Open Source digg-clone Pligg plugs security holes
Pligg, which is an open source attempt at a Digg-like social networking voting site application is being updated this week for some serious security vulnerabilities.
As opposed to many other vendors/projects which typically release an update alongside security advisories, that's not the case with the new Pligg 1.0.3 release. The full security advisory isn't coming out until tomorrow (Dec 2) giving Pligg users (and there are a whole lot of them) a running head start on potential attacks.
Security researchers from firms big and small have been saying for the last few years that it is web applications that pose the greatest security risk to users. That's because an attacker only need take advantage of one site to infect potentially thousands of the infected site's users.