Page 19 of 55

How attractive are our Canadian cities to cybersecurity professionals – and why does it matter?

Canada was the fifth most targeted country for cyber attacks in the world last year, according to the 2023 Blackberry Threat Report. These attacks hit our corporate and public infrastructure, and affect the livelihood and the lives of all Canadians.

Given the increase in threats, it is essential that Canada be able to attract and retain top cybersecurity talent. But how well are we doing at that?

Within that context, we should also be asking ourselves additional questions: How attractive are our cities to cybersecurity professionals? Which places are doing the best job? What can we all learn from that?

The Canadian Cybersecurity Network, Canada’s largest technology member network, in partnership with IT World Canada (ITWC), is looking to find out.

CyberTowns is a new research program which is conducting surveys and leveraging existing government and private sector data to discover which cities in Canada are doing the best job of welcoming and keeping precious cybersecurity talent in our country.

In this age of remote work, where workers have great choices about where they live, it’s even more important that we have a better understanding of what it takes to attract these essential workers. During the pandemic, we heard of a migration to smaller cities with a high quality of life. They offer access to nature, cultural resources, lower taxes, and some are investing in support for cyber security and learning, and in gathering places for tech resources.

Are these investments paying off?

CyberTowns will attempt to answer these and more key questions. The program will not only analyze data, but it will also recognize those municipalities that are most successful in attracting and retaining cybersecurity professionals.

Canadian cities with a population of over 100,000 have been the focus of the initial study, but there are plans to expand this as we move forward.

The CyberTowns awards will be presented during the Canadian Identity Summit (CIS) on April 30 in Ottawa. In addition to the awards, a report will be issued that shares the details of why some cities stood out from the rest, and what are they doing to attract, develop and retain talent in their communities.

Francois Guay, founder of the Canadian Cybersecurity Network, says communities that do this well will have the benefit of being the safest from a cybersecurity point of view. “Canada must attract and develop the best, and keep data in Canada to safeguard against additional threats that are outside of our control.

“We welcome corporate and civic support of this unique venture. Take the survey here: https://canadiancybersecuritynetwork.com/cybertown.”

To join the discussions leading up the awards, join ITWC on Mar. 6 for our next Technicity virtual event – Smart Cities are Safe Cities – where a special panel will discuss these issues.

And mark your calendar for April 30 in Ottawa, where we will present the awards and launch the full report. For those who can’t make it in person, IT World Canada will provide full coverage.

The post How attractive are our Canadian cities to cybersecurity professionals – and why does it matter? first appeared on IT World Canada.

Proposed Canadian AI law is like a race car without an engine, expert tells Parliamentary committee

The Liberal government’s proposed law controlling the use of artificial intelligence applications is like a badly built racing car, a computing expert has told a Parliamentary committee.

But instead of putting the proposed Artificial Intelligence and Data Act (AIDA) in a garage, Andrew Clement, professor emeritus at the University of Toronto’s faculty of information, told the Commons industry committee Wednesday that the government should start all over again, with proper public consultation including a wide range of Canadians.

Andrew Clement testified by video conference. Screen shot via ParlVu

Innovation Minister François-Philippe Champagne, the bill’s sponsor, “wants to make Canada a world leader in AI governance. That’s a fine goal. But it’s as if we’re in an International Grand Prix,” Clement said. “Apparently to allay the fears of Canadians, he proudly entered a made-in-Canada contender. Beyond the proud Maple Leaf and him smiling at the wheel, his AIDA vehicle barely has a chassis and an engine.”

“He insisted he was merely being ‘agile,’ promising that if you just help propel him over the finish line, all will be fixed through regulations.”

But, Clement said, as a previous witness testified, there is no prize for first place in AI oversight. “Good governance isn’t a race, but an ongoing learning project.”

Among the problems: The Innovation Minister would have “sweeping powers,” Clement said, which puts him in conflict with his job to advance the AI industry. And the proposed AI data commissioner for overseeing the law should be an independent officer of Parliament, he said, not someone who, as the bill proposed, would report to the Innovation Minister.

“With so much uncertainty about the perils and promise of AI, public consultation with informed expertise is a vital precondition for establishing a sound legal foundation,” Clement added. But while Champagne said his department held more than 300 meetings, by Clement’s count, 220 were with businesses, including 36 with U.S. tech giants. Only nine were with civil society representing Canadians.

“Canada also needs to carefully study developments in the E.U., U.S., and elsewhere, before settling on its own approach,” Clement said.

Asked by one MP if AIDA in its current form would protect Canadians, Clement replied “I would say not.”

AIDA demands businesses deploying “high impact” AI technologies to use them responsibly. In particular they would have to develop and deploy applications in a way that mitigates the risks of harm and bias. There would be criminal prohibitions and penalties for using data obtained unlawfully for AI development, where the reckless deployment of AI poses serious harm, and where there is fraudulent intent to cause substantial economic loss through its deployment.

Clement is the latest witness to call AIDA flawed and say it has to be sent back to the drawing board. The Information Technology Industry Council filed a brief telling MPs that more consultation is needed but also recommended wording changes. Lorraine Krugel, vice president for privacy and data at the Canadian Bankers Association, asked for “targeted amendments” to the CPPA.

Meanwhile the European Parliament is on track to pass its own AI law this year.

The post Proposed Canadian AI law is like a race car without an engine, expert tells Parliamentary committee first appeared on IT World Canada.

Hashtag Trending Feb.1-Software issues hit automakers; Poor performance linked to RTO mandates?; Microsoft continues to push Edge over Chrome

Software problems are hitting automakers hard, Tesla’s shares take a hit as Elon Musk’s compensation is reversed by a judge in a shareholder lawsuit, a study concludes that poor performance is more likely for companies that are forcing return to office and does your Chrome browser look different? It might be the old Microsoft switcheroo…



 

All this and more on the earn while you learn edition of Hashtag Trending. I’m your host Jim Love, CIO of IT World Canada and TechNewsDay in the US.  

General Motors (GM) is facing issues with bugs in the systems of its electric vehicles. These have led to a range of problems, both technical and operational, impacting customers, the company’s reputation, and its financial performance. 

Owners of affected GM EVs, such as the Chevrolet Blazer EV, have experienced various technical problems including flickering screens, looping error messages, and issues with charging. These glitches not only degrade the user experience but also raise concerns about the reliability and safety of the vehicles. For example, a software malfunction in a car can potentially lead to critical failures in vehicle operations, posing safety risks.

These are not only affecting customer satisfaction, they are having a big impact on the bottom line of the auto maker. GM’s decision to halt sales of the Chevrolet Blazer EV due to software issues directly affects the company’s revenue and market share. Additionally, GM recorded a $1.7 billion accounting charge related to the high cost of stockpiled battery cells, which it won’t be able to fully recover. 

Software problems have forced GM to delay the launch of several key EV models, including the Chevrolet Equinox EV, Silverado EV RST, GMC Sierra EV Denali, and Cadillac Escalade IQ. These delays hinder GM’s ability to compete effectively in the rapidly growing EV market.

GM isn’t the only company that is struggling with this transition. 

Sounds easy to say, huh? Every company is now a software company. 

Those of us who grew up in IT know all too well that building quality software on tight time frames ain’t easy. And we know all too well about what project delays can do. 

Looks like GM and other automakers are finding this out the hard way.

Sources include: Axios

Tesla’s shares took a bit of a dive when a Delaware court voided CEO Elon Musk’s $56 billion compensation package. 

The ruling, based on the lawsuit filed by a Tesla shareholder, concluded that Tesla’s board failed to demonstrate the fairness of the compensation plan or evidence of substantial negotiation with Musk. 

This decision led to a 3 per cent drop in Tesla’s share price in after-hours trading.

The 2018 compensation package, the largest in public corporate history, was pivotal in making Musk a centibillionaire. It gave Musk stock options, contingent on Tesla achieving specific market capitalization and revenue targets. 

The court case questioned the fairness of this package, highlighting Musk’s control over Tesla and the flawed process leading to the board’s approval.

Musk’s response to the ruling was critical of incorporating businesses in Delaware, and he suggested a poll about relocating Tesla’s incorporation to Texas.

But for the rest of us, the ruling highlights the challenges of ensuring fairness and transparency in executive compensation, protecting the rights of all shareholders, especially in high-profile, high-stakes situations like Musk and Tesla.

Sources include: CNBC 

They call it Nightshade. It’s a new tool developed by researchers at the University of Chicago, and it’s seen a remarkable uptake with 250,000 downloads in just five days. 

The tool is aimed at artists, and is designed to disrupt AI models that scrape and train on artworks without consent. 

Nightshade alters images at the pixel level, making them appear as entirely different content to machine learning algorithms. This “poisoning” of AI models can lead to the generation of inaccurate imagery based on user prompts.

The overwhelming response to Nightshade indicates a strong desire among artists to protect their work from unauthorized AI training. The tool’s popularity extends globally, reflecting widespread concerns over the use of unlicensed data in AI model training. Nightshade’s approach is to increase the cost of training on unlicensed data, making licensing images from creators a more viable option.

Following the success of Nightshade, the team, also known for their earlier tool Glaze, plans to release a combined version of both tools. Glaze, which has received 2.2 million downloads since April 2023, aims to protect an artist’s signature style from being learned by AI models. The combined tool will offer both defensive and offensive capabilities against AI model training on unlicensed artworks.

The project leader, Ben Zhao, has expressed surprise at the high level of enthusiasm for Nightshade and anticipates releasing an open-source version in the future. The team’s work highlights the growing tension between AI development and artists’ rights, emphasizing the need for ethical considerations in the training of AI models.

Sources include: VentureBeat

There’s a reason why one of my favourite phrases is that irony is dead. 

Meta, formerly known as Facebook, has argued against copyright protections when it comes to using online content for building AI models; it attempted to use the same law to protect its own AI model, Llama.

Meta’s argument to the US Copyright Office is that the vast amount of copyrighted text, imagery, and data used to train AI models, such as Llama, should not be protected under copyright law, considering it as “fair use.” This stance suggests that everything available on the internet is fair game for AI training purposes. 

But, when an initial version of Llama leaked online and was posted on GitHub, Meta invoked the Digital Millennium Copyright Act (DMCA) to demand its removal, asserting copyright over its own AI model.

Despite Meta’s efforts, the attempt to remove Llama from GitHub was unsuccessful. The GitHub user who posted Llama argued that the model’s specifications did not have sufficient originality to be copyrightable, as they were derived from works used to train Llama.

All of this from the company that makes billions by circulating everyone else’s content.

On a more serious note, the growth of AI may have finally force us to have a meaningful discussion about the balance between protecting intellectual property and fostering innovation in AI development.

Sources include: Business Insider 

And a couple of quick stories that caught my eye. I saw this one in Forbes and then looked up the study, and there’s a link in the show notes.

According to a recent research paper published by University of Pittsburgh, compelling evidence suggests that organizations are leveraging Return-To-Office mandates not to enhance firm value, but rather to reassert control and shift blame for poor performance onto employees. Contrary to the belief that RTO boosts company value, the study revealed that RTO mandates are more likely in firms with poor recent stock performance and have had no significant impacts on firm profitability or stock-returns.

You can check it out yourself.

And another story in Reuters noted that some of the big tech companies, Google, Microsoft, Meta and Amazon have taken a bit of a hit due to these companies’ investments in AI. It turns out that revenues are up, but so are costs and investors may be putting these companies in the penalty box. Alphabet (Google) shares fell by 6 per cent and that’s a lot. Wait til investors figure out how much Mark Zuckerberg has spent hoarding the world’s supply of GPU’s

Maybe this is why Microsoft announced that it’s put together a team to find ways to run AI in a less costly manner.  

Anyway, none of these companies will go broke and nobody will lose their job at the CEO level, but it points out that when hype takes over, there are going to be big swings in share prices in tech – and where have we seen that before?

Sources include: Reuters and the University of Pittsburg

Finally, 

If you think your Chrome browser looks a little different, maybe that’s because you shifted to Microsoft’s Edge without knowing it.  

How did that happen? Well, it turns out, according to Microsoft, that there is a bug that inadvertently might cause a switch of browsers for users of Windows 10 and 11. Now this came about because Microsoft had your best interests at heart – they wanted to simplify browser switching for you. 

Some of the more cynical among you might argue this incident reflects Microsoft’s strategy to push Edge and its services, including Bing, through less than clear system notifications and setup prompts. 

But what’s the big deal? Edge, utilizes the same Chromium engine as Chrome, and offers a similar browsing experience and a stronger integration of Microsoft’s ecosystem, from account sign-ins to Microsoft 365 applications.

You didn’t agree to it. Picky, picky, picky…

Seriously, we should always give clear consent to any change from our preferences. And we have to take Microsoft at their word that this is a bug, it is convenient that these types of bugs never seem to push people to Firefox.

And users are expressing some frustration at how pushy Microsoft is in trying to get you to shift over. Andrew Cunnigham, another tech writer complained in a recent post about being asked multiple times to shift his browser preferences. I can’t vouch for that; I use a Mac. 

And I’m not claiming that Apple is lily white pure on this either. Because for the last time, if I’d wanted Safari, I’d have chosen Safari. 

We wouldn’t tolerate this anywhere else. If instead of “do you want fries with that,” you never hear “here’s your fries you didn’t ask for. Don’t ask. It’s a bug.”

So it does point out the need for clear boundaries and user consent in software updates and changes.

Sources include: Ars Technica 

And that’s our show…

Hashtag Trending goes to air five days a week with a daily news show and every Saturday, we have an interview show called the Weekend Edition.  

We love your comments. Please let us know what you think. You can reach me at jlove@itwc.ca  or leave a comment under the show notes at www.itworldcanada.com/podcasts

I’m your host Jim Love, thanks for listening and have a Thrilling Thursday.

 

The post Hashtag Trending Feb.1-Software issues hit automakers; Poor performance linked to RTO mandates?; Microsoft continues to push Edge over Chrome first appeared on IT World Canada.

Industrial firms must pay more attention to OT cybersecurity, says vendor

American providers of critical infrastructure services still aren’t spending enough to protect their operational technology (OT) systems, says the head of a company that protects industrial internet-connected systems.

Some firms have acted, Robert Lee, CEO of Dragos Inc., told reporters during a webinar Tuesday. But he estimates less than five per cent of the world’s infrastructure has invested in OT visibility.

“We simply haven’t turned on the lights in the house to see what’s happening.”

One electricity provider told him it spends US$100 million a year on IT security, and just US$5 million on OT security, he said.

That’s understandable, he quickly added, because for years, boards and CEOs of firms with internet-connected industrial systems focused cybersecurity on enterprise IT networks, not realizing that didn’t include the OT side.

OT cybersecurity is unique because factory and industrial network communications and protocols can be different than on IT networks, so IT security solutions can’t merely be copied, Lee said.

What worries him is the possibility that more attack frameworks like Pipedream, which Dragos and U.S. cyber authorities discovered in 2022 and is attributed to a foreign government, may soon be within reach of threat actors with fewer resources than a nation-state.

Pipedream, which was found on a U.S. firm’s network, can manipulate a wide variety of programmable logic controllers (PLCs) and other industrial equipment, is highly scalable, reusable, and can cause damage in [almost] any OT system, Lee said.

Once deployed, there’s no way to stop it, he added. Pipedream isn’t like a vulnerability that can be patched.

“What concerns me is other countries are working on very similar capabilities,” said Lee, “and these capabilities will start proliferating to criminals.”

An example is the discovery earlier this year by Microsoft of a China-based group dubbed Volt Typhoon targeting critical infrastructure organizations — including communications providers, utilities, manufacturers, IT firms, and government departments — in Guam and the U.S. mainland.

This week, Reuters said the U.S. struck back at the IT infrastructure supporting Volt Typhoon.

Lee said Dragos has been watching Volt Typhoon for a while. “They consistently chose industrial targets and play the ‘low and slow game,’ where they get in and wait for the malware to be used when they want,” Lee said.

“We consistently see this as a pattern across the world, where adversaries want to have access to the operational technology portion of the critical infrastructure to be able to leverage it at the time and place of their choosing.”

What makes this kind of threat damaging is the fact that OT networks have moved from being customized for each environment to being automated and commoditized. That leaves them open to attacks whose damage can spread from merely one company to an entire industrial sector or geographic region, he said.

“For most companies in the United States that operate industrial infrastructure, the current reality is that growing complexity in automation means we are losing expertise in companies on the [OT] systems as a whole,” Lee said.

“We may just really understand [OT] subsystems. We may need to call in vendors and integrators and contractors and a bunch of other people to understand these systems of systems. What that means is something that can happen — the network can go down, the system can go down, physical destruction can take place, or a plant can go down — and we wouldn’t know why. That ability to do root cause analysis is only possible with a lot of preparation ahead of time.”

There has been recent progress in awareness, Lee admitted, particularly because the U.S. government is working more closely with industry, and publicizing the problem through Presidential executive orders and reports on Pipedream and Volt Typhoon.

“We are seeing win after win when governments do their part to use their unique capabilities and collaborate with the private sector, so we can use our [capabilities],” he said.

“If we can respect the fact OT is different from IT, we can elevate the discussion so executives and policy makers around the world can understand that reality, and how much we’ve under-invested” in identifying and responding to OT threats, he said.

With that understanding, “we can pull [together] a really powerful, really exciting group of asset owners and operators who give a damn about national security and local security” and, with experts in the private sector and government, “make it extremely costly and painful for adversaries to find success. That is what winning looks like, and it is absolutely doable,”

“But quite frankly,” he added, “we have a lot of ground to cover.”

The public has to understand why utilities and manufacturers are spending on OT security, Lee said. “The less [time] we’re debating on if we should do something, and the more [time spent] on executing on what we know right looks like, the better we’ll be.”

Separately, Kaspersky issued threat predictions for this year for the industrial control and OT sectors.

These include:

— ransomware will remain the No. 1 scourge of industrial enterprises in 2024;
— attacks on logistics and transport companies may become targeted not at the IT infrastructure supporting operations, but the vehicles themselves;
— politically motivated hacktivism along geopolitical fault lines will grow sharper teeth and have more destructive consequences;
— widespread use of “offensive cybersecurity” by companies and cybersecurity firms for gathering cyberthreat intelligence will have both positive and negative consequences;
— The ongoing and rapid automation and digitization of logistics and transport will lead to greater intertwining of cyber- and traditional crime, particularly in long-established criminal fields such as the theft of cars, maritime piracy and logistics fraud.

The post Industrial firms must pay more attention to OT cybersecurity, says vendor first appeared on IT World Canada.

Warning: Threat actors getting around some Ivanti mitigations

Cyber authorities in the U.S. and Australia have issued new warnings to IT administrators to take more action to protect Ivanti Connect Secure and Policy Secure Gateways. At the same time, Ivanti revealed that two new vulnerabilities for the devices have been discovered, on top of a pair revealed earlier this month.

The latest vulnerabilities are CVE-2024-21888, a privilege escalation vulnerability affecting Policy Secure, and CVE-2024-21893, a server-side request forgery vulnerability affecting supported versions of Connect Secure and Policy Secure Gateways.

Ivanti today issued a patch for Connect Secure (versions 9.1R14.4, 9.1R17.2, 9.1R18.3, 22.4R2.2 and 22.5R1.1) and ZTA version 22.6R1.3. that covers the new holes. More patches are coming.

“Out of an abundance of caution, we are recommending as a best practice that customers factory reset their appliance before applying the patch, to prevent the threat actor from gaining upgrade persistence in your environment,” Ivanti said this morning.  Customers should expect the reset process to take three to four hours.

The remaining patches for supported versions will still be released on a staggered schedule, Ivanti adds.

Australia’s Cyber Security Centre said this morning it is aware of reports that threat actors have developed workarounds to some mitigation and detection methods, leading to reported ongoing exploitation activity.

The Centre “strongly advises organizations operating vulnerable Ivanti Connect Secure and Ivanti Policy Secure products to conduct investigation and monitoring for potential compromise of systems,” the alert says. IT administrators should monitor authentication, account usage and identity management services, and consider isolating systems from any enterprise resources as much as possible.

The U.S. issued a similar warning on Tuesday.

“Threat actors are continuing to leverage vulnerabilities in Ivanti Connect Secure and Policy Secure Gateways to capture credentials and/or drop webshells that enable further compromise of enterprise networks,” the U.S. Cybersecurity and Infrastructure Security Agency (CISA) said. “Some threat actors have recently developed workarounds to current mitigations and detection methods and have been able to exploit weaknesses, move laterally, and escalate privileges without detection. CISA is aware of instances in which sophisticated threat actors have subverted the external integrity checker tool (ICT), further minimizing traces of their intrusion.”

If an organization has been running Ivanti Connect Secure (9.x and 22.x) and Policy Secure gateways over the last several weeks and/or continues to run these products, CISA recommends continuous threat hunting on any systems connected to — or recently connected to — the Ivanti device. Additionally, it said, organizations should monitor authentication, account usage, and identity management services that could be exposed, and isolate the system(s) from any enterprise resources as much as possible.

After applying patches, when these become available, CISA recommends that organizations continue to hunt their networks to detect any compromise that may have occurred before patches were implemented.

These warnings to take mitigation action come almost three weeks after Ivanti issued its first alert of an authentication bypass vulnerability (CVE-2023-46805) and a command injection vulnerability (CVE-2024-21887) in the devices.

Also today, Mandiant issued an update to its background blog on the vulnerabilities.  Mandiant has identified zero-day exploitation of these vulnerabilities in the wild, beginning as early as Dec. 3, 2023, by a suspected China-nexus espionage threat actor.

Mandiant notes that a threat actor found a way to get around Ivanti’s recommended mitigation, released Jan. 10, for the first pair of vulnerabilities. That bypass led to the deployment of a custom webshell. Mandiant believes the mitigation bypass activity is “highly targeted, limited, and is distinct from the post-advisory mass exploitation activity.” However, using Ivanti’s external integrity checker tool (ICT) successfully detected the presence of the new webshell.

Mandiant notes Ivanti’s external ICT should be used by IT administrators for reviewing logs, because it is more robust and resistant to tampering than the internal version.

The blog also outlines indicators of compromise.

The post Warning: Threat actors getting around some Ivanti mitigations first appeared on IT World Canada.

Cyber Security Today, Jan. 31, 2024 – A new ransomware strain found, and questions about the level of ransomware payments

A new ransomware strain found, and questions about the level of ransomware payments.

Welcome to Cyber Security Today. It’s Wednesday, January 31st, 2024. I’m Howard Solomon, contributing reporter on cybersecurity for ITWorldCanada.com and TechNewsday.com in the U.S.



A new ransomware strain has been circulating for almost a year. According to a researcher at Netenrich, the group calls itself Alpha. Its data leak site lists six victims. Three firms are in the U.S., two in the U.K. and one is in Israel. The group is relatively new and still in the process of setting up operations. Victims are sent a personal decryption key to log into a messaging portal where they can negotiate a ransom. The gang says victim firms can upload three encrypted files that will be unscrambled as proof the decryptor they buy actually works.

There’s evidence that fewer organizations hit by ransomware are paying up. Coveware, which acts for firms in ransomware negotiations, says the average ransomware payment dropped over 2023. In fact it went down 33 per cent in the fourth quarter compared to what was paid in the third quarter. This may be due to better IT defences and backups, allowing some victims to ignore payment demands — although by the count of other companies 2023 was a record year for successful ransomware attacks. It also may be that more organizations just don’t trust crooks to keep their promises that stolen data will be deleted. We’ll see if the trend continues.

Another report issued this week has conflicting data. The survey of security and IT pros done by Cohesity suggests that despite pleas by governments not to pay ransomware gangs, organizations haven’t discarded the option. More than 90 per cent of respondents believe their company would pay a ransom to recover data and restore business processes. Nine in 10 respondents said their organization paid a ransom in the last two years. Over two-thirds of respondents believe their organization would be willing to pay over US$3 million to recover data.

Almost half of cybersecurity leaders in financial institutions believe their firm has been successfully hacked without being detected. That’s according to a report from Contrast Security. It surveyed infosec leaders in financial institutions to find out the state of cybersecurity in the sector. Among the findings: Lots of attacks by threat actors trying to steal corporate information, lots of attacks involving the destruction of data and lots of attacks on application programming interfaces. The report suggests financial institutions have to up their defensive game.

Artificial intelligence is coming to Android device users. Google’s Bard AI platform will be used to analyze your Google Messages and become a personal assistant. But will this be a privacy problem — particularly because messages will be sent to Google’s cloud for processing. An article on Forbes.com raises interesting questions. There’s a link to it here.

Security teams have to invest more in automation and internal training to combat knowledge gaps, and on improving the visibility of their IT environment. That’s the conclusion of security vendor Exabeam, which commissioned a global survey of IT pros in eight countries. Over 90 per cent of respondents believed they had a good or excellent ability to detect cyber threats. However almost 60 per cent of respondents said they experienced security incidents in the previous 12 months so significant they required extra resources to remediate. Also, respondents think they are only seeing about 66 per cent of their IT environments.

Follow Cyber Security Today on Apple Podcasts, Google Podcasts or add us to your Flash Briefing on your smart speaker.

The post Cyber Security Today, Jan. 31, 2024 – A new ransomware strain found, and questions about the level of ransomware payments first appeared on IT World Canada.

Hashtag Trending Jan.31- Ransomware payments declining? ChatGPT leaking chat histories; UK law may ban Apple from issuing security updates worldwide



 

Hey out there. Someone wrote me yesterday to tell me that they had tried to pass on how to subscribe, but it was difficult to find Hashtag Trending – apparently a lot of similar names. 

Changing the name of the podcast is a big deal, but finding us isn’t. Just go to our page at itworldcanada.com/podcasts.  Look in any of the daily scripts and there are links that take you directly to us on Apple, Google or Spotify.  

Feel free to share a link to any of those pages with your friends who might want to subscribe. One click and they are there. And I hope I’ve said it enough – thank you for recommending us to your friends and colleagues. It’s working.

Ransomware payments may be on the decline. ChatGPT may be leaking information and no-one is quite sure why, Microsoft’s Future of work claims some huge gains in productivity – and some issues with accuracy. And…they are called Robot wranglers and they’re managing mischievous machines. 

All this and more this edition of, hey, robots have rights too version of Hashtag Trending. I’m your host Jim Love, CIO of IT World Canada and TechNewsDay in the US.  

According to a new report from ransomware negotiation firm Coveware, there has been a significant decline in the number of ransomware victims who choose to pay hackers. In the last quarter of 2024, only 29 per cent of organizations opted to pay a ransom to retrieve their stolen data and unlock their systems during a cyberattack. This figure marks a stark contrast to the first quarter of 2019, when 85 per cent of affected organizations were paying ransoms.

The average ransom payment in the fourth quarter of 2023 was approximately $568,000, which is a 33 per cent decrease from the third quarter. Coveware attributes this decline to several factors. Enterprises have strengthened their cyber defenses and have more robust data backups, enabling quicker recovery from attacks. Additionally, there’s a growing distrust among companies towards hackers’ promises to delete stolen data after receiving the ransom.

Ransomware has emerged as a top cyber threat for organizations of all sizes over the past five years. Government officials have been actively working to reduce the number of ransomware attacks targeting businesses, governments, and other entities. However, ransomware hackers are known for their adaptability and may simply change their tactics, so let’s not count them out just yet.

Sources include: Axios

A user of ChatGPT, Chase Whiteside, reported an alarming incident where he found chat histories from unrelated users in his account. These chats contained sensitive information, including unpublished research papers and other private data. OpenAI officials have stated that this issue resulted from Whiteside’s ChatGPT account being compromised, with unauthorized logins traced back to Sri Lanka. Whiteside, who logs in from Brooklyn, New York, expressed doubts about his account being compromised, citing the use of a strong, unique password.

OpenAI’s investigation suggests that the incident was not a case of ChatGPT leaking chat histories to unrelated users but rather a consequence of an account takeover. This situation highlights the lack of mechanisms such as two-factor authentication (2FA) or the ability to track IP locations of logins on the ChatGPT platform, which are standard security features on most major platforms.

The original suspicion that ChatGPT was leaking private conversations, including login credentials and personal details of unrelated users, has been refuted by OpenAI’s findings. However, the incident underscores the importance of maintaining robust security measures for online accounts and being cautious about sharing personal details in AI service queries.

This incident, along with similar experiences reported in the past, serves as a reminder of the potential risks associated with using AI services and the importance of safeguarding personal and proprietary data.

Sources include: ArsTechnica

Proposed amendments to the UK’s Investigatory Powers Act (IPA) could potentially ban Apple from issuing security updates worldwide, a move that Apple has labeled as an “unprecedented overreach.” This development raises significant concerns about data security and information privacy, not just for British citizens, but for tech users globally.

The IPA, enacted in 2016, already grants the UK government the power to issue orders to tech companies to build backdoors into their products to break encryption. Apple has been a vocal opponent of this, previously threatening to withdraw iMessage and FaceTime from the UK market rather than compromise end-to-end encryption.

The new amendments to the IPA could allow the UK government to prevent Apple from providing security updates to iOS if they interfere with the operations of UK security services. Apple argues that this could force non-UK companies to undermine the security of all users because of their UK user base. The company also points out that the Home Office proposes that the extraterritorial scope of the IPA should apply globally, regardless of a provider’s physical presence in the UK.

The proposed amendments have now moved to the next stage in the UK’s legislative process, first passing through the House of Commons and then to the House of Lords. The Lords, an unelected body, often provide a more considered response to legislation, potentially influencing the final outcome of these controversial measures.

Apple, backed by various civil liberties groups, has strongly objected to these new powers. They argue that the amendments would transform private companies into extensions of the surveillance state and erode the security of devices and the internet globally.

This situation highlights a significant conflict between government surveillance desires and the privacy and security of global tech users. The outcome of this legislative process could have far-reaching implications for tech companies and users worldwide.

I hear a Tom Petty song here – won’t back down. I’m not sure Apple can.

Sources include: 9TO5 Mac

Microsoft’s recent report titled “New Future of Work” acknowledges that AI can speed up certain tasks, like writing, by 37 per cent, but also notes downsides – a 19 per cent decrease in accuracy in work done by experts from Boston Consulting Group using large language models.

Microsoft claims its Copilot is “mostly neutral” in its effects on quality and touts it as a solution to AI-related problems. A survey of enterprise users with access to Copilot showed that 68 percent believed it improved the quality of their work, although this is based on perception.

However, since the announcement of Copilot Pro, a premium version of the OpenAI-powered LLM bot, there have been complaints about its effectiveness, pricing, and even why it exists. 

The report also mentions that LLMs are most helpful to less experienced workers.  

It also reveals that small semantic differences in writing prompts can lead to vastly different results. That’s why Microsoft’s Copilot Lab  is providing a collection of suggested prompts.

Microsoft’s vision of the future of work, heavily influenced by its AI investment, is facing regulatory scrutiny. The US Federal Trade Commission, the European Commission, and the UK Competition and Markets Authority are investigating whether the Microsoft/OpenAI partnership could lead to an anticompetitive situation.

This EU regulation thing isn’t going away, is it?

Sources include: YouTube and The Register

At a subsidiary of GE Appliances in LaFayette, Georgia, Scott Samples is pioneering a new profession: he’s a ‘robot wrangler.’ This new job has emerged as companies increasingly integrate robots into their operations, only to discover that these automatons sometimes need a bit of human guidance.

One notorious robot, nicknamed Blinky for its flashing lights signaling distress, is known for its mischievous antics. It often disrupts the smooth transfer of items due to its overzealous conveyor belt movements, leading to humorous exasperation among the staff. “Oh s—, not again. It’s him again,” they’d say, attributing a personality to the mechanical troublemaker. Blinky, unsurprisingly, had no comment on these allegations.

Scott Samples, the ‘robot wrangler’ at Roper, a GE Appliances subsidiary, is the go-to guy for robots that stray off course. The facility’s 25 robots, some resembling wheeled pumpkins, are programmed to follow digital maps and use advanced technology to navigate. Yet, they sometimes end up “lost like a child in the park” or awkwardly trying to hide under someone’s desk. When Samples receives a call about a wandering robot, he uses its cameras and sensors to locate and retrieve the wayward machine.

The human workers at the facility have named the robots everything from Herbie to Wonder Woman, generally coexisting peacefully with their automated counterparts. However, occasional standoffs occur when a robot and a human inadvertently play a game of ‘who moves first,’ leading to comical situations. “This thing is following me and will not let me by,” workers would complain to Samples, unaware of the technical reasons behind the robot’s behavior.

Sean Cusack, a robot engineer in Oakland, California, finds that explaining the robots’ roles isn’t too challenging. “People envision robots as these completely intelligent, Terminator-level things,” he said. In reality, they’re often quite silly. 

Jaci Story, working with Starship Technologies in San Francisco, shares a humorous anecdote about the robots’ unexpected quirks. While charging a robot, it suddenly blurted out, “Whoa, whoa, we have rights you know,” leading her to burst into laughter.

As robot wranglers like Samples and Rutenberg navigate this new landscape, they’re not only managing the robots’ technical needs but also fostering a harmonious relationship between man and machine. Their role is crucial in bridging the gap between traditional human labour and the automated future, ensuring that robots are seen as helpers rather than threats.

In this quirky world of robot wrangling, every day brings a new adventure, whether it’s dealing with a mischievous Blinky or reassuring a robot that, yes, “we have rights, you know.”

Sources include: Wall Street Journal

Hashtag Trending goes to air five days a week with a daily news show and every Saturday, we have an interview show called the Weekend Edition.  

We love your comments. Please let us know what you think. You can reach me at jlove@itwc.ca  or leave a comment under the show notes at www.itworldcanada.com/podcasts

I’m your host Jim Love, thanks for listening and have a Wonderful Wednesday.

 

The post Hashtag Trending Jan.31- Ransomware payments declining? ChatGPT leaking chat histories; UK law may ban Apple from issuing security updates worldwide first appeared on IT World Canada.

Canadian government investigating another hack at Global Affairs

The Canadian government is investigating what could be a major data breach at its foreign affairs department.

CBC News says there is an investigation into what it calls a prolonged data security breach on the internal network of Global Affairs Canada.

At least two internal hard drives, as well as emails, calendars and contacts of many staff members were affected, the news service says.

Some staff have been told they can’t work remotely because of the incident.

One government email to staff, seen by the CBC, says data of any staffer who connected remotely by virtual private network between December 30, 2023 and January 24th is at risk.

“Early results indicate there has been a data breach and that there has been unauthorized access to personal information of users, including employees,” Global Affairs said in a statement to IT World Canada.

“The Department is contacting those affected with mitigation measures to ensure that sensitive and personal information is secure. The incident has also been reported to Canada’s Office of the Privacy Commissioner.”

“An unplanned IT outage is currently affecting remote access to Global Affairs Canada (GAC)’s network in the country. The Department’s critical services and external communication channels remain accessible and operational. This partial outage was intentionally activated on January 24, 2024 to address the discovery of malicious cyber activity. Global Affairs Canada is working with IT partners, including Shared Services Canada and the Canadian Centre for Cyber Security (part of the Communications Security Establishment) to restore full connectivity as soon as possible.”

Shared Services Canada is responsible for consolidating and modernizing certain IT services across federal departments, including email, data centre, and network services.

On-site employee connectivity in government buildings is fully functioning, the Global Affairs statement said, allowing for normal computer/network access. “Employees working remotely in Canada have been provided with workarounds to ensure they remain operational. The Government of Canada deals with ongoing and persistent cyber risks and threats every day. Given its profile, Global Affairs Canada takes a proactive approach and employs a variety of security monitoring measures to detect and address potential risks. The Department is closely monitoring the situation and is conducting an investigation into the matter.

“We cannot comment further at the moment on any specific details for operational and security reasons.”

Global Affairs oversees the government’s foreign policy, and operates Canadian embassies and consulates around the world. Its minister is a member of the cabinet’s Global Affairs and Public Security committee, which not only deals with diplomatic and trade issues, but also threats and risks to the safety and security of the country.

Discovery of the incident comes almost exactly two years after Global Affairs revealed it had been compromised in a cyber attack. At that time, the Treasury Board of Canada Secretariat said the attack was detected on January 19, 2022.

According to The Hill Times, a department investigation after the attack concluded it was “very likely” Global Affairs would face another online threat that would have a “very high” impact.

David Shipley, head of New Brunswick’s Beauceron Security and co-chair of the Canadian Chamber of Commerce’s cyber council, said a key indicator of how serious this breach of security controls is will be how long the Global Affairs network is down. “The last time it happened, two years ago, they had a relatively quick recovery. If it’s a prolonged one [outage] then it’s a more significant compromise. That raises some interesting questions: Did they fully get them [the hackers] out [of the network] two years ago?”

The government needs to publicly explain this breach so other organizations can learn from the incident, he added.

The post Canadian government investigating another hack at Global Affairs first appeared on IT World Canada.

Retailers at critical juncture due to severe tech gaps: SOTI study

A new study released today reveals that the retail industry in Canada and elsewhere around the world faces major challenges as a result of consumers experiencing a major “disconnect between their shopping expectations and the in-store reality.”

The study, conducted by Mississauga-based SOTI, a provider of mobile and IoT device management offerings, concludes that while consumers “crave technology to improve their in-store shopping experience, those offered by retailers do not always meet expectations.”

An example of those expectations can be seen in the fact 45 per cent of those polled expect to be able to pick up an item ordered online from a physical store on the same day. Further, “74 per cent of global consumers expect to always knows the status of their orders, highlighting the need for efficient supply chain visibility.”

Based on interviews with 11,000 consumers from nine markets – Canada, the U.S., Mexico, the U.K., Germany, France, Sweden, the Netherlands. and Australia – conducted in September 2023, findings indicated that:

Security is a significant concern in the retail industry. More than three-quarters (76 per cent) of consumers globally express concerns about entering personal details online or through in-store devices, indicating a pervasive lack of trust in the data collection and payment technologies used in retail.
Security concerns extend to fraud, with 35 per cent of global consumers worrying about becoming a victim of financial fraud, and another 35 per cent expressing concerns about identity fraud.
Consumers cite challenges in-store such as lack of staff to assist with issues relating to self-serve machines (51 per cent of users), and as many as 35 per cent of users complain about Wi-Fi connectivity when using an in-store device.

During a press briefing held last week to discuss the findings, Stephanie Lopinski, vice president of global marketing at SOTI, said the company first launched a study into retail trends five years ago.

“During the pandemic, our research showed that customers went online in droves and retailers invested heavily in perfecting online shopping,” she said. “Fast forward to our 2024 report, the data we are seeing is that consumers are heading back in store, but they are noticing the tech available in stores is lacking the personalization they came to see as table stakes online.

“(This) report highlights that new technology is often poorly deployed and not fit for purpose. Consumers are frustrated. Batteries in tablets and in scanners in stores, they are dying. Self-serve checkouts are not easy to use, and consumers often need assistance.”

Lopinski went on to say that findings show, “there are no staff available to even address these device issues, leading to cart abandonment and frustration. Retailers need to focus on managing their devices and optimizing their tech investments to regain consumer satisfaction.”

Shash Anand, senior vice president of product strategy at SOTI, said it is “crucial to recognize that artificial intelligence (AI) plays a significant role in harnessing deeper intelligence from devices. AI-driven diagnostic intelligence and proactive support solutions empower retailers to identify and resolve issues before they impact the consumer experience.

“By integrating location, signal strength, and data speed with critical business information such as inventory levels and delivery status, AI can ensure that in-store hyper-personalization can replicate the seamlessness consumers expect from online shopping.”

Over the next three years, said Anand, the “focus should be on building trust, safeguarding data and providing seamless experiences that bridge the gap between online and in-store shopping.”

Canadian shoppers, like their counterparts around the globe, are now demanding real-time information, efficient product availability, and rapid delivery, in-store and online, a release from SOTI states.

The report indicates that 41 per cent of consumers will look elsewhere if delivery or pick-up of an item is more than two days away, and that 77 per cent expect to always know the status of their orders, highlighting the need for efficient supply chain visibility.

“When reflecting on the overall retail experience, Canadian respondents continue to expect change and see value in technology to enhance their interactions with retailers, but gaps between expectations and reality continue to jeopardize brand loyalty and sales,” said Anand.

“Looking to the future, retailers must focus on the technologies and infrastructure around them and ask how these applications, devices, and technology solutions are being managed, monitored and maintained.”

Intelligence offerings, he said, “can not only help you visualize your retail operations and entire supply chain – in real-time – but also allow you to uncover operational issues immediately by merging both business and device data, creating a holistic view of your operations both in-store and online.”

The post Retailers at critical juncture due to severe tech gaps: SOTI study first appeared on IT World Canada.

Canadian CEOs worried about economic outlook, but expect turnaround with AI: Report

Over the past year, an increasing number of companies have worried that they will not survive amid rapid technological change and growing economic uncertainties unless they reinvent themselves, PwC’s 27th annual global CEO survey found.

The report finds that artificial intelligence could be the key to reinvention, and consequently, to higher profit margins.

PwC interviewed 4,702 chief executives across 105 countries and territories, including 114 in Canada.

Forty-five per cent of CEOs said that their companies might not be viable in the next 10 years. This represents a 39 per cent increase from last year. A third (32 per cent) also suggested their businesses may not be around in a decade.

CEOs are also concerned about inflation, geopolitical conflict, and cybersecurity risks, as well as climate change, but the key area of concern remains the economy, with only 25 per cent of Canadian CEOs believing that the local economic growth will improve this year, compared to 44 per cent of global respondents who expect better times for their country’s economy.

A recent Capterra report also showed that the stalling economic growth rate in Canada would be the top factor influencing business goals.

“We are operating in a continued poly-crisis environment, further complicated by tough economic headwinds. Therefore, it is not surprising that Canadian CEOs are more pessimistic than their global counterparts when it comes to their outlook on economic growth,” said Nicolas Marcoux, CEO, PwC Canada. “While a soft recessionary landing may be anticipated, CEOs find themselves under increasing pressure to reinvent their organizations.”

On the bright side, the vast majority are taking action, mainly driven by the impetus of technological change and AI, the PwC survey indicated.

Many of them have already kicked off their generative AI journeys, with 36 per cent of Canadian respondents (versus 32 per cent globally) saying they’ve adopted the technology in the last 12 months. However, they continue to exercise caution, with most citing cybersecurity as a top risk, followed by misinformation, legal/reputational risks, and bias towards employees or customers.

For those who are optimistic about AI, upskilling, budget constraints and operational inefficiencies remain top barriers, the report highlighted.

Fifty-five per cent of Canadian CEOs, in fact, agreed that generative AI will require significant upskilling of their workforce in the next three years.

Additionally, they revealed that 44 per cent of the time currently spent on a range of work processes was inefficient.

“Reducing inefficiencies is one area where investments in technologies like generative AI can help,” the report reads. “And by engaging with employees to help them feel safe proposing new ways of doing things and giving them an active role in change and reinvention, CEOs can not only uncover opportunities to accelerate priorities like technology adoption, but also find even more solutions to the inefficient processes holding companies back.”

However, while investing in new software is also critical to reinvention initiatives, 56 per cent of Canadian decision makers end up regretting a software investment decision, with a third blaming unforeseen costs, Capterra noted in its 2024 Tech Trends survey.

The survey advises companies to drill down on four challenges before making a software investment decision:

Identifying the right technology
Security concerns
Staff acceptance and training
Compatibility with existing systems

Companies should also create a list of potential product vendors, gather information using diverse sources like software comparison websites, online reviews, and even generative AI tools such as ChatGPT.

PwC, on the other hand, advises Canadian companies to focus on resource allocation to enable reinvention initiatives.  This includes making tough calls about an organization’s assets and focusing on the benefits of looking beyond a company’s walls by embracing strategic partnerships, alliances, and ecosystems.

Canadian CEOs should also acknowledge the scale and the urgency of the challenges they face, and question the viability of their business models as well as the risks they are exposed to.

“CEOs who are more concerned about their organization’s long-term viability are doing more than others to adapt to today’s intense business pressures, which only heightens the need for Canadian executives to look at additional measures to spot emerging risks and hazards,” the PwC report said. “Those who do so will be better able to see the urgency to not just accelerate change and reinvention but also engage their teams and the whole organization in sustaining it.”

The post Canadian CEOs worried about economic outlook, but expect turnaround with AI: Report first appeared on IT World Canada.