Page 15 of 55

Warning: Phishing campaign aimed at senior executives

Accounts of hundreds of Microsoft Office and Azure user accounts — including those of senior executives — have been compromised recently in ongoing targeted phishing attacks, say researchers at Proofpoint.

“As part of this campaign, which is still active, threat actors target users with individualized phishing lures within shared documents,” the warning says. For example, some weaponized documents include embedded links to “View document” which, in turn, redirect users to a malicious phishing webpage upon clicking the URL.

“Threat actors seemingly direct their focus toward a wide range of individuals holding diverse titles across different organizations, impacting hundreds of users globally,” Proofpoint says.

“The affected user base encompasses a wide spectrum of positions, with frequent targets including Sales Directors, Account Managers, and Finance Managers. Individuals holding executive positions such as ‘Vice President, Operations’, ‘Chief Financial Officer & Treasurer’ and ‘President & CEO’ were also among those targeted.

“The varied selection of targeted roles indicates a practical strategy by threat actors, aiming to compromise accounts with various levels of access to valuable resources and responsibilities across organizational functions.”

Those behind this campaign are using this agent — which defenders should be watching for — during the access phase of the attack chain: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36 

Attackers predominantly utilize this user-agent to access the ‘OfficeHome’ sign-in application, says Proofpoint, along with unauthorized access to additional native Microsoft 365 apps, such as:

‘Office365 Shell WCSS-Client’ (indicative of browser access to Office 365 applications);
‘Office 365 Exchange Online’ (indicative of post-compromise mailbox abuse, data exfiltration and email threats proliferation);
‘My Signins’ (used by attackers for MFA manipulation)’
‘My Apps’
‘My Profile’

Successful initial access often leads to a sequence of unauthorized post-compromise activities, including multifactor authentication (MFA) manipulation so the attackers can maintain persistent access. Proofpoint has seen attackers choosing different authentication methods, including registering alternative phone numbers for MFA authentication via SMS or phone call. However, in most cases the attackers preferred to add a mobile authenticator app with notification and code.

From there, the attackers may access and download sensitive files, ravage email boxes, send fraudulent email messages to human resources and financial departments and, to hide their tracks, create dedicated obfuscation email rules.

Proofpoint urges IT and infosec leaders to:

monitor for the specific user agent string and source domains in your organization’s logs to detect and mitigate potential threats;
enforce immediate change of credentials for compromised and targeted users, and enforce periodic password change for all users;
identify account takeover (ATO) and potentially unauthorized access to sensitive resources in your cloud environment. Security solutions should provide accurate and timely detection for both initial account compromise and post-compromise activities, including visibility into abused services and applications;
identify initial threat vectors, including email borne threats (e.g. phishing, malware, impersonation, etc.), brute-force attacks, and password spraying attempts;
employ auto-remediation policies to reduce attackers’ dwell time and minimize potential damages.
The post Warning: Phishing campaign aimed at senior executives first appeared on IT World Canada.

Ransomware gang claims it hit Canadian oil pipeline operator

The AlphV ransomware gang claims it has hit Canadian oil transmission operator Trans-Northern Pipeline, which operates pipelines in three provinces.

Brett Callow, a B.C.-based threat researcher with Emsisoft, first broke the news earlier today in a tweet on the X social media platform.

The gang claims 190 GB of data was recently stolen, all of which is now publicly available.

In an email statement, Trans-Northern said the company “experienced a cybersecurity incident in November 2023 impacting a limited number of internal computer systems. We have worked with third-party cybersecurity experts and the incident was quickly contained. We continue to safely operate our pipeline systems. We are aware of posts on the dark web claiming to contain company information, and we are investigating those claims.”

There were no unusual or unplanned interruptions of pipeline operations, said Lisa Dornan, the company’s communications team leader.

The company didn’t answer emailed questions about how much, if any, data was stolen, how much, if any, data was encrypted and if any information involved the data of employees or customers.

Trans-Northern operates two lines: An oil pipeline between Calgary and Edmonton, and a separate line that roughly runs from Nanticoke, Ont. through Toronto to Montreal.

Separately, AlphV also listed as a victim the Canadian electronics retail chain The Source, which is owned by BCE, the parent company of Bell Canada.

The AlphV/BlackCat ransomware gang has been in the crosshairs of governments for some time. In December, the U.S. Justice Department said it had disrupted the gang’s operations after the FBI created and distributed a decryption tool to over 500 victim organizations. The U.S. also seized several websites the group operates.

Threat researchers differ on whether ransomware victims are targeted, or end up being hit because crooks find application vulnerabilities or take advantage of stolen passwords. AlphV is a ransomware-as-a-service operation, which means it uses affiliates who specialize in finding ways to initially break into a corporate network.

Certainly pipelines are a juicy target for extortion. When the U.S. Colonial Pipeline was hit by ransomware in 2021, the unprepared company stopped all pipeline operations to contain the attack. According to CNN, the shutdown was also because the attack impacted Colonial’s ability to bill customers. Regardless of the reason, one result was temporary long lineups for gasoline on the east coast of the U.S..

Experts said at the time that one mistake in attacking a critical infrastructure provider was that it brought in the weight of U.S. authorities. While Colonial paid a US$4.5 million ransom to the DarkSide ransomware gang, about half was recovered by the U.S. government.

During a Congressional hearing, the head of Colonial Pipeline told U.S. senators that hackers were able to get into its IT system by stealing a single password to a legacy Virtual Private Network (VPN) that did not have multifactor authentication.

The post Ransomware gang claims it hit Canadian oil pipeline operator first appeared on IT World Canada.

AI in network orchestration spend to reach US$20B by 2028: Juniper

A new report from Juniper Research indicates that global network operator spend on artificial intelligence (AI) for network orchestration will generate US$20 billion by 2028; rising 240 per cent from the US$6 billion expected to be generated this year.

Authors of the report are predicting that “enterprises’ increasing use of cellular networks, including for smart manufacturing and autonomous vehicles, will necessitate further investment into AI that automates key network processes.

“These use cases require various degrees of high throughput, low latency and geographical coverage. Therefore, to maximize networks’ efficiency and reduce operational expenditure, the report urged operators to accelerate the incorporation of AI into core networks.”

Findings revealed that as operators expand established 5G networks and build future 6G networks, AI must play an essential role, with performance optimization and network security being the most important use cases. They are expected to account for over 50 per cent of global operator spend on AI by 2028.

“Additionally, ever-increasing virtualization of network functions and demand for cellular data will drive operators to implement AI to decrease operational costs,” a Juniper release stated. “The ability to automate real-time network analysis and adjust network conditions accordingly will be crucial to minimizing the costs associated with network management and service provision.”

Report author Frederick Savage said, “as operators compete on the quality of their networks, AI will be essential to maximizing the value of using a cellular network for connectivity. High-spending users will gravitate to those networks that can provide the best service conditions.”

The post AI in network orchestration spend to reach US$20B by 2028: Juniper first appeared on IT World Canada.

Serious IT incidents in Canadian financial sector almost tripled in 2023

Canadian federal financial institutions suffered almost three times as many serious reportable IT incidents in 2023 as in the year before, a parliamentary committee debating proposed cybersecurity legislation for overseeing the country’s critical infrastructure providers was told Monday.

In 2023, there were 28 Priority 1 incidents reported to the Office of the Superintendent of Financial Institutions (OSFI), compared to 2022, when there were only 10 Priority 1 incidents reported.

Priority 1 covers “high impact incidents that cause disruption of service or leakage of data,” Tolga Yalkin, an assistant superintendent at the OFSI, told MPs. The agency later clarified to IT World Canada that a Priority 1 incident covers various sources of potential technology disruption, including but not limited to cyber-attacks.

The OSFI oversees 400 federally-regulated institutions, including 80 banks and 43 trust companies, as well as insurance companies,

The release of the two numbers is a rare view into the extent of serious IT incidents suffered by federally regulated Canadian banks, trust companies, and insurance firms.

“We are concerned with that number growing,” Yalkin told MPs. “We are tracking it very carefully. We are eagerly watching to see whether or not the trajectory continues to grow. This [cybersecurity] is an area of risk for financial institutions.”

Yalkin was testifying before the House of Commons national security committee looking into Bill C-26, which would force designated banks, telecommunications companies, and interprovincial transportation and energy firms to meet certain cybersecurity standards to protect their IT networks and report incidents to the government.

The legislation would impose some obligations on Canadian banks. But, Yalkin said, banks already have to follow OFSI cybersecurity risk management guidelines.

Bill C-26 has two parts: One would amend the Telecommunications Act to give the federal cabinet and the Minister of Industry the power to order designated telecom providers to do “anything” to secure their systems against a range of threats.

The bill would also create the Critical Cyber Systems Protection Act (CCSPA), which would apply to other critical infrastructure providers. Initially, these would be limited to banking, financial clearing firms, interprovincial transport and energy companies, and nuclear power operators. Similar to the Telecommunications Act changes, it would create a cyber security compliance regime for designated firms. Included would be a requirement to report cyber incidents “immediately” to the Canadian Security Establishment (CSE), the branch of the Defence Department responsible for government cybersecurity.

Industry witnesses have worried about having to report serious incidents immediately, preferring the law or regulations follow the American practice of reporting to government regulators within 72 hours. The U.S. Federal Communications Commission just modified its data breach notification rules for telcos there to 30 days.

Also at Monday’s committee meeting, a University of Toronto IT professor emeritus called C-26 “a very one-sided bill” that allows CSE to gather too much sensitive information.

CSE has a “boundless appetite for data collection,” Andrew Clement told the committee.

The proposed legislation needs “substantial” amendments to ensure the “sweeping and secretive powers it grants the government do not override other equally vital values such as privacy, freedom of expression, judicial transparency and government accountability.”

Eric Smith, senior vice-president of the Canadian Telecommunications Association (CTA), which represents the country’s major telcos, said the legislation allowing the Industry minister to order telcos to do — or not do — anything in the name of security “could be broadly interpreted.”

That could range from cutting off service to an organization or individual, he said, or putting equipment on a telco’s network that would weaken encryption or intercept communications. The CTA is asking MPs to amend C-26 to give the government only the power to issue “reasonably necessary’” orders to telcos. The law should also say compliance orders can only be made after the Industry minister has consulted with a list of experts — some of whom may be in the government — to ensure the orders are proportionate to the risk. An order should only have a limited impact on a telco’s service availability, the CTA says, and should be economically and operationally feasible for affected service providers

Even without C-26, in 2022 the government ordered telcos to remove some equipment from specific companies, Smith noted. That was a reference to the removal of equipment made by China’s Huawei and ZTE.

The CTA is asking C-26 be amended so carriers can at least ask the government for compensation if it has to remove or add networking gear.

It is also asking that the legislation allow a carrier a due diligence defence – that it tried to protect its IT network in good faith – if the government alleges the carrier violated an order. A due diligence defence is allowed for other critical infrastructure providers, Smith noted.

Federal privacy commissioner Philippe Dufresne asked for several changes to C-26, including limiting the ability of the government to share sensitive information that critical infrastructure providers would have to hand over to CSE with other departments or foreign governments; and that the government would have to report to him or Parliament the number and purpose of secret orders it issues under the law to a critical infrastructure provider.

Angelina Mason, general counsel and senior vice-president of the Canadian Bankers Association, which represents 60 of the country’s banks, asked MPs to add greater safeguards for the protection of confidential information banks would have to give the government; protect banks from civil and criminal prosecution for good faith compliance with the act’s reporting requirements and cybersecurity directives; and make the government share its cybersecurity information with the private sector.

The post Serious IT incidents in Canadian financial sector almost tripled in 2023 first appeared on IT World Canada.

Federal government procurement has massive overruns: Hashtag Trending, Tuesday February 13, 2024

Once again, Canadian federal government procurement has massive overruns, a driverless Waymo taxi is attacked by a mob, the CEO of Mozilla steps down in the face of Firefox’s decline to irrelevance…

All this and more on this oh my gawd, I hope this isn’t too preachy edition of Hashtag Trending. I’m your host Jim Love, CIO of IT World Canada and TechNewsDay in the US.

In a revealing audit, Canada’s Auditor General Karen Hogan has cast a spotlight on the mismanagement surrounding the ArriveCAN app, a digital tool developed to streamline the entry process into Canada during the COVID-19 pandemic. The report uncovers a series of failures by three federal government agencies: Canada Border Services Agency, the Public Health Agency of Canada, and Public Services and Procurement Canada, highlighting a disregard for good management practices in the app’s contracting, development, and implementation, which amounted to a staggering $59.5 million expenditure.

The audit paints a picture of a project marred by poor financial record-keeping, making it nearly impossible to ascertain the full cost of the ArriveCAN application. This lack of transparency and accountability has raised significant concerns about the value delivered for the taxpayer dollars spent. The report details how the agencies’ reliance on external resources, beyond the initial crisis of the pandemic, not only inflated costs but also brought into question the overall value achieved for the money spent.

One of the most alarming findings is the “disregard for policies, controls, and transparency” in the contracting process, particularly how the initial ArriveCAN contract was awarded to GC Strategies, an IT staffing company, through a non-competitive process without adequate documentation. This process limited competition opportunities and undermined the value for money, raising concerns about the integrity of the contracting practices.

The audit also highlighted the Canada Border Services Agency’s poor management of contracts, with essential information missing from contracts and routine approval of invoices that lacked detail on the work completed. This lack of diligence and oversight has compromised the accountability for public spending on the ArriveCAN project.

In response to these findings, the Auditor General has made several recommendations, including the need for accurate financial records, full documentation of interactions with potential contractors, and ensuring compliance with contracting policies. The government has acknowledged these “unacceptable gaps in management processes” and has taken steps to improve oversight and procurement practices.

That’s the official line – and none of this will make any difference. Nor will it keep this from happening. Why? Government procurement is broken and it’s time to fix it.

And talking about “transparency” and all those platitudes will not fix a thing. In fact, here’s my prediction – the next round of “improvements” will just make it worse.

I’ve been a procurement consultant for the federal government and it’s a joke. The crazy rules that are in place are not designed to give the best value for the taxpayer, they are part of Kafkaesque bureaucratic bungling that is guaranteed to yield the worst possible results.

When I worked on one major purchasing, we were not allowed to ask questions that might actually find out who knew what they were doing and who didn’t. And there was a “fairness” commissioner representative, that was actually a real paid job, and they were there to make sure we didn’t ask any question that would show who knew their stuff and who didn’t.

I want to emphasize that this is NOT the fault of the individual employees. We have a lot of people on our payroll who come to work every day and work hard to do their job.

The problem is with the leadership and the processes driven by people who have no accountability for the results of their actions.

This has nothing to do with political parties. Steven Harper’s conservatives screwed things up just as royally as Justin Trudeau’s Liberals. And the Poilievre’s Conservatives or Jagmeet Singh’s NDP will continue to screw it up. Do not listen to the politicians – they have no idea.

But this is not going to be fixed until someone has the courage to say that this is fundamentally broken and bring in some people who actually understand procurement and technology – and get out of the way while they do their job.

We need accountability for the people who drive the process. They don’t need a mass of bureaucrats and “fairness commissioners” – they need clear objectives, accountability for those, and for the rest of the system to just get out of the way.

Apologies for editorializing but if private companies do this, we can just choose to not buy their products. When the government does it, we have to pay, regardless.

My standing offer to take 5 other CIOs into any area and fix it once and for all still stands if anyone is interested.

Sources include: IT World Canada

In a startling incident in San Francisco’s Chinatown, a Waymo driverless taxi became the target of vandalism that escalated into a full-blown arson attack. The event unfolded around 9 PM PT, starting with an individual jumping onto the vehicle’s hood and smashing its windshield. This act of destruction quickly garnered applause, leading to a crowd forming around the car. The group proceeded to cover the vehicle in spray paint, break its windows, and, in a dramatic finale, set it ablaze. By the time the fire department arrived, the autonomous car was already engulfed in flames.

The motive behind this aggressive act remains unclear, with no reports suggesting why the Waymo car was targeted. Waymo, a leading name in the autonomous vehicle industry, confirmed that the car was operating without any passengers at the time of the attack. The incident was marked by the throwing of fireworks into the car, which ignited the fire. San Francisco Police Department responded to the scene to find the vehicle already in flames, fortunately with no injuries reported.

This incident occurs against a backdrop of growing tension between San Francisco residents and the operators of automated vehicles. Previous incidents involving robotaxis, including a pedestrian being struck and traffic disruptions, have fueled public debate over the safety and regulation of autonomous vehicles in the city. Just last year, city officials and residents expressed strong opposition to granting 24/7 operation licenses to these vehicles, with some going as far as to physically block the cars in protest.

The destruction of the Waymo taxi in Chinatown highlights the broader challenges tech companies face as they integrate their innovations into public spaces. Acts of vandalism and defiance against technology, from scooters thrown into lakes to cars being punched, underscore the friction between technological advancement and public acceptance.

As the investigation into the incident continues, the event serves as a stark reminder of the complexities surrounding the deployment of autonomous vehicles in urban environments. It raises critical questions about safety, regulation, and the societal impacts of rapidly advancing automotive technologies.

Sources include: The Verge and official statements from Waymo and the San Francisco Police Department.

In a move that has stirred the tech community, Mitchell Baker, CEO of Mozilla Corp, has announced her resignation. This decision comes at a time when Firefox, once the darling of the web browser world, continues its descent into what many fear could be obscurity. Steven J. Vaughan-Nichols, in his opinion piece for The Register, delves into the implications of Baker’s departure and the current state of Mozilla and its flagship product, Firefox.

Firefox’s journey from a pioneering web browser to its current position reflects a broader narrative of change and challenge within the tech industry. In the early 2000s, Firefox was celebrated for its innovation and security, offering a refreshing alternative to Internet Explorer. However, the landscape has dramatically shifted since then, with Firefox’s user base dwindling to a mere 2.2 percent of US government website visitors, as reported by the Digital Analytics Program (DAP).

The decline of Firefox is not a sudden phenomenon but a gradual erosion of market share, primarily to Google’s Chrome, which now dominates the browser space. This shift raises questions about Firefox’s relevance in today’s tech ecosystem and the strategic decisions that have led to its current state. Vaughan-Nichols points out that even Mozilla has recognized the challenge posed by Chrome, with former CEO Chris Beard acknowledging in 2017 that Firefox had failed to keep pace with market demands.

The article also highlights the financial and operational complexities within Mozilla, particularly concerning its funding model. Despite positioning itself as a champion of privacy and the open web, Mozilla’s financial sustainability heavily relies on royalties from Google, a fact that sits uncomfortably with its public mission. Baker’s compensation, amidst declining revenues and Firefox’s shrinking user base, further complicates the narrative around Mozilla’s priorities and management practices.

As Baker steps down, Laura Chambers has been named interim CEO, tasked with refining Mozilla’s vision and doubling down on core products like Firefox. Yet, the future direction of Mozilla and Firefox remains uncertain, with Vaughan-Nichols expressing skepticism about the possibility of a significant turnaround.

Baker’s new role will focus on representing Mozilla in public forums, emphasizing policy, open source, and community engagement. However, the connection between these activities and the revitalization of Firefox is not immediately clear. The overarching challenge for Mozilla is not just about leadership changes but finding a sustainable path forward in an internet landscape that has evolved beyond its early vision.

This episode raises critical questions about the viability of Firefox as a web browser, the strategic direction of Mozilla, and the broader implications for the tech industry’s commitment to open standards and user privacy.

And at the risk of making this edition totally opinionated, I think you only have to look at Perplexity to see how sadly irrelevant Firefox has become. I get the open source piece. I love open source. I get privacy idea. Love it. But for heaven’s sake, let’s learn one lesson if we want to compete – “we’re not the other guys” is not a unique value proposition. Understanding the needs and desires of your customer and trying to fulfil them – that’s where you take market share.

Sources include: The Register

And that’s our show for today.

And I don’t know why or how, but I scan a lot of stories to produce this podcast and on some days, they just seem to have a theme.

If I’m straying far too much into opinion, I’m trusting that you’ll let me know.

Hashtag Trending goes to air five days a week with daily news cast and a weekend interview show that we creatively called – the weekend edition.

We love to hear from you. Send us a note at jlove@itwc.ca or drop us a comment under the show notes at itworldcanada.com/podcasts – look for Hashtag Trending.

Thanks for listening and have a Terrific Tuesday.

 

 

 

 

 

 

 

 

The post Federal government procurement has massive overruns: Hashtag Trending, Tuesday February 13, 2024 first appeared on IT World Canada.

Montreal duo launch free cybersecurity training platform

Two childhood friends, both of whom are entrepreneurs based in Montreal, today launched Cyber101, a platform that offers organizations a chance to educate their employees about cybersecurity best practices free of charge, in both English and French. It is the brainchild of Benjamin Beauregard, the chief executive officer (CEO) of video production agency divisionX  and Guillaume Belanger, president of Exosource, an IT services company.

With Cyber101, according to a release, “business and individuals can immediately improve their cybersecurity posture in less than an hour.

By taking the course, the two said, organizations stand to:

Reduce the risks of fraud, data breaches, and disruptions
Meet the requirements of insurers and privacy laws
Improve employees’ technological skills
Demonstrate a serious commitment to cybersecurity to clients and staff.

The release went on to say that Statistics Canada estimated that the proportion of Canadians victimized by cybersecurity incidents increased from 58 per cent in 2020 to 70 per cent in 2022. The most commonly reported incidents were receiving unsolicited emails and fraudulent content.

“When teaching at the McGill Executive Institute, cybersecurity consistently emerges as a critical issue,” said Beauregard. “Guillaume and I created this platform because we believe that education is the key to effectively countering cyber threats.”

Belanger said the Cyber101 platform provides “essential tools to help you stay on top of threats in an increasingly hostile environment.”

Those tools are contained in nine mini-modules taking, the site said, “five minutes or less” and once completed, anyone who successfully answers a series of questions based on each module will then receive what the company calls “a personalized completion certificate.”

The Cyber101 website notes that “millions of businesses and individuals fall victim to cybercrime every year and the consequences can be catastrophic (identity theft, confidential data breaches, extortion ….)

“Cybersecurity awareness has become an absolute necessity for individuals and businesses. Yet, quality content remains out of reach for most. We have decided to produce quality training and to offer it for free.”

The post Montreal duo launch free cybersecurity training platform first appeared on IT World Canada.

Government departments ignored management practices, failed to oversee ArriveCan app: Auditor General

Three federal government agencies failed to follow good management practices in the contracting, development, and implementation of the $59.5 million ArriveCAN application, Canada’s auditor general said today.

As a result, concluded Auditor General Karen Hogan, it did not deliver the best value for taxpayer dollars spent.

But Hogan also said the lack of documentation makes it almost impossible to find out the exact cost of all the work paid for the app.

Canada Border Services Agency, the Public Health Agency of Canada, and Public Services and Procurement Canada were faulted by Hogan in the report filed in Parliament this morning.

The application was created in 2020 to digitally collect traveller contact and health information when they entered Canada during the COVID‑19 pandemic, so information could easily be presented to border authorities. The audit estimated that the ArriveCAN application cost approximately $59.5 million but emphasized that the exact cost was impossible to calculate because of the Canada Border Services Agency’s poor financial record keeping.

“The agency’s decision to continue relying on external resources throughout the application’s development, launch and updates, beyond the initial pandemic crisis, increased costs and brings into question the value achieved for money spent,” the auditor general’s office said in a statement.

The lack of documentation and controls extended to contracting practices, the statement says. The audit found that the Canada Border Services Agency’s “disregard for policies, controls, and transparency in the contracting process limited opportunities for competition and undermined value for money. There was little documentation to support how and why  a company called GC Strategies was awarded the initial ArriveCAN contract through a non‑competitive process.”

GC Strategies is an IT staffing company — that is, it hires, or subcontracts, developers to do work for organizations it contracts with.

The report says evidence shows GC Strategies was involved in setting the requirements that the Canada Border Services Agency later used to tender a competitive contract.

The audit found that Canada Border Services Agency managed contracts poorly, which raised concerns about value for money. Essential information, such as clear deliverables and required qualifications, was missing from contracts. Canada Border Services Agency routinely approved and paid invoices that contained little or no details on the work completed.

“Public servants must always be transparent and accountable to Canadians for their use of public funds”, said Hogan. “Many questions that Parliamentarians and Canadians are asking cannot be answered. The lack of information to support ArriveCAN spending and decisions has compromised accountability.”

The report says

18 per cent of invoices submitted by contractors that Hogan’s office tested did not provide enough information to determine whether expenses related to ArriveCAN or another information technology project. This made it impossible to accurately attribute costs to projects;
the AG’s office estimated that the average per diem cost for the ArriveCAN external resources was $1,090, whereas the average daily cost for equivalent IT positions in the Government of Canada was $675. The Canada Border Services Agency continued to rely on external resources, increasing the cost of the application;
between April 2020 and October 2022, the Canada Border Services Agency released 177 versions of ArriveCAN, with often little to no documentation of testing. In one update, in June 2022, around 10,000 travelers were wrongly instructed to quarantine.

As a result of that incident, the federal Privacy Commissioner found that the Canada Border Services Agency (CBSA) contravened the Privacy Act by not taking all reasonable steps to ensure that information about individuals recorded in the app was accurate;

there was no formal agreement between the Public Health Agency of Canada and the Canada Border Services Agency from April 2020 to July 2021 to clarify roles and responsibilities, the report says. “Each agency believed that its counterpart was responsible for establishing a governance structure. In our view, the Public Health Agency of Canada, as the business owner, was responsible for establishing the governance structure.
“As a result of the missing governance structure, good project management practices were not developed and implemented,” the report says. “For example, the Public Health Agency of Canada did not develop project objectives and goals, budgets and cost estimates, assessments of resource needs, or risk management activities.” It was only in July 2021, when a letter of intent was signed, that responsibilities for funding the development, implementation, management, and support of ArriveCAN was clarified;
the AG’s office found no evidence to show that some Canada Border Services Agency employees complied with the agency’s Code of Conduct by disclosing that they had been invited to dinners and other activities by contractors;
one reason the cost of the app went up: The Canada Border Services Agency added a digital customs and immigration declaration form into the ArriveCAN application at a cost of about $6.2 million, to replace a paper-based system. The new digital declaration form remained in use after government requirements to collect travellers’ contact and health information stopped in October 2022.

The Canada Border Services Agency was responsible for developing and managing the ArriveCAN application on the basis of the Public Health Agency of Canada’s health requirements. These requirements were implemented to meet Covid-19 emergency orders. The Public Health Agency of Canada assists the federal Minister of Health. The agency was the business owner of ArriveCAN until April 1, 2022. Public Services and Procurement Canada is the government’s central purchasing and contracting authority, and was responsible for issuing and administering contracts on the agencies’ behalf when the contract value exceeded their delegated authority to procure.

While the Treasury Board of Canada Secretariat introduced some flexibility into the procurement and contract processes during the pandemic to achieve results quickly, the report notes, it still required government organizations to demonstrate due diligence and controls around expenditures and to document their decisions.

Hogan recommends:

the Canada Border Services Agency maintain accurate financial records by correctly allocating expenses to projects. To better support these actions, the agency should work with contractors to obtain invoices that accurately detail the work completed by each resource by project, contract, and task authorization;
the Canada Border Services Agency and the Public Health Agency of Canada fully document interactions with potential contractors and the reasons for decisions made during non‑competitive procurement processes and should put in place a process to ensure compliance with the requirements of the contracting policies;
the Canada Border Services Agency should ensure that potential bidders are not involved in developing or preparing any part of a request for proposal, and should put in place controls that will prevent this from occurring.

In response to the AG report, the government issued a statement admitting there were “unacceptable gaps in management processes.”

CBSA has already created an Executive Procurement Review Committee to approve contracts and task authorizations, the government said, “which is already providing additional oversight on all contracting activities, focusing on delivering value for money.” CBSA has also established a procurement centre of expertise to help employees fully understand their obligations and authorities. The agency also now requires employees to disclose all interactions with potential vendors.

Public Services and Procurement Canada “will continue to strengthen all aspects of the federal procurement regime and will use the findings from this report to improve the way the Government of Canada does business with its suppliers,” the statement says. New measures have already been added to ensure that tasks and deliverables are clearly defined in professional services contracts, the government says, and the policy and guidance documentation used by procurement officials to ensure consistency has been updated.

The post Government departments ignored management practices, failed to oversee ArriveCan app: Auditor General first appeared on IT World Canada.

Cyber Security Today, Feb. 12, 2024 – US seizes a website selling the Warzone malware

The U.S. seizes a website selling the Warzone malware.

Welcome to Cyber Security Today. It’s Monday, February 12th, 2024. I’m Howard Solomon, contributing reporter on cybersecurity for ITWorldCanada.com and TechNewsday.com in the U.S.



American authorities have seized a website and several domains that sold the Warzone remote access trojan to threat actors. The malware takes screenshots, records keystrokes, turns on computer video cameras and steals data. As part of the operation the U.S. also indicted individuals in Malta and Nigeria for alleged computer crimes. Both have been arrested. American authorities are trying to extradite the man in Malta for trial in the U.S. The U.S. credited Canada, Croatia, Finland, Germany, the Netherlands and Romania with helping in the takedown of the Warzone servers.

Cyber investigators in France are still looking into data breaches at two supplementary health insurance companies two weeks ago which saw the theft of data of more than 33 million people. That’s about half the country. The country’s privacy commission said data stolen on policyholders included people’s names, date of birth and their social security number. No banking or health data was stolen.

Separately, the France Info radio network reports that a ransomware attack forced a hospital in northern France to take its IT systems offline Sunday. It also had to temporarily close its emergency department.

Personal data on over 13 million Americans was stolen last spring from a company that provides medical transcription services to healthcare organizations. The company is Perry Johnson & Associates. Among its clients is Concentra Health Services, which has clinics across the U.S. Perry Johnson said the attacker accessed the IT system that held data on Concentra patients in April. Notification of the millions of victims started in November. We’re learning about it now because Perry Johnson filed a description of the data breach notification letters last week with Maine’s attorney general’s office.

Planet Home Lending, an American loan provider, has updated the number of victims involved in a data breach that took advantage of a Citrix vulnerability in its servers. Last month it said data on just under 200,000 customers was stolen in November. In an updated filing with Maine’s attorney general the company now says the number is almost 285,000 people.

A new backdoor targeting Mac computers has been discovered. Researchers at Bitdefender say the malware seems to impersonal an update for Microsoft Video Studio. So Mac users should be wary of emails or popups claiming to be a patch for this application. This malware may have been circulating since last November. Bitdefender suspects it may have been created by a ransomware gang.

The U.S. Federal Communications Commission won’t allow anyone in the U.S. to use artificial intelligence software to create voice-cloned automated phone calls. The regulator said last week calls recorded with AI-generated voices are forbidden on the Telephone Consumer Protection Act. Crooks are sending out robocalls that imitate the voices of celebrities and politicians for scams or misinformation. They are even using the technology to imitate family members for extortion. Not only will police go after crooks for robocalls for fraud, they will now be able to prosecute for illegal use of AI.

Last November news emerged that a Pennsylvania water authority’s water pressure regulating system was hacked by an Iranian threat group. The group planted a message on the system’s interface. The entry point was the system’s Unitronics internet-connected controller. As a result of that attack researchers at Censys did some internet scanning and found 149 internet-exposed Unitronics devices and services in the U.S. Interestingly, a number of them are honeypots. That is they are designed to lure hackers. However, Censys said many operators of the web control panels of Unitronics PLCs are still using the default password of 1111. Censys warns IT and OT administrators to a) make sure the default password is changed and b) that if these devices do have to be connected to the internet they should be protected by a VPN or firewall.

Want to start the day with more news? IT World Canada’s Jim Love has a daily general IT news podcast. It’s called Hashtag Trending. It can be found here or where Cyber Security Today is: on Apple Podcasts and Google Podcasts.

The post Cyber Security Today, Feb. 12, 2024 – US seizes a website selling the Warzone malware first appeared on IT World Canada.

AI agents will transform AI usage in the coming months: Hashtag Trending for Monday February 12, 2024

Forget about Artificial General Intelligence, AI agents are going to rock your world in the coming weeks and months, if fewer companies are paying ransoms, why has the total amount paid almost doubled over last year, a testing device called Flipper is banned in Canada and a viral story about toothbrushes being compromised by malware is revealed to be an error in translation.

All this and more on this slip of the tongue edition of Hashtag Trending. I’m your host Jim Love, CIO of IT World Canada and TechNewsDay in the US.

OpenAI has hinted that they are on the brink of releasing AI agents, that will transform the way we handle complex tasks on our devices.

These agents, still under wraps regarding their launch timeline, promise to automate tasks that have traditionally required human intervention, could be the thing that reshapes the job landscapes in certain sectors.

Imagine an AI capable of transferring data from documents to spreadsheets, filling out and processing expense reports, or managing entries into accounting software.

That level of automation and more already exists. It allows the AI to perform tasks just like a human – mouse clicks, cursor movements, and text input across various applications.

Up until this point, communication between AI and other applications has been by programmatically developed functions and structured Application Program Interfaces (APIs).

This new breed of agents wouldn’t need that. It can simply learn and navigate through the web, autonomously devising and executing strategies to achieve result for the end user.

This is going to raise all kinds of issues. How to get and secure permission for the AI to take control of devices. As these devices store huge amounts of private data, the issues of privacy and data security, where the files are stored, and how much of this private interaction can be used to train future AI models.

While the world awaits what OpenAI will do, this is not theoretical. There are actual working applications using agents already in the marketplace, one of which is the Rabbit R1 unveiled at CES this year.

I’ll be doing a special piece on this in ITWorldCanada.com as part of my Best of YouTube series. Watch for it in the next day or two.

Sources include: Android Authority

In 2023, ransomware attacks not only intensified but also demonstrated a strategic shift towards high-profile targets, including critical infrastructure sectors such as healthcare, education, and government. All this according to a new report from a firm called Chainanalysis.

The year saw a notable surge in ransomware activity, with attackers exploiting vulnerabilities in widely used software like MOVEit, affecting organizations from the BBC to British Airways.

This aggressive approach led ransomware gangs to amass over $1 billion in cryptocurrency payments from their victims, marking a record-breaking year for ransomware revenue.

The resurgence of ransomware in 2023, following a brief decline in 2022, underscores the adaptable and resilient nature of cybercriminals.

Despite efforts to curb their activities, and reports that fewer companies are paying ransoms, it appears that ransomware gangs have refined their strategies, focusing on more lucrative and impactful attacks. This shift has not only increased the financial stakes but also highlighted the significant operational and reputational risks for affected organizations.

Other key insights from the Chainalysis report include:

– The economic impact of ransomware extends beyond the ransom payments, with companies like MGM Resorts facing over $100 million in damages despite not paying the ransom.

– Law enforcement interventions, such as the FBI’s infiltration of the Hive ransomware operation, have shown some success in mitigating the impact of ransomware by preventing millions in payments.

– The ransomware ecosystem is evolving, with a rise in Ransomware as a Service (RaaS) models and initial access brokers facilitating easier entry for cybercriminals and expanding the threat landscape.

In 2024, the ransomware threat persists, with new variants and tactics emerging. The continued innovation by ransomware actors, coupled with the lucrative returns from their activities, suggests that ransomware will remain a significant challenge. The insights from 2023 highlight the importance of proactive cybersecurity measures, international cooperation, and the development of strategies to disrupt the economic incentives driving ransomware attacks.

Sources include: Chainalysis

In a decisive move to curb the rising tide of car thefts, the Canadian government has announced plans to ban the importation, sale, and use of the Flipper Zero device, along with similar gadgets identified as tools for vehicle theft. The Flipper Zero, a versatile pen-testing tool designed for experimenting with and debugging various hardware and digital devices, has been under scrutiny due to its ability to conduct replay attacks that can unlock cars, open garage doors, and clone digital keys.

Canadian Industry Minister François-Philippe Champagne highlighted the government’s concern over the sophisticated tools criminals use to steal cars, prompting this regulatory action. This announcement followed a national summit on combating auto theft, reflecting the government’s commitment to addressing the issue head-on.

Statistics Canada reports approximately 90,000 vehicles stolen annually, translating to a car theft every six minutes and resulting in $1 billion in annual losses, including insurance costs. The surge in car thefts has significantly impacted the national Crime Severity Index, with motor vehicle theft being a major contributing factor to its increase in 2022.

The government’s Innovation, Science and Economic Development (ISED) department is set to collaborate with law enforcement agencies to remove devices like the Flipper Zero from the Canadian market. However, Flipper Devices, the company behind Flipper Zero, argues that their device cannot be used to steal vehicles built after the 1990s due to modern security systems employing rolling codes. They assert that the Flipper Zero is intended for security testing and development, with precautions taken to prevent its misuse.

This ban comes amidst broader concerns over the use of technology in criminal activities, with Amazon banning the sale of Flipper Zero since April 2023 for being a card skimming device, following actions by the Brazilian National Telecommunications Agency to seize incoming purchases due to alleged criminal use.

Sources include: BleepingComputer

In a world increasingly filled with smart devices, a recent story from the Swiss outlet Aargauer Zeitung caused quite a stir with claims that hackers had launched a distributed denial-of-service (DDoS) attack on approximately 3 million internet-connected toothbrushes. This story, which quickly went viral, suggested damages amounting to millions of euros. However, the cybersecurity firm Fortinet, cited as the source of this information, clarified that the attack scenario was purely hypothetical, presented during an interview to illustrate a type of cyberattack. The confusion was attributed to a translation error.

Mainstream publications, including ZDNet, Tom’s Hardware, and The Sun, reported on the incident, demonstrating how easily a hypothetical scenario can be misconstrued as a real event.

It’s not fanciful. Smart devices are vulnerable and often not well protected and there have been documented cases of attacks on smart devices.

But in retrospect, one could ask if we all should have been more skeptical.

I saw this story and didn’t run with it, but not because of my journalistic genius.  I just didn’t see it as the best story to run with – it was a little sensationalist and I already had a better story with a humorous twist to end with.

So, I gave it the brush off.

So, I’m not going to question the journalists who did run with the story. I hope, however, that it will cause us all to be more alert, but at the same time, I also struck that we live in a world, where this story is actually believable.

Sources include: Axios and several others

Hashtag Trending goes to air five days a week with daily news and a weekend interview show that we creatively called – the weekend edition.

We love to hear from you. Send us a note at jlove@itwc.ca or drop us a comment under the show notes at itworldcanada.com/podcasts – look for Hashtag Trending.

Thanks for listening and have a Marvelous Monday.

The post AI agents will transform AI usage in the coming months: Hashtag Trending for Monday February 12, 2024 first appeared on IT World Canada.

AI in cybersecurity from a hands on tech pro: Hashtag Trending, the Weekend Edition features Greg Statton from Cohesity

AI in cybersecurity is not a new concept. Almost every security vendor has been working on it for years. In fact, AI was a godsend for cybersecurity.

In the olden days, like 5 years ago, you pretty much needed to know what a threat was, what it did – what it’s “signature” was to be able to detect it and deal with it.

Vendors set up intricate traps – honey pots – they monitored traffic, did everything to stay on top of all the threats.  And frankly, they did a pretty good job of it.

But the sheer volume of new attacks and methods is simply overwhelming. According to a Forrester Research report I found online for 2019, 80% of cybersecurity decision-makers expected AI to increase the scale and speed of attacks and 66% expected AI “to conduct attacks that no human could conceive of.”

Well, if you listen to my sister podcast, CyberSecurity Today, that’s one prediction that came true. The host, my colleague Howard Solomon has no problem finding new threats to talk about – and he goes to air four times a week.

So at one point, this idea that we can know everything that’s out there and detect it breaks down.

And then there’s another problem – the sheer volume of attacks is astonishing. 20 years ago, a security expert at one of the major banks told me that if their firewall went down for 10 minutes, they’d be overwhelmed with attacks. Can you imagine what it’s like today?

And not just volume, it’s the speed of the attacks. If they get in to your system, they often take their time and set up an attack, spreading throughout your network, so that when they do mount the attack, it’s massive, fast and overwhelming.

People can’t move or think that fast.