* Patches from Red Hat, Mandrake Linux, others * Beware e-mail messages from "bill@microsoft.com" or "Dispatch@McAfee.com" * ISS hatches 'virtual patching' mgmt. plan, and other interesting reading Today’s bug patches and security alerts:Vulnerability in Yahoo Audio ConferencingAccording to an alert from Yahoo, “It may be possible for a remote attacker who can get a [Yahoo Audio Conferencing] user to view malicious html code, most likely executed by getting a user to visit their Web page, to cause the user to be involuntarily logged out of chat, crash the user’s browser, or potentially introduce executable code. To our knowledge, there have not been any executable code exploits related to this issue.” Users should upgrade to Version 1,0,0,45. For more, go to:https://messenger.yahoo.com/messenger/security **********Red Hat patches ghostscript Versions of ghostscript prior to 7.07A flaw in ghostscript, an interpreter for the PostScript language, could be exploited to run arbitrary commands on the affected machine. For more, go to:https://rhn.redhat.com/errata/RHSA-2003-181.html**********Microsoft revises two security bulletinsMicrosoft Wednesday updated security bulletins, fixing two recent software patches. The updates were for MS03-007, which was originally released in March, and MS03-013, originally released in April. MS03-007 patched a serious vulnerability in a common Windows component, “ntdll.dll.” The vulnerability, which affected a component used by the World Wide Web Distributed Authoring and Versioning (WebDAV) protocol, gave attackers the ability to remotely exploit vulnerable servers using specially formed HTTP requests. IDG News Service, 05/29/03. https://www.nwfusion.com/news/2003/0529microrevis.html**********Slackware, Mandrake Linux patch CUPS vulnerabilityA flaw in CUPS, a print spooler, for Linux and Unix could be exploited in a denial-of-service flaw against the affected machine. For more, go to: Slackware:https://www.slackware.com/security/viewer.php?l=slackware-security&y=2003&m=slackware-security.350709Mandrake Linux:https://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2003:062**********Today’s roundup of virus alerts:W32/Sobig-C – Another mass-mailing worm that also spreads via network shares. The e-mail version of the worm spreads via a message from “bill@microsoft.com“. (Sophos, Symantec)W32/Naco.B – A Trojan horse that could allow an attacker to open and close the CD-ROM drive door and switch mouse button functions (that’s annoying!). It also disables various security-related applications and send information about the infected machine to an e-mail address. (Panda Software)W32/Holar.H – A mass-mailer worm that spreads with a message from “Dispatch@McAfee.com.” Random subject lines and body texts are used. (Panda Software)W32/Auric – Another worm that disables antivirus applications and causes annoyances to the user, like making it difficult to move the mouse to a toolbar and changing colors of the various windows. (Panda Software)W32/Magold-A – Another nasty worm that spreads via all the usual channels and attempts to delete certain image file types. It also changes window colors and randomly opens the CD-ROM tray. (Sophos)JS/Fortnight-D – A JavaScript/Java Applet virus that spreads via e-mail and drops another Trojan horse app on it. (Sophos)**********From the interesting reading department:RSA Security teaming with Thor TechnologiesRSA Security and Thor Technologies Monday announced a partnership agreement under which the two will work closely to integrate their products. Jason Lewis, director of product management at RSA, said the goal is to integrate RSA’s ClearTrust authentication and access management software with Thor’s Xellerate provisioning software by the third quarter of this year. Under the agreement, RSA will be allowed to ship RSA ClearTrust with some of Thor’s basic provisioning capabilities, such as self-service, self-registration, resetting passwords and profile updates, Lewis said. Network World Fusion, 06/02/03.https://www.nwfusion.com/news/2003/0602rsathor.htmlDISA fortifying military’s IT defensesThe Defense Information Systems Agency, which provides the military with technical help on software and telecom projects around the world, is taking new steps to improve network security at bases and in the field. Network World, 06/02/03.https://www.nwfusion.com/news/2003/0602disa.htmlSourcefire ignites scanning effortIn a departure from developing intrusion-detection systems, Sourcefire this week divulged plans to build a network-discovery tool that will let users monitor system resources such as servers, desktop computers and applications. Network World, 06/02/03.https://www.nwfusion.com/news/2003/0602sourcefire.htmlISS hatches ‘virtual patching’ mgmt. planInternet Security Systems is readying technology it says could benefit companies fed up with current patch management techniques. Network World, 06/02/03.https://www.nwfusion.com/news/2003/0602iss.html Related content news analysis Cisco joins $10M funding round for Aviz Networks' enterprise SONiC drive Investment news follows a partnership between the vendors aimed at delivering an enterprise-grade SONiC offering for customers interested in the open-source network operating system. By Michael Cooney Dec 01, 2023 3 mins Network Management Software Industry Networking news Cisco CCNA and AWS cloud networking rank among highest paying IT certifications Cloud expertise and security know-how remain critical in building today’s networks, and these skills pay top dollar, according to Skillsoft’s annual ranking of the most valuable IT certifications. Demand for talent continues to outweigh s By Denise Dubie Nov 30, 2023 7 mins Certifications Network Security Networking news Mainframe modernization gets a boost from Kyndryl, AWS collaboration Kyndryl and AWS have expanded their partnership to help enterprise customers simplify and accelerate their mainframe modernization initiatives. By Michael Cooney Nov 30, 2023 4 mins Mainframes Cloud Computing Data Center news AWS and Nvidia partner on Project Ceiba, a GPU-powered AI supercomputer The companies are extending their AI partnership, and one key initiative is a supercomputer that will be integrated with AWS services and used by Nvidia’s own R&D teams. By Andy Patrizio Nov 30, 2023 3 mins CPUs and Processors Generative AI Supercomputers Podcasts Videos Resources Events NEWSLETTERS Newsletter Promo Module Test Description for newsletter promo module. Please enter a valid email address Subscribe