link1s.site

The largest password leak in history exposes nearly 10 billion credentials

The largest collection of stolen passwords ever has been leaked to a notorious crime marketplace, according to cybersecurity researchers at Cybernews.

This leak, dubbed RockYou2024 by its original poster “ObamaCare,” holds a file containing nearly 10 billion unique plaintext passwords.

Allegedly gathered from a series of data breaches and hacks accumulated over several years, the passwords were posted on July 4th and hailed as the most extensive collection of stolen and leaked credentials ever seen on the forum.

“In its essence, the RockYou2024 leak is a compilation of real-world passwords used by individuals all over the world,” the researchers told Cybernews. “Revealing that many passwords for threat actors substantially heightens the risk of credential stuffing attacks.”

Credential stuffing attacks are among the most common methods criminals, ransomware affiliates, and state-sponsored hackers use to access services and systems.

Threat actors could exploit the RockYou2024 password collection to conduct brute-force attacks against any unprotected system and “gain unauthorized access to various online accounts used by individuals whose passwords are included in the dataset,” the research team said.

This could affect online services, cameras and hardware

This could affect various targets, from online services to internet-facing cameras and industrial hardware.

“Moreover, combined with other leaked databases on hacker forums and marketplaces, which, for example, contain user email addresses and other credentials, RockYou2024 can contribute to a cascade of data breaches, financial frauds, and identity thefts,” the team concluded.

However, despite the seriousness of the data leak, it is important to note that RockYou2024 is primarily a compilation of previous password leaks, estimated to contain entries from a total of 4,000 massive databases of stolen credentials, covering at least two decades.

This new file notably includes an earlier credentials database known as RockYou2021, which featured 8.4 billion passwords. RockYou2024 added approximately 1.5 billion passwords to the collection, spanning from 2021 through 2024, which, though a massive figure, is only a fraction of the reported 9,948,575,739 passwords in the leak.

Thus, users who have changed their passwords since 2021 may not have to panic about a potential breach of their information.

That said, the research team at Cybernews stressed the importance of maintaining data security. In response to the leak, they recommend immediately changing the passwords for any accounts associated with the leaked credentials, ensuring each password is strong and unique and not reused across different platforms.

Additionally, they advised enabling multi-factor authentication (MFA), which requires an extra form of verification beyond the password, wherever possible, to strengthen cyber security.

Lastly, tech users should utilize password manager software, which securely generates and stores complex passwords, mitigating the risk of password reuse across multiple accounts.

TikTok to introduce a new feature that can clone your voice with AI in just 10 second
Use of AI is certainly the hottest topic in the tech industry and every major and minor player in this industry is using AI in some way. Tools like ChatGPT can help you do a wide range of task and even help you generate images. The other thing is - Voice Cloning. OpenAI recently introduced a voice engine that can generate clone of your voice with just 15 seconds of your audio. There is no shortage of voice cloning tools on the web which can help you do the same. The newest tech giant which is going to use AI to clone your voice is - TikTok. We all know TikTok, posting short videos with filters, effects and all other kind of things. So TikTok found a way to use the voice cloning AI in its app. TikTok is working on this feature, which does not seem to really have a proper name, it just references it as "Create your voice with AI" and "TikTok Voice Library". In the latest version of TikTok I came across some strings which indicates that TikTok is working on it. I was also able to access the initial UI which introduces the feature and was able to see the terms and condition of "TikTok Voice Library" which user have to accept in order to use the feature. Here are the screenshots from the app- As you can in the screenshot above, this is the initial screen which a user will see for the first time they access this feature. Tiktok claims that it can create an AI verison of your voice in just 10 seconds. The generated AI voice clone can be used with text-to-speech in TikTok videos. It also outline the process of how it will work. You have to record yourself speaking and TikTok will process the voice and use information about your voice to generate your AI voice. When it comes to privacy, your AI voice will stay private and you can delete it anytime. Tapping the "Continue" button brings "TikTok Voice Library Terms" screen which a user should definitely read, you can see here and read as well - How it will work After agreeing to terms and conditions I was introduced with a screen where TikTok will show some text and user have to press the record button while reading the text. Now unfortunately I did not see any text. This is probably because the feature is not fully ready or the backend from which it fetches the text is not live yet. Manually pressing the record button and saying random things also shows an error. So, it's also not possible to provide any sample voice generated with it and see how it compares to other voice cloning competitors. If it starts working someday, it will process your recorded voice and generate AI version of your voice. Here is a screenshot of that screen - My guess is that whenever the feature starts working, users have to clone voice only one time and the saved AI voice can be used through the text-to-speech method to add voice in your videos. You just have to type the words, choice is yours :p
EV maker Lucid to recall over 5,200 Air luxury sedans for software error, US regulator says
July 9 (Reuters) - Lucid Group (LCID.O), opens new tab will recall about 5,251 of its 2022-2023 Air luxury sedans due to a software error that could cause a loss of power, according to a notice from the U.S. National Highway Traffic Safety Administration published on Tuesday. The regulator added the EV maker will also recall about 7,506 of its 2022-2024 Air luxury sedans due to an issue with a coolant heater that could fail to defrost the windshield. Lucid had released an over-the-air software update in June as a fix for the software error and a separate update to identify a high voltage coolant heater failure and provide a warning to the drivers of the affected vehicles. The company had reported second-quarter deliveries above market expectations on Monday, as price cuts helped boost demand for its luxury electric sedans.
China will reach climate goal while West falls short
There has been constant low-level sniping in the West against China's record on climate change, in particular its expansion of coal mining, and its target of 2060 rather than 2050 for carbon zero. I have viewed this with mild if irritated amusement, because when it comes to results, then China, we can be sure, will deliver and most Western countries will fall short, probably well short. It is now becoming clear, however, that we will not have to wait much longer to judge their relative performances. The answer is already near at hand. We now know that in 2023 China's share of renewable energy capacity reached about 50 percent of its total energy capacity. China is on track to shatter its target of installing 1200GW of solar and wind energy capacity by 2030, five years ahead of schedule. And international experts are forecasting that China's target of reaching peak CO2 emissions by 2030 will probably be achieved ahead of schedule, perhaps even by a matter of years. Hitherto, China has advisedly spoken with a quiet voice about its climate targets, sensitive to the fact that it has become by far the world's largest CO2 emitter and aware that its own targets constituted a huge challenge. Now, however, it looks as if China's voice on global warming will carry an authority that no other nation will be able to compete with. There is another angle to this. China is by far the biggest producer of green tech, notably EVs, and renewable energy, namely solar photovoltaics and wind energy. Increasingly China will be able to export these at steadily reducing prices to the rest of the world. The process has already begun. It leaves the West with what it already sees as a tricky problem. How can it become dependent on China for the supply of these crucial elements of a carbon-free economy when it is seeking to de-risk (EU) or decouple (US) its supply chains from China? Climate change poses the greatest risk to humanity of all the issues we face today. There are growing fears that the 1.5-degree Celsius target for global warming will not be met. 2023 was the hottest year ever recorded. Few people are now unaware of the grave threat global warming poses to humanity. This requires the whole world to make common cause and accept this as our overarching priority. Alas, the EU is already talking about introducing tariffs to make Chinese EVs more expensive. And it is making the same kind of noises about Chinese solar panels. The problem is this. Whether Europe likes it or not, it needs a plentiful supply of Chinese EVs and solar panels if it is to reduce its carbon emissions at the speed that the climate crisis requires. According to the International Energy Authority, China "deployed as much solar capacity last year as the entire world did in 2022 and is expected to add nearly four times more than the EU and five times more than the US from 2023-28." The IEA adds, "two-thirds of global wind manufacturing expansion planned for 2025 will occur in China, primarily for its domestic market." In other words, willy-nilly, the West desperately needs China's green tech products. Knee-jerk protectionism demeans Europe; it is a petty and narrow-minded response to the greatest crisis humanity has ever faced. Instead of seeking to resist or obstruct Chinese green imports, it should cooperate with China and eagerly embrace its products. As a recent Financial Times editorial stated: "Beijing's green advances should be seen as positive for China, and for the world." The climate crisis is now in the process of transforming the global political debate. Hitherto it seemed relatively disconnected. That period is coming to an end. China's dramatic breakthrough in new green technologies is offering hope not just to China, but to the whole world, because China will increasingly be able to supply both the developed and developing world with the green technology needed to meet their global targets. Or, to put it another way, it looks very much as if China's economic and technological prowess will play a crucial role in the global fight against climate change. We should not be under any illusion about the kind of challenge humanity faces. We are now required to change the source of energy that powers our societies and economies. This is not new. It has happened before. But previously it was always a consequence of scientific and technological discoveries. Never before has humanity been required to make a conscious decision that, to ensure its own survival, it must adopt new sources of energy. Such an unprecedented challenge will fundamentally transform our economies, societies, cultures, technologies, and the way we live our lives. It will also change the nature of geopolitics. The latter will operate according to a different paradigm, different choices, and different priorities. The process may have barely started, but it is beginning with a vengeance. Can the world rise to the challenge, or will it prioritize petty bickering over the vision needed to save humanity? On the front line, mundane as it might sound, are EVs, wind power, and solar photovoltaics. The author is a visiting professor at the Institute of Modern International Relations at Tsinghua University and a senior fellow at the China Institute, Fudan University. Follow him on X @martjacques.
Poland and Ukraine sign bilateral security agreement
On July 8, Ukrainian President Zelensky, who was visiting Poland, and Polish Prime Minister Tusk signed a bilateral security agreement in Warsaw, the capital of Poland. The agreement clearly states that Poland will provide support to Ukraine in air defense, energy security and reconstruction. After signing the agreement, Tusk said that the agreement includes actual bilateral commitments, not "empty promises." Previously, the United States, Britain, France, Germany and other countries as well as the European Union signed similar agreements with Ukraine.
OpenAI's internal AI details stolen in 2023 breach, NYT reports
July 4 (Reuters) - A hacker gained access to the internal messaging systems at OpenAI last year and stole details about the design of the company's artificial intelligence technologies, the New York Times reported, opens new tab on Thursday. The hacker lifted details from discussions in an online forum where employees talked about OpenAI's latest technologies, the report said, citing two people familiar with the incident. However, they did not get into the systems where OpenAI, the firm behind chatbot sensation ChatGPT, houses and builds its AI, the report added. OpenAI executives informed both employees at an all-hands meeting in April last year and the company's board about the breach, according to the report, but executives decided not to share the news publicly as no information about customers or partners had been stolen. OpenAI executives did not consider the incident a national security threat, believing the hacker was a private individual with no known ties to a foreign government, the report said. The San Francisco-based company did not inform the federal law enforcement agencies about the breach, it added. OpenAI in May said it had disrupted five covert influence operations that sought to use its AI models for "deceptive activity" across the internet, the latest to stir safety concerns about the potential misuse of the technology. The Biden administration was poised to open up a new front in its effort to safeguard the U.S. AI technology from China and Russia with preliminary plans to place guardrails around the most advanced AI Models including ChatGPT, Reuters earlier reported, citing sources.