Archive for July, 2022

Get Your Messiest with Taco Bell Canada and Twitch

Posted in Commentary with tags on July 27, 2022 by itnerd

Things are about to get messy with Taco Bell Canada and Twitch. During July and August, three Canadian Twitch Streamers—Mtashed,TheStefSanjati, and DeadlyCreatorYT— are getting downright messy with Taco Bell Canada by giving away a bib adorned with taco remnants to their followers.

Twitch Streamers will create their own art made entirely of taco toppings—the sauciest of sauces and the cheesiest of cheeses—by wearing a canvas bib that collects their taco drippings as they stream online to thousands of followers. 

Viewers who take part in the streams can donate Bites, gift Subs or spam Taco Bell emotes to be entered to win a grand prize—their favourite streamer’s bib (food scraps, stains, and all) sealed and framed, along with all the fixings needed to create their very own beautiful mess.  

To watch Mtashed create his bib in real time, check out his Twitch stream here, or tune into the below Livestreams:

GoDaddy Launches Empower Program In Canada In Collaboration With Futurpreneur 

Posted in Commentary with tags on July 27, 2022 by itnerd

 GoDaddy today announced a national partnership with Futurpreneur for the Canadian launch of Empower by GoDaddy, a global community program equipping entrepreneurs with the training, digital tools, and expert guidance needed to accelerate their entrepreneurial journeys and grow their businesses online.

In collaboration with Futurpreneur, a national non-profit which has delivered financing, mentorship and resources for diverse young entrepreneurs aged 18-39 for over 25 years across Canada, Empower by GoDaddy will support aspiring entrepreneurs with dedicated training and educational resources. This collaboration provides passionate entrepreneurs with access to workshops and intensive bootcamps in both English and French, curated by Futurpreneur, as well as access to a global network of business experts. The Empower curriculum offers a chance to learn new skills in key areas from website building, e-commerce design and brand development, to better understanding search engine optimization tools and digital marketing on social media platforms.

The first workshops, titled “Website Best Practices” (in English) and “Les meilleures pratiques du Web” (in French) will focus on how to strategically build a website and improve a business’ digital presence. The next round of workshops, “Social Media Best Practices” (August 10, 2022, in English) and “Les meilleures pratiques des médias sociaux” (August 17, 2022, in French), will help entrepreneurs to better understand how social media can be leveraged to support their business goals.

Resources that Close a Gap for Small Businesses

According to a recent study conducted by Logit Group on behalf of GoDaddy Canada, small business owners see increasing value in digital tools and having an online presence. Yet nearly one-quarter of businesses reported unfamiliarity and a general lack of knowledge with digital tools.  

Understanding these challenges, the Empower by GoDaddy program is built on years of experience to help small business owners close the knowledge and skills gap in a business world facing digital transformation. With access to GoDaddy’s 10-course online curriculum and resources, participants can join workshops hosted by Futurpreneur and led by a GoDaddy expert to further empower them to take their first steps in building, managing and growing their online presence.

All Empower by GoDaddy program participants will receive a free two-year subscription to the GoDaddy Websites + Marketing commerce website builder tool, as well as a .com, .org or .ca domain name of their choice for two years. Participants can also access monthly live sessions on digital presence topics, hosted by Futurpreneur and facilitated by GoDaddy customer support experts.  

To learn more about Futurpreneur and Empower by GoDaddy and how entrepreneurs across Canada can register for the workshops hosted by Futurpreneur, visit:futurpreneur.ca/myonlinebusiness

TSO Indirectly Pwned In Ransomware Attack

Posted in Commentary with tags on July 26, 2022 by itnerd

If you are a patron of the Toronto Symphony Orchestra (TSO), I think you’d like to know that a company that the TSO hired has been pwned in a ransomware attack. The TSO posted a statement but let me hit the highlights:

On July 10, 2022, our email provider, WordFly, became aware of a network disruption that rendered their technology inaccessible. We have come to learn that WordFly was subject to a ransomware attack. As part of the incident, the attacker exported customers’ information from the WordFly environment, including patron information that WordFly was handling on behalf of the TSO. WordFly assures us that there is no evidence to suggest that the data was misused for any purpose by this attacker, nor made publicly available. Further, WordFly’s understanding is that the data has now been deleted from the attacker’s possession. If you wish to learn more, you can read WordFly’s statements on the incident, which are available on WordFly’s website. The TSO’s own systems were not impacted by this incident.

As for who and what was affected:

Your payment and financial data were not compromised in any way by this incident. Personal information potentially impacted includes your name, email address, TSO Patron ID and information about your TSO account (e.g. donor level, credit on account status, gift certificate status). It may also include personal information certain patrons have volunteered to the TSO when responding to a survey, such as demographic information (age range, gender, ethnicity) and opinions on the TSO.

Now that’s not trivial. The TSO then goes on to explain what they’re doing about it and steps that patrons can do to protect themselves. But this is an example of why you have to choose the companies who work with you carefully. Otherwise you can end up like the TSO. As for the email provider, they are still down and likely won’t be up anytime soon.
 

Cyber Attacks Increased 32% Year Over Year: Check Point

Posted in Commentary with tags on July 26, 2022 by itnerd

Check Point Research today released findings showing that weekly cyber attacks increased 32% year-over-year, with 1 out of 40 organizations impacted by a ransomware attack. Key highlights include:

  • Average weekly attacks per organization worldwide reached a peak of 1.2K attacks, a 32% increase year-over-year
  • Education/ Research sector continues to be the most heavily attacked industry, seeing a 53% increase year-over-year
  • Globally, 1 out of 40 organizations were impacted by Ransomware attacks, a worrying 59% increase year-over-year
  • Latin America seeing the largest increase in Ransomware attacks, with 1 out of 23 organizations impacted weekly, (43% increase YoY),
    with the Asia region following with 1 out of 17 organizations impacted weekly (33% increase YoY)

All of those numbers are pretty scary, but not surprising. Saryu Nayyar, CEO and Founder, Gurucul explains why:

     “It’s no surprise that cyber-attacks are increasing year over year. What is surprising is that organizations still aren’t deploying modern defenses to protect themselves from these increasingly sophisticated attacks. Ransomware in particular is a nasty trend since criminals often execute double extortion tactics whereby, they not only encrypt the victim’s data but also exfiltrate it for sale or exposure. This reinforces the need for newer and more advanced technologies beyond current XDR and SIEM platforms to prevent a successful detonation of ransomware. Prioritizing solutions that automate detection, prioritize seemingly random indicators of compromise for further investigation and automate responses with a high-level of confidence are critical in deciding where to invest.”

Chris Olson, CEO of The Media Trust has this to add:

     “The alarming acceleration of cyberattacks in 2022 has many factors, from rising financial and political incentives for cybercrime, to the proliferation of malware and exploits through easily accessible darknet markets. Attackers are also increasingly relying on the Web and mobile devices as channels for ransomware spread, expanding the number of surfaces through which consumers, organizations and government agencies can be targeted.

With consumers bearing the heaviest cost for data breaches, financial fraud and exposed credentials, today’s organizations must prioritize the safety of their customers, and vet their digital third parties for strong security practices.”

I think this Check Point report illustrates that the time for talking about cybersecurity is over and the time for action is now. I say that because everyone is a potential victim if they don’t take action to defend themselves.

Trend Micro Announces New Updates to Cloud Security Platform

Posted in Commentary with tags on July 26, 2022 by itnerd

After years of leadership in the fast-growing global market for cloud security, Trend Micro has announced its new deployment models and services to improve customer experience.

Throughout two years of the global crisis, enterprise leaders invested in cloud infrastructure and services to streamline business processes, lower costs and drive innovation. This also means that business-critical cloud-native applications increased in complexity and broadened their corporate cyber-attack surface.

Two new features for the cloud security platform include:

  • Simplified deployment and management of cloud intrusion prevention system infrastructure, removing burdens and reducing friction for running cloud-based network security.
  • Container security free from infrastructure deployment to scan container images faster with no impact to speed. This update extends the company’s existing container offering, which was the first offered by a cybersecurity provider.

It is also worth noting: 

  • Trend Micro was the first dedicated security provider to offer cloud protection in 2010. Since then, the company has built the most comprehensive cloud security platform, protecting all types of cloud environments and assets.
  • Last year, Trend Micro the launched its Cloud One regional data centre in Canada to uphold data residency, safeguard data privacy and reduce the risk of a security breach for Canadian organizations.
  • In 2022, Trend Micro has also added to its more than 15 AWS competencies to now include Healthcare and DevSecOps.
  • Trend Micro has been crowned no. 1 in cloud workload security for the fourth consecutive year and furthers its market leadership with ongoing innovations based on customer feedback.

It has also achieved the updated Amazon Web Services (AWS) Security Competency, which demonstrates that Trend Micro continues to be a key AWS Partner Network (APN) member in helping secure joint customers’ cloud environments.

Zoho Celebrating Major Milestones in Growth, Investments, and R&D

Posted in Commentary with tags on July 26, 2022 by itnerd

Zoho Corporation, a leading global technology company, announced achieving a rate of 38% year-over-year growth and surpassing the 80 million user mark. In addition to ongoing global expansion, the company continues to grow its product portfolio and make investments in automotive, robotics, and health care technologies. Zoho also celebrated opening 59 new global hub-and-spoke offices in rural areas and small cities over the last two years to expand into new markets and further support local communities.

The announcement, made at Zoho’s annual analyst summit, affirms the company’s commitment to developing resilient solutions that support all businesses, many of which have been negatively impacted by recent economic disruption.

Investments

Zoho has made strategic investments in the areas of automotive, robotics, and health care technology to support the development of and access to advanced solutions by those in need. These include:

  • An investment in Silicon Valley-based smart electric utility vehicles and powertrains manufacturer Boson, which focuses on light utility vehicles (LUVs). Boson’s initial focus is on farming, and Zoho shares that focus as it expands into rural areas across the globe.
  • An investment in electric motorcycle company Ultraviolette Automotive in partnership with TVS Motor Company, an India-based motorcycle manufacturer. The combined investment totals roughly $15 million and will support the launch of a new, high-performance electric two-wheel vehicle slated for release in 2022.
  • A $5 million investment in Voxelgrids, an Indian startup that builds Magnetic Resonance Imaging (MRI) scanners. This is being used to foster development of deep technological capabilities and intellectual property (IP) in the country.
  • Forming a consortium of local technology companies based in the Kongu region of India. Through this initiative, Zoho will make a capital investment to set up centers in the region focusing on the research and development of critical technologies for capital goods manufacturing, like machine tools, industrial automation software, and production process know-how.
  • A $2.5 million investment in Genrobotics, an Indian startup building robotics and AI-powered solutions for social issues such as hazardous working conditions. Zoho’s investment will assist Genrobotics in its mission to eradicate manual scavenging in India and provide safety and dignity to workers in the sanitation and oil and gas industries.

Innovation and R&D Diversity

Zoho’s investment and innovation philosophies are rooted in the research and development of powerful, unified tools that are customizable to any organization’s distinct business needs and vision. More than 60% of the company’s workforce is devoted to engineering, both in the development of new technologies and building ways for those apps to complement and integrate with one another. To date, Zoho has developed more than 55 apps, having grown from 40 only two years ago. Though the scope of our offerings continues to increase, our price does not, and we remain committed to affordability—offering both free and paid versions of every product—and delivering software tailored to the distinct needs of small and medium-sized businesses.

Zoho’s Proven Growth Philosophy: Transnational Localism

Zoho continues to celebrate global expansion through its Transnational Localism effort, first introduced in early 2020 as a means to create self-reliant local communities and economies. Since then, the initiative has grown to include new global offices, local hiring, partnerships with local organizations and government bodies to lower the technology adoption barrier for businesses, upskilling courses in association with educational institutes, language localization including RTL support for languages like Arabic, and local pricing for several countries. The offices opened as part of Zoho’s Transnational Localism efforts follow a hub-and-spoke model, with larger offices serving as hub to several dozen small spoke offices located in rural areas and towns around the world. This method of growth allows employees to stay in their hometowns and contribute to their local community while working for a leading, globally recognized technology company.

The company improved access to both software and localized Zoho support, opening 59 hub-and-spoke offices in the last two years. In addition to aggressive expansion into new territories and markets, including Canada, Latin America, the Middle East, Africa, and Southeast Asia, Zoho has announced plans to add 100 new small-scale offices in rural districts across India in the next few years.

Zoho celebrated impressive regional growth, with headcount up 300% outside of India since the start of 2020. It also aims to hire at least 2,000 employees across engineering, technology, and product development, particularly software developers, quality assessment engineers, web developers, designers, product marketers, writers, technical support engineers, and sales executives within the next year. The recent openings of Zoho’s McAllen and New Braunfels, TX, offices in April 2022 and December 2021, respectively, exemplifies this mission. Since its ribbon-cutting, the McAllen office now hosts 40+ employees from surrounding communities, and has maintained an ambitious hiring cadence. The New Braunfels office has added more than 30 employees since its opening.

LockBit Pwns Again…. This Time It’s Italy’s Tax Agency Who Gets Pwned

Posted in Commentary with tags on July 26, 2022 by itnerd

The LockBit ransomware group has been on a rampage as of late. The group has once again claimed to have stolen mass amounts of data, this time from Italy’s tax agency. The 78GB haul stolen from the Italian Revenue Agency was added to its dark web leak site. The ransomware gang has given the Agency five days to pay the ransomware to avoid the leak of stolen data. This is after the Town Of St. Mary’s Ontario was apparently pwned by the group.

Dr. Darren Williams, CEO and Founder of BlackFog had this to say:

“LockBit has been busy in the last few days, claiming 12 of the 18 attacks we’ve spotted. Other notable incidents include the small Canadian town of St Mary’s, and the Town of Frederick in Colorado. As with other cybercriminal gangs of late, data exfiltration followed by extortion is their weapon of choice. LockBit’s focus appears to be on targeting under resourced organizations with weak security where they can cause significant disruption, thus increasing the odds of a successful ransom payday. As with all attacks, extortion is the name of the ransomware game and organizations really need to add third generation cyber tools like data exfiltration technology to prevent this from happening.”

Clearly this is a big sign that everyone needs to make sure that they can defend themselves against either being pwned at all, or can recover from being pwned so that they don’t have to pay threat actors like LockBit. Because it is clear as day that LockBit means business.

Guest Post: Social Media Data Leaks Account For Over 40% Of All Breached Records

Posted in Commentary with tags on July 26, 2022 by itnerd

Social media is quickly turning into a primary security weak point. A single data breach within one of the major social media networks can result in millions of records being stolen.

Within the past few years, we have seen multiple large-scale data breaches involving companies like Facebook and Twitter. Yet, we rarely see the bigger picture.

Luckily, data presented by Atlas VPN gives insight into the scope of the issue. It turns out that 41% of all compromised records in 2021 originated from social media data leaks, which is a significant upsurge compared to 25% in 2020.

The data presented is based on the 2022 ForgeRock Consumer Identity Breach Report, which gathered data from various sources, such as 2021 Identity Theft Resource Center, IBM Ponemon, TechCrunch, Forrester Research, as well as UpGuard, and IdentityForce.

A few other factors make social media a security weak point within the current online landscape.

First, criminals can prey on business clients by posing as the company in order to obtain credentials. This is becoming especially prevalent since companies increasingly use social networks to communicate with customers.

Second, fraudsters frequently attempt to infiltrate businesses by leveraging mutual connections, which create a false sense of security.

Moreover, people who overshare on social media make it simple for thieves to locate personal information that aids in company breaches. 

To read the full article, head over to: https://atlasvpn.com/blog/social-media-data-leaks-account-for-41-of-all-records-breached

Review: Creative Aurvana Trio LS Earphones

Posted in Products with tags on July 26, 2022 by itnerd

Wireless earphones are all the rage. But audiophiles know that quality audio comes from having a hardwired connection. Which is why wired earphones haven’t faded into history. And today I have a pair of wired earphones that offer an insane value proposition. And those are the Creative Aurvana Trio LS. Let’s have a look at them:

One cool party trick is that each earbud has a magnet that allows them to click together like this. That means that they are less likely to get tangled.

In this picture you see a button and microphone. The single click button offers the following controls:

  • Single click to play
  • Single click to pause
  • Answer/hang up calls

This is a gold plated Gold-plated CTIA 4-pole 3.5 mm jack. This Plug has a number of uses for Audio, Video and Computer Applications. Since we’re talking audio at the moment, this type of plug allows for ground, left channel, right channel, and microphone.

Out of the box, the Aurvana Trio LS comes with the following:

  • The earphones
  • Small and large ear tips (medium eartips are preinstalled)
  • Cloth bag

So, the big questions are, how does it sound, and what is the microphone quality like. Let’s start with the sound. These earphones use a Liquid Silicone Rubber (LSR) driver. And that allows these earphones to sound as follows:

  • They sound responsive at lower frequencies
  • Treble does not sound harsh at all
  • While there is a emphasis on bass, they don’t sound over the top on that front.
  • The midrange is also emphasized but isn’t over the the top.

What helps with all of this is that the earphones are designed to be noise isolating. Meaning that it passively removes environmental noise because they are in your ear. So if you like a sound that is not bass or treble heavy, these earphones are for you.

To test the quality of the microphone, I plugged it into my MacBook Pro and recorded an MP3 file to get this result:

This to me suggests that the microphone will be perfectly fine for you if you have to do a Zoom or Teams call, or if you have to answer a good old fashioned phone call. Assuming that your phone still has a headphone jack.

Here’s the part that really gets my attention. Creative Aurvana Trio LS go for $39,99 USD which given what you get here, I would give my stamp of approval on. If you need a pair or wired earbuds that have quality audio and a quality microphone, these ones are ones that are worth a look.

TSA Releases Revised Cybersecurity Requirements For Oil And Gas Pipelines

Posted in Commentary with tags on July 25, 2022 by itnerd

The Transportation Security Administration on Thursday issued revised cybersecurity directives for oil and gas providers more focused on performance-based measures. This following extensive input from federal regulators and private industry stakeholders in the wake of the May 2021 ransomware attack on Colonial Pipeline.

Chris Clymer, Director & CISO, Inversion6 had this comment:

When a cyberattack took the Colonial Pipeline offline and caused gas shortages all up and down the east coast of the US, an inevitable question was “How can this happen?”  Even more perplexing for cybersecurity professionals was learning that rather than following under the well-established NERC-CIP security framework which covers most of the energy sector, the pipelines had actually been related to the authority of the TSA.  This is far from TSA’s area of expertise, but to their credit they had put some guidelines out before the incident…unfortunately, these were simply guidelines, not required.

It is extremely welcome news to see that the US’s most competent cybersecurity agency, CISA, has dove into the fray and helped TSA to establish new requirements…and that they have been made just that:  requirements.  As we’ve seen over and over unfortunately, cybersecurity investments are neglected in virtually every vertical without outside pressure.  Pipelines should be in better shape because of this attack.  The question now:  what other important infrastructure is sitting out there, falling into the political cracks and being neglected as a result?

Companies beyond the oil and gas sector should look at this guidance as it will provide a roadmap as to how they can protect themselves from attacks of all sorts. Because everyone these days is a target of cybercrime and cyberattacks.