Security Alert: Apache Log4j Zero Day Exploit
-
Apache Log4j Zero Day Exploit Puts Large Number of Servers at Severe Risk
A critical vulnerability in the open-source logging software Apache Log4j 2 is fueling a chaotic race in the cybersecurity world, with the Apache Software Foundation (ASF) issuing an emergency security update as bad actors searched for vulnerable servers.
-
CISA Adds Thirteen Known Exploited Vulnerabilities to Catalog | CISA
CISA has added thirteen new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence that threat actors are actively exploiting the vulnerabilities listed in the table below. These types of vulnerabilities are a frequent attack vector for malicious cyber actors of all types and pose significant risk to the federal enterprise.
-
- Login or register to post comments
Printer-friendly version
- 30384 reads
PDF version
More in Tux Machines
- Highlights
- Front Page
- Latest Headlines
- Archive
- Recent comments
- All-Time Popular Stories
- Hot Topics
- New Members
digiKam 7.7.0 is released
After three months of active maintenance and another bug triage, the digiKam team is proud to present version 7.7.0 of its open source digital photo manager. See below the list of most important features coming with this release.
| Dilution and Misuse of the "Linux" Brand
|
Samsung, Red Hat to Work on Linux Drivers for Future Tech
The metaverse is expected to uproot system design as we know it, and Samsung is one of many hardware vendors re-imagining data center infrastructure in preparation for a parallel 3D world.
Samsung is working on new memory technologies that provide faster bandwidth inside hardware for data to travel between CPUs, storage and other computing resources. The company also announced it was partnering with Red Hat to ensure these technologies have Linux compatibility.
| today's howtos
|
More on this today
Zero Day in Ubiquitous Apache Log4j Tool Under Active Attack | Threatpost
5 more links
Apache Log4j Security Vulnerabilities
“The [Internet’s] on fire” as techs race to fix critical software flaw
‘The [Internet]’s on fire’ as techs race to fix software flaw
‘Extremely bad’ vulnerability found in widely used logging system
Officials, experts sound the alarm about critical cyber vulnerability
Ariadne Conill's take
to secure the supply chain, you must properly fund it
The Register
Log4j RCE: Emergency patch issued to plug critical auth-free code execution hole in widely-used logging utility
Global race to patch critical computer bug
Global race to patch critical computer bug
Global tech experts race to fix ‘fully weaponised’ software flaw
Serious bug puts Apple iCloud, Twitter, Minecraft at hacking threat
In TC and IDG now
Apple iCloud, Twitter and Minecraft vulnerable to ‘ubiquitous’ zero-day exploit – TechCrunch
Countless Servers Are Vulnerable to Apache Log4j Zero-Day Exploit
SUSE Statement on log4j / log4shell / CVE-2021-44228...
SUSE Statement on log4j / log4shell / CVE-2021-44228 / Vulnerability
Critical RCE 0day in Apache Log4j library exploited in the wild
Critical RCE 0day in Apache Log4j library exploited in the wild (CVE-2021-44228)
The Log4j mess
The Log4j mess
Josh Bressers: log4j is hard to find and harder to fix
Josh Bressers: log4j is hard to find and harder to fix
A couple more
Logging library flaw opens software from different vendors to RCE
Global race to patch critical computer bug
Log4Shell explained
Log4Shell explained – how it works, why you need to know, and how to fix it – Naked Security
Six more today
No Java, No Cry - IPFire is NOT vulnerable to CVE-2021-44228
CyberInSecurity – Ah Oh it’s Java time
Log4Shell Exploitation Grows as Cybersecurity Firms Scramble to Contain Threat
Detect and block Log4j exploitation attempts with CrowdSec - The open-source & collaborative IPS
Hernan Vivani: log4j vulnerability – quick notes
PostgreSQL: PostgreSQL JDBC and the log4j CVE
CISA Creates Webpage for Apache Log4j Vulnerability
CISA Creates Wbpage for Apache Log4j Vulnerability CVE-2021-44228
Worst effects of logging flaw yet to be experienced
Worst effects of logging flaw yet to be experienced: security pro
Insecurity profiteers comment on it
Log4Shell vulnerability: What we know so far | WeLiveSecurity
Log4j: 5 more pieces
Log4j hole revives chatter on Big Biz funding open source • The Register
On the Log4j Vulnerability - Schneier on Security
Log4j Vulnerability Puts the Entire Internet at Risk: What You Need to Know - It's FOSS News
The Log4j bug exposes a bigger issue: Open-source funding (Updated)
Log4j Bug Highlights Open Source Funding Issues
Apache Log4j CVEs
Apache Log4j CVEs
PIA
Private Internet Access VPN Issues Update to Protect Users Against Apache Log4j/Log4Shell Exploit
Mining the Logs
Mining the Logs | Coder Radio 444
Nation-State Attackers, Ransomware Groups Take Aim...
Nation-State Attackers, Ransomware Groups Take Aim at Apache Log4j Flaw
Apache Log4j: remote code execution vulnerability
Apache Log4j: remote code execution vulnerability
Bruce Schneier
More Log4j News
Brodie Robertson
Log4J Vulnerability Isn't Going Anywhere Soon - Invidious
Log4j
Log4j is patched, but the exploits are just getting started
Lobbying
Officials point to Apache vulnerability in urging passage of cyber incident reporting bill
Behlendorf
Open Source Foundations Must Work Together to Prevent the Next Log4Shell Scramble
Hackaday
This Week In Security: Log4j, PDF CPU, And I Hacked Starlink | Hackaday
Corporate voices
The Log4j Vulnerability: What You Still Need to Know
CISA Issues ED 22-02 Directing Federal Agencies to Mitigate...
CISA Issues ED 22-02 Directing Federal Agencies to Mitigate Apache Log4j Vulnerabilities
Google's respons
Google Online Security Blog: Understanding the Impact of Apache Log4j Vulnerability
Understanding the Impact of Apache Log4j Vulnerability (Google) [LWN.net]
GIMP is not affected by the log4j vulnerability
GIMP is not affected by the log4j vulnerability
Steven J. Vaughan-Nichols
Security firm Blumira discovers major new Log4j attack vector
"Did you know that Ingenuity, the Mars 2020 Helicopter..."
Mars helicopter has Log4j bug, breaks records all the same • The Register
How to Check If Your Server Is Vulnerable to the log4j Java...
How to Check If Your Server Is Vulnerable to the log4j Java Exploit (Log4Shell)
Log4j: Everything You Need to Know
Log4j: Everything You Need to Know
Critical Log4Shell (Apache Log4j) Zero-Day Attack Analysis
Critical Log4Shell (Apache Log4j) Zero-Day Attack Analysis (CVE-2021-44228)
“Open source” is not broken
“Open source” is not broken
Massive Log4Shell internet security flaw threatens everyone
Massive Log4Shell internet security flaw threatens everyone — what you can do
Log4Shell Exploit, Vulnerability Explained: What to do If...
Log4Shell Exploit, Vulnerability Explained: What to do If You're Hacked
AP report
EXPLAINER: The security flaw that’s freaked out the internet
Canadian angle site
Canadian websites temporarily shut down as world scrambles to mitigate or patch Log4Shell vulnerability
How Apache Raced to Fix a Potentially Disastrous Software Flaw
How Apache Raced to Fix a Potentially Disastrous Software Flaw
Log4j gets a second update as security woes pile up
Log4j gets a second update as security woes pile up
Log4j's project sponsorship skyrockets after critical bug
Log4j's project sponsorship skyrockets after critical bug exploitation
What Is Log4j Security Flaw That's Freaking Out the Internet
What Is Log4j? The Security Flaw That's Freaking Out the Internet
US Warns Hundreds of Millions of Devices at Risk Over...
US Warns Hundreds of Millions of Devices at Risk Over New Software Vulnerability
Mainstream media
The Log4j security flaw could impact the entire internet. Here's what you should know
This security flaw could impact the entire internet. Here's what you should know
Software Flaw Sparks Global Race to Patch Bug
Software vulnerability expected to persist, possibly for months
4 more
A software flaw exposes major companies' servers
Mars helicopter mission (which Apache says is powered byLog4j) overcomes separate network glitch to confirm new flight record
Minecraft Log4J bug ‘worst computer vulnerability' in years, experts warn
Serious Security: OpenSSL fixes “error conflation” bugs – how mixing up mistakes can lead to trouble
VLC
VLC and log4j
The [Internet] runs on free open-source software
The [Internet] runs on free open-source software. Who pays to fix it?
Security News This Week: Buckle Up for More Log4j Madness
Security News This Week: Buckle Up for More Log4j Madness
Josh Bressers: Episode 302 – Log4j is a mess
Josh Bressers: Episode 302 – Log4j is a mess
Log4Shell: A new fix, details of active attacks, and risk...
Log4Shell: A new fix, details of active attacks, and risk mitigation recommendations
Log libraries and the tendency to open holes in things
Log libraries and the tendency to open holes in things
Log4j flaw needs immediate remediation
Log4j flaw needs immediate remediation
The Real Fix for Log4j Isn't a Patch.
The Real Fix for Log4j Isn't a Patch.
How To Detect and Mitigate the Log4Shell Vulnerability
Guide: How To Detect and Mitigate the Log4Shell Vulnerability (CVE-2021-44228 & CVE-2021-45046)
A couple more a couple of hours ago
AMD slips by as Log4Shell exploit affects other top tech giants, such as Intel, Microsoft, and NVIDIA
How to check if your Linux servers are vulnerable to the Log4j flaw with a single command - TechRepublic
Mitigating Log4Shell and Other Log4j-Related Vulnerabilities
Mitigating Log4Shell and Other Log4j-Related Vulnerabilities
Windows
Log4j vulnerability now used to install Dridex banking malware
Open-source software holds the key to solving Log4Shell...
Open-source software holds the key to solving Log4Shell-like problems
Security chief warns of new telco core threat
Security chief warns of new telco core threat, Security | TelecomTV
Belgian defence ministry admits attackers accessed its computers
Belgian defence ministry admits attackers accessed its computer network by exploiting Log4j vulnerability
Log4Shell — Preparing for What Comes Next
Log4Shell — Preparing for What Comes Next
Bad things come in threes: Apache reveals another Log4J bug
Bad things come in threes: Apache reveals another Log4J bug
Meanwhile in China
Alibaba Employee First Spotted Log4j Software Flaw but Now the Company Is in Hot Water With Beijing
‘Perfect storm’: Inside the race to fix a potentially disastrous
‘Perfect storm’: Inside the race to fix a potentially disastrous software flaw
Real-Time Protection of Log4j with AppTrana
Real-Time Protection of Log4j with AppTrana – Through its Risk-Based Approach
China regulator suspends cyber security deal with Alibaba Cloud
China regulator suspends cyber security deal with Alibaba Cloud
5 days ago
Major security flaw leaves companies vulnerable to ransomware
3 days ago
Apache's new security update for HTTP Server fixes two flaws
Josh Bressers: Episode 303 – Log4j Christmas Spectacular!
Josh Bressers: Episode 303 – Log4j Christmas Spectacular!
Check for Log4j vulnerabilities with this simple-to-use script
Check for Log4j vulnerabilities with this simple-to-use script
In CounterPunch
What is Log4j? The Latest Internet Vulnerability
Open source security leader Brian Behlendorf discusses...
Open source security leader Brian Behlendorf discusses the impact of Log4j
Oligarch-owned media
Lesson from Log4j: Open-source software improvements need help from feds
Open source isn't the security problem – misusing it is
Open source isn't the security problem – misusing it is [Ed: Richard Waters has a long history attacking Free software [1, 2, 3, 4, 5, 6, 7]; his employer receives money from Bill Gates]
Late one
5 Highlights from the U.S. Senate’s Log4J Vulnerability Hearing