Dive Brief:
-
62 Adobe Flash Player vulnerabilities that resulted in code execution on user machines were identified in the first five months of 2015, according to Cisco’s 2015 Midyear Security Report.
-
That’s more than the annual totals for any year back to 2001.
-
Cisco said Flash exploits are being rapidly integrated into widely used exploit kits.
Dive Insight:
The effectiveness of the exploits, Cisco said, is enhanced by the fact that users are failing to install updates that patch vulnerabilities in a timely manner.
“It appears many users have difficulty staying on top of Adobe Flash updates and perhaps may not even be aware of some upgrades,” the report noted.
Corporate security pros need to be on the lookout for malware designed to evade detection and to damage the operating systems of the machines it infects if detection efforts become too persistent, the report said.
Meanwhile, Java-based exploits are declining, with no zero-day exploits discovered since 2013. Improved patching and security improvements are the reason for the difference, according to Cisco.