Doubling Letterman, the SANS (System Administration, Networking, and Security) Institute has updated its top 20 security threats list. Taking the top this time around are the default installations of operating systems and applications, which invariably leave open all sorts of holes for malicious code to take advantage of. Wired has some coverage if you don't want to sort through the list yourself. Suffice to say you should opt for custom installations whenever possible.
