When you think about it, most vulnerabilities within the public eye appears to come down to Java in some respect – but it’s not just you – Cisco’s 2014 Annual Security Report points the blame at Oracle’s Java for being a leading cause of security woes.
In fact, the report suggest as much as 91 percent of all attacks can be pointed at Java’s insecurities being the culprit.
The data comes via the Vulnerability Research Team (VRT), which became part of Cisco in 2013 after a $2.7 billion acquisition of Sourcefire – already proven as a worthwhile purchase.
Levi Gundert, technical lead at Cisco Threat Research, Analysis, and Communications, said to eWEEK: “I was surprised to see that the Java IOC number was 91 percent, there were a number of Java zero days that were used in various attacks, but there were also a ton of well-known Java vulnerabilities that were packaged into various exploit packs.”
Oracle has been in constant battle against these exploits; only yesterday patching a further 51 vulnerabilities. Java has become necessary for many users, but after this news, they may consider attempting to go Java-free – especially those particularly concerned with security.
This necessity for many, and its availability on any device, is what makes Java such a high-value target.
Overall, Java threats are rising 14% year-on-year. It’s not just Cisco which has picked up upon this incredible surge in attack traffic throughout 2013, respected vendors; including Kaspersky Labs and Hewlett Packard – also reported a rise.
It was also found this week, and reported in the recently published SERT Q4 2013 Threat Intelligence Report (PDF), that Malware writers are using the big cloud hosting platforms – such as those from Amazon, GoDaddy, and Google – to quickly and effectively serve malware to Internet users, allowing them to bypass detection and geographic blacklisting by serving from a trusted provider.
Amazon and GoDaddy were identified as the top malware-hosting providers; with 16 percent and a 14 percent share, respectively. These services consistently change IP addresses and domain names; which help them avoid detection.
What do you think of these latest threats to your computer’s security?