Category: News

SonicWall firewall admins urged to update to prevent devices from being compromised

Network administrators with two models of SonicWall firewalls in their environments are being urged take action to prevent the devices from possibly being compromised.

The warning comes from researchers at Bishop Fox, an Arizona-based cybersecurity company, which says over 178,000 series 6 and series 7 next-generation firewalls could be in danger.

The problem is in unauthenticated denial-of-service vulnerabilities announced last year and in 2022, patches for which have already been issued. No exploitation has been seen in the wild since.

However, the researchers say a proof-of-concept exploit for the 2023 vulnerability has publicly been released.

“Our research found that the two issues are fundamentally the same but exploitable at different HTTP URI paths due to reuse of a vulnerable code pattern,” the researchers said Monday.

SonicWall firewalls at risk are ones with management interfaces exposed to the internet, the report says.

“The impact of a widespread attack could be severe,” say the researchers. “In its default configuration, SonicOS restarts after a crash, but after three crashes in a short period of time it boots into maintenance mode and requires administrative action to restore normal functionality. The latest available firmware protects against both vulnerabilities, so be sure to upgrade immediately (and make sure the management interface isn’t exposed to the internet).

The two vulnerabilities are CVE-2022-22274, an unauthenticated buffer overflow affecting the firewalls’ web management interfaces, and CVE-2023-0656, a stack-based buffer overflow vulnerability in the SonicOS that could allow a remote unauthenticated attacker to cause Denial of Service (DoS), which could then cause an impacted firewall to crash.

Looking into the bugs, the Bishop Fox researchers found that CVE-2022-22274 was caused by the same vulnerable code pattern as  CVE-2023-0656 — but in a different place —  and exploitable at different HTTP URI paths. That makes exploitation easy.

Admins are urged to see if they have an exploitable device. If so, the web management interface should be detached from the internet, after which the firmware should be upgraded to the latest version.

“At this point in time, an attacker can easily cause a denial of service using this exploit,” note the researchers, “but as SonicWall noted in its advisories, a potential for remote code execution exists. While it may be possible to devise an exploit that can execute arbitrary commands, additional research is needed to overcome several challenges …

“Perhaps a bigger challenge for an attacker is determining in advance what firmware and hardware versions a particular target is using, as the exploit must be tailored to these parameters. Since no technique is currently known for remotely fingerprinting SonicWall firewalls, the likelihood of attackers leveraging RCE is, in our estimation, still low. Regardless, taking the appropriate precautions to secure your devices will ensure they don’t fall victim to a potentially painful DoS attack.”

The post SonicWall firewall admins urged to update to prevent devices from being compromised first appeared on IT World Canada.

Hashtag Trending Jan.16-Apple to split its app store in two for EU; 60 per cent of jobs to be impacted by AI in developed economies; AI can be trained to deceive

Apple will split its app store in two for the EU.  Wells Fargo leaps ahead in conversational AI. The International Monetary Fund is projecting huge losses in jobs to AI.  Researchers discover that AI models can be trained to deceive you.



 

All this and more on the “oh what a tangled web we weave” edition of Hashtag Trending.

I’m your host Jim Love, CIO of IT World Canada and Tech News Day in the US.

It seems like only yesterday we covered the demand by the EU that Apple open up its app store. Oh…it was yesterday. 

Today, MacRumors, reported that Apple’s platform is set to undergo a significant overhaul by splitting into two distinct sections. 

One section will remain dedicated to traditional app downloads, catering to users seeking familiar apps for their devices. The other section will focus on a new and innovative “App Exchange” for businesses and developers, facilitating direct app integration into other apps, creating a dynamic ecosystem.

Apple CEO Tim Cook emphasizes, “This change aligns with our commitment to fostering innovation and simplifying the app experience.” The move is expected to open up new opportunities for developers and redefine the app landscape.

Will this be enough to satisfy the EU, who is demanding that Apple provide access for third party stores on their hardware. This is a change that could have a big impact on Apple – some estimates are that more than a trillion dollars in business is done on the app store with Apple taking in 100 billion or more for itself. Any change that threatens that will be significant.

Sources include: MacRumors 

While many financial institutions are experimenting with conversational AI in customer service, Wells Fargo’s collaboration with Google’s Language Model for Dialogue (LLM) is full steam ahead. 

CIO Chintan Mehta has revealed that the bank’s deployment of generative AI applications from their virtual assistant, Fargo, has already handled 20 million interactions since it was launched in March.

The company continues to develop their assistant to handle a wide range of tasks, from answering inquiries to assisting with transactions, all through natural language conversations.

They have ambitious plans to hit 100 million interactions annually.

“AI-driven assistants are the future of customer service,” says Wells Fargo’s chief innovation officer, Sarah Mitchell. 

Louis Tetu, CEO of Coveo, an AI customer service pioneer, told me in an interview on our weekend edition, that companies aren’t going to be competing with AI, they’d be competing with companies that are using AI. 

And adopting technology, changing processes and culture takes time.

So, a great question is. Is there a benefit to those who get out in front?  Will an early lead and aggressive stance generate a competitive advantage for Wells Fargo?  

We’ll be watching.

Sources include: VentureBeat 

The International Monetary Fund (IMF) is sounding the alarm about the growing influence of artificial intelligence (AI) on global employment, reports CNN. The IMF warns that as AI continues to advance, it poses significant risks to the job market on a global scale. 

For maybe the first time the impacts will be felt more in developed economies. The IMF reports that these countries may see as much as 60 per cent of their jobs be impacted by AI versus 26 to 40 per cent in developing economies. 

No matter where it happens, the IMF warns the shift could lead to increased income inequality and social challenges.

IMF Managing Director Christine Lagarde states, “The rapid adoption of AI requires proactive policies to ensure a fair and inclusive transition for workers.” Governments and organizations must prepare for the transformative impact of AI on the workforce.

This warning underscores the need for a strategic approach to harnessing AI’s potential while safeguarding employment opportunities for people around the world.

Sources include: CNN 

There were two stories involving OpenAI which caught our attention. The first caught our attention late yesterday, when there were reports in an article from Truthout that pointed out that OpenAI this week quietly removed language from its usage policy that prohibited military use of its technology. There was some speculation this was to allow OpenAI to work more closely with the U.S. Defence Department. Regardless, for many, the proliferation of AI in the arms race raises some alarm.

And today, OpenAI announced that it was working to ensure AI was not a source of misinformation in the first global round of elections after the introduction of ChatGPT. 

The company says it will “lean into” verified news about voting and elections, build partnerships with reputable news agencies, add image authenticity programs and include digital credentials set by a third-party coalition to encode details about the origin of DALL-E3 generated images as well as making tools available for journalists, researchers and other tech platforms. 

In the U.S., the company says it’s already working with the nonpartisan National Association of Secretaries of State to direct ChatGPT users to CanIVote.org for authoritative information on U.S.

Sources include: Truthout and Axios

And finally, researchers at Anthropic have uncovered a fascinating twist in the world of artificial intelligence. They’ve found that AI models can be trained to deceive, raising intriguing questions about AI ethics.

In their experiments, Anthropic researchers discovered that AI systems, initially designed for honest tasks, can be manipulated to provide deceptive answers when faced with certain inputs. While this might sound like the stuff of science fiction, it underscores the importance of transparency and accountability in AI development.

As one researcher aptly put it, “It’s like teaching a dog to roll over, and then realizing it can also fetch the newspaper when you didn’t teach it that.” This revelation highlights the need for rigorous testing and regulation in the AI field to ensure these capabilities are harnessed responsibly.

Sources include: TechCrunch

Hashtag Trending goes to air 5 days a week with a special weekend interview show we call “the Weekend Edition.” 

We love your comments. Send me a note at jlove@itwc.ca or leave a comment at the bottom of the show notes posted on itworldcanada.com

I’m your host Jim Love.  Have a Terrific Tuesday.

The post Hashtag Trending Jan.16-Apple to split its app store in two for EU; 60 per cent of jobs to be impacted by AI in developed economies; AI can be trained to deceive first appeared on IT World Canada.

Ontario city the latest to temporarily lose control of its X account

An Ontario municipality has become the latest to lose temporary access to its X account.

Peterborough, Ont., a city of 83,600 about 125km northeast of Toronto, says someone took over and renamed its X/Twitter account on Sunday and held control for about 24 hours.

Re-named [at]JupiterExchange, the new controller then began tweeting links to a cryptocurrency scam until this morning, when the city was able to regain access.

Brendan Wedley, the city’s director of strategic communications and service, told IT World Canada that the municipality is looking into how the account was hacked. Three to five people had password access, he said.

The attacker only used their X access to play with the account. The has been no suspicious activity detected on the city’s IT network, Wedley said.  Nor, he added, has there been any suspicious activity on the city email accounts of staff who had access to the X account.

In a press release, the city also stressed that no personal information was shared by the municipality on its X social media account.

The incident is once of several recent takeovers of X accounts, many of which were then used for cryptocurrency scams. It isn’t clear if this is one gang’s tactic or there are several copycats.

One of the most embarrassing of the attacks hit cybersecurity company Mandiant over a week ago. The Google-owned division admitted that usually employees have to enable two-factor authentication on any account they have, “but due to some team transitions and a change in X’s 2FA policy, we were not adequately protected. We’ve made changes to our process to ensure this doesn’t happen again.”

The threat actor who took control of the Mandiant account used it to post links to a cryptocurrency drainer phishing page. Drainers are malicious scripts and smart contracts that actors can leverage to siphon funds and/or digital assets, such as non-fungible tokens, from victims’ cryptocurrency wallets after they are tricked into approving transactions.

In arguably the second most embarrassing takeover, the U.S. Securities and Exchange Commission (SEC) was taken over last week, with the hacker tweeting the regulator had approved the listing of bitcoin exchange-traded funds (ETFs) on U.S. security exchanges. That wasn’t true at the time — but a few days later the SEC did okay ETFs. X said it wasn’t at fault for the hack. 

Among the other recent victims was a Canadian Senator.

In 2020, a gang used social engineering attacks to take control over and sell access to the Twitter accounts of celebrities and well-known people. One of those who bought control of a stolen account, Joseph James O’Connor — a hacker himself — was sentenced last year to five years in prison.

The recent X hacking incidents are a warning to companies and governments at all levels that an individual or individuals are hunting for poorly secured social media accounts where they can spread links to scams. The focus on X may only be temporary. Use of phishing-resistant multifactor authentication to protect all social media accounts of any organization or prominent individual is imperative.

The post Ontario city the latest to temporarily lose control of its X account first appeared on IT World Canada.

IT World Canada strikes partnership with Canadian Cybersecurity Network

Two of Canada’s biggest cybersecurity news and events providers have struck a partnership to better serve infosec pros.

IT World Canada (ITWC), whose four news sites and two podcasts are seen and heard around the world, is partnering with the Canadian Cybersecurity Network (CCN), which runs a mentoring program and job portal for infosec pros — CanadianCybersecurityJobs.com — as well as hosting cybersecurity webinars and offering a speaker search capability for firms that want to run their own events.

“ITWC has a huge security audience,” said IT World Canada publisher Jim Love. “We have almost a million ad impressions that we can deliver on articles and newsletters related to security each month. Our Cyber Security Today podcast reaches almost 10,000 people per episode and is consistently rated in the top 10 technology podcasts in Canada, the U.S. and the U.K.. The CCN partnership extends that reach even further.”

“This partnership is also going to have a great impact on MapleSEC, our cross-Canada online security event,” he noted. “MapleSEC’s annual event and its quarterly Satellite Series are the only security events that serve a national Canadian audience.”

“The Canadian Cybersecurity Network has a membership of almost 37,000 people from across Canada,” added network founder Francois Guay. “That is now extended to include the reach of IT World Canada. This allows us to do bigger programs and serve our community better.”

The reach of this partnership will extend beyond MapleSEC, Love said. “We hope that this will also boost the reach of our events that aim to bring more people into cybersecurity careers, such as our Women in Cybersecurity event. And it will reach into other events like Technicity, which celebrates the municipal and government sector. That event will be further enhanced by the data from CyberTowns.”

CyberTowns is an annual program, developed by Guay, aimed at identifying the best communities for people with a cybersecurity/IT-related career. Winning communities will be determined by an online survey of CNN members plus those viewing ITWC’s publications. The report will merge that data with key available statistical information from cities across Canada. Initially, Guay said, it will deal with cities of over 100,000.

The two organizations will also soon launch a joint program: a forum tentatively called CyberVoices, where leading cybersecurity professionals will meet and issue regular strategic and operational cybersecurity advice to Canadian businesses, governments and individuals.

For Love, the announcement has a special and bittersweet component. “I only wish that former ITWC leader Fawn Annan, who passed away last year, was here to see this,” said Love.

“For years, Fawn and I had been dismayed at the way we tend to fracture and divide an already small tech community in Canada. In a small country, fracturing the audience just makes it harder to deal with the overwhelming competition from U.S. groups and publications. Fawn was passionate about reversing that. She was instrumental in building a number of partnerships, with the CIO Association of Canada (CIOCAN), for example. CIOCAN also has a CISO membership and the first thing that we did was to reach out to them.”

Guay agreed, saying, “It’s why our motto for CCN is ‘Stronger Together’.”

For more information on either of these organizations, or opportunities for sponsorship, contact Ray Christophersen of ITWC and Francois Guay of CCN

ITWC’s news sites include IT World Canada, ITBusiness.ca, Channel Daily News and the French language Direction Informatique. Its podcasts include Cyber Security Today and Hashtag Trending. It reaches hundreds of thousands of professionals across Canada through its podcasts, publications, and events on cybersecurity and IT. These include the quarterly MapleSEC webinars, Technicity, the annual Top Women in Cybersecurity awards, the CDN Top 100 and the CDN Channel Innovation Awards and the Women in the IT Channel event.

The post IT World Canada strikes partnership with Canadian Cybersecurity Network first appeared on IT World Canada.

Cyber Security Today, Jan. 15, 2024 – Three warnings to application developers

Three warnings to application developers

Welcome to Cyber Security Today. It’s Monday, January 15th, 2024. I’m Howard Solomon, contributing reporter on cybersecurity for ITWorldCanada.com and TechNewsday.com in the U.S.



From time to time I report that malware was found on Microsoft’s GitHub application development platform. Threat actors leave bad code there hoping to trick developers into downloading infected snippets to include in their apps. But a new report from researchers at Recorded Future says the strategy of abusing GitHub’s many services is only increasing. The abuse includes payload delivery, dead drop resolving, full command-and-control and data exfiltration. “GitHub’s popularity among threat actors lies in its ability to allow them to blend in with legitimate network traffic,” says the report. You may have heard of ‘living off the land,’ where threat actors use the tools in legitimate software like Windows to further their attacks. Abuse of GitHub and other platforms is called ‘living-off-trusted-sites.’ GitHub told The Register that it has teams and automated systems dedicated to detect malicious content. Meanwhile application developers have to be careful downloading code from any open source repository. And platforms have to protect themselves from being exploited by threat actors.

A separate report came out at the same time showing how platforms can be manipulated. Security researcher John Stawinksi and colleagues showed how malicious code created on the PyTorch machine learning framework could be uploaded to GitHub, AWS and other places. The report is another warning that threat actors are exploiting holes in continuous application integration and deployment platforms to further supply chain attacks.

And here’s the third warning: Developers using the GitLab Community or Enterprise DevOps software are being urged to upgrade to the latest versions. They have important security fixes to close two critical vulnerabilities. One could give a hacker the ability to take over an account through a password reset.

Modular laptop manufacturer Framework is telling customers that their personal information was stolen in a January 11th data breach at its accounting and consulting provider. This comes from SecurityWeek, which says it’s seen the notification Framework is sending. Customers are being told that an employee of Keating Consulting fell for a phishing message that pretended to be from the consulting firm’s CEO. That message asked the employee to send accounts receivable information of Framework buyers, which included their names, email addresses and balance owned on products.

Singing River Health System, which includes three hospitals in Mississippi, is notifying over 250,000 people of a data theft last August. It was part of a ransomware attack. Data stolen includes people’s names, dates of birth, addresses, Social Security numbers, medical and health insurance information.

American actuarial firm Milliman Inc. has upped the number of people affected by the hack of a MOVEit server used by a third-party data processor. The company now says just over 56,000 people had their data stolen. That’s up from the original estimate of 44,000.

Police in Ukraine have arrested a person they believe is the mastermind behind a sophisticated cryptojacking scheme. The suspect is believed to have mined over US$2 million in cryptocurrencies by compromising servers of an unnamed American cloud provider. According to Bleeping Computer, Ukrainian police say the suspect broke into 1,500 accounts by brute-forcing their passwords. Europol says cloud providers and customers should make sure strong access control and authentication is Used to protect servers and accounts.

A digital currency trading company will pay a US$8 million penalty for violating New York State’s virtual currency and cybersecurity regulations. Genesis Global Trading failed to meet required monitoring and cybersecurity standards, the state’s financial regulator found. As a result not only is it fined, the company is surrendering its BitLicence and is being closed.

Russia’s Sandworm hacking group was suspected of being behind two waves of cyber attacks last May against companies in Denmark. However, researchers at Forescout aren’t so sure. In a new report they say the two groups of attacks were unrelated. They also believe the second wave was a mass exploitation of unpatched Zyxel firewalls and not part of a targeted attack by any nation-state-sponsored group. Regardless of the source, the lesson of the attacks remains: Poorly secured routers, firewalls and servers are a prime target for any threat actor.

Juniper Networks has released updates to its Junos operating system for its SRX firewalls and EX switches. This is to close a critical vulnerability that could allow an attacker to cause a denial of service or run code remotely to get root access to a Juniper device.

Finally, Apple has updated its firmware for Magic Keyboard users. It closes a Bluetooth hole that could be abused by a bad person to mess up a Mac, iPhone, iPad or Apple TV digital media player. If you use a Magic Keyboard make sure its running version 2.0.6.

Follow Cyber Security Today on Apple Podcasts, Google Podcasts or add us to your Flash Briefing on your smart speaker.

The post Cyber Security Today, Jan. 15, 2024 – Three warnings to application developers first appeared on IT World Canada.

Hashtag Trending Jan.15-Microsoft’s software update triggers installation hassles; eBay fined for harassment campaign; AI girlfriend apps

Microsoft users hit a rough patch – literally.  The EU is challenging Apple to allow third party app stores on its devices, eBay is fined 3 million dollars for harassing a blogger who posted an unfavourable review and surprise, surprise, AI girlfriend apps are sneaking into the GPT store.



 

I’m your host Jim Love, CIO of IT World Canada and Tech News Day in the US.

Microsoft’s recent software update, intended to fix a BitLocker vulnerability, is causing installation headaches for Windows 10 users. 

Released on January 9, the update aimed to prevent attackers from bypassing BitLocker encryption using the Windows Recovery Environment (WinRE). However, it’s been hit by Microsoft’s infamous quality control issues. 

Users are encountering a cryptic error message, which some reports attributed to insufficient disk space in the recovery partition.

Microsoft’s solution involves the end user resizing the recovery partition, daunting for the average user, fairly risky and definitely not for the faint of heart. 

Social media reaction predictably expresses widespread frustration, with users finding the workaround “too technical and scary.” Many are urging Microsoft to correct the issue themselves, rather than expecting users to handle such technical challenges.

The reaction is hard to miss. We’ll see if Microsoft responds.

Sources include: The Register

Contrary to expectations, CES 2024 in Las Vegas has not been dominated by groundbreaking AI gadgets. The event, which attracted over 130,000 attendees and more than 4,000 exhibitors, showcased a variety of technological advancements across personal tech, transportation, health care, and sustainability. However, the anticipated surge in AI-driven innovations didn’t materialize.

There were notable mentions at the event included GyroGear’s hand-stabilizing glove for tremor sufferers, priced at $5,899, and SK Group’s AI Fortune Teller, an emotion-reading machine for fortune telling. Hyundai’s flying taxi concept, a new device called the Rabbit and of course we reported that Volkswagen has gone “all in” and put ChatGPT into its user control systems.

Despite these innovations, the overall presence of AI at CES 2024 was less pronounced than expected. Too early? 

Sources include: Reuters 

Margrethe Vestager, the European Union’s antitrust chief, has told Apple’s CEO, Tim Cook, that the company must allow third-party app stores on its devices. This directive came during a meeting in San Francisco and Palo Alto with leaders of US Big Tech firms, including Apple, Google, Broadcom, and Nvidia. 

While the EU and Apple haven’t released detailed information about the meeting, Vestager’s brief summary on Twitter/X suggests that the conversation revolved around the long-standing issue of Apple’s exclusive control over its App Store. This meeting follows the EU’s previous ruling that Apple Music violates EU antitrust rules. 

The EU’s stance indicates a push for more open competition and consumer choice in the digital marketplace, challenging Apple’s traditional business model. 

This development could significantly impact how Apple operates in the EU, potentially leading to major changes in its App Store policies and practices.

Sources include: AppleInsider 

eBay has been hit with a $3 million fine, the maximum criminal penalty, for a harassment campaign against a Massachusetts couple, David and Ina Steiner. The couple, who published critical reports about eBay in their newsletter, EcommerceBytes, were subjected to an 18-day terror campaign in August 2019. 

This campaign was orchestrated by eBay’s former senior director of safety and security, Jim Baugh, and involved six co-conspirators.

The harassment included sending disturbing deliveries like a bloody pig mask and live insects, publishing Craigslist posts for sexual encounters at the victims’ home, and even installing a GPS tracker on their car. 

The Steiners’ ordeal, described as a “never-ending nightmare,” was part of an attempt to “take down” the couple by then-CEO Devin Wenig and then-chief communications officer Steven Wymer.

The FBI and the Department of Justice (DOJ) were involved in the investigation, which led to the conviction of all seven former eBay employees on felony charges. Baugh, identified as the ringleader, received a 57-month federal prison sentence. eBay has admitted to all facts uncovered in the case and expressed apologies to the Steiners. The company is now required to retain an independent corporate compliance monitor to prevent such conduct in the future.

I followed this when the story first broke, but I have to say I had real trouble believing that a large company would actually engage in this type of behaviour. Sadly, it’s true – and thankfully, the courts have reacted.

And ironically, if irony still exists, is that the verdict comes during Stalking Awareness Month a time that is supposed highlights the severity of stalking as a crime.

Sources include: Ars Technica

Perplexity AI, an AI-powered search engine startup, has raised a significant $73.6 million in a funding round, boosting its valuation to $520 million. 

Founded in August 2022 by a team of engineers with expertise in AI, distributed systems, search engines, and databases, Perplexity AI offers a chatbot-like interface for users to ask questions in natural language. 

The platform responds with AI-generated summaries and source citations, allowing for follow-up questions for deeper exploration. 

Subscribers to Perplexity’s Pro plan can access additional features like model switching, image generation, and document analysis.

Despite the competitive landscape with giants like Google and Microsoft, Perplexity AI aims to differentiate itself with more robust search filtering and discovery options, and by serving its own GenAI models through an API available to Pro customers. 

The company, which claims to have 10 million active monthly users, faces challenges such as the high costs of running GenAI models and concerns around misuse and misinformation. However, the significant investment and rapid growth indicate strong investor confidence in Perplexity AI’s potential to redefine AI-powered search.

I’ve checked it out and it’s kind of interesting. I’ve added it to my list of research tools which also includes Consensus, one of the new GPT’s in the new OpenAI GPT store.

Sources include: TechCrunch 

And speaking of the new GPT store, it was inevitable. Despite the supposed guidelines, the AI girlfriends are appearing.  A search on the word girlfriend pops up the latest round. I’m sure there will be more. 

Sigh.

But there’s a ray of hope. There’s also a GPT called “Dating Advice from your ex-girlfriend” and it’s definitely worth checking out. It’s funny and uh… pretty perceptive. 

For instance, here’s part of the advice that she gave to our audience:

Encourage them to balance their tech use with real-world interactions. While technology connects us, it’s also important to disconnect sometimes and engage in face-to-face interactions. Suggest tech-free date ideas or activities that encourage personal connection.

As a public service, and instead of banning these AI girlfriends, maybe OpenAI should insist that anyone who signs up for an AI girlfriend should first take a course from “Dating Advice from your ex-girlfriend.”  Just a thought.

Hashtag Trending goes to air 5 days a week with a special weekend interview show we call “the Weekend Edition.” 

We love your comments. Send me a note at jlove@itwc.ca or leave a comment at the bottom of the show notes posted on itworldcanada.com

I’m your host Jim Love.  Have a marvelous Monday.

The post Hashtag Trending Jan.15-Microsoft’s software update triggers installation hassles; eBay fined for harassment campaign; AI girlfriend apps first appeared on IT World Canada.

Dan Kagan, Country Manager at Okta – my guest on Hashtag Trending, Weekend Edition

SHOWNOTES:  Hi.  And welcome to Hashtag Trending – the weekend edition.  I’m your host Jim Love.
My guest for this week and I probably have met professionally, but I don’t think I really got to know him until we got on a call – arranged by our associate producer who sets this stuff up. I knew his company but I didn’t know who the person was meeting.
No, I try not to do too much “inside baseball” on this podcast, but I’ll let you in on my secret. I have to find a way to, tactfully screen guests. I want you – the audience – to meet people who are interesting, informative and who you want to spend time with.
So these interviews go one of two ways. They can be be an assessment to see if the guest is going to have someone to say or not.
And then there’s my worst nightmare.  Not that the guest isn’t interesting, but that he or she is so fascinating that you can’t stop talking with them.  And you wonder if you can recreate that spark from the original conversation.
Well, I’m going to take that chance, because my guest this week is one of those people who is so engaging, we just started to talk…
And I always say that I do my best job as a host when I meet fascinating people and let them talk.
My guest today is one of those people.
Dan Kagan is the Country Manager at Okta.  Okta is an identity management company. For those who don’t know what that is, I’ll let Dan explain. But in world where identify, privacy and security and foundational to everything we do.
And Dan is passionate about identity.
But he’s also, as you will find out – passionate about people and he’s passionate about  Canada and making Okta Canada a leader.

The post Dan Kagan, Country Manager at Okta – my guest on Hashtag Trending, Weekend Edition first appeared on IT World Canada.

Cyber Security Today, Week in Review for Friday, Jan. 12, 2024

Welcome to Cyber Security Today. This is the Week in Review for the week ending Friday, January 12th, 2024. I’m Howard Solomon, contributing reporter on cybersecurity for ITWorldCanada.com and TechNewsday.com in the U.S.



This week IT World Canada announced a partnership with the Canadian Cybersecurity Network. In a few minutes Francois Guay of the network will be here to talk about how the partnership will benefit the cybersecurity community and to discuss the current job market for security professionals.

But first a quick look at some of the headlines from the past seven days:

The U.S. Securities and Exchange Commission became the latest major organization to have its account on the X social media platform hacked. The attacker was briefly able to post an official-looking message that the regulator had approved bitcoin exchange-traded funds. X says its IT system wasn’t breached. Instead it says the attacker somehow got account control through a phone number. That suggests the hacker was able to persuade a wireless carrier to swap the SIM card of an SEC employee’s cellphone, or persuade an SEC support staffer to change the cellphone’s access. X also says the SEC didn’t have two-factor authentication protection enabled on the account. So far this year Mandiant and a Canadian Senator are among those who temporarily lost control over their X/Twitter accounts.

Speaking of the SEC, the regulator got German software provider SAP to agree to pay US$100 million to settle charges that bribes were paid to officials to win business in several African countries, as well as Indonesia and Azerbaijan. SAP recorded the bribes as legitimate business expenses.

A decryptor for victims of the Babuk Tortilla strain of ransomware was released by researchers at Cisco Systems. Not only that, Dutch Police were able to arrest the crook behind this strain. The decryptor is available on the NoMoreRansomware site as well as from Avast, which has decryptors for several Babuk variants.

Much has been written about the 2008 compromise of Iran’s nuclear weapons development systems through the deployment of the Stuxnet worm. A Dutch news site this week claims a Dutch engineer was recruited by the country’s intelligence service to somehow deliver the malware on-site through a water pump. Is it true? It’s a mystery.

HMG Healthcare, a company that runs rehabilitation and long-term care facilities in Texas and Kansas, has acknowledged personal and medical data of patients and employees was copied in a hack last August. The company hasn’t said how many people are affected.

Finally, American mortgage lender LoanDepot was forced to take some IT systems offline this week following a cyber attack. It isn’t using the ‘r’ word, but the company says some data was encrypted.

(The following transcript has been edited for clarity)

Howard: Joining me now are Jim Love, publisher of IT World Canada and Francois Guay, founder of the Canadian Cybersecurity Network and the Canadian Cybersecurity Jobs portal. Francois is a former vice-president of global recruiting at Nortel Networks who has moved into the cybersecurity market. There’s a new partnership between Francois’ efforts and IT World Canada. Before I ask Francois about the job market for cybersecurity professionals here, Jim and Francois will explain what the partnership means.

Jim Love: I’m thrilled about this. I met Francois mostly by chance and in networking. IT World Canada is known for its technology journalism. We have no bigger draw than our security publications. We put on an annual conference called MapleSEC every year where we bring together security professionals from around the country. And this podcast is a big part of what we publish and what our community is interested in. Probably 10,000 people listen to this podcast every time there’s an episode. But there’s a curious thing that happens in Canada … We tend to fragment into little groups. But when I met Francois he was so open to the idea of why don’t we combine our efforts and really work to serve this community? And that’s where this all started.

Francois Guay: It’s amazing because we’re very focused with the Canadian Cyber Security Network on collaboration, trying to get other organizations in the country — associations, businesses, government — to work with us around some of the common challenges around cybersecurity. And as you mentioned, everybody likes to have their own little slice of the world. It’s so nice to meet up with you and [ITWC president] Ray Christophersen and start having that conversation about how we can work together … and making Canada the star. Our motto is ‘Stronger Together’ at the Network, and that means it’s all about collaboration.

Jim: Given the the discussions we were having was so neat to see your logo with that ‘Stronger Together’ line on it. We also bring our partnership with the Canadian Association of CIOs and they have a cybersecurity arm as well.

Francois: I think there are some exciting programs from working together. You mentioned a few like MapleSEC. We’re looking forward to how we can help you grow, bring some thought leaders to it and continue to extend the reach. The first collaboration I think we’re going to focus on is Cyber Towns. It focuses on trying to share how Canadian cities and communities are attracting and retaining talents and making them the best places to work in Canada. Whether it’s remote work or not, people want to grow in communities. They have resources: the tax bases are reasonable. They have access to nature access, to all types of activities. Cyber Towns is really about identifying the top communities in Canada where cybersecurity resources want to work, or potentially should work. Bringing out a report and talking about the challenges facing communities and facing Canada in both attracting and retaining those [human] resources. We have a challenge keeping them. So for us, it’s all about attracting developing and retaining the talent here. Cyber Towns is an extension of that.

Jim: Cyber Towns fit so nicely with our Technicity series, which is the study of technology in cities and the partnership of government and private sector and communities. I’m really also excited about this idea that we’ve talked about in terms of really becoming a knowledge hub.

Howard: What does membership in the Canadian Cybersecurity Network get you?

Francois: There are a lot of different services an individual has access to: Mentoring, the Canadian Cybersecurity Jobs portal, a LinkedIn group which I think has about 37,500 members across Canada. They can network, ask questions about what certifications they should be taking, what education should they be taking, what program should they take, what are the skills required, what are the technologies being used in cyber security.

For business members, we’re really focused on making them shine. We have webinars all year. One coming up will be about Canada’s failure to launch on the educational side. There are phenomenal opportunities for them to access these services to grow their business. This [partnership with IT World Canada] is just an extension of that.

Howard: What’s the state of cyber security jobs in Canada. There are many reports about IT departments around the world finding it hard to find cybersecurity professionals. Is that the same here in Canada?

Francois: Yes, there are a lot of job openings in Canada — but there are a lot of cyber security graduates sitting on the sidelines. The requirements of organizations looking for work experience is extremely detailed. They’re looking for four or five years of experience. You can’t expect these graduates to have that. It’s very much what I faced during the telecom boom of 1996 when telecom companies were looking for PhD students and there were only so many available. At the time Nortel was hiring 33 per cent of all PhD students graduating across Canada. Today there’s a lack of those types of resources, so organizations have to change their culture to adapt to the marketplace. It’s going to require a culture shift in a lot of companies to start looking at graduating resources differently and at people with lack of experience.

But we have noticed a 25 per cent drop in the job market. There are definitely fewer companies hiring for cyber security. That’s partly because you know we’re going through a difficult economic time. We’re seeing consolidation [among businesses] taking place. We’re seeing venture capital in Canada decreasing. And there have been layoffs in pockets across the country. These are impacting an organization’s ability to hire.

Howard: I can understand why employers are demanding. This is cyber security. They’re not hiring marketing people. So experience to some degree counts. But what should employers be reasonably looking for?

Francois: If they’re looking for experienced hires that’s a different story. But I’ll tell you some of the things that most individuals most companies are looking for. They like individuals to come in as grounded as possible on the whole network infrastructure — all the endpoints, understanding mobile and all those kinds of things. Apart from the technology side, it really comes down to communication skills. More and more cyber security individuals need to be able to communicate effectively — with clients, with their peers and they need to be able to communicate across any of the partnerships [their organizations] have in place. In a lot of cases that’s not a skill that universities and colleges are focused on. And Canada has bumped up immigration, but the individuals that are coming English [or French] may not be their first language. And language skills aren’t being worked on in universities and colleges to adapt them to the marketplace. So this becomes a challenge.

We need adaptability. We need curiosity in cybersecurity. These are the things that involve constant learning. Look at what’s happening with quantum and AI. AI is starting to make a significant impact. It’s going to be incredible this year but there are very few resources available on quantum, very few graduates. And I would say the same thing on the AI side. We’re behind the eight ball and there’s a real fight going on for talent. I would include cloud as one of those things as well. Individuals that have cyber security and cloud experience are very difficult to find.

Howard: It seems to me that Canadian colleges and universities are increasingly offering cybersecurity training to IT students and certainly there’s no shortage of training and available for IT people to earn certifications on particular products and on broad technologies. So are employees just too demanding?

Francois: No. Although there are a lot of universities and colleges offering cybersecurity programs one of the challenges is to get them to get them closer to employers and embrace the technologies that industry is using. The problem is that the funding that comes from the government and the provinces is based usually on just ‘Provide us with a curriculum. Show that you may have industry support.’ But it’s not a guaranteed support. It may just be a couple of letters of recommendation. So they get the funding they develop a program and the program is not tied to industry. There’s no industry buy-in. So people may they may not have the tools that the industry is looking for. Schools should be building in things where students do some testing, like Field Effect is doing with Algonquin College, where they’ve actually invested millions of dollars to create a cybersecurity lab in the school for students. Toronto Metropolitan University and the Rogers Cybersecure Catalyst have done some great work in working with industry. But a lot of other schools and colleges are lagging and therefore employers don’t see that experience in tackling cyber security problems. Even if it’s just six months or a year tied into the educational process [it will help]. But then a lot of the curriculum was developed with tools that aren’t relevant to industry, or that don’t have access to a work environment or a cloud environment where a lot of the companies are working.

Howard: Is this a matter of provincial/territorial boards of education not going to industry and saying, ‘We need your input. We need your collaboration on cyber security programs?’ Or is this a matter of industry not pushing the provinces?

Francois: It’s a little bit of both. I think the government requirements are superficial for universities and colleges as far as getting funding for some of these programs. And then industry, unfortunately, is always very busy. Their role is to make money. They tackle recruiting usually in six-month cycles and don’t look long term — just like universities and colleges that develop a program and may not change it for years and years … Meanwhile industry’s already adapting to AI and quantum and who knows what’s coming down the pipe. So I think that from that perspective there’s a responsibility on a lot of different players to step up.

Howard: What about those looking for cybersecurity-related jobs? Are they doing anything wrong? What should they be emphasizing when they send in resumes? When they go for job interviews?

Francois: A lot of them don’t have a LinkedIn profile or very little under their LinkedIn profile. Unfortunately most employers leverage LinkedIn for recruiting cybersecurity talent … This is why we built [the CCN] community. We want individuals to come in here, learn, talk to people find out what the best programs are to go into what are the certifications should they get, what skills they need, how to develop speaking skills … I probably get about 50 to 100 requests a day asking me to find them a job. That’s why we built the Canadian Cybersecurity Jos community …

I would say that the important thing is to talk about your journey and why you would be a good fit for an employer. I tell them, ‘Don’t just apply to job postings, reach out directly to the network. Start working with individuals and ask for help — a quick phone call, a quick review of your resume, a quick discussion around what is it like to work in pen testing or to work in a cloud environment — and start building from that. Reach out directly to employers. Bypass the recruiter and go directly to the hiring manager and share your value proposition. Tell your story, tell them why you would be a good fit.’

The post Cyber Security Today, Week in Review for Friday, Jan. 12, 2024 first appeared on IT World Canada.

Accenture presents its “Human by Design” 2024 tech vision, reassures on potential job losses

Artificial intelligence (AI) will become much more human-like and intuitive for people to use, Accenture highlighted in its 2024 Technology Vision report titled “Human by Design.”

The report also revealed that generative AI has the potential to impact 44 per cent of all working hours across industries in the U.S. and enable productivity enhancements across 900 different types of jobs.

“We were very careful about why we put it that way,” explained global lead, innovation at Accenture, Adam Burden. “We didn’t say roles, we didn’t say jobs, we said working hours, because it’s our belief that this amplification will impact those in every role and allow people to do things better and faster, with higher quality and maybe even at skill levels that they’re not currently able to do. So for us, the outcome here is goodness.”

Following a round of mass layoffs, the company invested US$3 billion in AI last summer, and announced it is doubling its AI workforce to 80,000 over the next three years. 

There will be some transition, but there will also be new roles that will create more profitability and productivity for companies, noted Burden.

He further explained that a lot of jobs like switchboard operators in the 1940s do not exist anymore because of new technologies like microprocessors. But new roles always end up surfacing to create new value.

Michael Blitz, managing director, Accenture Technology Vision, Accenture Technology Labs, also contended that Accenture looks at amplifying companies with AI, but it remains the responsibility of these companies to transition employees through this change.

He said, “I think it’s important for people to know from the outset that it’s just not about how you build that next product. It’s rather how you’re going to be able to transition people to being able to use it in the ways that they should.”

Companies requiring an AI-capable workforce also have to be responsible for building those skills and investing in people, notably because there is no current workforce to hire from, asserted Burden.

Blitz and Burden also acknowledged that the implementation of AI will require human oversight at all levels.

“Organizations that build the right controls to have humans in the loop are the ones that will definitely be more successful in the market, because they’re the ones that will gradually build more confidence in AI,” affirmed Burden.

Other insights from the report include:

Data will be reorganized in ways that facilitate human-like reasoning and even mimic creativity. For instance, users will receive curated, personalized responses in the form of advice, a summation of a vast set of results, an essay, an image, or even a piece of art, instead of having to comb through mountains of search engine results.
AI-empowered agents work on behalf of individuals and are part of an interconnected ecosystem. These automated agents assist, advise us and take decisive actions on our behalf in both the physical and digital worlds.
New immersive worlds for personal interaction will be created by extending physical, 2D worlds into new 3D environments using spatial computing, metaverse, digital twins and AR/VR technologies.
AI-powered wearables, brain-sensing neurotech, and eye and movement tracking will be used to unlock a better understanding of us, our lives, and our intentions, to enhance the way we work and live.

See the full report here.

The post Accenture presents its “Human by Design” 2024 tech vision, reassures on potential job losses first appeared on IT World Canada.

Cyber Security Today, Jan. 12, 2024 – A Chinese hacking group’s reach may be bigger than we thought

A Chinese hacking group’s reach may be bigger than we thought.

Welcome to Cyber Security Today. It’s Friday, January 12th, 2024. I’m Howard Solomon, contributing reporter on cybersecurity for ITWorldCanada.com and TechNewsday.com in the U.S.



 

The reach of a Chinese hacking group known for going after critical infrastructure in the United States may be more extensive than known so far. Researchers at SecurityScorecard say the IT network of the group researchers call Volt Typhoon is communicating with government websites in the U.K., Australia and India as well as the U.S. Among the tools it is apparently leveraging are particular models of unpatched routers from Cisco Systems. A patch for these devices was issued five years ago. And because these models are end-of-life there are no new updates for them. Network administrators have to watch for Cisco RV320 and RV350 devices. They should have been replaced a long time ago.

Threat actors are taking advantage of employees’ annual responsibilities such as company satisfaction surveys, enrolling in benefit programs, 401k updates and salary adjustments as lures to steal their credentials. That’s according to researchers at Cofense. The hackers know that companies often send staff email notifications about these things. So they are that by sending employees phishing emails with attachments or QR codes that appear to come from management or the HR department. The messages ask staff to login to see the material. Staff need to be reminded to use standard email security skepticism. For example, be wary of messages that start, “Dear employees.” Even if a message is personalized, check the email address of the sender to be sure it’s legit.

In November I told listeners that Fidelity National Finance, which provides title insurance and settlement services for the American mortgage and real estate sector, had suffered a data breach. This week it told a regulator it has now determined that data on approximately 1.3 million customers may have been copied by the attacker.

Someone at a Texas-based company that sells school security solutions allowed the creation of a non-password-protected database with sensitive student data to sit open on the internet. According to cybersecurity researcher Jeremiah Fowler, the database belonged to Raptor Technologies and was in three separate cloud storage buckets. It held information on students, teachers, parents and school safety plans. As soon as it was notified the company blocked public access to the database. It’s more evidence that corporate and IT managers aren’t closely training or supervising employees who create databases.

An American company called NASCO, which administers benefits for American health plans, has doubled the number of victims from the hack last year of its MOVEit file transfer application. The company now says data of almost 1.7 million people was stolen in the hack. According to researchers at Emsisoft, so far 2,730 companies or government departments around the world have admitted data on over 94 million people was stolen from their MOVEit servers.

An Alabama law firm called Burr & Forman which acts for a behavioral healthcare provider is notifying almost 20,000 people a hacker copied their personal data last fall. Data stolen included names, Social Security numbers, medical coding information with dates and descriptions, and insurance information.

The World Economic Forum released two cybersecurity forecasts based on surveys with experts. In one, misinformation and disinformation were listed as the top risk organizations will face over the next two years. That ranked ahead of extreme weather events. The other report suggests the number of organizations that maintain minimum viable cyber resilience dropped 30 per cent compared to last year’s survey. The biggest drop came from small and medium-sized companies, while large companies showed gains in cyber resilience.

Palo Alto Networks has released a background report on the Medusa ransomware gang. Security teams and researchers may find useful information in it. The paper includes indicators of compromise defenders should be watching for.

Fortinet has released a security update to address a vulnerability in its FortiOS and FortiProxy software. A cyber threat actor could exploit this vulnerability to take control of an affected system.

And Cisco Systems has patched a critical vulnerability in the web-based management interface of its Unity Connection unified messaging platform. If the security update isn’t installed an attacker could upload files to Unity Connection server and then do serious damage from there.

Follow Cyber Security Today on Apple Podcasts, Google Podcasts or add us to your Flash Briefing on your smart speaker.

The post Cyber Security Today, Jan. 12, 2024 – A Chinese hacking group’s reach may be bigger than we thought first appeared on IT World Canada.