This site uses cookies. By continuing to browse the site you are agreeing to our use of cookies. > Find out more here
by Shaun Nichols
11 Jan 2013
The outbreak of yet another Java zero-day attack has led security experts to once again advise users to disable the platform.
A ransomware Trojan known as Reveton has been connected with the unpatched exploit. After targeting the Java flaw, the attack then installs the malware, which forces users to pay a fee in order to recover their data.
Researchers with Trend Micro have already spotted the flaw in use with two of the most popular automated exploit kits: Blackhole and the Cool Exploit Kit.
The attack has caused a number of vendors and security groups, including Trend Micro, to consider disabling Java altogether. The platform is considered to be among the most popular targets for automated exploits and malware install attempts.
"To prevent this exploit, and subsequently the related payload, we recommend users to consider if they need Java in their systems," the company said in its advisory.
"If it is needed, users must use the security feature to disable Java content via the Java Control Panel, that shipped in the latest version of Java 7."
This is not the first time experts have asked users to consider disabling Java as a security measure. Last year, the disclosure of a similar zero-day exploit and subsequent malware attacks plagued users and drove many to disable the component altogether.
Last November, Kaspersky Lab reported that Java was the single most popular target for online exploits.
According to Symantec, the attack could be the first in a string of similar operations.
"There has been a lot of coverage of late in relation to the Cool Exploit Kit author (supposedly the same author as the Blackhole exploit kit) having a large budget for buying up new zero-days," Symantec researchers explained.
"If this is the case, this may be the first zero-day in a string of zero-days to come from the Cool Exploit Kit."
Oracle has yet to give word on a possible patch or workaround for the flaw.
Latest stories from Security
Related videos
Related articles
Related jobs
Poll
Which productivity tools do you use for work?
BlackBerry's latest smartphone is a mid-tier handset that will cost less than the Q10 and Z10
Updating your subscription status
Connect with V3.co.uk
It's no longer one or other with web security; you can now have a virtualisation and SaaS hybrid model
BYOD is important for employee satisfaction, but poses challenges in terms of security, productivity loss and costs
Enterprise Architect - Information Security. To £85k...
Tier one investment bank is currently undertaking a number...
Key skills for this position include: Microsoft Windows...
Infrastructure Engineer: Microsoft Windows 2003 / 2008...
Keep up to date with the latest products, services and technologies from the world's leading IT companies. IThound.com brings you over 2,000 white papers, case studies and analyst reports.
Do you agree