Microsoft finds new BlackHole kit exploiting unpatched Java flaw
The BlackHole kit, a popular exploit set among hackers, has been updated to take advantage of a recently discovered Java hole that security researchers say many haven't updated yet.
Researchers at Microsoft reported last week that it had observed this vulnerability being exploited in the wild. The Java exploit allows attackers to bypass the Java Runtime Environment's sandbox platform to install malicious code remotely. The malicious Java applet is loaded from an obfuscated HTML file. The Java applet contains two Java class files - one Java class file triggers the vulnerability and the other one is a loader class used for loading.
The researchers claime samples like these are kind of unusual to see as they can be used to develop highly reliable exploits.