Adobe cockup means you may have two different versions of Flash installed on your PC

Shaun Nichols writing for The Register:

Adobe says a buggy installer is the reason some people have two different versions of Flash Player on their Windows PCs.

The software house told The Register it had to create an additional build of the browser plugin specifically for Microsoft’s Internet Explorer after the version made for other browsers – such as Mozilla’s Firefox and Microsoft’s Edge – wouldn’t install properly for IE.

So, for example, if you have Internet Explorer and Firefox on your machine, you’ll have two slightly different copies of Flash that should be functionally the same.

Quality control? Testing? What’s that then?

I wouldn’t blame you if you feel that this is the straw that broke the camel’s back. Here is how to completely uninstall Adobe Flash from your computer.

Continue reading Adobe cockup means you may have two different versions of Flash installed on your PC→

Get FREE threat intelligence on hackers and exploits with the Recorded Future Cyber Daily

Get trending info on hackers, exploits, and vulnerabilities every day for FREE with the Recorded Future Cyber Daily [Sponsor]

Graham Cluley Security News is sponsored this week by the folks at Recorded Future. Thanks to the great team there for their support!

Recorded Future provides deep, detailed insight into emerging threats by automatically collecting, analyzing, and organizing billions of data points from the Web.

And now, with its FREE Cyber Daily email all IT security professionals can access information about the top trending threat indicators – helping you use threat intelligence to help make better decisions quickly and easily.

Which means that you will be able to benefit from a daily update of the following:

  • Information Security Headlines: Top trending news stories.
  • Top Targeted Industries: Companies targeted by cyber attacks, grouped by their industries.
  • Top Hackers: Organizations and people recognized as hackers by Recorded Future.
  • Top Exploited Vulnerabilities: Identified vulnerabilities with language indicating malcode activity. These language indicators range from security research (“reverse engineering,” “proof of concept”) to malicious exploitation (“exploited in the wild,” “weaponized”).
  • Top Vulnerabilities: Identified vulnerabilities that generated significant amounts of event reporting, useful for general vulnerability management.

Infosec professionals agree that the Cyber Daily is an essential tool:

“I look forward to the Cyber Daily update email every morning to start my day. It’s timely and exact, with a quick overview of emerging threats and vulnerabilities. For organizations looking to strengthen their security program with threat intelligence, Recorded Future’s Cyber Daily is the perfect first step that helps to prioritize security actions.” – Tom Doyle, CIO at EBI Consulting.

So, what are you waiting for?

Sign up for the Cyber Daily today, and starting tomorrow you’ll receive the top trending threat indicators.


If you’re interested in exclusively sponsoring my site for a week, and reaching an IT-savvy audience that cares about computer security, you can find more information here.

Continue reading Get FREE threat intelligence on hackers and exploits with the Recorded Future Cyber Daily→

Android banking malware stops you calling customer service to cancel your cards

Symantec describes some Android banking malware making things more complicated for victims in Russia and South Korea:
Typically, when a banking customer calls a customer care number through a registered mobile device, their call will be routed to an In… Continue reading Android banking malware stops you calling customer service to cancel your cards→

How you could steal money from Instagram, Microsoft and Google with help from a premium rate phone number

Researcher Arne Swinnen found an ingenious way to make money from the likes of Google, Microsoft and Instagram – getting their two-factor authentication registration schemes to call a premium rate phone number:
“They all offer services to supply users … Continue reading How you could steal money from Instagram, Microsoft and Google with help from a premium rate phone number→

Ubuntu Forums hacked (again)

Canonical, the company behind Ubuntu, has warned that there has been a security breach on the Ubuntu Forums site, resulting in the theft of two million members’ usernames, IP addresses, and email addresses:

At 20:33 UTC on 14th July 2016, Canonical’s IS team were notified by a member of the Ubuntu Forums Council that someone was claiming to have a copy of the Forums database.

After some initial investigation, we were able to confirm there had been an exposure of data and shut down the Forums as a precautionary measure. Deeper investigation revealed that there was a known SQL injection vulnerability in the Forumrunner add-on in the Forums which had not yet been patched.

If you think you may have heard a similar story in the past, your memory isn’t deceiving you. Ubuntu Forums was previously hacked in 2013.

Continue reading Ubuntu Forums hacked (again)→

Be careful in your inbox. Massive Locky ransomware campaign underway

F-Secure is warning computer users about a significant increase in sightings of the Locky ransomware, typically spammed out posing as invoices or profiles for positions at your company.

Here is how researcher Päivi Tynninen described the scale of the malware campaign:

Yesterday, Tuesday, we saw two new campaigns with a totally different magnitude: more than 120,000 spam hits per hour. In other words, over 200 times more than on normal days, and 4 times more than on last week’s campaigns.

If you make the mistake of opening one of the ZIP files attached to the spammed out messages, you will find a JavaScript file inside. Clicking on it would be a big mistake and lead to your computer being hit by the notorious Locky ransomware. Before you know it, you may have lost access to your files and find yourself being blackmailed for their safe return.

Stay safe folks. Always be suspicious of unsolicited attachments.

Continue reading Be careful in your inbox. Massive Locky ransomware campaign underway→

Couldn’t care less about Pokémon Go? Get this Chrome extension

Chrome users may be interested in a new browser extension called PokeGone:

Remove Pokemon from the Internet!

Sick and tired of hearing about Pokemon? PokeGone will take care of that! This extension will stop your eyes from seeing grown adults raving on about Pokemon – simple as.

Remove all traces of Pokemon from the internet with one simple extension!

Unfortunately, there are mixed reports of PokeGone’s ability to “catch ’em all” – so it may be that you find it an ineffective way to filter talk of Pokémon Go from your screen.

This was a public service announcement.

Continue reading Couldn’t care less about Pokémon Go? Get this Chrome extension→

Here’s the very best advice on what you should do with Adobe Flash

On Tuesday, Adobe released a critical update patching over 50 security holes in its Flash Player plugin.

Security blogger Brian Krebs says it better than me:

It’s bad enough that hackers are constantly finding and exploiting zero-day flaws in Flash Player before Adobe even knows about the bugs.

The bigger issue is that Flash is an extremely powerful program that runs inside the browser, which means users can compromise their computer just by browsing to a hacked or malicious site that targets unpatched Flash flaws.

The smartest option is probably to ditch this insecure program once and for all and significantly increase the security of your system in the process.

That seems pretty reasonable to me.

Here is our guide on how you can update Adobe Flash on your computer or (even better) uninstall it entirely.

The full advisory on the Flash security vulnerabilities can be read on Adobe’s website, as can details of the security update they have released for another of their beleaguered products – Adobe Reader.

Continue reading Here’s the very best advice on what you should do with Adobe Flash→