Here's an interesting Black Hat paper detailing security considerations when deciding to use web services and what hackers look for when attacking web services. WSE's MTOM implementation is interoperating with a Java client (from Simon Guest) Interesting