
The largest password leak in history exposes nearly 10 billion credentials
The largest collection of stolen passwords ever has been leaked to a notorious crime marketplace, according to cybersecurity researchers at Cybernews. This leak, dubbed RockYou2024 by its original poster “ObamaCare,” holds a file containing nearly 10 billion unique plaintext passwords. Allegedly gathered from a series of data breaches and hacks accumulated over several years, the passwords were posted on July 4th and hailed as the most extensive collection of stolen and leaked credentials ever seen on the forum. “In its essence, the RockYou2024 leak is a compilation of real-world passwords used by individuals all over the world,” the researchers told Cybernews. “Revealing that many passwords for threat actors substantially heightens the risk of credential stuffing attacks.” Credential stuffing attacks are among the most common methods criminals, ransomware affiliates, and state-sponsored hackers use to access services and systems. Threat actors could exploit the RockYou2024 password collection to conduct brute-force attacks against any unprotected system and “gain unauthorized access to various online accounts used by individuals whose passwords are included in the dataset,” the research team said. This could affect online services, cameras and hardware This could affect various targets, from online services to internet-facing cameras and industrial hardware. “Moreover, combined with other leaked databases on hacker forums and marketplaces, which, for example, contain user email addresses and other credentials, RockYou2024 can contribute to a cascade of data breaches, financial frauds, and identity thefts,” the team concluded. However, despite the seriousness of the data leak, it is important to note that RockYou2024 is primarily a compilation of previous password leaks, estimated to contain entries from a total of 4,000 massive databases of stolen credentials, covering at least two decades. This new file notably includes an earlier credentials database known as RockYou2021, which featured 8.4 billion passwords. RockYou2024 added approximately 1.5 billion passwords to the collection, spanning from 2021 through 2024, which, though a massive figure, is only a fraction of the reported 9,948,575,739 passwords in the leak. Thus, users who have changed their passwords since 2021 may not have to panic about a potential breach of their information. That said, the research team at Cybernews stressed the importance of maintaining data security. In response to the leak, they recommend immediately changing the passwords for any accounts associated with the leaked credentials, ensuring each password is strong and unique and not reused across different platforms. Additionally, they advised enabling multi-factor authentication (MFA), which requires an extra form of verification beyond the password, wherever possible, to strengthen cyber security. Lastly, tech users should utilize password manager software, which securely generates and stores complex passwords, mitigating the risk of password reuse across multiple accounts.
How China can transform from passive to active amid US chip curbs
On Monday, executives from the three major chip giants in the US - Intel, Qualcomm, and Nvidia - met with US officials, including Antony Blinken, to voice their opposition to the Biden administration's plan of imposing further restrictions on chip sales to Chinese companies and investments in China. The Semiconductor Industry Association also released a similar statement, opposing the exclusion of US semiconductor companies from the Chinese market. First of all, we mustn't believe that the appeals of these companies and industry associations will collectively change the determination of US political elites to stifle China's progress. These US elites are very fearful of China's rapid development, and they see "chip chokehold" as a new discovery and a successful tactic formed under US leadership and with the cooperation of allies. Currently, the chip industry is the most complex technology in human history, with only a few companies being at the forefront. They are mainly from the Netherlands, Taiwan island, South Korea, and Japan, most of which are in the Western Pacific. These countries and regions are heavily influenced by the US. Although these companies have their own expertise, they still use some American technologies in their products. Therefore, Washington quickly persuaded them to form an alliance to collectively prevent the Chinese mainland from obtaining chips and manufacturing technology. Washington is proud of this and wants to continuously tighten the noose on China. The New York Times directly titled an article "'An Act of War': Inside America's Silicon Blockade Against China, " in which an American AI expert, Gregory Allen, publicly claimed that this is an act of war against China. He further stated that there are two dates that will echo in history from 2022: The first is February 24, when the Russia-Ukraine conflict broke out, and the second is October 7, when the US imposed a sweeping set of export controls on selling microchips to China. China must abandon its illusions and launch a challenging and effective counterattack. We already have the capability to produce 28nm chips, and we can use "small chip" technology to assemble small semiconductors into a more powerful "brain," exploring 14nm or even 7nm. Additionally, China is the world's largest commercial market for commodity semiconductors. Last year, semiconductor procurement in China amounted to $180 billion, surpassing one-third of the global total. In the past, China had been faced with the choice between independent innovation and external purchases. Due to the high returns from external purchases, it is easy for it to become the overwhelming choice over independent research and development. However, now the US is gradually blocking the option of external purchases, and China has no strategic choice but to independently innovate, which in turn puts tremendous pressure on American companies. Scientists generally expect that, although China may take some detours, such as recently apprehending several company leaders who fraudulently obtained subsidies from national semiconductor policies, China has the ability to gradually overcome the chip difficulties. And we will form our own breakthroughs and industrial chain, which is expected to put quite a lot of pressure on US companies. If domestic firms acquire half of China's $180 billion per year in chip acquisitions, this would provide a significant boost for the industry as a whole and help it advance steadily. The New York Times refers to the battle on chips as a bet by Washington. "If the controls are successful, they could handicap China for a generation; if they fail, they may backfire spectacularly, hastening the very future the United States is trying desperately to avoid," it argued. Whether it is a war or a game, when the future is uncertain, what US companies hope for most of all is that they can sell simplified versions of high-end chips to China, so that the option of external purchases by China continues to exist and remains attractive. This can not only maintain the interests of the US companies, enabling them to obtain sufficient funds to develop more advanced technologies, but also disrupt China's plans for independent innovation. This idea is entirely based on their own commercial interests and also has a certain political and national strategic appeal. Hence, there is no shortage of supporters within the US government. US Secretary of the Treasury Janet Yellen seems to be one of them, as she has repeatedly stated that the US' restrictions on China will not "fundamentally" hurt China, but will only be "narrowly targeted." The US will balance its strict suppression on China from the perspective of maintaining its technological hegemony, while also leaving some room for China, in order to undermine China's determination to counterattack in terms of independent innovation. China needs to use this mentality of the US to its advantage. On the one hand, China should continue to purchase US chips to maintain its economic fundamentals, and on the other hand, it should firmly support the development of domestic semiconductor companies from both financial and market perspectives. If China were to continue relying on exploiting the gaps in US chip policies in the long term, akin to a dependency on opium, it would only serve to weaken China further as it becomes increasingly addicted. China's market is extremely vast, and its innovation capabilities are generally improving and expanding. Although the chip industry is highly advanced, if there is one country that can win this counterattack, it is China. As long as we resolutely continue on the path of independent innovation, this road will definitely become wider. Various breakthroughs and turning points that are unimaginable today may soon occur.

Former British PM Sunak appoints Conservative Party shadow cabinet
On July 8, local time, former British Prime Minister Sunak announced the appointment of the Conservative Party Shadow Cabinet, which is the first shadow cabinet of the Conservative Party in 14 years. Several former British cabinet members during Sunak's tenure as prime minister were appointed to the Conservative Party Shadow Cabinet, including James Cleverly as Shadow Home Secretary and Jeremy Hunt as Shadow Chancellor of the Exchequer. But former Foreign Secretary Cameron was not appointed as Shadow Foreign Secretary. In addition, the new leader of the Conservative Party will be elected as early as this week. On July 4, the UK held a parliamentary election. The counting results showed that the British Labour Party won more than half of the seats and won an overwhelming victory; the Conservative Party suffered a disastrous defeat, ending its 14-year continuous rule.
Russia's economic strength gives it high-income status despite sanctions
Russia is seeing income growth of around 4-5%, with earnings growing in double digits, Ostapkovich said, stressing that the driving force is economic growth. "Incomes only grow when the economy grows. If the economy grows, then profits grow. If profits grow, then the entrepreneur is keen on hiring people and raising wages," he added. Russia’s economy grew by 3.6% in 2023, with real incomes and nominal wages up by 4.5% and 13% respectively. Industrial performance, particularly in manufacturing, is propelling this growth not seen in 20 to 30 years. Notably, mechanical engineering in the military industry is expanding at 25-30%, according to Ostapkovich. Andrey Kolganov, Doctor of Economics and Head of the Laboratory of Socio-Economic Systems at Moscow State University, acknowledged that despite the challenges posed by the growth stimuli, Western sanctions failed to inflict significant harm on the Russian economy. "The Russian economy has shown great potential in adapting to these difficulties. Moreover, these difficulties stimulated the development of domestic production, which in turn led to high rates of economic growth," he added. Kolganov noted that economic growth rates were higher in 2023, compared to 2022 - and even higher in 2024. These increases promoted Russia from the classification of middle-income countries, to the rank of high-income countries. Although Russia has not caught up with the richest countries, the achievement is nonetheless remarkable, especially in the face of unprecedented sanctions. Gross national income per capita in Russia is now $14,250, according to a document released by the World Bank that classifies countries that cross the $13,485 threshold as “high income.”

Google may bring Google Wallet for Indian users
Google Wallet can help you store your IDs, driving license, loyalty cards, concert tickets and more. You can also store your payment cards and use tap to pay to pay anywhere Google Pay is accepted. Google wallet is available in various countries but Google never launched it in India. Google let indian users stick with the Gpay which facilitates UPI payments. Tap to pay is not part of it. Also we can not store things such as IDs and Passes in indian version of Gpay. This might change and Google may launch Google Wallet in India. With the recent version of Google Wallet and Google Play Services, Google has added some flags and code which indicate that Google is working on something for Indian users regarding wallet. The first change I noticed recently when going through the Google Play Services apk was addition of two new flags Both flags are part of com.google.android.gms.pay package in the Google Play Services. This package contains all the flags for features of Gpay/Wallet. Google does server side flipping of flags to enable/disable features for users. So both these flags doesn't really provide any info about what features enabling these flags is going to bring. But the point here is that Google Wallet is not launched in India so why Google added these flags inside Play Services ? The answer could be that Google may be working on bringing Google Wallet to India. It can enable tap to pay, store payments and various other features for Indian users which we don't have in the current Gpay for India. I found similar flags in the analysis Google Wallet APK - These flags are also disabled by default. But this is again a clear indication of Google working towards something for Indian users. In both cases, enabling the flags doesn't bring anything noticeable UI or feature because there is nothing much added besides flags. Google has dogfood/testing versions internally, so the code will show up slowly in upcoming versions. The last piece of code I found is also from Google Play Services. In case you don't know, Google was working on Digilocker integration in the Google Files app which was supposed to bring your digital document inside the app such as driving license, COVID certificates, aadhar card. But Google has ditched the effort of bringing these features and they removed the "Important" tab (where digilocker was supposed to be integrated) from the Google Files app completely. So things are going to change and here is how. This is the code which I found in the Google Play Services - So the word "PASS" along with PAN, DRIVERS LICENCE, VACC CERTIFICATE & AADHAR CARD, is clear indication of the possibility of Google adding support for these directly through Google Wallet using Digilocker, just like Samsung Pass does it. This code is not old as I have checked older beta versions of Play Services where this code is not present. Here is a string which was added in a previous beta version a few weeks ago but I completely ignored it because it didn't make any sense without flags and the other code - This addition was surprising because there was nothing regarding digilocker before in the Play Services. In the words "pay_valuable", the "pay" to Wallet/Gpay and "valuable" refers to the things like Passes, loyalty cards and transit cards. Since we are talking about digilocker, these "valuable" are driving license, vaccination certificate, PAN card and Aadhar card which can be store in Google Wallet after digilocker integration. That's all about it. We will know more about it in upcoming app updates or maybe Google can itself annouce something about this.