China seen targeting banks, military in Forbes web attack

A Chinese hacking group infiltrated the Forbes.com site in November and used it to launch targeted attacks against website visitors from U.S. banking and defense companies, a cybersecurity company said on Tuesday.

The attack took place over a period of several days, starting Nov. 28, and took advantage of unpatched vulnerabilities in Adobe Flash and Microsoft Internet Explorer 9, according to ISight Partners. The vulnerability was kept quiet until Tuesday, when Microsoft issued a patch to plug the security hole in its web browser. Adobe had previously published a patch for Flash.

The attack used a Flash vulnerability and was launched from the “Thought of the day” Flash widget that appears when people first visit the financial magazine’s site, said Invincea, a second cybersecurity company that independently detected the attack.

To read this article in full or to leave a comment, please click here

Read more: China seen targeting banks, military in Forbes web attack

Story added 10. February 2015, content source with full text you can find at link above.