<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>VentureBeat &#187; zero-day attack</title>
	<atom:link href="http://venturebeat.com/tag/zero-day-attack/feed/" rel="self" type="application/rss+xml" />
	<link>http://venturebeat.com</link>
	<description>News About Tech, Money and Innovation</description>
	<lastBuildDate>Wed, 19 Jun 2013 04:22:00 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='venturebeat.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://0.gravatar.com/blavatar/c6d8c27ffa1c5a7f106f97e434437baf?s=96&#038;d=http%3A%2F%2Fs2.wp.com%2Fi%2Fbuttonw-com.png</url>
		<title>VentureBeat &#187; zero-day attack</title>
		<link>http://venturebeat.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://venturebeat.com/osd.xml" title="VentureBeat" />
	<atom:link rel='hub' href='http://venturebeat.com/?pushpress=hub'/>
<copyright>Copyright 2013, VentureBeat</copyright>		<item>
		<title>New Java zero-day attack offered for $5K on black market</title>
		<link>http://venturebeat.com/2013/01/16/java-zero-day/</link>
		<comments>http://venturebeat.com/2013/01/16/java-zero-day/#comments</comments>
		<pubDate>Wed, 16 Jan 2013 17:49:12 +0000</pubDate>
		<dc:creator>Meghan Kelly</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Department of Homeland Security]]></category>
		<category><![CDATA[exploit kits]]></category>
		<category><![CDATA[featured]]></category>
		<category><![CDATA[hacker forums]]></category>
		<category><![CDATA[Java]]></category>
		<category><![CDATA[zero-day attack]]></category>

		<guid isPermaLink="false">http://venturebeat.com/?p=605509</guid>
		<description><![CDATA[<p>Only one day after Oracle fixed a highly-publicized hole in Java, a new zero-day attack surfaced on online hacker forums. The zero-day owner says the exploit will be released to the highest&#160;bidder.</p>
<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=venturebeat.com&#038;blog=342986&#038;post=605509&#038;subd=venturebeat&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
				<content:encoded><![CDATA[<p><a href="http://venturebeat.files.wordpress.com/2013/01/spilled-coffee1.jpg" target="_blank"><img class="aligncenter size-full wp-image-605551" alt="Spilled Coffee" src="http://venturebeat.files.wordpress.com/2013/01/spilled-coffee1.jpg?w=708&#038;h=472" width="708" height="472" /></a></p>
<p>Get your exploit here, get your exploit here! Only days after Oracle <a href="http://venturebeat.com/2013/01/14/java-fix-issued/" target="_blank">patched a critical hole in Java</a>, a new vulnerability is being sold on the black market for $5,000 or the highest bidder.</p>
<p>A post popped up on a &#8220;hacker forum,&#8221; according to <a href="http://krebsonsecurity.com/2013/01/new-java-exploit-fetches-5000-per-buyer/" target="_blank" target="_blank">Krebs on Security</a>, the day after Oracle released its fix for Java. The post, created by one of the forum&#8217;s administrators, boasted about a zero-day attack in Java that is not included in any exploit packs &#8212; or bundled tools to aid a person in hacking someone&#8217;s systems that are often sold on these underground markets. The advertisement has since been removed from the website, perhaps because someone already paid up the money. It read, in part:</p>
<blockquote><p>&#8220;And you thought Java had epically failed when the last 0day came out. I lol’d. The best part is even-though java has failed once again and let users get compromised&#8230; guess what? I think you know what I’m going to say… there is yet another vulnerability in the latest version of java 7. I will not go into any details except with seriously interested buyers.&#8221;</p></blockquote>
<p>The hacker did mention, however, that the exploit came with Java source code and that it is a &#8220;weaponized version.&#8221; Bids higher than $5,000 are, of course, accepted.</p>
<p>The most recent hold Java fixed allowed hackers to enter a computer by using compromised websites as the entry-point into Java. Once in the system, they could steal any information, or hook up the computer to a botnet &#8212; or a string of infected computers that can be used to launch attacks against other computers.</p>
<p>The Department of Homeland Security issued a message prior to the fix, urging people to disable Java until it was patched up. After the patch came, however, <a href="http://venturebeat.com/2013/01/14/homeland-security-oracle-java/" target="_blank">DHS was unconvinced and warned people</a> that Java likely still had holes in it, and that people should keep Java disabled.</p>
<p><em><a href="http://www.shutterstock.com/pic-64627036/stock-photo-coffee-spilling-on-keyboard.html" target="_blank" target="_blank">Spilled coffee image</a> via <a href="http://www.shutterstock.com/" target="_blank" target="_blank">Shutterstock</a></em></p>
<br />Filed under: <a href='http://venturebeat.com/category/security/'>Security</a>  <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=venturebeat.com&#038;blog=342986&#038;post=605509&#038;subd=venturebeat&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://venturebeat.com/2013/01/16/java-zero-day/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	<enclosure url="http://venturebeat.files.wordpress.com/2013/01/spilled-coffee.jpg?w=160" /><source url="http://venturebeat.com/2013/01/16/java-zero-day/">New Java zero-day attack offered for $5K on black market</source>
		<media:content url="http://1.gravatar.com/avatar/a73335ff3a637d11555a46ba2b112ded?s=96&#38;d=http%3A%2F%2F1.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96&#38;r=G" medium="image">
			<media:title type="html">mkel31</media:title>
		</media:content>

		<media:content url="http://venturebeat.files.wordpress.com/2013/01/spilled-coffee1.jpg" medium="image">
			<media:title type="html">Spilled Coffee</media:title>
		</media:content>
	</item>
	</channel>
</rss>
