* Patches from Oracle, Gentoo, Mandriva, others * Attacks begin against critical Patch Tuesday bug * Researchers map Internet's 'black holes', and other interesting reading
Oracle’s quarterly update is coming this Tuesday and is slated to include some 41 total patches. Among the updates are two that fix “nasty” flaws in Oracle’s core database that could be exploited with a username or password. In advance of the Oracle release, we’ve also got updates from Gentoo, Mandriva, Debian and Ubuntu.
Oracle to ship critical database fixes this week
Oracle will release patches for a slew of products this week, including fixes for two nasty vulnerabilities for its database software. In total, Oracle plans to release 41 bug-fixes next Tuesday, but users are likely to pay particular attention to two bugs in the database that can be exploited over a network without a username and password. Oracle plans to ship 17 database fixes in all. IDG News Service, 04/11/08.
**********
Five new patches from Gentoo:
gnome-screensaver (authentication bypass, privilege escalation)
policyd-weight (non-secure temp files, symlink attack)
am-utils (non-secure temp files, file overwrite)
**********
Three new updates from Mandriva:
rsync (buffer overflow, code execution)
audit (stack oveflow, code execution)
php-apc (buffer overflow, code execution)
**********
Two new fixes from Debian:
gnumeric (integer overflow, code execution)
rsync (buffer overflow, code execution)
**********
Two new patches from Ubuntu:
rsync (buffer overflow, code execution)
Ghostscript (buffer overflow, code execution)
**********
Today’s malware news:
Attacks begin against critical Patch Tuesday bug
Hackers are trying to exploit a critical Windows vulnerability just patched on Tuesday, security researchers said this afternoon — and the only version of Windows not at risk is the unfinished Windows XP SP3. Computerworld, 04/12/08.
Symantec: Attempt at Exploiting Latest GDI Vulnerability Found in the Wild
**********
From the interesting reading department:
Researchers map Internet’s ‘black holes’
You would think there should be a really sophisticated way of detecting an Internet black hole. There isn’t. Network World, 04/10/08.
Browser exploits getting more intense
Threats against browsers are getting more sophisticated and branching out into such exotic areas as gaming, experts told attendees at RSA Conference 2008. Network World, 04/10/08.
Botnet economy runs wild
Cybercriminals have created a global business with a supply chain that’s every bit as organized and sophisticated as that of any legitimate business. Network World, 04/10/08.
Research fingers ActiveX, QuickTime as buggiest browser plug-ins
Microsoft’s ActiveX technology, which is primarily used to create add-ins for Internet Explorer, accounted for the vast majority of browser plug-in vulnerabilities in the second half of 2007, according to Symantec. Computerworld, 04/11/08.
Bot breaks Hotmail’s CAPTCHA in 6 seconds
A new bot can crack defenses erected by Microsoft to keep spammers from creating large numbers of accounts on its Live Hotmail service within seconds, a security researcher said today. Computerworld, 04/11/08.
Symantec observed 87,963 phishing Web site hosts during the second half of 2007. This is an increase of 167 percent from the first half of 2007, when Symantec detected only 32,939 phishing Web site hosts. Between the second half of 2006, when 13,353 phishing Web site hosts were detected, and the second half of 2007, Symantec observed a dramatic increase of 559 percent in phishing Web site hosts. Symantec Security Response blog, 04/11/08.
Three hackers found ‘Pwn To Own’ bug
The Flash vulnerability used to hijack a Windows Vista laptop during last month’s “PWN To OWN” hacker challenge was independently uncovered by two other researchers, one who noted it nearly five months ago, the company that paid the contest prize money said Thursday. Computerworld, 04/13/08.
U.S. presidential election can be hacked
This year, the U.S. will pick a new president using electronic voting machines that can be hacked, security experts said Thursday at the RSA Conference in San Francisco. IDG News Service, 04/11/08.
After arrest, founder of bug-selling company to stay
Five months after being arrested by Italian authorities on hacking and wiretapping charges, the founder of a controversial company that sells unpatched computer vulnerabilities says he’ll remain on board. IDG News Service, 04/10/08.
Inside the black market ‘bug trade’
The black market for software vulnerabilities is booming, with bugs regularly being sold for thousands of dollars a piece online. And one of the only ways to reduce this steady stream of hacks, according to Geekonomics author and IT security pro David Rice, is for software companies to simply write better code. Computerworld, 04/10/08.
DHS offers first take on Cyber Storm exercise
With its latest Cyber Storm II exercise now completed, the U.S. Department of Homeland Security said it expects to release an after-action report analyzing the event, and is now beginning planning for Cyber Storm III in 2010. IDG News Service, 04/10/08.
SanDisk warns of USB drive threat
SanDisk has warned that IT managers are unaware of the extent to which unsecured flash drives are being brought into their organizations, backing this with a new study of corporate end-users and IT executives. TechWorld, 04/11/08.
Malware filters bad for business
Up to 80% of Web sites flagged as malicious by antivirus and search engine indexes are legitimate businesses, according to security experts. Computerworld, 04/11/08.




