Monday, November 4, 2024
HomeSecurity UpdatesNew Java Vulnerabilities? Deserialization, Botnet Cannibalism, And Updates

New Java Vulnerabilities? Deserialization, Botnet Cannibalism, And Updates

Published on

Malware protection

Java is the programming language that is considered a favorite for both ethical and illegal hacking, according to Mehedi Hasan of Ubuntu Pit.

It is commonly used to gain access through backdoor entries, much as hackers do with JavaScript. It seems that Java continues to be besieged by new vulnerabilities, and Oracle is responding.

New Java Vulnerabilities

Zero-Day Deserialization Attack

The Java Deserialization Zero-Day specifically targets web hosts and cloud providers, according to Cisco Talos. The vulnerability exists through Java’s deserialization, where a hacker may overwrite script in the midst of the unpacking of data.

- Advertisement - SIEM as a Service

For end-users who make use of web hosting services, this can be quite devastating, as it may gain access to information being sent out and keep in servers. Experts recommend that end-users must respond by shoring up their security.

Users may protect their information through stringent JavaPipe practices such as SSL certification and backups. Cloud providers must also boost their protocols and consistently check their scripts for any odd new strains.

Botnet Cannibalism 

While not quite as recent, an active botnet operation has been busy gobbling up backdoors on multiple PHP and Java web servers. The hack is dangerous, as it is the latest manifestation of an old Windows trojan virus, according to Positive Technologies.

Instead of attacking end-users and their desktop computers, it has shifted its focus to online servers. Its purpose is to gain a backdoor entry and plant cryptocurrency-mining programs without the end-user being aware. Java is used by multiple programs and applications, which make every end-user vulnerable to this attack.

End-users can protect themselves by keeping abreast of the situation as it continues to develop and ensure a thorough understanding of the progress of the malware.

Effect Of Java Attacks On Users

The effects of hacking attempts and malware plants have left a mark on their victims. Prime examples of Java backdoor hacks were those of Equifax. While the main vulnerability stemmed from Apache Struts, hackers were able to gain access, since the scripts were written in Java.

Given Java’s flexible nature, it allowed interested parties to use the object-oriented programming to slip their own scripts and gain access to millions of pieces of customer information. The subsequent hack resulted in waves of identity theft, and millions of users left feeling vulnerable.

Oracle’s New Java Updates

Despite the vulnerabilities, Java has not waned in popularity. This is predominantly due to Oracle’s continued release of updates. As a brand, they constantly disclose any new vulnerabilities that crop up.

They rolled out a series of updates to their programming since April of this year, and have continued since. Most importantly, most of these updates are free for users.

While there exist premium updates, a majority of Java users rely on free updates to keep their applets safe from attacks.

There is no denying that Java remains to be useful to end-users and various application developers. As such, it will continue to be a target of hackers seeking to exploit any new vulnerabilities they can find.

Only time will tell if there will be new Java-based attacks that go through Oracle’s new updates.

Latest articles

Evasive Panda Attacking Cloud Services To Steal Data Using New Toolkit

The Evasive Panda group deployed a new C# framework named CloudScout to target a...

Massive Midnight Blizzard Phishing Attack Using Weaponized RDP Files

Researchers warn of ongoing spear-phishing attacks by Russian threat actor Midnight Blizzard targeting individuals...

Sophisticated Phishing Attack Targeting Ukraine Military Sectors

The Ukrainian Cyber Emergency Response Team discovered a targeted phishing campaign launched by UAC-0215...

Chinese Hackers Attacking Microsoft Customers With Sophisticated Password Spray Attacks

Researchers have identified a network of compromised devices, CovertNetwork-1658, used by Chinese threat actors...

Free Webinar

Protect Websites & APIs from Malware Attack

Malware targeting customer-facing websites and API applications poses significant risks, including compliance violations, defacements, and even blacklisting.

Join us for an insightful webinar featuring Vivek Gopalan, VP of Products at Indusface, as he shares effective strategies for safeguarding websites and APIs against malware.

Discussion points

Scan DOM, internal links, and JavaScript libraries for hidden malware.
Detect website defacements in real time.
Protect your brand by monitoring for potential blacklisting.
Prevent malware from infiltrating your server and cloud infrastructure.

More like this

New Windows Zero-Day Vulnerability Let Attackers Steal Credentials From Victim’s Machine

A security researcher discovered a vulnerability in Windows theme files in the previous year,...

Okta Verify Agent for Windows Flaw Let Attackers Steal User Passwords

A newly discovered vulnerability in Okta's Device Access features for Windows could allow attackers...

MediaTek High Severity Vulnerabilities Let Attackers Escalate Privileges

In its recent MediaTek Product Security Bulletin, the chipmaker disclosed two high-severity security vulnerabilities...