Welcome to DU! The truly grassroots left-of-center political community where regular people, not algorithms, drive the discussions and set the standards. Join the community: Create a free account Support DU (and get rid of ads!): Become a Star Member Latest Breaking News General Discussion The DU Lounge All Forums Issue Forums Culture Forums Alliance Forums Region Forums Support Forums Help & Search

bananas

(27,509 posts)
Wed Jul 8, 2015, 01:42 PM Jul 2015

Adobe Flash exploit that was leaked by Hacking Team goes wild; patch now!

Source: Ars Technica

Hours after the 0day was found, it was added to popular exploit kits.

Adobe Systems has updated its Flash media player to patch a vulnerability that attackers started exploiting soon after attack code leaked from the devastating Hacking Team breach.

As Ars reported Tuesday morning, the previously unknown Flash vulnerability was part of some 400 gigabytes of data dumped on the Internet by unknown attackers who hacked Hacking Team over the weekend. By Tuesday afternoon, the critical flaw was being targeted in the wild by an array of malware titles, including the Angler and Nuclear exploit kits, as first reported by Malwarebytes (and later documented by the security researcher known as Kafeine). The exploit has also been folded in to the Metasploit hacking framework.

The vulnerability is cataloged as CVE-2015-5119 and is active in Flash versions 18.0.0.194 and earlier. According to security firm Rapid 7, it stems from a use-after-free bug that can be exploited while Flash is handling ByteArray objects. The update is available for Windows, Mac OS X, and Linux systems. Adobe has credited Google's Project Zero and Morgan Marquis-Boire, director of security, First Look Media, for reporting the critical bug and working to protect Flash users.

With the exploit folded into exploit kits that are available on the Internet, users who rely on Flash should install the update immediately (don't forget to uncheck the boxes Adobe shamelessly checks by default to promote crapware). Readers may also want to experiment with uninstalling Flash altogether. If the results are acceptable, that's a more secure alternative since it drastically reduces attack surface.

<snip>

Read more: http://arstechnica.com/security/2015/07/adobe-flash-exploit-that-was-leaked-by-hacking-team-goes-wild-patch-now/

29 replies = new reply since forum marked as read
Highlight: NoneDon't highlight anything 5 newestHighlight 5 most recent replies
Adobe Flash exploit that was leaked by Hacking Team goes wild; patch now! (Original Post) bananas Jul 2015 OP
So, do I need to reboot and let Adobe update? House of Roberts Jul 2015 #1
is this true??..... riversedge Jul 2015 #2
does no harm to hit the update link PatrynXX Jul 2015 #12
?? Obama bothered to say don't a few years ago but some of us don't have much choice Romeo.lima333 Jul 2015 #21
Surveillance company loses control of flagship spy program bananas Jul 2015 #3
so, this must be the expected Wednesday patch.. riversedge Jul 2015 #4
I presume so, but haven't verified it myself. bananas Jul 2015 #6
That explains the Wall Street shutdown. Orrex Jul 2015 #5
Leaked Documents Show That the FBI, DEA and Army All Purchased Hacking Team Spyware bananas Jul 2015 #7
Deleted 18.0.0.194, then installed 18.0.0.203. About 5 minutes. Elmer S. E. Dump Jul 2015 #8
thanks riversedge Jul 2015 #10
Thanks LittleGirl Jul 2015 #22
Do you really have to delete .194 or can you just update? gvstn Jul 2015 #23
I don't think it's required. I just did it that way. Elmer S. E. Dump Jul 2015 #27
Did same. Thanks to all. n/t Paper Roses Jul 2015 #24
BBC: Adobe tackles new Flash threat after Hacking Team leak bananas Jul 2015 #9
Monday: Italian surveillance company hacked, documents stolen bananas Jul 2015 #11
Wow... SoapBox Jul 2015 #13
UPDATE and/or DISABLE flash: Triana Jul 2015 #14
Thanks for Letting Us Know Leith Jul 2015 #15
I just did an Adobe update two days ago. PADemD Jul 2015 #16
Yes, this is after last weeks update. herding cats Jul 2015 #18
Adobe Flash should just go away. hunter Jul 2015 #17
Flash has been the number one avenue for spyware for years. onehandle Jul 2015 #19
I might just do that, Delphinus Jul 2015 #28
To check your version number... PoliticAverse Jul 2015 #20
If you running chrome, it should be updated automatically passiveporcupine Jul 2015 #25
Bookmarking for later Thanks! LiberalElite Jul 2015 #26
K and r dembotoz Jul 2015 #29

riversedge

(70,242 posts)
2. is this true??.....
Wed Jul 8, 2015, 01:46 PM
Jul 2015

This was posted at the end of the article.....


Promoted Comments

acetothermusSmack-Fu Master, in training
jump to post
Instead of going to Adobes "main" download page go here...

http://www.adobe.com/products/flashplay ... tion3.html

Always download the offline installers of these apps because you don't get the crapware. Just the app you want to update.

PatrynXX

(5,668 posts)
12. does no harm to hit the update link
Wed Jul 8, 2015, 02:18 PM
Jul 2015

Considering the source I would say PATCH IT. if you installed it. Obama bothered to say don't a few years ago but some of us don't have much choice

bananas

(27,509 posts)
3. Surveillance company loses control of flagship spy program
Wed Jul 8, 2015, 01:49 PM
Jul 2015
http://phys.org/news/2015-07-surveillance-company-flagship-spy.html

Surveillance company loses control of flagship spy program
42 minutes ago

Italian surveillance company Hacking Team said Wednesday that it had lost control of its custom-built spy software, unleashing a new threat onto the Internet and depriving the company of its top selling point.

In a statement, Hacking Team said it believed anyone could now deploy its RCS software "against any target of their choice."

"We believe this is an extremely dangerous situation," the company said.

<snip>

Meanwhile software maker Adobe Systems Inc. says it is hoping to fix a critical flaw in its Flash Player program which was revealed when RCS became public.

A patch is expected later Wednesday.


bananas

(27,509 posts)
6. I presume so, but haven't verified it myself.
Wed Jul 8, 2015, 01:56 PM
Jul 2015

And I'm busy with other stuff, so I won't get to it til much later today.

gvstn

(2,805 posts)
23. Do you really have to delete .194 or can you just update?
Wed Jul 8, 2015, 04:53 PM
Jul 2015

I haven't seen any posts that say the old must be deleted and the new installed from scratch.
Are you just being cautious or is there a particular reason?
Thanks!

bananas

(27,509 posts)
9. BBC: Adobe tackles new Flash threat after Hacking Team leak
Wed Jul 8, 2015, 02:05 PM
Jul 2015
http://www.bbc.com/news/technology-33442789

Adobe tackles new Flash threat after Hacking Team leak
By Chris Foxx Technology reporter
8 July 2015

Adobe has updated its Flash software to fix a security hole, which was made public only after data was stolen from an online surveillance company.

Italian firm Hacking Team sells spying software to intelligence agencies around the world.

On Sunday, private data stolen from the company was posted online, indicating it knew about a serious flaw in Flash, but had not told Adobe.

One security blog said the bug had been "immediately weaponised" by attackers.

"This is one of the fastest documented cases of an immediate weaponisation in the wild, possibly thanks to the detailed instructions left by the Hacking Team," wrote Jerome Segura from Malwarebytes.

<snip>

bananas

(27,509 posts)
11. Monday: Italian surveillance company hacked, documents stolen
Wed Jul 8, 2015, 02:07 PM
Jul 2015
http://www.ksl.com/?nid=235&sid=35376689

Italian surveillance company hacked, documents stolen
By Raphael Satter, Associated Press
July 6th, 2015 @ 12:51pm


LONDON (AP) — An Italian surveillance firm known for selling malicious software used by police bodies and spy agencies has succumbed to a cyberattack, the firm's spokesman said Monday, confirming an embarrassing breach which sent documents and invoices ricocheting across the Internet.

<snip>

Still, some of the billing records being shared online appeared to corroborate work by Citizen Lab, a research group at the Munk School of Global Affairs at the University of Toronto, which has linked Hacking Team to two dozen countries, including several with atrocious human rights records.

"Early reports ... appear to validate our research showing use by repressive regimes like Ethiopia and Sudan," Citizen Lab said in a statement. "These reports point to the lack of transparency and accountability around the market for intrusion software. We think that a better understanding of this market is essential for a free and secure Internet."

The Milan-based company has been the subject of increased scrutiny after its malware was discovered targeting a series of journalists and activists.

SoapBox

(18,791 posts)
13. Wow...
Wed Jul 8, 2015, 02:37 PM
Jul 2015

What a mess.

I do have to say that thanks to a post previously by bananas, I had added Malwarebutes when it was free for life.

hunter

(38,317 posts)
17. Adobe Flash should just go away.
Wed Jul 8, 2015, 03:10 PM
Jul 2015

I don't install it on my computers.

If I can't see something on a website because it's using Flash, it's their loss, not mine.

onehandle

(51,122 posts)
19. Flash has been the number one avenue for spyware for years.
Wed Jul 8, 2015, 03:25 PM
Jul 2015

The Web is so much more of a pleasure without it.

Uninstall it. Don't look back.

passiveporcupine

(8,175 posts)
25. If you running chrome, it should be updated automatically
Wed Jul 8, 2015, 08:52 PM
Jul 2015

I don't even think I can update it because of Chrome.

Latest Discussions»Latest Breaking News»Adobe Flash exploit that ...