Security

Inside the Massive Crime Industry That's Hacking Billion-Dollar Companies (wired.com) 47

Cybercriminals have breached dozens of major companies including AT&T, Ticketmaster and Hot Topic by exploiting "infostealer" malware that harvests login credentials from infected computers, an investigation has found. The malware, spread through pirated software and social media, has infected 250,000 new devices daily, according to cybersecurity firm Recorded Future. Russian developers create the malware while contractors distribute it globally, deliberately avoiding former Soviet states. Hot Topic suffered potentially the largest retail hack ever in October when attackers accessed 350 million customer records using stolen developer credentials. Google and Microsoft are racing to patch vulnerabilities, but malware makers quickly adapt to new security measures.
Social Networks

Threads Soars to 275 Million Monthly Users, Says Zuckerberg (nbcnewyork.com) 36

An anonymous Slashdot reader shared this report from CNBC: Threads now has nearly 275 million monthly users, CEO Mark Zuckerberg said Wednesday. "We continue to be on track towards this becoming our next major social app," Zuckerberg said on a call with analysts, adding that he was "quite pleased" with the trajectory of the app.

The latest numbers indicate Threads is up 175% from a year ago when it reached 100 million users... The app is now signing up more than 1 million users per day, Zuckerberg also said on Wednesday. X remains ahead of Threads in terms of users, but not by much. Musk's social media app now has roughly 318 million monthly users, according to an estimate by market intelligence firm Sensor Tower. That's down 24% since Musk completed his acquisition of the company in October 2022, according to Sensor Tower.

The news also drew a reaction from ActivityPub/Activity Streams 2.0 co-author Evan Prodromou, who pointed out that the 275 million monthly active users is up from the 200 million reported just 13 weeks ago at the end of July.

"And most of them have access to the Fediverse. With more, hopefully, getting access soon."
AI

US Army Should Ditch Tanks For AI Drones, Says Eric Schmidt (theregister.com) 368

Former Google chief Eric Schmidt thinks the US Army should expunge "useless" tanks and replace them with AI-powered drones instead. From a report: Speaking at the Future Investment Initiative in Saudi Arabia this week, he said: "I read somewhere that the US had thousands and thousands of tanks stored somewhere," adding, "Give them away. Buy a drone instead."

The former Google supremo's argument is that recent conflicts, such as the war in Ukraine, have demonstrated how "a $5,000 drone can destroy a $5 million tank." In fact, even cheaper drones, similar to those commercially available for consumers, have been shown in footage on social media dropping grenades through the open turret hatch of tanks. Schmidt, who was CEO of Google from 2001 to 2011, then executive chairman to 2015, and executive chairman of Alphabet to 2018, founded White Stork with the aim of supporting Ukraine's war effort. It hopes to achieve this by developing a low-cost drone that can use AI to acquire its target rather than being guided by an operator and can function in environments where GPS jamming is in operation.

Notably, Schmidt also served as chair of the US government's National Security Commission on Artificial Intelligence (NSCAI), which advised the President and Congress about national security and defense issues with regard to AI. "The cost of autonomy is falling so quickly that the drone war, which is the future of conflict, will get rid of eventually tanks, artillery, mortars," Schmidt predicted.

Businesses

Ghost Jobs Are Wreaking Havoc On Tech Workers (sfgate.com) 90

An anonymous reader quotes a report from SFGATE: If you've recently been laid off and have started the arduous process of looking for a new job, you've probably seen them on networking platforms like LinkedIn: postings for roles that are 30 days old, maybe more, with suspiciously wide salary ranges. They usually have hundreds, or even thousands, of hopeful applicants vying for the same position, but if you do a quick cross-check and notice that the role isn't posted on the company's actual website -- or any of their social media pages -- you should probably stop drafting that cover letter, because it's possible they're not hiring at all. "Ghost jobs," or ads for positions that aren't actually open, are a common phenomenon in the tech industry, which has been plagued by layoffs and budget cuts over recent years. As unemployed workers struggle to regain their footing, recruiters and career coaches who spoke with SFGATE warned that these fake jobs posted by real companies serve multiple, sometimes insidious purposes.

According to a 2024 survey from MyPerfectResume, 81% of recruiters admitted to posting ads for positions that were fake or already filled. While some respondents said employers did it to maintain a presence on job boards and build a talent pool, it's also used to commit psychological warfare: 25% said ghost jobs helped companies gauge how replaceable their employees were, while 23% said it helped make the company appear more stable during a hiring freeze. Another damning 2024 report from Resume Builder said that 62% companies posted them specifically to make their employees feel replaceable. They also made ads to "trick overworked employees" into believing that more people would be brought on to alleviate their overwhelming workload.

After interviewing 1,641 hiring managers, Resume Builder researchers found that 40% of employers posted fake job listings in 2024, and that three in 10 currently had ghost jobs listed. The idea to post them mostly trickled down from HR, followed by senior management and executives, their June 2024 article continued. Though the listings were posted on multiple hiring platforms, the majority of them appeared on LinkedIn and the companies' websites. Evidence suggests this trend is taking hold throughout the Bay Area, too. A collaborative document circulating online reveals a growing list of employers accused of posting ghost jobs. Many of them, it turns out, are tech companies with offices based in California.

Facebook

Meta AI Surpasses 500 Million Users (engadget.com) 24

An anonymous reader quotes a report from Engadget: Last month at Meta Connect, Mark Zuckerberg said that Meta AI was "on track" to become the most-used generative AI assistant in the world. The company has now passed a significant milestone toward that goal, with Meta AI passing the 500 million user mark, Zuckerberg revealed during the company's latest earnings call. The half billion user mark comes just barely a year after the social network first launched its AI assistant last fall. Zuckerberg said the company still expects to become the "most-used" assistant by the end of 2024, though he's never specified how the company is measuring that metric. Zuck said that AI-driven improvements in feed and video recommendations have led to an 8% increase in time spent on Facebook and 5% increase on Instagram this year. Advertisers have also leveraged the company's AI tools to generate over 15 million ads in just the past month.

Separately, Meta's Threads app is gaining over a million new sign-ups daily, with nearly 275 million total monthly users.
Facebook

Mark Zuckerberg Says a Lot More AI Generated Content is Coming To Fill Up Facebook and Instagram Feeds 81

First we had friends. Then we had influencers. And if Mark Zuckerberg is correct, the next big thing in our social media feeds will be AI generated content. Lots of it. Fortune: Zuckerberg described our future feeds during Facebook-parent company Meta's third quarter earnings conference call on Wednesday, describing it as a natural evolution. "I think were going to add a whole new category of content which is AI generated or AI summarized content, or existing content pulled together by AI in some way," the Meta CEO said. "And I think that that's gonna be very exciting for Facebook and Instagram and maybe Threads, or other kinds of feed experiences over time."

Zuckerberg touted the company's Llama large language model and the success of products it powers, such as the Meta AI chatbot that is now used by more than 500 million users every month. But Llama will increasingly play a role across Meta's business, Zuckerberg said, including tools for business customers and advertisers. As AI tools become more widespread, AI content will proliferate within social media feeds. Such feeds are actively being worked on inside Meta, Zuckerberg noted. "It's something we're starting to test different things around." "I don't know if we know what's exactly going to work really well yet, but some things are really promising," he added. "I have high confidence that over the next several years, this will be one of the important trends and one of the important applications."
Businesses

WordPress Forces User Conf Organizers To Share Social Media Credentials, Arousing Suspicions (theregister.com) 56

Simon Sharwood, reporting for The Register: Organisers of WordCamps, community-organized events for WordPress users, have been ordered to take down some social media posts and share their login credentials for social networks. The order to share creds came from an employee of Automattic, the WordPress host whose CEO happens to be Matt Mullenweg, co-creator of WordPress.

A letter sent to WordCamp organizers explains that the creds are needed due to "recurrent issues with new organizing teams losing access to the event's social media accounts." So far, so sensible. But the requirement to share creds comes in the middle of a nasty spat in the WordPress community, sparked by Mullenweg's efforts to have rival hosting biz WP Engine license the WordPress trademark or devote more staff to working on the open source content management system's code.

Businesses

Reddit Is Profitable For the First Time Ever (theverge.com) 103

In Reddit's third-quarter earnings results, the company reported a profit of $29.9 million, with $348.4 million in revenue -- a 68% increase year over year. The Verge reports: The company hasn't been profitable at any point in its nearly 20-year history. Since going public, Reddit lost $575 million during its first quarter on the market, but it decreased that loss to $10 million last quarter, and is now finally in the green. Reddit also grew to 97.2 million daily users over the past few months, marking a 47 percent increase from the same time last year. That number exceeded 100 million users on some days during the quarter, Reddit says.

Reddit's advertising revenue grew to $315.1 million, while "other" revenue reached $33.2 million on account of "data licensing agreements signed earlier this year." Both Google and OpenAI have cut deals with Reddit to train their AI models on its posts.

Networking

BBC Interviews Charley Kline and Bill Duvall, Creators of Arpanet (bbc.com) 26

The BBC interviewed scientists Charley Kline and Bill Duvall 55 years after the first communications were made over a system called Arpanet, short for the Advanced Research Projects Agency Network. "Kline and Duvall were early inventors of networking, networks that would ultimately lead to what is today the Internet," writes longtime Slashdot reader dbialac. "Duvall had basic ideas what might come of the networks, but they had no idea of how much of a phenomenon it would turn into." Here's an excerpt from the interview: BBC: What did you expect Arpanet to become?
Duvall: "I saw the work we were doing at SRI as a critical part of a larger vision, that of information workers connected to each other and sharing problems, observations, documents and solutions. What we did not see was the commercial adoption nor did we anticipate the phenomenon of social media and the associated disinformation plague. Although, it should be noted, that in [SRI computer scientist] Douglas Engelbart's 1962 treatise describing the overall vision, he notes that the capabilities we were creating would trigger profound change in our society, and it would be necessary to simultaneously use and adapt the tools we were creating to address the problems which would arise from their use in society."

What aspects of the internet today remind you of Arpanet?
Duvall: Referring to the larger vision which was being created in Engelbart's group (the mouse, full screen editing, links, etc.), the internet today is a logical evolution of those ideas enhanced, of course, by the contributions of many bright and innovative people and organisations.

Kline: The ability to use resources from others. That's what we do when we use a website. We are using the facilities of the website and its programs, features, etc. And, of course, email. The Arpanet pretty much created the concept of routing and multiple paths from one site to another. That got reliability in case a communication line failed. It also allowed increases in communication speeds by using multiple paths simultaneously. Those concepts have carried over to the internet. Today, the site of the first internet transmission at UCLA's Boetler Hally Room 3420 functions as a monument to technology history (Credit: Courtesy of UCLA) As we developed the communications protocols for the Arpanet, we discovered problems, redesigned and improved the protocols and learned many lessons that carried over to the Internet. TCP/IP [the basic standard for internet connection] was developed both to interconnect networks, in particular the Arpanet with other networks, and also to improve performance, reliability and more.

How do you feel about this anniversary?
Kline: That's a mix. Personally, I feel it is important, but a little overblown. The Arpanet and what sprang from it are very important. This particular anniversary to me is just one of many events. I find somewhat more important than this particular anniversary were the decisions by Arpa to build the Network and continue to support its development.

Duvall: It's nice to remember the origin of something like the internet, but the most important thing is the enormous amount of work that has been done since that time to turn it into what is a major part of societies worldwide.

AI

LinkedIn Launches Its First AI Agent To Take On the Role of Job Recruiters 49

An anonymous reader quotes a report from TechCrunch: LinkedIn, the social platform used by professionals to connect with others in their field, hunt for jobs, and develop skills, is taking the wraps off its latest effort to build artificial intelligence tools for users. Hiring Assistant is a new product designed to take on a wide array of recruitment tasks, from ingesting scrappy notes and thoughts to turn into longer job descriptions, through to sourcing candidates and engaging with them. LinkedIn is describing Hiring Assistant as a milestone in its AI trajectory: it is, per the Microsoft-owned company, its first "AI agent" And one that happens to be targeting one of LinkedIn's most lucrative categories of users (recruiters).

LinkedIn said the AI assistant is now live with a "select group" of customers (large enterprises such as AMD, Canva, Siemens and Zurich Insurance among them). It's slated to be rolling out more widely in the coming months. [...] "It's designed to take on a recruiter's most repetitive task so they can spend more time on the most impactful part of their jobs," Hari Srinivasan, LinkedIn's VP of product, said in an interview -- "a big statement," he admitted. The product includes the ability to upload full job descriptions, or just note what you want it to have, along with job postings that you like the look of from other companies or roles. In turn, that becomes a list of qualifications you're looking for, as well as an initial pipeline of candidates that you can interact with -- to look for more potential hires that are similar to some, or less like others -- with algorithms designed to search based on skills rather than other indicators (such as where a person lives or went to school), per Srinivasan.

The AI assistant also integrates with third-party application tracking systems, although ultimately, the whole system is trained on LinkedIn data, which spans 1 billion users, 68 million companies and 41,000 skills. LinkedIn said Hiring Assistant is due to get more features soon, such as messaging and scheduling support for interviews, as well as handle follow-ups when candidates have questions before or after interviews. Basically the aim is for it to cover a lot of (time-consuming) admin-style tasks, plus take on some of the thinking, that recruiters have to do daily. Second, unlike many of the other AI features that LinkedIn has released, Hiring Assistant is very squarely aimed at LinkedIn's B2B business, the products it sells to the recruitment industry.
"We're really focused on making Hiring Assistant great," said Erran Berger, VP of engineering, in an interview. "This is all bleeding edge, and I mean everything from the experience and how our users are going to interact with it, to the technology that backs it. And so we're really focused on nailing that a lot of the technology we've built is applicable to problems that we're trying to solve for our members and customers. But right now, you know, we really just want to nail this, and then we can figure out where we go from there."
Privacy

Fitness App Strava Gives Away Location of Foreign Leaders, Report Finds 27

French newspaper Le Monde found that the fitness app Strava can easily track confidential movements of foreign leaders, including U.S. President Joe Biden, and presidential rivals Donald Trump and Kamala Harris. The Independent reports: Le Monde found that some U.S. Secret Service agents use the Strava fitness app, including in recent weeks after two assassination attempts on Trump, in a video investigation released in French and in English. Strava is a fitness tracking app primarily used by runners and cyclists to record their activities and share their workouts with a community. Le Monde also found Strava users among the security staff for French President Emmanuel Macron and Russian President Vladimir Putin. In one example, Le Monde traced the Strava movements of Macron's bodyguards to determine that the French leader spent a weekend in the Normandy seaside resort of Honfleur in 2021. The trip was meant to be private and wasn't listed on the president's official agenda.

Le Monde said the whereabouts of Melania Trump and Jill Biden could also be pinpointed by tracking their bodyguards' Strava profiles. In a statement to Le Monde, the U.S. Secret Service said its staff aren't allowed to use personal electronic devices while on duty during protective assignments but "we do not prohibit an employee's personal use of social media off-duty." "Affected personnel has been notified," it said. "We will review this information to determine if any additional training or guidance is required." "We do not assess that there were any impacts to protective operations or threats to any protectees," it added. Locations "are regularly disclosed as part of public schedule releases."

In another example, Le Monde reported that a U.S. Secret Service agent's Strava profile revealed the location of a hotel where Biden subsequently stayed in San Francisco for high-stakes talks with Chinese President Xi Jinping in 2023. A few hours before Biden's arrival, the agent went jogging from the hotel, using Strava which traced his route, the newspaper found. The newspaper's journalists say they identified 26 U.S. agents, 12 members of the French GSPR, the Security Group of the Presidency of the Republic, and six members of the Russian FSO, or Federal Protection Service, all of them in charge of presidential security, who had public accounts on Strava and were therefore communicating their movements online, including during professional trips. Le Monde did not identify the bodyguards by name for security reasons.
The Almighty Buck

JPMorgan Begins Suing Customers In 'Infinite Money Glitch' (cnbc.com) 222

JPMorgan Chase is suing customers who exploited an ATM glitch that allowed them to withdraw funds before a check bounced. CNBC reports: The bank on Monday filed lawsuits in at least three federal courts, taking aim at some of the people who withdrew the highest amounts in the so-called infinite money glitch that went viral on TikTok and other social media platforms in late August. [...] JPMorgan, the biggest U.S. bank by assets, is investigating thousands of possible cases related to the "infinite money glitch," though it hasn't disclosed the scope of associated losses. Despite the waning use of paper checks as digital forms of payment gain popularity, they're still a major avenue for fraud, resulting in $26.6 billion in losses globally last year, according to Nasdaq's Global Financial Crime Report.

The infinite money glitch episode highlights the risk that social media can amplify vulnerabilities discovered at a financial institution. Videos began circulating in late August showing people celebrating the withdrawal of wads of cash from Chase ATMs shortly after bad checks were deposited. Normally, banks only make available a fraction of the value of a check until it clears, which takes several days. JPMorgan says it closed the loophole a few days after it was discovered.

The lawsuits are likely to be just the start of a wave of litigation meant to force customers to repay their debts and signal broadly that the bank won't tolerate fraud, according to the people familiar. JPMorgan prioritized cases with large dollar amounts and indications of possible ties to criminal groups, they said. The civil cases are separate from potential criminal investigations; JPMorgan says it has also referred cases to law enforcement officials across the country.
"Fraud is a crime that impacts everyone and undermines trust in the banking system," JPMorgan spokesman Drew Pusateri said in a statement to CNBC. "We're pursuing these cases and actively cooperating with law enforcement to make sure if someone is committing fraud against Chase and its customers, they're held accountable."
Social Networks

The Fediverse Is Getting Its Own TikTok Competitor Called Loops (techcrunch.com) 13

An anonymous reader quotes a report from TechCrunch: Similar to how Mastodon offers an open source, distributed version of X, the fediverse is getting its own TikTok competitor. This week, an app called Loops began accepting signups on its new platform for sharing short, looping videos. Still in the early stages, Loops is not yet open sourced, nor has it completed its integration with ActivityPub, the protocol that powers Mastodon, Pixelfed, PeerTube, and other federated apps. However, both those efforts are in the works and when complete, will allow Loops to add another layer of social activity to the growing open social web known as the fediverse, which now has north of 11.6 million users and over 1 million monthly active users. (Mastodon accounts for roughly 65% of that activity.) Growth in this space has also encouraged other apps to adopt ActivityPub, like social magazine app Flipboard and Meta's Threads. The latter is not yet fully integrated but already has more than 200 million monthly active users.

Loops, meanwhile, was developed by Daniel Supernault, who also created the federated Instagram rival Pixelfed. In fact, Loops will run under the Pixelfed project, according to an FAQ on its website. [...] Aimed at users 13 and up, Loops will allow you to follow other users, as well as like, comment on, or share their videos. But as a part of the federated web -- the open social web running on ActivityPub -- remote users from other platforms like Mastodon and Pixelfed will also be able to follow users' Loops accounts and then view the videos in their home feed on those respective platforms. These remote followers will also be able to like, comment on, or share videos if their platform supports it. Videos published to the app will be held for moderation if the uploader has a low trust score, but trusted users will be able to skip the queue and publish immediately. The trust score is also used to hide problematic comments on posts and apply content warnings, Supernault notes. Other features, like profile sharing or the ability for Loops users to follow Mastodon and Pixelfed users in return, are still "to be announced," the site notes.

Social Networks

Instagram (and Meta) Throttle Video Quality as Views Go Down (theverge.com) 49

An anonymous reader shared this report from the Verge: Ever wondered why some of your Instagram videos tend to look blurry, while others are crisp and sharp? It's because, on Instagram, the quality of your video apparently depends on how many views it's getting.

Here's part of Mosseri's explanation, from the video, which was reposted by a Threads user today. "In general, we want to show the highest-quality video we can ... But if something isn't watched for a long time — because the vast majority of views are in the beginning — we will move to a lower quality video. And then if it's watched again a lot then we'll re-render the higher quality video...."

The shift in quality "isn't huge," Mosseri said in response to another Threads user, who'd asked if that approach disadvantaged smaller creators. That's "the right concern," he told them, but said people interact with videos based on its content, not its quality. That's consistent with how Meta has described its approach before... Meta wrote in a blog [post] that in order to conserve computing resources for the relatively few, most watched videos, it gives fresh uploads the fastest, most basic encoding. After a video "gets sufficiently high watch time," it receives a more robust encoding pass.

"It works at an aggregate level, not an individual viewer level," Mosseri wrote later on Threads. "We bias to higher quality (more CPU intensive encoding and more expensive storage for bigger files) for creators who drive more views. It's not a binary theshhold, but rather a sliding scale."
The Internet

One Argument Why Data Caps Are Not a Problem (fierce-network.com) 181

NoWayNoShapeNoForm writes: OpenVault believes that data caps on broadband are not a problem because most people do not exceed their existing data caps. OpenVault contends that people that do exceed their broadband data caps are simply being forgetful — leaving a streaming device on 24x7, or deploying unsecure WiFi access points, or reselling their service within an apartment building.

Yes, there may be some ISPs that have older networks that they have not upgraded. Or maybe they are unable to increase network capacity in "the middle mile" of their networks, but the Covid pandemic certainly encouraged many ISPs to upgrade their networks and capacity while many ISPs that had broadband data caps ended that feature.

Perhaps the biggest problem, according to OpenVault, is that most broadband users do not really have any idea how much bandwidth they "consume" every month. If Internet access is a service that people want to treat as a "utility", then you have to ask, Would they keep the water running after finishing their shower?

In the article Ookla's VP of Smart Communities adds that "Scrolling through social media feeds for hours can 'push' hundreds of videos to the user, many of which may be of no interest — they just start running." So the main driver for usage-based billing wasn't to increase revenue, OpenVault CEO Mark Trudeau tells the site, but to "balance the network a little more..." (Though he then also adds that sometimes a subscriber could also be reselling broadband service in their apartment building, "And that's not even legal.")

"If one or two customers on a given node is causing issues for 300 others, where those 300 are not getting the service that they paid for, then that's a problem right?" he said.

Having said that, the article also points out that "Many major fiber providers, like AT&T, Frontier, Google Fiber and Verizon Fios, don't have data caps at all."
Emulation (Games)

Video Game Libraries Lose Legal Appeal To Emulate Physical Game Collections Online (arstechnica.com) 15

An anonymous reader quotes a report from Ars Technica: Earlier this year, we reported on the video game archivists asking for a legal DMCA exemption to share Internet-accessible emulated versions of their physical game collections with researchers. Today, the US Copyright Office announced once again that it was denying that request, forcing researchers to travel to far-flung collections for access to the often-rare physical copies of the games they're seeking.

In announcing its decision, the Register of Copyrights for the Library of Congress sided with the Entertainment Software Association and others who argued that the proposed remote access could serve as a legal loophole for a free-to-access "online arcade" that could harm the market for classic gaming re-releases. This argument resonated with the Copyright Office despite a VGHF study that found 87 percent of those older game titles are currently out of print. "While proponents are correct that some older games will not have a reissue market, they concede there is a 'healthy' market for other reissued games and that the industry has been making 'greater concerted efforts' to reissue games," the Register writes in her decision. "Further, while the Register appreciates that proponents have suggested broad safeguards that could deter recreational uses of video games in some cases, she believes that such requirements are not specific enough to conclude that they would prevent market harms."

A DMCA exemption for remote sharing already exists for non-video-game computer software that is merely "functional," as the Register notes. But the same fair use arguments that allow for that sharing don't apply to video games because they are "often highly expressive in nature," the Register writes. In an odd footnote, the Register also notes that emulation of classic game consoles, while not infringing in its own right, has been "historically associated with piracy," thus "rais[ing] a potential concern" for any emulated remote access to library game catalogs. That footnote paradoxically cites Video Game History Foundation (VGHF) founder and director Frank Cifaldi's 2016 Game Developers Conference talk on the demonization of emulation and its importance to video game preservation. "The moment I became the Joker is when someone in charge of copyright law watched my GDC talk about how it's wrong to associate emulation with piracy and their takeaway was 'emulation is associated with piracy,'" Cifaldi quipped in a social media post.

AI

Polish Radio Station Replaces Journalists With AI 'Presenters' 29

OFF Radio Krakow sparked controversy by replacing its journalists with AI-generated presenters in an experiment to attract younger audiences. CNN Business reports: Weeks after letting its journalists go, OFF Radio Krakow relaunched this week, with what it said was âoethe first experiment in Poland in which journalists ... are virtual characters created by AI." The station in the southern city of Krakow said its three avatars are designed to reach younger listeners by speaking about cultural, art and social issues including the concerns of LGBTQ+ people. "Is artificial intelligence more of an opportunity or a threat to media, radio and journalism? We will seek answers to this question," the station head, Marcin Pulit, wrote in a statement.
Privacy

UnitedHealth Says Change Healthcare Hack Affects Over 100 Million (techcrunch.com) 35

UnitedHealth Group said a ransomware attack in February resulted in more than 100 million individuals having their private health information stolen. The U.S. Department of Health and Human Services first reported the figure on Thursday. TechCrunch reports: The ransomware attack and data breach at Change Healthcare stands as the largest known digital theft of U.S. medical records, and one of the biggest data breaches in living history. The ramifications for the millions of Americans whose private medical information was irretrievably stolen are likely to be life lasting. UHG began notifying affected individuals in late July, which continued through October. The stolen data varies by individual, but Change previously confirmed that it includes personal information, such as names and addresses, dates of birth, phone numbers and email addresses, and government identity documents, including Social Security numbers, driver's license numbers, and passport numbers. The stolen health data includes diagnoses, medications, test results, imaging and care and treatment plans, and health insurance information -- as well as financial and banking information found in claims and payment data taken by the criminals.

The cyberattack became public on February 21 when Change Healthcare pulled much of its network offline to contain the intruders, causing immediate outages across the U.S. healthcare sector that relied on Change for handling patient insurance and billing. UHG attributed the cyberattack to ALPHV/BlackCat, a Russian-speaking ransomware and extortion gang, which later took credit for the cyberattack. The ransomware gang's leaders later vanished after absconding with a $22 million ransom paid by the health insurance giant, stiffing the group's contractors who carried out the hacking of Change Healthcare out of their new financial windfall. The contractors took the data they stole from Change Healthcare and formed a new group, which extorted a second ransom from UHG, while publishing a portion of the stolen files online in the process to prove their threat.

There is no evidence that the cybercriminals subsequently deleted the data. Other extortion gangs, including LockBit, have been shown to hoard stolen data, even after the victim pays and the criminals claim to have deleted the data. In paying the ransom, Change obtained a copy of the stolen dataset, allowing the company to identify and notify the affected individuals whose information was found in the data. Efforts by the U.S. government to catch the hackers behind ALPHV/BlackCat, one of the most prolific ransomware gangs today, have so far failed. The gang bounced back following a takedown operation in 2023 to seize the gang's dark web leak site. Months after the Change Healthcare breach, the U.S. State Department upped its reward for information on the whereabouts of the ALPHV/BlackCat cybercriminals to $10 million.

AI

Goodreads' Founder Debuts AI-Powered App For Online Readers (techcrunch.com) 5

An anonymous reader quotes a report from TechCrunch: Smashing, a new app curating the best of the web from Goodreads co-founder Otis Chandler, is now available to the public. Like Goodreads, the app aims to create a community around content. But this time, instead of books, the focus is on web content -- like news articles, blog posts, social media posts, podcasts, and more. In addition, Smashing is introducing an AI Questions feature that allows you to engage with the content being shared in different ways, including by viewing a news story from different perspectives or asking the AI to poke holes in the story, among other things. By viewing different angles of a story, you can see how both the political left and right view the subject. Or, in the case of a company's stock, you might be presented with both the bull and bear case.

There are a good handful of AI prompts available at launch, notes Chandler, and not all will make sense to use on every news story or piece of content. For instance, there's a silly "make it funny" prompt, and others that can simplify the story, display a timeline, or introduce "unconventional" takes that may involve thinking outside the box, helping you weigh ideas you hadn't considered yet. You can also ask your own questions, if you prefer. On the app, users are able to create multiple interest feeds to stay informed about the topics that matter to them, like politics, investing, parenting, health and wellness, and more, or even narrower interests like specific companies, sports teams, crypto, climate change, or other subtopics. The app also leverages AI to surface content from around the web and then match it to an individual reader based on what articles they tend to read, what subtopics they like, and what's already popular in the community, as determined by upvotes and downvotes. Combined, the signals tune Smashing to a user's particular interests. As part of the AI Questions feature, Smashing is also introducing AI-powered Story Overview pages, which offer grouped articles, blog posts, and social media posts all about the same story.

Social Networks

LinkedIn Fined More Than $300 Million in Ireland Over Personal Data Processing (msn.com) 13

Ireland's data-protection watchdog fined LinkedIn 310 million euros ($334.3 million), saying the Microsoft-owned career platform's personal-data processing breached strict European Union data-privacy and security legislation. From a report: The Irish Data Protection Commission in 2018 launched a probe into LinkedIn's processing of users' personal data for behavioral analysis and targeted advertising after its French equivalent flagged a complaint it received from a non-profit organization. Irish officials raised concerns on the lawfulness, fairness and transparency of the practice, saying Thursday that LinkedIn was in breach of the EU's General Data Protection Regulation.

"The lawfulness of processing is a fundamental aspect of data protection law and the processing of personal data without an appropriate legal basis is a clear and serious violation of a data subjects' fundamental right to data protection," said Graham Doyle, deputy commissioner at the Irish Data Protection Commission. In their decision, Irish officials said LinkedIn wasn't sufficiently informing users when seeking their consent to process third-party data for behavioral analysis and targeted advertising and ordered the platform to bring its processing into compliance.

Slashdot Top Deals