Everyone upgrade/patch their bind servers? http://isc.sans.org/diary.html?storyid=6886
Just in case, I wrote a snort sig to detect external dns update packets. alert udp $EXTERNAL_NET any -> $HOME_NET 53 (msg:"DNS Update From External net"; flow:to_server; byte_test: 1,&,40,2; sid: XXXX; rev:1)
