link1s.site

The largest password leak in history exposes nearly 10 billion credentials

The largest collection of stolen passwords ever has been leaked to a notorious crime marketplace, according to cybersecurity researchers at Cybernews.

This leak, dubbed RockYou2024 by its original poster “ObamaCare,” holds a file containing nearly 10 billion unique plaintext passwords.

Allegedly gathered from a series of data breaches and hacks accumulated over several years, the passwords were posted on July 4th and hailed as the most extensive collection of stolen and leaked credentials ever seen on the forum.

“In its essence, the RockYou2024 leak is a compilation of real-world passwords used by individuals all over the world,” the researchers told Cybernews. “Revealing that many passwords for threat actors substantially heightens the risk of credential stuffing attacks.”

Credential stuffing attacks are among the most common methods criminals, ransomware affiliates, and state-sponsored hackers use to access services and systems.

Threat actors could exploit the RockYou2024 password collection to conduct brute-force attacks against any unprotected system and “gain unauthorized access to various online accounts used by individuals whose passwords are included in the dataset,” the research team said.

This could affect online services, cameras and hardware

This could affect various targets, from online services to internet-facing cameras and industrial hardware.

“Moreover, combined with other leaked databases on hacker forums and marketplaces, which, for example, contain user email addresses and other credentials, RockYou2024 can contribute to a cascade of data breaches, financial frauds, and identity thefts,” the team concluded.

However, despite the seriousness of the data leak, it is important to note that RockYou2024 is primarily a compilation of previous password leaks, estimated to contain entries from a total of 4,000 massive databases of stolen credentials, covering at least two decades.

This new file notably includes an earlier credentials database known as RockYou2021, which featured 8.4 billion passwords. RockYou2024 added approximately 1.5 billion passwords to the collection, spanning from 2021 through 2024, which, though a massive figure, is only a fraction of the reported 9,948,575,739 passwords in the leak.

Thus, users who have changed their passwords since 2021 may not have to panic about a potential breach of their information.

That said, the research team at Cybernews stressed the importance of maintaining data security. In response to the leak, they recommend immediately changing the passwords for any accounts associated with the leaked credentials, ensuring each password is strong and unique and not reused across different platforms.

Additionally, they advised enabling multi-factor authentication (MFA), which requires an extra form of verification beyond the password, wherever possible, to strengthen cyber security.

Lastly, tech users should utilize password manager software, which securely generates and stores complex passwords, mitigating the risk of password reuse across multiple accounts.

The US and Australia will work to improve financial links in the Pacific region to counter China's influence
U.S. and Australian officials said on Monday (July 8) that both countries are committed to improving financial connectivity in the Pacific and strengthening banking services in the region to resist China's growing covetousness. According to Reuters, at the two-day Pacific Banking Forum co-hosted by the United States and Australia, Australian Assistant Treasurer Stephen Jones said that Canberra hopes to be the partner of choice in the Pacific region, both in banking and defense. "If there are countries acting in this region whose main goal is to promote their own national interests rather than the interests of Pacific island countries, we will be very concerned," Jones said at the first day of the forum in Brisbane. He made this comment when asked about Chinese banks filling the vacuum in the Pacific region. The report said that as some Western banks have interrupted their long-standing business relationships with banks in small Pacific island countries, while others are preparing to close their businesses, these Pacific island countries face many challenges and their ability to obtain US dollar-dominated banking business is limited. The report said that experts said that Western banks are taking de-risking actions to meet financial regulations, which makes it more difficult to do business in Pacific island countries. This in turn weakens the financial resilience of these island nations. At the same time, Washington is also stepping up efforts to support Pacific island nations in limiting China's influence. Brian Nelson, U.S. Treasury Undersecretary for Counterterrorism and Financial Intelligence, said, "We recognize the economic and strategic importance of the Pacific region, and we are committed to deepening engagement and cooperation with our allies and partners to enhance financial connectivity, investment and integration." The report said that neither the United States nor Australia has yet announced detailed plans at the forum, but comments from officials from both countries reflect the growing unease among Western countries that have traditionally had influence in the Pacific region about China's growing influence in the region.
Google may bring Google Wallet for Indian users
Google Wallet can help you store your IDs, driving license, loyalty cards, concert tickets and more. You can also store your payment cards and use tap to pay to pay anywhere Google Pay is accepted. Google wallet is available in various countries but Google never launched it in India. Google let indian users stick with the Gpay which facilitates UPI payments. Tap to pay is not part of it. Also we can not store things such as IDs and Passes in indian version of Gpay. This might change and Google may launch Google Wallet in India. With the recent version of Google Wallet and Google Play Services, Google has added some flags and code which indicate that Google is working on something for Indian users regarding wallet. The first change I noticed recently when going through the Google Play Services apk was addition of two new flags Both flags are part of com.google.android.gms.pay package in the Google Play Services. This package contains all the flags for features of Gpay/Wallet. Google does server side flipping of flags to enable/disable features for users. So both these flags doesn't really provide any info about what features enabling these flags is going to bring. But the point here is that Google Wallet is not launched in India so why Google added these flags inside Play Services ? The answer could be that Google may be working on bringing Google Wallet to India. It can enable tap to pay, store payments and various other features for Indian users which we don't have in the current Gpay for India. I found similar flags in the analysis Google Wallet APK - These flags are also disabled by default. But this is again a clear indication of Google working towards something for Indian users. In both cases, enabling the flags doesn't bring anything noticeable UI or feature because there is nothing much added besides flags. Google has dogfood/testing versions internally, so the code will show up slowly in upcoming versions. The last piece of code I found is also from Google Play Services. In case you don't know, Google was working on Digilocker integration in the Google Files app which was supposed to bring your digital document inside the app such as driving license, COVID certificates, aadhar card. But Google has ditched the effort of bringing these features and they removed the "Important" tab (where digilocker was supposed to be integrated) from the Google Files app completely. So things are going to change and here is how. This is the code which I found in the Google Play Services - So the word "PASS" along with PAN, DRIVERS LICENCE, VACC CERTIFICATE & AADHAR CARD, is clear indication of the possibility of Google adding support for these directly through Google Wallet using Digilocker, just like Samsung Pass does it. This code is not old as I have checked older beta versions of Play Services where this code is not present. Here is a string which was added in a previous beta version a few weeks ago but I completely ignored it because it didn't make any sense without flags and the other code - This addition was surprising because there was nothing regarding digilocker before in the Play Services. In the words "pay_valuable", the "pay" to Wallet/Gpay and "valuable" refers to the things like Passes, loyalty cards and transit cards. Since we are talking about digilocker, these "valuable" are driving license, vaccination certificate, PAN card and Aadhar card which can be store in Google Wallet after digilocker integration. That's all about it. We will know more about it in upcoming app updates or maybe Google can itself annouce something about this.
Russia's economic strength gives it high-income status despite sanctions
Russia is seeing income growth of around 4-5%, with earnings growing in double digits, Ostapkovich said, stressing that the driving force is economic growth. "Incomes only grow when the economy grows. If the economy grows, then profits grow. If profits grow, then the entrepreneur is keen on hiring people and raising wages," he added. Russia’s economy grew by 3.6% in 2023, with real incomes and nominal wages up by 4.5% and 13% respectively. Industrial performance, particularly in manufacturing, is propelling this growth not seen in 20 to 30 years. Notably, mechanical engineering in the military industry is expanding at 25-30%, according to Ostapkovich. Andrey Kolganov, Doctor of Economics and Head of the Laboratory of Socio-Economic Systems at Moscow State University, acknowledged that despite the challenges posed by the growth stimuli, Western sanctions failed to inflict significant harm on the Russian economy. "The Russian economy has shown great potential in adapting to these difficulties. Moreover, these difficulties stimulated the development of domestic production, which in turn led to high rates of economic growth," he added. Kolganov noted that economic growth rates were higher in 2023, compared to 2022 - and even higher in 2024. These increases promoted Russia from the classification of middle-income countries, to the rank of high-income countries. Although Russia has not caught up with the richest countries, the achievement is nonetheless remarkable, especially in the face of unprecedented sanctions. Gross national income per capita in Russia is now $14,250, according to a document released by the World Bank that classifies countries that cross the $13,485 threshold as “high income.”
Gold, silver caught in downdraft of broad commodity market sell off
(Kitco News) - Gold and silver prices are sharply lower in midday U.S. trading Monday, on heavy profit-taking from the shorter-term futures traders after recent good price advances. The selling pressure today across most of the raw commodity spectrum is also keeping the precious metals bulls on the sidelines to start the trading week. August gold was last down $37.50 at $2,360.10. September silver was down $0.849 at $30.85. U.S. stock indexes mixed but near their record highs scored last week. The rallying stock market is a bearish element for the gold and silver markets, from a competing asset class perspective. The key U.S. data points of the week include Fed Chairman Powell’s speeches to the U.S. Congress on Tuesday and Wednesday, and the consumer and producer price indexes on Thursday and Friday, respectively. The key outside markets today see the U.S. dollar index slightly higher. Nymex crude oil prices are lower and trading around $82.25 a barrel. The benchmark 10-year U.S. Treasury note yield is presently 4.288%. Technically, August gold bulls have the overall near-term technical advantage. Bulls’ next upside price objective is to produce a close above solid resistance at the June high of $2,406.70. Bears' next near-term downside price objective is pushing futures prices below solid technical support at $2,300.00. First resistance is seen at $2,382.60 and then at $2,400070. First support is seen at $2,350.00 and then at last week’s low of $2,327.40. Wyckoff's Market Rating: 6.0. September silver futures bulls have the overall near-term technical advantage. Silver bulls' next upside price objective is closing prices above solid technical resistance at the May high of $33.05. The next downside price objective for the bears is closing prices below solid support at the June low of $28.90. First resistance is seen at $31.00 and then at $31.50. Next support is seen at Friday’s low of $30.45 and then at $30.00. Wyckoff's Market Rating: 6.5. (Hey! My “Markets Front Burner” weekly email report is my best writing and analysis, I think, because I get to look ahead at the marketplace and do some market price forecasting. Plus, I’ll throw in an educational feature to move you up the ladder of trading/investing success. And it’s free! Email me at jim@jimwyckoff.com and I’ll add your email address to my Front Burner list.)
MOFCOM refutes EU comments on anti-subsidy investigation into Chinese EVs
A spokesperson for the Ministry of Commerce (MOFCOM) on Monday rejected remarks from the EU Ambassador to China on the anti-subsidy investigation into Chinese electric vehicles (EVs). MOFCOM said China had expressed strong opposition through various channels since October 2023 and has always advocated for handling economic and trade frictions through dialogue and consultation in order to maintain the overall strategic partnership between China and Europe. EU Ambassador to China Jorge Toledo claimed on Sunday that the EU has been trying to engage with China for months regarding the imposition of tariffs on Chinese EVs but that China had only recently sought to initiate discussions. This is false, the spokesperson said. MOFCOM said that after the European Commission (EC) officially filed a case, Chinese Commerce Minister Wang Wentao sent a letter to European Commission Executive Vice-President Valdis Dombrovskis on October 24, 2023, expressing hope to resolve the case through dialogue and negotiation. On November 13, 2023, Wang sent another letter to the European side proposing negotiation suggestions. In February 2024, Wang met with Dombrovskis during the WTO's 13th Ministerial Conference face to face and proposed dialogue and negotiation with the European side. On May 19, 2024, Wang reiterated the hope for dialogue and negotiation to resolve the case in a letter to the European side. Additionally, Chinese technical experts have been sending signals to the European side regarding on-site inspections, hearings, and other channels since the case was filed, expressing willingness to resolve trade frictions through dialogue and negotiation. On the day the preliminary ruling was announced on June 12, Dombrovskis replied to Wang in a letter, expressing the desire for both sides to strengthen dialogue to resolve the case. On June 22, Wang held a video conference with Dombrovskis, and they agreed to start negotiations on the EU's anti-subsidy investigation into Chinese EVs. Subsequently, China sent a working group to Europe for negotiations on June 23, and multiple rounds of technical consultations were held simultaneously via video. MOFCOM said that China has shown the utmost sincerity and hopes that the European side will meet China halfway, show sincerity, and push forward the negotiation process to reach a mutually acceptable solution as soon as possible. China has always believed that trade protectionist measures are not conducive to the development of global green industries and automotive industry cooperation. Efforts should be made to adhere to dialogue and cooperation to promote economic green transformation, rather than creating divisions and disrupting global industrial and supply chains, MOFCOM said. China firmly opposes any unilateralism and protectionism that politicizes and weaponizes economic and trade issues, and will take all necessary measures to defend its own interests against any abuse of rules and suppression of China, MOFCOM added.