Just to update - the content server wasn't running at the time - which is why I was concerned - havent had it reoccur - even when I was running the server to transfer. Ran a full check on my computer and couldnt pick up any intrusions so I am going to assume it was benign.
A security vulnerability by using Calibre might be something to consider however.
|