Adobe Releases No Patch Tuesday Updates

Adobe released an update for Flash Player on Tuesday, but it does not include any security fixes. If no patches are released by the end of the month, it will be the first time since July 2012.
Adobe typically releases security updates for its products on the second Tuesday of every month, also known as “Patch Tuesday.” In some months, patches were released a few days sooner – particularly when zero-day vulnerabilities had been discovered – or a few days later.
Adobe says it does not have any security updates this month, but it has still advised users to update Flash Player to the latest version.
安全并非无法管控,不管你多么努力,总是没有绝对的安全,所以你不需要在安全方面的努力?当然不会是,你要建立可靠的安全事故响应体系,还要有业务持续运行计划和灾难恢复计划。
Only a total of four vulnerabilities were patched in Flash Player in August and September. The number of flaws discovered by researchers has decreased dramatically in the past period, particularly after Adobe announced its intention to kill the application by 2020.
Nevertheless, Flash Player exploits could still be valuable to malicious actors and we cannot rule out the possibility that a zero-day will be uncovered by the end of the month and the company will be forced to release a patch after all. The last Flash Player zero-day was addressed in December 2016.
Apple, Facebook, Google, Microsoft and Mozilla have recently outlined their plans for moving away from Flash Player. Mozilla announced in August that it had disabled the Flash plugin by default with the release of Firefox 55.
Since March 2008, when Adobe started announcing security updates on its Product Security Incident Response Team (PSIRT) blog, the only months when no vulnerability fixes were announced were May 2008, September 2008, January 2009, March 2010, July 2010, January 2011, July 2011 and July 2012.
Related: Adobe Accidentally Posts Private PGP Key
人人爱家金融严把信息安全关 荣获国家信息安全等级保护三级认证
Related: Adobe Fixes Vulnerabilities in Flash Player, Connect
Related: Adobe Patches Flaws in Flash Player, Experience Manager

Related: Adobe Patches Flash, Reader Flaws Exploited at Pwn2Own
离职员工通常会带走公司的重要文件,进而带来损失,我们必须加强用户和权限管理,只给用户完成其工作所需最少权限,另外还要及时停止离职员工的系统访问权限。

猜您喜欢

一份更好的云灾难恢复计划指南
商业间谍与黑客参与搜索专利大战 APT攻击让员工信息安全意识
Security-Frontline-安全前线
公开称特朗普“白痴”,美国务卿或被中情局长取代
NIKI-SURF CONSUMERCELLULAR
强化网络安全意识宣传网络信息安全重要性