
The largest password leak in history exposes nearly 10 billion credentials
The largest collection of stolen passwords ever has been leaked to a notorious crime marketplace, according to cybersecurity researchers at Cybernews. This leak, dubbed RockYou2024 by its original poster “ObamaCare,” holds a file containing nearly 10 billion unique plaintext passwords. Allegedly gathered from a series of data breaches and hacks accumulated over several years, the passwords were posted on July 4th and hailed as the most extensive collection of stolen and leaked credentials ever seen on the forum. “In its essence, the RockYou2024 leak is a compilation of real-world passwords used by individuals all over the world,” the researchers told Cybernews. “Revealing that many passwords for threat actors substantially heightens the risk of credential stuffing attacks.” Credential stuffing attacks are among the most common methods criminals, ransomware affiliates, and state-sponsored hackers use to access services and systems. Threat actors could exploit the RockYou2024 password collection to conduct brute-force attacks against any unprotected system and “gain unauthorized access to various online accounts used by individuals whose passwords are included in the dataset,” the research team said. This could affect online services, cameras and hardware This could affect various targets, from online services to internet-facing cameras and industrial hardware. “Moreover, combined with other leaked databases on hacker forums and marketplaces, which, for example, contain user email addresses and other credentials, RockYou2024 can contribute to a cascade of data breaches, financial frauds, and identity thefts,” the team concluded. However, despite the seriousness of the data leak, it is important to note that RockYou2024 is primarily a compilation of previous password leaks, estimated to contain entries from a total of 4,000 massive databases of stolen credentials, covering at least two decades. This new file notably includes an earlier credentials database known as RockYou2021, which featured 8.4 billion passwords. RockYou2024 added approximately 1.5 billion passwords to the collection, spanning from 2021 through 2024, which, though a massive figure, is only a fraction of the reported 9,948,575,739 passwords in the leak. Thus, users who have changed their passwords since 2021 may not have to panic about a potential breach of their information. That said, the research team at Cybernews stressed the importance of maintaining data security. In response to the leak, they recommend immediately changing the passwords for any accounts associated with the leaked credentials, ensuring each password is strong and unique and not reused across different platforms. Additionally, they advised enabling multi-factor authentication (MFA), which requires an extra form of verification beyond the password, wherever possible, to strengthen cyber security. Lastly, tech users should utilize password manager software, which securely generates and stores complex passwords, mitigating the risk of password reuse across multiple accounts.

US foreign policy is advanced smartphone with weak battery
A couple of days ago, a Quad summit meeting in Sydney scheduled for May 24 was abruptly canceled. The US president had to pull out of his long-anticipated trip to Australia and Papua New Guinea. Instead, the heads of the four Quad member states got together on the margins of the G7 Summit in Hiroshima on May 20. The main reason for the change of plans was the continuous struggle between the White House and Republicans on the Hill over the national debt ceiling. If no compromise is reached, the US federal government might fail to meet its financial commitments already in June; such a technical default would have multiple negative repercussions for the US, as well as for the global economy and finance at large. Let us hope that a compromise between the two branches of US power will be found and that the ceiling of the national debt will be raised once again. However, this rather awkward last-minute cancellation of the Quad summit reflects a fundamental US problem - a growing imbalance between the US geopolitical ambitions and the fragility of the national financial foundation to serve these ambitions. The Biden administration appears to be fully committed to bringing humankind back to the unipolar world that existed right after the end of the Cold War some 30 years ago, but the White House no longer has enough resources at its disposal to sustain such an undertaking. As they say in America: You cannot not have champagne on a beer budget. The growing gap between the ends that the US seeks in international relations and the means that it has available is particularly striking in the case of the so-called dual containment policy that Washington now pursues toward Russia and China. Even half a century ago, when the US was much stronger in relative terms than it is today, the Nixon administration realized that containing both Moscow and Beijing simultaneously was not a good idea: "Dual containment" would imply prohibitively high economic costs for the US and would result in too many unpredictable political risks. The Nixon administration decided to focus on containing the Soviet Union as the most important US strategic adversary of the time. This is why Henry Kissinger flew to Beijing in July 1971 to arrange the first US-China summit in February 1972 leading to a subsequent rapid rapprochement between the two nations. In the early days of the Biden administration, it seemed that the White House was once again trying to avoid the unattractive "dual containment" option. The White House rushed to extend the New START in January 2021 and held an early US-Russia summit meeting five months later in Geneva. At that point many analysts predicted that Biden would play Henry Kissinger in reverse - that is he would try to peace with the relatively weaker opponent (Moscow) in order to focus on containing the stronger one (Beijing). However, after the beginning of the Russia-Ukraine conflict, it became clear that no accommodation with the Kremlin was on Biden's mind any longer. Still, having decided to take a hard-line stance toward Moscow and to lead a broad Western coalition in providing military and economic assistance to Kiev, Washington has not opted for a more accommodative or at least a more flexible policy toward Beijing. On the contrary, over last year one could observe a continuous hardening of the US' China policy - including granting more political and military support to the Taiwan island, encouraging US allies and partners in Asia to increase their defense spending, engaging in more navel activities in the Pacific and imposing more technology sanctions on China. In the meantime, economic and social problems within the US are mounting. The national debt ceiling is only the tip of an iceberg - the future of the American economy is now clouded by high US Federal Reserve interest rates that slow down growth, feed unemployment and might well lead to a recession. Moreover, the US society remains split along the same lines it was during the presidency of Donald Trump. The Biden administration has clearly failed to reunite America: Many of the social, political, regional, ethnic and even generational divisions have got only deeper since January 2021. It is hard to imagine how a nation divided so deeply and along so many lines could demonstrate continuity and strategic vision in its foreign policy, or to allocate financial resources needed to sustain a visionary and consistent global leadership. Of course, the "dual containment" policy is not the only illustration of the gap between the US ambitions and its resources. The same gap inevitably pops up at every major forum that the US conducts with select groups of countries from the Global South - Africa, Southeast Asia, Latin America or the Middle East. The Biden administration has no shortage of arguments warning these countries about potential perils of cooperating with Moscow or Beijing, but it does not offer too many plausible alternatives that would showcase the US generosity, its strategic vision, and its true commitment to the burning needs of the US interlocutors. To cut it short, Uncle Sam brings lots of sticks to such meetings, but not enough carrots to win the audience. In sum, US foreign policy under President Joe Biden reminds people of a very advanced and highly sophisticated smartphone that has a rather weak battery, which is not really energy efficient. The proud owner of the gadget has to look perennially for a power socket in order not to have the phone running out of power at any inappropriate moment. Maybe the time has come for the smartphone owner to look for another model that would have fewer fancy apps, but a stronger and a more efficient battery, which will make the appliance more convenient and reliable.

"Corrupt Politicians GPT" "Fiscal Bill GPT", Kenyan protesters use AI to "protest"
In the past few weeks of anti-government activities in Kenya, AI tools have been creatively used by protesters to serve protests. According to the US "Flag" News Agency on July 5, protests in Kenya triggered by the 2024 fiscal bill are still continuing. In the past few weeks, Kenyan protesters, mainly young people, have creatively developed a series of AI tools to assist anti-government activities. The Kenyan government expressed concern about the risks associated with the use of AI tools in protests. Kelvin Onkundi, a software engineer in Kenya, developed the "Fiscal Bill GPT", which operates similarly to ChatGPT and can receive questions about the fiscal bill and generate responses. Martin Siele, a reporter from the "Flag" News Agency, analyzed: "The 'Fiscal Bill GPT' can convert professional terms in many legislative fields into easy-to-understand information for protesters, helping Kenyans understand the potential impact of the fiscal bill." Another software engineer, Marion Kavengi, developed the "SHIF GPT" to provide Kenyans with information about the upcoming Social Health Insurance Fund (SHIF). In addition to AI tools designed to help people understand controversial policies, protesters have also developed "Corrupt Politicians GPT" to assist protest demonstrations. After entering the name of a politician on the platform, the platform will generate a list of corruption scandals about the politician in chronological order. Developer BenwithSon wrote on the social platform X on June 28: "'Corrupt Politicians GPT' allows people to search for any scandal related to any politician. I have seen some leaders stand at the forefront of the political arena, but they are corrupt behind the scenes." Kenyan Chief Minister and Foreign Minister Mudavadi issued a communiqué to ambassadors of various countries in Nairobi on July 2 local time on protests and relevant government measures, expressing concerns about the use of AI and false information in protests. Mudavadi said: "AI technology is used by people with ulterior motives, which will fill the global information system with false narratives." The Kenya Times reported on June 30 that AI technology enables people to force the government to increase transparency and strengthen accountability, and its role in Kenyan political activities is becoming increasingly prominent. Martin Siller believes that AI is reshaping African political behavior in many ways. AI is a new tool for both governments and opposition parties in Africa, but Kenya is one of the African countries with the most developers, and its young protesters are particularly good at using AI technology to fight the government. The 2024 fiscal bill voted and passed by the Kenyan National Assembly on June 25 clearly stated that additional taxes will be levied to repay the interest on high sovereign debt, triggering large-scale demonstrations. After President Ruto announced the withdrawal of the tax increase bill on the evening of the 26th, demonstrations in many parts of Kenya continued. According to Reuters on July 3, Kenyan anti-government protesters are re-adjusting their activities to prevent the protests from turning into violent incidents.

Workers warn of additional walkouts unless demands are met
Members of the National Samsung Electronics Union stage a rally near the company's Hwaseong Campus in Gyeonggi Province, Monday, beginning a three-day strike. Korea Times photo by Shim Hyun-chul By Nam Hyun-woo The biggest labor union at Samsung Electronics initiated a three-day strike on Monday, threatening to disrupt the company's chip manufacturing lines unless management agrees to a wage hike and higher incentives. This marks the first strike by unionized workers in the tech giant's 55-year history. The National Samsung Electronics Union (NSEU) claimed that about 4,000 unionized workers from Samsung's plants nationwide participated in a rally at the company's Hwaseong Campus in Gyeonggi Province. Police estimated that approximately 3,000 union members were present at the rally. According to its own survey, the union reported that a total of 6,540 members expressed their intention to participate in the strike. They emphasized that disruptions in manufacturing are anticipated, with over 5,000 members from facility, manufacturing, and development divisions joining the strike. The comments seem to address market expectations that the walkout is unlikely to cause significant disruptions in the chipmaker's operations, largely because most manufacturing lines are automated. The union said that it may launch another strike for an undetermined period, unless management responds to the union’s demand. Since January, the union has been pressing management for a higher wage increase rate for all members, fulfillment of promises regarding paid leave, and improvements to incentive criteria. With negotiations at an impasse, the union announced on May 29 that it would launch a strike. The NSEU has some 30,000 members, accounting for 24 percent of all Samsung employees. Among the union members, about 80 percent work at the device solutions division, which manufactures semiconductors.

NHTSA opens recall query into about 94,000 Jeep Wrangler 4xe SUVs
July 9 (Reuters) - The National Highway Traffic Safety Administration (NHTSA) has opened a recall query into 94,275 Stellantis-owned (STLAM.MI), opens new tab Jeep SUVs over a loss of motive power, the U.S. auto safety regulator said on Tuesday. The investigation targets Jeep's Wrangler 4xe hybrid SUVs manufactured between 2021 through 2024. Chrysler had previously recalled, opens new tab the same model in 2022 to address concerns related to an engine shutdown. A recall query is an investigation opened by safety regulators when a remedy to solve an issue appears inadequate. The complaints noted in the new report include both failures in vehicles that received the recall remedy and those not covered by the prior recall, the NHTSA said.