Category: News

U.S. drug store chain banned from using facial recognition for five years

Rite Aid, an American drug store chain, will be banned by a regulator from using facial recognition applications to identify suspicious customers for five years because of the way it implemented the technology.

The U.S. Federal Trade Commission (FTC) said today its proposed order will settle charges that the retailer failed to implement reasonable procedures and prevent harm to consumers in its use of facial recognition technology in hundreds of stores.

The decision also covers an allegation that Rite Aid’s wrongful use of facial recognition technology also violated a 2010 FTC order that it adequately oversee its service providers.

Rite Aid’s reckless use of facial surveillance systems left its customers facing humiliation and other harms, and its [2010] order violations put consumers’ sensitive information at risk,” said Samuel Levine, director of the FTC’s bureau of consumer protection. “Today’s groundbreaking order makes clear that the Commission will be vigilant in protecting the public from unfair biometric surveillance and unfair data security practices.”

Rite Aid Corp., which has over 1900 stores in 16 states, is currently going through bankruptcy proceedings, and the order will go into effect after approval from a bankruptcy court and the federal district court.

The decision is a warning to American organizations that they risk sanctions for deploying facial recognition technology if they don’t consider and mitigate potential risks to consumers from misidentifying them, test and assess the accuracy of the facial recognition technology before deploying it, and regularly monitor or test the accuracy of the technology after deployment.

In a statement, Rite Aid said it had reached a settlement with the FTC. However, it added, “we fundamentally disagree with the facial recognition allegations in the agency’s complaint. The allegations relate to a facial recognition technology pilot program the company deployed in a limited number of stores. Rite Aid stopped using the technology in this small group of stores more than three years ago, before the FTC’s investigation regarding the company’s use of the technology began.”

If the order announced today is approved by a federal court, Rite Aid will have to implement comprehensive safeguards to prevent these types of harm to consumers when deploying automated systems that use biometric information to track them or flag them as security risks. It also will require Rite Aid to discontinue using any such technology if it cannot control potential risks to consumers. The company will also have to implement a robust information security program, which must be overseen by top executives.

The FTC alleged that, from 2012 to 2020, Rite Aid deployed artificial intelligence-based facial recognition technology to identify customers who may have been engaged in shoplifting or other problematic behavior. The complaint charges that the company failed to take reasonable measures to prevent harm to consumers who were erroneously accused by employees of wrongdoing because facial recognition technology falsely flagged the consumers as matching someone who had previously been identified as a shoplifter or other troublemaker.

Employees, acting on false positive alerts, followed consumers around its stores, searched them, ordered them to leave, called the police to confront or remove consumers, and publicly accused them, sometimes in front of friends or family, of shoplifting or other wrongdoing, according to the FTC complaint. In addition, the FTC says Rite Aid’s actions disproportionately impacted people of colour.

Rite Aid’s actions “subjected consumers to embarrassment, harassment, and other harm, ” the regulator alleged in its complaint. The company didn’t tell consumers that it was using the technology in its stores, and employees were discouraged from revealing it.

Earlier this year, the FTC issued a warning to firms about the potential abuse of biometric information.

According to the complaint, Rite Aid contracted with two companies to help create a database of images of individuals — considered to be “persons of interest” because Rite Aid believed they engaged in or attempted to engage in criminal activity at one of its retail locations — along with their names and other information such as any criminal background data. The company collected tens of thousands of images of individuals, many of which were low-quality and came from Rite Aid’s security cameras, employee phone cameras and even news stories, according to the complaint.

The system generated thousands of false-positive matches, the FTC says. For example, the technology sometimes matched customers with people who had originally been enrolled in the database based on activity thousands of miles away, or flagged the same person at dozens of different stores all across the United States, according to the complaint.

Issues around facial recognition are also being addressed in Canada. Last year a Canadian parliamentary committee recommended the government create a federal legal framework for facial recognition and artificial intelligence.

In April, B.C.’s information and privacy commissioner said four independently owned Canadian Tire affiliate stores broke the province’s privacy law in the way their facial recognition solution was implemented.

The Calgary-based legal advocacy organization Justice Centre for Constitutional Freedoms (JCCF) issued a report in August saying digital ID applications like facial recognition “undermine the inviolate personality or human dignity of their users.”

The post U.S. drug store chain banned from using facial recognition for five years first appeared on IT World Canada.

Federal government delays funding programs targeted towards R&D and SMBs

The Department of Finance Canada and Innovation, Science and Economic Development Canada (ISED) announced in a joint statement yesterday that the launch of Canada Innovation Corporation (CIC), initially slated for 2023, will be delayed to 2026-2027. That means CIC might not happen at all if there is a change in government after the next general election in October 2025.

The integration of the National Research Council of Canada Industrial Research Assistance Program (NRC RAP) into the CIC, announced in February, is consequently also delayed until 2026-2027. In the meantime, NRC IRAP will continue to be delivered by the NRC, the departments said.

The government said in February of this year that the CIC “will not be just another funding agency”, but rather be a “focused, outcome-driven mandate to increase Canadian business expenditure on R&D.” The CIC would have received C$2.6 billion over four years, the government announced in last February’s budget.

A senior government official told The Globe and Mail that the delay is due to the challenge in building an agency from scratch, and difficulty finding the right people from the private sector to run the agency.

As a matter of fact, the government still has not announced who will run the CIC, despite promising in June that CIC will be up and running in 2023, with a board and executive.

The president of Council of Canadian Innovators (CCI), a lobby group for 150 of Canada’s technology-intensive companies, Benjamin Bergen, referred to the delay as “disappointing news for the leaders of the Canadian innovation economy.”

“When it was first announced, we applauded the government for creating the Canadian Innovation Corporation, and we were excited for the refreshing approach to innovation policy it represented. Nearly two years, later we now hear that it will be delayed by a further two years, and in reality it is unlikely to ever be fully established in the way we had hoped.”

However, Bergen welcomed the review, also announced yesterday, of the Scientific Research and Experimental Development (SR&ED) tax incentive program, which he said he hopes will bring transparency to the recipients of the tax incentives. 

This program, which seeks to encourage businesses to conduct research and development and employ knowledge workers, provides about C$3 billion a year in tax incentives to over 20,000 claimants, of which 75 per cent are small businesses.

The announcement said that consultations will begin next month on a “cost-neutral modernization” of the program.

Further, it said that the government will implement improvements to the Business Development Bank of Canada (BDC), following recommendations from a legislative review. The BDC is a financial Crown corporation that provides support exclusively to SMEs and entrepreneurs.

The legislative review advised the government to strengthen support for under-represented entrepreneurs as well as improve the reach of BDC in underserved regions. It also concluded that the BDC should review its “risk appetite” to support entrepreneurs with the greatest need.

“The fact that the government has heard the concerns we’ve raised about BDC’s lack of risk appetite, and its unwillingness to support our best and brightest companies to allow them to achieve their full potential is positive,” said Bergen. “The proof will be in the actual decisions of BDC’s leadership team and staff in the months and years ahead, but we hope they are hearing loud and clear that the support they have been delivering thus far is not what Canadian innovators actually need.”

The post Federal government delays funding programs targeted towards R&D and SMBs first appeared on IT World Canada.

Cyber Security Today, Dec. 20, 2023 – Data on over 35 million Comcast customers stolen because patching wasn’t fast enough

Data on over 35 million Comcast customers stolen because patching wasn’t fast enough.

Welcome to Cyber Security Today. It’s Wednesday, December 20th, 2023. I’m Howard Solomon, contributing reporter on cybersecurity for ITWorldCanada.com and TechNewsday.com in the U.S.



 American telecommunications provider Comcast Cable wasn’t fast enough to patch a Citrix vulnerability. And that led to the theft of personal data of over 35 million customers of its Xfinity service. In a statement this week the company said Citrix released a patch for the hole on October 10th. Sometime after that Comcast patched and migrated its systems. But then it discovered that between October 16th and the 19th — before systems were mitigated — a hacker got into Comcast’s IT system through the vulnerability. The hole is in Citrix’s NetScaler Application Delivery Controller and Gateway. This vulnerability has been nicknamed CitrixBleed. Researchers at Mandiant told Cybersecurity Dive that the patch plugs the hole, but IT departments have to also make users re-authorize sessions to prevent a threat actor previously exploited the hole from maintaining access. Information copied could have included names, contact information, last four digits of Social Security numbers, dates of birth and/or secret password questions and answers, usernames and hashed passwords.

More big numbers from a data breach. American mortgage company Mr. Cooper now says an October data breach involved the theft of data of nearly 14.7 million current and former customers.

And over 15,000 American residents are being notified their data was stolen from a medical device manufacturer called Zoll Medical Corp. The company says an employee fell for a phishing message. The information stolen, including names, addresses and Social Security numbers, was included in company email messages.

VF Corp., the parent company of apparel brands Vans, Supreme and The North Face, says a cyber attack detected last week encrypted some IT systems. In a regulatory filing it didn’t call the attack ransomware. Personal information was stolen. The attack has disrupted the company’s business during the holiday season, the filing says. Shoppers can place orders on most of the brand’s e-commerce sites. But the ability to fulfill orders has been slowed.

The Rhysida ransomware gang has posted a huge amount of data stolen from Insomniac Games. According to the Australian news site Cyber Daily, this came after a deadline for paying a ransom passed. Many of the published files seem to come from the upcoming Wolverine video game, as well as the company’s Spider-Man 2 game. However part of the stolen data also appears to have been sold to someone.

Shutting the IT infrastructure of a malware operation doesn’t mean distribution goes away. The gang behind the malware often finds a way back. The latest example is the resurfacing of the Qakbot malware. The FBI took down the botnet of 700,000 compromised devices distributing the malware in August. However, Microsoft tweeted this week that someone is sending phishing messages with an infected Qakbot PDF. In one case the sender pretended to be an employee of the U.S. Internal Revenue Service.

The SSH protocol used around the world to protect IT network logins and file transfers is vulnerable to attack. That’s according to German university researchers. In a paper published this week the trio describes an attack called Terrapin that breaks the integrity of SSH’s secure channel. However, to be successful the attacker has to first conduct a successful man-in-the-middle attack at the network layer to modify a connection’s traffic. And the connection must use one of two particular encryption methods. And the attacker has to be on a local network. This kind of attack is difficult on the internet. Still, since quietly being alerted of the problem many vendors have updated their SSH implementation. IT managers should note that both clients and servers have to be patched.

Follow Cyber Security Today on Apple Podcasts, Google Podcasts or add us to your Flash Briefing on your smart speaker.

The post Cyber Security Today, Dec. 20, 2023 – Data on over 35 million Comcast customers stolen because patching wasn’t fast enough first appeared on IT World Canada.

Intel swings for the fence with new AI-centric offerings

Last Thursday’s major product launch by Intel Corp. proved that the organization is clearly on an upswing, says Denis Gaudreault, the country manager for Intel Canada, adding that his hope is that in a couple of years, “people will write books on our turnaround.”

The launch, he said in an interview with IT World Canada, has been well received by both corporate customers and the channel, who “have been telling us, we need you back like you used to be with better execution and more predictability on your roadmap.”

Gaudreault described the various announcements introduced at an event in New York City called AI Everywhere as the “turning point in our new strategy.”

They included the following:

The Intel Core Ultra mobile processor family, code-named Meteor Lake, which Intel described as “the first built on the Intel 4 process technology and the first to benefit from the company’s largest architectural shift in 40 years.” It delivers “Intel’s most power-efficient client processor and ushers in the age of the AI PC.”
The 5th Gen Intel Xeon processor family, which is built with artificial intelligence (AI) acceleration in “every core, bringing leaps in AI and overall performance and lowering total cost of ownership (TCO).”
Company chief executive officer (CEO) Pat Gelsinger showed, for the first time, an Intel Gaudi3 AI accelerator, which he said will arrive on schedule next year.

“AI innovation is poised to raise the digital economy’s impact up to as much as one-third of global gross domestic product,” Gelsinger said in a release. “Intel is developing the technologies and solutions that empower customers to seamlessly integrate and effectively run AI in all their applications – in the cloud and, increasingly, locally at the PC and edge, where data is generated and used.”

Intel Core Ultra, the release said, will “allow the launch of the AI PC generation with innovations on all fronts: CPU compute, graphics, power, battery life and new AI features.”

The company described the AI PC, which is expected to be available in 230 designs from laptop and PC makers worldwide, as the “largest transformation of the PC experience in 20 years since Intel Centrino untethered laptops to connect to Wi-Fi from anywhere.

“With dedicated AI acceleration capability spread across the central processing unit (CPU), graphics processing unit (GPU) and neural processing unit (NPU), Intel Core Ultra is the most AI-capable and power-efficient client processor in Intel’s history,” the release stated.

Intel’s newest NPU, branded Intel AI Boost, it added, is “purpose-built to handle longer-running AI workloads at low power, and it complements AI handled on both the CPU and GPU.”

During a keynote presentation, Gelsinger described what he called a “driving force of silicon: creating a trillion dollar market by the end of the decade, and the role of AI just making it go faster into the future.

“To use a baseball analogy, we are in the early innings. Well, no, maybe we are still at warm up. No, maybe we are still in the preseason of the impact that it is going to have. But when we think about artificial intelligence as something over there, and something we may not understand or may not control, we think it is a disservice to think about it that way.

“Instead, how we integrate it into our human lives, into human intelligence, how we make it part of us and everything that we do. And we think bringing this value into the human experience is the opportunity for AI – augmented intelligence.”

He used his own family history as an example of how the technology can help: “My family, we have a disorder – we lose our hearing at an early age. My father was almost deaf when he passed away, and my AI-enhanced Starkey hearing aids are making me better. It is not something over there. It is right here, augmenting my human experience.

“And we think this paradigm shift – how humans and technology come together – are going to be powerfully enabled by AI. And that hearkens us back to the Intel vision, that we are going to work on technology that improves the lives of every human on Earth.”

In the data centre, Intel said, the new Xeon processor family “delivers a 21 per cent average performance gain for general compute performance and enables 36 per cent higher average performance per watt across a range of customer workloads,” compared to the previous generation.

Its AI accelerators, it said, “together with optimized software and enhanced telemetry capabilities, enable more manageable and efficient deployments of demanding network and edge workloads for communication service providers, content delivery networks and broad vertical markets, including retail, healthcare and manufacturing.”

According to the release, both Intel Core Ultra and 5th Gen Xeon will “find their way into places you might not expect. Imagine a restaurant that guides your menu choices based on your budget and dietary needs; a manufacturing floor that catches quality and safety issues at the source; an ultrasound that sees what human eyes might miss; a power grid that manages electricity with careful precision.”

No specifications were provided for the upcoming Gaudi3, which, according to a published report, is expected to compete with AMD’s M1300 and the H100 from NVDIA. However, Gelsinger did describe it as “out of fab, in the lab, being powered on, looking healthy.”

The post Intel swings for the fence with new AI-centric offerings first appeared on IT World Canada.

AlphV/BlackCat ransomware gang’s websites seized, FBI releases decrypter

U.S. authorities have confirmed the disruption of the AlphV/BlackCat ransomware gang, including the seizure of several of the group’s data leak and communications sites and the publication of a decrypter that victim organizations can use to get access back to scrambled data.

The announcement comes after over a week of silence on the gang’s data leak site, leading to speculation that action against the prolific gang had taken place.

“In disrupting the BlackCat ransomware group, the Justice Department has once again hacked the hackers,” U.S. Deputy Attorney General Lisa Monaco said in a statement. “With a decryption tool provided by the FBI to hundreds of ransomware victims worldwide, businesses and schools were able to reopen, and health care and emergency services were able to come back online. We will continue to prioritize disruptions and place victims at the center of our strategy to dismantle the ecosystem fueling cybercrime.”

The decryption tool has been offered to 400 victims of the gang.

However, not long after the FBI announcement, one of the supposedly seized sites had a new message in Russian saying a new gang site had been set up. The translation says, “As you all know, the FBI received the keys to our blog, now we will tell you how it all happened.” It claims that while law enforcement knows of and can help 400 companies decrypt their scrambled data, more than 3,000 other victims can’t be helped.

Because of police action, the site says, the gang has removed all of its rules limiting the actions of affiliates. That means, the post says, there’s nothing stopping ransomware attacks on hospitals, nuclear power stations and other sensitive organizations.

The authenticity of the message couldn’t be verified by IT World Canada.

The international law enforcement action also involved Germany’s Bundeskriminalamt and Zentrale Kriminalinspektion Göttingen, Denmark’s Special Crime Unit, and the Europol police co-operative. The U.S. said several other groups provided substantial assistance and support, including the Australian Federal Police, the United Kingdom’s National Crime Agency and Eastern Region Special Operations Unit, Spain’s Policia Nacional, Switzerland’s Kantonspolizei Thurgau, and Austria’s Directorate State Protection and Intelligence Service.

The FBI says that over the past 18 months, AlphV/BlackCat became the second most prolific ransomware-as-a-service variant in the world, based on the hundreds of millions of dollars in ransoms paid by victims. Among the latest hit was the MGM Resort Las Vegas. After that hit, the gang said patrons shouldn’t blame it for losing money on reservations because closing the hotel and casino was management’s decision.

This interagency and multijurisdictional law enforcement operation “crowns a historical record of ransomware takedowns conducted in 2023,” commented Ilia Kolochenko, CEO of ImmuniWeb. “It is an excellent example of how well co-ordinated co-operation between the E.U., U.K. and U.S. authorities, with support from transnational agencies such as Europol, brings efficient results and slows down the surging pandemic of ransomware and interrelated hacking campaigns.

“Having said that, disruption of cybercrime’s infrastructure and selective arrests of identifiable cyber gang members is rarely sufficient. For example, a considerable number of seized hacking forums or marketplaces resurrected a few weeks after the seizure under a similar or new identity. Amid the global geopolitical uncertainty, many cybercrime groups safely operate from non-extraditable jurisdictions in absolute impunity.”

Unless nation-states manage to hammer out a truly global convention against cybercrime that would be ratified by all U.N. member states, he warned, the battle against organized cybercrime will be like fighting an immortal hydra.

That warning comes as nations are set for a final negotiating session at the end of January on a proposed international cybercrime treaty. Last week, the Cybersecurity Tech Accord, a group of leading IT companies including Microsoft, Cisco Systems, and Oracle complained that the latest draft “would significantly weaken cybersecurity, erode data privacy, and undermine online rights and freedoms across the world.”

This is a win for law enforcement, and almost certainly marks the end of AlphV as a brand, said Brett Callow, a Canadian-based threat researcher for Emsisoft. “Nobody will want to do business with an operation that has been compromised. In fact, their business associates and affiliates will already be wondering what information law enforcement obtained and whether any of it points to them – which isn’t at all unlikely.

“Unfortunately, the individuals behind AlphV are unlikely to be out of the ransomware game for good. They’ll probably spin up a new operation with a new name. But, even if they do, this is still a big win for good guys and a big loss for the bad guys.”

A search warrant used to support FBI action against AlphV/BlackCat says the agency relied in part on a confidential human source “who routinely provides reliable information related to ongoing cybercrime investigations.”

The source had answered a public advertisement the ransomware gang had posted for potential affiliates. After passing an interview, the source was given access credentials for the BlackCat’s affiliate system using a unique .onion address.

Sites seized by law enforcement were hidden on the Tor network. But through its investigation and the source, the FBI was able to collect 946 public/private key pairs for Tor sites that the ransomware gang used to host victim communication sites, leak sites, and affiliate panels.

The post AlphV/BlackCat ransomware gang’s websites seized, FBI releases decrypter first appeared on IT World Canada.

Coffee Briefing Dec. 19 – Toronto group warns of the impact of AI on the music industry; CGI and Google Cloud partner on sustainability; Rogers brings cellular coverage to Highway 16, BC; and more

Coffee Briefings are timely deliveries of the latest ITWC headlines, interviews, and podcasts. Today’s Coffee Briefing is delivered by IT World Canada’s editorial team! 

Missed last week’s Coffee Briefing? We’ve got you covered.

This is the final Coffee Briefing of 2023. Have a safe and joyous holiday season!

See you in 2024.

Toronto group urges the government of Canada to ensure AI does not replace music creators

The Society of Composers, Authors and Music Publishers of Canada (SOCAN), along with a coalition of music organizations, wrote a letter to the government of Canada containing recommendations that aim to ensure AI does not replace human creativity and culture. 

The letter outlined three specific concerns about the impact of AI on the music industry:

pre-existing creative works being exploited by AI models without consent from or compensation for rights holders;
the risk AI systems pose to the livelihood of human creators; and
the risk of AI systems being used to imitate creators’ voices and likeness without their knowledge or consent.

SOCAN and the other signatories recommend:

Ensure human expression is protected via copyright rights
Grant no new copyright exceptions for use of creators’ works without permission to develop AI models
AI developers must be transparent about their use of specific works for AI model training
Canadians should know whether they are listening to music created by a human or AI; explicit content labels should be adopted
AI developers must obtain permission from creators for the use of their intellectual property or personality traits like their voices

“We believe the principles outlined in our letter to Minister St-Onge and Minister Champagne set the foundation for an effective process for AI that will protect music creators by respecting the value of their extraordinary work. We hope our efforts will be considered to ensure the AI model can continue to evolve and grow responsibly,” said Jennifer Brown, SOCAN chief executive.

SOCAN is also participating in the open consultation on the implications of generative AI and copyright, held by Canadian Heritage and Innovation, Science and Economic Development Canada, which ends on Jan. 15, 2024.

Kitchener company launches AI-powered tool to understand customer behaviour

Technology and innovation consultancy Meta IT has launched a new tool designed to decipher customer behaviours using artificial intelligence (AI).

Specifically, the tool personalizes product journeys by delving into each customer’s life stage and preferences. 

In addition to historical customer transactional data, the tool uses external market databases to enrich data. Predictive recommendations are generated based on past patterns in the database, and enable continuous learning and adjustment as the market, products, and customers’ profiles change.

Meta IT says that the new tool will help boost order conversions by up to 30 per cent through personalized offerings, triple sales potential with new customers, achieve an impressive 94 per cent accuracy in production forecasting and rupture prevention, and culminate in a 20 per cent increase in companies’ overall revenue.

“This transformative solution not only optimizes production processes, but also catapults businesses into a realm of heightened customer understanding and engagement, fostering sustained growth and prosperity,” said Marcos Machado, executive director at Meta IT. “With this technology, we reaffirm our commitment to working with a human purpose, facilitating processes and strategies for companies, and enhancing customer experiences.”

CGI and Google Cloud partner to advance sustainability

CGI has partnered with Google Cloud to deliver the United Nations Industrial Development Organization (UNIDO) Sustainability Planet Platform, a data-driven source for countries to identify sustainability challenges such as air pollution, rising temperatures, and flooding.

We are proud of this collaboration with CGI to create the Sustainability Planet Platform, UNIDO’s first fully comprehensive data set, showcasing all its sustainability efforts and interventions across every territory,” said Teddra Burgess, director civilian sales, Google Cloud Public Sector.  “We look forward to working with CGI to continue to deliver sustainability outputs using cutting-edge technology and comprehensive planet data to enable further achievements towards global sustainability development goals.”

The Sustainability Planet Platform integrates data from multiple sources, including temperature data and other data from satellites such as Landsat, which is used in agriculture; land use and water resources data from CGI’s Sustainability Exploration and Environmental Data Science (SEEDS) program; data from Google Cloud’s Earth Engine; and UNIDO’s data on its global projects.

UNIDO member states will be able to assess progress with the Sustainable Development Goals (SDGs), not only at the country level, but also in relation to specific sectors such as steel and concrete.

Rogers provides wireless coverage on Highway 16 in British Columbia

Rogers has announced that it has turned on three new cellular towers along British Columbia’s (BC) Highway 16, providing 50 kilometres of 911 access for all travellers, and 5G wireless coverage for its customers.

One new tower at Seeley Lake Park is providing 13 kilometres of new wireless coverage and two new towers are providing 37 kilometres of new coverage between Seven Sisters Mountain and Pacific. Once all the project’s towers are completed, Rogers will provide 252 kilometres of new cellular coverage along the entire 720-kilometre corridor.

The new towers are part of an ongoing wireless service expansion project, in partnership with the government of Canada and the province of BC, to improve safety and remove wireless coverage gaps along the section of highway known as the Highway of Tears. This corridor between Prince Rupert and Prince George also honours the memory of the many Indigenous women and girls who have disappeared or have been found murdered along the route.

“These new cellular towers are lifelines to all of us who travel along Highway 16 regularly, and we are hopeful they will help prevent future tragedies,” said Mary Teegee, a Murdered and Missing Indigenous Women and Girls (MMIWG) activist. “It has been deeply rewarding watching this project unfold, and we look forward to celebrating its completion and benefiting from the social and economic advantages it provides.”

RoboGarden and Ontario Tech University come together to deliver new AI-supported developer program

 

Cloud-based teaching platform RoboGarden has announced that it has joined forces with Ontario Tech University to offer an AI-supported Full Stack Developer Bootcamp and make it accessible to the global learning community.

The Full Stack Developer Bootcamp teaches learners how to build and architect an application, starting from conceptualization through to design, development, and launch, while also considering various platforms and usability requirements.

The program also leverages proprietary AI-supported features, helping students progress faster and more effectively in their skill development. Plus, students are taught how to pitch, present, and sell their solutions in a professional programming environment.

“We emphasize not just learning, but mastering competencies essential for the digital age. Our advanced training platform and programs are meticulously designed to ensure students acquire vital skills,” said Mohamed Elhabiby, president, RoboGarden. “This approach is not just about individual success; it’s about cultivating a community of skilled innovators. Our graduates are set to propel the economy forward and solidify Ontario’s reputation as a hub of exceptional tech talent.”

Prospective students can learn more and enroll in the next Full Stack Development Bootcamp cohort until Feb. 2, 2024 at Ontario Tech Continuous Learning’s program information and registration page.

More to explore

Multisensory art exhibit at the Aga Khan Museum taps into AI, VR

It is called Night in the Garden of Love, is produced in partnership with Weils, the Centre for Contemporary Art in Brussels, and it combines traditional art with an obvious technology bent that, in the words of its creator, “transports visitors into new and imaginary worlds.”

Southern Ontario school board acknowledges ‘cyber incident’

One of the biggest public school boards in Southern Ontario has publicly acknowledged a cyber attack, over a month after it was detected.

Dental benefits group notifying almost 7 million Americans of MOVEit data theft

Almost 7 million U.S. residents are being notified by a dental benefits provider that their personal information was stolen in one of the biggest single attacks involving the MOVEit file transfer application.

Big budgets, laggard IT systems: Government officials questioned at House of Commons committee

The Benefit Delivery Modernization (BDM) program, the largest IT transformation initiative ever undertaken by the Government of Canada, was estimated to cost $1.75 billion when it launched in 2017.

Rogers and Lynk complete satellite-to-mobile phone call, 2024 launch anticipated

Rogers and Lynk Global have announced that they have completed Canada’s first successful satellite-to-mobile phone call, using Samsung Galaxy S22 smartphones.

BlackBerry names new CEO, will split cybersecurity and IoT businesses

BlackBerry’s new leader is the former head of its cybersecurity business unit.

Channel Bytes December 15, 2023 – RackWare launches channel program; MSP360 adds end-user restores to Managed Backup; Intel launches Core Ultra with NPU; and more

Staying informed is a constant challenge. There’s so much to do, and so little time. But we have you covered. Grab a coffee and take five while you nibble on these tidbits.

Listen to the latest episode of Hashtag Trending

Hashtag Trending Weekend Edition, December 16, 2023 – Our guest today is Arik Kalininsky, CEO of Dalikoo

Listen to the latest episode of Cybersecurity Today

Cyber Security Today, Dec. 18, 2023 – Customer contact info stolen from MongoDB, more stringent American cyber attack reporting rules start today, and more

Listen to the latest episode of Hashtag Tendances

If you live in Québec, or prefer to consume the latest technology news in French, our sister publication Direction Informatique has you covered. Follow them on Twitter as well.

The post Coffee Briefing Dec. 19 – Toronto group warns of the impact of AI on the music industry; CGI and Google Cloud partner on sustainability; Rogers brings cellular coverage to Highway 16, BC; and more first appeared on IT World Canada.

Cyber Security Today, Dec. 18, 2023 – Customer contact info stolen from MongoDB, more stringent American cyber attack reporting rules start today, and more

Customer contact info stolen from MongoDB, more stringent American cyber attack reporting rules start today, and more.

Welcome to Cyber Security Today. It’s Monday, December 18th, 2023. I’m Howard Solomon, contributing reporter on cybersecurity for ITWorldCanada.com and TechNewsday.com in the U.S.



 

This is a notable day if you’re a publicly traded company in the U.S. Most companies now have to file a notice of a data breach to the Securities and Exchange Commission within four business days of determining the attack many have a material impact on the company. Smaller companies have to start filing next June 15th. Firms can ask the FBI for a delay in filing if disclosure poses a substantial risk to national security or public safety.

Companies that operate in Utah should note that the state’s new data privacy law comes into effect on December 31st. The law requires businesses to implement data security practices to protect users’ confidentiality. It gives consumers the right to tell firms to stop using their data in advertising. It’s also the first U.S. state to give social media privacy rights to children. Utah is the fourth state to enact a comprehensive consumer data protection law.

Meanwhile, in California browser makers like Google, Microsoft and Apple and firms that do business online may see their personal data collection limited. The California Privacy Protection Agency has voted to ask the legislature for a new law. It would require browser vendors to give California residents the ability to forbid any business from selling or sharing the personal data they collect. That’s right: Instead of having to find an option on every website a user goes to, every browser would have a button or setting to check that limits personal data collection by anyone. Any firm the user connects to by a browser would have to obey the opt-out preference. That opt-out data collection option for firms came into effect under California’s new Consumer Privacy Act. However, so far only a limited number of browsers including Firefox, DuckDuckGo and Brave have a browser opt-out preference. The proposed new law would broaden that.

Administrators who oversee a MongoDB database are being warned to watch for signs of attack. This comes after the developer last week spotted an unauthorized access to MongoDB’s corporate IT systems. What the hacker might have seen is customer account metatdata and related contact information. The access had been going on for some time. So far there’s no evidence that any customer data stored in the Atlas developer platform has been copied. However, to be on the safe side users and administrators should watch for social engineering and phishing attacks that may appear to come from MongoDB. If they haven’t done so by now administrators should activate phishing-resistant multifactor authentication.

The PyPI website for publishing open-source Python projects continues to be abused by threat actors. The latest example comes from security researchers at ESET, who recently discovered 116 malicious packages with malware aimed at Windows and Linux systems. The final payload is data-stealing malware. I’ve said this several times before: Developers have to be careful before downloading anything from open-source project repositories like PyPI, NPM, GitHub and others. Often malicious projects have similar names to legitimate packages to fool victims.

The U.S. Cybersecurity and Infrastructure Security Agency has again urged hardware and software manufacturers to stop putting default passwords in their products. This comes after recent warnings that an Iranian-backed group is compromising critical infrastructure providers by learning of devices with default passwords on IT networks. Any default password that can be found in an instruction manual is gold for a threat actor. Stupid default passwords like ‘1234’, ‘default’ and ‘password’ are the first thing attackers will try even if they haven’t seen a manual. What makes things worse is if the product is used in operational technology networks in utilities or manufacturing plants. Hoping IT or OT administrators will change default passwords when a new product is installed isn’t working. Only action by product manufacturers will solve this problem.

Including a software bill of materials in applications is a smart way of helping IT managers understand what’s in their software and whether components — particularly open-source modules — need to be updated. Components like, for example Apache Log4j. As I reported last week, North Korea’s Lazarus group is hunting for and finding applications whose Log4j components haven’t been patched. But how do you create a software bill of goods? Well, last week guidance on how to do that was released by the U.S. National Security Agency. It’s not only developers that need to create a list of what’s inside their applications. Software buyers should pressure their vendors to do it. Knowing what’s in the applications you use helps mitigate cyber risk.

Finally, someone is stocking YouTube with pro-China and anti-U.S. videos propaganda. That’s according to the Australian Strategic Policy Institute. In a paper the institute says the videos have attracted an unusually large audience with themes such as how China is trying to win what video narrators says is the ‘U.S.-China technology war. Those narrators are voice-overs generated by artificial intelligence. The institute calls this campaign Shadow Play, and says it started in the middle of last year. The campaign includes a network of at least 30 YouTube channels that have produced more than 4,500 videos. So far they have had 120 million views. The report says that since being advised Google has taken down 19 of the YouTube channels because they were either created by phony people or were spam.

Follow Cybersecurity Today on Apple Podcasts, Google Podcasts or add us to your Flash Briefing on your smart speaker.

The post Cyber Security Today, Dec. 18, 2023 – Customer contact info stolen from MongoDB, more stringent American cyber attack reporting rules start today, and more first appeared on IT World Canada.

Multisensory art exhibit at the Aga Khan Museum taps into AI, VR

It is called Night in the Garden of Love, is produced in partnership with Weils, the Centre for Contemporary Art in Brussels, and it combines traditional art with an obvious technology bent that, in the words of its creator, “transports visitors into new and imaginary worlds.”

That creator is contemporary artist Shezad Dawood, a U.K. multidisciplinary artist who, according to his  bio, “interweaves stories, realities and symbolism to create richly layered artworks, spanning painting, textiles, sculpture, film, and digital media.”

Lateef and Dawood. Photo courtesy of Aga Khan Museum

Dawood based Night in the Garden of Love, which opened last month at the Aga Khan Museum in Toronto and runs until May 5, 2024, on the novella of the same name by African-American Muslim musician, composer, and polymath, Dr. Yusef Lateef, who passed away in 2013 at the age of 93.

Marianne Fenton, curator of special projects at the museum, described it as a “multisensory art experience. Centred around scores and rhythms, the exhibition explores the harmonic relationship between Dawood and Lateef’s work. It reflects the spirit and musicality of Lateef’s idea and drawings through Dawood’s interpretations, exploring gardens as realms of creation and optimism in the face of the climate crisis.”

During a media tour prior to the official opening, she described the exhibit, which contains a major virtual reality (VR) component as well as using artificial intelligence (AI), as “experiential, and we invite everyone to see it through that lens.”

The VR experience. Photo courtesy of Aga Khan Museum

Dawood collaborated with immersive film and digital arts production company UBIK Productions to create a two-player VR environment that Fenton said is designed to “immerse audiences in key scenes from the novella. This 3D reimagining of (it) begins in outer space, transports the players to the streets of Detroit, trails the mutant (a key figure in the novella) to a recycling plant, and culminates in a utopic garden adorned with imagined plants.

“The VR experience provides viewers with imagined interpretations of key moments from the novella. It also provides an interesting take on sustainability by viewing the discourse surrounding climate change through a hopeful lens.”

During the tour, Dawood, who is also a research fellow in experimental media at the University of Westminister in London, told IT World Canada he had never done a two-player VR before, and, he said, ” I was really interested, particularly with the thread of the narrative in the novella about this couple who the mutant leads into the Garden of Love. I was like, ‘oh, what is that experience of intimacy in the digital world? How do you bring intimacy into this space, which is not a likely candidate for intimacy?’

“I am actually very skeptical of digital media, believe it or not, even though I use it, but I think to use anything effectively, you have to be very critical of it. And it was this idea of like, ‘oh, what is that experience? Totally aside from VR, just the fact that you suddenly are in a position of a shared journey, or otherworldly space that opens up for you and one other person, if they are a partner, a friend, a colleague, or a perfect stranger.’ What does that do in terms of what you take away from the experience?”

AI was used in an unusual manner, according to a release issued prior to the Nov. 10 opening: “Accompanying the exhibition will be a scent created by Dawood in collaboration with Olivia Bransbourg of boutique perfume label Iconofly, perfumer Nicolas Bonneville, and fragrance house dsm-firmenich. The distinctive fragrance features eight middle notes. While some are recognizable, such as jasmine, others were crafted using artificial intelligence to represent plants that do not naturally produce a discernible scent.”

It is, said Fenton, “a union of nature and artificial intelligence. Here we see the digital and the analogue intersecting to create something previously unimagined and unique.”

According to the release, Dawood uses gardens as a starting point for creative, futuristic and intercultural conversations. It is a blend of two individuals – Dawood and Lateef, who the release notes was a “major force on the international music scene for more than six decades.

Photo courtesy of Aga Khan Museum

“Audiences will encounter a series of painted textile works by Dawood of real and imagined plants, original artwork by Lateef, and objects from the museum’s Permanent Collection as they journey through time, navigating a blend of analogue and digital spaces.”

Dawood’s interest in Lateef goes back well beyond his becoming an artist. “I knew the music of Yusef Lateef from my childhood,” he said during the media tour. “In a a very bizarre kind of twist of fate, my maternal uncle is called Yusef Lateef, so it was a running joke in our family, like, ‘not that Lateef, the other one.’”

He describes the exhibition as a “dynamic symphony with objects from the museum’s permanent collection joining the conversation as a juxtaposition between Lateef’s work and my own, it allows visitors to dive into the many flowerings and expressions of gardens throughout history.”

Admission prices for both the museum and Night in the Garden of Love are $20 for adults, $15 for seniors, $12 for students, $10 for those aged between seven and 13, and free for children six or younger. There is no admission charge on BMO Free Wednesdays, from 4 to 8 p.m.

The post Multisensory art exhibit at the Aga Khan Museum taps into AI, VR first appeared on IT World Canada.

Cyber Security Today, Week in Review for the week ending Friday, Dec. 15, 2023

Welcome to Cyber Security Today. This is the Week in Review for the week ending Friday, December 15th, 2023. I’m Howard Solomon, contributing reporter on cybersecurity for ITWorldCanada.com and TechNewsday.com in the U.S.



In a few minutes Terry Cutler of Montreal’s Cyology Labs will be here to discuss several stories from the past seven days. These include a U.K. Parliamentary report saying the country isn’t prepared for a targeted ransomware attack, North Korea’s Lazarus group is still exploiting the two-year old Log4j vulnerability and the latest on insider attacks in a jail sentencing and a U.S. Air Force report into data leaking by an Airman.

But before we get to the discussion on those stories, here’s other recent news that happened this week:

The United States and the U.K. issued sanctions against the Russian-based Callisto Group, which is accused not only of widespread cyber attacks but also of trying to undermine democratic processes in Britain.

The Edulog Parent Portal used by some school boards so parents could keep track of school buses had access control problems that impaired security. Researchers at Tenable said the vulnerability could have allowed anyone access to sensitive data. Edulog says it has fixed the issue in the portal’s API.

The outage at the AlphV/BlackCat ransomware gang’s data leak site is still unexplained. No law enforcement agency has acknowledged having a hand in the outage. However, on Thursday the gang managed to get a message out that it hit a Toronto business management firm. It claims 8TB of data was copied. The firm hasn’t replied to my email request for comment.

Microsoft has seized the U.S.-based websites and IT infrastructure of a gang it calls Storm-1152. It’s the number one creator and seller to crooks of fake Microsoft accounts. These accounts can be used to bypass identity verification software. However, the gang may have online distribution sites in other countries.

A number of data management products from Dell Technologies need to be patched. The company says its PowerProtect Data Domain, APEX Protection Storage and Data Manger Appliance servers need to be updated to fix serious vulnerabilities.

Police in France arrested a Russian man suspected of laundering funds for the Hive ransomware gang. More than a half a million euros worth of cryptocurrency was seized. The Hive network was dismantled in January.

The British Ministry of Defence has been fined the equivalent of almost $600,000 for making a common email mistake: Sending a mass email to many people and putting all their email addresses in the “To” section. The email addresses should have been sent as a blind copy. Instead, the names and details of 265 Afghans seeking admission to the United Kingdom were revealed. Had the list of names fallen into the hands of the Taliban their lives could have been threatened.

And Southern Illinois Healthcare is notifying over 147,000 patients of a data breach. The incident at its Harrisburg clinic happened 12 months ago. Data copied may have included names, dates of birth, Social Security numbers and clinical information.

(This edited transcript covers one of the four issues discussed. To hear the full conversation play the podcast)

Howard: How much should a government lead in the fight against ransomware?

A British Parliamentary National Security Strategy report on ransomware this week said because large parts of the U.K. critical infrastructure is vulnerable, a co-ordinated and targeted attack has the potential to cause severe damage to the British economy. The report says the government should consider establishing a national cyber resilience regulator for critical infrastructure, which would cover utilities, banks, telecommunications, transportation, agriculture and governments. The report complained firms hit by ransomware get next to no support from law enforcement or government agencies. At the very least the government National Cyber Security Centre should be funded to support all public sector victims — like municipalities and hospitals — to the point of full recovery. More critically the report complains that while the Home Office — which has responsibility for police departments among other things — is supposed to be the lead department on ransomware the former cabinet minister in charge, the Home Secretary, had no interest in it. The report says responsibility for ransomware should be in the hands of the Deputy Prime Minister.

This is pretty incendiary stuff. My first question is, is any country ready for what the report calls “a co-ordinated and targeted attack?”

Terry Cutler: There’s a lot to digest here, and not just because of the amount of sheer complexity that’s involved. There’s not just one group that handles everything [in a nation] so we have to have an advanced cyber security infrastructure and kept constantly up to date. And there would have to be collaboration between national and corporate levels. Just try to imagine the people involved in handling all this. You’ve got CISOs that are aging three years just in one company and they would probably lose 50 years of their life handling all this. So the biggest piece is going to be collaboration between government and the private sector. There’s got to be regular application updating, audits and penetration testing all the time, which we’re not seeing now with companies. And if they’re also to adhere to a stronger regulatory framework there’s got to be strong stronger laws in place — something like GDPR in Europe, where there has to be breach notifications to victims and government.

Howard: This year we’ve seen record reported ransomware attacks, which raises the question of can a country be ready for a co-ordinated and targeted ransomware attack that’s a worst-case scenario?

Terry: It’s going to come down to rapid response and detection. But we’re short staffed in cyber security. We’re 3 million personnel short worldwide. Not many of us want to work for the government, for example, because the pay is a lot less [than the private sector]. You have less flexibility with your schedule. All those factors come into place. I do agree there needs to be a specialized cyber security force that’s going to have the proper measures in place to help protect the country. There also needs to be collaboration with law enforcement because we can stop these attacks in certain ways, but we need to go to the source and and shut these bad guys down.

Howard: I’ve asked this question many times before: This is 2023, ransomware is only a couple of years old and surely every company knows by now to be prepared for any cyber attack. So why aren’t critical infrastructure sectors ready now?

Terry: You still have a lot of legacy IT systems lying around, especially in healthcare. We’re still seeing Windows XP [in organizations], and they’re not designed to work with more modern technologies that are out there. But you can’t just mass update these things or replace them because it can be extremely expensive. Not only that some operating systems are embedded into the technology. For example, in healthcare a radio radiology machine that can cost $200,000 may have Windows XP built right into the box. You can’t just update the firmware; you have to replace the entire equipment. And there are budget constraints. There’s not an infinite budget for cyber security, especially in the private sector. I think the biggest challenge, too, is that these threats are evolving so quickly that we need AI and other technologies to stop attacks.

…Human error is one of the biggest threats. Even if we do a lot of security awareness training one employee could have an off day. They click on something they’re not supposed to and it allows the hacker to get into their environment. We’re also dealing with supply chain issues like we saw with Solarwinds … There’s just too much complexity [in IT environments] and it’s very, very hard to protect them.

Howard: The report raises the question I think of how much of this falls on the shoulders of government. In Canada and the U.S. there are government agencies like the U.S. Cyber Security and Infrastructure Security Agency (CISA), the Canadian Center for Cyber Security. They’ve got resources that companies can draw on. And of course companies can rely on their major providers — Microsoft, IBM, Cisco Systems and so on. But it seems companies aren’t getting the message. One thing we know from investigations is that a lot of companies are still failing on basic cyber security. Why is that happening? Should governments be pushing on cyber security or should industry lead?

Terry: I think it should be industry-led because we’re on the front lines of of seeing these attacks. We’re doing a lot of incident response, we’re collecting a lot of evidence of how these attacks are coming in … Government’s role is to be in charge of setting standards and regulations. You want to make sure that organizations comply and ensure some type of baseline-level security. Now of course smaller companies think no one’s going to want to hack them. But cybercriminals know they don’t have the time money or resource to deal with cybersecurity, so it makes them the number one target. So they need help even if it’s government grants or tax breaks on help them get up to date [technology].

Government should also provide resources and guidance, like the CISA. They’re going to do some some R and D. Of course governments need international co-operation. There’s also public awareness campaigns to promote safer online behavior.

If we look at the private sector’s responsibility, they’re going to be tasked with implementing these measures, have technologies in place to help protect the company. This will also involve continuous training and education … The private sector also can invest in cyber talent. I think the biggest takeaway here is collaboration. We need to be able to share the the type of information that we’re seeing on the ground to the government and help them create proper frameworks.

Howard: The report raises the idea of the U.K. creating a new national cyber resilience regulator for critical infrastructure that would have the power to punish organizations that don’t meet a cyber security regulatory standard. What do you think about that idea in Canada or the U.S.?

Terry: It’s a really good idea. But a lot of companies will say they don’t have the time or budget. But if you have incentive programs like tax breaks that would probably help. There’s some pros and cons: Some of the benefits are they’re going to have a standardization of cyber security practices. A dedicated regulator could help enforce and standardize cybersecurity measures across all of these industries. At least there’s a baseline. There’ll be some accountability finally because we’re not seeing much of that right now. But you have regulatory complexity now … Cyber security is a global issue, so ensuring that regulators can align international norms and practices will be very, very difficult to do.

Howard: The Canadian government has proposed a cyber security law for overseeing critical infrastructure. It’s now before Parliament. One piece would give the Industry Minister the power to order telecommunications companies to take specific actions to secure the communications sector. The law would also create a cyber security compliance regime for all critical industries by using existing regulators like the Superintendent of Banks, who oversees the financial sector; the Canadian Energy Regulator, which oversees inter-provincial utilities. So there wouldn’t be a need to create a new regulator. But these bodies would have the ability to issue fines for not meeting cyber security standards. Athough the bill was introduced over a year ago it isn’t even at the committee discussion stage yet.

Terry: I remember presenting to the Conference Board of Canada back in 2013 about how much the telcos can see on the internet. One of the biggest problems is how do you defend against things that you don’t know or have never seen? This is where the telecommunication carriers come in, because they have the biggest visibility over the internet. And if you pair them with law enforcement cyber criminals are going to have a fight on their hands. Bill C 26 has some benefits here. It’ll help improve cyber security defences, especially in critical infrastructure. It’ll give authority to the Industry Minister, and it’ll help protect against cyber threats for sure because right now telecommunications companies are not providing much cyber security on the back end.

The post Cyber Security Today, Week in Review for the week ending Friday, Dec. 15, 2023 first appeared on IT World Canada.

Southern Ontario school board acknowledges ‘cyber incident’

One of the biggest public school boards in Southern Ontario has publicly acknowledged a cyber attack, over a month after it was detected.

The York Region District School Board, which covers an area stretching from Toronto in the south to Lake Simcoe in the north, with a student population of over 128,000, said in a statement this week that late on Nov. 8, the IT department became aware of a cyber incident.

The cyber security response team immediately took mitigating action to preserve and contain data and ensure critical systems were protected, the statement says.

Since then, board has been working with third-party experts, including legal and technical, to analyze the extent of the incident and restore services. Law enforcement has also been contacted.

As part of its due diligence, the board will conduct a full investigation into what occurred, the statement says, although there is no promise the results will be made public.

“We know the public rely and trust the Board to maintain its data secure,” the statement says. “All our actions have been taken to ensure the integrity of staff and student data and ensure privacy is protected.”

Public sector organizations like school boards are favoured targets of hackers, who believe they can be more easily pressured into paying to get access back to stolen or encrypted data.

Related content: Durham region school board hit by cyber attack

In January, the Huron-Superior Catholic District School Board said unnamed attackers who stole “a significant number of files from a board file server” had deleted the data. Ultimately current and former students were sent data breach notification letters. 

However, vindictive hackers who don’t get paid may release data on children. In April, NBC News reported that a ransomware gang that broke into the Minneapolis Public Schools earlier this year published an enormous cache of files that appear to include highly sensitive documents on schoolchildren and teachers, including allegations of teacher abuse and students’ psychological reports.

The post Southern Ontario school board acknowledges ‘cyber incident’ first appeared on IT World Canada.