Java deserialization vulnerabilities were discovered and disclosed in January 2015 by Gabriel Lawrence and Chris Frohoff. These serious vulnerabilities arise from the way in which Java deserializes serialized objects (see the presentation of Gabriel Lawrence and Chris Frohoff). The underlying flaw in Java has not been fixed by Oracle, most likely due to the impact a fix would have on various frameworks and libraries. However, many workarounds can be applied to prevent exploitation. What's new? If you are hunting for AppDefects try out this cool Java Deserialization Scanner.