Skip Navigation
stackdiary.com Webflow says 2TB of bandwidth is worth $1,250 per month

Webflow, a popular website-building platform, has been criticized by its user base following a significant increase in its pricing plans. The company

Webflow got caught with its hand in the cookie jar and wants to settle disputes quietly.

24
stackdiary.com Disney hack leads to 1.2TB of Slack communications leaked online

In a significant data breach, hacktivist group NullBulge has infiltrated Disney's internal Slack infrastructure, leaking 1.2TB of sensitive data. This

In a significant data breach, hacktivist group NullBulge has infiltrated Disney's internal Slack infrastructure, leaking 1.2TB of sensitive data. This breach, posted on the cybercrime platform Breach Forums on July 12, 2024, exposes many of Disney's internal communications, compromising messages, files, code, and other proprietary information.

58
https:// stackdiary.com /msi-warranty-claim-database-was-publicly-accessible-via-google/

According to the YouTube channel Gamers Nexus, over 600,000 customer warranty claims for MSI products were publicly accessible via Google search. MSI, a leading computer hardware and peripherals manufacturer, had exposed data that included sensitive information such as names, addresses, phone numbers, and specific order details.

20
stackdiary.com IdentifyMobile incident exposed 200M records from hundreds of companies

Imagine someone gaining access to your online banking account, your private email, or your social media profiles. Despite your efforts to secure these

British bulk SMS provider IdentifyMobile exposed 200M records because a developer misconfigured an AWS S3 bucket and made it public. A research group from Germany spotted the issue and were able to access more than six terabytes of data. The said data included not only SMS message content but also phone numbers, sender names, and sometimes other account information.

Twilio also recently disclosed a security incident in relation to this news, but their alert email completely downplayed the level of data that was available from this AWS bucket.

2
stackdiary.com Linksys Velop routers send Wi-Fi passwords in plaintext to US servers

According to Testaankoop, the Belgian equivalent of the Consumers' Association, two types of Linksys routers are sending Wi-Fi login details in plaintext

During installation, the router sent several data packets to an Amazon server in the US. These packets contained the configured SSID name and password in clear text, as well as some identification tokens for this network within a broader database and an access token for a user session that could potentially enable a MITM attack.

Linksys has refused to acknowledge/respond to the issue.

43
stackdiary.com Ticket-App der UEFA teilt Standortdaten der Nutzer mit Polizeibehörden

Die für den Stadioneinlass notwendige Ticket-App der UEFA trackt die Nutzer und teilt den Standort mit Polizeibehörden. Die App-Stores erwähnen dies aber nicht.

To attend the championship this year, fans must use a digital ticket provided through UEFA’s Ticket application. According to Heise, this app requires access to personal data, including name, email, phone number, and GPS permissions. While app store descriptions note the collection of personal information and activity data for analysis purposes, they omit any mention of location sharing.

9
stackdiary.com OpenAI seeks NYT source material for copyright defense

In a high-stakes legal battle over using copyrighted materials to train artificial intelligence models, OpenAI is pushing the New York Times to disclose

OpenAI, which is co-defendant with Microsoft, is seeking an informal discovery conference to compel the Times to produce documents demonstrating the originality and ownership of the copyrighted works in question. According to OpenAI’s court filing, the information is critical to their defense against claims of copyright infringement.

2
stackdiary.com EU Council has withdrawn the vote on Chat Control - Stack Diary

The EU Council and its participants have decided to withdraw the vote on the contentious Chat Control plan proposed by Belgium, the current EU President. Moritz Körner, member of the European Parliament, disclosed the decision on Twitter. Swedish publisher SVG said,

Moritz Körner, Member of the European Parliament, disclosed the decision on Twitter. Swedish publisher SVG said, “The question was removed at the last moment from Thursday’s ambassadorial meeting in Brussels”.

105
stackdiary.com Patrick Breyer and Pirate Party lose EU Parliament seats - Stack Diary

In the wake of the recent European Parliament elections, the Pirate Party has lost its representation in the legislative body. This outcome was confirmed by Patrick Breyer, a Member of the European Parliament (MEP) and a prominent figure within the Pirate Party. Breyer, known for his staunch opposit...

Patrick Breyer, a staunch defender of digital rights, laments the Pirate Party’s exit from the EU Parliament as a blow to online privacy.

162
stackdiary.com The New York Times source code leaked by a 4chan user - Stack Diary

A user on the online forum 4chan has leaked a massive 270GB of data purportedly belonging to The New York Times. This leak includes what is claimed to be the source code for the newspaper’s digital operations. The user who posted the data claimed that The New York Times has over 5,000 source code...

A user on the online forum 4chan has leaked a massive 270GB of data purportedly belonging to The New York Times. This leak includes what is claimed to be the source code for the newspaper’s digital operations.

83
stackdiary.com France considers approval of European chat control plan - Stack Diary

France is considering approving a new proposal to monitor all chat messages from European citizens. If this proposal is adopted, the chat app Signal has announced it will exit the EU. With France's backing, a European majority in favor of the plan seems likely. Netzpolitik (German) has reported this...

The latest proposal mandates user consent for monitoring messages on all communication apps, including those with end-to-end encryption.

38
stackdiary.com Ticketmaster confirms data breach with a SEC filing - Stack Diary

Live Nation Entertainment, also known as Ticketmaster, has submitted an official Form 8-K with the U.S. Securities and Exchange Commission (SEC), acknowledging and confirming that the recently rumored data breach is real. In the filing (which can be seen here), Ticketmaster says that on May 20, 2...

Access was gained through a third-party cloud database provider, which we know to be Snowflake.

7
stackdiary.com Meta will train AI with data from European users - Stack Diary

Meta has announced that it will begin training its own AI using data from European users. The company claims that it has a legitimate interest in this practice. Users can object to the use of their data; however, there have been complaints regarding the procedure for submitting these objections. ...

The only exception is private messages, and some users have reported difficulty opting out.

40
stackdiary.com Spy.pet is harvesting your Discord history with no ability to opt-out - Stack Diary

The service offers the ability to purchase credits through cryptocurrencies, as well as offers the data for AI training purposes.

The service offers the ability to purchase credits through cryptocurrencies, as well as offers the data for AI training purposes.

35
stackdiary.com A developer recreates the fake Gemini multimodal demo with GPT-4 - Stack Diary

In case you're not up to speed, Google recently launched its latest AI model, Gemini, which I vehemently called out as a PR stunt on launch day. And so far, it hasn't proved to be anything but. It took Bloomberg almost 24 hours to figure out that the Gemini multimodal demo was fake (which I immediat...

Greg Sadetsky introduces his demo, Sagittarius, as a response to Google's Gemini. Utilizing GPT-4, Sadetsky's demo showcases real-time capabilities similar to those claimed by Gemini but were lacking in Google's demonstration.

0
stackdiary.com Grok refuses to answer a prompt, says its a violation of the

Grok, the conversational AI chatbot developed by Elon Musk's xAI, has been reported to refuse user prompts for violating

Twitter enforces strict restrictions against external parties using its data for AI training, yet it freely utilizes data created by others for similar purposes.

31
stackdiary.com Meta's behavioral Ads banned in EU/EEA by EDPB - Stack Diary

This is a breaking story, more details to follow! The European Data Protection Board (EDPB) has taken a significant step in data protection enforcement by issuing an urgent binding decision against Meta Ireland Limited (Meta IE). This decision, stemming from an initial request by the Norwegian Da...

The EDPB issued an urgent binding decision that essentially bans Meta from using personal data for behavioral advertising in the entire European Economic Area (EEA).

20
stackdiary.com 23andMe is updating its TOS to force binding arbitration with a limited opt-out window - Stack Diary

23andMe, the personal genomics and biotechnology company, has been trying to contain a security breach that was first disclosed on October 6th. On October 19th, 23andMe disclosed another security breach by the same hacker who had initially claimed responsibility. The hacker said he had access to mor...

This change will force its users into binding arbitration, which is a means to resolve disputes (such as a cybersecurity breach leaking your DNA data) outside of court.

13

Microsoft is working on a Jarvis that will monitor anything and everything about your digital life to try and optimize your life for "well being".

9
Jump
The data of 760,000 Discord.io users was put up for sale on the darknet
  • I'm actually curious where did they got the passwords from? Discord.io looks to be using Discord itself for authenticating users, but I myself have never used the service so I have no idea.

    34