Connect with us

Hi, what are you looking for?

HEADLINES

Study reveals surge in Java exploit attacks to 14.1 million in a year

The number of attacks using Java exploits from September 2012 to August 2013 amounted to 14.1 million – one third more than in the same period in 2011-2012,

The number of attacks using Java exploits from September 2012 to August 2013 amounted to 14.1 million – one third more than in the same period in 2011-2012, according to the Kaspersky Lab study, “Java Under Attack – The Evolution of Exploits in 2012-2013.”

Exploits are malicious programs designed to take advantage of vulnerabilities in legitimate software and penetrate users’ computers. The fact that they function surreptitiously makes them all the more dangerous.

If a computer is running vulnerable versions of any software, simply visiting an infected web page or opening a file containing malicious code is enough to trigger an exploit. Traditionally, the most frequent targets for attacks have been Oracle Java, Adobe Flash Player, and Adobe Reader. However, the Kaspersky Lab study revealed that in the past year Java is increasingly becoming the prime target for cybercriminals.

The study was based on data gathered from users of Kaspersky products around the world who consented to provide information to Kaspersky Security Network.

Advertisement. Scroll to continue reading.

Of the 14.1 million attacks detected using Java exploits, most happened in the second half of the study period – over 8.54 million attacks were registered from March to August 2013, up 52.7% on the previous six months.

The study also found that over a 12-month period, Kaspersky Lab’s products protected more than 3.75 million users across the globe from Java exploit attacks.

Approximately 80% of attacked users live in 10 countries; the Top 3 includes the USA, Russia and Germany.

Canada, the USA, Germany and Brazil experienced the fastest growth in the number of attacks. Approximately 50% of all attacks were launched using just six families of Java exploits.

For home users, installing newly released updates is rarely a high priority – which plays into the cybercriminals’ hands. According to the research, most users keep working with a vulnerable version of Java for six weeks after an update is released.

Advertisement. Scroll to continue reading.

Over a one-year period, each user faced an average of 3.72 attacks. Over the period from September 2012 – February 2013, the average exposure was 3.29 attacks per individual user; in March – August 2013, it 4.15 was attacks per user. In the space of six months exposure rates rose by 26.1%.

The study also revealed that 1,210,000 unique attack sources were identified in 95 countries.

The large number of attacks launched using Java exploits is little surprise: over the 12 months of Kaspersky Lab’s research, 161 vulnerabilities were identified in Java.

In comparison, over the period of September 2011 to August 2012, information about 51 vulnerabilities was published. Six of the newly detected vulnerabilities were rated as critical, or very dangerous; these six were most actively used in attacks by cybercriminals.

“Java is a victim of its own popularity,” said Vyacheslav Zakorzhevsky, Head of the Vulnerability Research Group at Kaspersky Lab.

Advertisement. Scroll to continue reading.

“Cyber criminals know they are better off focusing their efforts on finding a vulnerability in Java and then attacking millions of computers at one stroke, rather than creating multiple exploits for several less popular products and still finding that they are affecting fewer computers,” he added.

To protect themselves against the potential costs of a malicious attack launched using Java exploits, Kaspersky Lab’s experts advise both home and corporate users to install Java updates promptly as well as choosing security solutions that can reliably block exploit-based cyber-attacks.

Advertisement
Advertisement
Advertisement

Like Us On Facebook

You May Also Like

HEADLINES

Someone illegally acquires or uses personal information such as bank account or credit card numbers of another person to obtain money, goods or services....

HEADLINES

To stay ahead of these challenges, organizations need to invest in AI-driven defenses, transition to quantum-safe encryption, and adopt a Zero Trust approach to...

HEADLINES

There was a 121% Year-on-Year (YoY) increase in identity fraud in 2024 across the region, with significant surges recorded in Singapore (207%), Thailand (206%)...

HEADLINES

As part of RCBC’s 2024 Cybersecurity literacy program, the webinar aims to help Filipinos level up their online banking safety by providing them with...

White Papers

The survey found that CXO’s feel less prepared than their global peers. Less than half or 48% in APAC said they felt completely prepared...

HEADLINES

On average, a single organization in the Philippines experiences 4,003 attacks per week, significantly higher than the APAC average of 2,870 attacks per week.

White Papers

Exploiting this vulnerability, cybercriminals craft deceptively authentic phishing emails that align with current trends, exploiting human emotions to invoke urgency and trick recipients into...

HEADLINES

As the year 2024 draws to a close, cybersecurity solutions provider Fortinet unveiled predictions that expect hackers will leverage as well as trends that...

Advertisement