Aside from patching a couple Critical vulnerabilities, the update also includes a new and improved background updater tool. Adobe is releasing a new version of Flash Player today. The update addresses a couple critical vulnerabilities, but the real news from Flash 11.2 are the changes Adobe has made to the background updating mechanics.The Flash update should be applied as soon as possible from a security perspective. A post on the Adobe ASSET (Adobe Secure Software Engineering Team) blog cites recent studies like the September 2011 CSIS Report, and volume 11 of the Microsoft Security Intelligence Report to point out that known flaws left unpatched are a much higher risk than zero day exploits.The flaws addressed are memory corruption vulnerabilities rated as Critical by Adobe. They could cause a crash or potentially allow an attacker to take control of the affected system, and they impact virtually all versions of Flash. Adobe claims that neither of the patched vulnerabilities is being actively exploited at this time, but that can change quickly so you should apply the update.Within Flash 11.2, though, Adobe also tackles a larger issue, and one that contributes to a security risk of another kind. The ASSET blog post explains, “Attackers have been taking advantage of users trying to manually search for Flash Player updates by buying ads on search engines pretending to be legitimate Flash Player download sites.” Adobe has improved the background updater tool to streamline the process of keeping Adobe Flash up to date. Users who install Flash 11.2 will be presented with a dialog box to indicate how future updates should be handled.There are three choices, similar to the options available for Automatic Updates in the Windows operating system: Install updates automatically when availableNotify me when updates are availableNever check for updatesUnless you check “Never check for updates”, the background updater touches base with Adobe once per day to see if there are any updates available, and handles any updates according to your selection. The Adobe updater uses the Windows Task Manager rather than running as a separate service, so it isn’t consuming additional resources or opening up another potential attack vector.The best part of the new background updater, though, is that it if there are multiple browsers on the PC, the updater will update Flash across all of them so users don’t have to apply the Flash update multiple times.As a side note, Adobe is also officially dropping support for Internet Explorer 6. Flash can still be installed on IE6, and will probably work as it always has, but Adobe will no longer be testing or certifying updates on IE6, so users are on their own. Related content news UK government plans 2,500 new tech recruits by 2025 with focus on cybersecurity New apprenticeships and talent programmes will support recruitment for in-demand roles such as cybersecurity technologists and software developers By Michael Hill Sep 29, 2023 4 mins Education Industry Education Industry Education Industry news UK data regulator orders end to spreadsheet FOI requests after serious data breaches The Information Commissioner’s Office says alternative approaches should be used to publish freedom of information data to mitigate risks to personal information By Michael Hill Sep 29, 2023 3 mins Government Cybercrime Data and Information Security feature Cybersecurity startups to watch for in 2023 These startups are jumping in where most established security vendors have yet to go. By CSO Staff Sep 29, 2023 19 mins CSO and CISO Security news analysis Companies are already feeling the pressure from upcoming US SEC cyber rules New Securities and Exchange Commission cyber incident reporting rules don't kick in until December, but experts say they highlight the need for greater collaboration between CISOs and the C-suite By Cynthia Brumfield Sep 28, 2023 6 mins Regulation Data Breach Financial Services Industry Podcasts Videos Resources Events SUBSCRIBE TO OUR NEWSLETTER From our editors straight to your inbox Get started by entering your email address below. Please enter a valid email address Subscribe