CVE detail
CVE-2021-44228
Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0 (along with 2.12.2, 2.12.3, and 2.3.1), this functionality has been completely removed. Note that this vulnerability is specific to log4j-core and does not affect log4net, log4cxx, or other Apache Logging Services projects.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 30.0 · diversity 20.0 · KEV 25.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 2
- within the 30d window
- Peak daily
- 1
- highest bucket
Evidence
Source links by recency
179 source links · newest first
QSC Product and Tech Patch Management VMDR Vulnerabilities and Threat Research Patch Tuesday Threat Thursday Top Posts CVE-2021-3156: Heap-Based Buffer Overflow in Sudo (Baron Samedit) Apache Log4j Zero Day Threat: CVE-2021-44228 Detection and Response Remote Unauthenticated Code Execution Vulnerability in OpenSSH Server (regreSSHion) PwnKit: Local P
vendorblog.qualys.comJul 14, 2026, 6:00 PM- When AI-Accelerated Discovery Outruns Patching, Exploitability Proof Decides What Gets Fixed FirstQualys
QSC Product and Tech Patch Management VMDR Vulnerabilities and Threat Research Patch Tuesday Threat Thursday Top Posts CVE-2021-3156: Heap-Based Buffer Overflow in Sudo (Baron Samedit) Apache Log4j Zero Day Threat: CVE-2021-44228 Detection and Response Remote Unauthenticated Code Execution Vulnerability in OpenSSH Server (regreSSHion) PwnKit: Local P
vendorblog.qualys.comJul 8, 2026, 10:15 PM ne Exposure Management Platform showed: 1,865 organizations still exposed to the 2024 vulnerability in Fortinet FortiOS CVE-2024-21762 3,569 organizations still exposed to the 2021 Log4Shell vulnerability CVE-2021-44228 1,430 organizations still exposed to the 2017 WannaCry vulnerability CVE-2017-0144 Moreover, based on aggregated data from more than 1
vendorwww.tenable.comJun 24, 2026, 1:00 PMFor years, I watched organizations treat vulnerability data like a compliance chore. It was something to scan, sort and patch against deadlines. Yet buried in those reports is a treasure map of sorts, where an attacker is likely to strike first. In my previous red team and incident responder roles, minus a credential leak or […]
newswww.csoonline.comNov 19, 2025, 2:06 PM- Kernel-level container insights: Utilizing eBPF with Cilium, Tetragon, and SBOMs for securityHelp Net Security
As applications become more distributed, traditional monitoring and security tools are failing to keep pace. This article explores how eBPF, when utilized by the graduated CNCF Cilium and its sub-project Tetragon, combined with Software Bills of Materials (SBOMs), can provide insights and a security feedback loop for modern systems. We’ll create a container image and its SBOM. We’ll then launch it, simulate a breach, and see how our eBPF-based setup with Tetragon captures the issue. … More →
newswww.helpnetsecurity.comJun 18, 2025, 6:00 AM - Ransomware Group Claims Attacks on UK RetailersSecurityWeek
The DragonForce ransomware group has claimed responsibility for the recent cyberattacks on UK retailers Co-op, Harrods, and M&S.
newswww.securityweek.comMay 5, 2025, 11:00 AM - A new era of cyber threats is approaching for the energy sectorHelp Net Security
Cyber threats targeting the energy sector come in many forms, including state-sponsored actors seeking to disrupt national infrastructure, cybercriminals motivated by profit, and insiders intentionally causing damage. The consequences of a successful attack can be severe, potentially disrupting energy supplies and causing economic and social damage, according to Darktrace’s research focused on the UK and US energy sector over a three-year period (November 2021 – Dec 2024). “Our three-year analysis reveals critical vulnerabilities in UK … More →
newswww.helpnetsecurity.comApr 24, 2025, 5:00 AM Black Basta, one of the most successful ransomware groups over the past several years, had a major leak of its internal communications recently. The logs provide a glimpse into the playbook of a high-profile ransomware group and its preferred methods for gaining initial access to networks, as analysis from security researchers shows. “Key attack vectors […]
newswww.csoonline.comMar 3, 2025, 8:00 AM- What 2024 taught us about security vulnerabiltiesHelp Net Security
From zero-day exploits to weaknesses in widely used software and hardware, the vulnerabilities uncovered last year underscore threat actors’ tactics and the critical gaps in organizational defenses. This roundup showcases the standout findings from 2024’s cybersecurity reports, highlighting critical risks and emerging threats that demand attention. Whether you’re a security leader, IT professional, or cybersecurity-conscious, these insights will help frame the priorities and strategies needed to stay resilient. Zero-days dominate top frequently exploited vulnerabilities The … More →
newswww.helpnetsecurity.comJan 14, 2025, 4:00 AM - Zero-days dominate top frequently exploited vulnerabilitiesHelp Net Security
A joint report by leading cybersecurity agencies from the U.S., UK, Canada, Australia, and New Zealand has identified the most commonly exploited vulnerabilities of 2023. Zero-day vulnerabilities on the rise The advisory highlights that malicious cyber actors increasingly targeted zero-day vulnerabilities, posing significant threats to enterprise networks. Notably, the exploitation of these zero-days rose compared to 2022. Unlike previous years, where older, unpatched vulnerabilities dominated the list, 2023 saw a spike in zero-day exploits, reflecting … More →
newswww.helpnetsecurity.comNov 14, 2024, 5:00 AM Most of the top frequently exploited vulnerabilities in 2023 were initially exploited as zero-days, according to data from government agencies.
newswww.securityweek.comNov 13, 2024, 3:46 PMMore than two years after the Log4j crisis, organizations are still being hit by crypto-currency miners and backdoor scripts.
newswww.securityweek.comAug 22, 2024, 2:44 PMMultiple cybersecurity agencies released a joint advisory warning about a China-linked group APT40 ‘s capability to rapidly exploit disclosed security flaws. Cybersecurity agencies from Australia, Canada, Germany, Japan, New Zealand, South Korea, the U.K., and the U.S. released a joint advisory warning about the China-linked group APT40 (aka TEMP.Periscope, TEMP.Jumper, Bronze Mohawk, Gingham Typhoon, ISLANDDREAMS, Kryptonite Panda, […]
newssecurityaffairs.comJul 10, 2024, 1:17 PMSeven nations are backing Australia in calling out a China-linked hacking group for compromising government networks.
newswww.securityweek.comJul 9, 2024, 10:43 AMThe cybercrime group ExCobalt targeted Russian organizations in multiple sectors with a previously unknown backdoor known as GoRed. Positive Technologies researchers reported that a cybercrime gang called ExCobalt targeted Russian organizations in multiple sectors with a previously unknown Golang-based backdoor known as GoRed. Members of the ExCobalt group have been active since at least 2016, […]
newssecurityaffairs.comJun 24, 2024, 7:36 AMThe TellYouThePass ransomware gang started exploiting a recent code execution flaw in PHP days after public disclosure.
newswww.securityweek.comJun 12, 2024, 8:50 AM- Why Hackers Love LogsSecurityWeek
Log tampering is an almost inevitable part of a compromise. Why and how do cybercriminals target logs, and what can be done to protect them?
newswww.securityweek.comJun 6, 2024, 2:13 PM - Find out which cyber threats you should be concerned aboutHelp Net Security
This article includes excerpts from various reports that offer statistics and insights into the current cyber threat landscape. Human error still perceived as the Achilles’ heel of cybersecurity Proofpoint | 2024 Voice of the CISO | May 2024 Human error continues to be perceived as the Achilles’ heel of cybersecurity, with 74% of CISOs identifying it as the most significant vulnerability. In a year of growing insider threats and people-driven data loss, more CISOs than … More →
newswww.helpnetsecurity.comJun 5, 2024, 3:00 AM - Log4Shell shows no sign of fading, spotted in 30% of CVE exploitsHelp Net Security
Organizations continue to run insecure protocols across their wide access networks (WAN), making it easier for cybercriminals to move across networks, according to a Cato Networks survey. Enterprises are too trusting within their networks The Cato CTRL SASE Threat Report Q1 2024 provides insight into the security threats and their identifying network characteristics for all aggregate traffic—regardless of whether they emanate from or are destined for the internet or the WAN—and for all endpoints across … More →
newswww.helpnetsecurity.comMay 14, 2024, 3:00 AM - Cybercrime stats you can’t ignoreHelp Net Security
In this article, you will find excerpts from various reports that offer stats and insights about the current cybercrime landscape. Behavioral patterns of ransomware groups are changing GuidePoint Security | GRIT Q1 2024 Ransomware Report | April 2024 Q1 2024 resulted in a nearly 20% increase in reported victims over Q1 2023, despite the disruption of LockBit and the disbandment of Alphv, two of the largest and most prolific ransomware groups. The number of active … More →
newswww.helpnetsecurity.comMay 7, 2024, 4:30 AM Attackers continue to aggressively target small and mid-size businesses using high-profile vulnerabilities dating back a decade or more, network telemetry shows. Between January and March this year, five high-severity flaws stood out above all others in terms of their frequency in intrusion prevention system (IPS) data from SonicWall’s predominantly SMB customer base. At the top […]
newswww.csoonline.comApr 30, 2024, 6:00 AM- Cybersecurity crisis in schoolsHelp Net Security
Primary school systems handle sensitive data concerning minors, while higher education institutions must safeguard intellectual property data, making them prime targets for cyberattacks, according to Trustwave. These attacks not only threaten the safety and security of teachers and administrators but also put the privacy of students, staff, and other associated entities at risk. With millions of students now learning through technology in hybrid, remote, or in-class settings, device security is no longer optional. It’s crucial … More →
newswww.helpnetsecurity.comFeb 26, 2024, 4:00 AM - FritzFrog botnet exploits Log4Shell, PwnKit vulnerabilitiesHelp Net Security
The FritzFrog cryptomining botnet has new potential for growth: a recently analyzed variant of the bot is exploiting the Log4Shell (CVE-2021-44228) and PwnKit (CVE-2021-4034) vulnerabilities for lateral movement and privilege escalation. The FritzFrog botnet The FritzFrog botnet, initially identified in August 2020, is a peer-to-peer (rather than centrally-controlled) botnet powered by malware written in Golang. It targets SSH servers by brute-forcing login credentials, and has managed to compromise thousands of them worldwide. “Each compromised host … More →
newswww.helpnetsecurity.comFeb 1, 2024, 3:21 PM - Week in review: Apache Struts vulnerability exploit attempt, EOL Sophos firewalls get hotfixHelp Net Security
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: SCS 9001 2.0 reveals enhanced controls for global supply chains In this Help Net Security interview, Mike Regan, VP of Business Performance at TIA, discusses SCS 9001 Release 2.0, a certifiable standard crafted to assist organizations in operationalizing the NIST and other government guidelines and frameworks. Balancing AI advantages and risks in cybersecurity strategies In this Help Net Security interview, … More →
newswww.helpnetsecurity.comDec 17, 2023, 9:00 AM Despite receiving a patch two years ago, the Log4Shell vulnerability remains a popular attack vector even for sophisticated threat actors. An example is a recently documented attack campaign against companies from several industries by the North Korean state-run Lazarus APT group. The Lazarus attackers exploited Log4Shell (CVE-2021-44228) in publicly facing and unpatched VMware Horizon servers […]
newswww.csoonline.comDec 14, 2023, 3:04 PMNorth Korea-linked APT group Lazarus was spotted exploiting Log4j vulnerabilities to deploy previously undocumented remote access trojans. The North Korea-linked APT group Lazarus is behind a new hacking campaign that exploits Log4j vulnerabilities to deploy previously undocumented remote access trojans (RATs). Cisco Talos researchers tracked the campaign as Operation Blacksmith, the nation-state actors are employing at least […]
newssecurityaffairs.comDec 12, 2023, 3:31 PM- Lazarus exploit Log4Shell vulnerability to deliver novel RAT malwareHelp Net Security
North Korea-backed group Lazarus has been spotted exploiting the Log4Shell vulnerability (CVE-2021-44228) and novel malware written in DLang (i.e., the memory-safe D programming language). “This campaign consists of continued opportunistic targeting of enterprises globally that publicly host and expose their vulnerable infrastructure to n-day vulnerability exploitation such as CVE-2021-44228. We have observed Lazarus target manufacturing, agricultural and physical security companies,” Cisco Talos researchers shared. Log4Shell still opens doors Log4Shell is a critical remote code execution … More →
newswww.helpnetsecurity.comDec 12, 2023, 2:33 PM North Korean hackers have used Dlang-based malware in attacks against manufacturing, agriculture, and physical security organizations.
newswww.securityweek.comDec 11, 2023, 2:19 PM- Insight – Holiday Threat Awareness 2023Horizon3.ai
Amidst the hustle and bustle of holiday preparations and last-minute shopping, cybercriminals often take advantage of the increased online activity and spending complacency of individuals and businesses…
exploithorizon3.aiDec 1, 2023, 1:00 PM New CISA guidance details cyber threats and risks to healthcare and public health organizations and recommends mitigations.
newswww.securityweek.comNov 20, 2023, 2:52 PM- Nation-state actors exploit Fortinet FortiOS SSL-VPN and Zoho ManageEngine ServiceDesk Plus, CISA warnsSecurity Affairs
U.S. CISA warned that nation-state actors are exploiting flaws in Fortinet FortiOS SSL-VPN and Zoho ManageEngine ServiceDesk Plus. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned that nation-state actors are exploiting security vulnerabilities in Fortinet FortiOS SSL-VPN and Zoho ManageEngine ServiceDesk Plus. The US agency has detected the presence of indicators of compromise (IOCs) […]
newssecurityaffairs.comSep 8, 2023, 12:06 PM - Old vulnerabilities are still a big problemHelp Net Security
A recently flagged phishing campaign aimed at delivering the Agent Tesla RAT to unsuspecting users takes advantage of old vulnerabilities in Microsoft Office that allow remote code execution. “Despite fixes for CVE-2017-11882/CVE-2018-0802 being released by Microsoft in November, 2017 and January, 2018, this vulnerability remains popular amongst threat actors, suggesting there are still unpatched devices in the wild, even after over five years,” says Fortinet researcher Xiaopeng Zhang. “We are observing and mitigating 3000 attacks … More →
newswww.helpnetsecurity.comSep 6, 2023, 1:51 PM - Healthcare organizations in the crosshairs of cyberattackersHelp Net Security
In an era where cyber threats continue to evolve, healthcare organizations are increasingly targeted by malicious actors employing multiple attack vectors, according to Trustwave. In its new research, Trustwave SpiderLabs has documented the attack flow utilized by threat groups, shedding light on their tactics, techniques, and procedures. From phishing emails to exploiting known vulnerabilities and compromising third-party vendors, these persistent threats pose significant risks to the healthcare industry. Healthcare industry bears heavier financial burden While … More →
newswww.helpnetsecurity.comJul 18, 2023, 3:30 AM - 3rd July – Threat Intelligence ReportCheck Point Research
For the latest discoveries in cyber research for the week of 3rd July, please download our Threat_Intelligence Bulletin TOP ATTACKS AND BREACHES The LockBit ransomware group has recently claimed responsibility for hacking the Taiwan Semiconductor Manufacturing Company (TSMC), the largest contract chip manufacturer globally, serving tech giants such as Apple and Qualcomm. TSMC denied it […]
vendorresearch.checkpoint.comJul 3, 2023, 12:04 PM The number of fileless or memory-based attacks that exploit existing software, applications, and protocols have surged 1,400% in the last year. That’s according to Aqua Security’s 2023 Cloud Native Threat Report, which summarizes research and observations of threat actors’ changing tactics, techniques, and procedures (TTPs), along with outlining strategies for protecting cloud environments. Based on […]
newswww.csoonline.comJun 27, 2023, 8:00 AM- CISA adds TP-Link, Apache, and Oracle bugs to its Known Exploited Vulnerabilities catalogSecurity Affairs
US Cybersecurity and Infrastructure Security Agency (CISA) added TP-Link, Apache, and Oracle vulnerabilities to its Known Exploited Vulnerabilities catalog. U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added the following three new issues to its Known Exploited Vulnerabilities Catalog: CVE-2023-1389 (CVSS score: 8.8) – TP-Link Archer AX-21 Command Injection Vulnerability. The CVE-2023-1389 flaw is an unauthenticated […]
newssecurityaffairs.comMay 2, 2023, 7:11 AM - 17th April – Threat Intelligence ReportCheck Point Research
For the latest discoveries in cyber research for the week of 17th April, please download our Threat_Intelligence Bulletin TOP ATTACKS AND BREACHES Two major automotive manufacturers Hyundai and Toyota have disclosed significant data breaches. Hyundai’s Italian and French car owners were affected, along with individuals who booked a test drive. The leaked data consists of […]
vendorresearch.checkpoint.comApr 17, 2023, 7:51 AM The Log4Shell critical vulnerability that impacted millions of enterprise applications remains a common cause for security breaches a year after it received patches and widespread attention and is expected to remain a popular target for some time to come. Its long-lasting impact highlights the major risks posed by flaws in transitive software dependencies and the […]
newswww.csoonline.comDec 28, 2022, 10:00 AMAlmost exactly a year after the Log4Shell security crisis sent defenders scrambling to reduce attack surfaces, new data shows that remediation has been a long, slow, painful slog for most organizations around the world.
newswww.securityweek.comNov 30, 2022, 4:30 PM- Holiday Season Threat AwarenessHorizon3.ai
As we approach the holiday season, it is important that our customers remain stay and continue a regular cadence of autonomous pentests. Although it’s the time of year for holiday cheer, we’ve seen cyber threat actors (CTAs) take advantage of lackadaisical company manning and low staff.
exploithorizon3.aiNov 23, 2022, 3:33 PM - 21st November– Threat Intelligence ReportCheck Point Research
For the latest discoveries in cyber research for the week of 21st November, please download our Threat Intelligence Bulletin. Top Attacks and Breaches US CISA has discovered nation-state threat activity affecting an American federal government entity. The attackers, who CISA estimates to be Iran-sponsored, exploited the 2021 ‘Log4Shell’ vulnerability in an unpatched server to gain […]
vendorresearch.checkpoint.comNov 21, 2022, 4:19 PM - Iran-linked threat actors compromise US Federal NetworkSecurity Affairs
Iran-linked threat actors compromised a Federal Civilian Executive Branch organization using a Log4Shell exploit and installed a cryptomining malware. According to a joint advisory published by the FBI and CISA, an Iran-linked APT group compromised a Federal Civilian Executive Branch (FCEB) organization using an exploit for the Log4Shell flaw (CVE-2021-44228) and deployed a cryptomining malware. Log4Shell impacts […]
newssecurityaffairs.comNov 17, 2022, 7:58 AM On Tuesday, October 25 a new OpenSSL hot-fix release was announced which will patch a critical vulnerability that exists within the v3.0.X branch. OpenSSL 3.0.7 will be released on Tuesday, November 1 and in tandem the details of the vulnerability and its associated CVE will be made public. OpenSSL is an open source project that […]
exploithorizon3.aiOct 26, 2022, 6:52 PM- 24th October – Threat Intelligence ReportCheck Point Research
For the latest discoveries in cyber research for the week of 24th October, please download our Threat Intelligence Bulletin. Top Attacks and Breaches Iranian Hacktivist group ‘Black Reward’ claim to have breached Iran’s government and exfiltrated data related to the country’s nuclear program. After the group’s demands to release political prisoners were not met, the group […]
vendorresearch.checkpoint.comOct 24, 2022, 9:33 AM On October 17, 2022, the Wordfence Threat Intelligence team began monitoring for activity targeting CVE-2022-42889, or “Text4Shell” on our network of 4 million websites. We started seeing activity targeting this vulnerability on October 18, 2022. Text4Shell is a vulnerability in the Apache Commons Text library versions 1.5 through 1.9 that can be used to achieve … Read More
vendorwww.wordfence.comOct 20, 2022, 6:40 PMResearcher discovered a remote code execution vulnerability in the open-source Apache Commons Text library. GitHub’s threat analyst Alvaro Munoz discovered a remote code execution vulnerability, tracked as CVE-2022-42889, in the open-source Apache Commons Text library. Apache Commons Text is a library focused on algorithms working on strings. The vulnerability, dubbed “Text4Shell,” is an unsafe script evaluation issue […]
newssecurityaffairs.comOct 19, 2022, 10:50 PM- China-linked Budworm APT returns to target a US entitySecurity Affairs
The Budworm espionage group resurfaced targeting a U.S.-based organization for the first time, Symantec Threat Hunter team reported. The Budworm cyber espionage group (aka APT27, Bronze Union, Emissary Panda, Lucky Mouse, TG-3390, and Red Phoenix) is behind a series attacks conducted over the past six months against a number of high-profile targets, including the government of […]
newssecurityaffairs.comOct 13, 2022, 11:10 PM A China-linked cyberespionage group was recently observed targeting a state legislature in the United States, Symantec warns.
newswww.securityweek.comOct 13, 2022, 10:06 AMResearch shows that companies can have over 100,000 vulnerabilities in their systems, but 85% cannot realistically be exploited Vulnerability management firm Rezilion commissioned Ponemon Institute to conduct research into the state of vulnerability management, given the known difficulties in timely patching and the continuous growth in the number of new vulnerabilities that need to be patched or otherwise mitigated. “The survey ( PDF ) is based on responses from 634 IT and security practitioners, primarily based in North America,” Larry Ponemon, chairman of Ponemon Institute told SecurityWeek . “All of the respondents work in organizations that have an effective DevSecOps program in place. Technically, it has a margin of error of approximately 3.5%.” One of his biggest concerns is that less than half of the respondents (47%) believe their development team ‘is able to deliver both an enhanced customer experience and secure applications’. The problem may stem from one of the headline f…
newswww.securityweek.comSep 20, 2022, 3:18 PM- 19th September – Threat Intelligence ReportCheck Point Research
For the latest discoveries in cyber research for the week of 19th September, please download our Threat Intelligence Bulletin. Top Attacks and Breaches Uber has suffered a data breach, allegedly by an 18-year-old hacker who managed to gain access using social engineering tactics on an employee. The hacker claims to have access to Uber’s internal […]
vendorresearch.checkpoint.comSep 19, 2022, 12:57 PM Government agencies in the US, UK, Canada, and Australia say that threat groups associated with Iran’s Islamic Revolutionary Guard Corps (IRGC) have been engaging in data encryption and extortion operations.
newswww.securityweek.comSep 15, 2022, 3:45 PM- 12th September – Threat Intelligence ReportCheck Point Research
For the latest discoveries in cyber research for the week of 12th September, please download our Threat Intelligence Bulletin. Top Attacks and Breaches Check Point Research uncovered a malicious campaign dubbed “DangerousSavanna” targeting multiple major financial groups in French-speaking Africa for the past two years. Threat actors used spear-phishing as the initial infection method, sending […]
vendorresearch.checkpoint.comSep 12, 2022, 1:49 PM - 29th August – Threat Intelligence ReportCheck Point Research
For the latest discoveries in cyber research for the week of 29th August, please download our Threat Intelligence Bulletin. Top Attacks and Breaches Montenegro has suffered a large-scale cyber attack, affecting multiple government services. According to some sources, it potentially affected critical infrastructure, transportation and telecommunications. Montenegro’s security agency has claimed that the attack was […]
vendorresearch.checkpoint.comAug 29, 2022, 2:22 PM An Iran-linked Mercury APT group exploited the Log4Shell vulnerability in SysAid applications for initial access to the targeted organizations. The Log4Shell flaw (CVE-2021-44228) made the headlines in December after Chinese security researcher p0rz9 publicly disclosed a Proof-of-concept exploit for the critical remote code execution zero-day vulnerability (aka Log4Shell) that affects the Apache Log4j Java-based logging library. The flaw can be exploited […]
newssecurityaffairs.comAug 26, 2022, 5:19 PMA threat group linked to the Iranian government appears to be the first to exploit the Log4Shell vulnerability in SysAid applications for initial access to the targeted organizations.
newswww.securityweek.comAug 26, 2022, 1:10 PMA new report from Trustwave SpiderLabs has revealed that the number of CVEs published so far this year could be as much as 35% higher than in the same period in 2021. The findings come from the security firm’s 2022 Telemetry Report. While organizations appear to be exhibiting greater awareness of effective patch management compared […]
newswww.csoonline.comAug 25, 2022, 2:06 PM- Risky Business: Enterprises Can’t Shake Log4j flawSecurity Affairs
70% of Large enterprises that previously addressed the Log4j flaw are still struggling to patch Log4j-vulnerable assets. INTRODUCTION In December 2021 security teams scrambled to find Log4j-vulnerable assets and patch them. Eight months later many Global 2000 firms are still fighting to mitigate the digital assets and business risks associated with Log4j. The ease of […]
newssecurityaffairs.comAug 10, 2022, 5:17 PM The Log4j vulnerability, initially reported in November 2021, has affected millions of devices and applications around the world. It has the potential to allow a malicious actor to take full control of vulnerable devices. As a result of how Log4j controls the logging of strings and code, the vulnerability allows malicious actors to inject malicious … Read More
vendorwww.wordfence.comAug 2, 2022, 2:06 PMThe US Cybersecurity and Infrastructure Security Agency (CISA) has been investigating attacks exploiting the Log4Shell vulnerability in third-party products like VMware Horizon and Unified Access Gateway (UAG). The agency published indicators of compromise (IOCs) collected from incidents it investigated as recently as June, highlighting the long-lasting impact of this vulnerability that’s over six months old. […]
newswww.csoonline.comJul 29, 2022, 6:25 PMThe 2022 Unit 42 Network Threat Trends Research Report includes an analysis of the CVEs most commonly exploited in 2021 and predictions for which CVEs attackers will likely focus on in the year to come.
vendorunit42.paloaltonetworks.comJul 21, 2022, 1:00 PM- The Long Tail of Log4Shell ExploitationHorizon3.ai
It’s been more than six months since the Log4Shell vulnerability (CVE-2021-44228) was disclosed, and a number of post-mortems have come out talking about lessons learned and ways to prevent the next Log4Shell-type event from happening.
exploithorizon3.aiJul 13, 2022, 12:54 PM - Week in review: Log4Shell exploitation, DevSecOps myths, 56 vulnerabilities impacting OT devicesHelp Net Security
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: QNAP NAS devices hit by DeadBolt and ech0raix ransomware Taiwan-based QNAP Systems is warning consumers and organizations using their network-attached storage (NAS) appliances of a new DeadBolt ransomware campaign. Fake voicemail notifications are after Office365, Outlook credentials A phishing campaign using fake voicemail notifications has been and is still targeting various US-based organizations, in an attempt to grab employees’ Office365 … More →
newswww.helpnetsecurity.comJun 26, 2022, 8:30 AM The U.S. CISA and the Coast Guard Cyber Command (CGCYBER) warn of attacks exploiting the Log4Shell flaw in VMware Horizon servers. The U.S. Cybersecurity and Infrastructure Security Agency (CISA), along with the Coast Guard Cyber Command (CGCYBER), published a joint advisory to warn of hacking attempts exploiting the Log4Shell flaw in VMware Horizon servers to […]
newssecurityaffairs.comJun 24, 2022, 3:07 PMThe United States Cybersecurity and Infrastructure Security Agency (CISA) and the Coast Guard Cyber Command (CGCYBER) have issued a joint advisory to warn organizations that threat actors continue to exploit the Log4Shell vulnerability in VMware Horizon and Unified Access Gateway (UAG) servers.
newswww.securityweek.comJun 24, 2022, 10:30 AMIf your organization is running VMware Horizon and Unified Access Gateway servers and you haven’t implemented the patches or workarounds to fix/mitigate the Log4Shell vulnerability (CVE-2021-44228) in December 2021, you should threat all those systems as compromised, the Cybersecurity and Infrastructure Security Agency (CISA) has advised on Thursday. The agency accompanied the warning with detailed technical information and indicators of compromised related to two separate incident response engagements they and the United States Coast Guard … More →
newswww.helpnetsecurity.comJun 24, 2022, 9:41 AMIn slightly more than a month, the Conti ransomware collective compromised more than 40 companies worldwide, and the fastest attack took only three days, Group-IB’s noted in its latest report detailing the workings of one of the most prolific ransomware / extortion gangs out there. In two years, the ransomware operators attacked more than 850 victims including corporations, government agencies, and even a whole country (Costa Rica). Double hit The Conti gang’s existence first came … More →
newswww.helpnetsecurity.comJun 23, 2022, 12:06 PMSoftware supply chain attacks have received increased attention over the past year with high-profile examples such as the SolarWinds SUNBURST attack, the Kaseya VSA (REvil) attack, or the Log4j vulnerability making headlines and impacting thousands of enterprises. It isn’t that a handful of examples happen to make the news: Supply chain attacks are growing more […]
newswww.csoonline.comJun 13, 2022, 6:30 PMMetasploit is the world’s most used penetration testing framework. It helps security teams verify vulnerabilities, manage security assessments, and improve security awareness. Metasploit 6.2.0 is now available. It includes 138 new modules, 148 enhancements and features, improvements, and 156 bug fixes. “Our continued focus for Metasploit is on on adding support for modern attacks so the community can highlight risk and test security controls for paths that attackers use regularly. Metasploit 6.2.0 continued this theme … More →
newswww.helpnetsecurity.comJun 13, 2022, 12:14 PMNetwork security trends observed November 2021 to January 2022 included high levels of cross-site scripting.
vendorunit42.paloaltonetworks.comMay 31, 2022, 7:00 PMThe operators of the EnemyBot botnet added exploits for recently disclosed flaws in VMware, F5 BIG-IP, and Android systems. Operators behind the EnemyBot botnet are expanding the list of potential targets adding exploits for recently disclosed critical vulnerabilities in from VMware, F5 BIG-IP, and Android. The botnet was first discovered by Fortinet in March, the […]
newssecurityaffairs.comMay 30, 2022, 7:09 AM- 23rd May – Threat Intelligence ReportCheck Point Research
For the latest discoveries in cyber research for the week of 23rd May, please download our Threat Intelligence Bulletin. Top Attacks and Breaches Check Point Research has unveiled a targeted cyber-espionage operation against at least two research institutes in Russia, which are part of the Rostec Corporation, a state-owned defense conglomerate. The sophisticated campaign, which […]
vendorresearch.checkpoint.comMay 23, 2022, 1:28 PM North Korea-linked Lazarus APT is exploiting the Log4J remote code execution (RCE) in attacks aimed at VMware Horizon servers. North Korea-linked group Lazarus is exploiting the Log4J RCE vulnerability (CVE-2021-44228) to compromise VMware Horizon servers. Multiple threat actors are exploiting this flaw since January, in January VMware urged customers to patch critical Log4j security vulnerabilities impacting Internet-exposed […]
newssecurityaffairs.comMay 22, 2022, 3:48 PMThe Log4Shell RCE vulnerability in Apache Log4j, CVE-2021-44228, dates to 2013 when Log4j 2.0-beta9 was released. An analysis of our pentesting data using NodeZero identified and provided proof of exploit for over 105 unique instances of the CVE within our customers’ environments.
exploithorizon3.aiMay 16, 2022, 9:55 PMGlobal cybersecurity authorities have published a joint advisory on the 15 Common Vulnerabilities and Exposures (CVEs) most routinely exploited by malicious cyber actors in 2021. The advisory is co-authored by the U.S. Cybersecurity and Infrastructure Security Agency (CISA), U.S. National Security Agency (NSA), U.S. Federal Bureau of Investigation (FBI), Australian Cyber Security Centre (ACSC), Canadian […]
newswww.csoonline.comApr 28, 2022, 10:55 AM- The 15 most exploited vulnerabilities in 2021Help Net Security
In 2021, threat actors aggressively exploited newly disclosed critical software vulnerabilities to hit a broad set of targets worldwide, says the latest advisory published by the US Cybersecurity and Infrastructure Security Agency. Most exploited vulnerabilities, new and old Compiled by cybersecurity authorities from the Five Eyes intelligence alliance, the list of top 15 CVEs routinely exploited by attackers in 2021 looks like this: CVE-2021-44228 (aka Log4Shell) – in Apache Log4j CVE-2021-40539 – in Zoho ManageEngine … More →
newswww.helpnetsecurity.comApr 28, 2022, 7:48 AM We identified severe security issues within AWS Log4Shell hot patch solutions. We provide a root cause analysis and overview of fixes and mitigations.
vendorunit42.paloaltonetworks.comApr 19, 2022, 10:00 PM- Enemybot, a new DDoS botnet appears in the threat landscapeSecurity Affairs
Enemybot is a DDoS botnet that targeted several routers and web servers by exploiting known vulnerabilities. Researchers from Fortinet discovered a new DDoS botnet, tracked as Enemybot, that has targeted several routers and web servers by exploiting known vulnerabilities. The botnet targets multiple architectures, including arm, bsd, x64, and x86. The researchers attribute the botnet […]
newssecurityaffairs.comApr 17, 2022, 5:53 PM A recently identified DDoS botnet has targeted several router models and various types of web servers by exploiting known vulnerabilities, Fortinet warns.
newswww.securityweek.comApr 15, 2022, 10:41 AM- Week in review: Disrupted Cyclops Blink botnet, public software apps at risk, Patch Tuesday forecastHelp Net Security
Here’s an overview of some of last week’s most interesting news, articles and interviews: April 2022 Patch Tuesday forecast: Spring is in the air (and vulnerable) March Patch Tuesday releases followed in the footsteps of February with low numbers of CVEs reported and resolved, and all updates rated as important except one critical update for Microsoft Exchange Server. Log4Shell exploitation: Which applications may be targeted next? Spring4Shell (CVE-2022-22965) has dominated the information security news these … More →
newswww.helpnetsecurity.comApr 10, 2022, 8:00 AM - CISA adds Spring4Shell to list of exploited vulnerabilitiesHelp Net Security
It’s been almost a week since the Spring4Shell vulnerability (CVE-2022-22965) came to light and since the Spring development team fixed it in new versions of the Spring Framework. There have been reports of scanning, exploit attempts and attempts to deploy a web shell on vulnerable systems, but it seems that a successful exploitation has yet to be documented. The consensus amongst the thread and everybody I talk to in private is there are no incidents … More →
newswww.helpnetsecurity.comApr 5, 2022, 11:07 AM - Log4Shell exploitation: Which applications may be targeted next?Help Net Security
Spring4Shell (CVE-2022-22965) has dominated the information security news these last six days, but Log4Shell (CVE-2021-44228) continues to demand attention and action from enterprise defenders as diverse vulnerable applications are being targeted in attacks in the wild. Attackers in the wild exploiting Log4Shell Log4Shell is widespread because Apache Log4j – the logging library that it affects – is widely used. While its exploitability depends on the Java version, the Log4j version (only Log4j v2 is vulnerable) … More →
newswww.helpnetsecurity.comApr 5, 2022, 9:07 AM - 14th March – Threat Intelligence ReportCheck Point Research
For the latest discoveries in cyber research for the week of 14th March, please download our Threat Intelligence Bulletin. Top Attacks and Breaches Check Point Research has analyzed the Conti Ransomware gang’s chat leaks and revealed insights on the group’s Hi-tech company type of management, with physical offices, HR & finance departments and more. CPR […]
vendorresearch.checkpoint.comMar 14, 2022, 3:48 PM - 7th March – Threat Intelligence ReportCheck Point Research
For the latest discoveries in cyber research for the week of 7th March, please download our Threat Intelligence Bulletin. Top Attacks and Breaches Check Point Research reports on cyber criminals’ and hacktivists’ increased activity leveraging Telegram amid the Russia-Ukraine war. Anti-Russian cyber-attack groups have been growing, while others claiming to fundraise for Ukraine are suspected […]
vendorresearch.checkpoint.comMar 7, 2022, 4:26 PM The UK’s NHS Digital agency warns of an RCE in the Windows client for the Okta Advanced Server Access authentication management platform. The UK’s NHS Digital agency published a security advisory to warn organizations of a remote code execution flaw, tracked as CVE-2022-24295, impacting the Windows client for the Okta Advanced Server Access authentication management […]
newssecurityaffairs.comFeb 26, 2022, 10:45 AM- 21st February– Threat Intelligence ReportCheck Point Research
For the latest discoveries in cyber research for the week of 21st February, please download our Threat Intelligence Bulletin. Top Attacks and Breaches Check Point Research has investigated the attack against Iranian broadcasting that occurred in late January. CPR was able to discover part of the tools that were utilized in this operation, including the […]
vendorresearch.checkpoint.comFeb 21, 2022, 2:12 PM - Week in review: Kali Linux 2022.1 released, attackers leveraging Microsoft Teams to spread malwareHelp Net Security
Here’s an overview of some of last week’s most interesting news, articles and interviews: Kali Linux 2022.1 released: New tools, kali-linux-everything, visual changes Offensive Security has released Kali Linux 2022.1, the latest version of its popular open source penetration testing platform. DDoS attacks knock Ukrainian government, bank websites offline Unknown attackers have mounted disruptive distributed denial-of-service (DDoS) attacks against several Ukrainian government organizations and state-owned banks. Attackers use Microsoft Teams as launchpad for malware Hackers … More →
newswww.helpnetsecurity.comFeb 20, 2022, 9:00 AM - Log4Shell: A retrospectiveHelp Net Security
Now that the dust has settled on both the holiday season and the Log4j vulnerability that saw many of us working through it (CVE-2021-44228), it makes sense to look back and take stock of how things played out. What strategies worked in the face of one of the most notable vulnerabilities of the last decade? To begin with, let’s briefly look at the issue itself. Log4j is a Java logging utility used by just about … More →
newswww.helpnetsecurity.comFeb 15, 2022, 6:15 AM Here’s an overview of some of last week’s most interesting news, articles and interviews: Log4j exploitation risk is not as high as first thought, cyber MGA says When the Log4Shell vulnerability (CVE-2021-44228) was publicly revealed in December 2021, CISA Director Jen Easterly said that it is the “most serious” vulnerability she has seen in her decades-long career and it could take years to address. Apple fixes actively exploited iOS, macOS zero-day (CVE-2022-22620) Another month, another … More →
newswww.helpnetsecurity.comFeb 13, 2022, 9:00 AMWhen the Log4Shell vulnerability (CVE-2021-44228) was publicly revealed in December 2021, CISA Director Jen Easterly said that it is the “most serious” vulnerability she has seen in her decades-long career and it could take years to address. It’s true: the flaw is remotely exploitable by unskilled attackers and vulnerable versions of the open source library are seemingly ubiquitous – and are still being downloaded and used. Attackers have been trying to exploit the vulnerability to … More →
newswww.helpnetsecurity.comFeb 11, 2022, 9:21 AM- Product showcase: Sniper – automatically detect and exploit critical CVEs in minutesHelp Net Security
High-risk, widespread vulnerabilities cause significant disruptions to already struggling security teams. In 2021, 1100+ CVEs with 9-10 CVSSv3 scores flooded the tech ecosystem. Fixing a critical vulnerability takes 100+ days on average and some may take years to eliminate through patching or other solutions. So how can security specialists cope? Automation is an option, as teams still do a lot of manual work to confirm the real impact of a CVE with remote code execution … More →
newswww.helpnetsecurity.comFeb 10, 2022, 6:15 AM - 31st January– Threat Intelligence ReportCheck Point Research
For the latest discoveries in cyber research for the week of 31st January, please download our Threat Intelligence Bulletin. Top Attacks and Breaches Hacktivist group from Belarus called “Belarusian Cyber Partisans” has breached the computers systems of Belarusian Railways. Threat actors claim to have encrypted the network and are extorting the Belarusian government, asking for […]
vendorresearch.checkpoint.comJan 31, 2022, 2:37 PM Ivanti, Cyber Security Works and Cyware announced a report which identified 32 new ransomware families in 2021, bringing the total to 157 and representing a 26% increase over the previous year. The report also found that these ransomware groups are continuing to target unpatched vulnerabilities and weaponize zero-day vulnerabilities in record time to instigate crippling attacks. At the same time, they are broadening their attack spheres and finding newer ways to compromise organizational networks and … More →
newswww.helpnetsecurity.comJan 28, 2022, 6:00 AMVMware is urging customers to patch their VMware Horizon instances as these systems have been targeted in a recent wave of attacks exploiting the Log4Shell vulnerability.
newswww.securityweek.comJan 27, 2022, 11:46 AMVMware released security patches to address critical Log4j security vulnerabilities in VMware Horizon servers targeted in ongoing attacks. VMware urges customers to patch critical Log4j security vulnerabilities impacting Internet-exposed VMware Horizon servers targeted in ongoing attacks. Searching for Internet-exposed VMware Horizon servers with Shodan, we can find tens of thousands of installs potentially exposed to […]
newssecurityaffairs.comJan 26, 2022, 1:20 PMThe past few weeks left IT professionals overwhelmed as organizations scrambled to assess if they were vulnerable to threats posed by the Log4Shell vulnerability. As if that weren’t enough of a challenge over the holidays, more Log4j CVEs followed, not all of which deserved equal attention. And Microsoft’s January Patch Tuesday flaws caused even more […]
newswww.csoonline.comJan 25, 2022, 10:00 AMLog4Shell, the critical unauthenticated remote code execution vulnerability identified in early December 2021 in the Apache Log4j logging utility, hasn’t seen the mass exploitation that many expected, but an exploit for it is now part of the Mirai botnet’s arsenal, researchers warn.
newswww.securityweek.comJan 25, 2022, 9:43 AMThe Dutch National Cybersecurity Centre (NCSC) warns organizations of risks associated with cyberattacks exploiting the Log4J vulnerability. The Dutch National Cybersecurity Centre (NCSC) warns organizations to remain vigilant on possible attacks exploiting the Log4J vulnerability. According to the Dutch agency, threat actors the NCSC will continue to attempt to exploit the Log4Shell flaw in future […]
newssecurityaffairs.comJan 22, 2022, 8:34 PMOracle on Tuesday announced its first set of quarterly security updates for 2022, which include a total of 497 new patches. More than half of the addressed vulnerabilities can be exploited remotely without authentication.
newswww.securityweek.comJan 19, 2022, 3:24 PM- 17th January– Threat Intelligence ReportCheck Point Research
For the latest discoveries in cyber research for the week of 17th January, please download our Threat Intelligence Bulletin. Top Attacks and Breaches Russia’s Federal Security Service (FSB) has arrested several members of the REvil ransomware group, responsible for the JBS attack and the Kaseya supply chain attack, among others, after carrying out raids at 25 […]
vendorresearch.checkpoint.comJan 17, 2022, 1:55 PM - Night Sky ransomware operators exploit Log4Shell to target hack VMware Horizon serversSecurity Affairs
Another gang, Night Sky ransomware operation, started exploiting the Log4Shell vulnerability in the Log4j library to gain access to VMware Horizon systems. The Night Sky ransomware operation started exploiting the Log4Shell flaw (CVE-2021-44228) in the Log4j library to gain access to VMware Horizon systems. The ransomware gang started its operations on December 27, 2021, and […]
newssecurityaffairs.comJan 11, 2022, 2:52 PM - APT35 exploits Log4j vulnerability to distribute new modular PowerShell toolkitCheck Point Research
Introduction With the emergence of the Log4j security vulnerability, we’ve already seen multiple threat actors, mostly financially motivated, immediately add it to their exploitation arsenal. It comes as no surprise that some nation-sponsored actors also saw this new vulnerability as an opportunity to strike before potential targets have identified and patched the affected systems. APT35 […]
vendorresearch.checkpoint.comJan 11, 2022, 11:09 AM - 10th January– Threat Intelligence ReportCheck Point Research
For the latest discoveries in cyber research for the week of 10th January, please download our Threat Intelligence Bulletin. Top Attacks and Breaches A series of attacks targeting Russia’s Ministry of Foreign Affairs has been attributed to North Korean APT group Konni. Threat actors gained access by leveraging a socially engineered phishing campaign with New […]
vendorresearch.checkpoint.comJan 10, 2022, 3:16 PM Researchers disclosed a critical RCE flaw in the H2 open-source Java SQL database which is similar to the Log4J vulnerability. Jfrog researchers discovered a critical vulnerability in the H2 open-source Java SQL database related to the Log4Shell Log4J vulnerability. The flaw, tracked as CVE-2021-42392, could allow attackers to execute remote code on vulnerable systems, the […]
newssecurityaffairs.comJan 8, 2022, 7:53 PMA threat actor attempted to exploit the Log4Shell vulnerability to hack VMWare Horizon servers at UK NHS and deploy web shells. The security team at the UK National Health Service (NHS) announced to have spotted threat actors exploiting the Log4Shell vulnerability to hack VMWare Horizon servers and install web shells. “An unknown threat group has […]
newssecurityaffairs.comJan 7, 2022, 3:47 PMThe Apache Log4j vulnerability has made global headlines since it was discovered in early December. The flaw has impacted vast numbers of organizations around the world as security teams have scrambled to mitigate the associated risks. Here is a timeline of the key events surrounding the Log4j vulnerability as they have unfolded. Thursday, December 9: […]
newswww.csoonline.comJan 7, 2022, 10:00 AM- January 2022 Patch Tuesday forecast: Old is new againHelp Net Security
Welcome to 2022 and a new year of patch management excitement! I’m rapidly approaching 40 years working in this industry and I can honestly say there is rarely a dull day. If you are willing to take on the challenges presented, it is a great industry to work in and I hope you all are excited to start the new year too. Let’s look at some recent events which will be influencing this month’s patch … More →
newswww.helpnetsecurity.comJan 7, 2022, 6:20 AM - Using NodeZero to Find and Fix Log4ShellHorizon3.ai
Log4Shell is a “once-in-a-decade” type of vulnerability that will linger in environments for years to come. For a vulnerability with such a broad, lasting impact, it’s important to establish a principled and disciplined approach for discovering and remediating it. NodeZero both detects and exploits Log4Shell, surfacing a wealth of information that can be used to understand its real impact and prioritize its remediation.
exploithorizon3.aiJan 6, 2022, 11:43 PM - ICS Vendors Respond to Log4j VulnerabilitiesSecurityWeek
SecurityWeek has compiled a list of the advisories published by industrial control system (ICS) and other industrial-related vendors in response to the recent Log4j vulnerabilities. Several vulnerabilities have been discovered in the Log4j logging utility since early December, but the most important of them is CVE-2021-44228, which has been dubbed Log4Shell. Log4Shell has been exploited in many attacks by cybercriminals and state-sponsored threat actors, including against industrial organizations . Major companies that provide industrial services and solutions have released advisories to inform customers about the impact of the Log4j vulnerabilities. This article presents the information that is currently available from vendors, but their advisories may be updated with additional impacted products or versions. ABB ABB says it’s still investigating the impact of the Log4j vulnerabilities on its products. To date, it has confirmed that its B&R products and ABB Remote Access Platform (RA…
newswww.securityweek.comJan 5, 2022, 3:14 PM The US Federal Trade Commission (FTC) has warned legal action against companies who fail to secure their infrastructure against Log4Shell attacks. The US Federal Trade Commission (FTC) warns legal action against companies who protect their systems against Log4Shell (CVE-2021-44228) attacks. The move aims at urging organizations in protecting their infrastructure while both nation-state actors and cybercriminals are […]
newssecurityaffairs.comJan 5, 2022, 2:48 PMThe U.S. Federal Trade Commission (FTC) on Tuesday informed companies that they could face legal action if their customers are impacted by an attack that involves exploitation of the recent Log4j vulnerabilities.
newswww.securityweek.comJan 5, 2022, 12:13 PMThreat actors continue to attempt to exploit Apache Log4J vulnerabilities in their campaigns to deploy malware on target systems, Microsoft warns. Microsoft is warning of continuing attempts by nation-state actors and cybercriminals to exploit recently discovered vulnerabilities in the Apache Log4j library to deploy malware on vulnerable systems. Microsoft recommends customers review their infrastructure looking […]
newssecurityaffairs.comJan 5, 2022, 10:46 AM- 3rd January– Threat Intelligence ReportCheck Point Research
For the latest discoveries in cyber research for the week of 3rd January, please download our Threat Intelligence Bulletin. Top Attacks and Breaches The Vietnamese trading platform ONUS was victim of a ransomware attack leveraging the Log4j flaw on its payment system. Cyber criminals demanded a $5 million ransom in a double extortion scheme. ONUS […]
vendorresearch.checkpoint.comJan 3, 2022, 2:31 PM - The worst cyber attacks of 2021Security Affairs
Which are the cyber attacks of 2021 that had the major impact on organizations worldwide in terms of financial losses and disruption of the operations? CNA Financial (March 2021) – CNA Financial, one of the largest insurance companies in the US, reportedly paid a $40 million ransom to restore access to its files following a […]
newssecurityaffairs.comJan 3, 2022, 11:03 AM The Apache Software Foundation released Log4j 2.17.1 version to address recently discovered arbitrary code execution flaw tracked as CVE-2021-44832. The Apache Software Foundation released Log4j 2.17.1 version to address a recently discovered arbitrary code execution flaw, tracked as CVE-2021-44832, affecting Log4j 2.17.0. CVE-2021-44832 is the fifth vulnerability discovered in the popular library in the last […]
newssecurityaffairs.comDec 29, 2021, 2:34 PMThe developers of Log4j have patched another remote code execution vulnerability affecting the widely used logging utility.
newswww.securityweek.comDec 29, 2021, 12:35 PMember discovery. While the vast majority of products written in Java are thought to be vulnerable to the RCE tracked as CVE-2021-44228 , the true breadth of the attack surface is still yet to be confirmed and isn’t likely to be fully realised for months, according to experts. Attackers, however, can certainly utilise a long-known exploitation method kn
newswww.itpro.comDec 28, 2021, 8:00 AMResearchers from DrWeb monitored attacks leveraging exploits for vulnerabilities in the Apache Log4j library Researchers from DrWeb monitored attacks leveraging exploits for vulnerabilities (CVE-2021-44228, CVE-2021-45046, CVE2021-4104, and CVE-2021-42550) in the Apache Log4j library warning of the need to adopt protective measures. The vulnerabilities can allow threat actors to execute arbitrary code on the target systems, […]
newssecurityaffairs.comDec 27, 2021, 2:26 PM- 27th December – Threat Intelligence ReportCheck Point Research
For the latest discoveries in cyber research for the week of 27th December, please download our Threat Intelligence Bulletin. Top Attacks and Breaches Researchers have revealed an APT-like campaign targeting the US Federal Government Commission on international rights and religious freedom. Threat actors used a backdoor that possibly gave them full visibility and control over […]
vendorresearch.checkpoint.comDec 26, 2021, 2:42 PM - Week in review: Log4j new vulnerabilities, Microsoft patch bypass, 2022 e-commerce threat trendsHelp Net Security
Here’s an overview of some of last week’s most interesting news, articles and interviews: The Log4j saga: New vulnerabilities and attack vectors discovered The Apache Log4j saga continues, as several new vulnerabilities have been discovered in the popular library since Log4Shell (CVE-2021-44228) was fixed by releasing Log4j v2.15.0. Log4Shell is a dumpster fire that should have been avoided If basic IT hygiene guidance had been followed, Log4j would have easily been immune to this type … More →
newswww.helpnetsecurity.comDec 26, 2021, 9:00 AM NVIDIA and Hewlett Packard Enterprise (HPE) have confirmed that some of their products are affected by the recently disclosed vulnerabilities in the Apache Log4j logging utility.
newswww.securityweek.comDec 23, 2021, 1:44 PMGovernment agencies in the United States, Canada, the United Kingdom, Australia and New Zealand on Wednesday announced the release of a joint cybersecurity advisory to provide guidance on addressing the recently disclosed vulnerabilities affecting the widely used Log4j logging utility.
newswww.securityweek.comDec 23, 2021, 11:50 AMThe DHS has announced that it is expanding the ‘Hack DHS’ bug bounty program to report for Log4J impacting its systems. The Department of Homeland Security (DHS) announced that white hat hackers can now report the impact of the Log4J on its systems as part of the ‘Hack DHS‘ bug bounty program. Below is the […]
newssecurityaffairs.comDec 23, 2021, 9:57 AM- Log4Shell is a dumpster fire that should have been avoidedHelp Net Security
On Thursday, December 9, 2021, my young, Minecraft-addicted kids were still completely oblivious of the Log4j vulnerabilities in their favorite game. Then again, so was every cybersecurity professional in the world. That all changed when the Apache Log4j project announced CVE-2021-44228 (aka Log4Shell) – a zero-day vulnerability in Log4j’s standardized method of handling log files used by apps all over the world, from Microsoft’s Minecraft to Twitter to Tesla to Apple’s iCloud. This led to … More →
newswww.helpnetsecurity.comDec 23, 2021, 8:53 AM US CISA release of a scanner for identifying web services affected by two Apache Log4j remote code execution vulnerabilities. The Cybersecurity and Infrastructure Security Agency (CISA) has announced the release of an open-source scanner for identifying web services impacted by Apache Log4j remote code execution vulnerabilities, tracked as CVE-2021-44228 and CVE-2021-45046. “This repository provides a scanning solution […]
newssecurityaffairs.comDec 22, 2021, 10:10 PMThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) says it’s currently not aware of any federal agencies suffering a breach as a result of Log4Shell attacks. The agency told SecurityWeek that it does “not have any confirmed compromises of federal agencies” resulting from the recently disclosed Log4j vulnerability tracked as Log4Shell and CVE-2021-44228. CISA last week issued emergency directive ED 22-02 , which directs federal agencies to identify affected internet-exposed systems and address the flaw — either via patches, mitigations or removal of software — by December 23. CVE-2021-44228 has been added to CISA’s catalog of known exploited vulnerabilities, which compels federal civilian agencies to take immediate action. The binding operational directive BOD 22-01, which CISA issued in early November when it announced the catalog, instructs government agencies to quickly address actively exploited bugs. Log4Shell has been exploited in attacks by profit-driven cybercrimi…
newswww.securityweek.comDec 22, 2021, 3:53 PM- Chinese Government Punishes Alibaba for Not Telling It First About Log4Shell Flaw: ReportSecurityWeek
China’s Ministry of Industry and Information Technology (MIIT) said it will temporarily suspend its collaboration with Alibaba Cloud as a cyber threat intelligence partner due to the fact that the company did not inform the government first about the discovery of the Log4Shell vulnerability, according to local media reports.
newswww.securityweek.comDec 22, 2021, 11:47 AM Cybersecurity and cyber resilience measures are most effective when applied in concert
newswww.securityweek.comDec 22, 2021, 11:18 AMTick… On December 9, 2021, the world was alerted to the Log4j vulnerability [CVE-2021-44228 aka Log4Shell]. Tock… Most likely bad actors already knew about this prior to December 9th as it’s been reported that the vulnerability was exposed much earlier in Minecraft chat forums. The vulnerability exposes how the ubiquitous Log4j Java logging utility can be […]
newswww.csoonline.comDec 21, 2021, 8:54 PM- Log4j Vulnerability AftermathSecurity Affairs
Uptycs researchers have observed attacks related to miners, DDOS malware and some variants of ransomware actively leveraging LogforShell flaw in log4j. Last week the Log4j vulnerability turned the internet upside down. The impact of the vulnerability is massive and attackers have started taking advantage of the flaw. So far we have observed attacks related to […]
newssecurityaffairs.comDec 21, 2021, 8:04 AM The computer security industry is bracing for travel on long, bumpy roads littered with Log4j security problems as experts warn that software dependency patching hiccups will slow global mitigation efforts.
newswww.securityweek.comDec 20, 2021, 7:29 PMPatches released by VMware to address a couple of vulnerabilities in the Workspace ONE Access authentication solution also resolve the recent Log4Shell security flaw.
newswww.securityweek.comDec 20, 2021, 2:06 PMCISA Orders Federal Agencies to Mitigate Log4j Vulnerabilities The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an emergency directive instructing federal agencies to mitigate the Log4j vulnerabilities. The announcement came just before the disclosure of a new flaw affecting the popular logging utility.
newswww.securityweek.comDec 20, 2021, 11:47 AM- 20th December – Threat Intelligence ReportCheck Point Research
For the latest discoveries in cyber research for the week of 20th December, please download our Threat Intelligence Bulletin. Top Attacks and Breaches Check Point Research has reported that an Iranian threat group commonly associated with the local regime, “Charming Kitten”, has been attempting to exploit the Log4j vulnerability against 7 Israeli targets in Government […]
vendorresearch.checkpoint.comDec 20, 2021, 10:05 AM - The Log4j saga: New vulnerabilities and attack vectors discoveredHelp Net Security
The Apache Log4j saga continues, as several new vulnerabilities have been discovered in the popular library since Log4Shell (CVE-2021-44228) was fixed by releasing Log4j v2.15.0. There’s CVE-2021-45046, a DoS/RCE flaw that was fixed in v2.16.0, then CVE-2021-45105, a DoS hole plugged in v2.17.0. Oh, and there’s CVE-2021-4104, a RCE vulnerability affecting Log4j v1.2, which will not be fixed because the 1.x branch has reached end-of-life. But these new revelations should not make you panic. While … More →
newswww.helpnetsecurity.comDec 20, 2021, 7:31 AM The TellYouThePass ransomware resurged and exploits the Apache Log4j flaw (Log4Shell) to target both Linux and Windows systems. Researchers from KnownSec 404 Team and Sangfor Threat Intelligence Team reported that the TellYouThePass ransomware resurged and is exploiting the Apache Log4j CVE-2021-44228 flaw to target both Linux and Windows systems. “On December 13, Sangfor’s terminal security […]
newssecurityaffairs.comDec 19, 2021, 2:08 PM- Week in review: Log4Shell updates, Kronos ransomware attack, unused identities threatHelp Net Security
Here’s an overview of some of last week’s most interesting news, articles and interviews: Log4Shell: A new fix, details of active attacks, and risk mitigation recommendations Due to the extraordinary widespread use of the open-source Apache Log4j library, the saga of the Log4Shell (CVE-2021-44228) vulnerability is nowhere near finished. The Log4j JNDI attack and how to prevent it The disclosure of the critical Log4Shell (CVE-2021-44228) vulnerability and the release of first one and than additional … More →
newswww.helpnetsecurity.comDec 19, 2021, 9:00 AM - Apache releases the third patch to address a new Log4j flawSecurity Affairs
Multiple flaws in the Log4J library are scaring organizations worldwide while threat actors are already exploiting them. 2.17 is the third fix issued in a week. While the experts were warning that threat actors are actively attempting to exploit a second vulnerability, tracked as CVE-2021-45046, disclosed in the Log4j library a third security vulnerability made the headlines. […]
newssecurityaffairs.comDec 18, 2021, 3:20 PM - Conti ransomware gang exploits Log4Shell bug in its operationsSecurity Affairs
The Conti ransomware gang is the first ransomware operation exploiting the Log4Shell vulnerability to target VMware vCenter Servers. Conti ransomware gang is the first professional race that leverages Log4Shell exploit to compromise VMware vCenter Server installs. The ransomware group used the exploit to target internal devices that are not protected. Conti operators run a private Ransomware-as-a-Service (RaaS), […]
newssecurityaffairs.comDec 17, 2021, 9:44 PM Russia has been added to the list of nation states targeting the recently disclosed Log4Shell vulnerability, with exploitation attempts linked to several of the country’s cyberespionage groups.
newswww.securityweek.comDec 17, 2021, 6:36 PMCustomers of the MobileIron security and endpoint management product are being targeted in Log4Shell attacks, just as researchers identify new attack vectors and Cloudflare reports a surge in exploit activity.
newswww.securityweek.comDec 17, 2021, 12:09 PMA second vulnerability impacting Apache Log4j has been discovered as the security industry has scrambled to mitigate and fix a severe zero-day Java library logging flaw (CVE-2021-44228) dubbed Log4Shell. The new vulnerability, CVE 2021-45046, could allow attackers to craft malicious input data using a JNDI lookup pattern resulting in a denial-of-service (DoS) attack, according to […]
newswww.csoonline.comDec 16, 2021, 4:48 PMExperts warn that threat actors are actively attempting to exploit a second bug disclosed in the popular Log4j logging library. American web infrastructure and website security company Cloudflare warns that threat actors are actively attempting to exploit a second vulnerability, tracked as CVE-2021-45046, disclosed in the Log4j library. The CVE-2021-45046 received a CVSS score of 3.7 and affects […]
newssecurityaffairs.comDec 16, 2021, 2:25 PM- Multiple Nation-State actors are exploiting Log4Shell flawSecurity Affairs
Nation-state actors from China, Iran, North Korea, and Turkey are attempting to exploit the Log4Shell vulnerability to in attacks in the wild. Microsoft researchers reported that Nation-state actors from China, Iran, North Korea, and Turkey are now abusing the Log4Shell (CVE-2021-44228) in the Log4J library in their campaigns. Some of the groups exploiting the vulnerability are China-linked Hafnium and […]
newssecurityaffairs.comDec 16, 2021, 12:24 PM WhiteSource launched WhiteSource Log4j Detect, a free command-line interface (CLI) tool to help organizations quickly detect and remediate the Log4j vulnerabilities CVE-2021-44228 and CVE-2021-445046. This free developer tool, which is hosted on GitHub and is now available for use, quickly scans projects to find vulnerable Log4j versions and provides the exact path — both to direct or indirect dependencies — along with the fixed version for speedy remediation. As a standalone tool, developers can download … More →
newswww.helpnetsecurity.comDec 16, 2021, 12:15 PMMultiple threat groups are reportedly working on developing a worm that leverages the recently disclosed Log4j vulnerability.
newswww.securityweek.comDec 16, 2021, 12:10 PMThe IT security community has been hard at work for the past week to investigate a critical and easy-to-exploit vulnerability in a hugely popular Java component called Log4j that’s present in millions of applications and products. Since the flaw was first disclosed and attackers started exploiting it, security researchers have discovered additional security issues in […]
newswww.csoonline.comDec 16, 2021, 11:54 AM- The impact of the Log4j vulnerability on OT networksHelp Net Security
Operational Technology (OT) networks are at risk from the recently-announced Apache Log4j (CVE-2021-44228) vulnerability. On the surface, it is not clear why this should be. The vulnerability affects millions of web servers, allowing remote attackers to inject any code they wish into vulnerable Java applications on the Internet. The defect is being widely exploited in the wild, which is why security teams all over the world are scrambling to identify which of their web applications … More →
newswww.helpnetsecurity.comDec 16, 2021, 7:15 AM - Syxsense Secure protects businesses against the Log4j vulnerabilityHelp Net Security
Syxsense announced the ability to scan for Log4j using Syxsense Secure, identifying endpoints that are exposed to this new vulnerability. “Although a number of popular IT management and security tools are vulnerable, Syxsense is pleased to confirm that it does NOT use Log4j,” commented Ashley Leonard, CEO of Syxsense. “It imperative that IT departments respond quickly to this new threat by scanning their environment and identifying exposed endpoints.” A vulnerability in Log4j which is a … More →
newswww.helpnetsecurity.comDec 16, 2021, 3:15 AM If defenders needed any more urgency to patch and mitigate the explosive Log4j zero-day, along comes word that APT actors linked to China, Iran, North Korea and Turkey have already pounced and are actively exploiting the CVSS 10.0 vulnerability.
newswww.securityweek.comDec 15, 2021, 9:31 PM- StealthLoader Malware Leveraging Log4ShellCheck Point Research
Introduction While monitoring the exploit activity, Check Point Research detected many attacks involving the mining of cryptocurrencies. While most miners detected are Linux based, Check Point researchers recently discovered a Win32 executable malware identified as StealthLoader. This .NET-based malware surfaced right after the Log4j vulnerability was discovered. The StealthLoader Trojan performs various evasion techniques in […]
vendorresearch.checkpoint.comDec 15, 2021, 3:05 PM - Industry Reactions to Log4Shell VulnerabilitySecurityWeek
The widely used Log4j logging tool is affected by a critical remote code execution vulnerability that has been increasingly exploited by malicious actors, including profit-driven cybercriminals and state-sponsored groups.
newswww.securityweek.comDec 15, 2021, 2:26 PM German software maker SAP is scrambling to patch the Log4Shell vulnerability in its applications and has rolled out fixes for tens of other severe flaws in its products.
newswww.securityweek.comDec 15, 2021, 12:58 PMDevelopers of the widely used Apache Log4j Java-based logging tool have disabled problematic functionality as more security issues have come to light.
newswww.securityweek.comDec 15, 2021, 11:47 AM- Log4Shell: A new fix, details of active attacks, and risk mitigation recommendationsHelp Net Security
Due to the extraordinary widespread use of the open-source Apache Log4j library, the saga of the Log4Shell (CVE-2021-44228) vulnerability is nowhere near finished. As Dr. Johannes Ullrich, Dean of Research at the SANS Technology Institute, recently noted, “Log4Shell will continue to haunt us for years to come.” His advice? “Dealing with Log4Shell will be a marathon. Treat it as such.” So let’s see what’s the latest news that can impact your mitigation and remediation efforts. … More →
newswww.helpnetsecurity.comDec 15, 2021, 11:32 AM Chinese and Iranian state actors are exploiting the recently disclosed “Log4Shell” vulnerability that has sparked chaos across the tech world, cybersecurity firm Mandiant warned late Tuesday.
newswww.securityweek.comDec 15, 2021, 2:13 AMBitdefender researchers discovered that threat actors are attempting to exploit the Log4Shell flaw to deliver the new Khonsari ransomware on Windows machines. Bitdefender researchers discovered that threat actors are attempting to exploit the Log4Shell vulnerability (CVE-2021-44228) to deliver the new Khonsari ransomware on Windows machines. Experts warn that threat actors are attempting to exploit the Log4Shell flaw […]
newssecurityaffairs.comDec 14, 2021, 8:57 PM- What SMBs can do to protect against Log4Shell attacksMalwarebytes Labs
As you may already know, the business, tech, and cybersecurity industries have been buzzing about Log4Shell (CVE-2021-44228), aka Logjam, the latest…
newswww.malwarebytes.comDec 14, 2021, 5:00 PM - The Laconic Log4Shell FAQCheck Point Research
What is Log4Shell (CVE-2021-44228)? A Remote Code Execution vulnerability in log4j2, a popular logging framework used in Java applications. What does this mean in practice? It means you can compromise a machine by sending it the string ${ jndi:ldap://path/to/code}, as long as you can get the string logged by a Java application that uses a […]
vendorresearch.checkpoint.comDec 14, 2021, 4:00 PM US CISA ordered federal agencies to address the critical Log4Shell vulnerability in the Log4j library by December 24th, 2021. US CISA ordered federal agencies to address the critical Log4Shell vulnerability in the Log4j library by December 24th, 2021. The order aims at preventing threat actors could exploit the vulnerability in attacks against government systems. The CVE-2021-44228 flaw […]
newssecurityaffairs.comDec 14, 2021, 3:54 PMSecurityWeek has compiled a list of useful Log4Shell tools and resources for defenders.
newswww.securityweek.comDec 14, 2021, 2:11 PMSeveral types of malware are being delivered in attacks exploiting the recently disclosed Log4j vulnerability named Log4Shell and LogJam.
newswww.securityweek.comDec 14, 2021, 12:16 PMIndustrial organizations are exposed to attacks leveraging a recently disclosed — and already exploited — vulnerability affecting the widely used Log4j logging utility.
newswww.securityweek.comDec 14, 2021, 9:34 AM- The Log4j JNDI attack and how to prevent itHelp Net Security
The disclosure of the critical Log4Shell (CVE-2021-44228) vulnerability and the release of first one and than additional PoC exploits has been an unwelcome surprise for the entire information security community, but most of all those who are tasked with keeping enterprise systems and network secure. The timing of it all could be worse – it could have happened on Christmas Eve, for example – but the news hitting on a Thursday evening/Friday in the run-up … More →
newswww.helpnetsecurity.comDec 13, 2021, 6:35 PM - 13th December – Threat Intelligence ReportCheck Point Research
For the latest discoveries in cyber research for the week of 13th December, please download our Threat Intelligence Bulletin. Top Attacks and Breaches Check Point Research warns of potential ransomware attacks as samples of Emotet are fast-spreading via Trickbot. Since the Emotet takedown 10 months ago, CPR has spotted over 140,000 victims of Trickbot, across […]
vendorresearch.checkpoint.comDec 13, 2021, 3:46 PM The U.S. CISA added 13 new vulnerabilities to the Known Exploited Vulnerabilities Catalog, including Apache Log4Shell Log4j and Fortinet FortiOS issues. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added 13 new vulnerabilities to the Known Exploited Vulnerabilities Catalog, including recently disclosed Apache Log4Shell Log4j and Fortinet FortiOS flaws. Below is the list of new vulnerabilities added […]
newssecurityaffairs.comDec 13, 2021, 1:44 PMThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added 13 new vulnerabilities to its list of security errors known to be exploited, including Apache Log4j and Fortinet FortiOS bugs that were disclosed last week.
newswww.securityweek.comDec 13, 2021, 12:31 PMSeveral days have passed since the dramatic reveal of CVE-2021-44228 (aka Log4Shell), an easily exploitable (without authentication) RCE flaw in Apache Log4j, a popular open-source Java-based logging utility that’s seemingly used by most enterprise applications out there. The existence of the vulnerability and the public release of PoCs exploiting it have made this weekend a nightmare for those that are tasked with mitigating its fallout and keeping company systems and networks secure. Log4Shell update: What … More →
newswww.helpnetsecurity.comDec 13, 2021, 11:53 AMGovernment organizations and the private sector are responding to the disclosure of a critical vulnerability affecting the widely used Log4j logging utility, as exploitation attempts are on the rise. Apache Log4j is a Java-based logging tool that is included in various open source libraries, and is directly embedded in many popular software applications. It came to light recently that the cross-platform library is affected by a critical remote code execution vulnerability — tracked as CVE-2021-44228 and dubbed Log4Shell — that can be exploited to gain complete access to the targeted system by getting the affected application to log a specially crafted string. Log4Shell was reported to Log4j developers by the Alibaba cloud security team on November 24 and a patch was made available on December 6 with the release of version 2.15.0. Proof-of-concept (PoC) exploits were developed shortly after. The list of affected companies and software includes Apple, Tencent, Twitter, Baidu, Steam, Min…
newswww.securityweek.comDec 13, 2021, 11:31 AMThreat actors are already abusing Log4Shell vulnerability in the Log4j library for malicious purposes such as deploying malware. A few hours ago, researchers at NetLab 360 reported that their Anglerfish and Apacket honeypots were already hit by attacks attempting to trigger the Log4Shell flaw in the Log4j library. The attempts were carried out by Muhstik and Mirai botnets in […]
newssecurityaffairs.comDec 13, 2021, 9:44 AMQuebec shut down nearly 4,000 of its sites in response to the discovery of the Log4Shell flaw in the Apache Log4j Java-based logging library. Quebec shut down nearly 4,000 of its sites as a preventative measure after the disclosure of a PoC exploit for the Log4Shell flaw (CVE-2021-44228) in the Apache Log4j Java-based logging library. On Friday, 10, 2021, Chinese […]
newssecurityaffairs.comDec 12, 2021, 8:27 PM- Week in review: Apache Log4j 0day exploited, Kali Linux 2021.4 released, Patch Tuesday forecastHelp Net Security
Here’s an overview of some of last week’s most interesting news, articles and interviews: Critical RCE 0day in Apache Log4j library exploited in the wild (CVE-2021-44228) A critical zero-day vulnerability in Apache Log4j (CVE-2021-44228), a widely used Java logging library, is being leveraged by attackers in the wild. Kali Linux 2021.4 released: Wider Samba compatibility, The Social-Engineer Toolkit, new tools, and more! Offensive Security released Kali Linux 2021.4, which comes with a number of improvements: … More →
newswww.helpnetsecurity.comDec 12, 2021, 9:00 AM Cybereason researchers released a “vaccine” that mitigates the critical ‘Log4Shell’ Apache Log4j code execution vulnerability. Chinese security researcher p0rz9 publicly disclosed a Proof-of-concept exploit for a critical remote code execution zero-day vulnerability, tracked a CVE-2021-44228 (aka Log4Shell), in the Apache Log4j Java-based logging library. p0rz9 revealed that the CVE-2021-44228 can only be exploited if the log4j2.formatMsgNoLookups option is set to false. The Log4j is widely […]
newssecurityaffairs.comDec 11, 2021, 10:05 AMAttackers are actively exploiting a critical vulnerability in Apache Log4j, a logging library that’s used in potentially millions of Java-based applications, including web-based ones. Organizations should immediately review if their apps, especially the publicly accessible ones, use the library and should implement mitigations as soon as possible. A proof-of-concept exploit for the vulnerability, now tracked […]
newswww.csoonline.comDec 10, 2021, 9:40 PM- Another Apache Log4j Vulnerability Is Actively Exploited in the Wild (CVE-2021-44228) (Updated)Unit42
We provide background and a root cause analysis of CVE-2021-44228, a remote code execution vulnerability in Apache log4j, and we recommend mitigations.
vendorunit42.paloaltonetworks.comDec 10, 2021, 9:00 PM Understanding Log4Shell: the Apache log4j2 Remote Code Execution Vulnerability (CVE-2021-44228)
exploithorizon3.aiDec 10, 2021, 6:18 PMA critical zero-day vulnerability in Apache Log4j (CVE-2021-44228), a widely used Java logging library, is being leveraged by attackers in the wild – for now, fortunately, primarily to deliver coin miners. Reported to the Apache Software Foundation by Chen Zhaojun of Alibaba Cloud Security Team, the bug has now apparently been fixed in Log4j v2.15.0, just as a PoC has popped up on GitHub and there are reports that attackers are already attempting to compromise … More →
newswww.helpnetsecurity.comDec 10, 2021, 5:32 PMEnterprise security response teams are bracing for a hectic weekend as public exploits — and in-the-wild attacks — circulate for a gaping code execution hole in the widely used Apache Log4j utility.
newswww.securityweek.comDec 10, 2021, 4:53 PMExperts publicly disclose Proof-of-concept exploits for a critical zero-day vulnerability in the Apache Log4j Java-based logging library. Experts publicly disclose Proof-of-concept exploits for a critical remote code execution zero-day vulnerability, tracked a CVE-2021-44228 (aka Log4Shell), in the Apache Log4j Java-based logging library. The Chinese security researcher p0rz9 who publicly disclosed the PoC exploit code revealed […]
newssecurityaffairs.comDec 10, 2021, 3:18 PM- [Update: CISA issues Log4j vulnerabilities scanner] Log4j zero-day “Log4Shell” arrives just in time to ruin your weekendMalwarebytes Labs
If you’re running a service that relies on Apache Struts or uses the popular Apache Log4j utility we hope you haven’t…
newswww.malwarebytes.comDec 9, 2021, 5:00 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2021-45046CVSS 9.0 · Critical
It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configurations. This could allows attackers with control over Thre…
- CVE-2026-16723CVSS 9.0 · Critical
A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable under fastjson's stock default configuration — no AutoType…
- CVE-2026-61160CVSS 8.1 · High
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager). The supported version that is…
- CVE-2026-60719CVSS 9.9 · Critical
Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Web Service API). Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0…
- CVE-2026-60620CVSS 6.4 · Medium
Vulnerability in the JD Edwards EnterpriseOne Configurator product of Oracle JD Edwards (component: Configuration Management). The supported version that is affected is 9.2. Dif…
- CVE-2026-15535CVSS 2.1 · Low
A vulnerability was determined in AkariAsai self-rag up to 1fcdc420e48f50a7d7ab1ece5494221b93252e99. Affected by this issue is the function Indexer.deserialize_from of the file re…