Mark Russinovich writes about a class of security bugs that many applications (including lots of 3rd party "security" solutions) suffer from. Squatting Attacks are enabled when improper security permissions are applied to files and synchronization objects.