Turns out, a new Java vulnerability is being exploited in the wild as I speak, with exploits already being put to use across some of the most popular crimeware toolkits. So where does it exist? ALL VERSIONS OF JAVA 7!
While Oracle took the rare step of releasing an out-of-band patch for that zero-day bug a few days after the flaw was identified, at the moment, there is no word of a fix or mitigation controls from the company at this time. Users should disable the Java plugin (version 1.7) in their browser (or if they already have done so, leave it disabled for the time being).
Full story can be found here.
(Source: SecurityWeek)
Login to the community
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.