News

On Sunday, Oracle rushed out a fix for a critical bug in Java that had been folded into exploit kits, crimeware made to automate the exploitation of computers via Web browser vulnerabilities.
Another previously unpublicized flaw in Java threatens the security of millions of PCs that may still have the application running on it.
Researchers at Seculert have linked a nearly two-year-old Java exploit to the Red October espionage malware campaign uncovered by Kaspersky Lab this week. Red October uses a variety of malware and ...
Researchers have discovered that the Gong Da Exploit Kit has been bundling numerous Java exploits for months, setting the stage for additional assaults on the Oracle Java platform.
A new exploit for a previously unknown and unpatched Java vulnerability is being actively used by attackers to infect computers with malware, according to researchers from security firm FireEye.
A new vulnerability was found last week in the latest Java 7 runtime from Oracle. The vulnerability is currently being used by malware developers to exploit systems with runtime installed. Similar ...
A security researcher finds that seven exploit kits have added an attack for a previously unreported flaw in the latest version of the Java Runtime Environment.
If your computer is running Java and you have not updated to the latest version, you may be asking for trouble: A powerful exploit that takes advantage of a newly-disclosed security hole in Java ...
Java the Hutt meets CVE-2012-1723: the Evil Empire strikes back The Java exploit for CVE-2012-1723 is already included in the latest update of the BlackHole exploit kit.
The infamous exploit packs Blackhole and Nuclear Pack now feature a new zero-day Java exploit that exploits the Java vulnerability CVE-2013-0422. The latest version of Java 7 Update 10 is affected.
A new exploit for a recently fixed vulnerability in Java has been added to the Metasploit penetration testing framework, according to vulnerability management firm Rapid7, which owns the open ...
A researcher says a newly released exploit for a Java vulnerability patched in June was added to the Styx exploit toolkit.