Emergency Adobe Flash Patch Fixes Zero-Day Under Attack
msm1267 writes: Adobe has released an emergency patch for a Flash zero-day used in targeted attacks by APT3, the same group behind 2014's Clandestine Fox attacks. Adobe said Flash Player 18.0.0.161 and earlier for Windows and Macintosh systems are affected, as is 11.2.202.466 for Linux 11.x versions.
The current iteration of Clandestine Fox attacks shares many traits with last year's attacks, including generic, almost spam-like phishing emails intent on snaring as many victims as possible that can be analyzed for their value before additional attacks are carried out. The two campaigns also share the same custom backdoor called SHOTPUT, as well as an insistence on using a throwaway command and control infrastructure.
The current iteration of Clandestine Fox attacks shares many traits with last year's attacks, including generic, almost spam-like phishing emails intent on snaring as many victims as possible that can be analyzed for their value before additional attacks are carried out. The two campaigns also share the same custom backdoor called SHOTPUT, as well as an insistence on using a throwaway command and control infrastructure.
Any relation to the CrytoWall virus? So far three companies that I know of got hit hard by this SOB. I've blocked TOR and i2P traffic in attempt to break future contact between infected computers and it's bonet/C&C servers. CryptoWall is a nasty motherfucker!
Life is not for the lazy.
i said it before and i'll say it again.
there are very few reasons to keep flash installed/enabled. if you must have it, use flashblock but chances are you can just disable/remove it completely. if some site still uses flash to play video, leave a complaint in the comments. those that haven't switched to html5 yet will do so soon enough.
if you still have java plugin installed, you better have a good reason because no (sane) sites use that shit.
Anons need not reply. Questions end with a question mark.
Fuck. Another goddamn Adobe update? Fuck Adobe updates.
Youtube uses HTML5 now. Why does anyone still have a reason to use flash? (I mean besides for watching pr0n, which you do inside a virtual machine, and you restore to a checkpoint afterwards to completely avoid any possibility of malware infestation or cross-session cookies, right?)
tl;dr: Uninstall flash. You don't need it anymore.
vmware vsphere is still flash based
need to crush their candy and blitz their jewels.
How does Adobe distinguish between 'normal' and 'emergency' when it comes to attacks facilitated by the Adobe Malware Runtime?
I have de-installed the "Flash" malware some time ago and it will _not_ find its way on my computer again. This thing is a solution for nothing, but a persistent problem. It really is a pity, Adobe used to make good software. Not anymore.
Most ACs are not even worth the keystrokes to insult them. Be generically insulted by this and ignored otherwise.
I look forward to the Flash programmers soon being tried for their crimes against humanity.
Hmm. Maybe not, as it will probably be broadcast using Flash.
If they were a female hacker group, they should haven take the name APT3-G. That would have made the "Clandestine Fox" attack even more deliciously-named.
Drives me nuts ever week or so asking me to install updates. It's a stupid pop-up updated app that gets triggered when a page with flash is loaded.
Yes I understand that running a browser non-stop for weeks goes against their updating philosophy. Too bad. The constant "Update now!" alerts just make their users more likely to fall for phishing scams.
Instead, if you can't update your plugin on already loaded pages... Refactor your app.
Make the bit loaded by the browser a wrapper that can allow its back end to update when convenient. Otherwise everyone who uses tabs is going to hate you. (Those who don't already)
Cwm, fjord-bank glyphs vext quiz
As long as he's getting paid well, why should he change? (Unless something better comes along of course.) This isn't his personal computer, it's his work computer. If you have shitty software on your work PC and it causes problems, who cares; just call IT, and when your manager complains about slipped schedules you can blame the crapware and IT.
For personal stuff though, you can't blame others when flash fucks up your PC. So he should find another bank.
Mozilla couldn't run a piss-up in a brewery these days, I went to the plugin check page and it is broken, no plugin check, no link to adobe.
Waterfox - a Firefox fork with legacy extension support, security updates and better privacy by default.
Despite me or my predecessor not loading Flash onto any systems we images and put out, I found it's on about 85% of our user's systems. Today I finally caved after seeing this and pushed the latest MSI from Adobe with this patch included out via GPO. Nearest I figure you're better controlling the beast than letting it run rampant and make sure users stay up to date. Tomorrow I will checking with management and pushing Chrome MSI as well to force users to use Chrome for all non local-Intranet sites.