Java Exploits on the Rise
By: Stephanie Chaumont
Publication: The Community Banker, Winter 2012
Last month, Kaspersky Lab reported that Java is the target for more than half of all malware exploit attempts. Combine that with the fact that one very common audit finding is to encounter older versions of Java on a bank's network, and you have a recipe for disaster.
I may need to clarify something about older versions of Java. Java does not work like Microsoft. When Microsoft discovers a vulnerability, they release a patch for you to install on your existing platform, so it's possible that you have an older version of Microsoft that is completely patched. When software companies like Adobe and Oracle (Java) discover a vulnerability, the patch is released in a new version of the product. That's why you constantly see new versions available…they are not usually released for the purpose of adding some cool new feature. They are most likely released to fix a security issue.