Page 24 of 55

Hashtag Trending Jan.19-Impact of AI on employment headlines at Davos; New study shows how much data is shared with Facebook; Starlink announces pricey Gigabit internet

Where does Open Source fit into the global AI picture? Davos is abuzz with concerns about AI. A new study shows just how much data is shared with Facebook, Starlink announces Gigabit internet but it comes with a steep price, and your smart headphones might be raising eyebrows – literally.



 

All this and more in this edition of Hashtag Trending. I’m your host Jim Love, CIO of IT World Canada and Tech News Day in the US.

At this year’s World Economic Forum in Davos, a crucial question looms large: Will AI reshape the future of employment? The discussions, drawing top academics, business leaders, and government representatives, are centered on the potential impact of generative AI on job markets.

OpenAI CEO Sam Altman reassures that AI, in its current state, isn’t replacing jobs but enhancing productivity. It’s viewed more as a powerful tool that magnifies human capabilities, allowing people to perform their jobs better.

A PwC survey of over 4,700 CEOs reveals a split in perception. While 45 per cent believe their business models might not survive the rise of AI in the next decade, 60 per cent expect AI to make their companies more efficient, especially in tasks like email response, report analysis, and presentation drafting.

The International Monetary Fund predicts that up to 60 per cent of jobs in developed countries may be impacted by AI, with both high and low-skilled positions affected. While AI integration could enhance productivity for half of these jobs, the rest may see reduced labour demand, lower wages, and even job disappearance.

The discussions at Davos reflect a global concern about AI’s disruptive potential. While some, like Bill Gates, see AI as a path to greater productivity and reduced work hours, others, including the United Nations Secretary-General, warn of the technology’s social and human rights implications.

Sources include: The Register

Analytics India published a list of the top 7 AI apps on Hugging Face. 

For those who don’t know it, Hugging Face is an open-source data science and machine learning platform that serves as a hub for AI experts and enthusiasts. It allows users to host, collaborate on, and deploy machine learning models, as well as to train and run AI applications. Often referred to as the “GitHub of machine learning. 

The top 7 applications on the platform are an impressive showing of what is available as open source AI. 

Three of the top seven are what some might see as novelties. One is for the generation of 3D shapes. Another transforms pictures into Anime. Another generates comic books. 

But some of these are more serious and potentially powerful tools which are available to anyone. 

IP-Adapter-FaceID ensures consistent and accurate face generation by utilising a face recognition model to extract a unique face ID embedding from a provided portrait photo.

Int float/e5-mistral-7b-instruct is built on the European Mistal AI model, an impressive open source model that rivals results from ChatGPT. This application is used for creative writing tasks like composing poems, code, scripts, musical pieces, emails, and letters. 

Pharma Clip uses CLIP models, natural language predictor models, to help you investigate chemical compounds and their properties. It’s a tool for drug discovery and research.

Open Voice is purportedly a very sophisticated text to speech generator.

The point is that while we spend a great deal of time focused on proprietary models from OpenAI, Google and others, there is an increasingly, I can only call it, sophisticated set of open source offerings that are making their way into usage and Hugging Face is increasingly becoming a place to watch for open source AI development.

Sources include: Analytics India

A study by Consumer Reports and The Markup has unveiled the sheer magnitude of data sharing with Facebook by companies. For the average solo Facebook user an AVERAGE of 2,230 companies, and sometimes over 7,000, are involved in handing over personal information.

This research, involving 709 volunteers over three years, revealed that more than 186,000 organizations passed data about individuals to Facebook’s parent company, Meta.

It’s not just a handful of companies; it’s thousands, each contributing to the vast pool of information that Facebook collects.

For many users, the extent of this data sharing remains unseen and often unacknowledged.

The study does provide a link to a tool that I didn’t know about that allows you to download the information that Facebook has on you.  It might be interesting to see. 

There’s a link to the full study and the tool in the show notes at itworldcanada.com/podcasts.  And remarkably, you can download the study without giving up your personal information. 

Sources include: Consumer Reports

SpaceX’s Starlink is taking internet connectivity to new heights with its latest offering, the “Community Gateways.” Designed for internet service providers (ISPs), this program promises to deliver gigabit speeds to remote areas, albeit with a hefty price tag.

The program requires a substantial upfront investment of $1.25 million. In exchange, SpaceX provides not just a satellite dish but an entire facility capable of receiving up to 10Gbps broadband speeds from its fleet of satellites.

The ‘Community Gateways’ aren’t for average consumers; they’re aimed at ISPs seeking to expand high-speed broadband access in hard-to-reach areas. This business program is a strategic move to bridge the digital divide in remote locations.

Starlink’s first Community Gateway, built for the residents of Unalaska, an island near Alaska, is a testament to the program’s potential. Local ISP OptimERA is using the gateway to significantly enhance broadband for its customers, providing 10 gigabits of symmetric uplink and downlink throughput and maintaining over 99 per cent uptime.

By offering fiber-like speeds through satellite connectivity, Starlink’s Community Gateways represent a significant leap in providing internet access to underserved regions. While the cost is high, the impact on remote communities could be transformative.

Sources include: PC Magazine

Smart headphones might be playing a surprising role in what can only be called eyebrow transformations. A study by the International Beauty and Wellness Council (IBWC) found that 80 per cent of respondents reported significant changes in eyebrow shape and density, sparking curiosity and extensive research.

It turns out, the secret to fuller brows might just be sitting on your ears. The infrared sensors in smart headphones are suspected to stimulate hair growth, thanks to their proximity to the eyebrow area.

Josh Gordon from Geonode explains that the infrared light emitted by these headphones could be increasing blood circulation and stimulating cell activity in dormant hair follicles, leading to lush, full eyebrows.

While the survey suggests a fascinating correlation, it’s crucial to remember that more research is needed to establish a definitive cause-and-effect relationship. But just to be sure I’ll be wearing my headphones on the top of my head for a while – just in case.

Credit: Geonode

And that’s our show for today. Join us tomorrow for a great weekend interview.  I have the author of a new book called the Algorithm with award winning journalist and NYU professor Hilke Schellmann. It’s one of the most thought provoking books on AI that I’ve read. I hope you’ll like the conversation.

Hashtag Trending goes to air 5 days a week with a special weekend interview show we call “the Weekend Edition.” 

We love your comments. Send me a note at jlove@itwc.ca or leave a comment at the bottom of the show notes posted on itworldcanada.com

I’m your host Jim Love.  Have a Fantastic Friday.

The post Hashtag Trending Jan.19-Impact of AI on employment headlines at Davos; New study shows how much data is shared with Facebook; Starlink announces pricey Gigabit internet first appeared on IT World Canada.

A Q&A with Rubrik CEO and venture capitalist Bipul Sinha

Bipul Sinha did not become a successful entrepreneur, engineer and venture capitalist by following staid career moves and adhering to traditional business strategies or pursuing cool ideas. Instead, taking the opposite approach has allowed him to profitably carve out a career that combines all three vocations.

His assortment of skill sets no doubt played a role in Microsoft’s announcement in August 2021 that it had signed a strategic agreement with the data security firm that Sinha helped fund, co-founded and now runs as its chief executive officer (CEO), Palo Alto, Calif.-based Rubrik.

The agreement, which included an undisclosed equity investment in the company by Microsoft, saw the two organizations pledge to address what a release stated as “the rising customer needs to protect against surging ransomware attacks, which are growing 150 per cent annually.”

“Rubrik takes a Zero Trust approach to data management which follows the NIST principles of Zero Trust for everyone interacting with data,” it went on to explain. “This means operating with the assumption that no person, application, or device is trustworthy. To meet this standard, data must be natively immutable so that it is not modified, encrypted, or deleted by ransomware.

“Together, Rubrik and Microsoft will help enterprises manage hybrid and multi-cloud data security and defend against escalating ransomware threats.”

During a visit to Toronto last week, Sinha sat down with IT World Canada at Microsoft Canada’s downtown head office to discuss issues ranging from the importance of the Canadian market to the impact the generative artificial intelligence (GenAI) movement is and will have when it comes to combating the myriad of cybersecurity issues and challenges that exist.

“We have a special relationship with Microsoft, but we work with other hyperscalers, and we have partnerships with them as well,” he said. “But with Microsoft, we have really aligned our engineering teams, our product teams to doing joint product development and driving this vision of secure computation, secure applications.”

Below is an edited version of the rest of the conversation

ITWC:  First, what is the purpose of your trip?

Sinha: I am here to meet with our customers and partners and understand what is driving their priorities and how do we align our vision of cyber recovery and cyber resilience with them. As you know, prevention strategy around cyber is not working. You cannot prevent the unpreventable. Businesses have to have a strategy around how do they recover when the inevitable cyber attack happened and how do they continue to operate the business in the presence of cyberattacks and breaches?

ITWC: How important is the Canadian market to the company?

Sinha: In terms of the Canadian market, it is a developed economy with deep digital transformation that has happened. But with digital transformation, you have security issues. Security is like a tax to your digital economy. Whether it is nation-state actors, whether it is a bored teenager sitting in the basement and swinging the middle finger to large corporation, you could have many different scenarios. Businesses have to be ready for all scenarios to ensure that their services are up all up and running.

At the end of the day, digital economies’ success depends upon digital trust. Digital trust means that whenever I go to a business to access services, those services are up and running, otherwise I lose trust. Having data integrity, cyber recovery and cyber resilience helps businesses enhance and enforce their cyber trust and service their customers better.

ITWC: How big of a game changer is the AI juggernaut in your mind?

Sinha: Computing is all about productivity gains, and GenAI is the next generation of a platform that is evolving around productivity gains. And we see a clear cut productivity gain for an IT operations team to do the cyber work without being an expert on cyber. As you know, in North America, there are  over a million cybersecurity jobs open and there are not enough trained people on cybersecurity to fill those jobs.

So how do you increase the productivity of the operations team so that they can do cyber work? That was our vision of bringing the IT operations team and security operations teams together on a common platform.

We built Ruby, which is the generative AI companion for our Rubrik security cloud. And it helps the IT operations team identify a malware or a threat, is able to do threat hunting, quarantining, and do a successful cyber recovery, using a natural language interface where you do not have to know the nitty gritty of cybersecurity.

ITWC: The company history is an interesting one. How did it come about?

Sinha: As a venture capitalist, I always believed in going after a market that the cool kids were not paying attention to, which essentially means that you want to bet on a non-consensus market. If everybody knows that this market is going to be lucrative, there will be a lot of companies getting started, which means that the value creation will get diluted.

The cool kids were not thinking about backup and recovery. And there was an opportunity to reframe, re-platform backup and recovery into a data security platform to deliver cyber resilience.

The post A Q&A with Rubrik CEO and venture capitalist Bipul Sinha first appeared on IT World Canada.

Should the CIO be solely responsible for keeping AI in check? Info-Tech weighs in

In a recent webinar, research director at Info-Tech Research Group Brian Jackson explained how he thought it was surprising that IT workers think that the CIO should be solely responsible for AI.

The next most popular answer after that, he added, was “well, nobody.”

The research company surveyed 894 respondents who either work in IT or direct IT for its 2024 Tech Trends report.

“It’s early days for many organizations who are deploying AI, and that’s probably why we’re seeing these types of responses. But making the CIO solely accountable is likely not what you want to do,” said Jackson. “If AI is being deployed to drive business outcomes, then you have to get the business leaders involved.”

Info-Tech also examined how organizations that have already invested in AI or plan to invest in AI, which it refers to as “AI adopters”, compare to organizations that either do not plan to invest in AI or don’t plan to invest until after 2024, referred to as “AI skeptics”.

Only one in six AI adopters are going to be creating a committee that will be accountable, and one in 10 share accountability across two or more executives.

Jackson advises organizations to think about three key concepts when implementing a responsible AI model:

Trustworthy AI – Do people understand how it works, how it generates output, or what data goes into its training?
Explainable AI – Ability to explain how an AI model makes its predictions, its anticipated impact, and its potential biases
Transparent AI – Can we communicate the impacts of the decisions that are being made regarding AI, can we monitor the results and report on them, show people the negative aspects, and adjust accordingly.

Having guardrails in place would be even more critical as AI starts creating customer value directly, Info-Tech said.

AI will no longer be just complimentary to the core value of an e-commerce business or an entertainment business, such as when Netflix predicts what you’re going to watch next, explained Jackson.

“We’re seeing business models created where AI is the value that the customer gets out of the service,” he affirmed.

 OpenAI is a perfect example of that, but we also see firms like Intuit, which is retooling its whole platform around generative AI. Specifically, it released a custom-trained financial large language model it calls GenOS that sits at the center of the company’s operating system, and solves tax, accounting, marketing, cashflow, and many other personal finance challenges.

However, as much as it is valid to hold executives accountable for regulating AI, security by design would be equally critical, explained Jackson.

Every year, organizations are investing more in cybersecurity, and yet they continue to face more attacks than ever before.

“Somehow, we’ve created this industry where software vendors create the risk, yet the customers bear the cost mitigating it,” Jackson noted.

He added, “It’s becoming everybody’s job. I bet you’ve been through some sort of phishing, email testing or cybersecurity training from your own organization, no matter what your job title is. So how do we get out of the cycle of always spending more on cybersecurity? How do we start to shift the accountability for security back away from the users to the builders?”

In 2024, he pointed out, we will see the White House and the new National Cybersecurity Strategy put the onus on technology makers to prioritize security or mandate, for instance, internal and external testing of AI systems before release.

“The bottom line is – if you’re making new AI models, you don’t have a choice,” said Jackson. “We can’t afford to build fast and cheap today and pay the cost of vulnerability later. We need to build with security by design now. And if you’re on the other side of it – you’re a customer of these AI providers, you have more leverage.”

Another key trend that organizations looking to mitigate AI risks need to think about is their digital sovereignty, Jackson said.

Organizations can, for instance, update their robots.txt file if they do not want their website data to be used to train an AI model. 

However, you’ll need a lot more, he added, to keep your data locked down, with people using data to train open source models. Artists have been especially at the receiving end of the widespread mimicry by AI.

Many artists and organizations have already sought to protect their intellectual property with tools like Glaze from the University of Chicago, which puts images through a filter tasked to protect the style from being interpreted by an AI algorithm. 

The university is also developing another project called Nightshade which “poisons” the training data, rendering the outputs useless – dogs become cats, cars become cows and so forth.

“While we wait for the courts to make the rulings, maybe the law makers will catch up and introduce new laws that redefine copyright in this AI age, “said Jackson. “But for now, it seems like it’s open season on scraping your data and imitating your intellectual property. So to defend our digital sovereignty, we have to use technology against technology.”

The post Should the CIO be solely responsible for keeping AI in check? Info-Tech weighs in first appeared on IT World Canada.

Russian threat group spreading backdoor through phishing, says Google

A Russian-based espionage group known for stealing login credentials of government and military officials is also trying to trick victims into downloading malware.

Google’s Threat Analysis Group (TAG) says the attackers, known to researchers as ColdRiver, UNC4057, Star Blizzard or Callisto, has added to its arsenal by adding poisoned PDF attachments in phishing messages that lead to the installation of a backdoor.

It’s a warning to ColdRiver’s usual targets, which include high profile individuals in non-governmental organizations like think tanks, universities, former intelligence and military officers, NATO governments, and Ukraine.

ColdRiver often creates an online persona pretending to be an expert in a particular field or somehow affiliated with the target, Google says. The impersonation account is then used to establish a rapport with the target, increasing the likelihood of the phishing campaign’s success. Eventually the gang sends a phishing link or document containing a link.

“As far back as November 2022, TAG has observed ColdRiver sending targets benign PDF documents from impersonation accounts,” TAG said in a report today. “ColdRiver presents these documents as a new op-ed or other type of article that the impersonation account is looking to publish, asking for feedback from the target. When the user opens the benign PDF, the text appears encrypted. If the target responds that they cannot read the encrypted document, the ColdRiver impersonation account responds with a link, usually hosted on a cloud storage site, to a ‘decryption’ utility for the target to use. This decryption utility, while also displaying a decoy document, is in fact a backdoor, tracked as SPICA, giving ColdRiver access to the victim’s machine.”

SPICA was detected as early as last September, but Google believes it was used almost a year before that. It’s the first custom malware that Google attributes as having been developed and used by ColdRiver.

Written in Rust, this backdoor uses JSON over websockets for command and control. It steals cookies from browsers, allows the uploading and downloading of files, and lists contents of file systems.

The backdoor establishes persistence via an obfuscated PowerShell command which creates a scheduled task named CalendarChecker.

Google’s report includes the latest indicators of compromise.

Last week, the Reuters news agency reported that ColdRiver targeted three nuclear research laboratories in the United States in 2023: the Brookhaven (BNL), Argonne (ANL) and Lawrence Livermore National Laboratories (LLNL), according to internet records. They showed the hackers creating fake login pages for each institution and emailing nuclear scientists in a bid to make them reveal their passwords, Reuters said.

Microsoft has been among the cybersecurity companies trying to disrupt this attacker, which it calls Star Blizzard. In December it reported that the group was trying to improve its detection evasion capabilities.

The post Russian threat group spreading backdoor through phishing, says Google first appeared on IT World Canada.

Hashtag Trending Jan.18- Google Search quality declining?; Samsung taking on Apple by integrating AI; The end of self checkout

Google Search quality may be getting worse.  Samsung partners with Google to embrace AI after its move to number the number 2 spot in the smartphone market. Sam Altman says that we might be uncomfortable with new AI developments, self-checkout may be on its way out. And it turns out that incognito mode doesn’t mean you can’t be tracked. 



 

All this and more in this edition of Hashtag Trending.

I’m your host Jim Love, CIO of IT World Canada and Tech News Day in the US.

It’s not your imagination.

A recent study by German researchers has highlighted a significant issue with Google Search: it’s swamped with SEO spam. 

The study, conducted by Leipzig University, Bauhaus-University Weimar, and the Center for Scalable Data Analytics and Artificial Intelligence, focused on 7,392 product review queries across Google, Bing, and DuckDuckGo over a year. 

The findings? A deluge of low-quality content, particularly in product searches, is burying useful information. 

The researchers observed a constant battle between spam sites and search engines, with spam often winning the top spots in Google’s rankings. Despite efforts by search engines to remove spam, the impact is only temporary. 

The study noted a downward trend in text quality across all three search engines, with AI-generated spam expected to exacerbate the problem. The researchers call for more attention to this dynamic adversarial spam, which produces mass low-quality commercial content.

And what about the ads masquerading as search results?  Just asking…

Sources include: Mashable 

Samsung aims to reclaim its position in the global smartphone market, having recently fallen behind Apple with a big bet on integrating AI into its phones and moving up in price.

Samsung and Google have entered a multi-year partnership, integrating Google Cloud’s generative AI into Samsung devices.

The Galaxy S24 series, including a base model, a “+” version, and the high-end Ultra model, showcases varying features like larger screens, multiple camera lenses, and for the Ultra, a titanium frame. Pricing starts at $799.99 for the base model, with the Ultra at $1,299.99.

The S24 series stands out with its AI capabilities, offering a mix of on-device and cloud-based features. These include advanced photo editing, live translation, and summarization tools. 

The Samsung Google partnership will utilize Google’s Gemini Pro and Imagen 2 models, enhancing user experience with innovative features like screen-based search and access to Google’s top-tier Gemini Ultra AI model.

Samsung is placing its bet that AI can push them back to the number one spot they occupied for many years. 

Sources include: Axios

Google is revising the warning for Chrome’s Incognito mode, clarifying that data collection by Google and other websites still occurs in this supposedly private browsing option. 

This update aligns with Google’s move to settle a class-action lawsuit accusing it of privacy violations in Incognito mode. 

The new warning, currently in Chrome Canary (a developer build), states, “You’ve gone Incognito… This won’t change how data is collected by websites you visit and the services they use, including Google.” 

This change aims to educate users about the limitations of Incognito mode, which prevents data storage on devices but does not stop external tracking.

The update is significant as it addresses a common misconception about private browsing modes. While Incognito mode stops Chrome from saving browsing history, cookies, and form data, it explicitly mentions that downloads, bookmarks, and reading list items will be saved. 

Yeah, I thought incognito meant…incognito.  Silly me.

Sources include: Ars Technica 

OpenAI CEO Sam Altman said  OpenAI’s next big model “will be able to do a lot, lot more” than the existing models can.”

Altman also said,  AI is evolving much more rapidly than previous technologies that took Silicon Valley by storm. But he also conceded that the evolution and proliferation of OpenAI’s technology will require “uncomfortable” decisions.

What is uncomfortable? Altman said that while some ethical boundaries and norms, like extreme human rights violations are “out of bounds,… but he said,  “there are probably other things that I don’t personally agree with, but a different culture might. … We have to be somewhat uncomfortable as a tool builder with some of the uses of our tools.”

Hands up if you understand what that means. He had me at uncomfortable.

Altman also highlighted the potential for AI to transform knowledge work and accelerate scientific discovery. 

Reflecting on his brief ousting as CEO, Altman discussed internal debates over balancing growth with responsible technology use. He defended OpenAI’s content licensing deals and addressed the controversy with the New York Times over copyright infringement. 

Sources include: Axios

The era of self-checkout kiosks in retail stores might be on the decline. Initially hailed as a futuristic solution, these kiosks have turned out to be more problematic than beneficial, both for consumers and retailers. Major retailers like Target and Walmart are scaling back or removing these systems. Target has limited self-checkout to ten items or less in some stores, while Walmart has removed them entirely from certain locations. 

The primary issue with self-checkout is theft. It’s not only easier to steal from these machines, but shoppers often end up stealing unintentionally due to the complicated nature of the self-checkout process. 

A Lending Tree survey found that one in five shoppers accidentally stole items during self-checkout, and one in seven did so intentionally. 

Despite their high installation costs, self-checkout kiosks have not delivered the expected reduction in overall expenses. 

While 60 per cent of consumers in 2021 preferred self-checkout, frustration and negative experiences are leading to a growing disenchantment with these systems.

Sources include: Gizmodo  

Hashtag Trending goes to air 5 days a week with a special weekend interview show we call “the Weekend Edition.” 

We love your comments. Send me a note at jlove@itwc.ca or leave a comment at the bottom of the show notes posted on itworldcanada.com

I’m your host Jim Love.  Have a Thrilling Thursday!

The post Hashtag Trending Jan.18- Google Search quality declining?; Samsung taking on Apple by integrating AI; The end of self checkout first appeared on IT World Canada.

CISOs are both anxious and see opportunities: Report

Chief information and security officers both have feelings of anxiety and see opportunity as the new year starts.

That’s the summation of the analysis done by IANS Research and Artico Search in their State of the CISO 2023-2024 report. It’s an 18-page summary of interviews conducted last fall with 100 American and Canada CISOs, plus data collected from 663 CISOs in the middle of last year on compensation, budget dynamics, board engagement and job satisfaction.

It notes pressures on CISOs include the facts that many companies are pulling back cybersecurity spending because of the economy, cyber attacks are increasing, regulators are breathing down the necks of companies, and the rise of generative AI tools offer new opportunities for advanced threat detection and automation, but also pose new threats in themselves.

“In this rapidly evolving landscape, traditional CISO role characteristics may no longer suffice,” says the report. “This situation gives CISOs an unprecedented opportunity to argue for a place in the executive ranks. Furthermore, the increased security pressure on organizations gives CISOs more ammunition to influence leaders outside of their direct sphere of control.”

Most CISOs surveyed were either at the VP or director level. Source: IANS report

Among the findings:
Compared with 2022, CISO job satisfaction fell — a sign of unease with the status quo. The drop in satisfaction coincides with a growing share of CISOs considering a job change (75 per cent considering a change, up from 67 per cent in the previous study);
This may have something to do with lack of recognition. While 63 per cent of respondents said they have a VP or director-level position, just 20 percent are at the C-level;
CISOs seeking clear risk guidance from boards often don’t find it. Only 36 of the respondents said their board offered clear guidance on their organization’s risk tolerance for the CISO to act on;
One bright spot: There’s evidence that spending time enhancing leadership skills through external training pays off. CISOs who engaged in formal leadership training courses or one-on-one executive coaching programs earn more, with a difference of over US$200,000.

The report argues that the U.S. Securities and Exchange Commission’s updated cybersecurity reporting rules, and the increased exposure that CISOs face, call for strong collaboration between the CISO and company leadership, including the board. That includes regular and recurring CISO-board collaboration in the form of quarterly updates, tabletop exercises and the like.

For half of the respondents, this is the case at their organization. However, a quarter of the respondents said board access is limited to just once or twice a year. Twelve per cent said they meet with the board purely on an ad hoc basis. But 13 per cent said they never see the board.

“Even among companies with annual revenue exceeding US$10 billion — most of which are publicly listed firms — just 60 per cent of respondents said they meet with the board regularly,” says the report.  Director-level CISOs are the least likely to have quarterly recurring board engagement.

Related content: Advice to CISOs: Shut up and listen

The report warns that for CISOs to effectively communicate demands for risk guidance and budget needs with their board, they need:
business acumen, meaning the ability to understand corporate strategy and financial statements as well as the ability to frame risks in terms of possible economic impact on the organization;
and executive presence, which is the ability to be persuasive, direct and decisive with the board and C-suite.

Related content: Empathy is now a key skill CISOs need

The post CISOs are both anxious and see opportunities: Report first appeared on IT World Canada.

Canada Post announces shakeup: IT services group sold to Deloitte

Canada Post announced that its IT shared-service provider, Innovapost, will be sold off to Deloitte Canada.

As part of the agreement, Deloitte will deliver and support Canada Post’s day-to-day IT operational services.

“Today is the start of an exciting journey to transform Canada Post’s information technology model so that we can better meet the demands of our customers, particularly in the competitive parcel market,” said Doug Ettinger, president and chief executive officer, Canada Post. “This change not only enhances our strategic focus, it also ensures we have the world-class expertise in place to deliver results for Canadians.”

This transaction adds to the slew of IT contracts that private consultants like Deloitte have been gobbling up from the government, and which has been under scrutiny the last few months in the House of Commons.

Members of Parliament have, in fact, called out the beefy contracts given to system integrators like Deloitte, Accenture, IBM, PwC, and many others, while the IT systems of the government continue to suffer.

Plus, in last year’s budget, the government proposed scaling back spending on consulting, travel, and other professional services by 15 per cent of planned 2023-24 spending, which was expected to save C$7.1 billion over the next four years.

But the Canada Post shakeup also comes on the heels of years-long revenue struggles for the crown corporation. In the third quarter of 2023, the crown corporation recorded a loss before tax of C$290 million, while its cost of operations rose to C$26 million.

A detailed examination showed that Innovapost “was not providing the speed and agility needed to compete today and in the future”, Canada Post said in a release.

Last week, Canada Post also announced it was selling off its logistics division, SCI Group, to Montreal-based provider of third-party logistics services Metro Supply Chain. 

Metro Supply Chain provided no details as to what would happen to the 3000 employees currently at SCI Group.

The future of employees at Innovapost is also uncertain, as Canada Post said that the “majority of the organization’s talented employees will be integrated with Deloitte.”

Innovapost’s president and CEO, Franco Chirichella, will become Canada Post’s new chief information officer (CIO) and lead a team of former Innovapost leaders who will also transition to Canada Post in the new organization, or into other roles supporting the corporation’s IT transformation.

The sale and agreements with Deloitte Canada, which followed a comprehensive, multi-stage bidder selection process, will be finalized in the coming months, subject to customary closing conditions. Canada Post spokesperson Jon Hamilton told the Globe and Mail that further details will be released in public financial statements once the sale is finalized.

The post Canada Post announces shakeup: IT services group sold to Deloitte first appeared on IT World Canada.

Holidays are over, but don’t let employees’ guard drop over fake shipping emails

The December holidays are over, but don’t expect phony malware-filled shipping emails to stop being sent to your employees.

In fact, researchers at Cofense say in a report released today, these phishing messages threaten several industries all year round and only increase slightly during holiday periods.

These are messages with subject lines such as “Important Shipment,” and “Invoice attached,” with messages claiming to be from well-known package handling firms — including DHL, Maersk, and FedEx — about invoices, air waybills (AWB), and bills of ladings (BoL).

A typical shipping-themed phishing message sent to employees. Source: Cofense

The goal is to get an employee to download the supposed document — which is malware — or enter personal information.

The researchers did a three-year analysis, from 2021 to 2023, looking at phishing trends for this type of attack against several industries.

“Manufacturing stands out from the other industries as the most significant targeted industry in the three-year sample,” the analysis found.

“Despite the marginal increase during the holiday seasons, shipping-themed emails remain a consistent threat all year round, with significant volumes appearing in June, October, and November.”

After manufacturing, the top industries targeted were, in order, finance, insurance, metals and mining, and financial services.

The most common payload is the Agent Tesla keylogger, followed by FormBook, both of which are used for stealing data from infected computers. The third most common payload is malware that steals credentials.

The most popular delivery mechanism is Microsoft Office documents that try to exploit unpatched versions of the Office Equation Editor (CVE-2017-11882).

The second most popular way of delivering malware is through HTML files, through a technique called HTML smuggling, the report says. Infosec pros should note that usually this technique delivers credential phishing as attachments or via an infection URL embedded into the email. During the analysis it was seen that the total volume of HTML files and credential phishing were almost identical. This suggests that shipping-themed emails with credential phishing have a better chance of being delivered via an HTML file.

“Employees should always be prepared for when they receive a malicious email, whether personal or business, at any point in the year,” the report says. “Shipping-themed emails remain a significant year-round threat that may infect company assets and lead to more significant threats like ransomware if employees are not adequately trained.

“Practicing email security by detecting and reporting malicious emails all year round will decrease the likelihood of a malware infection or unauthorized access.”

The post Holidays are over, but don’t let employees’ guard drop over fake shipping emails first appeared on IT World Canada.

Cyber Security Today, Jan. 17, 2024 – Security updates issued for Atlassian, Citrix, VMware and Chrome products

Security updates issued for Atlassian, Citrix, VMware and Chrome products

Welcome to Cyber Security Today. It’s Wednesday, January 17th, 2024. I’m Howard Solomon, contributing reporter on cybersecurity for ITWorldCanada.com and TechNewsday.com in the U.S.



This episode is filled with news about security updates.

Last week I wrote a story on ITWorldCanada.com on the need to mitigate vulnerabilities in Ivanti’s Connect Secure and Pulse Secure VPNs and gateways. Some network administrators didn’t act fast enough. According to researchers at Volexity, who discovered the holes, as of Monday over 1,700 devices had been exploited. In its initial report Volexity said it found only one organization had been victimized. Now it says there’s evidence companies had been compromised as early as last December 3rd. The mitigations Ivanti urges will have to do until the company issues security updates. It’s important that administrators not only work to mitigate the vulnerabilities but also look for signs of compromise by a web shell.

Attention administrators of Atlassian products: A critical severity vulnerability has been discovered in Confluence Server and Data Server collaboration application that needs patching. It includes current and an out of date versions released before December 5th of last year, as well as version 8.45

In addition Atlassian released patches for 28 high-severity vulnerabilities in its products, including five in Confluence Data Center and Server, nine in Bamboo Data Center and Server and eight in Bitbucket Data Center and Server.

VMware has issued patches for its Aria Automation products. These close a critical access control vulnerability that could allow an authenticated hacker to remotely access organizations using VMware products. Aria Automation, previously called Cloud Foundation, streamlines the deployment of cloud infrastructure and applications.

Citrix is urging administrators to patch their installations of NetScaler ADC and NetScaler Gateway to close two vulnerabilities. One allows an attacker logged in with low-privileges to execute code, while the other would allow a denial of service attack. This alert applies only to customer-managed versions of these products.

Threat actors are actively exploiting a Windows vulnerability announced last November. That’s according to researchers at Trend Micro. The vulnerability allows attackers to bypass the protection in Windows Smart Screen. Attackers are exploiting unpatched Windows systems to install the Phemedrone information stealer. It targets web browsers and data from cryptocurrency wallets and messaging apps, takes screenshots and collects system information such as hardware, location and operating system details for further exploitation. It’s another reason why Windows patches need to be installed as soon as they are available.

Google has issued an update for Windows, Linux and Mac versions of the Chrome browser. The update, which will be rolled out over the next few days, includes four security fixes. An exploit for one of them is already out there, so IT departments have to make sure the update is installed fast.

Here’s more on browsers: Sometimes an application feature designed to benefit customers ends up being a security risk. That’s what happened with the Opera browser’s My Flow feature, which allows notes and file sharing between the desktop computer of a user and their mobile devices. Researchers at Guardio Labs discovered the feature would execute a malicious file from Opera’s file system that pretended to be a browser extension. This file would execute outside of the browser’s security confines. The developers of Opera were notified last November and they implemented the most critical part of a fix by removing problematic and insecure extensions and files from their servers. One lesson: Browser extensions can be easily created to steal data. Another lesson: Security has to be built into every app development workflow.

Any smart device — that is, a product that connects to the internet — has the possibility of being an entryway into a corporate IT network if security isn’t tight. The latest example is the Bosch BCC100 Wi-Fi smart thermostat used in buildings. Researchers at Bitdefender discovered a vulnerability that could let an attacker on the same network replace the device’s firmware with a rogue version. From there the attacker could do nasty things. The vulnerability was fixed in November. But, again, one lesson is security has to be built into every app development workflow.

Another company has allowed an unsecured database of sensitive information to be left open on the internet. According to security researcher Jeremiah Fowler, the database belonged to an American e-commerce provider. The database included photos of credit cards, drivers licences and other documents. How someone was able to create the database and leave access exposed isn’t explained.

Finally, the British Library’s catalogue of printed and rare books and other material is back online after the institution suffered a ransomware attack last October. However, for now the catalogue is available only in read-only format, meaning people can’t order items online. Full recovery of all IT services is still some time away. The Rhysida ransomware group stole and leaked some employee data.

Follow Cyber Security Today on Apple Podcasts, Google Podcasts or add us to your Flash Briefing on your smart speaker.

The post Cyber Security Today, Jan. 17, 2024 – Security updates issued for Atlassian, Citrix, VMware and Chrome products first appeared on IT World Canada.

Hashtag Trending Jan.17- Microsoft opens copilot to companies of size; Increased visits to piracy sites; Open source and online hacking tools fueling supply chain attacks

Microsoft drops the requirement for having 300 users or more and opens co-pilot to companies of any size, there’s a huge increase in visits to “piracy sites”, Open source code and online hacking tools are fueling growth in supply chain attacks and  Apple is now number 1 in smartphone sales.



 

All this and more in this edition of Hashtag Trending.

I’m your host Jim Love, CIO of IT World Canada and Tech News Day in the US.

Microsoft has unveiled Copilot Pro, a premium subscription service for its AI tool, priced at $20 per month. One writer described it as “if Clippy went to get his MBA.” 

Copilot Pro is targeted at power users and creators, offering an advanced version of the free tier. It provides a unified AI experience across devices, including priority access to OpenAI’s GPT-4 Turbo during peak times. A standout feature is the enhanced AI image creation with Image Creator, boasting faster performance and more detailed images.

Additionally, Microsoft announced the Copilot GPT Builder, allowing users to create their own Copilot GPT with simple instructions, although the launch date remains unspecified. For mobile users, a Copilot app is now available on Google Play Store and Apple App Store, aiming to streamline services across devices. 

In a significant move for small businesses, Microsoft 365 will integrate Copilot without the previous 300-seat purchase minimum, and the Microsoft 365 mobile app will include Copilot, facilitating direct exports to Word or PDF documents.

Sources include: Gizmodo 

Online piracy, a long-standing issue since the dawn of the internet, has seen a notable increase in recent years. A new analysis by MUSO, a U.K.-based anti-piracy analyst, and Kearney, a consultancy, reveals a 12 per cent rise in visits to piracy websites since 2019. In 2023, these sites attracted a staggering 141 billion visits, averaging 386 million daily.

The United States and India lead in piracy numbers, but per-capita rates are higher in Europe and the Asia Pacific. The analysis shows an average of 34 visits per person in Asia in 2023, compared to 26 in North America. Christophe Firth of Kearney views this rise as both a concern and an opportunity for media companies to commercialize pirate users and reduce revenue loss.

Andy Chatterley, CEO of MUSO, attributes this increase to the proliferation of platforms and subscription fatigue. Users, overwhelmed by multiple subscriptions across various platforms, find piracy services offering a more seamless viewing experience. This trend is particularly evident in the growing normalization of piracy among new internet users, with movie piracy in India increasing by 80 per cent between 2022 and 2023.

Anime content, representing 25 per cent of pirated content globally last year, highlights the demand-driven nature of piracy. Chatterley suggests that understanding the audience’s content preferences can be valuable for streaming services. He emphasizes that many who access pirated content are not doing so for financial gain but out of a desire to access specific content.

The potential for the industry to recover revenue lost to piracy is significant. Firth suggests that reclaiming even a quarter of this lost revenue could boost the video-on-demand market by 4 per cent, or $24 billion. Addressing factors like cost, availability, and viewer experience could steer users away from piracy sites.

Sources include: Fast Company

A new report highlights a concerning trend in cybersecurity: the increasing use of open-source code and legitimate hacking tools in software supply chain attacks. These attacks, once rare and complex, have become more popular among various malicious actors, from nation-state groups to lower-level cybercriminals.

In 2023, there was a notable rise in the sharing of open-source tools and resources among attackers, making it easier to execute these sophisticated attacks. This collaboration has effectively lowered the barrier to entry for software supply chain attacks, as reported by cybersecurity company ReversingLabs. The company found a 28 per cent increase in malicious packages across major open-source repositories in the first nine months of 2023 compared to the same period in 2022.

These malicious packages often contain code that helps hackers create backdoors, spread malware, and facilitate trojan horse attacks, while evading basic network monitoring tools. One notable campaign, “Operation Brainleeches,” involved phishing schemes based on packages hosted on the npm platform, complete with tools for email phishing campaigns.

The rise in supply chain attacks underscores the need for continuous auditing of technologies, scanning code for security flaws during development, and developing new software supply chain guidance. As malicious actors continue to evolve their tactics, these types of attacks are expected to remain a significant threat in 2024.

Sources include: Axios, Reversing Labs

In a remarkable shift in the smartphone market, Apple has clinched the top spot for the first time ever in 2023, according to market research firm IDC. Apple’s market share hit an all-time high of 20.1 per cent, marking a 3.7 per cent increase from 2022. This achievement is particularly notable given the higher price point of Apple products compared to its Android counterparts.

Samsung, previously leading the market, now trails at second place with a 19.4 per cent share, experiencing a 13.6 per cent decline in 2023. Other Android manufacturers like Xiaomi and Oppo also saw declines, with Xiaomi at 12.5 per cent and Oppo at 8.8 per cent. Interestingly, Transsion, a lesser-known brand dominant in emerging markets like Africa, emerged as a big winner, growing by 30 per cent and securing an 8.1 per cent market share.

Apple’s success is attributed to its strategy of selling premium devices, with its top-selling models being the high-priced iPhone 14 Pro Max, iPhone 14 Pro, and iPhone 14. 

In contrast, Android manufacturers typically lead market share by selling more affordable and mid-range phones. The average selling price (ASP) for Android phones was $250, while iPhones averaged $949 in Q2 2023. Apple’s dominance, despite its premium pricing strategy, underscores a growing trend towards high-end devices, propelled by aggressive trade-in offers and interest-free financing plans.

Sources include: Ars Technica 

Hashtag Trending goes to air 5 days a week with a special weekend interview show we call “the Weekend Edition.” 

We love your comments. Send me a note at jlove@itwc.ca or leave a comment at the bottom of the show notes posted on itworldcanada.com

I’m your host Jim Love.  Have a Wonderful Wednesday.

The post Hashtag Trending Jan.17- Microsoft opens copilot to companies of size; Increased visits to piracy sites; Open source and online hacking tools fueling supply chain attacks first appeared on IT World Canada.