Showing posts with label Flash Player. Show all posts
Showing posts with label Flash Player. Show all posts

Wednesday, 5 September 2018

Google Chrome Will No Longer Show 'Protected' At HTTPS Sites



To celebrate the tenth anniversary of Google Chrome, a new version of the browser has appeared that does not show the word 'secured' at https sites, makes using Flash Player more difficult, introduces an improved password manager and fixes 40 security vulnerabilities.

On 2 September 2008 , Google launched its own browser, which has since become the dominant browser. According to StatCounter, Chrome has a market share of almost 68 percent on the desktop . In the Netherlands, around 54 percent of desktop users would browse with Chrome. Yesterday evening the 69th version of Chrome appeared that contains all kinds of new features and improvements.

This allows Chrome 69 to enter passwords, address details and credit card numbers more accurately. It is data stored in the user's Google account and accessible directly from the Chrome toolbar. The browser also has an improved password manager that can generate unique passwords for websites and accounts. Saved passwords are then available to users with a Google account on both the computer and mobile devices.

Furthermore, Chrome 69 does not show the word "secured" on websites with a secure connection. Only the lock icon indicates that a secure connection is being used. Eventually the lock icon will also disappear. Google decided in July to display the message "Unprotected" at all http sites. The internet giant wants https sites to be the norm and users will only see a notification at http sites.

Also, in the browser measures have been taken to make the use of Adobe Flash Player more difficult. Previously, users could whitelists websites that wanted to access the built-in Flash Player. That has now changed. Users must allow this separately each time a website wants to enable Flash content, regardless of whether they have done so in previous sessions.

In addition, Google has fixed 40 vulnerabilities in the browser that prevented an attacker from stealing or modifying data from other websites in the worst case scenario. Updating to Chrome 69.0.3497.81 will happen automatically on most systems. For Android users, Chrome 69.0.3497.76 has been made available.

Monday, 2 November 2015

Flash Player And Internet Explorer Favorite Cyber Criminal



Internet users who do not update their software run mainly risk of becoming infected with malware if they use Adobe Flash Player and Microsoft Internet Explorer, according to figures from the Russian anti-virus firm Kaspersky Lab. This involves infections via so-called "drive-by downloads."

These cyber criminals use of exploit kits, which automatically infect Internet through unpatched vulnerabilities with malware.Most kits include attacks to exploit vulnerabilities in IE, Flash Player and Silverlight. It is in all of these cases vulnerabilities this year by Adobe and Microsoft were patched. We look at the attacked software, it is mainly Flash Player and Internet Explorer. Attacks on Java even took off. In recent exploit kits there are no exploits for Java included.

Kaspersky Lab also looked at attacks from "web resources" and where those resources are located. 

Sunday, 1 November 2015

Fraudulent Android App Appears As A Word Document


Researchers regularly rogue Android apps by posing as porn app or Flash Player, but now there's also discovered a malicious app that will let the user into believing that it is a Microsoft Word document. For example, the icon of the app resembles that of Word.

The file allows users think that matters 'data'. If the file is opened, the app asks for administrator privileges. After installation, the malware seeks to SMS messages and other information like IMEI number, SIM card number, device ID, contact information and other matters and sends it to the attacker. The malware can also send text messages and dial phone numbers specified by the attacker. The app is aimed at Chinese users and is distributed outside of Google Play.

According to security firm Zscaler, discovered that the app is not surprising that PC-based malware techniques appear in the mobile domain, since mobile devices are now ubiquitous. For Windows, there is still active malware via common icons and file names occurs as a document and try to entice users to open.

Friday, 30 October 2015

Recent Poem Flash Leak In Crosshairs Of Cyber Criminals



A critical vulnerability in Adobe Flash Player which ten days ago an emergency patch rolled out is now being actively attacked by cyber criminals. At the time Adobe update rolled out the company claimed that the vulnerability was used only in targeted attacks on a limited scale.

Now reports researcher JuK of the blog Malware do not need Coffee that an exploit of the vulnerability using the Angler-exploitkit added. Consequently have less technical knowledge cybercriminals with the means to attack the Flash leak. The Angler exploitkit was in recent months in large-scale advertising campaigns on popular websites used.

Criminals use this ad network of popular websites to spread infected ads. These ads send visitors unnoticed to a page with the Angler-exploitkit. In case users have their Flash Player or other software is not up-to-date, they can become infected with malware. Now the recent poems Flash leak also been added to the Angler-exploitkit cyber criminals have a greater opportunity to infect internet users, since the update of October 16 may not yet installed anywhere.

In case the attack is successful, the Bedep Trojan is installed on computers. This Trojan can install additional malware, including malware for advertising fraud and ransomware, and the computer part of a botnet. The Flash vulnerability was two weeks before the attack on the 'wild' was discovered already by Google to Adobe reported. Through this page to monitor Internet users whether they are using Flash version.

Wednesday, 28 October 2015

Update 450 Million Users Shockwave Player



More than 450 million people get from Adobe advised to install an important update for Shockwave Player within 72 hours. Shockwave, not to be confused with Flash Player is a browser plug-in, for example to play games. According to Adobe runs on more than 450 million systems.

The now discovered vulnerability allows attackers to execute arbitrary code on the computer. Visiting a hacked or malicious website is enough in this case, no further action is required. Adobe makes installing the update, then the highest priority with a time window of up to 72 hours is recommended. One problem with Shockwave is that it does not have an automatic update feature. Users will also have Adobe Shockwave Player 12.2.1.171 using the Adobe website must install to have the most recent version in which the problem is solved.

Thursday, 24 September 2015

American 'Funda' Spread Malware Via Infected Ads


Cyber criminals are again managed to place infected ads on a very popular website with tens of millions of visitors who attempted to install malware. It is Realtor.com, the US counterpart of Funda which all kinds of real estate is offered.

The website is according to market researcher Alexa at the 101st place of most visited websites in the United States and a 485ste place worldwide. It is estimated that Realtor.com monthly 28 million visitors. The attackers previously infected ads on the English website of eBay, Drudge Report and other major websites were seated according to anti-malware company Malwarebytes also behind this attack. Through advertising network Adspirit.net the affected ads were posted on the website.

The ads sent visitors without being noticed this through to a website with the Angler-exploitkit. This exploitkit uses known vulnerabilities include Adobe Flash Player and Internet Explorer to install malware. For whatever it's malware was not disclosed. After being informed, the publisher of Realtor.com and Adspirit off the ads. Internet users whose software was up-to-date were no known risk. Yesterday it became known that criminals a week infected ads on Forbes.com have shown.

Wednesday, 23 September 2015

Forbes.com Spread Malware Via Infected Adverts


On the very popular website of business magazine Forbes have been infected for some time ads shown to infect visitors with malware tried. Forbes.com state according to market researcher Alexa on the 74th spot of most visited websites in the United States and the 154th place worldwide.

The website is monthly by more than 31 million visited visitors. Those visitors were from 8 to 15 September dished ads so they were undetected to a website with the Angler- and Neutrino-exploit kits. This exploit kits exploit known vulnerabilities include Adobe Flash Player. In case there is no up-to-date software was used silently malware could be installed on the computer, says security firm FireEye.

For what exactly will the malware was not disclosed. The ads were via an advertising service from a third party displayed on the Forbes website. According FireEye use of contaminated advertising remains a popular attack method for criminals.Via advertising platforms, especially those that hold real-time auctions for ad space, attackers can choose exactly where their malicious content is displayed.

In case the infected appear ads on popular websites the chance of massive infection is significantly increased, allowing both users and businesses at risk, according to the security company. After being informed Forbes has removed the infected ads. Last year, even though malware via Forbes.com spread. When attackers used a widget on the website that zero-day vulnerabilities in Internet Explorer and Adobe Flash Player attacked.

Tuesday, 15 September 2015

Infected Advertisements On EBay Weeks Remain Unnoticed


Cyber criminals are recent weeks managed to commonly-used ad networks like DoubleClick and AppNexus a large number of infected ads on popular websites such as eBay, Drudge Report and Answers.com get without that were noticed initially.

Which claims anti-malware company Malwarebytes. The attackers pretended to be legitimate advertisers and offered their ads through various real-time auctions to. Several ad networks allow advertisers bidding through auctions on the available ad space. To convincingly come across criminals used the companies that were registered with the US Chamber of Commerce, whose websites were sometimes recorded years ago.

According to analyst Jerome Segura was enough to fool most ad networks. The ads themselves were not provided with malware, but visitors were redirected to a page via an abbreviated URL that contained the Angler-exploitkit. This exploitkit uses vulnerabilities in Flash Player, among others. In the case the attack was successful Bedep the Trojan was installed on computers.

This Trojan can install additional malware on the computers, as malware, ad fraud and ransomware. The ads appeared on the UK eBay site, which receives 139 million monthly visitors and Drudgereport.com, which receives 61 million monthly visitors. All affected websites monthly gain of about 500 million. In total, the infected ads would have turned nearly three weeks undisturbed. Internet users whose software is up to date ran no risk in this attack.

Wednesday, 9 September 2015

Website Headache Centers New Twitter Malware



At several websites attackers have posted malicious code that attempt to infect visitors with malware. It is the Society's website of Dutch Headache Centers and New Twitter, says security researcher Yonathan Klijnsma via Twitter.

In the case of New Twitter that Twitter has more than 10,000 followers, the added code points to the Angler-exploitkit. This exploitkit uses known vulnerabilities, including Adobe Flash Player. What malware is being spread Klijnsma do not know by exploitkit. Angler among other things used to install the Bedep Trojan on unpatched computers.

This Trojan may download additional malware onto the computer and use the system for various forms of cyber crime, such as click and advertising fraud. Klijnsma, also a researcher at the Delft security firm Fox-IT, warned in recent weeks regularly for hacked websites which malware spread. According to the researcher, there is a campaign in which criminals hack into websites and provide malicious code.

Saturday, 8 August 2015

Chrome Will Block Deceptive Inline Installations



To protect Chrome users from unwanted extensions, Google has announced a new measure. From September, the browser inline installations of extensions that originate block of misleading websites and advertisements.

Inline systems were introduced in 2011 as a way to easily install extensions from the website of a developer. The mechanism is now used by Web sites to trick users into installing unwanted extensions. So users can get a pop-up stating that they need to update their Flash Player to view the video. However, the pop-up does not point to Flash Player, but an inline installation of another extension.

According to Google unwanted extensions are a major annoyance for users and a major source of complaints. In recent years, the company decided to take several measures. Blocking of inline installations, there is one of them. The blockade starts on September 3rd. In this case, Chrome will block the installation and users can now send it to the Chrome Web Store, so they can decide as to whether or not to install the extension. The new measure would affect less than 0.2% of all extensions, but it is an important measure to keep the extension ecosystem healthy, says Andrew Kim from Google.

Sunday, 26 July 2015

US Government Attacked Via Flash Player Flaw


Several agencies of the US government in June and July attacked via a Flash Player vulnerability that was discovered by the Italian Hacking Team and true at the time of the attacks had no patch yet, says the FBI. Details about the vulnerability were found in the data that were stolen from the Italian surveillance company. However, the break-in at Hacking Team was made ​​public on July 6.

Now, according to information from the FBI's Flash Player flaw had been since June 8 by assailants known and actively used to penetrate US government agencies. Previously had anti-virus company Trend Micro already know that the vulnerability before the disclosure in targeted attacks against targets in Korea and Japan had begun, namely July 1 . The FBI goes in the case for the attacks against US government agencies for two campaigns which probably gathering information aim.

Campaigns

The first phishing campaign took place on 8, 9 and 11 June, the second was observed on July 8, according to a warning that spread the FBI and by Public Intelligence online ( pdf is put). Both attacks emails were sent with a link. The link pointed to an exploit that took advantage of the vulnerability in Flash Player. The attack on July 8, the FBI more information mentioned in the warning. Thus, the government received a spear phishing e-mail with a link to a PDF document. When users opened a website loaded there the link containing JavaScript code. This code then loaded a malicious Flash file that vulnerability in Flash Player attacked to infect your computer with malware.

The spear phishing emails had different topics such as 'BBW Analysis report - 2015', 'Tomorrow Morning New Starts', "Perry Dale Club for Leadership: Financial Literacy 101", "FAS Analysis Report - 2015", "AEP Energy Program Update: 2015 Program Year Kick Off ',' Review Link "and" PLS Account A42660861. All spear phishing emails that were submitted in July had the same sender. The timing of the attack in July is remarkable, because on July 8 wrote poetry namely the vulnerability in Adobe Flash Player version 18.0.0.194 and earlier on an emergency patch . In the warning, the FBI also recorded several IP addresses and domains that were used by the attackers and can help detect a possible attack.

Saturday, 18 July 2015

Zero-Day Vulnerability In Microsoft Office Used For Cyber-Espionage


Last Tuesday, Microsoft patched a zero-day vulnerability in Office, which recently has been actively used by a group engaged in cyber espionage. The group sent at least one RTF document on the nuclear negotiations with Iran. The document, which was discovered in Georgia, contained an exploit for a critical vulnerability in Microsoft Office 2013 Service Pack 1 and earlier versions of Office.

Once users opened the paper exploits document was replaced by a genuine document with information on the nuclear negotiations. In the background, however, was installed a backdoor that attackers had full control over the computer, says security firm iSIGHT Partners . According to the company, the group behind the attacks also associated with a recently patched zero-day vulnerability in Java that was also used in targeted attacks.

The group would in April two zero-day vulnerabilities in Flash Player and Windows have used and the recently unveiled Flash exploits which was available to the Italian Hacking Team. The group would have to cater for the collection of military and diplomatic intelligence, although telecoms and defense companies have been targeted. The Office leak that the group is used patched by MS15-070 .

Tuesday, 7 July 2015

Hacking Team Had Zero Day Vulnerabilities For Windows And Flash



The Italian developer of government spyware Hacking Team had zero day vulnerabilities for Windows and Adobe Flash Player, according to the files that were stolen from the company. Yesterday published attackers a file of about 400GB with all sorts of information that was captured by Hacking Team.

The files have now discovered two vulnerabilities for which no security update available yet, says security researcher The Grugq . It is a vulnerability in Windows that allows an attacker can increase his rights on the system. In this case, the attacker must already have access to the computer in order to use the leak. The second vulnerability is in Adobe Flash Player. Through this vulnerability, an attacker computers or completely take over, for example, when users visit a hacked or malicious website.

The embedded Flash Player in Google Chrome is vulnerable. According to security researcher Kevin Beaumont makes the leak is possible to escape from the sandbox of Chrome. Researcher Rik van Duijn of security Dear Bytes however, leaves know that a sandbox escape "through the published code is not possible and therefore a second exploit is required. Hacking Team, which develops spyware for government agencies, has in statement confirming that it has been hacked. "We think there are documents of the company have been stolen. We have launched an investigation to determine the extent of the attack and to determine what exactly is captured," said a spokesman. The company's website has been offline since yesterday.

Update

The National Cyber ​​Security Center (NCSC) government has a warning issued for the flaw in Flash Player. Through the leak, an attacker execute arbitrary code on the computer with the rights of the logged in user. The NCSC states that there is no update available for the leak yet.

Update 13:48

The attack on Hacking Team is claimed by the hacker who last year by spyware developer Gamma International managed to break in and there gigabytes of data was captured, says Vice Magazine . The hacker says soon come up with the details of how he managed to break into Hacking Team.

Update 15:09

Anti-virus company Symantec confirms that this is a zero-day vulnerability in the latest version of Flash Player. The virus firefighter expects that attackers will probably make use of the vulnerability.

Update 15:19

The CERT Coordination Center (CERT / CC) at Carnegie Mellon University warns also the vulnerability and says that users can protect themselves by installing Microsoft EMET unreliable or not Flash content to perform.

Monday, 6 July 2015

Disguised As MP3 EXE Get Hundreds Of Clicks Per Day



Drive-by downloads and email attachments are still very popular ways to infect internet users with malware, so get daily also infected many users as they download executable files that they think are mp3s or illegal software.

It mainly involves users who search on Google for example songs. By manipulating the results cyber criminals know their pages with "tracks" to get high in the index of Google and so these users to lure to their website. The songs offered themselves as MP3 files, but in reality .exe files. However, Windows displays the default file extension is not. Once the files may contain malware or potentially unwanted software downloads, warns security company Blue Coat .

Software piracy

Security firm Zscaler recently paid attention even to the same strategy for infecting Internet users, only through so-called illegal software. Again it goes to sites offering exe files that occur for example as popular games, software and drivers. In reality, it is adware / spyware named OutBrowse and Multiplug. The programs collect information about the user and send them back and show unsolicited ads.

According to analyst Chris Mannon the problem lies mainly with the awareness of Internet users "Users know reliable download sites for software such as Flash Player or Skype, but as they search for pirated software and media, any link that promises results suddenly familiar." Mannon also advises users to content that is obtained illegally not to be trusted. "Users make bad decisions if they think the desired content can be obtained free of charge. We recommend downloading illegal content occasionally advise to pay just for the desired media."

Saturday, 4 July 2015

Malware Install Flash Player Update On Infected Computers


Vulnerable versions of Adobe Flash Player have become a popular target for cyber criminals to infect computers with malware. Reason for Kovter malware to update after infection from a computer to the existing Flash Player, so other malware can not infect the system.

Kovter can use computers to commit fraud ad (click fraud) or install ransomware. The malware can spread through various ways, such as contaminated ads that make unpatched Flash Player vulnerabilities use but can also be installed on computers that are already part of a botnet. Security Researcher JuK of the blog Malware Do not Need Coffee discovered the new method of malware.

The system that the researchers used for finding exploits suddenly decided to download Flash Player, whereas that was not the intention. The system must remain fragile namely, JuK notes. Further investigation revealed that it was the Kovter malware that the Flash Player update was downloaded and installed. It is not the first time that malware is taking measures to prevent infection by other malware. The betabot has, for instance an option to prevent attacks using Java and Adobe Reader.

Thursday, 28 May 2015

Android Ransomware Not Give Paying User Penalty


Last week, more than 15,000 e-mails are sent with Android ransomware that occurs when a security update for Adobe Flash Player. The messages contain little text, except that the enclosed APK file, "Check Updates.apk" is an update to Flash Player.

In reality, it is ransomware that locks the device and a warning from the FBI shows. According to the warning, the user would have viewed pornographic websites. To unlock the device must be an amount of $ 500 to be paid. If the user attempts to unlock the device, the amount is increased to $ 1,500, reports the Romanian antivirus company BitDefender .

According to the Spanish security company S21sec ransomware makers find new ways to spread their creations. Currently used mainly social engineering, but new capabilities are added continuously, according to the IT security officer. Users also are advised to install APK files from untrusted sources and email filtering with MOT attachments.

Wednesday, 13 May 2015

Website Chef Jamie Oliver Hacked For Third Time


Attackers are there for the third time succeeded in hacking the website of the British chef Jamie Oliver and use for distributing malware. Previously it had been hit in February and March . As with these incidents the attackers malicious code added to jamieoliver.com.

This code sends visitors unnoticed to another website through which uses known vulnerabilities in Adobe Flash Player and Java to infect visitors with malware. It is malware that attempts to steal passwords. In case the software of visitors up-to-date, they are not at risk. The team that know the website of Oliver would be responsible of the incident and take measures to solve the "once and for all", says anti-virus company Malwarebytes . How the attackers were able to gain access to site is unknown.

Sunday, 15 March 2015

Website Chef Jamie Oliver Spreading Malware Again


The website of the British chef Jamie Oliver has been hacked again and again spreading malware. The site places attackers malicious code that visitors unnoticed forward to another site. This site contains the Fiesta exploitkit which makes abuse of vulnerabilities in Flash Player, Silverlight and Java.

These are vulnerabilities where all updates to be available. Users who are up-to-date are therefore not at risk. In case users are not up-to-date, it will install a Trojan horse, which is recognized by few virus scanners on VirusTotal. In addition, the malware is signed, even though the certificate used now no longer valid, as reported anti-virus company Malwarebytes. The virus fighter discovered the first hack the website and then warned webmasters that it fixed the problem. Or so it seemed.

The structure used by the attackers to now placed malicious code is very similar to that of the first attack. "That's why we think this is the same infection that was not completely removed or perhaps that a vulnerability in the server or content management system (CMS) is still present," said the researchers. Oliver's website is on the 536ste place of most visited websites in Britain and would attract 10 million visitors each month.

Friday, 13 March 2015

New Ransomware Encrypts Computer Games And iTunes


Researchers have discovered a new form of ransomware that encrypts data from popular computer games like Call of Duty, Minecraft and World of Warcraft, as well as files from iTunes. It is a variant of the Crypto Locker ransomware via a recently patched flaw in Flash Player and a parent leak in IE spreads, let security bromine in a report to know.

For this, use the cyber criminals flash ad banners. An infected banner sends visitors to the website on which it is displayed automatically to another website, where it attempts to infect your computer through vulnerabilities in IE and Flash Player.Remarkably, the banner only users of Internet Explorer and Opera forward.

The attack is successful, the ransomware 185 will encrypt various file extensions. It also includes those stocks of computer games. Something unprecedented as bromine. The ransomware looks for specific games and gaming software directories like Steam, publishers, and development software. What is striking is that there are many "classics" stand between, like Diablo, Fallout 3, Half-Life 2 and WarCraft 3. Also, several online games targeted, including World of Warcraft, Day S, League of Legends and World of Tanks.

Evolution

"Encrypting these games shows an evolution in the crypto-ransomware which cyber criminals focus on niches," said the researchers. According bromine may be that young adults have no important files on their computers and store photos in the cloud. "But most certainly have a Steam account with some games and an iTunes account full of music."

"Even for adults these attacks can be frustrating, as they lose their games with the rest of their personal data." Remarkable about the games that are encrypted that these popular games, but not for games that currently top the list of most played and best-selling games. It is therefore possible that the ransomware maker games has chosen who he likes to play.

Monday, 23 February 2015

Shop Sees Increase In Adware Mac Users


A US store warns Mac users to download software only from the official supplier, after it saw an increase in clients who were infected with adware. According to Annie Hayes iCape Solutions is the number of Mac customers that come along because adware increasing.

"Although Macs are resistant to viruses, we have an increase of adware / malware seen as Genio and Install mac," says Hayes. This is because according to its Mac users software such as Adobe Flash Player for free outside the official Adobe website. Once active adware modifies the home page and search engines and injects ads. "In order to avoid this kind of programs you should only download programs from a reliable place. For example if you need the latest version of Flash, make sure that you are on the genuine Adobe website."

Another problem that the Mac store regular customers see return is MacKeeper. This is a program that claims to optimize Mac OS X systems and to protect the privacy of users. "I can give you a million reasons to avoid it, but I refer to this article on iMore , "Hayes says. "Ordinary users do not need anti-virus software or cleaner, and much of what is in circulation resembles MacKeeper, a program designed to let you pay for a service."