Microsoft report shows massive spike in Java exploits
Move over, Flash and PDF -- there's a new contender in the race for the "browser plug-in exploit" title belt! According to the numbers Microsoft has crunched, Java appears to have locked up 2010's number one spot.
You don't often see Java's name splashed across the headlines, however, which is why the Microsoft report shocked me a bit. From personal experience on my workbench, I also know that Java is one of the last things the average user bothers to update. Outdated software is a big risk, especially when that software is being exploited as actively as Java is. Just last week, for example, Oracle pushed a massive bundle of 29 patches -- which I'll wager have been ignored by the vast Java-using public. My guess is that the bad guys have figured this out, too.
The good news: unlike Flash, which is needed by most of your favorite video and casual gaming sites, the Java plug-in is required far less often -- so you probably won't notice a big difference if you disable or uninstall it.
[via ZDnet]
You don't often see Java's name splashed across the headlines, however, which is why the Microsoft report shocked me a bit. From personal experience on my workbench, I also know that Java is one of the last things the average user bothers to update. Outdated software is a big risk, especially when that software is being exploited as actively as Java is. Just last week, for example, Oracle pushed a massive bundle of 29 patches -- which I'll wager have been ignored by the vast Java-using public. My guess is that the bad guys have figured this out, too.
The good news: unlike Flash, which is needed by most of your favorite video and casual gaming sites, the Java plug-in is required far less often -- so you probably won't notice a big difference if you disable or uninstall it.
[via ZDnet]













Comments
6
Subscribe to commentsMxxConOct 18th 2010 8:13PM
Lee, that's a super cheesy pun :/
mer2329Oct 18th 2010 8:49PM
I use the Firefox plugin check to bulk check my plugins (I do this every month or every other month)
https://www.mozilla.com/en-US/plugincheck/
it checks a bunch of ones that Firefox wont update (for example: flash, java, reader, and Silverlight)
the ones that come up as research are usually updated by Firefox itself
pmupOct 18th 2010 10:57PM
Of course Microsoft hates Java
AemonyOct 19th 2010 1:22AM
Simple fix: Just disable the Java plugin in your browser.
The only reason why I even bother having Java installed is all because Minecraft forces me. And the only thing I use with my web browser that requires Java is the Falling Sand game, which I only occasionally use.
EmilOct 19th 2010 4:15AM
This has a huge impact on corporate users. Corporations are the reason why IE6 still has a lot of marketshare and a lot of Java VMs are just as outdated as well. Updating web-based applications to work with newer Java versions is a pain and often developers don't even care. Updating to a newer version often means that important applications do not work at all anymore so this is indeed bad news.
NyaROct 19th 2010 4:36AM
yo dog...