Adobe releases new versions of Flash for Windows, Macintosh, Linux and Chrome OS that include a patch for the flaws. A group of attackers with apparent ties to the government of North Korea have been exploiting a zero-day vulnerability in the Flash browser plug-in. “A successful attack can lead to arbitrary code execution,” Adobe’s Common Vulnerabilities and Exposures database warns. A malicious Microsoft Excel spreadsheet, written in Korean, exploits CVE-2018-4878 via an embedded Flash object. Researchers say ROKRAT appears to be a tool developed and used by a hacking team designated “Group 123″”]
Source: https://www.govinfosecurity.com/flash-hack-adobe-updates-plug-in-after-zero-day-attacks-a-10635