Java zero-day exploit reportedly for sale

By
Follow google news

Affects latest platform version.

A zero-day exploit against the latest version of Java is reportedly up for sale on online cybercrime forums.

Java zero-day exploit reportedly for sale

The seller had asked for a five-figure sum for the exploit which targeted a vulnerability within the Java Class MidiDevice.Info, Krebsonsecurity reported.

The exploit was reportedly successfully tested against Java 7 Update 9 running on Firefox and Internet Explorer on Windows 7 machines, and would be sold only once.

It was the latest in a string of attacks against Java, considered by many to be a security risk due to its complexity, popularity and that it runs cross-platform.

The recent attacks have spurred security experts to recommend uninstalling Java from web browsers unless it is needed, while Apple last month removed the Java plug-in from Safari.

Got a news tip for our journalists? Share it with us anonymously here.

Copyright © SC Magazine, Australia

Tags:

Most Read Articles

Australia's big end of town is paying ransomware groups

Australia's big end of town is paying ransomware groups

Services Australia describes fraud, debt-related machine learning use cases

Services Australia describes fraud, debt-related machine learning use cases

Seven years' prison for Australian who sold zero-days to Russia

Seven years' prison for Australian who sold zero-days to Russia

AI can unmask online users for just a few dollars each

AI can unmask online users for just a few dollars each

Log In

  |  Forgot your password?