Category: News

Cyber Security Today, Week in Review for Friday, February 24, 20223

Welcome to Cyber Security Today. From Toronto, this is the Week in Review edition for the week ending Friday, February 24th, 2023. I’m Howard Solomon, contributing reporter on cybersecurity for ITWorldCanada.com and TechNewsday.com in the U.S.



In a few minutes Terry Cutler of Montreal’s Cyology Labs will be here to discuss recent news. But first a summary of some of what happened in the last seven days:

Twitter users will soon have to pay to get their two-factor authentication (2FA) codes by SMS. They’ll have to subscribe to the premium Twitter Blue service. Is this logical? Terry and I have opinions.

More malware has been discovered in the open-source NPM and PyPI code repositories. We’ll ask why repository operators can’t put a lid on this.

Game developer Activision acknowledged it was hacked in December after an employee fell for a text messaging scam. That will be part of our discussion.

In France five people were indicted for using a device normally only accessible to police. They used it to capture hundreds of thousands of mobile phone numbers for spam.

And Gartner predicts there may be upheaval in infosec departments. Stress is causing cybersecurity leaders to re-evaluate their careers, the company said, predicting that over the next two years nearly half of them will change jobs. Terry will have some thoughts on the pressure on leaders.

Researchers at ESET suspect North Korea’s Lazarus threat group is deploying a new backdoor. It’s part of malware discovered in 2021 capable of downloading Windows binaries. The new backdoor is one of the payloads. The backdoor module collects system information and provides ways of deleting or exfiltrating files.

Fruit and salad processor Dole had to temporarily shut its production plants in North America earlier this month because of a ransomware attack.

And a new information-stealing malware is being marketed to threat actors. According to researchers at the French firm Sekoia, the malware is called Stealc. It’s similar to other code that steals data from infected computers like Vidar, Raccoon, Mars and Redline. One way Stealc is spreading is through infected software and mobile apps pretending to be utilities.

(The following is an edited transcript of part of the discussion. To hear the full talk play the podcast)

Howard: Gartner published research this week about how worn out cyber security leaders are. By 2025, it predicts, half of the cybersecurity leaders will have changed their jobs, and of them 25 per cent will just leave the IT profession for different roles entirely due to multiple work-related stressors. These include low executive support for cybersecurity and making IT focus on compliance rather than risk management. What are you hearing from cybersecurity leaders that you talk to?

Terry Cutler: I’m not sure if you’ve ever seen this meme on the internet where day one of your cybersecurity job you looked like baby Yoda, and two years or three years later, you looked like 900-year-old Yoda. The burnout’s real. It’s very, very, very difficult this field, especially if you’re not passionate about it. You’re gonna burn out even quicker. How many times have you heard folks say, ‘Cybersecurity is paying really, really well.’ But if you’re a plumber, for example, and you want to switch over to cyber, it’s very, very difficult. So you have to be passionate about this field to get in. But there’s a lot of high pressure to manage consistent, evolving threats. Then you got limited resources and conflicting priorities.

For example, you’ll have issues in cybersecurity, but then other business leaders are not on the same page as you. They’re not going to prioritize your requests. And that’ll leave you with a sense of frustration and isolation because you’ll say, ‘This is a threat. It’s a zero-day [vulnerability]. We have to deploy these patches right away.’ I actually experienced this often in healthcare: There was a vulnerability out and we said let’s scan the [IT] environment. I’m still waiting four months later to get the approval to scan the environment for vulnerabilities. There’s so much red tape in some of these companies. it’s crazy. You have to wait for all the groups to be on the same page and give you permission. As an advisor and such you’re always faced with these delays. And if you’re not on the same page as the other folks, because they don’t understand the risk level, you’re just going to feel like you’re banging your head against the wall. And that’s why people just leave.

You know what? You wanna get hacked? Don’t blame me. Here, sign this paper. That’s what I think CISOs are going to have to do to cover their butts: ‘I’m advising you of this threat. You don’t want to do it, sign here.’

Howard: What will it take for CEOs to prevent cybersecurity leaders from leaving their company?

Terry: CEOs need to prioritize cybersecurity as a critical business function and provide the necessary resources and support to help cybersecurity leaders be successful. The biggest is provide adequate funding. How many times do we try to do audits that are really inexpensive, that could save the company hundreds of thousands, if not millions, of dollars? It probably would’ve just cost 10 grand to avoid headaches. The other thing is the CEOs need to build a cybersecurity culture. Even if the janitor has access to the network to check his email he can click on a ransomware link and infect the whole company. So everybody needs to be on the same page that cybersecurity is really important and understand if the firm gets hit with a cyber attack it could cost their jobs.

One of the bigger things is to bring the CISO to the [executive] table as a respected thought leader. It’s important that the CISO is able to articulate the risks. And provide career paths [for infosec leaders] … If you don’t do these things you’re not going to attract the top talent to your company.

The post Cyber Security Today, Week in Review for Friday, February 24, 20223 first appeared on IT World Canada.

Dell issues flurry of announcements in lead-up to MWC 2023

Dell Technologies said this week it is helping the telecommunications industry “accelerate the adoption of open, cloud-native technologies” with a series of new product offerings and partnerships timed to coincide with the start of Mobile World Congress 2023 next week in Barcelona.

Launched were Dell Telecom Infrastructure Blocks for Red Hat, new Dell PowerEdge edge servers, a private wireless program and expanded lab capabilities.

“The promise of open telecom network architecture is clear to operators, but has so far been a challenge to realize,” said Dennis Hoffman, senior vice president and general manager at the company’s telecom systems business.

“To address this challenge, the industry needs to create consumable, tested solutions that telecom operators can confidently deploy in their networks.”

An example is the joint initiative with Red Hat, to be available in the second half of this year, which is designed to help network operators meet the demands of 5G core and radio access network (RAN) workloads.

Co-designed with Red Hat, and backed by Dell services and support, the release said that the cloud-native offering includes the hardware, software and subscriptions that network operators need to build, scale out and power core network functions using Red Hat OpenShift and Red Hat Advanced Cluster Management for Kubernetes.

With the expanded Telecom Infrastructure Block portfolio, network operators can improve the efficiency of how they use their IT resources to reduce operational costs and power consumption, which lowers their carbon footprint, Dell said.

ACG Research estimates that communications service providers (CSPs) deploying it can reduce opex (operating expense) by as much as 40 per cent and capex (capital expense) by 10 per cent versus deploying telecom cloud infrastructure.

According to the Dell release, ACG found that, by “reducing power and cooling expenses, 833 Metric tons of total CO2 emissions can be saved over five years, which is equivalent to driving 179 gas-powered cars for one year or the average amount of electricity used by 162 homes during one year.”

Honoré LaBourdette, vice president, telco, media, entertainment, and edge ecosystem at Red Hat, said, “networks operating at scale from the core to the edge require layered capabilities, across infrastructure and software-defined architecture, with added security measures, orchestration and cloud-native applications.”

PowerEdge servers

The new Dell PowerEdge XR8000, XR7620 and XR5610 servers, which are based on 4th Gen Intel Xeon Scalable processors, are designed for telecom, open RAN and mobile edge computing workloads while simplifying edge operations, the company said. They will be available in May, but Dell is not disclosing pricing at this time,

Private wireless

The Dell Private Wireless Program is designed to offer CSPs and enterprise customers more choice in private wireless offerings, so that they can find the best fit for their own needs, Dell said. Jointly developed with technology partners, the private wireless solutions, based on open architectures, are pre-tested and validated by Dell, and include self-service operations capabilities.

Open Telecom Ecosystem Labs

Finally, the Dell Open Telecom Ecosystem Lab, located in Round Rock, Texas, according to the company supports “more than 25 customers and partners with testing, certifying and validating open telecom solutions and applications, so they can be quickly and easily deployed in telecom networks.”

Dell is ramping its efforts to accelerate innovation and simplify ecosystem collaboration with the following:

A new Open Telecom Ecosystem Lab in Cork, Ireland, which will provide customers and partners with another location to collaborate “across the global, open telecom ecosystem.”
Dell Open Telecom Ecosystem Lab Validation Services, which build upon the lab’s capabilities to give customers dedicated access to Dell engineers for ongoing design consultation and validation, helping CSPs to mitigate risk and launch new offerings and services more quickly.
A new Wind River self-certification lab testing environment for partners to test and validate their software with the Wind River Studio cloud-native platform before deploying in a telecom network.
The post Dell issues flurry of announcements in lead-up to MWC 2023 first appeared on IT World Canada.

Researchers looking into cybersecurity of Canada’s power, IoT sectors

Researchers at a Québec university are investigating two of the country’s biggest cybersecurity worries: The readiness of power utilities to face cyber attacks, and the security of wireless industrial internet-connected devices.

News of the projects came Thursday when Ottawa announced it has given the University of Sherbrooke the second half of just under $2 million for the studies.

Sébastien Roy, a professor in the Department of Electrical Engineering, and one of the co-principal investigators, told IT World Canada that the money was awarded over two years ago, when work started, but the announcement was delayed by the pandemic. Reports on both are due in 2024.

One project is assessing the resiliency of Hydro Sherbrooke, a medium-sized power distributor, in the context of Industry 4.0, particularly its ability to identify new threats. According to Roy, this project is almost done.

Industry 4.0 refers to the integration of new technologies (Internet of Things, cloud computing, artificial intelligence) into a company’s production centres and overall operations.

The second project is analyzing the security of the industrial Internet of Things devices with 5G connectivity and edge computing. It includes studying the devices’ applications to agriculture, water management, and building management.

Partners in this study include Bell Canada, VMware, Honeywell, and the cities of Sherbrooke and Magog, QC.

For both projects, lessons learned will be spread through the electric, telecommunications, and IT manufacturing industries, Roy said.

The funding from Public Safety Canada came under the National Cyber Security Strategy.
The projects are being overseen by a multi-faculty and multi-disciplinary team involving five university faculties, 11 researchers, and more than 50 students from 14 countries.

“This work will strengthen the resiliency of Canada’s critical infrastructure, or the assets and equipment that a third party needs to access to offer its own product or service in a market,” the university said in a news release.

“There is a lot of synergy between the two projects, although the objectives are distinct,” said Roy. The underlying theme in both is protecting critical infrastructures. In the first case it’s energy distribution, the second is more about communications infrastructures.”

5G is different from previous cellular technologies, Roy said, in that it is less centralized and puts more control at the edge of wireless networks. That causes security concerns, particularly access authentication. It doesn’t help that typically 5G IoT devices “have no security,” he added.

“At the end we will be able to recommend good practices and technological architectures for these areas to the government and our industrial partners for specific use cases. In the meantime, we’re training over 50 students at the master’s, PhD and post-doctorate levels, in addition to a lot of interns, who will then move on to use their expertise in industry.”

The post Researchers looking into cybersecurity of Canada’s power, IoT sectors first appeared on IT World Canada.

Cogeco Connexion acquires ISP oxio

Cogeco Connexion, which brings together all of the Canadian cable operations of Cogeco Communications, this week announced the acquisition of the telecommunications activities of internet service provider (ISP) oxio. The ISP will continue to operate independently, and serve its customers under its own brand.

Oxio provides internet and telecommunications services to residential customers in Canada, mainly serving customers in Québec, Ontario and western provinces.

As part of this transaction, Cogeco Connexion will also become the licensee of gaiia, oxio’s proprietary software, and will use it to serve oxio’s customers.

“As we are making the strategic shift to focus exclusively on the growth of our software business, Cogeco presented itself as the best home for our Internet customers,” said Marc-André Campagna, chief executive officer and co-founder of oxio in a press release. “As a Québec-based company with a human scale and an entrepreneurial culture, we believe that Cogeco is best-positioned to enable oxio to reach new heights.”

Through its Cogeco Connexion and Breezeline (formerly Atlantic Broadband) business units, Cogeco Communications provides broadband internet, television, and telephone services to 1.6 million residential and business customers in Québec and Ontario, as well as in thirteen states of the United States.

“Oxio is an attractive brand with high customer satisfaction and a great team. Its home internet offering, based on a digital-only experience, is an exciting addition to our wide range of high-quality telecommunications services. With the acquisition of oxio, Cogeco Connexion will now have a second brand to serve the telecommunications needs of Canadians,” said Frédéric Perron, president of Cogeco Connexion.

The post Cogeco Connexion acquires ISP oxio first appeared on IT World Canada.

RingCentral and AWS enter strategic partnership

Cloud giant Amazon Web Services (AWS) will offer RingCentral MVP (Message Video Phone) and RingCentral Contact Center solutions to its customers, as part of a multi-year agreement announced last week.

This partnership between RingCentral and AWS seeks to help organizations accelerate their cloud journeys while transforming their employee and customer communications.

“Together, AWS and RingCentral are giving customers across multiple industries greater choice and support for their call center and business communications needs,” said Matt Garman, senior vice president of sales, marketing, and global services at AWS. “By making RingCentral’s cloud communications solution available on AWS, large enterprise and mid-size customers can benefit from the reliability and scalability of the cloud, while giving employees and customers the ability to collaborate in new ways.”

RingCentral’s unified communications as a service (UCaaS) solutions enable employees to communicate from any location and any device through a single platform that integrates team messaging, video meetings and a cloud phone system.

RingCentral also plans to provide technical resources for workstreams to make RingCentral offerings functional and transactable for AWS customers – supporting AWS Marketplace Listings and integrations to AWS services.

Further, both companies will work together to deploy end-to-end cloud migration solutions for businesses in the healthcare, financial service, retail, education, and public sector industries. Users will be able to access flexible migration options through bring-your-own-carrier (BYOC) and hybrid PBX solutions.

The two companies will also share their resources to enable experts to better assist customers with their cloud adoption and technical integrations. 

This collaboration will initially be rolled out in North America, followed by additional countries in Europe, Asia Pacific, and Latin America over the multi-year period.

The post RingCentral and AWS enter strategic partnership first appeared on IT World Canada.

The Russia-Ukraine cyber war: one year later

To soften up Ukraine just prior to its February 24, 2022 invasion, Russia, or Russian-backed threat groups, unleashed a wave of wiperware against the country’s organizations, deployed a new version of the Industroyer malware against power generating stations and took down thousands of routers used by Ukrainian (and other) subscribers to Viasat’s satellite internet service.

That was just the start of the cyber war.

Wiperware is a favoured weapon. Alex Rudolph, a Carleton University doctoral candidate, told a House of Commons defence committee last week that there have been at least 16 wiper malware families deployed into Ukraine since the start of fighting.

Those 12 months are giving a window into what modern hybrid war — physical and cyber combat — looks like, at least in a limited theatre of war. Global cyber war officially hasn’t broken out yet.

But, for example, the bombardment of some Ukrainian power stations was combined with cyber attacks, notes Jean-Ian Boutin, Ottawa-based director of threat research for ESET, which is headquartered in Slovakia. He’s not sure if was a coincidence or a combined attack.

Meanwhile, there have been suspected cyber attacks against countries supporting Ukraine. Last week, for example, a group called Anonymous Russia took credit for DDoS [distributed denial of service] attacks on the websites of several German airports. The pro-Russian Killnet group took credit for an IT outage at Lufthansa — which the airline blamed on damaged broadband cables mistakenly cut on a railway line during construction work.

In November, 2022, hackers from the Russian-affiliated group KillNet took down the website of the European parliament, hours after the legislative body declared Russia a terrorist state.

However, cyber attacks outside Ukraine haven’t been as crippling as some experts feared.

On the anniversary of the start of the invasion, we look back at what happened since and lessons learned.

Cyber attacks are a feared weapon: Under the worst conditions, they can cripple a heathcare system and cause death. But a Canadian expert points out that cyber attacks alone can’t win wars.

“Cyber-attacks cannot gain territory, but they can disrupt the other side’s operations, target infrastructure and civilians, and affect public opinion during the process of gaining physical territory,” wrote Abby MacDonald, a fellow at the Canadian Global Affairs Institute, when the war was only two months old. “In this conflict, complete cyber-war does not appear to be strategically useful, though cyber-activities including disinformation will continue.”

To David Swan, Alberta-based cyber intelligence director of the Center for Strategic CyberSpace and International Studies, an international think tank, the outset of the cyber war held no surprises.

“Russia has a very well-developed standard cyber battle plan,” he said. “They used it in Georgia [in 2008], they used it in Estonia [in 2007] … it’s been developing since the mid-1990s”

That plan sees cyber or DDoS attacks to impair or close media websites and broadcast systems; on financial institutions to block residents from making any purchases unless they had cash; on infrastructure (eg: gas stations with electronic pumps regulated over the internet were shut or jammed); on government web sites to stop the country from running; and on military wireless communications.

But against Ukraine, the Russians haven’t been as successful for a number of reasons. “They believed most Ukrainians were pro-Russian and would happily support the Russians coming in,” Swan believes. “Wow, did they get that wrong!”

Second, Swan said, Ukraine has been preparing for physical and cyber war since the Russian capture of Crimea in 2014. It learned some lessons during cyber attacks that knocked power out across parts of Ukraine in 2015. Ukraine said the attack came from inside Russia.

In addition, said Swan, in the months leading up to the invasion, Ukraine moved closer to the European Union. In June, 2021, the EU and Ukraine held their first cyber dialogue about responsible state behaviour in cyberspace, but also about cyber resilience. Two days before the invasion, several EU countries activated a cyber rapid response team to help Ukraine. Since the war started, the U.S., Canada and the EU have been offering intelligence and cyber defence support. U.S. cyber support began in 2017. This May 2022 U.S. document outlines what has been done since.

Separately, since the war began, Microsoft, Google, Amazon, Mandiant, ESET, Palo Alto Networks, Cisco Systems and other IT companies have donated software, threat intelligence and countered misinformation to augment Ukraine’s capabilities. They helped the government and the Ukrainian hacker underground that emerged.

Microsoft’s role began earlier. Before the start of the invasion, Russia launched a cyberattack that targeted Ukrainian government and financial websites, notes this analysis of the first six months of the cyberwar in the journal Lawfare. This attack — known as FoxBlade — was poised to wipe data from computers. Within hours of its appearance, the Microsoft Threat Intelligence Center had written code to stop it, which was quickly shared with Ukraine.

Ukraine has come up with at least one unique defensive tactic: It ordered wireless carriers in the country to block mobile devices from roaming with carriers in Russia and Belarus. This is unprecedented, said Cathal Mc Daid, chief technology officer of Sweden’s Enea AdaptiveMobile Security. It meant Russian forces in Ukraine couldn’t use mobile phones as a backup or primary communication system. “We know from history (Russia-Georgia war of 2008) and in Ukraine itself, that Russian forces have used mobile phones to communicate,” he said in an email to IT World Canada, “but this decision by Ukraine, on the day of the invasion, made Russian forces’ communications problems much worse.”

None of this suggests that Ukraine has been impervious to cyber attacks. But the government has been able so far to persevere and direct military action. Or, to put it another way, Russia has so far failed to strike a knockout cyber blow.

Russia, and threat groups that support it, meanwhile, are still active. In fact news emerged this week that Russian hackers planted backdoors in multiple government websites as far back as December 2021. Ukraine’s computer emergency response team said it spotted a webshell deposited through one of those backdoors yesterday (Feb. 23). It isn’t clear if the access has been used undetected for months.

There’s a long list of Russian-deployed [and Western-named] wiperware that has been deployed since the invasion: HermeticWiper, IsaccWiper, WhisperGate, and CaddyWiper, to name a few. And Ukrainian hacktivists struck back with the RURansom wiper.

Just as Ukraine has its civilian cyber forces, so does Russia. One, Swan says, is dubbed NoName057(16). He believes it was formed from KillNet members. This group’s attacks have hit the Polish government and organizations in Lithuania (mainly cargo and shipping firms). For more on NoName057(16) see this report from SentinelLabs.

In a January report published by CSCIS, Swan said it is also attempting to recruit and encourage hackers to attack targets by starting a project called “DDosia”. Volunteers are encouraged to attack ‘anti-Russian targets’, earning as much as 80,000 rubles (US$1,200) for a successful attack.

In a first-year analysis of attacks, researchers at CheckPoint software noticed that, since September, there has been a gradual but major decline in the number of attacks per gateway in Ukraine. On the flip side, it added, there was a significant increase in the attacks against NATO members.

In its analysis of the war so far, Google predicts with “high confidence” that Moscow will increase disruptive and destructive attacks in response to developments on the battlefield that fundamentally shift the balance – real or perceived – towards Ukraine (e.g., troop losses, new foreign commitments to provide political or military support, etc.). These attacks will primarily target Ukraine, it says, but increasingly expand to include NATO partners.

More than one analyst has noted DDoS attacks don’t have large impacts. Nor, seemingly are they aimed at causing significant damage — so far.

“This begs a critical question,” said Dave Masson, head of Darktrace Canada. “One year on, is the risk of a cyber fallout still there? The answer is a resounding yes. While there is no direct evidence of a large-scale cyber-attack on the horizon, it is absolutely critical that defenders stay on guard. The history of cyber threats has shown us time and time again that we cannot rely on historical attack data to predict future threats. The risk of Russian retaliation is real, pervasive, and cannot be underestimated.”

Among the lessons of the cyber conflict so far, said Jean-Ian Boutin of ESET, is the importance of public and private sectors working together. “We already knew that communications is key, but this really strengthened our thinking that the key to thwarting attacks is to keep communications open and report attacks as soon as we see them.”

The Communications Security Establishment (CSE), responsible for securing Canadian government networks, declined a request for an interview. Instead, it sent this statement:

“As mentioned in CSE’s National Cyber Threat Assessment (NCTA 2023-24), Russia’s unlawful invasion of Ukraine in February 2022 gave the world a new understanding of how cyber activity is used to support wartime operations.

“While we can’t speak about specific events or tactics that we’ve monitored through our foreign intelligence mandate, we can confirm that CSE has been tracking cyber threat activity associated with Russia’s war with Ukraine. CSE has been sharing valuable cyber threat intelligence with key partners in Ukraine. We also continue to work with the Canadian Armed Forces (CAF) in support of Ukraine, including intelligence sharing, cyber security, and cyber operations.”

Through the Canadian Centre for Cyber Security, the CSE urges Canadian organizations to

isolate critical infrastructure components and services from the internet and corporate/internal networks if those components would be considered attractive to a hostile threat actor to disrupt. When using industrial control systems or operational technology, conduct a test of manual controls to ensure that critical functions remain operable if the organization’s network is unavailable or untrusted;
increase organizational vigilance. Monitor your networks with a focus on the Tactics, Techniques, and Procedures (TTPs) reported in the CISA advisory. Ensure that cybersecurity/IT personnel are focused on identifying and quickly assessing any unexpected or unusual network behavior. Enable logging in order to better investigate issues or events.
enhance your security posture: Patch your systems with a focus on the vulnerabilities in the CISA advisory, enable logging and backup. Deploy network and endpoint monitoring (such as anti-virus software), and implement multifactor authentication where appropriate. Create and test offline backups.
have a cyber incident response plan, a continuity of operations and a communications plan and be prepared to use them.
inform the Cyber Centre of suspicious or malicious cyber activity.

“The thing I’m expecting is one of those wiper families with a new front end, a new way of breaking into networks, to get loose and come West,” said Swan. “I know that there’s a lot of effort going into backstop to support Ukraine and pre-empt malware families coming West. The problem is Russia only has to get it right once, and they’ve got some of the world’s best hackers on their side writing this stuff. My concern is the longer the war goes on, the higher the likelihood that one or more of these things is going to get loose and there’s going to be hell to pay.”

The post The Russia-Ukraine cyber war: one year later first appeared on IT World Canada.

Cyber Security Today, Feb. 24, 2023 – Holes in open source software, ransomware gang tries to evade cyber insurers and more

Holes in open source software, ransomware gang tries to evade cyber insurers and more

Welcome to Cyber Security Today. It’s Friday, February 24th, 2023. I’m Howard Solomon, contributing reporter on cybersecurity for ITWorldCanada.com and TechNewsday.com in the U.S.



Creators of open-source projects still aren’t doing enough to ensure their code is squeaky clean. Researchers at Synopsys released their annual Open Source Security and Risk Analysis report this week, which looked at 1,700 audits of commercial and proprietary software. And the results weren’t pretty. Eighty-four per cent of the codebases examined had at least one known open source vulnerability. That’s up four per cent from last year. Here’s something else: Of the 1,480 audited codebases that included risk assessments by corporate owners of the software, 91 per cent contained outdated versions of open-source components. Developers of applications and IT departments that buy them need to have complete visibility of their software, says Synopsys. It helps for developers to create and buyers to demand a software bill of goods, the company adds.

Hackers have created a new class of bugs that get around the security protection of iPhones,iPads and Macs. Researchers at Trellix found the malware could evade protections preventing unapproved software running on the macOS and iOS operating systems. Normally this would be a significant breach of the Apple security model. However, the vulnerabilities were addressed with the recent releases of macOS 13.2 and iOS 16.3. Which is why you should have installed them by now.

The HardBit ransomware gang has a new tactic for dealing with corporate victims: Rather than haggling over payment to get access to encrypted data back, organizations are asked to go behind the backs of their insurers and divulge details of their cyber insurance policies (if they have one). Then the payment demanded will just be the maximum under the coverage. It’s pitched as a deal: If the gang knows you are insured only for, say $10 million, it promises not to demand more than $10 million.

A Russian citizen has been extradited to the U.S. from the republic of Georgia to face computer fraud and other charges. The man was arrested last October. It is alleged he created a program able to decrypt scrambled login credentials, a program he sold to other crooks. He also sold the cracked passwords.

Finally, if you use the Google Chrome browser make sure it’s running the latest version. This week it began rolling out a Windows version that starts with 110 and ends with .117 that fixes 10 security flaws, one of which is critical

That’s it for now. But later today the Week in Review will be available. Guest commentator Terry Cutler and I will look at employees falling for SMS text scams, information security leaders leaving their jobs and more.

Links to details about podcast stories are in the text version at ITWorldCanada.com. That’s where you’ll also find other stories of mine.

Follow Cyber Security Today on Apple Podcasts, Google Podcasts or add us to your Flash Briefing on your smart speaker. Thanks for listening. I’m Howard Solomon

The post Cyber Security Today, Feb. 24, 2023 – Holes in open source software, ransomware gang tries to evade cyber insurers and more first appeared on IT World Canada.

Hashtag Trending Feb.24th- Google asks employees to share desks, Canada starts investigation against TikTok and AI-created images loses copyright

Google Cloud asks employees to share desks, Canada starts investigation into TikTok and AI-created images lose their copyright protection.



 

It’s Friday, February 24th. These stories and more on Hashtag Trending–today’s top technology news stories. I’m your host, Jim Love.

In its latest cost-cutting moves, the cloud unit of Google has asked employees to transition to a desk-sharing workspace in five of its locations.

The new desk-sharing model will apply to Google Cloud’s five largest U.S. locations — Kirkland, Washington; New York City; San Francisco; Seattle; and Sunnyvale, California.

Google has said previously in its fourth-quarter earnings call that it expects to incur costs of about $500 million related to reduced global office space and other real estate charges. 

Employees and partners are being asked to share their desks on alternate days with their desk mates, starting next quarter.

The memo announcing the change says employees may come in on other days, but if they’re in on an unassigned day, they will use “overflow drop-in space.”

Internal documents reveal that the tech giant is pushing a slow return to office patterns, while ensuring “real estate efficiency” and continued investment in the Cloud unit;s growth.

The new seating arrangement is called “Cloud Office Evolution”, which the company described as “combining the best of pre-pandemic collaboration with the flexibility” of hybrid work.”

The company has noted the new workspace plan is not a temporary pilot and will lead to more efficient use of its space.

Following the announcement, memes rolled in, specifically on the “corpspeak” used by the head of the company to promote the new desk-sharing model.

One meme read; “Not every cost-cutting measure needs to be word mangled into sounding good for employees. A simple ‘We are cutting office space to reduce costs’ would make leadership sound more believable.”

Source: CNBC

Concerns about TikTok are spreading across the US and now into Canada and even the European Union.

Canada’s federal privacy commissioner, along with three provincial privacy commissioners, have started an investigation into TikTok, examining how the video-streaming platform collects the personal data of Canadian users.

The three participating provincial commissioners are Québec, Alberta, and British Columbia.

The privacy watchdogs will assess whether TikTok’s data collection practices are in compliance with Canadian privacy legislation, particularly whether valid and meaningful consent is being obtained for collection, use, and disclosure of personal information. The investigation will also examine whether the company is meeting the transparency requirements when collecting personal information of its users.

Source: IT World Canada   

The European Commission, on the other hand, has straight up banned the use of TikTok on its staff devices.

The commission says it has around 32,000 permanent and contract employees.

They must remove the app as soon as possible and no later than the 15th of March

TikTok said the commission’s decision was based on mistaken ideas about its platform. E tu, EU?

Source: BBC

Perhaps fearing that the Edge browser will be used to download Chrome, and then remain unused, Microsoft is aggressively trying to keep customers on Edge and that’s by bombarding them with full-size ads, on the Chrome website. 

An attempt to install Chrome using Edge Canary now results in the browser displaying two ads: a small one that first pops on the screen when the Chrome website loads and second, a full-size banner once the download starts.

The banner states that Edge uses the same technology as Chrome but with the “added trust of Microsoft”.

Google also shows banners to promote Chrome, but they appear only on the company’s websites.

But Microsoft crying foul every time a user wants to download another browser remains questionable. Maybe, promoting the AI Bing might be a better strategy, after all, some of its behaviour has kept people on Edge.

Microsoft may be revising their strategy as apparently, the latest Edge releases did not get the banner.

In fact, as of today, the banner doesn’t show up in Edge Canary, Dev, and Stable. Beta is the only version still displaying the banner when you try to download Chrome.

Source: Neowin

Pirated Final Cut Pro is no bargain. Security researchers at Jamf Threat Labs found a cryptomining operation targeting macOS pirated version of Final Cut Pro. 

The software is distributed via Pirate Bay, a popular torrent site that allows people to download and stream entertainment media and software

It appears that users have also been uploading other macOS apps like Adobe Photoshop and Logic Pro X since 2019, all of them containing a payload for cryptocurrency mining.

The malware has undergone three major development stages, each time adding more complex evasion techniques. Security tools today only detect the first generation of threat, which stopped circulating in April 2021, according to Bleeping Computer.

The third and current generation appeared in October 2021 with a new capability to disguise its malicious processes as system processes on Spotlight to evade detection.

The latest version also incorporates a script that constantly checks for the Activity Monitor, and if it’s launched, it immediately terminates all of its processes to remain hidden from the user’s inspections.

The latest version of macOS, codenamed “Ventura,” has more stringent code-signing checks that may render hidden malware within user-launched apps, especially pirated ones, ineffective.

However, this only prevents the legitimate application from running, not the cryptocurrency miner, so Apple’s new security system still has some way to go to protect the user effectively.

Source: Bleeping Computer

Images created using AI may not protected by copyright.

At least that’s the case for images used in the graphic novel “Zarya of the Dawn,” according to a U.S. Copyright Office ruling.

The author of the graphic novel, Kris Kashtanova was informed that he is entitled to a copyright for the parts of the book that he wrote and arranged, but not for the images produced by Midjourney.

The decision is one of the first by a U.S. court or agency on the scope of copyright protection for works created with AI, and comes as generative AI software like Midjourney, Dall-E and ChatGPT are growing in popularity.

The author on Wednesday called it “great news” that the office allowed copyright protection for the novel’s story and the way the images were arranged, which he said “covers a lot of uses for the people in the AI art community.”

Kashtanova said he was considering how to best counter the argument that the images themselves were not a “direct expression of someone’s creativity and therefore copyrightable.”

The decision may not apply to all AI images. “The fact that Midjourney’s specific output cannot be predicted by users makes Midjourney different for copyright purposes than other tools used by artists,” the U.S. Copyright Office’s decision said.

So naturally we went to the real authority on this and asked ChatGPT who owned copyright from AI generated images, here’s the answer we got. 

Ultimately, the question of copyright ownership from AI-generated images is a complex legal issue that may depend on the specific facts and circumstances of each case. As AI technology continues to evolve, legal frameworks may need to be adapted to address these issues more effectively.

Couldn’t have said it better. 

Source: Reuters

That’s the top tech news stories for today

Links to these stories can be found in the article posted on itworldcanada.com/podcasts. You can also find more great stories and more in-depth coverage on itworldcanada.com or in the US on technewsday.com

Hashtag Trending goes to air five days a week with a daily newscast and we have a special weekend edition with an interview featuring an expert in some aspect of technology that is making the news.

Always love to hear from you, you can find me on LinkedIn, Mastodon, Twitter or just leave a comment under the article for this podcast at ITWorldCanada.com.  

I’m Jim Love, and on a personal note, I turn 67 today, so you have a great Friday. I’m going to have an old one.

The post Hashtag Trending Feb.24th- Google asks employees to share desks, Canada starts investigation against TikTok and AI-created images loses copyright first appeared on IT World Canada.

Breaking news: Telus investigating sale of alleged code, employee information

Someone on a criminal forum is selling what they claim is data on all Telus employees, as well as the Canadian telecommunications company’s GitHub software code repositories.

In response to an IT World Canada reporter’s query about the posting, Telus director of public affairs Richard Gilhooley said the company is looking into the allegation.

“We are investigating claims that a small amount of data related to internal Telus source code and select Telus team members’ information has appeared on the dark web,” he said in an email. “We can confirm that to this point our investigation, which we launched as soon as we were made aware of the incident, has not identified any corporate or retail customer data.”

The first dark web posting by someone named “Sieze” was made on Feb. 17. “Today we’re selling email lists of Telus employees from a very recent breach,” it says. “We have over 76k unique emails and on top of this have internal information associated with each employee scraped from Telus’ API.”

As proof, this posting includes what appears to be a list of Telus employee email addresses. It isn’t known if these are current or former staff — or even real.

A Feb. 21 posting adds, “We’re bringing you even more from the recent Telus breach!” The poster asks US$7K for the database file of “every person that works at Telus”; US$6K for a payroll file with 770 records of “all of the white collar workers … including the president of Telus”; and US$50K for all of the allegedly copied data, including a list of Telus private Github repositories, subdomains, and screenshots.

Interested buyers are asked to connect to one of two people on the Telegram messaging service.

It’s important to note that it’s not clear whether the data being sold is real, commented Brett Callow, a British Columbia-based threat analyst for Emsisoft. “That said, if it is real, this is a potentially serious incident which exposes Telus’ employees to increased risk of phishing and social engineering and, by extension, exposes the company’s customers’ to risk. The alleged exposure of the private Github repositories, supposedly including a sim-swap API, represents an additional tier of potentially significant risk.”

In 2020, a Telus division called Medisys Health Group was hit by a cyber attack involving customer data. At that time the company said it “securely retrieved the data by making a payment.”

The post Breaking news: Telus investigating sale of alleged code, employee information first appeared on IT World Canada.

Technicity GTA 2023 keynote: 10x thinking for the public sector

Innovation is key, no matter what your business. And at a behemoth like Google, said John Cousens, managing director, public sector at Google Cloud Canada, it means taking what he called an approach of 10x thinking: coming up with radical solutions to huge problems, and solutions that provide a 10x improvement over what was done before.

That approach can also work for the public sector, he said in his keynote at IT World Canada’s Technicity GTA 2023 virtual event today.

Google has six primary principles around innovation, but to Cousens, the most important one for the public sector and those who work there is the first: Psychological safety.

“Psychological safety is a condition in which humans feel included, safe to learn, and safe to contribute, and safe to challenge the status quo,” he said. “Often government, which has a hierarchical structure,  challenges people to be able to express or do that in that hierarchy.”

It is, he added, not necessarily conducive to psychological safety if someone has to sit in front of a committee and defend something – “it’s adversarial in nature, versus open and transparent.”

Source: Google keynote

“So how do you have that psychological safety, where people are free to test things out and push different boundaries? That is a number one predictor of team success at Google, and I believe in public sector, we could adopt some more of these principles to ensure that we can drive this kind of success when we’re looking at digital transformation across the board.”

The second principle is Focus on the User. Google platforms are widely adopted, he said, because they are user-centric. “Focus on the user and everything else will follow,” he said. And be transparent – share information. Collaboration helps drive a culture of innovation.

“And frankly, innovation comes from everywhere,” said Cousens. “Too often in government, especially in technology, we find ourselves saying, ‘I’m this type of a shop’. In the digital era, I would argue that you can no longer say ‘I only use this tech’, because innovation is coming at us faster than ever before. And innovation comes from everywhere.”

Google, he said, tries to inspire innovation by encouraging employees to have 20 per cent projects – side projects that aren’t part of their core role.

“Taking this kind of principle means that no one’s questioning agendas. No one is questioning where the strategy is. It’s in the open and all the time,” Cousens noted.

Finally, he said, “have a healthy disregard for the impossible.” Don’t be bound by the status quo. Google, for example, he noted, has been using its Waze data, originally gathered to assist drivers in getting around traffic jams, and Google Cloud to give cities insights into everything from traffic patterns to environment insights around emissions.

It also provides the Waymo open data set containing data collected from millions of kilometres of autonomous driving in urban environments, which, Google says, empowers autonomous smart mobility providers with data.

“Think about this for the future of how we’re looking at innovation,” he said.

The post Technicity GTA 2023 keynote: 10x thinking for the public sector first appeared on IT World Canada.