Adobe website suffers SQL injection attack
The threat of the SQL infection rears its ugly head again as Adobe becomes the latest big brand to suffer an attack on its website.

Visitors to the Adobe website were warned to be vigilant after security firm Sophos revealed that it had hosted malicious code which could infect visiting computers.
Sophos said that it had repeatedly tried to contact Adobe about the problem, with the malicious code present until last Thursday.
The vendor identified the threat Mal/Badsrc-C' as being present on the Adobe website's Vlog IT support centre section', an area which provides tips for video bloggers.Sophos said that Mac/Badsrc-C was a dangerous piece of malware which spread by infecting PCs with SQL injection. This downloaded malicious scripts from the net to infect users with spyware.
SQL infection has been an increasing problem this year, with many legitimate sites suffering web-based malware attacks.
Graham Cluley, senior technology consultant at Sophos, quoted a figure of over 90 per cent of web infections being found on legitimate sites.
He said: "Organisations need to wake up and ensure their websites are properly coded, and that security is in place to stop these kinds of attacks."
Sophos also discovered a new mobile virus called Troj/Konov-A, a Trojan horse which sent out SMS messages to premium rate numbers.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
Adobe could not be reached for comment at the time of publication.
-
Should AI PCs be part of your next hardware refresh?
AI PCs are fast becoming a business staple and a surefire way to future-proof your business
By Bobby Hellard Published
-
Westcon-Comstor and Vectra AI launch brace of new channel initiatives
News Westcon-Comstor and Vectra AI have announced the launch of two new channel growth initiatives focused on the managed security service provider (MSSP) space and AWS Marketplace.
By Daniel Todd Published
-
96% of SMBs are missing critical cybersecurity skills – here's why
News The skills shortage hits SMBs worse as they often suffer from a lack of budget and resources
By George Fitzmaurice Published
-
Sophos Firewall Virtual review: Affordable network protection for those that like it virtualized
Reviews Extreme network security that's cheaper than a hardware appliance and just as easy to deploy
By Dave Mitchell Published
-
MSPs are struggling with cyber security skills shortages
News A shortage of tools and difficulties keeping pace with solutions were also ranked as key issues for MSPs
By George Fitzmaurice Published
-
Nearly 70 software vendors sign up to CISA’s cyber resilience program
News Major software manufacturers pledge to a voluntary framework aimed at boosting cyber resilience of customers across the US
By Solomon Klappholz Published
-
Sophos and Tenable team up to launch new managed risk service
News The new fully managed service aims to help organizations manage and protect external attack surfaces
By Daniel Todd Published
-
Ransomware groups are using media coverage to coerce victims into paying
News Threat actors are starting to see the benefits of a more sophisticated media strategy for extracting ransoms
By Solomon Klappholz Published
-
Shrinking cyber attack “dwell times” highlight growing war of attrition with threat actors
News While teams are becoming more proficient at detecting threats, attackers are augmenting their strategies
By Ross Kelly Published
-
Warning issued over “incomplete” fix for Adobe ColdFusion vulnerability
News An incomplete fix for a vulnerability disclosure could be placing users at risk, researchers warned
By Ross Kelly Published