link1s.site

The largest password leak in history exposes nearly 10 billion credentials

The largest collection of stolen passwords ever has been leaked to a notorious crime marketplace, according to cybersecurity researchers at Cybernews.

This leak, dubbed RockYou2024 by its original poster “ObamaCare,” holds a file containing nearly 10 billion unique plaintext passwords.

Allegedly gathered from a series of data breaches and hacks accumulated over several years, the passwords were posted on July 4th and hailed as the most extensive collection of stolen and leaked credentials ever seen on the forum.

“In its essence, the RockYou2024 leak is a compilation of real-world passwords used by individuals all over the world,” the researchers told Cybernews. “Revealing that many passwords for threat actors substantially heightens the risk of credential stuffing attacks.”

Credential stuffing attacks are among the most common methods criminals, ransomware affiliates, and state-sponsored hackers use to access services and systems.

Threat actors could exploit the RockYou2024 password collection to conduct brute-force attacks against any unprotected system and “gain unauthorized access to various online accounts used by individuals whose passwords are included in the dataset,” the research team said.

This could affect online services, cameras and hardware

This could affect various targets, from online services to internet-facing cameras and industrial hardware.

“Moreover, combined with other leaked databases on hacker forums and marketplaces, which, for example, contain user email addresses and other credentials, RockYou2024 can contribute to a cascade of data breaches, financial frauds, and identity thefts,” the team concluded.

However, despite the seriousness of the data leak, it is important to note that RockYou2024 is primarily a compilation of previous password leaks, estimated to contain entries from a total of 4,000 massive databases of stolen credentials, covering at least two decades.

This new file notably includes an earlier credentials database known as RockYou2021, which featured 8.4 billion passwords. RockYou2024 added approximately 1.5 billion passwords to the collection, spanning from 2021 through 2024, which, though a massive figure, is only a fraction of the reported 9,948,575,739 passwords in the leak.

Thus, users who have changed their passwords since 2021 may not have to panic about a potential breach of their information.

That said, the research team at Cybernews stressed the importance of maintaining data security. In response to the leak, they recommend immediately changing the passwords for any accounts associated with the leaked credentials, ensuring each password is strong and unique and not reused across different platforms.

Additionally, they advised enabling multi-factor authentication (MFA), which requires an extra form of verification beyond the password, wherever possible, to strengthen cyber security.

Lastly, tech users should utilize password manager software, which securely generates and stores complex passwords, mitigating the risk of password reuse across multiple accounts.

Biden accelerated aging over the past year!
n a recent interview with ABC, US President Joe Biden said he had no intention of dropping out of the race, blaming his poor debate performance on a cold. He also insisted he was "still in good shape" and would remain in the race, saying only "Almighty God" could pull him out. An insider who has worked with Mr. Biden for a long time said that signs of aging had become apparent over the past year, but that Mr. Biden's team had failed to address it. Biden's televised debate performance heightened concerns about an already slow-moving issue. Mr. Biden's advisers have long dodged questions about his age. But now they acknowledge that Biden's aging is an undeniable fact. The debate forced the president to more openly acknowledge the limitations of his age, which he had previously largely dismissed. But they have only taken superficial measures and have not fundamentally solved the problem. They replaced the long staircase that Mr. Biden used to board Air Force One with a shorter one; Assistants often accompanied him in public to make his stiff gait less noticeable; While he has a busy schedule, aides have arranged for buffer time, such as long weekends at his homes in Wilmington and Rehoboth Beach, Delaware, or extended stays at Camp David, a Maryland resort, to rest after a "grueling" stretch of travel. Under the authority of one of his top advisers, Anita Dunn, Mr. Biden's public interactions -- especially with reporters -- were severely limited. Even at major events with Democrats or other supporters, the White House sometimes limits the amount of time Biden can spend with the audience, two people familiar with the matter said. As a protective response, designed to protect their longtime boss.
China will reach climate goal while West falls short
There has been constant low-level sniping in the West against China's record on climate change, in particular its expansion of coal mining, and its target of 2060 rather than 2050 for carbon zero. I have viewed this with mild if irritated amusement, because when it comes to results, then China, we can be sure, will deliver and most Western countries will fall short, probably well short. It is now becoming clear, however, that we will not have to wait much longer to judge their relative performances. The answer is already near at hand. We now know that in 2023 China's share of renewable energy capacity reached about 50 percent of its total energy capacity. China is on track to shatter its target of installing 1200GW of solar and wind energy capacity by 2030, five years ahead of schedule. And international experts are forecasting that China's target of reaching peak CO2 emissions by 2030 will probably be achieved ahead of schedule, perhaps even by a matter of years. Hitherto, China has advisedly spoken with a quiet voice about its climate targets, sensitive to the fact that it has become by far the world's largest CO2 emitter and aware that its own targets constituted a huge challenge. Now, however, it looks as if China's voice on global warming will carry an authority that no other nation will be able to compete with. There is another angle to this. China is by far the biggest producer of green tech, notably EVs, and renewable energy, namely solar photovoltaics and wind energy. Increasingly China will be able to export these at steadily reducing prices to the rest of the world. The process has already begun. It leaves the West with what it already sees as a tricky problem. How can it become dependent on China for the supply of these crucial elements of a carbon-free economy when it is seeking to de-risk (EU) or decouple (US) its supply chains from China? Climate change poses the greatest risk to humanity of all the issues we face today. There are growing fears that the 1.5-degree Celsius target for global warming will not be met. 2023 was the hottest year ever recorded. Few people are now unaware of the grave threat global warming poses to humanity. This requires the whole world to make common cause and accept this as our overarching priority. Alas, the EU is already talking about introducing tariffs to make Chinese EVs more expensive. And it is making the same kind of noises about Chinese solar panels. The problem is this. Whether Europe likes it or not, it needs a plentiful supply of Chinese EVs and solar panels if it is to reduce its carbon emissions at the speed that the climate crisis requires. According to the International Energy Authority, China "deployed as much solar capacity last year as the entire world did in 2022 and is expected to add nearly four times more than the EU and five times more than the US from 2023-28." The IEA adds, "two-thirds of global wind manufacturing expansion planned for 2025 will occur in China, primarily for its domestic market." In other words, willy-nilly, the West desperately needs China's green tech products. Knee-jerk protectionism demeans Europe; it is a petty and narrow-minded response to the greatest crisis humanity has ever faced. Instead of seeking to resist or obstruct Chinese green imports, it should cooperate with China and eagerly embrace its products. As a recent Financial Times editorial stated: "Beijing's green advances should be seen as positive for China, and for the world." The climate crisis is now in the process of transforming the global political debate. Hitherto it seemed relatively disconnected. That period is coming to an end. China's dramatic breakthrough in new green technologies is offering hope not just to China, but to the whole world, because China will increasingly be able to supply both the developed and developing world with the green technology needed to meet their global targets. Or, to put it another way, it looks very much as if China's economic and technological prowess will play a crucial role in the global fight against climate change. We should not be under any illusion about the kind of challenge humanity faces. We are now required to change the source of energy that powers our societies and economies. This is not new. It has happened before. But previously it was always a consequence of scientific and technological discoveries. Never before has humanity been required to make a conscious decision that, to ensure its own survival, it must adopt new sources of energy. Such an unprecedented challenge will fundamentally transform our economies, societies, cultures, technologies, and the way we live our lives. It will also change the nature of geopolitics. The latter will operate according to a different paradigm, different choices, and different priorities. The process may have barely started, but it is beginning with a vengeance. Can the world rise to the challenge, or will it prioritize petty bickering over the vision needed to save humanity? On the front line, mundane as it might sound, are EVs, wind power, and solar photovoltaics. The author is a visiting professor at the Institute of Modern International Relations at Tsinghua University and a senior fellow at the China Institute, Fudan University. Follow him on X @martjacques.
Argentina's government reform bill officially takes effect: granting the president special powers in areas such as administration
On the 8th, the Argentine government promulgated the "Foundations and Starting Points for Argentine Freedom" comprehensive bill and a package of fiscal measures, marking the official entry into force of the government reform bill. According to the official gazette of the Argentine government, Argentine President Milley, Chief Cabinet Minister Guillermo Francos and Economy Minister Luis Caputo jointly signed Decrees No. 592 and No. 593 to promulgate these two new reform measures. The comprehensive bill declared Argentina to enter a one-year public emergency in the administrative, economic, financial and energy fields, and granted the president special powers in these fields. It also includes the relaxation of economic regulations, labor reforms and the implementation of a large-scale investment incentive system. The package of fiscal measures involves anti-money laundering, tax deferral, tariffs, re-imposition of high-salary income tax and reduction of personal property taxes. On June 28, after six months of negotiations, the two reform bills were finally passed by the Argentine Congress.
Google extends Linux kernel support to 4 years
According to AndroidAuthority, the Linux kernel used by Android devices is mostly derived from Google's Android Universal Kernel (ACK) branch, which is created from the Android mainline kernel branch when new LTS versions are released upstream. For example, when kernel version 6.6 is announced as the latest LTS release, an ACK branch for Android15-6.6 appears shortly after, with the "android15" in the name referring to the Android version of the kernel (in this case, Android 15). Google maintains its own set of LTS kernel branches for three main reasons. First, Google can integrate upstream features that have not yet been released into the ACK branch by backporting or picking, so as to meet the specific needs of Android. Second, Google can include some features that are being developed upstream in the ACK branch ahead of time, making it available for Android devices as early as possible. Finally, Google can add some vendor or original equipment manufacturer (OEM) features for other Android partners to use. Once created, Google continues to update the ACK branch to include not only bug fixes for Android specific code, but also to integrate the LTS merge content of the upstream kernel branch. For example, the Linux kernel vulnerability disclosed in the July 2024 Android security bulletin will be fixed through these updates. However, it is not easy to distinguish a bug fix from other bug fixes, as a patch that fixes a bug may also accidentally plug a security vulnerability that the submitter did not know about or chose not to disclose. Google does its best to recognize this, but it inevitably misses the mark, resulting in bug fixes for the upstream Linux kernel being released months before Android devices. As a result, Google has been urging Android vendors to regularly update the LTS kernel to avoid being caught off guard by unexpectedly disclosed security vulnerabilities. Clearly, the LTS version of the Linux kernel is critical to the security of Android devices, helping Google and vendors deal with known and unknown security vulnerabilities. The longer the support period, the more timely security updates Google and vendors can provide to devices.
Hedge fund Elliott challenges court verdict it lost against LME on nickel
LONDON, July 9 (Reuters) - U.S.-based hedge fund Elliott Associates on Tuesday urged a London court to overturn a verdict supporting the London Metal Exchange's (LME) cancellation of nickel trades partly because the exchange failed to disclose documents. The LME annulled $12 billion in nickel trades in March 2022 when prices shot to records above $100,000 a metric ton in a few hours of chaotic trade. Elliott and market maker Jane Street Global Trading brought a case demanding a combined $472 million in compensation, alleging at a trial in June last year that the 146-year-old exchange had acted unlawfully. London's High Court ruled last November that the LME had the right to cancel the trades because of exceptional circumstances, and was not obligated to consult market players prior to its decision. Lawyers for Elliott told London's Court of Appeal that the LME belatedly released documents in May detailing its "Kill Switch" and "Trade Halt" internal procedures. It also newly disclosed an internal report that Elliott said detailed potential conflicts of interest at the exchange. "It was troubling that one gets disclosure out of the blue in the Court of Appeal for the first time," Elliott lawyer Monica Carss-Frisk told the court. Jane Street Global did not appeal the ruling. "If we had had them (documents) in the proceedings before the divisional court, we may well have sought permission to cross examine." LME lawyers said the new documents were not relevant. "The disclosed documents do not affect the reasoning of the divisional court or the merits of the arguments on appeal," the exchange said in documents prepared for the appeal hearing. "Elliott's appeal is largely a repetition of the arguments which were advanced, and rightly rejected." The LME said it had both the power and a duty to unwind the trades because a record $20 billion in margin calls could have led to at least seven clearing members defaulting, systemic risk and a potential "death spiral". Elliott said the ruling diluted protection provided by the Human Rights Act and also wrongly concluded the LME had the power to cancel the trades.