Conficker borks London council
[...]
The May incident took several days to clean-up and landed the west London council with a bill of €£500,000 in lost revenue and repairs, The Guardian reports. Because IT systems were borked, the council was unable to process more than 1,800 parking tickets, at an estimated cost of €£90,000, libraries lost out on €£25,000 in fines and booking fees, council property rent went uncollected, and €£14,000 was spent in overime sorting out delayed housing benefit claims.
New IIS attacks (greatly) expand number of vulnerable servers
[...]
Attackers have begun actively targeting an unpatched hole in Microsoft's Internet Information Services webserver using new exploit code that greatly expands the number of systems that are vulnerable to the bug.
Exploit code affecting the FTP module for certain versions of Microsoft IIS has been posted online. US-CERT recommends taking countermeasures.
For more than a year, Microsoft has been sitting on a purported SQL Server vulnerability that could enable a malicious insider to obtain users' passwords, claims database security vendor Sentrigo.
Sentrigo has discovered a vulnerability in Microsoft SQL Server that allows any user with administrative privileges to openly see the unencrypted passwords of other users, or the credentials presented by applications accessing the server using SQL Server authentication.
While changes to Windows 7’s UAC benefit the home user market, enterprises must be aware that the new “slider” feature is only for administrators and may increase security risks.
McAfee false alert snares innocent JavaScript files
[...]
Faulty virus definition updates from McAfee that flagged legitimate JavaScript files as potentially malign caused a headache for some sysadmins earlier this week.
Compromised Computers Host an Average of 3 Malware Families
[...]
Unfortunately, we are talking about infected files and not doughnuts. According to security company ESET, the average compromised machine is home to 13 infected files as well as malicious programs from three different malware families.
An Illinois district court has allowed a couple to sue their bank on the novel grounds that it may have failed to sufficiently secure their account, after an unidentified hacker obtained a $26,500 loan on the account using the customers’ user name and password.
--Brian Valentine, Microsoft executive