* Patches from Microsoft, Debian, Gentoo, others * Bank of America's New Banking Site * How to Handle Security Patches With Sanity, and other interesting reading
endif; ?>Microsoft is sending 2008 out with bang, patching some 28 vulnerabilities in the latest Patch Tuesday update released this week. Of course, it’s the 29th bug that got them: Chinese security researchers said they accidently released an exploit for Internet Explorer 7 that takes advantage of an unpatched bug. If Microsoft holds to the schedule for its next update, that will mean this IE7 exploit will have a full month to be targeted. Redmond is not saying if it will release an emergency patch early or not.
Microsoft issues slew of critical security patches
Microsoft Tuesday released its final eight patches of 2008, which address 28 vulnerabilities including a critical flaw in the new search component in Vista and Windows Server 2008. Network World, 12/09/2008.
But it looks like the didn’t get all the vulnerabilities in this mega release:
New Web attack exploits unpatched IE flaw
As Microsoft readies its latest set of security updates, online attackers have begun exploiting a new flaw in the company’s Internet Explorer browser. IDG News Service, 12/09/2008.
Chinese team mistakenly released unpatched IE7 exploit
**********
Three new updates from Debian:
streamripper (buffer overflows)
SquirrelMail (cross scripting)
**********
Three new patches from Gentoo:
Archive::Tar (directory traversal)
Mgetty (temp files, symlink attack)
**********
Two new fixes from Mandriva:
**********
Two new patches from Ubuntu:
**********
Today’s malware news:
Bank of America’s New Banking Site
As Christine mentioned earlier today in her post regarding Koobface and how it uses fake Flash players to trick people into downloading malware, a smart move is to only download Adobe Flash player from: Adobe! F-Secure, 12/09/2008.
**********
From the interesting reading department:
How to Handle Security Patches With Sanity
Patch management is just one of the necessary evils that cause us pain month after month with the onslaught of patches that come from various software vendors. If you are new to the patch management game, or have just taken on the duties of the patch administrator in your company or organization, here is a simple framework that can be used to begin or augment any company’s patch management process. CSO, 12/09/2008.
The seven deadly sins of network security
Anyone worth their salt in information security will tell you a solid defense is built upon multiple layers of technology, policy and practice. That’s defense-in-depth. CSO, 12/10/2008.
November 2008 – A Historic Month in the Political and Spam Landscape
November 2008: what a month! A new U.S. president is elected and spam volumes drop significantly as a hosting company called McColo is shutdown. While both these events were generally welcomed, the new President and the antispam community continue to face tough obstacles in the year ahead. Symantec Security Response, 12/09/2008.




