Category: News

Hiring to increase in Canada, despite market volatility: Robert Half study

The job market has been facing the changing demands of a new workforce and a new economic environment, but it remains robust. More than half of Canadian companies are planning to hire early this year, a new study by recruitment agency Robert Half found.

A survey of over 1,400 managers was conducted on behalf of Robert Half from Oct. 20 to Nov. 3 2022. The respondents had hiring responsibilities in finance, accounting, technology, marketing, creative, legal, administrative, customer support, and human resources at companies with 20 or more employees in Canada.

The survey found that 51 per cent of companies plan to hire for permanent positions. The administration, customer service, marketing, and creative divisions have the highest staffing needs.

Source: Robert Half

The survey showed that the top traits employers look for in potential hires are timeliness and professionalism during interviews, knowledge of the company, and passion for the company’s mission.

Gartner’s “9 Future of Work Trends For 2023” study, in comparison, points out that organizations are diversifying their talent pipelines by pursuing nontraditional candidates. Hiring managers are less concerned with industry experience and technical skills than they once were, and are now looking to assess candidates solely on their ability to perform in the role.

Companies also aim to have more people back in the office, but need to work on striking the right partnership with employees looking for more choice and flexibility in how they execute their job responsibilities, said David King, senior managing director, Robert Half, Canada and South America.

Furthermore, over 60 per cent of respondents in Robert’s Half study say that they are swinging towards adding more contract staff as a tactic to manage heavy workloads, increase support for key projects, and reduce burnout, King explained.

Having more contract staff aligns better with the newer generation that mostly anticipate to stay at a job for a maximum of 2-3 years and then transition to the next opportunity. “That whole gig economy mentality is very much alive in our newer demographics in the workforce. Let’s face it, they’re no longer being typically offered the attraction of a pension plan or things like that, that may have been more in fashion in past years,” stated King.

Accordingly, Gartner says that savvy HR leaders will leverage alternate approaches to recruitment by hiring gig workers or calling in former employees to flexibly bring in talent only as needed, a practice known as “quiet hiring”. Quiet hiring also includes upskilling existing employees and focusing on internal talent mobility to address organizational priorities without changing headcount.

Efficiency is also a key factor that the new workforce is looking for, despite the concern that automation and artificial intelligence might take away everyone’s jobs. 

In fact, what automation actually does is change the nature of work and add a whole set of newer jobs, said Jeremy Shaki, chief executive officer of tech education firm, Lighthouse Labs.

Shaki added that companies mostly use new technologies to enhance productivity and tasks, instead of replacing people. But employees also need to ensure that they are comfortable and up to date with the use of technology, AI, and data, because at some point in their career, these new technologies will interact with their roles in a more meaningful way.

In addition, big tech companies that are laying off thousands, and subsequently automating roles like marketing, customer service, and sales, are taking big risks in doing so, said Shaki, because customers, in general, still have a much higher preference for talking to a person than an AI.

“When you deal with customer service coming from anywhere other than in your own backyard, and not with a person, you tend to hear a lot of complaints and negativity about that. And I don’t think we’re there yet [with AI],” affirmed Shaki.

Recent tech layoffs have, without a doubt, raised anxiety over impending job losses, but King argued that the “headlines” fail to include the type of profiles being let go, and are hence not an accurate reflection of the broader tech market, that, in fact, still has a high demand for digital talent.

These layoffs are rather result of a hiring spree during the pandemic that does not fit today’s reality and economic conditions. The number of layoffs appears massive, but it is, in fact, only a fraction of new headcount added in 2022 alone, tweeted Tom Goodwin, author of Digital Darwinism.

Headcount added (purple) versus layoffs (orange), from Yahoo Finance

Furthermore, the Robert Half study stressed the need for a streamlined hiring process. Employers claimed that they conduct about four interviews with a candidate before extending a job offer.

“Hiring mistakes and regrets can occur when the pressure to staff a role overrides the search for the right candidate,” King noted. “However, drawn-out hiring processes can also be an obstacle in securing top talent, who may lose interest or accept another offer if the timeline is not streamlined.”

More organizations are using AI in their hiring process, and while it can be effective when dealing with large numbers of applications, some companies will use it poorly and “automate out” talent, Shaki said. 

Gartner pointed out that the ethical implications of using AI for hiring, in terms of fairness, diversity, inclusion, and data privacy, are also becoming increasingly salient. Organizations and vendors that use AI and machine learning will face pressure to be more transparent on their AI use, publicize their data audits, and give employees and candidates the choice to opt out from AI-led processes.

An efficient hiring process helps with the branding of a company, and so does the information that they put out there, King noted. “Given the reality of social media and access to information, companies have to be very mindful of their brand. And if their brand is not one of being supportive of initiatives like DEI or ESG initiatives, it could portray a negative brand to the market, and that may impact the ability to attract talent.”

But implementing new HR measures that align with a new generation and a new set of values can irk existing employees. Gartner’s study showed that a significant 42 per cent of employees believe their organization’s DEI efforts are divisive. And two out of five agree that a growing number of employees feel alienated, or even resent their organization’s DEI efforts.

The post Hiring to increase in Canada, despite market volatility: Robert Half study first appeared on IT World Canada.

Reddit on data breach: ‘As we all know, the human is often the weakest part of the security chain’

Cybersecurity experts have long said that attackers need only to get lucky only once, while organizations have to be lucky every time there’s an attack.

Evidence of that maxim was demonstrated in the explanation by Reddit of its recent data breach.

On Feb. 5, an unknown attacker launched what the discussion site called a  “sophisticated phishing campaign that targeted Reddit employees. As in most phishing campaigns, the attacker sent out plausible-sounding prompts pointing employees to a website that cloned the behavior of our intranet gateway, in an attempt to steal credentials and second-factor tokens.

“After successfully obtaining a single employee’s credentials, the attacker gained access to some internal docs, code, as well as some internal dashboards and business systems.”

As a result of the incident, the statement said, Reddit is working to “fortify” employees’ security skills. “As we all know, the human is often the weakest part of the security chain,” the statement added.

To this employee’s credit, however, they reported their mistake, allowing Reddit’s security team to quickly remove the infiltrator’s access.

There is no evidence the site’s primary production systems — the parts of the stack that run Reddit and store the majority of its data — were accessed, the statement said.  Reddit user passwords and accounts are safe, it added.

However, the site admitted the attacker accessed “some internal documents, code, and some internal business systems.”

Exposed data included what the statement called “limited contact information for (currently hundreds of) company contacts and employees (current and former), as well as limited advertiser information. Based on several days of initial investigation by security, engineering, and data science (and friends!), we have no evidence to suggest that any of your non-public data has been accessed, or that Reddit’s information has been published or distributed online.”

The statement also urges Reddit users to enable multifactor authentication to protect their login credentials, and to use a password manager.

Johannes Ullrich, dean of research at the SANS Technology Institute, noted in an email that there is a lot of technology to detect website impersonation. “For example, companies like Google have invested a lot of effort to clean up the TLS [transport layer security, which encrypts data] infrastructure to produce reliable certificates identifying the identity of websites a browser connects to, and to prevent machine-in-the-middle attacks,” he wrote. “But at the same time, little progress has been made to find better ways to communicate to users which organization they interact with.

“Instead of relying on users to decide if a website is legit or not, we need to leverage phishing-resistant authentication schemes like FIDO2. These systems leverage existing technology like TLS to prevent the use of authentication secrets across different sites.”

The post Reddit on data breach: ‘As we all know, the human is often the weakest part of the security chain’ first appeared on IT World Canada.

Indigo Books still recovering from cyber attack

Canadian bookstore chain Indigo is still dealing with last week’s cyber attack.

This morning, the company’s website was still offline. Stores were open but some were having trouble: Shoppers at the Indigo store in Toronto’s Yorkdale mall were told on Saturday that the point of sales stations on the main floor weren’t working and they had to buy products at stations on the second floor.

Immediately after the attack, purchasers were only able to pay for items in cash. Now they can use credit and debit cards. However, customers still can’t use gift cards or return purchases.

Notice on Indigo store window after Feb 2023 cyber attack (ITWC photo)

Shoppers are urged not to log into any site that claims to be Indigo Books.

Asked on Sunday for comment on the cause of the incident, a company spokesperson issued this statement: “We are working hard with third-party experts to gather more information about this incident and can provide you with an update as more information becomes available.”

The post Indigo Books still recovering from cyber attack first appeared on IT World Canada.

Cyber Security Today, Feb. 13, 2023 – Hole in GoAnywhere file transfer utility exploited, ransomware attacks in the U.S. and Israel, and more

A hole in the GoAnywhere file transfer utility is exploited, ransomware attacks in the U.S. and Israel, and more.

Welcome to Cyber Security Today. It’s Monday, February 13th, 2023. I’m Howard Solomon, contributing reporter on cybersecurity for ITWorldCanada.com and TechNewsday.com in the U.S.

&nbsp
;



The Clop ransomware gang is back. According to Bleeping Computer, the gang says it recently stole data from over 130 organizations that use the GoAnywhere MFT file transfer utility. At risk are IT environments that exposed the tool’s administrative console to the internet, allowing a vulnerability to be exploited. The news report says Clop claims they didn’t encrypt data, only stole files. The claims couldn’t be verified. Forta, the company that develops GoAnywhere MFT, issued an emergency security update last Tuesday for on-premise versions of the utility, and one on Thursday for those using the cloud version.

That vulnerability has been added to the Known Exploited Vulnerabilities Catalog kept by the U.S. Cybersecurity and Infrastructure Security Agency. Also just added to the catalog is a hole in Intet’s Ethernet Diagnostics Driver for Windows, and a vulnerability in TerraMaster’s OS operating system for its data storage solutions. Patches for these holes are available.

The city of Oakland, California is recovering from a ransomware attack last week. While its website is now up the city took affected systems offline. Core functions including 911 service, fire and emergency resources and municipal financial data were not affected. However, non-emergency systems including voicemail may be impacted.

The Israel Institute of Technology — more commonly known as the Technion — was the victim of a ransomware attack over the weekend. According to the Jerusalem Post a hacker or hackers are demanding 80 bitcoin, worth about $2 million, to unscramble stolen data. The news site DataBreaches.net says the ransom note claims all of the Technion’s data is encrypted. That hasn’t been verified. No one knows anything about the group claiming responsibility, which calls itself DarkBit. The ransom note says someone should pay for occupation and crimes against humanity. But it also talks about the firing of high-skilled experts. The Jerusalem Post quotes the Israel National Cyber Directorate saying last year there were 53 cyber attacks last year on higher education institutions in the country.

In California, more than three million patients of four medical groups that suffered ransomware attacks late last are receiving data breach notification letters. According to The Register, the four are Regal Medical Group, Lakeside Medical Organization, ADOC Medical Group and Greater Covinia Medical. All are associated with the Heritage Provider Network. Some of the stolen data might have included patients’ names, dates of birth, Social Security numbers and medical records.

A now-closed Virginia university is notifying more than 78,000 students and employees of a data breach last August. At the time the REvil ransomware gang was one of three groups claiming responsibility for attacking Stratford University. According to a copy of the letter being sent to those affected, an attacker obtained some school data, including information from the student database.

A North Carolina software company that provides solutions to the healthcare sector is notifying more than 11,000 patients of a data breach. Intelligent Business Solutions says in November it detected its network had been infected with malware that prevented access to data on certain IT systems. Data copied included patient names, Social Security numbers, dates of birth and medical information.

Canadian bookstore chain Indigo is still dealing with last week’s cyber attack. On Sunday, when this podcast was recorded, the company’s website was still offline. Stores were open. At first, purchasers were only able to pay for items in cash. Now they can use credit and debit cards. However, customers still can’t use gift cards or return purchases. Shoppers are urged not to log into any site that claims to be Indigo Books.

Finally, don’t forget not only is tomorrow Valentine’s Day, it’s also Patch Tuesday, when Microsoft and many major companies release security updates. However, those with SonicWall devices using Capture Client might want to hold off installing Windows 11 updates. That’s because on February 17th SonicWall will release a fix to solve a clash between Capture Client and Win11. A commentator at the SANS Institute says administrators should think about first installing the SonicWall patch before updating Windows.

Follow Cyber Security Today on Apple Podcasts, Google Podcasts or add us to your Flash Briefing on your smart speaker. Thanks for listening. I’m Howard Solomon

 

The post Cyber Security Today, Feb. 13, 2023 – Hole in GoAnywhere file transfer utility exploited, ransomware attacks in the U.S. and Israel, and more first appeared on IT World Canada.

Hashtag Trending Feb.13th-Google employees criticize “botched” announcement of Bard, AI learns without being trained and coping with the biggest issue with hybrid and remote work

Google employees have choice words for their company’s mismanagement of their AI rollout last week. AI that might be able to learn without being trained and ways to cope with what some are calling the “biggest issue in hybrid and remote work.”



 

It’s Monday, February 13th. These stories and more on  Hashtag Trending – today’s top technology news stories. I’m your host, Jim Love.

Employees at Google had choice words for their company’s performance last week in the rollout of the Google’s AI offerings. According to a story on MSNBC, staffers took to the internal message forum Memegen to express their displeasure, calling the rollout of Bard, “rushed” “botched” and even “un-Googley.”

They were of course, referring to the fact that Google’s AI – called Bard – had made a very simple factual error, one that was not detected and found its way into the corporate presentation. That caused an uproar on twitter and sent the company’s stock plummeting.

It also raised the ire of Google employee’s, already unhappy in the face of recent layoffs.

“Dear Sundar, the Bard launch and the layoffs were rushed, botched, and myopic,” read one meme that included a serious picture of Google CEO Sundar Pichai. “Please return to taking a long-term outlook.” The post received many upvotes from employees.

Another popular post stated: “Sundar, and leadership, deserve a Perf NI,” which is the the lowest rating in the company’s employee performance review system. The author goes on to say, “They are being comically short sighted and un-Googlely in their pursuit of ‘sharpening focus.’”

Source: CNBC

Popular user forum Reddit was the victim of a cybersecurity breach. According to Bleeping Computer, hackers managed to gain access to the company’s internal business systems and to steal internal documents and even source code.

Hackers gained access by using a phishing technique which targeted Reddit employees and sent them to a landing page which impersonated Reddit’s internal intranet site. Using that now common technique, they were able to steal employee’s credentials and even two factor authentication tokens.

As Reddit explained in their security incident notice, “After successfully obtaining a single employee’s credentials, the attacker gained access to some internal docs, code, as well as some internal dashboards and business systems,” But the report further notes:

“We show no indications of a breach of our primary production systems (the parts of our stack that run Reddit and store the majority of our data).”

Reddit said that the employee self-reported the incident to the company’s security team.

The stolen data includes limited contact information for company contacts and current and former employees, according to Reddit and the data also included some details about the company’s advertisers. Reddit also noted that credit card information and passwords were not affected.

Source: Bleeping Computer

The Cisco 2023 Data Privacy Benchmark Report had some very interesting insights which point to a real divide between consumer and corporate perceptions of how personal data should be handled, particularly when it comes to its use by Artificial Intelligence based systems.

In the study, 95 per cent of companies called privacy a “business imperative” and said that is was an “integral” part of company culture. 94 per cent believe customers will not buy from them if they are not protecting personal data.

That belief has shown itself in corporate spending on privacy, which, according to the report, increased in 2019, and “at least held steady “in 2022 as companies saw or believed there were financial benefits from these investments.

But the report noted some strong negative responses in terms of customer trust, particularly when it comes to the use of AI. Only 43 per cent of consumers believe AI will prove useful in improving people’s lives. Only just over half (54 per cent) are willing to share even anonymized personal data to improve AI products. 60 per cent say they are concerned about how business will make use of AI, and most punishing, 65 per cent say that current uses have eroded their trust

Companies seem to recognize this, with 92 per cent saying that they need to do a better job of reassuring customers that “AI solutions will only use data for intended and legitimate purposes.”

But the study showed a real disconnect in terms of what is important to consumers versus what is important to the companies surveyed. Consumers stated that that their priority was clear transparency into how data is being used. Organizations were focused on compliance with privacy laws with transparency taking second place.

The big surprise came when 90 per cent of consumers seemed to prefer global data storage providers in terms of security. In prior studies consumers have strongly preferred the idea of local storage or what has come to be termed data sovereignty.

Source: Cisco

According to an article in Vice, researchers at the Massachusetts Institute of Technology, Stanford University, and Google have discovered a “apparently mysterious” phenomenon where AI systems appear to be learning new tasks they have not been trained for – what they have referred to as “in-context” learning.

Normally, to learn how to perform a new task, machine learning models need to be retrained with new data —a tedious and time-consuming process. But what if these systems could learn new tasks from only a few examples, essentially picking up new skills it hasn’t been explicitly trained for?

That’s exactly what these researchers appeared to have observed. If true, this means their model isn’t just copying training data, it’s building on previous knowledge, doing just what humans would do.

The researchers weren’t using ChatGPT or other popular tools, but they are smaller version of the same types of models, so their work does offer insights into these larger tools and data sets.

The researchers fed their model synthetic data, and gave it prompts that the program never could have seen before. “Despite this, the language model was able to generalize and then extrapolate knowledge from them”, according to one of the researchers.

The team hypothesized that AI models that exhibit in-context learning actually create smaller models inside themselves to achieve new tasks. This may be possible due to a concept called “self-attention” used by transformer models, like ChatGPT to track relationships in sequential data, like words in a sentence.

The paper is just being posted and undoubtedly will be the subject of further research, but unraveling how and why this occurs could be a huge step forward in understanding how large language models learn and store information.

Source: Vice

Many companies are reporting that one of the biggest challenges in hybrid and remote work is the on-the-job training and integration of junior employees. A report in Forbes claims that remote and hybrid mentoring may be the solution to this problem.

The article notes that in an effective structured mentoring program companies need to pair up senior staff members with junior staff members for virtual mentoring sessions. They should also be part of a team that also includes two members from outside the employees regular work group. One should be from the junior staff members’ business unit, and another from a different unit. At least one should be from a different geographical area.

The team composition will address one of the key problems in remote and hybrid work – not just helping junior staff build their network, but increasing cross functional connections for staff.

Staff members from the person’s own team should meet with their mentee monthly in a brief 20-30 minute meeting, and go through a checklist that includes a check up on their progress, a list of questions to determine how the employee is feeling and how confident they are in their role. In addition, it should look at what obstacles they are facing and what further things they need for their progress and growth.

The article has a list of questions, but suggests that each company or even team should customize these for their own use.

Source: Forbes

That’s the top tech news stories for today.

Links to these stories can be found in the article posted on itworldcanada.com/podcasts. You can also find more great stories and more in- depth coverage on itworldcanada.com or in the US on technewsday.com.

If you’re trying to keep up on cybersecurity, you might want to follow our sister podcast, CyberSecurityToday.

Hashtag Trending goes to air five days a week with a daily newscast and we have a special weekend edition with an interview featuring an expert in some aspect of technology that is making the news.

Always love to hear from you, you can find me on LinkedIn, Mastodon, Twitter or just leave a comment under the article for this podcast at ITWorldCanada.com

I’m Jim Love – Have great Monday.

The post Hashtag Trending Feb.13th-Google employees criticize “botched” announcement of Bard, AI learns without being trained and coping with the biggest issue with hybrid and remote work first appeared on IT World Canada.

Getting value from our data – the real idea of data governance. Interview with Carter Cousineau, Vice President, Data & Model Governance, Thomson Reuters

I used to cringe when I’d hear people say, data is the new oil.  Like any of these phrases that get tossed around and often misused, it just bugged me.

But then I thought about it some more.  Maybe this metaphor works better than I originally thought.

The first discoveries of oil were almost accidental.  How it would be used was not immediately apparent. Then someone got a bright idea and applied it, making initial products that had some value.  For example, oil was discovered in 1858 a place in Ontario, Canada called, fittingly, Oil Springs.  Later additional discoveries were made around a town that came to be called Petrolia.

Initial discoveries were by chance and they were noted in the Geological Surveys of the time.  The oil was close to the surface, not like the wells of today.  And the wells were dug by hand.

Remember, this was before the first gas powered automobile, made by Karl Benz in 1885 – so the oil was refined by some pretty primitive processes and used for kerosine for lamps.  It was a smaller industry than what we know today, but if fulfilled a real need.

It wasn’t until the gas fired automobile came into existence in the 1890’s that the real demand for petroleum began in a big way and oil discoveries led to untold wealth.  By that time, the “easy” discoveries were made.  If you wanted to find oil sufficient to be part of the new automobile and industrial demand, you had to invest what would be today, hundreds of millions of dollars. And there was a risk. You could do the planning, the development and invest all that money – and have little or nothing to show for it.

Actually this sounds a lot more like data exploration than I thought.

Toronto university to help train Ukrainians in cybersecurity

A Canadian university is partnering with Ukraine for a pilot program to train up to 100 Ukrainians to become cybersecurity professionals.

The Brampton, Ont.-based Rogers Cybersecure Catalyst, a centre for training, innovation and collaboration in cybersecurity that is part of Toronto Metropolitan University, said today the program will be delivered online in collaboration with Ukraine’s Information Systems Security Partners (ISSP), a cyber company, and the country’s Ministry of Digital Transformation.

The program will provide foundational cybersecurity training to Ukrainians who have been displaced from previous employment by the war, the university said in a news release. Program participants will graduate with an internationally recognized cybersecurity certification.

Recruitment for the program will start soon. Once complete, the pilot training program will be evaluated for potential expansion to a larger cohort of Ukrainian learners.

“We believe this program will have a positive impact on the Ukrainian economy as well as contribute to the long-term development of Ukraine’s cybersecurity sector,” Charles Finlay, the Catalyst’s founding executive director, said in a statement. “We are committed to helping make this project a success and hope we can grow this program in the future.”

“The Catalyst answered the call to support the economic reconstruction of Ukraine through its expertise and leadership in cybersecurity training,” said Canadian Minister of Foreign Affairs Melanie Joly. “We all have a duty to think of the future of Ukraine, and our Government looks forward to this pilot program’s success.”

Related content: Ukraine deputy cyber leader speaks to BlackBerry conference 

Ukraine has developed considerable cybersecurity expertise after facing Russian-based cyber attacks for at least eight years. In December 2015, and again almost exactly a year later, the country’s power grid was temporarily knocked out by cyber attacks.

Cyber attacks on Ukrainian websites in January 2022 were a prelude to the February 2022 invasion by Russian forces. Since then, a number of tech companies have been helping Ukraine, including Google, Microsoft and SpaceX.

The country has asked the International Criminal Court to investigate whether certain Russian cyberattacks could constitute war crimes.

Still, Ukrainian organizations face daily cyber attacks, many of which involve wiperware. Attackers are sending tempting — and infected — email messages to Ukrainians, with links to applications or supposedly official Ukrainian government documents.

Last month, a Ukrainian cybersecurity official was quoted as saying the country has suffered a threefold growth in cyberattacks over the past year.

The post Toronto university to help train Ukrainians in cybersecurity first appeared on IT World Canada.

Cyber Security Today, Week in Review for Friday, February 10, 2023

Welcome to Cyber Security Today. This is the Week in Review edition for the week ending Friday, February 10th, 2023. I’m Howard Solomon, contributing reporter on cybersecurity for ITWorldCanada.com and TechNewsday.com in the U.S.



In a few minutes Terry Cutler of Montreal’s Cyology Labs will be here to discuss recent news. But first a look back at some of the headlines from the past seven days:

A security researcher discovered several vulnerabilities in Toyota’s supplier website that gave access to … everything. Terry and I will talk about how this happened.

We’ll delve into the rush to protect servers running unpatched and outdated versions of VMware’s ESXi hypervisor from ransomware, and ask why are companies running old applications.

Lists of some 20 million customers who used two U.S. companies for background checks of employers and individuals are being pedalled by crooks. Terry and I will have something to say about that.

And we’ll look at a suggestion the Canadian government offer tax breaks to encourage small businesses to spend more on cybersecurity.

In other news, IT administrators whose firms use open-source and free versions of certain document management systems were warned of vulnerabilities. Researchers at Rapid7 say the problems are in on-premise versions of OnlyOffice Workspace, OpenKM, Logical-IDOC and Mayan EDMS. At the time of the recording of this podcast the vendors hadn’t patched the holes. So administrators have to take precautions, some of which are outlined in the Rapid7 report.

The U.S. and the United Kingdom have sanctioned seven people who they say are members of the Trickbot cybercrime group. The Trickbot malware is widely distributed through botnets and email campaigns. Sometimes its also used to help deploy ransomware. The U.S. says current members of the gang are associated with Russia’s intelligence service. The sanctions mean the seven can’t access any assets they have in the U.S.

A British member of Parliament says he fell for a phishing scam. Stewart McDonald admitted he opened a message sent to his personal email account with a supposed military update on Ukraine. Clicking on the document opened a form where he filled in his email address and password. The suspicion is a Russian-based group dubbed Seaborgium was behind this attack.

Another DDoS-as-a-service provider has sprung up in Russia. Researchers at Radware say the Passion group is offering denial of service capabilities to Russian hacktivists. The botnet was seen last month attacking hospitals in the U.S., the United Kingdom and several European countries that support Ukraine. It’s another reason for companies in NATO countries to beef up their cybersecurity.

Authorities in the Netherlands, Germany and Poland have dealt another blow to the communication lines of crooks. They did it by dismantling the Exclus encrypted messaging system, which had an estimated 3,000 users. Forty-five people, including the service’s administrators and owners, were arrested. Two drug laboratories were dismantled and 200 smart phones were also seized. In the past two years European police also shut the Sky ECC and EncroChat encryption services used by crooks.

Atlassian has released fixes to patch a critical vulnerability in Jira Service Management Server and Data Center. Versions 5.3 and above have to be patched.

And a 20-year-old man in Australia was sentenced to community service for taking advantage of last year’s theft of data from telecom provider Optus. For a brief time that data was publicly available, and this man got hold of some of it. Then he tried to extort people out of money or their personal information would be sold to hackers.

(The following is a transcript of one part of our discussion. To hear the entire conversation play the podcast)

Howard: France and Italy sparked a worldwide ransomware alert about attacks on vulnerable VMware ESXi servers. They include version 7.0, which is supported. But also versions 6.7 and 6.5 which are no longer supported by VMware. Unpatched versions of ESXi are at risk from a targeted ransomware strain dubbed ‘ESXiArgs.’ The thing is, a patch for the vulnerability was issued two years ago. In theory, no one should be running versions 6.7 and 6.5, let alone unpatched servers. However, the SANS Institute says there are some 300 unsupported or unpatched versions of ESXi out there. Another source says the number is more like 2,400. Terry, what’s worse: Organizations running unpatched severs or running non-supported software?

Terry Cutler: I think the problem is more around how critical the guests that are running on these [virtual] hosts. As you know, we do a lot of work in health care and a lot of these guests have to be up 24/7, 365 days a year. If you try to update the VMware host it usually requires a reboot, which would shut down all the guests that are running on the host. Gawd forbid there’s a problem with with upgrade and the host doesn’t come back up, that means the company is down. Most IT admins are scared of this. I’ve been there. I know the pressure when a system doesn’t come back online and management is breathing down your neck and all you could tell them is, “10 more minutes! Ten more minutes, I promise it’ll be up!” Also, the fact that it ] is on the Linux operating system, most IT managers believe that Linux is never going to get hacked, so they leave it unpatched.

Howard: The good news is the U.S. Cybersecurity and Infrastructure Security Agency issued a recovery script for victims of this strain of ransomware. The bad news is, according to a story on the Bleeping Computer news site, is that the crooks behind this particular ransomware strain quickly issued a new version that apparently gets around the fix that. The recovery script works for the original strain of ransomware, but not version two.

Terry: It is some great news. But then again I think a lot of this could be prevented by running some free vulnerability tools that will help discover what assets are on your network and what’s vulnerable. As I mentioned countless times, if your systems are exposed to the internet and they’re vulnerable they will be exploited. The biggest concern that I see is that most companies don’t even know what assets they have or what’s exposed, and that’s why they need to team up with cyber security experts that will come in and assess that for them and give their risk level.

The post Cyber Security Today, Week in Review for Friday, February 10, 2023 first appeared on IT World Canada.

U.S., South Korea issue alert on North Korean-based ransomware groups

North Korean state-sponsored ransomware groups are targeting hospitals and other critical infrastructure organizations, U.S. and South Korean law enforcement and intelligence agencies are warning.

“The authoring agencies assess that an unspecified amount of revenue from these cryptocurrency operations supports DPRK (Democratic People’s Republic of Korea) national-level priorities and objectives, including cyber operations targeting the United States and South Korea governments,” the alert issued Thursday says.

“Specific targets include Department of Defense Information Networks and Defense Industrial Base member networks. The IOCs [indicators of compromise] in this product should be useful to sectors previously targeted by DPRK cyber operations (e.g., U.S. government, Department of Defense, and Defense Industrial Base). The authoring agencies highly discourage paying ransoms as doing so does not guarantee files and records will be recovered and may pose sanctions risks.”

The report includes the latest tactics, techniques, and procedures (TTPs) and indicators of compromise (IOCs) used by North Korean-based attackers. Among the more recent weapons are attempts to exploit unpatched applications with the Apache Log4J2 vulnerability and unpatched SonicWall appliances.

North Korean attackers are known for hiding where they are coming from, the report adds, including sometimes pretending to be other ransomware groups, such as the REvil gang.

The alert is an update to a July 6, 2022 warning by American intelligence and law enforcement agencies, including the Cybersecurity and Infrastructure Security Agency (CISA), the FBI and the NSA.

That report noted the use by North Korean groups of the Maui strain of ransomware. The new report adds that these groups are also using a strain called H0lyGhost, described by Microsoft in a July 14, 2022 report.

The latest report comes the same week as the Associated Press reported that a United Nations panel concluded North Korean hackers working for the government stole virtual assets, including cryptocurrency and intellectual property, estimated to be worth between US$630 million and more than US$1 billion.

“2022 was a record-breaking year for DPRK virtual asset theft,” the AP quoted the report saying. In April, 2022, the U.S. linked North Korean-backed hackers to the US$615 million crypto heist on the popular online game Axie Infinity.

The AP said the panel identified three groups – Kimsuky, Lazarus Group and Andariel — as the main North Korean attackers.

Between February and July 2022, AP quoted the panel as saying the Lazarus Group “reportedly targeted energy providers in multiple member states using a vulnerability” to install malware and gain long-term access. It said this “aligns with historical Lazarus intrusions targeting critical infrastructure and energy companies … to siphon off proprietary intellectual property.”

The U.S./South Korea alert urges IT and security departments to

limit access to data by authenticating and encrypting connections with network services (e.g., using public key infrastructure certificates in virtual private network (VPN) and transport layer security (TLS) connections), Internet of Things (IoT) medical devices, and the electronic health record system;
implement the principle of least privilege by using standard user accounts on internal systems instead of administrative accounts, which grant excessive system administration privileges.
turn off weak or unnecessary network device management interfaces, such as Telnet, SSH, Winbox, and HTTP, for wide area networks (WANs), and secure with strong passwords and encryption when enabled;
protect stored data by masking the permanent account number (PAN) when displayed and rendering it unreadable when stored — through cryptography, for example;
secure the collection, storage, and processing practices for personally identifiable information (PII) and protected health information (PHI) at rest and in transit using technologies such as TLS. Only store personal patient data on internal systems that are protected by firewalls, and ensure extensive backups are available;
implement and enforce multi-layer network segmentation, with the most critical communications and data resting on the most secure and reliable layer;
and use monitoring tools to observe whether IoT devices are behaving erratically due to a compromise.
The post U.S., South Korea issue alert on North Korean-based ransomware groups first appeared on IT World Canada.

Cyber Security Today, Feb. 10, 2023 – Cyber threats against executives are increasing, the latest on email scams and more

Cyber threats against executives are increasing, the latest on email scams and more.

Welcome to Cyber Security Today. It’s Friday, February 10th, 2023. I’m Howard Solomon, contributing reporter on cybersecurity for ITWorldCanada.com and TechNewsday.com in the U.S.



Threat actors are increasingly targeting executives and board members. According to researchers at BlackCloak, there’s been a recent surge in doxing and swatting of these people. Doxxing is the threat to release personal information on victims. Swatting is getting police to respond to a fake threat at a victim’s office or home. Infosec leaders should have their executives remove any mention of where their residences are on corporate websites or in social media. As an extra precaution homes should be registered in an anonymous trust or corporation to keep strangers from finding out where they live.

Hackers are increasingly using HTML email attachments to deliver malware. This is called HTML smuggling, according to researchers at Trustwave. It works because the malware is in a blob of data within JavaScript code that gets decoded when opened in a web browser. Email scanners may miss these packages. Ever since Microsoft last year started blocking macros in Office documents sent over the internet by default hackers have shifted to HTML smuggling. Tricks include crafting documents that look like they came from Google Drive, Dropbox or are Adobe Acrobat PDFs. Employees need to be warned — again — to be wary of attachments.

Here’s another warning about phishing emails from crooks: Researchers at Proofpoint are seeing attachments or URLs that lead to the installation of a tool that takes screenshots of victims’ computers. A common message to targets is a request to check the attached business presentation. Clicking on the document or the URL downloads the malware. With a screenshot of the victim’s machine the attacker hopes to see passwords and get information on the victim. Then the attacker will download more malware. Targets have been seen in the U.S. and Germany. Again, employee education is a good way to fight this attack.

Finally, the Super Bowl is this Sunday. It’s available on cable and over the air, but some people want to use illegal internet streaming websites for supposed high-definition viewing. Don’t. Researchers at OpenText note that these services have to make money somehow. Usually they do it by getting victims to download software to help them see the game. That software has malware for stealing passwords. —

Later today the Week in Review podcast will be available. Guest commentator Terry Cutler of Cyology Labs and I will discuss the new ransomware strain going after unpatched installments of VWware’s ESXi hypervisor, holes found in Toyota’s supplier website and more.

Follow Cyber Security Today on Apple Podcasts, Google Podcasts or add us to your Flash Briefing on your smart speaker.

The post Cyber Security Today, Feb. 10, 2023 – Cyber threats against executives are increasing, the latest on email scams and more first appeared on IT World Canada.