Adobe Reader and Adobe Acrobat zero-day flaws to be fixed this week
Adobe Reader and Adobe Acrobat will be patched in the coming days.

Software giant Adobe has confirmed that a software patch will be released this week to fix two security vulnerabilities in its Reader and Acrobat software.
As reported by IT Pro last week, security flaws were recently found in several versions of Adobe Reader and Adobe Acrobat that experts feared could be used to carry out targeted attacks on Mac and PC users.
Security vendor, FireEye, discovered the vulnerabilities and claimed they were already being exploited in the wild.
The vulnerabilities, which are identified as critical in a security advisory on Adobe's website, can cause applications to crash and puts the system at a higher risk for infiltration by attackers.
"Adobe is aware of reports that these vulnerabilities are being exploited in the wild in targeted attacks designed to trick Windows users into clicking on a malicious PDF file delivered in an email message," a section of the Adobe advisory read.
However, in a follow-up advisory published over the weekend, Adobe confirmed that it plans to roll out an update that will fix the security holes later this week.
In the meantime, Adobe has advised users to take proper security precautions until the updates are released. They have also been advised not to open PDF documents from unknown sources.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
"Users of Adobe Reader XI and Acrobat XI for Windows can protect themselves from this exploit by enabling Protected View," the advisory added.
"To enable this setting, choose the 'Files from potentially unsafe locations' option under the Edit > Preferences > Security (Enhanced) menu," it continued.
-
Third time lucky? Microsoft finally begins roll-out of controversial Recall feature
News The Windows Recall feature has been plagued by setbacks and backlash from security professionals
By Emma Woollacott Published
-
The UK government wants quantum technology out of the lab and in the hands of enterprises
News The UK government has unveiled plans to invest £121 million in quantum computing projects in an effort to drive real-world applications and adoption rates.
By Emma Woollacott Published
-
Hackers are stepping up ‘qishing’ attacks by hiding malicious QR codes in PDF email attachments
News Malicious QR codes hidden in email attachments may be missed by traditional email security scanners, with over 500,000 qishing attacks launched in the last three months.
By Solomon Klappholz Published
-
The threat prevention buyer's guide
Whitepaper Find the best advanced and file-based threat protection solution for you
By ITPro Published
-
Supply chain as kill chain
Whitepaper Security in the era Zero Trust
By ITPro Published
-
Microsoft under fire for “negligent” security practices in scathing critique by industry exec
News Microsoft took more than 90 days to issue a partial fix for a critical Azure vulnerability, researchers found
By Ross Kelly Published
-
Apple patches zero day linked to spyware campaign
News Kaspersky researchers were the first to report a zero day used in a sophisticated attack chain
By Rory Bathgate Published
-
MOVEit cyber attack: Cl0p sparks speculation that it’s lost control of hack
News The hackers return with their second major data-extortion attack of 2023, but may have bitten off more than they can chew
By Connor Jones Published
-
Microsoft says it knows who was behind cyber attacks on MOVEit Transfer
Dozens of organizations may have already lost data to hackers exploiting the critical flaw
By Rory Bathgate Published
-
Trend Micro security predictions for 2023
Whitepaper Prioritise cyber security strategies on capabilities rather than costs
By ITPro Published