Microsoft has released 5 security bulletins for Windows and updates to address the 8 vulnerabilities described in them. All 5 bulletins have a maximum severity rating of "critical," but some Windows versions are affected more severely than others. The recently-announced vulnerability in the IIS FTP service is not addressed, nor is this morning's new SMB2 vulnerability.
Article link
Two days after disclosing two vulnerabilities that had been fixed in Firefox 3.5 (which had been released weeks before), Mozilla has disclosed 4 more vulnerabilities, 2 of them critical, and released new versions of Firefox to address them.
Article link
Microsoft has issued a security advisory for a vulnerability in the IIS web server that comes with Windows Server versions. The vulnerability is in the WebDAV (Web-based Distributed Authoring and Versioning) feature which is a set of HTTP extensions to allow clients to manipulate files on web servers. Because of the vulnerability, an unauthenticated user could gain access to files that normally require authentication.
Article link
A San Jose Mercury News news report says that over 300 hospital devices, including MRI systems, were infected with the Conficker worm and attacking other devices on the network.
Article link