Vol. I · No. 283Everything you need. Nothing you don't.Evening Edition

Oztir


The Octopus · Evening Edition

Today's theme is trust: a password anyone would guess, a wallet that shipped with a hidden implant, and a deal we know little about.

3Stories
2Min read

Danish CPR breach traced to company using '123456' passwords

Politiken reports that at least three accounts at Pays, an Odense IT company, used the password "123456", including the administrator account. The hacker reached Denmark's CPR register, the central civil registration database, and the breach exposed information tied to about 8.8 million CPR numbers. Access lasted 21 days and 17 hours from 10 September. Pays confirmed to TV 2 that its legitimate search access was abused. The hacker says they got in first with a leaked password from a former employee of another small Danish company, then wrote two programs to pull the data out. The hacker also says they won't sell or publish it, which is an unverified claim. An Aarhus University professor called the security "hopeless".

Why it mattersYou should treat this as a reminder that a tiny vendor with legitimate access to a national database is only as safe as its weakest password.

Full story at Hacker News →

Tampered Ledger wallets suspected in $86 million theft wave

Users of Ledger crypto wallets have reported drained accounts, and the trail points to devices sold by the reseller CryptoBillis. Ledger confirmed that one affected user's device held an unauthorized hardware implant. Photos and videos appear to show a small circuit board under the screen. Reports say it captures what the screen shows, including the seed passphrase during setup, and uses an embedded SIM to send it to the attacker. Reported losses top $86 million across hundreds of wallets, mostly among users in Southeast Asia. Ledger has asked CryptoBillis to pause sales, and there's no sign that Ledger's own systems or wallets bought directly from it are affected. Ledger has published guidance for checking a device.

Why it mattersYou should buy hardware wallets only straight from the maker, because the device itself can be the weak link.

Full story at The Verge →

Nvidia reportedly in talks to acquire Reflection AI

Nvidia is reportedly in talks to buy Reflection AI, a US startup that builds "open" models. The material we have gives no price, terms, timeline or confirmation from either company. Until there is more, treat it as talks, not a deal.

Why it mattersYou should watch whether this goes ahead, since it would show how much the chip giant wants to control the open-model space.

Full story at Hacker News →

Get this in your inbox

The Octopus writes twice a day: 6 AM and 4 PM.

Three to seven stories on ai, gadgets, big tech, and startups. Only what you need to know, in under 10 minutes. Free.

Join Oztir with The Octopus →

“Happiness consists of living each day as if it were the first day of your honeymoon.”

Ralph Waldo Emerson