PowerPoint gets a virus
Microsoft last week warned about a virus that could exploit a vulnerability in its PowerPoint presentation software. The virus is carried out when a user launches a PowerPoint attachment to an e-mail or opens a file provided by an attacker. Hackers could lure users to a Web page that offers content or advertisements containing a file that exploits the PowerPoint software, Microsoft said. The vulnerability applies to PowerPoint 2000, 2002 and 2003. Once the user triggers the corrupt PowerPoint file, the virus installs a keystroke logging system to capture everything typed on the machine. It also leaves the machine open to having a hacker install other malicious programs. Microsoft said it was completing development of a security update to fix the vulnerability and was on schedule to release the patch by Aug. 8.
A federal judge last week denied motions by the U.S. government and AT&T to stop a lawsuit over alleged participation by the carrier in an illegal wiretapping program by the National Security Agency. Judge Vaughn Walker of the U.S. District Court for the Northern District of California denied the government’s motion for dismissal of the case or summary judgment on the basis that the case involved state secrets. He also denied AT&T’s motion to have the case dismissed. The civil liberties group Electronic Frontier Foundation sued AT&T in January on behalf of the carrier’s customers, alleging it diverts traffic from its fiber-optic lines to the NSA as part of an illegal antiterrorist surveillance program. The suit, one of several in the works, followed press reports last year about major carriers providing data for broad domestic spying initiatives. The case still could be halted. In his decision, Judge Walker allowed the parties to make an instant appeal to a higher court, a move that could lead to all or part of the case being stayed.
A consortium consisting of researchers from Japan and Europe is using balloons, airships and unmanned solar-powered planes to relay wireless and optical communications in a project called Capanina. The three-year project, led by the University of York in England, is designed to bring low-cost broadband connections to remote areas and possibly to high-speed trains. Disaster management is another possible application. The researchers boast that the technology could provide data rates 100 times faster than asymmetric DSL.
Hackers are striking databases in record numbers, trying to pilfer a rich trove of personal and financial data. Managed security provider SecureWorks says it is detecting as many as 8,000 attacks per day on databases owned by its clients, up from an average of 100 to 200 attacks per day in the first three months of this year. The statistics come from data on its 1,300 clients, including financial institutions and utilities, most of which are in the United States. SecureWorks has detected hackers working from computers in Russia, China, Brazil, Hungary and Korea. They are using a method known as a SQL injection attack, the company says. Visa and MasterCard are rewriting security rules for merchants that accept credit card payments to better guard against attacks, such as SQL injection.
Oracle has issued 65 fixes for a wide range of software products as part of its quarterly security release, called the Critical Patch Update. The patches address problems in the company’s database, application server and e-business suite products, among others, according to Oracle. Some of the patches are also designed for client software that works with Oracle’s databases. More information on the patches can be found at www.nwdocfinder. com/4448. Oracle’s next Critical Patch Update is scheduled for Oct. 17.
IBM last week won a 10-year contract to handle the human-resources department of drugstore chain CVS. Financial terms of the deal were not disclosed, but it is thought to be worth several hundred million dollars. IBM will take over payroll processing, benefit administration, employee intranet portals and other functions for CVS, whose workforce has grown to 170,000 through acquisitions in the past couple years. Big Blue said the CVS contract is one of its biggest such outsourcing contracts in recent years and its largest in the retail industry.




