MS08-038 – Important: Vulnerability in Windows Explorer Could Allow Remote Code Execution (950582) 08 Jul 2008 08:00 GMTBulletin Severity Rating:Important - This security update resolves a publicly reported vulnerability in Windows Explorer that could allow remote code execution when a specially crafted saved-search file is opened and saved. If a user is logged on with administrative user rights, an attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.
Source: TechNet MS08-037 – Important: Vulnerabilities in DNS Could Allow Spoofing (953230) 08 Jul 2008 08:00 GMTBulletin Severity Rating:Important - This security update resolves two privately reported vulnerabilities in the Windows Domain Name System (DNS) that could allow spoofing. These vulnerabilities exist in both the DNS client and DNS server and could allow a remote attacker to redirect network traffic intended for systems on the Internet to the attacker’s own systems.
Source: TechNet $1 Million prize offered for cracking an encryption algorithm 07 Jul 2008 22:55 GMTIt's 2008, and companies perhaps rich on VC money to waste in a guerilla marketing tactic for generating viral buzz, still talk and act as the utopian "unbreakable encryption" algorithm is the panacea of security, or the "Hackers Hell: Privacy That Can't Be Compromised" as they pitch it. ...
Source: ZDNet Approximately 800 vulnerabilities discovered in antivirus products 07 Jul 2008 20:44 GMTIn what appears to be either a common scenario of "when the security solution ends up the security problem itself", or a product launch basing its strategy on outlining the increasing number of critical vulnerabilities found in competing antivirus products, the IT/Security consulting firm n.runs AG claims to have discovered...
Source: ZDNet Twitter's holiday battle with spammers 07 Jul 2008 19:59 GMTGuest post by Adam J. O'Donnell, Ph.D., of Cloudmark, on Twitter's holiday weekend spam attack and methods the microblogging site might use to combat it. by Jennifer Leggio
Source: ZDNet Microsoft warns of "active, targeted" ActiveX control attacks 07 Jul 2008 17:29 GMTMicrosoft has issued a pre-patch security advisory to warn about "active, targeted attacks" against an ActiveX control for the Snapshot Viewer for Microsoft Access. The skinny: An attacker could exploit the vulnerability by constructing a specially crafted Web page. When a user views the Web page,...
Source: ZDNet Twitter as a PayPal killer? Umm, not so fast 07 Jul 2008 16:32 GMT* Ryan Naraine is on vacation. Guest Editorial by Dan Glass A recent blog proclaiming that Twitter could soon become a rival to PayPal made me shudder in fear. The blog author postulated that Twitter could offer a method to...
Source: ZDNet Pediatric market opened to statins 07 Jul 2008 14:20 GMTYes, if you have to give your kid a statin at 8 to prevent a future heart attack I think there is something wrong with your parenting. But should the kid pay for it with an early death? When it can be prevented? by Dana Blankenhorn
Source: ZDNet