A U.S military botnet in the works 13 May 2008 12:54 GMTMake botnets, not war? In April, last year, I asked the question "Why establish an offensive cyber warfare doctrine when you can simple install a type of Lycos Spam Fighting screensaver on every military and government computer and have it periodically update its hit lists?" A year...
Source: ZDNet Apani and Cross-Platform Server Isolation 13 May 2008 10:00 GMTA while ago, I spoke with the folks of Apani about security in virtualized environments. Although this isn't a topic that is getting as much media attention as virtual machine software, virtual access software or virtual application environment software, it is a very important topic. Security risks still exist even...
Source: ZDNet Srizbi grows into world's largest botnet 13 May 2008 09:48 GMTThe Storm botnet hasn't completely blown over, but already there's a new big threat in town: the rampaging Srizbi botnet. (Nostalgic yet for the days when you could pronounce the name of the thing that tormented you?) A disturbing new feature makes Sribzi especially pernicious.

Source: Computerworld Hacker posts Chilean government data on 6 million 13 May 2008 09:48 GMTChile's remarkably lax data and privacy protections are in the spotlight as a hacker -- looking to do exactly that -- posts personal data on around six million Chileans.

Source: Computerworld MS08-029 – Moderate: Vulnerabilities in Microsoft Malware Protection Engine Could Allow Denial of Service (952044) 13 May 2008 08:00 GMTBulletin Severity Rating:Moderate - This security update resolves two privately reported vulnerabilities in the Microsoft Malware Protection Engine. An attacker could exploit either of the vulnerabilities by constructing a specially crafted file that could allow denial of service when received by the target computer system and scanned by the Microsoft Malware Protection Engine. An attacker who successfully exploited this vulnerability could cause the Microsoft Malware Protection Engine to stop responding and automatically restart.
Source: TechNet MS08-028 – Important: Vulnerability in Microsoft Jet Database Engine Could Allow Remote Code Execution (950749) 13 May 2008 08:00 GMTBulletin Severity Rating:Critical - This security update resolves a security vulnerability in the Microsoft Jet Database Engine (Jet) in Windows. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.
Source: TechNet MS08-027 – Critical: Vulnerability in Microsoft Publisher Could Allow Remote Code Execution (951208) 13 May 2008 08:00 GMTBulletin Severity Rating:Critical - This security update resolves a privately reported vulnerability in Microsoft Publisher that could allow remote code execution if a user opens a specially crafted Publisher file. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.
Source: TechNet MS08-026 – Critical: Vulnerabilities in Microsoft Word Could Allow Remote Code Execution (951207) 13 May 2008 08:00 GMTBulletin Severity Rating:Critical - This security update resolves several privately reported vulnerabilities in Microsoft Word that could allow remote code execution if a user opens a specially crafted Word file. An attacker who successfully exploited these vulnerabilities could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.
Source: TechNet Call for military to operate botnet 13 May 2008 00:26 GMTFiled under bold proposals: Col. Charles W. Williamson III. staff judge advocate, Air Force Intelligence, Surveillance and Reconnaissance Agency, writes in Armed Forces Journal that what the military really needs is an offensive bot-net. (via /. The world has abandoned a...
Source: ZDNet