Researchers at Morphisec have uncovered a watering hole attack on leading Hong Kong Telecom website exploiting the CVE-2018-4878 flash vulnerability. Adobe rolled out an emergency patch that fixed two critical remote execution vulnerabilities in February. North Koreas APT group was spotted exploiting the vulnerability in targeted attacks. Experts noticed that despite the advanced evasive features, the attack used basic Metasploit framework components that were compiled just before the attack and did not show any sophistication, obfuscation or evasion.”]
Source: https://securityaffairs.co/wordpress/70691/cyber-crime/watering-hole-cve-2018-4878.html

