Cyber attacks target ISIS in a new line of comba... » Security experts react to The New York Times article, “US Cyberattacks Target ISIS in New Line of Co... FAST and V.i. Labs join forces to educate market... » The Federation Against Software Theft (FAST) and long-term industry member V.i. Labs, have launched ... Wick Hill Wins ‘Distributor of the Year’ at IT E... » Woking, Surrey: Wick Hill has won the strongly contested ‘Distributor of the Year’ title at the IT E... Thales delivers digital trust across connected ... » Samsung Developer Conference, San Francisco, CA: Thales has announced that the SAMSUNG ARTIK™ platfo... BeyondTrust contributes threat analytics to the ... » PHOENIX: BeyondTrust has announced today that the 2016 Verizon Data Breach Investigations Report (DB... Construction hoist standard for transporting ... » BSI, the business standards company has revised BS 7212:2016 Code of practice for the safe use of co... FireMon delivers record 2015 Revenue...adds secu... » London, UK: FireMon CEO Jim Lewandowski has announced the security management firm achieved record g... PALFINGER achieves new record levels of revenue » - Revenue grew by 9.1 per cent to EUR 318.8 million - EBIT showed extraordinarily strong increase o... Industry leader covers nearly 700 compliance pol... » London, UK: Tripwire, Inc. has announced that Tripwire® Enterprise coverage for security policy and ... Varonis to stifle ransomware with new threat model... » London, UK: Varonis Systems, Inc. has announced the beta availability of more than 20 new threat mod...

CLICK HERE TO

Viewpoints Header

In response to the news that Oracle has carried out an emergency security update on Java, Lamar Bailey, Director of Security Research and Development at nCircle has the following comments:

 

Here we go yet again. 2013 has seen a surge of critical vulnerabilities in IE, Java and Ruby on Rails. Attackers are targeting cross platform applications to try to obtain access to as many systems as possible using as few exploits as possible.

Oracle has taken a beating this year on Java. It is good to see they are fixing critical vulnerabilities in a code base they want to quit updating but it is past time for them to get serious and do a deep dive on Java to fix the security issues.

I have always thought Oracle did a good job of securing their products but I am losing some of my faith in them with the rash of Java vulnerabilities. I hope these security problems are not found in their other products. My advice to end users is to remove Java from your system and only install it when is needed to access a business critical application, then if possible run Java in a VM or an isolated environment. This is easier said than done as my Windows box had no less that 4 Java versions with various updates. I hope Oracle will assign a team of their best security engineers to Java to squash any of the remaining security issues. Until then many users will be updating Java as often as they update AV signatures.