Page 26 of 55

Cyber Security Today, Week in Review for Friday, Jan. 12, 2024

Welcome to Cyber Security Today. This is the Week in Review for the week ending Friday, January 12th, 2024. I’m Howard Solomon, contributing reporter on cybersecurity for ITWorldCanada.com and TechNewsday.com in the U.S.



This week IT World Canada announced a partnership with the Canadian Cybersecurity Network. In a few minutes Francois Guay of the network will be here to talk about how the partnership will benefit the cybersecurity community and to discuss the current job market for security professionals.

But first a quick look at some of the headlines from the past seven days:

The U.S. Securities and Exchange Commission became the latest major organization to have its account on the X social media platform hacked. The attacker was briefly able to post an official-looking message that the regulator had approved bitcoin exchange-traded funds. X says its IT system wasn’t breached. Instead it says the attacker somehow got account control through a phone number. That suggests the hacker was able to persuade a wireless carrier to swap the SIM card of an SEC employee’s cellphone, or persuade an SEC support staffer to change the cellphone’s access. X also says the SEC didn’t have two-factor authentication protection enabled on the account. So far this year Mandiant and a Canadian Senator are among those who temporarily lost control over their X/Twitter accounts.

Speaking of the SEC, the regulator got German software provider SAP to agree to pay US$100 million to settle charges that bribes were paid to officials to win business in several African countries, as well as Indonesia and Azerbaijan. SAP recorded the bribes as legitimate business expenses.

A decryptor for victims of the Babuk Tortilla strain of ransomware was released by researchers at Cisco Systems. Not only that, Dutch Police were able to arrest the crook behind this strain. The decryptor is available on the NoMoreRansomware site as well as from Avast, which has decryptors for several Babuk variants.

Much has been written about the 2008 compromise of Iran’s nuclear weapons development systems through the deployment of the Stuxnet worm. A Dutch news site this week claims a Dutch engineer was recruited by the country’s intelligence service to somehow deliver the malware on-site through a water pump. Is it true? It’s a mystery.

HMG Healthcare, a company that runs rehabilitation and long-term care facilities in Texas and Kansas, has acknowledged personal and medical data of patients and employees was copied in a hack last August. The company hasn’t said how many people are affected.

Finally, American mortgage lender LoanDepot was forced to take some IT systems offline this week following a cyber attack. It isn’t using the ‘r’ word, but the company says some data was encrypted.

(The following transcript has been edited for clarity)

Howard: Joining me now are Jim Love, publisher of IT World Canada and Francois Guay, founder of the Canadian Cybersecurity Network and the Canadian Cybersecurity Jobs portal. Francois is a former vice-president of global recruiting at Nortel Networks who has moved into the cybersecurity market. There’s a new partnership between Francois’ efforts and IT World Canada. Before I ask Francois about the job market for cybersecurity professionals here, Jim and Francois will explain what the partnership means.

Jim Love: I’m thrilled about this. I met Francois mostly by chance and in networking. IT World Canada is known for its technology journalism. We have no bigger draw than our security publications. We put on an annual conference called MapleSEC every year where we bring together security professionals from around the country. And this podcast is a big part of what we publish and what our community is interested in. Probably 10,000 people listen to this podcast every time there’s an episode. But there’s a curious thing that happens in Canada … We tend to fragment into little groups. But when I met Francois he was so open to the idea of why don’t we combine our efforts and really work to serve this community? And that’s where this all started.

Francois Guay: It’s amazing because we’re very focused with the Canadian Cyber Security Network on collaboration, trying to get other organizations in the country — associations, businesses, government — to work with us around some of the common challenges around cybersecurity. And as you mentioned, everybody likes to have their own little slice of the world. It’s so nice to meet up with you and [ITWC president] Ray Christophersen and start having that conversation about how we can work together … and making Canada the star. Our motto is ‘Stronger Together’ at the Network, and that means it’s all about collaboration.

Jim: Given the the discussions we were having was so neat to see your logo with that ‘Stronger Together’ line on it. We also bring our partnership with the Canadian Association of CIOs and they have a cybersecurity arm as well.

Francois: I think there are some exciting programs from working together. You mentioned a few like MapleSEC. We’re looking forward to how we can help you grow, bring some thought leaders to it and continue to extend the reach. The first collaboration I think we’re going to focus on is Cyber Towns. It focuses on trying to share how Canadian cities and communities are attracting and retaining talents and making them the best places to work in Canada. Whether it’s remote work or not, people want to grow in communities. They have resources: the tax bases are reasonable. They have access to nature access, to all types of activities. Cyber Towns is really about identifying the top communities in Canada where cybersecurity resources want to work, or potentially should work. Bringing out a report and talking about the challenges facing communities and facing Canada in both attracting and retaining those [human] resources. We have a challenge keeping them. So for us, it’s all about attracting developing and retaining the talent here. Cyber Towns is an extension of that.

Jim: Cyber Towns fit so nicely with our Technicity series, which is the study of technology in cities and the partnership of government and private sector and communities. I’m really also excited about this idea that we’ve talked about in terms of really becoming a knowledge hub.

Howard: What does membership in the Canadian Cybersecurity Network get you?

Francois: There are a lot of different services an individual has access to: Mentoring, the Canadian Cybersecurity Jobs portal, a LinkedIn group which I think has about 37,500 members across Canada. They can network, ask questions about what certifications they should be taking, what education should they be taking, what program should they take, what are the skills required, what are the technologies being used in cyber security.

For business members, we’re really focused on making them shine. We have webinars all year. One coming up will be about Canada’s failure to launch on the educational side. There are phenomenal opportunities for them to access these services to grow their business. This [partnership with IT World Canada] is just an extension of that.

Howard: What’s the state of cyber security jobs in Canada. There are many reports about IT departments around the world finding it hard to find cybersecurity professionals. Is that the same here in Canada?

Francois: Yes, there are a lot of job openings in Canada — but there are a lot of cyber security graduates sitting on the sidelines. The requirements of organizations looking for work experience is extremely detailed. They’re looking for four or five years of experience. You can’t expect these graduates to have that. It’s very much what I faced during the telecom boom of 1996 when telecom companies were looking for PhD students and there were only so many available. At the time Nortel was hiring 33 per cent of all PhD students graduating across Canada. Today there’s a lack of those types of resources, so organizations have to change their culture to adapt to the marketplace. It’s going to require a culture shift in a lot of companies to start looking at graduating resources differently and at people with lack of experience.

But we have noticed a 25 per cent drop in the job market. There are definitely fewer companies hiring for cyber security. That’s partly because you know we’re going through a difficult economic time. We’re seeing consolidation [among businesses] taking place. We’re seeing venture capital in Canada decreasing. And there have been layoffs in pockets across the country. These are impacting an organization’s ability to hire.

Howard: I can understand why employers are demanding. This is cyber security. They’re not hiring marketing people. So experience to some degree counts. But what should employers be reasonably looking for?

Francois: If they’re looking for experienced hires that’s a different story. But I’ll tell you some of the things that most individuals most companies are looking for. They like individuals to come in as grounded as possible on the whole network infrastructure — all the endpoints, understanding mobile and all those kinds of things. Apart from the technology side, it really comes down to communication skills. More and more cyber security individuals need to be able to communicate effectively — with clients, with their peers and they need to be able to communicate across any of the partnerships [their organizations] have in place. In a lot of cases that’s not a skill that universities and colleges are focused on. And Canada has bumped up immigration, but the individuals that are coming English [or French] may not be their first language. And language skills aren’t being worked on in universities and colleges to adapt them to the marketplace. So this becomes a challenge.

We need adaptability. We need curiosity in cybersecurity. These are the things that involve constant learning. Look at what’s happening with quantum and AI. AI is starting to make a significant impact. It’s going to be incredible this year but there are very few resources available on quantum, very few graduates. And I would say the same thing on the AI side. We’re behind the eight ball and there’s a real fight going on for talent. I would include cloud as one of those things as well. Individuals that have cyber security and cloud experience are very difficult to find.

Howard: It seems to me that Canadian colleges and universities are increasingly offering cybersecurity training to IT students and certainly there’s no shortage of training and available for IT people to earn certifications on particular products and on broad technologies. So are employees just too demanding?

Francois: No. Although there are a lot of universities and colleges offering cybersecurity programs one of the challenges is to get them to get them closer to employers and embrace the technologies that industry is using. The problem is that the funding that comes from the government and the provinces is based usually on just ‘Provide us with a curriculum. Show that you may have industry support.’ But it’s not a guaranteed support. It may just be a couple of letters of recommendation. So they get the funding they develop a program and the program is not tied to industry. There’s no industry buy-in. So people may they may not have the tools that the industry is looking for. Schools should be building in things where students do some testing, like Field Effect is doing with Algonquin College, where they’ve actually invested millions of dollars to create a cybersecurity lab in the school for students. Toronto Metropolitan University and the Rogers Cybersecure Catalyst have done some great work in working with industry. But a lot of other schools and colleges are lagging and therefore employers don’t see that experience in tackling cyber security problems. Even if it’s just six months or a year tied into the educational process [it will help]. But then a lot of the curriculum was developed with tools that aren’t relevant to industry, or that don’t have access to a work environment or a cloud environment where a lot of the companies are working.

Howard: Is this a matter of provincial/territorial boards of education not going to industry and saying, ‘We need your input. We need your collaboration on cyber security programs?’ Or is this a matter of industry not pushing the provinces?

Francois: It’s a little bit of both. I think the government requirements are superficial for universities and colleges as far as getting funding for some of these programs. And then industry, unfortunately, is always very busy. Their role is to make money. They tackle recruiting usually in six-month cycles and don’t look long term — just like universities and colleges that develop a program and may not change it for years and years … Meanwhile industry’s already adapting to AI and quantum and who knows what’s coming down the pipe. So I think that from that perspective there’s a responsibility on a lot of different players to step up.

Howard: What about those looking for cybersecurity-related jobs? Are they doing anything wrong? What should they be emphasizing when they send in resumes? When they go for job interviews?

Francois: A lot of them don’t have a LinkedIn profile or very little under their LinkedIn profile. Unfortunately most employers leverage LinkedIn for recruiting cybersecurity talent … This is why we built [the CCN] community. We want individuals to come in here, learn, talk to people find out what the best programs are to go into what are the certifications should they get, what skills they need, how to develop speaking skills … I probably get about 50 to 100 requests a day asking me to find them a job. That’s why we built the Canadian Cybersecurity Jos community …

I would say that the important thing is to talk about your journey and why you would be a good fit for an employer. I tell them, ‘Don’t just apply to job postings, reach out directly to the network. Start working with individuals and ask for help — a quick phone call, a quick review of your resume, a quick discussion around what is it like to work in pen testing or to work in a cloud environment — and start building from that. Reach out directly to employers. Bypass the recruiter and go directly to the hiring manager and share your value proposition. Tell your story, tell them why you would be a good fit.’

The post Cyber Security Today, Week in Review for Friday, Jan. 12, 2024 first appeared on IT World Canada.

Accenture presents its “Human by Design” 2024 tech vision, reassures on potential job losses

Artificial intelligence (AI) will become much more human-like and intuitive for people to use, Accenture highlighted in its 2024 Technology Vision report titled “Human by Design.”

The report also revealed that generative AI has the potential to impact 44 per cent of all working hours across industries in the U.S. and enable productivity enhancements across 900 different types of jobs.

“We were very careful about why we put it that way,” explained global lead, innovation at Accenture, Adam Burden. “We didn’t say roles, we didn’t say jobs, we said working hours, because it’s our belief that this amplification will impact those in every role and allow people to do things better and faster, with higher quality and maybe even at skill levels that they’re not currently able to do. So for us, the outcome here is goodness.”

Following a round of mass layoffs, the company invested US$3 billion in AI last summer, and announced it is doubling its AI workforce to 80,000 over the next three years. 

There will be some transition, but there will also be new roles that will create more profitability and productivity for companies, noted Burden.

He further explained that a lot of jobs like switchboard operators in the 1940s do not exist anymore because of new technologies like microprocessors. But new roles always end up surfacing to create new value.

Michael Blitz, managing director, Accenture Technology Vision, Accenture Technology Labs, also contended that Accenture looks at amplifying companies with AI, but it remains the responsibility of these companies to transition employees through this change.

He said, “I think it’s important for people to know from the outset that it’s just not about how you build that next product. It’s rather how you’re going to be able to transition people to being able to use it in the ways that they should.”

Companies requiring an AI-capable workforce also have to be responsible for building those skills and investing in people, notably because there is no current workforce to hire from, asserted Burden.

Blitz and Burden also acknowledged that the implementation of AI will require human oversight at all levels.

“Organizations that build the right controls to have humans in the loop are the ones that will definitely be more successful in the market, because they’re the ones that will gradually build more confidence in AI,” affirmed Burden.

Other insights from the report include:

Data will be reorganized in ways that facilitate human-like reasoning and even mimic creativity. For instance, users will receive curated, personalized responses in the form of advice, a summation of a vast set of results, an essay, an image, or even a piece of art, instead of having to comb through mountains of search engine results.
AI-empowered agents work on behalf of individuals and are part of an interconnected ecosystem. These automated agents assist, advise us and take decisive actions on our behalf in both the physical and digital worlds.
New immersive worlds for personal interaction will be created by extending physical, 2D worlds into new 3D environments using spatial computing, metaverse, digital twins and AR/VR technologies.
AI-powered wearables, brain-sensing neurotech, and eye and movement tracking will be used to unlock a better understanding of us, our lives, and our intentions, to enhance the way we work and live.

See the full report here.

The post Accenture presents its “Human by Design” 2024 tech vision, reassures on potential job losses first appeared on IT World Canada.

Cyber Security Today, Jan. 12, 2024 – A Chinese hacking group’s reach may be bigger than we thought

A Chinese hacking group’s reach may be bigger than we thought.

Welcome to Cyber Security Today. It’s Friday, January 12th, 2024. I’m Howard Solomon, contributing reporter on cybersecurity for ITWorldCanada.com and TechNewsday.com in the U.S.



 

The reach of a Chinese hacking group known for going after critical infrastructure in the United States may be more extensive than known so far. Researchers at SecurityScorecard say the IT network of the group researchers call Volt Typhoon is communicating with government websites in the U.K., Australia and India as well as the U.S. Among the tools it is apparently leveraging are particular models of unpatched routers from Cisco Systems. A patch for these devices was issued five years ago. And because these models are end-of-life there are no new updates for them. Network administrators have to watch for Cisco RV320 and RV350 devices. They should have been replaced a long time ago.

Threat actors are taking advantage of employees’ annual responsibilities such as company satisfaction surveys, enrolling in benefit programs, 401k updates and salary adjustments as lures to steal their credentials. That’s according to researchers at Cofense. The hackers know that companies often send staff email notifications about these things. So they are that by sending employees phishing emails with attachments or QR codes that appear to come from management or the HR department. The messages ask staff to login to see the material. Staff need to be reminded to use standard email security skepticism. For example, be wary of messages that start, “Dear employees.” Even if a message is personalized, check the email address of the sender to be sure it’s legit.

In November I told listeners that Fidelity National Finance, which provides title insurance and settlement services for the American mortgage and real estate sector, had suffered a data breach. This week it told a regulator it has now determined that data on approximately 1.3 million customers may have been copied by the attacker.

Someone at a Texas-based company that sells school security solutions allowed the creation of a non-password-protected database with sensitive student data to sit open on the internet. According to cybersecurity researcher Jeremiah Fowler, the database belonged to Raptor Technologies and was in three separate cloud storage buckets. It held information on students, teachers, parents and school safety plans. As soon as it was notified the company blocked public access to the database. It’s more evidence that corporate and IT managers aren’t closely training or supervising employees who create databases.

An American company called NASCO, which administers benefits for American health plans, has doubled the number of victims from the hack last year of its MOVEit file transfer application. The company now says data of almost 1.7 million people was stolen in the hack. According to researchers at Emsisoft, so far 2,730 companies or government departments around the world have admitted data on over 94 million people was stolen from their MOVEit servers.

An Alabama law firm called Burr & Forman which acts for a behavioral healthcare provider is notifying almost 20,000 people a hacker copied their personal data last fall. Data stolen included names, Social Security numbers, medical coding information with dates and descriptions, and insurance information.

The World Economic Forum released two cybersecurity forecasts based on surveys with experts. In one, misinformation and disinformation were listed as the top risk organizations will face over the next two years. That ranked ahead of extreme weather events. The other report suggests the number of organizations that maintain minimum viable cyber resilience dropped 30 per cent compared to last year’s survey. The biggest drop came from small and medium-sized companies, while large companies showed gains in cyber resilience.

Palo Alto Networks has released a background report on the Medusa ransomware gang. Security teams and researchers may find useful information in it. The paper includes indicators of compromise defenders should be watching for.

Fortinet has released a security update to address a vulnerability in its FortiOS and FortiProxy software. A cyber threat actor could exploit this vulnerability to take control of an affected system.

And Cisco Systems has patched a critical vulnerability in the web-based management interface of its Unity Connection unified messaging platform. If the security update isn’t installed an attacker could upload files to Unity Connection server and then do serious damage from there.

Follow Cyber Security Today on Apple Podcasts, Google Podcasts or add us to your Flash Briefing on your smart speaker.

The post Cyber Security Today, Jan. 12, 2024 – A Chinese hacking group’s reach may be bigger than we thought first appeared on IT World Canada.

Hashtag Trending; Microsoft surpasses Apple as most valuable company; Broadcom dumps VMWare partners; Google layoffs

Microsoft overtakes Apple as the most valuable company. Broadcom stirs up a hornets nest when it dumps VMWare partners. The U.S. government demands that hospitals improve cybersecurity if they want government funding and Google is not only axing people, it’s dropping services as well. 



 

These and more top tech stories on this edition of Hashtag Trending

I’m your host Jim Love, CIO of IT World Canada and Tech News Day in the US.

Microsoft has dethroned Apple to become the world’s most valuable public company. 

This shift in market value comes as Apple’s share price dipped by a mere one percent. 

The news marks a notable moment in the ongoing rivalry between these tech giants. 

Microsoft has always been a highly valued company and some of us remember when Microsoft had to lend Apple money so it wouldn’t go out of business and leave Microsoft as a monopoly. 

But the resurgence of Apple under Steve Jobs brought it to the status of the world’s most valuable company.  Now, the fact that Microsoft can catch up and even surpass it is a tribute to Microsoft’s leadership team. 

Sources include: MacRumors 

Hawaii has taken a big step in its clean energy journey by replacing its last coal plant with a massive battery system.  

The Kapolei Energy Storage project marks a significant shift from fossil-fueled power to renewable energy. This project, developed by Plus Power, features 158 Tesla Megapacks and boasts an impressive 185 megawatts of discharge capacity, matching the power output of the old coal plant. 

The battery’s rapid response time and ability to store and release energy make it a crucial component in stabilizing the grid. It’s not just about replacing the coal plant’s energy production; this battery system enables more renewable energy to be added to the grid, reducing the curtailment of renewables by an estimated 69 per cent for the first five years. 

The story of how this works is fascinating from a tech standpoint and you may want to check out the full article to geek out on this one. There’s a link on the show notes.

The Kapolei project isn’t the biggest battery of its kind, but it does mark one of the most sophisticated systems and maintains Hawaii’s leadership example of how to maintain a reliable grid while transitioning to clean energy sources, a model that could be replicated nationwide.

Sources include: Canary Media 

Broadcom’s acquisition of VMware has led to a significant shake-up in the virtualization giant’s partner programs, leaving many in the dark. The $61 billion deal, followed by plans to reorganize VMware into several Broadcom divisions, has particularly impacted Cloud Services Providers (CSPs). 

Broadcom announced the termination of the VMware Cloud Services Provider program by April 30, 2024. This move affects smaller cloud operators who sell VMware-based cloud services. The abrupt change has sparked industry chatter that Broadcom is focusing on larger, more profitable customers, potentially leaving smaller users and providers out in the cold. The decision has left many smaller providers and their customers facing uncertainty, with fears of needing to migrate to new providers on short notice.

My colleague Paul Barker is covering this in Channel Daily News if you want some more perspective on this. 

Sources include: Channel Daily News  and The Register

The U.S. government is set to introduce new cybersecurity standards for hospitals, linking federal funding to compliance with these standards. This move, expected to be proposed by the White House in the coming weeks, aims to address the increasing threat of ransomware attacks on healthcare facilities. The Centers for Medicare and Medicaid Services (CMS) are reportedly drafting rules that will require hospitals to implement basic network defenses to qualify for federal funding. These rules are a response to the growing number of ransomware attacks on hospitals, which not only compromise sensitive patient data but also employ aggressive extortion tactics. In 2023 alone, at least 46 U.S. hospital corporations were hit by ransomware, with patient data often being stolen. While the intention is to improve hospital security, some experts, like Emsisoft Threat Analyst Brett Callow, caution that cutting off funding might not be the most effective approach and could potentially worsen the situation.

Given the recent hits that Canadian hospitals and health care services have taken, it might behoove the Canadian governments to take a look at what’s happening here as well. 

Sources include: The Register 

Google has announced significant layoffs across multiple teams, including its Voice Assistant unit, hardware team, and central engineering team. The hardware team, responsible for products like Pixel, Nest, and Fitbit, is notably affected, with the augmented reality (AR) team facing the majority of layoffs. 

Google’s spokesperson gave the usual blah blah about enhanced efficiency and better aligning resources but these changes raise some questions. 

We assume that some of this realignment is towards artificial intelligence (AI) technology, with Google planning to integrate generative AI into its virtual assistant. But Google has also slashed the team and some of the services for the Google smart speaker. 

I saw the list of services they cut, supposedly because no one is using them. I had no idea that the smart speaker had features like waking up to music and others. Which might explain why nobody is using them. 

And the severe layoffs in Augmented Reality is a bit of a surprise.  Many had thought that Google and others would be gearing up to compete with Apple’s new A/R offering.

Google is the other G word that works in mysterious ways. 

Sources include: Reuters 

Hashtag Trending goes to air 5 days a week with a special weekend interview show we call “the Weekend Edition.”

You can get us anywhere you get audio podcasts and there is a copy of the show notes at itworldcanada.com/podcasts 

I’m your host, Jim Love. Have a Fantastic Friday!

The post Hashtag Trending; Microsoft surpasses Apple as most valuable company; Broadcom dumps VMWare partners; Google layoffs first appeared on IT World Canada.

Canadian Cyber Centre now ranks threats with SecurityScorecard solution

The Canadian government’s cyber authority has started using a U.S. company’s security ratings platform to rank cyber threats to the country’s critical infrastructure.

The Canadian Centre for Cyber Security said Thursday it has contracted to use SecurityScorecard’s security ratings platform. Under an arrangement with the company, the scoring will help the Cyber Centre educate critical infrastructure owner-operators on the risks facing their organizations, assisting them in remediating and measuring cybersecurity risks.

It gives the Cyber Centre a simple way to instantly measure and quantify the cyber risk of any critical infrastructure entity with an “A” through “F”  rating system, SecurityScorecard said in a news release, using continuously monitored threat intelligence data. This scoring is only for critical infrastructure operators and won’t be made public.

Nayeli Sosa, a Cyber Centre spokesperson, said though it can already pinpoint vulnerabilities and help protect critical infrastructure systems before the threats happen — for example through advisories, alerts, cyber flashes, and pre-ransomware notification — “this kind of tool bolsters our existing services and our toolset.”

Terms of the arrangement weren’t announced.

“We have comprehensive data on government systems, but our visibility into emerging threats to critical infrastructure has been limited historically – and that’s precisely where the greatest risks lie,” Cyber Centre head Sami Khoury said in a statement.

“According to the World Economic Forum, critical infrastructure remains the prime target for threat actors. Our partnership with SecurityScorecard provides us with authoritative and trusted data on critical infrastructure and insight to manage such risks at scale. We are committed to increasing the confidence of Canadians in the critical systems they rely on daily, offering support to critical infrastructure networks and other systems of importance to Canada. This will help the Cyber Centre ensure we can provide tailored support to critical infrastructure owner-operators vital to the security of Canada.”

The partnership “serves as a model for other governments to collaborate with the private sector to achieve real-time visibility into the cyber threats facing critical infrastructure,” said Sachin Bansal, SecurityScorecard’s chief business officer.

The Cyber Centre is the government’s authority for advising federal departments as well as critical infrastructure providers on cybersecurity issues.

Based in New York, Security Scorecard has modules that can check public datasets for evidence of high-risk or insecure ports in an organization’s IT network, analyze how quickly an organization installs security updates, and more.

The post Canadian Cyber Centre now ranks threats with SecurityScorecard solution first appeared on IT World Canada.

Warning issued to admins of Ivanti Connect Secure and Policy Secure gateways

IT administrators with Ivanti’s  Connect Secure/Pulse Secure VPNs and Policy Secure gateways are urged to install mitigations immediately.

The mitigations are to temporarily deal with two vulnerabilities (CVE-2023-46805, an authentication bypass and CVE-2024-21887, a command injection) that impact all supported versions of these products.

If they are chained together, “exploitation does not require authentication and enables a threat actor to craft malicious requests and execute arbitrary commands on the system,” the company said.

“It is critical that you immediately take action to ensure you are fully protected,” the company said in an advisory.

Patches will be released in a staggered schedule, with the first version targeted to be available to customers the week of Jan. 22, with the final version targeted to be available the week of Feb. 19. Until then, the mitigations will have to do.

The vulnerabilities were discovered by researchers at Volexity, who in December detected suspicious lateral movement on the network of one of its network security monitoring service customers. An attacker was placing webshells on the customer’s internal and external-facing web servers. Investigating further, Veloxity found that logs on the customer’s Ivanti Connect Secure VPN had been wiped and logging had been disabled. It then discovered two different zero-day exploits which were being chained together to achieve unauthenticated remote code execution.

“When combined, these two vulnerabilities make it trivial for attackers to run commands on the system,” Volexity says in its report. “In this particular incident, the attacker leveraged these exploits to steal configuration data, modify existing files, download remote files, and reverse tunnel from the … VPN appliance.”

Among other things, the attacker modified legitimate Connect Secure components and made changes to the system to evade the the VPN’s Integrity Checker Tool.

“As organizations continue to improve and harden their defense, attackers are continually looking for ways to bypass them,” the Volexity report says. “Internet-accessible systems, especially critical devices like VPN appliances and firewalls, have once again become a favorite target of attackers. These systems often sit on critical parts of the network, cannot run traditional security software, and typically sit at the perfect place for an attacker to operate.

“Organizations need to make sure they have a strategy in place to be able to monitor activity from these devices and quickly respond if something unexpected occurs.”

The post Warning issued to admins of Ivanti Connect Secure and Policy Secure gateways first appeared on IT World Canada.

Mandiant admits hacked X account didn’t have 2FA

Mandiant says the loss of control of its X/Twitter account last week was likely caused by a brute force password attack on one employee’s account by a cryptocurrency scammer.

Normally, two-factor authentication (2FA)would have mitigated the attack, the Google-owned division said in a tweet on Wednesday, “but due to some team transitions and a change in X’s 2FA policy, we were not adequately protected. We’ve made changes to our process to ensure this doesn’t happen again.”

The tweet doesn’t explain the change in X’s 2FA policy, or how it contributed to the hack.

There is no evidence the attacker used malware or compromised any Mandiant or Google Cloud systems in the moves that led to account takeover, Mandiant also said in a separate blog.

In a brute force attack, a threat actor submits stolen usernames and passwords, passphrases or a list of suspected passwords to a login page until the correct one is found.

The threat actor who got access used it to post links to a cryptocurrency drainer phishing page. Drainers are malicious scripts and smart contracts that actors can leverage to siphon funds and/or digital assets, such as non-fungible tokens, from victims’ cryptocurrency wallets after they are tricked into approving transactions.

Along with the explanatory tweet, Mandiant published a detailed blog on a drainer it calls Clinksink which was temporarily leveraged by the attacker. “Numerous actors have conducted campaigns since December 2023 that leverage the Clinksink drainer to steal funds and tokens from Solana (SOL) cryptocurrency users,” it says.

The identified campaigns included at least 35 affiliate IDs that are associated with a common drainer-as-a-service (DaaS) which uses Clinksink. “The operator(s) of this DaaS provide the drainer scripts to affiliates in exchange for a percentage of the stolen funds, typically around 20 per cent. We estimate the total value of assets stolen by affiliates in these recent campaigns to be at least US$900,000.”

It’s not uncommon for attackers to use social media and chat applications, including X and Discord, to distribute cryptocurrency-themed phishing pages that entice victims to interact with the Clinksink drainer, the report says.

The incident is another example of why organizations have to ensure their social media accounts are locked down to prevent crooks from taking them over and leveraging their access for profit or mischief.

This week, the U.S. Securities and Exchange Commission briefly lost control of its X account. In a tweet, X said the SEC didn’t have two-factor authentication protection enabled on the account. It said the cause was “an unidentified individual obtaining control over a phone number associated with the [SEC] account through a third party.”

The post Mandiant admits hacked X account didn’t have 2FA first appeared on IT World Canada.

Hashtag Trending Jan.11- OpenAI’s GPT store; AI and disinformation top WEF’s list of global risks; Research links brain cells to computer chip

It’s here – OpenAI has launched the GPT store and I have more questions than answers at this point. AI and disinformation make it to the top of the World Economic Forum’s list of global risks, ahead of climate change and researchers publish a paper on how they have linked brain cells to a computer chip. 



 

These and more top tech stories on the “gosh Toto we’re not in Kansas anymore” edition of Hashtag Trending

I’m your host Jim Love, CIO of IT World Canada and Tech News Day in the US.

OpenAI has unveiled the GPT Store, a new platform for discovering and sharing custom versions of ChatGPT. Since the announcement of GPTs two months ago, over three million custom ChatGPTs have been created. 

The GPT Store is accessible to ChatGPT Plus, Team, and Enterprise users, and features a variety of GPTs developed by both partners and the community. 

Users can browse through categories like DALL·E, writing, research, programming, education, and lifestyle. 

The store will regularly highlight what it says are new and impactful GPTs, with initial offerings including things like a personalized trail recommender from AllTrails, a research tool from Consensus, and a coding tutor from Khan Academy and something called Books for finding – books. 

It appears that anyone can save and submit a GPT but with three million already out there, it’s going to be interesting to see how they keep this organized. 

They have topics and a top 5 in each topic area, which make you curious as to how these were prioritized.

There is a mention of usage policies and GPT brand guidelines as well as a review system for safety measures. The review system includes both human and automated review. As well, users are able to report GPTs.

There is a comment about not using your conversations with GPTs to improve their models but it’s put there in a way that makes you wonder if only Team and Enterprise customers get this treatment or if Plus members need to pay the extra five bucks a month to get that protection. 

And once again, it’s going to be quite interesting to see how they manage the sheer volume.

OpenAI also plans to launch a revenue program for GPT builders based on user engagement. 

Sources include: OpenAI Blog

The platform formerly known as Twitter, now referred to as “X,” recently suspended several prominent journalists and leftist figures without explanation. Among those affected were Ken Klippenstein of The Intercept, Steven Monacelli of Texas Observer, podcaster Rob Rousseau, and Alan MacLeod of MintPress News. These suspensions also extended to left-leaning accounts like the TrueAnon podcast and @zei_squirrel, a media-criticizing cartoon squirrel. 

The affected users received no communication from X regarding the reason for their suspension, leading to speculation about political motivations behind these actions. 

Notably, the suspensions were briefly lifted hours after initial reporting, following public outcry from figures like former British MP George Galloway. 

X owner Elon Musk later attributed the bans to a routine spam filter sweep, but this explanation has not been universally accepted. This incident follows previous instances where X has banned reporters critical of Musk.

And curiously, this happened the day after Musk was featured on Canadian national news criticizing the Canadian Prime Minister for his treatment of a right wing journalist. 

Sources include: Vice News

Fidelity National Financial, a major player in real estate services, has confirmed a significant data breach. In November, hackers accessed FNF systems, deploying malware and exfiltrating data on 1.3 million customers. The breach caused a week-long outage, severely disrupting the company’s operations and its subsidiaries, leaving customers unable to pay their mortgages. The specific nature of the stolen customer data hasn’t been disclosed, but FNF is offering credit monitoring and identity theft services to the affected individuals, indicating the sensitive nature of the breach.

The ransomware gang ALPHV, also known as BlackCat, claimed responsibility for the attack. They are known for using dark web leak sites to extort victims. The group removed FNF from its site, which sometimes indicates that a ransom has been paid. This incident is part of a recent wave of cyberattacks targeting the mortgage and loan industry. FNF’s response included notifying state attorneys general and regulators, and they have contained the cyberattack since November 26.

Sources include: TechCrunch

The World Economic Forum’s “Global Risks Report 2024” has identified artificial intelligence’s role in election disruption as the top global risk for the year. This concern surpasses climate change, war, and economic instability. The report, a collaboration between the WEF, Marsh McLennan, and Zurich Insurance Group, highlights AI-driven misinformation and disinformation as key factors contributing to societal polarization. Over 1,400 global risk experts, policymakers, and industry leaders contributed to this assessment.

Carolina Klint from Marsh McLennan emphasized the unprecedented influence AI models could have on voter behaviour. 

But the report also forecasts a shift in risk focus over the next decade, with extreme weather conditions and significant changes in the political world order becoming more prominent. The WEF calls for global cooperation and the establishment of guardrails against emerging disruptive risks. The report’s release coincides with a critical election year globally, including major polls in the U.S., India, Russia, South Africa, and Mexico. The Eurasia Group’s separate 2024 global risks report also underscores the significance of the U.S. election and the challenges posed by “ungoverned AI.”

Sources include: CNBC

Researchers from Indiana University of Bloomington, the University of Florida, and the University of Cincinnati School of Medicine have made a groundbreaking advancement in AI hardware with the development of “Brainoware,” a human brain on a chip. This innovation, detailed in their paper “Brain Organoid Computing for Artificial Intelligence,” represents a significant leap in biocomputing.

I’ll note that the paper has not been peer reviewed yet, but I went with the story because there have been some experiments establishing the workability of the idea. 

The team cultivated specialized stem cells into neuron clusters, or organoids, each less than a nanometer wide. These organoids, connected to a circuit board via electrodes, allow machine-learning algorithms to interpret their responses. 

In a practical test, Brainoware reports achieving a 78 per cent accuracy in a speech recognition task, identifying speakers based on the organoid’s neural activity in response to electrical stimulation. While less accurate than traditional AI systems and requiring different resources like a CO2 incubator, Brainoware’s energy efficiency is part of the holy grail. One estimate is that the human brain uses about 20 watts. When we compare that to the reported 8 million watts used by current AI hardware, you can see why researchers say that “organoid intelligence” (OI) is the future of computing, powered by living human brain cells. 

And once you get past the creepy factor, the other reason to pursue this may also be to study neurological conditions and cognitive aspects, and offer a new dimension to AI computations and learning.

The author of one article on this says, “while Elon Musk is installing chips inside human brains…researchers are planning to plant brains inside of chips.”  And there we are, back to the creepy factor again.

Sources include: Analytics India Magazine

Hashtag Trending goes to air 5 days a week with a special weekend interview show we call “the Weekend Edition.”

You can get us anywhere you get audio podcasts and there is a copy of the show notes at itworldcanada.com/podcasts 

I’m your host, Jim Love. Have a Thrilling Thursday!

The post Hashtag Trending Jan.11- OpenAI’s GPT store; AI and disinformation top WEF’s list of global risks; Research links brain cells to computer chip first appeared on IT World Canada.

CES 2024: Why the AI PC? Intel’s Pat Gelsinger makes a case

The AI PC democratizes access to artificial intelligence in ways that are unprecedented and kind of exciting. Intel’s chief executive officer Pat Gelsinger asserted last night during a talk at CES 2024.

The company said last month during the launch of its “AI Everywhere” strategy that “The AI PC represents the largest transformation of the PC experience in 20 years, since Intel Centrino untethered laptops to connect to Wi-Fi from anywhere.”

The AI PC is pretty much what it sounds like: A personal computer with the processing power to run high-end AI workloads locally instead of in the cloud.

To further sell the idea, Gelsinger pointed to what he calls the three laws of edge computing: economics, physics and land.

The law of economics explains how it is cheaper to run AI workloads on your personal device, instead of having to rent cloud servers.

The law of physics enables your workload to be more responsive, since you will not have to roundtrip the data to the cloud and then back.

And finally, the law of land allows you to have more control over where your data is. You can store your data locally if you are not comfortable with storing it in the cloud and do not want to deal with the complications of using a hyperscaler.

These three laws would drive more of these AI use cases to the devices that we use across the edge, Gelsinger said.

The company said last month that its latest Intel Core Ultra mobile processor family, featuring its first client on-chip AI accelerator — the neural processing unit, or NPU — would usher in the age of the AI PC and bring AI to more than 230 designs from laptop and PC makers worldwide. 

According to the Boston Consulting Group, AI PCs will comprise 80 per cent of the PC market in 2024. That raises questions about the viability of hybrid cloud options. 

Gelsinger explained that the creation of foundation models requires “big huge cloud environments”, but that most of us are going to be just using those models. That seems to be a trend, where people are using, for instance, open source foundation models like Meta’s Llama 2 to run smaller models on their data for their applications, he added.

Nvidia was also featured at CES 2024 on Monday, touting the AI PC and announcing a number of AI-ready laptops. But Intel claims the AI PC, affirmed Gelsinger, adding “We’re the driving force behind it. But you know, we love it when people copy us.” 

Yesterday, Intel also announced that it is bringing the AI PC experience to the car, as part of its “AI Everywhere” strategy, launching automotive versions of its newest AI-enabled chips as well as with the acquisition, announced yesterday, of Silicon Mobility, a fabless silicon and software company that specializes in SoCs (system on chips) for intelligent electric vehicle (EV) energy management.

China-based Geely’s Zeekr brand will be the first original equipment manufacturer (OEM) to use Intel’s new family of SDV SoCs.

The post CES 2024: Why the AI PC? Intel’s Pat Gelsinger makes a case first appeared on IT World Canada.

Impact of HPE’s US$14 billion buy of Juniper huge: Dell’Oro Group

Describing it as a “tectonic shift” for the networking industry, industry analyst Mauricio Sanchez has predicted that yesterday’s US$14 billion acquisition of Juniper Networks by HPE will clearly extend the latter’s reach into distributed denial of service (DDoS) attack protection offerings, firewalls, cloud workload security, and distributed cloud networking markets.

Sanchez, senior director of enterprise security and networking research at Dell’Oro Group, wrote in an advisory released late last night that “Juniper has long been known as a premier service provider router company, and, more recently, as a darling in the enterprise networking space with the AI-powered MIST WLAN solutions.

“HPE has been in the networking industry even longer, going back to the 1980s, and most recently, a well-regarded enterprise networking player with Aruba campus solutions. However, both firms have a wider portfolio that spans the network security and SASE/SD-WAN technology landscape.”

He said key strengths of the deal are the fact that Juniper brings a number of network security technologies that HPE lacks, and that its reputation in the cloud and comms service provider space will help HPE’s overall credibility.

The major weakness is that “Juniper’s network security market share is small compared to the big three of Cisco, Fortinet, and Palo Alto Networks.”

According to a release issued by the two companies, the acquisition – an all-cash transaction of US$40 per share – is “expected to double HPE’s networking business, creating a new networking leader with a comprehensive portfolio that presents customers and partners with a compelling new choice to drive business value.

“The explosion of AI and hybrid cloud-driven business is accelerating demand for secure, unified technology solutions that connect, protect, and analyze companies’ data from edge to cloud. These trends, and AI specifically, will continue to be the most disruptive workloads for companies, and HPE has been aligning its portfolio to capitalize on these substantial IT trends with networking as a critical connective component.”

Upon completion of the sale, which is expected to close either the end of this year or early 2025, Juniper chief executive officer (CEO) Rami Rahim will lead the combined HPE networking business and report to HPE president and CEO Antonio Neri.

Neri, in the release, said the acquisition represents “an important inflection point in the industry and will change the dynamics in the networking market and provide customers and partners with a new alternative that meets their toughest demands.

“This transaction will strengthen HPE’s position at the nexus of accelerating macro-AI trends, expand our total addressable market, and drive further innovation for customers as we help bridge the AI-native and cloud-native worlds, while also generating significant value for shareholders.”

During a press briefing this morning, Rahim said, “those who know Juniper know that we were born in the era of the internet, and we build the products that help the internet scale to what it is today. Fast forward to today, the biggest inflection since the dawn of the internet itself is artificial intelligence, it is AI.

“And the thing that I am most excited about with this combination is that we will be able to bring the depth and the breadth of the portfolios necessary to capture the full market opportunity that AI presents in front of us. I think that combination is going to be incredibly powerful to solving our customers most compelling AI needs in the market.”

Neri added that the combination of the two companies, “will not only will make us more relevant, it’s going to disrupt the networking market, and it’s going to deliver significant value to our combined shareholders.”

The post Impact of HPE’s US$14 billion buy of Juniper huge: Dell’Oro Group first appeared on IT World Canada.