A vulnerability in Java technology could be exploited by attackers and used to compromise computers running Windows if they visit a Web page hosting malicious code, two researchers warned on Friday.Google engineer Tavis Ormandy released details on the Full Disclosure e-mail list and Ruben Santamarta, an engineer for Wintercore, wrote about it on his company’s blog site.
The problem is with the Java Web Start framework, which allows developers an easy way to create Java applications. Disabling the Java plug-in will not protect against an attack, according to Ormandy. Read more »




Posted in
Tags:
The downturn was not unexpected. “This is indicative of the on and off cycle that Microsoft uses,” said Andrew Storms, director of security operations at nCircle Network Security. “Last month was more OS related, this month they’re patching some applications.”


