New York Times Source Code Stolen Using Exposed GitHub Token

The New York Times has confirmed that its internal source code was leaked on 4chan after being stolen from the company’s GitHub repositories in January 2024. BleepingComputer reports: As first seen by VX-Underground, the internal data was leaked on Thursday by an anonymous user who posted a torrent to a 273GB archive containing the stolen data. “Basically all source code belonging to The New York Times Company, 270GB,” reads the 4chan forum post. “There are around 5 thousand repos (out of them less than 30 are additionally encrypted I think), 3.6 million files total, uncompressed tar.”

While BleepingComputer did not download the archive, the threat actor shared a text file containing a complete list of the 6,223 folders stolen from the company’s GitHub repository. The folder names indicate that a wide variety of information was stolen, including IT documentation, infrastructure tools, and source code, allegedly including the viral Wordle game. A ‘readme’ file in the archive states that the threat actor used an exposed GitHub token to access the company’s repositories and steal the data. The company said that the breach of its GitHub account did not affect its internal corporate systems and had no impact on its operations. The Times said in a statement to BleepingComputer: “The underlying event related to yesterday’s posting occurred in January 2024 when a credential to a cloud-based third-party code platform was inadvertently made available. The issue was quickly identified and we took appropriate measures in response at the time. There is no indication of unauthorized access to Times-owned systems nor impact to our operations related to this event. Our security measures include continuous monitoring for anomalous activity.”

Read more of this story at Slashdot.

The Word ‘Bot’ Is Increasingly Being Used As an Insult On Social Media

The definition of the word “bot” is shifting to become an insult to someone you know is human, according to researchers who analyzed more than 22 million tweets. Researchers found this shift began around 2017, with left-leaning users more likely to accuse right-leaning users of being bots. “A potential explanation might be that media frequently reported about right-wing bot networks influencing major events like the [2016] US election,” says Dennis Assenmacher at Leibniz Institute for Social Sciences in Cologne, Germany. “However, this is just speculation and would need confirmation.” NewScientist reports: To investigate, Assenmacher and his colleagues looked at how users perceive what is a bot or not. They did so by looking at how the word “bot” was used on Twitter between 2007 and December 2022 (the social network changed its name to X in 2023, following its purchase by Elon Musk), analyzing the words that appeared next to it in more than 22 million English-language tweets. The team found that before 2017, the word was usually deployed alongside allegations of automated behavior of the type that would traditionally fit the definition of a bot, such as “software,” “script” or “machine.” After that date, the use shifted. “Now, the accusations have become more like an insult, dehumanizing people, insulting them, and using this as a technique to deny their intelligence and deny their right to participate in a conversation,” says Assenmacher. The study has been published in the journal Proceedings of the Eighteenth International AAAI Conference on Web and Social Media.

Read more of this story at Slashdot.

Birmingham’s $125M ‘Oracle Disaster’ Blamed on Poor IT Project Management

It was “a catastrophic IT failure,” writes Computer Weekly. It was nearly two years ago that Birmingham City Council, the largest local authority in Europe, “declared itself in financial distress” — effectively declaring bankruptcy — after the costs on an Oracle project costs ballooned from $25 million to around $125.5 million.

But Computer Weekly’s investigation finds signs that the program board and its manager wanted to go live in April of 2022 “regardless of the state of the build, the level of testing undertaken and challenges faced by those working on the programme.” One manager’s notes “reveal concerns that the program manager and steering committee could not be swayed, which meant the system went live despite having known flaws.”

Computer Weekly has seen notes from a manager at BCC highlighting a number of discrepancies in the Birmingham City Council report to cabinet published in June 2023, 14 months after the Oracle system went into production. The report stated that some critical elements of the Oracle system were not functioning adequately, impacting day-to-day operations. The manager’s comments reveal that this flaw in the implementation of the Oracle software was known before the system went live in April 2022… An insider at Birmingham City Council who has been closely involved in the project told Computer Weekly it went live “despite all the warnings telling them it wouldn’t work”….

Since going live, the Oracle system effectively scrambled financial data, which meant the council had no clear picture of its overall finances. The insider said that by January 2023, Birmingham City Council could not produce an accurate account of its spending and budget for the next financial year: “There’s no way that we could do our year-end accounts because the system didn’t work.”

A June 2023 report to cabinet “stated that due to issues with the council’s bank reconciliation system, a significant number of transactions had to be manually allocated to accounts rather than automatically via the Oracle system,” according to the article. But Computer Weekly has seen a 2019 presentation slide deck showing the council was already aware that Oracle’s out-of-the-box bank reconciliation system “did not handle mixed debtor/non-debtor bank files. The workaround suggested was either a lot of manual intervention or a platform as a service (PaaS) offering from Evosys, the Oracle implementation partner contracted by BCC to build the new IT system.”

The article ultimately concludes that “project management failures over a number of years contributed to the IT failure.”

Read more of this story at Slashdot.