* Patches from Ubuntu, Debian, Mandriva, others * 'Experimental' security fix is malware, Microsoft says * Black box for the enterprise protects data from terrorists, hurricanes, and other interesting reading
endif; ?>When Microsoft releases new patches, as it does this week with its 10 vulnerability haul, everyone seems to get them installed pretty quickly after they’re released. Maybe it’s the automatic update feature in Windows or the fact that people are always wary of Microsoft security. Whatever the case, it’s a good thing patches are installed quickly. Contrast that to a report from Computerworld that says while Oracle releases patches on a quarterly basis – with 36 delivered this week – database admins are not always as quick to apply those patches. Why? Are the systems too complex or cannot be taken offline to update quickly? Do they require more testing? All likely scenarios. Hopefully hackers are not exploiting the gap between patch release (and vulnerability disclosure) and the time it takes to patch.
Microsoft reveals critical holes in Active Directory, mainframe gateway
Microsoft Tuesday issued four critical patches to close 10 vulnerabilities, some on critical IT systems such as Active Directory. The platforms affected by the critical vulnerabilities include Active Directory, Internet Explorer, Host Integration Server and Excel. In all, Microsoft issued 11 patches (see complete list here). In addition to the four that were critical, six were listed as important and one as moderate.
Microsoft October Patch Tuesday advisory**********Adobe patches Flash clickjacking and clipboard-poisoning bugsAdobe Systems Inc. patched five vulnerabilities in Flash today, including one that could be used in “clickjacking” attacks to secretly spy on users through their webcams. That fix, and others, were rolled into Flash Player 10, the new version of the popular browser plug-in the company launched earlier today. Computerworld. 10/15/2008.Adobe: Flash Player update available to address security vulnerabilities**********Oracle issues 36 patches, but is anyone applying them?Many database administrators don’t always apply security patches to their environments in a speedy fashion, but that’s not stopping Oracle Corp. from releasing dozens of them on a quarterly basis. The latest batch was released yesterday and includes fixes for 36 newly discovered vulnerabilities across a wide range of Oracle products. Computerworld, 10/15/2008.Oracle Critical Patch Update Advisory – October 2008**********
Half dozen new patches from Ubuntu:
D-Bus (security policy bypass)
Ruby (multiple flaws)**********
Five new fixes from Debian:
libxml2 (buffer overflow, code execution)
linux-2.6 (denial of service, privilege escalation)
openldap2.3 (denial of service)**********
Four new updates from Mandriva:
D-Bus (security policy bypass)
libxml2 (buffer overflow, code execution)
mono (HTTP injection)**********
Today’s malware news:
‘Experimental’ security fix is malware, Microsoft saysScammers are sending out phoney e-mails that claim to include critical Windows security alerts, Microsoft warned Monday. IDG News Service, 10/13/2008.Two Good Looking Windows Security Centers: One Fake, One Real
Another fake Windows Security Center has emerged. Much like versions in the past, on appearance this one is nearly identical to the actual Windows Security Center. And like older versions, it is installed by a trojan and falsely warns the user of non-existent infections (the true infection is the fake Security Center). CA Security Advisor Research Blog, 10/14/2008.
Surge in Facebook MalwareWe received reports from our colleagues in Hong Kong yesterday about more malware being distributed on Facebook. F-Secure, 10/15/2008.
**********
From the interesting reading department:
Black box for the enterprise protects data from terrorists, hurricanesA new disaster recovery vendor is taking the concept of an airplane black box and adapting it to the enterprise to create a new way of protecting crucial data from natural disasters and terrorist attacks. Network World, 10/13/2008.Patch releases push down Microsoft’s stock, researcher saysMicrosoft’s stock price regularly takes a hit on the days the company issues security patches, but it typically rebounds the next day, according to research by McAfee. Computerworld, 10/14/2008.Large Twitter Spamrun Incoming!All I’ve seen on Twitter this morning are comments regarding the absolute bombardment by Spammers promoting anything and everything they can think of (including porno sites). Looks like someone bought Little Jimmy his first Spamming set as an early Christmas present. The SpywareGuide Greynets Blog, 10/15/2008.
Plus: Smart Alteration To Suspended Twitter Accounts




