Election Security Risks Revealed By Illinois Voters Data Breach

Posted in Commentary with tags on October 17, 2024 by itnerd

In a previous report, cybersecurity researcher Jeremiah Fowler uncovered a significant breach where 4.6 million Illinois voter records were exposed due to unsecured databases, exposing Voter’s sensitive data. +This incident underscores election security vulnerabilities and the risks associated with it such as identity theft and fraud among many others. 

VPN Mentor’s new report provides valuable insights and protection tips from Jeremiah related to this situation.

You can read the report here: https://www.vpnmentor.com/news/votersdb-lessons/ 

Here’s A Couple Of New Reasons To Dump Twitter ASAP

Posted in Commentary with tags on October 17, 2024 by itnerd

If you’re one of the few people left on Twitter, you might have noticed that a pop up informing you of a change to the Twitter terms of service is happening.

Now I encourage you to read their blog post on this here. But that doesn’t tell the whole story. For that you have to go to the actual terms of service and scroll down to the section called “Your Rights and Grant of Rights in the Content” you will see this:

The key part of this paragraph is here:

In short, if you post content to Twitter, Elon gets to use it to train his AI models. I’ve read this a few times, along with looking at the Twitter app and it doesn’t seem that there is any way that you can opt out of this. Though I am free to be proven wrong about this via posting a comment below showing me where you can opt out of this. But assuming that I am right about this, this is really inexcusable and Elon has really crossed the line here.

But that’s not all. If you continue to read these terms of service, you’ll also see this.

If you view more than 1 million posts, which includes replies, within 24 hours, you will be charged $15,000 USD per 1 million posts. No human could actually do that. Thus one plausible explanation is that this is there to stop organizations from scraping his site using automated tools. For example organizations that are looking at Twitter to see how racist, homophobic, or whatever else that dumpster fire of a site has become. I say that because this sounds sort of like Elon charging for Twitter API access, and these sorts of organizations finding ways around that. Another plausible explanation is that it would stop people like me from embedding Tweets in their stories. Particularly big news organizations that gets millions of views on something they post so that Elon either gets paid, or he can hid the bad behaviour that is pretty pervasive on Twitter these days. If you have other possible explanations for this, please post them in the comments below.

It wouldn’t surprise me if this drives more signups on platforms like Threads, Bluesky, and Mastodon once word of the changes to Twitter’s terms of service start to circulate. Because this is the sort of stuff that upsets people and drives them away. Which if a problem if you’re Elon and you desperately need eyeballs on Twitter to sell advertising. I wonder how he’s going to square that circle?

The new terms of service go into effect on November 15th. But you’re going to see the backlash happen way before then.

Twitter Changes How The Block Function Works And Gets Trolled By Bluesky On Twitter As A Result

Posted in Commentary with tags , on October 17, 2024 by itnerd

Elon Musk must really want to destroy the social media platform that he bought for $44 billion. I say that because Elon has decided to change how Twitter’s block function works as per this Tweet:

To be frank, this is stupid. I block accounts because they harass me, or I don’t want to see their content. But more specifically because I don’t want them to see what I am doing. This must be about Elon and the fact that I suspect that he gets blocked a lot and feels that this change needs to be made to address the fact that he has the thinnest skin on the planet. Well, if you look at the replies to this, it’s not going over well. And rival social network Bluesky who has a presence on Twitter joined in:

And they also posted this:

And the fact that Bluesky is trending on Twitter as evidenced here shows that people are at least going to take a look at this rival social network:

Once again, Elon has found a new and creative way to drive people off of Twitter and into the hands of his competition. Which continues to illustrate that Elon isn’t all that smart. I for one cannot wait to see the boost to Bluesky’s numbers that comes from this ill advised move by Elon.

275% Rise In Ransomware-Related Attacks: Microsoft

Posted in Commentary with tags on October 17, 2024 by itnerd

Yesterday, Microsoft published its annual Digital Defense Report analyzing trends among its customers from June 2022 to July 2023 with the company noting a 275% year-over-year rise in human-operated ransomware-linked encounters.

On a positive note, over the past two years, the number of ransomware attacks that reached the encryption stage fell by 300%, primarily due to advancements in automatic attack disruption technologies.

In over 90% of cases where attacks advanced to the ransom stage, the attackers exploited unmanaged devices within the network, either to gain initial access or to remotely encrypt assets during the impact phase.

The most common initial access techniques continue to be social engineering, identity compromise and exploiting vulnerabilities in publicly facing applications or unpatched operating systems.

According to Tom Burt, Microsoft’s corporate vice president of customer security and trust, the ransomware issue underscores the connection between nation-state activities and financially motivated cybercrime. This problem is exacerbated by countries leveraging these operations for profit, as well as those that take little to no action against cybercrime occurring within their borders.

Expert Evan Dornbush, former NSA cybersecurity expert, offers perspectives on the matter:

  “This report signals one trend currently getting little attention and likely to define the future of cyber: the amount of money criminals can earn.

  “Per the Microsoft report, government, as a sector, only makes up 12% of the aggressors’ targeting sets. The vast majority of victims are in the private sector.

  “Tom writes “improved defense will not be enough”. Until the economic model is fundamentally altered, making it cheaper to defend or more expensive to attack, the advantage will increasingly drift towards the criminal.”

The Microsoft Digital Defense Report is required reading as it provides facts on how dangerous and complex the threat is. And by understanding that, it will allow organizations to better prepare for the attacks that are headed their way.

Two Canadian companies nominated for Procore’s Groundbreaker Awards 2024

Posted in Commentary with tags on October 17, 2024 by itnerd

Yesterday, Procore announced the nominees for its Groundbreaker Awards 24. Two of the nominees are from Canada, including Toronto-based Multiplex Construction for the Excellence in Sustainability Award; and Burnaby, B.C.-based Houle Electric for the Excellence in Culture & Workforce Development Award. 

Procore’s Groundbreaker Awards 24

Procore looked for the companies, projects and people behind the construction industry’s boldest achievements in the following categories: 

  • Excellence in Sustainability
  • Excellence in Innovation
  • Excellence in Health & Safety
  • Excellence in Community
  • Excellence in Culture & Workforce Development
  • Groundbreaker of the Year
  • Excellence in Project Delivery – People’s Choice Award

Two Canadian companies are among this year’s nominees.

Excellence in Sustainability
This award celebrates the company or project that most efficiently uses resources and embraces environmentally responsible processes throughout every stage of construction.

Nominee: 

Multiplex Construction (Toronto, ON)
Multiplex Construction Canada is focused on their path towards sustainability— they intend to reach net zero carbon in their supply chain by 2050 or earlier, plus zero Scope 1 & 2 on-site and office emissions by 2030. Multiplex is the first Canadian construction company to set a Science-Based Target and the first contractor globally to sign the World Green Building Council’s Net Zero Carbon Commitment. As they progress on their Decarbonization Roadmap, they utilize alternative fuels, conduct embodied carbon assessments, embrace low carbon solutions and engage their supply chain to track and collaboratively reduce emissions throughout the construction process.

Other nominees in this category:

REI Distribution Center 4, Al. Neyer (US)
Ceylon E-8 (Responsive Arts & STEAM Academy) for Denver Public Schools, U.S. Engineering (US)

Excellence in Culture & Workforce Development
This award celebrates the company that displays a focus on company culture including, but not limited to diversity, equity and inclusion and best promotes a continued focus on developing the next construction generation.

Nominee: 

Houle Electric Limited (Burnaby, B.C.)
As BC’s leading electrical contractor and systems integrator, Houle is a company that puts people first–empowering communities through local projects that positively impact people’s lives. Houle champions diversity, equity, and inclusion and is committed to fostering a workplace where everyone is valued, supported, and provided the opportunity to grow. In addition to initiatives that focus on employee development, professional advancement, and continuous improvement, Houle supports programs for underrepresented groups, provides training for 300+ apprentices annually, and has higher than industry average participation of women in the electrical trade. By connecting people with purpose, they’re building a safer, more inclusive workplace and industry for everyone. 

Read more about Houle Electric.

Other nominees in this category: 

McCarthy Holdings, Inc. (US)
Hardy Corporation (US)

Winners will be announced and celebrated at Groundbreak 2024 in Denver, Colorado, on November 20-21, 2024. For more information on this year’s award nominees, please visit: https://www.procore.com/groundbreaker-awards

Holiday Gift Ideas & Black Friday Deals from Epson

Posted in Commentary with tags on October 16, 2024 by itnerd

Tis the season for gift giving! As the holidays quickly approach, Epson has curated the perfect gift guide for any shopping list. And with Epson’s exclusive Black Friday deals, Canadians can get top notch printers, projectors and scanners at unbeatable prices.  

Black Friday Deals: 

  • The Epson EpiqVision Mini EF22 projector will be on sale for $999.99 (Regular Price: $1,299.99) during Black Friday online and at participating stores.  
  • The Epson EcoTank ET-2850 Printer  will be on sale for $319.00 (Regular Price: $399.99 CAD) during Black Friday online and at participating stores.  
  • The Epson EcoTank ET-4850 Printer   will be on sale for $399.00 (Regular Price: $599.99 CAD) during Black Friday online and at participating stores.  
  • The Epson EcoTank ET-2800  Printer is on sale now for $229.00 (Regular Price: $329.99 CAD) and through Black Friday online and at participating stores.  
  • The Epson EcoTank Photo ET-8550 Printer will be on sale for $699.00 (Regular Price: $1,099.99) during Balck Friday online and at participating stores. 
  • The Epson EcoTank ET-15000 Printer will be on sale for $729.00 (Regular Price: $899.99) during Balck Friday online and at participating stores. 
  • The Epson EcoTank Pro ET-5150 Printer will be on sale for $549.00 (Regular Price: $699.99) during Balck Friday online and at participating stores. 
  • The Epson EcoTank Pro ET-5850 Printer will be on sale for $979.00 (Regular Price: $1,099.99) during Balck Friday online and at participating stores. 

Top Gift Picks:

Epson EpiqVision Mini EF22 Portable Smart Laser Projector (MSRP: $1,299.99 CAD

Get ready for a truly epic viewing experience brought to you by Epson’s newest laser projector with a screen size reaching up to 150”, full HD HDR picture quality and stereo speakers with Dolby audio. The Epson EpiqVision Mini is also portable, so you can easily set it up in any room of your house – or bring it with you on the road! Its new 360-degree swivel-stand with tilt ability maximizes your viewing options so you can always get the best picture. Hosting a holiday movie marathon? Stream all your favourites seamlessly with the projector’s built-in HDMI and Google TV  with access to Netflix 

Epson EcoTank ET-2850 Wireless Colour All-in-One Cartridge-Free Supertank Printer(MSRP: $399.99 CAD)  

The EcoTank ET-2850 is the perfect practical holiday gift for any busy parent. It can print just about anything, from financial documents to school projects and more. This printer is cartridge-free and uses high-capacity, easily refillable ink tanks, so, they won’t have to worry about black & white or colour printing, and save a lot on replacement ink . Plus, with its hands-free, voice-activated printing , parents will appreciate having one less thing to juggle.  

Epson EcoTank ET-4850 Wireless Colour All-in-One Cartridge-Free Supertank Printer(MSRP: $599.99 CAD) 

For the parent or business owner who always runs a tight ship. The Epson EcoTank ET-4850’s innovative cartridge-free printing will bring joy to any type-A who works from home, with its premium productivity features like an Auto Document feeder and high-resolution flatbed scanner. You can feel confident that this gift will be used and appreciated over time. With up to 2 years of ink in the box, you’ll be giving a gift that spares loved ones the hassle of constant trips to the store. Each EcoFit bottle set is equivalent to about 80 individual cartridges , so Canadian’s don’t have to worry about buying expensive cartridges refills.  

Epson FastFoto FF-680W Wireless High-speed Photo Scanning System (MSRP: $799.99

The Epson FastFoto FF-6680W photo scanner is the perfect gift for the family with lots of old photographs just waiting to be digitized. This scanner is speedy and can scan thousands of photos as fast as 1 photo per second. The FastFoto’s features are so easy to use, you don’t need to be tech savvy to operate it, allowing you to organize, auto enhance and colour restore even the most ancient photos that have been boxed up collecting dust. 

You can also check Epson.ca for weekly specials and even more savings. 

Ricoh introduces new A4 imaging series

Posted in Commentary with tags on October 16, 2024 by itnerd

Ricoh USA, Inc. today announced a new color A4 multifunction printer (MFP) and printer series specifically designed to meet the demands of today’s hybrid workplaces. Ideal for space-constrained locations, the series provides innovative features and solutions for workplace optimization, information sharing and sustainability that are typically reserved for larger A3 devices, but in a smaller footprint.

The RICOH IM C320FRICOH M C320FW, and RICOH P C375 ensure that employees can stay productive, securely access information from anywhere, and benefit from innovative digital workflows. Pairing Ricoh’s advanced imaging capabilities with its cutting-edge workflow solutions, including RICOH CloudStreamRICOH Smart Integration, andRICOH Streamline NX, these devices facilitate seamless information sharing and help modernize the print infrastructure for businesses operating in decentralized, hybrid work settings.

Enhanced Features for Efficiency and Productivity

  • Intelligent MFP capabilities: The IM C320F MFP offers a 7″ Smart Operation Panel and leverages RICOH Always Current Technology to maximize hardware value by allowing for periodic updates and ongoing improvements. This model also leverages the latest cybersecurity and compliance standards to support information security in the evolving workplace.
  • Compact, lightweight design: With up to a 40% smaller footprint compared to Ricoh’s current model in the same speed range, the IM C320F and M C320FW MFPs can fit comfortably on a desk or countertop, making them ideal for space-constrained locations, including retail and healthcare environments.
  • Affordable, user-friendly solutions: The M C320FW features a 4.3″ touch panel, enhanced RICOH Web API functionality, and supports the integrated RICOH Support Station app, which streamlines setup and ongoing operation, making it an ideal choice for small offices needing cost-effective and straightforward device management.
  • Versatile print-only model The P C375 delivers exceptional performance in the mid-range segment with a 4-line LCD panel while supporting a print speed of 32 pages-per-minute (ppm) and a maximum input sheet capacity of 1,300 sheets, providing the flexibility needed for growing offices.

The IM C320F and M C320FW also support a 32-ppm print speed and include a Single-Pass Document Feeder, which scans both sides of a page in a single pass for fast scanning, simplifying the management of multi-page documents, and increasing overall productivity in busy offices.

Commitment to Sustainability and Security

Embodying Ricoh’s long-standing commitment to environmental sustainability, each model is manufactured with 50% post-consumer recycled plastic and features a significant reduction in single-use plastic packaging – up to 31% compared to other models. Additionally, Ricoh toner cartridges now come in entirely plastic-free packaging. With ENERGY STAR certification and incorporating innovations such as a more thermally efficient transfer unit and low-melting-point toner achieving among the best Typical Energy Consumption values in the industry, Ricoh’s commitment to sustainability helps businesses meet their ESG and net-zero goals while maintaining high performance.

All three models offer robust security features, including:

  • User authentication and data encryption (TLS 1.3) for protecting sensitive information.
  • Enhanced network filter and log functions for comprehensive monitoring and compliance.


As organizations continue to navigate the evolving office landscape and adapt to hybrid workstyles, Ricoh remains committed to providing innovative technologies, such as the IM C320F, M C320FW, and P C375, that increase productivity, streamline operations, and support sustainability for customers in the transformation of their print infrastructures for the future.

For more information about Ricoh’s imaging technology, click here.

Gryphon Healthcare Pwned…. 400,000 People Affected

Posted in Commentary with tags on October 16, 2024 by itnerd

Houston-based healthcare billing services provider Gryphon Healthcare has disclosed that a cyberattack may have compromised the personal and medical information of up to 393,358 individuals. 

Gryphon detected the incident on August 13, confirmed unauthorized access began on July 6, and began notifying those affected on Friday.

Gryphon provided medical billing services for hospitals, emergency departments and EMS providers, imaging centers, independent labs, healthcare facilities, ambulatory surgery centers, and private practices. Potentially exposed data includes: Names, DOBs, Addresses, SSNs, Medical diagnoses, Treatment details, Insurance information, Prescriptions and Medical record numbers.

Approov CEO Ted Miracco offers this perspective:

  “This Gryphon Healthcare incident highlights the urgent need for faster detection and response to cyberattacks, especially in sectors like healthcare, where sensitive data is involved. In this case, the initial breach occurred in early July, yet those affected were only informed in October. Such delays are unacceptable as they allow attackers months to exploit the stolen data—names, social security numbers, medical histories, and more. During this time, personal and medical identities can be sold or used for malicious purposes, leading to irreparable damage to the victims.

  “Healthcare data is extremely sensitive, making it crucial to have a proactive approach with real-time monitoring, rapid breach detection, and immediate response mechanisms. Relying on post-attack credit monitoring and dark web surveillance, as Gryphon appears to have done, is simply not enough. Companies need to ensure robust protection through enhanced cybersecurity frameworks, as seen in technologies like runtime app attestation​​, to minimize attack windows. Importantly, cyber insurance should not be the default solution for poor response times, as it shifts responsibility from preventative measures to post-incident compensation, leaving patients vulnerable.

Once again, the healthcare sector is the target of threat actors. And that’s due to the fact that healthcare continues to be low hanging fruit for them. This needs to change or stories like these along with the downstream effects of every one of these incidents will continue to be news for all the wrong reasons.

Wallarm Launches Industry-First SaaS Solution to Deliver Security at the API Edge

Posted in Commentary with tags on October 16, 2024 by itnerd

Wallarm, a leader in API security solutions, announced today Security Edge, a breakthrough SaaS solution that delivers security at the API edge. As the industry’s first offering to modernize API Security deployments, Wallarm is taking on legacy Content Delivery Networks (CDNs) that claim most of the traffic is API traffic but are unable to provide real-time API threat protection.

Wallarm’s new solution represents a major shift in how organizations secure and gain visibility into their APIs. It eliminates the need for inefficient and cumbersome distributed traffic redirection, giving organizations immediate and local API protection. Unlike traditional methods that route API traffic through distant cloud servers or rely on CDNs, Security Edge enables organizations to secure API traffic at the API’s edge, where it’s most effective and performant.

Security Edge works by distributing Wallarm filtering nodes positioned as close to the customers’ APIs as possible, using existing cloud providers and infrastructure. While a self-managed deployment can be fully integrated into a customer’s API infrastructure, Security Edge removes the management burden while providing low latency.

Security Edge’s key features and benefits include:

  • Hosted, Managed, Simplified: Wallarm handles infrastructure, deployment, and monitoring and ensures that nodes are up-to-date and functional, removing maintenance requirements.
  • Low Latency, Lower Cost: Security Edge nodes can be geographically distributed at the API edge to deliver security capabilities with minimal latency. 
  • Operational Visibility: Customers can access logs, events, and real-time traffic statistics. 

With Security Edge, Wallarm is opening a new market segment for API security, currently occupied by traditional CDN vendors with infrastructure built for caching traditional web content. Security Edge enables customers to achieve greater protection at a fraction of the cost using a purpose-built API edge solution. 

For more information, visit http://www.wallarm.com/resources/security-edge.

Mission Welcomes Glenn Grant as SVP of Professional Services

Posted in Commentary with tags on October 15, 2024 by itnerd

Mission, a leading US-based Amazon Web Services (AWS) Premier Tier Partner, has announced the return of Glenn Grant as Senior Vice President of Professional Services. Grant’s appointment reinforces Mission’s dedication to enabling customers with cloud and AI solutions on AWS and positioning Mission to further deliver cutting-edge services that drive measurable business outcomes for its customers. 

Glenn Grant, founder of G2 Tech Group—a company acquired by Mission in 2018—brings over 25 years of experience in IT and outsourced services. A pioneer in managed services in the early 2000s, Grant has a proven track record of transforming businesses and driving growth.

Since the acquisition, Grant has served as Mission’s advisor and board member. At the same time, Grant worked as a business coach and entrepreneur advisor, helping tech companies increase their business value and build strong leadership teams. This experience in scaling businesses and working with private equity-backed ventures is invaluable as Mission grows and expands its services.

As SVP of Professional Services, Grant will lead the team in implementing cutting-edge solutions and best practices to support Mission’s growing customer base. He will focus on scaling the professional services organization to meet the increasing demand for AI and cloud services. “We’re taking what we’ve learned over the last few years, especially in AI, machine learning, and data operations, and up leveling our already rock-solid cloud and DevOps offerings,” Grant explained. 

Grant’s role reinforces Mission’s commitment to reinvesting in AWS technologies and growing customer workloads on the AWS platform. This strategic direction aligns with Mission’s goal of continually enhancing its service offerings to meet the evolving needs of its cloud customers.