Spring4Shell: Zero-Day vulnerability CVE-2022-22965 in Spring Framework

A Zero-day Remote Code Execution Vulnerability with critical severity has been identified as CVE-2022-22965 aka Spring4Shell or SpringShell…

Quick Heal thwarts attempts of a JAVA jRAT phishing campaign targeting an international embassy in India

Earlier we had blogged about how JAVA based jRAT malware were evolved in the recent times. At Quick Heal Security Labs, we are…

Web security basics: Watering hole attacks VS phishing attacks

Computer users who are well versed with security threats know why and how clever phishing pages must be…

Security news and updates from the last week

New York Times website breached by Chinese hackers The New York Times recently discovered that their computer systems…

As another Java flaw is discovered, is it time to disable Java completely?

After a massive Java 0-day vulnerability surfaced in August 2012, Oracle released an out-of-cycle update to combat the…

Oracle releases Java 0-day vulnerability security patch

Yesterday we highlighted the Java 7 0-day vulnerability (CVE-2012-4681) that necessitated immediate attention by disabling the Java plug-in….

How to avoid the latest Java 0-day vulnerability

Java application software has always been extremely vulnerable due to its cross-platform nature. Exploits developed for this software…