Here's a service to avoid.

Scams, Frauds & Viruses
On this page there's a write-up of a service called MarketScore which tracks your movements on the Internet by becoming an Internet proxy for your browser, if you sign up to it. Now that's maybe something you wouldn't want, but there's more.
As part of the installation they install their own root certificates into your browser and then proxy all your SSL connections!!!
So this means that all your online banking passwords could be intercepted by this company, or if their servers were to be successfully attacked, by the attacker, and I would expect that this kind of company would prove a very tempting target for hackers (why compromise individual PC's when you can get all the traffic passing through a proxy)
Apart from anything else, I would expect that using a services which interrupts the SSL connection to your bank or other service, may violate their Terms of Service (allowing someone else access to your sign-on credentials)

Bank Attack...

BBC NEWS | UK | London police foil huge bank raid
Whilst there's limited information available on this attack, what's being mentioned so far is that the attackers used keylogging software to gather passwords etc.
Now this comes onto a pet crusade of mine (I've mentioned it before here ). Companies need to realise that access to all their critical information assets is through client devices, so it's pretty pointless to spend lots of money securing network perimeters and key servers and then leave the client devices which connect to them open to attack!
At the least devices used by people with elevated privileges (eg, sys admins) should get additional protection like host firewalls and IDS, and where possible should be in a physically secure location, as it's very difficult to secure the device once the attacker has physical access to it.

Unintended consequences

Schneier on Security: Melbourne Water-Supply Security Risk
Another interesing piece, on SCADA security, from Bruce Schneier's blog. It's a good example of unintended consequences. When SCADA systems were designed it looks like most weren't expected to ever be connected to a general corporate network (let alone the Internet) and as such rarely had the kind of security built in that you would expect from systems controlling critical infrastructure pieces.
There's some interesting commentary on this piece as well and some good links on SCADA security....

IT systems solve your SOx problems...

This story covers an an angle of the Regulatory compliance issue, where companies Compliance burdens are leading them to purchase additional IT Security systems...
I hope this story is only telling one piece of the story for these companies 'casue without decent policies and procedures, a whole load of new tools won't help you much in proving to regulators that you have a well controlled IT environment....

The web is not a safe place to be these days!

SANS - Internet Storm Center - Cooperative Cyber Threat Monitor And Alert System - Current Infosec News and Analysis
Interesting to see new categories of attacks gaining in popularity, as highlighted in this handlers' diary entry.
Adding malicious content to hosted websites is a handy way for malware authors to ensure that their code will be executed, rather than relying on e-mails with links which (hopefully) are a less useful vector (Surely by now a decent percentage of Internet users don't go around clicking links sent in e-mail....)
Also another good example (as if anyone needed more) of why patching is critical to protecting PC's at the moment.

Interesting commentary on md5 collision attacks

Financial Cryptography: Cryptographers have a Responsibility to Explain Results
An interesting post over at financial crpytography looks at the practical implications of a recent paper on collisions in MD5 and possible effects on the security of certificates.
I'd agree that the paper has been taken out of context in a lot of stories, but then that seems to happen a lot when the journalists covering something aren't maybe experts in that field, also I suppose there must be a temptation for the researchers to talk up their findings...