Delete Or Update All Adobe Flash Player Instances, Experts Warn (threatpost.com)
An anonymous reader quotes an article from BankInfoSecurity:
Security experts are once again warning enterprises to immediately update -- or delete -- all instances of the Adobe Flash Player they may have installed on any system in the wake of reports that a zero-day flaw in the web browser plug-in is being targeted by an advanced persistent threat group.... The bug exists in Adobe Flash Player 21.0.0.242 and earlier versions -- running on Windows, Mac, Linux, and Chrome OS -- and "successful exploitation could cause a crash and potentially allow an attacker to take control of the affected system."
Thursday Adobe released an updated version of Flash patching 36 separate vulnerabilities, including the critical vulnerability which "if exploited would allow malicious native-code to execute, potentially without a user being aware." While applauding Adobe's quick response, researchers at Kaspersky Lab say it's already been exploited in Russia, Nepal, South Korea, China, India, Kuwait and Romania, and BankInfoSecurity writes that "The latest warning over this campaign reinforces just how often APT attackers target Flash, thus making a potential business case for banning it for inside the enterprise."
Flash is literally a zombie at this point.
Ok, so if we stick with Flash we might be subjected to security problems.
But if we stick with HTML5-based technologies, then we'll just be more easily tracked by advertisers.
Sounds like we are fucked in both cases!
Since you haven't listened to the 483 times we have told you before, we will tell you again. Uninstall Flash Player. That is all.
For undermining security to try and trick users into installing McAffe when upgrading. That should be opt IN not opt OUT.
Flash was never a "standard". I've always recommended clients to get rid of Flash sites because it wasn't a standard and not everyone could use it. When Flash was first introduced, a large number of people were still on dial-up and Flash sites were a big no-no because by then we already knew that people would click away if their site didn't load in 5s or less. Flash was then marketed towards people marketing towards broadband (video and interactive sites and DHTML were going to be all the rage once everyone got broadband).
When everyone started getting broadband, companies like Google sprang up (or rather, became embedded in the culture) and "SEO" became the buzzword, Google wasn't Flash-aware or compatible, Flash was dead as a 'standard' platform for 'broadband' because no 3rd party company (outside Macromedia and later Adobe) wanted to support it.
It eventually got taken over by Adobe and it was dead then because nobody trusted Adobe to fix it. It had many security issues already and many compatibility issues even within it's own tools. Adobe never fixed it, they just kind of half-integrated it with the rest of their suite but they effectively put it on life support. When Apple released the iPhone, Flash was dead and now it's just being this zombie process you know you have to get rid of at some point, but you don't really want to because maybe you may need it in some obscure corner of the web.
Custom electronics and digital signage for your business: www.evcircuits.com