A drive-by download attack done with the Magnitude exploit kit exploited a Flash Player vulnerability patched Tuesday. The flaw, tracked as CVE-2015-3113 in the Common Vulnerabilities and Exposures database, had zero-day status when Adobe released a patch for it. It had already been exploited by a China-based cyberespionage group for several weeks in targeted attacks against organizations from the aerospace, defense, construction, engineering, technology, telecommunications and transportation industries. This highlights the increasingly small time frame users have to deploy patches.”]

