Microsoft warns of spike in Java attacks

Microsoft researchers discovered a surge in attacks against Java that has gone undetected thanks to "Java-blindness."

In the course of researching and preparing volume 9 of the Security Intelligence Report, Microsoft analysts discovered an interesting trend. According to Microsoft's findings, attacks against Java have recently surged to unprecedented levels -- dwarfing attacks against Adobe PDFs.

Microsoft is accustomed to being a prime target for malware attacks, and Adobe has been hogging center stage for a while as well. But, a post on the Microsoft Malware Protection Center (MMPC) blog notes, "by the beginning of this year, the number of Java exploits (and by that I mean attacks on vulnerable Java code, not attacks using JavaScript) had well surpassed the total number of Adobe-related exploits we monitored."

Attacks on Java make sense for precisely the same reason that attacks on Adobe make sense. A malware developer that has to choose which operating system platform to attack will choose Microsoft because it offers significantly more potential targets. But, as Microsoft has developed more secure applications, and improved security controls, attackers have discovered that third-party cross-platform technologies are often a weak spot in the security armor.

Microsoft's Holly Stewart explains in the MMPC blog, "Java is ubiquitous, and, as was once true with browsers and document readers like Adobe Acrobat, people don't think to update it. On top of that, Java is a technology that runs in the background to make more visible components work. How do you know if you have Java installed or if it's running?"

Stewart also raises the question of why this surge in Java attacks seems to have flown under the radar. She dubs the phenomenon "Java-blindness". Essentially, Stewart theorizes that the IPS (Intrusion Prevention System) products that we expect to detect and identify new threats are blind to Java because the performance impact of interpreting Java in real-time is too great.

While the number of attacks against Java spiked, the attacks focused primarily on three Java vulnerabilities. More importantly, all three Java flaws already had patches available. Java just kind of runs silently doing its thing, though, so--while users and IT admins focus on Microsoft's monthly Patch Tuesday updates, or Adobe's quarterly security patches--Java is sort of "out of sight, out of mind" and vulnerabilities may go unpatched.

In the grand scheme of things, the attacks on Java are a drop in the bucket. The surge in Java attacks may be significant and unprecedented, but Java is still a relative blip on the radar. That said, Microsoft's findings highlight an alarming trend, and should provide incentive for users and IT admins to be more diligent about identifying and patching vulnerabilities in third-party apps that could expose systems to attack.

Join the newsletter!

Or

Sign up to gain exclusive access to email subscriptions, event invitations, competitions, giveaways, and much more.

Membership is free, and your security and privacy remain protected. View our privacy policy before signing up.

Error: Please check your email address.

Tags Microsoftmalwareintelspamvirusesantispamonline security

Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

Tony Bradley

PC World (US online)
Show Comments

Essentials

Brother MFC-L3745CDW Colour Laser Multifunction

Learn more >

Mobile

Exec

Sony WH-1000XM4 Wireless Noise Cancelling Headphones

Learn more >

Budget

Back To Business Guide

Click for more ›

Most Popular Reviews

Latest Articles

Resources

PCW Evaluation Team

Tom Pope

Dynabook Portégé X30L-G

Ultimately this laptop has achieved everything I would hope for in a laptop for work, while fitting that into a form factor and weight that is remarkable.

Tom Sellers

MSI P65

This smart laptop was enjoyable to use and great to work on – creating content was super simple.

Lolita Wang

MSI GT76

It really doesn’t get more “gaming laptop” than this.

Jack Jeffries

MSI GS75

As the Maserati or BMW of laptops, it would fit perfectly in the hands of a professional needing firepower under the hood, sophistication and class on the surface, and gaming prowess (sports mode if you will) in between.

Taylor Carr

MSI PS63

The MSI PS63 is an amazing laptop and I would definitely consider buying one in the future.

Christopher Low

Brother RJ-4230B

This small mobile printer is exactly what I need for invoicing and other jobs such as sending fellow tradesman details or step-by-step instructions that I can easily print off from my phone or the Web.

Featured Content

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?