Category: News

Apple gets hammered by the EU again: Hashtag Trending for Tuesday, March 26, 2024

Apple gets hammered by the EU once again while there’s a threat in the US of breaking up the big tech giants. Google appears to have another problem AI implementation, Steve Wozniak is back as an unlikely critic of the TikTok ban, a new open source AI that runs on your computer an an Amazon executive has a different take on Artificial General Intelligence.

These stories and more on the “Breaking up is hard to do” edition of Hashtag Trending. I’m your host, Jim Love, let’s get into it:

Big tech is taking a big beating on a number of fronts, with some asking if the ultimate end game isn’t the breaking up of some of the giants – Meta, Google and even Apple.

Apple got hammered in the European Unio again this week. The EU announced that it’s not satisfied that Apple’s App Store changes are compliant with the Digital Markets Act and the company is now officially under investigation for non-compliance.

What it really all boils down to is that the EU is not convinced that Apple is complying with their anti-trust laws. These laws are supposed to ensure that tech giants can’t use their market dominance to give their products and services an unfair advantage over their competitors.

Apple has been flagged for some of what the EU regards as anti-competitive behaviour in the way it forced developers to not be able to recommend any payment method other that through the Apple store and the EU also forced Apple to allow for other stores that could sell software for iPhones and other devices.

But each time, the “solutions” that Apple offered were criticized for not, to put it kindly, being anything resembling a true compliance to the EU requirements.

The rules and restrictions were so complex that they would take regulators a lot of time to analyze.

But for some of them, when you worked through the convoluted rules, left Apple competitors worse off than before the changes. For example, one of the provisions they implemented to allow developers to participate in another app store had provisions that could bankrupt smaller developers just for being successful in attracting a lot of downloads.

So the EU is pushing back, big time, opening another investigation into Apple’s potential “non-compliance.”

This is serious stuff in the EU. Apple was fined 1.8 billion dollars for supposedly breaking rules for supposed anti-competitive behaviour in music streaming. But there’s a much bigger potential set of penalties for these latest charges.. Companies can be fined up to 10% of their world-wide sales, or “turnover” is what the legislation calls it, and this increases to 20% for repeat offences.

And to add to the bad news, Apple is under investigation in the US as the Department of Justice launched legal action along with 15 state governments against the company, again for what they feel is anti-competitive behaviour.

But unlike the EU which relies on monetary penalties, the US has had a history of breaking up companies that engage in anti-competitive behaviour. The biggest of these goes back to the breakup of AT&T in the US. AT&T was broken up into 7 different companies, the so-called Baby Bells.

But Google and Meta can’t be smug. The EU is also turning its sights on them. The news release reads:

Today, the Commission has opened non-compliance investigations under the Digital Markets Act (DMA) into Alphabet’s rules on steering in Google Play and self-preferencing on Google Search, Apple’s rules on steering in the App Store and the choice screen for Safari and Meta’s “pay or consent model”.

And while the EU leads in this area, so far the US may take time, but has traditionally moved in the same direction, like it did with Apple.

Sources include:  Reuters and 9to5Mac and the BBC

Google’s new AI-powered “Search Generative Experience” is supposed to be a big move forward in AI powered search. But it turns out that this new offering seems to be promoting scams and spam sites.

The new feature gives a summary of search queries followed by recommendations of sites to visit. But it turns out, as one SEO consultant, Lily Ray spotted, those conversational responses are making it easier for people to fall for scams and sites with malicious behaviours.

Bleeping Computer did some of its own testing and found similar results. Many sites that were part of what is called SEO poisoning, where legitimate sites are taken over and used to promote scams with seemingly legitimate ads and links. They can also be taken through a series of redirects to the scam sites.

Whatever the tactic, it appears that Google’s new feature is prone to promoting these sites, making this yet another time that Google has “stepped in it” as it tries to promote its use of AI.

Sources include: Bleeping Computer

An new open source AI caught my attention. I was recently interviewed by Red Hat for a series called Todd Talks where I talked about Open Source AI as potentially democratizing AI by making it available to everyone and then, lo and behold, I saw a story on Jan.

Jan is being described as an Open Source ChatGPT alternative that runs completely offline on a regular computer.

Developed by a team of researchers from Jan Labs intent on democratizing AI, as well as giving users greater control over the privacy of their information, Jan is described as having the “power of ChatGPT locally on the desktop.”

Jan can run on a wide range of different computers from Apple’s M series to Nvidia GPU’s.

Jan’s founders envision AI as “an extension of human intelligence” and have developed it based a four principles:

Ownership: After being freed from external data tracking or storage, users can maintain complete ownership of Jan. Jan is a tool created by users and for users that promotes independence and self-determination.
Privacy: Jan prioritizes user privacy by minimizing reliance on external servers, primarily operating in a local context. The user’s device securely stores data, providing unmatched privacy control.
User Support: Jan has a community-driven development approach, allowing users to access, alter, and add to its codebase. Because of this cooperative approach, Jan is guaranteed to change in response to user requirements and preferences.
Ethical Design: Jan upholds user welfare and agency by prioritizing ethical design principles over deceptive methods or proprietary lock-ins.

Jan is avaiable under AGPLv3 license, and is being developed via collaborative platforms like Discord and tools like Kanban boards, to foster what the team says is information sharing and creativity.

Support for Python runtimes and mobile platforms are some of the planned additions to

Sources include: Martech Post

Steve Wozniak, the co-founder of Apple Computer is back in the news as an unlikely defender of TikTok. Or at least as someone who thinks that its hypocritical to  single  out TikTok, while letting big players like Meta and Google are also gathering our data and tracking us. As he said in the CNN interview,

“If you have a principle [that] a person should not be tracked without them knowing it, you apply it the same to every company, or every country. You don’t say, ‘Here’s one case where we’re going to outlaw an app, but we’re not gonna do it in these other cases.’ So I don’t like the hypocrisy, and that’s obviously coming from a political realm.”

He went on to say,  “And tracking you – tracking you is questionable. But my gosh, look at what we’re accusing TikTok of, and then go look at Facebook and Google and that’s how they make their businesses,I mean, Facebook was a great idea. But then they make all their money just by tracking you and advertising, and Apple doesn’t really do that so much.”

Wozniak was actually quite complimentary to Apple’s “walled garden” approach as being more protective of user data and privacy.

Wozniak has always been out on the leading edge, as far back as the founding of Apple. He’s led the charge for digital rights as one of the founders of the Electronic Frontier Foundation.

But you might be forgiven for seeing him as an unlikely champion of TikTok. But actually, Wozniak says he prefers prefers it to the other social networks.

In this CNN interview he said, he largely avoids “the social web,” but gets a lot of fun out of watching TikTok “even if it’s just for rescuing dog videos and stuff.”

There was another brighter moment to Wozniak’s interview. He was hospitalized last fall in Mexico City with a stroke and much to the joy of fans (myself included) he looks like he has fully recovered.

Sources include: The Register

What is Artificial General Intelligence. Is it AI that’s smarter than us? Is it AI that is self-aware? Or is it simply, AI that can hold down a job?

The problem is that we don’t have an agreed upon standard for what differentiates what we think of as an algorithm to what we think of as a more human type of intelligence.

The lines are getting blurrier all the time. Autonomous agents, we’ve covered these, are able to plan, learn and execute tasks. If you’ve followed the conversations with Anthropic’s Claude or Inflection’s pi.ai it’s getting harder and harder to convince yourself that there is not some kind of emergent behaviour that is, at least possible.

AGI has a certain fear factor which accompanies it, with visions of it taking over from humans like some bad sci-fi novel. Even a report prepared for the US government warned of the dangers of AGI.

But while might not have agreement on what the definition of Artificial General Intelligence is, but that’s not stopping Amazon from projecting where they think it will play in our future.

To Amazon, AGI may be a more personal thing, not a monolithic intelligence, but instead a series of functions that serve humans.

Vishal Sharma, Amazon’s VP for artificial general intelligence announced at the South by Southwest conference that “the future is a personal AGI for everyone.”

It’s this idea of “ambient intelligence” which is personified, if that’s the right word, but the Alexa assistant. It’s an AI that presents itself when needed and then fades into the background.

Today with Alex, there are something in the neighbourhood of “30 models powering more than 130,000 skills,” Sharma said. And 40% of smart home interactions are initiated by Alexa, according to Amazon.

According to Sharma this is the path that will lead to what he called “embodied AI” – more than simply a speaker in your room.Amazon is experimenting with Astro, an AI powered house robot with the same name as the 1960’s futuristic cartoon the Jetson’s.

But closer to reality are services like Alexa’s “hunches” which can lock your door if you forget to.

Sharma noted that he thought we are still a ways away from AGI and that we might hit a wall in ceiling in that development where we find that our language is too abstract to train AI to achieve AGI.

But it’s brighter future than what we have been hearing, more like the Jetson’s than Terminator.

Sources include: Axios

And that’s our show for today.

Remind your friends that they can get us anywhere you get audio podcasts Google, Apple, Spotify, whereever, and even on their smart speakers – and remind yourself that if you like the podcast, please give us a good review – it matters. And as I’m sure you know, there is a copy of the show notes at itworldcanada.com/podcasts

I’m your host, Jim Love. Have a Wonderful Wozniak Wednesday.

 

 

The post Apple gets hammered by the EU again: Hashtag Trending for Tuesday, March 26, 2024 first appeared on IT World Canada.

CIOs complain of “application sprawl” – Hashtag Trending, Monday March 25th, 2024

Apple may get an unexpected penalty from the US Governments new lawsuit, survey of CIOs complains of application sprawl but proposes that the way to get out of it is “more applications”, 1% of employees cause 89% of data loss events and information surfaces about some potentially enormous developments in AI in the coming months.

These stories and more on the “sum of all fears” edition of Hashtag Trending. I’m your host, Jim Love, let’s get into it:

Even if Apple manages to win the lawsuit launched by the  US Department of Justice last week, it  may get a penalty that it fears more than fines  – disclosure.

This legal battle could force the revelation of Apple’s most closely guarded secrets, potentially exposing detailed insights into its operations, strategies, and unannounced projects during the discovery process.

Apple’s obsession with managing both its secrecy and  its public image could be hurt badly as the courtroom becomes a stage where aspects of its business, usually shrouded in secrecy, may be disclosed.

This has happened in past legal skirmishes. When Apple sued Samsung a decade ago, Apple was forced to share details of unlaunched prototypes, market research and its highly secret design process. That lawsuit brought in details that other tech companies wanted kept secret, such and Intel, Qualcomm and others filed motions to try to keep their business dealings from being part of the public record.

And in 2005, Apple was again forced to confirm unannounced products, ironically when it went to court to punish people for leaking its product info.

Perhaps with this experience, Apple’s getting better at protecting its information in lawsuits, or it could just be PR bravado, but an Apple spokesperson told Axios that “We have litigated dozens of high-profile cases over the last 15 years,” the official said. “DOJ has already had access to millions of documents during the course of the investigation. Yet they only used the same tired documents that have been part of the public record.”

We’ll see.

Source: Axios

A Harris poll claims that 84% of the CIOs they surveyed are concerned about “application sprawl.” Again according to the report the number of new applications is growing alarmingly. In 2022 the amount was 20 to 40 new applications per year. By 2024 that amount has grown to 30 to 60 new applications per year.

Not surprisingly, half of those surveyed were planning to consolidate various applications.

Where are these applications coming from? While the report doesn’t explicity state this, it would seem that a number of these are new AI applications.

90% of the CIOs sampled agree that AI tools can dramatically improve their own performance as well as the performance of their employees.

When asked what the benefits of AI applications were, half or 52% said that AI saved time on creative tasks. 50%  felt that AI helped them get data driven insights. And in an answer I couldn’t quite understand, half of them felt that AI would help them consolidate applications – my question was, would it consolidate them faster than the growth that was causing this growth in the number of applications, because despite the earlier findings on “application sprawl” 94% plan to invest in these new AI driven tools.

Some other observations? 70% claim that they have established some “guard rails” for safe use of AI in the workplace.

The study covered 1,369 CIOs in the US with approximately 150 in each country – the US, Spain, German, France, Brazil, Mexico, India and Australia.

And once more – watch how many times this happens – there’s no mention of Canada. So, we’re not going to mention who sponsored the poll. Sounds fair to me.

Source: Harris Poll

A report by security company Proofpoint reveals that the average organization has grappled with approximately 15 incidents of data loss in the past year alone, translating to more than one episode per month. A staggering 71% of the respondents pinpoint careless users as the culprits behind these breaches.

This spans a range of actions, from misdirecting emails to visiting phishing sites, installing unauthorized software, and emailing sensitive data to personal accounts. These behaviors, although preventable, suggest a significant lapse in organizational vigilance.

One of the most common, yet easily avoidable, sources of data loss is misdirected email. The report one-third of employees have sent emails to the incorrect recipient, posing a considerable risk to data security.

In a company with 5,000 employees, that would be 3,400 misdirected emails annually. These errors are not just simple operational mistakes – they could also lead to hefty fines under GDPR or other privacy legisltation due to the potential exposure of sensitive information.

The rise of generative AI technologies, including ChatGPT, Grammarly, Bing Chat, and Google Gemini, marks the fastest-growing area of concern. With these tools gaining traction these models are increasingly being used for sensitive information.

Not all data loss incidents are accidents or carelessness. About 20% of respondents identified malicious insiders, such as employees or contractors, as potentially intentionally causing breaches. These may also be presumed to have more severe consequences because of this deliberate intent.

The survey identifies departing employees as a significant risk factor. Not because individuals perceive their actions as malicious; rather, they feel entitled to take certain information with them. Data from Proofpoint indicates a troubling trend where 87% of anomalous file exfiltration among cloud tenants over nine months was attributed to departing employees.

But privileged users, such as those in HR and finance with access to sensitive data, are deemed the highest risk, with a mere 1% responsible for 88% of data loss events. This finding underscores the importance of actively managing and monitoring privileged access – something many organizations do not do effectively.

On a positive note, the survey reveals a growing maturity in organizations’ approach to data loss prevention and a move away from compliance-driven measures towards a more holistic view of data security particularly in areas that have shown great vulnerability such as healthcare and government.

Source: Proofpoint

And finally, there are reports that Open AI will release a new model, which some are calling GPT5 mid-year. Whatever the name, Sam Altman himself said in a recent speech that this will be a major upgrade.

Wes Roth, a YouTube commentator who follows OpenAI closely reported some CEO’s have had early access to this new model and one is reported to have said, “it’s materially better.”

So, what will this new development be? The speculation, again fueled by comments from those who have seen the model, is that it’s going to be autonomous agents. These intelligent agents can learn, plan, and take actions in the real world and they mark the next phase of AI development.

These autonomous agents already exist. We covered them a while ago when RabbitR1 launched with the ability to use them.

But in the past week there’s been another example of how powerful these agents can be. DevinAI is an autonomous AI agent built by Cognition Labs to be a software developer. Devin, an agent that learns from its work and its mistakes has shown to be extremely powerful and sophisticated development tool.

Ethan Millick, a professor at Wharton, asked Devin to go on Reddit and advertise its services for web development. In a thread that has since been taken down, Devin got on Reddit, was able to understand and obey the rules for how developers can solicit for assignments.

It also understood that it should try to charge for its work.

Devin got on Reddit, posted and monitored the thread for responses.

Devin’s post got 366 views and some comments and Devin asked for the API key to Reddit to respond. At that point, Mollick stopped the experiment and took down the post.

The intent was not to fool anyone or to make money, it was to demonstrate that even with the level of GPT4, you can build autonomous agents that can successfully navigate even the nuances of social media successfully.

That’s where we are today. What will the next level of autonomous agents be able to do? This is going to be a huge development. AI will no longer be a passive agent that answers questions, it will be able to take actions in the real world.

When you combine that with what is happening in robotics – buckle up, this is going to be an interesting year.

And that’s our show for today.

Remind your friends that they can get us anywhere you get audio podcasts Google, Apple, Spotify, whereever, and even on their smart speakers – and remind yourself that if you like the podcast, please give us a good review – it matters. And as I’m sure you know,  there is a copy of the show notes at itworldcanada.com/podcasts

I’m your host, Jim Love. Have a Marvelous Monday.

 

 

The post CIOs complain of “application sprawl” – Hashtag Trending, Monday March 25th, 2024 first appeared on IT World Canada.

Cyber Security Today, March 25, 2024 – A suspected China threat actor going after unpatched F5 and ScreenConnet installations

A suspected China threat actor going after unpatched F5 and ScreenConnet installations.

Welcome to Cyber Security Today. It’s Monday, March 25th, 2024. I’m Howard Solomon, contributing reporter on cybersecurity for ITWorldCanada.com and TechNewsday.com in the U.S.



Hundreds of organizations in the U.S., Canada, the U.K., Australia and other countries are being targeted by a China-based threat actor. That’s according to researchers at Mandiant. Given the name UNC5174, this threat actor is going after unpatched installations of F5’s BIG-IP appliances, ConnectWise’s ScreenConnect, Atlassian’s Confluence servers, Zyxel Firewalls and Linux servers. The suspicion is this person used to be with a Chinese hacktivist collective and is now selling access to compromised companies it gets to China’s Ministry of State Security. IT administrators are urged to quickly take recommended remediation steps for F5 appliances and ScreenConnect software.

Over 100 companies in the U.S. and Europe have been targeted by threat actors in the latest phishing message campaign spreading the StrelaStealer malware for stealing email passwords. Researchers at Palo Alto Networks say this new campaign began in January. Some messages claim the attachment is an invoice that has to be paid. High-tech companies are particularly being targeted. Employees need to be reminded not to click on email or text attachments unless they are sure who the message comes from.

A more powerful variant of the Russian AcidRain data wiper that crippled satellite modems across Europe at the beginning of the invasion of Ukraine has been spotted. Researchers at SentinelOne call this variant AcidPour. While the first version was aimed at devices with MIPS processors, AcidPour can hit those running x86 processors. These include Linux-powered networking and IoT devices, RAID arrays and large storage devices. This new wiper is being used against internet and telecom service providers in Ukraine. IT and network administrators in critical industries in any country need to keep vital devices patched to avoid successful infrastructure attacks.

Microsoft has released an emergency Windows Server update to cure a problem with the March patches it released a few weeks ago. The problem causes Windows domain servers to crash. Bleeping Computer said the updates are for WinServer 2022, 2016 and 2012. A fix for WinServer 2019 will be released shortly.

German authorities have seized the darknet market called Nemesis as part of an operation with the U.S. and Lithuania. Founded in 2021, the Nemesis Market sold stolen data, ransomware and phishing services, and drugs. Forensic data gathered in the seizure will help investigate the over 150,000 users and 1,100 sellers on the market.

What will it take to get American hospitals and healthcare providers to get tougher on cybersecurity? Being forced to act with legislation, says American Senator Mark Warner. He introduced a bill on Friday to allow health care providers to get accelerated medicare payments if they are victims of a cyber attack — but only if they meet minimum cybersecurity standards. Those proposed standards haven’t been set yet. Warner introduced the legislation because of the impact across the U.S. on a ransomware attack on Change Healthcare, which processes payments for patients. According to the news site Cyberscoop, major American healthcare groups oppose having to meet mandatory minimum cybersecurity standards.

Mozilla, the group behind the Firefox browser, has dropped a reputation service called Onerep that it had been bundling with its Mozilla Plus subscription service. This comes after security journalist Brian Krebs reported that Onerep’s owner also owns dozens of services that do internet searches on people, including one that sells background reports on individuals. Onerep’s owner said there was no information sharing between that company, called Nuwber, and Onerep. But that didn’t satisfy Mozilla.

Here’s the latest data breach news:

Select Education Group, which runs several post-secondary schools in California and Oregon including the Institute of Technology, Bauman College, Fremont University and the National Holistic Institute, is notifying just over 67,000 people personal data it holds was stolen. The incident happened last November. Data stolen included names, Social Security numbers, billing and payment records and/or academic records.

Monmouth College of Illinois, which has a student body of about 750 students, is notifying just under 45,000 people that their personal data was exposed in a ransomware attack last December.

By coincidence — or not — nearby Henry County was hit by a ransomware attack last week. According to the cybersecurity news service The Record, the Medusa ransomware gang is taking credit for that attack.

The city of Jacksonville Beach, Fla., is notifying about 49,000 people their personal data was copied in a January cyber attack. According to a local news site, the mayor says this was a ransomware attack.

The American division of GardaWorld Cash, a cash management provider for banks and retailers, is notifying almost 40,000 people of the theft of personal data held in administrative files. It happened last fall, but it took until this month to identify and get the addresses of the victims. Data stolen included names, Social Security numbers, drivers licence numbers, dates of birth and either insurance benefits or health information.

Finally, March is when individuals in Canada, the U.S., the U.K. and other countries prepare to file their income taxes. It’s also a time when crooks unveil their latest email or text-based tax scams. Ignore emails that purport to be from a government tax agency with an attachment that’s supposed to help fill out your taxes. Also, ignore phone messages warning to you to call a number because of a tax problem. Usually the government will tell you to log into your tax account to look for a message rather than send you an email with an attachment. Scammers are also sending out emails promising to help with large refunds under certain government programs, or to help you fill out your taxes. Here’s an IRS list of common tax scams and a Microsoft report on tax scams.

Follow Cyber Security Today on Apple Podcasts, Google Podcasts or add us to your Flash Briefing on your smart speaker. Thanks for listening.

The post Cyber Security Today, March 25, 2024 – A suspected China threat actor going after unpatched F5 and ScreenConnet installations first appeared on IT World Canada.

A hacker’s view of the civic infrastructure: Hashtag Trending, the Weekend Edition for March 23rd, 2024

What does the civic infrastructure look like through the eyes of a hacker?
The legendary general Sun Tzu in the Art of War said that in order to defeat your enemy, you must first understand your enemy. How do you do this? He said, “to know your enemy, you must become your enemy.”
If we are to defend our infrastructure, we have to see ourselves through the eyes of the hackers who may attack us. We have to see ourselves clearly, looking for all of our weaknesses.
There is nobody better to help us do this than Nick Aleks, who describes himself as the Chief Hacking Officer at a new firm ASEC.IO
Nick is proud to call himself a hacker. Not the type of hacker who does damage, but one who has the mindset and the skills to see what hackers see and to test defences so that we can strengthen them.
Nick has been a CISO, he’s an author, he’s worked with us on hosting events, and I hope we’ll be seeing a lot more of him in the future.
Join us as Nick and I take a tour of our civic infrastructure through the eyes of a hacker.

The post A hacker’s view of the civic infrastructure: Hashtag Trending, the Weekend Edition for March 23rd, 2024 first appeared on IT World Canada.

Cyber Security Today, Week in Review for week ending Friday, March 22, 2024

Welcome to Cyber Security Today. This is the Week in Review for the week ending Friday, March 22nd, 2024. I’m Howard Solomon, contributing reporter on cybersecurity for ITWorldCanada.com and TechNewsday.com in the U.S.



 

In a few minutes Terry Cutler of Montreal’s Cyology Labs will be here to talk about recent news. That includes lessons learned from the ransomware attack on the British Library last year, the latest crooks in court, app developers leaving their Google Firebase instances unprotected, and advice for corporate leaders on managing their expectations of cybersecurity teams.

Before we get to the discussion here’s a quick roundup of other news that happened in the last seven days:

Crooks have been quick to exploit a recently-discovered vulnerability in the on-premise version of JetBrains’ TeamCity continuous integration development server. Trend Micro says servers that haven’t been patched are being hit with ransomware, backdoors and cryptomining malware.

Ivanti is urging administrators using its Standalone Sentry gateway to install a security patch. This is to close a remote code execution vulnerability. It’s rated 9.8 on the Common Vulnerably Scoring System.

A February ransomware attack that hit Change Healthcare, a company that processes healthcare transactions for institutions across the U.S., continues to impact healthcare providers across the company. According to SCMagazine.com, facilities say they can’t pay medical suppliers or employees, and patients have to pay out of their savings for medications. Washington is trying to help. The Health and Human Services Secretary told Congress this week that the department is issuing US$2.5 billion in advance Medicare and Medicaid payments to institutions.

Developers and IT administrators using hardware and applications that run on the Zephyr OS are reminded to update the operating system as soon as possible. This comes after researchers at Synopsys discovered serious vulnerabilities. Fixes were released in January. Word was publicly released this month.

German researchers have discovered a new type of denial of service attack that could affect 300,000 network devices. It takes advantage of vulnerabilities in communications protocols such as DNS, NTP, TFTP and some legacy protocols. Called a loop attack, it can be blunted by applying the latest security patches or mitigations such as firewalls to network equipment from Cisco Systems, Honeywell, Broadcom, Microsoft, MikroTik and more.

Mintlify, which offers a cloud service that helps developers generate code documentation on their computers or in GitHub, says a hacker has accessed 91 access tokens of customers who use the service to analyze GitHub. These were tokens stored in Mintlify databases. Those tokens have been revoked.

As I said earlier, Terry and I will talk about the dangers of misconfiguring Google Firebase. This week researchers at Tenable released a report on how they found a vulnerability in Amazon Web Services that could have been exploited with the help of a misconfiguration to take over a web management panel. AWS has fixed the problem, but it’s also a warning to other cloud providers to put in a guardrail to their domain architecture to prevent similar risks.

Finally, GitHub’s promised code scanning autofix tool is now in public beta. Developers can use the tool to identify many vulnerabilities in Java, JavaScript, Typescript and Python and suggest fixes. While it’s in beta only those with an enterprise GitHub account and use GitHub Advanced Security can access the tool.

(The following is an edited transcript of the first of the four news items Terry Cutler and I discussed. To hear the full conversation play the podcast)

Howard: I want to start with a report on lessons learned by the British Library from the ransomware attack by the Rhysida gang last October. For those who don’t know, the British Library is the national library that houses 170 million pieces of the country’s most valuable books, ancient documents, maps, sound recordings and more. It’s open to the public and researchers. Five months later it still hasn’t completely recovered from the attack. But to make sure the public understands what it has been doing for several months — and to help pass on lessons to cybersecurity and IT pros — the Library released an incident analysis.

Much of the server infrastructure was either encrypted or destroyed, with some 600GB of data copied. That was later dumped on the dark web after the Library refused to pay for decryption keys. To recover the Library has to completely overhaul its IT infrastructure, in part because some major software legacy systems aren’t supported any more by their vendors or won’t function under the new secure infrastructure.

What did you learn when you read the report?

Terry Cutler: A couple of things. So every time we come in for an incident response after a company got hacked there’s usually three things that occurred: One, no one [in IT] is watching the alerts. They’re all getting alert fatigue. We see this all the time, even when we’re doing adversarial testing we come in, do a test and nobody sees the [incident] alerts. When they do check in their emails or in their event log manager, they see that the alert was there, but nobody was watching it. Number two, they’re watching the alerts, but they aren’t skilled enough to understand that there’s an incident occurring. Or three, they’re relying on log managers to monitor the threats and these logs are coming in delayed.That usually happens a lot. That’s why we really push for full [ntework] packet capture whenever we’re doing incident response.

The other thing you need to understand is it’s very important to baseline the network [activity]. Is it normal that people are port scanning all the time? How much data is being traversed through things like external backups? You need to understand, have a baseline of what’s going on inside the network. You also need to have proper incident response protocols up to date. We see a lot of cases where there’s a short version of an incident response plan because the company outsources their IT. The plan would say, ‘Call this person.’ But then when you talk that person they have no idea how to prepare for it. They have to call another person.

The other problem too is that a lot of times they [IT] have too many tools that are trying to piece together what just happened. They’re using one vendor for one software, one vendor for servers, another vendor for EDR on the endpoints, another vendor for network monitoring. These tools aren’t necessarily made to work together. So they need to have proper technology in place that can look at all this holistically.

In a lot of cases when we do either a penetration test or adversarial test to see if the third party is actually monitoring their network, the organization isn’t being told port scanning is occurring, reconnaissance is occurring.

Howard: As you said earlier, the best evidence is that the hackers got in through a Terminal Services server that was set up to allow IT contractors to access the library network for maintenance. Those people didn’t have to log in with multifactor authentication. The interesting thing is permanent staff needed multifactor authentication to log into their email. However, the IT contractors didn’t have to use MFA. The library knew that was risky, but they thought other [login] mitigations would suffice. Apparently, they didn’t. So a lesson here, it seems to me, is multifactor authentication for everyone just can’t be put off.

Terry: It needs to be on for everybody. It doesn’t matter if you’re the janitor or the CEO. Everybody needs to have it on. And you want to have like a layered approach, right? So even though if your MFA fails, there should be other technologies in place that will help detect the problem. Just before jumping on this call I ran a dark web scan against the library’s domain and found over a thousand [British Library] leaked passwords [up for sale]. That means that the cyber criminals could log into these accounts without even getting additional security prompting for them [unless MFA was enabled] …So MFA really is important. And if you’re not sure if your organization has it on or off or who’s missing it, get an audit done. Find out who has a password set to never expire, who has never logged in before, because that happens all the time where a contractor or an employee gets hired, but then maybe quits almost immediately and the account never gets shut down. So a [password] audit is required here.

Howard: The timeline of the response of this attack is really interesting. At 7:35 in the morning, there was a realization that there was something wrong. Two hours later, the crisis management plan was evoked and that led to the library’s Gold Crisis Response Team being notified. By 10 o ‘clock, a WhatsApp video call was arranged with senior people. They were using WhatsApp because they couldn’t rely on email [after a successful breach of security controls]. This is a lesson on how a well-prepared organization planned [to respond to] a cyber attack, which is a lesson a lot of companies should learn. But what do you do if you’re a small company? You’re not going to set up a gold crisis team. You’re going to have fewer resources. So how does a small organization have an incident response plan and prepare to set up people to respond to an attack?

Terry: They had such a really great incident response plan set up — but yet they didn’t put on 2FA for everybody. That’s one of the basics. It’s step one. [But] you’re on step eight and you didn’t do step one. So listen up, small business owners: You’ve got to have even a simple incident response plan with the basics, like if an incident is detected who’s in charge of the recovery process? Who’s in charge of PR? And you also have to be doing [daily] the cybersecurity basics. Do you have proper patch management? Are you doing proper backups? Are you doing your assessments? Is IT properly equipped to rebuild the network in case there’s an incident?

Here’s a perfect example. I had a meeting recently with a customer who has pretty much a one-man IT operation inside the organization. When we asked them for his incident management plans, he says, ‘I just call this guy.’ To confirm, we called that other person, who’s the outsourced IT department, and they’re completely unprepared …

Howard: I noticed the report said that “previously approved investment updates are now being implemented.” That’s like closing the barn door after the horses escaped. You know, to me, the lesson is don’t put off getting rid of legacy equipment. Do it fast, do it now.

Terry: It’s the ‘It’ll never happen to us’ approach. So you need to really perform regular [security] assessments and [security] updates all the time … A lot of folks are still carrying Windows XP and they can’t get rid of it because it’s required to handle the door security, for example. So if they wanna upgrade that system, which has an embedded Windows XP, they have to change the whole security infrastructure. Sometimes they just don’t have the budget to do this. So they’re stuck with it. That’s why it’s very, very important that you start segmenting your network and baselining what you have. During an audit, you’ll be able to see what machines are aging, for example. So if you see machines that are seven years old you should already have a plan in place to replace or upgrade it. Because with software sometimes the vendors no longer exist and you’re stuck with it.

Howard: Another lesson I took from the report was that a lack of network segmentation is going to lead to more damage than necessary from a cyber attack.

Terry: I had that exact conversation with a person this week. Their entire network was flat. Everything was on one subnet. No, you need to segment this off because you need to contain the environment if something happens. So if an attacker breaks in, he’s not going to have access to the whole lot. You want to make sure that he’ll be limited by segment. So this way the damage is contained.

People say, ‘I got this brand new firewall.’ But hackers aren’t wasting time trying to hack your firewall. Why would they when all they have to do send an email to one of your employees [and if they fall for a scam] they [the attacker] becomes an insider.

The post Cyber Security Today, Week in Review for week ending Friday, March 22, 2024 first appeared on IT World Canada.

Cyber Security Today, March 22, 2024 – Mac CPUs are vulnerable to encrypted key theft, white hat hackers win a second Tesla, and more

Mac CPUs are vulnerable to encrypted key theft, white hat hackers win a second Tesla, and more.

Welcome to Cyber Security Today. It’s Friday, March 22nd, 2024. I’m Howard Solomon, contributing reporter on cybersecurity for ITWorldCanada.com and TechNewsday.com in the U.S.



 IT pros have heard about side channel attacks on Intel and AMD processors that can lead to computers and servers being hacked. News has emerged that Apple’s M-series of chips in Macintosh computers have a similar problem. According to seven American university researchers the vulnerability can allow an attacker to extract scrambled keys for encrypting data from a Mac’s memory. The attack is called GoFetch. Because the vulnerability lies inside a processor’s code it can’t be patched. The best thing Mac owners and administrators can do is make sure the applications they use have the latest security updates. Developers of cryptographic libraries can change a setting so data memory-dependent prefetching (DMP) is disabled. But that may only work on some CPUs. Apple was notified of the problem in December.

New information has been released on a malicious implant being spread by a Russian espionage group. Researchers at Cisco Systems have discovered the entire attack chain used by the gang, which it calls Turla. This information will be helpful to defenders. One tactic after gaining network access is to configure the victim’s anti-virus software to evade detection a backdoor. The gang sets up persistence through batch files that create what looks like a system device manager that hides the backdoor. Then it installs a tool dubbed Chisel to communicate back to a command and control server. The gang has already infected several IT systems in an unnamed European non-governmental organization.

KDE, which makes the Plasma front end for desktop Linux, has warned users to think twice about installing themes and widgets for the platform. That’s because a user lost data after the installation of a global theme. Themes are only supposed to change the look of Plasma. But as a result of the incident the KDE community is being asked to find defective apps in the KDE Store. This was first reported by Bleeping Computer.

Administrators with Fortinet’s FortiClientEMS enterprise management server in their environments are urged to install the latest security update. It closes an SQL injection vulnerability that is being exploited by threat actors. This vulnerability was reported last month. This week Fortinet added IPS signature information to the warning.

Finally, a team from the French cybersecurity company Synactiv won their second Tesla vehicle in a year at this week’s Pwn2Own hacking contest in Vancouver, British Columbia. They did it this time by hacking into the electronic control unit of a Tesla Model 3. For accomplishing the feat they also won US$200,000. Held in several cities throughout the year, the Pwn2Own contest sees individuals and teams challenged to find new vulnerabilities and hack into applications for cash. This year’s targets included Windows 11, Ubuntu Linux, the Chrome browser, Microsoft SharePoint, Adobe Reader and more. At the time this podcast was recorded just under US$900,000 in prizes had been awarded. The contest helps companies close unknown vulnerabilities in their applications.

That’s it for now. But later today the Week in Review podcast will be out. On this edition guest commentator Terry Cutler of Cyology Labs will discuss lessons learned from the ransomware attack on the British Library, and more.

Follow Cyber Security Today on Apple Podcasts, Google Podcasts or add us to your Flash Briefing on your smart speaker.

The post Cyber Security Today, March 22, 2024 – Mac CPUs are vulnerable to encrypted key theft, white hat hackers win a second Tesla, and more first appeared on IT World Canada.

Cyber Security Today, March 20, 2024 – Misconfigured Firebase instances are leaking passwords, a China-related threat actor is hacking governments and more

Misconfigured Firebase instances are leaking passwords, a China-related threat actor is hacking governments and more.

Welcome to Cyber Security Today. It’s Wednesday, March 20th. 2024. I’m Howard Solomon, contributing reporter on cybersecurity for ITWorldCanada.com and TechNewsday.com in the U.S.



 Misconfigured web services on 900 sites that use Google’s Firebase web application development platform are leaking valuable data including plaintext passwords. That’s according to three anonymous programmers. All I can tell you is one of them says they live in New Zealand. In a posting the trio said their work follows up on the discovery in January that an artificial intelligence hiring system used by many large companies called Chattr.ai had a Firebase vulnerability. Scanning the internet for misconfigured Firebase installations they found 900 vulnerable websites that allowed them to download 84 million usernames, 106 million email addresses, 20 million passwords — some of which were in plaintext — and more. Vulnerable firms include a learning management website for teachers and students, which exposed records of 27 million users. The researchers sent warning emails to the 900 websites. Of those, only 24 per cent fixed the misconfiguration by the time their blog was published.

A China-related threat actor is using unpatched vulnerabilities in OpenFire collaboration servers and Oracle Web Applications Desktop Integrator to attack government departments and companies around the world. That’s according to researchers at Trend Micro. This group, which the researchers call Earth Lusca, has been installing previously unseen backdoors through spear phishing emails in a new campaign. Once a government IT infrastructure is compromised, the attacker uses its position to host malicious payloads and send phishing emails to other government-related targets. That would take advantage of the trust message recipients would give to a government sender. The backdoors that get installed help the attackers steal credentials and data. The gang also tries to brute force Exchange servers through a list of common passwords. Trend Micro believes this latest campaign by the gang has hit 70 victim organizations in 23 countries including the U.K., Mexico, India and Brazil. Among the recommended defences: IT departments need to make sure software is updated with the latest security patches.

Researchers at Palo Alto Networks and Ukraine’s Cyber Protection Centre have released an analysis of the most recent use of a piece backdoor malware. It’s known by security researchers as Smoke Loader, Dofoil or Sharik. The reason for releasing the report is the discovery that this backdoor is being increasingly used by threat actors against government departments and financial institutions in Ukraine. However, Smoke Loader has been around since 2011 to break into Windows systems around the world. Threat actors often try to slip it into IT systems through infected emails, so security leaders need to — again — remind employees to be cautious when opening email attachments or clicking on links from unknown senders. They also need to be reminded to only download material from approved websites.

Does your firm have an operational technology network? We’re talking about networked industrial control systems and supervisory control and data acquisition systems (SCADA) that run factories, pipeline sensors and municipal traffic lights. If so a just-released report on OT cyber security by the U.K. National Cyber Security Centre may be worth reading. Among other things it has advice on making a risk-based decision to migrate a SCADA system to the cloud. You can do a full migration, a hybrid move or use the cloud just for standby or recovery. But what’s vital is making an informed decision. Here’s a link to the report.

Management frustration at a breach of security controls is only going to make it harder for an IT department to recover fast from an attack. That’s the advice Gartner analysts gave an audience this week at the advisory firm’s Security and Risk Management Summit in Australia. According to The Register, the speakers argued management has to remember that no amount of effort can stop security compromises. The quality of an IT and security team’s effectiveness is how fast they responds to an incident, the speakers argued. And they do that by having recovery plans. Does your organization have plans for recovering from different types of cyber attacks?

Finally, Fortra is publicly acknowledging that a critical vulnerability in its FileCatalyst file transfer software was reported and patched last August. The disclosure is being made now because the vulnerability has been given a number under the Common Vulnerability and Exposures system. This is just the latest in a series of vulnerabilities found in file transfer utilities such as MOVEit, Accellion, and Fortra’s GoAnywhere MFT.

Follow Cyber Security Today on Apple Podcasts, Google Podcasts or add us to your Flash Briefing on your smart speaker.

If you also want to start your day with a podcast on broader technology news IT World Canada has a daily news roundup called Hashtag Trending.

The post Cyber Security Today, March 20, 2024 – Misconfigured Firebase instances are leaking passwords, a China-related threat actor is hacking governments and more first appeared on IT World Canada.

Post Title

Gartner unveils their cybersecurity predictions with some good news and some bad news, more Apple AI rumours, Oracle tries a no-hype approach to AI, the US government may lose the ability to combat disinformation on social media and Microsoft aims to power through initial lukewarm responses to its AI integration.

These and more top tech stories on the “rumours and predictions” edition of Hashtag Trending

I’m your host Jim Love, CIO of IT World Canada and Tech News Day in the US.

Gartner Inc. unveiled their top eight Cyber Security Predictions for 2024 at their Security and Risk Management Summit in Sydney, Australia yesterday. For those not familiar with Gartner, they are the leading technology analyst firm, and their predictions aren’t always accurate, but they do reflect a lot of consultation with industries and consideration by some of the best minds in the industry.

There was some good news – and some bad news in their predictions.

One of their top predictions was that “by 2028 the adoption of Gen AI will collapse the skills gap, removing the need for specialized education form 50% of entry-level cybersecurity positions.

In another prediction they talk about 30% of cybersecurity functions will be in the hands of non-cyber experts and “owned by applications owners.”

Deepti Gopal, Director Analyst at Gartner said, “As we start moving beyond what’s possible with GenAI, solid opportunities are emerging to help solve a number of perennial issues plaguing cybersecurity, particularly the skills shortage and unsecure human behaviour. Any Chief Information Security Officer looking to build an effective and sustainable cybersecurity program must make this a priority.”

Another prediction stated that by 2026, enterprises combining GenAI with an integrated architecture in security behaviour and culture programs would have 40% fewer employee-driven cybersecurity instances.

Those are the benefits of AI.  Now the downside:

Clearly, they expect the trend to holding cyber security leaders legally accountable will continue as they recommend that organizations explore covering these leaders with insurance.

By 2028 they predict that enterprise spending on battling misinformation will surpass 500 billion dollars, and cannibalize 50% of marketing and cybersecurity budgets.

There’s a link to the full list of predictions with the show notes.

And Oracle is taking a “no-hype” approach to the Generative AI race and it might be paying off.

At the Oracle CloudWorld 2024 event, Doug Kehring, Executive Vice President of Oracle’s corporate operations, took centerstage to outline the company’s strategy. He emphasized Oracle’s unwavering focus on enterprise solutions, taking a few jabs at competitors along the way.

“Our sole focus is enterprise technology,” Kehring stated. “We don’t venture into gaming systems, consumer advertising, or even writing term papers for students.”

Amidst the whirlwind of hype surrounding generative AI over the past 15 months, Oracle seems to be setting its sights on delivering practical AI functionality.

Oracle says they will be supporting over fifty generative AI user cases withing Oracle Fusion cloud application suite and focusing these on “existing business workflows” in finance, supply chain, HR, sales, marketing and customer services.

Less well known than their competition and certainly smaller in terms of client base, still Oracle appears to be doing something right with this no hype approach. The companies cloud revenue jumped by 25% and they have surpassed their profit estimates.

Sources include: ITPro

More Mac rumours abound. This time there’s a lot of buzz saying that Apple may be working with Google to bring Google’s new Gemini AI to iOS devices.

Apple has long been rumoured to have invested billions in developing its own generative AI framework. It’s been acquiring companies quietly. After it abandoned its self driving electric car, most of those resources were thought to be going to its AI development.

But there are persistent rumours that Apple’s generative AI still remains inferior to Google’s offerings that are now moving into its Pixel series.

One of the key elements has to be the finding enough RAM and processing power to run AI on a phone. But clearly Google has made progress to make AI functionality work on their Pixel series phones.

It’s not the first time that these two competitors have found common ground. Google pays Apple at least 18 billion a year to maintain its position as the default search engine on iDevices.

And with Microsoft linking up with OpenAI to challenge Google’s AI dominance, maybe the old saying is true, the enemy of my enemy is my friend.  Or at least a good source of revenue.

Sources include: The Register

National Public Radio in the US is reporting the Supreme Court in the US is hearing arguments on Monday that could restrict the government’s ability to combat false, misleading or dangerous information online.

While the right to free speech is guaranteed in constitution of every Western democracy, the US takes it to a whole new level.

In September of last year, the 5th U.S. Circuit Court of Appeals, widely regarded as the most conservative federal appeals court in the United States, handed down a sweeping ruling that prohibited certain key government officials from engaging in contacts with social media companies. The order specifically targeted officials from the White House, the Centers for Disease Control and Prevention, the Office of the Surgeon General, the FBI, and a prominent cybersecurity agency, restricting their ability to interact with these platforms.

So with the idea that the US government could be restricted from even contacting a social media company and pointing out errors, it may be believable that they could be further restricted.

Given that the internet knows no borders, and how little ability that some countries like Canada have in restricting US social media companies, governments could be prevented from managing disinformation – even harmful disinformation. And while there are many challenges to regulating the safety of AI, disinformation is one of the most immediate clear and present dangers.

Sources include: NPR

And finally,  the jury is still out on the paid version of Copilot for Office 365, with many companies wondering if the extra 30 bucks per employee is really worth it.

Copilot has been generally available for enterprise since November 1 and Microsoft has been offering companies month-long trials hoping to they will convert to paying customers.

How is it going? Reportedly, Microsoft is telling investors to “temper their expectations.”

Part of the issue has been a “meh” type response from testers according to a Wall Street Journal report.  Even Microsoft couldn’t disagree with one executive saying that Copilot in various applications is at “different stages of development.”

From what we’ve seen as well, we agree with his assessment. Copilot is most effective in terms of information retrieval but not as well integrated into programs like Excel. From what we’ve seen first-hand, it’s promising but still has a long way to go.

One CIO told the paper, “I wouldn’t say we’re ready to spend $30 per user for every user in the company.Despite this, Microsoft seems to be doubling down on its AI in everything strategy.

There are reports from tech insiders indicate that upcoming builds of Windows 11 will integrate Copilot right into the right-click context menu when you select a file.

When a file is right-clicked, options will appear to “Send to Copilot” or “Summarize” using the AI capabilities. Sending the file to Copilot will allow you to ask questions about it or maybe even issue commands within the Copilot interface.

If you’re old enough to remember the early days of Windows, it’s not the first time that Microsoft has come to market with a product set that was not quite ready for prime time, but still triumphed over better products. So don’t count them out yet.

Sources include: The Register

And that’s our show for today.

Hashtag Trending goes to air 5 days a week with a special weekend interview show we call “the Weekend Edition.”

You can get us anywhere you get audio podcasts and there is a copy of the show notes at itworldcanada.com/podcasts

Once more I want to thank all of you who have responded to our informal census. The information is very helpful, and I do want to assure you all that we will absolutely respect your privacy.

I’m your host, Jim Love. Have a Terrific Tuesday.

 

 

 

The post first appeared on IT World Canada.

Cyber Security Today, March 18, 2024 – Fix this Python vulnerability, patch these industrial control system products, the latest data breaches and more

Fix this Python vulnerability, patch these industrial control system products, the latest data breaches and more.

Welcome to Cyber Security Today. It’s Monday, March 18th, 2024. I’m Howard Solomon, contributing reporter on cybersecurity for ITWorldCanada.com and TechNewsday.com in the U.S.



 

I’m back after some time away. A big thanks to Jim Love for doing recent podcasts.

Developers and IT administrators overseeing servers running the aiohttp open-source Python framework should make sure they’re using the latest version. This is because the ShadowSyndicate ransomware gang is looking for vulnerable versions of this utility as an entryway for network compromise. According to researchers at Cyble, a patch was released at the end of January to close this hole. However, the researchers say that since February 29th threat actors, including ShadowSyndicate, are scanning the internet for vulnerable servers. If you haven’t looked for and patched this framework by now you’re asking for trouble.

The U.S. Cybersecurity and Infrastructure Security Agency has released advisories for a bunch of network-connected industrial control systems. These include 11 products from Siemens, two for Mitsubishi Electric’s MELSEC line, one for Delta Electronics and one for Softing.

You may soon be able to buy intent-connected home surveillance cameras, refrigerators, fitness trackers, baby monitors and other consumer products in the United States with a cybersecurity safety information sticker. That’s because the U.S. Federal Communications Commission has voted to create a cybersecurity labeling program for wireless consumer products. It will be voluntary for manufacturers to meet the yet-to-be-created standard to earn a U.S. Cyber Trust Mark. But it could help people make informed purchasing decisions — like, ‘If this product doesn’t have the label, why should I buy it?’

There’s good news and bad news in Sophos’ latest annual Threat Report. The good news is that technology for blocking the execution of malicious macros in documents is working. The bad news is that threat actors are responding by increasingly distributing malware through malvertising, like manipulating search engine results to ensure high placement of poisoned websites. Employees need to be warned about this tactic. A link to the report is here. 

The FBI is investigating a ransomware attack that hit at least three of 14 district attorney’s offices in New Mexico last week. According to Source New Mexico, impacted servers belonged to the Administrative Office of the District Attorneys, which supports the DAs. One server affected is used by prosecutors and public defenders to share court records. Those records would include names of people accused of crimes, evidence and prosecutors’ case notes. The attack started last Wednesday. It was hoped things would have been back to normal on Friday.

Here’s the latest data breach news:

Personal data on as many as 43 million residents of France may have been stolen in a recent attack on France Travail, the nation’s job search site. A database with information of people registered over the past 20 years including names, dates of birth, the equivalent of social security numbers and email addresses was copied.

Missouri’s Saint Louis University is notifying over 93,000 students, faculty and employees that their email accounts were hacked over a seven-month period.

Nations Direct Mortgage, an American mortgage lender, is notifying over 83,000 people of a data breach. Information copied included names, addresses, Social Security numbers and individuals’ loan numbers.

Someone is pedaling a huge database of three-year-old information that claims to be from American communications provider AT&T. According to Security Affairs, this database was stolen in 2021 by a group called ShinyHunters. At the time AT&T denied the data had been stolen from its system, leading to speculation that it was copied from a third-party data processing firm.

The International Monetary Fund has acknowledged that 11 email accounts of staff were compromised earlier this year. It released no other details. The IMF provides short and medium-term loans to troubled nations around the world.

Over 18,000 people are being notified by a Texas oil and gas exploration company that personal data it holds about them was stolen in January. In a filing with the Maine attorney general’s office, Eland Energy said a hacker got into its virtual server and stole people’s names, dates of birth, Social Security numbers and addresses.

Over 11,000 people who bought wine and other items on the website of the Biltmore estate, a North Carolina tourist attraction, are being notified their credit or debit card information was stolen last month. The company says data-stealing code was inserted into the website application it uses to process online orders. This application is hosted by a third-party vendor.

Finally, people with older wireless devices that no longer get security updates should always think of moving up to newer hardware for security reasons. This is more important than ever because of a recently-discovered family of 5G vulnerabilities called 5Ghoul. They can knock the devices off the air or force downgrading to the slower 4G cellular service. As an article from the SANS Internet Storm Centre points out this can affect anything running 5G — laptops, industrial sensors, internet-connected TV cameras, and smartphones and tablets. Patches for many devices have been released, but if a 5G wireless modem on your network or your mobile device can’t be updated any more you could be hit by this malware.

Follow Cyber Security Today on Apple Podcasts, Google Podcasts or add us to your Flash Briefing on your smart speaker.

The post Cyber Security Today, March 18, 2024 – Fix this Python vulnerability, patch these industrial control system products, the latest data breaches and more first appeared on IT World Canada.

Apple buys Canadian AI startup: Hashtag Trending for Monday March 18, 2024

Apple buys a Canadian artificial intelligence startup, a new chip could promises to decrease costs and reduce the environmental footprint of AI, Citrix angers its partners and clients as rumours of new pricing and product bundling hit the street and are tech layoffs the “new normal?”

All this and more on the “how to lose friends and influence people” edition of Hashtag Trending. I’m your host, Jim Love, CIO of IT World Canada and TechNewsDay in the US.

Apple has acquired DarwinAI, a Canadian artificial intelligence startup focused on using AI for quality inspections in manufacturing. The acquisition highlights Apple’s growing investments in generative AI technology, an area the iPhone maker has said will be a major focus area.

While Apple has been tight-lipped about its specific plans, CEO Tim Cook recently teased that the company will share more details on its generative AI initiatives later this year. Cook described generative AI as a “huge opportunity” for Apple.

The DarwinAI deal follows Apple researchers publishing an academic paper just yesterday exploring multimodal large language models – focusing on computer vision and pattern recognition – Apples clearly has some deep research going on.

Though the financial terms were not disclosed, Apple confirmed the acquisition with its standard statement about buying smaller tech firms from time to time. But the move signals Apple is ramping up its AI capabilities, likely to integrate generative AI across its hardware, software and services offerings.

As one of the world’s most valuable companies, Apple’s moves in the generative AI space are worth watching.

Sources include Axios and Cornell University

While tech giants like Nvidia and Intel dominate the headlines in artificial intelligence hardware, a startup called Groq  is quietly positioning itself as a powerful new player in this chip design and manufacturing for AI.

This is not Elon Musk’s AI chat bot, which is spelled G R O K.  This is G R O Q – the names are similar, but this is a totally different company.

 

Based in Mountain View, California, Groq has developed specialized AI chips it calls “language processing units” or LPUs. The company, backed by investors like Tiger Global and Lee Fixel’s Addition, claims these LPU chips can run AI models 10 times faster than conventional hardware at just one-tenth the cost.

As the recent explosion in generative AI drives skyrocketing demand for computing power, Groq’s founder and CEO Jonathan Ross says his startup’s technology could reshape the economics of the industry. He estimates that while OpenAI has projected needing $7 trillion for a new chip business, Groq could achieve similar capabilities for just $700 billion thanks to its more efficient chips.

With about 4,500 LPU chips already deployed and plans for 1.5 million by the end of next year, Groq is betting big that its technology will be a key enabler as AI goes mainstream across industries. The company is not only selling cloud access to developers, but also pitching its hardware directly to enterprises running their own data centers.

So while Nvidia’s annual conference next week will likely capture outsized attention, this Silicon Valley startup could emerge as an unexpected disruption in AI’s critical chips race.

As concerns grow over the technology’s immense capital requirements and carbon footprint, Groq represents a tantalizing prospect – bringing the same cutting-edge AI capabilities at a fraction of the cost and environmental impact.

 

There are emerging reports that Citrix has made sweeping changes to its partner program that have left many in the channel stunned and outraged.

According to sources briefed on the new arrangements, Citrix plans to double the price for monthly partner licenses starting September 1st, unless partners commit to paying for an entire year upfront. The impacted products will be bundled into a new “Citrix Universal for CSP” offering.

Citrix has reportedly justified the price hike by claiming a flexible monthly model introduces too much cost uncertainty. But partners who were present at the unveiling described the atmosphere as “stunned silence followed by anger and disbelief” over the changes.

Not only will monthly licenses essentially double in price, but Citrix is also alleged to be slashing rebates paid to its channel partners. This one-two punch could force many to raise prices for customers or shift focus to rival services like Microsoft’s Windows 365 Cloud PCs.

And if those two weren’t enough, Citrix is  also rumoured to be unveiling a new “Platform License” that many see as adopting the same controversial bundling strategy employed by semiconductor giant Broadcom after their takeover of VMWare

The Platform License is reported to be an invitation-only offering that bundles all of Citrix’s existing products like its virtual desktop infrastructure, application delivery controllers, analytics tools and more.

 

This mirrors the recent moves by Broadcom after acquiring VMware, where it stopped selling certain VMware offerings individually in order to drive adoption of more comprehensive bundles.

The reported moves come as Citrix’s parent Cloud Software Group is facing intensified competition, including VMware’s desktop virtualization products potentially being spun out under new Broadcom ownership.

With over 2 million active Citrix subscribers, the pricing shakeup could trigger a significant disruption across the virtual desktop infrastructure space.

Citrix has so far declined to confirm or deny these changes, leaving partners anxiously awaiting official word on the controversial new program.

One thing is for certain. If you are dependent on partner support and Citrix is a critical part of your technology stack, it would be worth having a discussion with your support partner and also looking at your alternatives – not as a panic decision, but to take the time to educate yourself in advance of potential cost and support impacts.

Sources include:  The Register (Story 1 and Story 2)

The tech industry is facing a harsh new reality – mass layoffs may becoming the norm, not the exception.

According to an article in TechSpot in this first quarter of 2024, an astonishing 209 tech companies have already cut over 50,000 employees, according to data tracked by Layoffs.fyi. This comes on the heels of nearly 270,000 tech workers losing their jobs in 2023.

 

And it’s not just startups feeling the squeeze. Industry giants like Alphabet, Amazon, Microsoft and Meta have all implemented major workforce reductions in recent months. If these numbers are correct, this is second only to the dot-com bust of 2001.

While companies initially blamed over-hiring during the pandemic and inflation, that story is wearing thin this year as many of the big tech companies sit on significant cash reserves. Experts suggest the real reason for the layoffs is that it props up stock prices.

Not only are jobs insecure, but generous tech salaries and benefits appear to be stagnating after years of increases. According to compensation data, an entry-level AI role still commands six figures, but raises are no longer a given.

For tech workers accustomed to being heavily recruited, the landscape has shifted drastically. Some are leaving the industry entirely or settling for less lucrative positions with fewer perks.

With companies continuing to prioritize cost-cutting to please Wall Street, the new normal of cyclical layoffs looks poised to persist across Silicon Valley and beyond. As one professor warns – tech employees and investors have largely accepted this harsh reality, so the job cuts are likely here to stay for some time.

We did a story on the weekend edition where we talked about how some cybersecurity pros are now moonlighting on the dark web to find new employment or to make up for what they feel are inadequate wages.

I want to stress that I’ve had to let people go not so our shareholders could make more, but to try to ensure the survival of the company. It’s been agonizing and I think, no matter how we tried to handle it, it angered employees – even when I explained I hadn’t taken a salary in a year.

Imagine the resentment that is building in companies that have huge cash reserves, but are letting people go for no other reason that a few percentage points on their stock price in the short run. This is not a recipe for employee engagement and, while we don’t condone it in any circumstance, it’s also causing employees to take actions which might ultimately damage the tech industry.

We are smart people. There has to be a better way to handle this.

 

That’s our show for today.

Thank you to all of the people who got back to me in my attempt to do a census of our listeners. I have to say that Western Canada rocks! We got twice the response from the West and I answered every email that had a question or a comment personally. If I somehow missed you, my apologies, but you folks were great!

And if listeners in Toronto and Montreal and the east coast would like to redeem yourselves, here’s how to do it. Simply send me an email with hashtag yes in the subject line, include your position and the city you are in. The results are confidential, will never be shared except as a summary to report to potential sponsors so we can get the funding we need to continue the podcast.

Send it to jlove@itwc.ca

Subject line hashtag yes.  Job title. City.

jlove@itwc.ca

That’s all it takes to help ensure that we can keep bringing you this podcast.

 

 

Hashtag Trending goes to air five days a week with a daily news show and on the weekends we have an interview show we creatively named the Weekend Edition.

We love your comments you can also send those to jlove@itwc.ca

Thanks for listening and have a Marvelous Monday.

 

 

 

 

 

 

 

 

The post Apple buys Canadian AI startup: Hashtag Trending for Monday March 18, 2024 first appeared on IT World Canada.