Showing posts with label Adobe Flash Player Zero-Day Vulnerability. Show all posts
Showing posts with label Adobe Flash Player Zero-Day Vulnerability. Show all posts

Friday, 30 October 2015

Recent Poem Flash Leak In Crosshairs Of Cyber Criminals



A critical vulnerability in Adobe Flash Player which ten days ago an emergency patch rolled out is now being actively attacked by cyber criminals. At the time Adobe update rolled out the company claimed that the vulnerability was used only in targeted attacks on a limited scale.

Now reports researcher JuK of the blog Malware do not need Coffee that an exploit of the vulnerability using the Angler-exploitkit added. Consequently have less technical knowledge cybercriminals with the means to attack the Flash leak. The Angler exploitkit was in recent months in large-scale advertising campaigns on popular websites used.

Criminals use this ad network of popular websites to spread infected ads. These ads send visitors unnoticed to a page with the Angler-exploitkit. In case users have their Flash Player or other software is not up-to-date, they can become infected with malware. Now the recent poems Flash leak also been added to the Angler-exploitkit cyber criminals have a greater opportunity to infect internet users, since the update of October 16 may not yet installed anywhere.

In case the attack is successful, the Bedep Trojan is installed on computers. This Trojan can install additional malware, including malware for advertising fraud and ransomware, and the computer part of a botnet. The Flash vulnerability was two weeks before the attack on the 'wild' was discovered already by Google to Adobe reported. Through this page to monitor Internet users whether they are using Flash version.

Thursday, 24 September 2015

American 'Funda' Spread Malware Via Infected Ads


Cyber criminals are again managed to place infected ads on a very popular website with tens of millions of visitors who attempted to install malware. It is Realtor.com, the US counterpart of Funda which all kinds of real estate is offered.

The website is according to market researcher Alexa at the 101st place of most visited websites in the United States and a 485ste place worldwide. It is estimated that Realtor.com monthly 28 million visitors. The attackers previously infected ads on the English website of eBay, Drudge Report and other major websites were seated according to anti-malware company Malwarebytes also behind this attack. Through advertising network Adspirit.net the affected ads were posted on the website.

The ads sent visitors without being noticed this through to a website with the Angler-exploitkit. This exploitkit uses known vulnerabilities include Adobe Flash Player and Internet Explorer to install malware. For whatever it's malware was not disclosed. After being informed, the publisher of Realtor.com and Adspirit off the ads. Internet users whose software was up-to-date were no known risk. Yesterday it became known that criminals a week infected ads on Forbes.com have shown.

Wednesday, 23 September 2015

Forbes.com Spread Malware Via Infected Adverts


On the very popular website of business magazine Forbes have been infected for some time ads shown to infect visitors with malware tried. Forbes.com state according to market researcher Alexa on the 74th spot of most visited websites in the United States and the 154th place worldwide.

The website is monthly by more than 31 million visited visitors. Those visitors were from 8 to 15 September dished ads so they were undetected to a website with the Angler- and Neutrino-exploit kits. This exploit kits exploit known vulnerabilities include Adobe Flash Player. In case there is no up-to-date software was used silently malware could be installed on the computer, says security firm FireEye.

For what exactly will the malware was not disclosed. The ads were via an advertising service from a third party displayed on the Forbes website. According FireEye use of contaminated advertising remains a popular attack method for criminals.Via advertising platforms, especially those that hold real-time auctions for ad space, attackers can choose exactly where their malicious content is displayed.

In case the infected appear ads on popular websites the chance of massive infection is significantly increased, allowing both users and businesses at risk, according to the security company. After being informed Forbes has removed the infected ads. Last year, even though malware via Forbes.com spread. When attackers used a widget on the website that zero-day vulnerabilities in Internet Explorer and Adobe Flash Player attacked.

Thursday, 16 July 2015

Manufacturer Stops Installing Flash Player On Computers



The American computer manufacturer System76 has stopped the default install Adobe Flash Player on new computers. It includes both desktops and laptops now come without the video plug-in. System76 delivers desktops, laptops and servers, which all run on Ubuntu.

In 2007, the manufacturer of a license to install Adobe Flash Player advance new systems. Something the company did until now standard. Starting today, there came a change in systems and be delivered without Flash Player. According to the manufacturer's decision is based on two reasons. First, Flash Player no longer required to have a "full web experience", whereas previously it was often the case. In addition, the safety of users of the other reason.

In recent weeks, several zero-day vulnerabilities discovered in the video plug-in, which were then used by cyber criminals to infect computers silently by malware. Besides the decision to henceforth avoid Flash Player System76 also advises to remove the browser plug-in already purchased systems. "Even if you think you need Flash, you might have to experiment further by not using a time. You will be surprised how little your Internet experience is changing," the company said.

In case customers but not without Flash Player is advised to Google Chrome, which uses a proprietary Flash Player located in a sandbox. Still, this offers no guarantee, as one of the Flash Player vulnerabilities that an attacker had discovered had to break out here the Italian Hacking Team, and then take on the underlying system. Therefore, it is according to the manufacturer still more sensible to avoid flash at all.

Sunday, 12 July 2015

New Flash Player Flaw Hacking Team Actively Attacked


The Italian Hacking Team appears to have over many more unknown vulnerabilities in Adobe Flash Player than the one that was unveiled earlier this week and one of these leaks is now actively attacked by cyber criminals and an update from Adobe is not yet available.

Thereby running millions of Internet users risk. The situation looks like a repeat of the scenario that played out earlier this week. An attacker managed to break into Hacking Team and made ​​as 400GB of data booty. The data has a zero-day vulnerability for Flash Player encountered. After the discovery added to all kinds of so-called criminals who exploit kits with Internet attack . Adobe then came up with a patch to fix it.

Two new zero days

In the archives of Hacking Team researchers have now two new "zero-day vulnerabilities" found and made ​​public. The vulnerabilities in Adobe Flash Player version 18.0.0.204 and earlier are designated by the CVE numbers CVE-2015-5122 and CVE-2015-5123. One of these vulnerabilities, CVE-2015-5122, cyber criminals have been added to the Angler Exploitkit, reports researcher JuK of the blog Malware Do not Need Coffee. The code has also been added to Metasploit, a program for security professionals and penetration testers can test the security of networks and systems.

Thereby running Internet with Flash Player when visiting a hacked or malicious Web site, see getting infected ads or open a Word document with an embedded Flash file the risk of becoming infected with malware. As this week will come with Adobe emergency patch. However, to be published next week, as the software company in the late notice know, although the advisory refers to the week of 12 July. In the meantime, Internet users can protect themselves by temporarily disabling Flash Player.

Update

The CERT Coordination Center (CERT / CC) at Carnegie Mellon University warns also of vulnerability and allows users to protect themselves from the free Microsoft EMET to install or not to implement Flash content from unreliable.

Tuesday, 7 July 2015

Hacking Team Had Zero Day Vulnerabilities For Windows And Flash



The Italian developer of government spyware Hacking Team had zero day vulnerabilities for Windows and Adobe Flash Player, according to the files that were stolen from the company. Yesterday published attackers a file of about 400GB with all sorts of information that was captured by Hacking Team.

The files have now discovered two vulnerabilities for which no security update available yet, says security researcher The Grugq . It is a vulnerability in Windows that allows an attacker can increase his rights on the system. In this case, the attacker must already have access to the computer in order to use the leak. The second vulnerability is in Adobe Flash Player. Through this vulnerability, an attacker computers or completely take over, for example, when users visit a hacked or malicious website.

The embedded Flash Player in Google Chrome is vulnerable. According to security researcher Kevin Beaumont makes the leak is possible to escape from the sandbox of Chrome. Researcher Rik van Duijn of security Dear Bytes however, leaves know that a sandbox escape "through the published code is not possible and therefore a second exploit is required. Hacking Team, which develops spyware for government agencies, has in statement confirming that it has been hacked. "We think there are documents of the company have been stolen. We have launched an investigation to determine the extent of the attack and to determine what exactly is captured," said a spokesman. The company's website has been offline since yesterday.

Update

The National Cyber ​​Security Center (NCSC) government has a warning issued for the flaw in Flash Player. Through the leak, an attacker execute arbitrary code on the computer with the rights of the logged in user. The NCSC states that there is no update available for the leak yet.

Update 13:48

The attack on Hacking Team is claimed by the hacker who last year by spyware developer Gamma International managed to break in and there gigabytes of data was captured, says Vice Magazine . The hacker says soon come up with the details of how he managed to break into Hacking Team.

Update 15:09

Anti-virus company Symantec confirms that this is a zero-day vulnerability in the latest version of Flash Player. The virus firefighter expects that attackers will probably make use of the vulnerability.

Update 15:19

The CERT Coordination Center (CERT / CC) at Carnegie Mellon University warns also the vulnerability and says that users can protect themselves by installing Microsoft EMET unreliable or not Flash content to perform.

Sunday, 28 June 2015

Apple Blocks Unsafe Versions Of Flash Player


Because of a zero-day vulnerability in Adobe Flash Player which this week emergency patch released Apple has decided to block all versions of the emergency patch. The vulnerability was used in targeted attacks before the update was available from Adobe. Through the leak could allow an attacker complete control of the computer.

In order to achieve this, e-mails have been sent to links with different targets. The link in the message pointed to a website that then tried to install malware through the vulnerability in Flash Player. According to Adobe, the attacks against Firefox users on Windows XP and IE users on Windows 7 and older Windows versions. Nevertheless, Mac users were advised to install the emergency patch within 72 hours.

Mac users who have not yet done receive when visiting websites in Safari that Flash Player now invoke a pop-up . Which reports that Flash Player is outdated and needs to be updated. Something can be done via a button in the same message.The blockade applies to all Flash Player versions prior to version 18.0.0.194 and 13.0.0.296.

Saturday, 27 June 2015

Trend Micro: New Flash Vulnerability Same Reason As Earlier Leak


The latest vulnerability in Adobe Flash Player which this week an emergency patch appeared to have the same cause as previous vulnerabilities in the popular browser plug-in. This enables the Japanese anti-virus company Trend Micro after analysis. This week, the vulnerability was with he CVE number 2015-3113 patched after the leak was previously used in targeted attacks. According to researchers, the leak is very similar to CVE-2015-3043 that Adobe patched in April.

Both vulnerabilities cause a buffer overflow. It also appears that an exploit for the vulnerability also published in April version 18.0.0.160 could crash (the latest Flash Player version before the emergency patch released this week). Both vulnerabilities are caused handle FLV with the Nellymoser audio codec and can be attacked through a specially prepared audio tag of an FLV file.

"This incident shows how important it is carefully developing patches to prevent vulnerabilities patched at a later time be attacked again," said the researchers. Which argue that software developers need to perform regression tests to ensure that old bugs are not a threat to new versions of the software.

E-mail

It was already known this week that the attackers left in emails used to lure targets to a malicious page where the Flash Player flaw was then attacked. Security company Websense says that the emails had used the subject line "2015 Program Kick Off". The text stated that the recipient was invited to a meeting. Through the attached link could be found more information about the meeting. The attackers would have mainly focused on the technological and scientific sectors.

Thursday, 25 June 2015

New Flash Player Flaw Attacked Through The Link In Emails


A critical vulnerability exists in Adobe Flash Player which yesterday an emergency patch released was attacked from links in emails. That informs the American security company FireEye that the zero-day vulnerability discovered and reported to Adobe.

A China-based group, according to FireEye behind the attack. The attacks were aimed at companies and organizations in different sectors, such as aerospace, defense, telecom, engineering and transport. The targets were emails sent with a link.Remarkably, there is no targeted emails were used, but messages that seemed almost on spam. "Save between $ 200-450 by purchasing an Apple Certified Refurbished iMac through this link. Refurbished iMacs come with the same one-year extendable warranty as new iMacs. Supplies are limited, but updated frequently. Do not hesitate...> Go to Sale , "the text in the message.

The link in the email pointed to a compromised server where the target was profiled via JavaScript. Once the victim was determined downloaded a malicious SWF and FLV file. Eventually this led to the installation of a backdoor. Through this backdoor received the attackers access to the system and the network of the organization was infiltrated. In announcing the emergency patch let Adobe know that IE users on Windows 7 and older and Firefox users on Windows XP were the target of the attack.

Thursday, 18 June 2015

Adobe Flash Player Popular With Cyber Criminals


Despite an automatic update function Adobe Flash Player continues to be very popular with cyber criminals, who last week patched vulnerability now use the browser plug-in for the spread of ransomware. Reported that the Japanese anti-virus company Trend Micro .

Although the patch is available and can be installed automatically by Flash Player, shows that particularly American, British and Canadian users who did not. In Belgium and Germany are perceived attacks via the vulnerability. It has become a trend in which after the appearance of a Flash Player update cyber criminals develop an exploit to attack users who have not installed the update.

"Many people are still running the previous version, meaning that a large number of users at risk," said analyst Peter Pi. The exploit that uses the vulnerability in Flash Player has been added to the Magnitude Exploitkit. Once unpatched users land on a malicious or hacked page or see an ad that points to this exploitkit, they may become infected with undetected malware.

In this case CryptoWall 3.0-ransomware is installed. These kinds of ransomware encrypts files on the computer and then asks for a certain amount to decrypt the files. Recently warned ( pdf ) also anti-virus company McAfee mean it had observed a sharp increase in the number of attacks in the first quarter of this year via Flash Player vulnerabilities. Adobe Flash Player users would now be using version 18.0.0.160, which through this page can be checked.

Sunday, 19 April 2015

Zero-Day Vulnerabilities Attacked In Flash Player And Windows



Attackers have recent period zero-day vulnerabilities in Adobe Flash Player and Windows uses to break into organizations. The vulnerability in Flash Player has been patched , but Microsoft is still working on an update. According to security firm FireEye involves targeted attacks.

For carrying out the attack must open a link target of the attackers. Subsequently, a site loaded that leak in Flash Player used to execute code. Through the Windows Player attackers can then increase their rights on the computer. At the time of the attack were both vulnerabilities not yet been patched.

Although Windows still waiting for an update, users should install the latest Flash Player security risk no longer walk. The attack on the Windows play would effectively observed only in combination with the Flash Player leak, according to the American FireEye. In case the attack is successfully installed malware on the system that allows full access to the attackers. Who is behind the attack is unknown, but FireEye calls it "likely" that it is a Russian spy group.

Sunday, 22 March 2015

Just Patched Flash Player Flaw In sight Cybercriminals



A critical vulnerability in Flash Player that last week was patched used to attack Windows users. Through the vulnerability an attacker can place malware on your computer, for example if the user visits a malicious or hacked website or see a banner gets infected.

Report that security company FireEye and anti-virus company Malwarebytes . The exploits of the leak abuse is added to the Nuclear Exploitkit. This makes it easy for cybercriminals to attack unpatched Flash Users via the vulnerability. In the case, the attack is successful, a Trojan horse is installed there.

Although the update is available for a week does not mean that everyone who has installed, says analyst Jerome Segura."We know that in some cases, consumers, but usually companies, can not immediately install patches. In many cases, there must first be internally tested so that the patch does not disturb any business processes." The analyst advises organizations in this case to shield these systems from other systems on the network.

Friday, 20 March 2015

Zero-Day Vulnerabilities In Flash, Windows, IE11 And Firefox Shown


During the Pwn2Own contest in Vancouver researchers have multiple zero-day vulnerabilities in Adobe Flash Player, Adobe Reader, Windows, Internet Explorer and Firefox demonstrated. The Pwn2Ownd contest is an annual event organized during the CanSecWest conference where researchers and the safety of popular browsers, and browser plug-ins can be tested.

In total on the first day of the event three vulnerabilities in Adobe Reader, three vulnerabilities in Adobe Flash Player, three vulnerabilities in Windows, two vulnerabilities in Internet Explorer 11 and two leaks in Firefox displayed. Through the vulnerabilities could allow an attacker full control of the computer without user interaction is much here for required. This involves visiting a hacked or malicious Web site or open a malicious PDF file.

None of the demonstrated vulnerabilities A security update is available, so there is zero-day vulnerabilities. However, the Pwn2Own rules state that only details may be shared with the organization. Which will then inform the relevant suppliers. Only after a security update is available researchers may publish details of the vulnerabilities.

In total, the researchers for their leak 317,500 dollars , which researcher Nicolas Joly dragging $ 90,000 knew inside. The Keen Team, consisting of several researchers, however, managed to leak in Adobe Flash Player and Adobe Reader, as well as bugs to earn the rights to increase Windows, totaling $ 140,000. Later today , various researchers are trying to re-hack Firefox and IE but there are now planned attacks on Google Chrome and Apple Safari.

Wednesday, 11 March 2015

Zero-day Attack Infected Thousands Flash Users


An attack campaign in late January and early February took place and two zero-day vulnerabilities in Adobe Flash Player made ​​use has infected thousands Flash Users. To attack the leak with Flash User made ​​the cyber criminals use of contaminated ads.

Once a website showed an infected ad, visitors could get infected that had installed Flash Player. In this case the Bedep malware installed on computers. Bedep is a backdoor that gives attackers full control over the computer. While the malware was announced on the attack early this year, the first copies were observed in November last year.

Anti-virus company Trend Micro has identified more than 7,600 victims who were infected with Bedep. The malware does not only make use of vulnerabilities in software, which would also piggyback other software. Most Bedep victims, however, are the result of the zero-day attacks in late January and early February, according to Trend Micro. It is said to be more than half of all infections. Once active Bedep used infected computers to commit fraud and ad click and install additional malware.

Thursday, 12 February 2015

Flash And Unpatched IE Vulnerabilities Used On Forbes.com

Visitors to the popular business magazine Forbes late November attacked via vulnerabilities in Adobe Flash Player and Internet Explorer, which at the time of the attack still no updates were available.According to security iSight Partners and Invincea involved a highly targeted attack.

The attack would be directed cons American defense companies and financial institutions, whose staff Forbes.com visit regularly. The website is according to Alexa on the 68th spot of most visited websites in the US Possible are also other parties and organizations affected by the attack, but it is not yet clear. The same is true for the attack period. Which would have taken place on 28 November to 1 December, but a longer period is not excluded. Besides Forbes would have used several obscure websites for the attack.

The attack took place through the "Thought of the Day" (totd) Adobe Flash widget that appears when someone visits a page or Forbes article. Then, use was made of a zero-day vulnerability in Adobe Flash Player, which eventually on December 9 by Adobe was patched. The attack was combined with a vulnerability in Internet Explorer to bypass the ASLR protection measure in the browser. Bypassing the security measure yesterday evening remedied by Microsoft. How many computers are infected by the attack have both security companies do not know.

Tuesday, 10 February 2015

Dailymotion Denies Showing Infected Ads


The very popular video website Dailymotion states that it has shown no infectious ads that tried to infect visitors with malware, but one security expert says that this is not true and users are indeed attacked. On February 2, warned anti-virus company Trend Micro that on Dailymotion.com were infected ads appeared who attacked a new vulnerability in Adobe Flash Player.

At the time of the attack, there was no security available. Were therefore users of Internet Explorer and Firefox on Windows that had Flash Player installed the risk of becoming infected with malware. The observed attack only worked against these two browsers. Later confirmed also anti-virus company Malwarebytes that the infected ads on Dailymotion.com had seen.

Yet Dailymotion poses in a statement that users will not be attacked. All advertisements should be checked namely. JuK security expert criticizes the statement. "That's not right," as he lets on Twitter know. He points to an analysis of the Fiddler tool. This shows that there are infected ads are displayed on Dailymotion.

Friday, 6 February 2015

Ads With Flash Attack On Popular Websites


On several popular websites are infected ads appeared that abuse of a vulnerability in Adobe Flash Player were true at the time of the attack no update was available. It is about the vulnerability where yesterday emergency patch for appeared.

Before the emergency patch was available display ads on various websites infecting users with Flash Player. It was Firefox and Internet Explorer users on Windows. Google Chrome users would have run no risk. It was already known that the infected ads on the wildly popular video site Dailymotion appeared. Now let anti-virus company Malwarebytes know that the ads also include theblaze.com , nydailynews.com , tagged.com , webmail.earthlink.net , mail.twc.com and my.juno.com shown.

The infected ads would have ended through a bidding process on the websites. For only 0.9 cents per impression they were eventually appear. Although this ad campaign was discovered recently left a researcher F-Secure recently know that this particular flaw in Flash Player possibly since December 20 last year will be used for attacks.

The emergency patch will be distributed via the automatic update feature of Flash Player. Google Chrome and Internet Explorer 10 and 11 on Windows 8 and 8.1, which have an embedded Flash Player, the update will eventually be rolled out by Google and Microsoft. However, these updates are not yet available. In the case of IE, users therefore advised to temporarily disable Flash Player or use a different browser.

Tuesday, 3 February 2015

Symantec Recommends Temporarily Disabling Flash Player


Internet users who are worried about the new vulnerability in Flash Player which no update is available, get anti-virus company Symantec's advice to temporarily disable the browser plug-in. The vulnerability allows cybercriminals in the worst case the computer can take over completely when users visit a compromised or malicious website or see infected ads.

The leak could have been used by infected ads on Dailymotion, one of the most popular video sites on the Internet. Users who have the website with Flash Player and Internet Explorer or Firefox on Windows visited at risk to be infected with malware. "Users who do not block ads and Flash are set to automatically play the most vulnerable," said Adam Winn software company OPSWAT.

He advises Flash Player from users who want to protect themselves against infectious ads to set Click to play and use an ad blocker. "Although controversial ad blocking a highly effective way that enables users to protect themselves against malvertising. An average user can these two things set up within an hour and be sure that he is nearly invulnerable to malvertising and Flash attacks in general "said Winn. Adobe announced this week that it comes with an emergency patch for the leak.

Monday, 2 February 2015

Adobe Vulnerability: "Warning New Attacked Flash Player Leak"

Internet users are warned again a new vulnerability in Adobe Flash Player which no update is available and actively used to infect computers with malware. The vulnerability is in Flash Player 16.0.0.296 and earlier versions.

Visiting a hacked or malicious Web site with a vulnerable Flash Player installation is enough to get infected. The attacks which until now have been observed to focus on users of Internet Explorer and Firefox on Windows 8.1 and older, according to the advisory . The leak, which is listed as CVE-2015-0313, was discovered by researchers at Trend Micro and Microsoft.

Adobe says that it will come this week with an emergency patch. It would be the third emergency patch in less than two weeks. Previously published a need patches on January 23 and January 26 . This emergency patches were for vulnerabilities via contaminated ads , among other porn sites were attacked. Through this page, Adobe, Internet users see which version of the software on their computers and what is the latest version.

Trend Micro let know that the new zero-day vulnerability has been used by infected ads on the website Dailymotion.com . A website according to Alexa on the 83th spot of most visited websites on the Internet is Dailymotion. Visitors to the popular video site were without them knowing redirected to a page with an exploit that made ​​abuse of the Flash Player leak. The attacks since January 14 monitored by the anti-virus company, which is from January 27 to see a spike in the number of users will be redirected to the exploit. Meanwhile the infected ads would not be shown on Dailymotion.