21 Jan 2013

DHS warns of Java exploit

The Department of Homeland Security warned computer users to disable Java software completely on January 14th citing a loophole with the potential to allow hackers to take control.  What made the exploit particularly disconcerting was that it allowed attackers to download a malicious program onto victims’ machines without prompting.

”Java 7 Update 10 and earlier contained an unspecified vulnerability that can allow a remote, unauthenticated attacker to execute arbitrary code on a vulnerable system,” the agency said in an alert. ”This and previous Java vulnerabilities have been widely targeted by attackers, and new Java vulnerabilities are likely to be discovered.” 

Oracle has since released a patch for the security hole.

]]>