Page 22 of 55

Global ransomware threat surely will rise with AI, U.K.’s NCSC warns

Artificial intelligence (AI) is expected to increase the global ransomware threat over the next two years, U.K. cyber chiefs have warned in a new report published today by the National Cyber Security Centre (NCSC).

The report, entitled The near-term impact of AI on the cyber threat, concludes that AI is already being used in malicious cyber activity and will almost certainly increase the volume and impact of cyber attacks – including ransomware – in the near term.

The NCSC is part of the Government Communications Headquarters (GCHQ), an intelligence security organization that focuses on identifying, analyzing and disrupting cyber threats in the U.K..

Among other conclusions, the report suggests that by “lowering the barrier of entry to novice cyber criminals, hackers-for-hire and hacktivists, AI enables relatively unskilled threat actors to carry out more effective access and information-gathering operations. This enhanced access, combined with the improved targeting of victims afforded by AI, will contribute to the global ransomware threat in the next two years.

“Ransomware continues to be the most acute cyber threat facing U.K. organizations and businesses, with cyber criminals adapting their business models to gain efficiencies and maximize profits.”

Commenting on the findings, NCSC chief executive officer (CEO) Lindy Cameron said, “we must ensure that we both harness AI technology for its vast potential and manage its risks – including its implications on the cyber threat. The emergent use of AI in cyber attacks is evolutionary not revolutionary, meaning that it enhances existing threats like ransomware but does not transform the risk landscape in the near term.

“As the NCSC does all it can to ensure AI systems are secure-by-design, we urge organizations and individuals to follow our ransomware and cyber security hygiene advice to strengthen their defences and boost their resilience to cyber attacks.”

A release from the organization notes that The Bletchley Declaration, which was agreed on at the U.K.-hosted AI Safety Summit at Bletchley Park in November, also announced a first-of-its-kind global effort to manage the risks of frontier AI and ensure its safe and responsible development.

It goes on to say that analysis from the U.K.’s National Crime Agency (NCA) suggests that “cyber criminals have already started to develop criminal Generative AI (GenAI) and to offer ‘GenAI-as-a-service’, making improved capability available to anyone willing to pay. Yet, as the NCSC’s new report makes clear, the effectiveness of GenAI models will be constrained by both the quantity and quality of data on which they are trained.”

According to the NCA, “it is unlikely that in 2024 another method of cybercrime will replace ransomware due to the financial rewards and its established business model.”

James Babbage, director general for threats at the agency, said, “ransomware continues to be a national security threat. As this report shows, the threat is likely to increase in the coming years due to advancements in AI and the exploitation of this technology by cyber criminals.

“AI services lower barriers to entry, increasing the number of cyber criminals, and will boost their capability by improving the scale, speed and effectiveness of existing attack methods. Fraud and child sexual abuse are also particularly likely to be affected.”

Meanwhile, authors of the NCSC report note that “while it is essential to focus on the risks posed by AI, we must also seize the substantial opportunities it presents to cyber defenders. For example, AI can improve the detection and triage of cyber attacks and identify malicious emails and phishing campaigns, ultimately making them easier to counteract.”

The post Global ransomware threat surely will rise with AI, U.K.’s NCSC warns first appeared on IT World Canada.

Cyber Security Today, Jan. 24, 2024 – The latest ransomware news and a controversy over alleged viruses in HP printer cartridges

The latest ransomware news and a controversy over alleged viruses in HP printer cartridges.

Welcome to Cyber Security Today. It’s Wednesday, January 24th, 2024. I’m Howard Solomon, contributing reporter on cybersecurity for ITWorldCanada.com and TechNewsday.com in the U.S.



 

There’s a lot of ransomware-related news today:

A company that provides water management services to 550 U.S. and Canadian municipalities was hit ransomware last week. Veolia North America says some of its software applications and IT systems were affected. Some customers faced delays in paying bills online because back-end systems were taken offline until they could be restored. However, the company says personal data of an unstated number of persons may also have been stolen.

Australia, the U.S. and the United Kingdom have sanctioned a Russian hacker they say is responsible for the 2022 ransomware attack against a major Australian health insurer. Data on 9.7 million current and former users of Medibank’s services was copied and then released on the dark web. Under the Australian sanctions it’s a criminal offence to provide financial assets to or handle assets of Alexander Ermakov. Under the American sanctions all property and interests in the property of Ermakov have to be blocked and reported to Washington.

A Canadian hospital is finally upgrading its digital records system after a ransomware attack last fall. Bluewater Health of Sarnia, Ont., announced this month it is switching to Oracle Cerner for its patient records. Its existing Meditech system was hacked in October. According to the Globe and Mail, the hospital committed 10 years ago to replacing Meditech. The hospital is one of five southwestern Ontario facilities that shares an IT services provider that was hacked. The others already use Oracle Cerner but the ransomware gang could only get into Bluewater Health’s Meditech platform.

Aercap Holdings, an Irish-based aviation leasing company, suffered a ransomware attack last week. In a filing with U.S. Securities and Exchange Commission the company says it now has full control over IT systems. It’s investigating how much if any data was stolen.

On Monday’s podcast I reported a data centre in Sweden had been attacked last week. The company that owns that facility now says this was a ransomware attack by someone deploying the Akira ransomware strain. Agence France Presse quoted a government spokesperson saying IT services of more than 120 government agencies were impacted. So were some retailers.

Palo Alto Networks has issued a background report on the BianLian ransomware gang. Defenders may be interested in the tactics and indicators of compromise listed in the report.

If you had any doubts, ransomware really did hit records last year. According to the year-end numbers compiled by the NCC Group, there were 4,667 ransomware attacks in 2023. Will the trend continue this year?

Splunk has patched several vulnerabilities in the Enterprise version of its network monitoring platform for Windows. One covers a deserialization of untrusted data issue.

HP has stirred controversy over its decision to brick its printers through a firmware update that prevents machines from using third-party ink cartridges. Last week CEO Enrique Lores told CNBC it’s because a virus can be embedded in a chip that cartridges use to communicate with its printers. However, experts interviewed by Ars Technica are skeptical malware could be planted this way. Could the claim have something to do with a proposed class action lawsuit HP might face? Read the article and make your own decision.

Apple has released security updates for all of its operating sytems and its Safari browser. According to the SANS Institute, the updates fix at least 16 security issues — some of which are being actively exploited. There’s also a new feature that — if a user enables it — helps protect against a person who steals an Apple device and then tries to log in with a password or PIN number they’ve seen the owner use.

Finally, although it’s only January scammers have started sending email and text messages impersonating the U.S. tax man. The messages supposedly from the Internal Revenue Service are about a tax refund or tax refund e-statement. The goal is to get victims to click on a link and get them to either download malware or fill out a form and steal personal information. The IRS won’t ask for personal information through an email or text.

Follow Cyber Security Today on Apple Podcasts, Google Podcasts or add us to your Flash Briefing on your smart speaker.

The post Cyber Security Today, Jan. 24, 2024 – The latest ransomware news and a controversy over alleged viruses in HP printer cartridges first appeared on IT World Canada.

Hashtag Trending Jan.24- Mother of all breaches leaks 26 billion user records; Gen Z more likely to fall for cyber scams; Humanoid robots make their way to BMW’s auto plants

The mother of all breaches has leaked 26 billion user records, Gen Z are more likely to fall for a phishing or other cyber scam, humanoid robots are making their way to BMW’s auto plants and maybe we haven’t learned much in decades about the risks of using technology in the justice system.



 

All this and more on this “isn’t this privacy week” edition of Hashtag Trending. I’m your host Jim Love, CIO of IT World Canada and TechNewsDay in the US.  

Here is a 90 second summary for the podcast:

A massive data breach called the Mother of All Breaches has exposed an astounding 26 billion user records. Cybersecurity researchers discovered the 12 terabyte leak which contains personal information from past breaches of sites like LinkedIn, Twitter, and Tencent. While some records are likely duplicates, billions appear to be published for the first time. 

The compiled data could allow cyber criminals to launch damaging phishing campaigns, identity theft, and account takeovers. Records include names, passwords, phone numbers, addresses and other sensitive details from thousands of breached databases. Governments were also impacted.

Researchers aren’t sure who’s behind it but suspect a malicious actor given the huge scale. They warn consumers who reuse passwords to change them immediately. Other tips – use strong unique passwords, turn on two-factor authentication, watch for phishing attempts, and check if your information was exposed. With over 26 billion exposed identities, the consumer risk is massive.

If you are in the practice of not having unique complex passwords for each system you log into, with 26 billion records, chances are there is at least one occurrence of your favourite username and password.  

Best practice. Use a different password for each system. Longer is better. Make them difficult to guess. 

Two factor authentication wherever you can. 

Keep up on cybersecurity news by following our sister podcast Cybersecurity Today with Howard Solomon. You can find it on Google, Apple, Spotify – wherever you get your podcasts. Or at ITWorldCanada.com/podcasts.

Sources include: Cybernews.com

Contrary to expectations, Gen Z falls for online scams much more than older generations – 3 times more than baby boomers according to a recent survey by Deloitte. The first “digital native” generation uses the internet extensively across devices and platforms. But familiarity seems to breed complacency rather than caution.  

Gen Z reported higher rates than boomers of phishing scams, identity theft, romance fraud, and cyberbullying in Deloitte’s poll. The convenience of staying permanently logged into apps like Instagram makes security friction unappealing. But experts say reinforcing good habits needn’t limit internet use.

The types of scams target the behaviours of Gen Z whether online shopping, social media use or meeting people virtually. According to Social Catfish’s 2023 report, scam victims under age 20 lost an estimated $210 million last year compared to just $8.2 million in 2017 – as the generation processes life online, more exposure occasions more risk. Still, better design of platforms and privacy controls could reduce vulnerabilities.

Education focused on the incentives perpetuating scams may raise awareness effectively for youth. Rather than a choice between safety and convenience, a customized, empowering approach to online safety serves Gen Z best according to advocates.

Apologies to my Canadian listeners. I think this is one place where the Canadian Zed doesn’t work. 

Sources include: Vox

BMW is bringing in a new type of autoworker – humanoid robots from a company called Figure. These 5 foot 6 machines can walk, pick up objects with dexterous robot hands, and take breaks to recharge. 

It’s the first-time human-shaped robots will join auto manufacturing. While roles are still being defined, the robots’ mobility and flexibility are assets for automation. Industry analysts see it as a harbinger of increasing robotization to counter labour costs.

The deal has an initial phase identifying applications followed by deployment at BMW’s South Carolina plant. Further stages will explore how to integrate AI and other advances. Figure’s CEO says humanoids can handle most tasks people can within a few years.  

When auto manufacturers are asked how they will pay for the recent contract increases for auto workers, they are saying – more efficiency.

Certainly, BMW sees efficiency and productivity benefits from adding these humanoid robots. 

Warehouse robots are also emerging and some complex jobs like car production remain a stretch currently. Still robot capability is advancing. One day roles like equipment repair in risky areas may shift and even though mass replacement of humans is a long way off, these humanoid robots are a big first step.

Sources include: Axios

A false facial recognition match led to a devastating injustice for Harvey Murphy Junior. Macy’s, the U.S. department store’s security system incorrectly identified him as an armed robber – resulting in 10 days in jail.

Not only was he falsely accused, but he was sexually assaulted while being held in detention. 

The potential for these mistakes is known.  The technology’s accuracy depends heavily on image quality and database size. Despite police claims it’s only an investigative lead, this case shows the damage done once someone is identified as a criminal.

It adds to similar incidents where incomplete evidence paired with misplaced confidence in facial recognition tech, led officers to accuse innocent citizens like Murphy. While rare, the instances span race and gender. 

The FTC recently sanctioned RiteAid for enforcement practices stemming from their software’s mismatches. Still popularity grows among retailers like Macy’s seeking theft deterrence through instant screening of in-store cameras. 

Before we blame this all on a new technology, here’s another story that hit the air this week with  a similar theme. 

A software scandal has rocked Britain’s postal service. Bugs in a faulty accounting system helped convict over 900 postal workers of theft from 1999 to 2015. Innocent employees went to jail or paid to cover nonexistent shortfalls. 

The code defects were well known by the builder, Fujitsu, and postal authorities from the start. But this stayed hidden from courts and workers’ lawyers. 

93 verdicts have been overturned so far while victims await compensation. Fujitsu apologized this month for the injustice they enabled. Their executive admitted shameful, appalling concealment of exculpatory evidence from prosecutors. The fiasco fuels outrage at private prosecutions in the UK. Officials promise new laws to swiftly aid the falsely accused. But past harm haunts many victimized by rapid faith in flawed technology.

Police should be looking for corroborating proof before charges are laid, but critics say that everything is stacked against an accused person once they are brought under suspicion. 

And over the last 20 years, we still have issues that should be resolved before we let any algorithm or system be used without heavy scrutiny. 

The faith we seem to have in facial recognition and AI are just another reason to remember the phrase justice should be blind, doesn’t mean it should be blind to the risks of using technology.


Sources include: ArsTechnica and Washington Post

Hashtag Trending goes to air five days a week with a daily news show and every Saturday, we have an interview show called the Weekend Edition. 

We love your comments. Please let us know what you think. You can reach me at jlove@itwc.ca  or leave a comment under the show notes at www.itworldcanada.com/podcasts

I’m your host Jim Love, thanks for listening and have a Wonderful Wednesday!

 

The post Hashtag Trending Jan.24- Mother of all breaches leaks 26 billion user records; Gen Z more likely to fall for cyber scams; Humanoid robots make their way to BMW’s auto plants first appeared on IT World Canada.

Global tech spend set to grow a healthy 5.3% in 2024, says Forrester

Technology companies faced a difficult 2023 due to a range of issues, but this year looks far brighter, new findings from Forrester Research reveal.

Forrester is predicting that, after last year, where the overall technology spend growth reached only 3.9 per cent, improving economic conditions as a result of lower energy prices, abating supply constraints, and declining inflation will see the increase this year hit the 5.3 per cent mark and reach US$4.7 trillion.

In a blog about the findings, Michael O’Grady, forecast analyst, and data researcher Michael Kearney wrote, there is a “lot to be excited about when it comes to the technology market in 2024 – whether due to the rapid rise of the Asia Pacific market, huge demand for software, the wide-ranging possibilities of generative AI, and/or a growing need for green and digital innovation.

“In 2024, Forrester suggests that companies invest in technology that backs their long-term growth. Among their focuses should be software, generative AI (GenAI), and green and digital innovation, which will let companies be more adaptive and resilient by streamlining operations, providing the platform for future growth, and reducing enterprise risk.”

This year, Forrester is forecasting that:

Overall, the software market will grow 10.5 per cent, with commercial off-the-shelf software revenues increasing by 11.9 per cent. Meanwhile, demand for cloud services will remain strong, as witnessed by the cloud performance last year: Microsoft’s annual cloud revenues grew 27 per cent to surpass US$110 billion, Google Cloud grew revenues 26 per cent in the first nine months of 2023, and AWS had a more modest 13 per cent revenue increase.
IT services are expected to grow by four per cent, but, that said, Forrester said the outlook is uncertain: For example, Accenture, which expects only two-to five per cent growth for FY 2024, had double-digit growth in its cloud and security business in  FY 2023, but its consulting revenues only grew three per cent in constant currency – significantly more slowly than its 14 per cent growth in managed services.
Computer equipment will grow 3.6 per cent. Microsoft plans for capex spending on data centres and servers to support Azure’s forecasted 25 per cent revenue growth in the next year; its capex reached US$10.7 billion in Q4 2023. Microsoft, Google, and AWS will also optimize capex spend by extending the useful life of cloud servers and network equipment.

“To accelerate tech spend growth in 2024, tech firms will focus on developing new technology markets, the green economy, digital innovation, the re-configuring of chip supply chains, and 5G’s return on investment,” authors of the report note.

“As the tech market converges around key themes like cloud, AI, digital transformation, automation, e-commerce, and digital marketing, tech vendors will acquire or extend their reach to new markets and verticals, especially in software and IT services that see the fastest growth.”

As for the Canadian market, Forrester predicts that “tech growth in Canada will lag behind the U.S., as the federal government plans a 3.2 per cent reduction in science and technology budgets for 2024.”

The post Global tech spend set to grow a healthy 5.3% in 2024, says Forrester first appeared on IT World Canada.

Stop combining patches with new features, networking vendors advised

Networking vendors should avoid combining critical security updates with new features, to make patches easier to understand, prioritize, and implement, says an industry group, which also urges manufacturers to provide clearer details on their products’ lifespans.

The recommendations came in a white paper released Tuesday by the Network Resilience Coalition, a group of network hardware and software manufacturers, IT networking providers, and customers that is trying to improve the security of IT network hardware and software around the world.

The white paper proposes best practices for both product creators and buyers, to boost network security at a time of increasing cyber threats that are seeing not only record numbers of data thefts and ransomware attacks, but also networks knocked completely offline.

In particular, Matt Fussa, Cisco Systems’ chief trust officer, told a press conference accompanying the release of the report, the coalition wanted to address the problem of threat actors exploiting vulnerabilities that manufacturers had issued patches for.

The coalition is confident that increasing the transparency of software updates and having more secure application development processes “will yield substantial benefits in the U.S.” and other nations.

“I’ll make a prediction,” he added: “A lot of the suggestions you see in this paper in three years will be requirements in law both in Europe and the U.S.

“The time to start adopting these practices is now. The time to build a better software development practice, the time to automate patching, the time to adopt machine-readable threat and vulnerability information and consume readable patching information is now.” But, he admitted, “it’s going to take years to adopt this across the economy.”

Still, he added, “rather than looking at this as something we can take in stride, I encourage you all to think about doing this with urgency. Deploying [the NIST] Secure Software Development Framework with urgency, building and giving your customers a software bill of materials with urgency, and frankly, driving security with a sense of urgency because threat actors aren’t waiting.”

Failure to protect network infrastructure not only presents heightened business risks, but also poses risks to the technologies that our society relies on to function, the group said in a news release accompanying the report. “Too often, misconfigured or discontinued, end-of-life products are generating a massive attack surface for adversaries, and communication gaps between product vendors and service providers, as well as additional challenges,” the release says.

In addition to recommending manufacturers automate patching and provide more information on their products’ end-of-life status and level of support, the group also recommended vendors align their software development practices with the NIST Secure Software Development Framework to produce more secure applications, and that they consider participation in the OpenEoX effort, a cross-industry effort to standardize the way end-of-life information is communicated and to provide it in a machine-readable format.

But the group also said IT departments buying network products also can do their part to improve network security by:

• buying from vendors that are aligned with the NIST SSDF, that provide clear end-of-life information and that plan to provide separate critical security fixes;

• increasing cybersecurity vigilance through vulnerability scanning and configuration management on products they chose to rely upon outside of their support period;

• periodically ensuring that product configuration is aligned with vendor recommendations — and increasing the frequency of checking configurations as products age;

• and consider participation in the OpenEoX effort.

The patching dilemma was stated bluntly during a panel discussion accompanying the release of the report. “The problem is, there are still some customers that don’t upgrade” for whatever reason, said Carl Windsor, Fortinet’s senior vice-president of product technology and solutions. “I stlll hear from certain organizations they have a six-month upgrade window,” he added. “They’ll upgrade when they get to that window.”

Manufacturers need to learn why network administrators are reluctant to either patch or patch quickly, Windsor said. Until those problems are solved, he added — including finding ways updates can be installed with zero downtime — manufacturers can’t automate the installation of patches on network equipment. In the meantime, some manufacturers offer other solutions, he added, such as managed services that take products out of the data centre.

Eric Wenger, Cisco Systems’ senior director for technology policy, said separating features from security updates “may be complicated” for manufacturers, because it’s sometimes not clear if a change is a patch, a security update, or a security feature update. If manufacturers unbundle patches from new security features, customer networks may be at different states, which could affect a patch. “That will prove to be an interesting conversation” with customers, he said.

“Managing a network is a really complex task,” said Fussa. “The individual devices are endlessly configurable. They require lots of maintenance. and despite the best efforts of every software manufacturer and hardware vendor in the world, these will continue to be complex systems. The good news is there hope on the horizon” through partnerships like the coalition that work with vendors, customers and governments.

The post Stop combining patches with new features, networking vendors advised first appeared on IT World Canada.

AI adoption in Canada rising, but upskilling remains top barrier: IBM

AI adoption among large organizations has remained steady globally, while Canada saw an uptick from 34 per cent in April 2023 to 37 per cent in November 2023, a new study by IBM Canada found.

The company surveyed over 2,000 IT professionals in organizations with over 1,000 employees in Australia, Canada, China, France, Germany, India and many more countries.

In Canada, early adopters are leading the way, with 35 per cent of enterprises already working with AI with the aim to accelerate and increase investment in the technology. An additional 48 per cent of Canadian companies are still exploring using AI.

The increased accessibility of AI tools (46 per cent), the need to reduce costs and automate key processes (46 per cent), as well as the increasing amount of AI embedded into standard off-the-shelf business applications (34 per cent) are the top factors driving AI adoption.

However, despite the rise in adoption, AI investments are less likely to accelerate, notably as organizations struggle to find the right talent, the study highlighted. Limited AI skills and expertise (41 per cent) is, in fact, the number one barrier hindering successful AI adoption at enterprises both exploring and deploying AI.

Around one-in-five (21 per cent) organizations do not have employees with the right skills in place to use new AI or automation tools, and 17 per cent cannot find new hires with the skills to address that gap. Plus, only 25 per cent are currently training or reskilling employees to work with new automation and AI tools.

“Technology is a critical engine driving transformation across industries, but as the gap between the skills organizations need in order to deliver digital transformation and the availability of a workforce with those skills widens, the strength of this engine is at risk,” affirmed Deb Pimentel, general manager, technology, IBM Canada. “Some of the challenges companies face include lack of customization to organizations’ specific needs and goals, using a one-size-fits-all approach, ineffective ways of delivering the training, and limited opportunities to apply the skills in the real world.”

Upskilling becomes even more tricky when companies do not yet know what the best use cases of AI are, or when the executives themselves are not using it at all, affirmed Jeremy Shaki, chief executive officer of Canadian tech education company, Lighthouse Labs.

Added to that is the fact the tools and use cases are changing so rapidly that it makes it very difficult for most companies to know how exactly they should approach upskilling in the AI space, explained Shaki.

The dominant narrative, that AI will provide opportunities for companies to have less people also does not help, added Shaki, because a pragmatic employee should see that and consider how they can remain in the company by being the user of AI who makes other roles redundant.

“The real reason to upskill in AI is because of the value and growth it will provide companies,” he explained. “Jobs will change and adjust, but if AI at a higher level is bringing in better insights, predictions, and certainty for a business, it will allow that business to grow aggressively. In that moment, companies won’t be talking about layoffs, they will be talking about having enough people to service the opportunity AI is affording them.” 

Pimentel concurred that, with AI, new roles will be created, many more will be transformed, and some will transition away. But the main challenge for organizations is to be able to vocalize that.

She added, “This means organizations will have to think about providing people with the relevant skills to work with AI to accomplish goals faster than ever before. They will also have to think systematically about how to move people who have been freed from routine work by AI into roles that are more fulfilling and impactful to the business.”

Shaki agreed that companies should engage with education spaces to discuss where the use cases are the most valuable, and have custom training developed for their teams to immediately drive adoption. 

“Pairing the goals of employee adoption and company goal alignment is a powerful way of building the first real training in this space,” he said.

Canada has the right resources lined up  — talent, leading researchers and academics, investment by both global and Canadian organizations, and government commitment, said Pimentel, adding that a thoughtful plan is necessary to build up the strategic and trusted adoption of AI.

She advises the following:

Have a clear AI strategy – Canadian business leaders need to set clear AI strategies that define clear problems they want to solve, make sure they have the right data in the right place to drive those outcomes, overcome the skills gap with the right people and automation tools, and build in AI governance from the start.
Reimagine how work gets done – Look to automate the mundane and tedious tasks that take up precious time, so employees can focus on higher value projects. This will require organizations to have a POV on what skills are going to increase in demand and decrease in demand, and have the right training programs in place.
Ensure the technology is trustworthy and responsible AI – Any organization that wants to apply AI models needs to establish appropriate guardrails that ensure the AI in use is transparent, governed, and trusted. Ethical considerations must be addressed from the outset.
The post AI adoption in Canada rising, but upskilling remains top barrier: IBM first appeared on IT World Canada.

Coffee Briefing Jan. 23 – FedDev Ontario supports ventureLAB; Telus’s new plan for low-income seniors; Intuit says Canadians do not want financial advisors to be replaced by AI; and more

Coffee Briefings are timely deliveries of the latest ITWC headlines, interviews, and podcasts. Today’s Coffee Briefing is delivered by IT World Canada’s editorial team! 

Missed the last Coffee Briefing? We’ve got you covered.

FedDev Ontario invests $4.5 million in ventureLAB’s Hardware Catalyst Initiative

 

The Federal Economic Development Agency for Southern Ontario (FedDev Ontario) has announced an investment of C$4.5 million in Markham-based incubator ventureLAB.

The investment is targeted towards Hardware Catalyst Initiative, ventureLAB’s accelerator program tasked with helping Canadian hardware and semiconductor-focused companies grow and scale up to become globally competitive.

“This new investment in our Hardware Catalyst Initiative by FedDev Ontario will have a tremendous impact on our ability to continue to grow and scale these great hardtech companies from Canada, while also building a stronger knowledge-based economy,” said Hugh Chow, chief executive officer, ventureLAB.

The investment adds to the C$10.7 million that FedDev has provided in funding for the growth and expansion of HCI over the past years.

The expansion is expected to support 30 more companies, create and maintain over 170 high-quality jobs, and lead to the commercialization of 25 new products.

Cisco and OECD partner to build a knowledge hub on responsible use of technology

 

Cisco and the Organisation for Economic Co-operation and Development (OECD) on Well-being, Inclusion, Sustainability and Equal Opportunity (WISE)  have teamed up to build a knowledge hub that will gather people’s insights on digital well-being, as well as on the digital divide.

The partnership builds on existing research into digital well-being. It acknowledges that while digital technologies offer benefits like improved access to education and health information, they also pose mental health risks and safety concerns.

Cisco and the OECD will continue to conduct research aimed at helping users make informed decisions, empower individuals to navigate the digital landscape responsibly, and to promote a healthy relationship with emerging technology.   

“While we continue to strive for full digital inclusion around the world, we cannot do so at any cost. It is our responsibility to keep well-being top of mind, and this partnership will help us connect with people around the world to learn about their experiences with digital technology—how it influences their social connections, their jobs and work-life balance, and their physical and mental health. Co-building a model and better understanding the role technology plays in everyday life is fundamental to our work at Cisco, and to pursuing our purpose to power an inclusive future for all,” said Fran Katsoudas, executive vice president and chief people, policy and purpose officer, Cisco.

The partnership will launch its ‘Digital Well-being Hub’ in the second half of 2024.

Governments of Canada and British Columbia to bring high speed internet to rural communities in BC

The governments of Canada and British Columbia (BC) have jointly invested C$600,000 in two projects to bring high-speed internet access to more than 140 households in the communities of sḵelhp (formerly Saltery Bay) and Lund, British Columbia.

BC-based telecommunications company CityWest will be undertaking the projects.

“CityWest specializes in serving rural and remote communities, and we’re thrilled to bring improved internet services to even more communities in the qathet Regional District,” said Stefan Woloszyn, chief executive, CityWest. “These last-mile projects are crucial to ensure that all British Columbians have access to internet connectivity, allowing them to participate in the digital world.”

This funding is part of a 2022 agreement between the governments of Canada and BC to invest up to C$830 million to connect households in all remaining rural, remote and Indigenous communities throughout the province.

Bell Let’s Talk announces $1 million for mental health programs

 

Bell’s mental health campaign, Bell Let’s Talk has  announced C$1,000,000 in new grants from the Bell Let’s Talk Diversity Fund to support 10 additional organizations working to reduce the stigma of mental illness and increase access to mental health programs for members of Black, Indigenous and People of Colour (BIPOC) communities in Canada.

“We are excited to announce our latest Bell Let’s Talk Diversity Fund recipients,” said Mary Deacon, chair of Bell Let’s Talk. “These exceptional organizations are providing essential support and services in many diverse communities across Canada. The grants will help the organizations make a difference and create real change for people struggling with mental health issues.”

Since the launch of the fund in 2020, 49 organizations from across the country have received grants.

Telus expands Telus’s Mobility for Good program for low-income seniors

 

Telus has launched a new rate plan, C$35/month with 10GB of data, for youth aging out of care, low-income seniors, and government-assisted refugees, as part of the Mobility for Good program.

The program is currently supporting more than 21,000 low-income seniors, youth aging out of care, and government-assisted refugees across Canada.

The new plan joins the existing $25/3GB plan offering in the Mobility for Good program.

Both plans also come with data at 5G+ speeds, shareable data, unlimited Canada-wide talk, and unlimited data at reduced speeds per month with no contract, on bring your own device.

Canadians want their financial advisors augmented and not replaced by generative AI: Intuit

 

Nearly 70 per cent of Canadians want future financial tools to be a hybrid of human financial advisors and generative AI, a recent survey from Intuit revealed.

The human element is critical, as 53 per cent want financial advisors to be the main resource, with generative AI in a complementary role. And only seven per cent want financial advisors to be replaced by generative AI and other AI products.

One possible explanation is the uncertainties associated with new technologies. Seventy-two per cent, in fact, lack basic knowledge about how their data is gathered and used.

The key, Intuit said, is pairing GenAI tools with human advice and guidance.

However, the financial software firm also zeroed in on the importance of improving data education to increase the access and potential impact of purpose-built tools for managing common challenges.

Over 1500 Canadians aged 18 years and older were surveyed from July 14, 2023, to November 14, 2023 for this report.

More to explore

Responding to challenges of new tech, children’s rights among federal privacy czar’s priorities

Promoting Canadians’ fundamental right to privacy, addressing the privacy impacts of new technologies like artificial intelligence, and championing children’s privacy rights will be the priorities of the federal Office of the Privacy Commissioner (OPC) for the next three years.

SIM card swap led to takeover of SEC’s X account

The hacker who took over the U.S. Security and Exchange Commission’s account on the X social media platform this month did it by fooling a cellphone carrier into giving it control over an employee’s cellphone in a SIM card swap.

Ericsson and Telus partner to launch 5G standalone network across Canada

Ericsson has partnered with Telus to launch and optimize its 5G standalone (5G SA) network from coast-to-coast.

Most enterprises still at beginning of their AI journeys: Report

Talk about the endless possibilities and impact of artificial intelligence is rampant, yet a new report by Everest Group shows that the majority of enterprises (83 per cent) are currently only testing the capabilities of AI through pilot programs, or have adopted generative AI for one or more production-grade use cases.

Drilling down into the impact AI is having on data centres, climate change

Lost in all of the hype around how artificial intelligence (AI) advances are going to change everything from how people work to how they function is just how much electrical power it will take to make this happen, and, equally important, what impact that will have in addressing  legally binding sustainability mandates such as the Paris Agreement.

Samsung launches AI-powered Galaxy S24 series

For the first half hour of Samsung’s Galaxy Unpacked event Wednesday, one could be forgiven for thinking that it was a software launch, as speaker after speaker touted Galaxy AI, the company’s new set of artificial intelligence (AI) tools driving the Galaxy S24 series of devices.

Data Privacy Week: Get ready for tougher regulation

In 2023, regulators around the world stiffened or vowed to tighten their data privacy and cybersecurity laws. Expect more of that in 2024.

Channel Bytes January 19, 2024 – Are you one of Canada’s Top 100 solution providers; AML firm announces channel program; Toad Data Studio is now GA; and more

Staying informed is a constant challenge. There’s so much to do, and so little time. But we have you covered. Grab a coffee and take five while you nibble on these tidbits.

Listen to the latest episode of Hashtag Trending

Hashtag Trending Jan. 23- Microsoft accelerates efforts to power data centres with nuclear energy; Is RTO really better for productivity?; Deepfakes hit the New Hampshire primary

Listen to the latest episode of Cybersecurity Today

Cyber Security Today, Jan. 22, 2024 – the LockBit ransomware gang hits the Subway fast food chain, and this is the start of Data Privacy Week

 

The post Coffee Briefing Jan. 23 – FedDev Ontario supports ventureLAB; Telus’s new plan for low-income seniors; Intuit says Canadians do not want financial advisors to be replaced by AI; and more first appeared on IT World Canada.

Hashtag Trending Jan. 23- Microsoft accelerates efforts to power data centres with nuclear energy; Is RTO really better for productivity?; Deepfakes hit the New Hampshire primary

Microsoft goes nuclear, an Atlassian study debunks the idea that the return to office has better results, there’s a big gap between what AI can to in terms of eliminating jobs and what workers fear it can do – at least for now, deep fakes hit the New Hampshire primary and if AI kills the internet, it might be a murder suicide. 



 

All this and more on this edition of Hashtag Trending. I’m your host Jim Love, CIO of IT World Canada and TechNewsDay in the US.  

Microsoft is accelerating efforts to power data centers with nuclear energy. The tech giant just hired Erin Henderson, a former nuclear plant executive, to lead the push.  

Henderson spent 13 years at the Tennessee Valley Authority working on major nuclear sites. Now she’ll drive Microsoft’s small modular reactor and microreactor strategy.

Demand for data centers is booming, but grids are struggling to provide enough clean energy. So Microsoft is getting creative, even teaming up to train AI on nuclear regulations.  

The company has bought credits from Canadian utility OPG’s nuclear plants. And it signed a 24/7 deal with Constellation for a Virginia data center.  

Nuclear saw support at last year’s major climate summit COP28. But the industry also faces turbulence – a leading small modular reactor firm had a major project canceled recently.

Microsoft appears undeterred, charging ahead to develop next-gen nuclear. With grids maxing out, data centers need solutions. And companies like Microsoft have the scale to spark innovation.

Sources include: Data Center Dynamics

There’s been a number of stories of CEOs pushing employees back to the office, but is that working?

Despite the stories of employees being forced back, flexible work is gaining more acceptance, even with executives who have resisted it.  One study noted that  remote versus in office work numbers have stabilized at about a 50/50 split. But what works better? 

Atlassian, a company that has embraced remote work set out to find out the answer. They surveyed 5000 of their own employees and also 100 Fortune 1000 and 100 Fortune 500 CEOs. The key insight: 92 per cent of Atlassian’s staff say flexibility is critical for their best work. 

And 99 per cent of CEOs they surveyed now believe distributed work is the future.  

1 in 3 executives say mandatory office policies haven’t impacted productivity at their firms. They increasingly realize you can focus on how work happens, not where. 

And at Atlassian 91 per cent of the staff say that the ability to have remote work is one of the main reasons they stay with the company.

Atlassian’s head of remote work research Annie Dean isn’t surprised by the data. Past evidence shows forced commuting damages morale and retention. Workers want autonomy in location.

Dean says hybrid models just create an “illusion of choice” with their mandatory days. Creativity depends on management, not physical proximity. Maybe we’re finally moving past tired water cooler myths.  

The message from employees and CEOs is clear: help people succeed on their own terms. Trust and flexibility now look essential, even to formerly strict executives. Work can thrive whether you’re at home or HQ.

Sources include: CNN

To paraphrase Mark Twain, rumours of the death of our jobs may be somewhat exaggerated. 

A survey by a firm called Spokeo found 66 per cent of U.S. workers think AI could perform their jobs. 

Nearly 75 per cent are concerned about AI’s impact on their industry. 

But there’s optimism too – over 75 per cent believe AI will reduce workplace stress and shorten the workweek. 

Still, people see the threat to incomes in the near term. So that’s what this group of U.S. workers think.

But how much can AI actually replace? 

An MIT study dug into the actual feasibility of AI automation. It modeled the economics of visual AI across 800 occupations. 

The finding? 

This study found that only 23 per cent of U.S. wages are in roles where machine vision automation would be cost effective today. It would require major tech cost reductions to boost viability. Why machine vision? An analysis of jobs like bakery workers showed humans still do key visual tasks cheaper than deploying cameras and AI. 

Not that some jobs won’t be affected. AI replacements,areas like retail and healthcare show more potential. 

So while new AI tools create anxiety about jobs, the reality is automation has limits today on both tech capability and budgets.  

Worker surveys reveal high anxiety over being replaced by thinking machines. But detailed economic analysis finds most roles aren’t ripe for cost-effective automation yet. 

At the speed AI is developing, who knows what the answer will be a year from now. But today, humans still have an edge at most tasks due to the high hidden costs of AI systems.

Sources include: National Post and FoxBusiness 

_____

It’s started – a deepfake with Biden’s voice is used to subvert New Hampshire primary voting. 

New Hampshire’s presidential primary got hit with a concerning dirty trick this weekend. Voters received a robocall in Joe Biden’s voice, urging Democrats not to vote on Tuesday. It said to save your vote for November instead.  

The call said it was from the phone number of prominent Democrat Kathy Sullivan. She’s running a super PAC to organize a Biden write-in campaign, since he’s not on the official ballot per DNC rules.

Sullivan and state officials blasted the deception and apparent attempt at voter suppression. The state Attorney General is now investigating potential violations of law.

The use of what sounds like artificially generated audio impersonating Biden raises alarms about “deep fake” techniques spreading to campaigns. Sullivan wants the source prosecuted fully.

Biden’s team is exploring further actions in response. Senator Maggie Hassan hopes it instead drives higher turnout to back Biden. But no matter the impact, the dark political dirty trick signals new ethical issues as AI capabilities advance.

All of this happens on the day that 11 Labs, one of the best known firms in AI voice production officially became a unicorn – worth more than 1 billion dollars. 

Something tells me the genie isn’t going back into the bottle on this one. 

Sources include: NBC News and Reuters

And if video killed the radio star, will AI kill the internet? Or will it be a suicide?

It’s called model decay…

Researchers are warning that AI models could poison themselves by training on other AIs’ synthetic output. These models, at least for now, need vast amounts of data. And it turns out that they are training on data created by other AI models – what some have termed the “slime” that is killing the internet.

Some examples of this model decay? Elon Musk’s bot Grok plagiarized an OpenAI response, exposing how it had “learned” from OpenAI code. 

Amazon product listings are turning up with oddly named products called “OpenAI policy errors.”

The next step in model decay is model collapse. As AIs scrape more web data, including each other’s made up text, they lose touch with reality. Output quality declines.  

Many developers still deny these risks, but are they hesitant to admit flaws in promising new revenue generators?  With models using unfathomable training data, there may be no reversing the damage.

One academic says we’re past hoping AIs can tell human versus bot content apart. The models will keep soaking up more machine falsehoods. She warns the internet itself may burn from disinformation.

In the end, last year’s AI promise may this year become an unreliability nightmare. The tech could spread spam and lies faster than we can correct. And that may only accelerate as adoption grows. 

But before we predict the end of the world there are a few other data points to consider.  Sam Altman talked last year about being able to use “synthetic data” to train and AI, making them less reliant on having to do vast scraping of Internet data. OpenAI and others are courting reliable sources like news outlets to find more accurate info. And I’m doing a story this week in IT World Canada on how what is termed RAG – short for Retrieval Augmented Generation where companies can use the conversational ability of AI engines, but restrict the answers to well contained and accurate data sets. 

Watch this space.

Sources include: Analytics India 

Hashtag Trending goes to air five days a week with a daily news show and every Saturday, we have an interview show called the Weekend Edition. 

We love your comments. Please let us know what you think. You can reach me at jlove@itwc.ca  or leave a comment under the show notes at www.itworldcanada.com/podcasts

I’m your host Jim Love, thanks for listening and have a Terrific Tuesday.

The post Hashtag Trending Jan. 23- Microsoft accelerates efforts to power data centres with nuclear energy; Is RTO really better for productivity?; Deepfakes hit the New Hampshire primary first appeared on IT World Canada.

SIM card swap led to takeover of SEC’s X account

The hacker who took over the U.S. Security and Exchange Commission’s account on the X social media platform this month did it by fooling a cellphone carrier into giving it control over an employee’s cellphone in a SIM card swap.

Access to the account, the regulator, added, wasn’t protected by multifactor authentication at the time. It had been, the SEC said, “but was disabled at [the SEC] staff’s request.”

There was no explanation in the statement of why that happened.

“Once in control of the phone number, the unauthorized party reset the password for the @SECGov account,” the SEC said in a statement. “Among other things, law enforcement is currently investigating how the unauthorized party got the carrier to change the SIM for the account, and how the party knew which phone number was associated with the account.”

A smartphone needs a SIM card, which registers a wireless device to a carrier, to operate.  When a phone owner changes carriers or devices, the card is physically shifted from one device to another. However, customers can ask a carrier’s support staff — or, an enterprise’s support team — in person or over the phone to change the device a SIM card is registered to, because they have lost their device or forgotten its password.

Control over a victim’s smartphone is vital to hacking an account that uses the mobile device as part of multifactor authentication.

Threat actors rely on the gullibility of support staff for SIM swapping. The result is the threat actor can receive voice and SMS communications associated with the number.

Access to the SEC employee’s phone number occurred this way, the regulator emphasized in its statement, and not via SEC systems.

Once the attacker got control of the SEC X account, they made one post purporting to announce the Commission had approved spot bitcoin exchange-traded funds. That wasn’t true at the time, but a few days later the SEC announced certain financial platforms could carry bitcoin ETFs.

Among those investigating the incident are the SEC’s Office of Inspector General, the FBI. and the Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency.

Threat actors have used SIM card swap attacks for years as a way to get around multifactor authentication, sometimes to break into an organization’s IT network — the work of the Lapsus$ gang is a prime example — and other times — as in this case — to take over social media accounts to promote cryptocurrency scams.

This month, an individual or individuals has been able to take temporary control of several prominent X accounts, including ones belonging to Mandiant, the city of Peterborough, Ont., and a Canadian Senator, to pump crypto junk. SIM card swaps may not always have been the tactic in every case. An attacker could take over a social media account not protected with MFA by guessing or brute-forcing a password. In the case of Mandiant, the company admitted MFA had been turned off during a staff transition.

In 2022, the FBI issued a warning on the risks of SIM card swaps. It urged carriers to:

educate employees and conduct training sessions on SIM swapping.
carefully inspect incoming email addresses containing official correspondence for slight changes that can make fraudulent addresses appear legitimate and resemble actual clients’ names.
set strict security protocols enabling employees to effectively verify customer credentials before changing their numbers to a new device.
authenticate calls from third-party authorized retailers requesting customer information.
The post SIM card swap led to takeover of SEC’s X account first appeared on IT World Canada.

Drilling down into the impact AI is having on data centres, climate change

Lost in all of the hype around how artificial intelligence (AI) advances are going to change everything from how people work to how they function is just how much electrical power it will take to make this happen, and, equally important, what impact that will have in addressing  legally binding sustainability mandates such as the Paris Agreement.

As Forbes noted in an article released late last year, “simply put, data centres and edge networks enable the magic that emerges from AI applications. They do so by using high-performance computing (HPC) clusters, which are made up of multiple servers connected through high-speed networks that allow for parallel processing and fast training times.

“These hard-working machines require considerable power and, as a result, generate a lot of heat. Because of this data- and compute-intensive AI workload, the need for high-density infrastructure, led by high-density cooling and power, is emerging at a record rate.”

Andrew Eppich, managing director of data centre provider Equinix Canada, said the company believes that “AI can provide sustainability-related benefits such as optimizing consumption in energy-intensive sectors, modeling and analyzing large data sets for weather and climate-related issues, and image recognition for wildlife conservation, to name a few.

“But we also recognize that training these models and analyzing massive data sets will require intensive computing resources that consume energy. This is why Equinix is committed to designing, building, and operating highly efficient data centres utilizing clean and renewable energy for our operations and our customers’ workloads.”

The highly efficient data centre capacity, said Eppich, will be “foundational to mitigating the carbon impacts of advanced computing such as AI and machine learning (ML).”

Jim Kalogiros, vice president of secure power at Schneider Electric Canada, said there is an interesting dichotomy now in play in that “data centres are going to be critical to driving the future in terms of technological advancement, and that is going to come by way of AI for the most part in the next 10-15 years. The catalyst, though, is that is going to be increasing our consumption of electricity and increasing emissions, so how do we do this in a mindful way without impacting the greater good, or the environment, or the climate?”

Schneider Electric, he said, has developed analytical software that allows data centre operators to not only lower their energy consumption, but reduce their energy costs. “With AI and the predictive nature of our software, it will tell you, ‘during these times of the day,  you’re going to move your workload from those servers to this server, and it is going to reduce your energy consumption by X, which means you are going to get a carbon savings of Y.’

“If you look at the studies, AI compute is going to drive the power consumption story by four or five times, which means there are a multitude of areas that are going to be impacted. Do we have the power grid that is going to be available to support this growth? Do we have the equipment that is going to be able to support this growth? Do we have the cooling solutions that are going to be able to support this growth?

“Now, the great thing is that we are working at developing a lot of new software and  hardware to help drive this call of revolution that’s happening from an AI standpoint, but the benefit is that AI is also going to help itself by coming up with solutions to solve a lot of these problems. It is like a blessing and a curse. We are working with a technology that is almost self-curing to some extent, because it is going to tell us what it needs to do to become better.”

Still, Kalogiros said that, in the short term, “I think we’ve got some challenges that we really have to face, which is, until we get these generative AI (GenAI) and these technologies up and running and out of incubation and humming along, we’re going to have to solve the power issue, we’re going to have to solve the cooling issue and we are going to have to be able to do it in a pragmatic way.”

Eppich, meanwhile, said Canadian data centres, like their global counterparts, face challenges in transitioning to more sustainable practices. “One of the significant challenges is that Canada’s energy mix includes both renewable and non-renewable sources,” he noted.

“Ensuring that a data centre operates at the speeds and reliability that customers expect without compromising on sustainability is an important indicator of a company that has invested strategically in sustainable practices within their business models.”

To overcome the challenge and support a target of 100 per cent clean and renewable energy coverage globally by 2030, he said that “Equinix is taking steps to build our renewable energy portfolio. Power purchase agreements (PPAs) are long-term contracts between electricity buyers and renewable energy generators like wind and solar farms.

“PPAs are a high-impact way for data centres to procure renewables and add new renewable energy sources to local markets. In 2023, we rapidly scaled our PPA purchasing globally, increasing our agreements by 300 per cent over 2022.”

Kalogiros contended that, while the Paris Agreement forces “people to do the right thing and legislation definitely helps, I would say there is an incentive for the data centre community to (reduce emissions) on their own for a multitude of reasons.

“The net benefit of being able to implement solutions that are going to drive efficiencies into your facility is that they are not just going to help the climate, they are going to help your bottom line. That is the beauty of this whole story.”

The post Drilling down into the impact AI is having on data centres, climate change first appeared on IT World Canada.