link1s.site

The largest password leak in history exposes nearly 10 billion credentials

The largest collection of stolen passwords ever has been leaked to a notorious crime marketplace, according to cybersecurity researchers at Cybernews.

This leak, dubbed RockYou2024 by its original poster “ObamaCare,” holds a file containing nearly 10 billion unique plaintext passwords.

Allegedly gathered from a series of data breaches and hacks accumulated over several years, the passwords were posted on July 4th and hailed as the most extensive collection of stolen and leaked credentials ever seen on the forum.

“In its essence, the RockYou2024 leak is a compilation of real-world passwords used by individuals all over the world,” the researchers told Cybernews. “Revealing that many passwords for threat actors substantially heightens the risk of credential stuffing attacks.”

Credential stuffing attacks are among the most common methods criminals, ransomware affiliates, and state-sponsored hackers use to access services and systems.

Threat actors could exploit the RockYou2024 password collection to conduct brute-force attacks against any unprotected system and “gain unauthorized access to various online accounts used by individuals whose passwords are included in the dataset,” the research team said.

This could affect online services, cameras and hardware

This could affect various targets, from online services to internet-facing cameras and industrial hardware.

“Moreover, combined with other leaked databases on hacker forums and marketplaces, which, for example, contain user email addresses and other credentials, RockYou2024 can contribute to a cascade of data breaches, financial frauds, and identity thefts,” the team concluded.

However, despite the seriousness of the data leak, it is important to note that RockYou2024 is primarily a compilation of previous password leaks, estimated to contain entries from a total of 4,000 massive databases of stolen credentials, covering at least two decades.

This new file notably includes an earlier credentials database known as RockYou2021, which featured 8.4 billion passwords. RockYou2024 added approximately 1.5 billion passwords to the collection, spanning from 2021 through 2024, which, though a massive figure, is only a fraction of the reported 9,948,575,739 passwords in the leak.

Thus, users who have changed their passwords since 2021 may not have to panic about a potential breach of their information.

That said, the research team at Cybernews stressed the importance of maintaining data security. In response to the leak, they recommend immediately changing the passwords for any accounts associated with the leaked credentials, ensuring each password is strong and unique and not reused across different platforms.

Additionally, they advised enabling multi-factor authentication (MFA), which requires an extra form of verification beyond the password, wherever possible, to strengthen cyber security.

Lastly, tech users should utilize password manager software, which securely generates and stores complex passwords, mitigating the risk of password reuse across multiple accounts.

US foreign policy is advanced smartphone with weak battery
A couple of days ago, a Quad summit meeting in Sydney scheduled for May 24 was abruptly canceled. The US president had to pull out of his long-anticipated trip to Australia and Papua New Guinea. Instead, the heads of the four Quad member states got together on the margins of the G7 Summit in Hiroshima on May 20. The main reason for the change of plans was the continuous struggle between the White House and Republicans on the Hill over the national debt ceiling. If no compromise is reached, the US federal government might fail to meet its financial commitments already in June; such a technical default would have multiple negative repercussions for the US, as well as for the global economy and finance at large. Let us hope that a compromise between the two branches of US power will be found and that the ceiling of the national debt will be raised once again. However, this rather awkward last-minute cancellation of the Quad summit reflects a fundamental US problem - a growing imbalance between the US geopolitical ambitions and the fragility of the national financial foundation to serve these ambitions. The Biden administration appears to be fully committed to bringing humankind back to the unipolar world that existed right after the end of the Cold War some 30 years ago, but the White House no longer has enough resources at its disposal to sustain such an undertaking. As they say in America: You cannot not have champagne on a beer budget. The growing gap between the ends that the US seeks in international relations and the means that it has available is particularly striking in the case of the so-called dual containment policy that Washington now pursues toward Russia and China. Even half a century ago, when the US was much stronger in relative terms than it is today, the Nixon administration realized that containing both Moscow and Beijing simultaneously was not a good idea: "Dual containment" would imply prohibitively high economic costs for the US and would result in too many unpredictable political risks. The Nixon administration decided to focus on containing the Soviet Union as the most important US strategic adversary of the time. This is why Henry Kissinger flew to Beijing in July 1971 to arrange the first US-China summit in February 1972 leading to a subsequent rapid rapprochement between the two nations. In the early days of the Biden administration, it seemed that the White House was once again trying to avoid the unattractive "dual containment" option. The White House rushed to extend the New START in January 2021 and held an early US-Russia summit meeting five months later in Geneva. At that point many analysts predicted that Biden would play Henry Kissinger in reverse - that is he would try to peace with the relatively weaker opponent (Moscow) in order to focus on containing the stronger one (Beijing). However, after the beginning of the Russia-Ukraine conflict, it became clear that no accommodation with the Kremlin was on Biden's mind any longer. Still, having decided to take a hard-line stance toward Moscow and to lead a broad Western coalition in providing military and economic assistance to Kiev, Washington has not opted for a more accommodative or at least a more flexible policy toward Beijing. On the contrary, over last year one could observe a continuous hardening of the US' China policy - including granting more political and military support to the Taiwan island, encouraging US allies and partners in Asia to increase their defense spending, engaging in more navel activities in the Pacific and imposing more technology sanctions on China. In the meantime, economic and social problems within the US are mounting. The national debt ceiling is only the tip of an iceberg - the future of the American economy is now clouded by high US Federal Reserve interest rates that slow down growth, feed unemployment and might well lead to a recession. Moreover, the US society remains split along the same lines it was during the presidency of Donald Trump. The Biden administration has clearly failed to reunite America: Many of the social, political, regional, ethnic and even generational divisions have got only deeper since January 2021. It is hard to imagine how a nation divided so deeply and along so many lines could demonstrate continuity and strategic vision in its foreign policy, or to allocate financial resources needed to sustain a visionary and consistent global leadership. Of course, the "dual containment" policy is not the only illustration of the gap between the US ambitions and its resources. The same gap inevitably pops up at every major forum that the US conducts with select groups of countries from the Global South - Africa, Southeast Asia, Latin America or the Middle East. The Biden administration has no shortage of arguments warning these countries about potential perils of cooperating with Moscow or Beijing, but it does not offer too many plausible alternatives that would showcase the US generosity, its strategic vision, and its true commitment to the burning needs of the US interlocutors. To cut it short, Uncle Sam brings lots of sticks to such meetings, but not enough carrots to win the audience. In sum, US foreign policy under President Joe Biden reminds people of a very advanced and highly sophisticated smartphone that has a rather weak battery, which is not really energy efficient. The proud owner of the gadget has to look perennially for a power socket in order not to have the phone running out of power at any inappropriate moment. Maybe the time has come for the smartphone owner to look for another model that would have fewer fancy apps, but a stronger and a more efficient battery, which will make the appliance more convenient and reliable.
Record numbers of people are flying. So why are airlines’ profits plunging?
New York CNN — A record number of passengers are expected to pass through US airports this holiday travel week. You’d think this would be a great time to run an airline. You’d be wrong. Airlines face numerous problems, including higher costs, such as fuel, wages and interest rates. And problems at Boeing mean airlines have too few planes to expand routes to support a record numbers of flyers. Strong bookings can’t entirely offset that financial squeeze. The good news for passengers is they will be spared most of the problems hurting airlines’ bottom lines — at least in the near term. Airfares are driven far more by supply and demand, not their costs. But in the long run, the airlines’ difficulties could mean fewer airline routes, less passenger choice and ultimately a less pleasant flying experience. Profit squeeze Industry analysts expect airlines to report a drop of about $2 billion in profit, or 33%, when they report financial results for the April to June period this year. That would follow losses of nearly $800 million across the industry in the first quarter. Labor costs and jet fuel prices, the airlines’ two largest costs, are both sharply higher this year. Airline pilot unions just landed double-digit pay hikes to make up for years of stagnant wages; flight attendant unions now want comparable raises. Jet fuel prices are climbing because of higher demand in the summer. According to the International Air Transport Association’s jet fuel monitor, prices are up 1.4% in just the last week, and about 4% in the last month. Adding to the airlines’ problems is the crisis at Boeing, as well as the less-well-publicized problems with some of the jet engines on planes from rival Airbus. Since an Alaska Airlines Boeing 737 Max jet lost a door plug on a January 5 flight, leaving a gaping hole in the side of the plane 10 minutes after takeoff, the Federal Aviation Administration has limited how many jets Boeing can make over concerns about quality and safety. As a result, airlines have dramatically reduced plans to expand their fleets and replace older planes with more fuel efficient models. In some cases, airlines have asked pilots to take time off without pay, and carriers such as Southwest and United have announced pilot hiring freezes. In addition to the problems at Boeing, hundreds of the Airbus A220 and A320 family of jets globally have also been grounded for at least a month or more to deal with engine problems. Just about all the planes with those engines have been out of sevice for at least a few days to undergo examinations. And Airbus has also cut back the number of planes it expects to deliver to airlines this year because of supply chain problems. Problems for flyers For now, competition in the industry remains fierce: There are 6% more seats available this month compared to July of 2023, according to aviation analytics firm Cirium. And that’s helped to drive fares down — good news for passengers, but more bad news for airlines’ profits. Southwest announced in April that it would stop serving four airports to trim costs — Bellingham International Airport in Washington state, Cozumel International Airport in Mexico, Syracuse Hancock International Airport in New York and Houston’s George Bush Intercontinental Airport. Many more cities lost air service during the financial hard times of the pandemic. While upstart airlines are driving prices lower for travelers, those discount carriers might not survive long term. As the major carriers are making less money, many of the upstarts are flat-out losing money.
Explainer: How Boeing's Starliner can bring its astronauts back to Earth
WASHINGTON, June 24 (Reuters) - Problems with Boeing's Starliner capsule, still docked at the International Space Station (ISS), have upended the original plans for its return of its two astronauts to Earth, as last-minute fixes and tests draw out a mission crucial to the future of Boeing's (BA.N), opens new tab space division. NASA has rescheduled the planned return three times, and now has no date set for it. Since its June 5 liftoff, the capsule has had five helium leaks, five maneuvering thrusters go dead and a propellant valve fail to close completely, prompting the crew in space and mission managers in Houston to spend more time than expected pursuing fixes mid-mission. Here is an explanation of potential paths forward for Starliner and its veteran NASA astronauts, Barry "Butch" Wilmore and Sunita "Suni" Williams. THE CURRENT SITUATION Starliner can stay docked at the ISS for up to 45 days, according to comments by NASA's commercial crew manager Steve Stich to reporters. But if absolutely necessary, such as if more problems arise that mission officials cannot fix in time, it could stay docked for up to 72 days, relying on various backup systems, according to a person familiar with flight planning. Internally at NASA, Starliner's latest targeted return date is July 6, according to this source, who spoke on condition of anonymity. Such a return date would mean that the mission, originally planned for eight days, instead would last a month. Starliner's expendable propulsion system is part of the craft's "service module." The current problems center on this system, which is needed to back the capsule away from the ISS and position it to dive through Earth's atmosphere. Many of Starliner's thrusters have overheated when fired, and the leaks of helium - used to pressurize the thrusters - appear to be connected to how frequently they are used, according to Stich.
Samsung expects profits to jump by more than 1,400%
Samsung Electronics expects its profits for the three months to June 2024 to jump 15-fold compared to the same period last year. An artificial intelligence (AI) boom has lifted the prices of advanced chips, driving up the firm's forecast for the second quarter. The South Korean tech giant is the world's largest maker of memory chips, smartphones and televisions. The announcement pushed Samsung shares up more than 2% during early trading hours in Seoul. The firm also reported a more than 10-fold jump in its profits for the first three months of this year. In this quarter, it said it is expecting its profit to rise to 10.4tn won ($7.54bn; £5.9bn), from 670bn won last year. That surpasses analysts' forecasts of 8.8tn won, according to LSEG SmartEstimate. "Right now we are seeing skyrocketing demand for AI chips in data centers and smartphones," said Marc Einstein, chief analyst at Tokyo-based research and advisory firm ITR Corporation. Optimism about AI is one reason for the broader market rally over the last year, which pushed the S&P 500 and the Nasdaq in the United States to new records on Wednesday. The market value of chip-making giant Nvidia surged past $3tn last month, briefly holding the top spot as the world's most valuable company. "The AI boom which massively boosted Nvidia is also boosting Samsung's earnings and indeed those of the entire sector," Mr Einstein added. Samsung Electronics is the flagship unit of South Korean conglomerate Samsung Group. Next week, the tech company faces a possible three-day strike, which is expected to start on Monday. A union of workers is demanding a more transparent system for bonuses and time off.
The largest password leak in history exposes nearly 10 billion credentials
The largest collection of stolen passwords ever has been leaked to a notorious crime marketplace, according to cybersecurity researchers at Cybernews. This leak, dubbed RockYou2024 by its original poster “ObamaCare,” holds a file containing nearly 10 billion unique plaintext passwords. Allegedly gathered from a series of data breaches and hacks accumulated over several years, the passwords were posted on July 4th and hailed as the most extensive collection of stolen and leaked credentials ever seen on the forum. “In its essence, the RockYou2024 leak is a compilation of real-world passwords used by individuals all over the world,” the researchers told Cybernews. “Revealing that many passwords for threat actors substantially heightens the risk of credential stuffing attacks.” Credential stuffing attacks are among the most common methods criminals, ransomware affiliates, and state-sponsored hackers use to access services and systems. Threat actors could exploit the RockYou2024 password collection to conduct brute-force attacks against any unprotected system and “gain unauthorized access to various online accounts used by individuals whose passwords are included in the dataset,” the research team said. This could affect online services, cameras and hardware This could affect various targets, from online services to internet-facing cameras and industrial hardware. “Moreover, combined with other leaked databases on hacker forums and marketplaces, which, for example, contain user email addresses and other credentials, RockYou2024 can contribute to a cascade of data breaches, financial frauds, and identity thefts,” the team concluded. However, despite the seriousness of the data leak, it is important to note that RockYou2024 is primarily a compilation of previous password leaks, estimated to contain entries from a total of 4,000 massive databases of stolen credentials, covering at least two decades. This new file notably includes an earlier credentials database known as RockYou2021, which featured 8.4 billion passwords. RockYou2024 added approximately 1.5 billion passwords to the collection, spanning from 2021 through 2024, which, though a massive figure, is only a fraction of the reported 9,948,575,739 passwords in the leak. Thus, users who have changed their passwords since 2021 may not have to panic about a potential breach of their information. That said, the research team at Cybernews stressed the importance of maintaining data security. In response to the leak, they recommend immediately changing the passwords for any accounts associated with the leaked credentials, ensuring each password is strong and unique and not reused across different platforms. Additionally, they advised enabling multi-factor authentication (MFA), which requires an extra form of verification beyond the password, wherever possible, to strengthen cyber security. Lastly, tech users should utilize password manager software, which securely generates and stores complex passwords, mitigating the risk of password reuse across multiple accounts.