eupolicy.social is one of the many independent Mastodon servers you can use to participate in the fediverse.
This Mastodon server is a friendly and respectful discussion space for people working in areas related to EU policy. When you request to create an account, please tell us something about you.

Server stats:

221
active users

#java

44 posts35 participants1 post today

SVG Smuggling - Image Embedded JavaScript Redirect Attacks

Threat actors are increasingly using Scalable Vector Graphics (SVG) files to deliver JavaScript-based redirect attacks. These SVGs contain embedded, obfuscated JavaScript that initiates browser redirects to attacker-controlled infrastructure. The campaign uses email spoofing and impersonation to deliver the SVGs, bypassing traditional file-based detection. The embedded code uses XOR encryption and reconstructs the redirect command at runtime. The attack targets B2B Service Providers, including those handling corporate financial and employee data. Mitigation strategies include implementing DMARC policies, blocking SVG attachments, and enhancing email security measures. The campaign demonstrates a shift towards smuggling techniques that avoid triggering traditional security alerts.

Pulse ID: 6878f6e6ce9d5286edc46238
Pulse Link: otx.alienvault.com/pulse/6878f
Pulse Author: AlienVault
Created: 2025-07-17 13:13:10

Be advised, this data is unverified and should be considered preliminary. Always do further verification.

LevelBlue Open Threat ExchangeLevelBlue - Open Threat ExchangeLearn about the latest cyber threats. Research, collaborate, and share threat intelligence in real time. Protect yourself and the community against today's emerging threats.

Davvero sono sconvolto sul bordello assurdo che tocca fare ogni anno per far girare su #Linux la specifica macchina virtuale #Java (#JAVAWS) che serve per far girare l'applicazione di turno, vedi #SOGEI e la sua MONDEZZA di software vergognosa

E' una cosa pazzesca, folle, incredibile 🤮

Ma cosa si fa ancora oggi, nel 2025, a distribuire software in questo modo?

E' INCIVILE

Stay updated with the latest in #Java development!

🔗 bit.ly/4lASsBq

The GA release of JobRunr 8.0; the second release candidate of Gradle 9.0; the fifth milestone release of Grails 7.0; point releases of Micronaut and JHipster Lite; and a CVE that affected Apache Tomcat.

Been comparing the differences between publishing a library on Maven Central to publishing on NPM.

Minutes for NPM vs the multiple verification steps needed for Maven.

Starting to see why supply chain attacks are _much_ easier with NPM 😬

🐑 Nearly 3 out of 4 Oracle Java users got audited in 3 years

「 Oracle introduced a paid subscription for Java in September 2018, and in January 2023, it decided to switch its pricing model to per employee rather than per user, creating a steep price hike for many users. In July 2023, Gartner recorded users experiencing price increases of between two and five times when they switched to the new licensing model 」

theregister.com/2025/07/15/ora

The Register · Nearly 3 out of 4 Oracle Java users say they've been audited in the past 3 yearsBy Lindsay Clark