December Patch Tuesday Summary

This month, Microsoft has released eight security bulletins addressing six critical and two important vulnerabilities.

MS08-070 Vulnerabilities in Visual Basic 6.0 Runtime Extended Files (ActiveX Controls) Could Allow Remote Code Execution MS08-071 Vulnerabilities in GDI Could Allow Remote Code Execution MS08-072 Vulnerabilities in Microsoft Office Word Could Allow Remote Code Execution MS08-073 Cumulative Security [...]

Window Snyder leaves Mozilla

Mozilla security chief Window Snyder is leaving the open-source group. Snyder, who joined Mozilla after stints at Microsoft and Matasano Security, announced her exit on the Mozilla security blog today. Snyder writes: I will be leaving Mozilla at the end of the year.  I am sad to be leaving, but I am excited to [...]

Gmail, Yahoo and Hotmail systematically abused by spammers

With the industry’s eyes constantly monitoring the usual suspects’ use of phony hosting providers, another market segment within the underground marketplace has been developing beneath the radar, aiming to build a malicious infrastructure (Spammers targeting Bebo, generate thousands of bogus accounts; Malware and spam attacks exploiting Picasa and ImageShack) through efficient CAPTCHA recognition. The [...]

DNS Changer Malware Evolves – Again

A new DNS changing malware with a twist was recently found by researchers. A new DNS Changer Trojan uses a new method to poison other hosts on the local subnet installing a rogue Dynamic Host Configuration Protocol (DHCP) server on the network. DHCP is a protocol used to disseminate required information to network clients in [...]

Vint Cerf’s Twitter account hacked, suspended for spam

(UPDATE: Cerf denies that this was his Twitter profile) It appears that Vint Cerf, the father of Internet who needs no introduction, has had his Twitter account compromised, with a multitude of spam messages posted on his behalf during the last 24 hours, all of which are redirecting to auction search sites (baysearch .net and [...]