Security News

Mark Adams Named Chief Security Officer of Adobe
2020-11-02 19:15

Adobe announced on Monday that it has appointed Mark Adams as its new chief security officer. Adams will report to Abhay Parasnis, Adobe's chief technology officer, and he will be responsible "For security-related decisions across the company, leading the teams responsible for the security of Adobe's infrastructure, products and services, as well as teams dedicated to security incident response and communications."

Adobe Flash – it’s the end of the end of the end of the road at last
2020-10-30 19:04

Worse still, Flash bugs seemed to show up very frequently as zero-days, the jargon term for exploitable security holes that are found by attackers before a patch is available, thus leaving even the most disciplined and swift-acting system administrators with zero days during which they could have been ahead of the crooks. If anything showed that Adobe's heart hasn't really been in Flash for many years, it was the story of how Apple banned Flash from the iPhone in 2010.

Microsoft releases update to remove Adobe Flash from Windows
2020-10-27 14:11

Microsoft has released the KB4577586 update to remove Adobe Flash from Windows and prevents it from being installed again. In September 2020, Microsoft announced that an optional update would be released in the fall to uninstall Adobe Flash Player and prevent it from being installed again on the same device.

Adobe Fixes 16 Critical Code-Execution Bugs Across Portfolio
2020-10-20 18:31

Adobe has released 18 out-of-band security patches in 10 different software packages, including fixes for critical vulnerabilities that stretch across its product suite. There are 16 critical bugs, all of which allow arbitrary code execution in the context of the current user.

Adobe Releases Security Updates for 10 Products
2020-10-20 18:31

Adobe on Tuesday announced that it has released security updates for 10 of its products, patching a total of 20 vulnerabilities. In the Windows and macOS versions of Illustrator, Adobe fixed 7 critical vulnerabilities that can lead to arbitrary code execution in the context of the current user.

Adobe fixes 18 critical bugs affecting its Windows, macOS apps
2020-10-20 13:55

Adobe has released security updates to address critical vulnerabilities affecting ten of its Windows and macOS products that could allow attackers to execute arbitrary code on devices running vulnerable software versions. Adobe has released a security update for Adobe InDesign that fixes an Uncontrolled Search Path vulnerability in the Creative Cloud Desktop Application installer for Windows that could lead to arbitrary code execution.

Adobe Patches 9 Vulnerabilities in Magento
2020-10-20 08:33

Adobe last week patched a total of nine vulnerabilities in its Magento e-commerce platform, including two critical issues. The vulnerabilities rated critical have been described as a "File upload allow list bypass" that can lead to arbitrary code execution, and an SQL injection flaw that can provide an attacker read or write access to the targeted store's database.

Critical Flash Player Flaw Opens Adobe Users to RCE
2020-10-13 17:46

The flaw stems from a NULL Pointer Dereference error and plagues the Windows, macOS, Linux and ChromeOS versions of Adobe Flash Player. Adobe is warning of a critical vulnerability in its Flash Player application for users on Windows, macOS, Linux and ChromeOS operating systems.

Adobe Patches Critical Code Execution Vulnerability in Flash Player
2020-10-13 16:01

Adobe has patched a critical arbitrary code execution vulnerability in Flash Player. "Successful exploitation could lead to an exploitable crash, potentially resulting in arbitrary code execution in the context of the current user," Adobe explained in its advisory.

Adobe fixes critical security vulnerability in Flash Player
2020-10-13 11:41

Adobe has released a security update for a critical remote code execution vulnerability in Adobe Flash Player that could be exploited by simply visiting a website. Adobe Flash has long been a source of security vulnerabilities that allow attackers to install malware, execute commands, and takeover of computers when visiting malicious websites.