Threat Level: green Handler on Duty: Russ McRee

SANS ISC: Diaries by Keyword Diaries by Keyword

Watch ISC TV. Great for NOCs, SOCs and Living Rooms: https://isctv.sans.edu

Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!
Date Author Title

JAVA SUPPORT ENDED

2014-07-05Guy BruneauJava Support ends for Windows XP

JAVA

2020-07-24/a>Xavier MertensCompromized Desktop Applications by Web Technologies
2020-07-08/a>Xavier MertensIf You Want Something Done Right, You Have To Do It Yourself... Malware Too!
2020-06-11/a>Xavier MertensAnti-Debugging JavaScript Techniques
2020-03-27/a>Xavier MertensMalicious JavaScript Dropping Payload in the Registry
2019-08-09/a>Xavier Mertens100% JavaScript Phishing Page
2019-06-10/a>Xavier MertensInteresting JavaScript Obfuscation Example
2019-02-07/a>Xavier Mertens Phishing Kit with JavaScript Keylogger
2018-07-13/a>Xavier MertensCryptominer Delivered Though Compromized JavaScript File
2018-06-18/a>Xavier MertensMalicious JavaScript Targeting Mobile Browsers
2017-11-03/a>Xavier MertensSimple Analysis of an Obfuscated JAR File
2017-06-22/a>Xavier MertensObfuscating without XOR
2017-03-24/a>Xavier MertensNicely Obfuscated JavaScript Sample
2017-03-04/a>Xavier MertensHow your pictures may affect your website reputation
2017-02-12/a>Xavier MertensAnalysis of a Suspicious Piece of JavaScript
2016-08-28/a>Guy BruneauSpam with Obfuscated Javascript
2016-06-18/a>Rob VandenBrinkControlling JavaScript Malware Before it Runs
2016-02-20/a>Didier StevensLocky: JavaScript Deobfuscation
2016-02-07/a>Xavier MertensMore Malicious JavaScript Obfuscation
2016-01-15/a>Xavier MertensJavaScript Deobfuscation Tool
2015-11-09/a>John BambenekICYMI: Widespread Unserialize Vulnerability in Java
2015-08-07/a>Tony CarothersCritical Firefox Update Today
2014-12-06/a>Rick WannerGoogle App Engine Java Security Sandbox bypasses
2014-08-29/a>Johannes UllrichFalse Positive or Not? Difficult to Analyze Javascript
2014-07-15/a>Daniel WesemannOracle Java: 20 new vulnerabilities patched
2014-07-13/a>Tony CarothersOracle July 2014 Update Pre-Notification
2014-07-05/a>Guy BruneauJava Support ends for Windows XP
2014-07-02/a>Johannes UllrichSimple Javascript Extortion Scheme Advertised via Bing
2013-12-23/a>Rob VandenBrinkHow-To's for the Holidays - Java Whitelisting using AD Group Policy
2013-10-28/a>Daniel WesemannExploit cocktail (Struts, Java, Windows) going after 3-month old vulnerabilities
2013-10-15/a>Rob VandenBrinkJava Quarterly Updates
2013-09-10/a>Swa FrantzenMore Black Tuesday workload
2013-08-07/a>Johannes UllrichFirefox 23 and Mixed Active Content
2013-04-23/a>Russ McReeMicrosoft's Security Intelligence Report (SIRv14) released
2013-04-19/a>Russ McReeJava 8 release schedule delayed for renewed focus on security
2013-04-16/a>Rob VandenBrinkJava 7 Update 21 is available - Watch for Behaviour Changes !
2013-03-07/a>Guy BruneauApple Blocking Java Web plug-in
2013-03-05/a>Richard PorterJava j6u43 update #YAJU http://www.oracle.com/technetwork/java/javase/6u43-relnotes-1915290.html
2013-03-04/a>Richard PorterJava 7u17 update #YAJU http://www.oracle.com/technetwork/java/javase/7u17-relnotes-1915289.html
2013-03-01/a>Jim ClausingAnd the Java 0-days just keep on coming
2013-02-26/a>Rob VandenBrinkAll I need Java for is ....
2013-02-20/a>Johannes UllrichUpdate Palooza
2013-02-19/a>Johannes UllrichOracle Updates Java (Java 7 Update 15, Java 6 update 41)
2013-02-08/a>Kevin ShorttIs it Spam or Is it Malware?
2013-02-01/a>Jim ClausingOracle quitely releases Java 7u13 early
2013-01-19/a>Guy BruneauJava 7 Update 11 Still has a Flaw
2013-01-15/a>Rob VandenBrinkWhen Disabling IE6 (or Java, or whatever) is not an Option...
2013-01-13/a>Stephen HallJava 0-Day patched as Java 7 U 11 released
2013-01-12/a>Stephen HallJava 0-day impact to Java 6 (and beyond?)
2013-01-10/a>Johannes UllrichJava is still exploitable and is likely going to remain so.
2012-11-01/a>Daniel WesemannPatched your Java yet?
2012-10-18/a>Rob VandenBrinkAnother Java update! Java SE 1.6.0_37 Available ==> http://www.oracle.com/technetwork/java/javase/releasenotes-136954.html
2012-10-17/a>Rob VandenBrinkTime to update - Java version 7 update 9 (JRE 7u9, JDK 7u9) is out! Release notes here - http://www.oracle.com/technetwork/java/javase/7u9-relnotes-1863279.html
2012-09-01/a>Russ McReeBlackhole targeting Java vulnerability via fake Microsoft Services Agreement email phish
2012-08-31/a>Russ McReeNot so fast: Java 7 Update 7 critical vulnerability discovered in less than 24 hours
2012-08-27/a>Kevin ListonQuick Bits about Today's Java 0-Day
2012-08-05/a>Daniel WesemannPhishing for Payroll with unpatched Java
2012-06-25/a>Guy BruneauUsing JSDetox to Analyze and Deobfuscate Javascript
2012-06-12/a>Swa FrantzenJava 7u5 and 6u33 released
2012-05-22/a>Johannes Ullrichnmap 6 released
2012-04-25/a>Daniel WesemannBlacole's obfuscated JavaScript
2012-04-12/a>Guy BruneauApple Java Updates for Mac OS X
2012-04-06/a>Johannes UllrichAnother OS X Java Patch
2012-03-25/a>Daniel Wesemannevilcode.class
2012-02-16/a>Tony CarothersJava Update for February
2012-01-22/a>Johannes UllrichJavascript DDoS Tool Analysis
2012-01-03/a>Bojan ZdrnjaThe tale of obfuscated JavaScript continues
2011-12-12/a>Daniel WesemannJava 6u30 released
2011-12-10/a>Daniel WesemannUnwanted Presents
2011-12-07/a>Lenny ZeltserV8 as an Alternative to SpiderMonkey for JavaScript Deobfuscation
2011-10-22/a>Guy BruneauOracle Java SE Critical Patch Update
2011-09-05/a>Raul SilesJava 7 Officially Released
2011-08-19/a>Kevin ShorttJava SE 6 Update 27 released. No security updates, many bug fixes ==> http://www.oracle.com/technetwork/java/javase/6u27-relnotes-444147.html
2011-07-28/a>Guy BruneauJava 7.0 released. Get it here - http://blogs.oracle.com/javase/entry/java_7_has_released
2011-06-28/a>Johannes UllrichUpdate: Java update for OS X fixes security issues http://support.apple.com/kb/HT1222
2011-06-07/a>Johannes UllrichOracle Releases Java Version 1.6.0.26 http://java.com/en/download/manual.jsp
2011-06-06/a>Manuel Humberto Santander PelaezPhishing: Same goal, same techniques and people still falling for such scams
2011-06-03/a>Guy BruneauOracle Java SE Critical Patch Update Pre-Release Announcement - June 2011
2011-05-01/a>Deborah HaleJava 6.25 Is Now Available
2011-04-23/a>Manuel Humberto Santander PelaezImage search can lead to malware download
2011-03-09/a>Jim ClausingApple updates Java
2011-02-15/a>Jason LamOracle Java 6 Update 24
2011-02-09/a>Mark HofmanJava Floating point issue (CVE-2010-4476)
2011-02-04/a>Daniel WesemannOh, just click "yes"
2010-12-29/a>Daniel WesemannBeware of strange web sites bearing gifts ...
2010-12-24/a>Daniel WesemannA question of class
2010-12-08/a>Rob VandenBrinkJava 6, Update 23 is out => http://java.sun.com/javase/6/webnotes/ReleaseNotes.html , http://www.oracle.com/technetwork/java/javase/6u23releasenotes-191058.html , http://www.oracle.com/technetwork/java/javase/2col/6u23bugfixes-191074.html
2010-12-02/a>Kevin JohnsonRobert Hansen and our happiness
2010-11-11/a>Daniel WesemannJava Exploits
2010-07-18/a>Manuel Humberto Santander PelaezNew metasploit GUI written in Java
2010-07-04/a>Manuel Humberto Santander PelaezMalware inside PDF Files
2010-05-23/a>Manuel Humberto Santander PelaezOracle Java SE and Java for Business 'MixerSequencer' Remote Code Execution Vulnerability
2010-04-10/a>Andre LudwigNew bug/exploit for javaws
2010-04-02/a>Guy BruneauOracle Java SE and Java for Business Critical Patch Update Advisory
2010-03-05/a>Kyle HaugsnessJavascript obfuscators used in the wild
2010-01-13/a>Guy BruneauSun Java JRE 6 Update 18 Released
2009-12-05/a>Guy BruneauJava JRE Buffer and Integer Overflow
2009-09-08/a>Guy BruneauBug Fixes in Sun SDK 5 and Java SE 6
2009-08-04/a>donald smithJava Security Update
2009-07-15/a>Bojan ZdrnjaMake sure you update that Java
2009-07-01/a>Bojan ZdrnjaMobile phone trojans
2009-06-10/a>Swa FrantzenJava 6 update 14 released
2009-05-22/a>Mark HofmanPatching and Apple - Java issue
2009-05-04/a>Tom ListonAdobe Reader/Acrobat Critical Vulnerability
2009-04-07/a>Bojan ZdrnjaAdvanced JavaScript obfuscation (or why signature scanning is a failure)
2009-04-02/a>Bojan ZdrnjaJavaScript insertion and log deletion attack tools
2009-03-25/a>David GoldsmithJava Runtime Environment 6.0 Update 13 Released
2009-02-25/a>Andre LudwigAdobe Acrobat pdf 0-day exploit, No JavaScript needed!
2009-02-10/a>Swa FrantzenJava up to date ?
2008-07-14/a>Daniel WesemannObfuscated JavaScript Redux
2008-07-09/a>Johannes UllrichJava Update
2008-06-30/a>Marcus SachsMore SQL Injection with Fast Flux hosting
2008-05-20/a>Raul SilesList of malicious domains inserted through SQL injection
2008-05-20/a>Raul SilesJava 6 Update 6 has been released
2008-04-06/a>Daniel WesemannAdvanced obfuscated JavaScript analysis
2008-04-03/a>Bojan ZdrnjaMixed (VBScript and JavaScript) obfuscation

SUPPORT

2020-02-05/a>Brad DuncanFake browser update pages are "still a thing"
2015-06-27/a>Guy BruneauIs Windows XP still around in your Network a year after Support Ended?
2014-07-05/a>Guy BruneauJava Support ends for Windows XP
2012-12-06/a>Daniel WesemannFake tech support calls - revisited
2012-10-03/a>Kevin ShorttFake Support Calls Reported
2011-05-23/a>Mark HofmanMicrosoft Support Scam (again)
2010-07-06/a>Rob VandenBrinkBogus Support Organizations use Live Operators to Install Malware
2010-06-15/a>Manuel Humberto Santander PelaezMicrosoft Windows Help and Support Center vulnerability (CVE 2010-1885) exploit in the wild
2010-03-01/a>Mark HofmanMicrosoft will drop support for Vista (without any Service Packs) on April 13 and support for XP SP2 ends July 13. (i.e. no more security updates). If you are still running these, it it time to update.
2010-02-03/a>Rob VandenBrinkSupport for Legacy Browsers

ENDED

2015-06-27/a>Guy BruneauIs Windows XP still around in your Network a year after Support Ended?
2014-11-24/a>Richard PorterSomeone is using this? PoS: Compressor
2014-07-05/a>Guy BruneauJava Support ends for Windows XP
2010-03-10/a>Rob VandenBrinkMicrosoft re-release of KB973811 - attacks on Extended Protection for Authentication