Forum Discussion

1492's avatar
1492
Moderator
Aug 10, 2015

Yahoo Hit With Large Scale Flash Malware Campaign

I first read about this early last week, but thought it would be of interest? If, nothing else, a reminder to use only the most current version of Flash Player. Better yet, keep Flash disabled by default in your browser. You can always enable it when needed.

Security researchers at Malwarebytes discovered a large scale campaign to embed malware in Yahoo Flash based ads. Apparently, with intent to exploit a Flash Player vulnerability to inject drive-by malware from Yahoo infected pages. The exploit is thought to have been going on for a week before being detected, with Malwarebytes estimating as much as 6.9 Billion visitors having past through the site during this period. Which would make it one of the largest attempts of ad based malware to date. You can read the article here at Large Malvertising Campaign Takes on Yahoo!

Facebook’s new chief security officer, Alex Stamos, has even called on Adobe to set an end of life for Flash, as it continues to be one of the most exploited apps used to distribute malware.
  • 1492 wrote:
    mr. ed wrote:
    How do I do this with Chrome?

    Fairly straightforward. Follow these instructions Adobe Flash Player plug-in.


    Thanks, I followed your instructions and found it was already disabled. :)
  • wa8yxm's avatar
    wa8yxm
    Explorer III
    There are two different FLASH programs.. I think Firefox and Google gave up on Adobe's
  • Once I was mad that Apple won't allow flash on iOS devices but I've long since hoped that would hasten its demise. Too many security issues with flash.
  • I'd recommend switching Flash to Ask to Activate. I believe the latest Firefox will do this automatically if you are running outdated Flash plugin.
  • riven1950 wrote:
    How do you disable it? I'm using Firefox

    Click Tools...ADD-ONS...PLUGINS...Change to Never Activate
  • I've been having on and off Flash issues for about a week and a half now from random sites and only on the PC.. It just doesnt load.
  • BTW, if you get an expired security certificate warning when trying to read the blog, apparently it expires today. You can make an exception, or read it Monday when they will likely update it. :S

About RV Must Haves

Have a product you cannot live without? Share it with the community!8,793 PostsLatest Activity: Aug 22, 2023