FireEye’s Malware Intelligence Lab is making the claim that there is a new zero day vulnerability in the wild. The vulnerability allows computers to be infected by visiting a specially crafted web page. The malware served in the current attacks contacts a C&C server in Singapore. It’s not clear when Oracle will release a patch for this vulnerability. Some security experts are prepping an unofficial patch for the program that should blunt this vulnerability, but uninstalling or disabling Java is probably not an acceptable solution.
Source: https://thehackernews.com/2012/08/fireeye-spotted-critical-0-day.html