Malvertizing Continued
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2010-0840 | Unspecified Remote Vulnerability in Oracle Java Runtime Environment (JRE) CVE-2010-0840 is an unspecified vulnerability in the Java Runtime Environment (JRE) component of Oracle Java SE that allows remote attackers to affect confidentiality, integrity, and availability through vectors Oracle did not publicly detail. Because the advisory withheld technical specifics, the exact trigger is undocumented, but the flaw is remotely exploitable, and the era's threat reporting (2011 exploit-kit and Java malware headlines) is consistent with drive-by exploitation of Java clients. A successful attacker gains the ability to compromise the confidentiality, integrity, or availability of the affected system, and Java flaws of this period were commonly leveraged to install malware such as bots. Any organization or end user running the affected JRE releases — whether the browser Java plug-in on desktops or server-side Java — is exposed, making the affected population extremely broad. The flaw is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-05-25), EPSS assigns it a 96.3% probability of exploitation in the next 30 days, and no public proof-of-concept is known. Do: Apply the Oracle Java SE updates specified by the vendor as required by CISA's KEV listing, and remove or disable obsolete or unsupported JRE versions, especially the browser Java plug-in where it is no longer needed. Prioritize internet-exposed and end-user systems, check for lingering legacy Java applets in use, and note that remediation is mandatory for federal agencies under the KEV program. | — | 96% | KEV |
| masshundreds of millions of JRE installations across desktops and servers |
Full article422 words · extracted from securelist.com · click to collapse
Over the past couple months, some advertising networks have been distributing ads that redirect browsers to sites hosting exploits.

Spotify’s advertising network was most recently outed (note that it is the third party banner ads rotating through the client’s ad frames). Most of the redirections we have been been monitoring have sent users to a variety of servers in the .cc TLD. We have been working with providers to ensure the ads aren’t on their networks, but the groups have been active in rotating malvertizing banners through multiple networks.
The hits on these ads, for the most part, have redirected browsers to Java, Adobe and Microsoft HCP related exploits. We are detecting this exploit content with a variety of names: Exploit.Java.CVE-2010-0840.a-f, Trojan-Downloader.Java.Openconnection.dt, Trojan.Win32.FakeWarn.d, Exploit.HTML.CVE-2010-1885.aj, Exploit.Script.Generic, Exploit.JS.Pdfka.cwm, Exploit.JS.Pdfka.dhm and more. All are a part of the Blackhole Exploit kit. At some point, our broader solutions kick in and just block connections with the web pages altogether.
Most of the redirects that we saw early on were from unusual adult interest sites, but the distributors have become more aggressive and managed to rotate their ads through major IM, webtailers’ regional sites and webmail provider sites too. At least that group of ads seem to have been dealt with properly. However, unpatched and unprotected systems that are being successfully exploited and download a variety of malware from these sites, including FakeAv, the more serious TDSS rootkit, Papras and Zbot banking credential stealers, among others.

The Blackhole exploit kit may not have the largest install base online, but because its hosters are abusing some of the bigger advertising networks to co-ordinate redirection to their exploit pages on these .cc servers. Accordingly, detections for their Java, pdf and hcp exploits are very high. Every eight hours during higher activity, our KSN network counts the prevention of a very high volume of attacks from .cc domains.
Latest Webinars
Reports
Kaspersky researchers have discovered new Mirage Kitten attacks using previously undocumented malware families: NodeRabbit in Node.js and PollCat in JavaScript.
Our experts discovered a new CoolClient backdoor variant with a kernel-mode rootkit driver that hides malicious processes, files, and network connections from security tools and threat analysts.
Kaspersky experts break down a new Armored Likho campaign that poses as a fundraising efforts and delivers a new Still Toolkit aimed at stealing Telegram data and eavesdropping on victims.
Kaspersky researchers reveal previously undocumented malware attributed to Mirage Kitten (UNC1549, Smoke Sandstorm, Nimbus Manticore): NightLedger backdoor, ArcBridge, and BridgeHead tunneling tools.
Text extracted automatically; images, tables and formatting may be missing. Original: https://securelist.com/malvertizing-continued-spotifys-ad-networks-outed/29782/