JAVA Security – Increased native layer attacks reported

Trend Micro updates further developments for Java security attacks. Oracle is improving Java security over time and this documents new sophistication in current approaches:

QUOTE: Recently, security researchers disclosed two Java native layer exploits (CVE-2013-2465 and CVE-2013-2471). This caused us too look into native layer exploits more closely, as they have been becoming more common this year. At this year’s Pwn2Own competition at CanSecWest, Joshua Drake showed CVE-2013-1491, which was exploitable on Java 7 running on Windows 8. CVE-2013-1493 has become a popular vulnerability to target in exploits kits such as Blackhole.

