Security News

Red Hat JBoss EAP on Azure enables the migration of Java applications to cloud environments
2021-05-27 02:00

Red Hat announced Red Hat JBoss Enterprise Application Platform on Microsoft Azure, enabling organizations to tap into the benefits of a cloud-based architecture for modernizing their existing Jakarta EE applications and building new ones on Azure. Customers can bring existing applications to Azure-including JBoss EAP applications running on-premises or other Jakarta EE applications running on different application servers-choosing how they want to manage business critical, Java-based applications in the cloud.

Adult site users targeted with ZLoader malware via fake Java update
2020-11-17 03:28

A malware campaign ongoing since the beginning of the year has recently changed tactics, switching from exploit kits to social engineering to target adult content consumers. Malwarebytes monitored the Malsmoke campaign all year long delivering Smoke Loader - a malware dropper - via Fallout exploit kit until its track went cold on October 18.

Sloppy string sanitization sabotages system security of millions of Java-powered 3G IoT kit: Patch me if you can
2020-08-20 10:02

A vulnerability in Thales' Cinterion EHS8 M2M module, a Java-powered embedded 3G system used in millions of Internet-of-Things devices for connectivity, was revealed yesterday by IBM's X-Force Red. The bug, disclosed to Thales and addressed in a patch made available to IoT vendors in February, makes it possible for an attacker to extract the code and other resources from a vulnerable device.

Multi-Platform 'Tycoon' Ransomware Uses Rare Java Image Format for Evasion
2020-06-04 18:38

A recently discovered multi-platform Java ransomware uses a Java image file to evade detection, BlackBerry security researchers report. After establishing a foothold onto the environment, the attackers executed the Java ransomware module, which encrypted all file servers connected to the network, including backup systems.

Yo, sysadmins! Thought Patch Tuesday was big? Oracle says 'hold my Java' with huge 334 security flaw fix bundle
2020-01-15 21:33

Oracle has released a sweeping set of security patches across the breadth of its software line. The January update, delivered one day after Microsoft, Intel, Adobe, and others dropped their scheduled monthly patches, addresses a total of 334 security vulnerabilities across 93 different products from the enterprise giant.

Oracle, Gemalto Downplay Java Card Vulnerabilities
2019-04-25 14:22

A cybersecurity research company has uncovered over 30 security issues in Java Card technology, but Oracle and Gemalto appear to downplay the impact of the flaws. read more

Oracle splats 300 vulns in MySQL, Database, Fusion, etc, pours fresh brew of Java SE terms
2019-04-16 22:52

Multiple pre-auth remote code exec holes need pasting over, enterprise IT giant warns Oracle has issued its quarterly security updates, patching a total of 296 vulnerabilities across its massive...

Unofficial Patch Released for Java Flaws Found by Google Researcher
2019-04-05 13:19

Unofficial patches have been released for two unfixed Oracle Java Runtime Environment (RE) vulnerabilities discovered by Google Project Zero researcher Mateusz Jurczyk. read more

Security storm brewing for Oracle Java-powered smart cards: More than a dirty dozen flaws found, fixes... er, any fixes?
2019-03-22 22:08

Vuln hunters warn malicious applets can bust through protections, snoop on or hijack access gizmos Bug hunters say Oracle's Java Card platform is host to a dozen and a half security flaws that...

Many Vulnerabilities Found in Oracle's Java Card Technology
2019-03-21 14:35

Poland-based cybersecurity research firm Security Explorations claims to have identified nearly 20 vulnerabilities in Oracle’s Java Card, including flaws that could be exploited to compromise the...