Adobe investigates clipboard Flash attacks
Investigations are under way after Mac and Windows users reported their clipboards were hijacked.
Adobe is currently investigating a "clipboard attack" involving its Flash Player, where Flash banner ads have been used to hijack clipboards.
The attack puts a weblink into the users's clipboard. If followed this leads to a website selling fake anti-virus software. The code has been found in Flash-based ads found on legitimate websites, reportedly including websites Newsweek and Digg.
Mac, Windows and Linux users running Internet Explorer, Firefox and Safari are said to have been affected.
The attack works by exploiting Adobe Flash files which are used to make display adverts. If the attack is successful it will endlessly delete other text from the clipboard and insert the malicious link in its place.
It is possible to see the effects of this attack from a harmless exploit test page by security researcher Aviv Raff. The aim is to show how easy it is to use Flash with ActionScript code to load a malicious URL onto a targeted clipboard.
If you click on this link and try to paste the contents of the clipboard it will come out as http://www.evil.com. If you try to copy something else it will still have the link http://www.evil.com and will do this continually. (Be warned that you will have to close the browser window or the tab with the exploit page to make it go away).
Adobe said on its Product Security Incident Response Team blog: "Adobe is currently investigating potential solutions to this issue and will update customers as soon as we have more information to provide."
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
-
What does modern security success look like for financial services?Sponsored As financial institutions grapple with evolving cyber threats, intensifying regulations, and the limitations of ageing IT infrastructure, the need for a resilient and forward-thinking security strategy has never been greater
-
Yes, legal AI. But what can you actually do with it? Let’s take a look…Sponsored Legal AI is a knowledge multiplier that can accelerate research, sharpen insights, and organize information, provided legal teams have confidence in its transparent and auditable application
-
Warning issued over “incomplete” fix for Adobe ColdFusion vulnerabilityNews An incomplete fix for a vulnerability disclosure could be placing users at risk, researchers warned
-
Adobe forced to patch its own failed security updateNews Company issues new fix for e-commerce vulnerability after researchers bypass the original update
-
Ask more from your CMSWhitepaper How to get the most value in the shortest timespan
-
Adobe battles fake photos with editing tagsNews Photoshop will include new tagging tools later this year to help fight against misinformation and deep fakes
-
Adobe Photoshop Elements 2019 review: Trapped in the photo-editing middle groundReviews A once peerless beginner’s photo-editing package that’s past its prime
-
How Adobe saved BT £630,000Sponsored Adobe’s digital signature platform is saving time and money - and forging stronger connections between businesses and customers
-
Don't settle when it comes to creativitySponsored Getting the best out of your creative design team means equipping them with the best software
-
The benefits of a subscription serviceSponsored Why software vendors are increasingly moving to a subscription model