Telecommunications play a critical role in the climate change discussion. It’s why companies like TELUS are invited to sit at the strategy table with wildfire experts during increasingly severe fire seasons. With climate change fuelling increasingly severe wildfires across Canada, TELUS has been building specialized expertise to ensure vital lines of communication remain open so that impacted residents and emergency providers are connected to reliable networks when and where they are needed the most. By necessity, that expertise has now expanded to seasonal flooding.
TELUS is also looking to the future; specifically, supporting Canada in reaching its Paris climate targets through digital technology.
A new report “Clean Connection: How Digitiation Can Support Canada’s Path to Net-Zero” developed by Toronto Metropolitan University in partnership with 17 cross-industry organizations, and sponsored by TELUS, has found that digital tech — missing from Canada’s climate action plan — is a virtually untapped resource and the missing link in Canada’s journey toward net-zero. The report lays out 10 recommendations that industry actors and policy-makers should take to realize the benefits that connectivity can have on lowering emissions.
The public conversation surrounding climate change policy completely misses this data-backed reality.
Here is the link to the report: https://dais.ca/reports/clean-connection-how-digitization-can-support-canadas-path-to-net-zero/
Shell Becomes The Latest Company To Be Pwned By The MOVEit Vulnerability
Posted in Commentary with tags Hacked on July 7, 2023 by itnerdShell has confirmed in a very brief statement that hackers accessed the personal information of some employees as part of the global MOVEit Transfer tool vulnerability exploitation.
The Clop ransomware group claims on its leak site that it published Shell’s data after the company refused to negotiate, but the links to the 23 archive files labeled ‘part1’ appear to be broken. Shell currently has 86,000 employees around the world, but they did not mention how many of those employees may have been affected or what data was be stolen.
Shell was also targeted by the Cl0p group in 2020, through a zero-day exploit targeting an Accellion file transfer service.
According to Brett Callow, threat analyst at Emsisoft, so far, the vulnerability in MOVEit has pwned this number of organizations:
Carol Volk, EVP, BullWall had this to say:
“According to Brett Callow, threat analyst at Emsisoft, so far, the vulnerability in MOVEit has Affected more than 17.5 million people’s PII. Much of this information will be used in attempts to access networks and some of those attempts will be successful. At this rate of exposure is almost impossible to fully protect networks from intrusion. Get your defenses up – get your backup and containment systems ready, they are definitely coming for the rest of us.”
Stephen Gates, Principal Security SME, Horizon3.ai followed up with this:
“The MOVEit debacle, and associate breaches now impacting 17.5+ million people (and counting), will likely go down in history as proof that organizations must do a better job of immediately applying patches when they are available. When organizations wait to apply patches means the window of opportunity is wide open for attackers.
“Although multiple patches have been available to address CVE-2023-36934, 36933, and 36932, the Clop ransomware group is still making claims that it has compromised data from many organizations. The conclusion one can draw from this is that many organizations have not applied the patches. So why is that probably the case?
“Regardless of their reasoning, organizations are putting tens of millions of people at risk.”
I think it’s more than clear that the MOVEit vulnerability is a “today problem.” Organizations need to patch. And then if new patches come out, they need to patch some more. Alternately they can just dump MOVEit. Either way, sitting on the sidelines is not an option.
Leave a comment »