Thursday, March 28, 2024

New Java Vulnerabilities? Deserialization, Botnet Cannibalism, And Updates

Java is the programming language that is considered a favorite for both ethical and illegal hacking, according to Mehedi Hasan of Ubuntu Pit.

It is commonly used to gain access through backdoor entries, much as hackers do with JavaScript. It seems that Java continues to be besieged by new vulnerabilities, and Oracle is responding.

New Java Vulnerabilities

Zero-Day Deserialization Attack

The Java Deserialization Zero-Day specifically targets web hosts and cloud providers, according to Cisco Talos. The vulnerability exists through Java’s deserialization, where a hacker may overwrite script in the midst of the unpacking of data.

For end-users who make use of web hosting services, this can be quite devastating, as it may gain access to information being sent out and keep in servers. Experts recommend that end-users must respond by shoring up their security.

Users may protect their information through stringent JavaPipe practices such as SSL certification and backups. Cloud providers must also boost their protocols and consistently check their scripts for any odd new strains.

Botnet Cannibalism 

While not quite as recent, an active botnet operation has been busy gobbling up backdoors on multiple PHP and Java web servers. The hack is dangerous, as it is the latest manifestation of an old Windows trojan virus, according to Positive Technologies.

Instead of attacking end-users and their desktop computers, it has shifted its focus to online servers. Its purpose is to gain a backdoor entry and plant cryptocurrency-mining programs without the end-user being aware. Java is used by multiple programs and applications, which make every end-user vulnerable to this attack.

End-users can protect themselves by keeping abreast of the situation as it continues to develop and ensure a thorough understanding of the progress of the malware.

Effect Of Java Attacks On Users

The effects of hacking attempts and malware plants have left a mark on their victims. Prime examples of Java backdoor hacks were those of Equifax. While the main vulnerability stemmed from Apache Struts, hackers were able to gain access, since the scripts were written in Java.

Given Java’s flexible nature, it allowed interested parties to use the object-oriented programming to slip their own scripts and gain access to millions of pieces of customer information. The subsequent hack resulted in waves of identity theft, and millions of users left feeling vulnerable.

Oracle’s New Java Updates

Despite the vulnerabilities, Java has not waned in popularity. This is predominantly due to Oracle’s continued release of updates. As a brand, they constantly disclose any new vulnerabilities that crop up.

They rolled out a series of updates to their programming since April of this year, and have continued since. Most importantly, most of these updates are free for users.

While there exist premium updates, a majority of Java users rely on free updates to keep their applets safe from attacks.

There is no denying that Java remains to be useful to end-users and various application developers. As such, it will continue to be a target of hackers seeking to exploit any new vulnerabilities they can find.

Only time will tell if there will be new Java-based attacks that go through Oracle’s new updates.

Website

Latest articles

GoPlus’s Latest Report Highlights How Blockchain Communities Are Leveraging Critical API Security Data To Mitigate Web3 Threats

GoPlus Labs, the leading Web3 security infrastructure provider, has unveiled a groundbreaking report highlighting...

Wireshark 4.2.4 Released: What’s New!

Wireshark stands as the undisputed leader, offering unparalleled tools for troubleshooting, analysis, development, and...

Zoom Unveils AI-Powered All-In-One AI Work Workplace

Zoom has taken a monumental leap forward by introducing Zoom Workplace, an all-encompassing AI-powered...

iPhone Users Beware! Darcula Phishing Service Attacking Via iMessage

Phishing allows hackers to exploit human vulnerabilities and trick users into revealing sensitive information...

2 Chrome Zero-Days Exploited at Pwn2Own 2024: Patch Now

Google has announced a crucial update to its Chrome browser, addressing several vulnerabilities, including...

The Moon Malware Hacked 6,000 ASUS Routers in 72hours to Use for Proxy

Black Lotus Labs discovered a multi-year campaign by TheMoon malware targeting vulnerable routers and...

Mitigating Vulnerability Types & 0-day Threats

Mitigating Vulnerability & 0-day Threats

Alert Fatigue that helps no one as security teams need to triage 100s of vulnerabilities.

  • The problem of vulnerability fatigue today
  • Difference between CVSS-specific vulnerability vs risk-based vulnerability
  • Evaluating vulnerabilities based on the business impact/risk
  • Automation to reduce alert fatigue and enhance security posture significantly

Related Articles