Category: News

Dental benefits group notifying almost 7 million Americans of MOVEit data theft

Almost 7 million U.S. residents are being notified by a dental benefits provider that their personal information was stolen in one of the biggest single attacks involving the MOVEit file transfer application.

Delta Dental of California and its affiliates, which provide dental benefits to individuals through commercial groups, said the attacker copied subscribers’ names, Delta financial account number or their credit/debit card numbers, along with security access codes, passwords or PIN numbers with the accounts. Passport numbers in some cases were also copied.

According to numbers tracked by Emsisoft, this is the third biggest publicly confirmed data theft from an individual company so far. The biggest is Maximus Inc., a U.S. government services provider, which said information on 11.3 million people was stolen from its MOVEit Transfer system.

The Clop/Cl0p ransomware gang has taken credit for discovering and exploiting a zero day vulnerability allowing it to bypass multifactor authentication on both on-premises and cloud versions of Progress Software’s MOVEit application.

The vulnerability, CVE-2023-34362, has been assigned a severity rating of 9.8 out of 10. 

U.S.-based organizations account for 78.4 per cent of known victims, Emsisoft says, Canada-based 13.8 percent and Germany-based 1.4 per cent. The most heavily impacted sectors are education (40.0 percent), health (19.6 percent), and finance and professional services (12.7 percent).

According to researchers at Kroll LLC, the most common technique of compromise involved a dropped web shell to inject a session or create a malicious account. From there, threat actors were able to reauthenticate and use the MOVEit application itself to transfer files.

However, in a few instances, the attacker passed three variables to the web shell: The organization ID, the folder ID and the file name. From there, the web shell utilized MOVEit API calls for file enumeration and data exfiltration. A Python script was used exfiltrate data during the initial wave of co-ordinated and largely automated attacks across MOVEit servers.

Kroll forensic analysis has also seen activity suggesting the Clop gang was likely experimenting with ways to exploit this particular vulnerability as far back as 2021.

The post Dental benefits group notifying almost 7 million Americans of MOVEit data theft first appeared on IT World Canada.

Hackers abusing OAuth to automate cyber attacks, says Microsoft

Threat actors are misusing OAuth-based applications as an automation tool for authentication, says Microsoft.

“Threat actors compromise user accounts to create, modify, and grant high privileges to OAuth applications that they can misuse to hide malicious activity,” the company said in a blog this week. “The misuse of OAuth also enables threat actors to maintain access to applications even if they lose access to the initially compromised account.”

Threat actors are launching phishing or password-spraying attacks to compromise user accounts that don’t have strong authentication mechanisms and have permissions to create or modify OAuth applications. The attackers misuse the OAuth applications with high privilege permissions to deploy virtual machines (VMs) for cryptocurrency mining, establish persistence following business email compromise (BEC), and launch spamming activity using the targeted organization’s resources and domain name.

IT managers should take the following steps to mitigate against OAuth abuse:
— implement security practices that strengthen account credentials, such as enabling multifactor authentication. That dramatically reduces the chance of attack, says Microsoft;
— to protect against attacks that leverage stolen credentials, enable conditional risk-based access policies;
— ensure continuous access evaluation is enabled if available in your environment;
— enable all security defaults in identity platforms;
— audit all apps and consented permissions to ensure applications are only accessing necessary data and adhering to the principles of least privilege access.

The report gives an example of what one threat actor, which Microsoft dubs Storm-1283, is doing. (Under Microsoft’s new naming taxonomy, groups dubbed ‘Storm’ are newly discovered or under development.)

Storm-1283 used a compromised user account to create an OAuth application and deploy VMs for cryptomining. The compromised account allowed the attacker to sign in through a VPN, create a new single-tenant OAuth application in Microsoft Entra ID named similarly to the Microsoft Entra ID tenant domain name, and add a set of secrets to the application.

A diagram of Storm-1283’s attack chain involving the creation of VMs for cryptocurrency mining. Microsoft graphic

As the compromised account had an ownership role on an Azure subscription, the actor also granted Contributor’ role permission for the application to one of the active subscriptions using the compromised account.

The attacker also leveraged existing line-of-business OAuth applications that the compromised user account had access to in the tenant by adding an additional set of credentials to those applications, the report says. The actor initially deployed a small set of VMs in the same compromised subscriptions using one of the existing applications, and initiated the cryptomining activity. The actor then later returned to deploy more VMs using the new application. Targeted organizations incurred compute fees ranging from US$10,000 to US$1.5 million from the attacks, depending on the actor’s activity and duration of the attack.

The post Hackers abusing OAuth to automate cyber attacks, says Microsoft first appeared on IT World Canada.

Cyber Security Today, Dec. 15, 2023 – A botnet expands, threats to unpatched TeamCity servers, and more

A botnet expands, threats to unpatched TeamCity servers, and more.

Welcome to Cyber Security Today. It’s Friday, December 15th, 2023. I’m Howard Solomon, contributing reporter on cybersecurity for ITWorldCanada.com and TechNewsday.com in the U.S.



A botnet of compromised small and home office firewalls and routers continues to expand. Researchers at Lumen say those behind what it calls the KV-botnet most recently added internet-connected video cameras made by Axis and Netgear ProSafe firewalls. Lumen suspect the botnet is growing so it can be used for phishing campaigns during the holiday season. The researchers aren’t sure how devices are being infected. But they believe it’s run by a threat group dubbed Volt Typhoon or Bronze Silhouette by other researchers. It’s a state-sponsored group based in China that has been infiltrating critical infrastructure providers in the U.S. Often this botnet takes over out-of-date devices that can’t receive security patches anymore so they are ripe for picking. The report is a warning to IT and network leaders — as well as homeowners — to get rid of internet-connected equipment that isn’t supported anymore. At the very least make sure devices are regularly rebooted because that will flush some types of malware.

Unpatched servers hosting JetBrains’ TeamCity software are being exploited by Russian government hackers. That’s according to cyber authorities in the U.S., the U.K. and Poland. The Russian group, known as CozyBear, Nobelium or APT29 by security researchers, has been exploiting a vulnerability since September. Because TeamCity is used by software developers, a successful hacker gets access to source code and signing certificates that can be used to authenticate malware — everything needed for a supply chain attack. Companies using compromised and internet availableTeamCity servers have been found in the United States, Europe, Asia, and Australia. They include an energy trade association, internet hosting providers and more. Administrators of TeamCity who haven’t applied recent patches or workarounds should assume their servers have been compromised and take action.

Here’s another example of someone not configuring a database properly and leaving it open in the internet. It was discovered by security researcher Jeremiah Fowler and appears to belong to an American company that makes a cloud-based management suite for nonprofits. It has subscribing organizations around the world. Had someone found this particular database they would have been able to download over 460GB of data. Fowler saw a document from a hospital charity that named a child, their medical conditions and their doctor. This is another reminder that organizations have to make sure all employees handling the personal data of customers and employees know how to protect data from exposure. In addition IT leaders have to constantly watch data stores created by employees for security breaches.

On a November podcast I told you that personal information of staff working at the Idaho National Laboratory, a federal nuclear energy research facility, had been stolen. The number of victims has now been released: It’s just over 45,000 current and former employees, their spouses and dependents. The notice to victims says the data was stolen from an off-site data centre and not the lab’s IT system.

Finally, users of the Discord voice, video and chat app can now use security key-based multifactor authentication to protect their accounts from being hacked. That means they can use Windows Hello, Apple Face ID, Touch ID or physical security keys for logging in to Discord.

That’s it for this podcast. However, later today the Week in Review edition will be available. Guest Terry Cutler of Cyology Labs will join me to discuss a report on the readiness of the U.K. to face malware, why applications with old versions Log4j is still being compromised and more.

Follow Cyber Security Today on Apple Podcasts, Google Podcasts or add us to your Flash Briefing on your smart speaker.

The post Cyber Security Today, Dec. 15, 2023 – A botnet expands, threats to unpatched TeamCity servers, and more first appeared on IT World Canada.

Hashtag Trending Dec.15- Dropbox’s new AI feature raises privacy concerns; Intel’s AI-enabled chip for PCs; X’s ad revenue continues to plunge

Dropbox communication slip up has users thinking their AI search may compromise their privacy, Intel launches its AI enabled chip for PCs. What might be behind OpenAI’s partnership with a German publishing group and our final installment of the X files for 2023. 

The Musk is out there.



 

I’m your host Jim Love, CIO of IT World Canada and Tech News Day in the US.

Dropbox’s new AI feature raises privacy concerns. Dropbox recently introduced a feature that automatically shares user data with OpenAI for an AI-powered search tool, causing unease among its users. 

This setting, enabled by default, only shares data when the feature is actively used, and Dropbox assures that the data isn’t used to train AI models and is deleted within 30 days. Despite these assurances, the default activation of this feature led to user discontent. 

Dropbox CEO Drew Houston apologized for the confusion, clarifying that no data is sent to third-party AI services without explicit user action. Critics argue that Dropbox could have communicated this change more transparently. 

The feature, part of the “Dropbox AI alpha,” allows users to interact with a ChatGPT-style bot for file inquiries. Dropbox emphasizes user control over the feature, which can be easily disabled in account settings. Currently, OpenAI is the sole AI provider for this Dropbox feature.

Sources include: ArsTechnica 

Intel Sees Growing Adoption of AI Chips in PCs  

Intel announced that dozens of manufacturers are utilizing its latest processors enabled with AI acceleration technology. The chip, with the code name Meteor Lake was developed specifically to handle AI workloads on laptops and desktops.

By embedding specialty AI circuitry – a neural processing unit within central processors, Intel promises to make AI more accessible in mainstream computing.

Wide adoption by major PC brands like Dell, Microsoft and Lenovo demonstrates burgeoning demand for on-device AI. Intel is positioning itself at the forefront with dedicated silicon tailored to intensive neural network computations. 

This new chip is only the first salvo as Intel ramps up to compete with Nvidia and AMD in this crucial new area. The company said it was working on a new chip called Gaudi 3 (again, I have to ask who makes these names up?)  Anyway, Intel hopes its new Guadi 3 will have what it takes to take on Nvidia in particular.  

Sources include: Reuters

European Union to classify gig workers as employees using the “duck test.” You know the saying – if it walks like a duck and talks like a Duck.

After two years of negotiation, the European Council and Parliament have reached a provisional agreement to reclassify many gig workers as employees. 

This change affects those who use apps for tasks like food delivery or taxi services. Currently, most of the EU’s 28 million platform workers are self-employed, but about 5.5 million may be misclassified. 

The new directive sets criteria for determining employment status and limits algorithmic management of workers. Workers will be considered employees if they meet at least two of five conditions related to payment caps, performance supervision, task allocation, control over working conditions, and discretion in work execution. 

The agreement also mandates human decision-making in dismissals and restricts the use of personal data for profiling or predicting union activity. The European Trade Union Confederation has welcomed the agreement, highlighting its potential to address issues of false self-employment and ensure fair labor rights.

Sources include: The Register

In recent events, the EU has passed the EU AI Act, which stipulates that foundation models must comply with specific transparency obligations before being placed on the market. The EU differentiates general-purpose AI models based on risks, and OpenAI falls under the high-risk category. Axel Springer’s partnership would assist OpenAI in demonstrating to EU officials that it has not used stolen data to train its models.

It turns out that OpenAI’s partnership with European global publisher Axel Springer may be much more strategic than it first appears. 

Axel Springer publishes Politico and Business Insider into ChatGPT. This collaboration, which also includes compensation for Axel Springer, aims to improve GPT-4’s capabilities. 

This move follows OpenAI’s earlier partnership with the Associated Press. 

But here’s where the strategy piece lies.  

OpenAI has a strained relationship with the European Union, especially after Germany considered banning ChatGPT over privacy concerns. 

This collaboration could help OpenAI navigate the EU’s new AI Act, which imposes strict transparency obligations on high-risk AI models like those of OpenAI. 

The partnership also comes amidst competition from Grok, which offers real-time information access. And there is also competition coming from Open Source like Mistral AI.  Open source companies are exempt from the EU’s legislation.

One drawback is that OpenAI’s decision to partner with a specific media house could introduce bias into ChatGPT’s responses, which is a concern for OpenAI’s safety team. 

Despite potential drawbacks, this partnership is seen as a strategic move to and potentially one which could enhance ChatGPT’s accuracy and reduce misinformation.

Sources include: Analytics India 

Elon Musk’s X (formerly Twitter) is facing a significant downturn in advertising revenue. Insider sources revealed that X expects to end 2023 with around $2.5 billion in ad revenue, a substantial drop from previous years and half a billion short of its $3 billion target. 

In 2022, Twitter generated over $1 billion in ad revenue per quarter, but X has only managed a little over $600 million in each of the first three quarters of 2023. 

The recent advertiser fallout over antisemitic content on X, estimated to have caused a $75 million loss, further clouds the fourth quarter’s outlook. Advertising earnings, which comprise 70-75 per cent of X’s revenue, suggest total earnings of roughly $3.4 billion in 2023, including subscriptions and data licensing deals. 

If the damage caused by anti-semetic tweets wasn’t enough, Musk has doubled down by allowing Alex Jones, who denied the Sandy Hook massacres, to be allowed back on Twitter. How that will win new advertising revenue is a bit of a mystery to us mere mortals.

X’s head of business operations, Joe Benarroch, emphasized that X should no longer be compared to Twitter, as it is now an evolving business with multiple revenue streams. 

Amidst these challenges, X is attempting to attract more users and content creators with ad revenue sharing, but the current advertiser boycott and Musk’s controversial statements and behaviours may hinder these efforts.

Sources include: ArsTechnica 

Amazon’s ‘Alexa, thank my driver’ campaign has returned. 

Amazon has brought back its initiative to appreciate delivery drivers during the holiday season. By saying “Alexa, thank my driver,” customers can express their gratitude, and the first two million drivers to receive thanks will also get a $5 bonus from Amazon. 

This gesture acknowledges the crucial role of delivery drivers in the holiday economy, from stocking shelves to sorting packages. To thank a driver, users can simply use their Echo device or the Amazon shopping or Alexa app. The ‘Thank my driver’ feature is available for deliveries made within the past 14 days. 

After the first two million drivers have been thanked, customers can still express gratitude, but no monetary reward will be included. Additionally, customers can show appreciation by leaving snacks and refreshments or small gifts for their regular delivery drivers. This campaign is a way for Amazon to recognize the hard work of drivers during the busiest time of the year.

Sources include: ZDNet 

And that’s what’s trending today.

Hashtag Trending goes to air 5 days a week with a special weekend interview show we call “the Weekend Edition.” We’ll be off the air with the daily show until January 8th, but I’ll be doing a few live shows through that time, so keep checking on us.

One last request for this year – two actually.  One let me know how we are doing.  Are we hitting the right articles for you? Do you want to hear more of one thing and less of another. I’d love to use this in our planning for the coming year. Write to me at jlove@itwc.ca – it’s easy. J for Jim. Love and then itwc.ca for IT World Canada. jlove@itwc.ca Or just leave a comment after the show notes posted on itworldcanada.com 

And if you have enjoyed this podcast this year, why not send it to a friend and let them know about us. You can send them an email or post it to social media. You can find a shareable version at ITWorldCanada.com/podcasts

You can get us anywhere you get audio podcasts and there is a copy of the show notes at itworldcanada.com/podcasts 

I’m your host Jim Love.  Have a Fabulous Friday and a Happy Holiday.

The post Hashtag Trending Dec.15- Dropbox’s new AI feature raises privacy concerns; Intel’s AI-enabled chip for PCs; X’s ad revenue continues to plunge first appeared on IT World Canada.

Big budgets, laggard IT systems: Government officials questioned at House of Commons committee

The Benefit Delivery Modernization (BDM) program, the largest IT transformation initiative ever undertaken by the Government of Canada, was estimated to cost $1.75 billion when it launched in 2017. Five years later, the cost estimate reached $2.2 billion, and chances are it will be revised again, as delays and challenges persist, deplored Andrew Hayes, deputy auditor general, during a House of Commons Standing Committee on Public Accounts (CAPH) meeting today.

Halfway through the program’s 13 year timeline, we’re “still running on systems that are between 20 and 60 years old,” he added.

BDM is tasked with transforming how three key programs: Employment Insurance, the Canada Pension Plan, and Old Age Security benefits, are delivered to Canadians. Paul Thompson, deputy minister, Department of Employment and Social Development said that the transformed systems will be safer, agile and capable of delivering a better customer experience.

So far, Public Services and Procurement Canada (PSPC) has spent $817 million on the program, out of the $2.2 billion cost estimate, which includes $669 million in contracts with outside consultants. Four main system integrators, including Accenture, CGI Information Systems, Deloitte, and Fujitsu Consulting, account for the majority of that amount, said Thompson. And there are yet other million dollar contracts with IBM and Price Waterhouse Cooper (PwC).

“We’re approaching a billion dollars. These are astronomical figures. They’re immense, and they’re heavy for Canadians. And all this spending has led to the brutal findings from the Auditor General, warning of another Phoenix,” said NDP representative Blake Desjarlais.

A recent report from the Office of the Auditor General of Canada (OAG), in fact, showed that two-thirds of the government’s 7500 software applications were in poor health. Of those, 562 are essential to the health, safety, security, or economic well being of Canadians. Some of the systems date back to the early 1960s.

Canada’s chief information officer, Catherine Luelo, who appeared via videoconference, said, “We spend about $10 billion a year on technology, but I’m not sure this is about more money at this stage.”

The biggest challenge, she said, is a lack of skilled personnel in the public sector to carry out modernization.

“The reality is that there’s recruitment and retention challenges. It is a competitive marketplace for skilled IT professionals, which means that the government has to look creatively at how to retain and attract these people, but also has to take a good careful look at how they will train and upskill their current employees.”

Plus, she said, “we’re not paying our staff enough.”

Desjarlais added, “It’s much easier to work for IBM, it’s much easier to work for McKinsey, it’s much easier to work for these other companies that then hold the government hostage and say, ‘you will pay us because there’s no one else to do this work’, because you failed to pay our employees properly or at least a competitive rate.”

Audit after audit showed a continued pattern of outsourcing, which balloons cost while also diminishing public service, lamented Desjarlais.

However, Luelo maintained that modernization will be impossible without third party help. Hiring challenges, labour intensity and the volume of work all contribute to the decision to bring in third party firms.

Further, Luelo pointed to a lack of a central control around the disbursement of funds when it comes to modernizing Canada’s IT systems.

She explained that when she was a CIO in the private sector, she had the ability to set the strategy and then control the funding, meaning that there was a level of control when there was a sign-off on technology work that went across multiple divisions of publicly traded organizations. 

“That same level of oversight [in the government] does not exist. We are in a very vertical model for many good reasons. But these are horizontal problems, and we don’t have, in my opinion, the right horizontal financial controls in place on technology investment.”

Within the government, there’s also an issue of prioritization that staggers progress, as not all issues can be addressed at once, Luelo said.

“In prioritization, there’s winners and losers, and we don’t seem to have a comfort with stopping programs or delaying them to allow us to do the work that needs to happen on the higher risk program.”

Scott Jones, president of Shared Services Canada, explained that the information upon which priority decisions are made also delays progress.

“Departments themselves are responsible for modernizing their applications,” he said. “They sometimes have to make difficult decisions with their financing because if they have to pay for modernization, it might have to come out of the funds that they would otherwise use for services or programs for Canadians.”

During the committee meeting, Luelo also addressed her recent resignation.

“I would observe within the public service, I’m used to being in meetings talking about delivery velocity, talking about budgets, talking about change management, talking about adoption, talking about ‘the doing’. And what I find is we spend more talking about ‘the what we might do’ versus actually talking about the ‘how we’re doing it and the result’, and my opinion is that needs to change.”

The post Big budgets, laggard IT systems: Government officials questioned at House of Commons committee first appeared on IT World Canada.

Rogers and Lynk complete satellite-to-mobile phone call, 2024 launch anticipated

Rogers and Lynk Global have announced that they have completed a successful satellite-to-mobile phone call, using Samsung Galaxy S22 smartphones.

The two companies also tested SMS, data, and emergency alerting services.

Newfoundland and Labrador Premier Andrew Furey conducted the call with a NL Search and Rescue volunteer, using Lynk’s low-earth orbit (LEO) satellites and Rogers national wireless spectrum.

Watch Premier Furey and Mabel Tilley (First Responder, Newfoundland and Labrador Search and Rescue Association) making the test call here.

“Newfoundland and Labrador is a vast, largely rural province, and connectivity is an important issue for us,” said Furey. “As Premier, I am excited about the breakthrough technology Rogers is testing to improve network coverage and the safety of people in our province and across the country.”

The call was conducted in Heart’s Content, NL, where the world’s first transatlantic telegraph cable transmission took place between Canada and Ireland, over 150 years ago.

Rogers said it will launch satellite-to-mobile phone technology in 2024, starting with SMS texting, mass notifications, and machine-to-machine AI applications, and then expand the service to include voice and data services.

Wireless spectrum ensures this technology works on existing smartphones so customers don’t need to install customized apps or not yet available hardware.

“We’re bringing coverage to Canada’s most remote areas to improve public safety and to connect communities that aren’t connected today,” said Tony Staffieri, president and chief executive, Rogers. “We’re proud to work with Lynk to bring Canadians the very latest global technology that will give them access to 911 and wireless services.”

Last month, Telus also used satellite connectivity to conduct voice calls, send text messages between smartphones, and connect to IoT devices, partnering with non-terrestrial-network (NTN) service provider Skylo and wholesale satellite services provider TerreStar.

The company also has made plans to introduce devices equipped with 5G satellite capabilities to customers in 2024.

The post Rogers and Lynk complete satellite-to-mobile phone call, 2024 launch anticipated first appeared on IT World Canada.

Hashtag Trending Dec.14- White House wades in open source AI debate; Cloudflare’s 2023 web report; Google Cloud partners with Mistral AI

White House dives into open source AI debate, bots boom and Google comes back to the top spot in Cloudflare’s 2023 web report, Google Cloud partners with Mistral AI on generative language models and Google admits that its demonstration of Gemini was what it “could” be like. All that, and the ultimate Canadian Christmas gifts on Hashtag Trending.



 

I’m your host Jim Love, CIO of IT World Canada and Tech News Day in the US.

The Biden administration is wading into the debate  on the potential benefits and risks of open-source AI. The National Telecommunications and Information Administration (NTIA) is spearheading the initiative, aiming to determine whether freely accessible AI models can make society safer or unleash unforeseen dangers.

This move comes amid rising concerns about the potential misuse of AI and worries about the easy accessibility of open-source models.

Proponents of open-source AI argue that it fosters transparency and collaboration, allowing researchers to identify and mitigate biases and vulnerabilities in AI systems. 

Critics warn that open access could enable bad actors to exploit these models for malicious purposes or even weaponize them. 

The NTIA’s involvement signals the Biden administration’s commitment to shaping the responsible development and deployment of AI. 

Their efforts will involve convening stakeholders from academia, industry, and civil society to hash out a framework for open source AI that hopefully balances innovation with safety.

Sources include: Axios 

Cloudflare published its 2023 Year in Review and here are some of the key takeaways.

Global internet traffic increased by 25 per cent, driven by device connectivity and content consumption.

After a brief TikTok reign, Google recaptured the top spot as the most visited website.

Mobile devices now generate over 42 per cent of global internet traffic, with Android dominating most regions. Surprisingly, Finland, the land of Nokia, boasts the highest desktop traffic (80 per cent) globally.

Satellite internet provider Starlink tripled its traffic in 2023, showing rapid growth wherever it lands.

Bot Boom – Bot traffic surged by 33 per cent, with one-third originating from the US. 

However, Cloudflare notes that not all bots are malicious. 

IPv6 Lags: Despite years of anticipation, IPv6 adoption remains sluggish, with only 33.75 per cent of traffic on Cloudflare’s network utilizing the “next-generation” protocol.

You can explore the full report with interactive charts and graphs.  A link is included in the show notes at itworldcanada.com/podcasts 

 https://radar.cloudflare.com/year-in-review/2023

Sources include: https://radar.cloudflare.com/year-in-review/2023

We did a story on Mistral yesterday – it’s a new AI that is making waves because of its faster and cheaper training and operations, the fact that it rivals OpenAI 3.5 and beats other models in terms of its speed, accuracy and performance.  And oh yes, it’s open source.

Today Google Cloud announced a new partnership with Mistral AI to provide access to the generative language model via its cloud platform. Mistral integration with Google Cloud allows it to scale up rapidly, taking advantage of Google’s infrastructure, security and experience.

This partnership follows on the disappointing launch of Google’s Gemini, with allegations that the cloud giant may even have misled people with its video unveiling of its new AI update.

Sources include: Reuters 

And on that story Google acknowledged it may have misrepresented the capabilities of its Gemini AI chatbot during what was presented to appear as a live demo. 

The video that the company issued had been selectively edited to make it seem like the AI was having a real time conversation and responding to someone drawing in real time. This was not the case.

The actual demo was done with a text interface and still pictures.  

And Google’s response to the criticism that follows is:

Google’s vice president of research, Oriol Vinyals wrote a post on X which said “The video illustrates what the multimode user experiences built with Gemini could look like.” 

Operative word is COULD. 

The revelation demonstrates the gray area emerging around marketing language for generative AI products. There are already reports of tricks used to fool benchmark tests by including the questions in the model training set – like bringing crib notes to an exam in the old days.

There’s a lot of talk about responsibilities and guardrails to keep AI from misleading the public. Maybe we need a little more focus on human responsibility. 

As public excitement builds, and competition increases, tech companies feel pressure to position themselves as leaders.  

While showcasing AIs that can mimic human conversations generates buzz, responsibly portraying current limitations is what will foster public trust. 

Sources include: Yahoo News 

And this has nothing to do with technology, other than it’s digital marketing,  but our editor sent it to me and it’s delightful.

Expedia is partnering with Destination Canada to unveil a new tourism campaign focused on boosting travel to Canada. Dubbed “YesYouCanada,” it aims to inspire Americans to visit by highlighting unique Canadian destinations and experiences.

The promotion leans into playful Canadian stereotypes while showcasing the country’s vibrant culture and stunning landscapes. Example itineraries feature dog sledding, NHL games, and trips to see the Northern Lights.  

But the promotion also features for $20.23 each, and bookable on a first-come, first served basis, the right to name:

A resident moose at the Yukon Wildlife Preserve in the Yukon

limited-edition beer at Container Brewing in Vancouver, British Columbia

train seat on the Rocky Mountaineer that crosses the Canadian Rockies

storm-watching hot tub at the Black Rock Oceanfront Resort on Vancouver Island

polar bear at Churchill Wildlife Management Area in Churchill, Manitoba

pond hockey team at Elk Ridge Resort in Saskatchewan

potato field at FarmBoys Inc. on Prince Edward Island

golf hole at Fairmont Chateau Whistler Golf Club in Whistler, British Columbia

An ice fishing shack on Lake Winnipeg in Gimli, Manitoba

canoe at the iconic Fairmont Chateau Lake Louise in Banff, Alberta

And my personal favourite – a bar stool at the Rundle Lounge inside the Fairmont Banff Springs Hotel in Banff, Alberta

The press release notes that this “The chance to name one of these items after a loved one comes at a perfect time as many of us are struggling to finish up holiday shopping lists.” 

Like everyone whose been married for more than forty years, I’m always struggling to find a new idea. But I’m not sure about giving my wife a moose named after her. Maybe I’ll go for the beer.

Is this working? Expedia says they are seeing surging search queries for Canadian vacations. 

Sources include: Multivu

And that’s what’s trending today.

Hashtag Trending goes to air 5 days a week with a special weekend interview show we call “the Weekend Edition.”

You can get us anywhere you get audio podcasts and there is a copy of the show notes at itworldcanada.com/podcasts 

I’m your host Jim Love.  Have a thrilling Thursday!

The post Hashtag Trending Dec.14- White House wades in open source AI debate; Cloudflare’s 2023 web report; Google Cloud partners with Mistral AI first appeared on IT World Canada.

Provincial privacy commissioners oppose proposed federal privacy tribunal

Privacy commissioners from Alberta, B.C., and Quebec say the proposed overhaul of Canada’s federal privacy law shouldn’t add an appointed privacy tribunal to hear appeals of certain decisions made by the national privacy commissioner.

Instead, they argued Tuesday before the House of Commons industry committee, any objections or appeals should go straight to a court — as they do now both federally and in the three provinces that have their own privacy laws covering the private sector.

The commissioners echoed the argument of the current Privacy Commissioner Philippe Dufresne and the former Commissioner Daniel Therien that the proposed creation of a new Personal Information and Data Protection Tribunal will be a waste of time and money.

The data privacy tribunal was added when the proposed Consumer Protection Privacy Act (CPPA) increased the powers of the federal Privacy Commissioner to issue compliance orders and recommend multi-million dollar fines for violating the CPPA. If businesses don’t like the decision of the tribunal they could then appeal to the Federal Court.

But firms can now go directly to the Federal Court if they don’t like certain rulings of the Privacy Commissioner under the current law. Critics say inserting the privacy tribunal between the Privacy Commissioner and the Federal Court will only cause delays in respecting privacy law.

The CPPA is part of Bill C-27, which includes legislation creating the tribunal and the Artificial Intelligence and Data Act (AIDA) for regulating high-risk AI systems.

“It is critical that when privacy regulators are able to ensure that, when fines are necessary for multi-jurisdictional violations, they are levied in a co-ordinated, proportionate and non-overlapping way,” B.C. privacy commissioner Michael McEvoy told MPs. “That is not simply possible under Bill C-27, which strips away power from the federal Privacy Commissioner to levy fines and instead puts it in the hands of a third party (the tribunal) that would not be in a position to co-ordinate matters with other authorities.”

“If a party were concerned about an imposed fine, a direct referral to the court system is more than adequate to ensure administrative oversight.”

While McEvoy agreed some organizations might consider a fine a cost of doing business, the CPPA also gives the federal privacy commissioner another new weapon: The ability to issue orders to firms to “stop doing what you are doing.”

Also testifying were Diane Poitras, president of the Commission d’accès à l’information du Québec and Diane McLeod, Information and Privacy Commissioner of Alberta.

McEvoy also said the federal political parties should also have to comply with the data collection rules of the CPPA. Poitras and McEvoy noted that provincial political parties have to follow their provincial privacy laws.

The Liberal government has proposed the Elections Act be changed to require federal political parties to have privacy policies for the collection of personal data. That was described as inadequate by Dufresne.

McLeod said C-27 is “an important step in modernizing Canada’s privacy sector privacy law.” But she worried about a proposed exemption for businesses from getting consent for personal data collection under certain circumstances. The proposed exemption (S.18) says an organization may collect or use an individual’s personal information without their knowledge or consent if the collection or use is made for an activity in which the organization has a legitimate interest that outweighs any potential adverse effect on a person. There are two conditions: A reasonable person would expect the collection or use  of personal data for such an activity; and the personal information is not collected or used to influence an individual’s behaviour or decisions.

Worries about how this exemption will be used by firms has also been raised by other witnesses.

Hearings on C-27 will resume in January.

The post Provincial privacy commissioners oppose proposed federal privacy tribunal first appeared on IT World Canada.

Cyber Security Today for Wednesday, Dec. 13, 2023 – Mystery surrounds the outage at a ransomware gang’s site, and more

Mystery surrounds the outage at a ransomware gang’s site, and more

Welcome to Cyber Security Today. It’s Wednesday, December 13th, 2023. I’m Howard Solomon, contributing reporter on cybersecurity for ITWorldCanada.com and TechNewsday.com in the U.S.



The official data leak site of the AlphV/BlackCat ransomware gang was still down on Tuesday afternoon, when this podcast was recorded. That would make it the sixth day in a row the site has been inaccessible. According to researchers at RedSense, the gang believes an unnamed law enforcement agency or agencies is responsible. In a tweet RedSense said the gang’s administrator has told others that “everything will work soon.”

Administrators with Netgate’s pfSense open-source firewall should install the latest patch. It closes two cross-site scripting vulnerabilities and a command injection vulnerability. According to researchers at SonarSource, there are patches for pfSense Plus, and the community edition of the firewall.

There are two new reports about fraudulent job application emails:

A threat actor who has been phishing for corporate victims for years by replying to job listings has added a new tactic: Trying to trick personnel recruiters. That’s according to researchers at Proofpoint. The group, which has been dubbed TA4557, recently started emailing headhunters saying they are interested in being hired for a corporate position. Their updated resume is available on the so-called applicant’s personal home page. Here’s the trick: Knowing that for security reasons people may be reluctant to click on a link in an email, or that an email scanner may block a link, the threat actor offers an alternative: To see the so-called resume the recruiter is asked to use the domain name in the email. So if the applicant’s email address is “john[at]johnjones[dot]com.” the recruiter themselves would go to “www[dot]johnjones[dot]com.” That’s probably to convince the recruiter that the so-called applicant is security-conscious. The alleged personal website looks real, but it leads to the downloading of malware. People in HR either responding to job postings or emailed cold-calls need to be aware that behind every message could be a crook.

Separately, researchers at Nisos say hackers believed to be from North Korea are applying for IT jobs with American companies. Their goal is to infiltrate organizations and steal data that can help in North Korea’s weapons development. These applicants claim to have expert programming skills, and may even say they live in the U.S. Those involved in the scheme aren’t very sophisticated because they have created several web pages on IT networking sites with resumes that have different names but the same photo.

SAP issued 17 new or updated security patches this week, including four HotNews Notes and four High Priority Notes. According to researchers at Onapsis, two of the updates are follow-ups to an operating system vulnerability patched in July. Another addresses a critical escalation of privileges vulnerability in the SAP Business Technology Platform.

The U.S. telecommunications regulator has — again — reminded wireless carriers that they have to protect their customers from threat actors. In particular the Federal Communications Commission has warned carriers to find ways of preventing crooks from convincing them to digitally switch the SIM cards in phones of customers. SIM-card swapping is one of the ways threat actors can get control over a victim’s phone and from there access victims’ personal and corporate email and possibly their bank account. Failure to reasonably protect customer information is a violation of federal law and FCC rules. This reminder comes after the FCC last month issued new rules carriers that have to follow to prevent scams.

There’s a link between a threat group nicknamed Sandman and suspected Chinese-based groups. That’s according to researchers at SentinelLabs, Microsoft and PwC. The link is that Sandman’s malware and a backdoor used by suspected Chinese groups have been seen together in the IT environments of some victim organizations. The belief is these groups share infrastructure control and attack management practices. The researchers aren’t sure if this is one group, so for the time being they are being monitored individually. Their report includes indicators of compromise that defenders can watch for.

There’s a new version available of Apache Struts, an open-source framework for creating Java web applications. It fixes a critical vulnerability that could allow an attacker to do nasty things.

Finally, yesterday was December’s Patch Tuesday, when Microsoft and others released security updates. There are 34 Windows fixes available. In addition, Atlassian released patches for four critical vulnerabilities. They include fixes for Confluence Data Center and Confluence Server, the cloud, server and data centre versions of Jira, and Atlassian Companion for MacOS.

Follow Cyber Security Today on Apple Podcasts, Google Podcasts or add us to your Flash Briefing on your smart speaker.

The post Cyber Security Today for Wednesday, Dec. 13, 2023 – Mystery surrounds the outage at a ransomware gang’s site, and more first appeared on IT World Canada.

Hashtag Trending Dec.13- Epic Games’ legal victory over Google; NY Times has an editorial director of AI; Is ChatGPT slowing down because of Christmas?

Epic Games scores Epic victory over Google, The New York Times appoints an editorial director of AI, an upstart Paris startup is challenging some of the big players with a smaller open source model and is ChatGPT slowing down because Christmas is approaching?



 

These and more top tech stories on Hashtag Trending

I’m your host Jim Love, CIO of IT World Canada and Tech News Day in the US.

Google Workspace has added a feature allowing users to record their name’s pronunciation on their profile card, aiming to reduce mispronunciations. This update, applicable to Google Docs and Gmail, lets colleagues hear the recorded name by clicking a play button next to the user’s name. 

The feature, which rolled out on December 11, is on by default but can be disabled by admins. It’s available for various Google Workspace accounts, including Business and Enterprise levels, as well as Google for Nonprofits customers. 

This feature already exists in other workplace applications like Slack and LinkedIn.

For me this is more of a public service announcement than a news story. As someone who struggles with names constantly, I didn’t know that this was already on LinkedIn or Slack.  It’s easy on both – once you know it’s there – google it.

Sources include: ZDNet

Epic Games’ legal victory over Google may have far-reaching impacts

Google’s legal defeat to Epic Games over its Play Store’s practices could have significant financial implications, potentially costing billions in revenue. A California jury found Google’s Play Store to be an illegal monopoly, leading to potentially major changes in how it operates. The ruling increases scrutiny on Google amidst other antitrust battles and may also have some implications for Apple’s app store, although Apple won their suit with Epic. 

An appeal process could delay these changes for years.

The final outcome remains uncertain as that lengthy process begins.

Sources include: Reuters

The New York Times has appointed Zach Seward as the editorial director of artificial intelligence initiatives

This move reflects the growing interest in AI within media organizations. Seward, co-founder of Quartz, will collaborate with newsroom leaders to define AI usage principles, focusing on ethical considerations and public trust. His role includes forming a team to explore AI tools, developing journalist training programs, and guiding the use of AI to enhance journalistic work.

The Times said that Seward was selected in part because of his support for journalists and their critical role in news, indicating they are pursuing AI as a supporting technology and not a way to replace journalists.

Sources include: Axios

U.S. Border Security Innovations: AI and Robotic Enhancements

The U.S. is enhancing border security with AI and robotics, including AI-powered vehicle and cargo scanning and robot dogs for patrol. Pangiam and West Virginia University are developing AI algorithms for unusual movement detection, while Altana will assist in tracking precursor chemicals for fentanyl. DHS’s research arm is collaborating with Ghost Robotics on robot dogs capable of transmitting real-time data. These advancements come amid staffing shortages and concerns over data transparency and use in surveillance.

Sources include: Axios article one and Axios article two.

And an upstart Paris-based startup, is challenging the dominance of OpenAI, Google, and Meta with its new open source model, Mixtral 8x7B. 

This model, which integrates Sparse Mixture of Experts architecture, has been released with an open-source license and is extremely competitive in its performance on industry benchmarks. 

 “Mixture of Experts” allows models to be pre-trained and using far less compute making it cheaper and faster to train and scale up.

Despite that, Mixtral equalled ChatGPT 3.5 on tests and surpassed Llama 2 70B on most benchmarks with 6x faster inference.

Mistral AI has recently raised substantial funding and is launching ‘La Plateforme’ for API endpoints of its models. That and the fact that it offers three models, Mistral Tiny, Mistral Small and is charging for the use of  the yet to be released Mistral medium, gives it two revenue sources.  So even though it is an open-source company, it’s valuation is already potentially more than two billion dollars.

Obviously, there is still room to compete in the AI model business.

Sources include: Analytics India Magazine 

Users of ChatGPT have observed a perceived decrease in effort from the AI.  OpenAI has admitted there is a problem but has said that they have not made changes to the model that could cause this. 

This has led to some speculation, most of it based on anecdotal evidence. One of these is the “winter break hypothesis.” This unproven idea suggests that ChatGPT mimics human behavior by slowing down in December

Tests on response lengths for different dates have shown some indications of this, but it’s really difficult to do effective tests given that generative AI models don’t produce the exact same results each time. 

But the fact that the problem exists and the December hypothesis is as good of a guess as anything else, reveals  the unpredictable nature of large language models (LLMs) and how little even their creators know about the behaviour.

Sources include: ArsTechnica.  

And that’s what’s trending today.

Hashtag Trending goes to air 5 days a week with a special weekend interview show we call “the Weekend Edition.”

You can get us anywhere you get audio podcasts and there is a copy of the show notes at itworldcanada.com/podcasts 

I’m your host Jim Love.  Have a Wonderful Wednesday!

The post Hashtag Trending Dec.13- Epic Games’ legal victory over Google; NY Times has an editorial director of AI; Is ChatGPT slowing down because of Christmas? first appeared on IT World Canada.