Ouch. Big hole in Moveable Type: the email addresses entered for sending entry notifications are not validated. This gives attackers the opportunity to abuse it - for example, according to this post, spammers have used the hole to send spam. A patch is also provided there that you can use to add validation, so that spammers can no longer easily abuse MT.

So, people, patch your Moveable Type! Or better yet: get rid of the script!

Here's the original article.