The latest Java zero-day saga has taken another fresh twist, as malicious hackers started offering a fake patch as bait for fresh attacks, whilst an exploit for another flaw has reportedly sold for well over its $5000 asking price.
The most recent new weakness to hit Oracle’s software was used in various attacks, as exploit kits used it to serve up malware via hacked websites. Larry Ellison’s firm issued a patch, but that hasn’t stopped hackers hitting Java in any way they see fit.
Trend Micro spotted “malware under the veil of a Java update”, “Once executed, this backdoor connects to a remote server that enables a possible attacker to take control of the infected system,” the security firm noted in a blog post.
“In light of the recent events surrounding Java, users must seriously consider their use of Java.”
Meanwhile, noted security blogger Brian Krebs gave an update today on what he believed to be a separate Java zero-day flaw. Underground sellers were offering an exploit for the vulnerability for $5000, but Krebs said sources indicated it “actually sold for quite a bit more”.
A “bidding war ensued”, according to Krebs, who reported on a sales pitch from the “underweb” offering access to two people to unencrypted source files to the exploit.
Oracle still hasn’t patched a number of Java flaws, which could allow for remote code execution, even though it was alerted to the vulnerabilities by a security firm way back in September. Oracle was even offered guidance as to how to fix the flaw in less than an hour, but still has not offered an update.
Interested by tech and fascinating plots? Try our tech in the movies quiz!
Welcome to Silicon UK: AI for Your Business Podcast. Today, we explore how AI can…
Japanese tech investment firm SoftBank promises to invest $100bn during Trump's second term to create…
Synopsys to work with start-up SiMa.ai on joint offering to help accelerate development of AI…
Start-up Basis raises $34m in Series A funding round for AI-powered accountancy agent to make…
Data analytics and AI start-up Databricks completes huge $10bn round from major venture capitalists as…
Congo files legal complaints against Apple in France, Belgium alleging company 'complicit' in laundering conflict…