Exploits for two more Flash vulnerabilities found in Hacking Team leak; Adobe expected to patch the flaws this week
again— to new 0-day attacks Chris Williams / The Register : Flash HOLED AGAIN TWICE below waterline in fresh Hacking Team reveals Kafeine / Malware don't need Coffee : CVE-2015-5122 (HackingTeam 0d two - Flash up to 18.0.0.203) and Exploit Kits Cale Guthrie Weissman / Business Insider : Facebook's chief security officer follows Steve Jobs' lead and calls for an end to Adobe Flash Christopher Budd / Trend Micro Simply Security : The Hacking Team Flash Zero-Day Trifecta Jared Newman / PCWorld : How to disable Flash Player: Why now's a better time than ever Shane Cole / AppleInsider : It's time to uninstall Adobe's Flash from your Mac - here's how Peter Pi / TrendLabs Security Intelligence Blog : Another Zero-Day Vulnerability Arises from Hacking Team Data Leak Alan Buckingham / BetaNews : Second zero-day flaw found in Adobe Flash thanks to Hacking Team Swati Khandelwal / The Hacker News : Second Flash Player Zero-day Exploit found in ‘Hacking Team’ Dump Samuel Gibbs / Guardian : Hacking Team boss: we sold to Ethiopia but 'we're the good guys' Brian Krebs / Krebs on Security : Adobe To Fix Another Hacking Team Zero-Day Abhimanyu Ghoshal / The Next Web : Two more critical Flash flaws discovered in Hacking Team data breach Eduard Kovacs / SecurityWeek : Two New Flash Player Zero-Day Bugs Found in Hacking Team Leak Gregg Keizer / Computerworld : Adobe to patch second Hacking Team Flash zero-day bug Help Net Security : Two more Flash 0-day exploits found in Hacking Team leak, one already exploited in the wild Nick Farrell / TechEye : Hacking Team clients outed Lucian Constantin / PCWorld : Exploit for second Flash vulnerability found in Hacking Team leak; Adobe expects to release a fix in the next week Tweets: InfoSec Taylor / @swiftonsecurity : [!] New Flash 0day in exploit kits. No patch. From Hacking Team leak. This is bad. #CVE-2015-5122 http://malware.dontneedcoffee.com/ ...
Context & Ripple Effects
The second Flash exploit surfaced from the Hacking Team leak just a day before this report confirmed two more, making this the latest in a rapid sequence: January's Angler-kit zero-day, February's third flaw in a single month, and now a cache of weaponized exploits dumped from a surveillance vendor's own servers. The difference is supply — attackers didn't have to discover these bugs, they inherited them wholesale.
The leak also reignited the platform-level argument: Facebook's chief security officer publicly echoed Steve Jobs' call to kill Flash, and guides on disabling the player spread alongside the exploit news. Adobe's promise of a patch within the week became the test of whether its emergency-response cadence could keep pace.
First-order effects
- Adobe must ship an out-of-band Flash Player update within days while unpatched users face active attacks, since exploit kits are already incorporating one of the leaked zero-days in the wild.
- Enterprises and publishers running Flash face immediate pressure to disable or sandbox it — PCWorld, AppleInsider and others publishing disable instructions signals mainstream guidance shifting from 'patch' to 'remove'.
Second-order effects
- Browser vendors and platforms gain leverage to accelerate deprecation: Facebook's security chief invoking Jobs' 2010 letter turns each new Flash hole into ammunition for HTML5 migration, squeezing Adobe's remaining install base.
- Exploit-kit operators get cheaper inventory — a leaked vendor stockpile lowers the cost of fresh zero-days relative to original research, raising attack volume against every Flash-dependent site until the patch lands.
Third-order effects
- The pattern — a commercial surveillance firm's leak arming the broader criminal market — foreshadows scrutiny of the offensive-exploits trade itself, where one customer's spyware becomes everyone's breach vector; the same dynamic resurfaced years later when Google patched a Chrome zero-day exploited by a commercial spyware vendor.
- If emergency-patch cadence keeps failing to outpace exploit-kit integration, plugins like Flash lose their enterprise license to exist, completing the consolidation around evergreen, auto-updating browsers as the default attack surface.
The trend: Commercial spyware leaks are collapsing the distance between state-grade exploits and commodity criminal kits, accelerating the retirement of legacy browser plugins like Flash.