* Patches from Microsoft, Apple, Cisco * Safari 'carpet bomb' attack code released * U.S. Congressmen accuse China of hacking their computers, and other interesting reading
Big week with 10 new fixes from Microsoft, including an interesting one to the company’s Bluetooth stack, plus updates from OpenOffice.org, Apple for QuickTime, and the SNMPv3 protocol. Also, a couple of U.S. Congressmen have accused China of hacking into their governemnt computers, systems that could include information on Chinese dissidents.
Microsoft patches 10 bugs in Windows, IE and Bluetooth
Microsoft Tuesday patched 10 vulnerabilities, four marked “critical,” in Windows and Internet Explorer (IE), and disabled a little-known third-party ActiveX control bundled with Logitech hardware, including keyboards and mice. The one that caught the eyes of most analysts was MS09-030 , a critical update that patches a single bug in Windows’ implementation of Bluetooth. Computerworld, 06/10/2008.
**********
New version of OpenOffice.org fixes critical bug
OpenOffice.org has issued a patch for a security vulnerability affecting several versions of its open-source office suite. The vulnerability is a memory problem called a heap overflow, OpenOffice.org said in an advisory. IDG News Service, 06/11/2008.
Version information for new update
**********
Apple releases QuickTime 7.5 with bug fixes
Apple has again released a new version of QuickTime, its multimedia player that has been plagued by software vulnerabilities. The latest version, 7.5, repairs five vulnerabilities, all of which could result in a hacker taking control over a person’s PC. Four out of the five problems affect both Apple’s OS X and Microsoft’s XP and Vista operating systems. IDG News Service, 06/10/2008.
**********
US-CERT warns of SNMPv3 vulnerability
A flaw in many implementations of SNMPv3 could be exploited to bypass the authentication mechanism of affected systems. Simply put, attackers could read SNMP packets to find system credentials, then used forged packets to gain access to the system. US-CERT is urging users to check with their vendors for an update.
Cisco’s update is available here
**********
Two new updates from Mandriva
**********
Today’s malware news:
Safari ‘carpet bomb’ attack code released
A hacker has posted attack code that exploits critical flaws in the Safari and Internet Explorer Web browsers. IDG News Service, 06/10/2008.
**********
From the interesting reading department:
U.S. Congressmen accuse China of hacking their computers
Two U.S. Congressmen on Wednesday accused China of hacking their office computers, possibly compromising information on Chinese dissidents, the Congressmen and news reports said. IDG News Service, 06/12/2008.
Disaster recovery paramount now that hurricane season is here
With hurricane season starting this month, businesses need to establish and test plans for how they will protect network data and gear, and recover from outages, the Association for Information Communications Technology Professionals in Higher Education says. Network World, 06/11/2008.
Most data breaches discovered too late, study says
Most companies only learn about network data breaches in the months after their data has already been compromised, according to a new study. Network World, 06/11/2008.
Stolen laptop teaches Stanford a lesson on encryption
From the “Why aren’t these systems encrypted already?” department comes yet another story of a laptop theft resulting in the potential compromise of personal data belonging to a large number of people. Computerworld, 06/09/2008.
E-discovery error leads to loss of attorney-client privilege
A federal judge in Maryland ruled late last month that a company being sued for copyright infringement waived attorney-client privilege for 165 documents accidentally disclosed to opposing counsel during the e-discovery process. Computerworld, 06/09/2008.
Hacker pleads guilty to attacking anti-phishing group
A Fairfield, California, hacker has pleaded guilty to launching a Valentine’s Day 2007 computer attack that nearly knocked an anti-phishing Web site offline. IDG News Service, 06/10/2008.




