Security Brief: China Retaliates Against Accusations, More Java Vulnerabilities

Security Brief: China Retaliates Against Accusations, More Java Vulnerabilities

The main events of the week between February 25 - March 3

Bit9 Hack Connected to Latest Java Zero-Day Attacks

Bit9 Hack Connected to Latest Java Zero-Day Attacks

Both Symantec and FireEye experts agree that the malware and the C&C are the same

Zero-Day Affecting Java 6 U41 and Java 7 U15 Exploited in the Wild

Zero-Day Affecting Java 6 U41 and Java 7 U15 Exploited in the Wild

FireEye researchers say the exploit is not very reliable

Oracle Assigns Tracking Numbers to Java 7 Update 15 Issues, but Fails to Confirm Flaws

Oracle Assigns Tracking Numbers to Java 7 Update 15 Issues, but Fails to Confirm Flaws

Security Explorations says it only takes 10 minutes to verify the exploit

Zero-Day Vulnerability in Japanese Word Processor Ichitaro Exploited in the Wild

Zero-Day Vulnerability in Japanese Word Processor Ichitaro Exploited in the Wild

JustSystems has released a patch to address the flaw

Vulnerability Affecting Java 7 Update 15 and Earlier Versions Identified

Vulnerability Affecting Java 7 Update 15 and Earlier Versions Identified

Security Explorations has discovered another sandbox bypass flaw

Adobe Updates Reader X, XI and 9.5.3 to Address Zero-Day Vulnerabilities

Adobe Updates Reader X, XI and 9.5.3 to Address Zero-Day Vulnerabilities

Customers must install the updates immediately because the flaws are exploited in the wild

Adobe to Patch Reader and Acrobat Zero-Day During the Week of February 18

Adobe to Patch Reader and Acrobat Zero-Day During the Week of February 18

In the meantime, customers are advised to enable Protected View

Facebook Hacked in Sophisticated Attack, Java Zero-Day Used to Push Malware

Facebook Hacked in Sophisticated Attack, Java Zero-Day Used to Push Malware

Fortunately, there’s no evidence that user data has been compromised

Adobe Advises Users to Enable Protect View Until Reader Zero-Day Is Fixed

Adobe Advises Users to Enable Protect View Until Reader Zero-Day Is Fixed

The company provides instructions for regular customers and enterprises

The Use of Zero-Day Exploits by Governments Makes the Web Less Safe, Experts Say

The Use of Zero-Day Exploits by Governments Makes the Web Less Safe, Experts Say

State actors are paying impressive amounts of money to develop offensive capabilities

New Adobe Reader Zero-Day Identified, Versions 9.5.3, 10.1.5 and 11.0.1 Affected

New Adobe Reader Zero-Day Identified, Versions 9.5.3, 10.1.5 and 11.0.1 Affected

FireEye researchers are the ones who have discovered the new vulnerability

Adobe Updates Flash Player 11.5 and 11.2 to Address 2 Zero-Day Vulnerabilities

Adobe Updates Flash Player 11.5 and 11.2 to Address 2 Zero-Day Vulnerabilities

A memory corruption and a buffer overflow plague the older versions on all platforms

Adobe Fixes Reader Flaw, but It’s Uncertain If It’s the Zero-Day Found by Group IB

Adobe Fixes Reader Flaw, but It’s Uncertain If It’s the Zero-Day Found by Group IB

Adobe still hasn't received the proof-of-concept of the vulnerability

Security Explorations Identifies Two Vulnerabilities in Java 7 Update 11

Security Explorations Identifies Two Vulnerabilities in Java 7 Update 11

The security holes can be exploited for a complete sandbox bypass

Java 7 Update 11 Zero-Day Exploit Sold for $5,000 on Underground Market

Java 7 Update 11 Zero-Day Exploit Sold for $5,000 on Underground Market

The exploit is not integrated into any known crime kits

Java 7 Zero-Day Exploit Used to Distribute Reveton Ransomware

Java 7 Zero-Day Exploit Used to Distribute Reveton Ransomware

The best way for users to protect themselves is to disable Java

 
Want more? Browse: