* Patches from Yahoo, Gentoo, Mandriva, others * Two New Mac OSX Trojans * Are smartphone viruses really a threat to your network?, and other interesting reading
Ruby on Rails programmers will want to take note of this newsletter: The company that oversees development of the coding language is warning of “serious” flaws in the system, which could be exploited to take over systems. Also, the major VOIP hardware vendors are issuing patches for a number of common flaws in their respective systems. And, Adobe has patched Acrobat to fix a flaw that could be used to take over an non-patched system.
Ruby creators warn of serious flaws
The Ruby programming language, which has become popular as the basis for Web 2.0 sites such as Twitter, contains serious security flaws that could allow attackers to take over an organization’s Web server, according to the Ruby development team. TechWorld, 06/24/2008.
**********
Avaya, Cisco and Nortel face VoIP vulnerabilities
VoIP customers of Avaya, Cisco and Nortel should look Wednesday for patches that correct newly found vulnerabilities that, if exploited, can result in remote code execution; unauthorized access; denial of service; and information harvesting. Network World, 06/24/2008.
**********
Security Update for Adobe Reader, Acrobat
Adobe has issued a security update for its Adobe Acrobat and free Adobe Reader applications. The patch plugs a critical flaw that Adobe said attackers could leverage to take control of a vulnerable system. Washington Post Security Fix blog, 06/25/2008.
**********
Yahoo Mail vulnerability discovered, fixed, company says
Yahoo says it has fixed a vulnerability in Yahoo Mail that might have allowed savvy hackers to steal a victim’s Yahoo identity and gain access to private information. Discovered by security vendor Cenzic last month, the underlying problem was a cross-site scripting (XSS) vulnerability that affected its current version of Yahoo Messenger and its new Yahoo Mail client Version 9, still in beta. Network World, 06/25/2008.
**********
Five new patches from Gentoo:
FreeType (integer overflow, code execution)
OpenSSL (denial of service flaws)
X.Org X server (multiple flaws)
**********
Four new fixes from Mandriva:
imlib2 (buffer overflows, code execution)
nasm (denial of service, code execution)
**********
Today’s malware news:
F-Secure reported two new Mac Trojans this week: Backdoor.Mac.Hovdy.a and Trojan-PSW:OSX/PokerStealer.A. The first one installs a program that takes advantage of a root access-flaw in the Mac ARDAgent module. The second is an application that tricks users into entering user credentials.
**********
From the interesting reading department:
Video: Dealing with security in an open network environment
What can corporate IT shops, which are faced with increasing pressure to allow mobile devices and more open access, learn from a university environment? Boston College’s David Escalante, director of computer policy and security, explains. Network World.
Audio-only version
Are smartphone viruses really a threat to your network?
From our 5 Burning Wireless Questions: All evidence points to the fact that smartphone viruses will be a threat to your network even though they aren’t at this moment. Network World, 06/23/2008.
Cleaning Chinese malware sites a ‘bigger challenge’ than in U.S., says researcher
More than half the sites spreading malicious code are hosted on Chinese networks, an anti-malware group said today.Of the over 213,000 malware-hosting sites analyzed last month by Stopbadware.org — a joint effort of researchers at Harvard University, Oxford University and several corporations, including Google Inc. and Sun Microsystems Inc. — 52% were hosted by servers running Chinese IP addresses. Of the top 10 networks serving malicious code, six are Chinese. Computerworld, 06/25/2008
The staff, the thief, the device and its data
Data being leeched from company databases by less secure mobile devices is a common occurrence, making data leakage the big technology issue of 2008. With the increasing use of mobile phones, PDAs and laptops as work tools, important company data is removed from the office every day. CIO, 06/24/2008.
Seven steps to disaster-recovery planning
Unpredictability is a fact of life. Whether terrorist attacks, cataclysmic weather or simply a backhoe severing a power cable, enterprises never know when their operations may be threatened. Network World, 06/25/2008.
Microsoft, HP ship tools to protect Web sites from hackers
Microsoft and HP on Tuesday unveiled free tools to help Web developers and site administrators defend against the rapidly growing number of SQL injection attacks that aim to hijack legitimate sites. Computerworld, 06/24/2008.
$1B market for meddling with DNS poses security problem
The interception of Internet traffic to snoop on phone calls or track surfers’ behavior is a hot topic — but what’s keeping members of ICANN’s Security and Stability Advisory Committee up at night is the interception of traffic to and from sites that don’t even exist. They explained why in a session at ICANN’s public meeting in Paris on Monday. IDG News Service, 06/24/2008.
CNET employees notified after data breach
More than 6,500 CNET Networks employees and relatives are being notified of a possible data breach after burglars stole computer systems from the offices of the company that administers the Internet publisher’s benefit plans. IDG News Service, 06/23/2008.
Most corporate networks vulnerable to cyberattacks
Eighty-one percent of corporate end points failed basic security checks in a wide ranging global survey by security solutions and services provider Sophos. Computerworld, 06/23/2008.




