Blog

Adobe

CVE-2018-4990 – Adobe Reader Double Free (Zero Day) vulnerability alert!

 May 16, 2018

Estimated reading time: 1 minute

The recent zero-day vulnerability CVE-2018-4990 in Adobe Reader enables attackers to perform a Remote Code Execution on targeted machines. Adobe has released a security advisory APSB18-09 on May 14, 2018 to address this issue. According to Adobe, the in-wild attack is targeted and it impacts limited Windows users. Vulnerable versions...

A massive security flaw discovered in Skype. Fix not coming anytime soon.

  • 18
    Shares
 February 14, 2018

Estimated reading time: 2 minutes

Quick Heal Security Labs has recently learned about a serious vulnerability in Skype’s update installer – that’s the bad news. The worse news is, Microsoft is not going to patch the vulnerability anytime soon as this would require the updater to go through a ‘large code revision’. What is this...

Vulnerabilities found in Broadcom Wi-Fi adapter of Lenovo laptop chipsets

  • 32
    Shares
 February 13, 2018

Estimated reading time: 2 minutes

Lenovo recently released an advisory, warning customers about two critical Broadcom vulnerabilities which impact 25 models of its popular ThinkPad lineup. The Broadcom Wi-Fi chipsets used by Lenovo ThinkPad devices are affected by the CVE-2017-11120 & CVE-2017-11121 vulnerabilities. Both these issues are rated as “critical” and received a CVSS 10 score...

An analysis of an MS office document exploiting a zero-day flash player vulnerability (CVE-2018-4878)

 February 7, 2018

Estimated reading time: 3 minutes

Important update! Adobe Systems released a critical security update on 6.02.2017 to fix the vulnerability discussed in this post. We recommend you to apply the update immediately. Summary of the vulnerability CVE-2018-4878 is a use-after-free vulnerability present in Adobe Flash Player 28.0.0.137 and its earlier versions are being exploited in...

What is Bad Rabbit Ransomware and how can you stay safe?

  • 43
    Shares
 October 25, 2017
Bad Rabbit Ransomware

Estimated reading time: 2 minutes

On 24 October 2017 (Tuesday), a new ransomware was let loose on the Internet. It is known as Bad Rabbit and seems to bear similar characteristics to the infamous NotPetya ransomware. Victims of Bad Rabbit Organizations in Russia and Ukraine were the initial casualties of this ransomware – they include...

Beware of Fake Flash Player apps on Google Play

  • 45
    Shares
 August 2, 2017

Estimated reading time: 4 minutes

Quick Heal Security Labs has found 2 fraudulent apps pretending to be Adobe Flash Player on the Google Play Store. Presently, no official apps of Adobe Flash Player are available on the Play Store. The rest of the post will tell you more. Fake App #1. Plugin for Video Flash...

Anatomy of Flash Exploit (CVE-2015-8651) integrated into Rig Exploit Kit

  • 6
    Shares
 April 25, 2017
cybersecurity

Estimated reading time: 4 minutes

We all know how the infamous RIG Exploit Kit have been used to infect the end users. We are seeing a constant spike in the usage of the RIG Exploit Kit by malware actors to spread malware. Its use has been noticed in different campaigns such as EITest, pseudoDarkleech, and...

Potentially Unwanted Applications (PUAs) in Disguise of Software Updates

  • 3
    Shares
 March 21, 2016

Estimated reading time: 5 minutes

It has been observed that cyber criminals are using genuine names to enter into their targeted victim’s system. They are doing this by displaying random pop-up ads on Internet Explorer, Firefox, or Google Chrome that prompts the user to update Adobe Flash Player, Java, media players, etc. These pop-up ads...

Quick Heal Detects Flash Exploit from China

 December 29, 2015

Estimated reading time: 2 minutes

Quick Heal’s Malware Intelligence reporting system keeps a track of threats that are detected on its customers’ machines. From last quarter’s malware detection stats, we found that there were constant detection alerts for a well-known Adobe flash exploit in India. It is known as CVE-2015-5119. Our analysis of this threat...