Page 28 of 55

Hashtag Trending Jan.9- Apple quietly integrating AI; Microsoft to train 100,000 Indian developers in AI; New ransomware attack strategies sink to new lows

A tale of two strategies – Apple’s stealth approach to AI and Microsoft’s move to upskill India’s developers to use AI. If you thought ransomware attacks on hospitals and ambulance dispatch was as low as it can get – the latest strategies sink even lower.



 

These and more top tech stories on Hashtag Trending

I’m your host Jim Love, CIO of IT World Canada and Tech News Day in the US.

While other tech giants are making noise with their AI advancements, Apple is taking a different approach. Apple has been quietly integrating AI into its products and services without much fanfare. 

From its neural engine in iPhones to advanced algorithms in the Apple Watch, the company is using AI but not doing much in the way of publicizing it. 

Apple’s strategy seems to focus on seamless integration, ensuring that AI enhancements are not disruptive but rather an organic part of the user experience. 

This differs from competitors who often highlight AI as a major selling point. But is this a lack of progress or just “stealth marketing” from Apple. The company is notorious for its secrecy in product development.

Tim Cook, Apple’s CEO has said that AI work is “going on” but not much more than that. 

Which leaves us all reading the tea leaves and looking for hints. 

We know, for instance, that Apple has been courting publishers at the same time OpenAI is out there, only Apple seems to be looking for media partners ahead of any big release.

In October, Apple and Columbia University released an open-source multi-modal language model called Ferret which raised some interest due to the potential for local models to power small devices. 

Apple also released two research papers on new techniques for 3-D avatars and more efficient language model inference which could be seen as driving more immersive experiences – again from a focus in the papers on using these on regular devices without using too much memory.

And the big open question is, when – or will we – see these in Apple products?  

Will “slow but steady” win the race? 

And the one question that everyone wants answered, when is Apple going to replace the old structure of Siri with a new, generative AI model?

Sources include: Analytics India

Microsoft has launched a program called “AI Odyssey” to train 100,000 Indian developers in artificial intelligence by 2024. 

AI Odyssey includes a series of workshops, webinars, and hackathons, focusing on areas like machine learning, data science, and AI ethics. 

The program aims to train developers with the skills needed to drive innovation in AI. 

Microsoft’s program reflects the increasing demand for AI skills in India, which was and remains a powerhouse in outsourced development. 

But that huge workforce, many of whom support legacy systems from the west could be threatened by AI’s coding ability.  

With what everyone sees now as a brilliant investment in AI with OpenAI, is this the next strategic move for Microsoft? Yes, it has a positive impact on the Indian tech sector as they help develop new skills. But it also strengthens Microsoft’s position in a key global market. 

Sources include:  Analytics India

A troubling new trend in cybercrime is gaining traction, as extortionists are increasingly using “swatting” as a tactic. 

Swatting involves making a hoax call to emergency services, typically reporting a serious but fabricated incident, to draw a large police response to a victim’s address. 

This dangerous and disruptive practice has now evolved into a tool for cybercriminals seeking ransom from individuals and businesses, threatening them with swatting if their demands are not met. 

When my sister found out she had a potentially life-threatening cancer and was forced to wait in Sarnia and London’s hospitals for hours because of recent ransomware attacks, I thought I’d seen the lowest it can get. Who slows down surgery for those who need it quickly to have a chance at living?

Recently cybercrooks have been doing this to patients from stolen hospital data. Apparently, following them home and scaring the life out of these people – victimizing them twice – is the next trend.  

I make no further predictions on how low these predators can go. 

—–

Volkswagen is set to change the in-car experience by integrating ChatGPT into its voice assistant system. This was announced at CES, and Volkswagen hopes to make the car’s voice assistant more conversational, intuitive, and helpful. 

The company is betting that ChatGPT will allow for more fluid and human-like interactions. 

This marks a significant step in the automotive industry And where others are still testing it, or offering an alternative to existing voice driven systems, Volkswagen has gone all in, a bold move for the company that has had some serious setbacks in terms of image and sales. 

Whatever they do has to be better than the frustration of dealing with systems that cause more distraction than they prevent.  

Sources include: The Verge

There was a story that made the news this morning about a plane which had a door seal blow out in mid-air. No one was injured, thankfully, although I may never take a seat on the exit door again. 

But when someone found the door seal, they also found an iPhone that got sucked out of the plane. And the phone still worked. 

That tied in with the story I did yesterday on nostalgia for for pre-internet and pre-digital devices. There was a famous commercial for an analogue watch called Times, with the slogan “takes a licking, and keeps on ticking.” 

Well falling from 30,000 feet or whatever and still being able to take a call? I think the digital age has us beat on that one.

Hashtag Trending goes to air 5 days a week with a special weekend interview show we call “the Weekend Edition.”

You can get us anywhere you get audio podcasts and there is a copy of the show notes at itworldcanada.com/podcasts 

I’m your host, Jim Love. Have a Terrific Tuesday. 

The post Hashtag Trending Jan.9- Apple quietly integrating AI; Microsoft to train 100,000 Indian developers in AI; New ransomware attack strategies sink to new lows first appeared on IT World Canada.

Toronto Zoo hit by ransomware

The municipally-owned Toronto Zoo has been hit by a ransomware attack.

The cyber attack was first detected early Friday, Jan. 5, the zoo said in a statement Monday,

“We are investigating the impact, if any, to our guests, members and donor records,” the statement says. “We can confirm we do not currently store any credit card information. Once we have more information we will share it broadly.

In addition to member and donor records, the IT system might have information on the 273 permanent full-time and 330 part-time or seasonal employees.

“We are working with the City of Toronto’s Chief Information Security Office and third-party cyber security experts to resolve the situation and have reported it to Toronto Police Services” the statement said.

The internationally respected zoo is located in a river valley at the eastern edge of the city, spread over 287 hectares (710 acres). It attracts about 1.3 million visitors a year. Its collection includes 5,816 animals, not including invertebrates, representing 495 different
species.

Asked for comment, Katie Gray, the zoo’s strategic communications manager, said, “We can’t share anything further than what’s in the release.”

The incident comes after a ransomware attack in October on the Toronto Public Library system. Among the questions is whether there is a link between that attack and the zoo compromise. The City of Toronto was itself one of the over 2,000 victim organizations of the vulnerability in the MOVEit file transfer application, which was leveraged by the Cl0p ransomware gang last May.

The post Toronto Zoo hit by ransomware first appeared on IT World Canada.

How AI and machine learning solutions drive value for financial institutions

In an era where technology is reshaping industries, BMO is making waves in the financial sector through its robust artificial intelligence (AI) initiatives and machine learning technologies.

A recent interview with Eric Morrow, Managing Director, Enterprise Data Science & AI, Data & Analytics, and Alex Tait, U.S. Chief Data and Analytics Officer, Data & Analytics, shed light on the transformative power of AI, where increased model performance directly correlates with amplified revenue, reduced costs, and most importantly, enhanced customer experiences.

At BMO, the benefits of broadly applying AI, data science and machine learning are clear. “There’s almost endless opportunity for taking data and applying models to it within a financial services organization,” said Tait. “Potential applications span everything from marketing to defending against cybersecurity threats.”

Driving AI integration at BMO

BMO considers AI an integral part of the bank’s strategy, tightly interwoven with revenue streams and cost-effectiveness. Morrow describes AI integration as a “powerful concept” that can be applied cross-functionally with active engagement across BMO’s lines of business and various Data and Analytics leaders.

“On our mobile app, for instance, you provide personalized insights to the individual, and that’s a powerful thing that really creates that connection with the customer,” he said.

In addition to AI’s application in retail banking, BMO has created new and innovative ways to apply advanced analytics to commercial customers’ needs. Earlier in 2023, Datos Insights, a global advisory firm focused on technology, regulation, strategy, and operations in the financial services industry, presented BMO with a 2023 Impact Innovation Awards in Cash Management and Payments for AI and advanced analytics for its “Digital Workbench” technology.

BMO Digital Workbench provides real-time analytics and reporting in various areas through a cloud-based self-service portal accessible to multiple businesses within the bank. It integrates scattered data sets across different bank systems with an easy-to-use, cloud-based web interface that drives cohesive and accessible analytics, facilitates insightful customer conversations, and transforms pricing and product mix strategies. A suite of data-driven tools with dynamic customer analytics and forecasting capabilities powers the technology.

Yet implementing customer solutions using AI and analytics is only part of the story. BMO supports cutting-edge research to ensure AI solutions provide functionality, accuracy, efficiency, and automation.

Supporting AI’s broader application in financial services

An example is BMO’s sponsorship of Next AI, a Montreal-based founder development network for entrepreneurs looking to solve global challenges with AI-based ventures and technology commercialization. Next AI helps identify and support early-stage ventures, which receive access to resources, mentorship education and the network they need to succeed.

Another notable endeavour illustrating BMO’s commitment to AI excellence is its partnership with the Vector Institute, a collaboration that epitomizes BMO’s dedication to staying at the forefront of AI innovation.

The Vector Institute offers a platform for BMO to explore leading AI research, turning academic insights into practical applications. A past, prominent project involves Natural Language Processing (NLP), a domain critical for a bank dealing with vast amounts of textual data.

According to Morrow, BMO can leverage NLP to help better understand why customers call into contact centres. “Being able to ensure that we’re providing the right level of service and care back to them when there are engagements between the agents is the goal,” says Morrow.

And BMO is making progress towards it. In 2023, Digital Banker recognized BMO with an Outstanding Machine Learning Initiative Award, which focused on leveraging NLP association with a contact centre.

The future of AI at BMO

BMO’s journey into AI and machine learning isn’t just about the present; it’s about building a future where technology seamlessly integrates with customer needs. The bank’s strategic direction emphasizes a digital-first approach and cloud-centricity. This focus on technological integration ensures operational efficiency and positions BMO as a pioneer in the banking industry’s digital transformation, and it starts from within the bank. This past year, more than 3,500 BMO employees participated in deep technical learning and licensing in subjects like AI, Machine Learning and Cloud.

Additionally, BMO is experimenting with new technologies enterprise-wide to develop digital capabilities to advance the bank’s Climate Ambition. Through BMO’s developing Climate Analytics Platform, the bank is using its digital capabilities, and developing the ability to use AI, to help understand the impacts and risks from weather-related events, such as floods, droughts, extreme heat and more. For any company seeking to manage this evolving risk, it is important to identify how these physical climate impacts are expected to change over time and by location, and how those changes intersect with economic systems. For banks like BMO who have a large financing footprint, it is important to identify where climate hazards are projected to manifest, and to manage the risk and capture opportunities associated with this changing future. While these programs are still under development, our technology teams can support innovation within the bank by piloting new and innovative technology driven approaches to climate related analysis.

BMO’s integration of AI is a testament to the bank’s commitment to delivering value through exceptional banking experiences across all its lines of business. Outside the bank, BMO is raising the bar in applying AI and machine learning in the financial services sector by extending that commitment to research and collaboration with esteemed organizations like the Vector Institute. As AI continues to influence the future, BMO stands as a beacon, showcasing how innovative technology can redefine banking, enrich customer interactions, and drive business growth.

The post How AI and machine learning solutions drive value for financial institutions first appeared on IT World Canada.

NIST issues cybersecurity guide for AI developers

No foolproof method exists so far for protecting artificial intelligence systems from misdirection, warns an American standards body, and AI developers and users should be wary of any who claim otherwise.

The caution comes from the U.S. National Institute of Standards and Technology (NIST) in a new guideline for application developers on vulnerabilities of predictive and generative AI and machine learning (ML) systems, the types of attacks they might expect, and approaches to mitigate them.

“Adversaries can deliberately confuse or even “poison” artificial intelligence (AI) systems to make them malfunction — and there’s no foolproof defense that their developers can employ,” says NIST.

The paper, titled Adversarial Machine Learning: A Taxonomy and Terminology of Attacks and Mitigations (NIST.AI.100-2), is part of NIST’s effort to support the development of trustworthy AI. It can also help put NIST’s AI Risk Management Framework into practice.

One major issue is that the data used to train AI systems may not be trustworthy, NIST says. Data sources may be websites and interactions with the public. There are many opportunities for bad actors to corrupt this data — both during an AI system’s training period and afterward, while the AI continues to refine its behaviors by interacting with the physical world. This can cause the AI to perform in an undesirable manner. Chatbots, for example, might learn to respond with abusive or racist language when their guardrails get circumvented by carefully crafted malicious prompts.

“For the most part, software developers need more people to use their product so it can get better with exposure,” NIST computer scientist Apostol Vassilev, one of the publication’s authors, said in a statement. “But there is no guarantee the exposure will be good. A chatbot can spew out bad or toxic information when prompted with carefully designed language.”

In part because the datasets used to train an AI are far too large for people to successfully monitor and filter, there is no foolproof way as yet to protect AI from misdirection. To assist the developer community, the new report offers an overview of the sorts of attacks AI products might suffer and corresponding approaches to reduce the damage.

They include

— evasion attacks, which occur after an AI system is deployed, attempt to alter an input to change how the system responds to it. Examples would include adding markings to stop signs to make an autonomous vehicle misinterpret them as speed limit signs or creating confusing lane markings to make the vehicle veer off the road;

— poisoning attacks, which occur in the training phase by introducing corrupted data. An example would be slipping numerous instances of inappropriate language into conversation records, so that a chatbot interprets these instances as common enough parlance to use in its own customer interactions;

— privacy attacks, which occur during deployment, are attempts to learn sensitive information about the AI or the data it was trained on to misuse it. An adversary can ask a chatbot numerous legitimate questions, and then use the answers to reverse engineer the model to find its weak spots — or guess at its sources. Adding undesired examples to those online sources could make the AI behave inappropriately, and making the AI unlearn those specific undesired examples after the fact can be difficult;

— abuse attacks, which involve the insertion of incorrect information into a source, such as a webpage or online document, that an AI then absorbs. Unlike poisoning attacks, abuse attacks attempt to give the AI incorrect pieces of information from a legitimate but compromised source to repurpose the AI system’s intended use.

“Most of these attacks are fairly easy to mount and require minimum knowledge of the AI system and limited adversarial capabilities,” said report co-author Alina Oprea, a professor at Northeastern University. “Poisoning attacks, for example, can be mounted by controlling a few dozen training samples, which would be a very small percentage of the entire training set.”

Many mitigations focus on data and model sanitization. However, the report adds, they should be combined with cryptographic techniques for origin and integrity attestation of AI systems. Red teaming — creating an internal team to attack a system — as part of pre-deployment testing and evaluation of AI systems to identify vulnerabilities is also vital, the report says.

On the other hand, the report also admits that a lack of reliable benchmarks can be a problem in evaulating the actual performance of proposed mitigations.

“Given the multitude of powerful attacks, designing appropriate mitigations is a challenge
that needs to be addressed before deploying AI systems in critical domains,” says the report.

This challenge, it notes, is exacerbated by the lack of secure machine learning algorithms for many tasks. “This implies that presently designing mitigations is an inherently ad hoc and fallible process,” the report says.

The report also says developers and buyers of AI systems will have to accept certain trade-offs: That’s because the trustworthiness of an AI system depends on all of the attributes that characterize it, the report notes. For example, an AI system that is accurate but easily susceptible to adversarial exploits is unlikely to be trusted. Conversely, an AI system optimized for adversarial robustness may exhibit lower accuracy and deteriorated fairness outcomes.

“In most cases, organizations will need to accept trade-offs between these properties and
decide which of them to prioritize depending on the AI system, the use case, and potentially many other considerations about the economic, environmental, social, cultural, political, and global implications of the AI technology.”

Joseph Thacker, principal AI engineer and security researcher at AppOmni, called the report “the best AI security publication I’ve seen. What’s most noteworthy are the depth and coverage. It’s the most in-depth content about adversarial attacks on AI systems that I’ve encountered. It covers the different forms of prompt injection, elaborating and giving terminology for components that previously weren’t well-labeled. It even references prolific real-world examples like the DAN (Do Anything Now) jailbreak, and some amazing indirect prompt injection work. It includes multiple sections covering potential mitigations, but is clear about it not being a solved problem yet.

“It also covers the open vs closed model debate. There’s a helpful glossary at the end, which I personally plan to use as extra ‘context’ to large language models when writing or researching AI security. It will make sure the LLM and I are working with the same definitions specific to this subject domain. Overall, I believe this is the most successful over-arching piece of content covering AI security.”

The post NIST issues cybersecurity guide for AI developers first appeared on IT World Canada.

Cyber Security Today, Jan. 8, 2024 – How a Spanish cellular carrier’s network was knocked offline, and more

How a Spanish cellular carrier’s network was knocked offline, and more.

Welcome to Cyber Security Today. It’s Monday, January 8th, 2024. I’m Howard Solomon, contributing reporter on cybersecurity for ITWorldCanada.com and TechNewsday.com in the U.S.



 

Despite all the money organizations spend on cybersecurity, some continue to shoot themselves by ignoring basic cybersecurity practices. The latest example is last week’s compromise of cellular carrier Orange Spain. How was it done? A threat actor infiltrated the computer of an administrator and stole their login credentials to a regional IP network co-ordination centre called RIPE. Never mind the administrator’s password was ‘ripeadmin,‘ which could have been guessed. Worse is that — according to researcher Kevin Beaumont — this IP network account wasn’t protected with multifactor authentication. Let me repeat that: Login to a service that looks after internet routing of a telecommunications provider had no multifactor authentication protection. By the way, the stolen administrator credential had been available for sale on a criminal marketplace since last August to any threat actor. It isn’t known how the admin’s computer was compromised so the password could be stolen. But they likely fell for a phishing or social media scam, which allowed malware to be planted on their machine. Fortunately all that happened was Orange Spain customers lost connectivity for several hours.

Meanwhile, all telecommunications providers in Europe, the Middle East and Asia that use the RIPE network should note there are thousands of stolen credentials for accessing this system being sold on dark web marketplaces. You have been warned.

A midwife service for expectant mothers in Southern Ontario is notifying women it suffered a data breach last April. CBC News says Midwives of Windsor is telling clients that one of its email accounts was compromised. An unknown number of names, mailing addresses, phone numbers, dates of birth and other personal information of mothers and children may have been copied.

Someone was able to compromise the flight information displays at Beirut International Airport on Sunday and post anti-Hezbollah messages. Hezbollah is an Islamist political party and militant group in the country. According to the Associated Press, those in the airport hoping to see departure and arrival times instead saw a message accusing Hezbollah of putting Lebanon at risk of an all-out war with Israel.

Some organizations are already implementing solutions to protect their encrypted applications from future quantum computer attacks. However, researchers are warning one solution already has a vulnerability that has to be patched. The solution is CRYSTALS, a set of algorithms approved by the National Institute of Standards and Technology (NIST). Within CRYSTALS is a security key encapsulation mechanism called Kyber, and that’s where the problem is. According to Bleeping Computer, researchers found Kyber has two vulnerabilities. One was patched on December 1st, the other on December 30th. If your application uses Kyber as part of its CRYSTALS solution this has to be looked after.

And by the way, if your application handles encrypted sensitive or financial data you need to be investigating quantum-safe solutions now before quantum computers can unscramble them.

Pharmaceutical manufacturer Merck & Co. has reached a settlement with insurers over hundreds of millions of dollars it was claiming for damages in the 2017 NotPetya cyber attack. You may recall that was the cyber attack aimed at Ukraine by compromising an accounting program used in that country. But the destructive worm escaped to ravage unpatched Windows computers around the world, including Merck’s systems. A New Jersey appeal court ruled insurers had to pay Merck about US$700 million for computer damages the company suffered. Last week the insurers were about to fight that decision before the New Jersey Supreme Court. But Bloomberg Law says there was a last-minute settlement. The terms of that settlement are confidential. The appeal court ruled the insurers had to pay under Merck’s all risks property coverage. While the policies basically said there was no payout for damages caused by war-like actions, the appeal court said the wording only applied to traditional forms of war and not cyber attacks. The language for insurance policies is tighter these days.

Five years ago the U.S. seized control and laid charges in the operation of the online xDedic criminal marketplace. Last week the government said its investigation has peaked. Seventeen people were charged. All were convicted. Eleven got sentences ranging from 78 to 12 months in prison. One was sentenced to five years probation. Five others are awaiting sentencing. The marketplace sold stolen login credentials to more than 700,000 servers around the world as well as stolen personal information.

A New York State healthcare provider has agreed to pay US$450,000 and spend US$1.2 million to strengthen its cybersecurity following a ransomware attack two years ago. An attacker claiming to be the Lorenz ransomware gang accessed the data of 250,000 people held by Rafuah Health Centre. New York’s attorney general’s office found the health centre failed to encrypt patient information, failed to use multifactor authentication to protect logins, failed to decommission inactive user accounts, failed to rotate user account credentials and failed to restrict employee’s access to data to only those who needed it..

A San Francisco law firm that specializes in technology now says the personal information of over 630,000 people was copied in a cyber attack it suffered early last year. Originally the firm of Orrick, Herrington & Sutcliffe LLP reported to Maine’s attorney general’s office that 152,000 people were impacted. Then the number rose to 461,000. The attacker got into a file share where certain client files were stored including emails and email attachments. Stolen data could have included peoples’ names, dates of birth, Social Security numbers, government-issued identification numbers, passport numbers, financial account information, medical information and more. Last month the law firm reached a proposed settlement in a class action suit stemming from the data breach.

Finally, do you have an idea of how to detect the use of voice cloning for audio and video crimes? You have until Friday to submit a solution to the U.S. Federal Trade Commission. It’s running a contest to find ways of stopping threat actors from defrauding victims or spreading disinformation. Voice cloning uses text-to-speech technology originally developed to help people who have lost their voices from accidents or illness. But crooks are using it to impersonate people. The contest winner gets US$25,000.

Follow Cyber Security Today on Apple Podcasts, Google Podcasts or add us to your Flash Briefing on your smart speaker.

The post Cyber Security Today, Jan. 8, 2024 – How a Spanish cellular carrier’s network was knocked offline, and more first appeared on IT World Canada.

Hashtag Trending Jan.8- Cybersecurity challenges in 2024; Tech companies still cutting back; OpenAI sued for copyright infringement

2024 promises to have more cybersecurity challenges including a continued shortage of cybersecurity workers.  Are tech companies quietly continuing to cut back. OpenAI is sued for copyright infringement – again. 



 

I’m your host Jim Love, CIO of IT World Canada and Tech News Day in the US.

As we dive into 2024, cybersecurity experts are sounding the alarm on the evolving tactics of hackers. The emerging threats are not just more sophisticated but are also exploiting new technologies and platforms.

We can expect more of the same in some areas:

– AI-Powered Attacks: Hackers are increasingly leveraging artificial intelligence to automate attacks, making them more efficient and harder to detect.

– Deepfakes and Misinformation: The use of deepfakes to spread misinformation or impersonate individuals is on the rise, posing significant risks to personal and corporate security.

– Crypto and Blockchain Vulnerabilities: Cryptocurrency platforms are becoming prime targets for cyberattacks.

– Supply Chain Compromises: Hackers are focusing on supply chain vulnerabilities, aiming to disrupt entire networks through a single entry point.

But an article in Axios that I read had some haunting comments from Wendi Whitmore, senior vice president of Palo Alto Networks.

She pointed out that data leaks rose exponentially in 2023 as cybercrooks got better at exploiting critical vulnerabilities before companies discovered them.

And in 2023 hackers demonstrated a deep understanding of how businesses work and the way they operate with suppliers – all of this will be fuel for future exploits.

With these challenges, and despite other news that some tech companies are still cutting back, the shortage of cybersecurity workers continues into 2024.

The US has only enough workers to fill 72 per cent of the available cybersecurity jobs according to a report from CyberSeek

So 2024 is just another day in paradise.

Sources include: Axios and CyberSeek

Are tech companies quietly continuing to cut back?

An article in TechPro featured claims from a senior AWS developer about Amazon’s alleged strategy to subtly encourage employees to leave. 

The report suggests that Amazon is creating conditions that subtly nudge employees towards leaving, rather than openly conducting layoffs.

Amazon, like many tech companies, appears to be facing continuing market pressures and economic uncertainties. 

I doubt that this is just Amazon. It appears that the troubles continue in the tech industry, with companies trying to deal with a challenging economic landscape.

That’s despite a critical shortage of cybersecurity workers and unemployment numbers that are the lowest they’ve been in decades. 

We live in strange times.  And they may just get stranger. A recent edX survey of 800 executives and 800 employees has brought to light some startling predictions about the future of workplace skills. Nearly half of the current workforce skills are expected to become obsolete in just two years, primarily due to advancements in artificial intelligence.

About 49 per cent of existing skills in the workforce today are predicted to be irrelevant by 2025.

Over half (56 per cent) of entry-level knowledge worker roles are expected to be eliminated within the next five years because of AI.

47 per cent of C-Suite executives believe that most or all of the CEO role could be automated or replaced by AI, with 49 per cent of CEOs themselves agreeing with this view

92 per cent of executives acknowledge the importance of improving their AI skills within the next one to two years, with 79 per cent fearing they’ll be unprepared for the future of work if they don’t learn to use AI.  And 56 per cent thought their own roles will be completely or partly replaced by AI. 

Sources include: Forbes

Nonfiction authors Nicholas Basbanes and Nicholas Gage have filed a class-action lawsuit against Microsoft and OpenAI, alleging copyright infringement. The lawsuit claims the defendants used the authors’ copyrighted works to develop a billion-dollar AI system. This follows another suit by The New York Times against Microsoft and OpenAI, that happened over the holidays. 

Among the damning evidence that Times produced was a prompt that generated an almost word for word copy of an article from ChatGPT. Talk about getting caught red handed. 

That may be why there are reports that OpenAI is frantically making the rounds and trying to build partnerships with publishers.  

And my favourite story coming back is from Axios where they reported there’s a growing nostalgia for the pre-internet era, especially among those who never experienced it. 

There are interesting relics like pay phones, paper maps, and typewriters.

Shows like Friends and Seinfeld are seeing a resurgence of interest.

Apparently for younger generations who grew up in the internet age, these relics offer a glimpse into a different way of life, fostering a sense of curiosity and nostalgia.

I guess we’re sort of like vinyl records – from when analogue was where it’s at.  

I don’t know. Since I read this article I’m of two minds. One, I’m not sure how I feel about being a relic. But I also keep hearing that old song from Hughie Lewis and the News – it’s hip to be square. 

If you don’t know the song – google it. Or better, buy the album on vinyl.

And that’s what’s trending as we come back for another year. 

Hashtag Trending goes to air 5 days a week with a special weekend interview show we call “the Weekend Edition.” 

To those of you who wrote me at jlove@itwc.ca –thanks. With a special shout out to one reader who pointed out some inconsistencies from last year. You know who you are. And thanks. 

You can also leave a comment after the show notes posted on itworldcanada.com

I’m your host Jim Love.  It’s great to be back.  Talk to you tomorrow.

The post Hashtag Trending Jan.8- Cybersecurity challenges in 2024; Tech companies still cutting back; OpenAI sued for copyright infringement first appeared on IT World Canada.

Hacked U.S. healthcare provider’s data archive involved over 900,000 people

Securing archived sensitive data from a data breach is just as important as protecting transactional information, experts say.

The latest example of this is an American medical services provider, Transformative Healthcare, that had to notify just over 911,000 people at the end of December that some of their personal information it had archived from a now-defunct division, Fallon Ambulance Services, was copied by a hacker.

Transformative Healthcare bought Fallon, which operated in Massachusetts, in 2018, but closed the company in 2022. For legal reasons, the parent company has to keep an archived copy of Fallon’s records on its computer systems.

However, as detailed in a regulatory filing with Maine’s attorney general’s office, last April suspicious activity was detected in the Fallon archive. On investigation, it was realized a hacker accessed the data in February. It took the company seven months to determine how many people may have been affected by the compromise.

Data copied could have included people’s names, addresses, Social Security numbers, medical information, including COVID-19 testing or vaccination information, and information provided to Fallon in connection with employment or application for employment.

Attackers may go after an organization’s data archives deliberately, or because they can’t get into production data. Regardless, researchers at Proofpoint argue in a blog, “attackers know that archives have a wealth of information on organization intellectual property, internal messages, and financial data. These data archives are a target for attackers who gain access to high-privilege network accounts or exploit vulnerabilities that give them access to archive data.”

The post Hacked U.S. healthcare provider’s data archive involved over 900,000 people first appeared on IT World Canada.

Cyber Security Today, Jan. 5, 2023 – 23andMe blames poor user password practices for a data breach

23andMe blames poor user password practices for a data breach.

Welcome to Cyber Security Today. It’s Friday, January 5th, 2024. I’m Howard Solomon, contributing reporter on cybersecurity for ITWorldCanada.com and TechNewsday.com in the U.S.



 

Who’s at fault for the recent huge data breach at the genetic testing service 23andMe? Users and their poor password practices, says the company. That’s according to a news story on TechCrunch.  The company is writing people that some customers “negligently recycled and failed to update their passwords,” which led to the data breach. The company denies the attack was the result of 23andMe failing to maintain reasonable security measures. According to the news story, before the data theft the use of multifactor authentication for login protection was optional. Now it’s mandatory. Hackers were able to access the accounts of about 14,000 people by brute-forcing logins with a list of stolen usernames and passwords from other sites. Those accounts held personal information of linked relatives, so the total number of victims added up to 6.9 million people.

In a commentary Ken Westin, field CISO of Panther Labs said blaming victims for a data breach isn’t fair. On the other hand, other IT experts say subscribers to any service have to take some responsibility for their password practices.

Users of the LastPass password manager can’t get away with short master passwords any more. According to Bleeping Computer, the company says subscribers now have to create master passwords of at last 12 characters. Since April that’s been the rule for new users or those resetting their passwords. But older accounts were still able to use short master passwords. As many people say, the longer the better.

Russian hackers were inside the biggest Ukrainian telecom provider for at least seven months before knocking it offline last month. That’s what the head of Ukraine’s cybersecurity agency has told the Reuters news agency. Service to about 24 million users was chopped for days when the attack wiped thousands of the telco’s virtual servers. The official said the incident is a warning to countries around the world that “no one is actually untouchable.”

Canadian mining company Barrick Gold has become the latest business to tell people their data was stolen in the hack of a MOVEit file transfer server. The company notified the Maine Attorney General’s office this week that it is sending letters to over 2,700 victims. It isn’t clear if these are only Americans. Barrick spokespersons didn’t reply to an emailed query for clarification. So far over 2,726 organizations have been victimized directly or indirectly of the hack of MOVEit file transfer systems, resulting in the exposure of data of over 93 million people.

Xerox says some personal information held by its Business Solutions subsidiary was stolen in a recent cyber attack. The incident had no impact on Xerox’s corporate systems, operations or data, the company says.

Finally, Google is expected to soon start publicly testing a version of its web browser that by default deletes third-party cookies. The goal is to improve privacy. According to The Register, an estimated 30 million Chrome users – representing roughly one percent of the user base – will be involved in the test. In the second half of this year a broader phase out of third-party cookies is expected. Chrome users have been able to opt-in to a program of dropping third-party cookies for several months.

Note that because of the holidays there won’t be a Week in Review podcast this afternoon. The show resumes next Friday.

Follow Cyber Security Today on Apple Podcasts, Google Podcasts or add us to your Flash Briefing on your smart speaker.

The post Cyber Security Today, Jan. 5, 2023 – 23andMe blames poor user password practices for a data breach first appeared on IT World Canada.

Ransomware gang starts leaking data stolen from Quebec university

The LockBit ransomware gang has started releasing data it says was stolen last month from a Quebec university.

The data is from the University of Sherbrooke, with a student body of about 31,000 and 8,200 faculty and staff. Sherbrooke is a city about a two-hour drive east of Montreal.

Asked in an email to comment on the action by LockBit, university Secretary General Jocelyne Faucher referred to the institution’s Dec. 7 statement that said, “certain data from one research laboratory has been compromised.” The incident has had no impact on the university’s activities, the statement added. An investigation continues.

According to a news report on the French language Radio Canada, the university said last month it had not been hit with ransomware.

The university hasn’t said if the compromised data included personal information or intellectual property.

Threat actors go after the education sector for several reasons: First, they believe public school boards can be pressured into paying to get access back to stolen data about children. Second, they believe post-secondary institutions will be subject to pressure from students to pay for the return of stolen personal and research data.

According to Sophos’ most recent annual ransomware report, the education sector was the most likely to have experienced a ransomware attack in 2022. Eight per cent of educational institutions surveyed said they had been hit. “Education traditionally struggles with lower levels of resourcing and technology than many other industries,” the report says, “and the data shows that adversaries are exploiting these weaknesses.”

In June, Ontario’s University of Waterloo interrupted a ransomware attack after being tipped off by the RCMP. The university’s on-premises email server was compromised, but “only a tiny number of users were impacted,” the institution said. All university IT users had to re-set their login passwords.

One of the most recent cyber attacks on a Canadian university happened in December, when Memorial University’s Grenfell campus in Corner Brook, NL, was hit. According to the CBC, IT services at the Marine Institute were temporarily shut down. The start of the new semester at Grenfell had to be shifted to Monday, Jan. 8 from Thursday, Jan. 4.

All Grenfell faculty, staff and students have to change their login passwords. The university said today it has been told the campus “will likely feel the impacts of this incident for at least a few weeks.” Work includes providing laptops for faculty and staff and securing internet and Wi-Fi hotspots.

In the U.S., recent cyber attacks on the education sector included the forced IT shut down in November at Indiana’s DePauw University and an attack claimed by a ransomware gang in October at California’s Stanford University.

The post Ransomware gang starts leaking data stolen from Quebec university first appeared on IT World Canada.

In surprise move, Intel, DigitalBridge launch enterprise GenAI firm

Intel and global investment firm DigitalBridge Group yesterday announced the formation of Articul8 AI, an independent company offering enterprise customers what was described as a “full-stack, vertically-optimized and secure generative artificial intelligence (GenAI) software platform designed to keep customer data, training, and inference within the enterprise security perimeter.” It will be available in the cloud, on premises, or in a hybrid deployment.

The intellectual property and technology driving the platform were developed at Intel, and in addition, it is also providing Articul8’s first chief executive officer (CEO), Arun Subramaniyan, formerly vice president and general manager in Intel’s data centre and AI group.

According to a release, “the two companies will remain strategically aligned on go-to-market opportunities and collaborate on driving GenAI adoption in the enterprise.”

The move was something Brian Jackson, principal research director at Info-Tech Research Group, did not expect. “We know their chips aren’t ideal for training these large models used for GenAI, and we don’t typically think of Intel for its software development prowess,” he said. “Yet here it is launching a generative AI software platform.

“It looks like they are looking to sell out-of-the-box GenAI solutions to specific industry problems, with several examples listed on the Articul8 website. They focus on positioning the software platform as able to run within a company’s security perimeter. Definitely one of the top concerns we hear from enterprise customers about using GenAI is that data could be exposed to third-party providers, or worse yet used to train a provider’s own large language model.

“That could threaten a company’s business model, so guarantees of privacy and security by virtue of running models on your own infrastructure will appeal to many enterprises, especially those in the critical infrastructure or government category.”

Jackson also sees the logic in DigitalBridge’s involvement, given its investments in managed service providers who could provide enterprises with necessary services, and noted that the spinoff of the unit made sense.

“Intel is also working to mitigate its perceived weaknesses in the GenAI area,” he said. “Articul8 will support NVIDIA processors as well, and being able to work with a competitor’s hardware is probably the main reason Intel felt the need to spin out this business unit.”

But, he added, there’s still a lack of clarity about what Articul8 will actually provide: “Is it about training and customizing models or does it have specific solutions ready to deploy to operations? Is this for developers to get creative about what they want to build, or is it for business leads to get access to GenAI capabilities out of the box?”

In a release, Intel chief executive officer (CEO) Pat Gelsinger said that “with its deep AI and HPC domain knowledge and enterprise-grade GenAI deployments, Articul8 is well positioned to deliver tangible business outcomes for Intel and our broader ecosystem of customers and partners.”

DigitalBridge Ventures is the lead investor in the company, with Intel and a syndicate of other investors including Fin Capital, Mindset Ventures, Communitas Capital, GiantLeap Capital, GS Futures and Zain Group also on board.

The post In surprise move, Intel, DigitalBridge launch enterprise GenAI firm first appeared on IT World Canada.