New zero-day vulnerabilities zero-day vulnerabilities in Java:Threats and Advice
The allegations come
from Researchers who claim to have found several vulnerabilities zero-day vulnerabilities in Java.
So according to Update posted by Security Explorations, the flaws could be exploited to
completely bypass Java's security sandbox and infect
computers in a similar
fashion to the attacks which recently troubled :Facebook, Apple and Microsoft.
This means that cybercriminals
hacked legitimate websites and planted code which exploited Java
vulnerabilities when developers visited using web browsers that had a
vulnerable version of the Java plugin.
Therefore Sophos has delivered
advice we can give you right now: ‘’If
you don't need Java enabled in your browser, here's how to turn it off now.’’
‘Many people who have Java
enabled in their browser simply do not need it (By the way, don't mix up Java with JavaScript - they're different things), so the best
solution for many folks is to rip Java out of their browser entirely.’’