Slashdot

News for nerds, stuff that matters

Hackers Steal 8 Million Citizens' Records From Danish Government Database

Hackers stole records belonging to roughly 8 million Danish citizens and residents from Denmark's Central Person Register (CPR), including names, addresses, social security numbers and other personal information. The breach is believed to be the largest in Denmark's history. TechCrunch reports: The CPR is a government database of Danish citizens' information, including their government-issued identity number for paying taxes and accessing other services. Denmark's current population is about 6 million people, but the database includes records for about 11 million people, with some of the data going back decades.

The Danish government would not say who is behind the breach, which happened in September but was discovered on October 2. However, it said the unauthorized access was obtained by "abusing a Danish company's lawful access to search for information in the CPR system." (Some companies in Denmark have access to the CPR for verifying people's information with the government.)

Read more of this story at Slashdot.

Wikipedia Operator Says OpenAI's 'Rogue' Bots May Be Linked to a May Outage

The Wikimedia Foundation says it found evidence that "rogue" OpenAI agents edited Wikimedia wikis without approval, unsuccessfully tried to exploit its Etherpad service, and generated millions of automated requests across Wikimedia projects. Here's a summary of what Wikimedia observed (via The Verge): Wiki editing: We've identified edits to Wikimedia wikis that we believe are from AI agents operated by OpenAI. These edits were not published to pages with visibility to general readers; almost all of them were testing edits in "sandbox" areas of the wiki. It also included a few edits to the configuration for a citation tool, which we believe were potentially malicious edits that were intended to misuse this tool as a proxy for fetching data from remote services. While Wikipedia policies allow bots to edit when they are disclosed and approved by the community, none of those approvals were sought in these incidents.
Etherpad probing and use: Agents we believe to be operated by OpenAI made some unsuccessful attempts to compromise our public Etherpad, a note-taking tool we host as a community service. Agents unsuccessfully tried to use it to fetch data from other websites as a proxy. Other agents also likely operated by OpenAI took notes about their tasks, though this did not appear to turn into coordination.

Excessive data downloading: Agents we believe to be operated by OpenAI made millions of automated requests to our public APIs to access the knowledge on Wikimedia projects, crawled millions of pages (mainly from our projects Wikidata and Wikimedia Commons), and made hundreds of thousands of data queries to the Wikidata Query Service (WQDS). This traffic may have contributed to a partial outage on WQDS in May.

Read more of this story at Slashdot.

Meta Rushed To Fix Muse 'VM Escape' Vulnerability Soon Before Launch

An anonymous reader quotes a report from 404 Media: In the immediate weeks before Muse's launch, Meta engineers found several security vulnerabilities in the company's viral AI agent product, at least one of which could have allowed malicious users to break outside of Muse's intended environment and access Meta's own sensitive databases and services, 404 Media has learned. The issues were so severe that they reached Mark Zuckerberg and staff worked overtime to fix them. These specific vulnerabilities were discovered before the launch of the product but required a multi-team "mad dash" to fix "a sudden spike in reported KVM escapes," according to an internal post by Meta executives to its core infrastructure team seen by 404 Media. In order for Muse to work, a user gives the AI agent access to various important services and accounts that they own. On Meta's end, each individual Muse instance runs on a kernel-based virtual machine, which connects to, but is supposed to be isolated from, Meta's own critical infrastructure. A "KVM escape," then, is when, through a security vulnerability, a Muse instance is able to escape from that virtual machine and interact with the system that runs it, or with other users' virtual machines.

According to a Meta source, as well as internal security documentation and internal posts viewed by 404 Media, at least one of the vulnerabilities could have allowed an outside attacker -- that is, a normal Muse user -- to access data in sensitive internal Meta databases. At least one of the vulnerabilities was related to an exploit found in Linux kernel-based virtual machine code in July. 4 Several of the vulnerabilities were in the underlying Linux virtualization software that Meta uses for Muse. The security issue was considered serious enough that it was raised to Mark Zuckerberg, and several different security teams worked nights and weekends in the leadup to launch to fix the issues. [...] The Meta source said they felt security teams were asked to push hot fixes to these bugs as quickly as possible and in a way that wouldn't delay Muse's launch, leading to what they described as "half-baked protections being rushed out to enable the launch. Many senior engineers believe it's inevitable we're going to have a massive data breach as a result of Hatch." Muse is called "Hatch" internally and in Meta's codebase.

Read more of this story at Slashdot.

Norway Plans Temporary Ban on Smart Glasses

Norway is preparing legislation that would temporarily ban camera-equipped smart glasses in a range of public places, including parks, beaches, museums, shopping centers, schools, daycare centers, healthcare facilities, gyms and public events. Private use would still be allowed. The Guardian reports: Torgeir Micaelsen, Norway's minister of digital affairs, said he was worried that new, powerful technology is being introduced where people risk being photographed, filmed or audio-recorded without knowing it."

"We do not want a society where people worry about being recorded without their knowledge, photographed or filmed in places and situations where they are accustomed to not being monitored," he said.
Norway's Labour party, which heads a minority government, needs the support of other parties to pass the proposed ban. It said it planned to submit a bill "as soon as possible," while tasking an expert group with drawing up permanent regulations on the issue.

Read more of this story at Slashdot.

thexiffy

Last.fm last recent tracks from thexiffy.

Tool - Merkaba

Tool

The Doors - Cars Hiss by My Window

The Doors

Formula 1 News

Formula 1® - The Official F1® Website

Singapore Grand Prix betting guide and latest odds

Our experts bring you all the important betting information you need before making your predictions for Marina Bay.

Alkmaarse gemeenteraad kritisch op draai burgemeester rond weren Hapoel-fans na aandringen Amsterdam

Pas nadat haar Amsterdamse collega Femke Halsema had gewezen op veiligheidsrisico’s, besloot burgemeester Anja Schouten van Alkmaar dat supporters van de Israëlische club Hapoel Be’er Sheva niet welkom zijn bij de wedstrijd tegen AZ van volgende week donderdag.

VK: Voorpagina

Volkskrant.nl biedt het laatste nieuws, opinie en achtergronden

Staat New York roept noodtoestand uit vanwege snelle stijging mazelengevallen

The Guardian

Latest news, sport, business, comment, analysis and reviews from the Guardian, the world's leading liberal voice

Nations League roundup: Olise leads late charge as France bowl over Belgium

  • France score four goals in 14 minutes to triumph

  • Italy see off Turkey, Hungary edge out Ukraine

Michael Olise came off the bench to inspire France to a 4-1 win over Belgium in the Nations League, handing Zinedine Zidane his first home victory since taking charge.

Dodi Lukébakio put Belgium on course for their first competitive win over Les Bleus in 45 years when he fired the visitors in front in the first half at the Stade de France. But the hosts turned the match on its head in a blistering finish, scoring four times in 14 minutes to preserve Zidane’s unbeaten start and move closer to the quarter-finals.

Continue reading...