73
Hackers exploit BleedingPipe RCE to target Minecraft servers, players
(www.bleepingcomputer.com)
I wish newer Java versions would disable object streams by default. They're such a horrible feature and should never be used. Especially over the network.
Bear in mind these are very old versions of minecraft. Mods on these versions are still somewhat popular in a dedicated group, but these won't be a problem for a typical minecraft player.
That said, EnderIO in 1.12 is probably still fairly popular. It would be a good idea for server admins and players who use that mod in particular to look into this.
This is a most excellent place for technology news and articles.