Posts

#TikTok mob attack led by middle schoolers tormenting teachers

Image
  A bunch of eighth graders in a "wealthy Philadelphia suburb" recently targeted teachers with an extreme online harassment campaign that The New York Times reported was "the first known group TikTok attack of its kind by middle schoolers on their teachers in the United States." According to The Times, the Great Valley Middle School students created at least 22 fake accounts impersonating about 20 teachers in offensive ways. The fake accounts portrayed long-time, dedicated teachers sharing "pedophilia innuendo, racist memes," and homophobic posts, as well as posts fabricating "sexual hookups among teachers." The Pennsylvania middle school's principal, Edward Souders, told parents in an email that the number of students creating the fake accounts was likely "small," but that hundreds of students piled on, leaving comments and following the fake accounts. Other student...

#Police pulled over a Waymo car for driving in the oncoming lane

Image
  On June 19th, a Phoenix police officer pulled over an autonomous Waymo vehicle that had been driving in an oncoming traffic lane. The car was apparently confused by some construction signs and reportedly ran a red light before pulling over in a parking lot to let the officer talk to one of Waymo’s support representatives. In about two-and-a-half minutes of bodycam footage published by  AZCentral,  t he officer told Waymo the car was driving in a construction zone when it “went into opposing lanes of traffic, which is real bad.” He then told a curious bystander what had happened, adding, “so I light it up and it takes off in the intersection.” A dispatch record reportedly said the car drove through a red light and ‘FREAKED OUT’ before it pulled over. Waymo spokesperson Chris Bonelli told  The Verge  in an email that the vehicle, which had no passengers, drove into the oncoming lane whe...

#The biggest password leak ever: nearly 10 billion credentials exposed

Image
    Cybersecurity researchers are calling it the largest password compilation leak of all time. On July 4, a newly registered user on a popular hacking forum posted a file containing nearly 10 billion compromised passwords in plaintext. The post was first noticed by researchers at  Cybernews . RockYou2024 leaked password compilation This gigantic list of leaked passwords known as RockYou2024 provides hackers with an important tool that can be utilized in a brute force attack.  A brute force attack is a popular hacking method where the attacker guesses a user's password by trial-and-error. Hackers commonly use automated scripts when carrying out a brute force attack, which enables them to try out a slew of passwords within a short period of time. With a leaked password database this big, hackers have a nearly unlimited pool of passwords to try out.  “In its essence, the RockYou2024 leak is a comp...

#440,000 Taylor Swift Eras Tour tickets leaked

Image
  The ShinyHunters hacker group claims the Ticketmaster breach is far bigger than previously anticipated, stealing 193 million barcodes, including 440,000 Taylor Swift tickets. Valued at $22 billion, they now demand $8 million from LiveNation! In May 2024, the notorious hacker group ShinyHunters breached Ticketmaster – LiveNation, as we know it. However, the hackers have now released new details about the extent of their breach. These details have been published on the infamous cybercrime and hacker platform Breach Forums titled “Ticketmaster event barcodes ‘Taylor Swift’ pt 1/65000.”   The Breach Unveiled ShinyHunters marked the Fourth of July with a disturbing announcement: they claim to have stolen 440,000 tickets for Taylor Swift’s Eras Tour. In a symbolic twist, they suggest that instead of Swift performing on her tour, she will be “performing in front of Congress,” indicating this breach’s severity and public exposure.   The Staggering Numbers      Th...

#New App Lets You Spy on Bars to See How Busy They Are

Image
  A weird new app lets San Francisco residents monitor local bars via live video feed to see what’s happening there and to check how busy the venues are. 2Nite, which launched earlier this year, uses a network of cameras at various Bay Area establishments to provide remote insights into what’s happening at those locations. “The all in one app for managing, promoting, and discovering nightlife,” the app’s website proclaims. On its app page, meanwhile, the program encourages users to “scroll through” its “discovery page,” where the various live streams are visible. Users can also purchase tickets to events (like concerts) at the venues in question, through the app. So far, the app only has contracts with “five to eight venues,” The San Francisco Standard writes. “This app got me laid,” says one five-star review on the Apple App Store. “Best way to buy tickets for events. 2nite is the truth and the future,”...

#This man used Fake Wi-Fi Scam on Domestic Flights

Image
  An Australian man has been charged with running a fake Wi-Fi access point during a domestic flight with an aim to steal user credentials and data. The unnamed 42-year-old "allegedly established fake free Wi-Fi access points, which mimicked legitimate networks, to capture personal data from unsuspecting victims who mistakenly connected to them," the Australian Federal Police (AFP) said in a press release last week. The agency said the suspect was charged in May 2024 after it launched an investigation a month earlier following a report from an airline about a suspicious Wi-Fi network identified by its employees during a domestic flight. A subsequent search of his baggage on April 19 led to the seizure of a portable wireless access device, a laptop, and a mobile phone. He was arrested on May 8 after a search warrant was executed at his home. The individual is said to have staged what's called an evil ...

#This government didn't have backups of ransomwared data, because DR was only an option

Image
  Indonesia’s president Joko Widodo has ordered an audit of government datacenters after it was revealed that most of the data they store is not backed up. The audit and revelation that Indonesia lacks a backup plan came in aftermath of ransomware attack on the nation’s Temporary National Data Center (PDNS) that took place on June 20th and resulted in widespread disruption of digital services. Government officials communicated that a fresh variant of the LockBit malware, named Brain Cipher, was used in the attack. “Just like other ransomware, it encrypts all data, all files on the server they attack," Deputy Minister of Communication and Information Nezar Patria explained. The data is being held hostage for 131 billion Rupiah (US$8 million.) Communication and Informatics Minister Budi Arie Setiadi told journalists the government does not intend to pay. Authorities are instead attempting to decrypt the data. The audit order reportedl...

#Former IT employee accessed data of over 1 million US patients

Image
  Geisinger, a prominent healthcare system in Pennsylvania, has announced a data breach involving a former employee of Nuance, an IT services provider contracted by the organization. Geisinger is a non-profit organization that operates 134 care sites, ten hospitals, and the Geisinger Health Plan, serving a total of 1.2 million people. It employs 26,000 staff, including 1,600 doctors, and is considered one of Pennsylvania’s most important organizations. An announcement published earlier this week explains that in November 2023, Geisinger detected unauthorized access to its patients’ database by a former Nuance employee. Nuance was promptly informed and took action to block the former employee’s access to Geisinger’s systems holding patient records. “On Nov. 29, 2023, Geisinger discovered and immediately notified Nuance that a former Nuance employee had accessed certain Geisinger patient information two days after th...

#Microsoft's AI boss thinks it’s perfectly OK to steal content if it's on the open web

Image
  Microsoft AI boss Mustafa Suleyman incorrectly believes that the moment you publish anything on the open web, it becomes “freeware” that anyone can freely copy and use. When CNBC’s Andrew Ross Sorkin asked him whether “AI companies have effectively stolen the world’s IP,” he said: I think that with respect to content that’s already on the open web, the social contract of that content since the ‘90s has been that it is fair use. Anyone can copy it, recreate with it, reproduce with it. That has been “freeware,” if you like, that’s been the understanding. Microsoft is currently the target of multiple lawsuits alleging that it — and OpenAI — are stealing copyrighted online stories to train generative AI models, so it may not surprise you to hear a Microsoft exec defend it as perfectly legal. I just didn’t expect him to be so very publicly and obviously wrong! I am not a lawyer, but even...

#Massive Recall! Tesla recalls every Cybertruck

Image
  Remember Tesla Cybertruck's oversized windshield wiper? The one that appears too large to exist, at least not without malfunctioning in some way? Well, it turns out that it is. Tesla just issued a recall for over 11,000 Cybertrucks over a windshield wiper issue. The recall includes all model year 2024 Cybertruck vehicles manufactured from Nov. 13, 2023, to June 6, 2024, which is pretty much all of them given that the Cybertruck deliveries started in Nov. 2023. "On affected vehicles, the front windshield wiper motor controller may stop functioning due to electrical overstress to the gate driver component," the recall report says. "A non-functioning windshield wiper may reduce visibility in certain operating conditions, which may increase the risk of a collision." The report also said that Tesla is not aware of any collisions, injuries, or deaths relating to the issue. For Cybertruck owners...

#TeamViewer hacked by Russian Spies

Image
  TeamViewer, the company that makes widely used remote access tools for companies, has confirmed an ongoing cyberattack on its corporate network.  In a statement Friday, the company attributed the compromise to government-backed hackers working for Russian intelligence, known as APT29 (and Midnight Blizzard). The Germany-based company said its investigation so far points to an initial intrusion on June 26 “tied to credentials of a standard employee account within our corporate IT environment.”  TeamViewer said that the cyberattack “was contained” to its corporate network and that the company keeps its internal network and customer systems separate. The company added that it has “no evidence that the threat actor gained access to our product environment or customer data.”  Martina Dier, a spokesperson for TeamViewer, declined to answer a series of questions from TechCrunch, including whether th...

#Shopping app Temu is "dangerous malware," spying on your texts

Image
  Temu—the Chinese shopping app that has rapidly grown so popular in the US that even Amazon is reportedly trying to copy it—is "dangerous malware" that's secretly monetizing a broad swath of unauthorized user data, Arkansas Attorney General Tim Griffin alleged in a lawsuit filed Tuesday. Griffin cited research and media reports exposing Temu's allegedly nefarious design, which "purposely" allows Temu to "gain unrestricted access to a user's phone operating system, including, but not limited to, a user's camera, specific location, contacts, text messages, documents, and other applications." "Temu is designed to make this expansive access undetected, even by sophisticated users," Griffin's complaint said. "Once installed, Temu can recompile itself and change properties, including overriding the data privacy settings users believe they have in place." ...

#Google AI Uses Enough Electricity in 1 Second to Charge 7 Electric Cars

Image
  Nobody asked for this AI search bullshit, Google. Not only are the AI generated responses demonstrably worse than normal, they’re infringing on intellectual property rights, killing traditional media, and—thanks to a new Jacobin report we now know—soaking up gobs of electricity in the process. Artificial intelligence-powered search engines are an all-around bad idea, and a stop should be put to the whole thing as quickly as humanly possible. Google’s AI Overviews feature has only been operational for two months, but it’s already done a lot of harm and will only continue to get worse. As it turns out, these AI search results require around ten times the energy to power them as a traditional Google search. According to research firm Digiconomist, adding AI-generated answers to all Google searches could approach the energy usage of the entire country of Ireland. Each search requires three watt-hours of...

#Dozens of Tesla Cybertrucks vandalized by someone who really doesn't like Elon Musk

Image
  Elon Musk may have just won approval for a $56 billion pay package from his adoring supporters, but someone in Fort Lauderdale is clearly not a fan of the controversial CEO. Last week, dozens of Tesla Cybertrucks were defaced with the words “Fuck Elon” in black spray paint, according to  InsideEVs citing local news reports. Police say that 34 stainless steel trucks were tagged with the message, which was discovered on Friday. The Cybertrucks were being stored in the public parking lot, without any fencing or security, likely being held because of a previously reported problem with the windshield wiper. Tesla is also experiencing an inventory pileup as a result of cooling demand for its electric vehicles. Local news reports that the spray paint was easily removed, with a few trucks still showing some black smudges. But thanks to a few social media accounts, we can still exper...

#MustKnow- What is catfishing and what can you do if you are catfished?

Image
  Catfishing is when a person uses false information and images to create a fake identity online with the intention to trick, harass, or scam another person. It is often on social media or dating apps and websites as a common tactic used to form online relationships under false pretenses, sometimes to lure people into financial scams. The person doing the pretending, or the “catfish” may also obtain intimate images from a victim and use them to extort or blackmail the person. This is known as sextortion, or they may use other personal information shared with them to commit identity theft. The term is believed to originate from the 2010 documentary “Catfish,” in which a young Nev Schulman starts an online relationship with teenager “Megan”, who turns out to be an older woman. In the final scene of the documentary, the woman’s husband shares an anecdote about how live cod used to be exported from Alaska alongside ca...

#A Catastrophic Hospital Hack Ends in a ...

Image
  Russian hackers have stolen records covering 300m patient interactions with the NHS, including the results of blood tests for HIV and cancer, the Guardian can reveal. The amount and sensitive nature of the data obtained by the Qilin hacking gang has caused alarm among NHS bosses, who are scrambling to set up a helpline to deal with inquiries from what could be a large number of worried patients and also health service staff. Seven hospitals run by two NHS trusts were affected by the attack, which targeted Synnovis, a private/NHS joint venture that provides pathology services such as blood tests and transfusions. It is unclear at this stage if the hack involves only hospitals in the trusts or is more widespread. The NHS’s anxiety about the impact of the attack increased on Friday after Qilin acted overnight on a threat to put stolen NHS data into the public domain, an indication that Synnovis has refused to p...