link1s.site

The largest password leak in history exposes nearly 10 billion credentials

The largest collection of stolen passwords ever has been leaked to a notorious crime marketplace, according to cybersecurity researchers at Cybernews.

This leak, dubbed RockYou2024 by its original poster “ObamaCare,” holds a file containing nearly 10 billion unique plaintext passwords.

Allegedly gathered from a series of data breaches and hacks accumulated over several years, the passwords were posted on July 4th and hailed as the most extensive collection of stolen and leaked credentials ever seen on the forum.

“In its essence, the RockYou2024 leak is a compilation of real-world passwords used by individuals all over the world,” the researchers told Cybernews. “Revealing that many passwords for threat actors substantially heightens the risk of credential stuffing attacks.”

Credential stuffing attacks are among the most common methods criminals, ransomware affiliates, and state-sponsored hackers use to access services and systems.

Threat actors could exploit the RockYou2024 password collection to conduct brute-force attacks against any unprotected system and “gain unauthorized access to various online accounts used by individuals whose passwords are included in the dataset,” the research team said.

This could affect online services, cameras and hardware

This could affect various targets, from online services to internet-facing cameras and industrial hardware.

“Moreover, combined with other leaked databases on hacker forums and marketplaces, which, for example, contain user email addresses and other credentials, RockYou2024 can contribute to a cascade of data breaches, financial frauds, and identity thefts,” the team concluded.

However, despite the seriousness of the data leak, it is important to note that RockYou2024 is primarily a compilation of previous password leaks, estimated to contain entries from a total of 4,000 massive databases of stolen credentials, covering at least two decades.

This new file notably includes an earlier credentials database known as RockYou2021, which featured 8.4 billion passwords. RockYou2024 added approximately 1.5 billion passwords to the collection, spanning from 2021 through 2024, which, though a massive figure, is only a fraction of the reported 9,948,575,739 passwords in the leak.

Thus, users who have changed their passwords since 2021 may not have to panic about a potential breach of their information.

That said, the research team at Cybernews stressed the importance of maintaining data security. In response to the leak, they recommend immediately changing the passwords for any accounts associated with the leaked credentials, ensuring each password is strong and unique and not reused across different platforms.

Additionally, they advised enabling multi-factor authentication (MFA), which requires an extra form of verification beyond the password, wherever possible, to strengthen cyber security.

Lastly, tech users should utilize password manager software, which securely generates and stores complex passwords, mitigating the risk of password reuse across multiple accounts.

Exclusive: Japan must strengthen NATO ties to safeguard global peace, PM says
TOKYO, July 9 (Reuters) - Russia's deepening military cooperation with North Korea has underlined the need for Japan to forge closer ties with NATO as regional security threats become increasingly intertwined, Prime Minister Fumio Kishida told Reuters. In written remarks ahead of his attendance at a NATO summit in Washington DC this week, Kishida also signalled concern over Beijing's alleged role in aiding Moscow's two-year-old war in Ukraine, although he did not name China. "The securities of the Euro-Atlantic and the Indo-Pacific are inseparable, and Russia’s aggression against Ukraine and its deepened military cooperation with North Korea are strong reminders of that," Kishida said. "Japan is determined to strengthen its cooperation with NATO and its partners," he added. The world, the Japanese leader said, should not tolerate attempts by some countries to disrupt the established international order and reiterated a warning that Ukraine today could be East Asia tomorrow. He also urged cooperation to confront new security threats that transcend geographical boundaries, such as cyber-attacks and conflicts in space. The U.S. and its allies have accused Pyongyang of providing ballistic missiles and artillery shells that Russia has used in its war in Ukraine and say they fear Moscow in return could provide support for North Korea's nuclear missile development. Washington has also said China is supplying droneWithout naming China, Kishida told Reuters "some countries" have allegedly transferred dual-use civilian-military goods to Russia which has served "as a lifeline" for its Ukraine war. "It is necessary to grapple with such situations in a multi-faceted and strategic manner, taking a panoramic view that considers the full range of international actors fuelling Russia’s attempt to change the status quo by force," he said. "The geographical boundary of 'Euro-Atlantic' or 'Indo-Pacific' is no longer relevant in safeguarding global peace and security. Japan and Indo-Pacific partners can play a great role for NATO allies from this perspective." Constrained by decades of pacifism, Tokyo has been reluctant to supply lethal aid to Ukraine. It has, however, provided financial aid to Kyiv, spearheaded efforts to prepare for its post-war reconstruction, and contributed to NATO’s fund to provide Ukraine with non-lethal equipment such as anti-drone detection systems. Tokyo has also repeatedly warned about the risks of a similar conflict emerging in East Asia, where China has been taking an increasingly muscular stance towards its territorial claims including the democratic island of Taiwan. "This summit is a critical opportunity for Japan, the U.S., and the other NATO allies to confront the ongoing challenges against the international order and to reaffirm values and principles that have shaped global peace and prosperity," he said. There may be limits, however, over how far NATO members are prepared to go in forging closer ties in Asia. A plan that surfaced last year for NATO to open a liaison office in Japan, its first in Asia, was blocked by France and criticised by China. and missile technology, satellite imagery and machine tools to Russia, items which fall short of lethal assistance but are helping Moscow build its military to sustain the Ukraine war. Beijing has said it has not provided any weaponry to any party.
World's deepest diving pool opens in Poland, 45.5 meters deep
The world's deepest diving pool, Deepspot, opened this weekend near the Polish capital Warsaw. The 45.5-meter pool contains artificial underwater caves, Mayan ruins and a small shipwreck for scuba divers and free divers to explore. Deepspot can hold 8,000 cubic meters of water, more than 20 times the capacity of a normal 25-meter swimming pool. Unlike ordinary swimming pools, Deepspot can still open despite Poland's COVID-19 epidemic prevention restrictions because it is a training center that provides courses. The operator also plans to open a hotel where guests can observe divers at a depth of 5 meters from their rooms. "This is the deepest diving pool in the world," Michael Braszczynski, 47, Deepspot's director and a diving enthusiast, told AFP at the opening yesterday. The current Guinness World Record holder is a 42-meter-deep pool in Montegrotto Terme, Italy. The 50-meter-deep Blue Abyss pool in the UK is scheduled to open in 2021. On the first day of Deepspot's opening, about a dozen people visited, including eight experienced divers who wanted to pass the instructor exam. "There are no spectacular fish or coral reefs here, so it can't replace the ocean, but it is certainly a good place to learn and train safe open water diving," said 39-year-old diving instructor Przemyslaw Kacprzak. "And it's fun! It's like a kindergarten for divers."
Hedge fund Elliott challenges court verdict it lost against LME on nickel
LONDON, July 9 (Reuters) - U.S.-based hedge fund Elliott Associates on Tuesday urged a London court to overturn a verdict supporting the London Metal Exchange's (LME) cancellation of nickel trades partly because the exchange failed to disclose documents. The LME annulled $12 billion in nickel trades in March 2022 when prices shot to records above $100,000 a metric ton in a few hours of chaotic trade. Elliott and market maker Jane Street Global Trading brought a case demanding a combined $472 million in compensation, alleging at a trial in June last year that the 146-year-old exchange had acted unlawfully. London's High Court ruled last November that the LME had the right to cancel the trades because of exceptional circumstances, and was not obligated to consult market players prior to its decision. Lawyers for Elliott told London's Court of Appeal that the LME belatedly released documents in May detailing its "Kill Switch" and "Trade Halt" internal procedures. It also newly disclosed an internal report that Elliott said detailed potential conflicts of interest at the exchange. "It was troubling that one gets disclosure out of the blue in the Court of Appeal for the first time," Elliott lawyer Monica Carss-Frisk told the court. Jane Street Global did not appeal the ruling. "If we had had them (documents) in the proceedings before the divisional court, we may well have sought permission to cross examine." LME lawyers said the new documents were not relevant. "The disclosed documents do not affect the reasoning of the divisional court or the merits of the arguments on appeal," the exchange said in documents prepared for the appeal hearing. "Elliott's appeal is largely a repetition of the arguments which were advanced, and rightly rejected." The LME said it had both the power and a duty to unwind the trades because a record $20 billion in margin calls could have led to at least seven clearing members defaulting, systemic risk and a potential "death spiral". Elliott said the ruling diluted protection provided by the Human Rights Act and also wrongly concluded the LME had the power to cancel the trades.
Exclusive: India's Paytm gets government panel nod to invest in payments arm, sources say
NEW DELHI, July 9 (Reuters) - India's beleaguered Paytm (PAYT.NS), opens new tab has secured approval from a government panel that oversees investments linked to China to invest 500 million rupees ($6 million) in a key subsidiary, three sources with direct knowledge of the matter said. The approval, which still has to be vetted by the finance ministry, will remove the main stumbling block to the unit, Paytm Payment Services, resuming normal business operations. Paytm Payment Services is one of the biggest remaining parts of the fintech firm's business, accounting for a quarter of consolidated revenue in the financial year ended March 2023. A separate unit, Paytm Payments Bank, was wound down this year by order of the central bank due to persistent compliance issues, triggering a meltdown in Paytm's stock. The government panel had earlier held back approval due to concerns about the 9.88% stake in Paytm held by China's Ant Group. India has intensified scrutiny of Chinese businesses since a 2020 border clash between the two countries. All in all, Paytm has been waiting for the nod from the government panel for about two years and without it, it would have had to also wind down its payment services business, which was forbidden from taking on new customers in March 2023. Once the approval has been formalised, it will be able to seek a so-called "payment aggregator" licence from the Reserve Bank of India. The sources, two of whom are government sources, declined to be identified as the decision has not been formally announced. India's foreign, home, finance and industries ministries, whose representatives sit on the panel, did not reply to emails seeking comment. A Paytm spokesperson said the company does not comment on market speculation. "We will continue to make disclosures in compliance with our obligations under the SEBI Regulations, and will inform the exchanges when there is any new material information to share," the spokesperson said.
The Apple Watch is reportedly getting a birthday makeover
Apple is planning to revamp its smartwatch as its 10th birthday nears. The improvements include larger displays and thinner builds, Bloomberg reported. The revamped watches may also get a new chip, which could enable some AI enhancements. The Apple Watch is about to turn 10, so Apple is planning a birthday revamp, including larger displays and thinner builds, Bloomberg reported. Both versions of the new Series 10 watches will have screens similar to the large displays found on the Apple Watch Ultra, the report said. The revamped watches are also expected to contain a new chip that may permit some AI enhancements later on. Last month, Apple pulled back the curtain on its generative-AI plans with Apple Intelligence. Advertisement It hopes the artificial-intelligence features will prove alluring enough to persuade consumers to buy new Apple products. The announcement has been generally well received by Wall Street. Dan Ives of Wedbush Securities wrote in a Monday note that the "iPhone 16 AI-driven upgrade could represent a golden upgrade cycle for Cupertino." "We believe AI technology being introduced into the Apple ecosystem will bring monetization opportunities on both the services as well as iPhone/hardware front and adds $30 to $40 per share," he added. Apple's stock closed on Friday at just over $226 a share, up 22% this year and valuing the company at $3.47 trillion. That puts it just behind Microsoft, which was worth $3.48 trillion at Friday's close. The tech giants have been vying for the title of the world's most valuable company in recent months — with the chipmaker Nvidia briefing claiming the crown last month. Apple also announced some software updates for the watch at its Worldwide Developers Conference last month. The latest version of the device's software, watchOS 11, emphasizes fitness and health, introducing tools that allow users to rate workouts and adjust effort ratings. WatchOS 11 will also use machine learning to curate the best photos for users' displays. Apple has previously used product birthdays to release new versions of devices. The iPhone X's release marked the 10th anniversary of the smartphone. However, it's not clear exactly when Apple plans to release the revamped watches, Bloomberg said. The company announced the Apple Watch in September 2014, with CEO Tim Cook calling it "the most personal product we've ever made." Apple did not immediately respond to a request for comment made outside normal working hours.