WordPress update kyboshes XSS flaw

Blog pwnage risk busted
WordPress has fixed a cross-site scripting (XSS) flaw in its blogging software.…

Read more…

Srizbi spam botnet in failed resurrection

Rebirth before redeath
After being stranded for weeks, a monster botnet responsible for an estimated 40 percent of the world’s spam was able to briefly reconnect to its mothership in a tense international duel playing out online that could have a dramatic effect on the amount of junkmail flowing into inboxes everywhere.…

Read more…

Srizbi Botnet Re-Emerges Despite Security Firm’s Efforts

In the fallout resulting from knocking McColo Corp. offline, this past week may prove to be a missed opportunity in the prevention of a dramatic reappearance of junk e-mail, as a botnet that once controlled 40 percent of the world’s spam apparently has found a new home. The botnet Srizbi was knocked offline Nov. 11 along with Web-hosting firm McColo, which Internet security experts say hosted machines that controlled the flow of 75 percent of the world’s spam. One security firm, FireEye, thought it had found a way to prevent the botnet from coming back online by registering domain names it thought the Srizbi was likely to target. But when that approach became too costly for the firm, they had to abandon their efforts. “This cost us a lot of money. We engaged all the right people. In the end, it comes back to the fact that there wasn’t a

Read more…