Showing posts with label Adobe Flash Player Download. Show all posts
Showing posts with label Adobe Flash Player Download. Show all posts

Tuesday, 10 February 2015

Dailymotion Denies Showing Infected Ads


The very popular video website Dailymotion states that it has shown no infectious ads that tried to infect visitors with malware, but one security expert says that this is not true and users are indeed attacked. On February 2, warned anti-virus company Trend Micro that on Dailymotion.com were infected ads appeared who attacked a new vulnerability in Adobe Flash Player.

At the time of the attack, there was no security available. Were therefore users of Internet Explorer and Firefox on Windows that had Flash Player installed the risk of becoming infected with malware. The observed attack only worked against these two browsers. Later confirmed also anti-virus company Malwarebytes that the infected ads on Dailymotion.com had seen.

Yet Dailymotion poses in a statement that users will not be attacked. All advertisements should be checked namely. JuK security expert criticizes the statement. "That's not right," as he lets on Twitter know. He points to an analysis of the Fiddler tool. This shows that there are infected ads are displayed on Dailymotion.

Sunday, 8 February 2015

Emergency Patch Flash Player Addresses 18 Vulnerabilities


The emergency patch Adobe this week for a critical vulnerability in Flash Player fixes rolled out a total of 18 vulnerabilities. This is evident from the Security Bulletin that the software company has disclosed.Initially suggested that the Adobe emergency patch only attacked leak CVE-2015-0313 rectified.

The update to version 16.0.0.305 was first rolled out only via the automatic update feature of Flash Player. Now the update also manually download the full Adobe Security Bulletin published. Besides leak which the emergency patch initially appeared also includes 17 other vulnerabilities mentioned. 14 of them make it possible for an attacker to take vulnerable computers at worst completely.

Google played an important role in the discovery of the now patched problems. Eight vulnerabilities were in fact discovered by employees of Google and the Google Project Zero team. Four other leaks were reported through the Chromium Vulnerability Rewards Program from Google. Users are advised to update to Adobe Flash Player 16.0.0.305, which can be done via the automatic update feature and Adobe.com . This page shows which version is installed on the computer.

Saturday, 7 February 2015

Flash Player Vulnerability In Chrome And Internet Explorer Patched


Both Microsoft and Google yesterday released updates for a critical Flash Player vulnerability in Google Chrome and Internet Explorer 10 and 11 on Windows 8 and Windows 8.1. The vulnerability was Wednesday already patched by Adobe. Both Chrome on all supported platforms as IE10 and IE11 on the newer Windows versions feature an embedded Flash Player must update Google and Microsoft.

The vulnerability in Flash Player, the last few days and possibly since late last year actively used in attacks against Windows users. This happened partly through contaminated ads on popular websites . The exploit used in these attacks would according to Trend Micro not against Google Chrome users. Adobe also said in the warning that the observed attacks only against Firefox and IE users place on Windows.

In the case of Google Chrome in addition to the Flash Player leak also eleven vulnerabilities fixed in the browser itself.Through these vulnerabilities, an attacker could in the worst case read confidential information of other websites or modify.For most users of both Chrome and IE update will be installed automatically. Through this page , users can check whether they are using the latest version of Flash Player (16.0.0.305).

Friday, 6 February 2015

Ads With Flash Attack On Popular Websites


On several popular websites are infected ads appeared that abuse of a vulnerability in Adobe Flash Player were true at the time of the attack no update was available. It is about the vulnerability where yesterday emergency patch for appeared.

Before the emergency patch was available display ads on various websites infecting users with Flash Player. It was Firefox and Internet Explorer users on Windows. Google Chrome users would have run no risk. It was already known that the infected ads on the wildly popular video site Dailymotion appeared. Now let anti-virus company Malwarebytes know that the ads also include theblaze.com , nydailynews.com , tagged.com , webmail.earthlink.net , mail.twc.com and my.juno.com shown.

The infected ads would have ended through a bidding process on the websites. For only 0.9 cents per impression they were eventually appear. Although this ad campaign was discovered recently left a researcher F-Secure recently know that this particular flaw in Flash Player possibly since December 20 last year will be used for attacks.

The emergency patch will be distributed via the automatic update feature of Flash Player. Google Chrome and Internet Explorer 10 and 11 on Windows 8 and 8.1, which have an embedded Flash Player, the update will eventually be rolled out by Google and Microsoft. However, these updates are not yet available. In the case of IE, users therefore advised to temporarily disable Flash Player or use a different browser.

Thursday, 5 February 2015

Adobe Distributes Emergency Patch Attacked Flash Leak


Adobe has released an emergency patch yesterday rolled out for a critical vulnerability in Flash Player that is actively used to infect Windows users with malware. It is the third emergency patch in a short time made ​​available for Flash Player. The previous patches appeared on 22 and 24 January

In this case, the update to Adobe Flash Player 16.0.0.305 meant for the vulnerability that is identified as CVE-2015-3013. As with the previous emergency patch rollout takes first place among users who have enabled the automatic update feature. This is the default browser plug-in. Expected to appear today manual download.

It also cooperates there with Google and Microsoft. Chrome and Internet Explorer 10 and 11 on Windows 8 and 8.1, namely feature an embedded Flash Player that can be updated using the browser and operating system. The attacks so far observed are directed against users of Internet Explorer and Firefox on Windows 8.1 and older. Previously showed Trend Micro already know that the exploit does not work against Google Chrome. Through this page , see what version of Flash Player is installed on the system.

Wednesday, 4 February 2015

1800 Subdomains Used For Flash Player Attack


Cybercriminals last week a large number of subdomains created and used for attacking Flash Player users. For carrying out the attack, the attackers used more than 50 legitimate GoDaddy accounts that they had hijacked. GoDaddy is an Internet domain registrar where to register. In addition, customers can through the GoDaddy account to manage their domain names. By this steal account information the attackers had access to a large number of domain names.

They used the access to create subdomains , which were then used to host a Flash Player exploit. This is an exploit for a vulnerability in Adobe Flash Player that on January 26 was patched this year. The use of subdomains took place between 26th and 30th of January. Unlike many attacks where cyber criminals hacking and using legitimate websites to infect visitors were not adjusted in this case the main domains.

The attackers used the subdomains created to host the Flash Player operates as well as an exploit for Microsoft Silverlight.Contaminated ads was then made ​​to these subdomains. Users with vulnerable Flash Player who got to see could be infected with malware in this way the ads, according to Cisco . Statistics from VirusTotal shows that exploits barely detected by virus scanners, which indicates that it is important to immediately install the available updates.

Tuesday, 3 February 2015

Symantec Recommends Temporarily Disabling Flash Player


Internet users who are worried about the new vulnerability in Flash Player which no update is available, get anti-virus company Symantec's advice to temporarily disable the browser plug-in. The vulnerability allows cybercriminals in the worst case the computer can take over completely when users visit a compromised or malicious website or see infected ads.

The leak could have been used by infected ads on Dailymotion, one of the most popular video sites on the Internet. Users who have the website with Flash Player and Internet Explorer or Firefox on Windows visited at risk to be infected with malware. "Users who do not block ads and Flash are set to automatically play the most vulnerable," said Adam Winn software company OPSWAT.

He advises Flash Player from users who want to protect themselves against infectious ads to set Click to play and use an ad blocker. "Although controversial ad blocking a highly effective way that enables users to protect themselves against malvertising. An average user can these two things set up within an hour and be sure that he is nearly invulnerable to malvertising and Flash attacks in general "said Winn. Adobe announced this week that it comes with an emergency patch for the leak.

Monday, 2 February 2015

Adobe Vulnerability: "Warning New Attacked Flash Player Leak"

Internet users are warned again a new vulnerability in Adobe Flash Player which no update is available and actively used to infect computers with malware. The vulnerability is in Flash Player 16.0.0.296 and earlier versions.

Visiting a hacked or malicious Web site with a vulnerable Flash Player installation is enough to get infected. The attacks which until now have been observed to focus on users of Internet Explorer and Firefox on Windows 8.1 and older, according to the advisory . The leak, which is listed as CVE-2015-0313, was discovered by researchers at Trend Micro and Microsoft.

Adobe says that it will come this week with an emergency patch. It would be the third emergency patch in less than two weeks. Previously published a need patches on January 23 and January 26 . This emergency patches were for vulnerabilities via contaminated ads , among other porn sites were attacked. Through this page, Adobe, Internet users see which version of the software on their computers and what is the latest version.

Trend Micro let know that the new zero-day vulnerability has been used by infected ads on the website Dailymotion.com . A website according to Alexa on the 83th spot of most visited websites on the Internet is Dailymotion. Visitors to the popular video site were without them knowing redirected to a page with an exploit that made ​​abuse of the Flash Player leak. The attacks since January 14 monitored by the anti-virus company, which is from January 27 to see a spike in the number of users will be redirected to the exploit. Meanwhile the infected ads would not be shown on Dailymotion.

Saturday, 31 January 2015

Apple Blocks Unsafe Flash Player On Mac OS X


To protect users from potential attacks, Apple insecure versions of Adobe Flash Player on Mac OS X blocked. Mac OS X has a "Web Plugin blocking mechanism" that Apple regularly will update to block unsafe plug-ins and prevent drive-by downloads.

This weekend Adobe patched a critical vulnerability in Flash Player that is actively used to attack Windows users. Who surfs on Mac OS X with Safari and not using the latest version of Flash Player and a site visit to see the plug-in calls notifies ranging from "Blocked plug-in", "Flash Security Alert" or "Flash out-of-date ". The message is that Adobe Flash Player is outdated and there is a newer version can be downloaded from Adobe.

Flash Player versions on Mac OS X Flash Player 16.0.0.296 and 13.0.0.264. All versions are blocked before. Users who still want to use an older version of Flash Player can do this via the "Internet Plug-in management" in Safari, and so the plug-in running on reliable websites in an insecure fashion. Further notes that Apple users who have problems downloading or installing Flash Player, this should contact Adobe.

Monday, 26 January 2015

Emergency Patch For Adobe Flash Player Attacked Leak


Adobe has this weekend an emergency patch released for a critical vulnerability in Flash Player that asset is used by cybercriminals to infect computers with malware. Because of the vulnerability had Internet Storm Center decided to alert the Internet to color code yellow to increase.

The emergency patch this weekend only rolled out to users who have enabled the automatic update feature, which is the default for Flash Player. For users who want to download the update itself will update appear this week at the Adobe website.Additionally, Adobe has announced that with distribution partners cooperate to the update for Google Chrome and Internet Explorer 10 and 11 make it available. These browsers include an embedded version of Flash Player.

Adobe confirms that the leak is used to attack users of Internet Explorer and Firefox on Windows versions up to Windows 8.1.Initially, it was stated that users until Windows 8 walked risk. The critical vulnerability has been fixed in Adobe Flash Player 16.0.0.296 . Through this page can be viewed which version is installed on the system.

Friday, 23 January 2015

Latest Flash Attack Is Part Of Botnet Computers


A new vulnerability in Adobe Flash Player cybercriminals actively use to infect computers with malware and for which no security update is available is the ultimate goal of creating a botnet that among other things used for committing click fraud.

The zero-day vulnerability in Flash Player was wednesday afternoon reported by security researcher 'JuK. Visiting a malicious or hacked website with the latest version of Flash Player would be enough to get infected. The researcher also advised to temporarily disable Flash Player. Adobe will facing the business magazine Forbes that examines the message, but still has not announced any details.


Meanwhile, security Malwarebytes malware examined using the new Flash Player attack is installed on computers. In case the attack is successful, the computer part of the Bedep botnet. This botnet can then, by installing additional malware, use the computer for different purposes. In the case of the malware that saw the researchers concerned the click fraud.

The malware infects the explorer.exe process and let the infected computers to send any requests for ad networks, without the user does this by. According to researcher Jerome Segura are difficult to distinguish them from real traffic requests, allowing advertisers end up paying for impressions and clicks that do not originate from a human and which benefit cybercriminals.