Security News > 2022 > November

Feds find Silk Road thief's $1b+ Bitcoin stash in popcorn tin, hidden safe
2022-11-07 22:28

A crook who stole more than 50,000 Bitcoins from the dark web souk Silk Road in 2012 has pleaded guilty and lost the lot, with a stretch behind bars likely ahead of him. James Zhong, 32, admitted committing wire fraud in September 2012 by creating nine Silk Road accounts he used to trigger "Over 140 transactions in rapid succession in order to trick Silk Road's withdrawal-processing system," the US Department of Justice said Monday.

Microsoft is showing ads in the Windows 11 sign-out menu
2022-11-07 21:55

Microsoft is now promoting some of its products in the sign-out flyout menu that shows up when clicking the user icon in the Windows 11 start menu. Redmond has pushed ads within the user interface of Microsoft Office apps or other Windows apps before.

All the US midterm-related lies to expect when you're electing
2022-11-07 21:30

Misinformation related to tomorrow's US midterm elections hasn't slowed, according to security researchers. This includes more misleading election ads on Google, as well "Alternate facts" about voting systems manufacturers, all of which aims to cast doubt on election results, according to two reports published today.

#US
U.S. unmasks hacker who stole 50,000 bitcoins from Silk Road
2022-11-07 20:23

The U.S. Department of Justice has announced today the conviction of James Zhong, a mysterious hacker who stole 50,000 bitcoins from the 'Silk Road' dark net marketplace. Zhong pled guilty to money laundering crimes on Friday, November 4, for exploiting a "Withdrawal processing flaw" that allowed him to withdraw many times more Bitcoin than he deposited on the dark web marketplace.

Public URL scanning tools – when security leads to insecurity
2022-11-07 19:59

Well-known cybersecurity researcher Fabian Bräunlein has featured not once but twice before on Naked Security for his work in researching the pros and cons of Apple's AirTag products. Now, Bräunlein is back with another worthwhile warning, this time about the danger of cloud-based security lookup services that give you a free opinion about cybersecurity data you may have collected.

Microsoft WinGet package manager failing due to CDN issues
2022-11-07 19:12

We and our store and/or access information on a device, such as cookies and process personal data, such as unique identifiers and standard information sent by a device for personalised ads and content, ad and content measurement, and audience insights, as well as to develop and improve products. With your permission we and our partners may use precise geolocation data and identification through device scanning.

Maple Leaf Foods suffers outage following weekend cyberattack
2022-11-07 17:59

Maple Leaf Foods confirmed on Sunday that it experienced a cybersecurity incident causing a system outage and disruption of operations.Maple Leaf Foods is Canada's largest prepared meats and poultry food producer, operating 21 manufacturing facilities, employing 14,000 people, and contracting over 700 barns.

Ransomware gang threatens to release stolen Medibank data
2022-11-07 17:50

A ransomware gang that some believe is a relaunch of REvil and others track as BlogXX has claimed responsibility for last month's ransomware attack against Australian health insurance provider Medibank Private Limited. While until now, the attack on Medibank hasn't yet been attributed to a specific ransomware group, the company did confirm that the malicious activity observed on its network matches ransomware activity.

Microsoft hits the switch on password-free smartphone authentication
2022-11-07 17:30

At its Ignite 2022 event last month, Microsoft announced general availability of Azure Active Director certificate-based authentication, addressing a component the Biden Administration's executive order last year to strengthen the US's cybersecurity. Microsoft is now offering a public preview of Azure AD CBA on devices running Apple's iOS and Android that uses certificates on Yubico's YubiKey hardware security key.

Mastodon now has over 1 million users amid Twitter tensions
2022-11-07 16:04

Mastodon, the free, open-source, decentralized micro-blogging social media platform, has surpassed a million monthly active users for the first time in its history. The platform's explosive growth was announced today by Eugen Rochko, the creator of Mastodon, who noted that almost half of the new users joined the platform since October 27, 2022, when Elon Musk's sealed the purchase of Twitter.