Page 12 of 55

FedDev Ontario invests $17 million in 12 companies to advance quantum computing

Today, the Federal Economic Development Agency for Southern Ontario (FedDev Ontario) announced a total repayable investment of C$17.2 million to help 12 local companies commercialize their quantum products for the domestic and international markets and support 150 jobs.

These 12 companies include AI Incorporated, CogniFrame, Crypto4A, Foqus Technologies, Foreqast Technologies, GoodLabs Studio, High Q Technologies, ISARA, ProteinQure, Qoherent, Quantropi, and Xanadu.

Bardish Chagger, member of parliament for Waterloo, made the announcement at High Q, a women-led life sciences company that uses quantum-enabled systems to solve complex problems in protein dynamics, including shortening the timeline to discover new drugs. That company received the biggest chunk of the investment, along with Xanadu and Crypto4A.

Other research projects undertaken by the 12 companies span areas such as security, medicine, radio signal sensing, encryption, logistics, finance and more.

“Southern Ontario is well-positioned for quantum breakthroughs because we are home to world-leading research centres and high-potential quantum companies, like the ones we are celebrating today,” said Minister of FedDev Ontario Filomena Tassi. “Businesses in this sector are creating incredible technologies and our government is providing support so they can bring them to market faster, advancing Canada’s role as a world leader in quantum technologies.”

The investment is delivered through FedDev Ontario’s Regional Quantum Initiative, which committed $23 million over six years (2022-27) to help companies advance and commercialize their quantum products.

That initiative came after the government of Canada announced the National Quantum Strategy last year, backed by an investment of $360 million committed in Budget 2021 to help quantum companies and talent grow.

Industry minister François-Philippe Champagne said that Canada was ambitious and led the way with the National Quantum Strategy and is now backing it with important investments to amplify Canada’s strength in quantum science.

The post FedDev Ontario invests $17 million in 12 companies to advance quantum computing first appeared on IT World Canada.

Leaked documents may show the inside of China’s hacking strategy

A leak of data from a Shanghai-based cybersecurity company has researchers speculating that it has exposed the workings of a Chinese government-sponsored hacking group.

The company is called i-Soon — also known as Anxun — which, according to researchers at SentinelOne, does contract work for many Chinese government departments, including the Ministry of Public Security, Ministry of State Security, and People’s Liberation Army.

Last weekend, a cache of more than 500 company documents was published on GitHub. “The leak provides some of the most concrete details seen publicly to date, revealing the maturing nature of China’s cyber espionage ecosystem,” says SentinelOne. “It shows explicitly how government targeting requirements drive a competitive marketplace of independent contractor hackers-for-hire.”

Although the source is not entirely clear, researchers at Malwarebytes say it’s likely a disgruntled staff member of the group leaked the information on purpose.

I-Soon employees complain about low pay and gamble over mahjong in the office, says SentinelOne. But the meat of the documents show the company appears to be responsible for the compromise of at least 14 governments, pro-democracy organizations in Hong Kong, universities, and NATO. The leaked documents align with previous threat intel on several named threat groups, SentinelOne says.

“Victim data and targeting lists, as well as names of the clients who requested them, show a company who competes for low-value hacking contracts from many government agencies,” says SentinelOne. “The finding indicates that historical targeting information from Advanced Persistent Threats thought to be PRC [People’s Republic of China] contractors does not provide strong guidance on future targets.”

Malwarebytes says the documents show i-Soon’s tools include

a Twitter (now X) stealer: Features include obtaining the user’s Twitter email and phone number, real-time monitoring, reading personal messages, and publishing tweets on the user’s behalf;
Custom Remote Access Trojans (RATs) for Windows x64/x86: Features include process/service/registry management, remote shell, keylogging, file access logging, obtaining system information, disconnecting remotely, and uninstallation;
the iOS version of the RAT also claims to authorize and support all iOS device versions without jailbreaking, with features ranging from hardware information, GPS data, contacts, media files, and real-time audio records as an extension. (Note: this part dates back to 2020);
the Android version can dump messages from all popular Chinese chatting apps QQ, WeChat, Telegram, and MoMo, and is capable of elevating the system app for persistence against internal recovery.
portable devices for attacking networks from the inside;
special equipment for operatives working abroad, to establish safe communication;
a user lookup database which lists user data, including phone number, name, and email, and can be correlated with social media accounts;
and a targeted automatic penetration testing scenario framework.

Many of the files are versions of marketing materials for advertising the company and its services to potential customers, says SentinelOne. In a bid to get work in Xinjiang – where China subjects millions of Ugyhurs to what the UN Human Rights Council has called genocide – the company bragged about past counterterrorism work, the report says. The company also listed other terrorism-related targets the company had hacked previously, as evidence of its ability to perform these tasks, including targeting counterterrorism centers in Pakistan and Afghanistan.

Technical documents showed potential buyers how the company’s products function to compromise and exploit targets. Included in the documentation were pictures of custom hardware snooping devices, including a tool meant to look like a powerbank for charging portable devices that passed data from the victim’s network back to the hackers. Other documentation diagrammed some of the inner workings of I-Soon’s offensive toolkit. While none were surprising or outlandish capabilities, they confirmed that the company’s main source of revenue is hacking for hire and offensive capabilities.

The selection of documents and chats leaked on GitHub seem meant to embarrass the company, says SentinelOne, but they also raise key questions for the cybersecurity community. One document lists targeted organizations and the fees i-Soon earned by hacking them. Collecting data from Vietnam’s Ministry of Economy paid out US$55,000;  i-Soon was paid less for data from other ministries. Another leaked messaging exchange shows an employee hacking into a university not on the targeting list. Their supervisor labeled that as an accident.

“The leaked documents offer the threat intelligence community a unique opportunity to re-evaluate past attribution efforts and gain a deeper understanding of the complex Chinese threat landscape,” says SentinelOne.

For defenders and business leaders, it adds, “the lesson is plain and uncomfortable. Your organization’s threat model likely includes underpaid technical experts making a fraction of the value they may pilfer from your organization. This should be a wakeup call and a call to action.”

The post Leaked documents may show the inside of China’s hacking strategy first appeared on IT World Canada.

Hashtag Trending Feb.22- ChatGPT generates gibberish responses; Japan tries to get back its chip manufacturing; New app to cut back on food waste

ChatGPT starts spewing gibberish. Critics complain about the environmental impact of AI and the secrecy of the major players, Japan aims to get back its chip manufacturing and a new app that saves money, cuts back on wasted food and reduces greenhouse gases.



 

These and more top tech stories on the “finally some good news” edition of Hashtag Trending

I’m your host Jim Love, CIO of IT World Canada and Tech News Day in the US.

ChatGPT has recently started producing a slew of gibberish responses, leaving users perplexed and concerned. 

Reports included a number of strange behaviours. There have been reports of ChatGPT speaking in Spanglish – a mix of Spanish and English. Another report noted that ChatGPT was “talking” like it was in the room with the user – which they reported as “creepy.” 

Other instances shared by users on Reddit include ChatGPT responding to a discussion about jazz albums with nonsensical shouts of “Happy listening!” and providing paragraphs of incoherence when asked simple questions like “What is a computer?”

The cause of this unusual behavior remains unclear, as is how widespread the behaviour is. OpenAI, the creators of ChatGPT, have acknowledged the issue and say that they are currently monitoring the situation. 

One suggestion has been that the “temperature” setting, which controls the creativity of responses, might be a factor, but that has not been confirmed.

It’s not the first-time users have complained about changes in ChatGPT’s behaviour. Late last year users were complaining that ChatGPT had gotten lazier – something we confirmed first hand. 

This new issue raises concerns about the unpredictability of AI responses, even in well-established models like ChatGPT. It underscores the importance of continuous monitoring and updating of AI systems. 

It also points out how these incidents can erode user trust in AI technologies particularly at a time when there are real debates emerging about how widespread our use of AI will be and how dependent we might become on its use.

Sources include: The Independent 

OpenAI’s CEO, Sam Altman, recently highlighted an impending energy crisis within the AI industry, noting that the next generation of AI systems will demand significantly more power than current models, potentially straining global energy resources.

This revelation brings to light the hidden environmental costs of AI development, including not just the staggering energy consumption but also the extensive use of fresh water needed to cool down the massive data centers that power these AI systems. For instance, the data center cluster in West Des Moines, Iowa, which supports OpenAI’s GPT-4, was reported to use about six per cent of the district’s water in July 2022, underscoring the substantial ecological footprint of advanced AI models.

Critics are saying there’s an urgent need for the AI industry to adopt more sustainable practices, such as developing energy-efficient models and utilizing renewable energy sources.

They also complain that environmental costs of AI are often closely guarded secrets. In response, they are lobbying for legislation, like the Artificial Intelligence Environmental Impacts Act introduced in the US, which aims to establish standards for assessing and reporting these impacts.

Supporters of these moves maintain that the industry’s move towards transparency and the adoption of greener practices could pave the way for a more sustainable future in AI development.

Sources include: Nature 

Japan is making a monumental $67 billion wager to reclaim its status as a global semiconductor powerhouse. This ambitious program is Japan’s attempt to catch up with global leaders in semiconductor production and mitigate vulnerabilities in its supply chain amid escalating US-China tensions.

There is some opposition. There is criticism about the environmental impact of large new manufacturing plants. Japan is moving quickly on this, and their time frames are incredibly ambitious versus much slower moves in the US. 

But this time, the US, once a previous opponent of chip manufacturing in Japan, is supportive, seeing Japan as a part of its move to protect supply chains disruptions that are feared as tensions between China and the west are rising on trade issues and the long-standing disputes over the independence of Taiwan.

Sources include: Yahoo Finance 

A couple of court rulings that may have some impact. 

Yesterday a federal appeals court overturned a $1 billion piracy verdict that a jury handed down against cable Internet service provider Cox Communications in 2019.

The size of the penalty made news and was chilling to ISPs and others who host and deliver copyrighted content.

 Judges rejected Sony’s claim that Cox profited directly from copyright infringement committed by users of Cox’s cable broadband network. Cox Communication is still not out of the woods, but they will get a new trial with a much more narrow focus on whether they had a blind eye to copyright infringement – a charge which should lead to a much lesser penalty. 

The European Court of Human rights has banned any laws that aim to weaken end-to-end encryption. This ruling is a major stumbling block for the EU Chat Control Bill critics claim would have weakened privacy and created back doors that could be exploited by governments and by threat actors.

Sources include:  Tuta.com 

And here’s some good news for a change…

Denmark-based app Too Good To Go has recently expanded its operations to Denver and Boulder, offering a unique solution that benefits consumers, businesses, and the environment – all at the same time. 

The app allows users to purchase surplus food from local restaurants at significantly discounted prices. This turns potential waste into delightful “Surprise Bags” of meals.

The “Surprise Bags,” are priced between $3.99 and $9.99, making it an affordable option for many, addressing food insecurity while offering deals up to two-thirds off the original price.

The app is incredibly popular and users are advised to turn on push notifications, as its offerings routinely sell out.

The app not only provides savings to consumers but the reduced waste and increased revenue benefits the businesses. As well, the reduction in greenhouse gases benefits the environment. 

Considering that by some reports, 100 billion pounds or 40 per cent of all food in the US goes unsold or uneaten while in Colorado as many as 1 in 3 people experience food insecurity, this app is a stunning example of how technology can truly improve our lives.

Sources include: Axios 

Hashtag Trending goes to air 5 days a week with a special weekend interview show we call “the Weekend Edition.”

You can get us anywhere you get audio podcasts and there is a copy of the show notes at itworldcanada.com/podcasts 

I’m your host, Jim Love. Have a thrilling Thursday.

The post Hashtag Trending Feb.22- ChatGPT generates gibberish responses; Japan tries to get back its chip manufacturing; New app to cut back on food waste first appeared on IT World Canada.

Hiring to continue in Canada despite challenges: Robert Half study

Over 50 per cent of Canadian technology managers plan to hire in the first half of 2024 despite persisting challenges to find skilled talent, a new study by hiring platform Robert Half reveals.

Respondents included executives, senior managers and workers from small (20-249 employees), medium (250-499 employees) and large (500+ employees) businesses in private, publicly listed, and public sector organizations across Canada.

Factors such as anticipated company growth, increased turnover, and lack of requisite skills among employees are the top factors influencing the decision to continue hiring in 2024. Many companies are also looking to capitalize on laid off talent, the report revealed.

While there’s an increased number of tech workers in the talent pool due to persisting tech layoffs, there will still be plenty of opportunities for them in 2024, affirmed Nathan Wawruck, director of permanent placement services in the tech practice at Robert Half.

Many technology leaders are also planning to hire more contract professionals in the first half of 2024, notably in areas like AI and machine learning, and cloud architecture, as well as software and applications development.

This could be related to the fact that managers are more strategic in their hiring than they were a few years ago and, importantly, because 70 per cent of companies will now be moving forward with projects that they put on hold in 2023.

However, the report emphasized the many hiring difficulties that are set to persist in 2024.

Nearly half of managers (48 per cent) said their team suffers from skill gaps, which degrade quality of work and can even leave projects at a standstill. 

“Our research shows that tech managers are facing the greatest challenges in finding skilled talent for AI and machine learning, security, privacy and compliance, and cloud architecture and operation—areas where they also say skills gaps are most evident in their companies,” explained Wawruck.

Recruiters are advised to act fast when they spot the gaps, the report noted, especially with 64 per cent of managers claiming that hiring now takes longer than it did a year ago, significantly setting back their companies as they lose skilled talent to competitors.

Wawruck added that companies need to ensure a streamlined interview process to keep the hiring process as smooth as possible, to avoid delays that risk them losing skilled candidates. Plus, their compensation and benefits packages should also be competitive and in line with industry expectations.

A higher salary (47 per cent) is the top priority for workers who plan to look for a new job, followed by advancement opportunities, and benefits and perks, as well as flexible work options, the report showed.

Candidates’ salary expectations being too high (54 per cent) is, in fact, the top reason that recruiters cited for losing skilled candidates. Others wanted more flexibility (50 per cent), accepted a counteroffer (42 per cent) or claimed that the company took too long (33 per cent) to make an offer.

Don’t wait to make compelling offers to good candidates, the report asserted.

The post Hiring to continue in Canada despite challenges: Robert Half study first appeared on IT World Canada.

OpenText sustainability report cites challenges IT departments face

A new report commissioned by OpenText, released yesterday, indicates that IT departments are playing a major role in achieving corporate sustainability objectives, but concludes a lack of innovative tools and expertise are primary roadblocks to allowing them to meet their goals.

The 2023 State of IT Sustainability Report, conducted by Dimensional Research, found that while 97 per cent of companies have adopted or plan to adopt sustainability initiatives, in terms of actual implementation, only 42 per cent of those polled have actually started “the journey” towards environmental responsibility.

“The sustainability movement is in the early days, with IT taking the lead in most cases,” said Muhi Majzoub, chief product officer at OpenText. “However, this report’s findings also show that companies are serious about making it a high operational priority.

“Sustainability is proving to be more than a popular social cause. There are solid business reasons pushing it: efficiency, cost savings, regulatory compliance. Because it is a ‘win-win’ scenario for all, sustainability is now a part of the decision-making process at most companies.”

According to a release issued by the company, implementing IT sustainability initiatives can bring several obvious benefits to enterprise organizations, whether it is in cost savings, resource efficiency, risk mitigation, or regulatory compliance.

However, the release noted, “there are other less obvious benefits, such as innovation in product design, process efficiency, or technology adoption, that ultimately could lead to new revenue streams or market opportunities, all brought through the pursuit of sustainability.

“Yet, for all the incredible business benefits of IT sustainability, it is not without its challenges.”

Findings, which are based on a recent survey of 328 executives from around the world, each of whom has sustainability responsibilities, revealed that only 51 per cent reported using software to help track their IT carbon footprint, with Europe outpacing North America in the adoption of tracking software.

The lack of expertise was the second biggest challenge, according to 46 per cent of respondents, underscoring the need for education and skills development in sustainable IT practices.

Survey results indicated that IT departments lead the pack in adopting green initiatives. IT has a higher adoption rate than other departments, followed by logistics, facilities, manufacturing, and warehousing.

“This trailblazing position may be inherent,” authors of the report note. “Unlike departments that rely on intricate physical systems, heavy machinery, or complex supply chains, IT has the flexibility to pivot – for example, to the cloud, to new vendors, to optimal resources, or to cloud cost control with FinOps.

“All these moves support green IT without the financial outlay required by other domains. At 19 per cent of companies, every department has a sustainability initiative. But 88 per cent of companies without company-wide participation plan to welcome new departments to their sustainability programs within the next year – so that 19 per cent will grow.”

Going green, they write, is “good for business and companies know it. The data suggests that business benefits – led by improved brand image, cost savings, and higher ESG (environmental, social and governance) scores – serve as a catalyst for IT’s sustainability efforts.

“To a lesser degree, but not by much, external factors such as regulatory and governmental influences play a key role in driving IT sustainability initiatives. Given that regulatory and governmental requirements are on the rise, we expect these factors to rank higher on reasons to embrace IT sustainability in the years to come.

“No longer just a theoretical topic in CIO magazines, environmental sustainability has become a front-and-centre initiative that organizations are planning for and acting on.”

The post OpenText sustainability report cites challenges IT departments face first appeared on IT World Canada.

Opposition MPs hammer head of PHAC over ArriveCAN app

Opposition MPs hammered the head of the Public Health Agency of Canada (PHAC) on Tuesday for its role in not tightly overseeing the $59 million spent on the ArriveCAN app, but failed to get answers to repeated demands asking who made decisions.

The Public Health Agency of Canada (PHAC) and the Canada Border Services Agency (CBSA) both worked on the requirements and development of the app, used by travelers to collect their contact and health information when they entered Canada during the COVID-19 pandemic. But as a report by Auditor General Karen Hogan last week spelled out, for the first year and a half, neither agency watched spending or set goals.

In testimony Tuesday before the House of Commons public accounts committee, Hogan said confusion between PHAC and CBSA “led to an accountability void that persisted for close to a year and a half. Each believed that the other was responsible for establishing a governance structure, and neither developed nor implemented good project management practices such as developing objectives and goals, budgets and cost estimates.”

There were oversight failures on ArriveCAN at many layers, Hogan added — contracting, project management, bookkeeping, and IT management. In fact, she said, these were worse than the notorious Phoenix project, which failed to deliver a modern federal public service payment system.

PHAC, which reports to the Minister of Health, responds to public health threats.

Treasury Board Secretariat — which sets policies for the public service — asked bureaucrats during the pandemic to be more flexible and do things quickly, Hogan said, but it also said departments had to still ensure accountability. “So why were the recommendations from Treasury Board not respected?” Hogan asked. “That’s a question you should put to the department.”

The ArriveCAN project started in 2020, but it wasn’t until April 1, 2022 that CBSA took full responsibility for the app. However, Hogan said, as the initial business owner of the app, the Public Health Agency was responsible for establishing the governance structure until then.

That put Heather Jeffrey, current president of PHAC, who was posted to her role in February 2023 after serving as Associate Deputy Minister of Health, in the committee’s spotlight.

“In the face of a global pandemic, with multiple lines of operation across borders, vaccine procurement, therapeutics, and all the other aspects of public health response meant insufficient attention was paid to the governance structure of this project,” Jeffrey said, “which we regret and which we have undertaken to rectify in the future.”

Who decided that there wouldn’t initially be governance, asked the NDP’s Blake Desjarlais.

“The intense nature of the collaboration [with CBSA] meant these teams were meeting on a daily or even weekly basis,” Jeffrey replied. “There was no deliberate decision to not put in a governance structure.”

This was “a dramatic failure, and one that has cost Canadians millions,” said Desjarlais. “We cannot simply say that there were good intentions between CBSA and the Public Health Agency of Canada. They met every week but failed to address the questions of governance and cost.”

The meetings of the two agencies in 2020 were focused on the “significant time pressure to develop an app that would allow the border to permit the flow of critical people and goods,” Jeffrey answered. “The operational outcomes were the overriding subject of conversations.”

Did the Health Minister at the time, Patty Hajdu, or the Clerk of the Privacy Council — the most senior bureaucrat — ask about the costs, asked Conservative Larry Brock.

Jeffrey replied that she wasn’t at PHAC at the time, and didn’t know.

“The ArriveCAN boondoggle has to have consequences,” said Brock, “and it’s little comfort that PHAC says it will do better next time.” Other than two officials suspended for allegations around the selection of GC Strategies to contract out work on the app, have another other employees been suspended, he asked.

No, replied Jeffrey. There have been no findings of wrongdoing in investigations into PHAC employees, she added.

“Can you agree with me the cabinet ministers at the time and the Prime Minister should step up and accept responsibility for this mess?” Brock asked.

“The governance of ArriveCAN was managed within the public service,” Jeffrey said. “As deputy head of the Public Health Agency, I take responsibility for its management.”

Two committee hearings into the reports of the Auditor General and the Procurement Ombudsman into ArriveCAN and contracts awarded to GC Strategies continue.

The post Opposition MPs hammer head of PHAC over ArriveCAN app first appeared on IT World Canada.

Bell, Rogers and Telus state their conditions as CRTC considers expanding wholesale internet mandate

Last week, the Canadian Radio-Television Telecommunications Commission (CRTC) kicked off a series of public hearings as part of a proceeding to examine its existing framework for wholesale high-speed access (HSA), inviting interventions from large telcos, and smaller competitors, as well as advocacy groups.

The proceeding, launched last year, saw a series of developments, including an interim mandate last November forcing large cable and telephone companies in Ontario and Quebec – Bell and Telus – to share their fibre-to-the-home  (FTTH) networks with competitors in order to increase competition.

The Commission deemed that competition had decreased the most in these two provinces, but suggested that this mandate could be expanded to other provinces and be made permanent.

Bell, as a result, rolled back a number of investments and blamed the CRTC for major headcount cuts, Robert Malcolmson, executive vice‑president and chief legal and regulatory officer at Bell Canada, affirmed during the hearing.

“The Commission’s view that there would be – and I quote: ‘minimal risk’ regarding investments in fibre by accelerating wholesale FTTP (fibre-to-the-premises) was dead wrong. The question in this final phase of the proceeding is whether the Commission will double down, or pause and consider how investment incentives can be restored while maintaining the vigorous price competition that is so clearly occurring in the marketplace.”

The company also proposed a number of conditions if the CRTC were to mandate wholesale internet access, including only mandating speeds of up to 1.5Gbps and that fibre-to-the-premises (FTTP) access would only apply to a location five years after the network was deployed there. These measures, Bell argued, would help reduce the negative impact on investment.

Telus also claimed that if the CRTC imposes a wholesale mandate, it should be narrowly tailored, for instance, to exempt rural and remote areas as well as high-cost buried fibre. A wholesale mandate, it added, should not be available to cable companies to access in their own serving territories, as this will result over time in the consolidation of a single physical network, creating vulnerabilities during natural disasters, technical failures and more.

Rogers, additionally, warned the CRTC to not distort competition and undermine investment with “excessive wholesale mandates.”

“The best way to ensure affordable, high‑quality services for Canadian consumers and businesses, and sustain the digital infrastructure that Canada needs to remain competitive with its global peers is through minimally intrusive regulation and compensatory rates,” noted Dean Shaikh, senior vice president, regulatory affairs, Rogers.

Smaller competitors like Xplore, on the other hand, deploring decreased competition, backed the CRTC’s wholesale rules.

“A competitive telecommunications ecosystem in rural Canada needs facilities‑based providers with scale, to offer meaningful and sustainable alternatives,” said Cindy Wallace, regulatory counsel, Xplore. “ The wholesale fibre framework can and should encourage this outcome.”

Others like Eastlink, Cogeco, and Beanfield have asked that Rogers, Bell, and Telus be excluded from accessing the wholesale access regime, the risk being that the mandate be inadvertently flipped on its head and that the Big Three use their dominance, along with flanker brands, acquired wholesale providers, and bundling strategies, to squeeze out regional carriers and independent ISPs.

Finally, advocacy groups like the Competition Bureau and the Public Interest Advocacy Centre (PIAC), intervened, lambasting the large telcos and supporting the CRTC’s wholesale access rules.

“The Commission has a mandate to achieve the telecommunications policy objectives and not to return monopoly rent to incumbents,” said John Lawford, executive director and general counsel, PIAC. “The incumbents are bullying the Commission into using their overheated definition of investment as a trump card that always wins, and they just must be told no.”

The public hearings concluded Friday, and the CRTC reminded intervenors that the deadline to submit the requested additional information is Mar. 1, 2023.

The post Bell, Rogers and Telus state their conditions as CRTC considers expanding wholesale internet mandate first appeared on IT World Canada.

Cyber Security Today, Feb. 21, 2024 – A patch warning from ConnectWise, the latest ransomware news, and more

A patch warning from ConnectWise, the latest ransomware news, and more.

Welcome to Cyber Security Today. It’s Wednesday, February 21st, 2024. I’m Howard Solomon, contributing reporter on cybersecurity for ITWorldCanada.com and TechNewsday.com in the U.S.



Business applications provider ConnectWise is urging IT administrators to take quick action to patch two critical vulnerabilities. They are in on-premise versions of ScreenConnect, which is used by help desks for remote computer control. The vulnerabilities could allow an attacker to execute remote code on systems, or directly impact confidential data or critical systems. The holes affect ScreenConnect versions 23.9.7 and earlier.

As cybersecurity pros around the world celebrated the takedown this week of the LockBit ransomware gang’s infrastructure there was also some sobering news: Ransomware attacks continue. German infrastructure management provider PSI Software SE said it was hit by ransomware last week. IT systems including email were taken offline. The company says no PSI customer installations have been compromised. And a Pennsylvania county said it paid an unnamed ransomware gang nearly US$350,000 in cryptocurrency to get access back to scrambled data.

Researchers at Arctic Wolf looked at data from responding to customers last year and figured your firm is much more likely to be hit by a business email compromise attack — where an employee is tricked into sending money to a threat actor — than ransomware. On the other hand firms hit by ransomware are 15 times more likely to have to undergo an incident response investigation than those victimized by business email compromise scams.

The report also confirms — again — that two strategies can lower the risk of a successful cyber attack: enforcing robust identity controls through identity and access management, and setting priorities for patching the most vulnerable systems.

Here’s more from the report: Want to get or retain cyber insurance? Insurers are looking for three things: Do you monitor your cloud assets for security, do you have logging and network monitoring, and do you have a privileged access management process.

Colorado’s Department of Health Care Planning has updated the number of employees who are victims of the hack of the department’s MOVEit file transfer server. The number originally was just over 4 million current and former staff. Now it’s 4.6 million people. Data on an estimated 94 million people from over 2,700 organizations with MOVEit on-prem or cloud services have been stolen since the end of May last year.

Threat actors are increasingly using a phishing kit called Greatness in attempts to trick Microsoft 365 users into clicking on malicious attachments. The goal, say researchers at Trustwave, is to steal login credentials. Microsoft 365 is a popular cloud business productivity suite so it’s regularly targeted by attackers. The Greatness platform allows a threat actor to insert an attachment to phishing messages that capture usernames and passwords. If the user’s system requires multifactor authentication, the Greatness platform can prompt the victim to enter the codes sent to their smartphones or emails. This particular kit is a phishing-as-a-service offering, so almost any crook can sign up. The cost: US$120 a month in Bitcoin.

Speaking of phishing, the most likely email scams that employees will fall for have a theme of an unpaid invoice or payment coming. That’s according to researchers at Abnormal Security. They looked at customer data of employees fooled by phishing lures into entering their login credentials. Just over 18 per cent of emails had themes that money was owed or is coming. Other scams that worked encourage document sharing, such as ‘Please review these documents’; emails saying there’s an unread or new message; emails saying action is quickly needed; and messages claiming an email or some sort of account has expired. As part of employee security awareness training your staff should be reminded of these tricks.

Attention IT administrators using the Redis in-memory data structure as a database, streaming engine or mesage broker: There’s a new attack you need to be aware of. Researchers at Cado Security have discovered new malware that will install cryptomining software on Redis servers. The report doesn’t say exactly how a system is initially compromised, but the result is a disabling of Redis safety configurations so the attacker can send commands to the server. One way administrators can defend against this kind of attack is to regularly watch their Redis server configurations for signs of change.

Finally, the European Commission says TikTok may not be doing enough to protect minors from harmful content. An investigation was announced on Monday into possible violations of the EU Digital Services Act. That includes whether TikTok’s algorithms result in an addictive design that affects physical or mental well-being or encourages radicalization. The Digital Services Act requires service providers to put in place measures that ensure a high level of privacy, safety and security for minors.

Follow Cyber Security Today on Apple Podcasts, Google Podcasts or add us to your Flash Briefing on your smart speaker.

The post Cyber Security Today, Feb. 21, 2024 – A patch warning from ConnectWise, the latest ransomware news, and more first appeared on IT World Canada.

Hashtag Trending Feb.21- LockBit website goes down; Microsoft takes on Nvidia; Online backlash against OpenAI

An international effort has brought down the notorious LockBit ransomware gang, Microsoft has developed its own tech to replace Nvidia and a huge backlash against OpenAI on social media. 



 

All this and more on the “Jeez, you take one long weekend and the world explodes” edition of Hashtag Trending. I’m your host Jim Love, CIO of IT World Canada and TechNewsDay in the US. 

In a landmark operation dubbed “Operation Cronos,” global law enforcement agencies have struck a significant blow against the notorious ransomware gang, LockBit, signaling a major victory in the fight against cybercrime. 

The UK’s National Crime Agency (NCA), in collaboration with the FBI and an international task force, has successfully seized the gang’s website, replacing its contents with a message indicating the site’s new control under law enforcement. This collaborative effort featured contributions from Europol and agencies from Australia, Germany, the Netherlands, Japan, France, Switzerland, Canada, Sweden, and Finland, showcasing an unprecedented level of international cooperation.

LockBit is infamous for its prolific and malicious attacks—including targeting a children’s hospital and major corporations like Infosys and Subway. It has been a formidable force in the cybercrime world. The group’s operations, marked by at least 1,700 attacks in the U.S. alone by mid-2023, have been a significant contributor to the global ransomware threat, accounting for almost a quarter of all ransomware attacks in some regions. 

They are reputed to be the pioneers of ransomware-as-a-service, a model allowed affiliates to carry out attacks, negotiate ransoms, and then share the proceeds with the gang, a system that had to be adjusted in late 2023 to demand larger ransoms due to waning efficiency.

The disruption of LockBit’s operations is not just a technical achievement but also carries substantial geopolitical weight, given the group’s believed connections to Moscow. This raises the operation’s significance beyond mere cyber defense, hinting at broader efforts to counteract campaigns aimed at disrupting Russia’s adversaries.

The collaborative success of Operation Cronos may serve as a blueprint for future actions against similar threats, marking a pivotal moment in the ongoing battle against ransomware gangs and their increasingly sophisticated networks. 

In the meantime, score one for the good guys.

Sources include: The Register  and ITWorldCanada.com

Microsoft is reported to be developing a new network card designed to enhance the performance of its Maia AI server chip. This initiative, spearheaded by Pradeep Sindhu, co-founder of Juniper Networks and head of the acquired server chip startup Fungible, marks a potential shift in Microsoft’s reliance on Nvidia, a leading chip designer known for its pivotal role in AI model training.

This new network card, likened to Nvidia’s ConnectX-7, aims not only to improve the efficiency of Microsoft’s servers but also to make the process of training OpenAI’s models faster and less costly. 

The implications of this development are vast, promising to accelerate Microsoft’s capabilities in AI and potentially alter the competitive dynamics with Nvidia.

Microsoft’s investment in OpenAI, the creators of ChatGPT, has already positioned it as a frontrunner in the AI domain, integrating cutting-edge technology into its suite of products. The introduction of the Maia chip last November further underscored Microsoft’s commitment to leading in AI computing infrastructure. This latest development to reduce dependency on external chip designs like those of Nvidia’s shows Microsoft’s ambition to control more of the AI technology stack, making AI training more efficient and possibly reshaping the economic landscape of AI development.

Sources include: Reuters

 Yesterday we covered the reaction from the AI community to OpenAI’s new Sora – a text to video offering that was simply astonishing in terms of its quality and light years ahead of many other offerings in terms of its ability to solve some of the problems that had plagued AI generated video – from the simple errors that generate people that have extra hands to the lack of permanence and continuity where characters and backgrounds keep changing.

Sora blew all of that away and was able to produce some astonishingly complex videos.

And it woke a lot of people up. I guess when it was primarily text, people had some anxiety, but once they could see what amounts to a simulation of real life, it got a reaction – and not a good one.  

The unveiling of OpenAI’s latest text-to-video model may have catalyzed a significant public backlash, evidenced by a wave of social media outcry. 

It was clear that OpenAI anticipated a reaction – but they’ve always gotten a positive reaction in the past. Were they anticipating anything this negative? Maybe. 

There was a tweet from an OpenAI employee, which stated, “We very intentionally are not sharing it widely. Yet the hope is that a mini public demo kicks a social response into gear.” This tweet was later removed, but it makes you wonder if Sora was announced to compete with Google’s Gemini launch – or was it to prepare the public for just how far AI has developed?

Google’s Gemini 1.5 was a game changer. Gemini 1.5 Pro can take in 700,000 words, or 30,000 lines of code  35x the amount Gemini 1.0 Pro can handle. And it’s not limited to text. Gemini 1.5 Pro can analyze up to 11 hours of audio or an hour of video in a variety of different languages. 

And Sora knocked it out of the park. 

But maybe not in a good way.

There have been a number of reports of some very negative social media posts. 

One example was from a YouTuber MoistCr1TiKaL, who tweeted  I’m struggling to think of a single positive thing making realistic AI generated videos like this will bring. It’s all just net negative and dystopian.

He is popular and he gets a couple of hundred thousand views on his tweets but that one got 153,000 likes, 11,000 retweets and 8 million views. 

Another twist to this came from comments from an insider known as Jimmy Apples who indicated that Open AI has had Sora since March and only just chose to release it now. 

Apples has been notoriously accurate in predicting what OpenAI will do next. 

But this negative reaction is something to watch. We’ve seen negative reactions to the advance of advanced tech – recently self-driving cars have become targets. Now we have this unveiling of Sora and a public backlash. 

There are fairly reliable predictions that show that Artificial General Intelligence will be here not in 2030 but perhaps as early as 2026. 

I did a piece last week on autonomous agents – these are, as the name implies, autonomous AI agents that can learn complex tasks and process them in the real world – from interacting with websites to operating your PC for you. 

Even if you don’t believe we will get to AGI, the impact that these autonomous agents will have on our world in the coming months will be staggering. And they are real and here today. 

If they were combined with AGI, I’m not sure what happens.

I’m not raising any alarms, I’m not predicting doom and I’m not saying the world is coming to an end. Our world is changing, more rapidly than we ever thought possible. 

But it seems like it took a video to really bring this to public attention.

This could fade out. It could intensify. Or it could be the start of the discussion that we’ve needed to have all along about how we will adapt to what is undoubtedly – for good or bad – you decide – but what is undoubtedly the biggest business and social transformation of the past several hundred years. 

We live in interesting times. 

Hashtag Trending goes to air five days a week with daily newscast and a weekend interview show that we creatively called – the weekend edition. 

I got comments on my story yesterday on the growth in C level titles. Thanks. I am really interested in what you think about AI and your reaction to the story today. 

I like to keep it real and knowing what you think is a big help. 

Send us a note at jlove@itwc.ca or drop us a comment under the show notes at itworldcanada.com/podcasts – look for Hashtag Trending. 

Thanks for listening and have a Wonderful Wednesday.

The post Hashtag Trending Feb.21- LockBit website goes down; Microsoft takes on Nvidia; Online backlash against OpenAI first appeared on IT World Canada.

The world according to Hinton: Slowing AI down is not the answer

Eight months ago, Geoffrey Hinton, the esteemed professor emeritus at the University of Toronto who resigned his post at Google over concerns about artificial intelligence (AI) advances, stated in a speech at Collision 2023 that the world is “entering a period of huge uncertainty.”

When he speaks, people listen, due in large part to the fact Hinton, along with Yoshua Bengio and Yann Andre LeCun, won the coveted Turing Award in 2018, an honour that resulted in the three computer scientists being known from that point on as the “Godfathers of AI.”

In recognizing the trio, the Association for Computer Machinery (ACM), which awards the annual prize, noted at the time, “working independently and together, Hinton, LeCun and Bengio developed conceptual foundations for the field, identified surprising phenomena through experiments, and contributed engineering advances that demonstrated the practical advantages of deep neural networks.

“In recent years, deep learning methods have been responsible for astonishing breakthroughs in computer vision, speech recognition, natural language processing, and robotics – among other applications.”

At Collision, Hinton pointed out that “people whose opinion I respect have very different beliefs from me.

“Yann LeCun thinks everything is going to be fine. They (AI chatbots) are just going to help us; it is all going to be wonderful. But we have to take seriously the possibility that, if they get to be smarter than us, which seems quite likely, and they have goals of their own, which seems quite likely, they may well develop the goal of taking control. And if they do that, we are in trouble.

“AI trained by good people will have a bias towards good, AI trained by bad people such as Putin or somebody like that will have a bias towards bad. We know they are going to make battle robots. They are busy doing it in many different defence departments. They are not going to be necessarily be good, since their primary purpose is going to be to kill people.”

Given those concerns, what seemed somewhat perplexing was that in March of last year, Hinton was not among the tech leaders who signed an open letter urging a six-month moratorium on development, saying that AI tools “present profound risks to society and humanity.”

The reason why became clearer earlier this month, when he spoke at an event in Toronto organized by the Vector Institute, a not-for-profit organization that focuses on AI research and where Hinton serves as chief scientific advisor.

When asked during a Q&A session whether the speed of AI is “spinning too fast,” he replied that while it certainly is, “I don’t think we’re going to solve it by slowing down,” adding that is the key reason he opted not to sign the letter.

“I do not think the right way to phrase the problem is in terms of whether you should go fast or slow. Partly because I do not think you are going to be able to slow things up. There’s too much economic gain from going fast. We have seen actually what happens if people try and slow things up in a situation that was slanted entirely in favor of safety, and profits still won. That is my view of what happened at Open AI.

“Slowing it down, A) is not feasible, and B) is not the main point. The main point is, it is possible, we can figure out how to make these things benevolent so we can deal with the existential threat that these things will take over. That is a different problem from figuring out how to stop bad people using them for bad things, which is more urgent. In my view, we should put huge effort into trying to figure it out.”

Hinton said that it will not solve all the problems, and, in particular, it will not solve the problem of bad people doing bad things with it.

“If you want regulations, the most important regulation should be not to open source big models. That is like being able to buy nuclear weapons at Radio Shack. It is crazy to open source these big models, because bad actors can then fine tune them for all sorts of bad things. In terms of regulations, I think that is probably the most important thing we can do right now.”

His presentation focused on whether digital intelligence will replace biological intelligence. There are today, he said, deep learning systems that “are incredibly powerful and understand in much the same way people do.

“When people say, ‘these models are different from us,’ ask them, ‘well, OK, how do we work? And what is different about it?’ And they cannot answer that question, except for Gary Marcus. Gary Marcus can answer that question. And he says, ‘we work by having symbol strings and rules, but you should still worry about it. Because although it does not understand anything, it is extremely dangerous.’ I call that wanting to have your cake and have it eat you too.”

The post The world according to Hinton: Slowing AI down is not the answer first appeared on IT World Canada.