link1s.site

The largest password leak in history exposes nearly 10 billion credentials

The largest collection of stolen passwords ever has been leaked to a notorious crime marketplace, according to cybersecurity researchers at Cybernews.

This leak, dubbed RockYou2024 by its original poster “ObamaCare,” holds a file containing nearly 10 billion unique plaintext passwords.

Allegedly gathered from a series of data breaches and hacks accumulated over several years, the passwords were posted on July 4th and hailed as the most extensive collection of stolen and leaked credentials ever seen on the forum.

“In its essence, the RockYou2024 leak is a compilation of real-world passwords used by individuals all over the world,” the researchers told Cybernews. “Revealing that many passwords for threat actors substantially heightens the risk of credential stuffing attacks.”

Credential stuffing attacks are among the most common methods criminals, ransomware affiliates, and state-sponsored hackers use to access services and systems.

Threat actors could exploit the RockYou2024 password collection to conduct brute-force attacks against any unprotected system and “gain unauthorized access to various online accounts used by individuals whose passwords are included in the dataset,” the research team said.

This could affect online services, cameras and hardware

This could affect various targets, from online services to internet-facing cameras and industrial hardware.

“Moreover, combined with other leaked databases on hacker forums and marketplaces, which, for example, contain user email addresses and other credentials, RockYou2024 can contribute to a cascade of data breaches, financial frauds, and identity thefts,” the team concluded.

However, despite the seriousness of the data leak, it is important to note that RockYou2024 is primarily a compilation of previous password leaks, estimated to contain entries from a total of 4,000 massive databases of stolen credentials, covering at least two decades.

This new file notably includes an earlier credentials database known as RockYou2021, which featured 8.4 billion passwords. RockYou2024 added approximately 1.5 billion passwords to the collection, spanning from 2021 through 2024, which, though a massive figure, is only a fraction of the reported 9,948,575,739 passwords in the leak.

Thus, users who have changed their passwords since 2021 may not have to panic about a potential breach of their information.

That said, the research team at Cybernews stressed the importance of maintaining data security. In response to the leak, they recommend immediately changing the passwords for any accounts associated with the leaked credentials, ensuring each password is strong and unique and not reused across different platforms.

Additionally, they advised enabling multi-factor authentication (MFA), which requires an extra form of verification beyond the password, wherever possible, to strengthen cyber security.

Lastly, tech users should utilize password manager software, which securely generates and stores complex passwords, mitigating the risk of password reuse across multiple accounts.

BRI: embracing Chinese green practices for a sustainable future
Editor's Note: This year marks the 10th anniversary of the Belt and Road Initiative (BRI) proposed by Chinese President Xi Jinping. Through the lens of foreign pundits, we take a look at 10 years of the BRI - how it achieves win-win cooperation between China and participating countries of the BRI and how it has given the people of these countries a sense of fulfillment. In an interview with Global Times (GT) reporter Li Aixin, Erik Solheim (Solheim), former under-secretary-general of the United Nations and former executive director of the UN Environment Programme, recalled how the BRI helped shorten a previously long journey in Sri Lanka to a half-hour trip. "We will all be losers in a de-globalized, de-coupled world. The BRI can play a key role in bringing the world together," Solheim said. This is the 18th piece of the series. GT: How do you evaluate the role of the BRI in promoting development in participating countries over the past 10 years? Solheim: The BRI has been a major driver of development since it was announced by President Xi Jinping in Kazakhstan 10 years ago. The China-Laos Railway has connected landlocked Laos to the Chinese and European rail network, making it possible for Laos to sell more goods and welcome more tourists. Rail corridors in Kenya and from Djibouti to Addis Ababa connect the interior of Africa to the coast, bringing opportunities for much faster development in East Africa. The Bandung-Jakarta railway in Indonesia, Hanoi metro, roads and ports in Sri Lanka - there are great examples of good south-south and BRI projects in almost every corner of the world. GT: In your experience of traveling around the world, has any BRI-related story left a deep impression on you? Solheim: Yes, many! I'll just mention two. When I was chief negotiator in the Sri Lanka peace process 15 years ago, it took a long time to travel from the airport to Colombo, the capital of Sri Lanka. When I came back last year, it took half an hour on wonderful Chinese-built highways. Traveling through Mombasa, a coastal city in Kenya, you see a lot of poverty and run down houses. Then all of a sudden, a green, clean, well-run oasis opens up. It's the end station of the Nairobi-Mombasa railway which links the capital Nairobi to the coast. The rail station stands out and is showing the future for Kenya. GT: The EU proposed the Global Gateway, and the US proposed the Build Back Better World. What do you think are the similarities and differences between these projects and the BRI? Solheim: I really wish success for the Western initiatives. What developing nations ask for is a choice of good cooperation with both China and the West. Unfortunately, up to now, a number of the Western-led initiatives have been more like media events. They lack structure, secretariat, finances and clear direction. Nearly all nations in the world want to see close people-to-people relations, investment and political cooperation with both China and the West. No one wants to choose. GT: Some people from the West are talking about "de-coupling" and "de-risking." Both seem to be another way of saying "de-globalization." Do you think "de-coupling" and "de-risking" will affect the BRI? And what role will the BRI play in maintaining globalization? Solheim: Decoupling is probably the most unwise idea in the world today. It's outright dangerous. Facing climate change, environmental degradation, economic troubles, war in Ukraine and other places, and the threat of pandemics, we need more, not less, cooperation. We will all be losers in a de-globalized, de-coupled world. The BRI can play a key role in bringing the world together. Almost all developing countries have made BRI agreements with China. As an example, when President Xi met all the leaders of Central Asia recently in Xi'an, Northwest China's Shaanxi Province, they made a very ambitious declaration on future green cooperation between China and Central Asia. GT: You have previously said that the BRI is a fantastic vehicle to promote green global development, which can boost the economy and ecology at the same time. Could you elaborate on how you think the BRI has achieved development of the economy and ecology? Solheim: In the beginning there were too many fossil fuel projects among BRI programs. In the BRI International Green Development Coalition, we argued this should stop. When President Xi pledged to stop building new coal-fired power projects overseas, it was one of the most important environmental decisions ever. Also, it happened at a time when important BRI nations like Bangladesh, Kenya and Pakistan decided they could grow their economies and go green without coal. The BRI will in the next decade become the world's most important vehicle for green energy and green transport. We will see massive investments in solar and wind power, hydrogen, electric batteries and more. GT: How do you view China's goal of achieving harmony between humanity and nature in modernization? In what way is China's story in pursuing harmony between humanity and nature relevant to other countries? Solheim: China now covers between 60 percent and 80 percent of all major green technologies in the world - solar, wind, hydro, batteries, electric cars and high-speed rail. Companies like Longi, BYD and CATL are the world leaders in their sectors. More remarkably and maybe less noticed abroad, China is also a global leader in protecting nature. It's embarking upon one of the most massive national park programs, with a focus on Qinghai Province and Xizang Autonomous Region. China is by far the biggest tree planter in the world and the global leader in desert control in Kubuqi, Inner Mongolia and other places. China has been hugely successful in the recovery of endangered species like the Giant Panda, Tibetan Antelope and Snow Leopard. A new center for mangrove restoration is being set up in Shenzhen and the fishing ban in the Yangtze will restore that magnificent ecosystem. The Belt and Road is a great opportunity for the world to learn from good Chinese green practices.
Diphtheria outbreak in Vietnam kills one person
On the afternoon of July 8, local time, the Vietnamese Ministry of Health issued a notice stating that an 18-year-old girl in the country died of diphtheria. The Ministry of Health asked Nghe An Province and Bac Giang Province to take urgent action to control the epidemic. Diphtheria is an acute respiratory infectious disease caused by Corynebacterium diphtheriae, which is mainly transmitted through droplets and can also be indirectly transmitted by contact with objects containing Corynebacterium diphtheriae. Severe cases may show symptoms of poisoning throughout the body, complicated by myocarditis and peripheral nerve paralysis.
OpenAI's internal AI details stolen in 2023 breach, NYT reports
July 4 (Reuters) - A hacker gained access to the internal messaging systems at OpenAI last year and stole details about the design of the company's artificial intelligence technologies, the New York Times reported, opens new tab on Thursday. The hacker lifted details from discussions in an online forum where employees talked about OpenAI's latest technologies, the report said, citing two people familiar with the incident. However, they did not get into the systems where OpenAI, the firm behind chatbot sensation ChatGPT, houses and builds its AI, the report added. OpenAI executives informed both employees at an all-hands meeting in April last year and the company's board about the breach, according to the report, but executives decided not to share the news publicly as no information about customers or partners had been stolen. OpenAI executives did not consider the incident a national security threat, believing the hacker was a private individual with no known ties to a foreign government, the report said. The San Francisco-based company did not inform the federal law enforcement agencies about the breach, it added. OpenAI in May said it had disrupted five covert influence operations that sought to use its AI models for "deceptive activity" across the internet, the latest to stir safety concerns about the potential misuse of the technology. The Biden administration was poised to open up a new front in its effort to safeguard the U.S. AI technology from China and Russia with preliminary plans to place guardrails around the most advanced AI Models including ChatGPT, Reuters earlier reported, citing sources.
Google extends Linux kernel support to 4 years
According to AndroidAuthority, the Linux kernel used by Android devices is mostly derived from Google's Android Universal Kernel (ACK) branch, which is created from the Android mainline kernel branch when new LTS versions are released upstream. For example, when kernel version 6.6 is announced as the latest LTS release, an ACK branch for Android15-6.6 appears shortly after, with the "android15" in the name referring to the Android version of the kernel (in this case, Android 15). Google maintains its own set of LTS kernel branches for three main reasons. First, Google can integrate upstream features that have not yet been released into the ACK branch by backporting or picking, so as to meet the specific needs of Android. Second, Google can include some features that are being developed upstream in the ACK branch ahead of time, making it available for Android devices as early as possible. Finally, Google can add some vendor or original equipment manufacturer (OEM) features for other Android partners to use. Once created, Google continues to update the ACK branch to include not only bug fixes for Android specific code, but also to integrate the LTS merge content of the upstream kernel branch. For example, the Linux kernel vulnerability disclosed in the July 2024 Android security bulletin will be fixed through these updates. However, it is not easy to distinguish a bug fix from other bug fixes, as a patch that fixes a bug may also accidentally plug a security vulnerability that the submitter did not know about or chose not to disclose. Google does its best to recognize this, but it inevitably misses the mark, resulting in bug fixes for the upstream Linux kernel being released months before Android devices. As a result, Google has been urging Android vendors to regularly update the LTS kernel to avoid being caught off guard by unexpectedly disclosed security vulnerabilities. Clearly, the LTS version of the Linux kernel is critical to the security of Android devices, helping Google and vendors deal with known and unknown security vulnerabilities. The longer the support period, the more timely security updates Google and vendors can provide to devices.
Workers warn of additional walkouts unless demands are met
Members of the National Samsung Electronics Union stage a rally near the company's Hwaseong Campus in Gyeonggi Province, Monday, beginning a three-day strike. Korea Times photo by Shim Hyun-chul By Nam Hyun-woo The biggest labor union at Samsung Electronics initiated a three-day strike on Monday, threatening to disrupt the company's chip manufacturing lines unless management agrees to a wage hike and higher incentives. This marks the first strike by unionized workers in the tech giant's 55-year history. The National Samsung Electronics Union (NSEU) claimed that about 4,000 unionized workers from Samsung's plants nationwide participated in a rally at the company's Hwaseong Campus in Gyeonggi Province. Police estimated that approximately 3,000 union members were present at the rally. According to its own survey, the union reported that a total of 6,540 members expressed their intention to participate in the strike. They emphasized that disruptions in manufacturing are anticipated, with over 5,000 members from facility, manufacturing, and development divisions joining the strike. The comments seem to address market expectations that the walkout is unlikely to cause significant disruptions in the chipmaker's operations, largely because most manufacturing lines are automated. The union said that it may launch another strike for an undetermined period, unless management responds to the union’s demand. Since January, the union has been pressing management for a higher wage increase rate for all members, fulfillment of promises regarding paid leave, and improvements to incentive criteria. With negotiations at an impasse, the union announced on May 29 that it would launch a strike. The NSEU has some 30,000 members, accounting for 24 percent of all Samsung employees. Among the union members, about 80 percent work at the device solutions division, which manufactures semiconductors.