Category: News

Cyber Security Today, Nov. 29, 2023 – More ransomware attacks on the healthcare sector

More ransomware attacks on the healthcare sector.

Welcome to Cyber Security Today. It’s Wednesday, November 29th, 2023. I’m Howard Solomon, contributing reporter on cybersecurity for ITWorldCanada.com and TechNewsday.com in the U.S.



The healthcare sector continues to be a popular target of ransomware gangs. In the latest incidents Ardent Health Service, which runs 30 hospitals in Texas, New Mexico, Oklahoma and New Jersey had to divert some emergency room patients to other area hospitals after a ransomware attack. The attack started on Thanksgiving Day. Ardent has had to shut down a number of its IT systems, including its health care records.

Meanwhile for the second time in two months an American distributor of medical products called Henry Schein Inc. has been hit by the BlackCat/AlphV ransomware gang. “The threat actor from the previously disclosed cyber incident has claimed responsibility,” the company said in a statement last week. In an update issued Monday the company said it has restored its e-commerce platform in the U.S., and expects to be back online in other countries soon. The suspicion is the gang re-encrypted the company’s files when ransom negotiations stalled. Researchers at BlackFog note the company is no longer on the gang’s ransomware list of victims, possibly indicating negotiations resumed or a ransom was paid.

Separately, as part of a continuing crack-down on ransomware gangs authorities in Ukraine arrested a man man allegedly behind a group that deployed four strains of ransomware against organizations in 71 countries. The Europol police co-operative said the arrest took place last week, which also saw four others detained. The gang’s tactics included brute force attacks, SQL injection attacks and sending emails with infected attachments.

Here’s a factoid for thought: According to BlackBerry’s November threat intelligence report, 52 per cent of the new software holes listed in the National Vulnerability Database had a severity score of 7 or more out of 10. Fifteen per cent of vulnerabilities had a score of 9. Question: Does your IT department have a process for determining how fast a critical vulnerability is patched?

Here’s another set of factoids: Researchers at Hornetsecurity looked at 45 billion emails that went through its systems in the past year. More than one-third of the messages were categorized as unwanted. Of those 3.6 per cent had either malicious phishing or web links. Question: Does your IT department have solutions for effectively scanning emails for malicious content?

Here’s another piece of data I pulled from a report: There’s been a ten-times increase in the number of deepfake videos, audio recordings or documents detected in the past 12 months. That’s according to researchers at Sumsub in their annual Identity Fraud Report. Question: Does your IT department have solutions for detecting synthetically generated fraud documents?

iPhone owners who have updated to iOS 17 should think about changing the default setting of a new feature called NameDrop. According to researchers at BuddoBot, it allows users to easily share their contact info by bringing iPhones close together. However, having the capability turned on all the time is a privacy risk. All proximity-based data-sharing features on any mobile device should be turned off until they are needed.

Finally, if you use the Google Chrome browser there’s an emergency update to be installed. You should be running version 119.0.6045.200.

Follow Cyber Security Today on Apple Podcasts, Google Podcasts or add us to your Flash Briefing on your smart speaker.

The post Cyber Security Today, Nov. 29, 2023 – More ransomware attacks on the healthcare sector first appeared on IT World Canada.

Hashtag Trending Nov.29- Fake women in the speaker’s list of a tech conference; Wooden data centres; Link between poor mental health and internet usage a myth?

A conference puts fake women in its speaker’s list to showcase diversity?, Global authorities arrest members of a major ransomware group, the potential of wooden data centers and is the association between poor mental health and internet usage a myth?



 

These and more top tech stories on Hashtag Trending.

I’m your host James Roy.

DevTernity, a coding conference has been canceled after allegations surfaced that there were one or more fake women in the speaker’s list.

Eduards Sizovs, the organizer of the conference confirmed the presence of at least one fake speaker,and said “The wrong conclusion has been made: we’ve done that to ‘boost diversity.’ And that’s a big and wrong ouch,”

Gergely Orosz, author of The Pragmatic Engineer newsletter flagged the fake profiles on social media.

One of the suspected fake speakers is Anna Boyko, purportedly a staff engineer at Coinbase and Ethereum core contributor. Orosz said she did not exist, and her name was removed from the speakers’ list.

Coinbase also confirmed that it was not aware of any employees speaking at the conference.

Another dubious profile was Alina Prokhoda, said to be a Microsoft MVP and WhatsApp senior engineer and whose name also vanished off the speakers’ list. No trace of hers could be found online either.

Meanwhile, Liz Fong-Jones, field CTO at Honeycomb.io pointed out that the Instagram posts of a popular female coding influencer largely mirror those of Eduards Sizovs, the very organizer of DevTernity.

​Scott Hanselman who works on the Web Platform Team at Microsoft and who was scheduled to speak said, “I remind all tech conference organizers that there are THOUSANDS of speakers of all walks of life, genders, ages, and backgrounds.”

Source: The Register, Engadget

Law enforcement agencies from seven nations have arrested the core members of a ransomware group linked to the attacks of more than 250 servers belonging to organizations in 71 countries. These attacks netted the group hundreds of millions of euros.

Europol said that five individuals were arrested in Ukraine including the 32-year-old leader of the group and four of its “most active accomplices.”

This operation follows other arrests in 2021 when the police detained 12 more suspects that were part of the same ransomware group linked to attacks against 1800 victims in 71 countries.

The cybercriminals would normally deploy different types of ransomware such as LockerGoga, MegaCortex, HIVE, and Dharma, and then present a ransom note to the victim to pay the attackers in bitcoin in exchange for decryption keys. They also use malware like Trickbot and post-exploitation tools such as Cobalt Strike in their attacks.

A spokesperson for Europol said that the latest arrest has led to the dismantlement of the group but that  there are still a few members which are being sought after, though they are of lesser importance.”

Source: The Register, Bleeping Computer

Are wooden data centers the key to sustainable design? 

Vertiv, a US-based manufacturer of turnkey digital infrastructure solutions seems to think so.

The company introduced TimberMod, a modular wooden data center concept that’s designed to help organizations reduce their carbon footprint and meet their sustainability goals.

This comes as issues around data center emissions are sounding alarm bells for harming the environment, especially as demand for data centers continue to boom.

Data centers are often primarily composed of non-renewable resources like steel and cement. Cement, for instance, is said to account for around 8 per cent of global carbon emissions.

Timber buildings, on the other hand, are sourced from sustainably harvested wood. 

Now, it’s fair to ask about fire safety- is wood suitable for housing servers and other power-hungry equipment?  Chief technology officer, Mikael Svanfeldt at Swedish-based EcoDataCenter explained that cross-laminated timber is different from normal wood and is actually self-extinguishing due to the lamination.

Vladimir Galabov, research director at Omdia’s cloud and data center unit said, “Prefabricated data centers can already shorten build time by 40-80%. The initial indication is that prefabricated modules made of timber are quicker to build than their steel or composite material alternatives, further shortening build time. It’s time to open our minds and embrace this solution which can reduce a data center building’s carbon footprint by two-thirds.”

Source: Data Center Knowledge

Reddit might be weighing yet another IPO. 

In December 2021, the company filed a draft registration statement with the SEC to go public. That was right after Reddit bagged in a beefy $410 million financing led by Fidelity, valuing it at $10 billion. 

Then, in January of 2022, Reddit even got Morgan Stanley and Goldman Sachs to work on the listing. At the time, it was considering a valuation of as much as $15 billion.

The IPO waters got eclipsed with Reddit’s war against the moderators but it’s now back on the table.

It is not known at what valuation it would go public next year if it does go through with the offering. The company has not commented on the rumours.

Source: Tech Crunch

There have been age old claims on the negative impact of internet use, social media, smartphones etc. But a recent study from the Oxford Internet Institute (OII) seems to debunk that long-held belief.

The researchers gathered data from 2.4 million people, between the ages of 15 and 89 in 168 countries between 2005 and 2022.

The report looked at the psychological well being of the participants based on self-reports of life satisfaction, positive experiences, and negative experiences. This was then contrasted against each country’s internet and mobile broadband adoption over the past two decades.

The study also looked  at mental health using meta-analytic rates of anxiety, depression, and self-harm over 20 years and their associations with internet-technology adoption.

The researchers concluded that there have been only small and inconsistent changes in global well-being and mental health across the past twenty years and this is despite the increase in global internet usage.

One author of the research said, “It is indeed possible that there are smaller and more important things going on, but any sweeping claims about the negative impact of the internet globally should be treated with a very high level of skepticism.”

However, the report agreed with other studies on the association between social media use and life satisfaction being more negative at specific time windows in adolescence.

Meta, for instance, came under fire recently doing very little to protect the mental health of younger users on its platforms and allegedly even actively coveting and targeting these demographics.

The study called on technology firms to be more open with their information for the sake of studies like these.

Source: TechSpot

And that’s the top tech news for today.

Hashtag Trending goes to air 5 days a week with a special weekend interview show we call “the Weekend Edition.”

You can get us anywhere you get audio podcasts and there is a copy of the show notes at itworldcanada.com/podcasts 

And while we cover cybersecurity stories that we think are of general interest, you can keep really up to date on cybersecurity with our podcast featuring security journalist Howard Solomon. It’s called CybersecurityToday.  It’s rated as one of North America’s top 10 tech podcasts.

I’m your host James Roy.  Have a Wonderful Wednesday!

The post Hashtag Trending Nov.29- Fake women in the speaker’s list of a tech conference; Wooden data centres; Link between poor mental health and internet usage a myth? first appeared on IT World Canada.

AWS touts growth, investments in Canada and progress on sustainability at re:Invent 2023

Amazon Web Services (AWS) has invested C$1.4 billion in Canada since June of 2016 and plans to invest C$21 billion by 2037. That was just one of the announcements at a special briefing session for the Canadian media at AWS’ re:Invent 2023 conference this week. Rejean Bourgault, country leader and managing director, public sector for AWS Canada, outlined a number of ways in which AWS is investing in Canada and the Canadian ICT sector.

New availability zone in western Canada

Bourgault announced that the company will officially launch a new “availability zone” in Calgary in early 2024. This brings the number of zones in Canada to three, which Bourgault stated was more than any other cloud provider.

The new western zone will reduce latency for companies in Western Canada, but it will also provide a number of other benefits.

Having a new major infrastructure in the west also allows large companies and governments to have a second geographically separate backup while still retaining their data in Canada. Bourgault pointed out, for example, that military requirements specify at least 1,000 kilometre separation for backup facilities, but the new facility will far exceed those requirements, giving “more than 3,000 kilometre separation of the facilities.

“Local zone” expansion

AWS is also making more investments in what it terms “local zones” that place compute, storage, database, and other select services closer to large population areas such as the one in Toronto. The aim of these is to provide the bandwidth and latency needed to support demands for high response, low latency and the growing demand for edge computing in key locations with significant population density and high usage.

Sustainability investments

Bourgault also touted the company’s commitment to sustainability and renewable energy. AWS, he noted, is “committed to be ‘net zero’ by 2040, ten years ahead of goals of the Paris accord.”

He noted that the company has also pledged to be using 100 per cent renewable energy sources by 2025, a goal that is both realistic and achievable, according to Bourgault. He noted that Amazon is already at 85 per cent of its target and is already the “largest purchaser of renewable energy in the world.”

Such investments are critical, given that by some estimates, the ICT sector already accounts for about seven per cent of global electricity consumption, currently representing somewhere from three to five per cent of global carbon emissions. The growth in cloud computing is accelerating rapidly with the vast amount of compute required for AI, which could take it to more than 13 per cent of global consumption.

Bourgault also pointed out that meeting these objectives has further economic benefits in Canada. The company has invested hugely in wind and solar. It has announced two giant solar farms, the largest of which, with over 1.3 million solar panels, is in western Canada. It also has a new 485 megawatt wind farm coming online in Alberta.

Social and educational investment

The company has recently announced plans to help contribute to education on cloud computing and AI in Canada, aimed at creating an AI ready work force. This is part of a worldwide program that, among other things, is providing free AI skills training to over 200,000 Canadians so far and has a goal of two million Canadians by 2025.

These courses are free, and more information can be found in a story published earlier on IT World Canada.

$8.5 billion in economic impact

Overall, Bourgault noted, the company believes that in 2021, it helped create over “C$8.5 billion of economic impact in Canada,” and “contributed to the growth of 308,000 businesses, which helped increase GDP growth by 1.7 per cent.”

Addition investments would continue this trend and further support the Canadian ICT sector and its contribution to the Canadian economy.

The post AWS touts growth, investments in Canada and progress on sustainability at re:Invent 2023 first appeared on IT World Canada.

Broadcom update: Layoff notices issued for some VMware employees

There is a distinct good news-bad news scenario quickly developing now that Broadcom’s US$69 billion acquisition of VMware has been formally approved.

News of the monumental deal finally going through came last week with the approval by China, which resulted in Hock Tan, president and chief executive officer of Broadcom, issuing the following statement: “We are excited to welcome VMware to Broadcom and bring together our engineering-first, innovation-centric teams as we take another important step forward in building the world’s leading infrastructure technology company.

“With a shared focus on customer success, together we are well positioned to enable global enterprises to embrace private and hybrid cloud environments, making them more secure and resilient. Broadcom has a long track record of investing in the businesses we acquire to drive sustainable growth, and that will continue with VMware for the benefit of the stakeholders we serve.”

From a financial perspective, the good news is that, according to investment.com, analysts at UBS and BofA (Bank of America) raised their price targets for Broadcom in research notes today. BofA’s analysts “lifted their firm’s price target for the stock to US$1,200 from US$1,050 per share, reiterating a Buy rating on the stock,” an article stated.

The bad news revolves around VMware personnel departing, some by choice, others after receiving a layoff notice. Among those announcing they were leaving was former VMware CEO Raghu Raghuram, who on his LinkedIn page, posted a modified version of an internal email that he had sent out last Wednesday when the deal was finally approved.

It read, in part, “it has been my absolute privilege and honour to lead VMware for the last three years. During this time, we have navigated a dizzying journey together that spans the full lifecycle of a business — from raising debt financing to spinning off from Dell and operating as a standalone public company, to being acquired by Broadcom and executing through a complex regulatory process to finally arrive at this milestone moment in VMware’s history.

“Throughout it all, I have been amazed at the resiliency and focus of the VMware team as we repeatedly beat our financial goals, broke new ground with our product releases, and took time to celebrate the values that make us a special company.”

He went on to write, “Regardless of whether you are joining Broadcom or starting your next chapter elsewhere, I wish each of you the very best and all the success in making a positive impact in this world.

“As for myself, I plan to take a short break, rejuvenate, and then find a new and impactful mission into which I can pour my energy and passion. I will also continue my association with VMware as a strategic advisor to Hock Tan. I have no doubt that our paths will cross again. Until then, thank you, goodbye and good health.”

Other VMware employees will have no choice but to take a break after news broke yesterday that layoff notices had been issued to a number of them.

Scott Young, principal advisory director at Info-Tech Research Group, said today that layoffs at Broadcom were expected upon the closing of this deal.

The company, he said, has “a proven track record of efficiently integrating acquisitions and ensuring that its Total Debt to LTM Adjusted EBITDA ratio trends relatively rapidly downward. Its playbook to do this will include immediately eliminating duplicate and administrative functions wherever possible as soon as possible. The expectation would be that the bulk of layoffs will fall into these categories.”

The recent restructuring of VMware into four divisions (VMware Cloud Foundation, Tanzu, Software Defined Edge, Application Networking and Security), added Young, “shows that Broadcom sees growth in infrastructure and potentially has less interest in the (unmentioned) end user compute area of the business. This could potentially lead to another area where jobs could be eliminated.”

The post Broadcom update: Layoff notices issued for some VMware employees first appeared on IT World Canada.

Coffee Briefing Nov. 28 – Canadian 5G users will pay more for quality experience; Holiday shoppers on board with GenAI; KPGM and Chainalysis partner; and more

Coffee Briefings are timely deliveries of the latest ITWC headlines, interviews, and podcasts. Today’s Coffee Briefing is delivered by IT World Canada’s editorial team! 

Missed last week’s Coffee Briefing? We’ve got you covered.

Canadian 5G users want the best quality of experience and will pay more for it

A new study by Ericsson ConsumerLab reveals more than one-in-five Canadian 5G smartphone users will pay more for a 5G plan that ensures elevated network performance. This would include a plan that caters to high-performing video streaming, gaming, and other popular apps that boost user satisfaction. 

The 5G Value: Turning Performance into Value report by Ericsson ConsumerLab examines the business potential for communication service providers (CSPs) as consumer satisfaction with 5G rises, with Canada showing a 12 per cent year-over-year increase. 

This increase is fuelled by more 5G devices in the market, faster speeds, and an increase in 5G availability.

The report also found that Canadian 5G users are three times more likely to switch providers over poor 5G connectivity experiences in crowded locations like shopping malls and arenas. 

In addition, 41 per cent of users demand more data to justify price hikes, with 17 per cent looking for bundles with innovative services. Twenty two per cent expect high quality performance, and prioritize connectivity.

Canadian holiday shoppers interested in GenAI, Acenture survey finds

Source: Accenture

According to Accenture’s 2023 Holiday Shopping Survey, 45 per cent of global retail executives said they are experimenting with generative AI to see how it can enhance their business.

Canadian consumers are on board with it too, especially if the technology helps them save time and money. However, the more invasive it gets, the more resistant consumers are.

Key consumer highlights from Accenture’s survey reveal: 

49 per cent would welcome AI assistance online to track prices and notify them of significant reductions.
42 per cent would welcome AI assistance with returns and refunds.
27 per cent would welcome AI in recommending other products that pair well with their purchase history, such as accessories to match a dress.
22 per cent would welcome AI assistance for virtual try-ons; for example, to see if a clothing item suits them.

Deloitte Canada reaches agreement for carbon credits with CarbonCure

As part of Deloitte Canada’s commitment to sustainability and climate action, the firm has announced a multi-year agreement with CarbonCure Technologies for the purchase of high-quality carbon credits. Through this agreement, Deloitte said it will directly support the deployment of CarbonCure’s carbon removal technologies around the globe.

Recognized as the North American Cleantech Company of the Year in 2020, and grand prize winner of the Carbon XPRIZE in 2021, the Halifax-based firm has developed technologies that, according to a release, “inject captured and liquefied CO2  from industries and Direct Air Capture (DAC) into concrete. This not only permanently stores CO2 , but increases the concrete’s strength, resulting in economic and climate benefits.”

The multi-year agreement, it said, helps evolve Deloitte’s carbon management strategy to support development and scale of meaningful market solutions.

“Corporate buyers play a critical role as early investors in climate solutions that enable decarbonization of high-emitting industries and permanent carbon removal,” said Sheri Penner, managing partner of purpose and sustainability at Deloitte Canada. “Supporting the development and verification of high-quality carbon removal credits is crucial to scale the gigaton market that is needed to meet net-zero.”

KPMG in Canada, Chainalysis team up with pact to prevent crypto fraud

Source: KPMG and Chainalysis

KPMG in Canada and Chainalysis have announced they are teaming up to help reduce the threat of crypto fraud with the signing of a strategic agreement in which KPMG will join the Chainalysis Solution Provider program. 

The collaboration advances the certification of KPMG professionals as Chainalysis Certified Investigators, a release stated, which in turn enhances their ability to assist clients across public sector agencies and private sector businesses to detect and prevent illicit activity related to cryptoassets.

“Our clients look to us as trusted advisors in the cryptoasset space, and our relationship with Chainalysis is a commitment to helping those clients be more agile, innovative and compliance-focused in an ecosystem that’s constantly evolving,” said Kunal Bhasin, partner and cryptoassets and blockchain co-leader at KPMG in Canada. “This collaboration will help to further solidify KPMG’s expertise in forensic investigations and cryptoassets and blockchain technology.”

The combination, the release said, leverages the expertise of both firms to provide enhanced blockchain monitoring, support, governance, and risk management to help organizations adhere to evolving cryptoasset regulations and advance their Anti-Money Laundering Compliance programs.

Persistent claims first with new open source maintenance service

Source: Persistent Systems

This week, provider of digital engineering and enterprise modernization services Persistent Systems launched what it called a “unique maintenance service” that it said is the first-of-its-kind, and keeps an organization’s open source software up to date with all patches, bug fixes, and the latest software releases.

A release from the firm said the new offering is comprised of a “dedicated team of experts and specialists dealing with a wide range of complex software, equipped with the latest technologies, and backed by a knowledge base to help clients maintain their open source software with all releases for the continuity of business operations.”

Known as Persistent Open Source Hub and available on a subscription basis, the offering is a partnership between Persistent and Lineaje Inc., which specializes in software supply chain security management and whose technology and AI capabilities are integrated into the service.

Lineaje will enable Persistent to help clients gain visibility into open-source components and provide impact assessment and prioritization of maintenance based on compatibility, integrity, and security in their supply chain, the release said.

“While open source software offers numerous advantages, it also presents particular challenges in an enterprise environment,” it said. “Organizations face delays in software upgrades and maintenance while waiting for the open source community to provide fixes, which in turn means potentially missing software delivery and security compliance obligations.”

More to explore

AWS re:Invent grabs the spotlight, with cloud, cybersecurity and AI in a business focus

As its re:Invent conference opens in Las Vegas this week, AWS will make the case that it, too, has a leading role in the transformation that lies at the nexus of artificial intelligence, cloud computing and cybersecurity.

OpenAI saga ends as deal reached to reinstate Altman as CEO

Ousted OpenAI CEO Sam Altman will be returning to his position with the company, OpenAI said in a post on X (formerly Twitter).

Canadian organization are not prepared for new ESG standards and reporting regulations, study finds

Canadian organizations are nowhere near ready for the new environmental, social and governance standards and reporting regulations, a study finds.

Mitacs celebrates researcher spearheading the development of next-gen AI networks

Nonprofit research organization Mitacs conferred the Mitacs Award for Exceptional Leadership on Georges Kaddoum, a top researcher at Montreal-based École de Technologie Supérieure (ÉTS).

Ottawa and provinces should harmonize privacy laws, says think tank

Ottawa should consider squeezing the provinces to enact similar federal, provincial and territorial privacy laws across Canada, says a new paper from the C.D. Howe Institute, which argues commonality will benefit businesses and consumers.

Broadcom’s VMware acquisition now official, GlobalData issues warning

The time it took for the US$69 billion purchase of VMware by Broadcom to finally be approved has potentially affected VMware’s standing and share value in the cyber security industry, says data and analytics firm GlobalData.

Channel Bytes November 24, 2023 – Open source maintenance service launches; KPMG in Canada & Chainalysis partner against crypto fraud; Protera offers enterprise cloud management platform; and more

Staying informed is a constant challenge. There’s so much to do, and so little time. But we have you covered. Grab a coffee and take five while you nibble on these tidbits.

Listen to the latest episode of Hashtag Trending

Hashtag Trending Nov.28- Files disappear from Google Drive; Meta’s spokesperson on Russia’s wanted list; Japanese tech startups woo employees back into the office with cash bonuses

Listen to the latest episode of Cybersecurity Today

This episode reports on the latest ransomware attacks, and details of how a gang that scams people selling used products online works

 

Listen to the latest episode of Hashtag Tendances

If you live in Québec, or prefer to consume the latest technology news in French, our sister publication Direction Informatique has you covered. Follow them on Twitter as well.

The post Coffee Briefing Nov. 28 – Canadian 5G users will pay more for quality experience; Holiday shoppers on board with GenAI; KPGM and Chainalysis partner; and more first appeared on IT World Canada.

Compel social media apps to toughen their privacy, trust practices, Parliament told

Social media platforms should be forced by the Canadian government to toughen their privacy practices, an expert told a parliamentary committee looking into illicit data harvesting by apps like China-based TikTok for foreign governments on Monday.

Ottawa banned federal employees in February from using TikTok on government-owned internet-connected devices following a similar ban in the U.S. in December 2022. Ottawa added a ban on using China-based WeChat in October.

“Despite being framed as a national security threat, to date there’s still no public evidence that the Chinese government has spied on Canadians using a backdoor or privileged access to the TikTok app,” Anatoliy Gruzd, Canada Research Chair in Privacy-Preserving Digital Technologies at Toronto Metropolitan University, told the House of Commons Ethics, Privacy and Access to Information Committee.

However, he added, “there are valid concerns regarding the potential for TikTok and other platforms to be exploited by malicious actors for propaganda and radicalization.”

For example, he said, according to a national survey his research lab released last year, half of Canadians reported encountering pro-Kremlin narratives on social media. And in August, Meta — which owns Facebook and WhatsApp — reported a sophisticated influence operation from China that spanned multiple platforms, including Facebook, Twitter, Telegram, and YouTube. The operation tried to impersonate E.U. and U.S. companies, public figures, and institutions, posting content that matched their identity before shifting to negative comments about Uyghur activists and critics of China, he said.

Therefore, Gruzd said, “we must take a comprehensive approach to address these issues by compelling platforms to commit to

— adopting the principles of privacy by design and by default;

— investing in expanding their trust and safety teams by partnering with fact-checking organizations and providing access to credible news content. “Unfortunately,” he said, “some platforms, like Meta and X, are doing the exact opposite;”

— and sharing their data with researchers and journalists. TikTok currently doesn’t provide data access to Canadian researchers but does offer it to those in the U.S. and Europe. “Sadly,” Gruzd said, “TikTok is not alone in this regard. X has recently shut down its free data access for researchers,”

It’s important to shift the focus from the responsibility of internet users to only share personal information online when necessary to one of developing strategies that compel social media companies to implement privacy by design and by default, Grudz said.

“Currently, it’s all too common for platforms to collect more data by default than necessary,” he said.

Parliament shouldn’t ban all Canadians from accessing an app, Gruzd added. That could lead to mistrust of Ottawa, legitimize censorship and create an environment for misinformation to thrive.

Last week, Cherie Henderson, an assistant deputy director of the Communications Security Establishment (CSE), which oversees the protection of federal communications, told the committee about foreign government use of social media. Much of her presentation was reflected in the annual National Cyber Security Threat Assessment released last October.

While Henderson said she worries about foreign interference here from Iran and North Korea, she saved her toughest words for Russia and the People’s Republic of China (PRC).

“Foreign state actors leverage all viable means to carry out their foreign interference activities, and social media platforms are ideal tools,” she said. “The Russian Federation and PRC exploit social media to spread disinformation, leveraging suggestive algorithms to amplify echo chambers and manipulating content for unsuspecting viewers.”

“The PRC uses its unfettered access to harvest data at a scale that outpaces every other country in the world combined, while fiercely protecting their own information. Emerging technologies, such as artificial intelligence, will only further enable their nefarious activities.”

“It is imperative that Canada builds resilience against foreign interference. This includes bolstering awareness of the PRC’s ability to harvest and use Canadians’ information obtained through social media to conduct foreign interference.”

Threat actors like social media platforms because of the data they generate and collect, she noted. Platforms run surveys, correlate data sets and request access to users’ personal data through terms and conditions, enabling access to users’ messages, photo albums and contact lists. Some of this data is benign in isolation, she said. But when collected and correlated on a massive scale it can provide detailed patterns and insights on populations, public opinion and individual networks.

As a result, Henderson said, Canadians should think carefully before sharing personal information on social media apps “especially when it is with foreign-owned companies” whose governments are not our allies.

The post Compel social media apps to toughen their privacy, trust practices, Parliament told first appeared on IT World Canada.

Hashtag Trending Nov.28- Files disappear from Google Drive; Meta’s spokesperson on Russia’s wanted list; Japanese tech startups woo employees back into the office with cash bonuses

Files vanishing off Google Drive, Russia adds Meta’s spokesperson to its wanted list, self-driving cars and their struggle for public acceptance, and Japanese startups test cash bonuses to woo employees back into the office.



 

These and more top tech stories on Hashtag Trending.

I’m your host James Roy.

Google Drive users took it to support forums after they found months of their work mysteriously vanished off the service.

One user claimed that their storage reverted to how it was in May 2023 and attempts to recover files remained unsuccessful.

Other users reported that synchronization had simply stopped working, so the cloud storage was out of date. Others claimed that they could get some of their information back by fiddling with cached files.

However, a message purporting to be from Google warned users to leave things alone until engineers come up with a solution.

That issue is still rumbling, although here’s yet another stark reminder that your files are not necessarily safe just because they’re stored in the cloud.

OVH suffered a disastrous fire in 2021, leaving customers scrambling for backups, and Google also has had its fair share of odd outages over the years.

Bleeping Computer advises its readers to backup important files locally or use a different cloud service until the problem is resolved.

Source: The Register; Bleeping Computer

Last year, Russia added Meta to its list of “terrorists and extremists” and has now decided to put the company’s spokesperson, Andy Stone, on its ‘wanted’ list.

The row between Russia and Meta started when Meta announced it was limiting the reach of Russian state-sponsored media on its platforms, when Putin’s forces invaded Ukraine.

When Russia’s invasion began, Stone announced temporary changes to Meta’s hate speech policy to allow for “forms of political expression that would normally violate (its) rules, like violent speech such as ‘death to the Russian invaders’”.

But Stone also maintained that “credible calls for violence against Russian civilians” would remain banned.

Anyway, this led to Russia blocking access to Meta’s Instagram and Facebook, and other Western platforms. The sites are only now available in Russia via VPNs.

Russia also formally barred Facebook CEO Mark Zuckerberg from entering the country.

Source: Axios

Robotaxis has had a bad rap over the last few months, and quite deservingly so, whether it be for jamming up the road or hurting pedestrians.

General Motors-owned Cruise had to pull its entire U.S. fleet of 950 driverless cars off the road after a series of such fiascos.

And paradoxically, the big promise of self-driving cars remains safety and making transportation accessible to everyone.

But how do you actually get people to trust self-driving cars, especially after a series of fiascos.

John Krafcik, former CEO of Google’s self-driving car project, Waymo, tells Axios that there are no shortcuts when it comes to the rollout of safe autonomous vehicles.

He said, “With technology as important as this one, we’ve always thought we need to make sure we launch with care and consideration so that it gains traction, that the technology endures, and that it delivers its full potential to the world.”

Advocates president Cathy Chase added that the way you build trust is to be transparent. 

Both Waymo and Cruise have published studies claiming their driverless vehicles are safer than human drivers, but safety experts flag the lack of evidence and limited data in their studies.

Chase says that AV companies should be candid: “‘These are the limitations of the vehicle. These are our concerns. This is what we’re trying to overcome, but she says, “We don’t see that.”

Source: Axios 

The UK’s National Cyber Security Agency (or NCSC) and US’s Cybersecurity and Infrastructure Security Agency (or CISA) have published an official guidance for securing AI applications.

Lindy Cameron, CEO at the NCSC said the guidelines seek to “ensure that security is not a postscript to development but a core requirement throughout.”

The guidelines adopt a secure-by-design approach, ideally helping AI developers make the most cyber-secure decisions at all stages of the development process. They’ll apply to applications built from the ground up and to those built on top of existing resources.

The guidelines would also look at the secure deployment of an AI system, like protecting the infrastructure, including access controls for APIs, models, and data.

And the final section of the guidelines covers how to secure AI systems after they’ve been deployed, encompassing maintenance and operations.

The guidance document is being endorsed by 17 countries, including Canada, Australia, France, Germany, Italy, Japan and more.

Source: The Register 

California’s Privacy Protection Agency (CPPA) is also preparing to put guardrails on AI.

The agency published draft regulations which would include opt-out rights, pre-use notice requirements, and access rights, which would enable state residents to obtain meaningful information on how their data is being used for automation and AI tech.

AI-based profiling could even fall within the scope of the planned rules. So, there could be big implications for U.S ad tech giants like Meta which has a business model that hinges on tracking and profiling users to target them with ads.

And that’s assuming the draft regulations survive the usual consultation process. 

Source: Tech Crunch

Tech companies, from the likes of Amazon, IBM, Meta, TikTok and even remote work poster child Zoom, have been determined to get their employees to come back to the office.

Japanese startups, meanwhile, are taking it back to the basics: with small bonuses for in-person working.

Osaka-based Agileware says it is offering employees ¥2,000 or roughly $13 for every day they show up to the workplace, while privacy tech firm Acompany has decided to award developers and those who “handle other tasks” about  ¥1,000 or about $6 for showing up after lunch for a half day of in-office work.

Agileware is also offering employees an extra $3 to go out to lunch with their colleagues, though both bonuses are reportedly limited to 10 days a month and require four hours to be spent in the office. That’s still $168 if employees take full advantage of the monthly deal. It might pay for meals, give employees a bit of face time together and, perhaps, a mental health boost.

Meanwhile in the West, Amazon, Meta, IBM and others have threatened to stifle employees’ career advancement if they do not come back to the office.

Wonder which approach works best…

Source: The Register 

And that’s the top tech news for today.

Hashtag Trending goes to air 5 days a week with a special weekend interview show we call “the Weekend Edition.”

You can get us anywhere you get audio podcasts and there is a copy of the show notes at itworldcanada.com/podcasts 

And while we cover cybersecurity stories that we think are of general interest, you can keep really up to date on cybersecurity with our podcast featuring security journalist Howard Solomon. It’s called CybersecurityToday.  It’s rated as one of North America’s top 10 tech podcasts.

I’m your host James Roy.  Have a Terrific Tuesday!

 

The post Hashtag Trending Nov.28- Files disappear from Google Drive; Meta’s spokesperson on Russia’s wanted list; Japanese tech startups woo employees back into the office with cash bonuses first appeared on IT World Canada.

Canada’s CIO Catherine Luelo resigns, highlights the fractured federal IT systems at the House of Commons

Catherine Luelo, Canada’s chief information officer, has announced her resignation, two years after taking up the job to modernize the technology systems of the federal government.

Shortly after the news broke, Luelo appeared by videoconference as a previously scheduled witness before the House of Commons Ethics Committee’s hearings into the use of social media by foreign entities for unethical or illicit sharing of personal information.

She was called on because of her recommendation in February to forbid federal employees from using China-based TikTok on federally-issued internet-connected devices. 

Luelo confirmed she will be leaving her post at the end of December, although she did not specify her reasons for leaving. However, she discussed the state of the federal IT systems, starting by referencing the recent report of the Auditor General on the progress of its IT modernization program.

In that report, the Auditor General said that the Treasury Board, which oversees the shared IT systems most departments use, “did not do enough to lead and support partner departments and agencies to modernize outdated information technology systems. It has been more than 24 years since the government first identified aging systems as a significant issue and the secretariat still does not have a strategy to drive modernization.”

Two thirds of the departments’ and agencies’ applications were reported as being in poor health and in critical need of modernization, that report said.

Luelo made clear that the former head of Treasury Board was supportive of her work.

But, she added, “I think [the Auditor General’s report] is a good and accurate reflection of where we find ourselves in terms of our current state of technology. We’ve not advanced in the last 13 years, and I don’t think that is a win for Canadians. In terms of my tour of service, it was always intended to be that [a term, rather than a career], and I hope that other private sector leaders will do the same. It is an incredible opportunity.”

She became Canada’s CIO in July 2021, at the height of the pandemic, which greatly shed light on the dire need for the government to modernize its IT systems and deliver efficient and secure services to citizens. 

A year into her appointment, she spearheaded the Digital Ambition, a government-wide strategy focusing on several digital transformation priorities, including ensuring operations are safe, progress is measurable, service is consistent and personalized for citizens, and a digital-first mindset reigned in the government.

However, speaking at technology conference FWD50 recently, Luelo addressed the numerous challenges that the various levels of government face in their digital transformation journey.

She said, “The government has to do the “hard work” of modernizing core and underlying systems, some of which are 50 years old.” Modernizing large projects, she added can be like a “well of despair,” adding they require “a lot of hard, but perhaps not so sexy work.”

Recent research by IDC, in fact, showed that 92 per cent of government agencies recognize that there is the need for a digital first strategy. Despite that, only 33 per cent are actively moving to it, while another 40 per cent are getting lost in the complexity and multiplicity of digital channels.

Related:

Government of Canada’s DX journey riddled with cyber-struggles, technical debt and staffing concerns: Report

The same research points to roadblocks like growing cyber threats, struggles with combining old and new technology systems, resulting in technical debt, and the lack of talent, an issue also acknowledged by Luelo.

“That role has to be one of the toughest CIO jobs in the country,” said David Shipley, chief executive of New Brunswick’s Beauceron Security. “She led during some of the most intense years where online government was more important than ever to Canadians.”

He added, “The technology debt at the federal government level is Herculean and requires much more support and attention at the political level and more scrutiny and interest by everyday Canadians. Neither of which I think are forthcoming.”

Luelo affirmed at FWD50 that public servants have to build credibility and win back the trust of Canadians by getting projects done on time and budget.

She said during the House of Commons Committee meeting today, “I wish we could go more quickly on things. We need to go more quickly on things. I think there is an overhead dealing with all of the different layers around government, past and present.”  

This story will be updated.

The post Canada’s CIO Catherine Luelo resigns, highlights the fractured federal IT systems at the House of Commons first appeared on IT World Canada.

Google upgrades Vertex AI, foundation models, adds Meta’s Llama 2, Anthropic to portfolio and more

Today, at Google Cloud Next 2023, Google announced that it is expanding the capabilities of Vertex AI, upgrading its own foundation models and is adding new third-party models to its Model Garden, including Meta’s Llama 2, Anthropic Claude 2 and more.

Upgrades to Vertex AI

Vertex AI, Google’s cloud-based platform for building, training and deploying machine learning models, received a series of upgrades to let it keep up with the generative AI boom.

This comes after the company made generative AI support generally available on Vertex AI in June, giving customers access to Google’s large generative AI models and tooling, including PaLM 2, Codey APIs, Text Embedding API and Imagen.

Today, it announced that Vertex Search and Conversation is now generally available,  allowing developers to ingest data, add customizations, or build a search engine or chatbot “with a few clicks”.

This product will have additional features including multi-turn search, which supports follow-up questions without starting the interaction over, and conversation and search summarization, as well as grounding, which roots generative AI outputs in enterprise data. 

The addition of Vertex AI extensions to Search and Conversation can retrieve information in real time and act on behalf of users across Google and third party applications, while Vertex AI data connectors help ingest data from enterprise and third-party applications such as Salesforce, Confluence, and JIRA.

Further, Google introduced two new products for Vertex AI focused on data science and machine learning engineering.

First is Colab Enterprise, announced in public preview today, enabling data scientists to accelerate AI workflows with access to Vertex AI platform capabilities, integration with BigQuery for direct data access, and even code completion and generation.

Second is a new MLOps Framework for predictive and generative AI to help customers navigate challenges around enterprise-readiness. It includes features that allow developers to tune models based on their specific needs, evaluate the quality of their models, as well as avoid data duplication and preserve data access policies.

Upgrades to Google’s foundation Models

Google announced upgrades to PaLM 2, Google’s large language model. That includes the general availability of 38 languages in PaLM and the possibility for customers to ground responses with their own enterprise data. 

The new version of PaLM 2 for text and chat also supports longer question-answer chats, with 32,000-token context windows, enough to include an 85-page document in a prompt. 

Further, Google announced that output from its code generator model, Codey, will be improved in quality by 25 per cent in major supported languages, for code generation and code chat.

Also, Google improved the visual appeal of its text-to-image foundation model, Imagen, and its recently added capabilities such as image editing, captioning, and visual questions and answering.

Notably, Google announced it is testing a digital watermarking feature to give customers the ability to verify AI-generated images produced by Imagen. This new experimental feature is powered by Google DeepMind SynthID, which, Google says, embeds the digital watermark directly into the image of pixels, making it invisible to the human eye, and very difficult to tamper with, without damaging the image. 

Additions to the Model Garden

Google is bringing Meta’s Llama 2 and TII’s Falcon into its Model Garden, and pre-announcing Claude 2 from Anthropic. Adding these models, Google says, will let enterprises match models to their needs and access full transparency into a model with Meta’s and Falcon’s open-source options.

Nenshad Bardoliwalla, who leads the product teams for Vertex AI at Google Cloud, announced during the opening keynote that Meta’s new Code Llama, unveiled last week, will also be available to all customers and partners in the Model Garden.

Developers and data scientists will also be able to tune these models with their own enterprise data with Colab Enterprise.

The post Google upgrades Vertex AI, foundation models, adds Meta’s Llama 2, Anthropic to portfolio and more first appeared on IT World Canada.

Authorities take down Qakbot infrastructure, issue commands to delete the malware

Government authorities have scored another — if perhaps temporary — win in the fight against cybercriminals.

Police in seven countries, including the U.S., said Tuesday they infiltrated and took down the infrastructure behind the Qakbot botnet, and then used that access to order infected computers to delete the malware.

The action, dubbed Operation Duck Hunt, represents the largest U.S.-led financial and technical disruption of a botnet infrastructure leveraged by cybercriminals to distribute ransomware, commit financial fraud, and engage in other cyber-enabled criminal activity, the U.S. Justice Department said in a statement.

The malware was used by many threat actors, including ransomware groups, as initial weapons of IT system compromise.

The Qakbot malware [called QBot or Pinkslipbot by some cybersecurity companies] primarily infects victim computers through spam email messages containing malicious attachments or hyperlinks, the U.S. statement says. If a computer is successfully infected, Qakbot can deliver additional malware, including ransomware, to the infected computer. Qakbot has been used as an initial means of infection by many prolific ransomware groups in recent years, including Conti, ProLock, Egregor, REvil, MegaCortex, and Black Basta.

According to BlackBerry, Qakbot was discovered in 2008. After updated versions were made available in 2015, Qakbot gained new momentum among threat actors. in 2020, threat researchers noted that the release of a novel Qakbot strain resulted in a 465 per cent increase in its year-over-year share of cyberattacks. In 2021, Qakbot was leveraged in the prominent cyber-breach of JBS, which disrupted its meat production facilities and forced an US$11 million ransom payment.

RELATED CONTENT: Black Basta adopts Qakbot

As part of the takedown, the FBI was able to gain access to Qakbot infrastructure and identify over 700,000 computers worldwide, including more than 200,000 in the United States, that appear to have been infected with Qakbot.

To disrupt the botnet, the FBI was able to redirect Qakbot botnet traffic to and through servers controlled by the FBI, which in turn instructed infected computers in the United States and elsewhere to download a file created by law enforcement that would uninstall the Qakbot malware. This uninstaller was designed to untether the victim computer from the Qakbot botnet, preventing further installation of malware through Qakbot.

In addition to the U.S., authorities in France, Germany, the Netherlands, the United Kingdom, Romania, and Latvia participated in the coup. As part of the combined action, US$9 million in cryptocurrency was also seized. Also credited with helping are Zscaler, Shadowserver, the Microsoft Digital Crimes Unit, the National Cyber Forensics and Training Alliance, and the Have I Been Pwned service.

Qakbot is a long-standing operation spanning more than a decade that has adapted and evolved with the times, noted Kimberly Goody, senior manager of Mandiant’s financial analysis unit. It initially focused on traditional banking fraud, and later pivoted to act as a foothold to support ransomware intrusions. “Any impact to these operations is welcomed, as it can cause fractures within the ecosystem and lead to disruptions that cause actors to forge other partnerships – even if it’s only temporary. Actors who were using Qakbot in ransomware intrusions, for example, may pivot to underground communities for initial access providers, resulting in more varied initial access tactics in the near term.”

Disrupting the Qakbot botnet of more than 700,000 victim computers is a great accomplishment for the FBI and their partners, said Chester Wisniewski, field CTO of applied research at Sophos. It will impose significant inconvenience on the botnet’s operators and dependent criminal groups. He added, “Sadly this will not stop Qakbot’s masters from reconstituting it and continuing to profit from our security failures. Any time we can raise the cost for criminals to operate their schemes we must take advantage of those opportunities, but this doesn’t mean we can rest on our laurels, we must continue to work to identify those responsible and hold them accountable to truly disable their operations.”

The post Authorities take down Qakbot infrastructure, issue commands to delete the malware first appeared on IT World Canada.