Category: News

Hashtag Trending Jan.10- Only 700 IT jobs added in the U.S. in 2023; 23 vulnerabilities in network-connected wrench used globally in factories; Microsoft discovery that could reduce lithium use in batteries by 70 percent

Only 700 net new jobs were added in the U.S. in 2023, an “intelligent wrench” has vulnerabilities that would permit hackers to breach a network, AI solves an innovation dilemma, more from the X files and – they might call it the “smellphone” 



 

These and more top tech stories on Hashtag Trending

I’m your host Jim Love, CIO of IT World Canada and Tech News Day in the US.

In a startling revelation for the tech industry, a mere 700 IT jobs were added in the U.S. in 2023, a dramatic downturn from the 267,000 jobs in the previous year. This information, based on an analysis of U.S. Bureau of Labor Statistics data by Janco Associates, highlights a significant shift in the IT job market. The report indicates that while over 21,000 IT jobs were created in the last quarter of 2023, the overall growth remained stagnant due to mass layoffs. Interestingly, despite these layoffs, there remains a surplus of vacant IT roles, with about 88,000 positions unfilled. This paradox is attributed to a skills mismatch in the industry, with a high demand for professionals skilled in AI, security, development, and blockchain, while entry-level positions are increasingly automated. Salaries in AI-related roles are on the rise, suggesting a pivot towards more specialized skills in the IT sector. 

So where are all the new jobs coming from if not from tech?  It turns out the construction industry is booming in Canada and the U.S.  Apparently nobody’s laughing at “bricks and mortar” now. 

Sources include: The Register

Security researchers from Nozomi have discovered 23 vulnerabilities in the Bosch Rexroth Handheld Nutrunner NXA015S-36V-B, a network-connected wrench used globally in factories for assembling sensitive instruments and devices. These vulnerabilities could allow hackers to sabotage or disable these tools, posing significant risks to manufacturing processes. The Nutrunner, critical for ensuring precise torque levels for safety and reliability, can be compromised to either tighten fastenings too loosely or too tightly, while falsely indicating correct settings.

Bosch Rexroth has acknowledged the issue and is working on a patch, expected to be released by the end of January 2024. The vulnerabilities allow for remote execution of arbitrary code with root privileges, enabling various attack scenarios. In a lab environment, Nozomi researchers demonstrated two potential attacks: installing ransomware to make the device inoperable and demanding a ransom, and stealthily altering the tightening programs while displaying normal values to the operator. These findings highlight the growing cybersecurity challenges in the increasingly networked manufacturing sector.

Sources include: Ars Technica

If you remember your high school science history you may know that Edison didn’t invent the light bulb. What he did was have 1,000 unsuccessful attempts before he figured out what filament in what bulb construction would work to design a light bulb that could be commercially produced and used in homes and businesses.  

That method of discovery hasn’t changed much in the decades since Edison until recently. 

Microsoft and the Pacific Northwest National Laboratory have discovered a new material using AI and supercomputing that could reduce lithium use in batteries by up to 70 per cent. This breakthrough was achieved by using advanced AI and high-performance computing to narrow down 32 million potential materials to 18 candidates in less than a week, a process that would traditionally take decades. 

The new material, a solid-state electrolyte, has been used to power a lightbulb and shows promise as a sustainable energy storage solution.  

It’s one of many proposed solutions to a key dilemma. Lithium is not only rare, but also dangerous.    

But this invention is the one that has also leveraged AI to accelerate innovation and invention.  

Sources include: BBC News

I almost didn’t cover this story, but in the end I had to run it, because IF it’s true, and that’s an IF, it explains a lot.

Elon Musk, the CEO of Tesla and SpaceX, is facing allegations of possible illegal drug use, according to a report in the Wall Street Journal. These allegations have raised concerns among executives within his companies. 

The report details an incident at a recent SpaceX meeting where Musk’s behavior was described as “nonsensical,” “unhinged,” and “cringeworthy.” He reportedly arrived nearly an hour late and was rambling and slurring his words. Linda Johnson Rice, a former Tesla board member, reportedly decided against re-election due to concerns about Musk’s drug use and unpredictable behavior.

According to recent reports, Musk has previously admitted to using ketamine to treat depression and smoked marijuana during a “Joe Rogan Experience” podcast in 2018, which led to complications with NASA.

Musk has denied these claims, stating that no drugs or alcohol have been found in his body during random tests conducted over the past three years.

Musk’s lawyer, Alex Spiro, confirmed that Musk had never failed a drug test and criticized the report for citing “false facts” without specifying them.

Source: Euronews 

And I’m getting tired of the continued bad news in tech jobs, but here’s another story I thought I had to cover.  

Unity, the company behind the popular game engine, is facing a significant workforce reduction, with plans to lay off about 25 percent of its staff, amounting to around 1,800 employees. This decision, as stated in a filing with the Securities and Exchange Commission, is part of Unity’s restructuring and refocusing efforts on its core business to achieve long-term and profitable growth.

This latest round of layoffs follows several others within the past year, including a notable reduction of 265 workers last November. The specifics of whether the 1,800 job cuts are in addition to last year’s layoffs remain unclear. Unity’s recent layoffs occurred shortly after the company altered its pricing model, which initially frustrated developers. These changes were partially reversed, and former CEO John Riccitiello resigned in the aftermath.

Kelly Ekins, Unity’s director of PR, expressed that the decision to reduce the workforce was challenging and extended gratitude to those affected for their dedication and contributions. Unity’s game engine is used in popular games like Fall Guys and Pokémon Go. The gaming industry has seen a wave of layoffs over the past year, with major companies like Epic Games, EA, and Naughty Dog also announcing job cuts, affecting over 9,000 people in the industry in 2023.

Source: The Verge

And to get a whiff of something different to close off the show…

An Israeli firm Mobile Physics, backed by Oracle founder Larry Ellison, has developed this technology to transform any cellphone into a personal “envirometer” and weather station. It utilizes a phone’s existing sensors to measure air quality, smoke levels, temperature, and UV exposure. In real-time, the technology can alert users to hazardous conditions, advising actions like opening or closing a window, turning on an air purifier, or wearing a mask.

This innovation is particularly timely as air pollution and increasingly severe wildfires pose growing health risks. The technology has been embedded within Qualcomm’s new Snapdragon 8 Gen 3 mobile processor, using STMicroelectronics’s direct time-of-flight (dToF) sensors, capable of detecting small particulate matter. Phone manufacturers like Samsung, Google, and Xiaomi have shown interest in this technology.

The data collected by these “envirometer” phones could be invaluable not only to individual users but also to governments, health authorities, and insurance companies, offering a detailed portrait of local environmental conditions. Mobile Physics also plans to introduce a subscription version with additional information, which could be especially beneficial for people with respiratory diseases.

Source: Axios

Hashtag Trending goes to air 5 days a week with a special weekend interview show we call “the Weekend Edition.”

You can get us anywhere you get audio podcasts and there is a copy of the show notes at itworldcanada.com/podcasts 

I’m your host, Jim Love. Have a Wonderful Wednesday!

The post Hashtag Trending Jan.10- Only 700 IT jobs added in the U.S. in 2023; 23 vulnerabilities in network-connected wrench used globally in factories; Microsoft discovery that could reduce lithium use in batteries by 70 percent first appeared on IT World Canada.

Female cyber pros group targeted in phishing scam

A threat actor is trying to con female cybersecurity pros into downloading malware.

The warning comes from the Canadian-based Women CyberSecurity Society (WCS2), which says someone is targeting members of the leadership team, members, and volunteers, trying to trick them into clicking on malicious links in text-based phishing messages, which is also called smishing.

“A volunteer recently reported receiving a text message claiming to be from founder Lisa Kearney citing an urgent need for help,” the warning says.

“We believe others will be targeted in such a manner and we urge you to exercise caution when interacting with emails, messages and online links from someone who you don’t know.”

The text message asked the volunteer to buy some Google certificate back codes.

One key this is a scam: The sender said they were in a meeting, could only text and asked the volunteer “to run a task urgently.”

Experts say a message asking a person to do something quickly — such as spend money, send money, or send a copy of sensitive information — should be seen as suspicious.

WCS2 believes the threat actor used LinkedIn and open-source intelligence to gather information about the organization, members, and volunteers to target them.

The group asks members to

– Verify caller identity: If you receive a call claiming to be from the Women CyberSecurity Society, ask for the caller’s name and contact information. Hang up, independently verify the information through official channels, and call back using a published contact number;

– Do not click on suspicious links: Avoid clicking on any links received through phone calls, voicemails, or text messages, especially if the communication seems unexpected or unusual;

– Report suspicious activity: If you receive any communication that seems suspicious or if you believe you have been targeted, please report it immediately to WCS2’s security team;

– Use security software: Install and regularly update security software on your mobile device, desktop, laptops and tablets to help detect and prevent smishing attacks.

– Educate yourself: Stay informed about common phishing tactics and be cautious when receiving unexpected messages, even if they appear to be from familiar sources.

WCS2’s next event is Jan. 30, when it will host a two-hour webinar on how to start a new career in cybersecurity.

The post Female cyber pros group targeted in phishing scam first appeared on IT World Canada.

Info-Tech analyst, VMware partner denounce Broadcom’s new channel strategy

Broadcom gave the market, and specifically the channel, an unwelcome New Year’s surprise when it announced plans to end the VMware partner program effective Feb. 5, precisely the sort of action that was predicted by analysts and feared by customers and (now) former resellers, says John Annand, executive councilor practice lead at Info-Tech Research Group.

Annand,  who in a former career once sold, installed, and configured VMware, said the VMWare partner program has been around since the company’s inception in 1998 and has long been a darling of the reseller, VAR, and channel communities.

“Almost a rite of passage certification for so many IT professionals, especially early in their career, it was so popular that a scant 12 years later, the unofficial meetups, chatrooms and email lists of practitioners banded together to form VMware User Group (VMUG),” he said.

“An organization independent of VMware that quickly turned into a global organization with a mission to help members connect, collaborate and network with fellow VMware users, VMUG has chapters in most major cities, put on its own conferences, and developed its own training materials, webcasts, and even awards.”

Among those partners severely impacted by Broadcom’s move is Whipcord Edge Data Centers, an infrastructure service provider with data centre facilities in Toronto and Lethbridge that has offered private cloud services for more than 10 years and leverages VMWare’s Cloud Service Provider program.

In addition to receiving the VMware Partner Programs Termination Notice on Dec. 22, said Dan Hamilton, Whipcord Edge’s chief operating officer (COO), the company also received a CSP-specific termination notice.

“The second paragraph starts with ‘effective April 30, 2024, the ability to transact as a VMware Cloud Services Provider, under the VMware Partner Connect Program, will come to an end.’

“This sentence in particular came as a tremendous shock to us. There was no forewarning; no indication at all that this was coming. We knew about the changes to the bundles and pricing on the reseller side, but nothing at all about changes to the CSP program. They mention the Broadcom Expert Advantage Partner Program, but to date we have not received any invitation.”

Hamilton added that the “other piece to this that is shocking is the silence from the aggregators. Under the CSP program, we rely on the aggregators to provide our link with VMware in terms of information and concerns regarding the program. Our aggregator (Ingram Micro) has been completely silent. No communication whatsoever. We have reached out multiple times and received no reply. When reaching out to VMware directly, they point back to the aggregator.”

This is, he said, a “a major component” of Whipcord’s business that is now in limbo:  “We have no idea if we will be invited to the Broadcom program, or how that program will be structured. Given the other changes we have seen, I am very concerned that the structure could change from the current consumption-based vRAM model to a core-based model. Or the program could end entirely; we do not know since VMware and Broadcom have not provided any details at all. Either way, this could kill VMware-based private cloud solutions like ours.”

Annand said that VMware was a company that embraced partners both on the sales enablement (resellers, MSPs and consultants) as well as on the technology side (Veeam, Microsoft, etc). It was a company that had collaboration as part of its DNA.

“The result was a product that was comparatively easy for the enterprise to buy and was a sufficiently complete as a solution. And where perhaps there were deficiencies, other OEMs and independent software vendors were encouraged and incentivized to help fill in those gaps. The result was stability and innovation which let whole generations of Infrastructure professional rest easy at night.”

Broadcom, at its heart, he said, “appears to me to be more like a private equity company. Concerned about operational efficiencies over technological upheaval and revolution. They have announced an end to perpetual licensing (which, to be fair, VMware was moving towards already) and promised a simplification of the license model.

“This means bundling fewer subscription-only SKUs at average higher price points. No longer will you just be able to buy the bare necessities of what you need. Fewer partners will mean less competition on price and greater onus for the enterprise to solution design for themselves.”

The acquisition, said Annand, has been a “great move for Broadcom and its shareholders. Broadcom’s ongoing public communications continue to prove that there is little to no – to perhaps negative – upside for former VMware customers.”

Channel Daily News did reach out to VMware Canada for comment, but at press time, had yet to receive a reply.

When contacted about Hamilton’s concerns, a spokesperson for Ingram Micro Canada said, “I have forwarded this to the team, to work with the customer. And at this time, we are unable to provide any comments.”

The post Info-Tech analyst, VMware partner denounce Broadcom’s new channel strategy first appeared on IT World Canada.

American regulator slams data broker for selling mobile location data without consent

In a warning that American data brokers need to be careful about selling precise geolocation information of mobile phone users, the U.S. Federal Trade Commission has proposed banning a major company from taking advantage of all the data it can collect.

Assuming the settlement is confirmed, the FTC will forbid Outlogic LLC from sharing or selling any sensitive location data. This would settle allegations that the company sold precise location data of mobile users, without their consent, that could be used to track people’s visits to sensitive locations such as medical and reproductive health clinics, places of religious worship, and domestic abuse shelters.

FTC also charged that Virginia-based Outlogic (the firm that acquired the operations of X-Mode Social in 2021, which is where the FTC investigation began) failed to put in place reasonable and appropriate safeguards on the use of such information by third parties.

“Geolocation data can reveal not just where a person lives and whom they spend time with but also, for example, which medical treatments they seek and where they worship. The FTC’s action against X-Mode makes clear that businesses do not have free license to market and sell Americans’ sensitive location data,” said FTC Chair Lina Khan. “By securing a first-ever ban on the use and sale of sensitive location data, the FTC is continuing its critical work to protect Americans from intrusive data brokers and unchecked corporate surveillance.”

X-Mode collected precise consumer geolocation data from a wide variety of sources, the FTC explained. That included third-party apps with X-Mode’s software development kit (SDK) built in, its own mobile apps, and information it bought from other data brokers and aggregators. The company then compiled consumers’ location data and sold it to hundreds of clients for advertising, brand analytics, and other marketing purposes. According to the  FTC complaint, the company also sold the raw data to private government contractors.

The FTC says this was done without consumers’ informed consent and without disclosing all of the purposes for which consumers’ data would be used, practices of unfair or deceptive conduct in violation of the FTC Act.

To settle the case, the company has agreed to make major changes to how it does business going forward, the FTC said. That includes putting substantial limits on sharing certain sensitive location data. The settlement requires the company to develop a comprehensive sensitive location data program to prevent the use and sale of consumers’ sensitive location data. Outlogic also must take steps to prevent clients from associating consumers with locations that provide services to LGBTQ+ individuals or with locations of public gatherings like marches or protests.

In addition, the company must take effective steps to see to it that clients don’t use their location data to determine the identity or location of a specific individual’s home. And even for location data that may not reveal visits to sensitive locations, Outlogic must ensure consumers provide informed consent before it uses that data. Finally, X-Mode/Outlogic must delete or render non-sensitive the historical data it collected from its own apps or SDK and must tell its customers about the FTC’s requirement that such data should be deleted or rendered non-sensitive.

Outlogic must also give consumers an easy way to withdraw their consent for the collection and use of their location data, to require the deletion of any location data that was previously collected, and to request the identity of any individual and business to whom their personal data has been sold or shared.

Once the proposed settlement is published in the Federal Register, the FTC will accept public comments for 30 days, after which the commission will decide whether to make the proposed consent order final.

In response to the settlement, Outlogic told TechCrunch that it disagrees with the implications of an FTC press release. “After a lengthy investigation, the FTC found no instance of misuse of any data and made no such allegation. Since its inception, X-Mode has imposed strict contractual terms on all data customers prohibiting them from associating its data with sensitive locations such as healthcare facilities. Adherence to the FTC’s newly introduced policy will be ensured by implementing additional technical processes and will not require any significant changes to business or products.”

Meanwhile, the FTC continues with its investigation against data broker Kochava Inc. for allegedly acquiring and selling consumers’ sensitive, identifying, and mobile geolocation information without their consent.

The collection and sale of information by data brokers has worried consumers and regulators for years. In Canada, the federal Office of the Privacy Commissioner began an investigation into the practices of six data brokers in 2018.

Last November, the Irish Council for Civil Liberties warned extraordinarily sensitive information about key European and U.S. figures and military personnel is being sold to foreign states and non-state actors through online advertising’s Real-Time Bidding (RTB) system.

Also in November, Duke University reported that sensitive personal information about active-duty American armed forces members, their families, and veterans is being sold by data brokers for 12 cents a person.

The post American regulator slams data broker for selling mobile location data without consent first appeared on IT World Canada.

Canadian companies struggling to put ESG mandates into action as reporting pressures ramp up

Over 1000 Canadian companies are facing environmental, social and governance (ESG) reporting requirements under the new Corporate Sustainability Reporting Directive (CSRD), research published in the Wall Street Journal revealed.

CSRD mandates companies both inside and outside the European Union (EU) to report on ESG. Canadian companies will need to publish their first report in 2025 and obtain an independent review of what they report. So time is of the essence.

However, a new report by Enterprise Ireland that surveyed 332 senior Canadian decision makers in Medium to Enterprise businesses found that 74 per cent are still struggling to put ESG mandates into action. In fact, only 39 per cent report having taken “substantial steps” toward implementing ESG initiatives.

Over half of the surveyed organizations had a moderate-to-low understanding of ESG commitments and implications, while 42 per cent saw pitfalls in resource constraints – which includes the adoption of technology to capture data, and report on progress. Additionally, only one-third have a dedicated ESG role or department, and another 18 per cent do not know how it is managed.

With these challenges, companies are employing a mix of internal initiatives like employee surveys and external initiatives such as sustainability reports and third-party audits to capture data. 

Over 70 per cent say they are likely to adopt new technologies in order to deliver on ESG initiatives in the future. Meanwhile, 38 per cent have developed such technology in the past 12 months, the report noted.

Forrester, in fact, predicts that the sustainability management software market will double next year due to compliance needs.

Nonetheless, only 26 per cent feel that they are capturing “very accurate” ESG data, while 34 per cent say it is not accurate, or they simply do not know.

Businesses that can’t answer questions from customers and investors about how they manage their material ESG risks and opportunities in a satisfactory manner—and are unable to produce trusted data to support their narrative—may lose market share and access to financing, PwC asserted in a recent report.

Canadian companies, accordingly, recognize the importance of ESG initiatives to corporate policy, with 67 per cent predicting that ESG would escalate as a company priority. 

“We know that today’s consumers are more purpose-oriented than ever before, and that
individuals are more likely to support a brand that aligns with their values, whether that’s
in support of climate change, human rights efforts, or ethical business practices,” said David McCaffrey, country manager and senior vice president at Enterprise Ireland Canada. “Based on this, organizations understand that ESG initiatives are more than a government
requirement, but a business imperative to effectively compete in today’s landscape.”

Between 42 and 66 per cent of the surveyed companies are targeting environmental initiatives, including waste management (66 per cent) and carbon footprint reduction (63 per cent). And 55 per cent plan to reduce scope 1, scope 2, or scope 3 emissions.

However, companies are targeting social initiatives more, with employee well-being and labour practices (both 89 per cent) marked as top priorities.

A possible reason for this is that “social initiatives have often more immediate and visible impacts on local communities and employees, making the targets and results more tangible for companies,” explained McCaffrey. “We have also seen that addressing social
issues may more closely align with a company’s values and mission, making it a priority.”

Finally, between 57 per cent and 76 per cent are targeting ESG governance and reporting, including ethical business practices, and anti-corruption measures as well as stakeholder engagement.

“The bottom line: these problems are not independent of one another, and that opens the
door for Canadian companies that might be feeling the pressure under this year’s
mandates to target ESG initiatives that can solve for more than one issue,” said McCaffrey.

The post Canadian companies struggling to put ESG mandates into action as reporting pressures ramp up first appeared on IT World Canada.

CES 2024: Intel drops full 14th Gen mobile and desktop processor lineup

Last night at CES 2024, Intel unveiled its full Intel Core 14th Gen mobile and desktop processor lineup as well as its new Intel Core mobile processor Series 1 family for mainstream thin and light mobile systems.

Core 14th Gen mobile processors

Led by the flagship Intel Core i9-14900HX, the latest generation mobile processor family includes 5 new processors, and is built mainly for creators and gamers who use laptops yet requiring higher compute performance.

It features up to 5.8 GHz turbo frequency and includes 24 cores (eight performance / 16 efficiency) plus 32 threads in its i9-14900HX processors. These chips also support up to 192 gigabytes (GB) of total DDR5-5600 megatransfers/second (MT/S) memory, integrated Intel Wi-Fi 6E and 7, the latest in Bluetooth connectivity, ThunderBolt 5 and more.

Intel did not offer any comparison to last year’s 13th Gen chips, but there have been minor upgrades in turbo frequency, and memory, as well as Wi-Fi 7 connectivity.

See also:

CES 2023: Intel unveils new mobile processors

Intel did however, compare its flagship with AMD’s Ryzen 9 7945HX and Ryzen 9 7945HX3D, touting higher gaming performance in several popular games at 1080p.

Source: Intel

More than 60 partner systems, including HP, Alienware, Acer, Lenovo, and more will use Intel’s mobile chips and launch new products in 2024, Intel said.

Core 14th gen desktop processors

Intel dropped 18 new desktop processors in addition to the six launched last October.

Overall, the desktop processors will include up to 5.8 GHz turbo frequency, support for up to 192 GB of total DDR5-5600/DDR4-3200 MT/S memory, support for in-box thermal solutions, Intel Wi-Fi 6E and 7 connectivity, ThunderBolt 4, integrated USB 3.2 connectivity support and more.

The flagship – Core i9-14900 processor with 24 cores (eight P-cores / 16 E-cores) and 32 threads – will cost US$549.

Intel again touted higher mainstream performance in everyday productivity and content creation, compared to AMD’s RyzenTM 9 7900.

New Intel Core mobile processor Series 1

The newly introduced Series 1 family will have three processors designed to provide balanced and efficient performance in thin and light devices, the company said.

The chips include up to 5.4 GHz turbo frequency along with up to 10 cores (two P-cores, eight E-cores) and 12 threads in its flagship Intel Core 7 processor 150U.

Additionally, the processors support up to 96 GB of total DDR5-5200/DDR4-3200 MT/S memory, include the latest Bluetooth and Thunderbolt 4 universal connectivity, support for both Intel Killer Wi-Fi 7 and 6E, and more.

Mobile systems powered by the Intel Core U Processor Series 1 will come to market in the first quarter of 2024, the company said.

The post CES 2024: Intel drops full 14th Gen mobile and desktop processor lineup first appeared on IT World Canada.

Many IT departments still don’t know how many APIs they have: Report

IT departments still don’t have an accurate count of the number of application programming interfaces (APIs) their app developers are putting into production, says a new report.

That’s one of several conclusions researchers at Cloudflare came to in a report on API security and management released today.

APIs, which allow applications to communicate with each other, outpace other internet traffic, the report found. They comprised more than half (57 per cent) of the dynamic internet traffic processed by Cloudflare last year.

However, many organizations don’t know how many APIs they are supposed to oversee. Cloudflare found some organizations have 30 per cent more API endpoints than they think they have.

“You can’t protect what you don’t know exists,” John Cosgrove, product manager for Cloudflare’s API gateway, commented in an interview about the report.

Not only that, the report says, IT may unintentionally block legitimate traffic because they don’t know how many APIs to protect.

So called ‘zombie’ or ‘shadow’ APIs may have been undocumented by developers who created them, but who have left the organization, Cosgrove said, or they may be hanging around from abandoned projects.

If exploited, these APIs can lead to data exposure, unpatched vulnerabilities, data compliance violations, lateral movement and other problems.

The 2019 data breach of a medical diagnostics company exposed the data of nearly 12 million patients when an unauthorized user gained access to an API that was sending information to billing vendors, the report notes.

“API threats are out there,” Cosgrove said. “They can be as old as SQL injection or as new as a broken authentication attack. You need to have a tool that compiles an API inventory and then you need protection from all these attacks.”

Some CISOs may be worried about advanced attacks, he said, but “if your web application firewall isn’t even protecting your APIs, the ‘old’ threats will still come and get you.” One problem, he said, is that a lot of APIs weren’t written to withstand large volumetric distributed denial of service attacks.

The report is based on traffic data collected by Cloudflare’s global network between Oct. 1, 2022 and Aug. 31, 2023.

Another possible problem the report discovered is the misinterpretation of API errors. For example, the most frequent HTTP status code error IT departments see is 429, which means the API server has automatically throttled traffic because of a certain action, such as an IP address exceeding a set number of requests per minute per endpoint. However, the report says, a wrongly-set request rate limit may be triggering that error.

As consumers and end users continue to expect faster, more dynamic web and mobile experiences, the report warns, development and API teams will come under more pressure to deploy and maintain many more APIs.

“These well-meaning app developers will continue to deploy APIs fast — sometimes without consulting other IT and security stakeholders,” the report says. This lack of a cohesive approach will force enterprises into difficult corners as they face several challenges, including an increase in business logic-based fraud attacks.

CISOs at the very least have to pay attention to API discovery, Cosgrove said. Those with more mature security programs should look at their rate-limiting strategies. Those who have no API security posture should at least have the bare basics, he added, including DDoS protection.

The report can be downloaded here. Registration is required.

The post Many IT departments still don’t know how many APIs they have: Report first appeared on IT World Canada.

Hashtag Trending Jan.9- Apple quietly integrating AI; Microsoft to train 100,000 Indian developers in AI; New ransomware attack strategies sink to new lows

A tale of two strategies – Apple’s stealth approach to AI and Microsoft’s move to upskill India’s developers to use AI. If you thought ransomware attacks on hospitals and ambulance dispatch was as low as it can get – the latest strategies sink even lower.



 

These and more top tech stories on Hashtag Trending

I’m your host Jim Love, CIO of IT World Canada and Tech News Day in the US.

While other tech giants are making noise with their AI advancements, Apple is taking a different approach. Apple has been quietly integrating AI into its products and services without much fanfare. 

From its neural engine in iPhones to advanced algorithms in the Apple Watch, the company is using AI but not doing much in the way of publicizing it. 

Apple’s strategy seems to focus on seamless integration, ensuring that AI enhancements are not disruptive but rather an organic part of the user experience. 

This differs from competitors who often highlight AI as a major selling point. But is this a lack of progress or just “stealth marketing” from Apple. The company is notorious for its secrecy in product development.

Tim Cook, Apple’s CEO has said that AI work is “going on” but not much more than that. 

Which leaves us all reading the tea leaves and looking for hints. 

We know, for instance, that Apple has been courting publishers at the same time OpenAI is out there, only Apple seems to be looking for media partners ahead of any big release.

In October, Apple and Columbia University released an open-source multi-modal language model called Ferret which raised some interest due to the potential for local models to power small devices. 

Apple also released two research papers on new techniques for 3-D avatars and more efficient language model inference which could be seen as driving more immersive experiences – again from a focus in the papers on using these on regular devices without using too much memory.

And the big open question is, when – or will we – see these in Apple products?  

Will “slow but steady” win the race? 

And the one question that everyone wants answered, when is Apple going to replace the old structure of Siri with a new, generative AI model?

Sources include: Analytics India

Microsoft has launched a program called “AI Odyssey” to train 100,000 Indian developers in artificial intelligence by 2024. 

AI Odyssey includes a series of workshops, webinars, and hackathons, focusing on areas like machine learning, data science, and AI ethics. 

The program aims to train developers with the skills needed to drive innovation in AI. 

Microsoft’s program reflects the increasing demand for AI skills in India, which was and remains a powerhouse in outsourced development. 

But that huge workforce, many of whom support legacy systems from the west could be threatened by AI’s coding ability.  

With what everyone sees now as a brilliant investment in AI with OpenAI, is this the next strategic move for Microsoft? Yes, it has a positive impact on the Indian tech sector as they help develop new skills. But it also strengthens Microsoft’s position in a key global market. 

Sources include:  Analytics India

A troubling new trend in cybercrime is gaining traction, as extortionists are increasingly using “swatting” as a tactic. 

Swatting involves making a hoax call to emergency services, typically reporting a serious but fabricated incident, to draw a large police response to a victim’s address. 

This dangerous and disruptive practice has now evolved into a tool for cybercriminals seeking ransom from individuals and businesses, threatening them with swatting if their demands are not met. 

When my sister found out she had a potentially life-threatening cancer and was forced to wait in Sarnia and London’s hospitals for hours because of recent ransomware attacks, I thought I’d seen the lowest it can get. Who slows down surgery for those who need it quickly to have a chance at living?

Recently cybercrooks have been doing this to patients from stolen hospital data. Apparently, following them home and scaring the life out of these people – victimizing them twice – is the next trend.  

I make no further predictions on how low these predators can go. 

—–

Volkswagen is set to change the in-car experience by integrating ChatGPT into its voice assistant system. This was announced at CES, and Volkswagen hopes to make the car’s voice assistant more conversational, intuitive, and helpful. 

The company is betting that ChatGPT will allow for more fluid and human-like interactions. 

This marks a significant step in the automotive industry And where others are still testing it, or offering an alternative to existing voice driven systems, Volkswagen has gone all in, a bold move for the company that has had some serious setbacks in terms of image and sales. 

Whatever they do has to be better than the frustration of dealing with systems that cause more distraction than they prevent.  

Sources include: The Verge

There was a story that made the news this morning about a plane which had a door seal blow out in mid-air. No one was injured, thankfully, although I may never take a seat on the exit door again. 

But when someone found the door seal, they also found an iPhone that got sucked out of the plane. And the phone still worked. 

That tied in with the story I did yesterday on nostalgia for for pre-internet and pre-digital devices. There was a famous commercial for an analogue watch called Times, with the slogan “takes a licking, and keeps on ticking.” 

Well falling from 30,000 feet or whatever and still being able to take a call? I think the digital age has us beat on that one.

Hashtag Trending goes to air 5 days a week with a special weekend interview show we call “the Weekend Edition.”

You can get us anywhere you get audio podcasts and there is a copy of the show notes at itworldcanada.com/podcasts 

I’m your host, Jim Love. Have a Terrific Tuesday. 

The post Hashtag Trending Jan.9- Apple quietly integrating AI; Microsoft to train 100,000 Indian developers in AI; New ransomware attack strategies sink to new lows first appeared on IT World Canada.

Toronto Zoo hit by ransomware

The municipally-owned Toronto Zoo has been hit by a ransomware attack.

The cyber attack was first detected early Friday, Jan. 5, the zoo said in a statement Monday,

“We are investigating the impact, if any, to our guests, members and donor records,” the statement says. “We can confirm we do not currently store any credit card information. Once we have more information we will share it broadly.

In addition to member and donor records, the IT system might have information on the 273 permanent full-time and 330 part-time or seasonal employees.

“We are working with the City of Toronto’s Chief Information Security Office and third-party cyber security experts to resolve the situation and have reported it to Toronto Police Services” the statement said.

The internationally respected zoo is located in a river valley at the eastern edge of the city, spread over 287 hectares (710 acres). It attracts about 1.3 million visitors a year. Its collection includes 5,816 animals, not including invertebrates, representing 495 different
species.

Asked for comment, Katie Gray, the zoo’s strategic communications manager, said, “We can’t share anything further than what’s in the release.”

The incident comes after a ransomware attack in October on the Toronto Public Library system. Among the questions is whether there is a link between that attack and the zoo compromise. The City of Toronto was itself one of the over 2,000 victim organizations of the vulnerability in the MOVEit file transfer application, which was leveraged by the Cl0p ransomware gang last May.

The post Toronto Zoo hit by ransomware first appeared on IT World Canada.

How AI and machine learning solutions drive value for financial institutions

In an era where technology is reshaping industries, BMO is making waves in the financial sector through its robust artificial intelligence (AI) initiatives and machine learning technologies.

A recent interview with Eric Morrow, Managing Director, Enterprise Data Science & AI, Data & Analytics, and Alex Tait, U.S. Chief Data and Analytics Officer, Data & Analytics, shed light on the transformative power of AI, where increased model performance directly correlates with amplified revenue, reduced costs, and most importantly, enhanced customer experiences.

At BMO, the benefits of broadly applying AI, data science and machine learning are clear. “There’s almost endless opportunity for taking data and applying models to it within a financial services organization,” said Tait. “Potential applications span everything from marketing to defending against cybersecurity threats.”

Driving AI integration at BMO

BMO considers AI an integral part of the bank’s strategy, tightly interwoven with revenue streams and cost-effectiveness. Morrow describes AI integration as a “powerful concept” that can be applied cross-functionally with active engagement across BMO’s lines of business and various Data and Analytics leaders.

“On our mobile app, for instance, you provide personalized insights to the individual, and that’s a powerful thing that really creates that connection with the customer,” he said.

In addition to AI’s application in retail banking, BMO has created new and innovative ways to apply advanced analytics to commercial customers’ needs. Earlier in 2023, Datos Insights, a global advisory firm focused on technology, regulation, strategy, and operations in the financial services industry, presented BMO with a 2023 Impact Innovation Awards in Cash Management and Payments for AI and advanced analytics for its “Digital Workbench” technology.

BMO Digital Workbench provides real-time analytics and reporting in various areas through a cloud-based self-service portal accessible to multiple businesses within the bank. It integrates scattered data sets across different bank systems with an easy-to-use, cloud-based web interface that drives cohesive and accessible analytics, facilitates insightful customer conversations, and transforms pricing and product mix strategies. A suite of data-driven tools with dynamic customer analytics and forecasting capabilities powers the technology.

Yet implementing customer solutions using AI and analytics is only part of the story. BMO supports cutting-edge research to ensure AI solutions provide functionality, accuracy, efficiency, and automation.

Supporting AI’s broader application in financial services

An example is BMO’s sponsorship of Next AI, a Montreal-based founder development network for entrepreneurs looking to solve global challenges with AI-based ventures and technology commercialization. Next AI helps identify and support early-stage ventures, which receive access to resources, mentorship education and the network they need to succeed.

Another notable endeavour illustrating BMO’s commitment to AI excellence is its partnership with the Vector Institute, a collaboration that epitomizes BMO’s dedication to staying at the forefront of AI innovation.

The Vector Institute offers a platform for BMO to explore leading AI research, turning academic insights into practical applications. A past, prominent project involves Natural Language Processing (NLP), a domain critical for a bank dealing with vast amounts of textual data.

According to Morrow, BMO can leverage NLP to help better understand why customers call into contact centres. “Being able to ensure that we’re providing the right level of service and care back to them when there are engagements between the agents is the goal,” says Morrow.

And BMO is making progress towards it. In 2023, Digital Banker recognized BMO with an Outstanding Machine Learning Initiative Award, which focused on leveraging NLP association with a contact centre.

The future of AI at BMO

BMO’s journey into AI and machine learning isn’t just about the present; it’s about building a future where technology seamlessly integrates with customer needs. The bank’s strategic direction emphasizes a digital-first approach and cloud-centricity. This focus on technological integration ensures operational efficiency and positions BMO as a pioneer in the banking industry’s digital transformation, and it starts from within the bank. This past year, more than 3,500 BMO employees participated in deep technical learning and licensing in subjects like AI, Machine Learning and Cloud.

Additionally, BMO is experimenting with new technologies enterprise-wide to develop digital capabilities to advance the bank’s Climate Ambition. Through BMO’s developing Climate Analytics Platform, the bank is using its digital capabilities, and developing the ability to use AI, to help understand the impacts and risks from weather-related events, such as floods, droughts, extreme heat and more. For any company seeking to manage this evolving risk, it is important to identify how these physical climate impacts are expected to change over time and by location, and how those changes intersect with economic systems. For banks like BMO who have a large financing footprint, it is important to identify where climate hazards are projected to manifest, and to manage the risk and capture opportunities associated with this changing future. While these programs are still under development, our technology teams can support innovation within the bank by piloting new and innovative technology driven approaches to climate related analysis.

BMO’s integration of AI is a testament to the bank’s commitment to delivering value through exceptional banking experiences across all its lines of business. Outside the bank, BMO is raising the bar in applying AI and machine learning in the financial services sector by extending that commitment to research and collaboration with esteemed organizations like the Vector Institute. As AI continues to influence the future, BMO stands as a beacon, showcasing how innovative technology can redefine banking, enrich customer interactions, and drive business growth.

The post How AI and machine learning solutions drive value for financial institutions first appeared on IT World Canada.