Ransomware gang leaks French government emails

A ransomware gang has published what it claims is sensitive data from multiple French organisations on a dark web forum.

The Stormous cartel, active since 2022, posted the dataset as a ‘comprehensive leak’ allegedly involving high-profile French government bodies.

However, researchers from Cybernews examined the information and found the data’s quality questionable, with outdated MD5 password hashes indicating it could be from older breaches.

Despite its age, the dataset could still be dangerous if reused credentials are involved. Threat actors may exploit the leaked emails for phishing campaigns by impersonating government agencies to extract more sensitive details.

Cybernews noted that even weak password hashes can eventually be cracked, especially when stronger security measures weren’t in place at the time of collection.

Among the affected organisations are Agence Française de Développement, the Paris Region’s Regional Health Agency, and the Court of Audit.

The number of exposed email addresses varies, with some institutions having only a handful leaked while others face hundreds. The French cybersecurity agency ANSSI has yet to comment.

Last year, France faced another massive exposure incident affecting 95 million citizen records, adding to concerns about ongoing cyber vulnerabilities.

Would you like to learn more about AI, tech and digital diplomacy? If so, ask our Diplo chatbot!

OpenAI to operate new AI cluster in Abu Dhabi’s Stargate UAE project

In a major development for AI and global cooperation, G42, OpenAI, Oracle, NVIDIA, SoftBank, and Cisco have announced a partnership to launch Stargate UAE.

The 1-gigawatt AI compute cluster will be part of a larger 5-gigawatt UAE–US AI Campus located in Abu Dhabi, aimed at supporting large-scale AI workloads and fostering innovation across sectors.

Stargate UAE will be constructed by G42 and operated jointly by OpenAI and Oracle, with Cisco providing cybersecurity and connectivity, and NVIDIA supplying its latest Grace Blackwell GB300 systems.

The project is scheduled to bring its first 200-megawatt cluster online by 2026. The facility will provide regional low-latency inferencing and high-performance AI compute infrastructure.

The broader UAE–US AI Campus will span 10 square miles and be powered by a combination of nuclear, solar, and natural gas energy. The campus will also include a science park to support research and workforce development.

Announced in the presence of leaders from both nations, the initiative aligns with the new US-UAE AI Acceleration Partnership framework, which aims to foster responsible and secure AI advancement.

The initiative also includes reciprocal investment in the US through projects like Stargate US, supporting the America First Investment Policy. Stargate UAE represents the first overseas expansion of the OpenAI for Countries initiative and demonstrates an effort to decentralize AI innovation globally.

This project highlights the growing role of international cooperation in shaping AI infrastructure and reflects the UAE’s ambition to lead in technological advancement through partnerships and long-term investment.

Would you like to learn more about AI, tech and digital diplomacy? If so, ask our Diplo chatbot!

Nvidia ramps up AI push with new Taiwan plans

Nvidia CEO Jensen Huang has urged Taiwan to embrace agentic AI and robotics to tackle its ongoing labour shortage.

Speaking before his departure from Taipei after a week-long visit, Huang said 2025 would be a ‘very exciting’ year for AI, as the technology now possesses the ability to ‘reason’ and carry out step-by-step problem-solving never encountered before.

The new wave of agentic AI, he explained, could assist people with various workplace and everyday tasks.

Huang added that Taiwan, despite being a hub of innovation, faces a lack of manpower. ‘Now with AI and robots, Taiwan can expand its opportunity,’ he said.

He also expressed enthusiasm over the production ramp-up of Blackwell, Nvidia’s latest GPU architecture built for AI workloads, noting that partners across Taiwan are already in full swing.

Huang’s trip included meetings with local partners and a keynote at Computex Taipei, where he unveiled Nvidia’s new Taiwan office and plans for the country’s first large-scale AI supercomputer.

In a TV interview, Huang urged the Taiwanese government to invest more in energy infrastructure to support the growing AI sector. He warned that the energy demands of AI development could exceed 100 megawatts in the near future, stressing that energy availability is the key limitation.

Taiwan’s expanding AI ecosystem — from chip plants to educational institutions — would require substantial support to thrive, he said, pledging to return for Chinese New Year.

Would you like to learn more about AI, tech and digital diplomacy? If so, ask our Diplo chatbot!

Infostealer malware suspected in major username and password leak

Cybersecurity researcher Jeremiah Fowler reported discovering a publicly accessible, unprotected database containing more than 184 million login credentials from services including Facebook, Instagram, Microsoft, Roblox, Snapchat, and many others.

Wired noted that the leak also included data from Apple, Amazon, Nintendo, Spotify, Twitter, Yahoo, banks, healthcare providers, and government portals.

Fowler was unable to determine the database’s origin, its intended purpose, or how long it remained exposed. After reporting it to the hosting provider, access was restricted.

He verified the data’s authenticity by contacting individuals using emails listed in the database and identifying himself as a researcher.

Fowler suspects the data was collected using infostealer malware, which targets credentials stored in browsers, email clients, and messaging apps. Cybercriminals may distribute such malware through phishing attacks, malicious links, or cracked software.

To avoid these threats, users are advised to scrutinize links in emails and messages, confirm website URLs before visiting, and avoid downloading software from unverified sources.

Apple users should rely on the Mac App Store or reputable developers’ websites. Promptly installing OS and app updates is also essential for staying secure.

Fowler’s discovery highlights the persistent threat of infostealer malware and the need for users to remain vigilant when interacting online.

Would you like to learn more about AI, tech and digital diplomacy? If so, ask our Diplo chatbot!

The power of compromise

In a recent blog post titled ‘Compromise is not a dirty word – It’s the glue holding humanity together,’ Jovan Kurbalija reflects on the often misunderstood nature of compromise. Prompted by the sight of Lucid cars in Geneva, Switzerland, bearing the slogan ‘Compromise Nothing,’ he questions why compromise is so frequently seen as weakness when it is the foundation of human coexistence.

From families to international diplomacy, our ability to meet halfway allows us to survive and thrive together. Kurbalija reminds us that the word comes from the Latin for ‘promising together’—a mutual commitment rather than a concession.

In today’s world, however, standing firm is glorified while compromise is dismissed. Yet, he argues, true courage lies in embracing others’ needs without surrendering one’s principles and navigating the messy but necessary space between absolutes.

He contrasts this human necessity with how compromise is portrayed in marketing—as a flaw to be avoided—and in tech jargon, where being ‘compromised’ means a breach or failure. These modern distortions have led us to equate flexibility with defeat, instead of maturity. In truth, refusing to compromise risks far more than bending a little.

Ultimately, Kurbalija calls for a shift in mindset: rather than rejecting compromise altogether, we should learn to use it wisely, to preserve the greater good over rigid standoffs. In a world as interconnected and fragile as ours, compromise is not surrender; it’s survival.

Would you like to learn more about AI, tech and digital diplomacy? If so, ask our Diplo chatbot!

The United Nations calls for urgent regulation of military AI

The UN and global experts have emphasised the urgent need for comprehensive regulation of AI in military applications. UN Secretary has called for ‘global guardrails’ to govern the use of autonomous weapons, warning that rapid technological development has outpaced current policies.

Recently, 96 countries met at the UN to discuss AI-powered weapons, expanding the conversation to include human rights, criminal law, and ethics, with a push for legally binding agreements by 2026. Unregulated military AI poses serious risks like cybersecurity attacks and worsening geopolitical divides, as some countries fear losing a strategic advantage to rivals.

However, if properly regulated, AI could reduce violence by enabling less-lethal actions and helping leaders choose non-violent solutions, potentially lowering the human cost of conflict. To address ethical challenges, institutions like Texas A&M University are creating nonprofits that work with academia, industry, and defence sectors to develop responsible AI frameworks.

These efforts aim to promote AI applications that prioritise peace and minimise harm, shifting the focus from offensive weapons toward peaceful conflict resolution. Finally, UN Secretary warned against a future divided into AI ‘haves’ and ‘have-nots.’

He stressed the importance of using AI to bridge global development gaps and promote sustainable progress rather than deepen inequalities, emphasising international cooperation to guide AI toward inclusive growth and peace.

Would you like to learn more about AI, tech and digital diplomacy? If so, ask our Diplo chatbot!

Uganda to launch ‘Tokigeza’ campaign against Telecom vandalism

The Ugandan Communications Commission (UCC), together with major telecom operators including MTN Uganda, Airtel Uganda, and ATC Uganda, has launched a national anti-vandalism campaign named ‘Tokigeza’ (meaning ‘Do not do it’) to combat the rising problem of telecom infrastructure vandalism. The three-month initiative aims to raise public awareness and mobilise communities to protect vital telecom assets.

The campaign employs a multi-channel approach involving radio, television, and digital media outreach, as well as grassroots engagement through schools, local meetings, landowners, law enforcement, and boda-boda (motorcycle taxi) drivers. Alongside the campaign, stakeholders call for stronger laws and better enforcement to combat vandalism.

Proposed measures include tougher penalties, tighter scrap metal trade controls, and linking telecom surveillance with national police monitoring. A cross-agency task force is also proposed.

The government supports these moves, with Ugandan President backing the classification of telecom towers as Critical National Infrastructure (CNI) and pushing for harsher penalties by treating vandalism as economic sabotage. The Ministry of ICT stresses the need for public-private cooperation to protect ICT infrastructure as Uganda’s digital network grows.

Despite these efforts, no formal timeline exists for legal reforms, and there are doubts about whether CNI status alone will stop vandalism. Nigeria’s experience shows that even with such classification, sabotage, especially of fibre optic cables, continues. Uganda will need sustained and coordinated action to protect its telecom infrastructure effectively.

Would you like to learn more about AI, tech and digital diplomacy? If so, ask our Diplo chatbot!

Meta and PayPal users targeted in new phishing scam

Cybersecurity experts are warning of a rapid and highly advanced phishing campaign that targets Meta and PayPal users with instant account takeovers. The attack exploits Google’s AppSheet platform to send emails from a legitimate domain, bypassing standard security checks.

Victims are tricked into entering login details and two-factor authentication codes, which are then harvested in real time. Emails used in the campaign pose as urgent security alerts from Meta or PayPal, urging recipients to click a fake appeal link.

A double-prompt technique falsely claims an initial login attempt failed, increasing the likelihood of accurate information being submitted. KnowBe4 reports that 98% of detected threats impersonated Meta, with the remaining targeting PayPal.

Google confirmed it has taken steps to reduce the campaign’s impact by improving AppSheet security and deploying advanced Gmail protections. The company advised users to stay alert and consult their guide to spotting scams. Meta and PayPal have not yet commented on the situation.

Would you like to learn more about AI, tech and digital diplomacy? If so, ask our Diplo chatbot!

Dutch central bank tells public to prepare for outages

Dutch citizens have been advised to keep emergency cash at home due to growing concerns over cyber threats and geopolitical instability.

The Netherlands’ central bank (DNB) recommends holding €70 per adult and €30 per child to cover essential needs for up to three days.

This guidance follows recent disruptions to payment systems in southern Europe. The advisory comes in response to fears that cyberattacks or power failures could make digital payments temporarily unavailable.

Cash would enable people to buy food, water, medicine, or transport even during system outages. The DNB also encouraged the use of contactless payments via phones or smartwatches as backups. Such steps are seen as vital amid increasing risks across the continent.

The warning follows a major blackout that affected Spain and Portugal in April, during which electronic transactions were disrupted. The European Commission has similarly urged households to be prepared for at least 72 hours with cash and basic supplies.

Would you like to learn more about AI, tech and digital diplomacy? If so, ask our Diplo chatbot!

Sui DEX Cetus suffers suspected $200m hack

A major security incident has struck Cetus, a decentralised exchange (DEX) on the Sui blockchain, with suspected losses exceeding $200 million. Onchain data revealed rapid asset drainage, prompting experts to label the event as a possible hack rather than a mere bug, as claimed by the Cetus team.

Reports indicate that at least $63 million has already been transferred to Ethereum, including a large single transaction of 20,000 ETH moved to a new wallet.

Transaction volumes on Cetus surged to $2.9 billion on 22 May, compared to $320 million the previous day, suggesting funds were rapidly siphoned from the platform.

Several tokens lost over 75% of their value, causing wider disruption; for instance, the Sui-based money market Scallop halted all borrowing activities as a precaution.

Concerns over transparency have grown as $212 million in assets were reportedly bridged to Ethereum at a rate of $1 million per minute. Analysts argue the scale and speed of transfers hint at something more serious than a simple software glitch.

Cetus paused the affected smart contract and announced an ongoing investigation, but has yet to provide a detailed response.

Would you like to learn more about AI, tech and digital diplomacy? If so, ask our Diplo chatbot