#java

63 posts · Last used 3d

Back to Timeline
OffSequence @offseq@infosec.exchange · Aug 03, 2026
BC-JAVA users: CVE-2026-59650 (CRITICAL, CVSS 9.3) exposes MTI/A0 Diffie-Hellman via improper input validation. Affects <1.85, 2.73.0 – 2.73.11. No patch yet — avoid affected versions & monitor for updates. https://radar.offseq.com/threat/cve-2026-59650-cwe-20-improper-input-validation-in-legion-of-the-bouncy-castle-inc-bc-java-bfb9720e803b614a #OffSeq #Vulnerability #Java #Cryptography
0
0
0
jbz @jbz@indieweb.social · Jul 30, 2026
👉 OpenJDK Interim Policy on Generative AI 「 Most generative AI tools, however, are trained on copyrighted and licensed content, and their output can include content that infringes those copyrights and licenses, so contributing such content would violate the OCA. Whether a user of a generative AI tool has IP rights in content generated by the tool is the subject of active litigation 」 https://openjdk.org/legal/ai #java #ai #opensource #openjdk
2
0
5
Cloud 🤖 @cloud@infosec.exchange · Jul 28, 2026
🤖 FastJson zero-day actively exploited in the wild targeting US firms. The Java deserialization bug (no CVE yet) enables unauthenticated RCE. No patch available; disable auto-type resolution as mitigation. 🔗 https://www.bleepingcomputer.com/news/security/hackers-target-us-firms-in-fastjson-rce-zero-day-attacks/ #CyberSec #RCE #0day #Java #InfoSec
0
0
0
jbz @jbz@indieweb.social · Jul 27, 2026
⚒️ Minecraft Java Edition raises recommended memory to 16GB ahead of Vulkan transition // VideoCardz 「 Mojang has updated the system requirements for Minecraft: Java Edition, raising recommended system memory from 4GB to 16GB. The minimum is now 8GB with a dedicated GPU or 12GB with integrated graphics. The recommended GPU tier starts with the GeForce RTX 2060, Radeon RX 5600 XT or Intel Arc A580 」 https://videocardz.com/newz/minecraft-java-edition-raises-recommended-memory-to-16gb-ahead-of-vulkan-transition #minecraft #java #vulkan
1
1
0
Daily CyberSecurity @DailyCyberSecurity@infosec.exchange · Jul 27, 2026
Apache Fory vulnerabilities hit Java, C++, and Rust deserialization, including CVE-2026-64606. Upgrade to Fory 1.4.0 to fix all four flaws. #ApacheFory #Deserialization #Java #Rust #Cpp #Vulnerability #OpenSource #Cybersecurity https://securityonline.info/apache-fory-vulnerabilities/?utm_source=mastodon&utm_medium=jetpack_social
0
0
0
Cloud 🤖 @cloud@infosec.exchange · Jul 26, 2026
🤖 CVE-2026-16723 (CVSS 9.0): Critical RCE in Alibaba Fastjson 1.x JSON library for Java. Actively exploited in attacks targeting Spring Boot apps — no patch available. A malicious JSON request can execute code without authentication. 🔗 https://thehackernews.com/2026/07/fastjson-1x-rce-vulnerability-targeted.html #CVE #RCE #CyberSec #Java
0
0
0
Cloud 🤖 @cloud@infosec.exchange · Jul 25, 2026
🤖 CVE-2026-16723 (CVSS 9.0): Critical RCE in Alibaba's Fastjson 1.x actively exploited — no patch available. Malicious JSON requests execute code on Spring Boot apps without authentication. Reported by ThreatBook & Imperva. 🔗 https://thehackernews.com/2026/07/fastjson-1x-rce-vulnerability-targeted.html #CVE #RCE #CyberSec #Java
0
0
0
dev2next @dev2next@mastodon.social · Jul 24, 2026
Asynchronous programming is becoming increasingly important in modern Java ☕ In this hands-on #dev2next workshop, Venkat Subramaniam explores callbacks, CompletableFuture, and virtual threads, helping you understand the tradeoffs of each and when to use them. Expect practical experience, not just theory. 🔗 Info + tickets: https://www.dev2next.com/schedule #Java #AsynchronousProgramming #VirtualThreads
0
0
1
sanitation @sanitation@lemmy.today · Jul 23, 2026

JEP 540: Simple JSON API (Incubator)

0
0
0
Krzysztof Nizioł :symfony: @kniziol@phpc.social · Jul 19, 2026
I recently finished watching https://www.youtube.com/watch?v=ZqGSg4b_cZA I’m thoroughly impressed by the history of #Java and its evolution over the years. It’s a significant and important piece of history that every #developer should be familiar with.
1
1
1
Daily CyberSecurity @DailyCyberSecurity@infosec.exchange · Jul 22, 2026
A fastjson RCE hits versions 1.2.68 to 1.2.83 under stock defaults. Details and public PoC code are out, so enable SafeMode or move to fastjson2. #fastjson #RCE #Java #SpringBoot #Vulnerability #PoC #Cybersecurity http://securityonline.info/fastjson-rce-1-2-83/?utm_source=mastodon&utm_medium=jetpack_social
0
0
0
Markus Eisele @myfear@mastodon.online · Jul 22, 2026
Vault's TOTP API can validate a six-digit code. That is not yet a complete MFA flow. This Quarkus tutorial adds the missing boundaries: authenticated subject, stored enrollment mapping, strict input validation, a two-minute step-up JWT, normal RBAC, and a replay test against a patched Vault runtime. https://www.the-main-thread.com/p/quarkus-vault-totp-step-up-auth #Java #Quarkus #Vault #TOTP #APISecurity
0
0
0
Jobs for Developers @jobsfordevelopers@mastodon.world · Jul 20, 2026
0
0
12