Category: News

Daniel Langlois, founder of Softimage, found dead in Dominica.

Daniel Langlois, the founder of Softimage, was found dead with his spouse, Dominique Marchand, in the remains of a burned car in Dominica, an island in the Caribbean, on Friday.

A story in Dominica News Online today said that three non-nationals and one Dominican are in custody. It quoted Dominican Minister of National Security and Legal Affairs Rayburn Blackmoore, who said, “Official requests for investigative support from Canadian authorities have been formally made, aligning with Dominica’s pursuit of justice in this matter.

“The government will provide the police force with all the resources needed to investigate this matter and to bring the perpetrators of this terrible crime to justice. Crimes like these do not only hurt international relations but this crime in particular has sent shockwaves throughout the island and left the employees, family and community of the victims in mourning.”

Daniel Langlois. Photo courtesy of Coulibri Ridge

Born in Jonquière, Québec, in 1957, Langlois made a name for himself in both the fields of technology and the arts when, in 1986, he founded Softimage, a company that developed 3D animation software, before selling it to Microsoft eight years later for some $200 million.

Softimage’s software has been used in many big-budget productions, such as Jurassic Park, Titanic and The Lord of the Rings. The company was awarded an Oscar in 1997.

That same year, Langlois created the Daniel Langlois Foundation, with a mission to support artistic and scientific research dedicated to the advancement and understanding of the relationship between humans and their natural and technological environment.

In 1999, he founded the Ex-Centris cinema, a mecca for repertory cinema. In December 2000, he bought the Cinéma du Parc and managed it until July 2006. In 2011, Langlois sold the Ex-Centris Complex’s movie theatres to the Centre du Cinéma Parallèle Inc.

In 1998, Langlois and his foundation founded the NGO Resilient Dominica, after Hurricane Maria hit Dominica on September 18, 2017, with the goal of rebuilding and strengthening resilience in the communities of Soufriere, Scotts Head and Gallion.

Lately, he has been involved in sustainable and eco-responsible development projects such as the off-grid eco-friendly Coulibri Ridge hotel project in Dominica.

Langlois held honourary doctorates from the universities of Sherbrooke, McGill, Concordia, UQAM and Ottawa. He was also a Knight of the Ordre national du Québec and an Officer of the Order of Canada. Earlier this year, he received the Dominican Commonwealth Meritorious Service Award.

In a statement announcing the couple’s passing, Coulibri Ridge said, “Daniel and Dominique were trailblazers in so many ways, most recently as founders and operators of Coulibri Ridge Resort. Their commitment to sustainability set a standard in the tourism industry, and their passion for the environment and helping others has touched the lives of many who experienced the magic of Coulibri Ridge. Their legacy will continue to live on through the efforts of The Daniel Langlois Foundation, the Resilient Dominica Project, and the Humane Society of Dominica.”

The post Daniel Langlois, founder of Softimage, found dead in Dominica. first appeared on IT World Canada.

re:Invent 2023: AWS aims to capture AI leadership by offering choice

AWS revealed its strategy for leadership in generative AI at its re:Invent conference last week, making it clear that, while rival Microsoft may have gotten off to an early start, AWS hasn’t been standing still.

Generative AI is relatively new – ChatGPT has only been on the market for a year. But artificial intelligence is not new. It’s been actively in use in business for more than a decade.

In fact, Amazon, AWS’ parent company, has been applying and integrating leading edge artificial intelligence (AI) on a global scale. Amazon’s retail operations leverage AI in every aspect of the company’s business, from sales to logistics. AWS’ message at re:Invent was that it has brought that breadth of experience of AI enabled business to the new opportunities presented by generative AI solutions.

In that context, AWS rolled out an overwhelming list of offerings, features and options at re:Invent. Presenters were often forced to acknowledge that if they covered all of the elements of their offerings, they’d far exceed the time they had for their presentations.

So how do you summarize AWS’ offerings in generative AI? If you had to do it in a single word, that word might very well be “choice.”

Choice of models

AWS has taken the position that it sees a world where there is no dominant model. This is consistent with how AI is evolving in the market. While there are some models that are better known in the public consciousness, there has been an explosion of different AI models. They range from large global models with billions of parameters to smaller specialized models with far fewer parameters that often rival bigger models in accuracy and function, at least for specific purposes.

There are also proprietary models, as well as many open source variations. There are models that are integrated into larger software packages and there are standalone models that can be adapted for multiple uses. There are text-based, voice-based and image-based models.

This list grows almost on a daily basis. AWS has chosen to embrace that diversity, and focus on the cloud infrastructure and tools that will enable companies to choose the right model for the right task.

So although AWS has made strategic investments in ChatGPT competitor Anthropic and its Claude.ai model, it also offers support for a wide range of others, ranging from Meta’s Llama 2 to Stable Diffusion’s text to image suite and a host of others.

AWS’s Bedrock allows customers to access multiple models. It can even allow for changing the model in use without changing the the underlying infrastructure, giving companies the choice of which generative AI model they use. Companies can select the right model for the right purpose, based on technical and business goals such as accuracy, cost and speed.

Understanding that this wealth of models can be confusing and even overwhelming, AWS’ Bedrock has tools to help evaluate models on more precise criteria, with both automatic and human evaluation. Taking these criteria and providing metrics such as “accuracy, robustness and even toxicity” allows companies to understand the advantages and the trade-offs they make when choosing one model over another.

Data privacy and performance

Another focus which was highlighted in many presentations was the need to provide an infrastructure that provides privacy, security, and performance.

One of the issues with LLMs that could hold back adoption is understanding how a customer’s data can be protected while dealing with models that learn from the data they process. In the early launches of generative AI products, there have been examples of model “leakage” and fears about the loss of key intellectual property.

AWS has focused on tools and structures to protect and isolate customer data.
In addition, it has added the concept of “clean rooms” that allow for applying models without sharing raw data. Their message that “it’s your data” came across loud and clear.

In addition to privacy, there is also the issue of performance. The strength of LLMs is the incredible amount of data that they can process. The challenge is to do this at scale and at a speed that supports tasks that often must be performed in real time.

In a consumer setting with a new and novel offering, you can tolerate some of the delays that have been part of early generative AI models. But at an enterprise level, the ability to scale and have split second response is critical. You can wait for a model to search and present you with an interesting fact, but to support a natural conversation or to do things like fraud prevention, even minor latency could be a real issue.

Some of the innovations that were showcased provided vector database integration with standard databases. Keeping these models and the data close together is one way to vastly increase performance.

Taking what one presenter called a “non-ETL” approach, avoiding the loading and unloading of data, is another way to bring processing into real-time applications.

Infrastructure options

Driving performance and scale while offering choice extends beyond the software and database right up to the hardware layer.

AWS has always allowed customers to choose the CPU chipsets that drive their servers, offering a choice of Intel, AMD and even its own Graviton chipset. Each has its own strengths and advantages. Having choice allows the end customer to balance performance and cost.

AWS announced that it will also offers choice in GPU chipsets. It has a close partnership with NVIDIA, which is the “gold standard” of AI processing. But it has also designed and implemented its own GPU chips which, depending on the usage, may offer lower cost, increased processing speeds and even better energy consumption.

Ease of use, accessibility and democratization

Generative AI solutions in business have divided into two major paths, with some possible variations. Everyone is familiar with the natural language applications that allow anyone to converse with the AI and conduct a wide range of tasks, even creating entire applications. That human level interaction and the democratization it supports has been a driving force in generative AI.

But once again, operating at scale or having highly specialized applications can also require the ability to customize, integrate, and fine-tune models using expert skills.

AWS has introduced a range of offerings that it feels will provide full natural language solutions and provide assistance with code development.

One demonstration really encapsulated this approach. There are still, and will continue to be, databases that need SQL queries to retrieve and interpret data. Tools which take natural language instruction speed up the process for the programmer and can do the heavy lifting, even down to the level of testing the program and checking for security and other issues. These still allow the programmer to intervene, change and adapt the solutions.

Equally, for an untrained user, the same facility can generate, test, and run a query, even reading the database schema and suggesting how to write the appropriate code.

Having both of these options allows AWS to appeal to enterprise technology groups and business users alike.

For the highly skilled, the emphasis is on productivity and security. For others, the natural language and no-code solutions emphasize the democratization possible with LLMs.

Summing it up

Those are our reflections from the time spent at re:Invent this week. I’ll be posting other stories in the coming week from some particular areas of interest.

For those who want to dive a little deeper, we’ll be updating this article with a list of resources, including links to presentations and papers that can provide more information. Check back for more information.

The post re:Invent 2023: AWS aims to capture AI leadership by offering choice first appeared on IT World Canada.

Cyber Security Today, Dec. 4, 2023 – A warning to water treatment utilities, a boot vulnerability could affect millions of PCs, and more.

A warning to water treatment utilities, a boot vulnerability could affect millions of PCs, and more.

Welcome to Cyber Security Today. It’s Monday, December 4th, 2023. I’m Howard Solomon, contributing reporter on cybersecurity for ITWorldCanada.com and TechNewsday.com in the U.S.



American water treatment utilities are increasingly being targeted by threat actors. You may recall that on Friday afternoon’s Week in Review podcast, I reported that a hacking group believed to be from Iran called CyberAv3ngers claimed credit for taking control of the internet-connected system of a municipal water authority in Pennsylvania. It is believed this group targeted the utility because of a vulnerability in a programmable logic controller it uses from an Israeli company called Unitronics. Three new things have happened since that report: First, late Friday American and Israeli cyber authorities issued an advisory that CyberAv3ngers and its affiliates are going after any organization using Unitronics devices. It says that since November 22nd several wastewater treatment plants have been compromised. How? Likely because the default passwords on the Unitronics devices weren’t changed, says the alert. The gang considers every piece of equipment made in Israel is a legal target. It’s not clear if CyberAv3ngers did any damage in these attacks. But three U.S. Congressmen have asked the U.S. Justice Department to investigate.

The third piece of related news is that the Hunters International ransomware gang has listed Florida’s St. Johns River Water Management District as one of its victims.

Cyber authorities urge any critical infrastructure provider to take security precautions including making sure as few IT devices as possible are open to the internet. And to make sure default passwords that come with internet-connected equipment are changed.

IT administrators and home computer owners should be watching this week for firmware patches from device manufacturers. Scheduled for Wednesday, the BIOS updates will plug vulnerabilities discovered in computers’ Unified Extensible Firmware Interface, or UEFI. The UEFI is part of a computer’s boot-up process. The holes were discovered by researchers at Binarly. The vulnerabilities, dubbed LogoFail, allow an attacker to get around crucial security boot protections. Researchers believe computers and servers from Intel, Acer, Lenovo and others running x86 or ARM processors are potentially vulnerable. Details will be revealed at this week’s Black Hat Europe conference, but you can get a preview in a Binarly blog.

About 60 American credit unions are dealing with the aftereffects of a ransomware attack one of their IT service providers. According to the news site The Record, the provider is called Ongoing Operations, which is owned by a credit union technology firm called Tellance. The news site quotes the National Credit Union Administration saying the incident happened November 26th. Not only have some credit unions been having IT trouble, so are other companies that rely on the same provider. It’s another example of the risks that an organization’s IT partners can bring unless there is built-in resilience.

It’s important organizations hit by a data breach don’t make things worse for the victims. Like accidentally publishing the names of those whose personal information was stolen. The latest example comes from MGM Resorts. You may recall it was hit by the BlackCat/AlphV ransomware gang in September. One of the victims was the wife of a Canadian-based cybersecurity researcher. On Saturday she was emailed a data theft notice by the hotel. However, while the email address was right the letter itself was addressed to another woman, presumably also a victim. So now at least one person knows that someone else’s personal information was stolen.

Are you still running a version of Microsoft Exchange email server that’s no longer supported with security updates? If so you’re foolish. And apparently, you’re not alone. According to a site called Shadow Server, almost 20,000 out-of-date Exchange Servers are open to the internet. About 6,000 of them are in the U.S. and Canada, and about 10,000 of them are in Europe. Versions no longer supported by Microsoft include Exchange Server 2013 and prior. If you’re administering an old version of any software and it gets hacked your excuse to the CEO is …

The U.S. headquarters of office supply chain Staples said it had to temporarily take some of its IT systems offline after a cybersecurity incident. It issued few other details.

Finally, a Russian man extradited from South Korea to the U.S. will be sentenced in March after pleading guilty for his role in developing and deploying the Trickbot malware. Trickbot is used by crooks to steal money and install ransomware. In June one of the convict’s partners was sentenced to two years and eight months in prison. This is the latest move in law enforcement’s attack on the distribution of Trickbot. The Russian man was extradited in 2021. Earlier this year U.S. named and sanctioned several suspected Trickbot gang members.

Follow Cyber Security Today on Apple Podcasts, Google Podcasts or add us to your Flash Briefing on your smart speaker.

The post Cyber Security Today, Dec. 4, 2023 – A warning to water treatment utilities, a boot vulnerability could affect millions of PCs, and more. first appeared on IT World Canada.

Hashtag Trending Dec.4-AWS has ‘choice’ of AI for your infrastructure; Broadcom pushes RTO; Elon Musk drop the F bomb on advertisers

AWS holds their annual re:Invent and announces that “choice” is here on AI for your infrastructure.  Return to office is dead – but not at Broadcom. Elon Musk drops the F bomb on his advertisers. 



 

And come’on – James Roy is good but admit you missed me.  Didn’t ya?

These and more top tech stories on Hashtag Trending

I’m your host Jim Love, CIO of IT World Canada and Tech News Day in the US.

So, I was away last week in Las Vegas covering AWS’s re:Invent conference. I’ve posted a number of stories on this and I’ll be writing a few more this week, but here’s the news from that conference:

Generative AI is real and it’s being built into corporate infrastructure. 

And this is not a commercial for AWS or any other cloud vendor, but I saw first hand how well integrated AI was going to be in our cloud based infrastructure. I’m not talking about watching keynotes – the folks at AWS granted me some one-on-one interviews with key people in their infrastructure and their AI development, among others. 

And from development of their own AI silicon chip to their infrastructure stack that accommodates a number of different AI models – here’s something you can take to the bank. No one AI model is going to win. Your corporate AI strategy will touch not just the big and well known models. There are going to be a plethora of smaller, focused models that are going to be, at least in certain cases, as effective or even more than the large models we all have top of mind. 

We talk a lot about OpenAI and ChatGPT, but there are also Anthropics CloudGPT, Google’s BARD and now Meta’s Llama and the list keeps growing. 

Anyway, the big news is – AI is being built into cloud infrastructure. Microsoft is a big player and got first mover advantage, but don’t count AWS out on this one. They have a very credible story.

Was that opinion or news? 

And here’s two stories that I picked up on the work from home versus return to office debate. Here’s two views on this.

Stanford economist Nick Bloom says the “Return to Office” movement might be hitting a dead end. Despite efforts by companies like IBM, Apple, Amazon, Google, and Meta to bring employees back to the office, the trend towards working from home (WFH) seems to have stabilized. 

Bloom’s research, along with data from the US Census Household Pulse Survey and commercial property services firm Kastle, indicates a flatlined trend in office occupancy since 2023. 

Interestingly, about 42 per cent of companies have reportedly lost more employees than expected following strict office mandates. As of mid-2023, 28 per cent of full workdays among Americans aged 20-64 were done from home, a significant increase from pre-pandemic levels. The paper “The Evolution of Work from Home” by Bloom and colleagues suggests that remote work offers benefits for both employers and employees, including access to a broader talent pool, reduced turnover, and potentially lower wages due to labour supply effects. This raises questions about the real motives behind the push for office returns, especially when remote work seems to offer several advantages.

Sources include: The Register

And on the other side of the issue, Broadcom’s CEO Hock Tan is shaking things up in the world of work-from-home policies. 

After Broadcom’s $69 billion acquisition of VMWare, Tan didn’t mince words with his new employees: “If you live within 50 miles of an office, you get your butt in here.” 

This directive was part of a meeting following the merger’s completion, which had just received the green light from Chinese regulators. Tan, like many executives, champions in-person work for its benefits in collaboration and company culture. 

Broadcom, known for its rigid stance on remote work even during the pandemic, contrasts sharply with companies like Atlassian, Dropbox, and Airbnb, who continue to support remote work. The tech world watches as Broadcom navigates integrating VMWare’s culture, which included support for employee resource groups (ERGs) and an approach to a more humanistic management style –  a concept Tan humorously called “alien” but is one he says he is “open to considering.” 

But first, Broadcom has to deal with layoffs of VMWare employees before it really deals with merging the two corporate cultures.  Good luck on that one.

Sources include: Fortune

OpenAI has pushed back the launch of its much-anticipated GPT store to early 2024, as revealed in a memo to developers. Initially set for release last month, the store is designed for distributing custom versions of ChatGPT. This delay is a significant shift from OpenAI’s announcement at last month’s DevDay conference. The reason? 

A few “unexpected things” is keeping the team busy. For now, custom GPTs can be shared via direct links, but the store’s launch will enable broader distribution. Additionally, OpenAI plans to share revenue from ChatGPT Plus subscriptions with creators of popular GPTs, though details are still forthcoming. Amidst these developments, OpenAI has experienced some internal turmoil, including the brief firing and rehiring of CEO Sam Altman. The company assures developers of upcoming updates to ChatGPT and expresses gratitude for their efforts in building GPTs.

Sources include: Axios

Google’s ambitious AI model, Gemini, has had its launch postponed to early 2024, as reported by The Information. 

Initially expected to debut in November, Gemini’s release has been delayed due to challenges in handling non-English prompts. Touted as a next-generation, multimodal AI, Gemini is designed to process various types of data, including text and images, and even generate content like websites from sketches or written descriptions. 

Despite the delay, Gemini is rumoured to significantly outperform OpenAI’s GPT-4, leveraging considerably more computing power. Google’s VP Sissie Hsiao has highlighted Gemini’s unique capabilities, such as generating novel images in response to specific requests, a feature not sourced from the internet. Although Google already has its generative AI model Bard, Gemini’s launch is highly anticipated and could potentially shift the balance in consumer awareness and preference in the AI space.

Sources include: Business Insider

Walmart announced it is no longer advertising on social media platform X, previously known as Twitter, now owned by Elon Musk. 

Walmart’s spokesperson stated the decision was based on finding other platforms more effective in reaching their customers. This move comes amid a broader trend of advertisers withdrawing from the platform following Musk’s acquisition in October 2022. The platform has faced challenges in retaining advertisers, particularly due to concerns over increasing antisemitic content.

The situation escalated earlier this month when Musk responded to a user’s false claim about the Jewish community, which referenced the “Great Replacement” conspiracy theory. 

Musk later apologized for his post during a New York Times DealBook event but expressed strong disapproval of advertisers suspending their ads, accusing them of “blackmail.”  Actually, he told advertisers to Eff off. 

And in the understatement of the year category, Reuters reported that there are some tensions, with an executive from a major ad-buying agency noting frustration among X’s ad sales representatives following Musk’s comments.

Sources include: Reuters

And that’s the top tech news for today.

Hashtag Trending goes to air 5 days a week with a special weekend interview show we call “the Weekend Edition.”

You can get us anywhere you get audio podcasts and there is a copy of the show notes at itworldcanada.com/podcasts 

And I’ll cover cybersecurity stories that I think are of general interest, but you can keep up todate on cybersecurity with our podcast featuring security journalist Howard Solomon and called CybersecurityToday.  It’s often rated as one of North America’s top 10 tech podcasts. 

I’m your host Jim Love.  Have a marvelous Monday. And it’s great to be back.

The post Hashtag Trending Dec.4-AWS has ‘choice’ of AI for your infrastructure; Broadcom pushes RTO; Elon Musk drop the F bomb on advertisers first appeared on IT World Canada.

Following triumphant return, Altman praises OpenAI employees

Buoyed with confidence now that he is back with the company he co-founded, Sam Altman this week told OpenAI employees in an internal blog that he has “never been more excited about the future (and) I am extremely grateful for everyone’s hard work in an unclear and unprecedented situation.”

Altman officially returned as CEO on Wednesday, after having been fired by the former board of directors last month in a stunning turn of events that saw him quickly resurface at Microsoft to launch a new AI research team, and just as quickly come back to the company that created ChatGPT.

There will, of course, be a new board, and this one currently consists of former Salesforce co-CEO Bret Taylor, who will be chair, economist and former U.S. Secretary Treasurer Lawrence Summers, and Adam D’Angelo, the CEO of Quora, who also sat on the board that voted to fire Altman.

Another member of that board was Ilya Sutskever, OpenAI’s chief scientist, who, according to one published report, played a key role in the Nov. 18 firing of both Altman and company president Greg Brockman. He then publicly said he regretted doing so.

“I love and respect Ilya, I think he’s a guiding light of the field and a gem of a human being,” wrote Altman. “I harbour zero ill will towards him. While Ilya will no longer serve on the board, we hope to continue our working relationship and are discussing how he can continue his work at OpenAI.”

Altman told employees the company has three “immediate” priorities:

“Advancing our research plan and further investing in our full-stack safety efforts, which have always been critical to our work.”
Continuing to “improve and deploy our products and serve our customers. It’s important that people get to experience the benefits and promise of AI, and have the opportunity to shape it.”
Taylor, Summers and D’Angelo are working “very hard on the extremely important task of building out a board of diverse perspectives, improving our governance structure and overseeing an independent review of recent events.”

In the same letter, Taylor said that “OpenAI is a more important institution than ever before. ChatGPT has made artificial intelligence a part of daily life for hundreds of millions of people. Its popularity has made AI – its benefits and its risks – central to virtually every conversation about the future of governments, business, and society.

“We understand the gravity of these discussions and the central role of OpenAI in the development and safety of these awe-inspiring new technologies. Each of you plays a critical part in ensuring that we effectively meet these challenges.”

The post Following triumphant return, Altman praises OpenAI employees first appeared on IT World Canada.

Cyber Security Today, Week in Review for Friday, December 1, 2023

Welcome to Cyber Security Today. this is the Week in Review podcast for the week ending Friday, December 1st, 2023. From Toronto, I’m Howard Solomon, contributing reporter on cybersecurity for ITWorldCanada.com and TechNewsday.com in the U.S.



In a few minutes Terry Cutler of Montreal’s Cyology Labs will be here to discuss some recent news. But first a look back at some of the headlines from the past seven days:

It almost wouldn’t be a Week in Review podcast if we didn’t talk about ransomware. This week a ransomware operation in Ukraine was broken up, a major American hospital chain was hit, and in this country a ransomware gang named an association that represents pork producers as one of its victims. In addition researchers said the BlackBasta ransomware gang got $107 million in payments over the past 22 months. Terry and I will discuss this.

We’ll also look at an updated report from Okta on a data breach of its customer support system, an authentication problem with Microsoft Access and a report on what information security leaders reflect on after a cyber breach.

In other news the Cactus ransomware gang is exploiting vulnerabilities in the Qlik Sense cloud analytics and business intelligence platform. Researchers at Arctic Wolf say IT departments that have allowed their Qlik Sense installations to be exposed to the internet are at risk. Administrators need to make sure this application has the latest security patches.

A hacking group called Cyber Av3ngers has claimed credit for taking control of an internet-connected system of a municipal water authority in Pennsylvania. Researchers at Check Point Software say the group is affiliated with the government of Iran. The suspicion is the utility was hit because it uses programmable logic controls from an Israeli company, Unitronics. The U.S. Cybersecurity and Infrastructure Security Agency issued a reminder to companies using Unitronics and other internet-connected sensors and controllers to do basic cybersecurity things like change the default password on the devices, not make them visible or disconnect them from the internet, and if they have to be on the ‘net protect them with multifactor login authentication.

Separately, authorities are investigating a suspected ransomware attack against a municipal water utility in Texas.

Zyxel released patches for four vulnerabilities in its network-attached storage devices. Affected are certain models of the NAS326 and NAS542 devices.

Almost two million employees of Dollar Tree and Family Dollar stores are being told some of their personal information was stolen when a data processor was hacked. That company is Zeroed-In Technologies, which does workforce analytics for companies. The hack took place early in August. Data that might have been stolen includes names, dates of birth and Social Security numbers.

Berglund Management Group, which oversees several car dealerships in Virginia, is notifying over 51,000 people of a data breach. Information stolen includes names and Social Security numbers.

Bluefield University of Virginia is notifying just over 23,000 people that some of their personal information was stolen in a May 1st data breach. Information stolen includes names and Social Security numbers.

Meta has purged thousands of Facebook accounts linked to China, Russia and Iran for spreading false or misleading information. Some of the fake personas posed as reporters, lawyers, human rights activists or American residents.

And a Los Angeles man was sentenced by an American judge to eight years in prison for online fraud. That included one incident when he took over a victim’s cellphone by convincing their carrier to change the phone’s SIM card to one the crook controlled. He also impersonated Apple Support staff to access victims’ iCloud accounts and steal their cryptocurrency. In one case, pretending to be from Apple, he persuaded the victim to give him their six-digit two-step authorization code to access their iCloud account.

(The following is a transcript of the first of the four news items discussed. To hear the entire conversation play the podcast)

Howard: In the past seven days hospitals in the U.S. have revealed ransomware attacks, police in Europe worked together to arrest the alleged head of a ransomware group in Ukraine and researchers released a report outlining how lucrative ransomware has been for one gang. According to Corvus Insurance and a blockchain analysis company called Elliptic, the Black Basta gang pulled in at least US$107 million in the past 22 months. The gang is either directly or indirectly connected to the people behind the Conti ransomware group, which stopped operating early last year — around the time Black Basta emerged. What stood out for you in this report?

Terry Cutler: The report touched on the wide range of who can be a victim. This report talked about 322 organizations that were targeted –and obviously they weren’t prepared –anybody can become a victim. You talked about the Conti connection. We’re seeing a lot of [gang] members switching teams, or maybe creating a new group. It’s always the same team, just recycled. This [ransomware] is not going away anytime soon. And because of the whole crypto back end, the cryptocurrency laundering, it’s very, very difficult to find out where these guys are coming from … So it goes to show if you’re connected to the internet you will be attacked. If your systems are vulnerable, you’ll be exploited. So get your [IT security] audits done.

Howard: What caught my eye was that about one-third of victims paid a ransom to this gang, and the average ransom payment was US$1.2 million dollars.

Terry: I witnessed that amount here in Canada. I really didn’t believe this number when I started seeing the stats. Who’s going to want to pay this kind of money? [But] we saw an MSP [managed service provider] get hacked and they [the hackers] got access to their customers and hacked the customers. By the time the MSP got back up and running their [recovery] bill went from a $10,000 audit to $1.2 million in less than two months because of legal fees, round-the-clock support to get their systems back up and running … If you get hit with a ransomware attack you’re going to be down for at least 100 hours. There’s a stat that shows that most small and medium-sized businesses are going to fold within six months of a cyber attack. The other thing is when you get hit with ransomware your data is encrypted.

We’ve talked about this — is it more cost-effective to pay the ransom get your data back? Or live what you have, because a lot of times the backups will be will be encrypted as well. It really depends on how sensitive this information is.

The post Cyber Security Today, Week in Review for Friday, December 1, 2023 first appeared on IT World Canada.

AI expert says report findings proof onset of ‘Terminal AI’ has begun

A new report highlighting an escalating rise in phishing incidents since the launch of ChatGPT is the start of a cascade of events that a Silicon Valley cloud and artificial intelligence (AI) expert predicts could result in a catastrophic “threat to mankind.”

The study by cybersecurity vendor SlashNext, which provides offerings for cloud email, mobile and web messaging apps, revealed an alarming 1,265 per cent increase in malicious phishing emails since the launch of OpenAI’s generative artificial intelligence (GenAI) platform a year ago.

“The one thing that is certain is the future of generative AI is still largely unknown,” authors of the document state. “The rapid growth of these tools on cybercrime forums and markets highlights how cybercriminals have embraced the technology and that the potential threat is real.”

While noting that “fortunately, there are cybersecurity vendors who have introduced generative AI technologies, which are used to detect and stop malicious generative AI attack attempts,” they add, “the results in the report highlight how much the threat landscape has changed since 2022.”

Other findings revealed that 68 per cent of all phishing emails are text-based Business Email Compromise (BEC) attacks, mobile phishing is on the rise, with 39 per cent of mobile threats consisting of Smishing (SMS phishing), and Credential Phishing “continues a stratospheric rise, with a 967 per cent increase.”

For Don Delvy, the CEO and founder of D1OL: The Digital Athlete Engine, a cloud-based sports smart platform, the findings should be a wake-up call for everyone when it comes to the downside of a technology that he says should never have been put into the public domain in the first place.

“The recent advancements in AI have ignited a global conversation about its potential impact on society,” he said. “While AI holds immense promise for transforming industries and enhancing human capabilities, it also raises concerns about ethical implications and responsible use.

“We are facing unprecedented ignorance, incompetence and corruption in the global technology industrial complex, at the worst possible time, the precipice of Terminal AI.”

Terminal AI, he said, “refers to artificial intelligence that becomes a catastrophic threat, potentially leading to a nuclear holocaust, the destabilization of governments, economies, and societies. This concept underscores the urgent need for strategies that future-proof AI to save the world. A proactive approach that focuses on the enduring sustainability and ethical foundations of AI would prevent such a dire outcome by ensuring AI develops in a safe, controlled, and beneficial manner for humanity.”

To address these concerns “and foster a constructive dialogue,” Delvy, a graduate of Purdue University who has been involved in software development for close to 30 years, says the following five steps need to be taken:

Promote transparency and open communication: AI developers, researchers, and companies should proactively engage with the public to explain their work, address potential risks, and foster trust.
Establish clear ethical guidelines: Industry bodies and government agencies should collaborate to develop and enforce robust ethical guidelines for AI development and deployment.
Emphasize education and public understanding: AI literacy should be integrated into educational curricula to equip individuals with the knowledge and critical thinking skills to navigate the AI landscape responsibly.
Encourage diversity and inclusion: AI development teams should reflect the diversity of society to ensure that AI solutions address the needs and perspectives of all stakeholders.
Prioritize human-centered AI: AI should be designed and implemented with the well-being of humanity at its core, ensuring that it augments human capabilities rather than replacing or dominating them.

In an interview with IT World Canada, Delvy described GenAI technologies as “hands down the most explosive technology the world has ever seen, right behind nuclear.

“I would never have put a large language model (LLLM) on a public cloud, that is first and foremost.”

As for the SlashNext report, he said the “mammoth rise in phishing emails created by ChatGPT is absolutely 100 per cent the beginning, and you are going to see actual damage.

“I have a seven-year-old son I am trying to  protect here.”

Asked about the recent firing and re-hiring of Sam Altman from OpenAI, Delvy pointed out that the entire incident “highlights the importance of ethical leadership in the AI sector. As AI continues to evolve at an unprecedented pace, it is crucial for industry leaders to embrace transparency, accountability and a commitment to responsible innovation.”

The post AI expert says report findings proof onset of ‘Terminal AI’ has begun first appeared on IT World Canada.

5G spectrum auction concludes; Bell, Rogers and Telus bag the most licenses

Twenty-two Canadian carriers collectively paid over C$2.1 billion for a record 4,099 licenses in the 3800 MHz spectrum auction. 

Bell, Rogers and Telus won the majority of the licenses. Telus acquired 1,430 licenses for around C$619 million, Bell won 939 licenses for around C$518 million, and Rogers won 860 for around C$474 million. Together, the Big Three carriers accounted for 76 per cent of the total amount raised.

During the 3500 MHz auction in 2021, carriers paid over $8.9 billion for 3,431 licenses, but the government only assigned a small amount of spectrum (200MHz) which limited spectrum access to only the biggest players, who, in turn, drove the valuation to record numbers.

This time, however, the government set a 100 MHz spectrum limit on how much combined 3500 MHz and 3800 MHz spectrum a provider could acquire, effectively reserving spectrum for smaller competitors and lowering prices.

Montreal-based carrier Cogeco, for instance, acquired 99 licenses for C$190 million this time around, compared to 38 for C$295 million in the last auction.

The company said it now has spectrum covering 100 per cent of its Canadian broadband footprint, and is preparing to launch mobile operations via the newly established mobile virtual network operator (MVNO) regime, provided it obtains satisfactory rates for wholesale access to the networks of the major players.

Eastlink, which also registered as an MVNO, netted 187 licenses for about C$10 million.

Additionally, Vidéotron paid about C$300 million to acquire 305 licenses in the 3800 MHz band.

The company said it plans to strengthen its presence outside of Quebec, as 61 per cent of the 305 blocks of wireless spectrum it acquired are located mainly in southern Ontario, Alberta and British Columbia.

Québecor also bought spectrum in Manitoba, where it now holds a total of 46 blocks in the 600, 3500 and 3800 MHz bands, as it prepares to enter that market.

3800 and 3500 MHz are typically complementary mid-band spectrum frequencies that provide speed and capacity, Rogers explained in a release. 600 MHz is low-band 5G spectrum that carries wireless data across long distances and through dense urban buildings. The combination creates consistent and reliable 5G coverage in both urban and remote areas.

Innovation, Science and Economic Development Canada (ISED) said that licenses in the 3800 MHz band will include strong deployment obligations that require companies to “use or lose” the spectrum within ambitious timelines, so that Canadian consumers, including those in remote regions, can benefit from the latest wireless technologies.

The post 5G spectrum auction concludes; Bell, Rogers and Telus bag the most licenses first appeared on IT World Canada.

Cyber Security Today, Dec. 1, 2023 podcast – More on Booking.com compromises

More on Booking.com compromises

Welcome to Cyber Security Today. It’s Friday, December 1st, 2023. I’m Howard Solomon, contributing reporter on cybersecurity for ITWorldCanada.com and TechNewsday.com in the U.S.



 

In previous podcasts In previous podcasts I’ve reported on abuse of the booking.com hotel reservation platform. Here’s the latest news: Researchers at Secureworks last month found a mistake made by an employee led to a hacker stealing the business’ Booking.com credentials. From there the hacker sent emails from Booking.com to people who made reservations at the hotel. The messages, of course, looked official. Unfortunately somehow the attacker then stole money from the guests’ accounts. The employee’s mistake? Responding to an email from a so-called former hotel guest who wanted help finding a lost passport. The initial email didn’t have an attachment or a link, so the employee wasn’t suspicious and trusted the message. However, a follow-up email did have a link to a supposed photo of the missing passport to help the hotel employee. Clicking on that link allowed malware to be downloaded that could copy passwords on the hotel employee’s computer. The hacker used those credentials to log into the Booking.com reservation system for the hotel, and then send phishing messages to hotel guests. It helped — and you know what’s coming — that the hotel didn’t enable multifactor authentication for employee logins to Booking.com.

The U.S. has seized the website of a cryptocurrency mixer called Sinbad used by North Korea and others to launder stolen digital currency. At the same time the U.S. sanctioned the service, meaning no one in the U.S. can use it. Sinbad is used by North Korea’s Lazarus group for exchanging stolen digital currency for cash. Others use Sinbad to hide drug trafficking and child abuse materials.

Remember the Stuxnet attack of 2010? That’s when attackers were able to compromise Siemens internet-connected programmable logic controllers to damage centrifuges processing uranium at a nuclear plant in Iran. Siemens altered the coding of the software to prevent that from happening again. But researchers at Enlyze say they found a way to bypass the fixes. For the past 12 months Siemens has been saying users of its S7 PLCs should be running on version 17 or later for better security.

Fake virus warnings are popping up on the screens of people going to popular websites like the Associated Press, ESPN and CBS. You’ll be on the site and suddenly what looks like an anti-virus scanner is checking your computer — and lo and behold there are three viruses found and a recommendation you take action — like downloading a file or buying a security product. This is a scam. An infected ad on the page triggers the so-called scanner, which is a video that looks like it’s scanning something. Researchers at Malwarebytes say the gang behind this is called ScamClub.

Finally, Apple has released updates for the iPhone iOS and iPadOS operating systems to close vulnerabilities. Your devices should be running versions 17.1.2.

Later today the Week in Review podcast will be available. I’ll talk with Terry Cutler of Cyology Labs about ransomware, the latest explanation from Okta about a data theft from its customer support system and a survey of information security officers whose firms were hacked.

Links to details about news in every podcast episode are in the text version at ITWorldCanada.com.

Follow Cyber Security Today on Apple Podcasts, Google Podcasts or add us to your Flash Briefing on your smart speaker.

The post Cyber Security Today, Dec. 1, 2023 podcast – More on Booking.com compromises first appeared on IT World Canada.

Hashtag Trending Dec.1 Microsoft joins OpenAI’s board; Google Drive’s missing files unsolved; Study finds that AI’s still dumb

Microsoft becomes a board member of OpenAI, Google Drive unveils a new homepage to find files faster, while the mystery of the missing files remains unsolved and AI is still very dumb.



 

These and more top tech stories on Hashtag Trending.

I’m your host James Roy.

Microsoft has finally joined the board of OpenAI, as a non-voting observer. 

Microsoft is a 49 percent shareholder of Open’s AI’s for-profit subsidiary and its largest investor, having injected more than $10 billion this year since the start of 2023.

OpenAI made the announcement as it formalized the return of Sam Altman as CEO.

The company also thanked Microsoft CEO, Satya Nadella for help resolving the conflict that – quick catch up – overthrew Altman, irked employees and partners, saw a couple of short-lived CEOs, regrets and finally the return of Altman, like nothing ever happened. 

The reinstated CEO, says he harbors zero ill toward co-founder Ilya Sutskever, who voted to oust Altman and who has now exited the company’s board.

However, Altman said in an interview with Axios that he’d like to understand better why he was ousted in the first place.

With Microsoft joining the board, Altman also said that the “highest priority” is now to explore changes to improve the governance structure of the company – including whether OpenAI remains controlled by a non-profit entity.

Its subsidiary’s for-profit work is overseen by a non-profit board, under the company’s current structure, the goal being to ensure that AI benefits all of humanity.

The company has already said it will seek to diversify its board, which currently consists of former Salesforce co-CEO Bret Taylor as chairman, former Treasury Secretary Larry Summers and Quora CEO Adam D’Angelo.

Source: Axios, Engadget

The mystery of the missing Google Drive files is still rumbling, with Google acknowledging the issue yesterday and expecting the solution in the next two days.

In the meantime, the company is rolling out a new homepage that aims to make it easier and faster for you to find files.

Google Drive’s new “Home” view uses machine learning algorithms to automatically suggest files and folders, including ones you’ve recently opened, shared, or edited. It will also suggest any documents attached to upcoming Google Calendar events. 

And, the homepage offers new filters or “search chips,” to search documents by type, people, modified date or location. Hope it works to retrieve the missing files too.

Google Drive’s Home view is now the default homepage. However, you can switch back to the old landing page by clicking on the “Change to My Drive” option in the banner.

Source: TechCrunch

Nucleos, a startup, is making e-learning tablets available to inmates in correctional facilities to help them prepare for life after release.

Co-founder and CEO Noah Freedman, said; “Without a solution like Nucleos, almost 95 per cent of digital e-learning and training material can’t be used in prisons or jails due to security reasons. What sets us apart is that we handle all security aspects, ensuring that all e-learning programs are delivered safely and securely. Simultaneously, we disable any components that could enable prohibited communication with the outside.”

The company does not make the education materials or the tablets but acts as a one-stop shop for making these things available to the facilities.

Nucleos also tracks the courses and credentials so the person can be ready to use them for job searchers after their release.

Source: TechCrunch

Onto the less gracious things. Elon Musk told advertisers leaving X over the antisemitic content proliferating on the platform to “Go, f- themselves”

He said during the appearance at The New York Times’ DealBook event, “If somebody is going to try and blackmail me with advertising, blackmail me with money? Go f- yourself. Is that clear? I hope it is.”

X came under fire with its management of the litany of antisemitic and islamophobic content on the platform amid the Israel-Hamas war. But advertisers mostly started pulling back after Elon Musk posted a tweet wherein he seemed to agree with an antisemitic conspiracy theory.

Documents that The Times has seen reveal that over 100 brands, including Airbnb, IBM, Apple, Microsoft, Netflix and other types of advertisers such as political candidates have fully paused their ads on the platform, while dozens more are considering pulling their campaigns. X could lose up to $75 million in ad revenue earnings if advertisers do not come back. 

The company said that the revenue at risk was only around $11 million as some advertisers return or increase their ad spending.

Source: Engadget

How intelligent is artificial intelligence? Turns out not very.

The potential of achieving artificial general intelligence in the near term has been making the rounds, but many AI scientists continue to maintain that AI does not come close to human capabilities.

According to recent research from Yann LeCun, Meta’s top AI scientist, AI is still much dumber than humans in the ways that matter most.

The study co-authored by scientists from other AI startups like HuggingFace and AutoGPT aimed to look at how AI’s general-purpose reasoning stacks up against the average human.

So, the research put together its own series of questions that, as the study describes, would be “conceptually simple for humans yet challenging for most advanced AIs.”

Answering the questions would require abilities like reasoning, multi-modality handling, web browsing, and generally tool-use proficiency. For instance, the LLM was asked to visit a specific website and answer a question specific to information on that site.

The questions were given to a sample of humans and to GPT-4, the latest large language model from OpenAI.

End result? The LLMs did not do very well and were outperformed by humans.

The study concluded that the advent of AGI would depend on the system’s capability to perform on such questions as robustly as a human does.

Source: Gizmodo

And that’s the top tech news for today.

Hashtag Trending goes to air 5 days a week with a special weekend interview show we call “the Weekend Edition.”

You can get us anywhere you get audio podcasts and there is a copy of the show notes at itworldcanada.com/podcasts 

And while we cover cybersecurity stories that we think are of general interest, you can keep really up to date on cybersecurity with our podcast featuring security journalist Howard Solomon. It’s called CybersecurityToday.  It’s rated as one of North America’s top 10 tech podcasts.

I’m your host James Roy.  Have a Fantastic Friday!

The post Hashtag Trending Dec.1 Microsoft joins OpenAI’s board; Google Drive’s missing files unsolved; Study finds that AI’s still dumb first appeared on IT World Canada.