Category: News

CyberTowns Initiative Aims to Spotlight Canada’s Top Locations for Cybersecurity Careers

A new program called CyberTowns is setting out to identify the best communities across Canada to start and grow a career in the cybersecurity and IT fields. Launched by the Canadian Cybersecurity Network and IT World Canada, the initiative will evaluate cities on factors like job opportunities, affordability, population growth, taxes, crime rates, weather, health amenities, community support, and internet access.

The goal is to highlight the unique advantages different municipalities offer in attracting and retaining cyber and IT talent. With cybersecurity skills in high demand, CyberTowns aims to showcase the locales positioned to thrive in this increasingly crucial industry.

“Cybersecurity professionals are a precious commodity in today’s digital economy,” said Francois Guay, founder of the CyberTowns program. “This initiative will recognize the cities cultivating environments where cyber careers can truly flourish.”

The six-month evaluation process involves surveying cybersecurity and IT professionals across Canada, as well as an analysis of key statistical data. Only communities with a population over 100,000 will be considered for the rankings.

An independent review committee will assess the findings before the results are published in a comprehensive report detailing each location’s advantages, challenges, and efforts to drive cybersecurity growth. Provincial and federal policies impacting the cyber workforce will also be examined.

The culmination will be an awards ceremony at the Canadian Identity Summit in Ottawa on April 30-May 1, 2024, where Canada’s top “CyberTowns” fostering cyber talent will be celebrated.

Partnership opportunities are available for sponsors looking to support this initiative highlighting the nation’s cybersecurity hubs. Interested organizations can visit the CyberTowns website for more details on how to get involved.

As cyberthreats continue to escalate, nurturing skilled cyber professionals has become an economic and security imperative for communities across Canada. The CyberTowns program promises to shine a light on the cities rising to meet that challenge.

The post CyberTowns Initiative Aims to Spotlight Canada’s Top Locations for Cybersecurity Careers first appeared on IT World Canada.

Cyber Security Today, April 5, 2024 – New ransomware gang claims 11 victims, Ivanti promises to overhaul product security, and more

A new ransomware gang claims 11 victims, Ivanti promises to overhaul product security, and more.

Welcome to Cyber Security Today. It’s Friday, April 5th, 2024. I’m Howard Solomon, contributing reporter on cybersecurity for ITWorldCanada.com and TechNewsday.com in the U.S.

 



 

A new ransomware group emerged last month. Dubbed the RedCryptoApp, researchers at Netenrich say the gang has published data allegedly stolen from 11 organizations. That includes five in the U.S., and one each in Canada, Denmark, Spain, Italy, India and Singapore. Victim firms are in the software, manufacturing, IT, education, construction and hospitality sectors. the gang has likely been in business since December.

After the discovery of several product vulnerabilities in the last three months Ivanti is promising a new era of security. CEO Jeff Abbot said Thursday that the company is looking critically at every phase of its development processes to ensure the highest level of protection for customers. The promise includes revamping of core product engineering and using secure-by-design methodology. This comes after four new holes in Ivanti Connect Secure and Policy Secure Gateways were disclosed. Patches are available now. In January Ivanti revealed two vulnerabilities in Connect Secure and Policy Secure, followed three weeks later by the disclosure of two more holes had been found. A fifth was disclosed in February. A suspected Chinese threat group is believed to be among those exploiting the vulnerabilities. Among the victims: The U.S. Cybersecurity and Infrastructure Security Agency (CISA).

The current value to cybersecurity pros of the Common Vulnerabilities and Exposures (CVE) List and the National Vulnerability Database is being questioned. That’s partly because the U.S. National Institute of Standards and Technology, which maintains the national database and uses the CVE list, has a backlog of vulnerabilities to process. NIST hopes a consortium of industry, governments and others will help. But SecurityWeek columnist Kevin Townsend also says the CVE database, which is overseen by the not-for-profit MITRE organization has its own problems. A hundred thousand vulnerabilities have no CVE number. And not all of those that do are real vulnerabilities. There’s also a problem with rating the criticality of vulnerabilities, which impairs the ability of IT administrators to decide which bugs needs to be patched first. IT pros need to pay attention to this issue and offer solutions.

IT administrators are being warned to check with their server providers for security updates to close vulnerabilities in their implementation of HTTP/2. A number of applications are vulnerable to a denial of service attack including Red Hat and SUSE Linux, the Apache HTTP Server Project including Apache Tomcat and Traffic Server, the Go programming language, AMPHP (a library for PHP-based projects) and some products from Arista Networks. Discovered by researcher Bartek Nowotarsk,i the root cause is an incorrect handling of headers and multiple Continuation frames which ultimately leads to Denial of Service. If no fix is available admins may have to disable HTTP/2 on servers.

Finally, Sophos released its latest Active Adversary report on cybersecurity attacks its staff investigated. For the fourth year in a row the most common way threat actors got into Windows systems was by taking advantage of security holes in a remote desktop server. In 90 per cent of attacks Sophos investigated last year abuse of RDP was in some way involved. In one case, an organization was compromised four times within six months through a customer’s exposed RDP ports. How are attackers abusing RDP? The most common way in the 150 cases investigated last year was through compromised credentials. In 43 per cent cases the organizations did not have multifactor authentication to protect logins. Is your IT department securing remote access?

Later today the Week in Review podcast will be available. Guest commentator Terry Cutler of Cyology Labs and I will discuss recent news including a report highly critical of Microsoft’s security by the U.S. Cyber Safety Review Board, a case study of a ransomware attack and a plot to infect a critical Linux library.

Follow Cyber Security Today on Apple Podcasts, Google Podcasts or add us to your Flash Briefing on your smart speaker

The post Cyber Security Today, April 5, 2024 – New ransomware gang claims 11 victims, Ivanti promises to overhaul product security, and more first appeared on IT World Canada.

Cyber Security Today, April 3, 2024 – New Linux vulnerability is found, and a must-read ransomware case study

A new Linux vulnerability is found and a must-read ransomware case study.

Welcome to Cyber Security Today. It’s Wednesday, April 3rd, 2024. I’m Howard Solomon, contributing reporter on cybersecurity for ITWorldCanada.com and TechNewsday.com in the U.S.



Following on the shattering discovery of a backdoor hidden in an open-source Linux compression utility comes news of a new Linux vulnerability. It’s in the util-linux package, and it’s been around since 2013. Briefly, the vulnerability allows a users’ password to be leaked. So far, says the researcher who discovered the hole, Ubuntu 22.04 is affected. Linux administrators should check with their distribution creators to see if their servers are affected.

An organization dedicated to cybersecurity has admitted a misconfigured server led to a data breach. The Open Worldwide Application Security Project, more commonly known as OWASP, says the misconfiguration was in an old Wiki web server. Copied was a decade-old list of resumes of members who joined between 2006 and 2014. They gave their resume as part of their membership application, which included names, email addresses, physical addresses and phone numbers. OWASP no longer collects resumes when members join. The incident was discovered in late February.

You may not have realized, but Google has been collecting browsing activity when you switch into Incognito Mode. Now, to settle a class action lawsuit, it’s going to delete that data. The suit alleged browsing data was collected without the knowledge of users. According to Time, Google says it never associated this data with users who are in Incognito Mode. News that there would be a settlement was announced in December. The details were only released on Monday.

The Rhysida ransomware gang has taken credit for an attack on MarineMax, an American boat retailer with branches in 13 U.S. states. According to Security Week, the gang is auctioning allegedly stolen data.

A small Michigan school board temporarily closed its doors Monday after being hit by a cyber incident. Traverse City Area Public Schools said it disconnected access to the IT network and began a comprehensive investigation.

Finally, the authors behind the DFIR Report have produced a detailed case study of a ransomware attack in 2023 against an unnamed company that should be read. Briefly, it started with an employee clicking on an infected attachment that was hosted on a Microsoft OneNote server. Threat actors are using malicious OneNote attachments to get around email security gateways that would see OneNote as a legitimate source of messages. In this case the malicious document led to the download of a Windows dynamic link library, or DLL to maintain persistence. Interestingly, after that not much happened for 33 days. Then malware was launched, and the AnyDesk remote access software was installed so the attacker could browse through the network. Unfortunately for the victim organization the employee who inadvertently started the thing was a member of the domain administrator’s group, which helped the attacker gain access privileges. From there …. well, I’ll give away the ending: The attacker exfiltrated data, and only encrypted two of the organization’s servers: The file server and the backup server. There’s a lot more in the story. This article should be read by anyone in IT, or studying for a career in IT, on how a cyber attack is carried out. There’s a link to it — as well as to other stories mentioned in today’s episode — in the text version of this podcast at ITWorldCanada.com.

Follow Cyber Security Today on Apple Podcasts, Spotify or add us to your Flash Briefing on your smart speaker.

The post Cyber Security Today, April 3, 2024 – New Linux vulnerability is found, and a must-read ransomware case study first appeared on IT World Canada.

Cyber Security Today, April 1, 2024 – An alert about a critical Linux vulnerability, a warning about password-spray attacks on Cisco VPNs, and more

An alert about a critical Linux vulnerability, a warning about password-spray attacks on Cisco VPNs, and more.

Welcome to Cyber Security Today. It’s Monday, April 1st, 2024. I’m Howard Solomon, contributing reporter on cybersecurity for ITWorldCanada.com and TechNewsday.com in the U.S.



Linux administrators and developers must take fast action after the discovery of a backdoor that can compromise some Linux distributions. It’s in a malicious version of the XZ Utils compression utility. For certain this library is in some versions of Red Hat Fedora, Debian Unstable and possibly other Linux distributions. Developers, users and admins should make sure they are using a version of XZ Utils before version 5.6.0. Red Hat says the use of Fedora Rawhide and Fedora Linux 40 should stop immediately unless it uses an older version of the compression utility. Red Hat Enterprise Linux is affected. Developers and users should consult with distributors of other versions of Linux for guidance. This vulnerability is rated critical. Under the right circumstances a threat actor could exploit the vulnerability to gain remote access to a Linux system.

The U.S. Cybersecurity and Infrastructure Security Agency urges developers and users who have affected systems to move to a safe version of the operating system, then hunt for any malicious activity. Any positive findings should be reported to CISA.

Threat actors are using password-spraying tactics to infiltrate Cisco Systems’ Secure Firewall. The warning comes from Cisco, which notes that password-spraying is also being used to attack VPN concentrators used by large enterprises. One tip-off your organization has been hit: Users can’t log into the VPN. Another is a log that shows huge numbers of rejected authentication attempts. Cisco urges network admins to make sure their Secure Firewall software is running the latest version. Admins should also use certificates for authentication to Cisco Secure Firewall rather than passwords. More broadly, security admins should ensure their gateway devices are properly configured.

JetBrains released a bunch of fixes for the on-prem version of its TeamCity continuous integration server. In total 26 security problems were fixed. By the way, starting with version 2024.03, TeamCity can auto-download lightweight security patches for crucial security issues.

Makers of keycard-controlled door locks used in hotels and offices should pay attention to research released last month. White-hat hackers discovered vulnerabilities in Saflock door locks made by Dormakaba which open using an RFID wireless technology. Actually, according to an article in Wired, they discovered the holes two years ago at a Black Hat Las Vegas conference. The manufacturer was notified in 2022 and has been working with hotels to fix or replace the vulnerable locks. On releasing their research last month the team estimated only 36 per cent of installed locks around the world have been updated. By the way, part of their research involved getting hold of and reverse engineering the manufacturer’s front desk software. How did they do that? They asked around. Vendors assume no one copies their software, the researchers said. There’s a lesson in that.

AT&T is forcing over 7 million of its current customers to reset their four-digit passcodes. This comes after an investigation into the posting of stolen data two weeks ago on a dark website. The American telecommunications carrier said Saturday that information on just over 73 million customers — 65 million of them former subscribers — are involved in the data posting. It isn’t clear where the data was stolen from. AT&T says the information appears to be from 2019 or earlier. It includes names, email addresses, mailing addresses, phone numbers, Social Security numbers and dates of birth.

The Chattanooga Heart Institute has issued a fourth update on the number of people affected by a data breach just over a year ago. In a filing with Maine’s attorney general’s office it now says over data on 547,000 people was stolen. Initially it said data on over 170,000 people was copied. Data stolen included credit or debit card numbers along with the security codes passwords or PIN numbers.

Prudential Insurance of America is notifying over 36,000 people that some of the personal data it holds was stolen in early February. Data copied included names, drivers’ licence numbers or identification card numbers.

Security experts urge IT departments to move to cloud application providers where possible for a number of reasons. One is that the provider can apply security updates faster than an on-prem IT team. However, that doesn’t solve all security problems. American university researchers recently discovered a new vulnerability if an organization uses a cloud email filtering service — such as Proofpoint or Barracuda — that scans incoming mail before passing it on to the firm’s cloud email system — for example, Gmail or Exchange Online. If the email system hasn’t been configured to only accept messages from the email filtering provider then malicious email could get through to employees. A clever threat actor could identify the server user by the company’s domain’s email hosting provider and send malicious mail directly to it. In other words, the attacker bypasses the email filtering provider. The researchers believe 80 per cent of email filtering systems can be bypassed. The lesson to IT departments: Make sure your email systems are properly configured.

Follow Cyber Security Today on all major podcast distributors including Apple and Spotify.

If you want a daily dose of general IT news, we also offer Hashtag Trending every morning. Subscribe wherever you get your podcasts.

The post Cyber Security Today, April 1, 2024 – An alert about a critical Linux vulnerability, a warning about password-spray attacks on Cisco VPNs, and more first appeared on IT World Canada.

The state of AI: Hashtag Trending, the Weekend Edition – Documentary Part 2

The state of AI is the second in this series prepared for the long weekend. In part one, we traced the evolution of Artificial Intelligence. In episode two, we discuss where we are today in the implementation of AI using a model developed by Jackie Fenn, a Gartner analyst who developed the “Hype Curve” – a way of understanding the introduction and maturity of technology developments and trends in a commercial setting.

We try to give some perspective on why there is such enthusiasm for AI, but so little in the way of practical implementations. In doing this we propose some reasons why companies must move forward. We also propose some ideas about how companies can move forward.

The post The state of AI: Hashtag Trending, the Weekend Edition – Documentary Part 2 first appeared on IT World Canada.

Cyber Security Today, Week in Review for the week ending Friday, March 29, 2024

Welcome to Cyber Security Today. This is the Week in Review for the week ending Friday, March 29th, 2024. From Toronto, I’m Howard Solomon, contributing reporter on cybersecurity for ITWorldCanada.com and TechNewsday.com in the U.S.



In a few minutes David Shipley of Beauceron Security will be here to discuss recent news. That includes a U.S. Senator’s call for the healthcare sector to meet minimum cybersecurity standards, whether the Canadian military’s Cyber Force needs more resources, what World Backup Day should mean to IT leaders and Beauceron Security’s new State of Security Awareness report.

But before we get to the discussion a quick look at other news from the past seven days:

You might think that financially motivated hacking gangs, or countries like Russia, North Korea and China are responsible for most of the zero-day vulnerabilities exploited in the wild. Nope. According to the latest numbers compiled by Google, commercial surveillance software companies that make spyware for governments were responsible for at least 58 of the 97 exploited zero-day vulnerabilities discovered last year. China was the biggest source of government-backed exploits with 12. Another trend, which may come as no surprise from my reporting: Attackers are increasingly planting zero-day vulnerabilities in open source components and libraries like GitHub, where it is hoped they can be widely spread in finished applications. Among the report’s recommendations: Software and product vendors should prepare for how they will respond when an in-the-wild zero-day is discovered targeting their applications.

At least 17,000 Microsoft Exchange servers in Germany are vulnerable to attack because they don’t have the latest security patches or are running outdated versions. That’s according to the country’s information security agency. Threat actors are already exploiting some of these servers, the agency adds.

A Chinese-language phishing-as-a-service platform called Darcula has been detailed in a report by researchers at Netcraft. The platform has been used for many high-profile email and text phishing attacks over the past year, including package scams pretending to be from the United States Postal Service. The site sells monthly subscriptions to hundreds of templates for phishing messages, abusing the names of airlines, utilities, financial institutions, government departments and telecom companies.

A number of organizations admitted this week to being hit by ransomware:

The INC ransomware gang threatened to publish data allegedly stolen from two districts in Scotland’s health service.

The Qilin ransomware gang says it hit The Big Issue, a street newspaper distributed in the U.K. The publication’s chief executive told the news site The Record that it is dealing with a cyber incident.

In this country the town of Huntsville, Ont., said the March 10th cyber attack it suffered was ransomware. Some data was “compromised,” the town said. But it couldn’t say at this point whether that included personal information.

In the U.S., the Tarrant County Appraisal District in Texas said it was hit by a ransomware attack on March 21st. The authority appraises property for an area that includes the city of Fort Worth. The Medusa ransomware gang is demanding US$700,000.

Gilmer County in Georgia said it took some IT systems offline in response to a ransomware attack.

The city of St. Cloud, Fla., told a local news service that municipal files were locked by ransomware.

And Harvard Pilgrim Health Care has updated the number of Americans it is notifying about a 2023 ransomware attack. That number is now just over 2.8 million people, an increase of several hundred thousand over the original notification.

(The following is an edited transcript of part of the discussion. To hear the full converstation play the podcast)

Howard: Your company, Beauceron Security, just released its second annual State of Security Awareness report. One of the biggest weapons that threat actors rely on is tricking employees into doing something that they shouldn’t — Click on an infected attachment, download corrupt software, allow a password to be changed and so on. These all lead to the installation of malware and data theft. So employee cybersecurity awareness is one of the biggest defences an organization can mount. Are there encouraging numbers in this report?

David Shipley: There are very encouraging numbers that look at organizations that have been running [awareness] programs that have become progressively more mature year after year. One of the most hopeful things that I saw over three years of study we’ve done with more than 150,000 people — most of them here in Canada — was double-digit improvements in attestations by employees. They go through a process where they’re surveyed annually about their attitudes and their knowledge levels — which for the record is the only way to get insight into that: You have to ask people these questions. We see major rises in adoption and use of password managers, in avoiding risky behaviours like reusing passwords or storing organizational information in personal clouds. People will change over time, but I can back it up with quantitative data in that we’ve seen year-over-year continuous improvements in almost every single industry that we work in. There’s a few exceptions, but we can see that consistent [awareness] programs that deliver education and simulations show great results. I’m really encouraged. There’s lots in the report that helps people sort of understand what maturing looks like, what going from a compliance-oriented, ‘check the box awareness program’ to one that actually can provably, demonstrably, reduce risk and drive return on investment looks like.

Howard: What about discouraging numbers in the report? I saw, for example, that only 22 per cent of respondents said that they report a phishing email or text the day is received.

David: Report rates are an underused metric across this industry. The report rate is the number of people who were sent to a [phishing] simulation who looked at it, decided something was wrong and took an active action — clicked a button or forwarded it — to say, ‘This looks like a phish.’ It’s a far more reliable and less manipulable metric for [measuring] security program effectiveness than a click rate, which which can be subject to chance and all kinds of fun things. Report rates are a metric of resilience and educational efficacy. What’s really cool is the higher you drive that number the more confident you are that people are more likely to catch and stop something than fall victim, the more likely you are to catch a bunch of stuff that are getting by email filters.

I just ran an internal test for Beauceron and we were able to look at what our email filter provider said they stopped for phishes and then we found out how many phishes got by thanks to reporting. We realized that we had a 20 per cent leakage rate last month for all the phishes that the email filter said it had stopped. But that still left a lot of phishes landing on us. There are things there to pay attention to.

The other thing in the report we’re highlighting is we are seeing a tightening of security budgets as a result of the continued economic waves from the pandemic. One of the areas that get squeezed is security awareness, and it’s such a shortsighted move.

Howard: Metrics are vital for each organization to understand where its employees are weak in awareness and the training they need. How do you gather these metrics and what are the most important metrics to measure employee security awareness?

David: In our industry oftentimes the metrics that are most cited are activity-based or point-in-time click rates, training completion percentage success rates — What was the average score? These are useful, but they are not outcome-based. What’s extremely valuable is a qualitative survey where people tell you how they feel about things and whether they’re getting the knowledge they need. You might think you can’t trust people. Listen, if your organization is so broken that you cannot trust people at all to tell you the truth your biggest problem isn’t cybersecurity. Surveys have to be balanced, but social sciences have proven a lot of different ways that we can gain value and confidence levels from human responses. So we need to do more listening [to staff].

The other thing is we need to start coming up with really good return-on-investment models for security awareness. We’re one of the few companies saying unlimited training does not yield the business benefits that some are advocating. We’ve seen some of our sector say that you should be spending 60 minutes annually and five minutes per month. That works out to be more than two hours of security awareness training per year, and we think that that is really expensive. The incremental benefit of that versus 30 minutes spread throughout the year is pretty damn small. We’re going to work on proving that because the biggest cost of a security awareness program is not licensing a [training] platform It’s the time you’re taking from employees from their regular jobs that really adds up.

Howard: What’s effective in getting employees to change behaviour so they do things that are more cyber safe?

David: One of the most important things that we’ve learned from the work we’ve done is saying, ‘Thank you.’ Saying, ‘Job well done.’ is the most powerful motivator. The system that we design is built around the concept of a personal cyber risk score. We give people positive incentive points when they do the right thing, and demerit points when they make mistakes. We give them a chance to learn from those mistakes. We’ve seen our [suspicious email] report rates skyrocket — we’ve get an increase in report rates of 90 per cent in the first 90 days because we changed the phishing simulation game. Right now in most phishing simulation exercises there are only two states: An employee either clicked the [test] phish and they lost the exercise, or they didn’t click on it. But when you have a positive recognition when people report the phish, they succeed. Even if they report it after they fall victim to a phish you still give them some kind of a win … Then you can do some cool things like give gift cards tied to random draws for the people that reported all 12 simulations.

Howard: One final thing: Expecting your staff to be perfect 100 per cent of the time isn’t realistic. No matter how much awareness training you do the organization also has to have defence in depth, multifactor authentication to protect logins, robust patch management network segmentation and the list goes on.

David: Absolutely. I will be the first to say to any organization out there if you think that just buying a security awareness platform solves all of your problems and all of your dreams are going to come true — No, But we [training platforms] are an absolutely important part of driving that.

The other part is it’s not just about telling employees about password strength or what phishing is. It’s about explaining their role in protecting their organization recognizing them for doing the right thing and giving them new tools to improve their digital literacy — particularly those who are managers. That actually drives the buy-in to achieve defence in depth. So many organizations are missing the opportunity to use their awareness campaign to generate [executive] buy-in to drive their security maturity. You can’t just do that with vendor content. It is not a fire-and-forget approach. But you can do it over time. We’ve worked with lots of organizations who’ve done that. I hope folks who are listening consider downloading the report. There’s lots of great advice in there and it doesn’t matter what platform you’re using. If you take some of these practices that we’re recommending into your program I guarantee 100 per cent it’s going to improve results for you.

The post Cyber Security Today, Week in Review for the week ending Friday, March 29, 2024 first appeared on IT World Canada.

The road to AI: Hashtag Trending, Weekend Edition – March 29, 2024

Welcome to Hashtag Trending, the Weekend Edition. I’m your host, Jim Love. On this long weekend, I thought we’d try something a little different.

I find that when I break my daily routine and get some time away, I can take a moment and reflect – see the bigger picture – and use that perspective to look forward. It’s chance to think strategically.

So, this weekend, that’s what I want to do with the issue that is dominating technology and business – Artificial Intelligence.

The road to Artificial Intelligence 

https://hashtagtrending.libsyn.com/the-road-to-ai-hashtag-trending-the-weekend-edition-for-march-29-2024

You can use this player or go to anyplace you get your podcasts and look for Hashtag Trending.

The Story

What I’ve produced is more of a documentary than an interview show and I’ve done it in two parts. The first part is a history of AI, taking it from earliest times and up to the launch of ChatGPT. It’s part historical, part philosophical. But I also think it lays a foundation for understanding our pursuit of AI and our fascination with it.

The second part or episode, is more in the current day and down to the practicalities of business and technology.

I’ll look at why what is called generative AI is transformational. Those of you who are fans of the show will know that I’m enthusiastic about technology, and I love it, but I’ve been in this game for 40 years – I try not to be caught up in the hype about any product, service or development.

So I’m not going to predict the future, all I’m going to do is talk about this like a scatter diagram. You put a lot of points on a two by two matrix and sometimes they’re all over the place. Other times, they start to show a pattern, they point in a direction.

Generative AI is like that, its seems like its all over the map, but when you connect the dots and draw the line, it leads you to what seems to me to be inevitable – one of the biggest transformations how we work and how we live in human history.

And not only is the change inevitable, but the pace of that change and the impact of that change, may be greater than we could possibly imagine.

So in our second episode, were going to take stock of what has happened the less than two years since ChatGPT was launched.  We’ll take stock of where we are now and we’ll look at what will happen over the coming months with a focus on what that will do, primarily to our businesses.

It will still take time for changes to work their way into our lives, but it will be less than you might think. And change – our ability to adapt, takes time as well.

Again, no hype – just drawing a line to the inevitable.

Here’s our first episode:

The road to Artificial Intelligence

https://traffic.libsyn.com/hashtagtrending/A_history_of_AI_episode_1.mp3The post The road to AI: Hashtag Trending, Weekend Edition – March 29, 2024 first appeared on IT World Canada.

Cyber Security Today, March 29, 2024 – PyPI repository shuts to stop malicious uploads, a plea to developers to stop creating apps with SQL vulnerabilities, and more

PyPI repository shuts to stop malicious uploads, a plea to developers to stop creating apps with SQL vulnerabilities, and more.

Welcome to Cyber Security Today. It’s Friday, March 29th, 2024. I’m Howard Solomon, contributing reporter on cybersecurity for ITWorldCanada.com and TechNewsday.com in the U.S.



I’ve reported before that threat actors are increasingly uploading malicious code into open-source repositories like GitHub and NPM. Well, things got so bad yesterday that the Python Package Index, known as PyPI, had to temporarily suspend new project creation and new user mitigation. According to researchers at Checkmarx, the administrators likely had to do this because someone automated the uploading of malware-filled Python code. A favourite tactic is to give the bad code a file name similar to a legitimate package that developers regularly look for. If a developer unknowingly plants malicious code in their application it can be exploited by the threat actor to steal data from software users or the developer. As I’ve said before, anyone downloading code from an open-source library has to take precautions. Make sure you’re not downloading something that’s infected.

The U.S. is offering a reward of up to US$10 million for information about anyone connected to the AlphV/BlackCat ransomware gang. This comes after the gang claimed responsibility for the February attack on American medical billing services provider Change Healthcare. According to some news reports the company paid US$22 million to the gang to get access back to scrambled data. Since then there have bveen reports the gang is dissolving.

A new Linux version of the XDealer remote access trojan has been discovered. It’s also called DinodasRAT by some researchers. Kaspersky says the new variant of this backdoor largely targets servers running Red Hat and Ubuntu Linux. There’s no detail in the report about how servers are infected. So far compromised servers have been seen in China, Taiwan, Turkey and Uzbekistan.

U.S. cyber authorities are begging application developers to stop creating software with SQL injection vulnerabilities. Ways of doing that have been around for 20 years. But software companies are still releasing products open to SQL compromise. Example number one: Progress Software’s MOVEit file transfer application, which the Cl0p ransomware gang leveraged last year to steal personal data on 94 million people from over 2,700 organizations around the world. Here’s a link to the advice to safely create applications.

Companies operating in critical infrastructure sectors in the U.S. have just under two months to comment on proposed regulations for cyber incident and ransom payment reporting to the Cybersecurity and Infrastructure Security Agency. Briefly, the proposed rules says some 316,000 organizations would have to report certain incidents within 72 hours after discovery, and within 24 hours of paying a ransom. Hospitals with under 100 beds would be exempt.

Also this week the Agency warned that threat actors are actively exploiting a code injection vulnerability in Microsoft SharePoint Server. This vulnerability was revealed 12 months ago. There’s no reason why IT departments haven’t installed a patch by now.

The Vulture malware that steals bank login information from Android devices has added new features. Researchers at NCC Group/Fox-IT say that among other things the malware can now disable Keyguard to bypass lock screen security on infected devices. Often victims are suckered into downloading the malware by falling for a text message that asks them to call a number if they didn’t authorize a large financial transaction or purchase.

Finally, a number of companies issued security patches for their products this week:

Splunk issued upgrades for Splunk Enterprise, Cloud Platform and Universal Forwarder. Cisco Systems patched the IOS and IOS XE software for multiple vulnerabilities., as well as its Access Point software. Nvidia released a software update for its ChatRTX artificial intelligence chatbot for Windows to close two holes. And the Cybersecurity and Infrastructure Security Agency released four advisories for industrial control systems. Three are for products from Rockwell Automation involving its PowerFlex 527, Arena Simulation and FactoryTalk ViewME products. The other is for Automation-Direct’s C-MORE display system.

Later today the Week in Review podcast will be available. Guest David Shipley of Beauceron Security will discuss his company’s latest State of Security Awareness report, what World Backup Day should mean to IT pros, a call for the U.S. healthcare sector to meet mandatory minimum cybersecurity standards, and more.

Follow Cyber Security Today on Apple Podcasts or add us to your Flash Briefing on your smart speaker.

The post Cyber Security Today, March 29, 2024 – PyPI repository shuts to stop malicious uploads, a plea to developers to stop creating apps with SQL vulnerabilities, and more first appeared on IT World Canada.

40 thousand routers compromised: Hashtag Trending for Wednesday, March 27th, 2024

A new cyberthreat is taking down home routers. Germany passes a law insisting on end to end encryption. Reports expose the craziness of tech hiring practices, the US government has had it with SQL injection attacks and Elon Musk gets a smackdown from a federal judge as we see more from the X files – The Musk is out there

These stories and more on the “check your references” edition of Hashtag Trending. I’m your host, Jim Love, let’s get into it:

A major new cyber threat has been uncovered that is targeting routers and smart home devices around the world. Researchers at communications company Lumen Technologies have revealed details of a widespread hacking campaign that has already infected tens of thousands of vulnerable devices.

A notorious botnet known as TheMoon, which researchers thought was taken down years ago, has been resurrected by hackers. In just a 72-hour period earlier this month, it infected more than 6,000 Asus routers.

But that’s just the tip of the iceberg. Lumen’s investigation uncovered that from January through February, TheMoon compromised over 40,000 routers and smart devices across 88 countries.

Many of these infected gadgets are now being used to power a criminal proxy service called Faceless, allowing users to disguise their identities and malicious internet activities.

Experts believe TheMoon’s revival is linked to cybercriminals seeking new ways to cover their tracks as law enforcement ramps up investigations into online crime rings. Nearly 7,000 new users are joining the Faceless network weekly.

While the specific hackers are unknown, it’s a disturbing broader trend. Lumen has seen seven separate campaigns just in the last two years exploiting vulnerabilities in routers and other smart home technology with poor security controls.

For consumers, the advice is clear – keep your router software updated with the latest security patches. Lumen has blocked access to the infected devices on its networks for now, but this evolving threat underscores how prevalent outdated and insecure connected devices have become.

Sources include: Axios

In a stark contrast to efforts by many governments to undermine digital privacy, Germany is taking a totally different approach by enshrining the “right to encryption” into law.

While the United States, United Kingdom and others push for ways to weaken encryption in the name of security, the German government is taking the opposite approach – drafting first-of-its-kind legislation to make end-to-end encryption mandatory for messaging, email and cloud service providers.

The proposed law, published this week by Germany’s Ministry for Digital and Transport Affairs, would require tech companies to use strong encryption wherever technically feasible to guarantee confidentiality and protect users’ fundamental rights.

Digital rights activists are applauding the draft bill as a landmark win for online privacy and data protection – areas where Germany has historically been a leader with its strict data laws.

The legislation specifies that “individual messenger services” can no longer forgo full encryption or only partially encrypt, unless there are legitimate technical limitations.

Maximilian Funke-Kaiser, digital policy spokesperson for Germany’s Free Democratic Party, says it’s a “necessary measure” to prevent future erosions of encryption after anti-encryption efforts like the controversial “Chat Control” proposals.

While the draft law still needs to pass Parliament, likely in 2025, its intent is being celebrated by privacy proponents as Germany bucks the global trend of governments seeking encryption backdoors or client-side scanning capabilities.

Ten years after encrypted email service Tutanota launched in Germany, the country is now poised to be the first in the world to enshrine digital secrecy and “the right to encryption” as fundamental citizen rights in federal law.

Sources include: Tuta

The U.S. government is cracking down on SQL injection flaws once and for all.

SQL injection attacks have plagued websites and applications for decades, allowing hackers to maliciously access and manipulate backend databases. Now, U.S. authorities say they’ve had enough of companies shipping products with these “unforgivable” vulnerabilities.

In a new alert, the FBI and the Cybersecurity and Infrastructure Security Agency are pressuring software vendors to launch formal code reviews and build security into their development lifecycles from the ground up.

Their call comes after last year’s massive supply chain hack against Modefit file transfer software, enabled by a SQL injection zero-day flaw that exposed data on 95 million individuals.

SQL injection holes exist when user input isn’t properly sanitized, allowing it to modify back-end database queries maliciously.

While a well-known issue for over 15 years, the government says such vulnerabilities are still prevalent and indefensibly included in new software releases.

Vendors are being advised to incorporate “secure by design” principles – using techniques like parameter binding that separate code from user input – rather than relying on brittle sanitization filters easily bypassed by hackers.

Beyond pushing for better coding practices, the alert urges transparency, telling companies to properly disclose SQL flaws using the standard CVE system so customers can track their exposure.

Analysts say the government message is clear – businesses dragging their feet on well-established security basics are jeopardizing the economy and national security.

Sources include: The Register

A federal judge has dismissed a high-profile lawsuit from Elon Musk’s social media platform X against an anti-hate group in a ruling is seen as a victory for free speech over the billionaire’s attempts to stifle criticism of his company’s policies.

The lawsuit against the Center for Countering Digital Hate, an organization that has been highly critical of the social network’s handling of hate speech and misinformation under Elon Musk’s ownership.

In a scathing ruling, Judge Charles Breyer said X’s motivation was clear – “to punish the defendants for their speech” criticizing the company, and perhaps “dissuade others” from similar criticism in the future.

The Center had published reports blasting X, formerly known as Twitter, for failing to act on hateful content posted even by premium users. It also alleged racist and antisemitic posts went unaddressed.

Musk’s company sued the non-profit last year, claiming it had waged a “scare campaign” that drove away advertisers and cost X tens of millions in lost revenue. It accused the Center of unlawfully scraping data from the platform.

But Judge Breyer dismissed the breach of contract and illegal scraping allegations, saying X did not adequately show any actual losses. He stated that if the Center’s reports were defamatory, that would be one thing – but X carefully avoided claiming they were.

The Center says the landmark ruling will embolden public interest researchers to ramp up efforts holding social media companies accountable for hate and misinformation they host.

It’s a stinging rebuke of Musk’s scorched-earth legal tactics against one of his chief critics – the very kind of speech his self-professed “free speech” stance claimed to uphold.

Sources include: The Verge

Is tech hiring is broken? The tech industry’s hiring practices are facing intense scrutiny.

It’s a tale of two extremes when it comes to hiring at Big Tech.

On one side, you have Google’s notoriously grueling interview process that has rejected highly skilled engineers. Ironically, one that they rejected is the creator of the popular Homebrew package manager, that a lot of Google teams use.

At Google, countless would-be employees talk about interviews that fixated on theoretical problems and rote memorization over practical troubleshooting abilities.

On the other, you have Meta reportedly hiring candidates for critical AI roles without any interviews at all, such is the company’s desperation to rapidly onboard talent amid the artificial intelligence arms race.

And Meta has CEO Mark Zuckerberg personally recruiting from rivals like DeepMind and offering extravagant counteroffers just to stanch the AI brain drain caused by the company’s push into generative AI.

However, the rush to hire has Meta employing candidates sight-unseen based on credentials alone, raising eyebrows about vetting standards.

The dysfunction isn’t limited to those two companies either. Accounts also depict Amazon discarding engineers every two years in a philosophy of constantly refreshing its workforce with new, wide-eyed talent.

Big tech’s hiring insanity is putting talent through the wringer or failing to properly evaluate it at all.  And then, of course, there’s the layoffs.

Just checking – anybody think there’s a correlation between Google’s hiring process and its failure to get traction with anything that grabs public imagination?

In a world where we know that your big advantage is your team and culture, this situation is nuts. I’ve said it before and I’ll say it again – we are smart people, with emphasis on people. We can do better than this.

Sources include: IndiaToday

And finally, the Daily Beast did a story on how older people are falling for AI generated fakes on Facebook.

According to a research report quoted in the article, older people are much more likely to be fooled by AI generated pictures and voices.

We used to dread the “talk” we had to have with our kids. Well, there’s another “talk” youhave to have – with your parents.

There’s one scam in particular that is growing – the fake kidnapping of a child.

If you think it can’t happen to you, I’ll tell you, my dad – a smart man – was fooled by a similar scam where someone told him my brother was being jailed and needed bail to get out. He sent them money. When he told me about it, he said, he knew it could be fake, but could he take the chance?

Now with AI and deep fakes, anyone could be fooled and they are being. So here’s out public service announcement and most our audience may be pretty savvy, but tell your friends – get a password with your kids and if you don’t have one, and god forbid you ever get one of these calls, ask for what the cops call proof of life – some piece of info only your kids or grandkids would know – not something they’d put on Facebook. Think about it now – not when you or your parents get a call in the middle of the night.

Sources include: The Daily Beast and WCPO TV

And that’s our show for today…

Remind your friends that they can get us anywhere you get audio podcasts Google, Apple, Spotify, wherever, and even on their smart speakers – and remind yourself that if you like the podcast, please give us a good review – it matters. And as I’m sure you know, there is a copy of the show notes at itworldcanada.com/podcasts

I’m your host, Jim Love. Have a Wonderful Wednesday.

 

 

The post 40 thousand routers compromised: Hashtag Trending for Wednesday, March 27th, 2024 first appeared on IT World Canada.

Cyber Security Today, March 27, 2024 – A botnet exploits old routers, a new malware loader discovered, and more warnings about downloading code from open source repositories

A botnet exploits old routers, a new malware loader discovered, and more warnings about downloading code from open source repositories.

Welcome to Cyber Security Today. It’s Wednesday March 27th, 2024. I’m Howard Solomon, contributing reporter on cybersecurity for ITWorldCanada.com and TechNewsday.com in the U.S.



Despite repeated warnings that old internet-connected devices are being compromised by threat actors, organizations and individuals continue to keep these devices online and inadvertently help spread malware. The latest alert comes from researchers at Lumen, who say a network of 40,000 infected small and home office routers and other devices are part of a criminal botnet. The botnet creates a network dubbed Faceless to anonymize the attacks of crooks. This botnet, in operation since 2014, is infecting these unpatched devices with malware that looks for and infects other devices. In the first week of March the botnet targeted over 6,000 Asus routers in less than 72 hours. Many small organizations and individuals install a router or internet-connected video camera and forget about it for years. They can’t. Like desktop computers and smartphones, any internet-connected device has to be regularly checked to see if security updates are available. And if updates aren’t available any more, these devices have to be replaced.

Attention owners of Apple devices running the iOS and macOS operating systems: New security patches are available to close a vulnerability.

Canadian discount retail chain Giant Tiger continues dealing with the theft of customer information earlier this month. That data was stolen from a company that manages its customer marketing. Giant Tiger is telling affected customers that their names, email addresses, street addresses and phone numbers are among the information that may have been copied. Victims subscribed to Giant Tiger email advertising, registered in a loyalty plan, or placed an order for home delivery or store pickup. No payment card data or passwords were stolen.

Threat actors are going after what some believe is a critical vulnerability in Anyscale Ray, a widely used open source artificial intelligence framework. Researchers at Oligo say it’s one of five recently discovered holes in Ray. Four were patched, but one issue hasn’t been addressed so has been exploited for the last seven months. All organizations using Ray are urged to review their IT environments to ensure they haven’t been compromised.

A new malware loader has been spotted that can bypass antivirus defences. Researchers at Trustwave, who spotted the loader, say at the moment it’s distributing the Agent Tesla malware. Agent Tesla executes in memory and steals data such as passwords from infected computers. In the incident Trustwave investigated an employee of an organization got an email with an attachment purporting to be a payment receipt from a bank. That tactic may change to other themes, all of which are aimed at getting a victim to click on the attachment. Every organization has to have a strategy of regularly reminding employees of suspicious signs to watch for before accepting email attachments.

Here’s another reminder to be careful downloading code from open-source repositories. Researchers at ReversingLabs recently discovered a suspicious package in the NuGet repository for .NET packages. This .dll may be targeting developers working with apps for a Chinese company called Bozhon Precision Industry. It makes a wide range of consumer and industrial products. If installed in an application this suspicious package takes screenshots from infected devices. Is the purpose to spy on Bozhon and steal data? To spy on its customers? Or was it created by a Bohzhon developer to help their work? No one knows. But it has been downloaded 2,400 times. As I said, it’s another example to be careful what you download.

Open-source repositories of code are targets for hackers because it’s a great way to spread malware. This week researchers at Checkmarx described a complex campaign by a threat actor to infect software supply chains. It includes compromising a GitHub community of developers and taking over accounts, and creating a mirror of the Python PyPi registry to publish an infected version of the popular ‘Colorama’ package. The malware that’s being spread harvests browser cookies, login credentials, credit card numbers, data from cryptocurrency wallets and more. Again, developers have to take great care in downloading packages for their applications even from trusted sources.

May 31st of every year is World Backup Day. This year it falls on Sunday. Regardless, the purpose is to remind senior corporate and IT leaders to review their data backup and recovery plans. Data backup is a vital part of any organization’s cybersecurity defence strategy. Start with identifying where your sensitive data is. It’s not just in the server or servers where data is initially stored. Sensitive data can be copied multiple times by staff for analysis, so it can be on employees’ desktop computers, sitting in individuals’ email folders or copied onto file transfer servers. You’ve got to know where data is to protect it, and then to back it up. Then decide how often data needs backing up in line with the organization’s recovery objectives. Some firms need to do it every minute, others at the end of the day. Whatever your needs are, data has to be backed up in several places — one copy on prem and one copy in the cloud at the very least. Finally, data backups and recovery have to be tested regularly not only for integrity but also so the IT staff involved have the practice down pat. You’ll find lots of advice on backups from government sources like the National Institute on Standards and Technology and the U.S. Cyber Security and Infrastructure Security Agency. On this Friday’s Week in Review podcast guest commentator David Shipley and I will discuss more about backups.

Finally, crooks continue to use phone scams to scare families for cash. One of the latest was reported Monday by a Cincinnati TV station, which said a local appliance store owner got what he thought was a hysterical call from his daughter. Then a man got on the line and demanded US$5,000 or his daughter would be harmed. Fortunately, a store employee heard what was happening and phoned his daughter, who was safe in school. This was a so-called virtual kidnapping. It may be helped by technology that can impersonate a voice. There are variations of this scam. For example, a supposed family member calls and says they’ve been in a car accident and need money immediately for a lawyer, or to be released on bail. The crooks may want money wired to them. Or they may want the victim to pay in cryptocurrency or a prepaid gift card. These are prime signs the call is a scam. How can you protect your family from being taken by scams like this? First, if you have a second phone call the family member who’s supposedly in trouble. If they answer the phone and say they are safe hang up on the scammer. Also, agree on a family codeword to be used in case there is trouble. Your family member has to give the codeword as proof they really are in trouble.

Follow Cyber Security Today on Apple Podcasts, Google Podcasts or add us to your Flash Briefing on your smart speaker.

The post Cyber Security Today, March 27, 2024 – A botnet exploits old routers, a new malware loader discovered, and more warnings about downloading code from open source repositories first appeared on IT World Canada.