Will security products debut at big tech shows this week?

Opinion
Sep 8, 20083 mins

* Patches from Microsoft, Gentoo, Mandriva, others * Researchers build malicious Facebook application * Data security now 10% of IT operating budgets, Forrester says, and other interesting reading

With some 120 new products being unveiled this week at the DEMOfall 08 and TechCrunch 50 events this week (I am at DEMOfall), it’ll be interesting to see how many are enterprise security related. Usually, not many. But every once in a while one slips through, such as Lucent’s Lojack-like system for laptops a few years ago. Hopefully we’ll get a couple of new security entries that will help lock down networks while continuing to allow workers to remain productive. If so, I’ll bring it to you in our Thursday newslettter. In the meantime, Microsoft’s got four new critical patches coming on Tuesday.

Microsoft to release four critical patches

Microsoft will release four critical updates to several software packages on Tuesday, the company said. The patches to be released on so-called Patch Tuesday include fixes for a vulnerability that allows remote code execution in Windows Media Player 11 on various Microsoft operating systems and for a vulnerability that allows remote code execution in various versions of the Windows OS and related products, including 2003 Server, Vista, XP, Office, .Net Framework, Works, Visual Studio, Visual FoxPro and other software.

Microsoft advance advisory

**********

Five new patches from Gentoo:

Courier Authentication Library (SQL injection, code execution)

MySQL (privilege bypass)

RealPlayer (buffer overflow, code execution)

dnsmasq (denial of service, DNS spoofing)

yelp (code execution)

**********

Two new updates from Mandriva:

tomcat5 (multiple flaws)

python (integer overflow, code execution)

**********

Two new fixes from rPath:

libtiff (buffer overflows, code execution)

ruby (multiple flaws)**********

Today’s malware news:

Researchers build malicious Facebook applicationA team of researchers have built a malicious Facebook program an experiment to demonstrate the possible dangers of social networking applications. The experiment shows the ease with which attackers could dupe large number of users into downloading a seemingly harmless application that actually performs a clandestine attack that can cripple a Web site. IDG News Service, 09/05/2008.Is Rock Phish cybergang set for a comeback?Do cybergangs work on evil “product upgrades” to improve their crimeware and attack methods? That’s what RSA, the security division of EMC, claims is happening with the Rock Phish gang, described as an East European cybercrime group responsible for creating botnets used in phishing attacks to steal personal information. Network World, 09/05/2008.

**********

From the interesting reading department:

Data security now 10% of IT operating budgets, Forrester saysIT security budgets are on the rise, reflecting growing concern over data breaches and increasing CEO involvement in the task of protecting sensitive data, Forrester Research analysts say. Network World, 09/04/2008.AT&T security guru talks DoS attacks, tomorrow’s hackersEdward Amoroso is the chief security officer at AT&T in Florham Park, N.J., as well as a professor who has written several textbooks on information security. Amoroso spoke with Network World’s Jon Brodkin this week in Boston, where he delivered a keynote about network security during Forrester’s Security Forum. Network World, 09/05/2008.Number of Bot-Infected PCs SkyrocketsThe number of PCs compromised with software that lets cyber criminals control the machines from afar has more than quadrupled over the last quarter, security experts warn. Washington Post’s Security Fix, 09/04/2008.Month of the VirusThe escalation of Internet spam can be attributed to the prevalence of malicious code being sent around via spam emails over the past month. It seems that spammers will stop at nothing to deliver their payload-various techniques in spam containing viruses were observed over “the month of the virus.” Symantec Security Response blog, 09/04/2008.