On February 7, Adobe issued a security bulletin warning of zero-day attacks that leverage two Flash vulnerabilities. One (CVE-2013-0634) is related to ActionScript regular expression handling. (Some sources refer to this vulnerability as CVE-2013-0633. We are waiting for Adobe to confirm the proper CVE ID.) McAfee Labs rapidly responded to the threat. While digging in Read more…
Tags: ActionScript, ASLR, CVE-2013-0633, CVE-2013-0634, DEP, exploitation, Flash Player, Zero-Day Attack
This blog was updated on January 14. See the end of the file. A new Java zero-day vulnerability is spreading malicious files to infect unprotected users. The threat is dangerous: Just browsing a malicious page or clicking a malicious link in spam is enough to cause an infection when combined with a vulnerable Java version. Read more…
Tags: Blackhole Exploit Kit, Cool Exploit Kit, CVE2013-0422, Exploit Analysis, Exploit-CVE2013-0422, Exploit-CVE2013-0422 Analysis, Exploit-Kits, Java Vulnerability, MBeanInstantiator vulnerability, Nuclear Exploit-Kit, Ransomware, Red Exploit-Kit, vulnerability, Zero-Day, Zero-Day Attack
Posts tagged under Zero-Day Attack