Oracle has released Java 27 and OpenJDK 27, introducing JEP 527 hybrid key exchange for TLS 1.3 to protect encrypted traffic against “harvest now, decrypt later” attacks enabled by future quantum computing. The release also makes the Garbage-First (G1) collector the default across all deployment environments, replacing the Serial collector in constrained deployments, and enables compact object headers by default, reducing headers from 96 to 64 bits to improve memory efficiency and deployment density.
Java 27 further advances the Vector API, structured concurrency, pattern matching, primitive-type support, and lazy constants through preview or incubator features. Oracle also issued an early-access JDK 28 build with initial Project Valhalla components, updated Helidon and JavaFX, and added the FIPS 140-3-certified Oracle Jipher 20 cryptographic module to its Java Verified Portfolio; it said these capabilities will progressively reach long-term-support releases.

Track how attackers are adapting to this technology.
3 events from the most recent confirmed update back to the earliest known activity.
Java 27 introduced JEP 527 support for hybrid key exchange in TLS 1.3, intended to mitigate the risk of adversaries harvesting encrypted data for future quantum-enabled decryption.
Oracle announced general availability of OpenJDK/Java 27 and Oracle JDK 27. The release makes the G1 garbage collector the default in all environments, enables compact object headers by default, and adds previews or incubators including structured concurrency, lazy constants, and the Vector API.
Oracle released an early-access JDK 28 build containing initial Project Valhalla components. It also updated Helidon and JavaFX, and added the FIPS 140-3-certified Oracle Jipher 20 cryptographic module to its Java Verified Portfolio.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.