Category: News

Predictions 2024 from cybersecurity vendors, Part 1

2024 will be a year dominated by artificial intelligence-created deepfakes and advanced phishing attacks, but also new AI-based detection applications to help defenders.

These are among the predictions from companies that provide cybersecurity solutions. We’ve collected comments from over 30 vendors to give infosec pros an idea of what they will face in the next 12 months:

Our reliance on AI for cybersecurity is undeniable,” said Sergey Shykevich, threat intelligence group manager at Check Point Software Technologies, “but as AI evolves so will the strategies of our adversaries. In the coming year, we must innovate faster than the threats we face to stay one step ahead. Let’s harness the full potential of AI for cybersecurity, with a keen eye on responsible and ethical use, ”

Next year will see more threat actors adopt AI to accelerate and expand every aspect of their toolkit, the company says. Whether that is for more cost-efficient rapid development of new malware and ransomware variants or using deepfake technologies to take phishing and impersonation attacks to the next level.

Brendan Peter, vice president of global government affairs, SecurityScorecard:

The forthcoming rewrite of Presidential Policy Directive 21 (PPD-21) will create a paradigm shift in critical infrastructure security. Expected in the first half of 2024, this comprehensive update will empower critical infrastructure sectors to embrace data-driven risk management and enhance their resilience against evolving threats.

By tightening requirements and definitions, PPD-21 will foster a culture of data-driven risk assessment and communication across all critical infrastructure sectors in the year ahead. This transformative overhaul will spark critical conversations around the unique needs of each sector, paving the way for a more collaborative and transparent approach to safeguarding the nation’s digital backbone.

The revamped PPD-21 marks a pivotal moment in critical infrastructure security, empowering sectors to stay ahead of the curve and protect the nation’s vital assets.

Jody Westby CEO, Global Cyber Risk LLC:

Cybersecurity will continue to be a top risk for organizations in 2024. The use of generative AI and deepfakes in targeted phishing attacks, AI-generated malware, and automated attacks will present significant challenges to organizations. Looking ahead, cloud and SaaS providers will continue to be favored targets as criminals understand a successful attack on one of these vendors can result in a jackpot of data from many companies. Organizations that have not established a vendor risk management program and integrated vendors into their incident response plans will struggle to manage these attacks.

Rick Howard, CSO N2K Networks:

The SEC fraud charges against SolarWinds and their CISO, Tim Brown, will have a chilling effect on hiring CISOs in the future. At the very least, most CISOs will insist on compensation packages that include directors’ and officers’ liability insurance and golden parachute firing clauses. At the most, companies will start to include CISOs as part of their executive officer team alongside the CEO, the CFO, and the CTO. You won’t see these things immediately, but the climate has changed. This is what CISOs are talking about now.

Zach Capers, manager of research lab and senior security analyst, GetApp:

In 2023, we finally saw some positive signs in the world of security as evidenced by our fifth annual data security report. Businesses appear to have rebounded from an influx of pandemic-fueled vulnerabilities and have begun locking down systems like never before. This means that cybercriminals will increase reliance on social engineering schemes that exploit employees rather than machines.

Moving into 2024, our research finds the number one concern of IT security managers is advanced phishing attacks. And we’re not only talking about email phishing. SEO poisoning attacks are a rising phishing threat designed to lure victims to malicious lookalike websites by exploiting search engine algorithms. This means that employees searching for an online cloud service might find a bogus site and hand their credentials directly to a cybercriminal, have their machine infected by malware, or both. In 2024, it will be more important than ever to educate employees on the sophisticated and increasingly dynamic methods used to trick them into handing over sensitive information that can result in damaging cyberattacks.

Andrew Newman, CTO and co-founder, ReasonLabs:

The MOVEit hacks, which affected more than 620 organizations and over 60 million individuals alone, should be warning enough for cybersecurity leaders everywhere. While building cybersecurity defenses across vast supply chain networks can be challenging, organizations must challenge themselves to further enhance their security, assess the security posture of their partners and vendors, and consistently monitor for abnormal activities within the supply chain to build additional lines of defence.

Michael Mestrovich, CISO, Rubrik:

Gaining access to any enterprise via valid credentials remains the preferred method of access for cyber actors. As generative AI matures over the next year and beyond, social engineering attacks fueled by generative AI will become easier to perpetrate, will increase in scale, and will be increasingly realistic. No amount of training will be able to prevent some of these tactics, so we will surely see an increase in cyberattacks. Therefore, over the next year we’ll see how many organizations have built their defense strategy around a cyber resilience mindset, e.g. micro-segmentation, passwordless authentication, phish-resistant MFA, moving from privilege escalation to separate privileged user accounts, and when it all fails, having immutable data backups.

Alexander Garcia-Tobar, CEO and co-founder, Valimail:

In 2024, there will be an acceleration in disinformation, exacerbated by ongoing global conflicts and the growing availability of AI tools that will create and/or spread false narratives more rapidly and convincingly. This trend will be viewed against a backdrop of declining public trust in institutions, a phenomenon intensified by the U.S. election year. With email being the primary communication tool used, validating sender authentication will become increasingly more important.

Don Boxley, CEO and co-founder, DH2i:

The cybersecurity landscape is rapidly evolving, with more sophisticated and frequent attacks. In response, the adoption of advanced network technologies like software-defined perimeter (SDP) and zero trust network access (ZTNA) will become critical in 2024. These technologies offer a more dynamic and adaptive approach to network security compared to traditional VPNs. SDP provides a way to create secure, context-aware connections between users and network resources, effectively reducing the attack surface. ZTNA, on the other hand, operates on the principle of “never trust, always verify,” ensuring that access to network resources is strictly controlled and monitored. These technologies will be especially important for protecting multi-cloud environments and remote work infrastructures.

John Baird, Co-Founder and CEO of Vouched:

In 2024, the trajectory of Identity Verification (IDV) and cybersecurity is set to leverage advanced technological capabilities – innovations akin to sophisticated identity authentication methods and AI-powered anomaly detection will reshape the landscape, minimizing fraud risks significantly. These advancements will integrate cutting-edge authentication, ensuring robust verification processes that proactively identify and prevent fraudulent activities. The seamless incorporation of these technological advancements into IDV strategies will fortify digital identities against emerging threats, setting new standards for security and trust across industries.

Etay Maor, senior director of security strategy, Cato Networks:

No, the end user is not stupid and it won’t be their fault – there is a tendency to blame the user and couple it with “humans are the weakest link,” but humans are not going anywhere so let’s focus on more productive approaches. Cyber security responsibility is moving upwards, to the CISO, CIO, and board, not downward towards the employees and practitioners. But it is on us (managers, security operation teams, and yes – vendors) to create security tools and processes that will be easier to manage. We are going to see organizations move to products and services that, while being more robust and advanced, offer simpler management with much less overhead of false positives, integration projects, and constant updates.

Shay Levi, CTO and co-founder, Noname Security:

In 2023, AI began transforming cybersecurity, playing pivotal roles both on the offensive and defensive security fronts. Traditionally, identifying and exploiting complex, one-off API vulnerabilities required human intervention. AI is now changing this landscape, automating the process, enabling cost-effective, large-scale attacks. In 2024, I predict a notable increase in the sophistication and scalability of attacks. We will witness a pivotal shift as AI becomes a powerful tool for both malicious actors and defenders, redefining the dynamics of digital security.

Richard Vibert, CEO Metomic:

In the world of SaaS, there are billions of sensitive data points in rest and in motion at any one time. Data security posture management tools can’t protect that data on a datapoint-by-datapoint level – there will be far too much noise. These tools will evolve from addressing individual data points to identifying higher-level risk patterns, e.g. there’s a script running in Slack that keeps posting email addresses of people subscribing to a newsletter. This shift will empower security teams to make more impactful changes by prioritizing risks with substantial financial implications.

JP Perez-Etchegoyen, CTO, Onapsis:

The surging investments in AI will trigger a momentous shift in AI security, reshaping the landscape of technological safeguarding. In 2024, as the investment in AI continues to surge, a pivotal shift will unfold in the realm of AI security. With AI models, particularly large language models and generative AI, being integrated into every facet of the software chain across diverse industries, the demand for safeguarding these technologies against evolving threats like prompt injection and other malicious attacks will reach unprecedented levels. Despite the relative novelty of these advancements, the imperative for stringent security measures will gain traction, marking a watershed moment in the journey of AI technology. As we continue to grapple with the uncharted territory of immense data and new challenges, we will witness a concerted effort to fortify the boundaries and ensure the responsible growth of this transformative technology.

Daniel Trauner, senior director, security at Axonius:

In 2024 it will continue to be imperative for professionals to understand the security implications of applying technology to new areas or expanding its existing use. Organizations that neglect to understand their total attack surface and gaps in defenses will have the highest risk of attack in the new year. Keeping a system’s attack surface small is one of the best ways to reduce the potential for new vulnerabilities. While companies that can’t quickly deploy updated patches may be at a disadvantage, security leaders must be prepared to start contextualizing vulnerability issues within their organizations rather than spinning their wheels to patch every single vulnerability that crosses their security landscape. As CVEs continue to be recognized at a rapid pace, organizations must regularly assess their business goals to determine what security issues must be prioritized and how. This method will result in greater risk reduction overall in 2024.

Ilia Kolochenko, chief architect at ImmuniWeb:

While numerous reports predict a surge of the malicious use of generative AI by cybercriminals in 2024, it will probably be less significant than most of the alarmistic predictions. First, sophisticated cybercrime actors don’t really need GenAI to write malware or phishing emails, they already have advanced skills and experience that will easily outperform any AI-powered chatbots. Some simple tasks may be automated by GenAI, however, it will unlikely cause a tectonic shift in their well-established cybercrime business. Second, inexperienced cybercriminals and newbies may ask a chatbot to create a simple exploit, payload or even primitive malware, however, they will still need an abuse-proof infrastructure to host and operate it, money-laundering mechanisms, and many other instruments that no GenAI can build for them. Most likely they will end up detected, arrested, and imprisoned. More harm will come from imprudent cybersecurity professionals who will try to automate code and config writing with GenAI, eventually producing suboptimal code quality. With Infrastructure-as-a-Code (IaC) in a multi-cloud environment, a single error in code may cost millions.

John Holmes chief legal officer and Brice Cagle, data protection officer, Forcepoint:

As AI becomes more embedded in our industries, the safe and measured adoption of it will become a critical factor in its long-term success and for companies to potentially benefit. And because we can’t put this genie back in the bottle at this point, the goal of incorporating AI should be focused on preventing the improper introduction of sensitive information to the great unknown of public generative AI. Organizations using AI should know exactly which applications employees use and what data they are interacting with to prevent AI from undermining the proprietary rights of a company’s content. And, by extension, to preserve sensitive information like PII.

Joey Stanford, VP of data privacy & compliance at Platform.sh:

We’ll see AI becoming increasingly popular in cybersecurity attacks next year because AI never sleeps – you just turn it on, it runs and learns. This is one reason why AI will find vulnerabilities and new exploits very quickly. In addition, the use of AI to create phishing emails, virtually indistinguishable from a real sender, will leave companies struggling to prevent breaches by spear phishing attacks in 2024. Realistic, fake voicemails and videos will just add to the chaos. While governments are taking steps to regulate AI, no regulation will ever be able to contain it entirely, because laws always embody cultural norms. What’s permissible in China may not be in the EU or the U.S..

The post Predictions 2024 from cybersecurity vendors, Part 1 first appeared on IT World Canada.

Predictions on 2024 developments in OpenAI: Best of YouTube

I watch far too much YouTube for my own good. You have to sift through numerous ill-informed and overly sensationalistic titles and articles to find a few individuals who conduct actual research and provide somewhat informative content. As I discover these and when they have something interesting to say, I thought I’d present them to our audience. If it’s successful and interesting, I’ll continue to do it. But in the light of New Year’s predictions, this YouTuber has predictions backed by evidence and they are also consistent with what I have been finding.

OpenAI ChatGPT: What’s coming in 2024

According to this video, in 2024, OpenAI’s ChatGPT is poised to take a significant leap forward. Recently, Sam Altman, OpenAI’s CEO, sparked excitement with a Twitter thread detailing the roadmap for ChatGPT. Key areas of focus include enhanced reasoning, the much-anticipated GPT-5, improved voice modes, and a revolutionary feature termed “ChatGPT with Memory.”

Enhanced Reasoning: A Top Priority

Improved reasoning is a top priority for OpenAI. ChatGPT is excellent at writing text and has made vast improvements on its math abilities. But that disguises the fact that it struggles with true reasoning. What the world mistakenly labels as ‘hallucinations’ are actually due to ChatGPT not knowing what it doesn’t know or when it’s wrong. It lacks the basic reasoning skills that humans have.

There are innovations in prompting like “Chain of Thought” which compensate for the lack of  more sophisticated reasoning capabilities. However, there have been developments in other open-source models that demonstrate much more nuanced and accurate responses.

GPT-5: It’s in training now

GPT-5 is officially in training, fueling speculation about its potential superiority over GPT-4. With competitors like Google’s Gemini making waves, OpenAI is going to be highly motivated to maintain its edge. The trademark for GPT-5 suggests groundbreaking advancements, particularly in image capabilities and possibly video.

ChatGPT with Memory: A Game-Changer

Perhaps the most exciting development is “ChatGPT with Memory,” known internally as Project Sunshine. This feature enables ChatGPT to learn from previous interactions, making it more personalized and efficient.

Imagine if ChatGPT could actually remember all of your conversations and learn about you. This continuous learning approach could revolutionize how users interact with AI, offering a more tailored and context-aware experience.

The downside? ChatGPT is going to have to get more secure. Another video I’ll show you this week will illustrate how easy it is to bust through ChatGPT’s guard rails and obtain information that you should not be able to get this easily. Until that is solved, implementing a memory of all your interactions is a security nightmare.

Voice Modes: Enhancing User Interaction

If your only experience with voice interaciton is Alexa, Google or Siri, you may want to try what exists today in ChatGPT. Conversations with AI are eerily human-like. The only giveaway in many cases is the time delay while it calculates its responses, something that Google cleverly omitted in its demonstration when revealing its new Gemini AI offering.

Voice interaction is set to become more seamless and intuitive. The integration of Whisper’s API for speech recognition points to a future where users can engage with ChatGPT in their native language, hands-free, and with high accuracy.

Sign-in with OpenAI

One barrier to developing applications using ChatGPT’s API is how do you control and pass on the costs? While many calls to the API cost only pennies, it’s not difficult to imagine scenarios where the API costs could skyrocket.

But what if you could have a login that maintained the costs on the user’s account and API key? That would allow the creation and easy distribution of applications leveraging OpenAI’s API. This could be a game-changer in the development of sophisticated applications using ChatGPT – particularly when enhanced reasoning and other features from GPT5 are available.

These are some of the key predictions covered in this video by the YouTuber who refers to his program as AIGRID.” As I noted earlier, his work tends to be fairly well researched. I’d put my money on these predictions for 2024. 

 If you enjoyed this or have suggestions for this series please let me know in the comments below.

The post Predictions on 2024 developments in OpenAI: Best of YouTube first appeared on IT World Canada.

Why isn’t Sam Altman investing in Artificial Intelligence? Hashtag Trending Holdiay Byte – December 23, 2023

TRANSCRIPT AND SHOW NOTES:

On December 21st, Sam Altman published a blog with the title, “What I wish someone had told me.”

I’ll actually post show notes with this this Christmas Bytes edition so you can get the link to the full list if you want.

It’s interesting, but one in particular is really interesting.

Concentrate your resources on a small number of high-conviction bets; this is easy to say but evidently hard to do. You can delete more stuff than you think.

So what are Sam Altman’s “high conviction bets.” I would have guessed – Artificial Intelligence, Generative AI and the search for Artificial General Intelligence.

And you’d be right if you thought the same thing. After all he’s invested the past decade into Open AI.

Well, he’s invested his time. But what he hasn’t done isn’t where he’s placing his big bets

I’m sure he has some investments that are related to AI in some way. He’s invested as an angel investor in more than 100 startups and has holdings in other companies. But when we talk about “concentrating on a small number of high-conviction bets” where he’s placed his biggest bet is NOT in artificial intelligence.

It’s not easy to get definitive info on Altman but best estimate of his net worth is about 700 million dollars. He got in early on a number of investments including Stripe and Air BnB. So he’s not on the Forbes billionaire list, but he’s – let’s say – doing okay.

So out of that, what are his itwo large, or shall we say, “high conviction bets”:

The first is a firm called Helion Enterprises. Helion is a Washington based company aiming to tame nuclear fusion to create a limitless source of clean energy.

His second investment? A “healthy lifespan extension company” called Retro Biosciences. The goal of the company is to “add 10 good years to your life.”

This is certainly a high conviction bet. Back in March, MIT Technology reported that Altman had “emptied his bank account” to be the sole investor in Retro Biosciences writing cheques in a single year amounting to 180 million dollars.

Retro’s aim is to prolong human life by discovering how to rejuvenate our bodies, according to its CEO and cofounder, the entrepreneur Joe Betts-LaCroix.

Is any of this possible? Well so far, we probably generated enough net power from fusion to power a toaster. I’m not diminishing this, but it’s by no means a sure thing as a commercial venture, although there’s lots of talk about reactors being commercially available in the next decade. But so far, there’s nothing that proves this can really happen.

And the Retro BioSciences? They are looking at “reprogramming mature cells by some kind of genetic intervention” which will issue instructions to turn mature cells into youthful cells. It’s reverses aging.

If it works.

It’s not a new idea. Larry Page put money into a similar effort 10 years ago. Jeff Bezos has pumped billions in to Altos Labs aiming to prevent diseases and aging.

Some scientists call it impossible. Others say that they know what has to be done, it’s just an engineering challenge to actually make it work.

So Altman is betting big time on two possibly impossible investments. Both of these have been the holy grail for centuries from the time explore Ponce de Leon went off in search of the fountain of youth. And Nicola Tesla’s brilliant career was destroyed by his goal to provide free wireless power to the world.

So Altman is placing his two big bets on these. Both of which, by the way, will not succeed on his own money. They will have to raise billions more to meet the engineering challenges and to then commercialize these offerings.

So what’s the deal with AI? If these are his big bets? Why not pour your time into them. And that’s where the story gets interesting.

If you had something that you thought was theoretically possible, but would be an incredible engineering challenge – and you needed to solve that challenge, one that might be so complex that humans will struggle for decades or more trying to get it to work?

If that was the case wouldn’t it be great if you had a greater computing capability that could navigate the complexity of the mathematics of fusion – or map the human genome to understand how to reverse aging?

Like an artificial general intelligence?

Hmmm. Author F Scott Fitzgerald once said that “The truest sign of intelligence is the ability to entertain two contradictory ideas simultaneously.”

I have no doubt that this is true. But there’s another type of intelligence that can link seemingly different things together into a cohesive vision.

Has Altman found that? Is his end game leveraging Artificial General Intelligence to achieve limitless power and give us, if not immortality, at least longer, healthier life spans?

Maybe.

And even though there are lots of skeptics, me included, who aren’t sure that these are possible, at least in this century – I think the recent curfuffle at OpenAI has taught everyone one thing.

Don’t bet against Sam Altman.

Hashtag Trending returns with the weekend edition on Saturday January 5th and our daily news cast returns on Monday January 8th bright and early.

Merry Christmas and Happy New Year!

Jim

The post Why isn’t Sam Altman investing in Artificial Intelligence? Hashtag Trending Holdiay Byte – December 23, 2023 first appeared on IT World Canada.

AlphV/BlackCat allegedly calls for ransomware gang ‘cartel’ to stand up to police

Seemingly stunned by this week’s action by law enforcement agencies in several countries,  members of two ransomware groups allegedly talked about forming a partnership.

Security researchers on Twitter/X posted an online conversation that appears to be between a member of the AlphV/BlackCat ransomware group, whose sites were taken down, and a member of the LockBit ransomware gang.

“LockBit is right, we should all join a cartel or they will hunt us all down one by one,” an alleged AlphV/BlackCat gang member said.

In a commentary, Keegan Keplinger, senior security researcher with eSentire’s Threat Response Unit, noted that “as of December 21, AlphV still has a blog site up and running, and they posted a new victim as recently as December 20, alongside several other recent victims, who had appeared previously on their main data leak site.

“Whether or not the AlphV ransomware group rebrands to a new ransomware or not, it’s likely they’ll maintain most of their affiliate relationships to some degree. Because they face disruption efforts, some affiliates may be cautious not to invest time and energy into operations that may be disrupted or sanctioned from ransomware payments.  However, if AlphV rebrands, they get to reset their heat meter with law enforcement while maintaining much of the relationships and reputation they’ve developed in the cybercrime market.”

One of the AlphV/BlackCat gang’s most loyal and longtime affiliates is the Gootloader cybercrime group, Keplinger noted. The Gootloader operators, like the leaders of the AlphV/BlackCat, are Russian-speaking, and they have been running sophisticated, meticulously-planned attack campaigns, non-stop, for the past three and a half years.

Gootloader is a browser-based threat delivered through search engine optimization (SEO) poisoning. The gang has hijacked thousands of vulnerable WordPress blogs and injected them with malicious content, linked to no fewer than 3.5 million search terms, many of which are legal terms. As a result, a lawyer or paralegal who searches the Web for specific content, such as a type of legal agreement, may find the top search result leads to a Gootloader-infected file. The Gootloader operation infects about 30 computers a day on average, eSentire said.

The assault on AlphV/BlackCat raises the question of how the operators of Gootloader will respond, Keplinger said. It might drop AlphV/BlackCat in favour of another ransomware strain, such as LockBit or Clop (Cl0p), he said.

This year, the FBI took down the Hive ransomware gang and arrested the alleged head of BreachForums. The alleged operators behind DoppelPaymer ransomware gang were arrested. And the suspected developer of the Ragnar Locker ransomware gang was nabbed in Paris.

The post AlphV/BlackCat allegedly calls for ransomware gang ‘cartel’ to stand up to police first appeared on IT World Canada.

Cyber Security Today, Year in Review for 2023

Welcome to Cyber Security Today. This is a special Year in Review edition for 2023. I’m Howard Solomon, contributing reporter on cybersecurity for ITWorldCanada.com and TechNewsday.com in the U.S.



 

With me here  regular commentators Terry Cutler, head of Cyology Labs in Montreal, and David Shipley, head of Beauceron Security in Fredericton, New Brunswick.

(The following transcript has been edited for clarity, and only covers the first part of the conversation. To hear the full discussion play the podcast)

First, as you look back what kind of a year has 2023 been?

David Shipley: There’s a meme that comes to mind: A guy goes out to get pizza for his party and comes back and everyone’s running around in complete pandemonium and someone’s on fire and he has this look on his face — and that’s me this year. It’s just the absolute pandemonium of 2023 between some of the O-days that dropped, some of the nation-state hacking, the fact that the Russian hacking game against Ukraine as the year wraps up gets spicy … It has been a year and I don’t think 2024 is going to be much different.

Terry Cutler: Same here. It was very, very weird at the beginning of the year. It was very quiet. Even had competitors calling me up to see how we can all work together. But we’re seeing a lot of breaches that are occurring because companies still don’t have the basics in place. And what they’re doing going to their managed service provider saying, ‘Hey, how do we fix this?’ But they [the providers] aren’t cybersecurity experts. So they’re recommending the wrong stuff. We’re not advising them properly, and they’re getting breached. Hopefully 2024 is going to have better outcomes.

David: I think there’s been a lot of snake oil in the cybersecurity market, particularly since the pandemic. And now it’s snake oil with generative AI. It is [failure to do] the basic stuff, but the basic stuff isn’t sexy. It’s the diet and exercise of health applied to cybersecurity. And everyone still is running around looking for their $500 dollars a month. That’s not going to get what you think it is, and you’re going to put the weight on after you stop taking it. I don’t see executives yet moving away from the silver bullet snake oil: ‘I bought the latest ADR, MDR, AI, DLP solution. Why am I not safe?’

Howard: Let’s get to the top news story of the year as selected by me — because I’m the host and I have privileges. The number one story of the year: The exploitation of a zero-day vulnerability in Progress Software’s MOVEit file transfer application. Why is this the top story? According to statistics compiled by Emsisoft, as of December 15th, 2,686 organizations around the world had been hacked from this one vulnerability. Data on over 90 million people has been stolen.

IT departments use MOVEit to compress, encrypt and shift files to third parties for processing. They’re processing things like payrolls and benefits. The cybersecurity community started getting worried about this when Progress Software said at the end of May that there was a vulnerability in the on-premise and cloud versions of MOVEit that had to be patched. And since then, an avalanche of companies and governments around the world have admitted their on-prem or cloud stores of MOVEit had been hacked. Or if it wasn’t their directly their then it the data held by the companies doing their data processing was hacked.

The Clop ransomware gang has taken credit and for the most part didn’t deploy ransomware in these exploitations. It was pure data theft. Gentlemen, what do we say about this incident?

Terry: We’re seeing more discoveries of zero-day vulnerabilities. We’re seeing less and less companies implementing the right technology with detection and response built into it. So they’re not seeing a full holistic view of what’s happening in their environment. Zero days are extremely hard to detect because not even the vendor is aware of this vulnerability. And we’re seeing a shift now, where a ransomware gang is in the network for a long period of time. The average time that a cybercriminal is in your environment is over 280 days before being detected. So we’re seeing a shift now where they [attackers] are seeing more value in exfiltrating all the data versus just sending them a ransom.

David: I really think O-Days need to have like a league or a qualifier. Like, ‘This was not an NHL-level O-Day.’ This [MOVEit] is a SQL injection. This is a Pee-wee hockey O-Day and should never have happened in the first place.’ This is the equivalent of driving your car with your eyes closed right into a telephone pole. And so back to Terry’s point about the basics.

This [type of vulnerabilty] is in the OWASP [Open Web Application Security Project] Top 10 for how many years? How many decades at this point? So it should never have happened. But that’s on the vendor. But on the [customer] organizations, we have a fundamental fail down in the understanding of what the technology’s intent and purpose was. It was supposed to be secure file transfer. And in that, it was relatively successful. What it was never supposed to be was a data warehouse [for files about to be transferred or transferred files].

Whether it was driver’s licenses that go back years, birth certificates that go back years, employment information that go back years the fact is that this wasn’t used as a subway transit stop [by IT departments — you get on and then you leave]. This was the end warehouse [for data] and became the primary system of backup because of poor [data management] processes. That is on the organizations. That’s on them because good data hygiene would have reduced the scope of the impact. Not the presence of the vulnerability, but certainly we wouldn’t be 90 million people deep [in stolen data] if we had good, tight data governance. And that’s a shout-out to all of my friends in the privacy and data governance and security worlds. It’s not one of these items, it’s all three working together as a process.

Howard: Your point is that, for example, every month a company might have been sending a thick file to a data processor but what the [sending or recieving] company wasn’t doing was deleting that file [from the MOVEit server] every month after it had been used.

David: Exactly …

Terry: I think if companies start getting back to basics — regular patch management, security updates, putting in more holistic monitoring environments, technology that’ll look at what’s going on at both the network endpoint and cloud levels — the moment something like this occurs it should be able to trigger that this is not normal behavior. It should set off an alarm, quarantine the machines.

David: This is also part of what I call the sin of the city planning or the highway planning or the data planning of organizations. And I’m going to use Fredericton as a great example because it’s one of the few capital cities in Canada where you’re driving along the main provincial highway and the next thing you know you are at a three-way intersection. The highway just stops at an intersection. That’s poor design.

When we think about this [IT networks], it’s thinking about the architectural building blocks and the city planning of your digital world in your corporation. That’s where change management [is important].

Howard: So both of you are making the point that even though this is a zero-day, these hacks or the severity of the hacks could have been prevented by basic cybersecurity.

David: Yeah. It goes back to you cannot control an O-Day, but you can control all the things you do to mitigate the possibilities of an O-Day. So, control what you can and hold the vendors accountable because this O-Day should never have happened. This should not have happened this way. And I think the SEC [U.S. Securities and Exchange Commission] investigation into Progress Software is going to be very interesting in 2024.

Terry: I think it can be easy to have better systems in place. Obviously, make sure you have your proper patch management in place. Because if I remember correctly, folks that had EDR in place and they [hackers] tried to do an update it flagged it as malicious. So those had EDR in place already saw this alert. So it prevented the breach from happening on their systems. But, you know, they could have also been avoided by doing proper network segmentation. And of course awareness training is going to help as well too — identifying weird behavior can help lock it down.

Howard: David, you talked about the SEC investigation. My suspicion is that the SEC is going to investigate [Progress Software’s] communications. They’re not going to be doing a cybersecurity forensic investigation of progress software. One thing though, the Nova Scotia Information and Privacy Commissioner in has launched an investigation into the hack of the provincial department of health’s MOVEit server. So perhaps cybersecurity lessons will come out of that inquiry.

David: I want to give a shout-out to the Government of Nova Scotia … because they were communicating [to the public] very quickly about this incident, whereas some U.S. states didn’t communicate till months later. … I do think the SEC could potentially dig into all of the statements that companies make about their material cyber risks and how they’re managing those risks. It could look for evidence of how did this company’s code get so poorly written? Why didn’t it get caught on pen tests?

Terry: There’s going to be a nice fancy report with a set of recommendations to help prevent similar breaches in the future. But it’s going to be the same stuff again: Make sure you improve your security protocols, employee training, and make sure you update your incident response plans. How is this going to be different than what we’ve been talking about for the last 10 years?

Howard: One angle that I hope will be investigated is that according to researchers at Kroll not only was the Clop gang in the MOVEit systems of victim organizations for months before the data was stolen, the gang had figured out a vulnerability to exploit a similar file transfer application called Go Anywhere MFT. The gang decided for whatever reason to siphon data from victims from GoAnywhere first, and then they did the MOVEit exploit.

David: A couple of things: Clop is a type of blood-sucking bed bug. Two, this is one of the few groups that actually earns the advanced persistent threat methodology … because they ran a really advanced business operation. They sequenced how they were gonna go to market. They prioritize, they worked at scale, they figured out what was going to work … So A-Plus to cyber criminal innovation by Clop, which also is an important lesson to us defenders: They are working smarter, not harder. We have to work smarter, not harder.

The other top news stories of 2023 we discussed that you can hear on the podcast are:

–A record year for ransomware;
–U.S. Air National Guardsman charged with publishing classified documents. Investigation report released;
North Korean group hacks 3CX VoIP app;
Cyber attacks increasing on critical infrastructure;
Chinese-based hacker forges Microsoft Outlook access tokens;
Theft of 24 years of personal data of Canadian federal, military and RCMP employees from two moving companies;
U.S. Cyber Safety Review Board issues report on why the Lapsus$ gang was so successful.

The post Cyber Security Today, Year in Review for 2023 first appeared on IT World Canada.

Two Lapsus$ gang members sentenced in U.K.

One of two British teens in the Lapsus$ hacking gang has been sent to a secure hospital indefinitely by a judge, while another was given a youth rehabilitation order.

According to Bloomberg News, Judge Patricia Lees ruled an 18-year old accused of computer crimes should be placed in a secure hospital until a mental health tribunal decides he can leave in the future. The teen was still fixated with hacking and likely to offend again, the judge ruled. He was previously found unfit to stand a traditional trial because of his complex autistic-spectrum disorder.

According to the BBC, the court was told the 18-year old had been violent while in custody, with dozens of reports of injury or property damage.

The court was told that while on bail for hacking Nvidia and communications provider BT/EE  — and in police protection at a Travelodge hotel — the 18-year-old continued hacking and carried out his most infamous hack.

Despite having his laptop confiscated, he managed to breach Rockstar Games, the company behind GTA, using an Amazon Firestick, his hotel TV and a mobile phone.

He stole 90 clips of the unreleased and hugely anticipated game Grand Theft Auto 6.

A 17-year-old was sentenced to a youth rehabilitation order with an 18-month supervision requirement, Bloomberg News said. His sentence took into account crimes he pleaded guilty to at a separate youth court, including stalking and harassment.

The two were found guilty of serious computer misuse, blackmail and fraud against BT Group Plc.’s EE network and Nvidia in August, after a seven-week criminal trial. The 18-year old was also found to have hacked into Uber Technologies Inc., fintech firm Revolut Ltd., and Rockstar Games.

Lapsus$ was described by the U.S. Cyber Safety Review Board in a report earlier this year as a loosely organized group that conducted extortion-focused attacks against a wide range of targets. Members were based mainly in the United Kingdom and Brazil. As of April, 2022, experts thought there were no more than 10 known members. It claimed to have hacked Microsoft, Samsung, Okta, T-Mobile and others, stealing data including source code.

In a detailed analysis of the gang’s success, the safety review board noted the gang seemingly had no problem convincing telecommunications or identity management providers to give them control over the access accounts of their targets.

“If richly resourced cybersecurity programs [of corporations] were so easily breached
by a loosely organized threat actor group, which included several juveniles, how can organizations expect their programs to perform against well-resourced cybercrime syndicates and nation-state actors”, the report asked.

The post Two Lapsus$ gang members sentenced in U.K. first appeared on IT World Canada.

CRTC to bring high-speed internet to remote communities including Nunavut for the first time

The Canadian Radio-television Telecommunications Commission (CRTC) has disbursed $39.7 million from the Broadband Fund to bring high-speed internet to 28 remote communities in Northern Ontario, Northern British Columbia, and, for the first time, in Nunavut.

The CRTC said that municipalities, residents, businesses, and non-governmental organizations in Nunavut submitted letters to the commission emphasizing how high-speed internet will improve access to education and healthcare, while helping to preserve Inuit culture and language.

“We know how important high-quality internet and cellphone services are to every aspect of peoples’ daily lives,” said CRTC chairperson Vicky Eatrides. “Today marks a significant milestone, with the CRTC helping connect all communities in Nunavut to high-speed internet service for the first time.”

SSI Micro Ltd will be tasked to deliver satellite internet service to 11,405 households in 25 communities in Nunavut. 

Keewaytinook Okimakanak is the other recipient of that funding, designated to maintain satellite internet connectivity in 182 households in two First Nation communities in Northern Ontario.

Additionally, the CRTC is also providing more funding to Northwestel’s Yukon Fibre project, which was selected as part of the Broadband Fund in August 2020 and included 24 communities in Yukon. The project will now be expanded to bring fibre-based internet services to Atlin, a small community in northern British Columbia.

The CRTC says it continues to assess applications and will make more funding announcements in 2024.

To date, the Broadband Fund, launched in 2019 to connect the underserved rural, remote and Indigenous communities across Canada, has committed over C$300 million to improve high-speed internet and cellphone services in more than 230 communities.

The post CRTC to bring high-speed internet to remote communities including Nunavut for the first time first appeared on IT World Canada.

Scraped images of sexually abused children found in AI training database

Thousands of images of sexually abused children scraped from the internet are part of a commonly-used database used to train artificial intelligence image generators, according to a report, which warns that AI applications can use offensive photos to create realistic-looking fake child exploitation images that can be sold.

The report, released today by the Stanford University Internet Observatory (SIO), says removal of the source images is going on now because researchers reported the image URLs to the National Center for Missing and Exploited Children (NCMEC) in the U.S. and the Canadian Centre for Child Protection (C3P).

The investigation found the worrisome images in the biggest repository of images used by AI developers for training, known as LAION-5B, containing billions of images scraped from a wide array of sources, including mainstream social media websites and popular adult video sites.

According to the Associated Press, LAION, which stands for the nonprofit Large-scale Artificial Intelligence Open Network, said in a statement that it “has a zero tolerance policy for illegal content and in an abundance of caution” has taken down the datasets until the offending images can be deleted.

The SIO study of LAION-5B was primarily conducted using hashing tools such as Microsoft’s PhotoDNA, which match a fingerprint of an image to databases maintained by nonprofits that receive and process reports of online child sexual exploitation and abuse. Researchers did not view abuse content, and matches were reported to NCMEC and confirmed by C3P where possible.

There are methods to minimize child sexual abuse material (CSAM) in datasets used to train AI models, the SIO said in a statement, but it is challenging to clean or stop the distribution of open datasets with no central authority that hosts the actual data.

The report outlines safety recommendations for collecting datasets, training models, and hosting models trained on scraped datasets. Images collected in future datasets should be checked against known lists of CSAM by using detection tools such as Microsoft’s PhotoDNA or partnering with child safety organizations such as NCMEC and C3P.

The LAION‐5B dataset is derived from a broad cross‐section of the web, and has
been used to train various visual generative machine learning models. This dataset
was built by taking a snapshot of the Common Crawl5 repository, downloading
images referenced in the HTML, reading the “alt” attributes of the images, and using CLIP6
interrogation to discard images that did not sufficiently match the captions. The developers of LAION‐5B did attempt to classify whether content was sexually explicit as well as to detect some degree of underage explicit content.

However, the report notes, version 1.5 of one of the most popular AI image-generating models, Stable Diffusion, was also trained on a wide array of content, both explicit and otherwise. LAION datasets have also been used to train other models, says the report, such as Google’s Imagen, which was trained on a combination of internal datasets and the previous generation LAION‐400M.17.

“Notably,” the report says, “during an audit of the LAION‐400M, Imagen’s developers found
‘a wide range of inappropriate content including pornographic imagery, racist slurs, and harmful social stereotypes’, and deemed it unfit for public use.”

Despite its best efforts to find all CSAM in LAION-5B, the SIO says its work was a “significant undercount” due to the incompleteness of industry hash sets, attrition of live hosted content, lack of access to the original LAION reference image sets, and the limited accuracy of “unsafe” content classifiers.

Web-scale datasets are highly problematic for a number of reasons, even with
attempts at safety filtering, says the report. Ideally, such datasets should be restricted to research settings only, with more curated and well‐sourced datasets used for publicly distributed AI models.

The post Scraped images of sexually abused children found in AI training database first appeared on IT World Canada.

Threat actors still exploiting old unpatched vulnerabilities, says Cisco

The exploitation of a vulnerability in Progress Software’s MOVEit file transfer application was one of the biggest cybersecurity news headlines of the year.

However, according to Cisco Systems, the most targeted vulnerabilities this year — as in previous years — were older security flaws in common applications.

That again underscores the preference of threat actors to target unpatched systems that can cause major disruptions, Cisco’s Talos threat intelligence division said in its annual Year in Review report.

In many cases, the vulnerabilities were more than 10 years old, giving users lots of time for them to have been patched. In fact, four of the top five most targeted vulnerabilities were also cited by the U.S. Cybersecurity and Infrastructure Security Agency (CISA) as being frequently exploited in prior years.

The top 10 targeted vulnerabilities were

–CVE-2017-01999, found in Microsoft Office and WordPad;
–CVE-2017-11882, found in Microsoft Exchange server;
–CVE-2020-1472, found in Microsoft Windows’ Netlogon utility;
–CVE-2012-1461, found in the Gzip file parser utility;
–CVE-2012-0158, found in Microsoft Office;
–CVE-2010-1907, found in Apple’s Safari browser;
–CVE-2021-1675, found in Windows’ print spooler;
–CVE-2015-0507, found in Oracle’s Java SE;
–CVE-2015-2426, found in Windows’ font driver.

Most of the vulnerabilities would cause substantial impact if exploited, the report notes, with seven receiving the highest “critical” score from the Common Vulnerability Scoring System (CVSS).

Ransomware continued to threaten enterprises globally in 2023, the report notes, with LockBit remaining the top threat in this space for the second year in a row. Healthcare was the top targeted industry this year, as adversaries maintained their focus on entities that have cybersecurity funding constraints and low downtime tolerance.

However, some ransomware groups such as Clop/Cl0p — behind the MOVEit exploits — deployed a collection of zero-day exploits, behavior usually associated with advanced persistent threat (APT) activity, the report says. A new trend of ransomware actors turning to pure extortion, skipping encryption altogether while threatening to leak sensitive data, also emerged.

At the same time, the report adds, leaked ransomware source code allowed low-skilled actors to enter the market.

One other point the report notes: The use of valid accounts was consistently a top weakness in Talos incident response engagements.

The post Threat actors still exploiting old unpatched vulnerabilities, says Cisco first appeared on IT World Canada.

AWS Canada West (Calgary) Region goes live

Amazon Web Services (AWS) today announced the opening of its second infrastructure region in Canada, AWS Canada West (Calgary) Region. It offers three Availability Zones (AZs): large data centres which are, AWS said, “located far enough from each other to support customers’ business continuity, but near enough to provide low latency for high availability applications that use multiple AZs.”

Each has independent power, cooling, and physical security, and is connected through redundant, ultra-low-latency networks. AWS said that customers focused on high availability can design their applications to run in multiple AZs to achieve even greater fault tolerance.

Réjean Bourgault, country leader and managing director of public sector at AWS Canada, said that, in addition, customers using the AWS Canada (Central) Region in Montreal, which opened in 2016, will now be able to use the Calgary facilities for disaster recovery while maintaining Canadian data residency.

“And also,” he noted, “the other advantage of this is that western customers that require very low latency for their different workloads will be able to use the Canada West region.”

Bourgault said that the company’s four renewable energy projects in Alberta, including wind farms and solar farms, will, once in operation, generate enough energy to power the equivalent of 1.7 million Canadian homes, and contribute to Amazon’s goal of powering its overall infrastructure with renewable energy by 2025.

AWS plans to invest US$17.9 billion (about C$24.8 billion) in Canada through 2037, the company said, noting that the new AWS Canada West (Calgary) Region is estimated to support an average of more than 1,300 FTE (full-time equivalent) jobs annually, and that it plans to invest more than US$2.9 billion (approx. C$4 billion) in Alberta through 2037.

These jobs, including construction, facility maintenance, engineering, telecommunications, and others, will be part of the AWS supply chain in Canada.

In addition, it said, the construction and operation of the two Canadian AWS infrastructure Regions is estimated to generate more than US$31 billion (approx. C$43.02 billion) in gross domestic product (GDP), and the new AWS Canada West (Calgary) Region is estimated to add about US$4.1 billion (C$5.62 billion) to Canada’s GDP through 2037.

François-Philippe Champagne, federal minister of innovation, science and industry, said in a release, “Our government is committed to positioning our domestic industries for long-term growth and sustainability.”

The digital infrastructure being established by AWS near Calgary, he added, will support Canadian developers, startups, large enterprises and academic institutions in their work by enabling access to AWS’s powerful advanced cloud technologies.

“This means faster and more reliable access to cloud services to support computing, storage, networking, analytics, artificial intelligence, mobile, hybrid, media, and security, which helps to secure well-paying jobs across many new industries.”

The post AWS Canada West (Calgary) Region goes live first appeared on IT World Canada.