New Java 7 bug prompts calls for web users to axe plug-in
Computer users ordered to uninstall or disable Java 7 until Oracle patches latest vulnerability.

PC and Mac users must disable Java in their web browsers following the discovery of another zero-day vulnerability that is reportedly being used by hackers to take over people's computers.
The stark warning was made by the US government's Computer Emergency Readiness Team (CERT) yesterday in an alert, which claims that all browsers using the Java 7 plug-in are at risk.
The group warned that the Java Deployment Tookit plug-in and Java Web Start can also be used by hackers to attack vulnerable systems.
Everyone running an updated version of Java is at risk right now, until Oracle releases a patch.
"Reports indicate this vulnerability is being actively exploited, and exploit code is publicly available," the US CERT advisory stated.
The vulnerability is understood to affect the Java Security Manager, allowing applets to grant themselves permission to execute arbitrary code.
"An attacker could use social engineering techniques to entice a user to visit a link to a website hosting a malicious Java applet," the alert added.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
"An attacker could also compromise a legitimate website and upload a malicious Java applet [known as a drive-by download' attack."
The organisation is urging computer users to disable or uninstall Java in their web browsers, and not to access Java applets from unknown sources, in a further advisory document.
It also claims users could mitigate the risk by using one browser for tasks that require Java.
"If you use a website that requires Java, choose and configure a browser to have Java enabled, and only access that resource with that browser," it stated.
"This helps minimise the exposure of Java to untrusted websites," it added.
Jaime Blasco, head of labs at security vendor AlienVault, said the zero-day vulnerability is similar to the ones that blighted web users last August.
"Everyone running an updated version of Java in Windows and probably in Mac OS X is at risk right now, until Oracle releases a patch," Blasco added.
-
Google faces 'first of its kind' class action for search ads overcharging in UK
News Google faces a "first of its kind" £5 billion lawsuit in the UK over accusations it has a monopoly in digital advertising that allows it to overcharge customers.
By Nicole Kobie
-
Neural interfaces promise to make all tech accessible – it’s not that simple
Column Better consideration of ethics and practical implementation are needed if disabled people are to benefit from neural interfaces
By John Loeppky
-
Organizations shift away from Oracle Java as pricing changes bite
News A survey from Azul Systems finds that, along with cost, customers cite a preference for open source and the threat of a Java usage audit
By Emma Woollacott
-
Why Java 17 growth is ‘exploding’
News Java 17 is now the most popular LTS version, according to application data from New Relic, but what's driving this growth?
By Steve Ranger
-
SuiteWorld 2023: NetSuite's day-two announcements
Live Blog Keep up-to-date with all the day-two announcements from NetSuite SuiteWorld 2023
By Rory Bathgate
-
Can Oracle really be Linux's knight in shining armor?
Opinion The self-proclaimed champion of open source freedom would like you to forget about its history
By Richard Speed
-
Zero Trust myths: Fact or fiction?
Whitepaper What the myths get right and wrong about Zero Trust
By ITPro
-
ZTNA vs on-premises VPN
Whitepaper How ZTNA wins the network security game
By ITPro
-
A roadmap to Zero Trust with Cloudflare and CrowdStrike
Whitepaper Achieve end-to-end protection across endpoints, networks, and applications
By ITPro
-
Oracle’s Java subscription changes spark concerns over cost hikes for smaller businesses
News Smaller businesses could incur significant cost hikes as high as 1,400% with most new customers expected to pay at least double
By Ross Kelly