Just in case there are people who use Movable Type and read my journal but don't follow Movable Type development that closely: there's a hole in the mt-send-entry.cgi script that comes with Movable Type that can be exploited to send spam, similar to the formail bugs that have been around for quite a while.

See the Movable Type announcement for more details. The easiest solution for most people is to just delete that script entirely unless you've started using it for something.

