Skip to main content

Adobe Patches Flash Zero-Day Used by BlackOasis APT

  • October 16, 2017
  • 2 replies
  • 7 views

Jasper_The_Rasper
Moderator
Forum|alt.badge.img+54
October 16, 2017  By Catalin Cimpanu
 


 
Last week, Adobe claimed it wouldn't release security updates for the first time since July 2012 because it had nothing to patch.
 
Less than six days later, the company released a critical update for Flash Player that fixes a zero-day vulnerability exploited in live attacks.
 
The zero-day, CVE-2017-11292, is a "type confusion" that leads to remote code execution on targeted systems.
 
The issue affects Flash Player 27.0.0.159 on Windows, Linux, macOS, and Chrome OS. Adobe fixed the vulnerability in Flash Player version 27.0.0.170.
 
Full Article.

2 replies

  • New Voice
  • October 16, 2017
My original attack two years ago used a Mac Safari plugin on my wifes Mac computer popping open modal (!) dot net windows laughing at me from a money web site post I made. The details were provided to homeland security through Webroot and I stayed silent and began my security tightening program. There were two other pieces of software that had to be compromised IMO for it to have happened. Microsoft fixed them all in patches. Kudos. 60 minutes exposed the SS7 (AKA skype) and 36 (!) flash plugin problems 9 months or so later. Such began my descent into darkness.
 
The most sophisticated cross platform attack I have ever seen. Triggered by my comment on a website that I use trip wires all the time on my computer like James Bond when he placed a hair across his suitcase and left the room. They same jokers mocked me and stepped on my tripwire and blew themselves up. Riling up emotions is a good way to catch them. They often have a cause but their own passion does them in. Military  grade infections are not so easy to detect. Are they laughing now trip wire folks? Not sure.
 
We don't use flash anymore as a basic household security rule. Your mileage may vary. FWIW.

  • Community Guide
  • October 16, 2017
Well they woke up and smelled the coffee and patched.....................................