<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://msmvps.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>DP's Security Bits : News</title><link>http://msmvps.com/blogs/donpatterson/archive/tags/News/default.aspx</link><description>Tags: News</description><dc:language>en</dc:language><generator>CommunityServer 2008.5 SP2 (Build: 40407.4157)</generator><item><title>DDoS Attack Briefly Interrupts Online Holiday Shopping</title><link>http://msmvps.com/blogs/donpatterson/archive/2009/12/29/ddos-attack-briefly-interrupts-online-holiday-shopping.aspx</link><pubDate>Tue, 29 Dec 2009 18:07:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1748153</guid><dc:creator>Don</dc:creator><slash:comments>0</slash:comments><description>&lt;p&gt;A distributed denial-of-service (DDoS)
attack on a major DNS service provider caused a brief hiccup in online
shopping last week at some of the Web&amp;#39;s biggest online destinations.
&lt;/p&gt;
&lt;p&gt;UltraDNS, which counts such giants as Amazon and Wal-Mart among
its customers, was DDoS&amp;#39;d after business hours on Dec. 23, according to
&lt;a href="http://status.aws.amazon.com/" target="new"&gt;Amazon Web Services&lt;/a&gt; and other reports from victims and news outlets.
&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.darkreading.com/security/attacks/showArticle.jhtml?articleID=222100176"&gt;Story&lt;/a&gt; continues at darkreading.com&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1748153" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/donpatterson/archive/tags/News/default.aspx">News</category></item><item><title>How The Koobface Worm Gang Makes Money </title><link>http://msmvps.com/blogs/donpatterson/archive/2009/12/22/how-the-koobface-worm-gang-makes-money.aspx</link><pubDate>Tue, 22 Dec 2009 12:47:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1747180</guid><dc:creator>Don</dc:creator><slash:comments>0</slash:comments><description>&lt;p&gt;Chances are you know someone who has been
hit by Koobface, one of the first successful social networking worms.
But there are many faces to Koobface, and many ways its authors make
money from it.
&lt;/p&gt;
&lt;p&gt;New research from Trend Micro details how Koobface&amp;#39;s creators
monetize the worm through scareware or fake antivirus, click fraud,
information-stealing malware, and online dating services. &amp;quot;Unlike in
the past when we always thought of malware as one piece of malware,
like Melissa or Lovebug, in today&amp;#39;s world Koobface is an ongoing
criminal enterprise using hundreds and thousands of pieces of code,&amp;quot;
says David Perry, global director of education for Trend Micro. &amp;quot;That
makes it more difficult to describe to the public at large. It&amp;#39;s not
just one file.&amp;quot;
&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.darkreading.com/vulnerability_management/security/attacks/showArticle.jhtml?articleID=222002862"&gt;Continues&lt;/a&gt; at darkreading.com&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1747180" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/donpatterson/archive/tags/News/default.aspx">News</category></item><item><title>Lab Test Results: Symantec, Kaspersky Lab, PC Tools, AVG, Detect The Most Zero-Day Attacks</title><link>http://msmvps.com/blogs/donpatterson/archive/2009/12/18/lab-test-results-symantec-kaspersky-lab-pc-tools-avg-detect-the-most-zero-day-attacks.aspx</link><pubDate>Fri, 18 Dec 2009 11:02:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1746377</guid><dc:creator>Don</dc:creator><slash:comments>0</slash:comments><description>&lt;p&gt;Top Internet security suite products scored
high when detecting zero-day attacks during a three-month period,
according to new data released today from independent German lab
AV-Test, with Symantec and Kaspersky Lab finding 98 and 97.5 percent,
respectively.
&lt;/p&gt;
&lt;p&gt;AV-Test tested 10 zero-day threats during a three-month period
on Windows XP SP3 machines running Symantec Norton Internet Security
2010, Kaspersky Internet Security 2010, PC Tools Internet Security
2010, AVG Internet Security 9.0, G Data Internet Security 2010, Panda
Internet Security 2010, Avira Premium Security Suite 9.0, McAfee
Internet Security 2010, CA Internet Security 2010, F-Secure Internet
Security 2010, BitDefender Internet Security 2010, and Trend Micro
Internet Security 2010.
&lt;/p&gt;
&lt;p&gt;AVG caught 92.2 percent of the threats, followed by G Data, 90
percent; Panda, 90 percent; Avira, 87.7 percent; McAfee, 87.2 percent;
CA, 86.7 percent; F-Secure, 85.8 percent; BitDefender, 84.3 percent;
and Trend Micro, 83.3 percent. &lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.darkreading.com/security/antivirus/showArticle.jhtml?articleID=222002625"&gt;Story continues at darkreading.com&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1746377" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/donpatterson/archive/tags/News/default.aspx">News</category></item><item><title>Mozilla Releases Firefox 3.5.6</title><link>http://msmvps.com/blogs/donpatterson/archive/2009/12/16/mozilla-releases-firefox-3-5-6.aspx</link><pubDate>Wed, 16 Dec 2009 13:13:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1745944</guid><dc:creator>Don</dc:creator><slash:comments>0</slash:comments><description>&lt;p&gt;Get it at &lt;a href="http://www.mozilla.com/en-US/firefox/all.html"&gt;http://www.mozilla.com/en-US/firefox/all.html&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;What&amp;rsquo;s New in Firefox 3.5.6&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;Firefox 3.5.6 fixes the following issues:&lt;/p&gt;
&lt;ul&gt;
&amp;bull; Fixed several security issues.&lt;br /&gt; &amp;bull; Fixed several stability issues.
&lt;/ul&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1745944" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/donpatterson/archive/tags/News/default.aspx">News</category></item><item><title>Adobe Reader and Acrobat Remote Code Execution Vulnerability</title><link>http://msmvps.com/blogs/donpatterson/archive/2009/12/15/adobe-reader-and-acrobat-remote-code-execution-vulnerability.aspx</link><pubDate>Tue, 15 Dec 2009 23:11:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1745835</guid><dc:creator>Don</dc:creator><slash:comments>0</slash:comments><description>&lt;p&gt;&lt;span style="font-family:Arial,Geneva,Helvetica;"&gt; &lt;a href="http://www.us-cert.gov/current/index.html#adobe_reader_and_acrobat_remote"&gt;US_CERT Reports:&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-family:Arial,Geneva,Helvetica;"&gt;Adobe has stated that they
are investigating public reports of a vulnerability affecting Adobe
Reader and Acrobat. Public reports indicate that exploitation of this
vulnerability may occur when a user opens a specially crafted PDF file.
Exploitation of this vulnerability may result in arbitrary code
execution. Public reports currently indicate active exploitation of
this vulnerability.&lt;br /&gt;&lt;br /&gt;US-CERT
encourages users and administrators to do the following to help
mitigate the risks until the vendor is able to provide an update:&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;span style="font-family:Arial,Geneva,Helvetica;"&gt;
&lt;li&gt;Review the Adobe &lt;a href="http://blogs.adobe.com/psirt/2009/12/new_adobe_reader_and_acrobat_v.html" target="_self"&gt;blog entry&lt;/a&gt; regarding this issue.&lt;/li&gt;
&lt;li&gt;Use caution when opening PDF files from untrusted sources.&lt;/li&gt;
&lt;li&gt;Disable
JavaScript in Adobe Acrobat and Reader. To do this, click &amp;quot;Edit,&amp;quot; then
&amp;quot;Preferences&amp;quot; and then &amp;quot;JavaScript,&amp;quot; and uncheck &amp;quot;Enable Acrobat
JavaScript.&amp;quot;&lt;/li&gt;
&lt;/span&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;span style="font-family:Arial,Geneva,Helvetica;"&gt;US-CERT will provide additional information as it becomes available.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-family:Arial,Geneva,Helvetica;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1745835" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/donpatterson/archive/tags/News/default.aspx">News</category></item><item><title>SQL attacks take off in last year</title><link>http://msmvps.com/blogs/donpatterson/archive/2009/12/15/sql-attacks-take-off-in-last-year.aspx</link><pubDate>Tue, 15 Dec 2009 13:02:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1745703</guid><dc:creator>Don</dc:creator><slash:comments>0</slash:comments><description>&lt;p&gt;&lt;span class="body"&gt;
&lt;p&gt;
Online attacks against databases have taken off in the past 18 months,
according to data released by IBM&amp;rsquo;s X-Force security team.&lt;/p&gt;
&lt;p&gt;
In May 2008, IBM&amp;rsquo;s customers encounters about 2,500 SQL injection
attacks every day. By midsummer 2009, the technology giant&amp;rsquo;s product
were seeing 600,000 database attacks per day on average, said Tom
Cross, a security researcher at IBM. The attacks attempt to inject
legitimate structured query language (SQL) commands into whichever
database software runs a particular Web site.&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.securityfocus.com/brief/1048"&gt;http://www.securityfocus.com/brief/1048&lt;/a&gt;&lt;/p&gt;
&lt;/span&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1745703" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/donpatterson/archive/tags/News/default.aspx">News</category></item><item><title>TechNet Webcast: Information About Microsoft December Security Bulletins</title><link>http://msmvps.com/blogs/donpatterson/archive/2009/12/08/technet-webcast-information-about-microsoft-december-security-bulletins.aspx</link><pubDate>Tue, 08 Dec 2009 18:55:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1744296</guid><dc:creator>Don</dc:creator><slash:comments>0</slash:comments><description>&lt;table border="0" cellpadding="0" cellspacing="0" width="90%"&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td class="EventInfo" style="width:18%;" valign="top"&gt;&lt;span id="eventInfo_lblEvntLangDisplay"&gt;&lt;b&gt;Language(s):&lt;/b&gt;&lt;/span&gt;
        &lt;/td&gt;
&lt;td class="EventInfo"&gt;
            &lt;span id="eventInfo_lblLanguage"&gt;English.&lt;/span&gt;
        &lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td class="EventInfo" valign="top"&gt;
            &lt;span id="eventInfo_lblFeaturedProductsTitle"&gt;&lt;b&gt;Product(s):&lt;/b&gt;&lt;/span&gt;
        &lt;/td&gt;
&lt;td class="EventInfo"&gt;
            &lt;span id="eventInfo_lblFeaturedProducts"&gt; Security.&lt;/span&gt;
        &lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td class="EventInfo" valign="top"&gt;
            &lt;span id="eventInfo_lblTargetAudiencesTitle"&gt;&lt;b&gt;Audience(s): &lt;/b&gt;&lt;/span&gt;
        &lt;/td&gt;
&lt;td class="EventInfo"&gt;
            &lt;span id="eventInfo_lblTargetAudiences"&gt; IT Generalist.&lt;/span&gt;
        &lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td class="EventInfo" valign="top"&gt;
            
        &lt;/td&gt;
&lt;td class="EventInfo"&gt;
            
        &lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td class="EventInfo" valign="top"&gt;
            
        &lt;/td&gt;
&lt;td class="EventInfo"&gt;
            
        &lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td class="EventInfo" valign="top"&gt;
            &lt;span id="eventInfo_lblEventDurationTitle"&gt;&lt;b&gt;Duration:&lt;/b&gt;&lt;/span&gt;
        &lt;/td&gt;
&lt;td class="EventInfo"&gt;
            &lt;span id="eventInfo_lblEventDuration"&gt;90 Minutes&lt;/span&gt;
        &lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td class="EventInfo" valign="top"&gt;
            &lt;span id="eventInfo_lblStartDate"&gt;
            &lt;b&gt;Start Date:&lt;/b&gt;
            &lt;/span&gt;
        &lt;/td&gt;
&lt;td class="EventInfo"&gt;
&lt;div id="eventInfo_StartDatePanel"&gt;
	
                &lt;span id="eventInfo_lblStDate"&gt;Wednesday, December 09, 2009 11:00 AM Pacific Time (US &amp;amp; Canada)&lt;/span&gt;
            
&lt;/div&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td colspan="2"&gt;
            &amp;nbsp;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td class="EventInfo" colspan="2"&gt;
            
        &lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td colspan="2" class="eventInfo"&gt;
            &lt;br /&gt;
            &lt;b&gt;&lt;span id="eventInfo_lblEventDescHeading"&gt;Event Overview&lt;/span&gt;&lt;/b&gt;
        &lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td colspan="2"&gt;
&lt;div class="eventdetails"&gt;
&lt;p&gt;&lt;span id="eventInfo_lblEventDescription"&gt;
&lt;p&gt;&lt;span style="font-family:verdana;"&gt;Join
us for a brief overview of the technical details of the December
security bulletins. We intend to address your concerns in this webcast,
therefore, most of the webcast is devoted to attendees asking questions
about the bulletins and getting answers from Microsoft security experts.&lt;/span&gt;&lt;/p&gt;
&lt;span style="font-family:verdana;"&gt;&lt;span style="font-family:verdana;"&gt;
&lt;p&gt;&lt;b&gt;Presenters:&lt;/b&gt; Jerry Bryant, Senior Security Program
Manager Lead, Microsoft Corporation and Adrian Stone, Senior Security
Program Manager Lead, Microsoft Corporation&lt;/p&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;&lt;a href="http://msevents.microsoft.com/CUI/WebCastEventDetails.aspx?EventID=1032407802&amp;amp;EventCategory=4&amp;amp;culture=en-US&amp;amp;CountryCode=US"&gt;Register Online&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1744296" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/donpatterson/archive/tags/News/default.aspx">News</category></item><item><title>Microsoft warns of IE exploit code in the wild</title><link>http://msmvps.com/blogs/donpatterson/archive/2009/11/23/microsoft-warns-of-ie-exploit-code-in-the-wild.aspx</link><pubDate>Mon, 23 Nov 2009 20:56:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1741815</guid><dc:creator>Don</dc:creator><slash:comments>0</slash:comments><description>&lt;p&gt;Microsoft on Monday said it is investigating a possible vulnerability
in Internet Explorer after exploit code that allegedly can be used to
take control of computers, if they visit a Web site hosting the code,
was posted to a security mailing list.&lt;/p&gt;
&lt;p&gt;Microsoft confirmed that the exploit code affects IE 6 and IE 7, but not
&lt;a href="http://download.cnet.com/Internet-Explorer/3000-2356_4-10013275.html"&gt;IE 8&lt;/a&gt;,
and it said it is &amp;quot;currently unaware of any attacks trying to use the
claimed vulnerability or of customer impact,&amp;quot; according to a statement.&lt;/p&gt;
&lt;p&gt;&lt;a href="http://news.cnet.com/8301-27080_3-10403756-245.html"&gt;CNet News&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1741815" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/donpatterson/archive/tags/News/default.aspx">News</category></item><item><title>Facebook beats the 'spam king'</title><link>http://msmvps.com/blogs/donpatterson/archive/2009/11/18/facebook-beats-the-spam-king.aspx</link><pubDate>Wed, 18 Nov 2009 16:50:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1740509</guid><dc:creator>Don</dc:creator><slash:comments>0</slash:comments><description>&lt;p&gt;&lt;b&gt;Facebook was awarded $711m in a judgement on Thursday against self-described &amp;#39;spam king&amp;#39; Sanford Wallace.&lt;/b&gt;
&lt;/p&gt;
&lt;p&gt;
Judge Jeremy Fogel of the US District Court of the Northern District of
California granted Facebook&amp;#39;s application for a default judgement
against Wallace for violating the Can-Spam Act, which bans &amp;quot;false and
misleading&amp;quot; marketing emails. Fogel also found that Wallace &amp;quot;wilfully
violated&amp;quot; a temporary restraining order and preliminary injunction
issued in the case and referred the matter to the US Attorney&amp;#39;s Office
for prosecution of criminal contempt.
&lt;/p&gt;
&lt;p&gt;&amp;quot;The record demonstrates that Wallace wilfully violated the
statutes in question with blatant disregard for the rights of Facebook
and the thousands of Facebook users whose accounts were compromised by
his conduct,&amp;quot; Fogel wrote in his judgement order, which also
permanently prohibits Wallace from accessing the Facebook website or
creating a Facebook account, among other restrictions.
&lt;/p&gt;
&lt;p&gt;
For more, read &amp;quot;&lt;a href="http://news.cnet.com/8301-1023_3-10387021-93.html"&gt;Facebook awarded $711 million in spam lawsuit&lt;/a&gt; on CNET News.

			&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1740509" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/donpatterson/archive/tags/News/default.aspx">News</category></item><item><title>Apple Releases Safari 4.0.4</title><link>http://msmvps.com/blogs/donpatterson/archive/2009/11/13/apple-releases-safari-4-0-4.aspx</link><pubDate>Fri, 13 Nov 2009 10:05:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1739473</guid><dc:creator>Don</dc:creator><slash:comments>0</slash:comments><description>&lt;p&gt;&lt;span style="font-family:Arial,Geneva,Helvetica;"&gt; Apple has released Safari
4.0.4 to address multiple vulnerabilities in a number of components.
Exploitation of these vulnerabilities may allow an attacker to execute
arbitrary code, cause a denial-of-service condition, conduct cross-site
request forgery, or obtain sensitive information. These vulnerabilities
affect Safari running on both the Mac OS X and Windows platforms.&lt;br /&gt;&lt;br /&gt;US-CERT encourages users and administrators to review Apple article &lt;a href="http://support.apple.com/kb/HT3949" target="_self"&gt;HT3949&lt;/a&gt; and upgrade to Safari 4.0.4 to help mitigate the risks.

  &lt;/span&gt;&lt;/p&gt;

&lt;p&gt;
&lt;span style="font-family:Arial,Geneva,Helvetica;"&gt;&lt;a href="http://www.us-cert.gov/current/index.html#apple_releases_safari_4_03"&gt;http://www.us-cert.gov/current/index.html#apple_releases_safari_4_03&lt;/a&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1739473" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/donpatterson/archive/tags/News/default.aspx">News</category></item><item><title>TechNet Webcast: Information About Microsoft November Security Bulletins</title><link>http://msmvps.com/blogs/donpatterson/archive/2009/11/10/technet-webcast-information-about-microsoft-november-security-bulletins.aspx</link><pubDate>Tue, 10 Nov 2009 18:04:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1738837</guid><dc:creator>Don</dc:creator><slash:comments>0</slash:comments><description>&lt;table border="0" cellpadding="0" cellspacing="0" width="90%"&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td class="EventInfo" style="width:18%;" valign="top"&gt;&lt;span id="eventInfo_lblEvntLangDisplay"&gt;&lt;b&gt;Language(s):&lt;/b&gt;&lt;/span&gt;
        &lt;/td&gt;
&lt;td class="EventInfo"&gt;
            &lt;span id="eventInfo_lblLanguage"&gt;English.&lt;/span&gt;
        &lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td class="EventInfo" valign="top"&gt;
            &lt;span id="eventInfo_lblFeaturedProductsTitle"&gt;&lt;b&gt;Product(s):&lt;/b&gt;&lt;/span&gt;
        &lt;/td&gt;
&lt;td class="EventInfo"&gt;
            &lt;span id="eventInfo_lblFeaturedProducts"&gt; Security.&lt;/span&gt;
        &lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td class="EventInfo" valign="top"&gt;
            &lt;span id="eventInfo_lblTargetAudiencesTitle"&gt;&lt;b&gt;Audience(s): &lt;/b&gt;&lt;/span&gt;
        &lt;/td&gt;
&lt;td class="EventInfo"&gt;
            &lt;span id="eventInfo_lblTargetAudiences"&gt; IT Generalist.&lt;/span&gt;
        &lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td class="EventInfo" valign="top"&gt;
            
        &lt;/td&gt;
&lt;td class="EventInfo"&gt;
            
        &lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td class="EventInfo" valign="top"&gt;
            
        &lt;/td&gt;
&lt;td class="EventInfo"&gt;
            
        &lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td class="EventInfo" valign="top"&gt;
            &lt;span id="eventInfo_lblEventDurationTitle"&gt;&lt;b&gt;Duration:&lt;/b&gt;&lt;/span&gt;
        &lt;/td&gt;
&lt;td class="EventInfo"&gt;
            &lt;span id="eventInfo_lblEventDuration"&gt;90 Minutes&lt;/span&gt;
        &lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td class="EventInfo" valign="top"&gt;
            &lt;span id="eventInfo_lblStartDate"&gt;
            &lt;b&gt;Start Date:&lt;/b&gt;
            &lt;/span&gt;
        &lt;/td&gt;
&lt;td class="EventInfo"&gt;
&lt;div id="eventInfo_StartDatePanel"&gt;
	
                &lt;span id="eventInfo_lblStDate"&gt;Wednesday, November 11, 2009 11:00 AM Pacific Time (US &amp;amp; Canada)&lt;/span&gt;
            
&lt;/div&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td colspan="2"&gt;
            &amp;nbsp;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td class="EventInfo" colspan="2"&gt;
            
        &lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td colspan="2" class="eventInfo"&gt;
            &lt;br /&gt;
            &lt;b&gt;&lt;span id="eventInfo_lblEventDescHeading"&gt;Event Overview&lt;/span&gt;&lt;/b&gt;
        &lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td colspan="2"&gt;
&lt;div class="eventdetails"&gt;
&lt;p&gt;&lt;span id="eventInfo_lblEventDescription"&gt;
&lt;p&gt;&lt;span style="font-family:verdana;"&gt;On
November 11, 2009, Microsoft releases its monthly security bulletins.
Join us for a brief overview of the technical details of the November
security bulletins. We intend to address your concerns in this webcast,
therefore, most of the webcast is devoted to attendees asking questions
about the bulletins and getting answers from Microsoft security experts.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-family:verdana;"&gt;&lt;b&gt;Presenters:&lt;/b&gt;
Jerry Bryant, Senior Security Program Manager Lead, Microsoft
Corporation and Adrian Stone, Senior Security Program Manager Lead,
Microsoft Corporation&lt;/span&gt;&lt;/p&gt;
&lt;/span&gt;&lt;/p&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;&lt;a href="http://msevents.microsoft.com/CUI/WebCastEventDetails.aspx?EventID=1032407490&amp;amp;EventCategory=4&amp;amp;culture=en-US&amp;amp;CountryCode=US"&gt;Register Online&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1738837" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/donpatterson/archive/tags/News/default.aspx">News</category></item><item><title>Mozilla Firefox 3.5.5 Released</title><link>http://msmvps.com/blogs/donpatterson/archive/2009/11/06/mozilla-firefox-3-5-5-released.aspx</link><pubDate>Fri, 06 Nov 2009 10:00:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1737974</guid><dc:creator>Don</dc:creator><slash:comments>0</slash:comments><description>&lt;p&gt;&lt;em&gt;v.3.5.5, released November 5th, 2009&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="https://bugzilla.mozilla.org/buglist.cgi?quicksearch=ALL%20status1.9.1%3A.5-fixed"&gt;Fixes in this version&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1737974" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/donpatterson/archive/tags/News/default.aspx">News</category></item><item><title>Sun Releases JRE Update v1.6.0_17 - November 3, 2009</title><link>http://msmvps.com/blogs/donpatterson/archive/2009/11/03/sun-releases-jre-update-v1-6-0-17-november-3-2009.aspx</link><pubDate>Tue, 03 Nov 2009 22:55:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1737445</guid><dc:creator>Don</dc:creator><slash:comments>0</slash:comments><description>&lt;p&gt;Available at: &amp;raquo;&lt;a href="http://java.sun.com/javase/downloads/index.jsp"&gt;java.sun.com/javase/downloads/index.jsp&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Release notes: &amp;raquo;&lt;a href="http://java.sun.com/javase/6/webnotes/ReleaseNotes.html"&gt;java.sun.com/javase/6/webnotes/R&amp;middot;&amp;middot;&amp;middot;tes.html&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1737445" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/donpatterson/archive/tags/News/default.aspx">News</category></item><item><title>Microsoft Security Intelligence Report (SIR)</title><link>http://msmvps.com/blogs/donpatterson/archive/2009/11/02/microsoft-security-intelligence-report-sir.aspx</link><pubDate>Mon, 02 Nov 2009 19:06:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1737132</guid><dc:creator>Don</dc:creator><slash:comments>0</slash:comments><description>&lt;p&gt;The Microsoft Security Intelligence Report (SIR) provides an in-depth
perspective on the changing threat landscape including software
vulnerability disclosures and exploits, malicious software (malware),
and potentially unwanted software. Using data derived from hundreds of
millions of Windows computers, and some of the busiest online services
on the Internet, this report also provides a detailed analysis of the
threat landscape and the changing face of threats and countermeasures
and includes updated data on privacy and breach notifications. &lt;b&gt;The seventh volume of the report is now available:&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.microsoft.com/security/portal/Threat/SIR.aspx"&gt;http://www.microsoft.com/security/portal/Threat/SIR.aspx&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1737132" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/donpatterson/archive/tags/News/default.aspx">News</category></item><item><title>Mozilla Releases Firefox 3.5.4</title><link>http://msmvps.com/blogs/donpatterson/archive/2009/10/28/mozilla-releases-firefox-3-5-4.aspx</link><pubDate>Wed, 28 Oct 2009 09:20:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1735791</guid><dc:creator>Don</dc:creator><slash:comments>0</slash:comments><description>&lt;p&gt;Firefox 3.5.4 is &lt;a href="http://www.mozilla.com/en-US/"&gt;available for download&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.mozilla.org/security/known-vulnerabilities/firefox35.html"&gt;Fixed in Firefox 3.5.4&lt;/a&gt;:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.mozilla.org/security/announce/2009/mfsa2009-64.html"&gt;MFSA 2009-64&lt;/a&gt; Crashes with evidence of memory corruption (rv:1.9.1.4/ 1.9.0.15)&lt;br /&gt;&lt;a href="http://www.mozilla.org/security/announce/2009/mfsa2009-63.html"&gt;MFSA 2009-63&lt;/a&gt; Upgrade media libraries to fix memory safety bugs&lt;br /&gt;&lt;a href="http://www.mozilla.org/security/announce/2009/mfsa2009-62.html"&gt;MFSA 2009-62&lt;/a&gt; Download filename spoofing with RTL override&lt;br /&gt;&lt;a href="http://www.mozilla.org/security/announce/2009/mfsa2009-61.html"&gt;MFSA 2009-61&lt;/a&gt; Cross-origin data theft through document.getSelection()&lt;br /&gt;&lt;a href="http://www.mozilla.org/security/announce/2009/mfsa2009-59.html"&gt;MFSA 2009-59&lt;/a&gt; Heap buffer overflow in string to number conversion&lt;br /&gt;&lt;a href="http://www.mozilla.org/security/announce/2009/mfsa2009-57.html"&gt;MFSA 2009-57&lt;/a&gt; Chrome privilege escalation in XPCVariant::VariantDataToJS()&lt;br /&gt;&lt;a href="http://www.mozilla.org/security/announce/2009/mfsa2009-56.html"&gt;MFSA 2009-56&lt;/a&gt; Heap buffer overflow in GIF color map parser&lt;br /&gt;&lt;a href="http://www.mozilla.org/security/announce/2009/mfsa2009-55.html"&gt;MFSA 2009-55&lt;/a&gt; Crash in proxy auto-configuration regexp parsing&lt;br /&gt;&lt;a href="http://www.mozilla.org/security/announce/2009/mfsa2009-54.html"&gt;MFSA 2009-54&lt;/a&gt; Crash with recursive web-worker calls&lt;br /&gt;&lt;a href="http://www.mozilla.org/security/announce/2009/mfsa2009-53.html"&gt;MFSA 2009-53&lt;/a&gt; Local downloaded file tampering&lt;br /&gt;&lt;a href="http://www.mozilla.org/security/announce/2009/mfsa2009-52.html"&gt;MFSA 2009-52&lt;/a&gt; Form history vulnerable to stealing&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1735791" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/donpatterson/archive/tags/News/default.aspx">News</category></item><item><title>TechNet Webcast: Information About Microsoft October Security Bulletins</title><link>http://msmvps.com/blogs/donpatterson/archive/2009/10/13/technet-webcast-information-about-microsoft-october-security-bulletins.aspx</link><pubDate>Tue, 13 Oct 2009 17:52:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1732175</guid><dc:creator>Don</dc:creator><slash:comments>0</slash:comments><description>&lt;table border="0" cellpadding="0" cellspacing="0" width="90%"&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td class="EventInfo" style="width:18%;" valign="top"&gt;&lt;span id="eventInfo_lblEvntLangDisplay"&gt;&lt;b&gt;Language(s):&lt;/b&gt;&lt;/span&gt;
        &lt;/td&gt;
&lt;td class="EventInfo"&gt;
            &lt;span id="eventInfo_lblLanguage"&gt;English.&lt;/span&gt;
        &lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td class="EventInfo" valign="top"&gt;
            &lt;span id="eventInfo_lblFeaturedProductsTitle"&gt;&lt;b&gt;Product(s):&lt;/b&gt;&lt;/span&gt;
        &lt;/td&gt;
&lt;td class="EventInfo"&gt;
            &lt;span id="eventInfo_lblFeaturedProducts"&gt; Security.&lt;/span&gt;
        &lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td class="EventInfo" valign="top"&gt;
            &lt;span id="eventInfo_lblTargetAudiencesTitle"&gt;&lt;b&gt;Audience(s): &lt;/b&gt;&lt;/span&gt;
        &lt;/td&gt;
&lt;td class="EventInfo"&gt;
            &lt;span id="eventInfo_lblTargetAudiences"&gt; IT Generalist.&lt;/span&gt;
        &lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td class="EventInfo" valign="top"&gt;
            
        &lt;/td&gt;
&lt;td class="EventInfo"&gt;
            
        &lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td class="EventInfo" valign="top"&gt;
            
        &lt;/td&gt;
&lt;td class="EventInfo"&gt;
            
        &lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td class="EventInfo" valign="top"&gt;
            &lt;span id="eventInfo_lblEventDurationTitle"&gt;&lt;b&gt;Duration:&lt;/b&gt;&lt;/span&gt;
        &lt;/td&gt;
&lt;td class="EventInfo"&gt;
            &lt;span id="eventInfo_lblEventDuration"&gt;90 Minutes&lt;/span&gt;
        &lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td class="EventInfo" valign="top"&gt;
            &lt;span id="eventInfo_lblStartDate"&gt;
            &lt;b&gt;Start Date:&lt;/b&gt;
            &lt;/span&gt;
        &lt;/td&gt;
&lt;td class="EventInfo"&gt;
&lt;div id="eventInfo_StartDatePanel"&gt;
	
                &lt;span id="eventInfo_lblStDate"&gt;Wednesday, October 14, 2009 11:00 AM Pacific Time (US &amp;amp; Canada)&lt;/span&gt;
            
&lt;/div&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td colspan="2"&gt;
            &amp;nbsp;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td class="EventInfo" colspan="2"&gt;
            
        &lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td colspan="2" class="eventInfo"&gt;
            &lt;br /&gt;
            &lt;b&gt;&lt;span id="eventInfo_lblEventDescHeading"&gt;Event Overview&lt;/span&gt;&lt;/b&gt;
        &lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td colspan="2"&gt;
&lt;div class="eventdetails"&gt;
&lt;p&gt;&lt;span id="eventInfo_lblEventDescription"&gt;
&lt;p&gt;&lt;span style="font-family:Verdana;"&gt;&lt;span style="font-family:Verdana;"&gt;On
October 14, 2009, Microsoft releases its monthly security bulletins.
Join us for a brief overview of the technical details of the October
security bulletins. We intend to address your concerns in this webcast,
therefore, most of the webcast is devoted to attendees asking questions
about the bulletins and getting answers from Microsoft security experts.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-family:Verdana;"&gt;&lt;span style="font-family:Verdana;"&gt;&lt;b&gt;Presenters:&lt;/b&gt;
Christopher Budd, Trustworthy Computing Senior Public Relations
Manager, Microsoft Corporation and Adrian Stone, Senior Security
Program Manager Lead, Microsoft Corporation&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/span&gt;&lt;/p&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;&lt;a href="http://msevents.microsoft.com/CUI/WebCastEventDetails.aspx?EventID=1032407488&amp;amp;EventCategory=4&amp;amp;culture=en-US&amp;amp;CountryCode=US"&gt;Register Online&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1732175" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/donpatterson/archive/tags/News/default.aspx">News</category></item><item><title>AVG Goes Back to Basics with AVG 9.0</title><link>http://msmvps.com/blogs/donpatterson/archive/2009/10/05/avg-goes-back-to-basics-with-avg-9-0.aspx</link><pubDate>Mon, 05 Oct 2009 20:52:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1730010</guid><dc:creator>Don</dc:creator><slash:comments>0</slash:comments><description>&lt;p&gt;AVG Technologies, developers of the world&amp;rsquo;s most popular free
anti-virus software, today announced that its family of free and paid
internet security products, AVG 9.0, would be generally available to
the market in October 2009. Boosted by significant enhancements in
speed and levels of protection, AVG 9.0 is also easier to use and
improves end user experience. Additionally, all AVG users in the U.S.
will benefit from a groundbreaking identity theft offering, powered by
a partnership with Intersections Inc., North America&amp;rsquo;s leading and most
innovative provider of consumer identity theft prevention solutions
which has served more than 25 million consumers. AVG&amp;rsquo;s new technology
products ensure that users are safe in whatever online or offline
activities they undertake.
&lt;/p&gt;
&lt;p&gt;&amp;ldquo;AVG 9.0 will provide home computer users with a more powerful and
more streamlined solution that adds protection without impacting user
experience, taking us back to our core strength of low impact, high
performance security,&amp;rdquo; said J.R. Smith, CEO, AVG Technologies. &amp;ldquo;We&amp;rsquo;ve
always believed that everyone has the right to a safe online
experience. With AVG 9.0, we are providing first-class assistance to
our users in their development of tools and measures for their safety
from all of the threats posed by cybercriminals and identity thieves,
whether they&amp;rsquo;re working, playing, banking or shopping on the web.&amp;rdquo;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.avg.com/us-en/press-releases-news.ndi-224899"&gt;Press Release&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1730010" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/donpatterson/archive/tags/News/default.aspx">News</category></item><item><title>Firefox feature looks to foil XSS attacks</title><link>http://msmvps.com/blogs/donpatterson/archive/2009/10/02/firefox-feature-looks-to-foil-xss-attacks.aspx</link><pubDate>Fri, 02 Oct 2009 17:44:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1729056</guid><dc:creator>Don</dc:creator><slash:comments>0</slash:comments><description>&lt;p&gt;&lt;span class="body"&gt;
&lt;p&gt;
The Mozilla Foundation released on Wednesday a preview version of the
Firefox browser that implements a technology to protect against
scripting attacks.&lt;/p&gt;
&lt;p&gt;
The technology, known as Content Security Policy, allows Web sites to
specify restrictions on how they handle scripts. Using CSP, a Web site
can create a white list of sites from which the browser should accept
scripts as well as mandate that the scripts are labeled as applications
and are not obfuscated. A &lt;a href="https://wiki.mozilla.org/Security/CSP/Spec" target="_blank"&gt;number of other features&lt;/a&gt; are also available, all aiming to prevent malicious scripts from executing in the context of the current site.&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.securityfocus.com/brief/1019"&gt;Story&lt;/a&gt; continues at securityfocus.com&lt;/p&gt;
&lt;/span&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1729056" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/donpatterson/archive/tags/News/default.aspx">News</category></item><item><title>Microsoft’s New Tool in the Fight Against Malware Free to Consumers</title><link>http://msmvps.com/blogs/donpatterson/archive/2009/09/29/microsoft-s-new-tool-in-the-fight-against-malware-free-to-consumers.aspx</link><pubDate>Tue, 29 Sep 2009 05:11:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1728108</guid><dc:creator>Don</dc:creator><slash:comments>0</slash:comments><description>&lt;p&gt;&lt;strong&gt;REDMOND, Wash. &amp;mdash; Sept. 28, 2009 &amp;mdash;&lt;/strong&gt; Microsoft Security
Essentials, Microsoft Corp.&amp;rsquo;s new no-cost, core anti-malware service
that helps protect consumers against viruses, spyware and other
malicious software, will be available tomorrow, Tuesday, Sept. 29.
Microsoft Security Essentials, independently certified by West Coast
Labs, is backed by the company&amp;rsquo;s global security response team and is
built on the same award-winning core security technology found in the
company&amp;rsquo;s security solutions for businesses. It requires no
registration, trials or renewals and will be available for download
directly from Microsoft at &lt;a href="http://www.microsoft.com/security_essentials/"&gt;http://www.microsoft.com/security_essentials&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.microsoft.com/presspass/press/2009/sep09/09-28securityessentialspr.mspx"&gt;Press Release&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1728108" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/donpatterson/archive/tags/News/default.aspx">News</category></item><item><title>Social-networking sites short on security</title><link>http://msmvps.com/blogs/donpatterson/archive/2009/09/18/social-networking-sites-short-on-security.aspx</link><pubDate>Fri, 18 Sep 2009 23:37:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1724847</guid><dc:creator>Don</dc:creator><slash:comments>0</slash:comments><description>&lt;p&gt;&lt;span class="body"&gt;
&lt;p&gt;
Web 2.0 sites that allow user-generated content make up the majority of
top distributors of malicious software, stated a report that security
firm Websense published this week.&lt;/p&gt;
&lt;p&gt;
The &lt;a href="http://community.websense.com/blogs/websense-features/archive/2009/09/15/websense-security-labs-report-state-of-internet-security-q1-q2-2009.aspx"&gt;report&lt;/a&gt;,
which covers Internet security trends for the first half of 2009, found
that a stunning 95 percent of user-generated comments to blogs, chat
rooms and message boards are either spam or contain links to malicious
programs. In all, the number of malicious sites detected by Websense
more than tripled in the last six months, growing almost eight-fold in
the last year. The report also found that more than three-quarters of
the Web sites hosting some malicious code are legitimate sites that
have been compromised.&lt;/p&gt;
&lt;p&gt;
&amp;quot;The very aspects of Web 2.0 sites that have made them so revolutionary
-- the dynamic nature of the content on the the sites, the ability for
anyone to easily create and post content, and the trust that users have
for others in their online networks -- are the same characteristics
that radically raise the potential for abuse,&amp;quot; the company stated in
the report.&lt;/p&gt;
&lt;p&gt;
The report echoed a recent survey by researchers from TippingPoint and Qualys, who found that legitimate Web sites are &lt;a href="http://www.securityfocus.com/news/11560"&gt;failing to patch significant vulnerabilities&lt;/a&gt;, leaving themselves open to compromise.&lt;/p&gt;
&lt;p&gt;
The Websense report found that 61 of the Top 100 Web sites &amp;quot;either
hosted malicious content or contained a masked redirect to lure
unsuspecting victims from legitimate sites to malicious content.&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.securityfocus.com/brief/1014"&gt;SecurityFocus&lt;/a&gt;&lt;/p&gt;
&lt;/span&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1724847" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/donpatterson/archive/tags/News/default.aspx">News</category></item></channel></rss>