* WinHex Virus? Here you go... * The do's and don'ts of data breaches, and other interesting reading
endif; ?>Today’s bug patches and security alerts:
Two new updates from Debian:
**********
Five new patches from rPath:
util-linux (authentication weakness)
squirrelmail (cross-scripting flaw)
evolution-data-server (multiple flaws)
SpamAssassin (denial of service)
**********
Six new fixes from Mandriva:
SpamAssassin (denial of service)
FreeType2 (integer overflow, code execution)
**********
Two new patches from Gentoo:
**********
Today’s malware news:
A few days ago someone sent us a new proof-of-concept virus. This time it was for WinHex, the powerful computer forensics, data recovery, and IT security tool. The virus prepends itself to all available .WHS (WinHex script) files. F-Secure blog, 06/15/07.
**********
From the interesting reading department:
The do’s and don’ts of data breaches
Believe it or not, a data breach isn’t the worst thing that could happen to your organization. Reacting poorly to the incident could be, however. Experts agree every organization that stores personal or financial information about customers, partners or employees, or that has intellectual property in electronic form should be considered a target — that’s arguably just about every organization doing business.
Online bank security worsens
Banks’ online security is getting worse as they rush to offer services online, according to new research. This year’s Annual Security Report from NTA Monitor, a security testing firm, found that 20% more security vulnerabilities turned up in the infrastructures of banks, building societies and other financial institutions compared with last year’s report. The survey covers networks, applications and systems. TechWorld, 06/14/07.




