Vehicle & Property Records Exposed In Data Breach

Posted in Commentary with tags on November 27, 2024 by itnerd

A data breach involving SL Data Services/Propertyrec — an Information Research Provider — was discovered and reported to WebsitePlanet by cybersecurity researcher Jeremiah Fowler. 

What happened: 

A non-password-protected database containing more than 600K records was exposed. The leaked data includes PII, real estate data, court records, vehicle records (license plate and VIN), background check documents and more. 

Why it matters: 

A potential concern is targeted phishing or social engineering attacks, where a criminal could impersonate an individual whose personal information was exposed in a background check document. 

Read their detailed report here: https://www.websiteplanet.com/news/propertyrecs-breach-report/

Microsoft To World: We Don’t Use Word And Excel To Gather Your Data To Train Our AI Models

Posted in Commentary with tags on November 27, 2024 by itnerd

You might recall that I posted a story on Word and Excel using your data to train Microsoft’s AI. Well, Microsoft has finally come out and said something about this via Twitter:

That’s seems on the surface to be a definitive statement. But The Register decided to go down the rabbit hole on this:

Microsoft’s Connected Experiences option in its productivity suite has been causing consternation amid accusations that the default setting might allow Microsoft to train AI models using customers’ Word and Excel documents and other data.

The Windows giant vehemently denies the claims. A spokesperson told The Register: “In Microsoft 365 consumer and commercial applications, Microsoft does not use customer data to train large language models without your permission.”

We asked Microsoft what it meant by “permission” and if the permission was opt-in or opt-out, and the IT titan has yet to respond.

Maybe I am reading too much into this. But you would think that if you were doing nothing wrong, you’d want to get that out there quickly. Thus the fact that Microsoft hasn’t responded to the question of what they meant by “permission” and whether it was opt in or opt out is curious. I’ll be watching this because I don’t think that this story is over and done with by a long shot.

New Research Warns of Continuous Use of Sextortion Tactics Targeting Victims

Posted in Commentary with tags on November 27, 2024 by itnerd

Secureworks has just shared information on a scam that is targeting people in the guise of Sextortion. The scam suggests victims have been caught on video and demands payment in bitcoin to have the video deleted. In reality, the alleged videos do not exist, and it is an attempt to leverage the fear of a real Sextortion scam.

Though Sextortion is not a new tactic, Secureworks Counter Threat Unit (CTU) researchers have tracked the scams since at least 2018, and observed that very little has changed in these attacks, suggesting that the tactics continue to be successful.

Commenting on the findings, Rafe Pilling, Director of Threat Intelligence, Secureworks Counter Threat Unit says:

“Cyber criminals are opportunistic, always looking for a way to make money fast at the expense of others. Sextortion is a horrendous crime, and one that the public is increasingly aware of. So, while this scam is awful in its methods, it is not surprising to see it being deployed. One of the key triggers of any scam is fear, creating concern and an instant feeling of urgency that is designed to panic people into making fast decisions that can be very costly. It’s important that people are aware of these scams so that they can avoid falling victim.”

The full blog is available here: https://www.secureworks.com/blog/phorpiex-continues-to-deliver-sextortion-spam

Canadian SMBs Outpace Global Average in Digital Adoption: Sage Study

Posted in Commentary with tags on November 27, 2024 by itnerd

Sage’s annual survey of 12,000 small and medium-sized business (SMBs) leaders globally – ‘Small Business, Big Opportunity’ – finds that business confidence among SMBs has reached new highs, with 86% expressing optimism about their success, up from 80% in 2023.   

This surge in confidence is attributed to improved operational efficiency, increased consumer spending, adoption of new technology, and enhanced cash flow, with nearly all SMBs (95%) recognizing their essential role in driving growth within their national economies. 

The data shows that Canadian SMBs are outpacing the global average in key areas, like digital investment (94% prioritize it versus the global average of 87%) and anticipated revenue growth (81% in Canada versus 70% globally). Canada’s leadership in digital adoption and growth among SMBs could be attributed to several factors: government support through digital adoption programs and the nation economies’ stability and resilience, allowing businesses to invest in growth and technology.  

Key Canada Findings:  

  • Confidence & Revenue Growth: Canadian SMBs reported impressive revenue gains, with 58% seeing growth over the past year, surpassing the global average of 45%. Looking ahead, 81% of Canadian SMBs expect further revenue increases, reflecting a higher optimism than their global peers (70%). 
  • Focus on Digital Transformation: A remarkable 94% of Canadian SMBs indicated that digital technologies are integral to their revenue strategies, compared to 87% globally. Driven by this priority, 76% of Canadian SMBs plan to increase their investment in technology over the next year, with a particular emphasis on artificial intelligence (AI) as a catalyst for future growth. 
  • Efficiency and Innovation: By embracing digital tools, 78% of Canadian SMBs report they can focus more on higher-value tasks, significantly exceeding the global average (71%). This shift underscores a commitment to operational efficiency and workforce productivity, as 60% credit improved efficiency for their business confidence. 

While Canadian SMBs have shown remarkable resilience, they continue to face challenges, particularly in managing rising costs and cash flow concerns. More than 60% of businesses report increased operating costs, and 53% anticipate further cost pressures in the coming year. As they navigate these challenges, SMBs express a need for supportive policies that can alleviate financial burdens and sustain their digital progress. 

As SMBs in Canada prepare for growth in the year ahead, digital investment will be a clear focus to drive productivity and time savings. Sage will continue to amplify their voices and work closely with partners and policymakers to foster an environment that supports their growth. This report is part of Sage’s ongoing commitment to championing the needs and priorities of SMBs and supporting their journey toward sustainable, technology-driven growth. 

As Canadian SMBs set their sights on growth, optimism and investment are on the rise, with a clear focus on technology as a driver of productivity and time savings. However, many SMBs also recognize the need for greater support to fully capitalize on these benefits.  

For more information on Sage’s “Small Business, Big Opportunity” 2024 report and to access the full findings, visit Sage’s digital newsroom

Arcitecta Data Management 2025 Predictions

Posted in Commentary with tags on November 27, 2024 by itnerd

Here’s some predictions for 2025 from Arcitecta from CEO Jason Lohrey that are very interesting:

Emergence of Next-Generation Archive Storage

As data volumes grow, more efficient and cost-effective archival storage solutions have become critical. Flash and disk-based storage options, while fast, come with high costs when scaling to large capacities. This has led to a resurgence in tape storage as a viable solution for modern needs, and the introduction of new, emerging technologies like storage on glass. Companies will look to aggregate smaller units into larger configurations that combine the scalability of tape with the flexibility of cloud standards. The renewed interest in tape and other archival storage solutions will continue to expand as the demands of modern data management evolve.

Real-Time Data Streaming and the Geo-Distributed Workforce

The rise of remote work and geographically distributed teams has changed how businesses operate. Real-time data streaming allows organizations to record events and share live feeds globally, enabling employees to collaborate on continuous data streams without needing to be physically present. This trend will likely accelerate in 2025 as more companies adopt tools that facilitate seamless broadcasting and data distribution. By enabling real-time collaboration across a distributed workforce, businesses can reduce travel costs, increase efficiency, and make quicker, more informed decisions. The global reach of data streaming technology will expand, allowing organizations to tap into a wider talent pool and create more dynamic and flexible operational structures.

GLAM Sector Will Face a Big Data Challenge

The GLAM (Galleries, Libraries, Archives, and Museums) sector is quickly becoming a significant player in the big data landscape. As these institutions curate petabytes of data, their needs evolve beyond traditional digital asset management systems. The complexity of managing vast amounts of multimedia data requires new big data solutions, including scalable storage systems and advanced analytics tools. As GLAM institutions embrace big data, they will require tools that can handle not just large volumes but also the diverse nature of the data they manage, paving the way for innovations in data curation and preservation.

Strengthening Security Amid Growing Data Exposure

Organizations will recognize that their current security measures are often inadequate in the face of sophisticated cyber threats. By 2025, more institutions will implement multi-factor authentication (MFA) in the data path to better protect their digital assets. This approach goes beyond securing user access to individual accounts and extends to securing the data flow itself.

Rogue actors continuously attempt to exploit vulnerabilities within data infrastructures. The rise in awareness of these risks will drive a shift towards more robust security protocols, ensuring that data remains protected from unauthorized access throughout its lifecycle.

The Rise of Storage Virtualization and the Data Fabric

As organizations look to optimize their storage strategies, the rise of storage virtualization is making it easier to interconnect various data storage technologies. Businesses can maximize their existing investments and avoid vendor lock-in by leveraging a data fabric—an architecture that unifies cloud, disk, tape, and flash storage into a single, logical namespace. This trend towards virtualization allows for a more flexible approach to data management, enabling businesses to mix and match technologies to meet specific needs. For example, high-performance workloads can run on flash storage while archival data is moved to tape. The ability to integrate various storage solutions seamlessly will be a key enabler for organizations aiming to improve efficiency, reduce costs, and scale their operations.

TELUS announces Black Friday Buy One Give One campaign

Posted in Commentary with tags on November 26, 2024 by itnerd

TELUS is transforming Black Friday shopping into a force for social good this holiday season: replacing the traditional BOGO (Buy One Get One) with BOGO+ (Buy One Give One).

In a uniquely Canadian promotion, TELUS is flipping the script on Black Friday deals with a powerful initiative: For every new customer who purchases a phone between November 29 and December 1, TELUS will provide a free phone and plan to a youth aging out of foster care through their Mobility for Good program

As part of a network that cares for its communities, customers are helping bridge digital divides and create a friendlier, more sustainable future by providing pre-loved devices that might otherwise end up in landfills. The Buy One Give One offer is available by phone, online, and in-store at select locations. Whether shopping for yourself or a loved one, Canadians can purchase with purpose and enjoy the latest technology while making a meaningful difference in their communities and giving the vital gift of connection to someone who needs it most.

Find out more about this and other Black Friday deals at https://www.telus.com

Thrive Opens New Data Center in Montreal

Posted in Commentary with tags on November 26, 2024 by itnerd

Thrive, a global technology outsourcing provider for cybersecurity, Cloud, and IT managed services, today announced it will be opening a Montreal-based SOC 2 certified data center to support its private Cloud offering. With this new opening, Thrive continues to expand its data center locations, enabling customers throughout Canada to better secure and protect their data.

Data breaches continue to be on the rise. In fact, according to the Identify Theft Resource Center, the number of data compromises reported in the first half of 2024 increased 14% compared to the same period in 2023. With potential threats always looming, organizations must ensure their data, and their customers’ data, are properly housed, managed, and secured. With the addition of the data center in Montreal, Thrive adds to their list of enterprise-class data center locations to ensure all Canadian customers have access to secure and reliable Cloud infrastructure to store their most valuable data.

As is the case with all Thrive’s data center locations, customers will gain a range of benefits, including:

  • Security: Thrive’s data centers utilize best practices in on-site physical security, including biometric access controls, perimeter monitoring, and 24×7 staffing, along with cutting-edge digital security measures.
  • Reliability: Thrive’s purpose-built data center facilities deliver maximum reliability and connectivity for mission-critical infrastructure that powers organizations.
  • Scalability: No matter the specific needs of an organization, Thrive can provide the data center flexibility and capacity to handle future growth.
  • Emergency Backup: Thrive’s data centers offer fully redundant power, networking, and environmental systems, ensuring that each facility is available when needed most. Paired with best-of-breed replication and recovery technology platforms, Thrive can help protect critical systems and data from loss in the event of an emergency. 

Along with its private Cloud offering, Thrive offers an array of services, customized to each organization’s business needs. To keep pace with the evolving landscape, Thrive continues to grow their services, from managed detection and response to incident response & remediation.

To learn more about Thrive, visit the website.

The Pwnage Of Blue Yonder Is Worse Than Was Previously Thought

Posted in Commentary with tags on November 26, 2024 by itnerd

To say that this isn’t good is an understatement.

Yesterday I reported on a company called Blue Yonder getting pwned by ransomware. And with that some of their customers have been pwned as well. Today we’re finding out how bad this is.

Those disruption have extended to some of its major customers, with Starbucks’ employee schedules and payroll systems temporarily unavailable.

In the UK, Sainsbury’s and Morrisons, two of the country’s top six retailers, have also experienced some impact.

A Morrisons spokesperson told CNN, “We have reverted to a backup process but the outage has caused the smooth flow of goods to our stores to be impacted.”

And even automotive giant Ford seems to be affected:

Automaker Ford said Monday that it was investigating any potential impact.

“Ford is aware and is actively investigating if a cyber incident at a third-party supplier has any impact on our operations or systems,” said Ford spokesperson Ian Thibodeau.

And as time goes on, this is likely to get worse.

I think this situation illustrates something that I have been saying for a while. Which is that if you have third parties doing stuff for you on your network, you have to trust that those third parties are secure. Because if they’re not, you’re going to get affected by the fact that they got pwned by hackers. I hope that this situation makes it clear to organizations that they need to do their due diligence in terms of who has access to their network. And on top of that, they need to a have a plan to keep the bad guys out, kick them out if they get in, and get back online if the worst happens. This situation illustrates that having that sort of plan is not optional.

New Research Reveals Fake Stores Using LLMs to Generate Text for Product Listings During Holiday Season

Posted in Commentary with tags on November 26, 2024 by itnerd

With Cyber Week (running from Black Friday to Cyber Monday) just around the corner, online stores are offering significant discounts to entice consumers to buy products from their online stores. While legitimate brands provide great offers, some discounts are an indication of more malevolent activity—fraudulent online stores. In 2023, there was a 135% increase in fake online stores leading up to the holidays and has continued through 2024.

Netcraft has released its latest blog, exploring the company’s research into the global growth of fake stores, including activity that makes use of e-commerce platform, SHOPYY to target Black Friday shoppers.

SHOPYY is a Chinese e-commerce platform offering a broad portfolio of technical solutions to help retailers build and optimize online stores, promote products, and accept different payment types. SHOPYY also provides hosting and domain registration on behalf of store operators.

While some legitimate businesses use SHOPYY, Netcraft research has detected thousands of SHOPYY-powered fake stores and the Use of Large Language Models (LLMs) to generate text for product listings.

Highlights of the research include:

  • An increase of 110% in fake stores identified between August and October 2024
  • 20% more fake stores in November this year than in November 2023
  • Tens of thousands of fake stores utilizing e-commerce tech platform SHOPYY
  • More than 66% of SHOPYY-powered sites identified as fake stores

You can read the research here.

Fubo Expands Programming in Canada with New NBCU FAST Channels

Posted in Commentary with tags on November 25, 2024 by itnerd

FuboTV and NBC Universal announced today the launch of six NBCU FAST channels that will bring popular and iconic sports, entertainment, news and Latino programming to the leading sports-first live TV streaming platform in Canada. 

Available today on Fubo Canada’s Sports, Entertainment and Premium channel plans are NBC News Now, Noticias Telemundo Ahora and Telemundo al Dia with three additional English-language channels coming to all Canadian plans soon.  

The NBCU FAST channels launching on Fubo in Canada include: 

NBC News NOW: Get the latest breaking news and stay on top of the stories that matter most with in-depth reporting, 24/7. 

Noticias Telemundo Ahora: 24/7 Spanish-language news channel, featuring breaking news, live reports from major cities, and interviews with today’s leading newsmakers.  

Telemundo Al Dia: The most trusted news source for the Hispanic community in Canada, offering the most important news and the latest in entertainment, realities and sports. 

GolfPass: Co-founded by global golf superstar Rory McIlroy, GolfPass is the hub for all things golf, offering thousands of tips and lessons, original entertainment, news and tournament highlights from GOLF Channel, and more. 

Dateline 24/7: Stream Dateline 24 hours a day, 7 days a week on the Dateline 24/7 channel. Discover top true crime picks from the true crime original. All Dateline, all the time. 

American Crimes: Explore the dark side of the American dream and life behind bars, featuring CNBC’s award-winning original series American Greed and Lockup.