Showing posts with label Security update. Show all posts
Showing posts with label Security update. Show all posts

Monday, April 21, 2014

WARNING! Your Flash Player may be out of date.

Adobe Flash Malware driven by infected "Router" The Moon Malware

Few days ago, I started to receive a pop-message "WARNING! Your Flash Player may be out of date". Please update to Continue., when I was trying to access websites like Facebook, YouTube, Google, etc.

If you're receiving a similar message then continue to read but make sure you don't click on anything nor try to update the flash player from the pop-window. You may check your current version of the "Adobe Flash Player" by visiting "Adobe" official website. If you're using Google Chrome browser, it already includes Adobe Flash Player built-in. Google Chrome will automatically update when new versions of Flash Player are available.

You will also notice that the same message is poping-up on all the devices which are connected to the same router (mobile phones, laptops etc.).



Now even the dumbest person should know it is not coming from computer but from the network which means your router is infected. It's commonly happening with Linksys, Asus and few other manufacturers.

How to fix this?

  • Reset your router (by holding down the reset button under the router for 6 seconds). Note after restart all your ISP settings will be lost.
  • Configure your router again with the ISP settings (username and password also required).
  • Clear your browsers cache and pop-up message will not appear again.
Refer here for some basic tips on hardening your router to avoid such things happening again.

Friday, June 10, 2011

Security update available for Adobe Flash Player

Hackers exploiting Flash Player XSS vulnerability

Adobe has released another Flash Player update to fix a serious security vulnerability that could expose Windows, Mac OS X, Linux and Solaris users to cross-site scripting attacks.

“This universal cross-site scripting vulnerability (CVE-2011-2107) could be used to take actions on a user’s behalf on any website or webmail provider, if the user visits a malicious website,” Adobe warned in an advisory.

The release of this Flash Player patch follows reports that the vulnerability is being exploited in the wild in active targeted attacks.

In the targeted attacks, Adobe said users are being tricked into clicking on a malicious link delivered in an email message.

Adobe recommends users of Adobe Flash Player 10.3.181.16 and earlier versions for Windows, Macintosh, Linux and Solaris update to Adobe Flash Player 10.3.181.22 (10.3.181.23 for ActiveX). Adobe expects to make available an update for Flash Player 10.3.185.22 for Android during the week of June 6, 2011.

The company said it is still investigating the impact to the Authplay.dll component that ships with Adobe Reader and Acrobat X (10.0.2) and earlier 10.x and 9.x versions of Adobe Reader and Acrobat for Windows and Macintosh operating systems.

Refer here for further details.

Sunday, June 27, 2010

Apple customers have no privacy under new policy

Apple privacy policy is the latest in a series of privacy related issues

Unexpected new privacy rules give Apple and its associated “partners and licensees” the legal right to track, monitor, and store the whereabouts of its customers in real time. Users who do not agree to these draconian measures are prohibited from downloading from the iTunes store.

Apple says that its customers' consent to tracking improves service, although it leaves questions about privacy, security, and safety unanswered.

In spite of a pledge to keep data anonymous, Apple customers have no reason to believe they have any privacy or anonymity. Studies at the University of Texas have demonstrated that customers can be identified by their behavior even when their names are not explicitly stated. Even worse, Apple customers are not told why they are being tracked or who is tracking them.

Refer here for more details.

Saturday, June 26, 2010

World Cup web traffic - the distribution of malicious malware is way up

Cisco Warns Of Rising World Cup Malware


As the world’s legitimate Web traffic increases, so do instances of spam e-mail, Internet-borne malware and general hacker activity. When special or unusual events happen — such as the current Gulf oil spill or the FIFA World Cup soccer tournament in South Africa — communications traffic of all kinds skyrockets. This takes into account text messaging, e-mail, Web searches, cell phone usage, television and Web streaming video, among others.


Cisco ScanSafe SAAS Web security service reported June 18 that after a week of World Cup activities, the global increase in Web traffic is up by an average of 27 percent during World Cup matches.


Japan noted the highest increase (53 percent), followed by the U.K. (37 percent), Germany (32 percent), Australia (20 percent) and Singapore (9 percent). In the United States, the increase worked out to about 8 percent — lower because soccer isn’t the overwhelming phenomenon there as it is worldwide.


Refer here for more details on this news.

Thursday, June 25, 2009

Adobe Shockwave critical update

Critical Adobe Shockwave flaw affects millions

Adobe’s Shockwave Player contains a critical vulnerability that could be exploited by remote hackers to take complete control of Windows computers, according to a warning from Adobe.

The flaw affects Adobe Shockwave Player 11.5.0.596 and earlier versions. Details from Adobe’s advisory:

"This vulnerability could allow an attacker who successfully exploits this vulnerability to take control of the affected system. Adobe has provided a solution for the reported vulnerability (CVE-2009-1860). This issue was previously resolved in Shockwave Player 11.0.0.465; the Shockwave Player 11.5.0.600 update resolves a backwards compatibility mode variation of the issue with Shockwave Player 10 content. To resolve this issue, Shockwave Player users on Windows should uninstall Shockwave version 11.5.0.596 and earlier on their systems, restart, and install Shockwave version 11.5.0.600, available here
."

This issue is remotely exploitable.