Hacker News with Generative AI: Data Leaks

DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage (micahflee.com)
This morning, Distributed Denial of Secrets published 410 GB of data hacked from TeleMessage, the Israeli firm that makes modified versions of Signal, WhatsApp, Telegram, and WeChat that centrally archive messages. Because the data is sensitive and full of PII, DDoSecrets is only sharing it with journalists and researchers.
Google Chrome data leakage bug confirmed as actively exploited (scworld.com)
A Google Chrome vulnerability allowing the leak of OAuth codes was added to the Known Exploited Vulnerabilities catalog by the Cybersecurity & Infrastructure Security Agency (CISA) on Thursday.
xAI dev leaks API key for private SpaceX, Tesla LLMs (krebsonsecurity.com)
An employee at Elon Musk’s artificial intelligence company xAI leaked a private key on GitHub that for the past two months could have allowed anyone to query private xAI large language models (LLMs) which appear to have been custom made for working with internal data from Musk’s companies, including SpaceX, Tesla and Twitter/X, KrebsOnSecurity has learned.
An Employee Surveillance Company Leaked over 21M Screenshots Online (gizmodo.com)
With the refinement of digital tools, companies are subjecting their employees to increasing levels of surveillance — and increasing risks. Now, the security of thousands of employees and their parents companies is at risk after real-time images of their computers were leaked by an employee surveillance app.
Anonymous Releases 10TB of Leaked Data (reddit.com)
Anonymous Releases 10TB of Leaked Data: Exposing Kremlin Assets & Russian Businesses (trendsnewsline.com)
Anonymous Release 10TB Leaked Data Exposing Kremlin Assets, Russian Businesses (trendsnewsline.com)
In an unprecedented move that has sent shockwaves through the digital world, the Anonymous collective has just unleashed a staggering 10TB of leaked data. This massive trove includes sensitive information about all businesses operating in Russia, Kremlin assets in the West, pro-Russian officials, and much more. As the world watches closely, the implications of this leak are profound, and it raises a host of questions about security, transparency, and the ongoing conflict between Russia and Ukraine.
Payment processor publishes official NPM package that leaks credit card data (getsafety.com)
Safety’s research team has discovered an npm package published by Cashfree, a large Indian payment processing company, that leaks credit card data to an ngrok endpoint.
Leaked data exposes a Chinese AI censorship machine (techcrunch.com)
A leaked database seen by TechCrunch reveals China has developed an AI system that supercharges its already formidable censorship machine, extending far beyond traditional taboos like the Tiananmen Square massacre.
Meta is firing about 20 employees for leaking (theverge.com)
Meta has fired “roughly 20” employees who leaked “confidential information outside the company,” according to a spokesperson.
Leaked Microsoft pay data shows how much software engineers report making (businessinsider.com)
'RockYou2024': Nearly 10B passwords leaked online (malwarebytes.com)
270GB of source code from The New York Times leaked to 4Chan (twitter.com)
Google Leak Reveals Thousands of Privacy Incidents (404media.co)
Google accidentally published internal Search documentation to GitHub (arstechnica.com)
Space secrets leak disclosure (huggingface.co)
U.S. Inflation Data Was Accidentally Released 30 Minutes Early (bloomberg.com)
El Salvador's Bitcoin Wallet Suffers Leak of Source Code and VPN Access (coinfeeds.io)