Adobe Releases No Patch Tuesday Updates

Adobe released an update for Flash Player on Tuesday, but it does not include any security fixes. If no patches are released by the end of the month, it will be the first time since July 2012.
Adobe typically releases security updates for its products on the second Tuesday of every month, also known as “Patch Tuesday.” In some months, patches were released a few days sooner – particularly when zero-day vulnerabilities had been discovered – or a few days later.
网络极客们可能会挑战组织的安全控制措施,不过他们会有些安全防范的基础。同时也要教育一般的用户,不能完全迷信网络信息安全机制,提高警惕,多重防御很必要。
网络安全法网络宣传片 002 国家网络安全的现状与重要性概述
Adobe says it does not have any security updates this month, but it has still advised users to update Flash Player to the latest version.
Only a total of four vulnerabilities were patched in Flash Player in August and September. The number of flaws discovered by researchers has decreased dramatically in the past period, particularly after Adobe announced its intention to kill the application by 2020.
Nevertheless, Flash Player exploits could still be valuable to malicious actors and we cannot rule out the possibility that a zero-day will be uncovered by the end of the month and the company will be forced to release a patch after all. The last Flash Player zero-day was addressed in December 2016.
Apple, Facebook, Google, Microsoft and Mozilla have recently outlined their plans for moving away from Flash Player. Mozilla announced in August that it had disabled the Flash plugin by default with the release of Firefox 55.
Since March 2008, when Adobe started announcing security updates on its Product Security Incident Response Team (PSIRT) blog, the only months when no vulnerability fixes were announced were May 2008, September 2008, January 2009, March 2010, July 2010, January 2011, July 2011 and July 2012.
Related: Adobe Accidentally Posts Private PGP Key

Related: Adobe Fixes Vulnerabilities in Flash Player, Connect
Related: Adobe Patches Flaws in Flash Player, Experience Manager
Related: Adobe Patches Flash, Reader Flaws Exploited at Pwn2Own
在业务分工越来越细化的今天,管理好供应商及合作厂商的安全,同保护好我们自己一样重要。

猜您喜欢

Linux下网络协议分析器Wireshark使用基础
浅谈在组织内部推进信息安全的方法
Security-Frontline-安全前线
季前赛-江苏加时6分胜深圳 布鲁克斯43分拼抽筋
SHIAPOST RANDRWOODCRAFTS
针对全员的ISO14001体系在线动画培训问世