “poisons” the training data, rendering the outputs useless – dogs become cats, cars become cows and so forth.

“While we wait for the courts to make the rulings, maybe the law makers will catch up and introduce new laws that redefine copyright in this AI age, “said Jackson. “But for now, it seems like it’s open season on scraping your data and imitating your intellectual property. So to defend our digital sovereignty, we have to use technology against technology.”

The post Should the CIO be solely responsible for keeping AI in check? Info-Tech weighs in first appeared on IT World Canada.