Adobe Flash zero-day included in Magnitude exploit kit – Hackers have managed to discover a new dangerous Adobe vulnerability and add it to the Magnitude exploit kit, according to independent security researcher Kafeine.adobe patch Adobe
The remote code execution vulnerability (CVE-2015 through 3113) disclosed last week in Adobe Flash allows attackers to compromise un-patched systems by targeting Internet Explorer on Windows 7 and XP.
Hackers have already begun distributing malware through phishing attacks, according to FireEye researchers
Researcher Kafeine says that the vulnerability has been added to the Magnitude exploit kit and that we will soon see an increase in attacks targeting Flash users.
The researcher also reports that attackers using the Magnitude exploit kit are distributing the Cryptowall ransomware.
"The vulnerability CVE-2015-3113, which has been flagged as a zero-day by FireEye, is being exploited in limited targeted attacks. However, it has now been added to the Magnitude exploit kit."
It should be noted that the developer of the Magnitude exploit kit was able to earn up to $100,000 per month since August 2014, according to Trustwave [PDF].
Researchers report that the developer of Magnitude must be Russian and that he could earn up to $3,000,000 per year.

