Critical Flash exploit emerges from Hacking Team breach

Feel safe with your fully-patched computer? If you use Flash and land on the wrong website, you may get a virus or even a cryptolocker that renders your machine unusable. That’s because a sophisticated “zero-day” exploit stolen from Hacking Team has now been released into the wild. As a reminder, Hacking Team is the infamous outfit that supplies US law enforcement and various governments around the world with digital spying tools. However, the company suffered an embarrassing attack on its own servers, and among the 400GB of data stolen were some nasty tools originally intended for use by agencies like the US Drug Enforcement Agency.

Security experts say attackers have now unleashed those tools on the internet, leaving all computers vulnerable until Adobe patches Flash, which it’s expected to do tomorrow. Malwarebytes called it “one of the fastest documented cases of an immediate weaponization in the wild, possibly thanks to the detailed instructions left by the Hacking Team.” So what can you do about it? Obviously, be careful about which sites you visit, but you may also want to either enable “click-to-play” for the Flash plug-in or disable it completely, as detailed by How-To Geek.

Meanwhile, there are questions about how this shitstorm happened in the first place. As Forbes pointed out, leaked emails show that the FBI and DEA were keen on Hacking Team’s software, which can run $500,000 for a full cross-platform setup. Other emails revealed that Hacking Team sold its wares to oppressive regimes in countries like Sudan.

Critics argue that increased cyber-spying by governments begets ultra-sophisticated hacking tools that can fall into the wrong hands. That in turn makes everyone more vulnerable, as today’s attack proves (again). Ironically, FBI director James Comey is also trying to convince lawmakers today that it should be trusted with backdoor access to encrypted cellphones. However, given the competence and questionable ethics of the companies it works with, it’s hard to see how that’s a good idea.

Filed under: Internet, Software

Comments

Source: Malwarebytes

Latest posts

Deezer launches an AI music detector for other streaming services

Deezer will now scan your playlists on other streaming platforms to detect AI-generated music. Deezer was the first of the big streaming services to...

Kalshi adds required employment verification for some prediction market bets

The CFTC is considering its first regulation for prediction markets, as arrests over "insider trading" on everything from military operations to Google Search data...

Apple, Google add support for Thread 1.4

The Google TV Streamer has been updated to Thread 1.4, allowing you to access a way to manually share its Thread credentials. | Photo...

Xbox warns of a ‘reset’ as it prepares for layoffs

Microsoft's Xbox division will be hit with significant layoffs next month, according to people familiar with Microsoft's plans. The company has been preparing for the...

Nearly a million passports and photo IDs were left unprotected on the public internet

Typing a few letters and numbers into my web browser, I find myself gaping at the identity documents of complete strangers. The passport...

Apple’s new Siri AI knows when to shut up

Apple's new Siri AI is finally here, and so far, it seems like it works. I have access and have been messing around with...

Framework delays its first Laptop 13 Pro shipments by a month

The Framework Laptop 13 Pro is delayed. The new 13-inch Framework flagship was set to launch in June, but shipments from the first batch...

Bluesky is getting ‘communities’

Bluesky will be getting "communities," which will function as smaller spaces where you can "go deeper and hang out with people who care about...

Google releases Android 17 QPR1 Beta 4 for Pixel

After the big release at I/O 2026 last month, Google is rolling out Android 17 QPR1 Beta 4 for Pixel devices. Read more @ 9to5google

Here’s everything new in Android 17 QPR1 Beta 4 [Gallery]

With Android 17 QPR1 Beta 4 today, Google is rolling out a much needed update that addresses various bugs from the last big release. Read...