Java surpasses Adobe kit as most attacked software

Researcher sees 'unprecedented wave of Java exploitation'


Oracle's Java framework has surpassed Adobe applications as the most attacked software package, according to a Microsoft researcher who warned she was seeing “an unprecedented wave of Java exploitation.”

The spike began in the third-quarter of last year and has climbed steadily since, according to data reported on Monday by Holly Stewart, a member of the Microsoft Malware Protection Center. By the beginning of this year, the number of Java exploits “had well surpassed the total number of Adobe-related exploits we monitored,” she said.

The spike is mostly driven by attacks on three separate vulnerabilities that Oracle patched long ago. As a result attacks on Java have “gone from hundreds of thousands per quarter to millions,” Stewart blogged.

As Microsoft has released new versions of its software that are harder to exploit, attackers looking for ways to install malware have turned their attention to other ubiquitous PC titles. With a massive share of Windows machines, Adobe Reader emerged earlier this year as the world's most exploited app, according to antivirus provider F-Secure. Adobe's Flash Player, also because of its broad base of users, has long been a favorite as well.

Java, which Oracle inherited from Sun Microsystems, has remained vulnerable, too, and exploits are now coming into the mainstream. One of the things driving the trend, according to security reporter Brian Krebs, are updates that add Java attacks to Eleonore, Crimepack and other exploit kits that malware purveyors use to streamline the installation of malware on victim machines.

“Java is ubiquitous, and, as was once true with browsers and document readers like Adobe, people don't think to update it,” Stewart wrote. “On top of that, Java is a technology that runs in the background to make more visible components work.”

The software has never lived up to many of the promises that Sun made about it. Chances are it can be uninstalled from most desktop machines and the user won't even notice. ®

Similar topics


Other stories you might like

  • Deepfake attacks can easily trick live facial recognition systems online
    Plus: Next PyTorch release will support Apple GPUs so devs can train neural networks on their own laptops

    In brief Miscreants can easily steal someone else's identity by tricking live facial recognition software using deepfakes, according to a new report.

    Sensity AI, a startup focused on tackling identity fraud, carried out a series of pretend attacks. Engineers scanned the image of someone from an ID card, and mapped their likeness onto another person's face. Sensity then tested whether they could breach live facial recognition systems by tricking them into believing the pretend attacker is a real user.

    So-called "liveness tests" try to authenticate identities in real-time, relying on images or video streams from cameras like face recognition used to unlock mobile phones, for example. Nine out of ten vendors failed Sensity's live deepfake attacks.

    Continue reading
  • Lonestar plans to put datacenters in the Moon's lava tubes
    How? Founder tells The Register 'Robots… lots of robots'

    Imagine a future where racks of computer servers hum quietly in darkness below the surface of the Moon.

    Here is where some of the most important data is stored, to be left untouched for as long as can be. The idea sounds like something from science-fiction, but one startup that recently emerged from stealth is trying to turn it into a reality. Lonestar Data Holdings has a unique mission unlike any other cloud provider: to build datacenters on the Moon backing up the world's data.

    "It's inconceivable to me that we are keeping our most precious assets, our knowledge and our data, on Earth, where we're setting off bombs and burning things," Christopher Stott, founder and CEO of Lonestar, told The Register. "We need to put our assets in place off our planet, where we can keep it safe."

    Continue reading
  • Conti: Russian-backed rulers of Costa Rican hacktocracy?
    Also, Chinese IT admin jailed for deleting database, and the NSA promises no more backdoors

    In brief The notorious Russian-aligned Conti ransomware gang has upped the ante in its attack against Costa Rica, threatening to overthrow the government if it doesn't pay a $20 million ransom. 

    Costa Rican president Rodrigo Chaves said that the country is effectively at war with the gang, who in April infiltrated the government's computer systems, gaining a foothold in 27 agencies at various government levels. The US State Department has offered a $15 million reward leading to the capture of Conti's leaders, who it said have made more than $150 million from 1,000+ victims.

    Conti claimed this week that it has insiders in the Costa Rican government, the AP reported, warning that "We are determined to overthrow the government by means of a cyber attack, we have already shown you all the strength and power, you have introduced an emergency." 

    Continue reading

Biting the hand that feeds IT © 1998–2022