Filtered by: Scitech
SciTech

Warning out vs 'Java update' malware


Computer users wary of security risks using Java were warned against a new malware attack - where the malware masquerades as a Java update.
 
Security vendor GFI said the attack exploits fears stemming from a new zero-day, critical flaw on Java that has been integrated into popular exploit kits.
 
"Please make sure that you’re downloading the patch straight from the Oracle website and nowhere else because it’s highly likely that what you may be installing onto your system is malware," it warned in a blog post.
 
Otherwise, it said the malware exploiting Java may allow remote code execution on a target system without authentication from the user.
 
It added this could give malware files the upper hand if users visit sites/URLs where they are hosted.
 
GFI also said that while Oracle has released a patch for Java, "many security experts have already began advising users to just forget the patch and disable Java in their browsers." — TJD, GMA News
Tags: java, malware