Today just as Adobe released a giant update for Flash and Reader that resolves numerous critical vulnerabilities, TrendMicro announced that they have discovered another new unpatched zero-day exploit in Flash. This exploit is actively being used by the Pawn Storm cyber-espionage campaign in spear-phising emails against several Ministries of Foreign affairs.  These emails contain news stories that when clicked lead to web pages hosting the exploit code.

Unfortunately, this vulnerability exists in the today's release of Adobe Flash 19.0.0.207 and there is currently no known way of blocking it.  TrendMicro has notified Adobe and working with them to resolve this exploit.

Related Articles:

Exploit released for Palo Alto PAN-OS bug used in attacks, patch now

Hackers earn $1,132,500 for 29 zero-days at Pwn2Own Vancouver

Windows 11, Tesla, and Ubuntu Linux hacked at Pwn2Own Vancouver

Exploit released for Fortinet RCE bug used in attacks, patch now

Exploit available for new critical TeamCity auth bypass bug, patch now