Skip to main content

New security vulnerability found in Java; experts recommend disabling the app

Image used with permission by copyright holder

Researchers have identified a zero-day security flaw in the Java program that hackers are exploiting. The concern is severe enough that the U.S. Computing Readiness Team, a unit of the Department of Homeland Security’s National Cyber Security Division, issued a note about the flaw. The vulnerability has already been incorporated into two of the most popular Web threat tools for hackers’ malware distribution, so the threat is live and putting computers at risk, The Next Web reported. 

The problem is a remote code execution vulnerability in Java 7 Update 10 and earlier versions of the application. This weakness allows a hacker to execute arbitrary code on an exposed machine. The Computing Readiness Team said there is no known workaround yet to protect against malicious attacks, and they recommended disabling Java if at all possible until maker Oracle can enact some repairs. If you can’t disable or uninstall the application, your best bet is to disable it in your main browser and keep all of your Java use confined to a separate browser.  

A French researcher working under the name Kafeine first reported the vulnerability, and security company AlienVault Labs confirmed the flaw. Kafeine said in his post about the problem that the latest version of Java was being exploited on a site receiving a heavy volume of traffic. 

Java has been a source of security concerns for years. Java 7 Update 7 was an out-of-cycle patch released in September to block a vulnerability that let hackers assume total control over a computer. The software is near-ubiquitous, making it an appealing target for hackers. Check out our explainer on Java for more information, including a walkthrough of how to disable and uninstall the app on your computer. 

Image via Jennie Faber

Editors' Recommendations

Anna Washenko
Former Digital Trends Contributor
Anna is a professional writer living in Chicago. She covers everything from social media to digital entertainment, from tech…
Apple’s new sign-in feature brings a secure way to log in to your iOS 13 apps
Sign In with Apple.

At WWDC 2019, Apple is continuing to make its case and push for stronger privacy features. To make it simpler and more secure for iOS 13 users to sign in to apps, Apple is launching a new sign in button called "Sign in with Apple." The tool works like similar social sign-in buttons -- like those that allow users to log into third-party apps with either their Google or Facebook ID -- but adds Apple's twist with a focus on privacy and security.

Most apps and services today require users to either create a user profile or login with a social ID to deliver a unique, customized experience. The former requires comes with a lot of friction, as it requires you to enter a lot of information, while the latter is convenient but could reveal a lot about you.

Read more
Vision Pro 2: everything we expect from the future of Apple’s headsets
The Apple Vision Pro reveals the wearer's eyes on a front-facing display.

Apple’s Vision Pro headset has just made a huge splash in the tech world, but Apple is already planning to follow it up with two new models that could take the headset to new heights -- and put it into the hands of more people. That includes a second-generation Apple Vision Pro, as well as a pared-back headset with a lower price.

What exactly should we expect from these devices? What kind of features will they offer, and when will they launch? If you’re seeking the answers to all those questions and more, you’re in the right place, as our rumor roundup will guide you through everything you need to know. Let’s get started.
Vision Pro 2: price and release date

Read more
ChatGPT: the latest news, controversies, and tips you need to know
ChatGPT app running on an iPhone.

ChatGPT has continued to dazzle the internet with AI-generated content, morphing from a novel chatbot into a piece of technology that is driving the next era of innovation. No tech product in recent memory has sparked as much interest, controversy, fear, and excitement.

If you're just now catching on, it'd be fair to wonder what the fuss is all about. You can try it out for yourself for free (or use the official free iOS app), but here's the detailed guide you've been looking for -- whether you're worried about an AI apocalypse or are just looking for an intro guide to the app.

Read more