Skip to main content

New security vulnerability found in Java; experts recommend disabling the app

Image used with permission by copyright holder

Researchers have identified a zero-day security flaw in the Java program that hackers are exploiting. The concern is severe enough that the U.S. Computing Readiness Team, a unit of the Department of Homeland Security’s National Cyber Security Division, issued a note about the flaw. The vulnerability has already been incorporated into two of the most popular Web threat tools for hackers’ malware distribution, so the threat is live and putting computers at risk, The Next Web reported. 

The problem is a remote code execution vulnerability in Java 7 Update 10 and earlier versions of the application. This weakness allows a hacker to execute arbitrary code on an exposed machine. The Computing Readiness Team said there is no known workaround yet to protect against malicious attacks, and they recommended disabling Java if at all possible until maker Oracle can enact some repairs. If you can’t disable or uninstall the application, your best bet is to disable it in your main browser and keep all of your Java use confined to a separate browser.  

A French researcher working under the name Kafeine first reported the vulnerability, and security company AlienVault Labs confirmed the flaw. Kafeine said in his post about the problem that the latest version of Java was being exploited on a site receiving a heavy volume of traffic. 

Java has been a source of security concerns for years. Java 7 Update 7 was an out-of-cycle patch released in September to block a vulnerability that let hackers assume total control over a computer. The software is near-ubiquitous, making it an appealing target for hackers. Check out our explainer on Java for more information, including a walkthrough of how to disable and uninstall the app on your computer. 

Image via Jennie Faber

Editors' Recommendations

Anna Washenko
Former Digital Trends Contributor
Anna is a professional writer living in Chicago. She covers everything from social media to digital entertainment, from tech…
TrickBot returns with new attack that compromised 250 million email addresses
nhs email gaffe button

The TrickBot malware, which earlier this year worked in tandem with the Ryuk ransomware to siphon millions of dollars for hackers, is back with a new attack that may have compromised as many as 250 million email accounts.

In a report by Deep Instinct, the cybersecurity company revealed a new variant of TrickBot that teams it up with a malicious, email-based infection and distribution module dubbed TrickBooster.

Read more
Apple’s new sign-in feature brings a secure way to log in to your iOS 13 apps
Sign In with Apple.

At WWDC 2019, Apple is continuing to make its case and push for stronger privacy features. To make it simpler and more secure for iOS 13 users to sign in to apps, Apple is launching a new sign in button called "Sign in with Apple." The tool works like similar social sign-in buttons -- like those that allow users to log into third-party apps with either their Google or Facebook ID -- but adds Apple's twist with a focus on privacy and security.

Most apps and services today require users to either create a user profile or login with a social ID to deliver a unique, customized experience. The former requires comes with a lot of friction, as it requires you to enter a lot of information, while the latter is convenient but could reveal a lot about you.

Read more
Dell’s XPS 13 for $599 deal is back, and who knows for how long
The Dell XPS 13 in front of a window.

Dell almost always has great laptop deals and for a little while now, it’s been selling an older model of the Dell XPS 13 for just $599. That deal continues today but we’re really not sure how long it’s going to stick around for. It feels like it must be ending very soon. The laptop usually costs $799 so you’re saving $200 but overall, this is a fantastic deal for the hardware involved. If you’re keen to learn more before the deal ends, keep reading.

Why you should buy the Dell XPS 13
Dell is one of the best laptop brands out there so you simply can’t go wrong with purchasing from it. With this model, you get a 12th-generation Intel Core i5-1230U processor along with 8GB of memory and 256GB of SSD storage. There’s also a 13.4-inch full HD+ screen with 1920 x 1200 resolution, 500 nits of brightness, and anti-glare properties. That’s fairly standard stuff at this price but it’s the build quality of the Dell XPS 13 which makes it stand out so much.

Read more