Fox IT, a Dutch security firm, recently revealed that hundreds of thousands of Yahoo.com visitors may have been infected with malware over the past few days from Yahoo's ad servers.
According to researchers, visitors were redirected through malicious ads to specially crafted websites, which exploited vulnerabilities in Javato install malware.
Yahoo issued two statements regarding the attacks:
“At Yahoo, we take user security and privacy seriously. We recently identified an ad that was designed to distribute malware to some of our users. The ad was immediately removed, and we continue to monitor and block any ads used for similar activity,” a Yahoo spokesperson said last Saturday.
On Sunday, Yahoo released more information about the attack, saying that the ads were primarily targeting European users, and that Mac computer users and mobile phone users were not affected by the attack.
Later, Yahoo issued a new statement noting that the malicious ads remained posted from December 31st to January 3rd.
At present, Yahoo has not disclosed further details about the number of users affected by the attack, how the malware entered its servers, and what measures victims of the attack should take.

