Category: News

Coffee Briefing Dec. 12- Lighthouse Labs’ new cyber upskilling program; Extended security updates for Windows 10; Canada’s AI code of conduct has new signatories; and more

Coffee Briefings are timely deliveries of the latest ITWC headlines, interviews, and podcasts. Today’s Coffee Briefing is delivered by IT World Canada’s editorial team! 

Missed last week’s Coffee Briefing? We’ve got you covered.

Lighthouse Labs launches new cyber upskilling program

Tech education company Lighthouse Labs has launched a new upskilling program for its Cyber Security Bootcamp in partnership with Upskill Canada, to help narrow the cyber security skills gap in Canada and provide cyber security training to 350 Canadian workers.

The program is also supported by funding from Innovation, Science and Economic Development Canada’s (ISED) Upskilling for Industry Initiative, tasked to connect more than 15,000 Canadians with work opportunities.

A 12-week program, the Cyber Security Bootcamp will be targeted towards working professionals that have at least three years of relevant industry experience, the company said. Topics covered include server administration, network security, threat modelling and more. Students will also have access to on-demand mentorship from industry experts in addition to the support of Lighthouse Labs’ Student Success Coordinators and Career Services team.

This announcement comes as Upskill Canada and Deloitte jointly released a report highlighting the rapid growth of Canada’s cyber sector, with total employment in that sector going up by 12.2  per cent from the previous year to 139,000 in 2022.

However, the same report sheds light on the struggles that organizations face to recruit cybersecurity staff, as there is a shortage of highly skilled and experienced professionals, and an excess of junior-level talent.

“The Lighthouse Labs Cyber Security Bootcamp, powered by Upskill Canada, will enable businesses to take advantage of untapped talent, and incentivize professionals to learn the skills needed to transition to a job in cyber security,” said Jeremy Shaki, chief executive officer, Lighthouse Labs. “Through this national talent platform, we’re helping fast-growing companies access the talent they need while creating new pathways for workers to transition into high-demand roles.” 

Picsume wins $20,000 ScaleUP prize

Amherstburg, Ont.-based hiring platform Picsume has won a prize of C$20,000 for being top performer of the seventh cohort of ScaleUP, a four-month accelerator program launched by WEtech Alliance and powered by Libro Credit Union and Invest WindsorEssex, which provides one-on-one mentoring, cohort sessions, and access to provincial, national, and global networks of programs and mentors that is valued at over C$15,000.

Picsume pitched its growth over the course of the accelerator program in front of a group of investors and industry experts, and outperformed three other companies from the graduation class of the seventh cohort.

Picsume seeks to eliminate the need for a resume through the creation of live dynamic work profiles. Its proprietary technology also extracts current job postings to its platform, pairing candidates directly with employers through curated opportunities across Canada. It has also built out a software and application tracking system (ATS) to assist with recruiting and hiring for SMBs. 

The ScaleUp program has seen over 30 graduates, C$26 million in revenue earned, 147 new products and services brought to market, and 184 jobs created, to date.

Applications for the eighth cohort will open in summer 2024.

Montreal company introduces AI content detection model with 99.98 per cent accuracy rate

AI company Winston AI has introduced an AI detection model, codenamed “Luka”, capable of differentiating AI-generated synthetic content from human creations with, the company said, a 99.98 per cent accuracy rate.

The company backs the accuracy of its model with a human-validated dataset of 10,000 texts, including an equal mix of human and AI-generated content from prominent models like ChatGPT and Claude. Winston AI’s model then employs stringent probabilistic evaluation methods to provide an assessment on whether the content was either human or AI generated.

“Machines are now creating the vast majority of the content humans consume,” said John Renaud, president of Winston AI. “It has never been more imperative to be able to detect synthetic content. Our latest detection model, with its industry-leading accuracy rate, represents our unwavering commitment to integrity and transparency in AI detection. It’s not just about distinguishing content; it’s about preserving the authenticity of human expression.”

The complete study, revealing the AI detection accuracy score of 99.98 per cent and a human detection accuracy score of 99.5 per cent, can be found here.

Microsoft announces extended security updates for Windows 10

Microsoft has announced that, when Windows 10’s official support ends on Oct. 14, 2025, both businesses, and, for the first time, individuals, will be able to subscribe to receive extended security updates (ESUs) for the operating system. The subscriptions may be renewed annually for three years.

“The ESU program enables PCs to continue to receive Critical and Important security updates (as defined by the Microsoft Security Response Center) through an annual subscription service after support ends. More details, including pricing, will be provided at a later date,” Microsoft said in its lifecycle FAQ. “The ESU program provides individual consumers and organizations of all sizes with the option to extend the use of Windows 10 PCs past the end of support date in a more secure manner.”

More organizations sign Canada’s voluntary AI code of conduct

Canada’s new voluntary AI code of conduct has new signatories, including AltaML, BlueDot, CGI, kama.ai, IBM, Protexxa Inc., Resemble AI and Scale AI.

IBM’s vice president and chief privacy and trust officer Christina Montgomery said, “We are pleased to join the Canadian government and other organizations in this effort to ensure the development and deployment of generative AI applications are used in smart and trusted ways.”

CGI’s president and chief operating officer, François Boulanger, said that being a signatory to the code of conduct reinforces the company plan to allocate C$1 billion over the next three years to continually expand its AI-based capabilities.

The code of conduct, announced in late September by Innovation Minister François-Philippe Champagne, identifies measures pertaining to the responsible development and management of advanced generative AI systems. 

At the time, companies like Cohere, OpenText, Appen, Blackberry, and more signed to commit to the code of conduct.

Canada’s AI voluntary code of conduct seeks to provide a bridge between now and when Bill C-27, the government’s proposed AI and Data Act (AIDA), would be coming into force.

More to explore

European political agreement paves the way for AI law

The European Union has reached agreement on the world’s first comprehensive artificial intelligence law.

BlackBerry names new CEO, will split cybersecurity and IoT businesses

BlackBerry’s new leader is the former head of its cybersecurity business unit.

Canadian mid-sized firms pay an average $1.13 million to ransomware gangs

The average ransomware payment made by mid-sized Canadian companies this year was just over $1 million, according to a new survey.

Analytics Unleashed keynoter Scheibenreif examines how ‘we shape AI, AI shapes us’

In a presentation at IT World Canada’s Analytics Unleashed on Tuesday, Gartner Distinguished VP analyst Don Scheibenreif discussed what organizations need to do in order to handle the generative artificial intelligence (GenAi) juggernaut and artificial intelligence (AI) in general.

Two charged in murders of Softimage founder and his partner

Police in Dominica have charged two American men, Jonathan Scott Lehrer and Robert Snyder Jr., with the murders of Softimage founder Daniel Langlois and his partner, Dominique Marchand, whose bodies were found in a burned-out car on Friday.

New AI Alliance to advance open source AI convenes IBM, Meta, AMD, excludes Microsoft, Google, AWS, Nvidia

IBM and Meta have partnered to form a new group, the AI Alliance, bringing together more than 50 organizations to promote open source development and innovation in artificial intelligence (AI).

Small Canadian energy producer reports cybersecurity incident

A Calgary oil and gas producer says it has suffered a cybersecurity incident that impacted certain aspects of its business.

Channel Bytes December 8, 2023 – OneSpan launches new partner program; Microsoft to offer extended security updates for Windows 10; High-end firewall market declines for third consecutive quarter; and more

Staying informed is a constant challenge. There’s so much to do, and so little time. But we have you covered. Grab a coffee and take five while you nibble on these tidbits.

Listen to the latest episode of Hashtag Trending

Hashtag Trending Dec.12- Telepathic communication with ChatGPT; BlackBerry not spinning off IoT business; Microsoft agrees to union contract terms

Listen to the latest episode of Cybersecurity Today

Cyber Security Today, Dec. 11, 2023 – Irish water treatment plant shut by cyber attack, WordPress issues a security patch, and more

Listen to the latest episode of Hashtag Tendances

If you live in Québec, or prefer to consume the latest technology news in French, our sister publication Direction Informatique has you covered. Follow them on Twitter as well.

 

The post Coffee Briefing Dec. 12- Lighthouse Labs’ new cyber upskilling program; Extended security updates for Windows 10; Canada’s AI code of conduct has new signatories; and more first appeared on IT World Canada.

Security risks after end-of-support for Windows Server and SQL Server 2012: TD Synnex weighs in

In October, Microsoft ended support for Windows Server 2012, and last year it did so for SQL Server 2012. This has left organizations vulnerable to cyberattacks, as they scramble to upgrade their servers to supported products.

TD SYNNEX’s business development manager, Microsoft Cloud, Adeeb Altaji and Maz Mohammadi, business development manager, Azure ISV, sat down with ITWC chief information officer, Jim Love, during an ITWC briefing to discuss the risks that organizations need to be mindful of during a period of technological transition.

End of support, Mohammadi explained, means that organizations will no longer receive important security updates and technical support from Microsoft in case of a cyberattack or data loss. Ransomware is also a constantly changing threat that organizations have to be wary of, he added.

“If you delay fixing your system, you’re essentially leaving the door wide open for an attack. The longer you wait, the higher the risk becomes,” he affirmed.

Even more concerning is that organizations delay upgrades either because it seems daunting, or the server is working fine. In other cases, organizations find that upgrading their servers just takes too much time, resources, and money, said Mohammadi.

But risks are increased with delays, especially given the wide prevalence of remote/hybrid work and its own associated security concerns.

End of support challenges have, therefore, given organizations a new impetus to consider moving to the cloud, explained the panelists.

For instance, under the on premises model, organizations usually have to pay for the extra years of support that come under the extended security updates program, while Azure takes care of that for free. Azure also is hybrid, so customers can manage the pace of their transition to the cloud.

“It’s there to complement and do as much as partners and customers want and need,” explained Altaji. “If they would like to move over some of their business, say their Windows Server and their SQL Server to get the extended security updates, Azure is able to do that. Or, for partners saying, ‘you know what, this is the perfect time to migrate our whole business and our whole infrastructure into the cloud and into Azure’, then Azure is able to do that as well.”

However, organizations remain unsure of the right direction to take when considering cloud adoption. To address that, TD SYNNEX first runs a free assessment to determine what the organization has on premises, what that would look like when they transition to the cloud, and whether the organization is up to standards when it comes to cost and optimization.

Then the TD SYNNEX professional services team assists the customer with migration and deployment opportunities, no matter their choice of cloud service provider. TD SYNNEX also provides funding to help alleviate the costs associated with cloud migration.

Post deployment, the company offers technical support to customers in case they run into issues.

Further, Altaji explained that TD SYNNEX hosts webinars, training and similar initiatives throughout the year to promote knowledge transfer to partners and customers.

Altaji concluded the briefing by highlighting TD SYNNEX’s ‘Empower’ program, which, he said, is “aptly named because that’s what we’re really here to do.” The program provides incentives, training, and support to help partners boost their Azure cloud practice and reach their sales and business goals.

“The business cycle doesn’t make sense for everyone, every single step of the way; the cost might be high or a timeline or resources might be tied up with other things,” explained Altaji. “That’s where we try to help alleviate some of those issues, whether it’s from a knowledge perspective, or even from promotions and funding.”

The post Security risks after end-of-support for Windows Server and SQL Server 2012: TD Synnex weighs in first appeared on IT World Canada.

Hashtag Trending Dec.12- Telepathic communication with ChatGPT; BlackBerry not spinning off IoT business; Microsoft agrees to union contract terms

A company claims it’s achieved telepathic communication with ChatGPT. BlackBerry backs down on spinning off its IoT business. One in five teenagers is using social media almost “constantly.” And did you ever think you see a union at Microsoft? And one that is negotiating the use of AI? 



 

These and more top tech stories on Hashtag Trending

I’m your host Jim Love, CIO of IT World Canada and Tech News Day in the US.

I know what you are thinking. Well, I don’t really, but if you think this is nuts, I wouldn’t blame you. 

I don’t believe in telepathy.  But if you can think something and it can be interpreted by another intelligence, even if that is artificial intelligence, what else do you call it. 

A company called MindPortal has announced the successful development of a non-invasive method for telepathic communication with ChatGPT. 

Their innovation allows users to form complete sentences in their minds and transmit them directly to ChatGPT, which, if it’s true, is significant milestone in human-AI interaction.

Based in London and San Francisco, MindPortal, is a pioneer in non-invasive brain-computer interfaces. 

It revealed its optical brain-computer interface on December 8, 2023. 

This interface enables users to interact seamlessly with ChatGPT using imagined speech. 

The project, supported by notable investors like Kleiner Perkins, 7percent Ventures, Learn Capital, Y Combinator, and prominent individuals including Luke Iseman, Julie Zhuo, Dan Siroker, and James Park, was developed by a top-tier scientific team from Oxford University, Cambridge University, Imperial College London, and advisors from DARPA.

Ekram Alam, CEO and co-founder of MindPortal, expressed the significance of this achievement, stating, “For the first time, we have enabled telepathic communication between humans and AI.” This technology translates a user’s thoughts into text, allowing real-time dialogue with ChatGPT, including follow-up questions.

Key breakthroughs of MindPortal’s technology include:

– translating brain activity related to thought into human language.

– using optical sensors in a non-invasive device to decode complex human language.

– thought-to-text from imagined speech without physical speech movements or sub-vocalizations.

– the ability to decode complete sentences in real-time, not just single words, without post processing.

In short? A direct brain-interface communication with a large language model AI, establishing a new standard for human-AI interaction.

If it’s true, this is an incredible breakthrough, and I hope it is, if only for how it could make life easier for those who have severe mobility issues. 

And I don’t want to trivialize the last point because it’s incredible. But having done that, I’d be very happy if I never had to try to type something on a virtual keyboard on my smartphone. Just sayin’

For more information, visit MindPortal’s website 

BlackBerry Ltd. has announced it is not going to spin off its internet-of-things (IoT) division as previously planned. Instead, the company will restructure to retain this unit alongside its cybersecurity segment. This decision aims to ensure both divisions operate independently and maintain profitability and positive cash flow. The news led to a 3.6 per cent drop in BlackBerry’s shares in premarket trading in New York.

In a further development, BlackBerry appointed John Giamatteo as the new CEO. Giamatteo, who has been serving as the president of BlackBerry’s cybersecurity business since 2021, brings extensive experience from his previous roles, including as president and chief revenue officer at McAfee Corp. and positions at other tech firms. BlackBerry is also in the process of selecting a consulting firm to assist with the reorganization.

Sources include:  Bloomberg’s article dated December 11, 2023

A recent Pew Research Center report reveals that nearly one in five teens is almost constantly on YouTube or TikTok, highlighting the significant role of social media in the lives of the younger generation. This finding is crucial amid ongoing discussions about the potential mental health impacts of such heavy social media usage.

The survey, which included 1,453 teens aged 13-17, found that internet use remains high, mirroring last year’s data and showing a substantial increase from the 2014-2015 survey. 

Nearly half of the teens reported using the internet almost constantly, a significant jump from 24 per cent in the earlier survey. 

YouTube remains the most popular platform among teens, with 90 per cent usage and 71 per cent accessing it daily. Other widely used platforms include TikTok (63 per cent), Snapchat (60 per cent), and Instagram (59 per cent), while Facebook (33 per cent) and Twitter (20 per cent) see declining usage.

For the first time, Pew included BeReal, an app promoting real-time photo sharing, in their survey, finding that 13 per cent of teens use it. A separate Gallup poll found that teens spend an average of 4.8 hours daily on social media, with older teens and girls being the heaviest users.

U.S. Surgeon General Vivek Murthy has warned about the dangers to kids’ mental health, ranging from sleep disruptions to suicidal thoughts. However, many teens also report that social media improves their lives by providing entertainment and reducing loneliness.

The Pew report also examined teen social media use by gender, race, age, and household income, revealing diverse patterns across these demographics. 

Sources include: Axios article on Pew Research Center’s findings and the Pew Study in full.

And let’s finish off with two Microsoft stories. 

Just when you think they’d weathered the worst crisis ever in their AI business….

Microsoft faces a potential investigation by the US Federal Trade Commission (FTC) regarding its significant investment in OpenAI. The FTC’s inquiry centers around antitrust concerns, given OpenAI’s non-profit roots and Microsoft’s substantial funding, which exceeds $10 billion. 

This funding is vital for powering AI model training and integrating ChatGPT into Microsoft’s product portfolio. 

Microsoft’s chief communications officer, Frank X Shaw, emphasizes that Microsoft does not own OpenAI but is entitled to profit shares. 

The FTC’s scrutiny aligns with its ongoing investigation into OpenAI’s ChatGPT for privacy and reputational issues, and its past scrutiny of Microsoft’s business practices, notably the $69 billion Activision Blizzard deal. The UK’s Competition and Markets Authority is also conducting a consultation on Microsoft’s relationship with OpenAI, examining potential competition impacts.

Sources include: The Register 

Microsoft has agreed to union contract terms – no, this is not a hallucination. 

The agreement concerns the use of artificial intelligence. It marks the first instance of collective bargaining in the company’s U.S. history. 

The agreement, reached with the Communications Workers of America union, applies to several hundred employees at Microsoft’s game studio ZeniMax. 

It includes clauses that demand AI systems to be fair and empowering, offering workers a means to raise concerns if Microsoft falls short in these areas. The contract also mandates Microsoft to notify the union when implementing AI or automation technologies that could affect workers. 

Additionally, Microsoft has partnered with the AFL-CIO, America’s largest union federation, to facilitate an open dialogue about AI’s impact on workers. 

This could be historic in how large tech companies deal with AI. 

Sources include: Engadget

And that’s what’s trending today.

Hashtag Trending goes to air 5 days a week with a special weekend interview show we call “the Weekend Edition.”

You can get us anywhere you get audio podcasts and there is a copy of the show notes at itworldcanada.com/podcasts 

I’m your host Jim Love.  Have a Terrific Tuesday.

The post Hashtag Trending Dec.12- Telepathic communication with ChatGPT; BlackBerry not spinning off IoT business; Microsoft agrees to union contract terms first appeared on IT World Canada.

BlackBerry names new CEO, will split cybersecurity and IoT businesses

BlackBerry’s new leader is the former head of its cybersecurity business unit.

The Waterloo, Ont., company said this morning that John Giamatteo is its new chief executive officer and a member of its board of directors, effective immediately.

John Giamatteo

Richard Lynch, who has served as interim chief executive officer since Nov. 4, after the departure of John Chen, will continue as board chair.

The company also announced that it will separate the IoT division (which offers its QNX operating system for industrial and automotive manufacturers) and its cybersecurity division (which offers Cylance endpoint and Mobile Threat Defence solutions) and that they will operate as fully standalone divisions. However, BlackBerry will no longer try to make the IoT business a publicly traded company.

Giamatteo has served as the president of BlackBerry’s Cybersecurity business unit since October 2021.

Giamatteo has over 30 years of experience with global technology companies, the BlackBerry announcement said.  As president of the cybersecurity business unit, he oversaw enhancements to the product portfolio, go-to-market strategy, and organizational efficiency, the statement said.

Before joining BlackBerry he was president and chief revenue officer at McAfee.  Before that, Giamatteo was chief operating officer at AVG Technologies, a provider of internet and mobile security.

“We are delighted to appoint John to the role of CEO for what will be a transformative period in BlackBerry’s history, as we work to fully separate our two core business units to drive enhanced shareholder value,”  Mike Daniels, chair of BlackBerry’s compensation, nomination and governance committee, said in a statement. “His deep industry experience and outstanding track record of inspiring teams and delivering operational excellence means he is strongly positioned to drive this critical transformation of BlackBerry.”

In a statement, Giamatteo said he is “honored and excited to lead the next phase of BlackBerry’s evolution as its CEO. BlackBerry’s IoT and cybersecurity businesses have market-leading technology, exceptional teams and large market opportunities.

“The Board and I are fully aligned on the next steps needed to unlock the value within BlackBerry, and work on this effort will proceed at full speed. I look forward to working with the entire team to uphold our legacy of innovation and continue providing exceptional service to our customers as we deliver on our goals.”

The announcement also made it clear that the company has given up plans to monetize the IoT division by making an initial public offering of stock. Instead, the board has decided that it will become a standalone division.

The process will include the separation and streamlining of BlackBerry’s centralized corporate functions into business unit-specific teams, with a view to each division operating independently and on a profitable and cashflow-positive basis going forward.

“The board, with input from its advisors, believes that a full separation of BlackBerry’s IoT and Cybersecurity businesses will open up a number of strategic alternatives that can unlock shareholder value,” said board chair Lynch said in a statement. “Management is focused on moving quickly to complete this reorganization that will further enhance the focus of both businesses on their respective markets as well as their capacity for fast, flexible decision-making.”

The post BlackBerry names new CEO, will split cybersecurity and IoT businesses first appeared on IT World Canada.

Cyber Security Today, Dec. 11, 2023 – Irish water treatment plant shut by cyber attack, WordPress issues a security patch, and more

An Irish water treatment plant is temporarily shut by cyber attack, WordPress issues a security patch, and more.

Welcome to Cyber Security Today. It’s Monday, December 11th, 2023. I’m Howard Solomon, contributing reporter on cybersecurity for ITWorldCanada.com and TechNewsday.com in the U.S.



 

Another water treatment plant has been hacked over its use of Israel-made equipment. It happened last week in an east coast area of Ireland called Erris. About 180 residences were without water for two days when the hackers got past the systems’ firewall and shut a small utility. Last week I reported that a hacking group believed to be from Iran called CyberAv3ngers is going after utilities using equipment from Israeli companies.

December is the second anniversary of the revelation of a serious vulnerability in the Apache Log4j2 open-source library used in many applications. So how many applications have been patched since then? Not enough, according to researchers at Veracode. They estimate 38 per cent of current applications are still vulnerable to attacks. Many of them are using a version of Log4j2 that stopped getting support in August, 2015 and can’t be patched. Do you know what’s in your organization’s software?

Here’s some healthcare-related cyber news:

Louisiana-based Lafource Medical Group has agreed to pay US$480,000 to the U.S. Department of Health and Human Services after one of the owners fell for a phishing email in 2021. That exposed some patient health data. An investigation showed that before the incident the company never conducted a security rule risk analysis or had procedures to regularly review records of IT system activity. In addition to the financial settlement the medical group also agreed to implement security measures to reduce the risks to electronic patient records as required by federal health law.

Norton Healthcare, which runs eight hospitals in Kentucky and Indiana, is notifying 2.5 million patients, as well as current and former employees, that their personal data might have been copied in a ransomware attack in May. The attacker got into network storage servers.

By the way, last week the Health and Human Services Department released a proposed plan to tighten cybersecurity requirements for American hospitals. As part of the plan the government will publish cybersecurity performance goals that hospitals ought to aim for, as well as new cybersecurity requirements they have to meet. The department is seeking comment before finalizing the plan.

New U.S. rules start a week today obliging publicly traded companies to publicly disclose material cyber incidents to the Securities and Exchange Commission within four business days. Companies can ask for a delay for national security or public safety reasons. Small companies will have an extra 180 days to comply.

Americold Logistics, a cold storage company based in Atlanta, is notifying just over 129,000 people of a data breach. It says got into its IT system in April. Data stolen may have included names, addresses, Social Security numbers, Drivers licence numbers and employment-related health insurance and medical information.

U.S. hotel chain Red Roof Inns is notifying over 27,000 people their personal information may have been stolen in a September ransomware attack. The data may have included credit or debit card numbers and their related security, access, PIN codes or passwords.

Among the latest American firms reporting data thefts in the hacks of MOVEit file transfer applications is Independent Living Systems. It which provides managed long-term services and support to people covered by certain health plans. It is notifying just under 20,000 people their personal information may have been copied when the company’s MOVEit Transfer application was hacked.

Officials from Google, Meta and X will testify later today and on Wednesday at Canadian parliamentary hearings into social media platforms. The committee is particularly looking into personal information data collection by platforms as well as the abuse of platforms by foreign governments.

Parliamentary hearings on Canada’s proposed federal privacy and artificial intelligence legislation continue on Tuesday. Privacy commissioners from Alberta, British Columbia and Quebec are scheduled to testify.

Here’s some patching news:

A new security update from WordPress is now available that fixes several problems including a big vulnerability. Threat actors could leverage it through some plugins, so install this update fast. You need to be running version 6.4.2.

Twenty-one new serious vulnerabilities have been found and need patching in Sierra Wireless Airlink cellular routers. That’s according to researchers at Forescout. Of the routers Forescout sees that are exposed to the internet, 90 per cent haven’t had patches installed that were released in 2019. And of those that expose a specific management interface, 90 per cent are end of life and can’t be patched. In addition to installing the latest patches, the default SSL certificates for Sierra Wireless routers have to be changed. This is an inventory control problem as well as a technology problem. Why? Because hardware and software can’t be patched if administrators don’t know about them. And they have to learn how devices like routers can be patched.

Finally, lots of companies offer utilities through app stores to help you do things better. But some of those apps may lead to the downloading of malware. Researchers at Spin.AI say this is especially important during this holiday period when people may be tempted to download shopping, news, travel and chat browser extensions that aren’t from reputable developers. Be suspicious of apps that aren’t regularly updated or ask for high levels of permissions to access your contact list and photos.

Follow Cyber Security Today on Apple Podcasts, Google Podcasts or add us to your Flash Briefing on your smart speaker. Thanks for listening. I’m Howard Solomon

The post Cyber Security Today, Dec. 11, 2023 – Irish water treatment plant shut by cyber attack, WordPress issues a security patch, and more first appeared on IT World Canada.

Hashtag Trending Dec.11-Altman, Time’s CEO of the year; Google cheated on its comparison of Gemini to ChatGPT?; Is ChatGPT lazy?

Did Google cheat on its comparison of Gemini to ChatGPT?  Sam Altman is named CEO of the year by Time magazine and is ChatGPT on a work to rule?



 

These and more top tech stories on Hashtag Trending

I’m your host Jim Love, CIO of IT World Canada and Tech News Day in the US.

Sam Altman: TIME’s 2023 CEO of the Year

This story hit just after we recorded the Friday morning newscast, so you might have caught it already, but it is news.  

Sam Altman, CEO of OpenAI, has been named TIME’s 2023 CEO of the Year. While Time’s person of the year is an event that we all watch for, I’m pretty certain that CEO of the year is a first for the magazine.

This marks a tumultuous yet transformative year for both Altman and the AI industry. 

Altman’s journey this year included an intense boardroom struggle at OpenAI, where he was briefly ousted and then reinstated as CEO. 

This period of corporate drama highlighted the significant impact of OpenAI’s products, particularly ChatGPT and GPT-4, which have revolutionized the tech world and brought AI into mainstream conversation. 

OpenAI, initially a nonprofit, evolved into an $80 billion entity under Altman’s leadership, reflecting his vision of AI for humanity’s benefit. 

However, the internal conflict raised questions about governance and the safe development of AI technologies. 

Altman’s return as CEO after a dramatic showdown underscores his influential role in the AI sector and the high stakes involved in leading a company at the forefront of technological innovation.

Sources include: TIME’s article on Sam Altman 

Google’s Gemini Project: A Marketing Mirage?

Google’s recent unveiling of its Gemini project, particularly the Gemini Ultra model, has created quite the controversy. Initially failing to meet its launch deadline, Google seemed to rush Gemini’s release, possibly feeling the heat from competitors like OpenAI and Microsoft. 

Gemini Ultra, claimed to outperform OpenAI’s GPT-4 in various benchmarks, but raised eyebrows with its use of Chain of Thought (CoT) prompting at 32 shots, rather than the standard 5-shot learning, to boost its performance metrics. 

Industry experts, including Bindu Reddy of Abacus AI, suggest that this methodology might be misleading, arguing that GPT-4 still holds superiority over Gemini Ultra. 

Furthermore, the AI community questions the real-world impact of these benchmark victories, as customer engagement and product utility often outweigh technical metrics. 

Adding to the skepticism, a demo video of Gemini Ultra was revealed to be edited (which might be saying it kindly) casting doubt on Google’s marketing tactics. 

Some commentators were fooled and got AI egg on their faces after rave reviews. It was only after the controversy broke about the video that people noticed the small print that said that it had been edited and potentially, the real testing wasn’t exactly as shown.

This revelation is not just damaging to Google’s reputation. It leaves the industry wondering whether Gemini Ultra will really surpass its competitors on its full release.

Sources include:  Analytics India Magazine’s article on Google’s Gemini  

Austin’s Tech Scene: Losing Its Tech Companies?

Austin, Texas, once hailed as a burgeoning tech hub rivaling California’s Silicon Valley, is facing challenges and apparently seeing a bit of an exodus of tech companies.

The city, known for attracting tech companies and talent, is seeing a shift as startups begin to leave and key industry players reduce their presence. A significant development is the pause in operations of Techstars’ Austin chapter, a major startup accelerator, following the departure of its Managing Director, Amos Schwartzfarb. 

This decision reflects broader concerns about Austin’s tech ecosystem, including brutal summers, a lackluster startup scene, and difficulties in securing funding, especially for midsize companies. 

The city’s rising cost of living, particularly in housing, has also dampened its appeal. Venture funding in Austin has seen a notable decline, with a 46 per cent drop in the first three quarters of 2023 compared to the same period in 2021. 

Other companies, like Cart and Laundris, have moved their headquarters out of Austin, citing various reasons including cost, convenience, and talent pool considerations. Despite these setbacks, some still see Austin as an attractive destination, but the gap between expectations and reality is becoming increasingly apparent.

Sources include: TechCrunch’s article on Austin’s tech scene

ChatGPT’s Performance Concerns: OpenAI Investigates reports of “laziness”?

OpenAI is currently investigating user complaints about ChatGPT’s performance, specifically its “laziness” in responding to queries. Users of the latest version, built on the GPT-4 model, have reported that ChatGPT often provides incomplete responses or appears disinterested in answering questions fully. 

For example, when asked for code, ChatGPT might offer minimal information and then suggest users complete the task themselves, sometimes in what’s been termed a “sassy” manner. 

These issues have been widely discussed in Reddit threads and OpenAI’s developer forums, leading to speculation that OpenAI might have intentionally modified ChatGPT to be more efficient and conserve computing resources. AI systems like ChatGPT require significant processing power, making detailed responses costly. 

OpenAI acknowledged these concerns on Twitter, but stated that no recent updates have been made to the model that could explain this change in behavior. The company is looking into the matter but has not confirmed if they believe ChatGPT’s responses have indeed altered.

Sources include: The Independent’s article on ChatGPT’s performance 

And that’s what’s trending today.

Hashtag Trending goes to air 5 days a week with a special weekend interview show we call “the Weekend Edition.”

You can get us anywhere you get audio podcasts and there is a copy of the show notes at itworldcanada.com/podcasts 

I’m your host Jim Love.  Have a marvelous Monday.

The post Hashtag Trending Dec.11-Altman, Time’s CEO of the year; Google cheated on its comparison of Gemini to ChatGPT?; Is ChatGPT lazy? first appeared on IT World Canada.

European political agreement paves the way for AI law

The European Union has reached agreement on the world’s first comprehensive artificial intelligence law.

According to the Associated Press, negotiators from the European Parliament and the bloc’s 27 member countries signed a tentative political agreement Friday that will ease passage of the Artificial Intelligence Act.

The European Parliament still has to approve the legislation, but with Friday’s consensus deal, that is believed to be a formality.

In a statement, the press office of the European Parliament said the agreed text will have to be formally adopted by both Parliament and the EU Council to become EU law. Parliament’s Internal Market and Civil Liberties committees will vote on the agreement in a forthcoming meeting.

An EU law wouldn’t just affect member countries of the European Union. Any company around the world that collects personal data of European residents and uses a generative AI system for processing data would have to meet its regulations.

Meanwhile, Canada’s proposed Artificial Intelligence and Data Act (AIDA) is still before the House of Commons industry committee. In the absence of federal legislation, the U.S. is relying on an executive order for AI guidance issued by President Joe Biden.

Following announcement of the EU deal, co-rapporteur Brando Benifei, an Italian member of the EU Parliament (MEP), said that “it was long and intense, but the effort was worth it. Thanks to the European Parliament’s resilience, the world’s first horizontal legislation on artificial intelligence will keep the European promise – ensuring that rights and freedoms are at the centre of the development of this ground-breaking technology. Correct implementation will be key – the Parliament will continue to keep a close eye, to ensure support for new business ideas with sandboxes, and effective rules for the most powerful models”.

Co-rapporteur Dragos Tudorache, a Romanian MEP, said “the EU is the first in the world to set in place robust regulation on AI, guiding its development and evolution in a human-centric direction. The AI Act sets rules for large, powerful AI models, ensuring they do not present systemic risks to the Union and offers strong safeguards for our citizens and our democracies against any abuses of technology by public authorities. It protects our SMEs, strengthens our capacity to innovate and lead in the field of AI, and protects vulnerable sectors of our economy. The European Union has made impressive contributions to the world; the AI Act is another one that will significantly impact our digital future”.

The law prohibits:

biometric categorization systems that use sensitive characteristics (e.g. political, religious, philosophical beliefs, sexual orientation, race);
untargeted scraping of facial images from the internet or CCTV footage to create facial recognition databases;
emotion recognition in the workplace and educational institutions;
social scoring based on social behaviour or personal characteristics;
AI systems that manipulate human behaviour to circumvent their free will;
AI used to exploit the vulnerabilities of people (due to their age, disability, social or economic situation).

According to the EU Parliament press office, negotiators agreed on a series of safeguards and narrow exceptions for the use of biometric identification systems (RBI) in publicly accessible spaces for law enforcement purposes, subject to prior judicial authorisation and for strictly defined lists of crimes. “Post-remote” RBI would be used strictly in the targeted search of a person convicted of or suspected of having committed a serious crime.

“Real-time” RBI would comply with strict conditions, and its use would be limited in time and location, for the purposes of:

targeted searches of victims (abduction, trafficking, sexual exploitation),
prevention of a specific and present terrorist threat, or
the localisation or identification of a person suspected of having committed one of the specific crimes mentioned in the regulation (e.g. terrorism, trafficking, sexual exploitation, murder, kidnapping, rape, armed robbery, participation in a criminal organisation, environmental crime).

For AI systems classified as high-risk (due to their significant potential harm to health, safety, fundamental rights, environment, democracy and the rule of law), clear obligations were agreed.

MEPs successfully managed to include a mandatory fundamental rights impact assessment, among other requirements, applicable also to the insurance and banking sectors. AI systems used to influence the outcome of elections and voter behaviour are also classified as high-risk. Citizens will have a right to launch complaints about AI systems and receive explanations about decisions based on high-risk AI systems that impact their rights.

The post European political agreement paves the way for AI law first appeared on IT World Canada.

Cyber Security Today, Week in Review for Friday, December 8, 2023

Welcome to Cyber Security Today. This is the Week in Review for the week ending Friday, December 8th, 2023. From Toronto I’m Howard Solomon, contributing reporter on cybersecurity for ITWorldCanada.com and TechNewsday.com in the U.S.



In a few minutes David Shipley of Beauceron Security will be here to discuss recent news. That includes a report that millions of medical images like x-rays and CAT scans are sitting on easily cracked servers open to the internet, a warning by American and Israeli cyber authorities that an Iranian-based group is going after utilities and industrial networks, and the discovery that a lot of people are still running unsupported versions of Microsoft Exchange.

But before we get to the discussion here’s a quick a look at other headlines from the past seven days:

More Canadian organizations are refusing to pay ransomware gangs. That’s according to a survey by Palo Alto Networks. However, those who do pay are spending on average twice as much — just over $1 million — as they did in 2021.

The DNA testing service 23andMe says personal data of nearly 7 million customers was accessed by a hacker in October. The attacker got into 14,000 accounts using credentials stuffing. With that access they were able to also copy the DNA profile data of 5.5 million those people’s relatives, plus some family tree profiles of another 1.4 million people connected to the accounts.

Bluetooth has a protocol flaw that undercuts the security of some Android, Linux and Apple wireless mice and keyboards. That’s according to a security researcher. He promised full vulnerability details at an upcoming conference.

Fancy programming aimed at increasing security in new Intel and AMD processors may end up decreasing security. University researchers in the Netherlands make that claim in a new paper. Watch for guidance from chip makers.

Cyber agencies from the Five Eyes security co-operative including Canada and the U.S. issued guidance to application developers on making software better protected from memory attacks. Memory vulnerabilities are the most prevalent type of disclosed application holes. The agencies urge developers to use memory-safe programming languages.

For the benefit of threat researchers and defenders, Microsoft issued an updated report on the tactics and techniques of a Russian government-sponsored threat actor it calls Star Blizzard. Other researchers call it Coldriver and the Callisto Group. It has espionage and cyber-influence goals.

There’s no shortage of news stories about the cyber risks third parties pose to organizations. But a report from Blue Voyant suggests not a lot is being done. Only 47 per cent of respondents to a survey said they monitor their supply chain for cyber risk monthly or more. That’s up from 41 per cent last year. And only 19 per cent said they work actively with a supplier to fix a security issue once its found. The rest mainly rely on the supplier to solve the problem.

Cyber authorities in U.S. and the European Union signed an agreement to work closer. The pact between the U.S. Cybersecurity and Infrastructure Security Agency and the European Union Agency for Cybersecurity will improve knowledge-sharing of cyber threats and ways to better regulate the public and private sectors.

Finally, Google released another update to the Chrome browser. It patches 10 vulnerabilities. You should be running a version that starts with 120.

(The following is a partial transcript of the discussion. To hear the whole conversation play the podcast)

Howard: Millions of medical patient records are at risk because hospitals and clinics aren’t properly securing their image servers. That’s according to a German cybersecurity firm called Aplite. The servers hold X-rays, CT scans and MRIs stored in the DICOM format, a 30-year-old protocol accepted around the world for sharing and viewing medical data. But researchers at Aplite scanned the internet and found just over 3,800 servers in 111 countries are accessible from the internet. Fewer than one per cent of those servers use effective login authorization. Of the 3,800 servers just under a third leak data containing more than 59 million pieces of medical and personal data. David, this sound like violations of cybersecurity 101.

David Shipley: There’s so many things fundamentally wrong with the story — and terrifying when you think about the implications for things like ransomware, extortion and more. This is not the first company to dive into the digital imagery repositories in healthcare and come out with some massive horror stories. In fact, as part of new regulations for device manufacturers that started in March the U.S. Government Accountability Office did a study of vulnerabilities, and one of the things they found was that up to 51 per cent of all X-ray machines had high severity CVEs, 44 per cent of CT scanners and 20 per cent of imaging devices. Computers in a healthcare environment were running unsupported and unpatched versions of Windows. The implications for this are huge. There was a really interesting research project done in 2019 where a group of Israeli researchers — with authorization –hacked into one of these imaging depository systems and added or removed cancer indicators using AI deepfakes, and then went to see if the radiologist could tell. Short answer: They couldn’t tell. This also puts patient safety at risk … When you take down diagnostic imaging you set back healthcare 200 years

Howard: It’s not just medical images. These researchers could find some systems also had patient names. So medical information could be used for blackmail but also identity theft.

David: Absolutely. Keep in mind that these systems — particularly healthcare systems — often have privileged access back into billing systems. You can probably jump from an insecure patient instance and find many other vulnerable systems on the business network.

Howard: The DICOM protocol itself is old and has weaknesses as well. So a hacker can disrupt images, deny access to images, add false signs of illness and because the images are arranged with unlimited sequential numbers for each implementation this can cause real mayhem.

David: The points made by the Israeli researchers in 2019 was the fact that industry standard best practices on the public internet such as using [digital] certificates to authenticate so communications are made securely and not interfered with between an X-ray, CT scan machine and the patient system don’t exist. Authentication is hilariously absent. But along with the other things, the GAO report and the U.S. found hard-coded credentials [in medical devices] and other problems. While it’s cool that the U.S. has new regulations as of March 2023 for device manufacturers to actually build these things with secure-by-design … 75 per cent of [current] drug infusion pumps had at least one major vulnerability that could throw up a security concern. It’s going to take decades to get this equipment retired and new equipment in. We’re basically telling cyber criminals it’s open season on health care for the next 20-plus years.

The post Cyber Security Today, Week in Review for Friday, December 8, 2023 first appeared on IT World Canada.

Canadian mid-sized firms pay an average $1.13 million to ransomware gangs

The average ransomware payment made by mid-sized Canadian companies this year was just over $1 million, according to a new survey.

The survey of IT professionals at 1,000 organizations with between 100 and 1,000 employees, done for Palo Alto Networks, was released Thursday.

Called the Canadian Ransomware Barometer, it found that while the volume of ransomware attacks here had decreased since the last study two years ago, the average ransom paid was $1.13 million. That’s a 150 per cent increase over 2021.

Of the majority of businesses that paid ransoms, just over half paid more than $500,000. By comparison, only 29 per cent paid over that amount in 2021.

The number of respondents saying their firm was hit by ransomware stayed roughly the same — 35 per cent this year, compared to 37 per cent in 2021.

However, the number of organizations willing to pay ransoms dropped. Of those hit this year, only 34 per cent of respondents said their organization paid to get access to data back. By comparison, 45 per cent of respondents in the 2021 survey said their firm paid.

As with the previous study, more than half of respondents (58 per cent) said that it took
more than a month to recover from a ransomware attack. One-quarter (24 per cent) said that it took longer than four months.

The report offers these tips to defend against ransomware attacks:

— train staff that if they think a phishing email has arrived in their inbox, it must be reported;
— ensure all software and hardware have the latest patches;
— have a solid and tested data backup and recovery plan.

The post Canadian mid-sized firms pay an average $1.13 million to ransomware gangs first appeared on IT World Canada.

Cyber Security Today, Dec. 8, 2023 – Ransomware is increasingly impacting OT systems, and more

Ransomware is increasingly impacting OT systems, and more.

Welcome to Cyber Security Today. It’s Friday, December 8th, 2023. I’m Howard Solomon, contributing reporter on cybersecurity for ITWorldCanada.com and TechNewsday.com in the U.S.



 

Ransomware attacks are increasingly hitting not only IT environments but also OT, or operational technology, systems. These are internet-connected systems running factories, power stations and pipelines. The information comes from a new survey by researchers at Claroty. Some 1,100 IT and OT security professionals in a number of countries answered a questionnaire in November. Thirty-seven per cent said ransomware attacks this year affected both their IT and OT environments. That compares to 27 per cent in 2021 — a 10 per cent rise in two years. Of those who were hit, 22 per cent said the impact was severe or extreme, meaning operations were impacted for more than a week. An additional 32 per cent said the impact was moderate. Sixty-nine per cent of respondents said their organization paid a ransom to get access back to their data or systems.

Hackers are taking advantage of AWS’s Secure Token Service to break into cloud applications and data. According to researchers at Red Canary, they’re doing it by generating short-term login credentials. These tokens last no longer than 36 hours and are offered to users so they don’t have to create an AWS identity. Ironically, the hacker gets short-term tokens by first creating a long-term identity and access token. The advantage of a short-term token is the hacker can hide themselves better. The best defences include logging all CloudTrail event data to a data lake for analysis of AWS services, and building altering to detect role chaining events and multifactor authentication abuse.

Many cyber attacks are opportunistic, taking advantage of vulnerabilities that hackers trip over. But Bloomberg News has a story about the 2020 attack on the U.S. Department of Health and Human Services at the outset of the COVID-19 pandemic. According to a synopsis of the article by The Cyberwire, it started with a large denial of service attack. It was probably used to hide penetration of the department’s servers. The attackers might have been looking for information the U.S. had on COVID-19. Whatever the motive, a former department official told the news service that the attackers had done their homework and knew where the large stores of data were.

Taylor Swift, Justin Bieber, Jennifer Lopez, Oprah and other celebrities are not denouncing Ukraine for resisting the Russian invasion. But fake ads on Facebook and X make it look that way. The ads have fake quotes beside the pictures of celebrities. According to Wired.com, Russia is suspected of placing the ads. It’s part of the Doppelganger influence campaign I told you about on Wednesday’s podcast. Researchers at a firm called Reset believe the campaign takes advantage of loopholes in Facebook’s ad verification and content moderation systems.

A Russian military-associated group is still going after vulnerable installations of Microsoft Outlook. That warning comes from Palo Alto Networks. The group is known by security researchers as Fighting Ursa, APT28 or Fancy Bear. It’s been exploiting unpatched Outlook servers for the past 20 months in 14 countries. Most of those countries are members of NATO. Targets are government departments and energy companies. This hole was patched in March. This group is still trying to find unpatched Outlook servers.

The Canadian Centre for Cyber Security has issued advisories that patches and mitigations are available for a number of products. These include Atlassian’s Confluence Data Centre and Server and Atlassian Companion App for MacOS; FA engineering software products from Mitsubishi Electric; and certain Facilities Explorer and Metasys products from Johnson Controls. IT and OT administrators need to pay attention to these warnings.

That’s it for now. But later today the Week in Review podcast will be available. Guest David Shipley and I will discuss why 20,000 out-of-date Microsoft Exchange servers are still online, why vulnerable medical images are open to the internet and cyber attacks against water utilities.

Follow Cyber Security Today on Apple Podcasts, Google Podcasts or add us to your Flash Briefing on your smart speaker. Thanks for listening. I’m Howard Solomon

The post Cyber Security Today, Dec. 8, 2023 – Ransomware is increasingly impacting OT systems, and more first appeared on IT World Canada.