• Trend Micro
  • About TrendLabs Security Intelligence Blog
Search:
  • Home
  • Categories
    • Ransomware
    • Vulnerabilities
    • Exploits
    • Targeted Attacks
    • Deep Web
    • Mobile
    • Internet of Things
    • Malware
    • Bad Sites
    • Spam
    • Botnets
    • Social
    • Open source
Home   »   Flash

Angler and Nuclear Exploit Kits Integrate Pawn Storm Flash Exploit

  • Posted on:November 3, 2015 at 8:49 am
  • Posted in:Vulnerabilities
  • Author:
    Brooks Li and Joseph C. Chen (Threats Analysts)
1

When it comes to exploit kits, it’s all about the timing. Exploit kits often integrate new or zero-day exploits in the hopes of getting a larger number of victims with systems that may not be as up-to-date with their patches. We found two vulnerabilities that were now being targeted by exploit kits, with one being…

Read More
Tags: adobe flashAngler Exploit KitExploitexploit kitFlashnuclear exploit kitPawn Stormvulnerability

Latest Flash Exploit Used in Pawn Storm Circumvents Mitigation Techniques

  • Posted on:October 16, 2015 at 8:36 am
  • Posted in:Exploits, Targeted Attacks, Vulnerabilities
  • Author:
    Peter Pi (Threats Analyst)
2

Our analysis of the Adobe Flash zero-day vulnerability used in the latest Pawn Storm campaign reveals that the previous mitigation techniques introduced by Adobe were not enough to secure the platform. Used in Pawn StormĀ to target certain foreign affairs ministries, the vulnerability identified as CVE-2015-7645 represents a significant change in tacticsĀ from previous exploits. It is…

Read More
Tags: 0dayAdobeAPTExploitFlashPawn StormTargeted Attackvulnerability

OS X Zero-days on the Rise—A 2015 Midyear Review and Outlook on Advanced Attack Surfaces

  • Posted on:August 12, 2015 at 8:36 am
  • Posted in:Exploits, Targeted Attacks, Vulnerabilities
  • Author:
    Weimin Wu (Threat Analyst)
0

2015 has so far been a very busy year for security researchers. The data leaked from Hacking Team shocked many, thanks to the multiple zero-days that were disclosed, as well as emails discussing theĀ unscrupulous tradeĀ in exploits and “tools”. Cybercriminals (including exploit kit authors) have been hard at work integrating these newly-discovered flaws into their “products”…

Read More
Tags: 0dayandroidExploitsFlashInternet ExplorerJavaOSXvulnerabilityWindowszero day

Magnitude Exploit Kit Uses Newly Patched Adobe Vulnerability; US, Canada, and UK are Most At Risk

  • Posted on:June 16, 2015 at 2:42 am
  • Posted in:Exploits, Malware, Vulnerabilities
  • Author:
    Peter Pi (Threats Analyst)
0

Adobe may have already patched a Flash Player vulnerability last week, but several users—especially those in the US, Canada, and the UK —are still currently exposed and are at risk of getting infected with CryptoWall 3.0. The Magnitude Exploit Kit included an exploit, detected asĀ SWF_EXPLOIT.MJTE, for the said vulnerability, allowing attackers to spread crypto-ransomware into…

Read More
Tags: Adobecrypto-ransomwareCryptoWallFlashMagnitude exploit kitransomware

Obfuscated Flash Files Make Their Mark in Exploit Kits

  • Posted on:November 24, 2014 at 10:32 am
  • Posted in:Exploits, Vulnerabilities
  • Author:
    Michael Du (Threats Analyst)
0

In recent years, we noticed that more and more malicious Adobe Flash (.SWF) files are being incorporated into exploit kits like the Magnitude Exploit Kit, the Angler Exploit Kit, and the Sweet Orange Exploit Kit. However, we did some more digging and found out thatĀ the number of Flash files isn’t the only thing that has…

Read More
Tags: adobe flashexploit kitsExploitsFlash
Page 1 of 212

Security Predictions for 2020

  • Cybersecurity in 2020 will be viewed through many lenses — from differing attacker motivations and cybercriminal arsenal to technological developments and global threat intelligence — only so defenders can keep up with the broad range of threats.
    Read our security predictions for 2020.

Business Process Compromise

  • Attackers are starting to invest in long-term operations that target specific processes enterprises rely on. They scout for vulnerable practices, susceptible systems and operational loopholes that they can leverage or abuse. To learn more, read our Security 101: Business Process Compromise.

Popular Posts

Sorry. No data so far.

Stay Updated

  • Home and Home Office
  • |
  • For Business
  • |
  • Security Intelligence
  • |
  • About Trend Micro
  • Asia Pacific Region (APAC): Australia / New Zealand, 中国, ę—„ęœ¬, ėŒ€ķ•œėÆ¼źµ­, å°ē£
  • Latin America Region (LAR): Brasil, MĆ©xico
  • North America Region (NABU): United States, Canada
  • Europe, Middle East, & Africa Region (EMEA): France, Deutschland / Ɩsterreich / Schweiz, Italia, Š Š¾ŃŃŠøŃ, EspaƱa, United Kingdom / Ireland
  • Privacy Statement
  • Legal Policies
  • Copyright © Trend Micro Incorporated. All rights reserved.