link1s.site

The largest password leak in history exposes nearly 10 billion credentials

The largest collection of stolen passwords ever has been leaked to a notorious crime marketplace, according to cybersecurity researchers at Cybernews.

This leak, dubbed RockYou2024 by its original poster “ObamaCare,” holds a file containing nearly 10 billion unique plaintext passwords.

Allegedly gathered from a series of data breaches and hacks accumulated over several years, the passwords were posted on July 4th and hailed as the most extensive collection of stolen and leaked credentials ever seen on the forum.

“In its essence, the RockYou2024 leak is a compilation of real-world passwords used by individuals all over the world,” the researchers told Cybernews. “Revealing that many passwords for threat actors substantially heightens the risk of credential stuffing attacks.”

Credential stuffing attacks are among the most common methods criminals, ransomware affiliates, and state-sponsored hackers use to access services and systems.

Threat actors could exploit the RockYou2024 password collection to conduct brute-force attacks against any unprotected system and “gain unauthorized access to various online accounts used by individuals whose passwords are included in the dataset,” the research team said.

This could affect online services, cameras and hardware

This could affect various targets, from online services to internet-facing cameras and industrial hardware.

“Moreover, combined with other leaked databases on hacker forums and marketplaces, which, for example, contain user email addresses and other credentials, RockYou2024 can contribute to a cascade of data breaches, financial frauds, and identity thefts,” the team concluded.

However, despite the seriousness of the data leak, it is important to note that RockYou2024 is primarily a compilation of previous password leaks, estimated to contain entries from a total of 4,000 massive databases of stolen credentials, covering at least two decades.

This new file notably includes an earlier credentials database known as RockYou2021, which featured 8.4 billion passwords. RockYou2024 added approximately 1.5 billion passwords to the collection, spanning from 2021 through 2024, which, though a massive figure, is only a fraction of the reported 9,948,575,739 passwords in the leak.

Thus, users who have changed their passwords since 2021 may not have to panic about a potential breach of their information.

That said, the research team at Cybernews stressed the importance of maintaining data security. In response to the leak, they recommend immediately changing the passwords for any accounts associated with the leaked credentials, ensuring each password is strong and unique and not reused across different platforms.

Additionally, they advised enabling multi-factor authentication (MFA), which requires an extra form of verification beyond the password, wherever possible, to strengthen cyber security.

Lastly, tech users should utilize password manager software, which securely generates and stores complex passwords, mitigating the risk of password reuse across multiple accounts.

China's generative AI patents are far ahead of the US!
The World Intellectual Property Organization (WIPO) recently said that China filed 38,000 artificial intelligtion-related generative AI patents from 2014-23, while the United States filed 6,276 of the 50,000 patents filed by all countries. Of the 50,000 applications, 25 percent were filed last year.The top five inventor regions are: China (38,210 inventions), the United States (6,276 inventions), the Republic of Korea (4,155 inventions), Japan (3,409 inventions) and India (1,350 inventions).
Israeli strike kills a senior Hezbollah commander in south Lebanon
BEIRUT/JERUSALEM July 3 (Reuters) - An Israeli strike killed one of Hezbollah's top commanders in south Lebanon on Wednesday, prompting retaliatory rocket fire by the Iran-backed group into Israel as their dangerously poised conflict rumbled on. The Israeli military said it had struck and eliminated Hezbollah's Mohammed Nasser, calling him commander of a unit responsible for firing from southwestern Lebanon at Israel. Nasser, killed by an airstrike near the city of Tyre in southern Lebanon, was the one of the most senior Hezbollah commanders to die yet in the conflict, two security sources in Lebanon said. Sparked by the Gaza war, the hostilities have raised concerns about a wider and ruinous conflict between the heavily armed adversaries, prompting U.S. diplomatic efforts aimed at deescalation. Israeli Defence Minister Yoav Gallant said Israeli forces were hitting Hezbollah "very hard every day" and will be ready to take any action necessary against the group, though the preference is to reach a negotiated arrangement. Hezbollah began firing at Israeli targets at the border after its Palestinian ally Hamas launched the Oct. 7 attack on Israel, declaring support for the Palestinians and saying it would cease fire when Israel stops its Gaza offensive. Hezbollah announced at least two attacks in response to what it called "the assassination", saying it launched 100 Katyusha rockets at an Israeli military base and its Iranian-made Falaq missiles at another base in the town of Kiryat Shmona near the Israeli-Lebanese border. Israel's Channel 12 broadcaster reported that dozens of rockets were fired into northern Israel from Lebanon. There were no reports of casualties. The Israeli Defence Ministry said that air raid sirens sounded in several parts of northern Israel. Israel's military did not give a number of rockets launched but said most of them fell in open areas, some were intercepted, while a number of launches fell in the area of Kiryat Shmona.
Microsoft to offer Apple devices to employees in China, cites absence of Android services
July 8 (Reuters) - Microsoft (MSFT.O), opens new tab intends to offer Apple's (AAPL.O), opens new tab iOS-based devices to its employees in China to access authentication apps, a company spokesperson said on Monday, citing absence of Google's (GOOGL.O), opens new tab Android services in the country. Microsoft has been under increased scrutiny after a series of security breaches, the latest being that of Russian hackers who spied and accessed emails of the company's employees and customers earlier this year. The development was first reported by Bloomberg News, which, citing an internal memo, said the Windows OS-maker instructed its employees in China to use Apple devices at workplace from September. As a part of Microsoft's global Secure Future Initiative, the move to switch to iOS-devices stems from the lack of availability of Google Play Store in China that limits its employees' access to security apps such as Microsoft Authenticator and Identity Pass, the report added. "Due to the lack of availability of Google Mobile Services in this region, we look to offer employees a means of accessing these required apps, such as an iOS device," a company spokesperson told Reuters in an email. Microsoft is among those U.S. companies that have a strong presence in China. It entered the Chinese market in 1992 and also operates a large research and development center in the country. The company will provide iPhone 15 models to employees, currently using Android handsets across China, including Hong Kong, the Bloomberg report said.
Australia pledges to provide more funds to Pacific island banks to counter China's influence
Australia pledged on Tuesday to increase investment in Pacific island nations, offering A$6.3 million ($4.3 million) to support their financial systems. Some Western banks are cutting ties with the region because of risk factors, while China is trying to increase its influence there. Some Western bankers have terminated long-standing banking relationships with small Pacific nations, while others are considering closing operations and restricting access to dollar-denominated bank accounts in those countries. "We know that the Pacific is the fastest-moving region in the world for correspondent banking services," Australian Treasurer Jim Chalmers said in a speech at the Pacific Banking Forum in Brisbane. "What's at stake here is the Pacific's ability to engage with the world," he said, with much of the region at risk of being cut off from the global financial system. Chalmers said Australia would provide A$6.3 million ($4.3 million) to the Pacific to develop secure digital identity infrastructure and strengthen compliance with anti-money laundering and counter-terrorist financing requirements. Experts say Western banks are de-risking to meet financial regulations, making it harder for them to do business in Pacific island nations, where compliance standards sometimes lag, undermining their financial resilience. Australia's ANZ Bank is in talks with governments about how to make its Pacific island businesses more profitable amid concerns about rising Chinese influence as financial services leave the West, Chief Executive Shayne Elliott said Tuesday. ANZ is the largest bank in the Pacific region, with operations in nine countries, though some of those businesses are not financially sustainable, Elliott said in an interview on the sidelines of the forum. "If we were there purely for commercial purposes, we would have closed it a long time ago," he said. Western countries, which have traditionally dominated the Pacific, are increasingly concerned about China's plans to expand its influence in the region after it signed several major defense, trade and financial agreements with the region. Bank of China signed an agreement with Nauru this year to explore opportunities in the country, following Australia's Bendigo Bank saying it would withdraw from the country. Mr. Chalmers said Australia was working with Nauru to ensure that banking services in the country could continue. ANZ Bank exited its retail business in Papua New Guinea in recent years, while Westpac considered selling its operations in Fiji and Papua New Guinea but decided to keep them. The Pacific lost about 80% of its correspondent banking relationships for dollar-denominated services between 2011 and 2022, Australian Assistant Treasurer Stephen Jones told the forum, which was co-hosted by Australia and the United States. “We would be very concerned if there were countries acting in the region whose primary objective was to advance their own national interests rather than the interests of Pacific island countries,” Mr. Jones said on the first day of the forum in Brisbane. He made the comment when asked about Chinese banks filling a vacuum in the Pacific. Meanwhile, Washington is stepping up efforts to support Pacific island countries in limiting Chinese influence. "We recognize the economic and strategic importance of the Pacific region, and we are committed to deepening engagement and cooperation with our allies and partners to enhance financial connectivity, investment and integration," said Brian Nelson, U.S. Treasury Undersecretary for Counterterrorism and Financial Intelligence. The United States is aware of the problem of Western banks de-risking in the Pacific region and is committed to addressing it, Nelson told the forum's participants. He said data showed that the number of correspondent banking relationships in the Pacific region has declined at twice the global average rate over the past decade, and the World Bank and the Asian Development Bank are developing plans to improve correspondent banking relationships. U.S. Treasury Secretary Janet Yellen said in a video address to the forum on Monday (July 8) that the United States is focused on supporting economic resilience in the Pacific region, including by strengthening access to correspondent banks. She said that when President Biden and Australian Prime Minister Anthony Albanese met at the White House last year, they particularly emphasized the importance of increasing economic connectivity, development and opportunities in the Pacific region, and a key to achieving that goal is to ensure that people and businesses in the region have access to the global financial system.
Morning Bid: Eyes switch to inflation vs elections, Powell up
A look at the day ahead in U.S. and global markets from Mike Dolan After an intense month focused on election risk around the world, markets quickly switched back to the more prosaic matter of the cost of money - and whether disinflation is resuming to the extent it allows borrowing costs to finally fall. Thursday's U.S. consumer price update for June is the key moment of the week for many investors - with the headline rate expected to have fallen two tenths of a percentage point to 3.1% but with 'core' rates still stuck at 3.4%. With Federal Reserve chair Jerome Powell starting his two-pronged semi-annual congressional testimony later on Tuesday, the consensus CPI forecast probably reflects what the central bank thinks of the situation right now - encouraging but not there yet. But as the U.S. unemployment rate is now back above 4.0% for the first time since late 2021, markets may look for a more nuanced approach from the Fed chair that sees it increasingly wary of a sudden weakening of the labor market as real time quarterly GDP estimates ebb again to about 1.5%. There were some other reasons for Fed optimism in the lead up to the testimony. The path U.S. inflation is expected to follow over coming years generally softened in June, amid retreating projections of price increases for a wide array of consumer goods and services, a New York Fed survey showed on Monday. Inflation a year from now was seen at 3% as of June - down from the expected rise of 3.2% in May - and five-year expectations fell to 2.8% from 3%. Crude oil prices are better behaved this week, too, falling more than 3% from the 10-week highs hit late last week and halving the annual oil price gain to 10%. The losses on Tuesday came after a hurricane that hit a key U.S. oil-producing hub in Texas caused less damage than many in markets had expected - easing concerns over supply disruption. Before Powell starts speaking later, there will also be an update on U.S. small business confidence for last month.